summary refs log tree commit diff
path: root/pkgs/os-specific/linux/busybox
diff options
context:
space:
mode:
authorAlyssa Ross <hi@alyssa.is>2022-04-05 16:09:18 +0000
committerAlyssa Ross <hi@alyssa.is>2022-04-05 16:09:18 +0000
commitac60e92b15adfcb14d65dcfb2265f24bb69e22c0 (patch)
tree79e9dd1744a2ab9cb99c71853cb44e81b38f48b9 /pkgs/os-specific/linux/busybox
parent21761f11914e1886ebc5b9d91d76b87e2ddc7a2a (diff)
downloadnixpkgs-ac60e92b15adfcb14d65dcfb2265f24bb69e22c0.tar
nixpkgs-ac60e92b15adfcb14d65dcfb2265f24bb69e22c0.tar.gz
nixpkgs-ac60e92b15adfcb14d65dcfb2265f24bb69e22c0.tar.bz2
nixpkgs-ac60e92b15adfcb14d65dcfb2265f24bb69e22c0.tar.lz
nixpkgs-ac60e92b15adfcb14d65dcfb2265f24bb69e22c0.tar.xz
nixpkgs-ac60e92b15adfcb14d65dcfb2265f24bb69e22c0.tar.zst
nixpkgs-ac60e92b15adfcb14d65dcfb2265f24bb69e22c0.zip
busybox: fix CVE-2022-28391
Diffstat (limited to 'pkgs/os-specific/linux/busybox')
-rw-r--r--pkgs/os-specific/linux/busybox/default.nix10
1 files changed, 10 insertions, 0 deletions
diff --git a/pkgs/os-specific/linux/busybox/default.nix b/pkgs/os-specific/linux/busybox/default.nix
index 7aaedb5b1ac..970129f9739 100644
--- a/pkgs/os-specific/linux/busybox/default.nix
+++ b/pkgs/os-specific/linux/busybox/default.nix
@@ -65,6 +65,16 @@ stdenv.mkDerivation rec {
 
   patches = [
     ./busybox-in-store.patch
+    (fetchurl {
+      name = "CVE-2022-28391.patch";
+      url = "https://git.alpinelinux.org/aports/plain/main/busybox/0001-libbb-sockaddr2str-ensure-only-printable-characters-.patch?id=ed92963eb55bbc8d938097b9ccb3e221a94653f4";
+      sha256 = "sha256-yviw1GV+t9tbHbY7YNxEqPi7xEreiXVqbeRyf8c6Awo=";
+    })
+    (fetchurl {
+      name = "CVE-2022-28391.patch";
+      url = "https://git.alpinelinux.org/aports/plain/main/busybox/0002-nslookup-sanitize-all-printed-strings-with-printable.patch?id=ed92963eb55bbc8d938097b9ccb3e221a94653f4";
+      sha256 = "sha256-vl1wPbsHtXY9naajjnTicQ7Uj3N+EQ8pRNnrdsiow+w=";
+    })
   ] ++ lib.optional (stdenv.hostPlatform != stdenv.buildPlatform) ./clang-cross.patch;
 
   separateDebugInfo = true;