[PATCH] lib/zlib: Fix a bug when getting a gzip header extra field

Tom Rini trini at konsulko.com
Sat Jul 15 17:03:26 CEST 2023


On Thu, Jun 15, 2023 at 05:54:34PM +0300, Oleksandr Suvorov wrote:

> This fixes CVE-2022-37434 [1] and bases on 2 commits from Mark
> Adler's zlib master repo - the original fix of CVE bug [2] and
> the fix for the fix [3].
> 
> [1]
> https://github.com/advisories/GHSA-cfmr-vrgj-vqwv
> [2]
> https://github.com/madler/zlib/commit/eff308af425b67093bab25f80f1ae950166bece1
> [3]
> https://github.com/madler/zlib/commit/1eb7682f845ac9e9bf9ae35bbfb3bad5dacbd91d
> 
> Fixes: e89516f031d ("zlib: split up to match original source tree")
> Signed-off-by: Oleksandr Suvorov <oleksandr.suvorov at foundries.io>

Applied to u-boot/master, thanks!

-- 
Tom
-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 659 bytes
Desc: not available
URL: <https://lists.denx.de/pipermail/u-boot/attachments/20230715/b7e01be9/attachment.sig>


More information about the U-Boot mailing list