From 67c37737ed474d25fd4dc535dfd822c426e6b971 Mon Sep 17 00:00:00 2001 From: Carlos O'Donell Date: Mon, 6 Feb 2023 10:36:32 -0500 Subject: NEWS: Document CVE-2023-25139. Reviewed-by: Siddhesh Poyarekar --- NEWS | 7 ++++++- 1 file changed, 6 insertions(+), 1 deletion(-) diff --git a/NEWS b/NEWS index b227e72..a7979a9 100644 --- a/NEWS +++ b/NEWS @@ -21,7 +21,12 @@ Changes to build and runtime requirements: Security related changes: - [Add security related changes here] + CVE-2023-25139: When the printf family of functions is called with a + format specifier that uses an (enable grouping) and a + minimum width specifier, the resulting output could be larger than + reasonably expected by a caller that computed a tight bound on the + buffer size. The resulting larger than expected output could result + in a buffer overflow in the printf family of functions. The following bugs are resolved with this release: -- cgit v1.1