From 4cf5cc0f5a186b7a97fcfea02bde7211c4547a80 Mon Sep 17 00:00:00 2001 From: zhouwenpei Date: Mon, 26 Jul 2021 16:50:51 +0800 Subject: [PATCH] modified the patch description --- CVE-2021-22918.patch | 29 +++++++++++++++++++++++++---- nodejs.spec | 5 ++++- 2 files changed, 29 insertions(+), 5 deletions(-) diff --git a/CVE-2021-22918.patch b/CVE-2021-22918.patch index 6c1af63..62083ba 100644 --- a/CVE-2021-22918.patch +++ b/CVE-2021-22918.patch @@ -1,8 +1,29 @@ -From e2487cfd6fc4dd29bca549bd8d40c61c83a2816c Mon Sep 17 00:00:00 2001 -From: zwx1052249 -Date: Mon, 19 Jul 2021 18:51:54 +0800 -Subject: [PATCH] CVE-2021-22918.patch +From d33aead28bcec32a2a450f884907a6d971631829 Mon Sep 17 00:00:00 2001 +From: Ben Noordhuis +Date: Fri, 21 May 2021 11:23:36 +0200 +Subject: [PATCH] deps: uv: cherry-pick 99c29c9c2c9b +Original commit message: + + idna: fix OOB read in punycode decoder + + Reported by Eric Sesterhenn in collaboration with + Cure53 and ExpressVPN. + + Deleted unintroduced test files. + + Reported-By: Eric Sesterhenn + PR-URL: https://github.com/libuv/libuv-private/pull/1 + Reviewed-By: Colin Ihrig + Reviewed-By: Richard Lau + +CVE-ID: CVE-2021-22918 +Refs: https://hackerone.com/reports/1209681 +PR-URL: https://github.com/nodejs-private/node-private/pull/267 +Reviewed-By: Matteo Collina +Reviewed-By: Richard Lau +Reviewed-By: Michael Dawson +Reviewed-By: Beth Griggs --- deps/uv/src/idna.c | 49 ++++++++++++++++++++++++++++++++++------------ 1 file changed, 36 insertions(+), 13 deletions(-) diff --git a/nodejs.spec b/nodejs.spec index 7e802b8..9dd75af 100644 --- a/nodejs.spec +++ b/nodejs.spec @@ -1,5 +1,5 @@ %bcond_with bootstrap -%global baserelease 8 +%global baserelease 9 %{?!_pkgdocdir:%global _pkgdocdir %{_docdir}/%{name}-%{version}} %global nodejs_epoch 1 %global nodejs_major 10 @@ -466,6 +466,9 @@ end %changelog +* Mon Jul 26 2021 zhouwenpei 1:10.21.0-9 +- modified the patch description + * Mon Jul 19 2021 zhouwenpei 1:10.21.0-8 - fix CVE-2021-22918 -- Gitee