summaryrefslogtreecommitdiffstats
path: root/meta/recipes-extended/libarchive/libarchive_3.6.2.bb
diff options
context:
space:
mode:
authorDivya Chellam <divya.chellam@windriver.com>2025-07-08 15:08:17 +0530
committerSteve Sakoman <steve@sakoman.com>2025-07-14 08:37:40 -0700
commit6b95583a823da8f676cab720d660b16bc29ff89e (patch)
treed81b919f5d62dac896b43d342da1a17e41e656cb /meta/recipes-extended/libarchive/libarchive_3.6.2.bb
parent6cc6cd3f8d2a981280ec5f90da699411c4a1a6c7 (diff)
downloadpoky-6b95583a823da8f676cab720d660b16bc29ff89e.tar.gz
libarchive: fix CVE-2025-5916
A vulnerability has been identified in the libarchive library. This flaw involves an integer overflow that can be triggered when processing a Web Archive (WARC) file that claims to have more than INT64_MAX - 4 content bytes. An attacker could craft a malicious WARC archive to induce this overflow, potentially leading to unpredictable program behavior, memory corruption, or a denial-of-service condition within applications that process such archives using libarchive. Reference: https://security-tracker.debian.org/tracker/CVE-2025-5916 Upstream-patch: https://github.com/libarchive/libarchive/commit/ef093729521fcf73fa4007d5ae77adfe4df42403 (From OE-Core rev: 0e939bf5fc7412c7357fcd7d8ae760f023ac40eb) Signed-off-by: Divya Chellam <divya.chellam@windriver.com> Signed-off-by: Steve Sakoman <steve@sakoman.com>
Diffstat (limited to 'meta/recipes-extended/libarchive/libarchive_3.6.2.bb')
-rw-r--r--meta/recipes-extended/libarchive/libarchive_3.6.2.bb1
1 files changed, 1 insertions, 0 deletions
diff --git a/meta/recipes-extended/libarchive/libarchive_3.6.2.bb b/meta/recipes-extended/libarchive/libarchive_3.6.2.bb
index c612c1b7e0..f90063ba3a 100644
--- a/meta/recipes-extended/libarchive/libarchive_3.6.2.bb
+++ b/meta/recipes-extended/libarchive/libarchive_3.6.2.bb
@@ -37,6 +37,7 @@ SRC_URI = "http://libarchive.org/downloads/libarchive-${PV}.tar.gz \
37 file://CVE-2025-25724.patch \ 37 file://CVE-2025-25724.patch \
38 file://CVE-2025-5914.patch \ 38 file://CVE-2025-5914.patch \
39 file://CVE-2025-5915.patch \ 39 file://CVE-2025-5915.patch \
40 file://CVE-2025-5916.patch \
40 " 41 "
41UPSTREAM_CHECK_URI = "http://libarchive.org/" 42UPSTREAM_CHECK_URI = "http://libarchive.org/"
42 43