mirror of
https://git.yoctoproject.org/poky
synced 2026-09-12 06:49:32 +02:00
rsync: fix CVE-2024-12085
A flaw was found in the rsync daemon which could be triggered when rsync compares file checksums. This flaw allows an attacker to manipulate the checksum length (s2length) to cause a comparison between a checksum and uninitialized memory and leak one byte of uninitialized stack data at a time. (From OE-Core rev: 3fd8bea3e72573cca03cd3f6f4fc077cd2fd45a3) Signed-off-by: Archana Polampalli <archana.polampalli@windriver.com> Signed-off-by: Steve Sakoman <steve@sakoman.com>
This commit is contained in:
committed by
Steve Sakoman
parent
a1fab4c1a9
commit
5d60b24103
@@ -17,6 +17,7 @@ SRC_URI = "https://download.samba.org/pub/${BPN}/src/${BP}.tar.gz \
|
||||
file://0001-Add-missing-prototypes-to-function-declarations.patch \
|
||||
file://CVE-2024-12084-0001.patch \
|
||||
file://CVE-2024-12084-0002.patch \
|
||||
file://CVE-2024-12085.patch \
|
||||
"
|
||||
|
||||
SRC_URI[sha256sum] = "4e7d9d3f6ed10878c58c5fb724a67dacf4b6aac7340b13e488fb2dc41346f2bb"
|
||||
|
||||
Reference in New Issue
Block a user