From patchwork Wed Aug 19 11:02:10 2015 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Koen Kooi X-Patchwork-Id: 52541 Return-Path: X-Original-To: linaro@patches.linaro.org Delivered-To: linaro@patches.linaro.org Received: from mail-lb0-f200.google.com (mail-lb0-f200.google.com [209.85.217.200]) by patches.linaro.org (Postfix) with ESMTPS id 37E85218CB for ; Wed, 19 Aug 2015 11:22:47 +0000 (UTC) Received: by lbbpd10 with SMTP id pd10sf519747lbb.3 for ; Wed, 19 Aug 2015 04:22:46 -0700 (PDT) X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20130820; h=x-gm-message-state:delivered-to:delivered-to:from:to:date :message-id:in-reply-to:references:cc:subject:precedence:reply-to :list-id:list-unsubscribe:list-archive:list-post:list-help :list-subscribe:mime-version:content-type:content-transfer-encoding :sender:errors-to:x-original-sender :x-original-authentication-results:mailing-list; bh=bi6ADZHIfuLxSQO12g5af/Q9a0Z2C9f3U+w2wbKTZgo=; b=BoBfJ+OpuyvltewVBWU5R5O4mXTV6rfFRp8kHF65xWPNa+4XEWbGX2bCNw/L0CnWvA a0C7PbIx6X7hetMTTU3Ngtyc4if4CdcL3dg6cEolHRYeO96uae7+TRceWTWYFEZtdOmL sWQk7svAQu4AQqAjCiACcWAnxQrBZYj7U7Q7TZ2HILHTplsUXSUFSLNKEwP2atBkAsou ZIq/yoR24jTIi3/WoNz5c2Mlckxm4yKypxG1eEt3ceSkFtYmwi/Vs18FCnU374ih33ZE sRj+84dygVRP8xVTLoRpwO3CaczwTapuHxsoZNSLRNFrfHuOoPZnHNKGYEHl0QcxZWSl KmIg== X-Gm-Message-State: ALoCoQky4U/cE7Gcvz7A6Q1go2wtkUIkkkEidduupgHvnCSQ0OpWzhx0JzGTmqsUILDq+r4VhSgN X-Received: by 10.112.170.67 with SMTP id ak3mr3147742lbc.6.1439983366249; Wed, 19 Aug 2015 04:22:46 -0700 (PDT) X-BeenThere: patchwork-forward@linaro.org Received: by 10.152.28.226 with SMTP id e2ls14329lah.14.gmail; Wed, 19 Aug 2015 04:22:46 -0700 (PDT) X-Received: by 10.152.43.228 with SMTP id z4mr9465895lal.99.1439983365967; Wed, 19 Aug 2015 04:22:45 -0700 (PDT) Received: from mail-lb0-f179.google.com (mail-lb0-f179.google.com. [209.85.217.179]) by mx.google.com with ESMTPS id e1si268646lbs.96.2015.08.19.04.22.45 for (version=TLSv1.2 cipher=ECDHE-RSA-AES128-GCM-SHA256 bits=128/128); Wed, 19 Aug 2015 04:22:45 -0700 (PDT) Received-SPF: pass (google.com: domain of patch+caf_=patchwork-forward=linaro.org@linaro.org designates 209.85.217.179 as permitted sender) client-ip=209.85.217.179; Received: by lbbsx3 with SMTP id sx3so988433lbb.0 for ; Wed, 19 Aug 2015 04:22:45 -0700 (PDT) X-Received: by 10.112.209.106 with SMTP id ml10mr10690492lbc.112.1439983365823; Wed, 19 Aug 2015 04:22:45 -0700 (PDT) X-Forwarded-To: patchwork-forward@linaro.org X-Forwarded-For: patch@linaro.org patchwork-forward@linaro.org Delivered-To: patch@linaro.org Received: by 10.112.162.200 with SMTP id yc8csp300768lbb; Wed, 19 Aug 2015 04:22:44 -0700 (PDT) X-Received: by 10.70.8.97 with SMTP id q1mr23849473pda.31.1439983364499; Wed, 19 Aug 2015 04:22:44 -0700 (PDT) Received: from mail.openembedded.org (mail.openembedded.org. [140.211.169.62]) by mx.google.com with ESMTP id n5si655809pda.156.2015.08.19.04.22.43; Wed, 19 Aug 2015 04:22:44 -0700 (PDT) Received-SPF: pass (google.com: domain of openembedded-devel-bounces@lists.openembedded.org designates 140.211.169.62 as permitted sender) client-ip=140.211.169.62; Received: from mail.openembedded.org (localhost [127.0.0.1]) by mail.openembedded.org (Postfix) with ESMTP id 42601767D6; Wed, 19 Aug 2015 11:22:42 +0000 (UTC) X-Original-To: openembedded-devel@lists.openembedded.org Delivered-To: openembedded-devel@lists.openembedded.org Received: from mail-wi0-f182.google.com (mail-wi0-f182.google.com [209.85.212.182]) by mail.openembedded.org (Postfix) with ESMTP id 644BD7585F for ; Wed, 19 Aug 2015 11:21:48 +0000 (UTC) Received: by wicja10 with SMTP id ja10so117355713wic.1 for ; Wed, 19 Aug 2015 04:21:48 -0700 (PDT) X-Received: by 10.195.11.202 with SMTP id ek10mr22827664wjd.12.1439983308057; Wed, 19 Aug 2015 04:21:48 -0700 (PDT) Received: from localhost ([2001:610:612:0:2ad2:44ff:fe4b:bc17]) by smtp.gmail.com with ESMTPSA id lg8sm1139895wic.12.2015.08.19.04.21.47 (version=TLS1_2 cipher=ECDHE-RSA-AES128-GCM-SHA256 bits=128/128); Wed, 19 Aug 2015 04:21:47 -0700 (PDT) From: Koen Kooi To: openembedded-devel@lists.openembedded.org Date: Wed, 19 Aug 2015 13:02:10 +0200 Message-Id: <1439982130-4423-2-git-send-email-koen.kooi@linaro.org> X-Mailer: git-send-email 2.1.0 In-Reply-To: <1439982130-4423-1-git-send-email-koen.kooi@linaro.org> References: <1439982130-4423-1-git-send-email-koen.kooi@linaro.org> Cc: Koen Kooi Subject: [oe] [meta-oe][PATCH 2/2] mariadb: update to 5.5.45 X-BeenThere: openembedded-devel@lists.openembedded.org X-Mailman-Version: 2.1.12 Precedence: list Reply-To: openembedded-devel@lists.openembedded.org List-Id: List-Unsubscribe: , List-Archive: List-Post: , List-Help: , List-Subscribe: , MIME-Version: 1.0 Sender: openembedded-devel-bounces@lists.openembedded.org Errors-To: openembedded-devel-bounces@lists.openembedded.org X-Removed-Original-Auth: Dkim didn't pass. X-Original-Sender: koen.kooi@linaro.org X-Original-Authentication-Results: mx.google.com; spf=pass (google.com: domain of patch+caf_=patchwork-forward=linaro.org@linaro.org designates 209.85.217.179 as permitted sender) smtp.mailfrom=patch+caf_=patchwork-forward=linaro.org@linaro.org Mailing-list: list patchwork-forward@linaro.org; contact patchwork-forward+owners@linaro.org X-Google-Group-Id: 836684582541 This is the latest release in the 5.5.x stable series. The CVE patch has been applied upstream. Signed-off-by: Koen Kooi --- ...b-native_5.5.43.bb => mariadb-native_5.5.45.bb} | 0 meta-oe/recipes-support/mysql/mariadb.inc | 5 +-- .../mysql/mariadb/fix-CVE-2015-2305.patch | 43 ---------------------- .../mysql/{mariadb_5.5.43.bb => mariadb_5.5.45.bb} | 0 4 files changed, 2 insertions(+), 46 deletions(-) rename meta-oe/recipes-support/mysql/{mariadb-native_5.5.43.bb => mariadb-native_5.5.45.bb} (100%) delete mode 100644 meta-oe/recipes-support/mysql/mariadb/fix-CVE-2015-2305.patch rename meta-oe/recipes-support/mysql/{mariadb_5.5.43.bb => mariadb_5.5.45.bb} (100%) diff --git a/meta-oe/recipes-support/mysql/mariadb_5.5.43.bb b/meta-oe/recipes-support/mysql/mariadb_5.5.45.bb similarity index 100% rename from meta-oe/recipes-support/mysql/mariadb_5.5.43.bb rename to meta-oe/recipes-support/mysql/mariadb_5.5.45.bb diff --git a/meta-oe/recipes-support/mysql/mariadb-native_5.5.43.bb b/meta-oe/recipes-support/mysql/mariadb-native_5.5.45.bb similarity index 100% rename from meta-oe/recipes-support/mysql/mariadb-native_5.5.43.bb rename to meta-oe/recipes-support/mysql/mariadb-native_5.5.45.bb diff --git a/meta-oe/recipes-support/mysql/mariadb.inc b/meta-oe/recipes-support/mysql/mariadb.inc index a11924a..e265a7d 100644 --- a/meta-oe/recipes-support/mysql/mariadb.inc +++ b/meta-oe/recipes-support/mysql/mariadb.inc @@ -11,11 +11,10 @@ SRC_URI = "http://mirrors.supportex.net/mariadb/mariadb-${PV}/source/mariadb-${P file://mysqld.service \ file://configure.cmake-fix-valgrind.patch \ file://fix-a-building-failure.patch \ - file://fix-CVE-2015-2305.patch \ " -SRC_URI[md5sum] = "c8760d6b5890fc1de76c07af48092c88" -SRC_URI[sha256sum] = "a0709997140549154edb87c9dfab564cd4755b238251acbf42369118f9bb4d01" +SRC_URI[md5sum] = "6ec397f717f6e2e4e9154e76de9ec9fc" +SRC_URI[sha256sum] = "4dc3aff6941ef1068412002915d795bcf67db0eaa38a5c6f3af57474c4226fb0" S = "${WORKDIR}/mariadb-${PV}" diff --git a/meta-oe/recipes-support/mysql/mariadb/fix-CVE-2015-2305.patch b/meta-oe/recipes-support/mysql/mariadb/fix-CVE-2015-2305.patch deleted file mode 100644 index 2d1b467..0000000 --- a/meta-oe/recipes-support/mysql/mariadb/fix-CVE-2015-2305.patch +++ /dev/null @@ -1,43 +0,0 @@ -From f5c1d00a9ceb61acfe038dcf2ec0236c2939328c Mon Sep 17 00:00:00 2001 -From: Roy Li -Date: Mon, 1 Jun 2015 15:31:48 +0800 -Subject: [PATCH] From 70bc2965604b6b8aaf260049e64c708dddf85334 Mon Sep 17 - 00:00:00 2001 From: Gary Houston Date: Wed, 25 Feb - 2015 13:29:03 +1100 Subject: [PATCH] Bug fix for integer overflow in regcomp - for excessively long pattern strings. CERT Vulnerability Note VU#695940. - Found by Guido Vranken. - -Upsteam-Status: Backport - -https://bugzilla.suse.com/attachment.cgi?id=627001 - -Signed-off-by: Roy Li ---- - regex/regcomp.c | 11 ++++++++++- - 1 file changed, 10 insertions(+), 1 deletion(-) - -diff --git a/regex/regcomp.c b/regex/regcomp.c -index abc1817..31e57c1 100644 ---- a/regex/regcomp.c -+++ b/regex/regcomp.c -@@ -138,7 +138,16 @@ struct cclass cclasses[CCLASS_LAST+1]= { - (NC-1)*sizeof(cat_t)); - if (g == NULL) - return(REG_ESPACE); -- p->ssize = (long) (len/(size_t)2*(size_t)3 + (size_t)1); /* ugh */ -+ { -+ /* Patched for CERT Vulnerability Note VU#695940, Feb 2015. */ -+ size_t new_ssize = len/(size_t)2*(size_t)3 + (size_t)1; /* ugh */ -+ if (new_ssize < len || new_ssize > LONG_MAX / sizeof(sop)) { -+ free((char *) g); -+ return REG_INVARG; -+ } -+ p->ssize = new_ssize; -+ } -+ - p->strip = (sop *)malloc(p->ssize * sizeof(sop)); - p->slen = 0; - if (p->strip == NULL) { --- -1.9.1 -