]> git.ipfire.org Git - thirdparty/openembedded/openembedded-core.git/commit
libsoup-2.4: fix CVE-2024-52532
authorChangqing Li <changqing.li@windriver.com>
Mon, 12 May 2025 05:21:02 +0000 (13:21 +0800)
committerSteve Sakoman <steve@sakoman.com>
Tue, 13 May 2025 16:05:03 +0000 (09:05 -0700)
commite91fb129f132aae628b3a942afe9259c25f1b539
treef051ebad6e3e4eba070ff1e067513bda1f104c5c
parent0c6561cc7a5ca9e82ce3f17a9d0e68a7c1c88c84
libsoup-2.4: fix CVE-2024-52532

CVE-2024-52532:
GNOME libsoup before 3.6.1 has an infinite loop, and memory consumption.
during the reading of certain patterns of WebSocket data from clients.

Refer:
https://nvd.nist.gov/vuln/detail/CVE-2024-52532

Signed-off-by: Changqing Li <changqing.li@windriver.com>
Signed-off-by: Steve Sakoman <steve@sakoman.com>
meta/recipes-support/libsoup/libsoup-2.4/CVE-2024-52532-1.patch [new file with mode: 0644]
meta/recipes-support/libsoup/libsoup-2.4/CVE-2024-52532-2.patch [new file with mode: 0644]
meta/recipes-support/libsoup/libsoup-2.4/CVE-2024-52532-3.patch [new file with mode: 0644]
meta/recipes-support/libsoup/libsoup-2.4_2.74.3.bb