mirror of
https://git.yoctoproject.org/poky
synced 2026-06-02 13:29:49 +00:00
Binutils: Security fix for CVE-2018-10373
Affects: <= 2.30 (From OE-Core rev: bea11092ddf2e6778bd55af1f2044a9e9fa1383b) Signed-off-by: Armin Kuster <akuster@mvista.com> Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
This commit is contained in:
committed by
Richard Purdie
parent
2d7d54a5c5
commit
711e5e7b08
@@ -66,6 +66,7 @@ SRC_URI = "\
|
||||
file://CVE-2017-17125.patch \
|
||||
file://CVE-2017-17123.patch \
|
||||
file://CVE-2018-10372.patch \
|
||||
file://CVE-2018-10373.patch \
|
||||
"
|
||||
S = "${WORKDIR}/git"
|
||||
|
||||
|
||||
@@ -0,0 +1,45 @@
|
||||
From 6327533b1fd29fa86f6bf34e61c332c010e3c689 Mon Sep 17 00:00:00 2001
|
||||
From: Nick Clifton <nickc@redhat.com>
|
||||
Date: Tue, 17 Apr 2018 14:30:07 +0100
|
||||
Subject: [PATCH] Add a check for a NULL table pointer before attempting to
|
||||
compute a DWARF filename.
|
||||
|
||||
PR 23065
|
||||
* dwarf2.c (concat_filename): Check for a NULL table pointer.
|
||||
|
||||
Upstream-Status: Backport
|
||||
Affects: <= 2.30
|
||||
CVE: CVE-2018-10373
|
||||
Signed-off-by: Armin Kuster <akuster@mvista.com>
|
||||
|
||||
---
|
||||
bfd/ChangeLog | 5 +++++
|
||||
bfd/dwarf2.c | 2 +-
|
||||
2 files changed, 6 insertions(+), 1 deletion(-)
|
||||
|
||||
Index: git/bfd/dwarf2.c
|
||||
===================================================================
|
||||
--- git.orig/bfd/dwarf2.c
|
||||
+++ git/bfd/dwarf2.c
|
||||
@@ -1587,7 +1587,7 @@ concat_filename (struct line_info_table
|
||||
{
|
||||
char *filename;
|
||||
|
||||
- if (file - 1 >= table->num_files)
|
||||
+ if (table == NULL || file - 1 >= table->num_files)
|
||||
{
|
||||
/* FILE == 0 means unknown. */
|
||||
if (file)
|
||||
Index: git/bfd/ChangeLog
|
||||
===================================================================
|
||||
--- git.orig/bfd/ChangeLog
|
||||
+++ git/bfd/ChangeLog
|
||||
@@ -1,3 +1,8 @@
|
||||
+2018-04-17 Nick Clifton <nickc@redhat.com>
|
||||
+
|
||||
+ PR 23065
|
||||
+ * dwarf2.c (concat_filename): Check for a NULL table pointer.
|
||||
+
|
||||
2017-11-28 Nick Clifton <nickc@redhat.com>
|
||||
|
||||
PR 22506
|
||||
Reference in New Issue
Block a user