mirror of
https://gitlab.com/buildroot.org/buildroot.git
synced 2026-10-01 06:21:56 -09:00
Patch 0005-seedrng-fix-for-glibc-2.24-not-providing-getrandom.patch is dropped as it is upstream as of https://git.busybox.net/busybox/commit/?id=200a9669fbf6f06894e4243cccc9fc11a1a6073a Patch 0006-seedrng-fix-for-glibc-2.24-not-providing-random-head.patch is dropped as it is upstream as of https://git.busybox.net/busybox/commit/?id=cb57abb46f06f4ede8d9ccbdaac67377fdf416cf Patch 0008-shell-fix-SIGWINCH-and-SIGCHLD-in-hush-interrupting-.patch is dropped as it is upstream as of https://git.busybox.net/busybox/commit/?id=93e0898c663a533082b5f3c2e7dcce93ec47076d Patch 0011-awk-fix-use-after-realloc-CVE-2021-42380-closes-1560.patch is dropped as it is upstream as of https://git.busybox.net/busybox/commit/?id=5dcc443dba039b305a510c01883e9f34e42656ae Patch 0012-awk-fix-use-after-free-CVE-2023-42363.patch is dropped as it is upstream as of https://git.busybox.net/busybox/commit/?id=fb08d43d44d1fea1f741fafb9aa7e1958a5f69aa Patch 0013-awk-fix-precedence-of-relative-to.patch is dropped as it is upstream as of https://git.busybox.net/busybox/commit/?id=0256e00a9d077588bd3a39f5a1ef7e2eaa2911e4 Patch 0014-awk-fix-ternary-operator-and-precedence-of.patch is dropped as it is upstream as of https://git.busybox.net/busybox/commit/?id=38335df9e9f45378c3407defd38b5b610578bdda Remaining patches are renumbered/refreshed. Patch 0010-libbb-sha-add-missing-sha-NI-guard.patch is added, taken from the mailing list, to fix a build issue. Patch 0011-syslogd-fix-wrong-OPT_locallog-flag-detection.patch, taken from the mailing list, is added to fix a runtime issue with syslogd which was pointed out by Bernd Kulhs. Signed-off-by: Clement Ramirez <clement@clementramirez.fr> [Thomas: update with more patches being dropped, renumber patches, backport some patches needed to fix known build and runtime issues] Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com> Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
44 lines
1.4 KiB
Diff
44 lines
1.4 KiB
Diff
From 88f8a046f27cb81ccc30d038465e963b8300cf1b Mon Sep 17 00:00:00 2001
|
|
From: Valery Ushakov <uwe@stderr.spb.ru>
|
|
Date: Wed, 24 Jan 2024 22:24:41 +0300
|
|
Subject: [PATCH] awk.c: fix CVE-2023-42366 (bug #15874)
|
|
|
|
Make sure we don't read past the end of the string in next_token()
|
|
when backslash is the last character in an (invalid) regexp.
|
|
a fix and issue reported in bugzilla
|
|
|
|
https://bugs.busybox.net/show_bug.cgi?id=15874
|
|
|
|
Upstream-Status: Submitted [http://lists.busybox.net/pipermail/busybox/2024-May/090766.html]
|
|
|
|
CVE: CVE-2023-42366
|
|
Signed-off-by: Khem Raj <raj.khem@gmail.com>
|
|
[Thomas: https://git.openembedded.org/openembedded-core/tree/meta/recipes-core/busybox/busybox/0001-awk.c-fix-CVE-2023-42366-bug-15874.patch?id=e0ff4813b1cf4df0d851c857d57fb88d7db51bdd]
|
|
Upstream: http://lists.busybox.net/pipermail/busybox/2024-May/090766.html
|
|
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
|
|
---
|
|
editors/awk.c | 6 ++++--
|
|
1 file changed, 4 insertions(+), 2 deletions(-)
|
|
|
|
diff --git a/editors/awk.c b/editors/awk.c
|
|
index 64e752f4b..222e6298d 100644
|
|
--- a/editors/awk.c
|
|
+++ b/editors/awk.c
|
|
@@ -1234,9 +1234,11 @@ static uint32_t next_token(uint32_t expected)
|
|
s[-1] = bb_process_escape_sequence((const char **)&pp);
|
|
if (*p == '\\')
|
|
*s++ = '\\';
|
|
- if (pp == p)
|
|
+ if (pp == p) {
|
|
+ if (*p == '\0')
|
|
+ syntax_error(EMSG_UNEXP_EOS);
|
|
*s++ = *p++;
|
|
- else
|
|
+ } else
|
|
p = pp;
|
|
}
|
|
}
|
|
--
|
|
2.48.1
|
|
|