summaryrefslogtreecommitdiffstats
path: root/meta/recipes-extended/xz/xz_5.2.4.bb
diff options
context:
space:
mode:
authorRalph Siemsen <ralph.siemsen@linaro.org>2022-04-08 22:17:15 -0400
committerRichard Purdie <richard.purdie@linuxfoundation.org>2022-04-21 21:26:01 +0100
commit62aefd3864e289c4ab71c80c4b27de93d184241a (patch)
tree2fd7774f89e555fd1fd3d57ee7f363c5d36f06f3 /meta/recipes-extended/xz/xz_5.2.4.bb
parentf36e87ec4f6e2d45533001b8c4b39d72501a3b5e (diff)
downloadpoky-62aefd3864e289c4ab71c80c4b27de93d184241a.tar.gz
xz: fix CVE-2022-1271
Malicious filenames can make xzgrep to write to arbitrary files or (with a GNU sed extension) lead to arbitrary code execution. Upstream-Status: Backport [https://tukaani.org/xz/xzgrep-ZDI-CAN-16587.patch] CVE: CVE-2022-1271 (From OE-Core rev: da4180062f12aa855a0dd2c0dbe4f0721df67055) Signed-off-by: Ralph Siemsen <ralph.siemsen@linaro.org> Signed-off-by: Steve Sakoman <steve@sakoman.com> Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
Diffstat (limited to 'meta/recipes-extended/xz/xz_5.2.4.bb')
-rw-r--r--meta/recipes-extended/xz/xz_5.2.4.bb4
1 files changed, 3 insertions, 1 deletions
diff --git a/meta/recipes-extended/xz/xz_5.2.4.bb b/meta/recipes-extended/xz/xz_5.2.4.bb
index 67a6cbd569..6d80a4f2e9 100644
--- a/meta/recipes-extended/xz/xz_5.2.4.bb
+++ b/meta/recipes-extended/xz/xz_5.2.4.bb
@@ -23,7 +23,9 @@ LIC_FILES_CHKSUM = "file://COPYING;md5=97d554a32881fee0aa283d96e47cb24a \
23 file://lib/getopt.c;endline=23;md5=2069b0ee710572c03bb3114e4532cd84 \ 23 file://lib/getopt.c;endline=23;md5=2069b0ee710572c03bb3114e4532cd84 \
24 " 24 "
25 25
26SRC_URI = "https://tukaani.org/xz/xz-${PV}.tar.gz" 26SRC_URI = "https://tukaani.org/xz/xz-${PV}.tar.gz \
27 file://CVE-2022-1271.patch \
28 "
27SRC_URI[md5sum] = "5ace3264bdd00c65eeec2891346f65e6" 29SRC_URI[md5sum] = "5ace3264bdd00c65eeec2891346f65e6"
28SRC_URI[sha256sum] = "b512f3b726d3b37b6dc4c8570e137b9311e7552e8ccbab4d39d47ce5f4177145" 30SRC_URI[sha256sum] = "b512f3b726d3b37b6dc4c8570e137b9311e7552e8ccbab4d39d47ce5f4177145"
29UPSTREAM_CHECK_REGEX = "xz-(?P<pver>\d+(\.\d+)+)\.tar" 31UPSTREAM_CHECK_REGEX = "xz-(?P<pver>\d+(\.\d+)+)\.tar"