All of lore.kernel.org
 help / color / mirror / Atom feed
From: Thomas Petazzoni via buildroot <buildroot@buildroot.org>
To: Waldemar Brodkorb <wbx@openadk.org>
Cc: buildroot@buildroot.org
Subject: Re: [Buildroot] [PATCH] package/asterisk: update to 20.8.1
Date: Thu, 11 Jul 2024 21:00:28 +0200	[thread overview]
Message-ID: <20240711210028.275966b6@windsurf> (raw)
In-Reply-To: <Zo+rUe629arAZsdA@waldemar-brodkorb.de>

On Thu, 11 Jul 2024 11:52:17 +0200
Waldemar Brodkorb <wbx@openadk.org> wrote:

> See here for a ChangeLog:
> https://downloads.asterisk.org/pub/telephony/asterisk/ChangeLog-20-current.md
> 
> Patch 0005 is applied upstream.
> 
> Signed-off-by: Waldemar Brodkorb <wbx@openadk.org>
> ---
>  ...es-stasis-control.c-include-signal.h.patch | 43 -------------------
>  package/asterisk/asterisk.hash                |  2 +-
>  package/asterisk/asterisk.mk                  |  2 +-
>  3 files changed, 2 insertions(+), 45 deletions(-)
>  delete mode 100644 package/asterisk/0005-res-stasis-control.c-include-signal.h.patch

Looking at the Changelog... this version update contains a security
vulnerability fix. However, deeper investigation revealed that the
vulnerability was introduced between 20.7.0 and 20.8.0... and we were
still using the 20.7.0, which did not include the vulnerability. So I
added the following text in the commit log:

    20.8.1 contains a fix for CVE-2024-35190. However, the vulnerability
    was introduced in commit 68a49128253f677f9e1b235c70d2316342372f7d
    between 20.7.0 and 20.8.0, and Buildroot was using 20.7.0, so we were
    not affected by this vulnerability.
    
Applied with this addition. Thanks!

Thomas
-- 
Thomas Petazzoni, CTO, Bootlin
Embedded Linux and Kernel engineering
https://bootlin.com
_______________________________________________
buildroot mailing list
buildroot@buildroot.org
https://lists.buildroot.org/mailman/listinfo/buildroot

      reply	other threads:[~2024-07-11 19:00 UTC|newest]

Thread overview: 2+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2024-07-11  9:52 [Buildroot] [PATCH] package/asterisk: update to 20.8.1 Waldemar Brodkorb
2024-07-11 19:00 ` Thomas Petazzoni via buildroot [this message]

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20240711210028.275966b6@windsurf \
    --to=buildroot@buildroot.org \
    --cc=thomas.petazzoni@bootlin.com \
    --cc=wbx@openadk.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.