binutls: Security fix for CVE-2017-15225

Affects: <= 2.29.1

(From OE-Core rev: 885e991934e5e20ac69551e73da9d3219eb4c24e)

Signed-off-by: Armin Kuster <akuster@mvista.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
This commit is contained in:
Armin Kuster 2018-08-06 19:29:45 -07:00 committed by Richard Purdie
parent 09d31d0806
commit e4c382ecc6
2 changed files with 49 additions and 0 deletions

View File

@ -49,6 +49,7 @@ SRC_URI = "\
file://CVE-2017-15023.patch \
file://CVE-2017-15024.patch \
file://CVE-2017-15025.patch \
file://CVE-2017-15225.patch \
"
S = "${WORKDIR}/git"

View File

@ -0,0 +1,48 @@
From b55ec8b676ed05d93ee49d6c79ae0403616c4fb0 Mon Sep 17 00:00:00 2001
From: Alan Modra <amodra@gmail.com>
Date: Mon, 9 Oct 2017 13:21:44 +1030
Subject: [PATCH] PR22212, memory leak in nm
PR 22212
* dwarf2.c (_bfd_dwarf2_cleanup_debug_info): Free
funcinfo_hash_table and varinfo_hash_table.
Upstream-Status: Backport
Affects: <= 2.29.1
CVE: CVE-2017-15225
Signed-off-by: Armin Kuster <akuster@mvista.com>
---
bfd/ChangeLog | 6 ++++++
bfd/dwarf2.c | 4 ++++
2 files changed, 10 insertions(+)
Index: git/bfd/dwarf2.c
===================================================================
--- git.orig/bfd/dwarf2.c
+++ git/bfd/dwarf2.c
@@ -4932,6 +4932,10 @@ _bfd_dwarf2_cleanup_debug_info (bfd *abf
}
}
+ if (stash->funcinfo_hash_table)
+ bfd_hash_table_free (&stash->funcinfo_hash_table->base);
+ if (stash->varinfo_hash_table)
+ bfd_hash_table_free (&stash->varinfo_hash_table->base);
if (stash->dwarf_abbrev_buffer)
free (stash->dwarf_abbrev_buffer);
if (stash->dwarf_line_buffer)
Index: git/bfd/ChangeLog
===================================================================
--- git.orig/bfd/ChangeLog
+++ git/bfd/ChangeLog
@@ -1,3 +1,9 @@
+2017-10-09 Alan Modra <amodra@gmail.com>
+
+ PR 22212
+ * dwarf2.c (_bfd_dwarf2_cleanup_debug_info): Free
+ funcinfo_hash_table and varinfo_hash_table.
+
2017-09-24 Alan Modra <amodra@gmail.com>
PR 22186