mirror of
https://github.com/NixOS/nixpkgs.git
synced 2026-10-02 13:00:23 +00:00
nats-streaming-server: add patch for CVE-2022-26652
This commit is contained in:
@@ -0,0 +1,41 @@
|
||||
Based on upstream's nats-server fix
|
||||
https://github.com/nats-io/nats-server/commit/b4128693ed61aa0c32179af07677bcf1d8301dcd
|
||||
with test changes removed, the path -> filepath changes omitted
|
||||
(as it is for the benefit of windows, which we don't really support)
|
||||
and re-targeted at the vendored copy.
|
||||
|
||||
--- a/vendor/github.com/nats-io/nats-server/v2/server/stream.go
|
||||
+++ b/vendor/github.com/nats-io/nats-server/v2/server/stream.go
|
||||
@@ -3620,6 +3619,17 @@
|
||||
}
|
||||
defer os.RemoveAll(sdir)
|
||||
|
||||
+ logAndReturnError := func() error {
|
||||
+ a.mu.RLock()
|
||||
+ err := fmt.Errorf("unexpected content (account=%s)", a.Name)
|
||||
+ if a.srv != nil {
|
||||
+ a.srv.Errorf("Stream restore failed due to %v", err)
|
||||
+ }
|
||||
+ a.mu.RUnlock()
|
||||
+ return err
|
||||
+ }
|
||||
+ sdirCheck := filepath.Clean(sdir) + string(os.PathSeparator)
|
||||
+
|
||||
tr := tar.NewReader(s2.NewReader(r))
|
||||
for {
|
||||
hdr, err := tr.Next()
|
||||
@@ -3629,7 +3639,13 @@
|
||||
if err != nil {
|
||||
return nil, err
|
||||
}
|
||||
- fpath := path.Join(sdir, filepath.Clean(hdr.Name))
|
||||
+ if hdr.Typeflag != tar.TypeReg && hdr.Typeflag != tar.TypeRegA {
|
||||
+ return nil, logAndReturnError()
|
||||
+ }
|
||||
+ fpath := filepath.Join(sdir, filepath.Clean(hdr.Name))
|
||||
+ if !strings.HasPrefix(fpath, sdirCheck) {
|
||||
+ return nil, logAndReturnError()
|
||||
+ }
|
||||
os.MkdirAll(filepath.Dir(fpath), defaultDirPerms)
|
||||
fd, err := os.OpenFile(fpath, os.O_CREATE|os.O_RDWR, 0600)
|
||||
if err != nil {
|
||||
@@ -14,6 +14,8 @@ buildGoPackage rec {
|
||||
sha256 = "sha256-VdYyui0fyoNf1q3M1xTg/UMlxIFABqAbqQaD0bLpKCY=";
|
||||
};
|
||||
|
||||
patches = [ ./2.2.1-CVE-2022-26652.patch ];
|
||||
|
||||
meta = {
|
||||
description = "NATS Streaming System Server";
|
||||
license = licenses.asl20;
|
||||
|
||||
Reference in New Issue
Block a user