-
-
Notifications
You must be signed in to change notification settings - Fork 13.7k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
lynx: add patch for CVE-2021-38165 #133057
Conversation
Referencing the mail with the patch you didn't use is confusing. Please add the correct reference. |
8f348ec
to
c542f81
Compare
69035a9
to
b248743
Compare
b248743
to
3e1bcd3
Compare
pkgs/applications/networking/browsers/lynx/CVE-2021-38165.patch
Outdated
Show resolved
Hide resolved
3e1bcd3
to
bacb518
Compare
@@ -22,6 +23,14 @@ stdenv.mkDerivation rec { | |||
|
|||
hardeningEnable = [ "pie" ]; | |||
|
|||
patches = [ |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
patches = [ | |
patches = [ |
You seem to have added unrelated commits. |
bacb518
to
e05f96c
Compare
Co-authored-by: nixinator <33lockdown33@protonmail.com> Co-authored-by: John Bargman <darthpjb@gmail.com> Co-authored-by: Martin Weinelt <hexa@darmstadt.ccc.de>
9feddac
to
ddce0ec
Compare
I have rebased with the suggested changes so far and added co-authorship to @mweinelt. Thanks for the guidance! I now know how to use fetchpatch. |
@ofborg build lynx |
Successfully created backport PR #133065 for |
The process '/usr/bin/git' failed with exit code 1 |
Co-authored-by: nixinator 33lockdown33@protonmail.com
Co-authored-by: John Bargman darthpjb@gmail.com
Motivation for this change
Fixes the security vulnerability in Lynx that resulted in this meltdown on the mailing list. Code was audited by @DarthPJB
https://lists.nongnu.org/archive/html/lynx-dev/2021-08/msg00007.html
Patch Source: https://git.alpinelinux.org/aports/tree/main/lynx/CVE-2021-38165.patch
Things done
sandbox
innix.conf
on non-NixOS linux)nix-shell -p nixpkgs-review --run "nixpkgs-review wip"
./result/bin/
)