diff options
| author | Divya Chellam <divya.chellam@windriver.com> | 2025-07-08 15:08:17 +0530 |
|---|---|---|
| committer | Steve Sakoman <steve@sakoman.com> | 2025-07-14 08:37:40 -0700 |
| commit | 6b95583a823da8f676cab720d660b16bc29ff89e (patch) | |
| tree | d81b919f5d62dac896b43d342da1a17e41e656cb /meta/recipes-extended/libarchive/libarchive_3.6.2.bb | |
| parent | 6cc6cd3f8d2a981280ec5f90da699411c4a1a6c7 (diff) | |
| download | poky-6b95583a823da8f676cab720d660b16bc29ff89e.tar.gz | |
libarchive: fix CVE-2025-5916
A vulnerability has been identified in the libarchive library. This flaw
involves an integer overflow that can be triggered when processing a Web
Archive (WARC) file that claims to have more than INT64_MAX - 4 content
bytes. An attacker could craft a malicious WARC archive to induce this
overflow, potentially leading to unpredictable program behavior, memory
corruption, or a denial-of-service condition within applications that
process such archives using libarchive.
Reference:
https://security-tracker.debian.org/tracker/CVE-2025-5916
Upstream-patch:
https://github.com/libarchive/libarchive/commit/ef093729521fcf73fa4007d5ae77adfe4df42403
(From OE-Core rev: 0e939bf5fc7412c7357fcd7d8ae760f023ac40eb)
Signed-off-by: Divya Chellam <divya.chellam@windriver.com>
Signed-off-by: Steve Sakoman <steve@sakoman.com>
Diffstat (limited to 'meta/recipes-extended/libarchive/libarchive_3.6.2.bb')
| -rw-r--r-- | meta/recipes-extended/libarchive/libarchive_3.6.2.bb | 1 |
1 files changed, 1 insertions, 0 deletions
diff --git a/meta/recipes-extended/libarchive/libarchive_3.6.2.bb b/meta/recipes-extended/libarchive/libarchive_3.6.2.bb index c612c1b7e0..f90063ba3a 100644 --- a/meta/recipes-extended/libarchive/libarchive_3.6.2.bb +++ b/meta/recipes-extended/libarchive/libarchive_3.6.2.bb | |||
| @@ -37,6 +37,7 @@ SRC_URI = "http://libarchive.org/downloads/libarchive-${PV}.tar.gz \ | |||
| 37 | file://CVE-2025-25724.patch \ | 37 | file://CVE-2025-25724.patch \ |
| 38 | file://CVE-2025-5914.patch \ | 38 | file://CVE-2025-5914.patch \ |
| 39 | file://CVE-2025-5915.patch \ | 39 | file://CVE-2025-5915.patch \ |
| 40 | file://CVE-2025-5916.patch \ | ||
| 40 | " | 41 | " |
| 41 | UPSTREAM_CHECK_URI = "http://libarchive.org/" | 42 | UPSTREAM_CHECK_URI = "http://libarchive.org/" |
| 42 | 43 | ||
