diff --git a/pkgs/tools/misc/coreutils/CVE-2025-5278.patch b/pkgs/tools/misc/coreutils/CVE-2025-5278.patch index c55b7a8694f0..197a77020fe2 100644 --- a/pkgs/tools/misc/coreutils/CVE-2025-5278.patch +++ b/pkgs/tools/misc/coreutils/CVE-2025-5278.patch @@ -19,6 +19,8 @@ Fixes https://bugs.gnu.org/78507 4 files changed, 51 insertions(+), 2 deletions(-) create mode 100755 tests/sort/sort-field-limit.sh +The new tests is NOT added in NixOS. + diff --git a/NEWS b/NEWS index 6ff403206..923aa72f8 100644 --- a/NEWS @@ -65,59 +67,3 @@ index b10183b6f..7af1a2512 100644 } return ptr; -diff --git a/tests/local.mk b/tests/local.mk -index 4da6756ac..642d225fa 100644 ---- a/tests/local.mk -+++ b/tests/local.mk -@@ -388,6 +388,7 @@ all_tests = \ - tests/sort/sort-debug-keys.sh \ - tests/sort/sort-debug-warn.sh \ - tests/sort/sort-discrim.sh \ -+ tests/sort/sort-field-limit.sh \ - tests/sort/sort-files0-from.pl \ - tests/sort/sort-float.sh \ - tests/sort/sort-h-thousands-sep.sh \ -diff --git a/tests/sort/sort-field-limit.sh b/tests/sort/sort-field-limit.sh -new file mode 100755 -index 000000000..52d8e1d17 ---- /dev/null -+++ b/tests/sort/sort-field-limit.sh -@@ -0,0 +1,35 @@ -+#!/bin/sh -+# From 7.2-9.7, this would trigger an out of bounds mem read -+ -+# Copyright (C) 2025 Free Software Foundation, Inc. -+ -+# This program is free software: you can redistribute it and/or modify -+# it under the terms of the GNU General Public License as published by -+# the Free Software Foundation, either version 3 of the License, or -+# (at your option) any later version. -+ -+# This program is distributed in the hope that it will be useful, -+# but WITHOUT ANY WARRANTY; without even the implied warranty of -+# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the -+# GNU General Public License for more details. -+ -+# You should have received a copy of the GNU General Public License -+# along with this program. If not, see . -+ -+. "${srcdir=.}/tests/init.sh"; path_prepend_ ./src -+print_ver_ sort -+getlimits_ -+ -+# This issue triggers with valgrind or ASAN -+valgrind --error-exitcode=1 sort --version 2>/dev/null && -+ VALGRIND='valgrind --error-exitcode=1' -+ -+{ printf '%s\n' aa bb; } > in || framework_failure_ -+ -+_POSIX2_VERSION=200809 $VALGRIND sort +0.${SIZE_MAX}R in > out || fail=1 -+compare in out || fail=1 -+ -+_POSIX2_VERSION=200809 $VALGRIND sort +1 -1.${SIZE_MAX}R in > out || fail=1 -+compare in out || fail=1 -+ -+Exit $fail --- -cgit v1.2.3 - diff --git a/pkgs/tools/misc/coreutils/default.nix b/pkgs/tools/misc/coreutils/default.nix index facfbd89bd49..8b0177f03fbe 100644 --- a/pkgs/tools/misc/coreutils/default.nix +++ b/pkgs/tools/misc/coreutils/default.nix @@ -2,8 +2,6 @@ lib, stdenv, fetchurl, - autoconf, - automake, autoreconfHook, buildPackages, libiconv, @@ -132,8 +130,6 @@ stdenv.mkDerivation rec { [ perl xz.bin - autoconf - automake ] ++ optionals stdenv.hostPlatform.isCygwin [ # due to patch