Release of the Glibc 2.32 system library

After six months of development has been published release of the system library GNU C Library (glibc) 2.32, which fully complies with the ISO C11 and POSIX.1-2017 standards. The new release includes fixes from 67 developers.

Implemented in Glibc 2.32 improvements notable mentions include:

  • Support has been added for Synopsys ARC HS (ARCv2 ISA) processors. A minimum of binutils 2.32, gcc 8.3, and Linux kernel 5.1 is required for the port. Three ABI variants are supported: arc-linux-gnu, arc-linux-gnuhf, and arceb-linux-gnu (big-endian);
  • Audit modules specified in the DT_AUDIT and
    DT_DEPAUDIT sections of the executable are now supported.
  • Support for the IEEE128 long double type has been implemented for the powerpc64le architecture, enabled when built with the ‘-mabi=ieeolongdouble’ option.
  • Some APIs are annotated using the GCC attribute ‘access’, which allows generating higher-quality warnings during compilation in GCC 10 for potential buffer overflows and other out-of-bounds scenarios.
  • For Linux systems, the functions pthread_attr_setsigmask_np and
    pthread_attr_getsigmask_np have been implemented, allowing applications to specify a signal mask for threads created with pthread_create.
  • Encoding data, character type information, and transliteration tables have been updated to support Unicode specification 13.0.0;
  • A new header file <sys/single_threaded.h> has been added, which defines the variable __libc_single_threaded, usable in applications for single-threaded optimizations.
  • Functions sigabbrev_np and sigdescr_np have been added, which return the abbreviated name and description of a signal (for example, ‘HUP’ and ‘Hangup’ for SIGHUP).
  • Functions strerrorname_np and strerrordesc_np have been added, which return the name and description of an error (for example, ‘EINVAL’ and ‘Invalid argument’ for EINVAL).
  • For the ARM64 platform, the flag ‘—enable-standard-branch-protection’ (or -mbranch-protection=standard in GCC) has been added, activating the ARMv8.5-BTI (Branch Target Indicator) mechanism to protect the execution of instruction sets that should not be branch-targeted. Blocking transitions to arbitrary code sections is implemented to counter the creation of gadgets in exploits using return-oriented programming (ROP), where the attacker does not attempt to place their own code in memory but operates on existing pieces of machine instructions that end with a return instruction, creating a chain of calls to obtain the desired functionality).
  • A major clean-up of obsolete features has been conducted, including the removal of options "—enable-obsolete-rpc" and "—enable-obsolete-nsl", header file . The functions sstk, siginterrupt, sigpause, sighold, sigrelse, sigignore, and sigset, arrays sys_siglist, _sys_siglist, and sys_sigabbrev, as well as the symbols sys_errlist, _sys_errlist, sys_nerr, and _sys_nerr, are deprecated; the NSS module hesiod.
  • By default, ldconfig is now translated to use the new ld.so.cache format, which has been supported in glibc for almost 20 years.
  • Fixed vulnerabilities:
    • CVE-2016-10228 — an infinite loop in the iconv utility that occurs when launched with the "-c" option when processing invalid multi-byte data.
    • CVE-2020-10029 — stack corruption occurs with trigonometric function calls using a pseudo-null argument.
    • CVE-2020-1752 — use-after-free memory access in the glob function when resolving a home directory reference ("~user") in paths.
    • CVE-2020-6096 — improper handling of negative parameter values in memcpy() and memmove() on the ARMv7 platform, which determines the size of the copied area. Allows the execution of code when processing specifically formatted data in the memcpy() and memmove() functions. Notably, the issue remained unresolved for nearly two months since the public disclosure and five months since notifying the Glibc developers.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster