From d62a7733e0db6d2295af5d12b6202b40040143cb Mon Sep 17 00:00:00 2001 From: Lee Chee Yang Date: Fri, 7 Aug 2020 17:45:19 +0800 Subject: webkitgtk: fix CVE-2020-13753 (From OE-Core rev: c19c4ef4efeebe4df03c06a995a60d1a31c605d8) Signed-off-by: Lee Chee Yang Signed-off-by: Steve Sakoman Signed-off-by: Richard Purdie --- meta/recipes-sato/webkit/webkitgtk/CVE-2020-13753.patch | 15 +++++++++++++++ meta/recipes-sato/webkit/webkitgtk_2.28.2.bb | 1 + 2 files changed, 16 insertions(+) create mode 100644 meta/recipes-sato/webkit/webkitgtk/CVE-2020-13753.patch (limited to 'meta/recipes-sato') diff --git a/meta/recipes-sato/webkit/webkitgtk/CVE-2020-13753.patch b/meta/recipes-sato/webkit/webkitgtk/CVE-2020-13753.patch new file mode 100644 index 0000000000..d8504c2b36 --- /dev/null +++ b/meta/recipes-sato/webkit/webkitgtk/CVE-2020-13753.patch @@ -0,0 +1,15 @@ +Upstream-Status: Backport [https://trac.webkit.org/changeset/262368/webkit?format=diff&new=262368] +CVE: CVE-2020-13753 +Signed-off-by: Chee Yang Lee + +Index: a/Source/WebKit/UIProcess/Launcher/glib/BubblewrapLauncher.cpp +=================================================================== +--- a/Source/WebKit/UIProcess/Launcher/glib/BubblewrapLauncher.cpp (revision 262367) ++++ b/Source/WebKit/UIProcess/Launcher/glib/BubblewrapLauncher.cpp (revision 262368) +@@ -642,5 +642,5 @@ + int r; + if (rule.arg) +- r = seccomp_rule_add(seccomp, SCMP_ACT_ERRNO(EPERM), scall, 1, rule.arg); ++ r = seccomp_rule_add(seccomp, SCMP_ACT_ERRNO(EPERM), scall, 1, *rule.arg); + else + r = seccomp_rule_add(seccomp, SCMP_ACT_ERRNO(EPERM), scall, 0); diff --git a/meta/recipes-sato/webkit/webkitgtk_2.28.2.bb b/meta/recipes-sato/webkit/webkitgtk_2.28.2.bb index 288c715cc3..9cfec83ec7 100644 --- a/meta/recipes-sato/webkit/webkitgtk_2.28.2.bb +++ b/meta/recipes-sato/webkit/webkitgtk_2.28.2.bb @@ -19,6 +19,7 @@ SRC_URI = "https://www.webkitgtk.org/releases/${BPN}-${PV}.tar.xz \ file://cross-compile.patch \ file://0001-Fix-build-with-musl.patch \ file://include_array.patch \ + file://CVE-2020-13753.patch \ " SRC_URI[md5sum] = "ec0ef870ca37e3a5ebbead2f268a28ec" SRC_URI[sha256sum] = "b9d23525cfd8d22c37b5d964a9fe9a8ce7583042a2f8d3922e71e6bbc68c30bd" -- cgit v1.2.3-54-g00ecf