From 610b395424c02274800d85585cb542ad66d9afea Mon Sep 17 00:00:00 2001 From: Efraim Flashner Date: Thu, 19 Sep 2024 09:57:10 +0300 Subject: gnu: expat: Fix security vulnerabilities. Fixes CVE-2024-45490, CVE-2024-45491, CVE-2024-45492. * gnu/packages/xml.scm (expat)[replacement]: New field. (expat/fixed): New variable. * gnu/packages/patches/expat-CVE-2024-45490.patch, gnu/packages/patches/expat-CVE-2024-45491.patch, gnu/packages/patches/expat-CVE-2024-45492.patch: New files. * gnu/local.mk (dist_patch_DATA): Register them. Change-Id: I74d5d7bce98d6c983b989c1afec7cf28777d1617 --- gnu/local.mk | 3 +++ 1 file changed, 3 insertions(+) (limited to 'gnu/local.mk') diff --git a/gnu/local.mk b/gnu/local.mk index fcdf174099..bdc740ead6 100644 --- a/gnu/local.mk +++ b/gnu/local.mk @@ -1205,6 +1205,9 @@ dist_patch_DATA = \ %D%/packages/patches/esmtp-add-lesmtp.patch \ %D%/packages/patches/eudev-rules-directory.patch \ %D%/packages/patches/exercism-disable-self-update.patch \ + %D%/packages/patches/expat-CVE-2024-45490.patch \ + %D%/packages/patches/expat-CVE-2024-45491.patch \ + %D%/packages/patches/expat-CVE-2024-45492.patch \ %D%/packages/patches/extempore-unbundle-external-dependencies.patch \ %D%/packages/patches/extundelete-e2fsprogs-1.44.patch \ %D%/packages/patches/fail2ban-0.11.2_CVE-2021-32749.patch \ -- cgit v1.2.3