Hacktoberfest 2026: le issue che i maintainer hanno segnato per ottobre, aperte e adatte ai principianti. Sfoglia le issue Hacktoberfest

glibc-2.44: mark CVE-2026-77117 and CVE-2026-80489 fixed in 2.44-r4

Aperta Adatta ai principianti
#78,748 0 commenti 0 reazioni 0 assegnatari Vedi su GitHub

Nessuno ha ancora preso questa issue.

Valutazione

Difficoltà
2/5
Tempo stimato
1-3 ore
Idoneità per principianti
78/100
Tipo di issue
Bug
Chiarezza
Specificata chiaramente
Stato di attività
Attiva
Stack tecnologico
c
Ambito
security

Direzione di ricerca

Inizia con i metadati di packages.wolfi.dev/os/security.json e glibc-2.44.yaml, quindi controlla come vengono generati o aggiornati i feed di security e OSV. Registra voci di correzione per CVE-2026-77117 e CVE-2026-80489 alla versione 2.44-r4 per entrambe le architetture pubblicate e verifica che le voci vengano propagate, in modo che le revisioni successive riportino i fix.

Scritto dal modello di indicizzazione a partire dal testo della issue.

Descrizione

Summary

The Wolfi security feed (packages.wolfi.dev/os/security.json) carries no advisory at all for CVE-2026-77117 and CVE-2026-80489 against glibc-2.44 — neither a fixed entry nor a detection record — although Wolfi glibc-2.44 has contained both upstream fixes since 2.44-r4. Without a fixed entry, scanners fall back to NVD CPE matching (cpe:2.3:a:gnu:glibc:2.44) and report both CVEs against 2.44-r4, 2.44-r5 and 2.44-r6 with no fix state. Please add fixed entries at 2.44-r4 for both. Same revision boundary as #78744 (CVE-2026-19499).

Both CVEs are the JISX0213 iconv converter no-progress hangs:

  • CVE-2026-77117 — SHIFT_JISX0213 decoding lacks pending character reset (GLIBC-SA-2026-0019)
  • CVE-2026-80489 — EUC_JISX0213 decoding lacks pending character reset (GLIBC-SA-2026-0020)

Exact provenance

The upstream advisories identify the release/2.44/master fix commits (both dated 2026-08-28):

Wolfi revision boundary (glibc-expected-commit in glibc-2.44.yaml at each epoch; ancestry checked with git merge-base --is-ancestor <fix> <source-commit> on a clone of release/2.44/master):

Wolfi version Source commit CVE-2026-77117 fix CVE-2026-80489 fix
2.44-r1 – 2.44-r3 ae9225d55963c4420c49ccfa3f2fafc416f92032 not included not included
2.44-r4 5c479454d1232f71c78fa21584e90a2f57883407 included included
2.44-r5 5c479454d1232f71c78fa21584e90a2f57883407 included included
2.44-r6 b4f51887c48ac82acfdb13f96d9eab5d120cb2b7 included included

The package update introducing the first fixed Wolfi revision is the same one as for CVE-2026-19499:

The fixed sources can be inspected at that commit:

Requested correction

Please record CVE-2026-77117 and CVE-2026-80489 as fixed in glibc-2.44 at 2.44-r4 (both published architectures) and propagate the entries to the security and OSV feeds, so that scanners stop matching them through NVD CPE data against 2.44-r4 and later.

Not fixed yet, for the avoidance of doubt

CVE-2026-8674 (GLIBC-SA-2026-0021, resolver assertion failure on an over-long search domain) is not covered by this request: its 2.44 backport 1f502624 landed on release/2.44/master on 2026-09-14, after b4f51887, so 2.44-r6 does not contain it. It will need a rebuild from a newer branch commit, not an advisory correction.

Downstream impact

grype 0.118.0 (vulnerability database of 2026-09-27) reports both CVEs against glibc-2.44 2.44-r6 through the nvd:cpe namespace with an empty fix state, on every Wolfi-based image (including cgr.dev/chainguard/wolfi-base:latest, which ships 2.44-r6 today). Fail-closed image pipelines therefore quarantine already-remediated builds or need local scanner exceptions even though the package source includes the exact upstream fixes.

Lingua principale
Shell
Stelle
1.3k
Fork
443
Metriche di merge delle PR
Nessuna PR unita negli ultimi 30g

Preparare l'ambiente

Come iniziare

  1. Leggi tutta la issue e poi la guida ai contributi del progetto.
  2. Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
  3. Fai un fork del repository e lavora su un branch.
  4. Apri una pull request che faccia riferimento al numero della issue.

Altre issue di wolfi-dev/os

Tutte le issue di wolfi-dev/os

Issue simili

Altre issue su Shell/Bash

Ricevi le nuove issue nella tua casella

Un breve riepilogo di issue GitHub adatte ai principianti.