Fedora has issued an advisory on February 8: https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/JF3RU3VMLP5SS4MXAEKQKAGTSPN3KMHJ/ Mageia 7 is also affected.
Whiteboard: (none) => MGA7TOO
Status comment: (none) => Patch available from Fedora
Assigning to Marc as the registered maintainer, CC wally as the main recent committer of 'texlive'.
Assignee: bugsquad => mageiaCC: (none) => jani.valimaa
I don't think we are affected. This is only true if not linked against libkpathsea; but we link against it. Running the testcase does not produce any buffer overflows. I thnik we can close this one.
Sometimes our compiler flags can protect us from actually seeing the buffer overflows, but I think that you're right that we're not hitting that codepath.
Status: NEW => RESOLVEDResolution: (none) => INVALID