diff options
author | Marek Vasut <marex@denx.de> | 2023-10-10 16:08:05 +0200 |
---|---|---|
committer | Martin Jansa <martin.jansa@gmail.com> | 2023-10-11 14:18:48 +0200 |
commit | 51cd2acfb67bbbd89985004c064835e7b2f5ac09 (patch) | |
tree | 2533042a6e273187371d00d07e4735be3b9546fb /recipes-qt/qt5/qtbase_git.bb | |
parent | 002d27e9bf8727e2680c76624198516f5a774741 (diff) |
qtbase: Pick CVE-2023-33285 fix
An issue was discovered in Qt 5.x before 5.15.14, 6.x before 6.2.9,
and 6.3.x through 6.5.x before 6.5.1. QDnsLookup has a buffer
over-read via a crafted reply from a DNS server.
Advisory:
https://nvd.nist.gov/vuln/detail/CVE-2023-33285
Patch:
https://download.qt.io/official_releases/qt/5.15/CVE-2023-33285-qtbase-5.15.diff
Signed-off-by: Marek Vasut <marex@denx.de>
Diffstat (limited to 'recipes-qt/qt5/qtbase_git.bb')
-rw-r--r-- | recipes-qt/qt5/qtbase_git.bb | 1 |
1 files changed, 1 insertions, 0 deletions
diff --git a/recipes-qt/qt5/qtbase_git.bb b/recipes-qt/qt5/qtbase_git.bb index e80335de..66e45392 100644 --- a/recipes-qt/qt5/qtbase_git.bb +++ b/recipes-qt/qt5/qtbase_git.bb @@ -41,6 +41,7 @@ SRC_URI += "\ file://0026-qsql_odbc-Patch-for-CVE-2023-24607.patch \ file://CVE-2023-32762.patch \ file://CVE-2023-32763-qtbase-5.15.diff \ + file://CVE-2023-33285-qtbase-5.15.diff \ " # Disable LTO for now, QT5 patches are being worked upstream, perhaps revisit with |