ELSA-2024-12444

ELSA-2024-12444 - glibc security update

Type:SECURITY
Impact:IMPORTANT
Release Date:2024-06-19

Description


[2.17-326.0.9.3]
- Forward-port Oracle patches to 2.17-326.3
Reviewed-by: Jose E. Marchesi
Oracle history:
June-22-2023 Cupertino Miranda - 2.17-326.0.9
- OraBug 35517820 Reworked previous patch for OraBug 35318841 and removed
free() of stack allocations.
Reviewed-by: Jose E. Marchesi
June-20-2023 Cupertino Miranda - 2.17-326.0.7
- OraBug 35517820 Do not allocate heap memory in __nptl_tunables_init.
- This issue was introduced and fixed in patch related to OraBug 35318841.
Reviewed-by: Jose E. Marchesi
April-21-2023 Cupertino Miranda - 2.17-326.0.5
- OraBug 35318841 Glibc tunable to disable huge pages on pthread_create stacks
Reviewed-by: Jose E. Marchesi
December-19-2022 Cupertino Miranda - 2.17-326.0.3
- OraBug 34909902 vDSO timer functions support on i686
Reviewed-by: Jose E. Marchesi
May-18-2022 Patrick McGehearty - 2.17-326.0.1
- Forward-port Oracle patches to 2.17-326.
Reviewed-by: Jose E. Marchesi
April-26-2022 Patrick McGehearty - 2.17-325.0.3
- OraBug 33968985 Security Patches
This release fixes CVE-2022-23219, CVE-2022-23218, and CVE-2021-3999
Reviewed-by: Jose E. Marchesi
October-12-2021 Patrick McGehearty - 2.17-325.0.1
- Merge el7 u9 errata4 patch with Oracle patches
Review-exception: Simple merge
- Merge el7 u9 errata patches with Oracle patches
Review-exception: Simple merge
- Adding three arm specific patches to allow glibc x86 tree to be used for
- ILOM and other arm builds
Reviewed-by: Jose E. Marchesi
- Merge el7 u8 patches with Oracle patches
Review-exception: Simple merge
- Adding Mike Fabian's C.utf-8 patch (C.utf-8 is a unicode-aware version
of the C locale)
Orabug 29784239.
Reviewed-by: Jose E. Marchesi
- Remove glibc-ora28641867.patch as duplicate of glibc-rh1705899-4.patch
- Make _IO_funlockfile match __funlockfile and _IO_flockfile match __flockfile
Both should test
if ((stream->_flags & _IO_USER_LOCK) == 0)
_IO_lock_lock (*stream->_lock);
OraBug 28481550.
Reviewed-by: Jose E. Marchesi
- Modify glibc-ora28849085.patch so it works with RHCK kernels.
Orabug 28849085.
- Reviewed-by: Egeyar Bagcioglu
- Use NLM_F_SKIP_STATS in uek2 and RTEXT_FILTER_SKIP_STATS in uek4 in getifaddrs.
- Orabug 28849085
- Reviewed-by: Patrick McGehearty
- Mention CVE numbers in the .spec file for CVE-2015-8983 and CVE-2015-8984.
- Orabug 25558067.
- Reviewed-by: Egeyar Bagcioglu
- Regenerate plural.c
- OraBug 28806294.
- Reviewed-by: Jose E. Marchesi
- intl: Port to Bison 3.0
- Backport of upstream gettext commit 19f23e290a5e4a82b9edf9f5a4f8ab6192871be9
- OraBug 28806294.
- Reviewed-by: Patrick McGehearty
- Fix dbl-64/wordsize-64 remquo (bug 17569).
- Backport of upstream d9afe48d55a412e76b0dcb28335fd4b390fe07ae
- OraBug 19570749.
- Reviewed-by: Jose E. Marchesi
- libio: Disable vtable validation in case of interposition.
- Backport of upstream c402355dfa7807b8e0adb27c009135a7e2b9f1b0.
- OraBug 28641867.
- Reviewed-by: Egeyar Bagcioglu
- Include-linux-falloc.h-in-bits-fcntl-linux.h
- Defines FALLOC_FL_PUNSH_HOLE, FALLOC_FL_KEEP_SIZE,
FALLOC_FL_COLLAPSE_RANGE, and FALLOC_FL_ZERO_RANGE
- OraBug 28483336
- Add MAP_SHARED_VALIDATE and MAP_SYNC flags to
- sysdeps/unix/sysv/linux/x86/bits/mman.h
- OraBug 28389572
- Update bits/siginfo.h with Linux hwpoison SIGBUS changes.
- Adds new SIGBUS error codes for hardware poison signals, syncing with
the current kernel headers (v3.9).
- It also adds si_trapno field for alpha.
- New values: BUS_MCEERR_AR, BUS_MCEERR_AO
- OraBug 28124569


Related CVEs


CVE-2024-2961
CVE-2024-33599
CVE-2024-33601
CVE-2024-33602
CVE-2024-33600

Updated Packages


Release/ArchitectureFilenamesha256Superseded By AdvisoryChannel Label
Oracle Linux 7 (x86_64) glibc-2.17-326.0.9.ksplice1.el7_9.3.src.rpm863fceabb3f255c6257d26f6fc17e0e0f050b19c2903c75c8f42b5b987a93ad1-ol7_x86_64_userspace_ksplice
glibc-2.17-326.0.9.ksplice1.el7_9.3.i686.rpm90c4c6467520bd2876f3cc14ce9d11863e6b1f0dd2b7dd6da8e6a25ef2858227-ol7_x86_64_userspace_ksplice
glibc-2.17-326.0.9.ksplice1.el7_9.3.x86_64.rpm4e00f0a762374ecd257ca5234a5ded15eecb4c69577f16740a186ea306b2b444-ol7_x86_64_userspace_ksplice
glibc-common-2.17-326.0.9.ksplice1.el7_9.3.x86_64.rpm049b96eaa1e2a8c58299c967c3902e55dbfe017a3ed34663a7546b5ad149a9d2-ol7_x86_64_userspace_ksplice
glibc-devel-2.17-326.0.9.ksplice1.el7_9.3.i686.rpm8dfdf4708c69bcd2e3c940872691439ab794067c7fd9b33acdcf4f857ba30c4e-ol7_x86_64_userspace_ksplice
glibc-devel-2.17-326.0.9.ksplice1.el7_9.3.x86_64.rpm6ae1fffd0df9c7336bd5de4b079f1713df11a1a708a24c11af9f6149e51d2c07-ol7_x86_64_userspace_ksplice
glibc-headers-2.17-326.0.9.ksplice1.el7_9.3.x86_64.rpmb9ffe2b5a9473e5ebf10a295d47592195465ef7357c1fbe4d73342e4e292228a-ol7_x86_64_userspace_ksplice
glibc-static-2.17-326.0.9.ksplice1.el7_9.3.i686.rpm42dbb19fcfdded76ac1cd399535ac2667050ab9ea5c8804da0b23b7ebbeff6d3-ol7_x86_64_userspace_ksplice
glibc-static-2.17-326.0.9.ksplice1.el7_9.3.x86_64.rpmfe18020982667407b9ff108b7b6a6e93e717f66cf8fcc3a80ca8c31cfbe7089f-ol7_x86_64_userspace_ksplice
glibc-utils-2.17-326.0.9.ksplice1.el7_9.3.x86_64.rpm47b0b3f952c71838f8ee7e0681e76f8ef8eef51a569f8800a7764f53947ef596-ol7_x86_64_userspace_ksplice
nscd-2.17-326.0.9.ksplice1.el7_9.3.x86_64.rpmf22b098adfcd3c3d3a556373c7fd8689516272259f99a54564d4ebd96ee7cd0c-ol7_x86_64_userspace_ksplice



This page is generated automatically and has not been checked for errors or omissions. For clarification or corrections please contact the Oracle Linux ULN team

software.hardware.complete