-
-
Notifications
You must be signed in to change notification settings - Fork 15.1k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
curl: add patches for CVE-2021-22897, CVE-2021-22898 & CVE-2021-22901 #124982
Conversation
Result of 163 packages marked as broken and skipped:
22187 packages skipped due to time constraints:
44 packages built successfully:
3 suggestions:
|
Did we consider leaving an older version of curl just for darwin? |
I think we'd have to be in a considerably deeper hole before we considered something like that. We'd be committing to backporting security fixes for a longer term and the version split would be ... weird. |
Successfully created backport PR #125309 for |
Motivation for this change
The bump covering these CVEs, #124502, has some complications around darwin support. Patching these vulnerabilities would allow us to come up with a solution without the security monkey on our backs.
Patches for curl need to be taken in-repo, and CVE-2021-22901's additionally need some adjustment.
Things done
sandbox
innix.conf
on non-NixOS linux)nix-shell -p nixpkgs-review --run "nixpkgs-review wip"
./result/bin/
)