From bce56ecf96c7fc1f851f2931437c8bb0932918d6 Mon Sep 17 00:00:00 2001 From: Steve Sakoman Date: Mon, 31 Jan 2022 07:15:20 -1000 Subject: expat: add missing Upstream-status, CVE tag and sign-off to CVE-2021-46143.patch (From OE-Core rev: a32cee6c9e1ff53e424b8386c36555e6cf3bf3af) Signed-off-by: Steve Sakoman (cherry picked from commit 7e33aa25acc0c29b8f5e78757c6557e614eb1434) Signed-off-by: Anuj Mittal Signed-off-by: Richard Purdie --- meta/recipes-core/expat/expat/CVE-2021-46143.patch | 6 ++++++ 1 file changed, 6 insertions(+) (limited to 'meta') diff --git a/meta/recipes-core/expat/expat/CVE-2021-46143.patch b/meta/recipes-core/expat/expat/CVE-2021-46143.patch index d6bafba0ff..b1a726d9a8 100644 --- a/meta/recipes-core/expat/expat/CVE-2021-46143.patch +++ b/meta/recipes-core/expat/expat/CVE-2021-46143.patch @@ -4,6 +4,12 @@ Date: Sat, 25 Dec 2021 20:52:08 +0100 Subject: [PATCH] lib: Prevent integer overflow on m_groupSize in function doProlog (CVE-2021-46143) +Upstream-Status: Backport: +https://github.com/libexpat/libexpat/pull/538/commits/85ae9a2d7d0e9358f356b33977b842df8ebaec2b + +CVE: CVE-2021-46143 + +Signed-off-by: Steve Sakoman --- expat/lib/xmlparse.c | 15 +++++++++++++++ 1 file changed, 15 insertions(+) -- cgit v1.2.3-54-g00ecf