-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Mon, 27 Apr 2026 22:14:33 +0200 Source: glibc Binary: libc-bin libc-bin-dbgsym libc-dev-bin libc-dev-bin-dbgsym libc-devtools libc-devtools-dbgsym libc6 libc6-dbg libc6-dev libc6-dev-dbgsym libc6-udeb locales-all nscd nscd-dbgsym Architecture: arm64 Version: 2.36-9+deb12u14 Distribution: bookworm Urgency: medium Maintainer: arm64 Build Daemon (arm-conova-03) Changed-By: Aurelien Jarno Description: libc-bin - GNU C Library: Binaries libc-dev-bin - GNU C Library: Development binaries libc-devtools - GNU C Library: Development tools libc6 - GNU C Library: Shared libraries libc6-dbg - GNU C Library: detached debugging symbols libc6-dev - GNU C Library: Development Libraries and Header Files libc6-udeb - GNU C Library: Shared libraries - udeb (udeb) locales-all - GNU C Library: Precompiled locale data nscd - GNU C Library: Name Service Cache Daemon Closes: 1125678 1125748 1126266 1131435 1131887 1132499 Changes: glibc (2.36-9+deb12u14) bookworm; urgency=medium . * debian/patches/git-updates.diff: update from upstream stable branch: - Fix a performance bottleneck with the Address Sanitizer (ASAN) on 32-bit arm. - Fix _dl_find_object when ld.so has LOAD segment gaps, causing wrong backtrace unwinding. This affects at least arm64. - Add GLIBC_ABI_DT_X86_64_PLT symbol version on amd64. - Fix typo in wmemset ifunc selector that caused AVX2/AVX512 paths to be skipped. - Fix POWER optimized rawmemchr function on ppc64el. - Optimize trylock for high cache contention workloads. - Fix and integer overflow in _int_memalign leading to heap corruption (CVE-2026-0861). Closes: #1125678. - Fix stack contents leak in getnetbyaddr (CVE-2026-0915). Closes: #1125748. - Fix bug in wordexp, which could return uninitialized memory when using WRDE_REUSE together with WRDE_APPEND (CVE-2025-15281). Closes: #1126266. - Fix invalid pointer arithmetic in ANSI_X3.110 iconv module - Fix a typo preventing new tst-wordexp-reuse-mem to run - Fix incorrect handling of DNS responses in gethostbyaddr and gethostbyaddr_r (CVE-2026-4437). Closes: #1131435. - Fix invalid DNS hostnames returned by gethostbyaddr and gethostbyaddr_r (CVE-2026-4438). Closes: #1131887. - Fix random failure of tst-link-map-contiguous-ldso. - Fix a possible crash due to an assertion failure when converting inputs from the IBM139x character sets (CVE-2026-4046). Closes: #1132499. * d/p/amd64/local-revert-x86-64-add-GLIBC_ABI_DT_X86_64_PLT-version.diff: revert addition of the GLIBC_ABI_DT_X86_64_PLT symbol version used as ABI flag, as the dpkg-shlibdeps version in bookworm is not able to handle it (see #1122107). Checksums-Sha1: 082a0e17fa967ee8828804c0ff5da6f3add8a0e1 13071 glibc_2.36-9+deb12u14_arm64-buildd.buildinfo f1445b6a9dc3dcb8989267d9febfc1f010470280 2247368 libc-bin-dbgsym_2.36-9+deb12u14_arm64.deb 273fd77ac3f09a5dececc19434a53b71bef3591a 534528 libc-bin_2.36-9+deb12u14_arm64.deb 6fb96e6b074b1d0e4efd326cd78e7a2aa4bae543 29412 libc-dev-bin-dbgsym_2.36-9+deb12u14_arm64.deb e494f7ed625060232251e49e6af2af701fdfbbdb 47220 libc-dev-bin_2.36-9+deb12u14_arm64.deb 2861728e068b94790a5a05a3e1b34bf2189b350b 44776 libc-devtools-dbgsym_2.36-9+deb12u14_arm64.deb 05f599d7b3e46fd6d145b2cbe630632fd432a71d 54484 libc-devtools_2.36-9+deb12u14_arm64.deb cc07551cc7a61b41300fdbefb00c475db76e0929 6530032 libc6-dbg_2.36-9+deb12u14_arm64.deb 71c3461a5d9a42d60a584aa7bd96f4bce6c501ff 14868 libc6-dev-dbgsym_2.36-9+deb12u14_arm64.deb 95000bbf7ff66aabc9a2d3f0ab027f39c894be96 1435692 libc6-dev_2.36-9+deb12u14_arm64.deb 4392d3c9c78bc6898c9934c74a7efff69f339886 900524 libc6-udeb_2.36-9+deb12u14_arm64.udeb 85af57bf1f9fa075163e51c99d9536154c21ab7e 2324660 libc6_2.36-9+deb12u14_arm64.deb 91562e250c90218dd99c099dbbc63a4140d7b515 10653316 locales-all_2.36-9+deb12u14_arm64.deb 40876424f08a90d0584668a9db87fa33ae8929b0 279812 nscd-dbgsym_2.36-9+deb12u14_arm64.deb 1c5efa4086e26a08b496942bd23d8c39bd03a6a7 98924 nscd_2.36-9+deb12u14_arm64.deb Checksums-Sha256: 976aa75171c746fd7dd4c0c84a825e4cbeb22393d8dbefa79efffd8a2e225692 13071 glibc_2.36-9+deb12u14_arm64-buildd.buildinfo 251bdcc9a0bf6a8f8870754f27ec03e70868ec2b4249549a968abb89dbf3fff2 2247368 libc-bin-dbgsym_2.36-9+deb12u14_arm64.deb 65166ea54c05213c4f48d889138179f1b7345edd05031a9af276aa5fb4a45c05 534528 libc-bin_2.36-9+deb12u14_arm64.deb 461876e6b2ffad6d07ef43cb4935a47ca75d4e7c341faa8b9652d7e63fdb15ea 29412 libc-dev-bin-dbgsym_2.36-9+deb12u14_arm64.deb 8fc74833f9eb19e39e760bff5b9d7e85a06d6513edf3685bf2ea6f9c710867a6 47220 libc-dev-bin_2.36-9+deb12u14_arm64.deb 59831344b526a9f854e8e2b4b08fbb43220aa53f504584855c50a003161a31ca 44776 libc-devtools-dbgsym_2.36-9+deb12u14_arm64.deb 9e5800e8cce353e46104c8225f23b6bb47a4af37c839efb9a66cfb4946780f89 54484 libc-devtools_2.36-9+deb12u14_arm64.deb 2ee8f5d4800a616ff9d31fea83e235f29b722105cf247387453fccdec79152de 6530032 libc6-dbg_2.36-9+deb12u14_arm64.deb f3b12dfaeb745b8174825c73bf252f4629bca7b9521ff923fd9e63652d96e064 14868 libc6-dev-dbgsym_2.36-9+deb12u14_arm64.deb 8bc395bf2ee9939f1a6ae395f974cffdcf541d98f99adfe89ce7e4bef36d159e 1435692 libc6-dev_2.36-9+deb12u14_arm64.deb 2dcfb441f6b3e7b59dc3f1f7ba1d5084a2fa8629c97d40c37165527efa0a3d5f 900524 libc6-udeb_2.36-9+deb12u14_arm64.udeb 01f4330719fd4f65580e16ea5a0527f372fca750e8f588d26deaf09f2d3b1cf4 2324660 libc6_2.36-9+deb12u14_arm64.deb da3c995c891ac5cceb84049774ddfb6041c25b82effd23e772a48f9d9b381c53 10653316 locales-all_2.36-9+deb12u14_arm64.deb 90de728e5614c70e67728aaf063cdbd1c5017144e15450aa729e48c29356c660 279812 nscd-dbgsym_2.36-9+deb12u14_arm64.deb e96faa50a13f524b54f339e531a5930363ef7ec9d9bb7c87b83470650169f651 98924 nscd_2.36-9+deb12u14_arm64.deb Files: b8ac10f02332ba27eae38d55261721fa 13071 libs required glibc_2.36-9+deb12u14_arm64-buildd.buildinfo 9d1867a15963cc768aaeb24f1e542bd0 2247368 debug optional libc-bin-dbgsym_2.36-9+deb12u14_arm64.deb 210acd8639e6fd8bdfe2601ea158b6ea 534528 libs required libc-bin_2.36-9+deb12u14_arm64.deb 3986257875baf54dd8c8468801363e1f 29412 debug optional libc-dev-bin-dbgsym_2.36-9+deb12u14_arm64.deb 807f68a761ca634608ce4a0b14a19518 47220 libdevel optional libc-dev-bin_2.36-9+deb12u14_arm64.deb 513661ae9f01abffde513e1c6d2c9cf2 44776 debug optional libc-devtools-dbgsym_2.36-9+deb12u14_arm64.deb 3fa74bae957e6bfbf096a61460cff7cb 54484 devel optional libc-devtools_2.36-9+deb12u14_arm64.deb 0def6426f48985a3ea403cb7ca979991 6530032 debug optional libc6-dbg_2.36-9+deb12u14_arm64.deb 36020f9c91fda57e0e01da68c866b9c8 14868 debug optional libc6-dev-dbgsym_2.36-9+deb12u14_arm64.deb 552da185b4913ca0a7fb8f014071029a 1435692 libdevel optional libc6-dev_2.36-9+deb12u14_arm64.deb 36ede8b9b7bd1a2ee3834c447424f121 900524 debian-installer optional libc6-udeb_2.36-9+deb12u14_arm64.udeb 96654eb25919c6f15deb9848c0f06601 2324660 libs optional libc6_2.36-9+deb12u14_arm64.deb 5071e7a6dff6ec8150f9098526522092 10653316 localization optional locales-all_2.36-9+deb12u14_arm64.deb c311a564391427f7c470dba5c36e411d 279812 debug optional nscd-dbgsym_2.36-9+deb12u14_arm64.deb 2064ac867d73ef35748247e7c1e13b5e 98924 admin optional nscd_2.36-9+deb12u14_arm64.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEElFiH1oZRZh1t4FSiXVp1sEH/1mIFAmn3wuoACgkQXVp1sEH/ 1mIPJg/6AwXWO6xUE9mPg9fwAHNci2qFcZy9YDZDcSubNgeMx6idm+/CpQo6G8CO AODfe2YB9RITfXoV+ex/fMwOvEV+69y/TitHqDLIzhVEFDXf4vm5vgNyCoBt+6go VpQQYioDJ6500637iocXKAI8XBrtxD1z/wiv7xKbBRvwPF/ylINnYcICt/qwRWOJ Rh9atlc4rOWQjuBUGl6wK9J//DWhDCjLCHD0pxeQqjOhBuwjBM5ck1BUPT+oU0Pi Gyr1B84Fv2x6mN4Q+8fvkvpAAwDDgoLECheMGo6s5S9VEEz4FXG20oB6FKYKNP55 KH7ZkHT95B6XnEYfHsVmOPq7w73A1/elQo1mwPr0aH1ONSKPv6VMvxvzzQPTOjz+ YwYaZzp9MEEq/TcS8ADxgzVfjS1rNkY1i0RnjWpQXOU4ofAQ49igqpf3n2tCnLZF t3WhgG5L2T/00T85cjN50ea9/JzHt44bFBPPWfbILxbGpULKB+NZVG0iLmDIKXuN 7G2ewtZUbxO+eZVMCZAK9Z7S7S19QMFRDgk8lE69m+xTFk7/jajE9utJfM8LdUkK sFNxiS7QftQrqP8c50WgmMF/FOg/2EgB/MMnWzR/vkFNhS9sPFlvvPC3RSdGuifH lXgSUgbpHg6fUHOJwC66qHdHP+oHiJHg5MIBkURwyKNSVYvY8mI= =XPG8 -----END PGP SIGNATURE-----