[UBUNTU 23.10] s390x: clone clobbers r7

Bug #2055175 reported by bugproxy
12
This bug affects 1 person
Affects Status Importance Assigned to Milestone
Ubuntu on IBM z Systems
Fix Released
Medium
Skipper Bug Screeners
glibc (Ubuntu)
Fix Released
High
Unassigned
Mantic
Won't Fix
Undecided
Unassigned
Noble
Fix Released
High
Unassigned

Bug Description

=== Description by <email address hidden> ==

On s390x, if clone is called with NULL for child-function or stack argument, then r7 is clobbered. This bug is needed for glibc 2.37, 2.38, 2.39. Please pick the committed bugfix.

See
- glibc bugzilla:
Bug 31402 - clone (NULL, NULL, ...) clobbers %r7 register on s390{,x}
https://sourceware.org/bugzilla/show_bug.cgi?id=31402

- glibc-commit on master:
S390: Do not clobber r7 in clone [BZ #31402]
https://sourceware.org/git/?p=glibc.git;a=commit;h=02782fd12849b6673cb5c2728cb750e8ec295aa3

- glibc-commit on release/2.37/master:
https://sourceware.org/git/?p=glibc.git;a=commit;h=9a1bdd7df731a4bc60f72dbdc1b849e02cfa9c34

- glibc-commit on release/2.38/master:
https://sourceware.org/git/?p=glibc.git;a=commit;h=ee4806e978467d705b26ccb7dfddb9e0a710f8e4

- glibc-commit on release/2.39/master:
https://sourceware.org/git/?p=glibc.git;a=commit;h=e0910f1d3278f05439fb434ee528fc9be1b6bd5e

CVE References

bugproxy (bugproxy)
tags: added: architecture-s3903164 bugnameltc-205731 severity-medium targetmilestone-inin---
Changed in ubuntu:
assignee: nobody → Skipper Bug Screeners (skipper-screen-team)
affects: ubuntu → linux (Ubuntu)
Frank Heimes (fheimes)
affects: linux (Ubuntu) → glibc (Ubuntu)
Changed in ubuntu-z-systems:
assignee: nobody → Skipper Bug Screeners (skipper-screen-team)
Changed in glibc (Ubuntu):
assignee: Skipper Bug Screeners (skipper-screen-team) → nobody
Changed in ubuntu-z-systems:
importance: Undecided → Medium
Revision history for this message
Frank Heimes (fheimes) wrote :

Since the current glibc situation in Ubuntu is like this:
 libc6 | 2.35-0ubuntu3 | jammy | amd64, arm64, armhf, i386, ppc64el, riscv64, s390x
 libc6 | 2.35-0ubuntu3.6 | jammy-security | amd64, arm64, armhf, i386, ppc64el, riscv64, s390x
 libc6 | 2.35-0ubuntu3.6 | jammy-updates | amd64, arm64, armhf, i386, ppc64el, riscv64, s390x
 libc6 | 2.38-1ubuntu6 | mantic | amd64, arm64, armhf, i386, ppc64el, riscv64, s390x
 libc6 | 2.38-1ubuntu6.1 | mantic-security | amd64, arm64, armhf, i386, ppc64el, riscv64, s390x
 libc6 | 2.38-1ubuntu6.1 | mantic-updates | amd64, arm64, armhf, i386, ppc64el, riscv64, s390x
 libc6 | 2.39-0ubuntu2 | noble | amd64, arm64, armhf, i386, ppc64el, riscv64, s390x
it will affect Ubuntu 23.10 and 24.04 - marking those as target series.

tags: added: noble
Frank Heimes (fheimes)
tags: added: rls-mm-incoming rls-nn-incoming
tags: added: foundations-todo
removed: rls-mm-incoming rls-nn-incoming
Revision history for this message
Simon Chopin (schopin) wrote :

This will be fixed in Noble in an upcoming bugfix upload of glibc (a couple of weeks), however we aren't planning on doing a Mantic SRU unless something critical comes up.

Changed in glibc (Ubuntu Mantic):
status: New → Won't Fix
Changed in glibc (Ubuntu Noble):
status: New → Triaged
importance: Undecided → High
Frank Heimes (fheimes)
Changed in ubuntu-z-systems:
status: New → Triaged
Simon Chopin (schopin)
Changed in glibc (Ubuntu Noble):
status: Triaged → Fix Committed
Frank Heimes (fheimes)
Changed in ubuntu-z-systems:
status: Triaged → Fix Committed
Revision history for this message
Launchpad Janitor (janitor) wrote :

This bug was fixed in the package glibc - 2.39-0ubuntu8

---------------
glibc (2.39-0ubuntu8) noble; urgency=medium

  * No-change rebuild for CVE-2024-3094

 -- Steve Langasek <email address hidden> Sat, 30 Mar 2024 07:42:05 +0000

Changed in glibc (Ubuntu Noble):
status: Fix Committed → Fix Released
Frank Heimes (fheimes)
Changed in ubuntu-z-systems:
status: Fix Committed → Fix Released
Revision history for this message
bugproxy (bugproxy) wrote : Comment bridged from LTC Bugzilla

------- Comment From <email address hidden> 2024-04-05 17:21 EDT-------
Fix has been released. Thanks for all your work!
With that, we can close this bug.

Changing status to: "CLOSED"

tags: added: targetmilestone-inin2404
removed: targetmilestone-inin---
Revision history for this message
bugproxy (bugproxy) wrote :

------- Comment From <email address hidden> 2024-04-10 12:39 EDT-------
*** Bug 205730 has been marked as a duplicate of this bug. ***

To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Duplicates of this bug

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.