mirror of
https://gitlab.com/buildroot.org/buildroot.git
synced 2026-09-09 07:51:59 -09:00
package/libde265: security bump version to 1.1.1
https://github.com/strukturag/libde265/releases/tag/v1.1.1 Fixes the following security problems: CVE TBD (GHSA-ccfw-29x7-rrx3) - Pixel accessor signed integer overflow causes heap OOB read/write CVE TBD (GHSA-j2qq-x2xq-g9wr) - SAO sequential filter heap buffer overflow via signed integer overflow This version bump includes upstream commit9ded37bda4which uses constexpr() and causes a build error caught by the Gitlab pipelines with the gcc-6-based bootlin-aarch64-glibc-old defconfig: /builds/bkuhls/buildroot/br-test-pkg/bootlin-aarch64-glibc-old/build/libde265-1.1.1/libde265/deblock.cc:594:14: error: expected ‘(’ before ‘constexpr’ if constexpr (sizeof(pixel_t)==1) { Therefore we need to raise the minimum gcc version according to https://gcc.gnu.org/projects/cxx-status.html#cxx17 to gcc 7. Signed-off-by: Bernd Kuhls <bernd@kuhls.net> Signed-off-by: Julien Olivain <ju.o@free.fr> (cherry picked from commit35b57a0787) Signed-off-by: Thomas Perale <thomas.perale@mind.be>
This commit is contained in:
committed by
Thomas Perale
parent
4a741d4b1a
commit
0aa6bf8b37
@@ -1,6 +1,7 @@
|
||||
config BR2_PACKAGE_LIBDE265
|
||||
bool "libde265"
|
||||
depends on BR2_INSTALL_LIBSTDCPP
|
||||
depends on BR2_TOOLCHAIN_GCC_AT_LEAST_7 # C++17
|
||||
depends on BR2_TOOLCHAIN_HAS_THREADS
|
||||
help
|
||||
libde265 is an open source implementation of the h.265 video
|
||||
@@ -8,5 +9,8 @@ config BR2_PACKAGE_LIBDE265
|
||||
|
||||
https://github.com/strukturag/libde265
|
||||
|
||||
comment "libde265 needs a toolchain w/ threads, C++"
|
||||
depends on !BR2_TOOLCHAIN_HAS_THREADS || !BR2_INSTALL_LIBSTDCPP
|
||||
comment "libde265 needs a toolchain w/ threads, C++, gcc >= 7"
|
||||
depends on \
|
||||
!BR2_TOOLCHAIN_HAS_THREADS || \
|
||||
!BR2_INSTALL_LIBSTDCPP || \
|
||||
!BR2_TOOLCHAIN_GCC_AT_LEAST_7
|
||||
|
||||
@@ -1,4 +1,4 @@
|
||||
# From https://github.com/strukturag/libde265/releases/tag/v1.1.0
|
||||
sha256 afc19dd28e2fc523de5952bba5224ee1d28e286c72436d2843df126cca1181fd libde265-1.1.0.tar.gz
|
||||
# From https://github.com/strukturag/libde265/releases/tag/v1.1.1
|
||||
sha256 fd48a927e94ed74fc7ce8829d222b9d8599fcbfe8b6448ba66705babc56ab219 libde265-1.1.1.tar.gz
|
||||
# Locally computed
|
||||
sha256 02cc1585a20677992e0ba578fa692635dc193735f2691dc81de924b51c4e8020 COPYING
|
||||
|
||||
@@ -4,7 +4,7 @@
|
||||
#
|
||||
################################################################################
|
||||
|
||||
LIBDE265_VERSION = 1.1.0
|
||||
LIBDE265_VERSION = 1.1.1
|
||||
LIBDE265_SITE = https://github.com/strukturag/libde265/releases/download/v$(LIBDE265_VERSION)
|
||||
LIBDE265_LICENSE = LGPL-3.0+
|
||||
LIBDE265_LICENSE_FILES = COPYING
|
||||
|
||||
Reference in New Issue
Block a user