From 30f6c5ae79407dbbe82f0992c355bd0f9b69a2ad Mon Sep 17 00:00:00 2001 From: Praveen Kumar Date: Fri, 24 Oct 2025 17:25:09 +0530 Subject: [PATCH] cjson: upgrade 1.7.18 -> 1.7.19 This includes CVE-fix for CVE-2023-26819. Removed CVE-2025-57052, as the issue was already resolved in v1.7.19. Changelog: ========== https://github.com/DaveGamble/cJSON/blob/master/CHANGELOG.md Signed-off-by: Praveen Kumar Signed-off-by: Anuj Mittal --- .../cjson/cjson/CVE-2025-57052.patch | 33 ------------------- .../{cjson_1.7.18.bb => cjson_1.7.19.bb} | 3 +- 2 files changed, 1 insertion(+), 35 deletions(-) delete mode 100644 meta-oe/recipes-devtools/cjson/cjson/CVE-2025-57052.patch rename meta-oe/recipes-devtools/cjson/{cjson_1.7.18.bb => cjson_1.7.19.bb} (95%) diff --git a/meta-oe/recipes-devtools/cjson/cjson/CVE-2025-57052.patch b/meta-oe/recipes-devtools/cjson/cjson/CVE-2025-57052.patch deleted file mode 100644 index ed3d4a7eba..0000000000 --- a/meta-oe/recipes-devtools/cjson/cjson/CVE-2025-57052.patch +++ /dev/null @@ -1,33 +0,0 @@ -From e53a1413304382d562176bed91609e00b4fcf87e Mon Sep 17 00:00:00 2001 -From: Lee -Date: Fri, 5 Sep 2025 14:53:20 +0800 -Subject: [PATCH] fix the incorrect check in decode_array_index_from_pointer - (#957) - -this fixes CVE-2025-57052 - -CVE: CVE-2025-57052 -Upstream-Status: Backport [https://github.com/DaveGamble/cJSON/commit/74e1ff4994aa] - -(cherry picked from commit 74e1ff4994aa4139126967f6d289b675b4b36fef) -Signed-off-by: Shubham Pushpkar ---- - cJSON_Utils.c | 2 +- - 1 file changed, 1 insertion(+), 1 deletion(-) - -diff --git a/cJSON_Utils.c b/cJSON_Utils.c -index 63651df..8fa24f8 100644 ---- a/cJSON_Utils.c -+++ b/cJSON_Utils.c -@@ -282,7 +282,7 @@ static cJSON_bool decode_array_index_from_pointer(const unsigned char * const po - return 0; - } - -- for (position = 0; (pointer[position] >= '0') && (pointer[0] <= '9'); position++) -+ for (position = 0; (pointer[position] >= '0') && (pointer[position] <= '9'); position++) - { - parsed_index = (10 * parsed_index) + (size_t)(pointer[position] - '0'); - --- -2.44.1 - diff --git a/meta-oe/recipes-devtools/cjson/cjson_1.7.18.bb b/meta-oe/recipes-devtools/cjson/cjson_1.7.19.bb similarity index 95% rename from meta-oe/recipes-devtools/cjson/cjson_1.7.18.bb rename to meta-oe/recipes-devtools/cjson/cjson_1.7.19.bb index 67d536cf24..799eb119d6 100644 --- a/meta-oe/recipes-devtools/cjson/cjson_1.7.18.bb +++ b/meta-oe/recipes-devtools/cjson/cjson_1.7.19.bb @@ -6,9 +6,8 @@ LIC_FILES_CHKSUM = "file://LICENSE;md5=218947f77e8cb8e2fa02918dc41c50d0" SRC_URI = "git://github.com/DaveGamble/cJSON.git;branch=master;protocol=https \ file://run-ptest \ - file://CVE-2025-57052.patch \ " -SRCREV = "acc76239bee01d8e9c858ae2cab296704e52d916" +SRCREV = "c859b25da02955fef659d658b8f324b5cde87be3" S = "${WORKDIR}/git"