Skip to content

Conversation

@nashif
Copy link
Member

@nashif nashif commented Apr 26, 2025

Fixes CVE-2021-3420
Fixes #892

Signed-off-by: Anas Nashif anas.nashif@intel.com

@nashif
Copy link
Member Author

nashif commented Apr 28, 2025

bah, the backport of the patch is not complete and missing a define, need to rework this.

@tfloch
Copy link

tfloch commented Apr 28, 2025

bah, the backport of the patch is not complete and missing a define, need to rework this.

Sorry, I didn't see the cherry-picked commit has dependencies.

ALIGN_SIZE is defined here: zephyrproject-rtos/newlib-cygwin@754386c#diff-92c1b50fe2a59e115ab2999c1a584cddaaac8934719481384fc48469453a0af5R111-R115

@tfloch
Copy link

tfloch commented Apr 28, 2025

Error fixed in [newlib] PR zephyrproject-rtos/newlib-cygwin#9.

sdk-ng CI pipeline should be OK now: https://github.com/zephyrproject-rtos/sdk-ng/pull/894/checks

Sorry for that!

Fixes CVE-2021-3420
Fixes zephyrproject-rtos#892

Signed-off-by: Anas Nashif <anas.nashif@intel.com>
@nashif nashif merged commit dffeb0c into zephyrproject-rtos:main May 1, 2025
39 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

newlib 3.3.0 is vulnerable to CVE-2021-3420

5 participants