Re: [OE-core] [dunfell][PATCHv2] u-boot: fix CVE-2022-34835

2022-08-31 Thread Tom Rini
On Tue, Aug 30, 2022 at 09:00:39PM +0200, Minjae Kim wrote: > i2c: fix stack buffer overflow vulnerability in i2c md command > > CVE: CVE-2022-34835 > > Signed-off-by:Minjae Kim While this is the full backport of the fix for the issue, at this point we now also have:

[OE-core] [dunfell][PATCHv2] u-boot: fix CVE-2022-34835

2022-08-30 Thread Minjae Kim
i2c: fix stack buffer overflow vulnerability in i2c md command CVE: CVE-2022-34835 Signed-off-by:Minjae Kim --- .../u-boot/files/CVE-2022-34835.patch | 124 ++ meta/recipes-bsp/u-boot/u-boot_2020.01.bb | 4 + 2 files changed, 128 insertions(+) create mode 100644