summaryrefslogtreecommitdiff
path: root/board/freescale/t208xrdb/t2080_pbi.cfg
diff options
context:
space:
mode:
authorChin Liang See <chin.liang.see@intel.com>2020-06-24 16:31:08 +0800
committerTom Rini <trini@konsulko.com>2020-07-17 08:51:29 -0400
commit499b7493e7a4d8c9171ff14accafe5a5b22cf00c (patch)
tree154a93e18a9d1e2e77bbe0066ba7166736cc51b7 /board/freescale/t208xrdb/t2080_pbi.cfg
parentb4d14bc81ad580000277deae5d51e3e3ef09875f (diff)
lib: zlib: Remove offset pointer optimization in inftrees.c
This fixes the CVE-2016-9840. Commit imported from [1]. inftrees.c was subtracting an offset from a pointer to an array, in order to provide a pointer that allowed indexing starting at the offset. This is not compliant with the C standard, for which the behavior of a pointer decremented before its allocated memory is undefined. Per the recommendation of a security audit of the zlib code by Trail of Bits and TrustInSoft, in support of the Mozilla Foundation, this tiny optimization was removed, in order to avoid the possibility of undefined behavior. [1]: https://github.com/madler/zlib/commit/6a043145ca6e9c55184013841a67b2fef87e44c0 Signed-off-by: Mark Adler <madler@alumni.caltech.edu> Signed-off-by: Chin Liang See <chin.liang.see@intel.com> Signed-off-by: Ley Foon Tan <ley.foon.tan@intel.com>
Diffstat (limited to 'board/freescale/t208xrdb/t2080_pbi.cfg')
0 files changed, 0 insertions, 0 deletions