<?xml version="1.0" encoding="UTF-8" standalone="yes" ?>
<!DOCTYPE bugzilla SYSTEM "https://bugzilla.yoctoproject.org/page.cgi?id=bugzilla.dtd">

<bugzilla version="5.0.6"
          urlbase="https://bugzilla.yoctoproject.org/"
          
          maintainer="it-coreprojects-helpdesk@linuxfoundation.org"
>

    <bug>
          <bug_id>10870</bug_id>
          
          <creation_ts>2017-01-02 07:42:31 +0000</creation_ts>
          <short_desc>CVE-2016-6323 for glibc</short_desc>
          <delta_ts>2018-02-02 20:41:35 +0000</delta_ts>
          <reporter_accessible>1</reporter_accessible>
          <cclist_accessible>1</cclist_accessible>
          <classification_id>7</classification_id>
          <classification>Build System, Metadata &amp; Runtime</classification>
          <product>Security - Recipe Upgrade</product>
          <component>security</component>
          <version>unspecified</version>
          <rep_platform>x86</rep_platform>
          <op_sys>arm</op_sys>
          <bug_status>RESOLVED</bug_status>
          <resolution>FIXED</resolution>
          
          
          <bug_file_loc></bug_file_loc>
          <status_whiteboard></status_whiteboard>
          <keywords></keywords>
          <priority>Undecided</priority>
          <bug_severity>normal</bug_severity>
          <target_milestone>---</target_milestone>
          
          
          <everconfirmed>1</everconfirmed>
          <reporter name="Ismo Puustinen">ismo.puustinen</reporter>
          <assigned_to name="Saul Wold">sgw</assigned_to>
          <cc>bluelightning</cc>
    
    <cc>stephano</cc>
          
          
          <cf_os>---</cf_os>
          <cf_regression_type>---</cf_regression_type>
          
          <cf_docchange>Don&apos;t know</cf_docchange>

      

      

      

          <comment_sort_order>oldest_to_newest</comment_sort_order>  
          <long_desc isprivate="0" >
    <commentid>69427</commentid>
    <comment_count>0</comment_count>
    <who name="Ismo Puustinen">ismo.puustinen</who>
    <bug_when>2017-01-02 07:42:31 +0000</bug_when>
    <thetext>https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2016-6323 :

The makecontext function in the GNU C Library (aka glibc or libc6) before 2.25 creates execution contexts incompatible with the unwinder on ARM EABI (32-bit) platforms, which might allow context-dependent attackers to cause a denial of service (hang), as demonstrated by applications compiled using gccgo, related to backtrace generation.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>77186</commentid>
    <comment_count>1</comment_count>
    <who name="Paul Eggleton">bluelightning</who>
    <bug_when>2017-09-27 22:53:20 +0000</bug_when>
    <thetext>The patch for this is in master, pyro and morty - can we mark this resolved?</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>79323</commentid>
    <comment_count>2</comment_count>
    <who name="Stephano Cetola">stephano</who>
    <bug_when>2018-02-02 20:41:35 +0000</bug_when>
    <thetext>pyro:
a3c2acee40c8875e311e03bff6906e7c93c491fc

morty:
e80d454711f67a9a3a2a43bb7d9ff911c4664a84</thetext>
  </long_desc>
      
      

    </bug>

</bugzilla>