mirror of
https://gitlab.com/buildroot.org/buildroot.git
synced 2026-09-30 22:11:59 -09:00
package/lldpd: security bump to version 1.0.22
https://github.com/lldpd/lldpd/releases/tag/1.0.22
https://github.com/lldpd/lldpd/releases/tag/1.0.21
Fixes CVE-2026-46433, an out-of-bound read access when removing the
VLAN tag. 1.0.21 fixes path traversal vulnerabilities and arbitrary
file deletion in the privileged process.
GPG signature verified with key AEF2348766F371C689A7360095A42FE8353525F9,
LICENSE hash unchanged.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
Signed-off-by: Julien Olivain <ju.o@free.fr>
(cherry picked from commit 03e4bebcd2)
Signed-off-by: Raphaël Mélotte <raphael.melotte@mind.be>
This commit is contained in:
committed by
Raphaël Mélotte
parent
f8c4315d4c
commit
e12ef9c652
@@ -1,6 +1,6 @@
|
||||
# Locally computed after checking gpg key
|
||||
# https://media.luffy.cx/files/lldpd/lldpd-1.0.20.tar.gz.gpg
|
||||
# https://media.luffy.cx/files/lldpd/lldpd-1.0.22.tar.gz.gpg
|
||||
# using key AEF2348766F371C689A7360095A42FE8353525F9
|
||||
# gpg --verify lldpd-1.0.20.tar.gz.gpg lldpd-1.0.20.tar.gz
|
||||
sha256 61b8cb22d4879e68f7825a2fb8e1e92abb4aba4773977cf0258bc32ed9f55450 lldpd-1.0.20.tar.gz
|
||||
# gpg --verify lldpd-1.0.22.tar.gz.gpg lldpd-1.0.22.tar.gz
|
||||
sha256 9587940ed2314a86774c5499f3dfb13a8eb86232a62d243a83a1f09886848e03 lldpd-1.0.22.tar.gz
|
||||
sha256 0e96a5aea65f16e2239231ce4ab90497f8bc3bb8fe6abe9299aade4726ff7c8d LICENSE
|
||||
|
||||
@@ -4,7 +4,7 @@
|
||||
#
|
||||
################################################################################
|
||||
|
||||
LLDPD_VERSION = 1.0.20
|
||||
LLDPD_VERSION = 1.0.22
|
||||
LLDPD_SITE = https://media.luffy.cx/files/lldpd
|
||||
LLDPD_DEPENDENCIES = \
|
||||
$(if $(BR2_PACKAGE_CHECK),check) \
|
||||
|
||||
Reference in New Issue
Block a user