diff options
author | Lee Chee Yang <chee.yang.lee@intel.com> | 2020-08-07 17:45:19 +0800 |
---|---|---|
committer | Richard Purdie <richard.purdie@linuxfoundation.org> | 2020-08-12 10:53:47 +0100 |
commit | d62a7733e0db6d2295af5d12b6202b40040143cb (patch) | |
tree | 347a04a49bf0867a7d6637820a40219447a0d6d1 /meta | |
parent | 24f6a075e52ab2d88bd24f61526ee21d58ca1b33 (diff) | |
download | poky-d62a7733e0db6d2295af5d12b6202b40040143cb.tar.gz |
webkitgtk: fix CVE-2020-13753
(From OE-Core rev: c19c4ef4efeebe4df03c06a995a60d1a31c605d8)
Signed-off-by: Lee Chee Yang <chee.yang.lee@intel.com>
Signed-off-by: Steve Sakoman <steve@sakoman.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
Diffstat (limited to 'meta')
-rw-r--r-- | meta/recipes-sato/webkit/webkitgtk/CVE-2020-13753.patch | 15 | ||||
-rw-r--r-- | meta/recipes-sato/webkit/webkitgtk_2.28.2.bb | 1 |
2 files changed, 16 insertions, 0 deletions
diff --git a/meta/recipes-sato/webkit/webkitgtk/CVE-2020-13753.patch b/meta/recipes-sato/webkit/webkitgtk/CVE-2020-13753.patch new file mode 100644 index 0000000000..d8504c2b36 --- /dev/null +++ b/meta/recipes-sato/webkit/webkitgtk/CVE-2020-13753.patch | |||
@@ -0,0 +1,15 @@ | |||
1 | Upstream-Status: Backport [https://trac.webkit.org/changeset/262368/webkit?format=diff&new=262368] | ||
2 | CVE: CVE-2020-13753 | ||
3 | Signed-off-by: Chee Yang Lee <chee.yang.lee@intel.com> | ||
4 | |||
5 | Index: a/Source/WebKit/UIProcess/Launcher/glib/BubblewrapLauncher.cpp | ||
6 | =================================================================== | ||
7 | --- a/Source/WebKit/UIProcess/Launcher/glib/BubblewrapLauncher.cpp (revision 262367) | ||
8 | +++ b/Source/WebKit/UIProcess/Launcher/glib/BubblewrapLauncher.cpp (revision 262368) | ||
9 | @@ -642,5 +642,5 @@ | ||
10 | int r; | ||
11 | if (rule.arg) | ||
12 | - r = seccomp_rule_add(seccomp, SCMP_ACT_ERRNO(EPERM), scall, 1, rule.arg); | ||
13 | + r = seccomp_rule_add(seccomp, SCMP_ACT_ERRNO(EPERM), scall, 1, *rule.arg); | ||
14 | else | ||
15 | r = seccomp_rule_add(seccomp, SCMP_ACT_ERRNO(EPERM), scall, 0); | ||
diff --git a/meta/recipes-sato/webkit/webkitgtk_2.28.2.bb b/meta/recipes-sato/webkit/webkitgtk_2.28.2.bb index 288c715cc3..9cfec83ec7 100644 --- a/meta/recipes-sato/webkit/webkitgtk_2.28.2.bb +++ b/meta/recipes-sato/webkit/webkitgtk_2.28.2.bb | |||
@@ -19,6 +19,7 @@ SRC_URI = "https://www.webkitgtk.org/releases/${BPN}-${PV}.tar.xz \ | |||
19 | file://cross-compile.patch \ | 19 | file://cross-compile.patch \ |
20 | file://0001-Fix-build-with-musl.patch \ | 20 | file://0001-Fix-build-with-musl.patch \ |
21 | file://include_array.patch \ | 21 | file://include_array.patch \ |
22 | file://CVE-2020-13753.patch \ | ||
22 | " | 23 | " |
23 | SRC_URI[md5sum] = "ec0ef870ca37e3a5ebbead2f268a28ec" | 24 | SRC_URI[md5sum] = "ec0ef870ca37e3a5ebbead2f268a28ec" |
24 | SRC_URI[sha256sum] = "b9d23525cfd8d22c37b5d964a9fe9a8ce7583042a2f8d3922e71e6bbc68c30bd" | 25 | SRC_URI[sha256sum] = "b9d23525cfd8d22c37b5d964a9fe9a8ce7583042a2f8d3922e71e6bbc68c30bd" |