Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

GLIBC-SA-2024-0004/CVE-2024-2961: ISO-2022-CN-EXT: fix out-of-bound writes when writing escape sequence #2121

Open
oerdnj opened this issue Apr 23, 2024 · 3 comments

Comments

@oerdnj
Copy link
Owner

oerdnj commented Apr 23, 2024

Just a quick summary:

  • There's nothing I can do on the PHP side, it needs to be fixed in libc
  • Ubuntu libc packages are already fixed
  • Debian unstable and stable is fixed, old stable is not

On older Debian, edit /usr/lib/x86_64-linux-gnu/gconv/gconv-modules.d/gconv-modules-extra.conf, comment out vulnerable locale and reload the iconv cache. Here's Rocky Linux guide that should be applicable (with just different paths) to Debian and Ubuntu: https://rockylinux.org/news/glibc-vulnerability-april-2024/

@oerdnj oerdnj pinned this issue Apr 23, 2024
@sleemanj
Copy link

Instructions for manually disabling on older systems generally....

https://old.reddit.com/r/PHP/comments/1c9lslg/security_vulnerability_in_php_caused_by_glibc/l0o6zi1/

@oerdnj
Copy link
Owner Author

oerdnj commented Apr 23, 2024

@sleemanj That's what the link to Rocky Linux contains. The Reddit connect looks copied from that page…

@oerdnj
Copy link
Owner Author

oerdnj commented May 14, 2024

Here's an update from PHP itself: https://www.php.net/archive/2024.php#2024-04-24-1

@oerdnj oerdnj unpinned this issue Jul 1, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants