Richard Purdie <[email protected]> writes: > Sadly, I suspect this is becoming all the more common and I share your > frustrations. > > We have an difficult position on whether to take things or not as we > probably don't have the time/experience to tell in many cases and not > taking a CVE fix means we'd get beaten over the head with the patch for > ever more as "there is a security problem" :(.
Perfectly understandable. By the way, I suggest applying this patch as well [1]. In the 9.11 release, short writes could cause issues with 'tee'. It was a silly mistake on my part, and cause SUSE some issues. The patch applies with NEWS removed. E.g., like this: $ sed '1,49d' 0d6fcb99d691d920961938e61c43478566ef626e.patch > fix.patch $ patch -p1 < fix.patch Collin [1] https://github.com/coreutils/coreutils/commit/0d6fcb99d691d920961938e61c43478566ef626e.patch
-=-=-=-=-=-=-=-=-=-=-=- Links: You receive all messages sent to this group. View/Reply Online (#242478): https://lists.openembedded.org/g/openembedded-core/message/242478 Mute This Topic: https://lists.openembedded.org/mt/120532929/21656 Group Owner: [email protected] Unsubscribe: https://lists.openembedded.org/g/openembedded-core/unsub [[email protected]] -=-=-=-=-=-=-=-=-=-=-=-
