poky/meta
Li Wang 6e1ca0e922 flac: fix CVE-2021-0561
In append_to_verify_fifo_interleaved_ of stream_encoder.c, there is
a possible out of bounds write due to a missing bounds check. This
could lead to local information disclosure with no additional
execution privileges needed. User interaction is not needed for
exploitation.Product: AndroidVersions: Android-11Android ID: A-174302683

References:
https://nvd.nist.gov/vuln/detail/CVE-2021-0561

Upstream patches:
e1575e4a7c

(From OE-Core rev: 76d5c8d876f78d86e755c12360d41e40154eca0b)

Signed-off-by: Li Wang <li.wang@windriver.com>
Signed-off-by: Joe Slater <joe.slater@windriver.com>
Signed-off-by: Anuj Mittal <anuj.mittal@intel.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
2022-04-03 20:49:03 +01:00
..
classes sstate: inside the threadedpool don't write to the shared localdata 2022-03-22 22:18:51 +00:00
conf uninative: Upgrade to 3.5 2022-03-02 00:22:13 +00:00
files sdk: fix search for dynamic loader 2022-02-20 15:32:27 +00:00
lib patch.py: Prevent git repo reinitialization 2022-03-22 22:18:51 +00:00
recipes-bsp grub2: fix CVE-2021-3981 2022-01-14 09:34:04 +00:00
recipes-connectivity mobile-broadband-provider-info: upgrade 20210805 -> 20220315 2022-04-03 20:49:03 +01:00
recipes-core libxml2: Fix CVE-2022-23308 2022-04-03 20:49:03 +01:00
recipes-devtools go: update to 1.16.15 2022-04-03 20:49:03 +01:00
recipes-extended zip: modify when match.S is built 2022-04-03 20:49:03 +01:00
recipes-gnome meta: add explicit branch and protocol to SRC_URI 2021-11-21 11:40:35 +00:00
recipes-graphics virglrenderer: update SRC_URI 2022-04-03 20:49:03 +01:00
recipes-kernel linux-yocto/5.10: update to v5.10.107 2022-04-03 20:49:03 +01:00
recipes-multimedia flac: fix CVE-2021-0561 2022-04-03 20:49:03 +01:00
recipes-rt meta/recipes-rt: Add HOMEPAGE / DESCRIPTION 2021-03-06 22:39:04 +00:00
recipes-sato webkitgtk : update to 2.30.6 2022-04-03 20:49:03 +01:00
recipes-support vim: Update to 8.2.4524 for further CVE fixes 2022-03-22 22:18:51 +00:00
site site/elfutils/libunistring: Drop patching for iconv and set in site file 2021-03-23 22:51:25 +00:00
COPYING.MIT
recipes.txt