[Bug 1794544] Re: [SRU] 2.56.3

Launchpad Bug Tracker 1794544 at bugs.launchpad.net
Mon Nov 12 19:50:26 UTC 2018


This bug was fixed in the package glib2.0 - 2.56.3-0ubuntu0.18.04.1

---------------
glib2.0 (2.56.3-0ubuntu0.18.04.1) bionic; urgency=medium

  * New upstream release (LP: #1794544)
    + The documentation for G_GNUC_MALLOC has changed to be more restrictive
      to avoid miscompilations; you should check whether any uses of it in
      your code are appropriate
    + Fix cancellation of g_subprocess_communicate_async() calls
    + Bug fixes:
      + /network-monitor/create-in-thread fails in (LXC) containers on glib-2-56
      + GBookmarkFile: nullptr access in current_element
      + GBookmarkFile: heap-buffer-overflow in g_utf8_get_char
      + Backport g_subprocess_communicate() cancellation fixes from !266 to
        glib-2-56 (LP: #1789476)
      + Many uses of G_GNUC_MALLOC are incorrect
      + Test for BROKEN_IP_MREQ_SOURCE_STRUCT is broken on Windows / Mingw
      + Fix persistent CI failure on glib-2-56
  * debian/watch: Only find 2.56 versions.
  * Drop CVE-2018-16428.patch and CVE-2018-16429.patch: applied in this release

 -- Iain Lane <iain.lane at canonical.com>  Wed, 26 Sep 2018 17:35:59 +0100

** Changed in: glib2.0 (Ubuntu Bionic)
       Status: Fix Committed => Fix Released

** CVE added: https://cve.mitre.org/cgi-bin/cvename.cgi?name=2018-16428

** CVE added: https://cve.mitre.org/cgi-bin/cvename.cgi?name=2018-16429

-- 
You received this bug notification because you are a member of Ubuntu
Foundations Bugs, which is subscribed to glib2.0 in Ubuntu.
https://bugs.launchpad.net/bugs/1794544

Title:
  [SRU] 2.56.3

Status in glib2.0 package in Ubuntu:
  Fix Released
Status in glib2.0 source package in Bionic:
  Fix Released

Bug description:
  [ Description ]

  The third stable release in the 2.56 series.

  [ QA ]

  Upstream release, so QA already performed by maintainers

  https://wiki.ubuntu.com/StableReleaseUpdates/GNOME

  This upload will trigger many autopkgtests that we expect to not be
  regressed by this upload.

  [ Regression potential ]

  Various fixes in multiple places so multiple apps could be affected.

    * New upstream release (LP: #xxx)
      + The documentation for G_GNUC_MALLOC has changed to be more restrictive
        to avoid miscompilations; you should check whether any uses of it in
        your code are appropriate
      + Fix cancellation of g_subprocess_communicate_async() calls
      + Bug fixes:
        + /network-monitor/create-in-thread fails in (LXC) containers on glib-2-56
        + GBookmarkFile: nullptr access in current_element
        + GBookmarkFile: heap-buffer-overflow in g_utf8_get_char
        + Backport g_subprocess_communicate() cancellation fixes from !266 to
          glib-2-56 (LP: #1789476)
        + Many uses of G_GNUC_MALLOC are incorrect
        + Test for BROKEN_IP_MREQ_SOURCE_STRUCT is broken on Windows / Mingw
        + Fix persistent CI failure on glib-2-56

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/glib2.0/+bug/1794544/+subscriptions



More information about the foundations-bugs mailing list