]> git.ipfire.org Git - thirdparty/openembedded/openembedded-core.git/commit
nasm: fix CVE-2022-44370
authorArchana Polampalli <archana.polampalli@windriver.com>
Wed, 6 Sep 2023 02:21:18 +0000 (10:21 +0800)
committerSteve Sakoman <steve@sakoman.com>
Fri, 29 Sep 2023 15:38:26 +0000 (05:38 -1000)
commit91e716b75861f2a4acee58a0c3f95e511058f1dc
treee7006b87ba6e9133e549cda6c68202b396338d04
parentbd594af20fce07908f8e0fb1765b0e0ccc641e86
nasm: fix CVE-2022-44370

NASM v2.16 was discovered to contain a heap buffer overflow in the
component quote_for_pmake() asm/nasm.c:856

References:
https://nvd.nist.gov/vuln/detail/CVE-2022-44370

Upstream patches:
https://github.com/netwide-assembler/nasm/commit/2d4e6952417ec6f08b6f135d2b5d0e19b7dae30d

( cherry picked from commit 1568df72136f46f0767bba56c10c48bf2a1ec259 )

Signed-off-by: Archana Polampalli <archana.polampalli@windriver.com>
Signed-off-by: Steve Sakoman <steve@sakoman.com>
Signed-off-by: Lee Chee Yang <chee.yang.lee@intel.com>
Signed-off-by: Steve Sakoman <steve@sakoman.com>
meta/recipes-devtools/nasm/nasm/CVE-2022-44370.patch [new file with mode: 0644]
meta/recipes-devtools/nasm/nasm_2.15.03.bb