diff --git a/CVE-2023-26964.patch b/CVE-2023-26964.patch deleted file mode 100644 index 6739c98..0000000 --- a/CVE-2023-26964.patch +++ /dev/null @@ -1,56 +0,0 @@ -From 4dcb5fb4162665cad436a18e9cb6d1735203d3ac Mon Sep 17 00:00:00 2001 -From: Alberto Planas -Date: Wed, 12 Apr 2023 16:48:26 +0200 -Subject: [PATCH] Update hyper to v0.14.25 (CVE-2023-26964) - -Signed-off-by: Alberto Planas ---- - Cargo.lock | 12 ++++++------ - 1 file changed, 6 insertions(+), 6 deletions(-) - -diff --git a/Cargo.lock b/Cargo.lock -index 70aeb97e..3fe2353c 100644 ---- a/Cargo.lock -+++ b/Cargo.lock -@@ -918,9 +918,9 @@ checksum = "d2fabcfbdc87f4758337ca535fb41a6d701b65693ce38287d856d1674551ec9b" - - [[package]] - name = "h2" --version = "0.3.14" -+version = "0.3.16" - source = "registry+https://github.com/rust-lang/crates.io-index" --checksum = "5ca32592cf21ac7ccab1825cd87f6c9b3d9022c44d086172ed0966bec8af30be" -+checksum = "5be7b54589b581f624f566bf5d8eb2bab1db736c51528720b6bd36b96b55924d" - dependencies = [ - "bytes", - "fnv", -@@ -1037,9 +1037,9 @@ dependencies = [ - - [[package]] - name = "hyper" --version = "0.14.20" -+version = "0.14.25" - source = "registry+https://github.com/rust-lang/crates.io-index" --checksum = "02c929dc5c39e335a03c405292728118860721b10190d98c2a0f0efd5baafbac" -+checksum = "cc5e554ff619822309ffd57d8734d77cd5ce6238bc956f037ea06c58238c9899" - dependencies = [ - "bytes", - "futures-channel", -@@ -1162,7 +1162,7 @@ dependencies = [ - name = "keylime" - version = "0.2.0" - dependencies = [ -- "base64 0.21.0", -+ "base64 0.13.1", - "hex", - "log", - "openssl", -@@ -1180,7 +1180,7 @@ version = "0.2.0" - dependencies = [ - "actix-rt", - "actix-web", -- "base64 0.21.0", -+ "base64 0.13.1", - "cfg-if", - "clap", - "compress-tools", diff --git a/rust-keylime.changes b/rust-keylime.changes index 8fe24cb..a151430 100644 --- a/rust-keylime.changes +++ b/rust-keylime.changes @@ -1,9 +1,6 @@ ------------------------------------------------------------------- Wed Apr 12 14:52:38 UTC 2023 - aplanas@suse.com -- Add CVE-2023-26964.patch to upgrade hyper crate (CVE-2023-26964, - bsc#1210344) - - Update to version 0.2.0+git.1681223954.646cf61: * Allow setting measured boot log path for testing * build(deps): bump base64 from 0.13.1 to 0.21.0 diff --git a/rust-keylime.spec b/rust-keylime.spec index 5cd96ee..1d31796 100644 --- a/rust-keylime.spec +++ b/rust-keylime.spec @@ -41,8 +41,6 @@ Source7: ima-policy.service Source8: README.suse # PATCH-FIX-OPENSUSE keylime-agent.conf.diff Patch1: keylime-agent.conf.diff -# PATCH-FIX-UPSTREAM CVE-2023-26964.patch https://github.com/keylime/rust-keylime/pull/560 -Patch2: CVE-2023-26964.patch BuildRequires: cargo-packaging BuildRequires: clang BuildRequires: firewall-macros diff --git a/vendor.tar.xz b/vendor.tar.xz index 84b1cc7..e36f173 100644 --- a/vendor.tar.xz +++ b/vendor.tar.xz @@ -1,3 +1,3 @@ version https://git-lfs.github.com/spec/v1 -oid sha256:540c04c5cba0ca0b67ac0adbc5bc8af3ce1fa6e9b9d9a46f9913c781180aba98 -size 26584652 +oid sha256:2e7a358d00578aa1248c30908de5368c0f673c8c800ecb415e2d4f7e7e7466db +size 26584112