-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Sat, 05 Jun 2021 20:20:42 +0200 Source: klibc Architecture: source Version: 2.0.6-1+deb10u1 Distribution: buster Urgency: medium Maintainer: maximilian attems <maks@debian.org> Changed-By: Ben Hutchings <benh@debian.org> Closes: 943425 989505 Changes: klibc (2.0.6-1+deb10u1) buster; urgency=medium . [ Ben Hutchings ] * Apply security fixes from 2.0.9 (Closes: #989505): - malloc: Set errno on failure - malloc: Fail if requested size > PTRDIFF_MAX (CVE-2021-31873) - calloc: Fail if multiplication overflows (CVE-2021-31870) - cpio: Fix possible integer overflow on 32-bit systems (CVE-2021-31872) - cpio: Fix possible crash on 64-bit systems (CVE-2021-31871) . [ Thorsten Glaser ] * {set,long}jmp [s390x]: save/restore the correct FPU registers (f8‥f15 not f1/f3/f5/f7) (Closes: #943425) Checksums-Sha1: 2f0f89eced8d45f0a08f1e3bc17fa607fb7c0730 2092 klibc_2.0.6-1+deb10u1.dsc 0c2f22490a85c7340f4c30eafa6a88df05d922fd 21444 klibc_2.0.6-1+deb10u1.debian.tar.xz 53cf4cd10be5a7cb0c538bd378ffd5aedc1a473b 5179 klibc_2.0.6-1+deb10u1_source.buildinfo Checksums-Sha256: 17f1cd026cfe8278a040a139d0d151c149732dae170dd7b1fa88c7a31e232299 2092 klibc_2.0.6-1+deb10u1.dsc 13616f100ca612ad59c785bfc427c3d86cd6aa067b1e7d270ba4ba07ebe3a28c 21444 klibc_2.0.6-1+deb10u1.debian.tar.xz b78752b3c518ddfa4ccc32547ae26a79818237bbd8960d351129040e3a665788 5179 klibc_2.0.6-1+deb10u1_source.buildinfo Files: 01d1a8fdebbb7fdb0bb96c639e2f981c 2092 libs optional klibc_2.0.6-1+deb10u1.dsc 919dc487eab25b7e766442497fb0aff3 21444 libs optional klibc_2.0.6-1+deb10u1.debian.tar.xz 261dabcfe4479482cc129ad2aad47ee9 5179 libs optional klibc_2.0.6-1+deb10u1_source.buildinfo -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEErCspvTSmr92z9o8157/I7JWGEQkFAmC7wRsACgkQ57/I7JWG EQklbRAAw6/kcJyX2nIps7/2eQD4Ecm3dD2dOOLIGLjfRUaQDcIYXqmiWbGOAp8s lru47V/BlEwuddFCctCLzHd+etqyaDNBvl7X+xxma3/h+FR+auLoQUB/HKy2y0gW MaFi2n5XPTTNkyH7CbWa18BMgIn0KWo21hDZ2vF80XlXiIO+b4PqlSgmqBTosVuQ DJKgiFw/BMXoMSJBxjyBiSfRtV8oD23hLzM+6a38Tg+KwPPnwsjEBZMprI+d/Z/H 6q4yArzvH+Yf6msqgaFGegy5WpZjTFXP0gXNq4k8UrfBZoEkGsHWnNaV/drPi+4G L89oafMViidsSUuEQ19U8Tc5tTmVCvmKGqVmhjI1y6vUnAKVQeIuAol3HaPVb9/a 6t5QBHN/NkjSseqfbG4teqGfoM2bQWg8LdowqbZxlIpORWs4EP2TMwMQ6/muAzmq iS3/VRt1317xFIJ9oEP9S+kJYAwzW5/kV/JtJbaB65uQdH5NwtoeAdtkKpaEs1+f 9a0ePqreBCbcdp6vBmt6ol+GKdgivkSpxCPmSIIPllVvQvZv1pAQUzk7lhwQlH+E ZnBvJKCaFCUQS5InDwXpNjhBWmutPnegOZQQ1oRulQ340qxNhCQu12XWoo3e+pvU wMLT8Og/WvBXkQDSNR6dxGaBfu3FUFseNANrjEclb+XoggTZLl4= =Qktz -----END PGP SIGNATURE-----