]> git.ipfire.org Git - thirdparty/openembedded/openembedded-core.git/commit
libsoup-2.4: fix CVE-2024-52532
authorChangqing Li <changqing.li@windriver.com>
Thu, 8 May 2025 09:54:28 +0000 (17:54 +0800)
committerRichard Purdie <richard.purdie@linuxfoundation.org>
Mon, 12 May 2025 21:01:25 +0000 (22:01 +0100)
commit4efb2f03cf47382bf79aec333109c78e309c337b
tree7a10bfbbcc9b991d1d1bf8c5ef013adc897e6955
parent31ddbed4155f36ff8cda5fcf7e6c301ae63cd62f
libsoup-2.4: fix CVE-2024-52532

CVE-2024-52532:
GNOME libsoup before 3.6.1 has an infinite loop, and memory consumption.
during the reading of certain patterns of WebSocket data from clients.

Refer:
https://nvd.nist.gov/vuln/detail/CVE-2024-52532

Signed-off-by: Changqing Li <changqing.li@windriver.com>
Signed-off-by: Mathieu Dubois-Briand <mathieu.dubois-briand@bootlin.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
meta/recipes-support/libsoup/libsoup-2.4/CVE-2024-52532-1.patch [new file with mode: 0644]
meta/recipes-support/libsoup/libsoup-2.4/CVE-2024-52532-2.patch [new file with mode: 0644]
meta/recipes-support/libsoup/libsoup-2.4/CVE-2024-52532-3.patch [new file with mode: 0644]
meta/recipes-support/libsoup/libsoup-2.4_2.74.3.bb