public inbox for libc-stable@sourceware.org
 help / color / mirror / Atom feed
From: Aurelien Jarno <aurelien@aurel32.net>
To: libc-stable@sourceware.org
Subject: Backporting CVE-2016-10739
Date: Tue, 01 Jan 2019 00:00:00 -0000	[thread overview]
Message-ID: <20190204134254.GA13816@aurel32.net> (raw)

Hi,

I am looking at backporting fixes for CVE-2016-10739 (ie commit
108bc404) in the 2.28 branch first, and probably in the 2.24 branch
later. I would need some guidance how to proceed:

- Is it acceptable to also to backport commit 5e30b8ef ("resolv: 
  Reformat inet_addr, inet_aton to GNU style")? Without this patch,
  there's a lot of conflicts that are a pain to fix.

- According to the commit message 6ca53a24 ("resolv: Do not send queries
  for non-host-names in nss_dns [BZ #24112]"), also needs to be
  backported. Is it fine to do so?

- The commit introduces a new symbol, which is something we usually do
  not want in a stable branch. However the __inet_aton_exact symbol is
  added under GLIBC_PRIVATE. Therefore I wonder if it is acceptable for
  a stable branch.

Thanks,
Aurelien

-- 
Aurelien Jarno                          GPG: 4096R/1DDD8C9B
aurelien@aurel32.net                 http://www.aurel32.net

             reply	other threads:[~2019-02-04 13:42 UTC|newest]

Thread overview: 18+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2019-01-01  0:00 Aurelien Jarno [this message]
2019-01-01  0:00 ` Florian Weimer
2019-01-01  0:00   ` Florian Weimer
2019-01-01  0:00     ` Carlos O'Donell
2019-01-01  0:00       ` Florian Weimer
2019-01-01  0:00         ` Carlos O'Donell
2019-01-01  0:00           ` Florian Weimer
2019-01-01  0:00             ` Carlos O'Donell
2019-01-01  0:00               ` Florian Weimer
2019-01-01  0:00                 ` Carlos O'Donell
2019-01-01  0:00                   ` Florian Weimer
2019-01-01  0:00                     ` Aurelien Jarno
2019-01-01  0:00                     ` Carlos O'Donell
2019-01-01  0:00   ` Carlos O'Donell
2019-01-01  0:00 ` Florian Weimer
2019-01-01  0:00   ` Aurelien Jarno
2019-01-01  0:00     ` Florian Weimer
2019-01-01  0:00       ` Aurelien Jarno

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20190204134254.GA13816@aurel32.net \
    --to=aurelien@aurel32.net \
    --cc=libc-stable@sourceware.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for read-only IMAP folder(s) and NNTP newsgroup(s).