From patchwork Mon Nov 4 14:26:52 2019 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Ross Burton X-Patchwork-Id: 178429 Delivered-To: patch@linaro.org Received: by 2002:a92:38d5:0:0:0:0:0 with SMTP id g82csp1554473ilf; Mon, 4 Nov 2019 06:27:03 -0800 (PST) X-Google-Smtp-Source: APXvYqxzi8uIu0fMY9j/p9VA22sAOacajwsotJslZkwh0LTPJ6g1I+PgnPv0yuSeq0155oFLOBv/ X-Received: by 2002:a17:90a:2e81:: with SMTP id r1mr35481938pjd.64.1572877623000; Mon, 04 Nov 2019 06:27:03 -0800 (PST) ARC-Seal: i=1; a=rsa-sha256; t=1572877622; cv=none; d=google.com; s=arc-20160816; b=iAY0Exj62s1p7xr2XpmHuk3V147MXrfRbZEBW2Sb910GGzy7h1dqtOjVgDqL36UOj9 u2pKWnWWdtoAsD4qPughTvUEVs5bFLO8DkAHWJe5f2fXFoU0ZFydi45VQDhxumOLWI+N 8MqMfPRx1EQ1WJBedSjHPNgG9p8KZVOogcVpnz8i2cRtRkMP0fJTNGnUOQKLHU2jNSMe B++j7pKFXEA+/X4BMd1wg7ma8YI/WW+EPrqhV9l0SLAfa9xI4i4HMqZ317gwnn2xZevk sUkfKRdX56ygOz1LXVYjQJZUA2I1BjLKMdC9RgoQqcmjZjRCQixSA4YW0OjKRNNUpdGf /hsQ== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=errors-to:sender:content-transfer-encoding:list-subscribe:list-help :list-post:list-archive:list-unsubscribe:list-id:precedence:subject :mime-version:message-id:date:to:from:dkim-signature:delivered-to; bh=ZGF4h5jjmai1Bps2IzeE0VgL4iBAkrqihG0lWUsrhvY=; b=nnC/KIlXoERUx4AvM0fKBb5fmsA2CNV+J+Q42GtQuz7Jc9ImeBX94aRZ2qB1+Pn8ne nDM7YalpGOOiIHUfllif/nUCoigHp/MSR7EyghyGWto+iMLwVzSedlqflRieirEWyJFr A0A45OeEym/g7+PsWSn7yfiG+Ipk2C4SWEQ+MBdA/c57LO/vQEsQkoy9KN8KHTPFj+Nm 2XQt7zL6nPr3ddPVHE09ng22sqSivua+QujUwzhPnRC8PNVJi2DOlecS34FnL35v74YT FIlV+DemMtY8RBrQz3vxSCEP/AYj1Eu5oz44PAr2uL43GVIzNFtZBDyB1RRxB1Q+md6U BH8g== ARC-Authentication-Results: i=1; mx.google.com; dkim=neutral (body hash did not verify) header.i=@intel-com.20150623.gappssmtp.com header.s=20150623 header.b=o5GdORdT; spf=pass (google.com: best guess record for domain of openembedded-core-bounces@lists.openembedded.org designates 140.211.169.62 as permitted sender) smtp.mailfrom=openembedded-core-bounces@lists.openembedded.org; dmarc=fail (p=NONE sp=NONE dis=NONE) header.from=intel.com Return-Path: Received: from mail.openembedded.org (mail.openembedded.org. [140.211.169.62]) by mx.google.com with ESMTP id f123si22738861pgc.34.2019.11.04.06.27.02; Mon, 04 Nov 2019 06:27:02 -0800 (PST) Received-SPF: pass (google.com: best guess record for domain of openembedded-core-bounces@lists.openembedded.org designates 140.211.169.62 as permitted sender) client-ip=140.211.169.62; Authentication-Results: mx.google.com; dkim=neutral (body hash did not verify) header.i=@intel-com.20150623.gappssmtp.com header.s=20150623 header.b=o5GdORdT; spf=pass (google.com: best guess record for domain of openembedded-core-bounces@lists.openembedded.org designates 140.211.169.62 as permitted sender) smtp.mailfrom=openembedded-core-bounces@lists.openembedded.org; dmarc=fail (p=NONE sp=NONE dis=NONE) header.from=intel.com Received: from ec2-34-214-78-129.us-west-2.compute.amazonaws.com (localhost [127.0.0.1]) by mail.openembedded.org (Postfix) with ESMTP id 4AF1B7F8CB; Mon, 4 Nov 2019 14:27:00 +0000 (UTC) X-Original-To: openembedded-core@lists.openembedded.org Delivered-To: openembedded-core@lists.openembedded.org Received: from mail-wr1-f67.google.com (mail-wr1-f67.google.com [209.85.221.67]) by mail.openembedded.org (Postfix) with ESMTP id 71AB07F8B1 for ; Mon, 4 Nov 2019 14:26:58 +0000 (UTC) Received: by mail-wr1-f67.google.com with SMTP id e6so15474569wrw.1 for ; Mon, 04 Nov 2019 06:26:59 -0800 (PST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=intel-com.20150623.gappssmtp.com; s=20150623; h=from:to:subject:date:message-id:mime-version :content-transfer-encoding; bh=53+b28IIfSQ2jhU2GL68wQ10l87FtLXRotEOeRlNVCo=; b=o5GdORdTsDtcA6hg7Kpx5oUraIjcKROAMBBygMfudqQ+I+DiKNdSXguMEszc95tR/+ wzYhtZ3AgzMmSvhDnQafumu1dX9nMNtKNYmfoImmHq26mZ6hsclEmYafE6vSzjZL2Xhn J7M3EPh5br6e9Ufua2I0ynqSlLnM8QyMEXiJDSXLFAZKJaQ+shPYwBvVrcl/SROVwV4V I5J8o9+SvDTBwdec7gHPl/rAd+SN0XSdJbjQccPrxE03hvrVSGGGcTnQxfR+SQnu8Oih pUw+Hkft8Jlmm1H46n1fzQ3e/8Kp5iUhWAbzhz0Zwp8I4IuLCwhsIEIWkTxmi1ZVYtuq /kZg== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:from:to:subject:date:message-id:mime-version :content-transfer-encoding; bh=53+b28IIfSQ2jhU2GL68wQ10l87FtLXRotEOeRlNVCo=; b=Pai3Q+jHUzCaOoe3FItIyMzf1Bvk6rlIZhTja2HtHBuBA6JEnYbC2Prnc7yLv09Lq8 xFzMFrZKmwINJYkS5g3gx1cXCrhv98Rfv1yLHm8pRAXZ7FmSatsRDzLZzY5S0LfbSQ/1 5v7HYUfN/lypqldI+IonnZdVOLa7VRv70AAs38eu9zy2I0cuIKcjrcXNoeaIRtEfvVBf 1r1iNjumhGxubgwnwTqHLUtynuW3SrJO05ZAddAYzVLfXTbIBeriLEttjN2sZ2dXy8Sy JVg+BsSmqJxmjISs5Qa+JhxGfT7mYxqsWFLrWoUvwA506dDpK+hThfrasozoiLYtEFhD xwDw== X-Gm-Message-State: APjAAAWT4uBuFWK4mWEeJCS8opjCq1g6xfUcFfCoesPdCwi/E9uRVU7M RgvXQBH8KKz4DqFGq8BIBDyrvXTXJ2A= X-Received: by 2002:adf:f1c7:: with SMTP id z7mr16067940wro.355.1572877618945; Mon, 04 Nov 2019 06:26:58 -0800 (PST) Received: from flashheart.burtonini.com (35.106.2.81.in-addr.arpa. [81.2.106.35]) by smtp.gmail.com with ESMTPSA id d4sm26873251wrc.54.2019.11.04.06.26.57 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 04 Nov 2019 06:26:57 -0800 (PST) From: Ross Burton To: openembedded-core@lists.openembedded.org Date: Mon, 4 Nov 2019 14:26:52 +0000 Message-Id: <20191104142654.20440-1-ross.burton@intel.com> X-Mailer: git-send-email 2.20.1 MIME-Version: 1.0 Subject: [OE-core] [PATCH v2 1/3] libpng: whitelist CVE-2019-17371 X-BeenThere: openembedded-core@lists.openembedded.org X-Mailman-Version: 2.1.12 Precedence: list List-Id: Patches and discussions about the oe-core layer List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Sender: openembedded-core-bounces@lists.openembedded.org Errors-To: openembedded-core-bounces@lists.openembedded.org This is actually a memory leak in gif2png 2.x, so whitelist it in the libpng recipe. Signed-off-by: Ross Burton --- meta/recipes-multimedia/libpng/libpng_1.6.37.bb | 3 +++ 1 file changed, 3 insertions(+) -- 2.20.1 -- _______________________________________________ Openembedded-core mailing list Openembedded-core@lists.openembedded.org http://lists.openembedded.org/mailman/listinfo/openembedded-core diff --git a/meta/recipes-multimedia/libpng/libpng_1.6.37.bb b/meta/recipes-multimedia/libpng/libpng_1.6.37.bb index 66af2f3d60e..2ed87a84374 100644 --- a/meta/recipes-multimedia/libpng/libpng_1.6.37.bb +++ b/meta/recipes-multimedia/libpng/libpng_1.6.37.bb @@ -29,3 +29,6 @@ PACKAGES =+ "${PN}-tools" FILES_${PN}-tools = "${bindir}/png-fix-itxt ${bindir}/pngfix ${bindir}/pngcp" BBCLASSEXTEND = "native nativesdk" + +# CVE-2019-17371 is actually a memory leak in gif2png 2.x +CVE_CHECK_WHITELIST += "CVE-2019-17371" From patchwork Mon Nov 4 14:26:53 2019 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Ross Burton X-Patchwork-Id: 178430 Delivered-To: patch@linaro.org Received: by 2002:a92:38d5:0:0:0:0:0 with SMTP id g82csp1554582ilf; Mon, 4 Nov 2019 06:27:08 -0800 (PST) X-Google-Smtp-Source: APXvYqx2ZMRA9+DisOyoyQe4OnmXXqM6Lckqhlh8/GztAMy/a/LpV8Ffsf0NhOhhY49uxt6tPpS1 X-Received: by 2002:a62:b504:: with SMTP id y4mr18616702pfe.124.1572877627986; Mon, 04 Nov 2019 06:27:07 -0800 (PST) ARC-Seal: i=1; a=rsa-sha256; t=1572877627; cv=none; d=google.com; s=arc-20160816; b=Pjl5KHbxeupvaPvgTgnTz/xjnkbRX50oHIGqnDKbpaauKPlCVarZxlBWTZ/M7I95/i pkm9yqNi70hVlbAqt5KMYJPGK/Je3kjOzyfooDPuc5vU9c5xgHpyGZfm6tlNfUt+tYwy usGYirNr+FZ3aylRkVwuRWNxPUx970P2alyWa/JTPaT0daB1P5vzgleOY7qO3MXusFC8 qq43QWAM8Liywus+Cd5jhDGoNjEdeSM5aAc1Bb6mXmGje4CvXips8/lEkhja/g1sfbU2 LqVHxYPYXYRCaev4livih3WjHesNKCUZmVO8PaXcV8uwgngGcPtfY/T73MLZI94h1f0Z Z+xQ== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=errors-to:sender:content-transfer-encoding:list-subscribe:list-help :list-post:list-archive:list-unsubscribe:list-id:precedence:subject :mime-version:references:in-reply-to:message-id:date:to:from :dkim-signature:delivered-to; bh=fOjctsKHXn/Dz/058EOgwEIL0SQlMfVUMF1cG7iy7Yo=; b=Hm3sbydjmD31gYjbZrVE/+5d9AmzP35oVJc+8H1qoYDrnBUe4Z3Fjk0dCRJ5oGWW9W plcdoUio1QeBN41AOJezyWR51yf2DhAOkXvbZlRAxnrRIebLtLZCUFicaxktFk+SPuOf eO8bwwoEjXrfIzpoQkQHmuNKqfCApEeeFqUgjFoCqB2N8Ol+ut61k4a9U4HOpzd9kslx Wst4eB4M2O2PUNuTsLEA1JwEMZdTZekeBr9pTfmzaakxITLUFXET5VcldAFaW8NBuS9D l7JUQbrQgr4aAT4UrJBoYHOVwuPDqDRnbIOkZ5dSrgHplOiH2rbVRIKOjPqu0iSMyZtT y8bw== ARC-Authentication-Results: i=1; mx.google.com; dkim=neutral (body hash did not verify) header.i=@intel-com.20150623.gappssmtp.com header.s=20150623 header.b=HsfexEHs; spf=pass (google.com: best guess record for domain of openembedded-core-bounces@lists.openembedded.org designates 140.211.169.62 as permitted sender) smtp.mailfrom=openembedded-core-bounces@lists.openembedded.org; dmarc=fail (p=NONE sp=NONE dis=NONE) header.from=intel.com Return-Path: Received: from mail.openembedded.org (mail.openembedded.org. [140.211.169.62]) by mx.google.com with ESMTP id 2si22392446pld.6.2019.11.04.06.27.07; Mon, 04 Nov 2019 06:27:07 -0800 (PST) Received-SPF: pass (google.com: best guess record for domain of openembedded-core-bounces@lists.openembedded.org designates 140.211.169.62 as permitted sender) client-ip=140.211.169.62; Authentication-Results: mx.google.com; dkim=neutral (body hash did not verify) header.i=@intel-com.20150623.gappssmtp.com header.s=20150623 header.b=HsfexEHs; spf=pass (google.com: best guess record for domain of openembedded-core-bounces@lists.openembedded.org designates 140.211.169.62 as permitted sender) smtp.mailfrom=openembedded-core-bounces@lists.openembedded.org; dmarc=fail (p=NONE sp=NONE dis=NONE) header.from=intel.com Received: from ec2-34-214-78-129.us-west-2.compute.amazonaws.com (localhost [127.0.0.1]) by mail.openembedded.org (Postfix) with ESMTP id EB88E7F8D0; Mon, 4 Nov 2019 14:27:02 +0000 (UTC) X-Original-To: openembedded-core@lists.openembedded.org Delivered-To: openembedded-core@lists.openembedded.org Received: from mail-wr1-f54.google.com (mail-wr1-f54.google.com [209.85.221.54]) by mail.openembedded.org (Postfix) with ESMTP id 2D7D07F8B1 for ; Mon, 4 Nov 2019 14:26:59 +0000 (UTC) Received: by mail-wr1-f54.google.com with SMTP id w18so17339171wrt.3 for ; Mon, 04 Nov 2019 06:27:00 -0800 (PST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=intel-com.20150623.gappssmtp.com; s=20150623; h=from:to:subject:date:message-id:in-reply-to:references:mime-version :content-transfer-encoding; bh=qzhcPzhbRcK3U+HEebUClC4GqRLxqaMypHSwoqOltTQ=; b=HsfexEHsIFyBjQq+bPgdVO8KZBzQJiDNRIgVcbZe5W7+AbHRnIAsZSN7F/ZTATByNG Fyd0qF/O7rS9IsnwzDNW1sgJg37o4APcPLZMVVmryKTCSelPXvTM742ex5JN00fz+zWE NnnP7NaAnCIRV59qf+BnSUGR2b/Kr7v0rFhjuSgqHg5HZo0ME3d4ZNk7VcnjAeN4Lg9a sj7R8VgjzAxo6UIebvfXrKR4X/WN2wetYk4pwlHqFZFQBWA8hkSa3WmNNVtNtswweMqv OOaYrsN7LcB8BNv7R4HNKh727UYPz5VzdJVdmsiBoNgiZdoNeIOz5vhBbLlU7/szc5C2 Eqdw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:from:to:subject:date:message-id:in-reply-to :references:mime-version:content-transfer-encoding; bh=qzhcPzhbRcK3U+HEebUClC4GqRLxqaMypHSwoqOltTQ=; b=EF+zgyDeJIVNerThEbLpw8WPJoeI0yNpUKXMA9ZHklZkqiRjliDpeBeT0yN8eVCG+v TD9igxY/wslmDV5S8yUK3zNrGGYNkx7emttx/8SwzSPbgo489PegQkAEmelGqlfSgbRH JVAndXP5d729jL6TDW04mtvjMTK05vWs/qPsnvHjWaKcllY2la35Ec/wfrB+35cATw8Y Vy5Q2IX7cvYF+rrjzxYvdmLBkLEbbQrCfBnkcpREqgh3FCfol7M66+vQ5xP+MHD8Ftdu HdoDy/qrC8Su5NPSyOaAbfnntnHsBBRf4JnJYVPvfGff8O4DlQ3OKUnkXwNb7AAshipi tgtQ== X-Gm-Message-State: APjAAAXcw1CrEPPMu5U34UBEE+tVLkYs67wK2y7Jxl2C2JyYK4XQhgCg H4KI33GSrciX+KEe6htcEAigJ/eEaGw= X-Received: by 2002:a5d:6cb0:: with SMTP id a16mr6039405wra.194.1572877619707; Mon, 04 Nov 2019 06:26:59 -0800 (PST) Received: from flashheart.burtonini.com (35.106.2.81.in-addr.arpa. [81.2.106.35]) by smtp.gmail.com with ESMTPSA id d4sm26873251wrc.54.2019.11.04.06.26.58 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 04 Nov 2019 06:26:59 -0800 (PST) From: Ross Burton To: openembedded-core@lists.openembedded.org Date: Mon, 4 Nov 2019 14:26:53 +0000 Message-Id: <20191104142654.20440-2-ross.burton@intel.com> X-Mailer: git-send-email 2.20.1 In-Reply-To: <20191104142654.20440-1-ross.burton@intel.com> References: <20191104142654.20440-1-ross.burton@intel.com> MIME-Version: 1.0 Subject: [OE-core] [PATCH v2 2/3] procps: whitelist CVE-2018-1121 X-BeenThere: openembedded-core@lists.openembedded.org X-Mailman-Version: 2.1.12 Precedence: list List-Id: Patches and discussions about the oe-core layer List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Sender: openembedded-core-bounces@lists.openembedded.org Errors-To: openembedded-core-bounces@lists.openembedded.org This CVE is about race conditions in 'ps' which make it unsuitable for security audits. As these race conditions are unavoidable ps shouldn't be used for security auditing, so this isn't a valid CVE. Signed-off-by: Ross Burton --- meta/recipes-extended/procps/procps_3.3.15.bb | 9 ++++++--- 1 file changed, 6 insertions(+), 3 deletions(-) -- 2.20.1 -- _______________________________________________ Openembedded-core mailing list Openembedded-core@lists.openembedded.org http://lists.openembedded.org/mailman/listinfo/openembedded-core diff --git a/meta/recipes-extended/procps/procps_3.3.15.bb b/meta/recipes-extended/procps/procps_3.3.15.bb index 9756db0e7b7..f240e54fd84 100644 --- a/meta/recipes-extended/procps/procps_3.3.15.bb +++ b/meta/recipes-extended/procps/procps_3.3.15.bb @@ -4,9 +4,9 @@ the /proc filesystem. The package includes the programs ps, top, vmstat, w, kill HOMEPAGE = "https://gitlab.com/procps-ng/procps" SECTION = "base" LICENSE = "GPLv2+ & LGPLv2+" -LIC_FILES_CHKSUM="file://COPYING;md5=b234ee4d69f5fce4486a80fdaf4a4263 \ - file://COPYING.LIB;md5=4cf66a4984120007c9881cc871cf49db \ - " +LIC_FILES_CHKSUM = "file://COPYING;md5=b234ee4d69f5fce4486a80fdaf4a4263 \ + file://COPYING.LIB;md5=4cf66a4984120007c9881cc871cf49db \ + " DEPENDS = "ncurses" @@ -64,3 +64,6 @@ python __anonymous() { d.setVarFlag('ALTERNATIVE_LINK_NAME', prog, '%s/%s' % (d.getVar('base_sbindir'), prog)) } +# 'ps' isn't suitable for use as a security tool so whitelist this CVE. +# https://bugzilla.redhat.com/show_bug.cgi?id=1575473#c3 +CVE_CHECK_WHITELIST += "CVE-2018-1121" From patchwork Mon Nov 4 14:26:54 2019 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Ross Burton X-Patchwork-Id: 178431 Delivered-To: patch@linaro.org Received: by 2002:a92:38d5:0:0:0:0:0 with SMTP id g82csp1554684ilf; Mon, 4 Nov 2019 06:27:14 -0800 (PST) X-Google-Smtp-Source: APXvYqzPs8zgx2cEhCJd/tmAgfMNJUMnhOBf9Uk0tmw0S38sL5zwdeaHi6OIueoRI72phzT4vz9e X-Received: by 2002:a63:ff46:: with SMTP id s6mr30488941pgk.337.1572877634776; Mon, 04 Nov 2019 06:27:14 -0800 (PST) ARC-Seal: i=1; a=rsa-sha256; t=1572877634; cv=none; d=google.com; s=arc-20160816; b=S2AzzemKdYoGZlqvfnIqry7DAxKz846Hwgt6a1w2B7/wSXo5yaGVp2ZIrBFwAnqGgW VQbu2YyNQvAgNqA13OPerWn+XDm6YjaKwDQwOHPPxAW3y8AyrwpGax7F96ybj7T8SRtE FhlABJIJ8tGIvQBsTD3XPswTYNr+/F0wgLQAl+m65vDXaoKSYenvP7ktMr8F9BguLuEC LE2/2+0/7ON8eYGx3tKQB4JyTm/wCSL74NGA+HFzT8IymnE4CG7J4iQB6yGMuJDBqxo2 BJBfN3tpvf2hMSgFmfPVjsmSbVoDDSSQRqUXQFbeiGnYqEDYl9FC8k43YeFAZ66W19Xo y+Xg== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=errors-to:sender:content-transfer-encoding:list-subscribe:list-help :list-post:list-archive:list-unsubscribe:list-id:precedence:subject :mime-version:references:in-reply-to:message-id:date:to:from :dkim-signature:delivered-to; bh=lRBcxdoKS4r8OXKwnUa3t76flaqk0Tq3maBZf1FHyLU=; b=RsTzKeUq74u8fjhTqF0hHucbv0eTdUSPP3V68IAk7IPr/UI0IlKOToaioSDxU8Rjwy p2Kz05bhtQdRGpA4Q9kgaViP3Bs6WmjQfDQ62qcmGMqmDmrqnYYvFuQ3s6wuRQ+bK/3b l+aje3PzkIHuBSAPtWg2rEMlepRQcmNNUo+bT3/I46T+EC7x3IB3+3KDZomcEf/Eyona yfjZiIe3Zprx34TrlSRdMMYGVgzDr1iz0IAB2Q9Po/43Birg0q1UMgSU+rKohZWboTfs /FVq7YaeaYfuvl93Qf2yPM3IZ6PT5enTKYtF6SjNF2GCKJNllKPKuQ9EWeoVdBWOUvxa GIYQ== ARC-Authentication-Results: i=1; mx.google.com; dkim=neutral (body hash did not verify) header.i=@intel-com.20150623.gappssmtp.com header.s=20150623 header.b=Z+6lZQP3; spf=pass (google.com: best guess record for domain of openembedded-core-bounces@lists.openembedded.org designates 140.211.169.62 as permitted sender) smtp.mailfrom=openembedded-core-bounces@lists.openembedded.org; dmarc=fail (p=NONE sp=NONE dis=NONE) header.from=intel.com Return-Path: Received: from mail.openembedded.org (mail.openembedded.org. [140.211.169.62]) by mx.google.com with ESMTP id s24si13556459plr.309.2019.11.04.06.27.14; Mon, 04 Nov 2019 06:27:14 -0800 (PST) Received-SPF: pass (google.com: best guess record for domain of openembedded-core-bounces@lists.openembedded.org designates 140.211.169.62 as permitted sender) client-ip=140.211.169.62; Authentication-Results: mx.google.com; dkim=neutral (body hash did not verify) header.i=@intel-com.20150623.gappssmtp.com header.s=20150623 header.b=Z+6lZQP3; spf=pass (google.com: best guess record for domain of openembedded-core-bounces@lists.openembedded.org designates 140.211.169.62 as permitted sender) smtp.mailfrom=openembedded-core-bounces@lists.openembedded.org; dmarc=fail (p=NONE sp=NONE dis=NONE) header.from=intel.com Received: from ec2-34-214-78-129.us-west-2.compute.amazonaws.com (localhost [127.0.0.1]) by mail.openembedded.org (Postfix) with ESMTP id 1CFF57F8E5; Mon, 4 Nov 2019 14:27:04 +0000 (UTC) X-Original-To: openembedded-core@lists.openembedded.org Delivered-To: openembedded-core@lists.openembedded.org Received: from mail-wr1-f48.google.com (mail-wr1-f48.google.com [209.85.221.48]) by mail.openembedded.org (Postfix) with ESMTP id F10527F8BD for ; Mon, 4 Nov 2019 14:26:59 +0000 (UTC) Received: by mail-wr1-f48.google.com with SMTP id b3so11545539wrs.13 for ; Mon, 04 Nov 2019 06:27:01 -0800 (PST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=intel-com.20150623.gappssmtp.com; s=20150623; h=from:to:subject:date:message-id:in-reply-to:references:mime-version :content-transfer-encoding; bh=c4QlwE9lZiA21lPqHcAyFAqKUF0TlKtsbyRAav+RBnQ=; b=Z+6lZQP3lFEJNfh/ETD6+UUrkDeUHgQ2b02GFTHSKqj8fnf0nLtH0QQRDvSDqvV/HE icj8BdLyWzINacwriw0vjoHsYw0IRslJS4w3jkTSOc6B79w2QfenpMDfaZ3WlcqWRyGW 0rsozEWPuF163o+tRWS19OU4olh9rm33/IxPX2Bcyqdv9GaW17CwWYk7FDPsaOer84tI PDrT0rEIL5UUBLg6I4Sq1Oh8/aOn6Txy+gAXTLbenQEhftvq4LvB3A3mHo6YjotehIH8 ogdMnrk8a/cfy73wrQMFFDNjkAo/mmGWQvnc3PszoeBg4zFFv4cKRafbNWn5r629ByX2 /tIQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:from:to:subject:date:message-id:in-reply-to :references:mime-version:content-transfer-encoding; bh=c4QlwE9lZiA21lPqHcAyFAqKUF0TlKtsbyRAav+RBnQ=; b=hz2dY5KOLx04w1nSrKB5bWfgxi/oUn2YPg6b0A2I5cdrftorKnDS+7svyy3c8M1gKL EFcKb+vmvakUmUQif2bDgwTBOFu4xVNi3J6/0xZb9lxuMT3f0y327HGEv8ROvoirF2YT l8KKnXTK239cWVirEETKgdaMLwVl+fg6wp7/1DrmGHCHl3tfwmQxY80uS6AId4+QDEfo l7jN1ZT+XTc0OW7ReaxtPcc+ricrArkBpnP079UDBvDcgT8lHKQsa2wntaO7byjd5OJW 22OXuuuxR7Dw/Oy7UMOIsu729xoa4dMaRERMotJkqW6zFwiB0fNGJu8pRSfLL83Sx/Zh eZeg== X-Gm-Message-State: APjAAAWXhUX8r/U4gU5/0Us15UhR+t6MstEiiwVGbPzWmTSZQkVoySDk xJTimliGPBcchF9I7lcIQx4mnpztVss= X-Received: by 2002:a5d:4e89:: with SMTP id e9mr10474647wru.342.1572877620515; Mon, 04 Nov 2019 06:27:00 -0800 (PST) Received: from flashheart.burtonini.com (35.106.2.81.in-addr.arpa. [81.2.106.35]) by smtp.gmail.com with ESMTPSA id d4sm26873251wrc.54.2019.11.04.06.26.59 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 04 Nov 2019 06:27:00 -0800 (PST) From: Ross Burton To: openembedded-core@lists.openembedded.org Date: Mon, 4 Nov 2019 14:26:54 +0000 Message-Id: <20191104142654.20440-3-ross.burton@intel.com> X-Mailer: git-send-email 2.20.1 In-Reply-To: <20191104142654.20440-1-ross.burton@intel.com> References: <20191104142654.20440-1-ross.burton@intel.com> MIME-Version: 1.0 Subject: [OE-core] [PATCH v2 3/3] libsndfile1: whitelist CVE-2018-13419 X-BeenThere: openembedded-core@lists.openembedded.org X-Mailman-Version: 2.1.12 Precedence: list List-Id: Patches and discussions about the oe-core layer List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Sender: openembedded-core-bounces@lists.openembedded.org Errors-To: openembedded-core-bounces@lists.openembedded.org This is a memory leak that nobody else can replicate and has been rejected by upstream. Signed-off-by: Ross Burton --- meta/recipes-multimedia/libsndfile/libsndfile1_1.0.28.bb | 4 ++++ 1 file changed, 4 insertions(+) -- 2.20.1 -- _______________________________________________ Openembedded-core mailing list Openembedded-core@lists.openembedded.org http://lists.openembedded.org/mailman/listinfo/openembedded-core diff --git a/meta/recipes-multimedia/libsndfile/libsndfile1_1.0.28.bb b/meta/recipes-multimedia/libsndfile/libsndfile1_1.0.28.bb index ffb45855a4b..7855008f3d8 100644 --- a/meta/recipes-multimedia/libsndfile/libsndfile1_1.0.28.bb +++ b/meta/recipes-multimedia/libsndfile/libsndfile1_1.0.28.bb @@ -33,3 +33,7 @@ PACKAGECONFIG[alsa] = "--enable-alsa,--disable-alsa,alsa-lib" PACKAGECONFIG[regtest] = "--enable-sqlite,--disable-sqlite,sqlite3" inherit autotools lib_package pkgconfig + +# This can't be replicated and is just a memory leak. +# https://github.com/erikd/libsndfile/issues/398 +CVE_CHECK_WHITELIST += "CVE-2018-13419"