From 7979cb54e653aadb5b88198a7874976be0cf7388 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Vladim=C3=ADr=20=C4=8Cun=C3=A1t?= Date: Sat, 5 May 2018 13:35:04 +0200 Subject: [PATCH] utillinux: patch CVE-2018-7738 (upstream) On nixpkgs master/staging we have 2.32 - that includes this patch. https://nvd.nist.gov/vuln/detail/CVE-2018-7738 claims 2.32-rc1 fixes this and upstream master hasn't changed umount completion except for this patch, so it has to be it. /cc #38994. --- pkgs/os-specific/linux/util-linux/default.nix | 5 +++++ 1 file changed, 5 insertions(+) diff --git a/pkgs/os-specific/linux/util-linux/default.nix b/pkgs/os-specific/linux/util-linux/default.nix index e8a2b3428496..17cef18fdd84 100644 --- a/pkgs/os-specific/linux/util-linux/default.nix +++ b/pkgs/os-specific/linux/util-linux/default.nix @@ -17,6 +17,11 @@ in stdenv.mkDerivation rec { patches = [ ./rtcwake-search-PATH-for-shutdown.patch + (fetchpatch { + name = "CVE-2018-7738.diff"; + url = "https://github.com/karelzak/util-linux/commit/75f03badd7ed9.diff"; + sha256 = "0b8x1s7b9bh9p8a99bpdgjbqzqwsvb7l7cf3yy83jip1c38p685w"; + }) ]; outputs = [ "bin" "dev" "out" "man" ];