]> code.ossystems Code Review - openembedded-core.git/commit
squashfs-tools: fix CVE-2021-40153
authorKai Kang <kai.kang@windriver.com>
Fri, 17 Sep 2021 23:58:06 +0000 (16:58 -0700)
committerSteve Sakoman <steve@sakoman.com>
Fri, 24 Sep 2021 14:27:46 +0000 (04:27 -1000)
commit48303d1c93cfcadf80830d07597805cc41d5f7e9
treea9b68d5f8dcdaf44400e3ad2d609406d5e35eabe
parent10f2333afd739669013a65112f6471f09e13d124
squashfs-tools: fix CVE-2021-40153

Source: http://git.yoctoproject.org/poky.git
MR: 113126
Type: Security Fix
Disposition: Backport from http://git.yoctoproject.org/cgit/cgit.cgi/poky/commit/?h=hardknott&id=cfc17a7ab5d3b0d6354a7194b8c8746c501959d9
ChangeID: cfc17a7ab5d3b0d6354a7194b8c8746c501959d9
Description:

Backport patch to fix CVE-2021-40153, and remove version update in
unsquashfs.c for compatible.

CVE: CVE-2021-40153

Ref:
* https://security-tracker.debian.org/tracker/CVE-2021-40153

(From OE-Core rev: 09de4ef3f33540069a37e9fe6e13081984b77511)

Signed-off-by: Kai Kang <kai.kang@windriver.com>
Signed-off-by: Anuj Mittal <anuj.mittal@intel.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
Signed-off-by: Armin Kuster <akuster@mvista.com>
Signed-off-by: Steve Sakoman <steve@sakoman.com>
meta/recipes-devtools/squashfs-tools/files/CVE-2021-40153.patch [new file with mode: 0644]
meta/recipes-devtools/squashfs-tools/squashfs-tools_git.bb