1
0
mirror of https://git.yoctoproject.org/poky synced 2026-06-02 01:19:52 +00:00
Files
poky/meta/recipes-connectivity
Praveen Kumar 9b99800fe7 connman :fix CVE-2025-32743
In ConnMan through 1.44, the lookup string in ns_resolv in dnsproxy.c
can be NULL or an empty string when the TC (Truncated) bit is set in
a DNS response. This allows attackers to cause a denial of service
(application crash) or possibly execute arbitrary code, because those
lookup values lead to incorrect length calculations and incorrect
memcpy operations.

Reference:
https://nvd.nist.gov/vuln/detail/CVE-2025-32743

Upstream-patch:
https://git.kernel.org/pub/scm/network/connman/connman.git/commit/?id=d90b911f6760959bdf1393c39fe8d1118315490f

(From OE-Core rev: ece0fb01bf28fa114f0a6e479491b4b6f565c80c)

Signed-off-by: Praveen Kumar <praveen.kumar@windriver.com>
Signed-off-by: Steve Sakoman <steve@sakoman.com>
2025-05-14 06:38:21 -07:00
..
2025-01-24 07:49:28 -08:00
2025-03-04 08:46:02 -08:00
2025-05-14 06:38:21 -07:00
2024-09-16 06:09:56 -07:00
2022-11-24 15:30:01 +00:00
2024-02-28 03:32:09 -10:00
2022-05-04 13:07:34 +01:00
2025-04-11 08:36:02 -07:00
2025-03-13 08:50:03 -07:00
2025-02-15 06:04:44 -08:00
2025-05-02 08:12:41 -07:00
2021-08-02 15:44:10 +01:00
2022-12-07 15:02:45 +00:00
2025-01-24 07:49:28 -08:00