musl libc @musl.treehouse.systems.ap.brid.gy · 03/10/2026We're aiming to put out a bugfix release of #musl libc in the next 1-2 weeks, then merge the new locale support to the mainline git branch after release. 🎉 102
musl libc @musl.treehouse.systems.ap.brid.gy · 23/09/2026Bikeshed time! The topic of default search path for musl locales is up for discussion: www.openwall.com/lists/musl/2026/09…openwall.commusl - Default path search for locale - request for comments 002
Reposted by musl libcCassandrich @dalias.hachyderm.io.ap.brid.gy · 21/09/2026I've just sent out the first version of the patch series for #musl making up the locale overhaul project. It's available to read on the mailing list to subscribers and in the web-based archive at www.openwall.com/lists/musl/2026/09… These should all be pretty close to the form […]hachyderm.ioOriginal post on hachyderm.io 102
Reposted by musl libcCassandrich @dalias.hachyderm.io.ap.brid.gy · 10/09/2026I've started a (private atm, will be rebased a few times) branch for the #musl locale project merge. First some preliminaries. Bumping the Unicode character data from version 12 to version 17. Only +10% size to iswalpha/iswpunct tables, +5% to upper/lower case mappings. About +20% to wcwidth […]hachyderm.ioOriginal post on hachyderm.io 312
Reposted by musl libcCassandrich @dalias.hachyderm.io.ap.brid.gy · 03/09/2026I'm pleased to announce a big step in the #musl locale overhaul project: collation is working! This is the result of a long project to design data structures and logic that would admit honoring the full Unicode Collation Algorithm rules, including equivalence under normalization, and keep the […]hachyderm.ioOriginal post on hachyderm.io 3110
Reposted by musl libcCassandrich @dalias.hachyderm.io.ap.brid.gy · 06/05/2026This exploit write-up features #musl 1.1.24, whose oldmalloc (dlmalloc-like) was used to convert the exploitable bug in the application into an arbitrary write primitive. www.synacktiv.com/en/publications/m… musl 1.2.1 […]hachyderm.ioOriginal post on hachyderm.io 001
musl libc @musl.treehouse.systems.ap.brid.gy · 10/04/2026SECURITY ADVISORY: musl libc up through 1.2.6 (present version) is affected by CVE-2026-40200 affecting qsort with large arrays. Unless you have a setup with at least tens of terrabytes of virtual memory, this does not affect 64-bit systems, only 32-bit ones. But all users should patch […]social.treehouse.systemsOriginal post on social.treehouse.systems 039
musl libc @musl.treehouse.systems.ap.brid.gy · 03/04/2026An issue has been reported in musl libc's iconv decoder for GB18030 (Chinese) character encoding, whereby performance for decoding certain characters is pathologically bad, allowing DoC in processes handling untrusted data in this encoding or with encoding declared by the input. The researcher […]social.treehouse.systemsOriginal post on social.treehouse.systems 001
musl libc @musl.treehouse.systems.ap.brid.gy · 20/03/2026musl 1.2.6 is now available. For details see the release announcement on the mailing list: www.openwall.com/lists/musl/2026/03… Source link: musl.libc.org/releases/musl-1.2.6.t… Detailed WHATSNEW: git.musl-libc.org/cgit/musl/tree/WH…openwall.commusl - musl 1.2.6 released 003
musl libc @musl.treehouse.systems.ap.brid.gy · 20/03/2026The public key fingerprint for #musl release signatures is: 8364 8929 0BB6 B70F 99FF DA05 56BC DB59 3020 450F Republishing this here now for the first time since our move to Treehouse, to follow a past practice for redundancy of sources of trust. 033