Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Update tracker and libcue for CVE-2023-43641. #46540

Merged
merged 3 commits into from Oct 10, 2023
Merged

Conversation

oreo639
Copy link
Member

@oreo639 oreo639 commented Oct 10, 2023

Testing the changes

  • I tested the changes in this PR: briefly

See here for more details: https://github.blog/2023-10-09-coordinated-disclosure-1-click-rce-on-gnome-cve-2023-43641/
The public example file only tests libcue, so that was all I could test, but the tracker update should also fix the sandbox escape issue.

@oreo639 oreo639 force-pushed the trackercve branch 3 times, most recently from a0b4f87 to 4537eba Compare October 10, 2023 00:52
@oreo639
Copy link
Member Author

oreo639 commented Oct 10, 2023

Fails to configure on 32-bit musl due to y2k38 checks failing, should I patch out the check?

@sgn sgn merged commit 82360ca into void-linux:master Oct 10, 2023
8 checks passed
@oreo639 oreo639 deleted the trackercve branch October 10, 2023 03:02
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

2 participants