diff options
| author | Ralph Siemsen <ralph.siemsen@linaro.org> | 2022-04-08 22:16:33 -0400 |
|---|---|---|
| committer | Richard Purdie <richard.purdie@linuxfoundation.org> | 2022-04-10 08:31:17 +0100 |
| commit | 30eb28dd02920f166d2deaf5114a8e810c42b948 (patch) | |
| tree | e7b6b09871d972e788f891f299b1c5be9f4ad929 /meta/recipes-extended/xz/xz_5.2.5.bb | |
| parent | 89efab2850766378d89579c094670357775b69b6 (diff) | |
| download | poky-30eb28dd02920f166d2deaf5114a8e810c42b948.tar.gz | |
xz: fix CVE-2022-1271
Malicious filenames can make xzgrep to write to arbitrary files
or (with a GNU sed extension) lead to arbitrary code execution.
Upstream-Status: Backport [https://tukaani.org/xz/xzgrep-ZDI-CAN-16587.patch]
CVE: CVE-2022-1271
(From OE-Core rev: 97bf86ccde4417daec8ef3945071a50a09134bc6)
Signed-off-by: Ralph Siemsen <ralph.siemsen@linaro.org>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
Diffstat (limited to 'meta/recipes-extended/xz/xz_5.2.5.bb')
| -rw-r--r-- | meta/recipes-extended/xz/xz_5.2.5.bb | 4 |
1 files changed, 3 insertions, 1 deletions
diff --git a/meta/recipes-extended/xz/xz_5.2.5.bb b/meta/recipes-extended/xz/xz_5.2.5.bb index 78aa6b20ca..720e070f4a 100644 --- a/meta/recipes-extended/xz/xz_5.2.5.bb +++ b/meta/recipes-extended/xz/xz_5.2.5.bb | |||
| @@ -24,7 +24,9 @@ LIC_FILES_CHKSUM = "file://COPYING;md5=97d554a32881fee0aa283d96e47cb24a \ | |||
| 24 | file://lib/getopt.c;endline=23;md5=2069b0ee710572c03bb3114e4532cd84 \ | 24 | file://lib/getopt.c;endline=23;md5=2069b0ee710572c03bb3114e4532cd84 \ |
| 25 | " | 25 | " |
| 26 | 26 | ||
| 27 | SRC_URI = "https://tukaani.org/xz/xz-${PV}.tar.gz" | 27 | SRC_URI = "https://tukaani.org/xz/xz-${PV}.tar.gz \ |
| 28 | file://CVE-2022-1271.patch \ | ||
| 29 | " | ||
| 28 | SRC_URI[md5sum] = "0d270c997aff29708c74d53f599ef717" | 30 | SRC_URI[md5sum] = "0d270c997aff29708c74d53f599ef717" |
| 29 | SRC_URI[sha256sum] = "f6f4910fd033078738bd82bfba4f49219d03b17eb0794eb91efbae419f4aba10" | 31 | SRC_URI[sha256sum] = "f6f4910fd033078738bd82bfba4f49219d03b17eb0794eb91efbae419f4aba10" |
| 30 | UPSTREAM_CHECK_REGEX = "xz-(?P<pver>\d+(\.\d+)+)\.tar" | 32 | UPSTREAM_CHECK_REGEX = "xz-(?P<pver>\d+(\.\d+)+)\.tar" |
