Skip to content

Update lz4.c from upstream#4156

Merged
Emanuele Sabellico (emasab) merged 3 commits intoconfluentinc:feature/upgrade-lz4from
filimonov:lz4fix
Mar 22, 2023
Merged

Update lz4.c from upstream#4156
Emanuele Sabellico (emasab) merged 3 commits intoconfluentinc:feature/upgrade-lz4from
filimonov:lz4fix

Conversation

@filimonov
Copy link
Copy Markdown
Contributor

@filimonov filimonov (filimonov) commented Jan 24, 2023

Update lz4.c from upstream
Fix potential memory corruption with negative memmove() size
CVE-2021-3520

Check also lz4/lz4#972

Backporting ClickHouse#6

P.S. newer lz4 1.9.4 has a lot of other improvements. Maybe worth upgrading?

@emasab Emanuele Sabellico (emasab) changed the base branch from master to feature/upgrade-lz4 March 22, 2023 16:21
@emasab Emanuele Sabellico (emasab) merged commit 28d9761 into confluentinc:feature/upgrade-lz4 Mar 22, 2023
@emasab
Copy link
Copy Markdown
Contributor

Thanks filimonov (@filimonov) . I've created an internal branch and #4232 to run the tests.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants