mirror of
https://github.com/NixOS/nixpkgs.git
synced 2026-10-02 13:00:23 +00:00
dav1d: add patch for CVE-2023-32570
This commit is contained in:
23
pkgs/development/libraries/dav1d/1.0.0-CVE-2023-32570.patch
Normal file
23
pkgs/development/libraries/dav1d/1.0.0-CVE-2023-32570.patch
Normal file
@@ -0,0 +1,23 @@
|
||||
Based on upstream cf617fdae0b9bfabd27282854c8e81450d955efa, omitting one
|
||||
of the 3 fixed call sites because it doesn't exist in 1.0.0
|
||||
|
||||
diff --git a/src/thread_task.c b/src/thread_task.c
|
||||
index 53aa41e..cd85b1c 100644
|
||||
--- a/src/thread_task.c
|
||||
+++ b/src/thread_task.c
|
||||
@@ -695,6 +695,7 @@ void *dav1d_worker_task(void *data) {
|
||||
if (!--f->task_thread.task_counter && f->task_thread.done[0] &&
|
||||
(!uses_2pass || f->task_thread.done[1]))
|
||||
{
|
||||
+ error = atomic_load(&f->task_thread.error);
|
||||
dav1d_decode_frame_exit(f, error == 1 ? DAV1D_ERR(EINVAL) :
|
||||
error ? DAV1D_ERR(ENOMEM) : 0);
|
||||
f->n_tile_data = 0;
|
||||
@@ -811,6 +812,7 @@ void *dav1d_worker_task(void *data) {
|
||||
if (!--f->task_thread.task_counter &&
|
||||
f->task_thread.done[0] && (!uses_2pass || f->task_thread.done[1]))
|
||||
{
|
||||
+ error = atomic_load(&f->task_thread.error);
|
||||
dav1d_decode_frame_exit(f, error == 1 ? DAV1D_ERR(EINVAL) :
|
||||
error ? DAV1D_ERR(ENOMEM) : 0);
|
||||
f->n_tile_data = 0;
|
||||
@@ -20,6 +20,10 @@ stdenv.mkDerivation rec {
|
||||
sha256 = "sha256-RVr7NFVxY+6MBD8NV7eMW8TEWuCgcfqpula1o1VZe0o=";
|
||||
};
|
||||
|
||||
patches = [
|
||||
./1.0.0-CVE-2023-32570.patch
|
||||
];
|
||||
|
||||
nativeBuildInputs = [ meson ninja nasm pkg-config ];
|
||||
# TODO: doxygen (currently only HTML and not build by default).
|
||||
buildInputs = [ xxHash ]
|
||||
|
||||
Reference in New Issue
Block a user