nodejs: Fix CVEs for nodejs

Add patch file CVE-llhttp.patch to fix CVE-2022-32213,
CVE-2022-32214, CVE-2022-32215, CVE-2022-35256 of nodejs.

Link: https://sources.debian.org/src/nodejs/12.22.12~dfsg-1~deb11u3/debian/patches/cve-llhttp.patch

Signed-off-by: Poonam Jadhav <Poonam.Jadhav@kpit.com>
Signed-off-by: Omkar Patil <omkarpatil10.93@gmail.com>
Signed-off-by: Armin Kuster <akuster808@gmail.com>
This commit is contained in:
Poonam Jadhav
2023-03-03 18:02:15 +05:30
committed by Armin Kuster
parent 9291a88738
commit 068acc4ec7
2 changed files with 4349 additions and 0 deletions
File diff suppressed because it is too large Load Diff
@@ -25,6 +25,7 @@ SRC_URI = "http://nodejs.org/dist/v${PV}/node-v${PV}.tar.xz \
file://CVE-2022-32212.patch \
file://CVE-2022-35255.patch \
file://CVE-2022-43548.patch \
file://CVE-llhttp.patch \
"
SRC_URI_append_class-target = " \
file://0002-Using-native-binaries.patch \