[23.11] python311Packages.uamqp: add patches for CVE-2024-25110 & CVE-2024-27099 #293099
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Description of changes
https://nvd.nist.gov/vuln/detail/CVE-2024-25110
https://nvd.nist.gov/vuln/detail/CVE-2024-27099
Backport from #293035 not quite as simple as I'd hoped - CVE-2024-25110's patch depends on a file in the vendored
azure-uamqp-c
's vendoredazure-c-shared-utility
which wasn't present in python-uamqp 1.6.5. Ended up having to include the patch adding it in-tree becausefetchpatch
will helpfully add anextraPrefix
to all paths - including/dev/null
- meaning theincludes
option won't be able to find files that are created in that patch.Things done
nix.conf
? (See Nix manual)sandbox = relaxed
sandbox = true
nix-shell -p nixpkgs-review --run "nixpkgs-review rev HEAD"
. Note: all changes have to be committed, also see nixpkgs-review usage./result/bin/
)Add a 👍 reaction to pull requests you find important.