Package: release.debian.org
Severity: normal
Tags:
X-Debbugs-Cc: glib2.0@packages.debian.org, debian-boot@lists.debian.org Control: affects -1 + src:glib2.0
User: release.debian.org@packages.debian.org
Usertags: unblock
[ Reason ]
CVE-2025-4373 (#1104930).
I also took the opportunity to catch up with the upstream glib-2-84
branch by adding one unrelated bugfix commit (a 1-line change).
[ Impact ]
Fixes an out-of-bounds write if an attacker can somehow arrange for GLib
to be acting on overwhelmingly large strings (half the address space in
a single GString object, so 2GB for 32-bit processes).
Ensures that localtime_r() is not called without first calling tzset(),
which has unspecified behaviour.
[ Tests ]
Not yet tested. I will run autopkgtests and boot a GNOME system with the proposed GLib before upload, and inform this bug if further changes are needed.
My tests were successful.
I don't see my original unblock request in the debian-boot@ web archive - perhaps it was discarded by the mailing list software?
-boot: do you want to be consulted on udeb unblocks at this stage of the freeze? Please see https://lists.debian.org/debian-release/2025/05/msg00301.html for the full diff for this one, if that's useful.
If your request is not urgent, I might give you a green light in a few
days. If you'd rather see it addressed right away, I could try and
squeeze your package into the next release.
I'm pondering an RC 1 now-ish, but trying to decide if and how it could >affect packages that could be ready in time for the hard freeze.
Now that RC 1 has been available for a few days, I've uploaded this to unstable - I hope that's OK from the d-i point of view?
(As before it isn't urgent to review or unblock this, but I wanted it
to exist somewhere other than my laptop!)
[ Reason ]
CVE-2025-4373 (#1104930).
I also took the opportunity to catch up with the upstream glib-2-84
branch by adding one unrelated bugfix commit (a 1-line change).
Needs a d-i ack due to the GTK-based graphical installer.
Sysop: | Keyop |
---|---|
Location: | Huddersfield, West Yorkshire, UK |
Users: | 486 |
Nodes: | 16 (2 / 14) |
Uptime: | 135:06:40 |
Calls: | 9,657 |
Calls today: | 5 |
Files: | 13,707 |
Messages: | 6,166,834 |