SUSE-SU-2025:20038-1

Source
https://www.suse.com/support/update/announcement/2025/suse-su-202520038-1/
Import Source
https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2025:20038-1.json
JSON Data
https://api.osv.dev/v1/vulns/SUSE-SU-2025:20038-1
Upstream
CVE (5)
Related
Published
2025-02-03T08:53:19Z
Modified
2026-03-23T04:48:08Z
Summary
Security update for glibc
Details

This update for glibc fixes the following issues:

Fixed security issues:

  • CVE-2024-33602: Use time_t for return type of addgetnetgrentX (bsc#1223425)
  • CVE-2024-33599: nscd: Stack-based buffer overflow in netgroup cache (bsc#1223423)
  • CVE-2024-33600: nscd: Avoid null pointer crashes after notfound response (bsc#1223424)
  • CVE-2024-33600: nscd: Do not send missing not-found response in addgetnetgrentX (bsc#1223424)
  • CVE-2024-33601, CVE-2024-33602: netgroup: Use two buffers in addgetnetgrentX (bsc#1223425)
  • CVE-2024-2961: iconv: ISO-2022-CN-EXT: fix out-of-bound writes when writing escape sequence (bsc#1222992)

Fixed non-security issues:

  • Add workaround for invalid use of libc_nonshared.a with non-SUSE libc (bsc#1221482)
  • Fix segfault in wcsncmp (bsc#1228041)
  • Also include stat64 in the 32-bit libc_nonshared.a workaround (bsc#1221482)
  • Avoid creating ULP prologue for _start routine (bsc#1221940)
  • Also add libc_nonshared.a workaround to 32-bit x86 compat package (bsc#1221482)
  • malloc: Use __get_nprocs on arena_get2
  • linux: Use rseq area unconditionally in sched_getcpu
References

Affected packages

SUSE:Linux Micro 6.0 / glibc

Package

Name
glibc
Purl
pkg:rpm/suse/glibc&distro=SUSE%20Linux%20Micro%206.0

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
2.38-7.1

Ecosystem specific

{
    "binaries":  [
        {
            "glibc":  "2.38-7.1",
            "glibc-devel":  "2.38-7.1",
            "glibc-locale":  "2.38-7.1",
            "glibc-locale-base":  "2.38-7.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2025:20038-1.json"