Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[qtbase] apply official patch for CVE-2023-38197 #32797

Conversation

carsten-grimm-at-ipolog
Copy link
Contributor

Fixes #32796

  • Changes comply with the maintainer guide
  • SHA512s are updated for each updated download
  • The "supports" clause reflects platforms that may be fixed by this new version
  • Any fixed CI baseline entries are removed from that file.
  • Any patches that are no longer applied are deleted from the port's directory.
  • The version database is fixed by rerunning ./vcpkg x-add-version --all and committing the result.
  • Only one version is added to each modified port's versions file.

The patch is the official patch for the issue from Qt: https://download.qt.io/official_releases/qt/6.5/

@jimwang118 jimwang118 self-assigned this Jul 28, 2023
@carsten-grimm-at-ipolog carsten-grimm-at-ipolog marked this pull request as ready for review July 28, 2023 06:59
@jimwang118
Copy link
Contributor

Note: I will be converting your PR to draft status. When the CI run ends, please revert to "ready for review". That way, I will review this PR.

@jimwang118 jimwang118 added the category:port-feature The issue is with a library, which is requesting new capabilities that didn’t exist label Jul 28, 2023
@carsten-grimm-at-ipolog carsten-grimm-at-ipolog marked this pull request as draft July 28, 2023 12:09
@carsten-grimm-at-ipolog carsten-grimm-at-ipolog marked this pull request as ready for review July 28, 2023 15:00
@BillyONeal BillyONeal merged commit 8b04a7b into microsoft:master Jul 28, 2023
15 checks passed
@BillyONeal
Copy link
Member

Thanks for the patch!

@carsten-grimm-at-ipolog
Copy link
Contributor Author

Thanks for the patch!

There is no need to thank me, the patch is from Qt! I am just adding it here :-)

@jimwang118 jimwang118 added the info:reviewed Pull Request changes follow basic guidelines label Jul 31, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
category:port-feature The issue is with a library, which is requesting new capabilities that didn’t exist info:reviewed Pull Request changes follow basic guidelines
Projects
None yet
Development

Successfully merging this pull request may close these issues.

[qtbase] lacks fix for CVE-2023-38197
3 participants