package/ntpsec: security bump version to 1.2.5

Fixes: CVE-2026-18321:
https://nvd.nist.gov/vuln/detail/cve-2026-18321

- bump version to 1.2.5 (for details see [1])
- rebased 0001-wscript-remove-checks-for-bsd-string.h-fixes-host-co.patch
- rebased 0002-disable-PIE-support.patch
- removed 0003-ntpd-refclock_gpsd.c-Add-missing-time.h-for-strptim.patch
  (from upstream [2])
- moved 0004-refclock_gpsd-add-build-fix-for-gcc-14.x.patch to
  0003-refclock_gpsd-add-build-fix-for-gcc-14.x.patch, rebased and enhanced
  as the original conflicts with upstream commit 5505260c ("Fix redefined
  _XOPEN_SOURCE warning in refclock_gpsd.c") [3] and leads to the following
  compile failure:

    ../../ntpd/refclock_gpsd.c:113:21: error: operator ‘<’ has no left operand
      113 |   #if _XOPEN_SOURCE < 700
          |                     ^

[1] https://lists.ntpsec.org/pipermail/devel/2026-July/011029.html
[2] 5137c155d8
[3] 5505260cd1

Signed-off-by: Peter Seiderer <ps.report@gmx.net>
[Julien: mark commit as "security bump"]
Signed-off-by: Julien Olivain <ju.o@free.fr>
(cherry picked from commit 1caeb632a6)
Signed-off-by: Raphaël Mélotte <raphael.melotte@mind.be>
This commit is contained in:
Peter Seiderer
2026-09-26 21:42:59 +02:00
committed by Raphaël Mélotte
parent 328e2e7a80
commit 36df8e9c46
6 changed files with 24 additions and 64 deletions

View File

@@ -1,4 +1,4 @@
From 54fbeaa68a59f536819d1cfb2e9204176fbff54b Mon Sep 17 00:00:00 2001
From 01d75b8d4624883133964deedc4c83e20adbee82 Mon Sep 17 00:00:00 2001
From: Peter Seiderer <ps.report@gmx.net>
Date: Thu, 16 Dec 2021 23:27:35 +0100
Subject: [PATCH] wscript: remove checks for bsd/string.h, fixes host-compile
@@ -15,6 +15,8 @@ in case target libbsd is found:
| ^~~~~~~~~~~~~~
compilation terminated.
Signed-off-by: Peter Seiderer <ps.report@gmx.net>
[Rebased on ntpsec-1.2.5]
Signed-off-by: Peter Seiderer <ps.report@gmx.net>
---
include/ntp_stdlib.h | 4 ----
@@ -22,7 +24,7 @@ Signed-off-by: Peter Seiderer <ps.report@gmx.net>
2 files changed, 18 deletions(-)
diff --git a/include/ntp_stdlib.h b/include/ntp_stdlib.h
index fe4d78e5c..73d97084f 100644
index 80e4765cf..c6cb04d04 100644
--- a/include/ntp_stdlib.h
+++ b/include/ntp_stdlib.h
@@ -16,10 +16,6 @@
@@ -37,10 +39,10 @@ index fe4d78e5c..73d97084f 100644
#define NTP_PRINTF(fmt, args) __attribute__((__format__(__printf__, fmt, args)))
#else
diff --git a/wscript b/wscript
index 641073f00..aa04b1d1c 100644
index 65592c997..ba8939aff 100644
--- a/wscript
+++ b/wscript
@@ -660,19 +660,6 @@ int main(int argc, char **argv) {
@@ -643,19 +643,6 @@ int main(int argc, char **argv) {
prerequisites=ft[1], use=ft[2],
mandatory=ft[3])
@@ -60,7 +62,7 @@ index 641073f00..aa04b1d1c 100644
# Nobody uses the symbol, but this seems like a good sanity check.
ctx.check_cc(header_name="stdbool.h", mandatory=True,
comment="Sanity check.")
@@ -691,7 +678,6 @@ int main(int argc, char **argv) {
@@ -674,7 +661,6 @@ int main(int argc, char **argv) {
optional_headers = (
"alloca.h",
("arpa/nameser.h", ["sys/types.h"]),
@@ -69,5 +71,5 @@ index 641073f00..aa04b1d1c 100644
("linux/if_addr.h", ["sys/socket.h"]),
("linux/rtnetlink.h", ["sys/socket.h"]),
--
2.34.1
2.55.0

View File

@@ -1,20 +1,22 @@
From 712675fbd2a736df817fecd7bfb39055946ef85b Mon Sep 17 00:00:00 2001
From 93c8fe7187d1f8b2b4a41829272ffefc717165be Mon Sep 17 00:00:00 2001
From: Waldemar Brodkorb <wbx@openadk.org>
Date: Sun, 13 Aug 2023 13:48:03 +0200
Subject: [PATCH] disable PIE support
Signed-off-by: Waldemar Brodkorb <wbx@openadk.org>
Upstream: N/A Not upstreamable
[Rebased on ntpsec-1.2.5]
Signed-off-by: Peter Seiderer <ps.report@gmx.net>
---
wscript | 1 -
1 file changed, 1 deletion(-)
diff --git a/wscript b/wscript
index 292e3a45b..105c7eac2 100644
index ba8939aff..bdc3a2748 100644
--- a/wscript
+++ b/wscript
@@ -299,7 +299,6 @@ def configure(ctx):
@@ -291,7 +291,6 @@ def configure(ctx):
# ('w_everything', "-Weverything"), # clang
cc_test_flags = [
('PIC', '-fPIC'),
- ('PIE', '-pie -fPIE'),
@@ -22,5 +24,5 @@ index 292e3a45b..105c7eac2 100644
('unused', '-Qunused-arguments'),
# This is a useless warning on any architecture with a barrel
--
2.39.2
2.55.0

View File

@@ -1,47 +0,0 @@
From 904983bf9465017753c6f5b602fc9c98458615f7 Mon Sep 17 00:00:00 2001
From: "Gary E. Miller" <gem@rellim.com>
Date: Mon, 27 Oct 2025 12:35:35 -0700
Subject: [PATCH] ntpd/refclock_gpsd.c: Add missing time.h for strptime()
Upstream: https://gitlab.com/NTPsec/ntpsec/-/commit/5137c155d8895cfc50fb577ee720b3b23589c662
Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
---
ntpd/refclock_gpsd.c | 14 +++++++-------
1 file changed, 7 insertions(+), 7 deletions(-)
diff --git a/ntpd/refclock_gpsd.c b/ntpd/refclock_gpsd.c
index 1dfec3103..0a2987d84 100644
--- a/ntpd/refclock_gpsd.c
+++ b/ntpd/refclock_gpsd.c
@@ -100,20 +100,20 @@ typedef unsigned long int json_uint;
* header stuff we need
*/
-#include <netdb.h>
-#include <unistd.h>
-#include <fcntl.h>
-#include <string.h>
#include <ctype.h>
+#include <fcntl.h>
#include <math.h>
+#include <netdb.h>
+#include <string.h>
+#include <time.h> // for strptime()
+#include <unistd.h>
-#include <sys/types.h>
+#include <sys/select.h>
#include <sys/socket.h>
#include <sys/stat.h>
+#include <sys/types.h>
#include <netinet/tcp.h>
-#include <sys/select.h>
-
#include "ntpd.h"
#include "ntp_io.h"
#include "ntp_refclock.h"
--
2.47.3

View File

@@ -1,4 +1,4 @@
From 55c230d61ece7213506f1dccac76c21aefbade9e Mon Sep 17 00:00:00 2001
From 19cba844e9df1ed3942d44a83cf7875bb52d9a33 Mon Sep 17 00:00:00 2001
From: Bernd Kuhls <bernd@kuhls.net>
Date: Mon, 27 Oct 2025 19:18:13 +0100
Subject: [PATCH] refclock_gpsd: add build fix for gcc => 14.x
@@ -10,23 +10,26 @@ Subject: [PATCH] refclock_gpsd: add build fix for gcc => 14.x
Upstream: https://gitlab.com/NTPsec/ntpsec/-/merge_requests/1484
Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
[Rebased on ntpsec-1.2.5 and fixed for changes from upstream commit
5505260c ("Fix redefined _XOPEN_SOURCE warning in refclock_gpsd.c")]
Signed-off-by: Peter Seiderer <ps.report@gmx.net>
---
ntpd/refclock_gpsd.c | 2 ++
1 file changed, 2 insertions(+)
diff --git a/ntpd/refclock_gpsd.c b/ntpd/refclock_gpsd.c
index a4a6f7095..a3995896a 100644
index a316f724a..55d4dfe83 100644
--- a/ntpd/refclock_gpsd.c
+++ b/ntpd/refclock_gpsd.c
@@ -59,6 +59,8 @@
*/
+#define _XOPEN_SOURCE
+#define _XOPEN_SOURCE 700
+#define _DEFAULT_SOURCE
#include "config.h"
#include "ntp.h"
#include "ntp_types.h"
--
2.47.3
2.55.0

View File

@@ -1,5 +1,5 @@
# Locally calculated
sha256 3abc1b057a252d214ef2e76aa375fe0d81432c626e75304b17850d68eee0c54f ntpsec-NTPsec_1_2_4.tar.bz2
sha256 48717ea84a8c89bfa082ab5d0dc58b44e6328158632e77d2a74c85b7a509e498 ntpsec-NTPsec_1_2_5.tar.bz2
sha256 074e6e32c86a4c0ef8b3ed25b721ca23aca83df277cd88106ef7177c354615ff LICENSES/Apache-2.0.txt
sha256 991d8a58e0b4be84a174a9bd333a8ca33807a0c1ce6d23a2e25a21f7ece482d0 LICENSES/Beerware.txt
sha256 899261d6eb6c922cf8f051225411f27b738ba0014be18c2eaf6afbf30d421bb1 LICENSES/BSD-2-Clause.txt

View File

@@ -4,7 +4,7 @@
#
################################################################################
NTPSEC_VERSION = 1.2.4
NTPSEC_VERSION = 1.2.5
NTPSEC_SOURCE = ntpsec-NTPsec_$(subst .,_,$(NTPSEC_VERSION)).tar.bz2
NTPSEC_SITE = https://gitlab.com/NTPsec/ntpsec/-/archive/NTPsec_$(subst .,_,$(NTPSEC_VERSION))
NTPSEC_LICENSE = Apache-2.0, \