]> code.ossystems Code Review - openembedded-core.git/commit
expat: fix CVE-2021-46143
authorSteve Sakoman <steve@sakoman.com>
Wed, 19 Jan 2022 14:59:07 +0000 (04:59 -1000)
committerSteve Sakoman <steve@sakoman.com>
Wed, 19 Jan 2022 15:02:51 +0000 (05:02 -1000)
commit41a65d27e4ecdc11977e2944d8af2f51c48f32ec
tree01037e7fcae455c5ad5be7959fdccd57174a3368
parent22fe1dea3164a5cd4d5636376f3671641ada1da9
expat: fix CVE-2021-46143

In doProlog in xmlparse.c in Expat (aka libexpat) before 2.4.3, an
integer overflow exists for m_groupSize.

Backport patch from:
https://github.com/libexpat/libexpat/pull/538/commits/85ae9a2d7d0e9358f356b33977b842df8ebaec2b

CVE: CVE-2021-46143
Signed-off-by: Steve Sakoman <steve@sakoman.com>
meta/recipes-core/expat/expat/CVE-2021-46143.patch [new file with mode: 0644]
meta/recipes-core/expat/expat_2.2.9.bb