From b0c311d784e939342c4bfa771790a0113fc7a704 Mon Sep 17 00:00:00 2001 From: Changqing Li Date: Tue, 14 Sep 2021 12:35:50 +0800 Subject: sqlite3: fix CVE-2021-36690 refer: https://nvd.nist.gov/vuln/detail/CVE-2021-36690 https://www.sqlite.org/forum/forumpost/718c0a8d17 https://sqlite.org/src/info/b1e0c22ec981cf5f Signed-off-by: Changqing Li Signed-off-by: Anuj Mittal --- meta/recipes-support/sqlite/sqlite3_3.35.0.bb | 4 +++- 1 file changed, 3 insertions(+), 1 deletion(-) (limited to 'meta/recipes-support/sqlite/sqlite3_3.35.0.bb') diff --git a/meta/recipes-support/sqlite/sqlite3_3.35.0.bb b/meta/recipes-support/sqlite/sqlite3_3.35.0.bb index 127065bbc1..8b2732640f 100644 --- a/meta/recipes-support/sqlite/sqlite3_3.35.0.bb +++ b/meta/recipes-support/sqlite/sqlite3_3.35.0.bb @@ -3,7 +3,9 @@ require sqlite3.inc LICENSE = "PD" LIC_FILES_CHKSUM = "file://sqlite3.h;endline=11;md5=786d3dc581eff03f4fd9e4a77ed00c66" -SRC_URI = "http://www.sqlite.org/2021/sqlite-autoconf-${SQLITE_PV}.tar.gz" +SRC_URI = "http://www.sqlite.org/2021/sqlite-autoconf-${SQLITE_PV}.tar.gz \ + file://CVE-2021-36690.patch \ +" SRC_URI[sha256sum] = "3dfb3f143c83695a555c7dd9e06ed924f9d273c287989874e102656724baf2d0" # -19242 is only an issue in specific development branch commits -- cgit 1.2.3-korg