Multiple vulnerabilities in outdated glibc 2.35

Problems with packages? Post here, using [tags] of the package name.

Multiple vulnerabilities in outdated glibc 2.35

Postby afunix » Thu Nov 09, 2023 2:15 pm

It's been a 1.5 years since glibc 2.35-5 was last built. Current version in upstream Archlinux repo is 2.38-7.
It might be not a big deal, however 2.35 version is vulnerable to CVE-2023-4911 with CVSS 7.9 (HIGH).
There are also a few medium and lows (CVE-2023-5156, CVE-2023-4813, CVE-2023-4527, etc).

I understand limited resources, but this is a high severity local vulnerability which is there for over a month.
Is there anything being done to address the outdated glibc? Is there a way community can help to speed this up?
afunix
 
Posts: 4
Joined: Thu Oct 27, 2022 4:17 pm

Return to Packages

Who is online

Users browsing this forum: No registered users and 11 guests