Openembedded Core Discussions
 help / color / mirror / Atom feed
From: Paul Eggleton <bluelightning@bluelightning.org>
To: Khem Raj <raj.khem@gmail.com>
Cc: openembedded-core@lists.openembedded.org
Subject: Re: [OE-core] [PATCH 03/10] zlib: Resolve CVE-2022-37434
Date: Mon, 15 Aug 2022 14:32:29 +1200	[thread overview]
Message-ID: <2841280.e9J7NaK4W3@linc> (raw)
In-Reply-To: <20220814222037.283943-3-raj.khem@gmail.com>

On Monday, 15 August 2022 10:20:30 NZST Khem Raj wrote:
> This is only seen in development branch as per [1]
> 
> [1]
> https://github.com/madler/zlib/commit/eff308af425b67093bab25f80f1ae950166be
> ce1#commitcomment-80753451 CVE: CVE-2022-37434

It's a little confusing, but I think that CVE-2022-37434 does affect existing 
zlib releases - at least the patch does apply. My reading was that the 
upstream comment was referring to the *fix* (and thus the additional segfault 
issue that it introduced) was not yet in any zlib release. A look around 
suggests Ubuntu is treating CVE-2022-37434 as needing to be fixed at least.

Cheers
Paul






  reply	other threads:[~2022-08-15  2:32 UTC|newest]

Thread overview: 13+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2022-08-14 22:20 [PATCH 01/10] json-c: Fix function prototypes Khem Raj
2022-08-14 22:20 ` [PATCH 02/10] xmlto: Update to use upstream tip of trunk Khem Raj
2022-08-15  6:54   ` [OE-core] " Alexander Kanavin
2022-08-14 22:20 ` [PATCH 03/10] zlib: Resolve CVE-2022-37434 Khem Raj
2022-08-15  2:32   ` Paul Eggleton [this message]
2022-08-15  2:40     ` [OE-core] " Khem Raj
2022-08-14 22:20 ` [PATCH 04/10] rsync: Backport fix to address CVE-2022-29154 Khem Raj
2022-08-14 22:20 ` [PATCH 05/10] rsync: Upgrade to 3.2.5 Khem Raj
2022-08-14 22:20 ` [PATCH 06/10] connman: Backports for security fixes Khem Raj
2022-08-14 22:20 ` [PATCH 07/10] libtirpc: Backport fix for CVE-2021-46828 Khem Raj
2022-08-14 22:20 ` [PATCH 08/10] libxml2: Ignore CVE-2016-3709 Khem Raj
2022-08-14 22:20 ` [PATCH 09/10] tiff: Backport a patch for CVE-2022-34526 Khem Raj
2022-08-14 22:20 ` [PATCH 10/10] libtirpc: Upgrade to 1.3.3 Khem Raj

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=2841280.e9J7NaK4W3@linc \
    --to=bluelightning@bluelightning.org \
    --cc=openembedded-core@lists.openembedded.org \
    --cc=raj.khem@gmail.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox