GNU social JP
  • FAQ
  • Login
GNU social JPは日本のGNU socialサーバーです。
Usage/ToS/admin/test/Pleroma FE
  • Public

    • Public
    • Network
    • Groups
    • Featured
    • Popular
    • People

Notices by musl libc (musl@fosstodon.org)

  1. Embed this notice
    musl libc (musl@fosstodon.org)'s status on Friday, 14-Feb-2025 07:13:03 JST musl libc musl libc
    in reply to

    FWIW, libxml2 looks like it would be affected except that it refuses to convert *from* an encoding unless iconv also supports conversion *to* that encoding, and musl does not have encoders for most legacy DBCSs, only decoders.

    In conversation about 3 months ago from fosstodon.org permalink
  2. Embed this notice
    musl libc (musl@fosstodon.org)'s status on Friday, 14-Feb-2025 07:13:02 JST musl libc musl libc
    in reply to

    Some clarification on impact: The most likely impacted programs are things which process data received in arbitrary text encodings.

    For example, mutt (mail user agent) is definitely affected. Other mail clients, web browsers, etc. that use iconv rather than their own converters are probably affected too.

    In conversation about 3 months ago from fosstodon.org permalink
  3. Embed this notice
    musl libc (musl@fosstodon.org)'s status on Friday, 14-Feb-2025 06:21:27 JST musl libc musl libc
    in reply to

    musl-cross-make has now also been updated to apply the CVE-2025-26519 patches to all supported musl versions when building: https://github.com/richfelker/musl-cross-make/commit/7b4c7b315226835bab03da73a45945acb1b3bedf

    In conversation about 3 months ago from fosstodon.org permalink

    Attachments

    1. Domain not in remote thumbnail source whitelist: opengraph.githubassets.com
      add patches for CVE-2025-26519 to all supported musl versions · richfelker/musl-cross-make@7b4c7b3
      Simple makefile-based build for musl cross compiler - add patches for CVE-2025-26519 to all supported musl versions · richfelker/musl-cross-make@7b4c7b3
  4. Embed this notice
    musl libc (musl@fosstodon.org)'s status on Friday, 14-Feb-2025 02:19:30 JST musl libc musl libc

    Security Advisory (CVE-2025-26519) for musl libc:

    https://www.openwall.com/lists/musl/2025/02/13/1

    All users running applications which use iconv with untrusted input (see link for details of what usage is affected) should patch ASAP.

    In conversation about 3 months ago from fosstodon.org permalink
  5. Embed this notice
    musl libc (musl@fosstodon.org)'s status on Friday, 14-Feb-2025 01:46:17 JST musl libc musl libc

    Heads up musl uses: keep an eye out for a security advisory that may affect you. It will be posted on the mailing list and website and linked from a post here, and should appear within the next hour.

    In conversation about 3 months ago from fosstodon.org permalink
  6. Embed this notice
    musl libc (musl@fosstodon.org)'s status on Tuesday, 02-Jul-2024 00:52:56 JST musl libc musl libc

    OpenSSH sshd on musl-based systems is not vulnerable to RCE via CVE-2024-6387 (regreSSHion).

    This is because we do not use localtime in log timestamps and do not use dynamic allocation (because it could fail under memory pressure) for printf formatting.

    While the sshd bug is UB (AS-unsafe syslog call from signal context), very deliberate decisions we made for other good reasons reduced the potential impact to deadlock taking a lock.

    In conversation about 11 months ago from fosstodon.org permalink
  7. Embed this notice
    musl libc (musl@fosstodon.org)'s status on Wednesday, 06-Mar-2024 22:29:07 JST musl libc musl libc

    #musl web infrastructure has now been switched entirely over to tipidee (https://skarnet.org/software/tipidee/) thanks to range request support that was added a while back, and to fix some breakage introduced with split backends. Thanks @ska for writing it, help setting up, and feature additions to meet site needs!

    In conversation about a year ago from fosstodon.org permalink

    Attachments

    1. No result found on File_thumbnail lookup.
      tipidee - a small and fast HTTP/1.1 server
      tipidee - a small and fast HTTP/1.1 server
  8. Embed this notice
    musl libc (musl@fosstodon.org)'s status on Friday, 01-Mar-2024 18:17:34 JST musl libc musl libc
    in reply to

    The 1.2.5 release also fixes a number of bugs, some of which have probably already been backported by distros, but not all.

    In conversation about a year ago from fosstodon.org permalink
  9. Embed this notice
    musl libc (musl@fosstodon.org)'s status on Friday, 01-Mar-2024 18:16:50 JST musl libc musl libc

    musl libc 1.2.5 is now available. Accouncement on the mailing list at https://www.openwall.com/lists/musl/2024/03/01/2

    In conversation about a year ago from fosstodon.org permalink

    Attachments

    1. Domain not in remote thumbnail source whitelist: www.openwall.com
      musl - musl 1.2.5 released
  10. Embed this notice
    musl libc (musl@fosstodon.org)'s status on Friday, 01-Mar-2024 18:16:49 JST musl libc musl libc
    in reply to

    While this release doesn't bring any major new functionality for existing platforms, two new ports are finally upstream in musl: loongarch64 and riscv32.

    In conversation about a year ago from fosstodon.org permalink
  11. Embed this notice
    musl libc (musl@fosstodon.org)'s status on Friday, 15-Dec-2023 03:57:58 JST musl libc musl libc
    in reply to

    Due to lack of support for request ranges, which are needed for friendly download support, static content is not switched over yet, but still using thttpd. We hope to have everything switched over in the near future.

    In conversation Friday, 15-Dec-2023 03:57:58 JST from fosstodon.org permalink
  12. Embed this notice
    musl libc (musl@fosstodon.org)'s status on Friday, 15-Dec-2023 03:56:44 JST musl libc musl libc

    musl libc web infrastructure is in the process of migration to the tipidee (https://skarnet.org/software/tipidee/) httpd software. This should greatly improve git repo access via https, which was previously flaky due to the non-conforming CGI implementation of thttpd.

    In conversation Friday, 15-Dec-2023 03:56:44 JST from fosstodon.org permalink

    Attachments

    1. No result found on File_thumbnail lookup.
      tipidee - a small and fast HTTP/1.1 server
      tipidee - a small and fast HTTP/1.1 server
  13. Embed this notice
    musl libc (musl@fosstodon.org)'s status on Wednesday, 03-May-2023 12:11:35 JST musl libc musl libc

    musl libc 1.2.4 is now released: https://www.openwall.com/lists/musl/2023/05/02/1

    In conversation Wednesday, 03-May-2023 12:11:35 JST from fosstodon.org permalink

    Attachments

    1. Domain not in remote thumbnail source whitelist: www.openwall.com
      musl - musl 1.2.4 released
  14. Embed this notice
    musl libc (musl@fosstodon.org)'s status on Wednesday, 03-May-2023 12:11:33 JST musl libc musl libc
    in reply to

    The highlight of musl 1.2.4 is the new TCP fallback for DNS lookups. This solves the longstanding inability to lookup large records using the libc DNS query API, as well as incompatibility with nameservers that don't handle truncation well.

    In conversation Wednesday, 03-May-2023 12:11:33 JST from fosstodon.org permalink

User actions

    musl libc

    musl libc

    Tags
    • (None)

    Following 0

      Followers 0

        Groups 0

          Statistics

          User ID
          116391
          Member since
          3 May 2023
          Notices
          14
          Daily average
          0

          Feeds

          • Atom
          • Help
          • About
          • FAQ
          • TOS
          • Privacy
          • Source
          • Version
          • Contact

          GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.

          Creative Commons Attribution 3.0 All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.