From e099b1462db0289d04ff2d89b55519faee0403b5 Mon Sep 17 00:00:00 2001 From: Roland Kovacs Date: Sat, 2 Aug 2025 23:55:36 +0200 Subject: [PATCH] jq: add Upstream-Status and CVE tags into .patch files v1 version was merged instead of v2 from: https://lists.openembedded.org/g/openembedded-devel/message/118302 add missing Upstream-Status and CVE tags from v2. Signed-off-by: Roland Kovacs Signed-off-by: Martin Jansa Signed-off-by: Anuj Mittal --- meta-oe/recipes-devtools/jq/jq/CVE-2024-23337.patch | 3 +++ meta-oe/recipes-devtools/jq/jq/CVE-2024-53427.patch | 3 +++ meta-oe/recipes-devtools/jq/jq/CVE-2025-48060.patch | 3 +++ 3 files changed, 9 insertions(+) diff --git a/meta-oe/recipes-devtools/jq/jq/CVE-2024-23337.patch b/meta-oe/recipes-devtools/jq/jq/CVE-2024-23337.patch index 93f55eecd0..8b8243b752 100644 --- a/meta-oe/recipes-devtools/jq/jq/CVE-2024-23337.patch +++ b/meta-oe/recipes-devtools/jq/jq/CVE-2024-23337.patch @@ -8,6 +8,9 @@ This commit fixes signed integer overflow and SEGV issues on growing arrays and objects. The size of arrays and objects is now limited to `536870912` (`0x20000000`). This fixes CVE-2024-23337 and fixes #3262. +Upstream-Status: Backport [https://github.com/jqlang/jq.git/commit/de21386681c0df0104a99d9d09db23a9b2a78b1e] +CVE: CVE-2024-23337 + (cherry picked from commit de21386681c0df0104a99d9d09db23a9b2a78b1e) Signed-off-by: Roland Kovacs --- diff --git a/meta-oe/recipes-devtools/jq/jq/CVE-2024-53427.patch b/meta-oe/recipes-devtools/jq/jq/CVE-2024-53427.patch index 3e27a13036..64a44a1307 100644 --- a/meta-oe/recipes-devtools/jq/jq/CVE-2024-53427.patch +++ b/meta-oe/recipes-devtools/jq/jq/CVE-2024-53427.patch @@ -7,6 +7,9 @@ This commit drops support for parsing NaN with payload in JSON like `NaN123` and fixes CVE-2024-53427. Other JSON extensions like `NaN` and `Infinity` are still supported. Fixes #3023, fixes #3196, fixes #3246. +Upstream-Status: Backport [https://github.com/jqlang/jq.git/commit/a09a4dfd55e6c24d04b35062ccfe4509748b1dd3] +CVE: CVE-2024-53427 + (cherry picked from commit a09a4dfd55e6c24d04b35062ccfe4509748b1dd3) Signed-off-by: Roland Kovacs --- diff --git a/meta-oe/recipes-devtools/jq/jq/CVE-2025-48060.patch b/meta-oe/recipes-devtools/jq/jq/CVE-2025-48060.patch index 237a50413f..c3dfd8ce21 100644 --- a/meta-oe/recipes-devtools/jq/jq/CVE-2025-48060.patch +++ b/meta-oe/recipes-devtools/jq/jq/CVE-2025-48060.patch @@ -9,6 +9,9 @@ GHSA-p7rr-28xf-3m5w (`0[""*0]`) was fixed by the commit dc849e9bb74a, but another case (`0[[]|implode]`) was still vulnerable. This commit ensures string data is properly null-terminated, and fixes CVE-2025-48060. +Upstream-Status: Backport [https://github.com/jqlang/jq.git/commit/c6e041699d8cd31b97375a2596217aff2cfca85b] +CVE: CVE-2025-48060 + (cherry picked from commit c6e041699d8cd31b97375a2596217aff2cfca85b) Signed-off-by: Roland Kovacs ---