summary refs log tree commit diff
path: root/pkgs/os-specific/linux/systemd
diff options
context:
space:
mode:
authorAndreas Rammhold <andreas@rammhold.de>2019-09-04 01:02:38 +0200
committerAndreas Rammhold <andreas@rammhold.de>2019-09-04 01:05:28 +0200
commitcde77150393ba1fec58ae0fa3f877766f92b5f28 (patch)
treed344e380d01f6446c238fb49d6a36bb74db4be9c /pkgs/os-specific/linux/systemd
parent7547a7a1d411f07e416c259b322e528d4d1430d1 (diff)
downloadnixpkgs-cde77150393ba1fec58ae0fa3f877766f92b5f28.tar
nixpkgs-cde77150393ba1fec58ae0fa3f877766f92b5f28.tar.gz
nixpkgs-cde77150393ba1fec58ae0fa3f877766f92b5f28.tar.bz2
nixpkgs-cde77150393ba1fec58ae0fa3f877766f92b5f28.tar.lz
nixpkgs-cde77150393ba1fec58ae0fa3f877766f92b5f28.tar.xz
nixpkgs-cde77150393ba1fec58ae0fa3f877766f92b5f28.tar.zst
nixpkgs-cde77150393ba1fec58ae0fa3f877766f92b5f28.zip
systemd: fix CVE-2019-15718
More details at: https://www.openwall.com/lists/oss-security/2019/09/03/1
Diffstat (limited to 'pkgs/os-specific/linux/systemd')
-rw-r--r--pkgs/os-specific/linux/systemd/default.nix10
1 files changed, 9 insertions, 1 deletions
diff --git a/pkgs/os-specific/linux/systemd/default.nix b/pkgs/os-specific/linux/systemd/default.nix
index 45f4d60e4e3..602d973bfb9 100644
--- a/pkgs/os-specific/linux/systemd/default.nix
+++ b/pkgs/os-specific/linux/systemd/default.nix
@@ -1,4 +1,4 @@
-{ stdenv, lib, fetchFromGitHub, pkgconfig, intltool, gperf, libcap, kmod
+{ stdenv, lib, fetchFromGitHub, fetchpatch, pkgconfig, intltool, gperf, libcap, kmod
 , xz, pam, acl, libuuid, m4, utillinux, libffi
 , glib, kbd, libxslt, coreutils, libgcrypt, libgpgerror, libidn2, libapparmor
 , audit, lz4, bzip2, libmicrohttpd, pcre2
@@ -28,6 +28,14 @@ stdenv.mkDerivation rec {
     sha256 = "0pyjvzzh8nnxv4z58n82lz1mjnzv44sylcjgkvw8sp35vx1ryxfh";
   };
 
+  patches = [
+    (fetchpatch {
+      name = "CVE-2019-15718.patch";
+      url = https://github.com/systemd/systemd/pull/13457/commits/35e528018f315798d3bffcb592b32a0d8f5162bd.patch;
+      sha256 = "0m0ypnnllx4r6a2qy1586as15i2qrzxwi1sqdp14rzdwajz1rvnv";
+    })
+  ];
+
   outputs = [ "out" "lib" "man" "dev" ];
 
   nativeBuildInputs =