mirror of
https://git.yoctoproject.org/poky
synced 2026-04-29 18:32:20 +02:00
import patch from debian to fix CVE-2025-32910 Upstream-Status: Backport [import from debian https://salsa.debian.org/gnome-team/libsoup/-/tree/debian/bullseye/debian/patches?ref_type=heads Upstream commite40df6d48a&405a8a3459&ea16eeacb0] Reference: https://gitlab.gnome.org/GNOME/libsoup/-/merge_requests/417 https://security-tracker.debian.org/tracker/CVE-2025-32910 (From OE-Core rev: b65e3d3a4dc2375d9bb81c7a91c84139cc667a47) Signed-off-by: Vijay Anusuri <vanusuri@mvista.com> Signed-off-by: Steve Sakoman <steve@sakoman.com>
27 lines
1.0 KiB
Diff
27 lines
1.0 KiB
Diff
From: Patrick Griffis <pgriffis@igalia.com>
|
|
Date: Fri, 27 Dec 2024 13:52:52 -0600
|
|
Subject: auth-digest: Fix leak
|
|
|
|
(cherry picked from commit ea16eeacb052e423eb5c3b0b705e5eab34b13832)
|
|
|
|
Upstream-Status: Backport [import from debian https://salsa.debian.org/gnome-team/libsoup/-/blob/debian/bullseye/debian/patches/CVE-2025-32910-3.patch?ref_type=heads
|
|
Upstream commit https://gitlab.gnome.org/GNOME/libsoup/-/commit/ea16eeacb052e423eb5c3b0b705e5eab34b13832]
|
|
CVE: CVE-2025-32910
|
|
Signed-off-by: Vijay Anusuri <vanusuri@mvista.com>
|
|
---
|
|
libsoup/soup-auth-digest.c | 1 +
|
|
1 file changed, 1 insertion(+)
|
|
|
|
diff --git a/libsoup/soup-auth-digest.c b/libsoup/soup-auth-digest.c
|
|
index 393adb6..a1db188 100644
|
|
--- a/libsoup/soup-auth-digest.c
|
|
+++ b/libsoup/soup-auth-digest.c
|
|
@@ -66,6 +66,7 @@ soup_auth_digest_finalize (GObject *object)
|
|
g_free (priv->nonce);
|
|
g_free (priv->domain);
|
|
g_free (priv->cnonce);
|
|
+ g_free (priv->opaque);
|
|
|
|
memset (priv->hex_urp, 0, sizeof (priv->hex_urp));
|
|
memset (priv->hex_a1, 0, sizeof (priv->hex_a1));
|