Description: "In radare2 through 5.3.0 there is a double free vulnerability in the pyc parse via a crafted file which can lead to DoS." Bug with patch: https://github.com/radareorg/radare2/issues/18679
Package list is empty or all packages have requested keywords.
The patch actually made it into the 5.3.0 release, in tree as of June 5, so just need cleanup.
The bug has been referenced in the following commit(s): https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=6857fe494583e031f9402e81777e91416902df95 commit 6857fe494583e031f9402e81777e91416902df95 Author: David Roman <davidroman96@gmail.com> AuthorDate: 2021-12-04 20:29:43 +0000 Commit: John Helmert III <ajak@gentoo.org> CommitDate: 2022-01-06 04:37:38 +0000 dev-util/radare2: verbump to 5.5.4 Closes: https://bugs.gentoo.org/815046 Bug: https://bugs.gentoo.org/790284 Bug: https://bugs.gentoo.org/807061 Package-Manager: Portage-3.0.28, Repoman-3.0.3 Signed-off-by: David Roman <davidroman96@gmail.com> Closes: https://github.com/gentoo/gentoo/pull/23184 Signed-off-by: John Helmert III <ajak@gentoo.org> dev-util/radare2/Manifest | 4 + .../radare2/files/radare2-5.5.0-vector35.patch | 22 +++++ dev-util/radare2/radare2-5.5.4.ebuild | 106 +++++++++++++++++++++ 3 files changed, 132 insertions(+)