Bug 34580 - glibc new security issue CVE-2025-8058
Summary: glibc new security issue CVE-2025-8058
Status: RESOLVED FIXED
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 9
Hardware: All Linux
Priority: Normal normal
Target Milestone: ---
Assignee: QA Team
QA Contact: Sec team
URL:
Whiteboard: MGA9-32-OK MGA9-64-OK
Keywords: advisory, validated_update
Depends on:
Blocks: 34584
  Show dependency treegraph
 
Reported: 2025-08-27 13:08 CEST by Nicolas Salguero
Modified: 2025-09-01 20:21 CEST (History)
5 users (show)

See Also:
Source RPM: glibc-2.36-56.mga9.src.rpm
CVE: CVE-2025-8058
Status comment:


Attachments

Description Nicolas Salguero 2025-08-27 13:08:50 CEST
CVE-2025-8058 was announced here:
https://www.openwall.com/lists/oss-security/2025/07/23/1

It is fixed in 2.42 so only Mageia 9 is affected.
Nicolas Salguero 2025-08-27 13:09:10 CEST

Source RPM: (none) => glibc-2.36-56.mga9.src.rpm
CVE: (none) => CVE-2025-8058

Comment 1 Nicolas Salguero 2025-08-27 14:47:27 CEST
Suggested advisory:
========================

The updated packages fix a security vulnerability:

Double-free after allocation failure in regcomp. (CVE-2025-8058)

References:
https://www.openwall.com/lists/oss-security/2025/07/23/1
========================

Updated packages in core/updates_testing:
========================
glibc-2.36-57.mga9
glibc-devel-2.36-57.mga9
glibc-doc-2.36-57.mga9
glibc-i18ndata-2.36-57.mga9
glibc-profile-2.36-57.mga9
glibc-static-devel-2.36-57.mga9
glibc-utils-2.36-57.mga9
nscd-2.36-57.mga9

from SRPM:
glibc-2.36-57.mga9.src.rpm

Assignee: bugsquad => qa-bugs
Status: NEW => ASSIGNED

katnatek 2025-08-27 22:43:57 CEST

Keywords: (none) => advisory

Comment 2 Brian Rockwell 2025-08-27 23:44:58 CEST
MGA9-32, AMD A6-3420M APU with Radeon(tm) HD Graphics, old Laptop

The following 11 packages are going to be installed:

- firefox-128.14.0-1.4.mga9.i586
- firefox-en_CA-128.14.0-1.mga9.noarch
- firefox-en_GB-128.14.0-1.mga9.noarch
- firefox-en_US-128.14.0-1.mga9.noarch
- glibc-2.36-57.mga9.i586
- libnspr4-4.37-1.mga9.i586
- libnss3-3.115.1-1.mga9.i586
- meta-task-9-4.mga9.noarch
- nss-3.115.1-1.mga9.i586
- rootcerts-20250808.00-1.mga9.noarch
- rootcerts-java-20250808.00-1.mga9.noarch

---rebooted

$ firefox -version
Mozilla Firefox 128.14.0esr
$ uname -a
Linux localhost 6.6.101-desktop-1.mga9 #1 SMP PREEMPT_DYNAMIC Sun Aug  3 00:54:01 UTC 2025 i686 GNU/Linux



spending time using firefox, etc.  - working
sound working fine
system behaving

CC: (none) => brtians1

Comment 3 katnatek 2025-08-28 00:03:27 CEST
RH i586

installing glibc-doc-2.36-57.mga9.noarch.rpm nscd-2.36-57.mga9.i586.rpm glibc-profile-2.36-57.mga9.i586.rpm glibc-i18ndata-2.36-57.mga9.i586.rpm from //home/katnatek/qa-testing/i586
Preparing...                     #######################################################################################
      1/4: glibc-i18ndata        #######################################################################################
      2/4: glibc-profile         #######################################################################################
      3/4: glibc-doc             #######################################################################################
      4/4: nscd                  #######################################################################################
      1/4: removing glibc-i18ndata-6:2.36-56.mga9.i586
                                 #######################################################################################
      2/4: removing glibc-profile-6:2.36-56.mga9.i586
                                 #######################################################################################
      3/4: removing nscd-6:2.36-56.mga9.i586
                                 #######################################################################################
      4/4: removing glibc-doc-6:2.36-56.mga9.noarch
                                 #######################################################################################

Reboot 
Looks OK for the moment
katnatek 2025-08-28 02:55:15 CEST

Blocks: (none) => 34584

PC LX 2025-08-28 11:18:30 CEST

CC: (none) => mageia

Comment 4 Morgan Leijström 2025-08-28 22:23:40 CEST
Updated installed packages to

- glibc-2.36-57.mga9.x86_64
- glibc-devel-2.36-57.mga9.x86_64

Kept using, install old and new kernels, Firefox, Thunderbird, LibreOffice, Printing...  various usage in Plasma, rebooting

On my workstation Svarten;

[morgan@svarten ~]$ inxi -SMCG
System:
  Host: svarten.tribun Kernel: 6.12.43-desktop-1.stable.mga9 arch: x86_64
    bits: 64
  Desktop: KDE Plasma v: 5.27.10 Distro: Mageia 9
Machine:
  Type: Desktop Mobo: ASRock model: P55 Pro serial: <superuser required>
    BIOS: American Megatrends v: P2.60 date: 08/20/2010
CPU:
  Info: quad core model: Intel Core i7 870 bits: 64 type: MT MCP cache:
    L2: 1024 KiB
  Speed (MHz): avg: 3214 min/max: 1200/2934 cores: 1: 3214 2: 3214 3: 3214
    4: 3214 5: 3214 6: 3214 7: 3214 8: 3214
Graphics:
  Device-1: Advanced Micro Devices [AMD/ATI] Navi 24 [Radeon RX 6400/6500
    XT/6500M] driver: amdgpu v: kernel
  Display: x11 server: X.org v: 1.21.1.8 with: Xwayland v: 22.1.9 driver: X:
    loaded: amdgpu,v4l dri: radeonsi gpu: amdgpu resolution: 3840x2160~60Hz
  API: EGL v: 1.5 drivers: kms_swrast,radeonsi,swrast
    platforms: gbm,x11,surfaceless,device
  API: OpenGL v: 4.6 compat-v: 4.5 vendor: amd mesa v: 25.0.7 renderer: AMD
    Radeon RX 6400 (radeonsi navi24 LLVM 15.0.6 DRM 3.61
    6.12.43-desktop-1.stable.mga9)

CC: (none) => fri

Comment 5 Brian Rockwell 2025-08-29 02:59:24 CEST
MGA9-64


- glibc-2.36-57.mga9.x86_64
- meta-task-9-4.mga9.noarch


Legacy Nextcloud server test

--- rebooted

working as expected
Comment 6 Thomas Andrews 2025-08-29 05:25:24 CEST
MGA9-64 Plasma,i5-7500, nvidia Quadro K620 graphics (nvidia-current).

No installation issues, and so far, no issues with operation.

CC: (none) => andrewsfarm

Comment 7 Brian Rockwell 2025-08-30 22:13:05 CEST
MGA9-64, Ryzen 2600, etc.

Seems to be installing with any testing patches and working as expected.
Comment 8 Thomas Andrews 2025-08-31 02:46:58 CEST
Built the nvidia-current module for the kernel currently under test with no issues.

Seems to be OK on both arches. Validating.

Whiteboard: (none) => MGA9-32-OK MGA9-64-OK
Keywords: (none) => validated_update
CC: (none) => sysadmin-bugs

Comment 9 Morgan Leijström 2025-08-31 14:34:31 CEST
Quickly adding that it works OK also on my T43, i586 together with kernel 6.6.103, and x86_64 on two additional systems.
Comment 10 Mageia Robot 2025-09-01 20:21:04 CEST
An update for this issue has been pushed to the Mageia Updates repository.

https://advisories.mageia.org/MGASA-2025-0220.html

Status: ASSIGNED => RESOLVED
Resolution: (none) => FIXED


Note You need to log in before you can comment on or make changes to this bug.