Skip to content

Commit 61f6d0a

Browse files
ffontainetpetazzoni
authored andcommitted
package/slirp: security bump to version 4.6.1
mtod()-related buffer overflows (CVE-2021-3592 #44, CVE-2021-3593 #45, CVE-2021-3594 #47, CVE-2021-3595 #46). Drop patch (already in version) https://gitlab.freedesktop.org/slirp/libslirp/-/blob/v4.6.1/CHANGELOG.md Signed-off-by: Fabrice Fontaine <fontaine.fabrice@gmail.com> Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
1 parent 92d8b98 commit 61f6d0a

3 files changed

Lines changed: 3 additions & 68 deletions

File tree

package/slirp/0001-slirp-check-pkt_len-before-reading-protocol-header.patch

Lines changed: 0 additions & 60 deletions
This file was deleted.

package/slirp/slirp.hash

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,3 +1,3 @@
11
# Locally computed:
2-
sha256 388b4b08a8cc0996cc5155cb027a097dc1a7f2cfe84b1121496608ab5366cc48 libslirp-4.3.1.tar.xz
2+
sha256 b8a22ac4d601ba16122a67827c0f4361785d4d283f21ff8ed48d4aa1e7693477 libslirp-4.6.1.tar.xz
33
sha256 b28aecf4796a6a22054167f0a976de13d9db335669d37afd2dc7ea4c335e1e13 COPYRIGHT

package/slirp/slirp.mk

Lines changed: 2 additions & 7 deletions
Original file line numberDiff line numberDiff line change
@@ -4,19 +4,14 @@
44
#
55
################################################################################
66

7-
SLIRP_VERSION = 4.3.1
7+
SLIRP_VERSION = 4.6.1
88
SLIRP_SOURCE = libslirp-$(SLIRP_VERSION).tar.xz
9-
# Other "official" tarballs don't ship .tarball-version resulting in a build
10-
# failure: https://gitlab.freedesktop.org/slirp/libslirp/-/issues/24
11-
SLIRP_SITE = https://elmarco.fedorapeople.org
9+
SLIRP_SITE = https://gitlab.freedesktop.org/slirp/libslirp/uploads/83b199ea6fcdfc0c243dfde8546ee4c9
1210
SLIRP_LICENSE = BSD-3-Clause
1311
SLIRP_LICENSE_FILES = COPYRIGHT
1412
SLIRP_CPE_ID_VENDOR = libslirp_project
1513
SLIRP_CPE_ID_PRODUCT = libslirp
1614
SLIRP_INSTALL_STAGING = YES
1715
SLIRP_DEPENDENCIES = libglib2
1816

19-
# 0001-slirp-check-pkt_len-before-reading-protocol-header.patch
20-
SLIRP_IGNORE_CVES += CVE-2020-29129 CVE-2020-29130
21-
2217
$(eval $(meson-package))

0 commit comments

Comments
 (0)