From a703a04256beb3d73d3f975e06e53a51a27cce3a Mon Sep 17 00:00:00 2001 From: Arthur Gautier Date: Wed, 1 Mar 2023 08:32:25 -0800 Subject: [PATCH] libtpms: 0.9.5 -> 0.9.6 tpm2: Check size of buffer before accessing it (CVE-2023-1017 & CVE-2023-1018) --- pkgs/tools/security/libtpms/default.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/tools/security/libtpms/default.nix b/pkgs/tools/security/libtpms/default.nix index 558c0fd0c37..a7249481454 100644 --- a/pkgs/tools/security/libtpms/default.nix +++ b/pkgs/tools/security/libtpms/default.nix @@ -7,13 +7,13 @@ stdenv.mkDerivation rec { pname = "libtpms"; - version = "0.9.5"; + version = "0.9.6"; src = fetchFromGitHub { owner = "stefanberger"; repo = "libtpms"; rev = "v${version}"; - sha256 = "sha256-gA3tXsrJgk0WCI2rKy81f3PrGu/Ml1WExJ0P9AzLQ+c="; + sha256 = "sha256-I2TYuOLwgEm6ofF2onWI7j2yu9wpXxNt7lJePSpF9VM="; }; nativeBuildInputs = [