package/musl: add CVE trailer in patch

Since Buildroot commit [1] the patches that fixes a security
vulnerability needs to reference the fixed vulnerability.

This patch adds the relevant information to the patch header.

[1] 1167d0ff3d docs/manual: mention CVE trailer

Signed-off-by: Thomas Perale <thomas.perale@mind.be>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
(cherry picked from commit c0921c6b38)
Signed-off-by: Thomas Perale <thomas.perale@mind.be>
This commit is contained in:
Thomas Perale
2025-12-28 19:56:34 +01:00
parent 99520a4485
commit 19f5ea0f92
2 changed files with 2 additions and 0 deletions

View File

@@ -17,6 +17,7 @@ buffer.
bug report was submitted in private by Nick Wellnhofer on account of bug report was submitted in private by Nick Wellnhofer on account of
potential security implications. potential security implications.
CVE: CVE-2025-26519
Upstream: https://git.musl-libc.org/cgit/musl/commit/?id=e5adcd97b5196e29991b524237381a0202a60659 Upstream: https://git.musl-libc.org/cgit/musl/commit/?id=e5adcd97b5196e29991b524237381a0202a60659
Signed-off-by: Peter Korsgaard <peter@korsgaard.com> Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
--- ---

View File

@@ -14,6 +14,7 @@ output byte count overflow, moving the output position backwards,
potentially past the beginning of the buffer, without storing any potentially past the beginning of the buffer, without storing any
bytes. bytes.
CVE: CVE-2025-26519
Upstream: https://git.musl-libc.org/cgit/musl/commit/?id=c47ad25ea3b484e10326f933e927c0bc8cded3da Upstream: https://git.musl-libc.org/cgit/musl/commit/?id=c47ad25ea3b484e10326f933e927c0bc8cded3da
Signed-off-by: Peter Korsgaard <peter@korsgaard.com> Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
--- ---