From a7a39f72406b0c2b821a93fa550bdddbb5404770 Mon Sep 17 00:00:00 2001 From: "Benjamin A. Beasley" Date: Wed, 25 Oct 2023 11:01:11 -0400 Subject: [PATCH] Document that 1454.patch fixes CVE-2023-43898 --- stb.spec | 7 +++++++ 1 file changed, 7 insertions(+) diff --git a/stb.spec b/stb.spec index cdcc5f4..f8159e0 100644 --- a/stb.spec +++ b/stb.spec @@ -65,6 +65,13 @@ Patch: %{url}/pull/1236.patch # Fixes null pointer dereference in https://github.com/nothings/stb/issues/1452 # https://github.com/nothings/stb/pull/1454 +# +# Fixes: +# +# NULL pointer dereference in the stb_image.h +# https://github.com/nothings/stb/issues/1452 +# NULL pointer derefence in PIC loading (CVE-2023-43898) +# https://github.com/nothings/stb/issues/1521 Patch: %{url}/pull/1454.patch # Fixed asan error on tiny input images