mirror of
https://github.com/NixOS/nixpkgs.git
synced 2026-10-01 20:45:12 +00:00
perlPackages.JSONXS: 4.03 -> 4.04
4.04 contains the upstream fix for CVE-2025-40928.
Assisted-by: Claude Code (Claude Opus 5)
Signed-off-by: Stig Palmquist <git@stig.io>
(cherry picked from commit eb5ca22318)
This commit is contained in:
committed by
Marcus Ramberg
parent
f5e9e9b4be
commit
6004c4f5d2
@@ -1,31 +0,0 @@
|
||||
--- a/XS.xs 2025-09-06 08:34:51.376455632 -0300
|
||||
+++ b/XS.xs 2025-09-06 08:35:30.725873619 -0300
|
||||
@@ -253,16 +253,16 @@
|
||||
// if we recurse too deep, skip all remaining digits
|
||||
// to avoid a stack overflow attack
|
||||
if (expect_false (--maxdepth <= 0))
|
||||
- while (((U8)*s - '0') < 10)
|
||||
+ while ((U8)(*s - '0') < 10)
|
||||
++s;
|
||||
|
||||
for (;;)
|
||||
{
|
||||
- U8 dig = (U8)*s - '0';
|
||||
+ U8 dig = *s - '0';
|
||||
|
||||
if (expect_false (dig >= 10))
|
||||
{
|
||||
- if (dig == (U8)((U8)'.' - (U8)'0'))
|
||||
+ if (dig == (U8)('.' - '0'))
|
||||
{
|
||||
++s;
|
||||
json_atof_scan1 (s, accum, expo, 1, maxdepth);
|
||||
@@ -282,7 +282,7 @@
|
||||
else if (*s == '+')
|
||||
++s;
|
||||
|
||||
- while ((dig = (U8)*s - '0') < 10)
|
||||
+ while ((dig = (U8)(*s - '0')) < 10)
|
||||
exp2 = exp2 * 10 + *s++ - '0';
|
||||
|
||||
*expo += neg ? -exp2 : exp2;
|
||||
@@ -18668,12 +18668,11 @@ with self;
|
||||
|
||||
JSONXS = buildPerlPackage {
|
||||
pname = "JSON-XS";
|
||||
version = "4.03";
|
||||
version = "4.04";
|
||||
src = fetchurl {
|
||||
url = "mirror://cpan/authors/id/M/ML/MLEHMANN/JSON-XS-4.03.tar.gz";
|
||||
hash = "sha256-UVU29F8voafojIgkUzdY0BIdJnq5y0U6G1iHyKVrkGg=";
|
||||
url = "mirror://cpan/authors/id/M/ML/MLEHMANN/JSON-XS-4.04.tar.gz";
|
||||
hash = "sha256-jv8enzBMViW1mre0IlhBX20+NoHB3atrclUYoBin9eA=";
|
||||
};
|
||||
patches = [ ../development/perl-modules/JSON-XS-CVE-2025-40928.patch ];
|
||||
propagatedBuildInputs = [ TypesSerialiser ];
|
||||
buildInputs = [ CanaryStability ];
|
||||
meta = {
|
||||
|
||||
Reference in New Issue
Block a user