summaryrefslogtreecommitdiffstats
diff options
context:
space:
mode:
authorLee Chee Yang <chee.yang.lee@intel.com>2020-08-07 17:45:19 +0800
committerRichard Purdie <richard.purdie@linuxfoundation.org>2020-08-12 10:53:47 +0100
commitd62a7733e0db6d2295af5d12b6202b40040143cb (patch)
tree347a04a49bf0867a7d6637820a40219447a0d6d1
parent24f6a075e52ab2d88bd24f61526ee21d58ca1b33 (diff)
downloadpoky-d62a7733e0db6d2295af5d12b6202b40040143cb.tar.gz
webkitgtk: fix CVE-2020-13753
(From OE-Core rev: c19c4ef4efeebe4df03c06a995a60d1a31c605d8) Signed-off-by: Lee Chee Yang <chee.yang.lee@intel.com> Signed-off-by: Steve Sakoman <steve@sakoman.com> Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
-rw-r--r--meta/recipes-sato/webkit/webkitgtk/CVE-2020-13753.patch15
-rw-r--r--meta/recipes-sato/webkit/webkitgtk_2.28.2.bb1
2 files changed, 16 insertions, 0 deletions
diff --git a/meta/recipes-sato/webkit/webkitgtk/CVE-2020-13753.patch b/meta/recipes-sato/webkit/webkitgtk/CVE-2020-13753.patch
new file mode 100644
index 0000000000..d8504c2b36
--- /dev/null
+++ b/meta/recipes-sato/webkit/webkitgtk/CVE-2020-13753.patch
@@ -0,0 +1,15 @@
1Upstream-Status: Backport [https://trac.webkit.org/changeset/262368/webkit?format=diff&new=262368]
2CVE: CVE-2020-13753
3Signed-off-by: Chee Yang Lee <chee.yang.lee@intel.com>
4
5Index: a/Source/WebKit/UIProcess/Launcher/glib/BubblewrapLauncher.cpp
6===================================================================
7--- a/Source/WebKit/UIProcess/Launcher/glib/BubblewrapLauncher.cpp (revision 262367)
8+++ b/Source/WebKit/UIProcess/Launcher/glib/BubblewrapLauncher.cpp (revision 262368)
9@@ -642,5 +642,5 @@
10 int r;
11 if (rule.arg)
12- r = seccomp_rule_add(seccomp, SCMP_ACT_ERRNO(EPERM), scall, 1, rule.arg);
13+ r = seccomp_rule_add(seccomp, SCMP_ACT_ERRNO(EPERM), scall, 1, *rule.arg);
14 else
15 r = seccomp_rule_add(seccomp, SCMP_ACT_ERRNO(EPERM), scall, 0);
diff --git a/meta/recipes-sato/webkit/webkitgtk_2.28.2.bb b/meta/recipes-sato/webkit/webkitgtk_2.28.2.bb
index 288c715cc3..9cfec83ec7 100644
--- a/meta/recipes-sato/webkit/webkitgtk_2.28.2.bb
+++ b/meta/recipes-sato/webkit/webkitgtk_2.28.2.bb
@@ -19,6 +19,7 @@ SRC_URI = "https://www.webkitgtk.org/releases/${BPN}-${PV}.tar.xz \
19 file://cross-compile.patch \ 19 file://cross-compile.patch \
20 file://0001-Fix-build-with-musl.patch \ 20 file://0001-Fix-build-with-musl.patch \
21 file://include_array.patch \ 21 file://include_array.patch \
22 file://CVE-2020-13753.patch \
22 " 23 "
23SRC_URI[md5sum] = "ec0ef870ca37e3a5ebbead2f268a28ec" 24SRC_URI[md5sum] = "ec0ef870ca37e3a5ebbead2f268a28ec"
24SRC_URI[sha256sum] = "b9d23525cfd8d22c37b5d964a9fe9a8ce7583042a2f8d3922e71e6bbc68c30bd" 25SRC_URI[sha256sum] = "b9d23525cfd8d22c37b5d964a9fe9a8ce7583042a2f8d3922e71e6bbc68c30bd"