mirror of
https://gitlab.com/buildroot.org/buildroot.git
synced 2026-09-29 21:41:43 -09:00
package/{binutils, gpsd, micropython, net-tools, util-linux, x11vnc, libfreeglut, libfreeimage, libical, proftpd, sylpheed, mupdf}: fix CVE patch information
Prior to improving check-package to verify that the comment preceding a <pkg>_IGNORE_CVES entry mentions an existing patch, and that the patch itself contains a CVE: tag, we fix all problematic cases that currently exist in Buildroot: - In the case of binutils: the CVE was only applicable to binutils 2.43/2.44, and the oldest version now supported is 2.45, so the patch doesn't exist anymore in Buildroot - For x11vnc, fix a typo in the patch name - Similarly for micropython, the patches were dropped in [1] along with the version bump - Add missing 'CVE:' tag to net-tools patch 0001 - edk2 add missing CVE trailer - libfreeglut add missing CVE trailer - libfreeimage correct reference to patch - libical add missing CVE trailer - proftpd correct reference to patch - sylpheed add missing CVE trailer [1]28eeca9a98package/micropython: bump to version 1.28.0 Signed-off-by: Titouan Christophe <titouan.christophe@mind.be> Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com> (cherry picked from commit636f69ab45) [thomas: adapt to 2025.02.x] Signed-off-by: Thomas Perale <thomas.perale@mind.be>
This commit is contained in:
@@ -8,6 +8,7 @@ In IScsiBuildKeyValueList, check if we have any data left (Len > 0) before advan
|
||||
Avoids wrapping Len. Also Used SafeUint32SubSafeUint32Sub call to reduce the Len .
|
||||
|
||||
Upstream: https://github.com/tianocore/edk2/commit/b3a2f7ff24e156e8c4d694fffff01e95a048c536
|
||||
CVE: CVE-2024-38805
|
||||
Signed-off-by: santhosh kumar V <santhoshkumarv@ami.com>
|
||||
Signed-off-by: Julien Olivain <ju.o@free.fr>
|
||||
---
|
||||
|
||||
@@ -21,9 +21,6 @@ BINUTILS_LICENSE = GPL-3.0+, GPL-2.0+, LGPL-2.1+
|
||||
BINUTILS_LICENSE_FILES = COPYING COPYING3 COPYING.LIB
|
||||
BINUTILS_CPE_ID_VENDOR = gnu
|
||||
|
||||
# 0003-objdump-memleak.patch
|
||||
BINUTILS_IGNORE_CVES += CVE-2025-3198
|
||||
|
||||
ifeq ($(BINUTILS_FROM_GIT),y)
|
||||
BINUTILS_DEPENDENCIES += host-flex host-bison
|
||||
HOST_BINUTILS_DEPENDENCIES += host-flex host-bison
|
||||
|
||||
@@ -8,7 +8,8 @@ glutAddSubMenu() is called the allocated menuEntry variable will
|
||||
leak. This commit postpones allocating menuEntry until after the
|
||||
error checks, thereby plugging the memory leak.
|
||||
|
||||
This fixes CVE-2024-24258 and CVE-2024-24259.
|
||||
CVE: CVE-2024-24258
|
||||
CVE: CVE-2024-24259
|
||||
Upstream: https://github.com/freeglut/freeglut/commit/9ad320c1ad1a25558998ddfe47674511567fec57
|
||||
Signed-off-by: Raphaël Mélotte <raphael.melotte@mind.be>
|
||||
---
|
||||
|
||||
@@ -37,7 +37,7 @@ LIBFREEIMAGE_IGNORE_CVES += CVE-2021-40266
|
||||
# 0014-CVE-2023-47995.patch
|
||||
LIBFREEIMAGE_IGNORE_CVES += CVE-2023-47995
|
||||
|
||||
# 0016-CVE-2023-47997.patch
|
||||
# 0015-CVE-2023-47997.patch
|
||||
LIBFREEIMAGE_IGNORE_CVES += CVE-2023-47997
|
||||
|
||||
define LIBFREEIMAGE_EXTRACT_CMDS
|
||||
|
||||
@@ -5,6 +5,7 @@ Subject: [PATCH] icaltypes.c - icalreqstattype_from_string(), copy the
|
||||
reqstattype's debug string into its own memory in the ring buffer.
|
||||
|
||||
Issue#253
|
||||
CVE: CVE-2016-9584
|
||||
Signed-off-by: Fabrice Fontaine <fontaine.fabrice@gmail.com>
|
||||
[Retrieved (and backported) from:
|
||||
https://github.com/libical/libical/commit/6b9438d746cec6e4e632d78c5244f4be6314d1c9]
|
||||
|
||||
@@ -15,9 +15,6 @@ MICROPYTHON_LICENSE_FILES = LICENSE
|
||||
MICROPYTHON_DEPENDENCIES = host-python3
|
||||
MICROPYTHON_CPE_ID_VENDOR = micropython
|
||||
|
||||
# 0004-py-objarray-fix-use-after-free-if-extending-a-bytearray-from-itself.patch
|
||||
MICROPYTHON_IGNORE_CVES += CVE-2024-8947
|
||||
|
||||
# Use fallback implementation for exception handling on architectures that don't
|
||||
# have explicit support.
|
||||
ifeq ($(BR2_i386)$(BR2_x86_64)$(BR2_arm)$(BR2_armeb),)
|
||||
|
||||
@@ -21,7 +21,7 @@ MUPDF_DEPENDENCIES = \
|
||||
lcms2 openjpeg \
|
||||
zlib
|
||||
|
||||
# libfreeglut/0001-Plug-memory-leak-that-happens-upon-error.patch
|
||||
# ../libfreeglut/0001-Plug-memory-leak-that-happens-upon-error.patch
|
||||
# Fix is in libfreeglut, but CVE applied to mupdf.
|
||||
MUPDF_IGNORE_CVES = \
|
||||
CVE-2024-24258 \
|
||||
|
||||
@@ -6,6 +6,7 @@ Subject: [PATCH] CVE-2025-46836: interface.c: Stack-based Buffer Overflow in
|
||||
|
||||
Coordinated as GHSA-pfwf-h6m3-63wf
|
||||
|
||||
CVE: CVE-2025-46836
|
||||
Upstream: https://github.com/ecki/net-tools/commit/7a8f42fb20013a1493d8cae1c43436f85e656f2d
|
||||
Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
|
||||
---
|
||||
|
||||
@@ -14,7 +14,7 @@ PROFTPD_SELINUX_MODULES = ftp
|
||||
# 0001-CVE-2026-42167.patch
|
||||
PROFTPD_IGNORE_CVES += CVE-2026-42167
|
||||
|
||||
# 0001-CVE-2026-44331.patch
|
||||
# 0002-CVE-2026-44331.patch
|
||||
PROFTPD_IGNORE_CVES += CVE-2026-44331
|
||||
|
||||
PROFTPD_CONF_ENV = \
|
||||
|
||||
@@ -3,6 +3,7 @@ From: Paul <paul@claws-mail.org>
|
||||
Date: Sun, 23 May 2021 12:16:40 +0100
|
||||
Subject: [PATCH] harden link checker before accepting click
|
||||
|
||||
CVE: CVE-2021-37746
|
||||
[Retrieved from:
|
||||
https://git.claws-mail.org/?p=claws.git;a=commit;h=ac286a71ed78429e16c612161251b9ea90ccd431]
|
||||
Signed-off-by: Fabrice Fontaine <fontaine.fabrice@gmail.com>
|
||||
|
||||
@@ -10,7 +10,7 @@ X11VNC_DEPENDENCIES = xlib_libXt xlib_libXext xlib_libXtst libvncserver
|
||||
X11VNC_LICENSE = GPL-2.0+
|
||||
X11VNC_LICENSE_FILES = COPYING
|
||||
X11VNC_CPE_ID_VALID = YES
|
||||
# 0002-scan-limit-access-to-shared-memory-segments-to-current-user.patch
|
||||
# 0002-scan-limit-access-to-shared-memory-segments-to-curre.patch
|
||||
X11VNC_IGNORE_CVES += CVE-2020-29074
|
||||
|
||||
# Source coming from github, no configure included
|
||||
|
||||
Reference in New Issue
Block a user