sgerrand / alpine-pkg-glibc

A glibc compatibility layer package for Alpine Linux
2.05k stars 280 forks source link

Update to glibc 2.32 #137

Closed a-thaler closed 4 years ago

a-thaler commented 4 years ago

There is a vulnerability reported with classification "high" that is fixed by glibc 2.32 - could the version in alpine-pkg-glibc be bumped to 2.32?

https://nvd.nist.gov/vuln/detail/CVE-2020-1752

Thanks!

frol commented 4 years ago

@sgerrand Kindly pinging you

sgerrand commented 4 years ago

Apologies all for the delay in getting this released. I'll do it now.

sgerrand commented 4 years ago

As per the "Current Status" section in http://www.gnu.org/software/libc/, the version you referenced hasn't been released yet.

The current development version of glibc 2.32, releasing on or around August 1st, 2020.

Once it's available, I'll release a new version of this package.

sgerrand commented 4 years ago

See https://github.com/sgerrand/docker-glibc-builder/pull/37 for the preparatory work.

prantlf commented 4 years ago

The status of the latest glibc has changed:

The current stable version of glibc is 2.32, released on August 5th, 2020.

Time to let the new child go? :-)