GNU bug report logs

#70581 PHP, glibc, and CVE-2024-2961

PackageSource(s)Maintainer(s)
guix PTS Buildd Popcon
Full log

Message #5 received at submit@debbugs.gnu.org (full text, mbox, reply):

Received: (at submit) by debbugs.gnu.org; 26 Apr 2024 06:45:31 +0000
From debbugs-submit-bounces@debbugs.gnu.org Fri Apr 26 02:45:31 2024
Received: from localhost ([127.0.0.1]:33648 helo=debbugs.gnu.org)
	by debbugs.gnu.org with esmtp (Exim 4.84_2)
	(envelope-from <debbugs-submit-bounces@debbugs.gnu.org>)
	id 1s0FKs-0007I5-MB
	for submit@debbugs.gnu.org; Fri, 26 Apr 2024 02:45:31 -0400
Received: from lists.gnu.org ([2001:470:142::17]:59610)
 by debbugs.gnu.org with esmtp (Exim 4.84_2)
 (envelope-from <cnx@loang.net>) id 1s0FKq-0007GL-76
 for submit@debbugs.gnu.org; Fri, 26 Apr 2024 02:45:29 -0400
Received: from eggs.gnu.org ([2001:470:142:3::10])
 by lists.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256)
 (Exim 4.90_1) (envelope-from <cnx@loang.net>) id 1s0FKP-0007Xb-E2
 for bug-guix@gnu.org; Fri, 26 Apr 2024 02:45:01 -0400
Received: from tem.loang.net ([2a03:3b40:100::1:2])
 by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_128_GCM_SHA256:128)
 (Exim 4.90_1) (envelope-from <cnx@loang.net>) id 1s0FKN-0004TU-Jx
 for bug-guix@gnu.org; Fri, 26 Apr 2024 02:45:01 -0400
DKIM-Signature: a=rsa-sha256; bh=D8uAUsG5rzYaKX3jUZL5JknVpaDuuKM9HneVWiP5Y5k=; 
 c=relaxed/relaxed; d=loang.net;
 h=Subject:Subject:Sender:To:To:Cc:From:From:Date:Date:MIME-Version:MIME-Version:Content-Type:Content-Type:Content-Transfer-Encoding:Content-Transfer-Encoding:Reply-To:In-Reply-To:Message-Id:Message-Id:References:Autocrypt:Openpgp;
 i=@loang.net; s=default; t=1714113892; v=1; x=1714545892;
 b=OwYJSxppqBcz3exTR3jxl6tG2Icl/SJOjaXXEg23WWBJ6UQvqP7Zfcjk/dhnOKUTSi0KUyaN
 S9pj4c5oRj+srP2I0qBQBXui1KYW01FO9b0r6BCgGDETwuKSBA43VLMHQXweZMCPeXxZr1qZTwh
 Mb8AxT7BwEdZ0NEg4/Iadg2lGdeVd1trlVekt/yVobR+SYnn616dUUzZ3pHNPWQ7HrW2fH+5vL4
 8Fd20q6l8VNkMd4sX49MIIGwfL14JUc6Psmv5r5UeMNgOSRpZDCzmcHYtwg54StBqC3ISBKOhlw
 fJAyoQT6aqA06RoZ/I2b9NDxuT71eTMWy1hRIeHpOaYKQ==
Received: by tem.loang.net (envelope-sender <cnx@loang.net>) with ESMTPS id
 6b865c07; Fri, 26 Apr 2024 06:44:52 +0000
Mime-Version: 1.0
Content-Transfer-Encoding: quoted-printable
Content-Type: text/plain; charset=UTF-8
Date: Fri, 26 Apr 2024 15:44:50 +0900
Subject: PHP, glibc, and CVE-2024-2961
To: <bug-guix@gnu.org>
From: "McSinyx" <cnx@loang.net>
Message-Id: <D0TUHV4220TM.G0XZHTPBKVOQ@guix>
X-Mailer: aerc 0.15.2
Received-SPF: pass client-ip=2a03:3b40:100::1:2; envelope-from=cnx@loang.net;
 helo=tem.loang.net
X-Spam_score_int: -13
X-Spam_score: -1.4
X-Spam_bar: -
X-Spam_report: (-1.4 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1,
 DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1,
 SPF_HELO_SOFTFAIL=0.732, SPF_PASS=-0.001 autolearn=no autolearn_force=no
X-Spam_action: no action
X-Spam-Score: 1.0 (+)
X-Debbugs-Envelope-To: submit
X-BeenThere: debbugs-submit@debbugs.gnu.org
X-Mailman-Version: 2.1.18
Precedence: list
List-Id: <debbugs-submit.debbugs.gnu.org>
List-Unsubscribe: <https://debbugs.gnu.org/cgi-bin/mailman/options/debbugs-submit>, 
 <mailto:debbugs-submit-request@debbugs.gnu.org?subject=unsubscribe>
List-Archive: <https://debbugs.gnu.org/cgi-bin/mailman/private/debbugs-submit/>
List-Post: <mailto:debbugs-submit@debbugs.gnu.org>
List-Help: <mailto:debbugs-submit-request@debbugs.gnu.org?subject=help>
List-Subscribe: <https://debbugs.gnu.org/cgi-bin/mailman/listinfo/debbugs-submit>, 
 <mailto:debbugs-submit-request@debbugs.gnu.org?subject=subscribe>
Errors-To: debbugs-submit-bounces@debbugs.gnu.org
Sender: "Debbugs-submit" <debbugs-submit-bounces@debbugs.gnu.org>
X-Spam-Score: -0.0 (/)
Hello Guix,

Last week, an overflow bug in glibc's iconv(3) was discovered:
https://www.openwall.com/lists/oss-security/2024/04/17/9

It may enable remove code execution through PHP.  Due to
the immutable nature of Guix, is it possible to hotpatch
this using graft, or do we need to rebuild to world?
https://rockylinux.org/news/glibc-vulnerability-april-2024/

Kind regards,
McSinyx




Send a report that this bug log contains spam.


debbugs.gnu.org maintainers <help-debbugs@gnu.org>. Last modified: Sat Dec 21 18:05:04 2024; Machine Name: wallace-server

GNU bug tracking system

Debbugs is free software and licensed under the terms of the GNU Public License version 2. The current version can be obtained from https://bugs.debian.org/debbugs-source/.

Copyright © 1999 Darren O. Benham, 1997,2003 nCipher Corporation Ltd, 1994-97 Ian Jackson, 2005-2017 Don Armstrong, and many other contributors.