package/{binutils, gpsd, micropython, net-tools, util-linux, x11vnc, libfreeglut, libfreeimage, libical, proftpd, sylpheed, mupdf}: fix CVE patch information

Prior to improving check-package to verify that the comment preceding
a <pkg>_IGNORE_CVES entry mentions an existing patch, and that the
patch itself contains a CVE: tag, we fix all problematic cases that
currently exist in Buildroot:

- In the case of binutils: the CVE was only applicable to binutils
  2.43/2.44, and the oldest version now supported is 2.45, so the
  patch doesn't exist anymore in Buildroot
- For x11vnc, fix a typo in the patch name
- Similarly for micropython, the patches were dropped in [1] along with
  the version bump
- Add missing 'CVE:' tag to net-tools patch 0001
- edk2 add missing CVE trailer
- libfreeglut add missing CVE trailer
- libfreeimage correct reference to patch
- libical add missing CVE trailer
- proftpd correct reference to patch
- sylpheed add missing CVE trailer

[1] 28eeca9a98 package/micropython: bump to version 1.28.0

Signed-off-by: Titouan Christophe <titouan.christophe@mind.be>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
(cherry picked from commit 636f69ab45)
[thomas: adapt to 2025.02.x]
Signed-off-by: Thomas Perale <thomas.perale@mind.be>
This commit is contained in:
Thomas Perale
2026-09-16 11:39:45 +02:00
parent c4c6602343
commit 029c492e87
11 changed files with 10 additions and 11 deletions

View File

@@ -8,6 +8,7 @@ In IScsiBuildKeyValueList, check if we have any data left (Len > 0) before advan
Avoids wrapping Len. Also Used SafeUint32SubSafeUint32Sub call to reduce the Len . Avoids wrapping Len. Also Used SafeUint32SubSafeUint32Sub call to reduce the Len .
Upstream: https://github.com/tianocore/edk2/commit/b3a2f7ff24e156e8c4d694fffff01e95a048c536 Upstream: https://github.com/tianocore/edk2/commit/b3a2f7ff24e156e8c4d694fffff01e95a048c536
CVE: CVE-2024-38805
Signed-off-by: santhosh kumar V <santhoshkumarv@ami.com> Signed-off-by: santhosh kumar V <santhoshkumarv@ami.com>
Signed-off-by: Julien Olivain <ju.o@free.fr> Signed-off-by: Julien Olivain <ju.o@free.fr>
--- ---

View File

@@ -21,9 +21,6 @@ BINUTILS_LICENSE = GPL-3.0+, GPL-2.0+, LGPL-2.1+
BINUTILS_LICENSE_FILES = COPYING COPYING3 COPYING.LIB BINUTILS_LICENSE_FILES = COPYING COPYING3 COPYING.LIB
BINUTILS_CPE_ID_VENDOR = gnu BINUTILS_CPE_ID_VENDOR = gnu
# 0003-objdump-memleak.patch
BINUTILS_IGNORE_CVES += CVE-2025-3198
ifeq ($(BINUTILS_FROM_GIT),y) ifeq ($(BINUTILS_FROM_GIT),y)
BINUTILS_DEPENDENCIES += host-flex host-bison BINUTILS_DEPENDENCIES += host-flex host-bison
HOST_BINUTILS_DEPENDENCIES += host-flex host-bison HOST_BINUTILS_DEPENDENCIES += host-flex host-bison

View File

@@ -8,7 +8,8 @@ glutAddSubMenu() is called the allocated menuEntry variable will
leak. This commit postpones allocating menuEntry until after the leak. This commit postpones allocating menuEntry until after the
error checks, thereby plugging the memory leak. error checks, thereby plugging the memory leak.
This fixes CVE-2024-24258 and CVE-2024-24259. CVE: CVE-2024-24258
CVE: CVE-2024-24259
Upstream: https://github.com/freeglut/freeglut/commit/9ad320c1ad1a25558998ddfe47674511567fec57 Upstream: https://github.com/freeglut/freeglut/commit/9ad320c1ad1a25558998ddfe47674511567fec57
Signed-off-by: Raphaël Mélotte <raphael.melotte@mind.be> Signed-off-by: Raphaël Mélotte <raphael.melotte@mind.be>
--- ---

View File

@@ -37,7 +37,7 @@ LIBFREEIMAGE_IGNORE_CVES += CVE-2021-40266
# 0014-CVE-2023-47995.patch # 0014-CVE-2023-47995.patch
LIBFREEIMAGE_IGNORE_CVES += CVE-2023-47995 LIBFREEIMAGE_IGNORE_CVES += CVE-2023-47995
# 0016-CVE-2023-47997.patch # 0015-CVE-2023-47997.patch
LIBFREEIMAGE_IGNORE_CVES += CVE-2023-47997 LIBFREEIMAGE_IGNORE_CVES += CVE-2023-47997
define LIBFREEIMAGE_EXTRACT_CMDS define LIBFREEIMAGE_EXTRACT_CMDS

View File

@@ -5,6 +5,7 @@ Subject: [PATCH] icaltypes.c - icalreqstattype_from_string(), copy the
reqstattype's debug string into its own memory in the ring buffer. reqstattype's debug string into its own memory in the ring buffer.
Issue#253 Issue#253
CVE: CVE-2016-9584
Signed-off-by: Fabrice Fontaine <fontaine.fabrice@gmail.com> Signed-off-by: Fabrice Fontaine <fontaine.fabrice@gmail.com>
[Retrieved (and backported) from: [Retrieved (and backported) from:
https://github.com/libical/libical/commit/6b9438d746cec6e4e632d78c5244f4be6314d1c9] https://github.com/libical/libical/commit/6b9438d746cec6e4e632d78c5244f4be6314d1c9]

View File

@@ -15,9 +15,6 @@ MICROPYTHON_LICENSE_FILES = LICENSE
MICROPYTHON_DEPENDENCIES = host-python3 MICROPYTHON_DEPENDENCIES = host-python3
MICROPYTHON_CPE_ID_VENDOR = micropython MICROPYTHON_CPE_ID_VENDOR = micropython
# 0004-py-objarray-fix-use-after-free-if-extending-a-bytearray-from-itself.patch
MICROPYTHON_IGNORE_CVES += CVE-2024-8947
# Use fallback implementation for exception handling on architectures that don't # Use fallback implementation for exception handling on architectures that don't
# have explicit support. # have explicit support.
ifeq ($(BR2_i386)$(BR2_x86_64)$(BR2_arm)$(BR2_armeb),) ifeq ($(BR2_i386)$(BR2_x86_64)$(BR2_arm)$(BR2_armeb),)

View File

@@ -21,7 +21,7 @@ MUPDF_DEPENDENCIES = \
lcms2 openjpeg \ lcms2 openjpeg \
zlib zlib
# libfreeglut/0001-Plug-memory-leak-that-happens-upon-error.patch # ../libfreeglut/0001-Plug-memory-leak-that-happens-upon-error.patch
# Fix is in libfreeglut, but CVE applied to mupdf. # Fix is in libfreeglut, but CVE applied to mupdf.
MUPDF_IGNORE_CVES = \ MUPDF_IGNORE_CVES = \
CVE-2024-24258 \ CVE-2024-24258 \

View File

@@ -6,6 +6,7 @@ Subject: [PATCH] CVE-2025-46836: interface.c: Stack-based Buffer Overflow in
Coordinated as GHSA-pfwf-h6m3-63wf Coordinated as GHSA-pfwf-h6m3-63wf
CVE: CVE-2025-46836
Upstream: https://github.com/ecki/net-tools/commit/7a8f42fb20013a1493d8cae1c43436f85e656f2d Upstream: https://github.com/ecki/net-tools/commit/7a8f42fb20013a1493d8cae1c43436f85e656f2d
Signed-off-by: Peter Korsgaard <peter@korsgaard.com> Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
--- ---

View File

@@ -14,7 +14,7 @@ PROFTPD_SELINUX_MODULES = ftp
# 0001-CVE-2026-42167.patch # 0001-CVE-2026-42167.patch
PROFTPD_IGNORE_CVES += CVE-2026-42167 PROFTPD_IGNORE_CVES += CVE-2026-42167
# 0001-CVE-2026-44331.patch # 0002-CVE-2026-44331.patch
PROFTPD_IGNORE_CVES += CVE-2026-44331 PROFTPD_IGNORE_CVES += CVE-2026-44331
PROFTPD_CONF_ENV = \ PROFTPD_CONF_ENV = \

View File

@@ -3,6 +3,7 @@ From: Paul <paul@claws-mail.org>
Date: Sun, 23 May 2021 12:16:40 +0100 Date: Sun, 23 May 2021 12:16:40 +0100
Subject: [PATCH] harden link checker before accepting click Subject: [PATCH] harden link checker before accepting click
CVE: CVE-2021-37746
[Retrieved from: [Retrieved from:
https://git.claws-mail.org/?p=claws.git;a=commit;h=ac286a71ed78429e16c612161251b9ea90ccd431] https://git.claws-mail.org/?p=claws.git;a=commit;h=ac286a71ed78429e16c612161251b9ea90ccd431]
Signed-off-by: Fabrice Fontaine <fontaine.fabrice@gmail.com> Signed-off-by: Fabrice Fontaine <fontaine.fabrice@gmail.com>

View File

@@ -10,7 +10,7 @@ X11VNC_DEPENDENCIES = xlib_libXt xlib_libXext xlib_libXtst libvncserver
X11VNC_LICENSE = GPL-2.0+ X11VNC_LICENSE = GPL-2.0+
X11VNC_LICENSE_FILES = COPYING X11VNC_LICENSE_FILES = COPYING
X11VNC_CPE_ID_VALID = YES X11VNC_CPE_ID_VALID = YES
# 0002-scan-limit-access-to-shared-memory-segments-to-current-user.patch # 0002-scan-limit-access-to-shared-memory-segments-to-curre.patch
X11VNC_IGNORE_CVES += CVE-2020-29074 X11VNC_IGNORE_CVES += CVE-2020-29074
# Source coming from github, no configure included # Source coming from github, no configure included