UbuntuUpdates.org

Package "glibc"

Name: glibc

Description:

This package is just an umbrella for a group of other packages, it has no description.
Description samples from packages in group:

  • GNU C Library: Documentation
  • GNU C Library: Binaries
  • GNU C Library: Development binaries
  • GNU C Library: Shared libraries

Latest version: 2.42-0ubuntu3.1
Release: questing (25.10)
Level: updates
Repository: main

Links



Other versions of "glibc" in Questing

Repository Area Version
base main 2.42-0ubuntu3
base universe 2.42-0ubuntu3
security main 2.42-0ubuntu3.1
security universe 2.42-0ubuntu3.1
updates universe 2.42-0ubuntu3.1

Packages in group

Deleted packages are displayed in grey.


Changelog

Version: 2.42-0ubuntu3.1 2026-02-03 11:08:01 UTC

  glibc (2.42-0ubuntu3.1) questing-security; urgency=medium

  * SECURITY UPDATE: use-after-free in wordexp_t fields
    - debian/patches/CVE-2025-15281.patch: posix: Reset wordexp_t fields
      with WRDE_REUSE
    - CVE-2025-15281
  * SECURITY UPDATE: integer overflow in memalign
    - debian/patches/CVE-2026-0861.patch: memalign: reinstate alignment
      overflow check
    - CVE-2026-0861
  * SECURITY UPDATE: memory leak in NSS DNS
    - debian/patches/CVE-2026-0915.patch: resolv: Fix NSS DNS backend for
      getnetbyaddr
    - CVE-2026-0915

 -- Nishit Majithia <email address hidden> Fri, 30 Jan 2026 13:59:18 +0530

CVE-2025-15281 Calling wordexp with WRDE_REUSE in conjunction with WRDE_APPEND in the GNU C Library version 2.0 to version 2.42 may cause the interface to return un
CVE-2026-0861 Passing too large an alignment to the memalign suite of functions (memalign, posix_memalign, aligned_alloc) in the GNU C Library version 2.30 to 2.42
CVE-2026-0915 Calling getnetbyaddr or getnetbyaddr_r with a configured nsswitch.conf that specifies the library's DNS backend for networks and queries for a zero-v



About   -   Send Feedback to @ubuntu_updates