Skip to content

Conversation

@jefferyto
Copy link
Member

@jefferyto jefferyto commented Dec 28, 2021

Maintainer: me
Compile tested: none (cherry picked from #17446)
Run tested: none

Description:
Includes fixes for:

  • CVE-2021-44716: unbounded growth of HTTP/2 header canonicalization cache
  • CVE-2021-44717: syscall.ForkExec error can close file descriptor 0

Added patches:

Signed-off-by: Jeffery To jeffery.to@gmail.com
(cherry picked from commit eac2e91)

Includes fixes for:
* CVE-2021-44716: unbounded growth of HTTP/2 header canonicalization
  cache
* CVE-2021-44717: syscall.ForkExec error can close file descriptor 0

Added patches:
* 001-cmd-link-use-gold-on-ARM-ARM64-only-if-gold-is-available.patch:
  golang/go#49748 backported for Go 1.17,
  this removes the requirement for the gold linker when building Go
  programs that use Go plugins on arm/arm64

Signed-off-by: Jeffery To <jeffery.to@gmail.com>
(cherry picked from commit eac2e91)
@jefferyto jefferyto force-pushed the golang-1.17.5-openwrt-21.02 branch from 56b643f to 2f52958 Compare December 28, 2021 07:17
@BKPepe BKPepe merged commit ab94e07 into openwrt:openwrt-21.02 Dec 29, 2021
@jefferyto jefferyto deleted the golang-1.17.5-openwrt-21.02 branch December 30, 2021 10:31
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

2 participants