Files
buildroot/package
Quentin Schulz ff80cc77b1 package/icu: backport upstream security fix for CVE-2025-5222
Fixes CVE-2025-5222[1]. The patch is generated with
git format-patch -1 2c667e31cfd0b6bb1923627a932fd3453a5bac77 --relative=icu4c
and matches the Debian patch[2] aside from s/NULL/nullptr/ in the git
context. This is expected as the Debian patch is based on 72-1 and we
are on 73-2, so we have commit 2e0d30cfcf43 ("ICU-21833 Replace NULL
with nullptr in all C++ code.")

While NVD[1] and Debian[3] list ICU-22957 in their bug reports, looking
at the icu bug report[4] one can see it's marked as a duplicate of
ICU-22973[5] which also happens to be the bug ID specified in the commit
log of the commit listed in the Debian advisory[3].

[1] https://nvd.nist.gov/vuln/detail/CVE-2025-5222
[2] https://sources.debian.org/src/icu/72.1-3%2Bdeb12u1/debian/patches/0001-ICU-22973-Fix-buffer-overflow-by-using-CharString.patch
[3] https://security-tracker.debian.org/tracker/CVE-2025-5222
[4] https://unicode-org.atlassian.net/browse/ICU-22957
[5] https://unicode-org.atlassian.net/browse/ICU-22973

Signed-off-by: Quentin Schulz <quentin.schulz@cherry.de>
Signed-off-by: Thomas Perale <thomas.perale@mind.be>
2026-07-10 11:41:58 +02:00
..
2026-06-04 12:11:22 +02:00
2026-06-04 12:35:14 +02:00
2026-06-11 11:40:41 +02:00
2026-06-04 11:52:28 +02:00
2026-06-11 11:41:14 +02:00
2026-06-04 12:02:46 +02:00
2026-07-08 14:27:00 +02:00
2026-06-04 12:03:43 +02:00
2026-06-04 11:53:39 +02:00
2026-06-11 11:40:05 +02:00
2026-06-18 14:58:37 +02:00
2026-06-04 11:41:11 +02:00
2026-07-08 14:53:52 +02:00
2026-06-11 10:05:24 +02:00
2026-07-08 13:50:16 +02:00
2026-06-11 10:33:12 +02:00