CVE-2025-0395 was announced here: https://www.openwall.com/lists/oss-security/2025/01/22/4 Fix: - for 2.40 (Cauldron): https://sourceware.org/git/gitweb.cgi?p=glibc.git;h=7d4b6bcae91f29d7b4daf15bab06b66cf1d2217c - for 2.36 (Mga9): https://sourceware.org/git/gitweb.cgi?p=glibc.git;h=7971add7ee4171fdd8dfd17e7c04c4ed77a18845
Whiteboard: (none) => MGA9TOOSource RPM: (none) => glibc-2.40-1.mga10.src.rpm, glibc-2.36-54.mga9.src.rpmCVE: (none) => CVE-2025-0395Status comment: (none) => Patches available from upstream
Suggested advisory: ======================== The updated packages fix a security vulnerability: When the assert() function in the GNU C Library versions 2.13 to 2.40 fails, it does not allocate enough space for the assertion failure message string and size information, which may lead to a buffer overflow if the message string size aligns to page size. (CVE-2025-0395) References: https://www.openwall.com/lists/oss-security/2025/01/22/4 ======================== Updated packages in core/updates_testing: ======================== glibc-2.36-55.mga9 glibc-devel-2.36-55.mga9 glibc-doc-2.36-55.mga9.noarch.rpm glibc-i18ndata-2.36-55.mga9 glibc-profile-2.36-55.mga9 glibc-static-devel-2.36-55.mga9 glibc-utils-2.36-55.mga9 nscd-2.36-55.mga9 from SRPM: glibc-2.36-55.mga9.src.rpm
Status: NEW => ASSIGNEDVersion: Cauldron => 9Assignee: bugsquad => qa-bugsStatus comment: Patches available from upstream => (none)Source RPM: glibc-2.40-1.mga10.src.rpm, glibc-2.36-54.mga9.src.rpm => glibc-2.36-54.mga9.src.rpmWhiteboard: MGA9TOO => (none)
MGA9-64, Xfce, Asus Laptop AMD A6-9225 RADEON R4 RTL8723BE Bluetooth The following 2 packages are going to be installed: - glibc-2.36-55.mga9.x86_64 - nscd-2.36-55.mga9.x86_64 0B of additional disk space will be used. ---- rebooted lived with it for awhile - no issues on my end
CC: (none) => brtians1
CC: (none) => mageia
MGA9-64 Plasma, I5-7500, Nvidia Quadro K620 graphics. Updated glibc, glibc-devel, and nscd. Rebooted without issues, so far. Will use it for a while before declaring it OK. Glibc is so basic to Mageia operation that we should have some 32-bit tests in addition to 64, and as many systems of both arches as reasonably possible.
CC: (none) => andrewsfarm
Keywords: (none) => advisory
x86_64 OK here; glibc, glibc-devel, and nscd updated on three Plasma systems i586 OK here: Updated incl all in testing on Thinpkad T43, LXDE: Used for a while with Firefox, Libreoffice, our (old) nextcloud-client Also suspend-resume, and hiobernate-restore OK incl wifi (using networkmanager)
CC: (none) => fri
MGA9-64 Plasma Wayland on Coompaq H000SB No installation issues. Did a cold restart after installation. Web access OK (wireless), Updating this bug. Tested different document types, pictures, music, video, no problems encountered.
CC: (none) => herman.viaene
MGA9-32, AMD A6-3420M APU with Radeon(tm) HD Graphics, old Laptop The following 2 packages are going to be installed: - glibc-2.36-55.mga9.i586 - nscd-2.36-55.mga9.i586 ---rebooted spending time using firefox, etc. - working
RH i586 installing glibc-2.36-55.mga9.i586.rpm glibc-utils-2.36-55.mga9.i586.rpm glibc-devel-2.36-55.mga9.i586.rpm from //home/katnatek/qa-testing/i586 Preparing... ####################################################################################### 1/3: glibc ####################################################################################### 2/3: glibc-devel ####################################################################################### 3/3: glibc-utils ####################################################################################### 1/3: removing glibc-utils-6:2.36-54.mga9.i586 ####################################################################################### 2/3: removing glibc-devel-6:2.36-54.mga9.i586 ####################################################################################### 3/3: removing glibc-6:2.36-54.mga9.i586 ####################################################################################### You should restart your computer for glibc restarting urpmi installing glibc-doc-2.36-55.mga9.noarch.rpm nscd-2.36-55.mga9.i586.rpm glibc-i18ndata-2.36-55.mga9.i586.rpm glibc-profile-2.36-55.mga9.i586.rpm from //home/katnatek/qa-testing/i586 Preparing... ####################################################################################### 1/4: glibc-profile ####################################################################################### 2/4: glibc-i18ndata ####################################################################################### 3/4: glibc-doc ####################################################################################### 4/4: nscd ####################################################################################### 1/4: removing glibc-profile-6:2.36-54.mga9.i586 ####################################################################################### 2/4: removing glibc-i18ndata-6:2.36-54.mga9.i586 ####################################################################################### 3/4: removing nscd-6:2.36-54.mga9.i586 ####################################################################################### 4/4: removing glibc-doc-6:2.36-54.mga9.noarch ####################################################################################### Reboot Not issues to report after use the system for a while
RH x86_64 installing glibc-2.36-55.mga9.x86_64.rpm glibc-devel-2.36-55.mga9.x86_64.rpm from //home/katnatek/qa-testing/x86_64 Preparing... ################################################################################################## 1/2: glibc ################################################################################################## 2/2: glibc-devel ################################################################################################## 1/2: removing glibc-devel-6:2.36-54.mga9.x86_64 ################################################################################################## 2/2: removing glibc-6:2.36-54.mga9.x86_64 ################################################################################################## You should restart your computer for glibc Error: Missing /usr/lib64/gconv/gconv-modules.cache file.n The last message is already reported bug#31909 not additional things to report The system works as usual after reboot
MGA9-32 on Foolishness, my Dell Inspiron 5100, P4, radeon RV200 graphics. Tested with both the desktop and desktop586 kernels. No installation issues with either kernel, and no issues apparent after the reboot.
More than enough tests, I think. Validating.
Keywords: (none) => validated_updateWhiteboard: (none) => MGA9-32-OK MGA9-64-OKCC: (none) => sysadmin-bugs
An update for this issue has been pushed to the Mageia Updates repository. https://advisories.mageia.org/MGASA-2025-0026.html
Resolution: (none) => FIXEDStatus: ASSIGNED => RESOLVED