Pull in stable branch fixes including:
* tunables: Terminate if end of input is reached (CVE-2023-4911)
* Propagate GLIBC_TUNABLES in setxid binaries
* Document CVE-2023-4806 and CVE-2023-5156 in NEWS
* Fix leak in getaddrinfo introduced by the fix for CVE-2023-4806 [BZ #30843]
Also set CVE_STATUS accordingly for the fixes pulled in.
(From OE-Core rev: 7d77bce6158bf11a2de0944f75589382f153bb91)
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>