From ceee8090d1d0bf3561ab3a58e77f5c3970e8a8a3 Mon Sep 17 00:00:00 2001 From: Robert Scott Date: Mon, 17 Oct 2022 20:25:21 +0100 Subject: [PATCH] qemu: add patch for CVE-2022-3165 --- pkgs/applications/virtualization/qemu/default.nix | 5 +++++ 1 file changed, 5 insertions(+) diff --git a/pkgs/applications/virtualization/qemu/default.nix b/pkgs/applications/virtualization/qemu/default.nix index 683d94fc2be9..42a556a451fb 100644 --- a/pkgs/applications/virtualization/qemu/default.nix +++ b/pkgs/applications/virtualization/qemu/default.nix @@ -112,6 +112,11 @@ stdenv.mkDerivation rec { revert = true; }) ./9pfs-use-GHashTable-for-fid-table.patch + (fetchpatch { + name = "CVE-2022-3165.patch"; + url = "https://gitlab.com/qemu-project/qemu/-/commit/d307040b18bfcb1393b910f1bae753d5c12a4dc7.patch"; + sha256 = "sha256-YPhm580lBNuAv7G1snYccKZ2V5ycdV8Ri8mTw5jjFBc="; + }) ] ++ lib.optional nixosTestRunner ./force-uid0-on-9p.patch;