重要な脆弱性情報 CVE番号: CVE-2021-3998 説明: - glibcの 関数が予期せぬ値を返す可能性があり、これにより情報漏洩や機密データの漏洩を引き起こす可能性があります。 影響を受けるパッケージおよび修正ステータス: - glibc: - bullseye およびその安全なバージョン: 2.31-13+deb11u11、修正済み - bookworm およびその安全なバージョン: 2.36-9+deb12u13、修正済み - forky, sid, trixie: 2.41-12、修正済み 影響を受けないバージョン: - stetch, buster, bullseye (これらのバージョンの後に脆弱性コードが導入されました) 修正バージョン: - glibc 不安定版: 2.33-4 補足情報: - 脆弱性は glibc 2.33 バージョンで導入されました。 - 参考リンク: - https://sourceware.org/bugzilla/show_bug.cgi?id=28770 - https://patchwork.sourceware.org/project/glibc/patch/20220113055920.155918-1-siddhesh@sourceware.org/ - https://www.openwall.com/lists/oss-security/2022/01/24/4 - コミット履歴: - https://sourceware.org/git/gitweb.cgi?p=glibc.git;h=ee8d533adb284601c00c94687bc907e10aec9bb - https://sourceware.org/git/gitweb.cgi?p=glibc.git;h=f7a79879c0b2bef0dadd6caaeeeb0d26423e04e5 - https://sourceware.org/git/gitweb.cgi?p=glibc.git;h=c6e0b0b5b0b7922cdf0dce2af671e0c7e500df95