BR2_PACKAGE_SYSPROF selects BR2_PACKAGE_LIBDEX but did not propagate:
depends on BR2_TOOLCHAIN_HAS_UCONTEXT || \
BR2_PACKAGE_LIBUCONTEXT_ARCH_SUPPORTS
from libdex. This commit fixes this missing dependency. In terms of
Config.in comment, we do the same as what libdex is doing: handle it
as a toolchain dependency (rather than an architecture dependency).
This was missed in commit a73ef093f7,
which added the ucontext related dependency to libdex, without
propagating it to sysprof.
Fixes: a73ef093f7 ("package/libdex: needs ucontext")
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
Signed-off-by: Julien Olivain <ju.o@free.fr>
(cherry picked from commit cd5eab10fe)
Signed-off-by: Raphaël Mélotte <raphael.melotte@mind.be>
BR2_PACKAGE_RPI_RGB_LED_MATRIX_IMAGE_VIEWER selects
BR2_PACKAGE_GRAPHICSMAGICK, but did not propagate its BR2_USE_MMU
dependency. This issue exists since the package was introduced in
commit e821078031.
It fixes the following Kconfig warning:
WARNING: unmet direct dependencies detected for BR2_PACKAGE_GRAPHICSMAGICK
Depends on [n]: BR2_USE_MMU [=n] && BR2_TOOLCHAIN_HAS_THREADS [=y]
Selected by [y]:
- BR2_PACKAGE_RPI_RGB_LED_MATRIX_IMAGE_VIEWER [=y] && BR2_PACKAGE_RPI_RGB_LED_MATRIX [=y]
which occurs when you configure an ARM noMMU FDPIC toolchain (because
we have noMMU, but shared libraries, so rpi-rgb-led-matrix can be
enabled).
Fixes: e821078031 ("package/rpi-rgb-led-matrix: new package")
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
Signed-off-by: Julien Olivain <ju.o@free.fr>
(cherry picked from commit e67b301f53)
Signed-off-by: Raphaël Mélotte <raphael.melotte@mind.be>
There's recently been autobuilder failures on
toolchain-external-bootlin, but I wasn't getting notified in the daily
autobuilder e-mail for those failures, which sounded odd as DEVELOPERS
contains:
N: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
[...]
F: toolchain/
And indeed, testing:
$ ./utils/get-developers -p toolchain-external-bootlin
returned nothing.
Turns out that the regexp FIND_INFRA_IN_PATCH and FIND_INFRA_IN_MK
used to find the package infrastructure, and ultimately decide if a
given .mk file contains a package, was a bit too strict:
"^\+\$\(eval \$\((host-)?([^-]*)-package\)\)$"
This would only allow packages named <something>-package or
host-<something>-package, but the <something> should not contain any
dash ("-"). So this works fine for cmake-package,
host-autotools-package, but not for toolchain-external-package where
<something> is toolchain-external and it contains a dash.
We fix this by relaxing the regexp a bit and allowing any character in
<something>. Consider the rest of the regexp that expects $(eval
$(<host>-<something>-package)), it seems highly unlikely to match
anything else but the line we're interested in.
With this fix:
$ ./utils/get-developers -p toolchain-external-bootlin
Giulio Benetti <giulio.benetti@benettiengineering.com>
Romain Naour <romain.naour@gmail.com>
Thomas Petazzoni <thomas.petazzoni@bootlin.com>
This issue has existed since the toolchain-external-package
infrastructure had been added.
Fixes: 1c99d70e52 ("toolchain-external: introduce toolchain-external-package")
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
Signed-off-by: Julien Olivain <ju.o@free.fr>
(cherry picked from commit 592d5c517e)
Signed-off-by: Raphaël Mélotte <raphael.melotte@mind.be>
Building zabbix without libcurl enabled would lead to the following
error:
/usr/bin/ld: .../src/libs/zbxxml/xml.c:515:(.text+0x1c64): undefined reference to `zbx_vector_str_append'
This issue has been addressed in the upstream commit [1] and backported
as a patch in Buildroot.
For more information see the upstream issue [2].
This error is reproducible with the following defconfig:
cat >.config <<EOF
BR2_arm=y
BR2_cortex_a7=y
BR2_TOOLCHAIN_EXTERNAL=y
BR2_TOOLCHAIN_EXTERNAL_BOOTLIN=y
BR2_PACKAGE_PHP=y
BR2_PACKAGE_ZABBIX=y
BR2_PACKAGE_ZABBIX_SERVER=y
BR2_PACKAGE_ZABBIX_SERVER_COPY_FRONTEND=y
EOF
make oldefconfig
make zabbix
[1] https://git.zabbix.com/projects/ZBX/repos/zabbix/commits/e8333ca2128
[2] https://support.zabbix.com/browse/ZBX-27635
Signed-off-by: Thomas Perale <thomas.perale@mind.be>
Signed-off-by: Julien Olivain <ju.o@free.fr>
(cherry picked from commit 489aefc22a)
Signed-off-by: Raphaël Mélotte <raphael.melotte@mind.be>
Zabbix 7.2 is EOL since December 2025 [1]
For more info on the version bump, see:
- https://www.zabbix.com/rn/rn7.2.14
- https://www.zabbix.com/rn/rn7.2.15
This fixes the following vulnerabilties:
- CVE-2026-23920:
Host and event action script input is validated with a regex (set by
the administrator), but the validation runs in multiline mode. If ^
and $ anchors are used in user input validation, an injected newline
lets authenticated users bypass the check and inject shell commands.
https://www.cve.org/CVERecord?id=CVE-2026-23920
- CVE-2026-23921:
A low privilege Zabbix user with API access can exploit a blind SQL
injection vulnerability in include/classes/api/CApiService.php to
execute arbitrary SQL selects via the sortfield parameter. Although
query results are not returned directly, an attacker can exfiltrate
arbitrary database data through time-based techniques, potentially
leading to session identifier disclosure and administrator account
compromise.
https://www.cve.org/CVERecord?id=CVE-2026-23921
[1] https://endoflife.date/zabbix
Signed-off-by: Thomas Perale <thomas.perale@mind.be>
Signed-off-by: Julien Olivain <ju.o@free.fr>
(cherry picked from commit 055a1e249c)
Signed-off-by: Raphaël Mélotte <raphael.melotte@mind.be>
check-package reports six warnings on S60lldpd: indentation with
spaces, no DAEMON variable, and shellcheck complaints.
The script also masks failures, the exit status of
"[ $? = 0 ] && echo OK || echo FAIL" is the one of echo, so start and
stop always return success. Stopping does not wait for the daemon to
exit either, so a restart can race the instance on its way out.
Rewrite it after package/busybox/S01syslogd, as the manual asks. lldpd
daemonizes and writes the PID file itself, but does not remove it on
exit, so pass the PID file to both start-stop-daemon and the daemon and
drop the stale file once the process is gone. Also pick up arguments
from /etc/default/lldpd and add the customary reload alias.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
[Julien: remove .checkpackageignore entry to fix check-package error]
Signed-off-by: Julien Olivain <ju.o@free.fr>
(cherry picked from commit 2fd1f6b629)
[raphael: fix conflict in .checkpackageignore]
Signed-off-by: Raphaël Mélotte <raphael.melotte@mind.be>
In commit 203725a46b ("package/clamav:
bump version to 1.0.1"), select BR2_PACKAGE_JSON_C was added to
BR2_PACKAGE_CLAMAV without propagating the BR2_TOOLCHAIN_HAS_SYNC_4
dependency from BR2_PACKAGE_JSON_C.
Since at the same time a dependency on
BR2_PACKAGE_HOST_RUSTC_TARGET_ARCH_SUPPORTS was added to clamav and
Rust is not supported on the few architectures that don't have 4-byte
sync intrinsics, this has basically no effect, but ensure a correct
propagation of dependencies.
Fixes: 203725a46b ("package/clamav: bump version to 1.0.1")
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
Signed-off-by: Julien Olivain <ju.o@free.fr>
(cherry picked from commit 39b840beef)
Signed-off-by: Thomas Perale <thomas.perale@mind.be>
BR2_PACKAGE_FALCOSECURITY_LIBS selects BR2_PACKAGE_HOST_GRPC and
BR2_PACKAGE_HOST_PROTOBUF, neither of which exists. These selects are
anyway not needed, so drop them.
Fixes: a15e35c4eb ("falcosecurity-libs: add new package")
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
Signed-off-by: Julien Olivain <ju.o@free.fr>
(cherry picked from commit 7f5bb493e2)
Signed-off-by: Thomas Perale <thomas.perale@mind.be>
BR2_PACKAGE_WEBKITGTK_MULTIMEDIA selects BR2_PACKAGE_GST1_LIBAV, which
depends on BR2_PACKAGE_FFMPEG_ARCH_SUPPORTS, but doesn't propagate
this dependency. In practice, there is no issue, as webkitgtk is only
available on a subset of CPU architectures, while
BR2_PACKAGE_FFMPEG_ARCH_SUPPORTS makes ffmpeg available on pretty much
all CPU architectures, except Cortex-M, m68k coldfire, and some
specific cases of OpenRISC, which are not supported by webkitgtk.
But for the sake of having correct dependency propagation, let's fix
this.
The other packages selected by BR2_PACKAGE_WEBKITGTK_MULTIMEDIA have
dependencies that are already handled at the top-level
BR2_PACKAGE_WEBKITGTK option.
Fixes: e6e549b9e4 ("ffmpeg: add BR2_PACKAGE_FFMPEG_ARCH_SUPPORTS")
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
Signed-off-by: Julien Olivain <ju.o@free.fr>
(cherry picked from commit da90655637)
Signed-off-by: Thomas Perale <thomas.perale@mind.be>
In commit
0e2c958e05 ("package/libseccomp: bump to
version 2.5.3"), the kernel headers dependency of seccomp was bumped
from 3.12 to 3.17, but BR2_PACKAGE_WEBKITGTK_SANDBOX, which is a
reverse dependency of BR2_PACKAGE_LIBSECCOMP was forgotten.
This commit fixes this inconsistency.
Fixes: 0e2c958e05 ("package/libseccomp: bump to version 2.5.3")
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
Signed-off-by: Julien Olivain <ju.o@free.fr>
(cherry picked from commit ef92929504)
Signed-off-by: Thomas Perale <thomas.perale@mind.be>
BR2_PACKAGE_LIBSSH_OPENSSL unconditionnally selects
BR2_PACKAGE_LIBOPENSSL_ENGINES even though libressl is also supported
as an OpenSSL provider (and BR2_PACKAGE_LIBOPENSSL_ENGINES doesn't
make sense for libressl).
This causes the following Kconfig warning:
WARNING: unmet direct dependencies detected for BR2_PACKAGE_LIBOPENSSL_ENGINES
Depends on [n]: <choice> && BR2_PACKAGE_LIBOPENSSL [=n]
Selected by [y]:
- BR2_PACKAGE_LIBSSH_OPENSSL [=y] && <choice> && BR2_PACKAGE_OPENSSL [=y]
We checked that libssh, with OpenSSL support and libressl selected as
an OpenSSL provider works fine, using the following defconfig:
BR2_aarch64=y
BR2_TOOLCHAIN_EXTERNAL=y
BR2_TOOLCHAIN_EXTERNAL_BOOTLIN=y
BR2_TOOLCHAIN_EXTERNAL_BOOTLIN_AARCH64_GLIBC_STABLE=y
BR2_PACKAGE_LIBSSH=y
BR2_PACKAGE_LIBSSH_SERVER=y
BR2_PACKAGE_LIBRESSL=y
Fixes: 62103be918 ("package/libssh: select BR2_PACKAGE_LIBOPENSSL_ENGINES")
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
Signed-off-by: Julien Olivain <ju.o@free.fr>
(cherry picked from commit f7fe354ada)
Signed-off-by: Thomas Perale <thomas.perale@mind.be>
BR2_PACKAGE_QT5CINEX selects BR2_PACKAGE_QT5BASE_PNG,
BR2_PACKAGE_QT5BASE_WIDGETS and BR2_PACKAGE_QT5BASE_EGLFS, which are
all sub-options of BR2_PACKAGE_QT5BASE_GUI, but we don't explicitly
selects BR2_PACKAGE_QT5BASE_GUI.
It turns out that things work because the package selects
BR2_PACKAGE_QT5GRAPHICALEFFECTS, which selects
BR2_PACKAGE_QT5DECLARATIVE_QUICK, which selects
BR2_PACKAGE_QT5BASE_GUI, but that is rather non-obvious, and it makes
more sense for BR2_PACKAGE_QT5CINEX to directly select
BR2_PACKAGE_QT5BASE_GUI if it also selects sub-options of it.
No functional change.
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
Signed-off-by: Julien Olivain <ju.o@free.fr>
(cherry picked from commit f077ba9e67)
Signed-off-by: Thomas Perale <thomas.perale@mind.be>
- BR2_PACKAGE_IVI_HOMESCREEN_AUDIO_PLAYERS selects gstreamer1, which
has a depends on BR2_USE_MMU, but does not propagate it
- BR2_PACKAGE_IVI_HOMESCREEN_FLUTTER_SECURE_STORAGE_PLUGIN selects
libsecret, which has a depends on BR2_USE_MMU, but does not propagate
it
In practice there is no problem since ivi-homescreen depends on glibc,
and glibc doesn't support any noMMU architecture. But just by walking
the chain of option dependencies, this is not something that is
theoretically guaranteed (making automated verification of
dependencies difficult).
The other "depends on" from gstreamer1 and libsecret, BR2_USE_WCHAR
and BR2_TOOLCHAIN_HAS_THREADS are on the other hand already handled by
the top-level BR2_PACKAGE_IVI_HOMESCREEN option, so there is no
ambiguity.
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
Signed-off-by: Julien Olivain <ju.o@free.fr>
(cherry picked from commit 90aeea08bb)
Signed-off-by: Thomas Perale <thomas.perale@mind.be>
BR2_PACKAGE_PULSEVIEW selects BR2_PACKAGE_QT5BASE_PNG and
BR2_PACKAGE_QT5BASE_WIDGETS, which both depend on
BR2_PACKAGE_QT5BASE_GUI. It ends working because we also select
BR2_PACKAGE_QT5SVG, which selects BR2_PACKAGE_QT5BASE_GUI, so there is
no bug, but it's bit inconsistent to select sub-options that have a
"depends on" without selecting the option they depend on.
This not a bug fix, it has no functional implication.
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
Signed-off-by: Julien Olivain <ju.o@free.fr>
(cherry picked from commit aff091c39d)
Signed-off-by: Thomas Perale <thomas.perale@mind.be>
This fixes the following vulnerability:
CVE-2026-82373: Use-after-free when unloading modules, triggered by
unprivileged users
Signed-off-by: Titouan Christophe <titouan.christophe@mind.be>
(alternative to commit 43558e103b)
Signed-off-by: Thomas Perale <thomas.perale@mind.be>
Even though kodi itself has architecture dependencies (expressed
through BR2_PACKAGE_KODI_ARCH_SUPPORTS, the option
BR2_PACKAGE_KODI_MYSQL selects BR2_PACKAGE_MARIADB, which has its own
architecture dependencies as well. Make sure to propagate those to
BR2_PACKAGE_KODI_MYSQL, which doesn't require adding a Config.in
comment as these are purely architecture dependencies.
We haven't replicate all dependencies of BR2_PACKAGE_MARIADB because
all the others are covered by the top-level BR2_PACKAGE_KODI, and
propagating them would require adding a Config.in comment for
BR2_PACKAGE_KODI_MYSQL.
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
Signed-off-by: Julien Olivain <ju.o@free.fr>
(cherry picked from commit 16e3d628bd)
Signed-off-by: Thomas Perale <thomas.perale@mind.be>
Since hidapi was introduced in commit
6267f34afd, it forgot to propagate some
dependencies of libgudev (which existed back then). Initially libgudev
was only needed when BR2_INIT_SYSTEMD=y, but still the dependencies
were not propagated for the systemd case.
Anyway, since e739dd5a11, libgudev is a
mandatory dependency of hidapi, independently from the selected init
system.
We make sure to propagate all dependencies of libgudev to hidapi, and
propagate them to the reverse dependencies of hidapi.
Fixes: 6267f34afd ("hidapi: new package")
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
Signed-off-by: Julien Olivain <ju.o@free.fr>
(cherry picked from commit 74def2cdd4)
[tperale: drop libmanette change not present]
Signed-off-by: Thomas Perale <thomas.perale@mind.be>
BR2_PACKAGE_ARGP_STANDALONE is defined as follows:
config BR2_PACKAGE_ARGP_STANDALONE
depends on !BR2_TOOLCHAIN_USES_GLIBC
Some packages did:
select BR2_PACKAGE_ARGP_STANDALONE if !BR2_TOOLCHAIN_USES_GLIBC
while a number of others did:
select BR2_PACKAGE_ARGP_STANDALONE if BR2_TOOLCHAIN_USES_UCLIBC || BR2_TOOLCHAIN_USES_MUSL
This commit harmonizes the situation, by settling on the first
solution ("if !BR2_TOOLCHAIN_USES_GLIBC") as it matches how
BR2_PACKAGE_ARGP_STANDALONE is defined in the first place.
No functional change.
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
Signed-off-by: Julien Olivain <ju.o@free.fr>
(cherry picked from commit 1799bf3680)
Signed-off-by: Thomas Perale <thomas.perale@mind.be>
BR2_PACKAGE_INTEL_VPL_GPU_RT selects BR2_PACKAGE_INTEL_MEDIADRIVER but
did not propagate "depends on BR2_TOOLCHAIN_GCC_AT_LEAST_8". This
commit fixes this issue, which was introduced in commit
ac65841def, when onevpl-intel-gpu was
introduced (it was later renamed to intel-vpl-gpu-rt).
Fixes: ac65841def ("package/onevpl-intel-gpu: new package")
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
Signed-off-by: Julien Olivain <ju.o@free.fr>
(cherry picked from commit 876023bc5a)
Signed-off-by: Thomas Perale <thomas.perale@mind.be>
BR2_PACKAGE_INTEL_MEDIASDK selects BR2_PACKAGE_INTEL_MEDIADRIVER but
forgets to propagate the "depends on BR2_TOOLCHAIN_GCC_AT_LEAST_8".
This issue was introduced in commit
51b60c8acf, when "depends on
BR2_TOOLCHAIN_GCC_AT_LEAST_8" was added to mesa3d, propagated to
intel-mediadriver, but not intel-mediasdk.
Fixes: 51b60c8acf ("package/mesa3d: needs gcc >= 8")
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
Signed-off-by: Julien Olivain <ju.o@free.fr>
(cherry picked from commit fa38fea91c)
Signed-off-by: Thomas Perale <thomas.perale@mind.be>
BR2_PACKAGE_PYTHON_GRPCIO_REFLECTION selects
BR2_PACKAGE_PYTHON_PROTOBUF, but forgot to replicate "depends on
BR2_PACKAGE_HOST_PROTOBUF_ARCH_SUPPORTS".
Fixes: 3217fedcb8 ("package/python-grpcio-reflection: new package")
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
Signed-off-by: Julien Olivain <ju.o@free.fr>
(cherry picked from commit 74dab03495)
Signed-off-by: Thomas Perale <thomas.perale@mind.be>
BR2_PACKAGE_PYTHON_GOOGLEAPIS_COMMON_PROTOS selects
BR2_PACKAGE_PYTHON_PROTOBUF but did not propagate
BR2_PACKAGE_HOST_PROTOBUF_ARCH_SUPPORTS.
Fixes: d37766a886 ("package/python-googleapis-common-protos: new package")
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
Signed-off-by: Julien Olivain <ju.o@free.fr>
(cherry picked from commit 548904619c)
Signed-off-by: Thomas Perale <thomas.perale@mind.be>
Commit 66ddec89e8 ("package/udisks: bump
to version 2.92") mistakenly removed the BR2_USE_MMU dependency of
udisks when dropping "select BR2_PACKAGE_LVM2". Indeed, BR2_USE_MMU is
a dependency of many other packages selected by udisks.
Interestingly, the Config.in comments in the same file still had the
"depends on BR2_USE_MMU" dependencies.
Fixes: 66ddec89e8 ("package/udisks: bump to version 2.92")
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
Signed-off-by: Julien Olivain <ju.o@free.fr>
(cherry picked from commit 4b8259bad9)
Signed-off-by: Thomas Perale <thomas.perale@mind.be>
Since bcc was introduced in commit
146498d13c, it lacked a dependency
propagation from clang for BR2_TOOLCHAIN_HAS_GCC_BUG_64735, this
commit fixes this mistake.
Fixes: 146498d13c ("package/bcc: new package")
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
Signed-off-by: Julien Olivain <ju.o@free.fr>
(cherry picked from commit c305370f36)
Signed-off-by: Thomas Perale <thomas.perale@mind.be>
BR2_PACKAGE_HOST_GO_TARGET_ARCH_SUPPORTS redefines the conditions to
determine if a host go compiler is available for the current host
architecture. Instead, make it explicit that those conditions are the
same by re-using BR2_PACKAGE_HOST_GO_HOST_ARCH_SUPPORTS.
No functional change.
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
Signed-off-by: Julien Olivain <ju.o@free.fr>
(cherry picked from commit 71d3ffd372)
Signed-off-by: Thomas Perale <thomas.perale@mind.be>
Fixes a sandbox escape through symlink traversal tracked in
CVE-2026-87766, which affects all previous versions.
Using the bwrap binary with the setuid bit set is no longer supported
and user namespaces are now always required, so a kernel config fixup
is applied.
A new build option allows indicating the minimum kernel version that
will be used, which removes code used for backwards compatibility with
kernels older than 5.6.0 when a newer version is specified. Passing
$(LINUX_VERSION_PROBED) seems reasonable here.
This version also changed the license from LGPL-2.0+ to LGPL-2.1+,
hence the updated hash.
Release notes:
https://github.com/containers/bubblewrap/releases/tag/v0.12.0
Signed-off-by: Adrian Perez de Castro <aperez@igalia.com>
[Julien: fix _LINUX_CONFIG_FIXUPS by adding the missing "_LINUX"]
Signed-off-by: Julien Olivain <ju.o@free.fr>
(cherry picked from commit 4cb6193d2e)
Signed-off-by: Thomas Perale <thomas.perale@mind.be>
Prior to improving check-package to verify that the comment preceding
a <pkg>_IGNORE_CVES entry mentions an existing patch, and that the
patch itself contains a CVE: tag, we fix all problematic cases that
currently exist in Buildroot:
- In the case of binutils: the CVE was only applicable to binutils
2.43/2.44, and the oldest version now supported is 2.45, so the
patch doesn't exist anymore in Buildroot
- For x11vnc, fix a typo in the patch name
- Similarly for micropython, the patches were dropped in [1] along with
the version bump
- Add missing 'CVE:' tag to net-tools patch 0001
- edk2 add missing CVE trailer
- libfreeglut add missing CVE trailer
- libfreeimage correct reference to patch
- libical add missing CVE trailer
- proftpd correct reference to patch
- sylpheed add missing CVE trailer
[1] 28eeca9a98 package/micropython: bump to version 1.28.0
Signed-off-by: Titouan Christophe <titouan.christophe@mind.be>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
(cherry picked from commit 636f69ab45)
[thomas: adapt to 2025.02.x]
Signed-off-by: Thomas Perale <thomas.perale@mind.be>
To indicate that a patch fixes a vulnerability in Buildroot, the convention is:
1. In the patch file, add a tag 'CVE: <cve id>'
2. In <pkg>.mk, and an entry to <PKG>_IGNORE_CVES, and add a comment above
that new entry to reference the patch file(s)
However, as packages get bumped and their patches are added, removed or
rebased; it happens that IGNORE_CVES get outdated. One important issue is
marking a CVE as ignored, while the corresponding patch is not in Buildroot.
To detect such cases, add a new checker to checkpackagelib that finds
occurences of:
# 000x-some-patch.patch
PKG_IGNORE_CVES += CVE-XXXX-YYYY
For each one of them, ensure that the mentioned patch files actually exist
and contain the `CVE: ...` tag.
Assisted-by: Claude:claude-opus-4.8
Signed-off-by: Titouan Christophe <titouan.christophe@mind.be>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
(cherry picked from commit b00ac4e346)
Signed-off-by: Thomas Perale <thomas.perale@mind.be>
https://github.com/PCRE2Project/pcre2/releases/tag/pcre2-10.48
Fixes the following security issues:
(Security fix for specific API usage, GHSA-2p8c-ff85-vh9x)
If pcre2_jit_compile() is called with options for some match modes, and
then pcre2_match() is used to perform a match for a different match
mode, an out-of-bounds read can occur if the match is attempted against
invalid UTF input.
(Security fix for pattern conversion, GHSA-q8g2-wprr-34m9)
If pcre2_convert() is called on untrusted input on platforms with
32-bit size_t, an out-of-bounds heap write can occur.
(Security fix, GHSA-3r4p-g7gg-ppmf) Fixed an out-of-bounds write in DFA
matching when using a heap limit; also fixed possible integer overflows
which could cause under-allocation of the workspace.
(Security fix, GHSA-fmgr-6ggq-9859) Added bounds checks for several
integer overflows while compiling patterns on 32-bit CPUs, which could
cause under-allocation followed by out-of-bounds writes.
(Security fix, GHSA-9qww-pwc4-77qq) Applied lower buffer bound to
prevent two out-of-bounds reads while scanning backwards through
invalid UTF data with PCRE2_MATCH_INVALID_UTF.
(Security fix for specific API usage, #937) Fixed a leak and later
invalid free when calling the fast-path pcre2_jit_match() function with
a match data object previously used with pcre2_match() and
PCRE2_COPY_MATCHED_SUBJECT.
(Low-severity security fix, GHSA-q7rw-r7qq-2hx6) Fixed exposure of two
uninitialised bytes from malloc() via pcre2_serialize_encode().
Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Julien Olivain <ju.o@free.fr>
(cherry picked from commit 664db5d62c)
Signed-off-by: Thomas Perale <thomas.perale@mind.be>
https://github.com/kernelsauce/turbo/releases/tag/v2.1.5https://github.com/kernelsauce/turbo/releases/tag/v2.1.4
Security fixes:
HTTP header injection: header values were only checked for a literal
\r\n, so a lone \r or \n could still split a header. Now rejected on
either character.
Transfer-Encoding requests are now rejected with 501 instead of silently
mishandled, closing a request smuggling avenue.
A real default request body size cap (128 MB) with a 413 response,
previously unbounded.
Secure cookie signature now binds the cookie name, so a value signed for
one cookie can no longer be replayed under a different name.
Verification failures return the default value instead of raising.
Constant-time comparison for the secure cookie HMAC, previously a
timing-leaky ==.
util.secure_random_bytes reads real OS entropy (/dev/urandom,
BCryptGenRandom on Windows) for WebSocket masks and util.rand_str,
previously math.random.
WebSocket: unmasked client frames are rejected per RFC 6455, and
fragmented message reassembly is capped to max_buffer_size to close a
memory exhaustion path.
StaticFileHandler decodes the request path before the traversal check,
closing a bypass.
Fixed a 32-byte-per-malformed-request memory leak in the C header parser
wrapper (found via libFuzzer).
Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Julien Olivain <ju.o@free.fr>
(cherry picked from commit 15a422cee1)
Signed-off-by: Thomas Perale <thomas.perale@mind.be>
https://github.com/the-tcpdump-group/libpcap/blob/libpcap-1.10.7/CHANGES
Fixes the following CVEs:
CVE-2026-0799: Access M[] safely in the BPF interpreter.
CVE-2026-31912: Mind the program bounds in pcap_offline_filter().
CVE-2026-31911: Fail opcodes safely in the BPF interpreter.
CVE-2026-6244: Avoid division by zero via pcap_offline_filter().
CVE-2026-6554: Limit "ja L" looping in pcap_offline_filter().
CVE-2026-18313: Fix a memory leak in rpcapd.
CVE-2026-18238: Fix RPCAP_MSG_PACKET validation.
Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Julien Olivain <ju.o@free.fr>
(cherry picked from commit 446c0f85b8)
Signed-off-by: Thomas Perale <thomas.perale@mind.be>
This fix has been released in OpenVPN 2.7.7, but is not available yet for
OpenVPN 2.6 series (which is included in Buildroot 2025.02.x)
(alternative to commit 25b8142ef7)
Signed-off-by: Titouan Christophe <titouan.christophe@mind.be>
Signed-off-by: Thomas Perale <thomas.perale@mind.be>
Commit 1afe223d4c was wrongly applied.
This commit was the v1 of a series that as since been superseeded and
fixed.
Revert this commit to correctly apply the patch that fix
CVE-2026-84732.
Signed-off-by: Thomas Perale <thomas.perale@mind.be>