]> git.ipfire.org Git - thirdparty/openembedded/openembedded-core.git/commit
nasm: fix CVE-2022-44370
authorArchana Polampalli <archana.polampalli@windriver.com>
Wed, 26 Apr 2023 06:46:18 +0000 (06:46 +0000)
committerSteve Sakoman <steve@sakoman.com>
Wed, 26 Apr 2023 16:09:24 +0000 (06:09 -1000)
commit1568df72136f46f0767bba56c10c48bf2a1ec259
treeeaab16dadd7cdcf60b8ff99636c39d0f82f24d3e
parentdc2c777cab0230fc54e078d20d872aaa9287a8b9
nasm: fix CVE-2022-44370

NASM v2.16 was discovered to contain a heap buffer overflow in the
component quote_for_pmake() asm/nasm.c:856

References:
https://nvd.nist.gov/vuln/detail/CVE-2022-44370

Upstream patches:
https://github.com/netwide-assembler/nasm/commit/2d4e6952417ec6f08b6f135d2b5d0e19b7dae30d

Signed-off-by: Archana Polampalli <archana.polampalli@windriver.com>
Signed-off-by: Steve Sakoman <steve@sakoman.com>
meta/recipes-devtools/nasm/nasm/CVE-2022-44370.patch [new file with mode: 0644]
meta/recipes-devtools/nasm/nasm_2.15.05.bb