]> code.ossystems Code Review - openembedded-core.git/commit
libxml2: fix CVE-2021-3516
authorTony Tascioglu <tony.tascioglu@windriver.com>
Fri, 14 May 2021 13:14:49 +0000 (09:14 -0400)
committerRichard Purdie <richard.purdie@linuxfoundation.org>
Sat, 22 May 2021 09:01:16 +0000 (10:01 +0100)
commit490cddd7baf1aacb814128b611aabf82fda3e77b
tree52fc1f7bc09905da45deaffec0bc744b57b332f7
parent16ad173ba0e8f88b23c62aa8357b8afca36c2161
libxml2: fix CVE-2021-3516

Fixes use-after-free in xmlEncodeEntitiesInternal() in entities.c

CVE: CVE-2021-3516
Upstream-Status: Backport [https://gitlab.gnome.org/GNOME/libxml2/-/commit/1358d157d0bd83be1dfe356a69213df9fac0b539]

Signed-off-by: Tony Tascioglu <tony.tascioglu@windriver.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
meta/recipes-core/libxml/libxml2/CVE-2021-3516.patch [new file with mode: 0644]
meta/recipes-core/libxml/libxml2_2.9.10.bb