summaryrefslogtreecommitdiffstats
path: root/meta/recipes-core/glib-2.0/glib-2.0/CVE-2021-27219-reg1-1.patch
diff options
context:
space:
mode:
authorNeetika Singh <Neetika.Singh@kpit.com>2021-11-30 21:00:11 +0530
committerRichard Purdie <richard.purdie@linuxfoundation.org>2021-12-08 20:28:00 +0000
commit090075eb3a7499d350dbd3ccd4c45711bd37ddba (patch)
tree7099ef2c4baf833fcdcadfb7fffa5eb4af917474 /meta/recipes-core/glib-2.0/glib-2.0/CVE-2021-27219-reg1-1.patch
parentd875c5e57b91c415292e530ce90f354107581be6 (diff)
downloadpoky-090075eb3a7499d350dbd3ccd4c45711bd37ddba.tar.gz
glib-2.0: Add security fixes
Add patches for below CVE issues: CVE-2021-27218 CVE-2021-27219 CVE-2021-28153 Link: https://mirrors.ocf.berkeley.edu/ubuntu/pool/main/g/glib2.0/glib2.0_2.64.6-1~ubuntu20.04.3.debian.tar.xz Also, add regression patchs for CVE-2021-27219. CVE-2021-27219-reg1-3.patch is not relevant for glib2.0 v2.64 (From OE-Core rev: 4fb30dd540b1fb56a14237e21e84b22f8b515dc5) Signed-off-by: Neetika.Singh <Neetika.Singh@kpit.com> Signed-off-by: Ranjitsinh Rathod <ranjitsinh.rathod@kpit.com> Signed-off-by: Ranjitsinh Rathod <ranjitsinhrathod1991@gmail.com> Signed-off-by: Steve Sakoman <steve@sakoman.com> Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
Diffstat (limited to 'meta/recipes-core/glib-2.0/glib-2.0/CVE-2021-27219-reg1-1.patch')
-rw-r--r--meta/recipes-core/glib-2.0/glib-2.0/CVE-2021-27219-reg1-1.patch36
1 files changed, 36 insertions, 0 deletions
diff --git a/meta/recipes-core/glib-2.0/glib-2.0/CVE-2021-27219-reg1-1.patch b/meta/recipes-core/glib-2.0/glib-2.0/CVE-2021-27219-reg1-1.patch
new file mode 100644
index 0000000000..3047062f54
--- /dev/null
+++ b/meta/recipes-core/glib-2.0/glib-2.0/CVE-2021-27219-reg1-1.patch
@@ -0,0 +1,36 @@
1From f8273b9aded135fe07094faebd527e43851aaf6e Mon Sep 17 00:00:00 2001
2From: "Jan Alexander Steffens (heftig)" <jan.steffens@gmail.com>
3Date: Sun, 7 Feb 2021 23:32:40 +0100
4Subject: [PATCH 1/5] giochannel: Fix length_size bounds check
5
6The inverted condition is an obvious error introduced by ecdf91400e9a.
7
8Fixes https://gitlab.gnome.org/GNOME/glib/-/issues/2323
9
10(cherry picked from commit a149bf2f9030168051942124536e303af8ba6176)
11
12Upstream-Status: Backport [https://mirrors.ocf.berkeley.edu/ubuntu/pool/main/g/glib2.0/glib2.0_2.64.6-1~ubuntu20.04.3.debian.tar.xz]
13CVE: CVE-2021-27219
14Signed-off-by: Ranjitsinh Rathod <ranjitsinh.rathod@kpit.com>
15
16---
17 glib/giochannel.c | 2 +-
18 1 file changed, 1 insertion(+), 1 deletion(-)
19
20diff --git a/glib/giochannel.c b/glib/giochannel.c
21index 4dec20f77..c3f3102ff 100644
22--- a/glib/giochannel.c
23+++ b/glib/giochannel.c
24@@ -896,7 +896,7 @@ g_io_channel_set_line_term (GIOChannel *channel,
25 {
26 /* FIXME: We’re constrained by line_term_len being a guint here */
27 gsize length_size = strlen (line_term);
28- g_return_if_fail (length_size > G_MAXUINT);
29+ g_return_if_fail (length_size <= G_MAXUINT);
30 length_unsigned = (guint) length_size;
31 }
32
33--
34GitLab
35
36