[Buildroot] [PATCH 1/1] package/blktrace: fix CVE-2018-10689

Peter Korsgaard peter at korsgaard.com
Sat Mar 14 18:37:53 UTC 2020


>>>>> "Fabrice" == Fabrice Fontaine <fontaine.fabrice at gmail.com> writes:

 > blktrace (aka Block IO Tracing) 1.2.0, as used with the Linux kernel and
 > Android, has a buffer overflow in the dev_map_read function in
 > btt/devmap.c because the device and devno arrays are too small, as
 > demonstrated by an invalid free when using the btt program with a
 > crafted file.

 > Signed-off-by: Fabrice Fontaine <fontaine.fabrice at gmail.com>

Committed to 2019.02.x and 2019.11.x, thanks.

-- 
Bye, Peter Korsgaard



More information about the buildroot mailing list