[Buildroot] [PATCH] package/busybox: add upstream gunzip security fix

Peter Korsgaard peter at korsgaard.com
Tue Apr 6 13:11:51 UTC 2021


>>>>> "Peter" == Peter Korsgaard <peter at korsgaard.com> writes:

 > Fixes the following security issue:
 > - CVE-2021-28831: decompress_gunzip.c in BusyBox through 1.32.1 mishandles
 >   the error bit on the huft_build result pointer, with a resultant invalid
 >   free or segmentation fault, via malformed gzip data.

 > Signed-off-by: Peter Korsgaard <peter at korsgaard.com>

Ups, I forgot the _IGNORE_CVES entry. Will send a v2.

-- 
Bye, Peter Korsgaard



More information about the buildroot mailing list