Skip to content

Commit 10c3059

Browse files
eltricoskraj
authored andcommitted
openjpeg: fix CVE-2022-1122
CVE: CVE-2022-1122 The defect is undergoing reanalysis and there may be follow-up commits. Ref: * uclouvain/openjpeg#1368 Signed-off-by: Nicolas Marguet <[email protected]> Signed-off-by: Khem Raj <[email protected]>
1 parent 04d196e commit 10c3059

File tree

2 files changed

+32
-0
lines changed

2 files changed

+32
-0
lines changed
Lines changed: 31 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,31 @@
1+
Upstream-Status: Backport [https://github.com/uclouvain/openjpeg/commit/0afbdcf3e6d0d2bd2e16a0c4d513ee3cf86e460d]
2+
CVE: CVE-2022-1122
3+
4+
While this patch improves things re-CVE-2022-1122, the defect is undergoing re-analysis and there may be follow-up commits.
5+
6+
From 0afbdcf3e6d0d2bd2e16a0c4d513ee3cf86e460d Mon Sep 17 00:00:00 2001
7+
From: xiaoxiaoafeifei <[email protected]>
8+
Date: Wed, 14 Jul 2021 09:35:13 +0800
9+
Subject: [PATCH] Fix segfault in src/bin/jp2/opj_decompress.c due to
10+
uninitialized pointer (fixes #1368) (#1369)
11+
12+
---
13+
src/bin/jp2/opj_decompress.c | 2 +-
14+
1 file changed, 1 insertion(+), 1 deletion(-)
15+
16+
diff --git a/src/bin/jp2/opj_decompress.c b/src/bin/jp2/opj_decompress.c
17+
index 0e028735..18ead672 100644
18+
--- a/src/bin/jp2/opj_decompress.c
19+
+++ b/src/bin/jp2/opj_decompress.c
20+
@@ -1356,7 +1356,7 @@ int main(int argc, char **argv)
21+
int it_image;
22+
num_images = get_num_images(img_fol.imgdirpath);
23+
24+
- dirptr = (dircnt_t*)malloc(sizeof(dircnt_t));
25+
+ dirptr = (dircnt_t*)calloc(1, sizeof(dircnt_t));
26+
if (!dirptr) {
27+
destroy_parameters(&parameters);
28+
return EXIT_FAILURE;
29+
--
30+
2.25.1
31+

meta-oe/recipes-graphics/openjpeg/openjpeg_2.4.0.bb

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -10,6 +10,7 @@ SRC_URI = " \
1010
file://0002-Do-not-ask-cmake-to-export-binaries-they-don-t-make-.patch \
1111
file://0001-This-patch-fixed-include-dir-to-usr-include-.-Obviou.patch \
1212
file://CVE-2021-29338.patch \
13+
file://CVE-2022-1122.patch \
1314
"
1415
SRCREV = "37ac30ceff6640bbab502388c5e0fa0bff23f505"
1516
S = "${WORKDIR}/git"

0 commit comments

Comments
 (0)