From be04d4198f4fe81e459dbed77db58ee937eafc64 Mon Sep 17 00:00:00 2001 From: Robert Scott Date: Fri, 2 Apr 2021 23:59:54 +0100 Subject: [PATCH] bind: add patch for CVE-2020-8622 fixes available for the 9.11 and 9.16 series are near identical, apart from the presence of an extra null-check in the 9.11 patch. conservatively went with the 9.11 version to include the check. --- pkgs/servers/dns/bind/default.nix | 5 +++++ 1 file changed, 5 insertions(+) diff --git a/pkgs/servers/dns/bind/default.nix b/pkgs/servers/dns/bind/default.nix index 9c6e532dc02c..f7440468868e 100644 --- a/pkgs/servers/dns/bind/default.nix +++ b/pkgs/servers/dns/bind/default.nix @@ -27,6 +27,11 @@ stdenv.mkDerivation rec { url = "https://gitlab.isc.org/isc-projects/bind9/commit/81514ff925dfc6e0c293745e0fc8320a8af95586.patch"; sha256 = "1h3p60xcxj1zd3ksqllhgr4z43li13n2famyvb8kyydycw0rhi4d"; }) + (fetchpatch { + name = "CVE-2020-8622.patch"; + url = "https://gitlab.isc.org/isc-projects/bind9/commit/6ed167ad0a647dff20c8cb08c944a7967df2d415.patch"; + sha256 = "1r191hvqabq8bpnik8hmx7qirghfv48fhrzzmiq8vbjmwkbvvjrj"; + }) ]; nativeBuildInputs = [ perl ];