{"id":"MGASA-2023-0270","summary":"Updated glibc packages fix security and other bugs","details":"getaddrinfo: Fix use after free in getcanonname (CVE-2023-4806)\n\nStack read overflow with large TCP responses in no-aaaa mode\n(CVE-2023-4527)\n\nelf: Introduce to _dl_call_fini\nelf: Do not run constructors for proxy objects\nelf: Always call destructors in reverse constructor order [BZ #30785]\nelf: Remove unused l_text_end field from struct link_map\nelf: Move l_init_called_next to old place of l_text_end in link map\nelf: Fix slow tls access after dlopen [BZ #19924]\nintl: Treat C.UTF-8 locale like C locale [BZ# 16621]\nx86: Increase non_temporal_threshold to roughly \"sizeof_L3 / 4\"\nx86: Fix slight bug in shared_per_thread cache size calculation\nx86: Use 3/4*sizeof(per-thread-L3) as low bound for NT threshold\nx86: Fix incorrect scope of setting shared_per_thread [BZ #30745]\n","modified":"2026-04-16T04:40:44.702760552Z","published":"2023-09-27T16:31:30Z","upstream":["CVE-2023-4527","CVE-2023-4806"],"references":[{"type":"ADVISORY","url":"https://advisories.mageia.org/MGASA-2023-0270.html"},{"type":"REPORT","url":"https://bugs.mageia.org/show_bug.cgi?id=32292"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-4527"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-4806"}],"affected":[{"package":{"name":"glibc","ecosystem":"Mageia:9","purl":"pkg:rpm/mageia/glibc?arch=source&distro=mageia-9"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.36-49.mga9"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2023-0270.json"}}],"schema_version":"1.7.5","credits":[{"name":"Mageia","contact":["https://wiki.mageia.org/en/Packages_Security_Team"],"type":"COORDINATOR"}]}