summary refs log tree commit diff
path: root/pkgs/applications/virtualization
diff options
context:
space:
mode:
authorRyan Burns <rtburns@protonmail.com>2021-10-27 21:34:32 -0700
committerRyan Burns <rtburns@protonmail.com>2021-10-27 21:51:17 -0700
commit18451cb59a89470d587d7265c95d4d9b2938d75d (patch)
treeee92e0085edb242aa22f109fdaa4235857686923 /pkgs/applications/virtualization
parent8652402ac5bc4dff28ac2b9cb37de6d621c9a706 (diff)
downloadnixpkgs-18451cb59a89470d587d7265c95d4d9b2938d75d.tar
nixpkgs-18451cb59a89470d587d7265c95d4d9b2938d75d.tar.gz
nixpkgs-18451cb59a89470d587d7265c95d4d9b2938d75d.tar.bz2
nixpkgs-18451cb59a89470d587d7265c95d4d9b2938d75d.tar.lz
nixpkgs-18451cb59a89470d587d7265c95d4d9b2938d75d.tar.xz
nixpkgs-18451cb59a89470d587d7265c95d4d9b2938d75d.tar.zst
nixpkgs-18451cb59a89470d587d7265c95d4d9b2938d75d.zip
qemu: fix CVE-2021-3713
Backport patch from 6.2.0-rc0
Diffstat (limited to 'pkgs/applications/virtualization')
-rw-r--r--pkgs/applications/virtualization/qemu/default.nix5
1 files changed, 5 insertions, 0 deletions
diff --git a/pkgs/applications/virtualization/qemu/default.nix b/pkgs/applications/virtualization/qemu/default.nix
index 224969cc264..4e0f459ac28 100644
--- a/pkgs/applications/virtualization/qemu/default.nix
+++ b/pkgs/applications/virtualization/qemu/default.nix
@@ -92,6 +92,11 @@ stdenv.mkDerivation rec {
       sha256 = "09xz06g57wxbacic617pq9c0qb7nly42gif0raplldn5lw964xl2";
       revert = true;
     })
+    (fetchpatch {
+      name = "CVE-2021-3713.patch"; # remove with next release
+      url = "https://gitlab.com/qemu-project/qemu/-/commit/13b250b12ad3c59114a6a17d59caf073ce45b33a.patch";
+      sha256 = "0lkzfc7gdlvj4rz9wk07fskidaqysmx8911g914ds1jnczgk71mf";
+    })
   ] ++ lib.optional nixosTestRunner ./force-uid0-on-9p.patch
     ++ lib.optionals stdenv.hostPlatform.isMusl [
     (fetchpatch {