From 029c492e87de6fd667c725f32ddd2525a9b4682c Mon Sep 17 00:00:00 2001 From: Thomas Perale Date: Wed, 16 Sep 2026 11:39:45 +0200 Subject: [PATCH] package/{binutils, gpsd, micropython, net-tools, util-linux, x11vnc, libfreeglut, libfreeimage, libical, proftpd, sylpheed, mupdf}: fix CVE patch information Prior to improving check-package to verify that the comment preceding a _IGNORE_CVES entry mentions an existing patch, and that the patch itself contains a CVE: tag, we fix all problematic cases that currently exist in Buildroot: - In the case of binutils: the CVE was only applicable to binutils 2.43/2.44, and the oldest version now supported is 2.45, so the patch doesn't exist anymore in Buildroot - For x11vnc, fix a typo in the patch name - Similarly for micropython, the patches were dropped in [1] along with the version bump - Add missing 'CVE:' tag to net-tools patch 0001 - edk2 add missing CVE trailer - libfreeglut add missing CVE trailer - libfreeimage correct reference to patch - libical add missing CVE trailer - proftpd correct reference to patch - sylpheed add missing CVE trailer [1] 28eeca9a98 package/micropython: bump to version 1.28.0 Signed-off-by: Titouan Christophe Signed-off-by: Thomas Petazzoni (cherry picked from commit 636f69ab450e9d1bf48eda22b507a68272c5c9d5) [thomas: adapt to 2025.02.x] Signed-off-by: Thomas Perale --- ...-NetworkPkg-IScsiDxe-Fix-for-out-of-bound-memory-acce.patch | 1 + package/binutils/binutils.mk | 3 --- .../0001-Plug-memory-leak-that-happens-upon-error.patch | 3 ++- package/libfreeimage/libfreeimage.mk | 2 +- ...es-c-icalreqstattype_from_string-copy-the-reqstattype.patch | 1 + package/micropython/micropython.mk | 3 --- package/mupdf/mupdf.mk | 2 +- ...-CVE-2025-46836-interface.c-Stack-based-Buffer-Overfl.patch | 1 + package/proftpd/proftpd.mk | 2 +- .../0001-harden-link-checker-before-accepting-click.patch | 1 + package/x11vnc/x11vnc.mk | 2 +- 11 files changed, 10 insertions(+), 11 deletions(-) diff --git a/boot/edk2/0001-NetworkPkg-IScsiDxe-Fix-for-out-of-bound-memory-acce.patch b/boot/edk2/0001-NetworkPkg-IScsiDxe-Fix-for-out-of-bound-memory-acce.patch index 4cc66eb0fe..066d880b59 100644 --- a/boot/edk2/0001-NetworkPkg-IScsiDxe-Fix-for-out-of-bound-memory-acce.patch +++ b/boot/edk2/0001-NetworkPkg-IScsiDxe-Fix-for-out-of-bound-memory-acce.patch @@ -8,6 +8,7 @@ In IScsiBuildKeyValueList, check if we have any data left (Len > 0) before advan Avoids wrapping Len. Also Used SafeUint32SubSafeUint32Sub call to reduce the Len . Upstream: https://github.com/tianocore/edk2/commit/b3a2f7ff24e156e8c4d694fffff01e95a048c536 +CVE: CVE-2024-38805 Signed-off-by: santhosh kumar V Signed-off-by: Julien Olivain --- diff --git a/package/binutils/binutils.mk b/package/binutils/binutils.mk index 7e4f213517..33cb29557b 100644 --- a/package/binutils/binutils.mk +++ b/package/binutils/binutils.mk @@ -21,9 +21,6 @@ BINUTILS_LICENSE = GPL-3.0+, GPL-2.0+, LGPL-2.1+ BINUTILS_LICENSE_FILES = COPYING COPYING3 COPYING.LIB BINUTILS_CPE_ID_VENDOR = gnu -# 0003-objdump-memleak.patch -BINUTILS_IGNORE_CVES += CVE-2025-3198 - ifeq ($(BINUTILS_FROM_GIT),y) BINUTILS_DEPENDENCIES += host-flex host-bison HOST_BINUTILS_DEPENDENCIES += host-flex host-bison diff --git a/package/libfreeglut/0001-Plug-memory-leak-that-happens-upon-error.patch b/package/libfreeglut/0001-Plug-memory-leak-that-happens-upon-error.patch index d09e9befb3..f039f665f4 100644 --- a/package/libfreeglut/0001-Plug-memory-leak-that-happens-upon-error.patch +++ b/package/libfreeglut/0001-Plug-memory-leak-that-happens-upon-error.patch @@ -8,7 +8,8 @@ glutAddSubMenu() is called the allocated menuEntry variable will leak. This commit postpones allocating menuEntry until after the error checks, thereby plugging the memory leak. -This fixes CVE-2024-24258 and CVE-2024-24259. +CVE: CVE-2024-24258 +CVE: CVE-2024-24259 Upstream: https://github.com/freeglut/freeglut/commit/9ad320c1ad1a25558998ddfe47674511567fec57 Signed-off-by: Raphaël Mélotte --- diff --git a/package/libfreeimage/libfreeimage.mk b/package/libfreeimage/libfreeimage.mk index 86362bc1c4..f8273d2b64 100644 --- a/package/libfreeimage/libfreeimage.mk +++ b/package/libfreeimage/libfreeimage.mk @@ -37,7 +37,7 @@ LIBFREEIMAGE_IGNORE_CVES += CVE-2021-40266 # 0014-CVE-2023-47995.patch LIBFREEIMAGE_IGNORE_CVES += CVE-2023-47995 -# 0016-CVE-2023-47997.patch +# 0015-CVE-2023-47997.patch LIBFREEIMAGE_IGNORE_CVES += CVE-2023-47997 define LIBFREEIMAGE_EXTRACT_CMDS diff --git a/package/libical/0002-icaltypes-c-icalreqstattype_from_string-copy-the-reqstattype.patch b/package/libical/0002-icaltypes-c-icalreqstattype_from_string-copy-the-reqstattype.patch index 0d74835e44..fb80ba3095 100644 --- a/package/libical/0002-icaltypes-c-icalreqstattype_from_string-copy-the-reqstattype.patch +++ b/package/libical/0002-icaltypes-c-icalreqstattype_from_string-copy-the-reqstattype.patch @@ -5,6 +5,7 @@ Subject: [PATCH] icaltypes.c - icalreqstattype_from_string(), copy the reqstattype's debug string into its own memory in the ring buffer. Issue#253 +CVE: CVE-2016-9584 Signed-off-by: Fabrice Fontaine [Retrieved (and backported) from: https://github.com/libical/libical/commit/6b9438d746cec6e4e632d78c5244f4be6314d1c9] diff --git a/package/micropython/micropython.mk b/package/micropython/micropython.mk index 826247069e..4e83f1d6a0 100644 --- a/package/micropython/micropython.mk +++ b/package/micropython/micropython.mk @@ -15,9 +15,6 @@ MICROPYTHON_LICENSE_FILES = LICENSE MICROPYTHON_DEPENDENCIES = host-python3 MICROPYTHON_CPE_ID_VENDOR = micropython -# 0004-py-objarray-fix-use-after-free-if-extending-a-bytearray-from-itself.patch -MICROPYTHON_IGNORE_CVES += CVE-2024-8947 - # Use fallback implementation for exception handling on architectures that don't # have explicit support. ifeq ($(BR2_i386)$(BR2_x86_64)$(BR2_arm)$(BR2_armeb),) diff --git a/package/mupdf/mupdf.mk b/package/mupdf/mupdf.mk index f209cafef2..c03e737bcd 100644 --- a/package/mupdf/mupdf.mk +++ b/package/mupdf/mupdf.mk @@ -21,7 +21,7 @@ MUPDF_DEPENDENCIES = \ lcms2 openjpeg \ zlib -# libfreeglut/0001-Plug-memory-leak-that-happens-upon-error.patch +# ../libfreeglut/0001-Plug-memory-leak-that-happens-upon-error.patch # Fix is in libfreeglut, but CVE applied to mupdf. MUPDF_IGNORE_CVES = \ CVE-2024-24258 \ diff --git a/package/net-tools/0001-CVE-2025-46836-interface.c-Stack-based-Buffer-Overfl.patch b/package/net-tools/0001-CVE-2025-46836-interface.c-Stack-based-Buffer-Overfl.patch index 0a02785f38..1405b5c9e9 100644 --- a/package/net-tools/0001-CVE-2025-46836-interface.c-Stack-based-Buffer-Overfl.patch +++ b/package/net-tools/0001-CVE-2025-46836-interface.c-Stack-based-Buffer-Overfl.patch @@ -6,6 +6,7 @@ Subject: [PATCH] CVE-2025-46836: interface.c: Stack-based Buffer Overflow in Coordinated as GHSA-pfwf-h6m3-63wf +CVE: CVE-2025-46836 Upstream: https://github.com/ecki/net-tools/commit/7a8f42fb20013a1493d8cae1c43436f85e656f2d Signed-off-by: Peter Korsgaard --- diff --git a/package/proftpd/proftpd.mk b/package/proftpd/proftpd.mk index ee290c7670..c8a9b61883 100644 --- a/package/proftpd/proftpd.mk +++ b/package/proftpd/proftpd.mk @@ -14,7 +14,7 @@ PROFTPD_SELINUX_MODULES = ftp # 0001-CVE-2026-42167.patch PROFTPD_IGNORE_CVES += CVE-2026-42167 -# 0001-CVE-2026-44331.patch +# 0002-CVE-2026-44331.patch PROFTPD_IGNORE_CVES += CVE-2026-44331 PROFTPD_CONF_ENV = \ diff --git a/package/sylpheed/0001-harden-link-checker-before-accepting-click.patch b/package/sylpheed/0001-harden-link-checker-before-accepting-click.patch index 46b4505837..e027ad689b 100644 --- a/package/sylpheed/0001-harden-link-checker-before-accepting-click.patch +++ b/package/sylpheed/0001-harden-link-checker-before-accepting-click.patch @@ -3,6 +3,7 @@ From: Paul Date: Sun, 23 May 2021 12:16:40 +0100 Subject: [PATCH] harden link checker before accepting click +CVE: CVE-2021-37746 [Retrieved from: https://git.claws-mail.org/?p=claws.git;a=commit;h=ac286a71ed78429e16c612161251b9ea90ccd431] Signed-off-by: Fabrice Fontaine diff --git a/package/x11vnc/x11vnc.mk b/package/x11vnc/x11vnc.mk index 645ef40643..4ec1813430 100644 --- a/package/x11vnc/x11vnc.mk +++ b/package/x11vnc/x11vnc.mk @@ -10,7 +10,7 @@ X11VNC_DEPENDENCIES = xlib_libXt xlib_libXext xlib_libXtst libvncserver X11VNC_LICENSE = GPL-2.0+ X11VNC_LICENSE_FILES = COPYING X11VNC_CPE_ID_VALID = YES -# 0002-scan-limit-access-to-shared-memory-segments-to-current-user.patch +# 0002-scan-limit-access-to-shared-memory-segments-to-curre.patch X11VNC_IGNORE_CVES += CVE-2020-29074 # Source coming from github, no configure included