From f9ed465dfc78fe1122075daeaacc01f296f0aca3 Mon Sep 17 00:00:00 2001 From: Stephen Gallagher Date: Wed, 7 Feb 2024 18:20:22 -0500 Subject: [PATCH] Update to libuv 1.48.0 https://github.com/libuv/libuv/releases/tag/v1.48.0 Resolves: CVE-2024-24806 Signed-off-by: Stephen Gallagher --- .gitignore | 1 + libuv-v1.48.0.tar.gz.sign | 16 ++++++++++++++++ libuv.spec | 14 +------------- sources | 2 +- 4 files changed, 19 insertions(+), 14 deletions(-) create mode 100644 libuv-v1.48.0.tar.gz.sign diff --git a/.gitignore b/.gitignore index 62016f7..5b1cbcc 100644 --- a/.gitignore +++ b/.gitignore @@ -84,3 +84,4 @@ libuv-v*/ /libuv-v1.45.0.tar.gz /libuv-v1.46.0.tar.gz /libuv-v1.47.0.tar.gz +/libuv-v1.48.0.tar.gz diff --git a/libuv-v1.48.0.tar.gz.sign b/libuv-v1.48.0.tar.gz.sign new file mode 100644 index 0000000..86a4e89 --- /dev/null +++ b/libuv-v1.48.0.tar.gz.sign @@ -0,0 +1,16 @@ +-----BEGIN PGP SIGNATURE----- + +iQIzBAABCgAdFiEEYS8OrZQBYiN530QC8ow8jaM8A74FAmXD5iAACgkQ8ow8jaM8 +A77Erw/+KSsWKi47qakBDtkjOsUY/PmvX9nPQn1wHvwABWSx/8vNkAjcENbAkEuX +U4gM2kqjyoe12tRhvVwriHYbRgIAkjkcRPYM1eAib7RT47fm7nGD3pPFoTylQCxH +sk+cJuWKTvEXqzDaUKG9nTx3WXU869Tq4T35a8PD7qTqfKnWIRI/xalyPd4b7RUT +/CURuvLrNH2UDwNFk7qF+So07TfABWbqNzdACV4+N+RyyJdy7/ct6LYIwy+ltwB/ +1R0dGkGyaMN0YFB/5rMLKH5Qy0dHjGV+MOmnEGp/JhPLvJGSHZZr8FXs8q+VUgrB +PogI74wWul83mRCFE0JDGPNeuDvDqUPKxcH1OhjVlkC/gwslHgQgui0fz+TKJSHj +dTXZu+R8rYULn+wgPCR3ND2xTayFS/AQejmLHPk9dfAGGlZGJOjw8IIMh70tts6V +hX3dGybLvKFOGFKZzx1TSJQOB3+tkkjgFPVzDRXm50w5YS2IH7sWoP2KUa4XmdMG +ymknB6PE5zhP/HfsfOL5vAcpCYkRb19YvActbfC8/kV+/Rid4r1jIC86HhuzFXYf +oCBTKQ5xN7SphhGNMOYPoYKCV8ttHYsuOVs9ZkV9OCTfMVJOy1o8/31YP27G4SDi +KrfPD/q1jP1g6qV5NQBDbuzDBgKWGr+YwjPmPR6f3QK4oB0TnLU= +=6mql +-----END PGP SIGNATURE----- diff --git a/libuv.spec b/libuv.spec index 92b56c4..af26ecd 100644 --- a/libuv.spec +++ b/libuv.spec @@ -9,7 +9,7 @@ Name: libuv Epoch: 1 -Version: 1.47.0 +Version: 1.48.0 Release: %autorelease Summary: Platform layer for node.js @@ -33,18 +33,6 @@ Source1: https://dist.libuv.org/dist/v%{version}/%{name}-v%{version}.tar. Source2: keysuv.gpg Source3: libuv.abignore -# Test fix for IPv6 interfaces with a NULL ifa_addr -# https://github.com/libuv/libuv/pull/4218 -Patch: 0001-unix-ignore-ifaddrs-with-NULL-ifa_addr-4218.patch - -# test: check if ipv6 link-local traffic is routable -# https://github.com/libuv/libuv/pull/4220 -Patch: 0002-test-check-if-ipv6-link-local-traffic-is-routable.patch - -# test: Use unsigned comparison for fs_type -# https://github.com/libuv/libuv/pull/4227 -Patch: 0003-test_fs.c-Fix-issue-on-32-bit-systems-using-btrfs.patch - BuildRequires: cmake BuildRequires: gcc BuildRequires: gnupg2 diff --git a/sources b/sources index aa3a44b..a6dc0b4 100644 --- a/sources +++ b/sources @@ -1 +1 @@ -SHA512 (libuv-v1.47.0.tar.gz) = 3fb6db0109dfa49db0e6028f6667ab5245b9707df337134ce6e1e9c9f82d4d686356cad30221094f79e87441e300f3c036a3cf04838d6eb23d4f27b1aaf4da13 +SHA512 (libuv-v1.48.0.tar.gz) = 7ae3a4c02f654a26056db1541e52ccc4c54aaea39c33585f0cf6949af997d0a0a29f30a294c8df6e92f6f6af7ce64c2766b1a2cc67f342e3e139cd55b7326c94