[Buildroot] [PATCH v2] package/busybox: add upstream gunzip security fix
Peter Korsgaard
peter at korsgaard.com
Wed Apr 7 07:26:36 UTC 2021
>>>>> "Peter" == Peter Korsgaard <peter at korsgaard.com> writes:
> Fixes the following security issue:
> - CVE-2021-28831: decompress_gunzip.c in BusyBox through 1.32.1 mishandles
> the error bit on the huft_build result pointer, with a resultant invalid
> free or segmentation fault, via malformed gzip data.
> Signed-off-by: Peter Korsgaard <peter at korsgaard.com>
Committed, thanks.
--
Bye, Peter Korsgaard
More information about the buildroot
mailing list