[PATCH][binutils][2_44] Backport Replace xmalloc with stat_alloc in ld parser (CVE-2025-1148)
Jan Beulich
jbeulich@suse.com
Thu Mar 13 10:40:08 GMT 2025
On 13.03.2025 10:39, Sadineni, Harish wrote:
>>> This isn't quite right, is it? The author of a backport is usually still ...
>>> ... the original author.
>
> Alright, I will add the "Signed-off-by: Modra amodra@gmail.com" before mine.
I don't think you may take an S-o-b out of thin air. It's From: that you want
to adjust.
>>> As indicated when the more general question was raised, I think what's missing
>>> here is a (good) justification for putting this on a stable branch. It's a
>>> relatively large change for a relatively low priority bug. Unless of course
>>> you know facts beyond what is stated there. Without extra justification
>>> personally I'd reject this; I'm happy for Nick or Alan to override me, though.
>
> Since we are backporting, I have used the same commit message. Could you kindly clarify what type of justification should be added?.
See my earlier reply on the matter: A post-commit-message remark may be what's
best to use in such a case. However, ...
> There are four CVEs associated with this bug (32576):
> https://nvd.nist.gov/vuln/detail/CVE-2025-1148
> https://nvd.nist.gov/vuln/detail/CVE-2025-1150
> https://nvd.nist.gov/vuln/detail/CVE-2025-1151
> https://nvd.nist.gov/vuln/detail/CVE-2025-1152
... there being whatever number of CVEs isn't a sufficient justification, imo.
CVEs, sadly, vary greatly in how important (and sometimes even relevant) it is
that they cover.
Jan
More information about the Binutils
mailing list