NEWS: insert list of CVEs

Signed-off-by: Andreas K. Hüttel <dilfridge@gentoo.org>
This commit is contained in:
Andreas K. Hüttel 2025-07-26 15:23:49 +02:00
parent 4d585d0afb
commit a92914de93
No known key found for this signature in database
GPG Key ID: DC2B16215ED5412A
1 changed files with 15 additions and 2 deletions

17
NEWS
View File

@ -83,8 +83,21 @@ Security related changes:
The following CVEs were fixed in this release, details of which can be The following CVEs were fixed in this release, details of which can be
found in the advisories directory of the release tarball: found in the advisories directory of the release tarball:
[The release manager will add the list generated by GLIBC-SA-2025-0001:
scripts/process-advisories.sh just before the release.] assert: Buffer overflow when printing assertion failure message
(CVE-2025-0395)
GLIBC-SA-2025-0003:
power10: strcmp fails to save and restore nonvolatile vector
registers (CVE-2025-5702)
GLIBC-SA-2025-0004:
power10: strncmp fails to save and restore nonvolatile vector
registers (CVE-2025-5745)
GLIBC-SA-2025-0005:
posix: Fix double-free after allocation failure in regcomp
(CVE-2025-8058)
The following bugs were resolved with this release: The following bugs were resolved with this release: