HomeFreeBSD

lz4: Cherrypick fix for CVE-2021-3520

Description

lz4: Cherrypick fix for CVE-2021-3520

There should be no risk of us accidentally hitting this since
we'd need maliciously malformed data to wind up in the pipeline,
or a very unfortunate random bit flip at exactly the right moment.
Still since we can handle it we should.

Reviewed-by: Igor Kozhukhov <igor@dilos.org>
Reviewed-by: George Melikov <mail@gmelikov.ru>
Reviewed-by: Brian Behlendorf <behlendorf1@llnl.gov>
Reviewed-by: Adam Moss <c@yotes.com>
Signed-off-by: Rich Ercolani <rincebrain@gmail.com>
Closes #12947

Details

Provenance
rincebrain_gmail.comAuthored on Jan 13 2022, 12:14 AM
GitHub <noreply@github.com>Committed on Jan 13 2022, 12:14 AM
Parents
rGd6c1bbdd6516: Updated the lz4 decompressor
Branches
Unknown
Tags
Unknown