UbuntuUpdates.org

Package "locales-all"

Name: locales-all

Description:

GNU C Library: Precompiled locale data

Latest version: 2.39-0ubuntu8.9
Release: noble (24.04)
Level: updates
Repository: universe
Head package: glibc
Homepage: https://www.gnu.org/software/libc/libc.html

Links


Download "locales-all"


Other versions of "locales-all" in Noble

Repository Area Version
base universe 2.39-0ubuntu8
security universe 2.39-0ubuntu8.9

Changelog

Version: 2.39-0ubuntu8.9 2026-09-10 16:07:47 UTC

glibc (2.39-0ubuntu8.9) noble-security; urgency=medium

  * SECURITY UPDATE: Buffer overflow in strfmon right-justification padding
    - debian/patches/CVE-2026-19499.patch: stdlib: Fix right-justification in
      strfmon (bug 34510, CVE-2026-19499) in stdlib/Makefile,
      stdlib/strfmon_l.c, stdlib/tst-strfmon-bug34510.c.
    - CVE-2026-19499
  * SECURITY UPDATE: Out-of-bounds stack array access in tdelete
    - debian/patches/CVE-2026-19542.patch: misc: Fix out-of-bounds array write
      in tdelete (bug 34506) in misc/tsearch.c.
    - CVE-2026-19542
  * SECURITY UPDATE: invalid memory when calling wordexp with WRDE_APPEND
    - debian/patches/CVE-2026-6368.patch: posix: Fix wordexp WRDE_APPEND to
      preserve state on non-NOSPACE errors (BZ 34090, CVE-2026-6368) in
      posix/Makefile, posix/tst-wordexp-append.c, posix/wordexp.c.
    - CVE-2026-6368
  * SECURITY UPDATE: stack clash issue when expanding long tilde paths
    - debian/patches/CVE-2026-6791.patch: posix: Fix stack overflow in wordexp
      tilde expansion (BZ 34091, CVE-2026-6791) in posix/Makefile, posix/tst-
      wordexp-tilde.c, posix/tst-wordexp-tilde.root/etc/group, posix/tst-
      wordexp-tilde.root/etc/nsswitch.conf, posix/tst-wordexp-
      tilde.root/etc/passwd, posix/wordexp.c.
    - CVE-2026-6791
  * SECURITY UPDATE: SHIFT_JISX0213 converter hang
    - debian/patches/CVE-2026-77117-1.patch: iconvdata: SHIFT_JISX0213 decoding
      lacks pending character reset (CVE-2026-77117) in
      iconvdata/shift_jisx0213.c.
    - debian/patches/CVE-2026-77117-2.patch: iconvdata: Test case for bug 34556,
      bug 34568 in iconvdata/Makefile, iconvdata/tst-jisx0213-progress.c.
    - CVE-2026-77117
  * SECURITY UPDATE: EUC_JISX0213 converter hang
    - debian/patches/CVE-2026-80489.patch: iconvdata: EUC_JISX0213 decoding
      lacks pending character reset (CVE-2026-80489) in iconvdata/euc-
      jisx0213.c.
    - CVE-2026-80489

 -- Marc Deslauriers Thu, 03 Sep 2026 10:15:12 -0400

Source diff to previous version
CVE-2026-19542 Out-of-bounds stack array access in tdelete
CVE-2026-6368 Calling wordexp with WRDE_APPEND in the GNU C Library version 2.0 to version 2.43 can cause the interface to return invalid memory in the we_wordv me
CVE-2026-6791 When expanding paths that begin with a tilde (~) followed by a username, the internal parse_tilde function extracts the username to determine the use

Version: 2.39-0ubuntu8.8 2026-07-27 17:08:06 UTC
No changelog available yet.
Source diff to previous version

Version: 2.39-0ubuntu8.7 2026-02-03 11:07:59 UTC

  glibc (2.39-0ubuntu8.7) noble-security; urgency=medium

  * SECURITY UPDATE: use-after-free in wordexp_t fields
    - debian/patches/CVE-2025-15281.patch: posix: Reset wordexp_t fields
      with WRDE_REUSE
    - CVE-2025-15281
  * SECURITY UPDATE: integer overflow in memalign
    - debian/patches/CVE-2026-0861.patch: memalign: reinstate alignment
      overflow check
    - CVE-2026-0861
  * SECURITY UPDATE: memory leak in NSS DNS
    - debian/patches/CVE-2026-0915.patch: resolv: Fix NSS DNS backend for
      getnetbyaddr
    - CVE-2026-0915

 -- Nishit Majithia <email address hidden> Fri, 30 Jan 2026 13:57:54 +0530

Source diff to previous version
CVE-2025-15281 Calling wordexp with WRDE_REUSE in conjunction with WRDE_APPEND in the GNU C Library version 2.0 to version 2.42 may cause the interface to return un
CVE-2026-0861 Passing too large an alignment to the memalign suite of functions (memalign, posix_memalign, aligned_alloc) in the GNU C Library version 2.30 to 2.42
CVE-2026-0915 Calling getnetbyaddr or getnetbyaddr_r with a configured nsswitch.conf that specifies the library's DNS backend for networks and queries for a zero-v

Version: 2.39-0ubuntu8.6 2025-09-22 22:08:01 UTC

  glibc (2.39-0ubuntu8.6) noble-security; urgency=medium

  * SECURITY UPDATE: double-free in regcomp function
    - debian/patches/any/CVE-2025-8058.patch: fix double-free after
      allocation failure in regcomp in posix/Makefile, posix/regcomp.c,
      posix/tst-regcomp-bracket-free.c.
    - CVE-2025-8058

 -- Marc Deslauriers <email address hidden> Wed, 17 Sep 2025 10:55:42 -0400

Source diff to previous version
CVE-2025-8058 The regcomp function in the GNU C library version from 2.4 to 2.41 is subject to a double free if some previous allocation fails. It can be accompl

Version: 2.39-0ubuntu8.5 2025-07-14 23:09:57 UTC

  glibc (2.39-0ubuntu8.5) noble-security; urgency=medium

  * SECURITY UPDATE: insecure power10 strcmp implementation
    - debian/patches/any/CVE-2025-5702.patch: remove power10 optimized
      strcmp.
    - CVE-2025-5702
  * Moved other security patches to debian/patches/any.

 -- Marc Deslauriers <email address hidden> Wed, 09 Jul 2025 12:47:47 -0400

CVE-2025-5702 The strcmp implementation optimized for the Power10 processor in the GNU C Library version 2.39 and later writes to vector registers v20 to v31 witho



About   -   Send Feedback to @ubuntu_updates