glibc: 2.42-84 -> 2.42-100

Fixes CVE-2026-19499, CVE-2026-19542, CVE-2026-8674, CVE-2026-80489, CVE-2026-77117.
Does NOT contain patches for "AT_SECURE program buffer overflow via $ORIGIN processing"
(CVE-2026-95818), as that isn't backported yet.
This commit is contained in:
Maximilian Bosch
2026-09-27 10:42:36 +02:00
parent 0eca75219c
commit 95015fc3de
2 changed files with 1074 additions and 2 deletions

File diff suppressed because it is too large Load Diff

View File

@@ -51,7 +51,7 @@
let
version = "2.42";
patchSuffix = "-84";
patchSuffix = "-100";
sha256 = "sha256-0XdeMuRijmTvkw9DW2e7Y691may2viszW58Z8WUJ8X8=";
in
@@ -69,7 +69,7 @@ stdenv.mkDerivation (
/*
No tarballs for stable upstream branch, only https://sourceware.org/git/glibc.git and using git would complicate bootstrapping.
$ git fetch --all -p && git checkout origin/release/2.42/master && git describe
glibc-2.42-67-g4ebd33dd77
glibc-2.42-100-gc7169c0684
$ git show --minimal --reverse glibc-2.42.. ':!ADVISORIES' > 2.42-master.patch
To compare the archive contents zdiff can be used.