mirror of
https://git.yoctoproject.org/poky
synced 2026-02-20 08:29:42 +01:00
binutls: Security fix CVE-2018-10373
Affects <= 2.30 (From OE-Core rev: 3c83b9be884015e238249c0382299aedf4d81459) Signed-off-by: Armin Kuster <akuster@mvista.com> Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
This commit is contained in:
committed by
Richard Purdie
parent
ea6a69cb83
commit
6d092834bd
@@ -43,6 +43,7 @@ SRC_URI = "\
|
||||
file://CVE-2018-7208.patch \
|
||||
file://CVE-2018-7569.patch \
|
||||
file://CVE-2018-7568.patch \
|
||||
file://CVE-2018-10373.patch \
|
||||
"
|
||||
S = "${WORKDIR}/git"
|
||||
|
||||
|
||||
45
meta/recipes-devtools/binutils/binutils/CVE-2018-10373.patch
Normal file
45
meta/recipes-devtools/binutils/binutils/CVE-2018-10373.patch
Normal file
@@ -0,0 +1,45 @@
|
||||
From 6327533b1fd29fa86f6bf34e61c332c010e3c689 Mon Sep 17 00:00:00 2001
|
||||
From: Nick Clifton <nickc@redhat.com>
|
||||
Date: Tue, 17 Apr 2018 14:30:07 +0100
|
||||
Subject: [PATCH] Add a check for a NULL table pointer before attempting to
|
||||
compute a DWARF filename.
|
||||
|
||||
PR 23065
|
||||
* dwarf2.c (concat_filename): Check for a NULL table pointer.
|
||||
|
||||
Upstream-Status: Backport
|
||||
Affects: Binutils <= 2.30
|
||||
CVE: CVE-2018-10373
|
||||
Signed-off-by: Armin Kuster <akuster@mvista.com>
|
||||
|
||||
---
|
||||
bfd/ChangeLog | 5 +++++
|
||||
bfd/dwarf2.c | 2 +-
|
||||
2 files changed, 6 insertions(+), 1 deletion(-)
|
||||
|
||||
Index: git/bfd/dwarf2.c
|
||||
===================================================================
|
||||
--- git.orig/bfd/dwarf2.c
|
||||
+++ git/bfd/dwarf2.c
|
||||
@@ -1565,7 +1565,7 @@ concat_filename (struct line_info_table
|
||||
{
|
||||
char *filename;
|
||||
|
||||
- if (file - 1 >= table->num_files)
|
||||
+ if (table == NULL || file - 1 >= table->num_files)
|
||||
{
|
||||
/* FILE == 0 means unknown. */
|
||||
if (file)
|
||||
Index: git/bfd/ChangeLog
|
||||
===================================================================
|
||||
--- git.orig/bfd/ChangeLog
|
||||
+++ git/bfd/ChangeLog
|
||||
@@ -1,3 +1,8 @@
|
||||
+2018-04-17 Nick Clifton <nickc@redhat.com>
|
||||
+
|
||||
+ PR 23065
|
||||
+ * dwarf2.c (concat_filename): Check for a NULL table pointer.
|
||||
+
|
||||
2018-01-29 Alan Modra <amodra@gmail.com>
|
||||
|
||||
PR 22741
|
||||
Reference in New Issue
Block a user