* Update from upstream release branche:
- CVE-2023-4527: Stack read overflow with large TCP responses in
no-aaaa mode
- CVE-2023-4806: use after free in getcanonname
- LP: #2031909: Fix oversized __io_vtables
* d/p/u/0001-Fix-leak-in-getaddrinfo-introduced-by-the-fix-for-CV:
Cherry-picked to fix a regression in one of the previous CVE fixes
(LP: #2037516, CVE-2023-5156)
* d/p/lp2032624.patch: add an escape hatch in arm64 math-vector.h.
This should help fixing multiple FTBFS (LP: #2032624)
This bug was fixed in the package glibc - 2.38-1ubuntu5
---------------
glibc (2.38-1ubuntu5) mantic; urgency=medium
* Update from upstream release branche: Fix-leak- in-getaddrinfo- introduced- by-the- fix-for- CV: patch: add an escape hatch in arm64 math-vector.h.
- CVE-2023-4527: Stack read overflow with large TCP responses in
no-aaaa mode
- CVE-2023-4806: use after free in getcanonname
- LP: #2031909: Fix oversized __io_vtables
* d/p/u/0001-
Cherry-picked to fix a regression in one of the previous CVE fixes
(LP: #2037516, CVE-2023-5156)
* d/p/lp2032624.
This should help fixing multiple FTBFS (LP: #2032624)
-- Simon Chopin <email address hidden> Wed, 27 Sep 2023 16:38:18 +0200