Debian Package Tracker
Register | Log in
Subscribe

glibc

Choose email to subscribe with

general
  • source: glibc (main)
  • version: 2.41-7
  • maintainer: GNU Libc Maintainers (archive) (DMD)
  • uploaders: Samuel Thibault [DMD] – Clint Adams [DMD] – Aurelien Jarno [DMD]
  • arch: all any
  • std-ver: 4.6.2
  • VCS: Git (Browse, QA)
versions [more versions can be listed by madison] [old versions available from snapshot.debian.org]
[pool directory]
  • o-o-stable: 2.28-10+deb10u1
  • o-o-sec: 2.28-10+deb10u4
  • oldstable: 2.31-13+deb11u11
  • old-sec: 2.31-13+deb11u12
  • old-upd: 2.31-13+deb11u5
  • old-p-u: 2.31-13+deb11u11
  • stable: 2.36-9+deb12u10
  • stable-sec: 2.36-9+deb12u7
  • testing: 2.41-7
  • unstable: 2.41-7
versioned links
  • 2.28-10+deb10u1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 2.28-10+deb10u4: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 2.31-13+deb11u5: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 2.31-13+deb11u11: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 2.31-13+deb11u12: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 2.36-9+deb12u7: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 2.36-9+deb12u10: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 2.41-7: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
binaries
  • glibc-doc (8 bugs: 0, 1, 7, 0)
  • glibc-source (1 bugs: 0, 0, 1, 0)
  • libc-bin (23 bugs: 0, 10, 13, 0)
  • libc-dev-bin (1 bugs: 0, 1, 0, 0)
  • libc-devtools (1 bugs: 0, 1, 0, 0)
  • libc-l10n
  • libc0.3
  • libc0.3-dbg
  • libc0.3-dev
  • libc0.3-udeb
  • libc6 (217 bugs: 0, 152, 65, 0)
  • libc6-amd64 (1 bugs: 0, 1, 0, 0)
  • libc6-dbg (1 bugs: 0, 0, 1, 0)
  • libc6-dev (32 bugs: 0, 18, 14, 0)
  • libc6-dev-amd64
  • libc6-dev-i386
  • libc6-dev-mips32
  • libc6-dev-mips64
  • libc6-dev-mipsn32
  • libc6-dev-powerpc
  • libc6-dev-ppc64
  • libc6-dev-s390
  • libc6-dev-sparc
  • libc6-dev-sparc64
  • libc6-dev-x32
  • libc6-i386 (2 bugs: 0, 1, 1, 0)
  • libc6-mips32
  • libc6-mips64
  • libc6-mipsn32
  • libc6-powerpc
  • libc6-ppc64
  • libc6-s390
  • libc6-sparc
  • libc6-sparc64
  • libc6-udeb
  • libc6-x32 (1 bugs: 0, 1, 0, 0)
  • libc6.1
  • libc6.1-dbg
  • libc6.1-dev
  • libc6.1-udeb
  • locales (49 bugs: 0, 31, 18, 0)
  • locales-all (3 bugs: 0, 2, 1, 0)
  • nscd (28 bugs: 0, 25, 3, 0)
action needed
lintian reports 282 errors and 343 warnings high
Lintian reports 282 errors and 343 warnings about this package. You should make the package lintian clean getting rid of them.
Created: 2025-03-15 Last update: 2025-04-14 16:31
7 security issues in buster high

There are 7 open security issues in buster.

4 important issues:
  • CVE-2024-33599: nscd: Stack-based buffer overflow in netgroup cache If the Name Service Cache Daemon's (nscd) fixed size cache is exhausted by client requests then a subsequent client request for netgroup data may result in a stack-based buffer overflow. This flaw was introduced in glibc 2.15 when the cache was added to nscd. This vulnerability is only present in the nscd binary.
  • CVE-2024-33600: nscd: Null pointer crashes after notfound response If the Name Service Cache Daemon's (nscd) cache fails to add a not-found netgroup response to the cache, the client request can result in a null pointer dereference. This flaw was introduced in glibc 2.15 when the cache was added to nscd. This vulnerability is only present in the nscd binary.
  • CVE-2024-33601: nscd: netgroup cache may terminate daemon on memory allocation failure The Name Service Cache Daemon's (nscd) netgroup cache uses xmalloc or xrealloc and these functions may terminate the process due to a memory allocation failure resulting in a denial of service to the clients. The flaw was introduced in glibc 2.15 when the cache was added to nscd. This vulnerability is only present in the nscd binary.
  • CVE-2024-33602: nscd: netgroup cache assumes NSS callback uses in-buffer strings The Name Service Cache Daemon's (nscd) netgroup cache can corrupt memory when the NSS callback does not store all strings in the provided buffer. The flaw was introduced in glibc 2.15 when the cache was added to nscd. This vulnerability is only present in the nscd binary.
2 issues postponed or untriaged:
  • CVE-2023-4806: (needs triaging) A flaw was found in glibc. In an extremely rare situation, the getaddrinfo function may access memory that has been freed, resulting in an application crash. This issue is only exploitable when a NSS module implements only the _nss_*_gethostbyname2_r and _nss_*_getcanonname_r hooks without implementing the _nss_*_gethostbyname3_r hook. The resolved name should return a large number of IPv6 and IPv4, and the call to the getaddrinfo function should have the AF_INET6 address family with AI_CANONNAME, AI_ALL and AI_V4MAPPED as flags.
  • CVE-2023-4813: (needs triaging) A flaw was found in glibc. In an uncommon situation, the gaih_inet function may use memory that has been freed, resulting in an application crash. This issue is only exploitable when the getaddrinfo function is called and the hosts database in /etc/nsswitch.conf is configured with SUCCESS=continue or SUCCESS=merge.
1 ignored issue:
  • CVE-2020-1751: An out-of-bounds write vulnerability was found in glibc before 2.31 when handling signal trampolines on PowerPC. Specifically, the backtrace function did not properly check the array bounds when storing the frame address, resulting in a denial of service or potential code execution. The highest threat from this vulnerability is to system availability.
Created: 2024-04-17 Last update: 2024-06-29 13:15
35 bugs tagged patch in the BTS normal
The BTS contains patches fixing 35 bugs (40 if counting merged bugs), consider including or untagging them.
Created: 2025-01-06 Last update: 2025-05-08 23:30
Fails to build during reproducibility testing normal
A package building reproducibly enables third parties to verify that the source matches the distributed binaries. It has been identified that this source package produced different results, failed to build or had other issues in a test environment. Please read about how to improve the situation!
Created: 2025-04-21 Last update: 2025-05-08 22:52
version in VCS is newer than in repository, is it time to upload? normal
vcswatch reports that this package seems to have a new changelog entry (version 2.41-8, distribution UNRELEASED) and new commits in its VCS. You should consider whether it's time to make an upload.

Here are the relevant commit messages:
commit 68e51b73e9c04f647ebed1b756a46589466018b7
Author: Aurelien Jarno <aurelien@aurel32.net>
Date:   Wed Apr 30 11:26:40 2025 +0200

    debian/patches/git-updates.diff: update from upstream stable branch:
    
    * debian/patches/git-updates.diff: update from upstream stable branch:
      - Fix elf/tst-audit10 test failure on x86 systems without AVX.  Closes:
        #1103303.
      - Fix pthread_getattr_np failure when executable stack tunable is set.

commit 560d21967dc6ff5d6872ebaf5428241b2f22d57b
Author: Aurelien Jarno <aurelien@aurel32.net>
Date:   Fri Apr 25 21:45:44 2025 +0200

    debian/rules.d/debhelper.mk: do not replace LIBC in debhelper.in files. This was used for lintian overrides, but it is not used anymore.  Closes: #1104099.

commit 531e195ed55f7a788a5b620d302ea56a29104c02
Author: Samuel Thibault <samuel.thibault@ens-lyon.org>
Date:   Mon Apr 21 20:28:38 2025 +0000

    debian/patches/hurd-i386/git-symlink-eexist.diff: Fix gnulib testsuite

commit 99766979f365df2fe52f8779eb599ffb05086389
Author: Samuel Thibault <samuel.thibault@ens-lyon.org>
Date:   Mon Apr 21 18:10:11 2025 +0000

    hurd: fix FPE crashes
    
      * debian/patches/hurd-i386/git-xstate-initialized.diff: Fix crash in dash.
      * debian/patches/hurd-i386/git-signal-fpe-exceptions.diff: Fix crash in FPE
        handlers.

commit 558218233e8d3fa5226eecde58a64d3b6fc13d2f
Author: Aurelien Jarno <aurelien@aurel32.net>
Date:   Mon Apr 21 16:08:27 2025 +0200

    Update Brazilian Portuguese debconf translation.  Closes: #1103446.

commit dd55e928a0747c222a81b97b0241a1af634edc42
Author: Samuel Thibault <samuel.thibault@ens-lyon.org>
Date:   Sun Apr 20 08:20:23 2025 +0000

    hurd: Make *utime*s catch invalid times
    
    debian/patches/hurd-i386/git-utime-EINVAL.diff

commit ec4da377e2f7d6a15e4ef1f4221a64bb22336f8f
Author: Samuel Thibault <samuel.thibault@ens-lyon.org>
Date:   Fri Apr 18 00:18:55 2025 +0000

    debian/patches/hurd-i386/local-intr-msg-clobber.diff: Drop now-useless patch

commit ae6120bea7e3a83135522fe11d3ba1619a8cd3f5
Author: Samuel Thibault <samuel.thibault@ens-lyon.org>
Date:   Fri Apr 18 00:17:41 2025 +0000

    debian/patches/hurd-i386/git-xstate.diff: Fix restoring SSE state on signals

commit db31d7fba14882797e5676b4a4473f6999860bdd
Author: Samuel Thibault <samuel.thibault@ens-lyon.org>
Date:   Fri Apr 18 00:04:24 2025 +0000

    debian/patches/hurd-i386/git-dup-refcnt.diff: Fix detecting too many dups

commit ac04b84bde8670fd2560e27892caeeb044778ddc
Author: Samuel Thibault <samuel.thibault@ens-lyon.org>
Date:   Thu Apr 17 20:24:25 2025 +0200

    testsuite-xfail-debian.mk: xfail tst-execstack-prog-static-tunable on hurd-any
    
      and drop duplicate unsupported stances commited uptream.
Created: 2025-04-17 Last update: 2025-05-03 10:30
debian/patches: 73 patches to forward upstream low

Among the 73 debian patches available in version 2.41-7 of the package, we noticed the following issues:

  • 73 patches where the metadata indicates that the patch has not yet been forwarded upstream. You should either forward the patch upstream or update the metadata to document its real status.
Created: 2023-02-26 Last update: 2025-04-14 09:03
Issues found with some translations low

Automatic checks made by the Debian l10n team found some issues with the translations contained in this package. You should check the l10n status report for more information.

Issues can be things such as missing translations, problematic translated strings, outdated PO files, unknown languages, etc.

Created: 2020-02-26 Last update: 2025-01-23 22:52
Build log checks report 2 warnings low
Build log checks report 2 warnings
Created: 2024-04-28 Last update: 2024-04-28 13:24
Standards version of the package is outdated. wishlist
The package should be updated to follow the last version of Debian Policy (Standards-Version 4.7.2 instead of 4.6.2).
Created: 2024-04-07 Last update: 2025-04-14 05:54
news
[rss feed]
  • [2025-04-30] Accepted glibc 2.31-13+deb11u12 (source) into oldstable-security (Sean Whitton)
  • [2025-04-21] glibc 2.41-7 MIGRATED to testing (Debian testing watch)
  • [2025-04-13] Accepted glibc 2.41-7 (source) into unstable (Aurelien Jarno)
  • [2025-03-22] glibc 2.41-6 MIGRATED to testing (Debian testing watch)
  • [2025-03-15] Accepted glibc 2.41-6 (source) into unstable (Aurelien Jarno)
  • [2025-03-14] Accepted glibc 2.41-5 (source) into unstable (Aurelien Jarno)
  • [2025-03-13] glibc 2.41-4 MIGRATED to testing (Debian testing watch)
  • [2025-03-09] Accepted glibc 2.41-4 (source) into unstable (Aurelien Jarno)
  • [2025-03-07] Accepted glibc 2.36-9+deb12u10 (source) into proposed-updates (Debian FTP Masters) (signed by: Aurelien Jarno)
  • [2025-03-01] Accepted glibc 2.41-3 (source) into unstable (Aurelien Jarno)
  • [2025-02-28] Accepted glibc 2.41-2 (source) into unstable (Aurelien Jarno)
  • [2025-02-22] glibc 2.40-7 MIGRATED to testing (Debian testing watch)
  • [2025-02-15] Accepted glibc 2.40-7 (source) into unstable (Aurelien Jarno)
  • [2025-01-30] Accepted glibc 2.41-1 (source) into experimental (Aurelien Jarno)
  • [2025-01-28] glibc 2.40-6 MIGRATED to testing (Debian testing watch)
  • [2025-01-22] Accepted glibc 2.40-6 (source) into unstable (Aurelien Jarno)
  • [2025-01-12] glibc 2.40-5 MIGRATED to testing (Debian testing watch)
  • [2025-01-03] Accepted glibc 2.40-5 (source) into unstable (Aurelien Jarno)
  • [2024-12-06] glibc 2.40-4 MIGRATED to testing (Debian testing watch)
  • [2024-11-23] Accepted glibc 2.40-4 (source) into unstable (Aurelien Jarno)
  • [2024-11-01] Accepted glibc 2.36-9+deb12u9 (source) into proposed-updates (Debian FTP Masters) (signed by: Aurelien Jarno)
  • [2024-10-10] glibc 2.40-3 MIGRATED to testing (Debian testing watch)
  • [2024-09-24] Accepted glibc 2.40-3 (source) into unstable (Aurelien Jarno)
  • [2024-08-31] glibc 2.40-2 MIGRATED to testing (Debian testing watch)
  • [2024-08-25] Accepted glibc 2.40-2 (source) into unstable (Aurelien Jarno)
  • [2024-08-23] glibc 2.39-7 MIGRATED to testing (Debian testing watch)
  • [2024-08-16] Accepted glibc 2.31-13+deb11u11 (source) into oldstable-proposed-updates (Debian FTP Masters) (signed by: Aurelien Jarno)
  • [2024-08-16] Accepted glibc 2.36-9+deb12u8 (source) into proposed-updates (Debian FTP Masters) (signed by: Aurelien Jarno)
  • [2024-08-14] Accepted glibc 2.39-7 (source) into unstable (Aurelien Jarno)
  • [2024-07-29] glibc 2.39-6 MIGRATED to testing (Debian testing watch)
  • 1
  • 2
bugs [bug history graph]
  • all: 418 441
  • RC: 1
  • I&N: 269 285
  • M&W: 146 152
  • F&P: 2 3
  • patch: 35 40
links
  • homepage
  • lintian (282, 343)
  • buildd: logs, checks, reproducibility, cross
  • popcon
  • browse source code
  • edit tags
  • other distros
  • security tracker
  • l10n (83, 97)
  • debian patches
  • debci
ubuntu Ubuntu logo [Information about Ubuntu for Debian Developers]
  • version: 2.41-6ubuntu1
  • 441 bugs (9 patches)
  • patches for 2.41-6ubuntu1

Debian Package Tracker — Copyright 2013-2025 The Distro Tracker Developers
Report problems to the tracker.debian.org pseudo-package in the Debian BTS.
Documentation — Bugs — Git Repository — Contributing