From patchwork Wed Nov 13 15:31:49 2019 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Armin Kuster X-Patchwork-Id: 179320 Delivered-To: patch@linaro.org Received: by 2002:a92:38d5:0:0:0:0:0 with SMTP id g82csp9759766ilf; Wed, 13 Nov 2019 07:33:35 -0800 (PST) X-Google-Smtp-Source: APXvYqxFDrjX/NIMh9IPmxqwaF6DrYIOcfM8w7kfH93rgxbWI6CrMigxU0/9r52nd1PhVMbe4sH3 X-Received: by 2002:a17:902:bb94:: with SMTP id m20mr796896pls.190.1573659215021; Wed, 13 Nov 2019 07:33:35 -0800 (PST) ARC-Seal: i=1; a=rsa-sha256; t=1573659215; cv=none; d=google.com; s=arc-20160816; b=nsyzrjJKW1B4IzwfzODkB9DWn868UWnUsTXQ2vYvfJ4bVULiIS8cyNREqwQiL8s3jr deAolvltbk1VgU0jbABblAkfWexjA4PrH6Bs2Q2E6hZyVqJTofdY93XFH+NxM1rlx41U HWCrmKsbLp0Hplsq8szLCAsSG1oUs8NEI8Bdp3xBU7F1HPenjEUZAjLp58r9NS2xBWmG 48LtriMGvbJsub3JjYrX7qQjn5Vm2kXcR+nLBGA7WfF5Zr5hejiPBOgzgftZyv0gXSQT QY6480MVUcl0vmUe0nOZqTwKdznhQIJekXXu5ykxO9iZ4uYm52Zt8dxCe6Mun6dvJTgK kG/w== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=errors-to:sender:content-transfer-encoding:mime-version :list-subscribe:list-help:list-post:list-archive:list-unsubscribe :list-id:precedence:subject:references:in-reply-to:message-id:date :to:from:dkim-signature:delivered-to; bh=Et4pwsZXcog60EhxBZzQ+l31MAP6pgdeiDh6MvCHVi4=; b=KFZm4l7S7l/9CeAKXr9NzbnrHLwlpf+9WuXMtTZm5KNq7sDSZgdgfCbcFIvQEl1vVe lYH8KQM9XJrzeTdYrQH1hEkZCWSFJ+9xA6BhadPspniYhY67eqFbOmYogyCXawEve1WZ iMTl+NltaJkNCttbl6GsU8qkvqHSW6UBZoDqCUKeNknTqPuHalvZuWyZvbjp8yfkbn+M Awzaw7IFsfQsQ3NyR9ZrdphihulRagxUQEVHyMmJ0EtRRo5KeGPFNziSWgeEiq9Y8wfV 4aUFfIUGbiq7dv4A1WUKI3TjmyTW00cktJsO7DlleFwfgJ48t+V3k+Ill4s7kaghUGx+ SmJQ== ARC-Authentication-Results: i=1; mx.google.com; dkim=neutral (body hash did not verify) header.i=@gmail.com header.s=20161025 header.b=BIHFP2P4; spf=pass (google.com: best guess record for domain of openembedded-core-bounces@lists.openembedded.org designates 140.211.169.62 as permitted sender) smtp.mailfrom=openembedded-core-bounces@lists.openembedded.org; dmarc=fail (p=NONE sp=QUARANTINE dis=NONE) header.from=gmail.com Return-Path: Received: from mail.openembedded.org (mail.openembedded.org. [140.211.169.62]) by mx.google.com with ESMTP id m189si3405367pfb.20.2019.11.13.07.33.34; Wed, 13 Nov 2019 07:33:35 -0800 (PST) Received-SPF: pass (google.com: best guess record for domain of openembedded-core-bounces@lists.openembedded.org designates 140.211.169.62 as permitted sender) client-ip=140.211.169.62; Authentication-Results: mx.google.com; dkim=neutral (body hash did not verify) header.i=@gmail.com header.s=20161025 header.b=BIHFP2P4; spf=pass (google.com: best guess record for domain of openembedded-core-bounces@lists.openembedded.org designates 140.211.169.62 as permitted sender) smtp.mailfrom=openembedded-core-bounces@lists.openembedded.org; dmarc=fail (p=NONE sp=QUARANTINE dis=NONE) header.from=gmail.com Received: from ec2-34-214-78-129.us-west-2.compute.amazonaws.com (localhost [127.0.0.1]) by mail.openembedded.org (Postfix) with ESMTP id 9F2F67F819; Wed, 13 Nov 2019 15:32:41 +0000 (UTC) X-Original-To: openembedded-core@lists.openembedded.org Delivered-To: openembedded-core@lists.openembedded.org Received: from mail-pf1-f179.google.com (mail-pf1-f179.google.com [209.85.210.179]) by mail.openembedded.org (Postfix) with ESMTP id 947BE7F7B9 for ; Wed, 13 Nov 2019 15:32:31 +0000 (UTC) Received: by mail-pf1-f179.google.com with SMTP id x28so1892845pfo.6 for ; Wed, 13 Nov 2019 07:32:33 -0800 (PST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025; h=from:to:subject:date:message-id:in-reply-to:references; bh=PkCqd4vEtfmaLVosU4E2Xl4LLtcqtEf+LHwEd8MjHPI=; b=BIHFP2P4lCajvI3mdr4x8RrJy0Q4s5hlNRyQQuG4trkn7DHJKFNZGsPmNHFnj01FKO YmdlWy2u0E03rDZrAuG2EaYOS+2S8PvAZ56vrZ7jEue+SAiG+8ljQ7ZcPt5tIrGaMrrI D+YWVEIBXeE/etSK06CCgLu61h2A6OSjCuS52496D/J/kwR0i/KvZM+xWPfptWGD/WhH YIqyT5HMbnHCj5qMYCIXYc0nWiGqrDDcRJrbOOa2Fys+ECLAMrtmqkLoS9sCXLt2Rmlq /oyz7wqZesNsWpfmg4h9/PzvIBe4oMefuMt2PE+0ikwI8CXtCTol1LCo7hs4zeaHtZyB 4vhA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:from:to:subject:date:message-id:in-reply-to :references; bh=PkCqd4vEtfmaLVosU4E2Xl4LLtcqtEf+LHwEd8MjHPI=; b=IwBVtVH3qzGYfUV/uOKZWYugKxZPix34vKwz+ELLf+tPvhRwo3TTNawtD5XNND1x2l 7/dpiQ/eFQgo8GFV2tA7C5Y5USGkgtU5m+sTTV7AB5JJqjbna5DZo6xYUNMXC/TMQ2E1 zfttT4gVeCj/5Gqkb2FjsJYaBU10Tc4HhDfGuxI/qUJ1dC7Hvf/AW49FS1JO5unuRVKs Bg6Udn8K6+L+c3Rw05xzwm0fvMoOasM2iB3/ifXzoTHORbSabNYfwRRiq9+q0RCbEMjj CslVZsUEgGwVdpWQanafqJx2hJwrQug/wFLeVdYw7LTTzuExoumqhA98/vVlBEaatp4j /i0Q== X-Gm-Message-State: APjAAAVWtnp/3nXW3XagA5Mwqixrl6jA0kFHG0zIn29hHCvFS5qiPnB8 CgCWGL8/cToMHDFwWB2hl1sj2xss X-Received: by 2002:a62:fb02:: with SMTP id x2mr5293414pfm.254.1573659152324; Wed, 13 Nov 2019 07:32:32 -0800 (PST) Received: from akuster-ThinkPad-T460s.mvista.com ([2601:202:4180:a5c0:2cf9:53ea:e6ab:d378]) by smtp.gmail.com with ESMTPSA id s18sm3713613pfm.27.2019.11.13.07.32.31 for (version=TLS1_2 cipher=ECDHE-RSA-AES128-SHA bits=128/128); Wed, 13 Nov 2019 07:32:31 -0800 (PST) From: Armin Kuster To: openembedded-core@lists.openembedded.org Date: Wed, 13 Nov 2019 07:31:49 -0800 Message-Id: <541ec2f0590ab1f2c0667bf36df7c4c1bb0b6a25.1573658916.git.akuster808@gmail.com> X-Mailer: git-send-email 2.7.4 In-Reply-To: References: Subject: [OE-core] [zeus 07/31] libsndfile1: whitelist CVE-2018-13419 X-BeenThere: openembedded-core@lists.openembedded.org X-Mailman-Version: 2.1.12 Precedence: list List-Id: Patches and discussions about the oe-core layer List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , MIME-Version: 1.0 Sender: openembedded-core-bounces@lists.openembedded.org Errors-To: openembedded-core-bounces@lists.openembedded.org From: Ross Burton This is a memory leak that nobody else can replicate and has been rejected by upstream. Signed-off-by: Ross Burton Signed-off-by: Richard Purdie Signed-off-by: Adrian Bunk Signed-off-by: Anuj Mittal --- meta/recipes-multimedia/libsndfile/libsndfile1_1.0.28.bb | 4 ++++ 1 file changed, 4 insertions(+) -- 2.7.4 -- _______________________________________________ Openembedded-core mailing list Openembedded-core@lists.openembedded.org http://lists.openembedded.org/mailman/listinfo/openembedded-core diff --git a/meta/recipes-multimedia/libsndfile/libsndfile1_1.0.28.bb b/meta/recipes-multimedia/libsndfile/libsndfile1_1.0.28.bb index ffb4585..7855008 100644 --- a/meta/recipes-multimedia/libsndfile/libsndfile1_1.0.28.bb +++ b/meta/recipes-multimedia/libsndfile/libsndfile1_1.0.28.bb @@ -33,3 +33,7 @@ PACKAGECONFIG[alsa] = "--enable-alsa,--disable-alsa,alsa-lib" PACKAGECONFIG[regtest] = "--enable-sqlite,--disable-sqlite,sqlite3" inherit autotools lib_package pkgconfig + +# This can't be replicated and is just a memory leak. +# https://github.com/erikd/libsndfile/issues/398 +CVE_CHECK_WHITELIST += "CVE-2018-13419"