aboutsummaryrefslogtreecommitdiffstats
path: root/target/linux/pistachio/patches-5.4/101-dmaengine-img-mdc-Handle-early-status-read.patch
diff options
context:
space:
mode:
authorPetr Štetiar <ynezz@true.cz>2020-11-20 13:13:27 +0100
committerPetr Štetiar <ynezz@true.cz>2020-11-20 13:24:48 +0100
commit4d4ef1058c0f10aa2fa4070cd6b9db4d48b94148 (patch)
treee4cf5882e4101c4f7f223e76e133906d4b29a14d /target/linux/pistachio/patches-5.4/101-dmaengine-img-mdc-Handle-early-status-read.patch
parentd36999389890fb952fc7cc8c0db8e1bbb671af12 (diff)
downloadupstream-4d4ef1058c0f10aa2fa4070cd6b9db4d48b94148.tar.gz
upstream-4d4ef1058c0f10aa2fa4070cd6b9db4d48b94148.tar.bz2
upstream-4d4ef1058c0f10aa2fa4070cd6b9db4d48b94148.zip
musl: handle wcsnrtombs destination buffer overflow (CVE-2020-28928)
The wcsnrtombs function in all musl libc versions up through 1.2.1 has been found to have multiple bugs in handling of destination buffer size when limiting the input character count, which can lead to infinite loop with no forward progress (no overflow) or writing past the end of the destination buffera. This function is not used internally in musl and is not widely used, but does appear in some applications. The non-input-limiting form wcsrtombs is not affected. All users of musl 1.2.1 and prior versions should apply the attached patch, which replaces the overly complex and erroneous implementation. The upcoming 1.2.2 release will adopt this new implementation. Signed-off-by: Petr Štetiar <ynezz@true.cz>
Diffstat (limited to 'target/linux/pistachio/patches-5.4/101-dmaengine-img-mdc-Handle-early-status-read.patch')
0 files changed, 0 insertions, 0 deletions