From 88fd0ec3459df2f97eec0e4b0457034b293c6f70 Mon Sep 17 00:00:00 2001 From: Thomas Gerbet Date: Wed, 20 Jan 2021 21:17:39 +0100 Subject: [PATCH] cifs-utils: fix for CVE-2020-14342 Did not backport 033208fd46e03178655f3c4a59add1d9dbf57731 because of some behavior changes in the CLIs. The patch comes from the issue in the Samba bugtracker [0]. [0] https://bugzilla.samba.org/show_bug.cgi?id=14442 --- pkgs/os-specific/linux/cifs-utils/default.nix | 10 +++++++++- 1 file changed, 9 insertions(+), 1 deletion(-) diff --git a/pkgs/os-specific/linux/cifs-utils/default.nix b/pkgs/os-specific/linux/cifs-utils/default.nix index ad136b811df8..d48e541abfe7 100644 --- a/pkgs/os-specific/linux/cifs-utils/default.nix +++ b/pkgs/os-specific/linux/cifs-utils/default.nix @@ -1,5 +1,5 @@ { stdenv, fetchurl, autoreconfHook, docutils, pkgconfig -, kerberos, keyutils, pam, talloc }: +, kerberos, keyutils, pam, talloc, fetchpatch }: stdenv.mkDerivation rec { pname = "cifs-utils"; @@ -14,6 +14,14 @@ stdenv.mkDerivation rec { buildInputs = [ kerberos keyutils pam talloc ]; + patches = [ + (fetchpatch { + name = "CVE-2020-14342.patch"; + url = "https://attachments.samba.org/attachment.cgi?id=16148"; + sha256 = "1xw3d11wb1l8a89jhdp6hhy987nq0gafxfhx5jdhcc5nazahc7s4"; + }) + ]; + makeFlags = [ "root_sbindir=$(out)/sbin" ]; meta = with stdenv.lib; {