Merge pull request #230947 from NixOS/cve-2023-32233

linux_*, except testing, 4.14: apply patch for CVE-2023-32233

authored by Ryan Lahfa and committed by GitHub 1e8ab5db 4b36fe99

+19
+9
pkgs/os-specific/linux/kernel/patches.nix
··· 62 name = "fix-em-ice-bonding"; 63 patch = ./fix-em-ice-bonding.patch; 64 }; 65 }
··· 62 name = "fix-em-ice-bonding"; 63 patch = ./fix-em-ice-bonding.patch; 64 }; 65 + 66 + CVE-2023-32233 = rec { 67 + name = "CVE-2023-32233"; 68 + patch = fetchpatch { 69 + name = name + ".patch"; 70 + url = "https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=c1592a89942e9678f7d9c8030efa777c0d57edab"; 71 + hash = "sha256-DYPWgraXPNeFkjtuDYkFXHnCJ4yDewrukM2CCAqC2BE="; 72 + }; 73 + }; 74 }
+10
pkgs/top-level/linux-kernels.nix
··· 115 [ kernelPatches.bridge_stp_helper 116 kernelPatches.request_key_helper 117 kernelPatches.modinst_arg_list_too_long 118 ]; 119 }; 120 ··· 123 kernelPatches.bridge_stp_helper 124 kernelPatches.request_key_helper 125 kernelPatches.rtl8761b_support 126 ]; 127 }; 128 ··· 130 kernelPatches = [ 131 kernelPatches.bridge_stp_helper 132 kernelPatches.request_key_helper 133 ]; 134 }; 135 ··· 137 kernelPatches = [ 138 kernelPatches.bridge_stp_helper 139 kernelPatches.request_key_helper 140 ]; 141 }; 142 ··· 145 kernelPatches.bridge_stp_helper 146 kernelPatches.request_key_helper 147 kernelPatches.export-rt-sched-migrate 148 ]; 149 }; 150 ··· 153 kernelPatches.bridge_stp_helper 154 kernelPatches.request_key_helper 155 kernelPatches.fix-em-ice-bonding 156 ]; 157 }; 158 ··· 169 kernelPatches.bridge_stp_helper 170 kernelPatches.request_key_helper 171 kernelPatches.fix-em-ice-bonding 172 ]; 173 }; 174 ··· 178 kernelPatches.request_key_helper 179 kernelPatches.fix-em-ice-bonding 180 kernelPatches.export-rt-sched-migrate 181 ]; 182 }; 183 ··· 186 kernelPatches.bridge_stp_helper 187 kernelPatches.request_key_helper 188 kernelPatches.fix-em-ice-bonding 189 ]; 190 }; 191 ··· 194 kernelPatches.bridge_stp_helper 195 kernelPatches.request_key_helper 196 kernelPatches.fix-em-ice-bonding 197 ]; 198 }; 199
··· 115 [ kernelPatches.bridge_stp_helper 116 kernelPatches.request_key_helper 117 kernelPatches.modinst_arg_list_too_long 118 + kernelPatches.CVE-2023-32233 119 ]; 120 }; 121 ··· 124 kernelPatches.bridge_stp_helper 125 kernelPatches.request_key_helper 126 kernelPatches.rtl8761b_support 127 + kernelPatches.CVE-2023-32233 128 ]; 129 }; 130 ··· 132 kernelPatches = [ 133 kernelPatches.bridge_stp_helper 134 kernelPatches.request_key_helper 135 + kernelPatches.CVE-2023-32233 136 ]; 137 }; 138 ··· 140 kernelPatches = [ 141 kernelPatches.bridge_stp_helper 142 kernelPatches.request_key_helper 143 + kernelPatches.CVE-2023-32233 144 ]; 145 }; 146 ··· 149 kernelPatches.bridge_stp_helper 150 kernelPatches.request_key_helper 151 kernelPatches.export-rt-sched-migrate 152 + kernelPatches.CVE-2023-32233 153 ]; 154 }; 155 ··· 158 kernelPatches.bridge_stp_helper 159 kernelPatches.request_key_helper 160 kernelPatches.fix-em-ice-bonding 161 + kernelPatches.CVE-2023-32233 162 ]; 163 }; 164 ··· 175 kernelPatches.bridge_stp_helper 176 kernelPatches.request_key_helper 177 kernelPatches.fix-em-ice-bonding 178 + kernelPatches.CVE-2023-32233 179 ]; 180 }; 181 ··· 185 kernelPatches.request_key_helper 186 kernelPatches.fix-em-ice-bonding 187 kernelPatches.export-rt-sched-migrate 188 + kernelPatches.CVE-2023-32233 189 ]; 190 }; 191 ··· 194 kernelPatches.bridge_stp_helper 195 kernelPatches.request_key_helper 196 kernelPatches.fix-em-ice-bonding 197 + kernelPatches.CVE-2023-32233 198 ]; 199 }; 200 ··· 203 kernelPatches.bridge_stp_helper 204 kernelPatches.request_key_helper 205 kernelPatches.fix-em-ice-bonding 206 + kernelPatches.CVE-2023-32233 207 ]; 208 }; 209