mirror of
git://git.openembedded.org/meta-openembedded
synced 2026-10-02 16:11:29 +00:00
Details: https://nvd.nist.gov/vuln/detail/CVE-2022-31212 A detailed writeup[1] is referenced by the nvd report, which describes that the vulnerability itself is not in the application, rather in a dependency of it, in c-shutil, which is pulled in as a submodule. Pick the patch from this submodule that fixes a stack overflow, and adds a test explictly verifying the described vulnerability. [1]: https://sec-consult.com/vulnerability-lab/advisory/memory-corruption-vulnerabilities-dbus-broker/ Signed-off-by: Gyorgy Sarvari <skandigraun@gmail.com>
35 lines
1.2 KiB
BlitzBasic
35 lines
1.2 KiB
BlitzBasic
SUMMARY = "dbus broker"
|
|
DESCRIPTION = "Drop-in replacement for dbus-daemon."
|
|
|
|
SECTION = "base"
|
|
|
|
LICENSE = "Apache-2.0"
|
|
LIC_FILES_CHKSUM = "file://LICENSE;md5=7b486c2338d225a1405d979ed2c15ce8"
|
|
|
|
SRC_URI = "https://github.com/bus1/dbus-broker/releases/download/v${PV}/dbus-broker-${PV}.tar.xz \
|
|
file://CVE-2022-31212.patch \
|
|
"
|
|
SRC_URI[sha256sum] = "4eca425db52b7ab1027153e93fea9b3f11759db9e93ffbf88759b73ddfb8026a"
|
|
|
|
UPSTREAM_CHECK_URI = "https://github.com/bus1/${BPN}/releases"
|
|
|
|
inherit meson pkgconfig systemd features_check
|
|
|
|
DEPENDS = "expat systemd"
|
|
DEPENDS += " ${@bb.utils.contains('DISTRO_FEATURES', 'selinux', 'libselinux (>= 3.2)', '', d)}"
|
|
DEPENDS += " ${@bb.utils.contains('DISTRO_FEATURES', 'selinux', 'audit (>= 3.0)', '', d)}"
|
|
|
|
RDEPENDS:${PN} += "dbus-common"
|
|
|
|
REQUIRED_DISTRO_FEATURES = "systemd"
|
|
|
|
SYSTEMD_SERVICE:${PN} = "${BPN}.service"
|
|
|
|
FILES:${PN} += "${systemd_system_unitdir}"
|
|
FILES:${PN} += "${systemd_user_unitdir}"
|
|
FILES:${PN} += "${nonarch_libdir}/systemd/catalog"
|
|
|
|
EXTRA_OEMESON += " -Dselinux=${@bb.utils.contains('DISTRO_FEATURES', 'selinux', 'true', 'false', d)}"
|
|
EXTRA_OEMESON += " -Daudit=${@bb.utils.contains('DISTRO_FEATURES', 'selinux', 'true', 'false', d)}"
|
|
|