Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Deepin Integration]~[V23-Release] fix: CVE-2024-33599, CVE-2024-33600, CVE-2024-33601, CVE-2024-33602 by UTsweetyfish@deepin-community/glibc by deepin-community-ci-bot[bot] #8387

Closed
deepin-bot bot opened this issue May 6, 2024 · 8 comments
Assignees
Labels
Project:integrated 集成管理相关 吴波 吴波
Milestone

Comments

@deepin-bot
Copy link

deepin-bot bot commented May 6, 2024

Package information | 软件包信息

包名 版本
glibc 2.38-6deepin3

Package repository address | 软件包仓库地址

deb [trusted=yes] https://ci.deepin.com/repo/obs/deepin:/CI:/TestingIntegration:/test-integration-pr-1369/testing/ ./

Changelog | 更新信息

glibc (2.38-6deepin3) unstable; urgency=medium

  • debian/patches/git-updates.diff: update from upstream stable branch.
    • Fix a stack-based buffer overflow in nscd netgroup cache
      (CVE-2024-33599).
    • Fix a null pointer dereferences in nscd after failed netgroup cache
      insertion (CVE-2024-33600).
    • Fix a DoS in nscd in case of memory allocation failure (CVE-2024-33601).
    • Fix a memory corruption in nscd when the underlying NSS callback
      function does not use the buffer space to store all strings
      (CVE-2024-33602).
@deepin-bot
Copy link
Author

deepin-bot bot commented May 6, 2024

Integration Test Info

Test suggestion | 测试建议

cve漏洞修复 详情查看一楼的changelog

Influence | 影响范围

安全漏洞

ADDITIONAL INFORMATION | 额外补充

@deepin-bot
Copy link
Author

deepin-bot bot commented May 6, 2024

IntegrationProjector Notify the author
@UTsweetyfish: Integrated issue updated

@deepin-bot
Copy link
Author

deepin-bot bot commented May 6, 2024

IntegrationProjector Bot
Deepin Testing Integration Project Manager Info
Link to deepin-community/Repository-Integration#1369

@babyfengfjx babyfengfjx assigned kobe337 and unassigned babyfengfjx May 6, 2024
@babyfengfjx babyfengfjx moved this from In progress to 测试中 in v23-集成管理 May 6, 2024
@babyfengfjx babyfengfjx added the 吴波 吴波 label May 6, 2024
@babyfengfjx
Copy link

@kobe337 请开展集成验证。

@kobe337
Copy link

kobe337 commented May 7, 2024

(CVE-2024-33599). 修复 nscd 网络组缓存中基于堆栈的缓冲区溢出
上游公告: 在 glibc 网络组缓存中发现基于堆栈的缓冲区溢出缺陷。在某些情况下,它可能会触发基于堆栈的缓冲区溢出情况,这可能导致溢出类攻击。经过查看上游给出的代码修复补丁,核对本次更新的代码通过。
截图_选择区域_20240507092640

@kobe337
Copy link

kobe337 commented May 7, 2024

通过核对修复代码,校验通过。CVE-2024-33600
image

@kobe337
Copy link

kobe337 commented May 7, 2024

CVE-2024-33601CVE-2024-33602,查看上游修复代码,校验通过
image

@kobe337
Copy link

kobe337 commented May 7, 2024

【环境】:
镜像:https://cdimage.uniontech.com/community/releases/23-Beta3/
仓库:提测单仓库
内核:Linux deepinb3-PC 6.6.25-amd64-desktop-hwe #23.01.00.25 SMP PREEMPT_DYNAMIC Wed Apr 10 21:20:25 CST 2024 x86_64 GNU/Linux

【结论】:
更新至20240430测试通过,暂无严重问题及影响,核对提测cve漏洞patch通过,安装校验、版本核对
image

@kobe337 kobe337 assigned Zeno-sole and unassigned kobe337 May 7, 2024
@kobe337 kobe337 moved this from 测试中 to 测试通过 in v23-集成管理 May 7, 2024
@Zeno-sole Zeno-sole moved this from 测试通过 to 已集成 in v23-集成管理 May 7, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Project:integrated 集成管理相关 吴波 吴波
Projects
Archived in project
Development

No branches or pull requests

4 participants