diff --git a/NEWS b/NEWS index a3ab26c046..14a58be747 100644 --- a/NEWS +++ b/NEWS @@ -83,8 +83,21 @@ Security related changes: The following CVEs were fixed in this release, details of which can be found in the advisories directory of the release tarball: - [The release manager will add the list generated by - scripts/process-advisories.sh just before the release.] + GLIBC-SA-2025-0001: + assert: Buffer overflow when printing assertion failure message + (CVE-2025-0395) + + GLIBC-SA-2025-0003: + power10: strcmp fails to save and restore nonvolatile vector + registers (CVE-2025-5702) + + GLIBC-SA-2025-0004: + power10: strncmp fails to save and restore nonvolatile vector + registers (CVE-2025-5745) + + GLIBC-SA-2025-0005: + posix: Fix double-free after allocation failure in regcomp + (CVE-2025-8058) The following bugs were resolved with this release: