glibc-2.44: mark CVE-2026-77117 and CVE-2026-80489 fixed in 2.44-r4
Nessuno ha ancora preso questa issue.
Valutazione
- Difficoltà
- 2/5
- Tempo stimato
- 1-3 ore
- Idoneità per principianti
- 78/100
Direzione di ricerca
Inizia con i metadati di packages.wolfi.dev/os/security.json e glibc-2.44.yaml, quindi controlla come vengono generati o aggiornati i feed di security e OSV. Registra voci di correzione per CVE-2026-77117 e CVE-2026-80489 alla versione 2.44-r4 per entrambe le architetture pubblicate e verifica che le voci vengano propagate, in modo che le revisioni successive riportino i fix.
Scritto dal modello di indicizzazione a partire dal testo della issue.
Descrizione
Summary
The Wolfi security feed (packages.wolfi.dev/os/security.json) carries no advisory at all for CVE-2026-77117 and CVE-2026-80489 against glibc-2.44 — neither a fixed entry nor a detection record — although Wolfi glibc-2.44 has contained both upstream fixes since 2.44-r4. Without a fixed entry, scanners fall back to NVD CPE matching (cpe:2.3:a:gnu:glibc:2.44) and report both CVEs against 2.44-r4, 2.44-r5 and 2.44-r6 with no fix state. Please add fixed entries at 2.44-r4 for both. Same revision boundary as #78744 (CVE-2026-19499).
Both CVEs are the JISX0213 iconv converter no-progress hangs:
- CVE-2026-77117 — SHIFT_JISX0213 decoding lacks pending character reset (GLIBC-SA-2026-0019)
- CVE-2026-80489 — EUC_JISX0213 decoding lacks pending character reset (GLIBC-SA-2026-0020)
Exact provenance
The upstream advisories identify the release/2.44/master fix commits (both dated 2026-08-28):
- https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0019 →
6f9b2bfa500bf5d1cff5d990adfff4b71298dadd(2.44-30) - https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0020 →
cb61572ea3f773e1e1978f6c412cc36a30acdb0c(2.44-31) - https://sourceware.org/git/?p=glibc.git;a=commit;h=6f9b2bfa500bf5d1cff5d990adfff4b71298dadd
- https://sourceware.org/git/?p=glibc.git;a=commit;h=cb61572ea3f773e1e1978f6c412cc36a30acdb0c
Wolfi revision boundary (glibc-expected-commit in glibc-2.44.yaml at each epoch; ancestry checked with git merge-base --is-ancestor <fix> <source-commit> on a clone of release/2.44/master):
| Wolfi version | Source commit | CVE-2026-77117 fix | CVE-2026-80489 fix |
|---|---|---|---|
2.44-r1 – 2.44-r3 |
ae9225d55963c4420c49ccfa3f2fafc416f92032 |
not included | not included |
2.44-r4 |
5c479454d1232f71c78fa21584e90a2f57883407 |
included | included |
2.44-r5 |
5c479454d1232f71c78fa21584e90a2f57883407 |
included | included |
2.44-r6 |
b4f51887c48ac82acfdb13f96d9eab5d120cb2b7 |
included | included |
The package update introducing the first fixed Wolfi revision is the same one as for CVE-2026-19499:
- https://github.com/wolfi-dev/os/commit/615cc78d5b49c57e4aad3c091d1363f379bd81bf (
glibc-2.44/2.44.1_git20260831 package update, #278611)
The fixed sources can be inspected at that commit:
- https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=iconvdata/shift_jisx0213.c;hb=5c479454d1232f71c78fa21584e90a2f57883407
- https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=iconvdata/euc-jisx0213.c;hb=5c479454d1232f71c78fa21584e90a2f57883407
Requested correction
Please record CVE-2026-77117 and CVE-2026-80489 as fixed in glibc-2.44 at 2.44-r4 (both published architectures) and propagate the entries to the security and OSV feeds, so that scanners stop matching them through NVD CPE data against 2.44-r4 and later.
Not fixed yet, for the avoidance of doubt
CVE-2026-8674 (GLIBC-SA-2026-0021, resolver assertion failure on an over-long search domain) is not covered by this request: its 2.44 backport 1f502624 landed on release/2.44/master on 2026-09-14, after b4f51887, so 2.44-r6 does not contain it. It will need a rebuild from a newer branch commit, not an advisory correction.
Downstream impact
grype 0.118.0 (vulnerability database of 2026-09-27) reports both CVEs against glibc-2.44 2.44-r6 through the nvd:cpe namespace with an empty fix state, on every Wolfi-based image (including cgr.dev/chainguard/wolfi-base:latest, which ships 2.44-r6 today). Fail-closed image pipelines therefore quarantine already-remediated builds or need local scanner exceptions even though the package source includes the exact upstream fixes.
- Lingua principale
- Shell
- Stelle
- 1.3k
- Fork
- 443
- Metriche di merge delle PR
- Nessuna PR unita negli ultimi 30g
Preparare l'ambiente
Come iniziare
- Leggi tutta la issue e poi la guida ai contributi del progetto.
- Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
- Fai un fork del repository e lavora su un branch.
- Apri una pull request che faccia riferimento al numero della issue.
Altre issue di wolfi-dev/os
-
mariadb: entrypoint hardcodes _mariadb_version() to 11.5.2, silently disabling upgrade detectionAperta
Difficoltà 2/5 1-3 ore Idoneità per principianti 75/100
-
py3-ecdsa: add new packageAperta
Difficoltà 2/5 1-3 ore Idoneità per principianti 76/100
-
needs-triage
Difficoltà 2/5 1-3 ore Idoneità per principianti 70/100
-
needs-triage
Difficoltà 1/5 Meno di un'ora Idoneità per principianti 68/100
-
bug needs-triage
Difficoltà 3/5 1-2 giorni Idoneità per principianti 68/100
Tutte le issue di wolfi-dev/os
Issue simili
-
documentation
Difficoltà 2/5 1-3 ore Idoneità per principianti 84/100
githubnext/gh-aw-workshop#3969 ·
I maintainer di solito rispondono entro 1 giorno
-
Request: Remove l-town appAperta
Difficoltà 2/5 1-3 ore Idoneità per principianti 85/100
getumbrel/umbrel-apps#6137 ·
I maintainer di solito rispondono entro 2 giorni
-
🎙️ task - fix(deployer): deploy --env prep runs deploy:dev where the repo declares deploy:prepAperta
Difficoltà 2/5 1-3 ore Idoneità per principianti 88/100
-
backlog bug
Difficoltà 2/5 1-3 ore Idoneità per principianti 86/100
WLAN-Pi/wlanpi-profiler#306 ·
I maintainer di solito rispondono entro 1 giorno
-
area: backend good first issue priority: P3 - low size: S type: bug
Difficoltà 2/5 1-3 ore Idoneità per principianti 78/100
Mizithra/ActiveTerrain#31 ·