Re: [PATCH] zlib: Port fix for CVE-2018-25032 to U-Boot

2022-06-07 Thread Tom Rini
On Tue, May 10, 2022 at 02:36:59PM -0400, Tom Rini wrote: > While our copy of zlib is missing upstream commit 263b1a05b04e ("Allow > deflatePrime() to insert bits in the middle of a stream.") we do have > Z_FIXED support, and so the majority of the code changes in 5c44459c3b28 > ("Fix a bug that c

[PATCH] zlib: Port fix for CVE-2018-25032 to U-Boot

2022-05-10 Thread Tom Rini
While our copy of zlib is missing upstream commit 263b1a05b04e ("Allow deflatePrime() to insert bits in the middle of a stream.") we do have Z_FIXED support, and so the majority of the code changes in 5c44459c3b28 ("Fix a bug that can crash deflate on some input when using Z_FIXED.") apply here dir