u-boot (2021.01+dfsg-5+deb11u1) bullseye-security; urgency=medium
authorDaniel Leidert <dleidert@debian.org>
Wed, 30 Apr 2025 23:19:02 +0000 (01:19 +0200)
committerDaniel Leidert <dleidert@debian.org>
Wed, 30 Apr 2025 23:19:02 +0000 (01:19 +0200)
commit1b1f7d717383c99663b58239ee7994d99eb58ca0
tree977fe43d50e6bb691b87aefd199ae26d85085366
parentdf707a8698e63750556f5c63fb92f9ffa529af0e
parent6e957e1b79acec86b58e4bc94730265fa29c6e29
u-boot (2021.01+dfsg-5+deb11u1) bullseye-security; urgency=medium

  * Non-maintainer upload by the Debian LTS team.
  * d/patches/CVE-2022-34835.patch: Add patch to fix CVE-2022-34835.
    - Fix an integer signedness error and resultant stack-based buffer overflow
      in the 'i2c md' command that enables the corruption of the return address
      pointer of the do_i2c_md function (closes: #1014529).
  * d/patches/CVE-2022-33967.patch: Add patch to fix CVE-2022-33967.
    - Fix a heap-based buffer overflow vulnerability due to a defect in the
      metadata reading process which may lead to a denial-of-service (DoS)
      condition or arbitrary code execution by loading a specially crafted
      squashfs image.
  * d/patches/CVE-2022-33103.patch: Add patch to fix CVE-2022-33103.
    - Fix an an out-of-bounds write (closes: #1014528).
  * d/patches/CVE-2022-30790.patch: Add patch to fix CVE-2022-30790 and
    CVE-2022-30552.
    - Fix a a Buffer Overflow (closes: #1014470).
  * d/patches/CVE-2022-30767.patch: Add patch to fix CVE-2022-30767.
    - Fix an unbounded memcpy with a failed length check, leading to a buffer
      overflow. This issue exists due to an incorrect fix for CVE-2019-14196
      (closes: #1014471).
  * d/patches/CVE-2022-2347.patch: Add patch to fix CVE-2022-2347.
    - Fix an unchecked length field leading to a heap overflow
      (closes: #1014959).
  * d/patches/CVE-2024-57254.patch: Add patch to fix CVE-2024-57254.
    - Fix an integer overflow in sqfs_inode_size (closes: 1098254).
  * d/patches/CVE-2024-57255.patch: Add patch to fix CVE-2024-57255.
    - Fix an integer overflow in sqfs_resolve_symlink (closes: #1098254).
  * d/patches/CVE-2024-57256.patch: Add patch to fix CVE-2024-57256.
    - Fix an integer overflow in ext4fs_read_symlink (closes: #1098254).
  * d/patches/CVE-2024-57257.patch: Add patch to fix CVE-2024-57257.
    - Fix a stack consumption issue in sqfs_size possible with deep symlink
      nesting (closes: #1098254).
  * d/patches/CVE-2024-57258-1.patch, d/patches/CVE-2024-57258-2.patch,
    d/patches/CVE-2024-57258-3.patch: Add patches to fx CVE-2024-57258.
    - Fix multiple integer overflows (closes: #1098254).
  * d/patches/CVE-2024-57259.patch: Add patch to fix CVE-2024-57259.
    - Fix an off-by-one error resulting in a heap memory corruption in
      sqfs_search_dir (closes: #1098254).

[dgit import unpatched u-boot 2021.01+dfsg-5+deb11u1]
113 files changed:
debian/bin/generate-qcom
debian/bin/u-boot-install-rockchip
debian/bin/u-boot-install-sunxi
debian/bin/u-boot-install-targets
debian/bin/update-lintian-overrides
debian/bin/update-substvars
debian/changelog
debian/control
debian/copyright
debian/env-configs/efikamx.config
debian/env-configs/guruplug.config
debian/env-configs/kurobox_pro.config
debian/env-configs/linkstation-mini.config
debian/env-configs/linkstation_pro_live.config
debian/env-configs/lsmipsel.config
debian/env-configs/lsppchg.config
debian/env-configs/mx6cuboxi.config
debian/env-configs/openmoko_gta01.config
debian/env-configs/openmoko_gta02.config
debian/env-configs/openrd.config
debian/env-configs/qnap_ts101.config
debian/env-configs/qnap_ts109-209.config
debian/env-configs/qnap_ts119-219.config
debian/env-configs/sheevaplug.config
debian/env-configs/udoo_quad.config
debian/env-configs/wandboard.config
debian/gbp.conf
debian/manpages/u-boot-install-sunxi.8
debian/patches/CVE-2022-2347.patch
debian/patches/CVE-2022-30767.patch
debian/patches/CVE-2022-30790.patch
debian/patches/CVE-2022-33103.patch
debian/patches/CVE-2022-33967.patch
debian/patches/CVE-2022-34835.patch
debian/patches/CVE-2024-57254.patch
debian/patches/CVE-2024-57255.patch
debian/patches/CVE-2024-57256.patch
debian/patches/CVE-2024-57257.patch
debian/patches/CVE-2024-57258-1.patch
debian/patches/CVE-2024-57258-2.patch
debian/patches/CVE-2024-57258-3.patch
debian/patches/CVE-2024-57259.patch
debian/patches/add-debian-revision-to-u-boot-version
debian/patches/am57xx/omap5_distro_bootcmd
debian/patches/arndale/board-spl-rule.diff
debian/patches/ensure-config-sandbox-for-make-env.patch
debian/patches/exynos/0001-arm-config-fix-default-console-only-to-specify-the-d.patch
debian/patches/mx53loco
debian/patches/n900/bootz_and_raw_initrd.patch
debian/patches/pinetab/0001-configs-add-PineTab-defconfig.patch
debian/patches/riscv64/qemu-riscv64_smode-sifive-fu540-fix-extlinux-define-.patch
debian/patches/rk3399/disable-preboot
debian/patches/series
debian/patches/test-imagetools-test-fixes
debian/patches/tools-generic-builds.patch
debian/patches/upstream/0001-efi_loader-switch-to-non-secure-mode-later.patch
debian/rules
debian/source/format
debian/source/include-binaries
debian/targets
debian/u-boot-amlogic.docs
debian/u-boot-amlogic.install
debian/u-boot-amlogic.lintian-overrides
debian/u-boot-exynos.docs
debian/u-boot-exynos.install
debian/u-boot-exynos.lintian-overrides
debian/u-boot-imx.README.Debian
debian/u-boot-imx.install
debian/u-boot-imx.links
debian/u-boot-imx.lintian-overrides
debian/u-boot-mvebu.docs
debian/u-boot-mvebu.install
debian/u-boot-mvebu.lintian-overrides
debian/u-boot-omap.README.Debian
debian/u-boot-omap.docs
debian/u-boot-omap.install
debian/u-boot-omap.lintian-overrides
debian/u-boot-qcom.README.Debian
debian/u-boot-qcom.install
debian/u-boot-qcom.lintian-overrides
debian/u-boot-qemu.README.Debian
debian/u-boot-qemu.install
debian/u-boot-qemu.lintian-overrides
debian/u-boot-rockchip.NEWS
debian/u-boot-rockchip.README.Debian
debian/u-boot-rockchip.docs
debian/u-boot-rockchip.install
debian/u-boot-rockchip.lintian-overrides
debian/u-boot-rpi.README.Debian
debian/u-boot-rpi.install
debian/u-boot-rpi.lintian-overrides
debian/u-boot-sifive.docs
debian/u-boot-sifive.install
debian/u-boot-sifive.lintian-overrides
debian/u-boot-sunxi.README.Debian
debian/u-boot-sunxi.docs
debian/u-boot-sunxi.install
debian/u-boot-sunxi.links
debian/u-boot-sunxi.lintian-overrides
debian/u-boot-sunxi.manpages
debian/u-boot-tegra.README.Debian
debian/u-boot-tegra.install
debian/u-boot-tegra.links.arm64
debian/u-boot-tegra.lintian-overrides
debian/u-boot-tools.docs
debian/u-boot-tools.examples
debian/u-boot-tools.install
debian/u-boot-tools.manpages
debian/u-boot.README.Debian
debian/u-boot.install
debian/u-boot.lintian-overrides
debian/upstream/signing-key.asc
debian/watch