Commit Graph

79054 Commits

Author SHA1 Message Date
Thomas Petazzoni
d75b314ec8 package/sysprof: propagate ucontext-related dependency from libdex
BR2_PACKAGE_SYSPROF selects BR2_PACKAGE_LIBDEX but did not propagate:

	depends on BR2_TOOLCHAIN_HAS_UCONTEXT || \
		BR2_PACKAGE_LIBUCONTEXT_ARCH_SUPPORTS

from libdex. This commit fixes this missing dependency. In terms of
Config.in comment, we do the same as what libdex is doing: handle it
as a toolchain dependency (rather than an architecture dependency).

This was missed in commit a73ef093f7,
which added the ucontext related dependency to libdex, without
propagating it to sysprof.

Fixes: a73ef093f7 ("package/libdex: needs ucontext")
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
Signed-off-by: Julien Olivain <ju.o@free.fr>
(cherry picked from commit cd5eab10fe)
Signed-off-by: Raphaël Mélotte <raphael.melotte@mind.be>
2026-09-23 17:47:00 +02:00
Thomas Petazzoni
74de503423 package/rpi-rgb-led-matrix: propagate BR2_PACKAGE_GRAPHICSMAGICK dependency
BR2_PACKAGE_RPI_RGB_LED_MATRIX_IMAGE_VIEWER selects
BR2_PACKAGE_GRAPHICSMAGICK, but did not propagate its BR2_USE_MMU
dependency. This issue exists since the package was introduced in
commit e821078031.

It fixes the following Kconfig warning:

WARNING: unmet direct dependencies detected for BR2_PACKAGE_GRAPHICSMAGICK
  Depends on [n]: BR2_USE_MMU [=n] && BR2_TOOLCHAIN_HAS_THREADS [=y]
  Selected by [y]:
  - BR2_PACKAGE_RPI_RGB_LED_MATRIX_IMAGE_VIEWER [=y] && BR2_PACKAGE_RPI_RGB_LED_MATRIX [=y]

which occurs when you configure an ARM noMMU FDPIC toolchain (because
we have noMMU, but shared libraries, so rpi-rgb-led-matrix can be
enabled).

Fixes: e821078031 ("package/rpi-rgb-led-matrix: new package")
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
Signed-off-by: Julien Olivain <ju.o@free.fr>
(cherry picked from commit e67b301f53)
Signed-off-by: Raphaël Mélotte <raphael.melotte@mind.be>
2026-09-23 17:46:53 +02:00
Thomas Petazzoni
9d2c262030 utils/getdeveloperlib.py: fix regexp used to find package infra
There's recently been autobuilder failures on
toolchain-external-bootlin, but I wasn't getting notified in the daily
autobuilder e-mail for those failures, which sounded odd as DEVELOPERS
contains:

N:      Thomas Petazzoni <thomas.petazzoni@bootlin.com>
[...]
F:      toolchain/

And indeed, testing:

$ ./utils/get-developers -p toolchain-external-bootlin

returned nothing.

Turns out that the regexp FIND_INFRA_IN_PATCH and FIND_INFRA_IN_MK
used to find the package infrastructure, and ultimately decide if a
given .mk file contains a package, was a bit too strict:

"^\+\$\(eval \$\((host-)?([^-]*)-package\)\)$"

This would only allow packages named <something>-package or
host-<something>-package, but the <something> should not contain any
dash ("-"). So this works fine for cmake-package,
host-autotools-package, but not for toolchain-external-package where
<something> is toolchain-external and it contains a dash.

We fix this by relaxing the regexp a bit and allowing any character in
<something>. Consider the rest of the regexp that expects $(eval
$(<host>-<something>-package)), it seems highly unlikely to match
anything else but the line we're interested in.

With this fix:

$ ./utils/get-developers -p toolchain-external-bootlin
Giulio Benetti <giulio.benetti@benettiengineering.com>
Romain Naour <romain.naour@gmail.com>
Thomas Petazzoni <thomas.petazzoni@bootlin.com>

This issue has existed since the toolchain-external-package
infrastructure had been added.

Fixes: 1c99d70e52 ("toolchain-external: introduce toolchain-external-package")
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
Signed-off-by: Julien Olivain <ju.o@free.fr>
(cherry picked from commit 592d5c517e)
Signed-off-by: Raphaël Mélotte <raphael.melotte@mind.be>
2026-09-23 17:46:41 +02:00
Thomas Perale
029033171c package/zabbix: fix build without libcurl
Building zabbix without libcurl enabled would lead to the following
error:

/usr/bin/ld: .../src/libs/zbxxml/xml.c:515:(.text+0x1c64): undefined reference to `zbx_vector_str_append'

This issue has been addressed in the upstream commit [1] and backported
as a patch in Buildroot.
For more information see the upstream issue [2].

This error is reproducible with the following defconfig:

cat >.config <<EOF
BR2_arm=y
BR2_cortex_a7=y
BR2_TOOLCHAIN_EXTERNAL=y
BR2_TOOLCHAIN_EXTERNAL_BOOTLIN=y
BR2_PACKAGE_PHP=y
BR2_PACKAGE_ZABBIX=y
BR2_PACKAGE_ZABBIX_SERVER=y
BR2_PACKAGE_ZABBIX_SERVER_COPY_FRONTEND=y
EOF
make oldefconfig
make zabbix

[1] https://git.zabbix.com/projects/ZBX/repos/zabbix/commits/e8333ca2128
[2] https://support.zabbix.com/browse/ZBX-27635

Signed-off-by: Thomas Perale <thomas.perale@mind.be>
Signed-off-by: Julien Olivain <ju.o@free.fr>
(cherry picked from commit 489aefc22a)
Signed-off-by: Raphaël Mélotte <raphael.melotte@mind.be>
2026-09-23 17:46:35 +02:00
Thomas Perale
fc4bfe4a15 package/zabbix: security bump to v7.2.15
Zabbix 7.2 is EOL since December 2025 [1]

For more info on the version bump, see:
 - https://www.zabbix.com/rn/rn7.2.14
 - https://www.zabbix.com/rn/rn7.2.15

This fixes the following vulnerabilties:

- CVE-2026-23920:
    Host and event action script input is validated with a regex (set by
    the administrator), but the validation runs in multiline mode. If ^
    and $ anchors are used in user input validation, an injected newline
    lets authenticated users bypass the check and inject shell commands.
    https://www.cve.org/CVERecord?id=CVE-2026-23920

- CVE-2026-23921:
    A low privilege Zabbix user with API access can exploit a blind SQL
    injection vulnerability in include/classes/api/CApiService.php to
    execute arbitrary SQL selects via the sortfield parameter. Although
    query results are not returned directly, an attacker can exfiltrate
    arbitrary database data through time-based techniques, potentially
    leading to session identifier disclosure and administrator account
    compromise.
    https://www.cve.org/CVERecord?id=CVE-2026-23921

[1] https://endoflife.date/zabbix

Signed-off-by: Thomas Perale <thomas.perale@mind.be>
Signed-off-by: Julien Olivain <ju.o@free.fr>
(cherry picked from commit 055a1e249c)
Signed-off-by: Raphaël Mélotte <raphael.melotte@mind.be>
2026-09-23 17:46:28 +02:00
Thomas Perale
fe4475f19c package/zabbix: update SITE
Zabbix version 7.2 is no longer maintained. The version 7.0 is the LTS
and the stable moved to 7.4 [1]. The source location moved from "stable"
to "oldstable" directory.

This error is present in the autobuilder since the 22nd of May.

[1] https://endoflife.date/zabbix

Fixes: https://autobuild.buildroot.org/results/636/636c4514c67f1b0fcd20976d064f17b0e0a314fe//
Signed-off-by: Thomas Perale <thomas.perale@mind.be>
Signed-off-by: Julien Olivain <ju.o@free.fr>
(cherry picked from commit 7878630479)
Signed-off-by: Raphaël Mélotte <raphael.melotte@mind.be>
2026-09-23 17:45:59 +02:00
Bernd Kuhls
94a3b0cba0 package/libheif: security bump version to 1.23.4
https://github.com/strukturag/libheif/releases/tag/v1.23.4

Fixes the following CVEs:

(CVE numbers will be added when assigned.)

CVE-2026-XXXXX (GHSA-vg7w-rp49-4fc2)
CVE-2026-XXXXX (GHSA-xrp2-63fq-jm8q)
CVE-2026-XXXXX (GHSA-prgh-72vc-3xmc)
CVE-2026-XXXXX (GHSA-fqpw-fj22-78w4)
CVE-2026-XXXXX (GHSA-4rv4-953r-p24q)
CVE-2026-XXXXX (GHSA-rhgw-q5g8-xjh2)

Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Julien Olivain <ju.o@free.fr>
(cherry picked from commit 053c724d6e)
Signed-off-by: Raphaël Mélotte <raphael.melotte@mind.be>
2026-09-23 17:45:51 +02:00
Joachim Wiberg
bea9b76f1c package/lldpd: rework start script
check-package reports six warnings on S60lldpd: indentation with
spaces, no DAEMON variable, and shellcheck complaints.

The script also masks failures, the exit status of
"[ $? = 0 ] && echo OK || echo FAIL" is the one of echo, so start and
stop always return success.  Stopping does not wait for the daemon to
exit either, so a restart can race the instance on its way out.

Rewrite it after package/busybox/S01syslogd, as the manual asks.  lldpd
daemonizes and writes the PID file itself, but does not remove it on
exit, so pass the PID file to both start-stop-daemon and the daemon and
drop the stale file once the process is gone.  Also pick up arguments
from /etc/default/lldpd and add the customary reload alias.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
[Julien: remove .checkpackageignore entry to fix check-package error]
Signed-off-by: Julien Olivain <ju.o@free.fr>
(cherry picked from commit 2fd1f6b629)
[raphael: fix conflict in .checkpackageignore]
Signed-off-by: Raphaël Mélotte <raphael.melotte@mind.be>
2026-09-23 17:45:01 +02:00
Joachim Wiberg
75063b2556 package/lldpd: security bump to version 1.0.22
https://github.com/lldpd/lldpd/releases/tag/1.0.22
https://github.com/lldpd/lldpd/releases/tag/1.0.21

Fixes CVE-2026-46433, an out-of-bound read access when removing the
VLAN tag.  1.0.21 fixes path traversal vulnerabilities and arbitrary
file deletion in the privileged process.

GPG signature verified with key AEF2348766F371C689A7360095A42FE8353525F9,
LICENSE hash unchanged.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
Signed-off-by: Julien Olivain <ju.o@free.fr>
(cherry picked from commit 03e4bebcd2)
Signed-off-by: Raphaël Mélotte <raphael.melotte@mind.be>
2026-09-23 16:57:24 +02:00
Akhilesh Nema
03fe784a0a package/lldpd: bump to version 1.0.20
Release notes:
https://github.com/lldpd/lldpd/releases/tag/1.0.20
https://github.com/lldpd/lldpd/releases/tag/1.0.19

Signed-off-by: Akhilesh Nema <nemaakhilesh@gmail.com>
Signed-off-by: Julien Olivain <ju.o@free.fr>
(cherry picked from commit 779e7cd7a9)
Signed-off-by: Raphaël Mélotte <raphael.melotte@mind.be>
2026-09-23 16:57:09 +02:00
Peter Korsgaard
0374d408e6 package/x11r7/xlib_libXfont2: security bump to version 2.0.9
Fixes the following vulnerabilities:

- CVE-2026-59679: Font Server Client encoding Out-Of-Bounds Read/Write
- CVE-2026-44950: Font Server Client Cumulative Glyph Data Heap Buffer
  Overflow

For more details, see the advisory:
https://lists.x.org/archives/xorg-announce/2026-August/003734.html

Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
Signed-off-by: Julien Olivain <ju.o@free.fr>
(cherry picked from commit 21f18cd012)
Signed-off-by: Raphaël Mélotte <raphael.melotte@mind.be>
2026-09-23 16:45:25 +02:00
Titouan Christophe
7c51110fc2 {linux, linux-headers}: bump 6.12 series
Update the latest kernel releases:
    - 6.12.110 -> 6.12.111

Signed-off-by: Titouan Christophe <titouan.christophe@mind.be>
2026-09-22 16:57:35 +02:00
Giulio Benetti
923b93426b package/nfs-utils: bump version to 2.8.7
Release announce:
https://lore.kernel.org/linux-nfs/4d11b9d7-7b49-4a1e-8c26-29ecb2fefe2f@redhat.com/

Signed-off-by: Giulio Benetti <giulio.benetti@benettiengineering.com>
Reviewed-by: Petr Vorel <petr.vorel@gmail.com>
[Julien: remove "security" in commit title]
Signed-off-by: Julien Olivain <ju.o@free.fr>
Fixes: https://gitlab.com/buildroot.org/buildroot/-/work_items/191
(cherry picked from commit 49c1e1181f)
Signed-off-by: Thomas Perale <thomas.perale@mind.be>
2026-09-18 13:06:53 +02:00
Thomas Petazzoni
51a16f40de package/clamav: add missing BR2_TOOLCHAIN_HAS_SYNC_4 dependency
In commit 203725a46b ("package/clamav:
bump version to 1.0.1"), select BR2_PACKAGE_JSON_C was added to
BR2_PACKAGE_CLAMAV without propagating the BR2_TOOLCHAIN_HAS_SYNC_4
dependency from BR2_PACKAGE_JSON_C.

Since at the same time a dependency on
BR2_PACKAGE_HOST_RUSTC_TARGET_ARCH_SUPPORTS was added to clamav and
Rust is not supported on the few architectures that don't have 4-byte
sync intrinsics, this has basically no effect, but ensure a correct
propagation of dependencies.

Fixes: 203725a46b ("package/clamav: bump version to 1.0.1")
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
Signed-off-by: Julien Olivain <ju.o@free.fr>
(cherry picked from commit 39b840beef)
Signed-off-by: Thomas Perale <thomas.perale@mind.be>
2026-09-18 11:19:38 +02:00
Thomas Petazzoni
d667e4e7a6 package/falcosecurity-libs: drop meaningless selects
BR2_PACKAGE_FALCOSECURITY_LIBS selects BR2_PACKAGE_HOST_GRPC and
BR2_PACKAGE_HOST_PROTOBUF, neither of which exists. These selects are
anyway not needed, so drop them.

Fixes: a15e35c4eb ("falcosecurity-libs: add new package")
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
Signed-off-by: Julien Olivain <ju.o@free.fr>
(cherry picked from commit 7f5bb493e2)
Signed-off-by: Thomas Perale <thomas.perale@mind.be>
2026-09-18 11:19:36 +02:00
Thomas Petazzoni
3fd4063c23 package/webkitgtk: propagate gst1-libav architecture dependency
BR2_PACKAGE_WEBKITGTK_MULTIMEDIA selects BR2_PACKAGE_GST1_LIBAV, which
depends on BR2_PACKAGE_FFMPEG_ARCH_SUPPORTS, but doesn't propagate
this dependency. In practice, there is no issue, as webkitgtk is only
available on a subset of CPU architectures, while
BR2_PACKAGE_FFMPEG_ARCH_SUPPORTS makes ffmpeg available on pretty much
all CPU architectures, except Cortex-M, m68k coldfire, and some
specific cases of OpenRISC, which are not supported by webkitgtk.

But for the sake of having correct dependency propagation, let's fix
this.

The other packages selected by BR2_PACKAGE_WEBKITGTK_MULTIMEDIA have
dependencies that are already handled at the top-level
BR2_PACKAGE_WEBKITGTK option.

Fixes: e6e549b9e4 ("ffmpeg: add BR2_PACKAGE_FFMPEG_ARCH_SUPPORTS")
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
Signed-off-by: Julien Olivain <ju.o@free.fr>
(cherry picked from commit da90655637)
Signed-off-by: Thomas Perale <thomas.perale@mind.be>
2026-09-18 11:19:33 +02:00
Thomas Petazzoni
b418c17fe8 package/webkit: fix kernel headers dependency due to seccomp select
In commit
0e2c958e05 ("package/libseccomp: bump to
version 2.5.3"), the kernel headers dependency of seccomp was bumped
from 3.12 to 3.17, but BR2_PACKAGE_WEBKITGTK_SANDBOX, which is a
reverse dependency of BR2_PACKAGE_LIBSECCOMP was forgotten.

This commit fixes this inconsistency.

Fixes: 0e2c958e05 ("package/libseccomp: bump to version 2.5.3")
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
Signed-off-by: Julien Olivain <ju.o@free.fr>
(cherry picked from commit ef92929504)
Signed-off-by: Thomas Perale <thomas.perale@mind.be>
2026-09-18 11:19:31 +02:00
Thomas Petazzoni
981c60907f package/libssh: fix select BR2_PACKAGE_LIBOPENSSL_ENGINES
BR2_PACKAGE_LIBSSH_OPENSSL unconditionnally selects
BR2_PACKAGE_LIBOPENSSL_ENGINES even though libressl is also supported
as an OpenSSL provider (and BR2_PACKAGE_LIBOPENSSL_ENGINES doesn't
make sense for libressl).

This causes the following Kconfig warning:

WARNING: unmet direct dependencies detected for BR2_PACKAGE_LIBOPENSSL_ENGINES
  Depends on [n]: <choice> && BR2_PACKAGE_LIBOPENSSL [=n]
  Selected by [y]:
  - BR2_PACKAGE_LIBSSH_OPENSSL [=y] && <choice> && BR2_PACKAGE_OPENSSL [=y]

We checked that libssh, with OpenSSL support and libressl selected as
an OpenSSL provider works fine, using the following defconfig:

BR2_aarch64=y
BR2_TOOLCHAIN_EXTERNAL=y
BR2_TOOLCHAIN_EXTERNAL_BOOTLIN=y
BR2_TOOLCHAIN_EXTERNAL_BOOTLIN_AARCH64_GLIBC_STABLE=y
BR2_PACKAGE_LIBSSH=y
BR2_PACKAGE_LIBSSH_SERVER=y
BR2_PACKAGE_LIBRESSL=y

Fixes: 62103be918 ("package/libssh: select BR2_PACKAGE_LIBOPENSSL_ENGINES")
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
Signed-off-by: Julien Olivain <ju.o@free.fr>
(cherry picked from commit f7fe354ada)
Signed-off-by: Thomas Perale <thomas.perale@mind.be>
2026-09-18 11:19:28 +02:00
Thomas Petazzoni
215f018aec package/qt5cinex: add missing select BR2_PACKAGE_QT5BASE_GUI
BR2_PACKAGE_QT5CINEX selects BR2_PACKAGE_QT5BASE_PNG,
BR2_PACKAGE_QT5BASE_WIDGETS and BR2_PACKAGE_QT5BASE_EGLFS, which are
all sub-options of BR2_PACKAGE_QT5BASE_GUI, but we don't explicitly
selects BR2_PACKAGE_QT5BASE_GUI.

It turns out that things work because the package selects
BR2_PACKAGE_QT5GRAPHICALEFFECTS, which selects
BR2_PACKAGE_QT5DECLARATIVE_QUICK, which selects
BR2_PACKAGE_QT5BASE_GUI, but that is rather non-obvious, and it makes
more sense for BR2_PACKAGE_QT5CINEX to directly select
BR2_PACKAGE_QT5BASE_GUI if it also selects sub-options of it.

No functional change.

Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
Signed-off-by: Julien Olivain <ju.o@free.fr>
(cherry picked from commit f077ba9e67)
Signed-off-by: Thomas Perale <thomas.perale@mind.be>
2026-09-18 11:19:26 +02:00
Thomas Petazzoni
84ef784c42 package/ivi-homescreen: add missing BR2_USE_MMU dependencies
- BR2_PACKAGE_IVI_HOMESCREEN_AUDIO_PLAYERS selects gstreamer1, which
  has a depends on BR2_USE_MMU, but does not propagate it

- BR2_PACKAGE_IVI_HOMESCREEN_FLUTTER_SECURE_STORAGE_PLUGIN selects
  libsecret, which has a depends on BR2_USE_MMU, but does not propagate
  it

In practice there is no problem since ivi-homescreen depends on glibc,
and glibc doesn't support any noMMU architecture. But just by walking
the chain of option dependencies, this is not something that is
theoretically guaranteed (making automated verification of
dependencies difficult).

The other "depends on" from gstreamer1 and libsecret, BR2_USE_WCHAR
and BR2_TOOLCHAIN_HAS_THREADS are on the other hand already handled by
the top-level BR2_PACKAGE_IVI_HOMESCREEN option, so there is no
ambiguity.

Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
Signed-off-by: Julien Olivain <ju.o@free.fr>
(cherry picked from commit 90aeea08bb)
Signed-off-by: Thomas Perale <thomas.perale@mind.be>
2026-09-18 11:19:23 +02:00
Thomas Petazzoni
d552543431 package/pulseview: add missing 'select BR2_PACKAGE_QT5GUI'
BR2_PACKAGE_PULSEVIEW selects BR2_PACKAGE_QT5BASE_PNG and
BR2_PACKAGE_QT5BASE_WIDGETS, which both depend on
BR2_PACKAGE_QT5BASE_GUI. It ends working because we also select
BR2_PACKAGE_QT5SVG, which selects BR2_PACKAGE_QT5BASE_GUI, so there is
no bug, but it's bit inconsistent to select sub-options that have a
"depends on" without selecting the option they depend on.

This not a bug fix, it has no functional implication.

Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
Signed-off-by: Julien Olivain <ju.o@free.fr>
(cherry picked from commit aff091c39d)
Signed-off-by: Thomas Perale <thomas.perale@mind.be>
2026-09-18 11:19:21 +02:00
Titouan Christophe
bef43a2af1 package/znc: add patch for CVE-2026-82373
This fixes the following vulnerability:

CVE-2026-82373: Use-after-free when unloading modules, triggered by
unprivileged users

Signed-off-by: Titouan Christophe <titouan.christophe@mind.be>
(alternative to commit 43558e103b)
Signed-off-by: Thomas Perale <thomas.perale@mind.be>
2026-09-18 11:19:19 +02:00
Thomas Petazzoni
592df64b46 package/kodi: propagate mariadb dependencies to BR2_PACKAGE_KODI_MYSQL
Even though kodi itself has architecture dependencies (expressed
through BR2_PACKAGE_KODI_ARCH_SUPPORTS, the option
BR2_PACKAGE_KODI_MYSQL selects BR2_PACKAGE_MARIADB, which has its own
architecture dependencies as well. Make sure to propagate those to
BR2_PACKAGE_KODI_MYSQL, which doesn't require adding a Config.in
comment as these are purely architecture dependencies.

We haven't replicate all dependencies of BR2_PACKAGE_MARIADB because
all the others are covered by the top-level BR2_PACKAGE_KODI, and
propagating them would require adding a Config.in comment for
BR2_PACKAGE_KODI_MYSQL.

Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
Signed-off-by: Julien Olivain <ju.o@free.fr>
(cherry picked from commit 16e3d628bd)
Signed-off-by: Thomas Perale <thomas.perale@mind.be>
2026-09-18 11:19:17 +02:00
Thomas Petazzoni
ec4c7979f9 package/hidapi: propagate dependencies of libgudev
Since hidapi was introduced in commit
6267f34afd, it forgot to propagate some
dependencies of libgudev (which existed back then). Initially libgudev
was only needed when BR2_INIT_SYSTEMD=y, but still the dependencies
were not propagated for the systemd case.

Anyway, since e739dd5a11, libgudev is a
mandatory dependency of hidapi, independently from the selected init
system.

We make sure to propagate all dependencies of libgudev to hidapi, and
propagate them to the reverse dependencies of hidapi.

Fixes: 6267f34afd ("hidapi: new package")
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
Signed-off-by: Julien Olivain <ju.o@free.fr>
(cherry picked from commit 74def2cdd4)
[tperale: drop libmanette change not present]
Signed-off-by: Thomas Perale <thomas.perale@mind.be>
2026-09-18 11:19:14 +02:00
Thomas Petazzoni
4d2f85fd01 package/*/Config.in: harmonize select of BR2_PACKAGE_ARGP_STANDALONE
BR2_PACKAGE_ARGP_STANDALONE is defined as follows:

config BR2_PACKAGE_ARGP_STANDALONE
	depends on !BR2_TOOLCHAIN_USES_GLIBC

Some packages did:

	select BR2_PACKAGE_ARGP_STANDALONE if !BR2_TOOLCHAIN_USES_GLIBC

while a number of others did:

	select BR2_PACKAGE_ARGP_STANDALONE if BR2_TOOLCHAIN_USES_UCLIBC || BR2_TOOLCHAIN_USES_MUSL

This commit harmonizes the situation, by settling on the first
solution ("if !BR2_TOOLCHAIN_USES_GLIBC") as it matches how
BR2_PACKAGE_ARGP_STANDALONE is defined in the first place.

No functional change.

Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
Signed-off-by: Julien Olivain <ju.o@free.fr>
(cherry picked from commit 1799bf3680)
Signed-off-by: Thomas Perale <thomas.perale@mind.be>
2026-09-18 11:19:12 +02:00
Thomas Petazzoni
650df664f0 package/intel-vpl-gpu-rt: add missing BR2_TOOLCHAIN_GCC_AT_LEAST_8 dependency
BR2_PACKAGE_INTEL_VPL_GPU_RT selects BR2_PACKAGE_INTEL_MEDIADRIVER but
did not propagate "depends on BR2_TOOLCHAIN_GCC_AT_LEAST_8". This
commit fixes this issue, which was introduced in commit
ac65841def, when onevpl-intel-gpu was
introduced (it was later renamed to intel-vpl-gpu-rt).

Fixes: ac65841def ("package/onevpl-intel-gpu: new package")
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
Signed-off-by: Julien Olivain <ju.o@free.fr>
(cherry picked from commit 876023bc5a)
Signed-off-by: Thomas Perale <thomas.perale@mind.be>
2026-09-18 11:19:10 +02:00
Thomas Petazzoni
71cbd3dab8 package/intel-mediasdk: add missing BR2_TOOLCHAIN_GCC_AT_LEAST_8 dependency
BR2_PACKAGE_INTEL_MEDIASDK selects BR2_PACKAGE_INTEL_MEDIADRIVER but
forgets to propagate the "depends on BR2_TOOLCHAIN_GCC_AT_LEAST_8".

This issue was introduced in commit
51b60c8acf, when "depends on
BR2_TOOLCHAIN_GCC_AT_LEAST_8" was added to mesa3d, propagated to
intel-mediadriver, but not intel-mediasdk.

Fixes: 51b60c8acf ("package/mesa3d: needs gcc >= 8")
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
Signed-off-by: Julien Olivain <ju.o@free.fr>
(cherry picked from commit fa38fea91c)
Signed-off-by: Thomas Perale <thomas.perale@mind.be>
2026-09-18 11:19:08 +02:00
Thomas Petazzoni
31843da841 package/python-grpcio-reflection: add missing BR2_PACKAGE_HOST_PROTOBUF_ARCH_SUPPORTS dependency
BR2_PACKAGE_PYTHON_GRPCIO_REFLECTION selects
BR2_PACKAGE_PYTHON_PROTOBUF, but forgot to replicate "depends on
BR2_PACKAGE_HOST_PROTOBUF_ARCH_SUPPORTS".

Fixes: 3217fedcb8 ("package/python-grpcio-reflection: new package")
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
Signed-off-by: Julien Olivain <ju.o@free.fr>
(cherry picked from commit 74dab03495)
Signed-off-by: Thomas Perale <thomas.perale@mind.be>
2026-09-18 11:19:05 +02:00
Thomas Petazzoni
a6af92fb3d package/python-googleapis-common-protos: add missing BR2_PACKAGE_HOST_PROTOBUF_ARCH_SUPPORTS dependency
BR2_PACKAGE_PYTHON_GOOGLEAPIS_COMMON_PROTOS selects
BR2_PACKAGE_PYTHON_PROTOBUF but did not propagate
BR2_PACKAGE_HOST_PROTOBUF_ARCH_SUPPORTS.

Fixes: d37766a886 ("package/python-googleapis-common-protos: new package")
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
Signed-off-by: Julien Olivain <ju.o@free.fr>
(cherry picked from commit 548904619c)
Signed-off-by: Thomas Perale <thomas.perale@mind.be>
2026-09-18 11:19:03 +02:00
Thomas Petazzoni
6b69e037cb package/udisks: add missing BR2_USE_MMU dependency
Commit 66ddec89e8 ("package/udisks: bump
to version 2.92") mistakenly removed the BR2_USE_MMU dependency of
udisks when dropping "select BR2_PACKAGE_LVM2". Indeed, BR2_USE_MMU is
a dependency of many other packages selected by udisks.

Interestingly, the Config.in comments in the same file still had the
"depends on BR2_USE_MMU" dependencies.

Fixes: 66ddec89e8 ("package/udisks: bump to version 2.92")
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
Signed-off-by: Julien Olivain <ju.o@free.fr>
(cherry picked from commit 4b8259bad9)
Signed-off-by: Thomas Perale <thomas.perale@mind.be>
2026-09-18 11:19:01 +02:00
Thomas Petazzoni
871b9edde8 package/bcc: propagate missing dependency from clang
Since bcc was introduced in commit
146498d13c, it lacked a dependency
propagation from clang for BR2_TOOLCHAIN_HAS_GCC_BUG_64735, this
commit fixes this mistake.

Fixes: 146498d13c ("package/bcc: new package")
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
Signed-off-by: Julien Olivain <ju.o@free.fr>
(cherry picked from commit c305370f36)
Signed-off-by: Thomas Perale <thomas.perale@mind.be>
2026-09-18 11:18:59 +02:00
Thomas Petazzoni
405a434132 package/go: use BR2_PACKAGE_HOST_GO_HOST_ARCH_SUPPORTS in BR2_PACKAGE_HOST_GO_TARGET_ARCH_SUPPORTS
BR2_PACKAGE_HOST_GO_TARGET_ARCH_SUPPORTS redefines the conditions to
determine if a host go compiler is available for the current host
architecture. Instead, make it explicit that those conditions are the
same by re-using BR2_PACKAGE_HOST_GO_HOST_ARCH_SUPPORTS.

No functional change.

Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
Signed-off-by: Julien Olivain <ju.o@free.fr>
(cherry picked from commit 71d3ffd372)
Signed-off-by: Thomas Perale <thomas.perale@mind.be>
2026-09-18 11:18:56 +02:00
Bernd Kuhls
740b132fed package/tpm2-tools: security bump version to 5.8
https://github.com/tpm2-software/tpm2-tools/blob/5.8/docs/CHANGELOG.md

Fixes: GHSA-v7w4-4gc9-qcgv, GHSA-gwfg-w3jr-xh66 & GHSA-qp88-8f4j-wv7q.

Switched to sha256 tarball hash provided by upstream.

Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Julien Olivain <ju.o@free.fr>
(cherry picked from commit 17be3c2dcd)
Signed-off-by: Thomas Perale <thomas.perale@mind.be>
2026-09-18 11:18:54 +02:00
Adrian Perez de Castro
35aad6bd0d package/xdg-dbus-proxy: security bump to verssion 0.1.8
Fixes and issue that caused broadcast messages to skip some checks.
Release notes:

  https://github.com/flatpak/xdg-dbus-proxy/releases/tag/0.1.8

Fixes:
https://github.com/flatpak/xdg-dbus-proxy/security/advisories/GHSA-r7hp-698j-2h6c

Signed-off-by: Adrian Perez de Castro <aperez@igalia.com>
[Julien: add link to GHSA]
Signed-off-by: Julien Olivain <ju.o@free.fr>
(cherry picked from commit 51b366290b)
Signed-off-by: Thomas Perale <thomas.perale@mind.be>
2026-09-18 11:18:50 +02:00
Bernd Kuhls
36545de94c package/apache: renumber patches
Buildroot commit 99bfbef093 removed patch
0002 but forgot to renumber the remaining patches.

Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
(cherry picked from commit 5c9fbf7efe)
Signed-off-by: Thomas Perale <thomas.perale@mind.be>
2026-09-18 11:18:47 +02:00
Titouan Christophe
0fe3e2e604 package/xz: add patch for GHSA-5qpq-xqfv-j9pg
This fixes the following vulnerability:
XZ Utils: Invalid write if a decoder is reinitialized after allocation failure
See https://github.com/tukaani-project/xz/security/advisories/GHSA-5qpq-xqfv-j9pg

There is still no CVE number assigned to the issue.

(alternative to commit 6f125a6530)
Signed-off-by: Titouan Christophe <titouan.christophe@mind.be>
Signed-off-by: Thomas Perale <thomas.perale@mind.be>
2026-09-18 11:18:32 +02:00
Adrian Perez de Castro
110d3ecb81 package/bubblewrap: security bump to version 0.12.0
Fixes a sandbox escape through symlink traversal tracked in
CVE-2026-87766, which affects all previous versions.

Using the bwrap binary with the setuid bit set is no longer supported
and user namespaces are now always required, so a kernel config fixup
is applied.

A new build option allows indicating the minimum kernel version that
will be used, which removes code used for backwards compatibility with
kernels older than 5.6.0 when a newer version is specified. Passing
$(LINUX_VERSION_PROBED) seems reasonable here.

This version also changed the license from LGPL-2.0+ to LGPL-2.1+,
hence the updated hash.

Release notes:

  https://github.com/containers/bubblewrap/releases/tag/v0.12.0

Signed-off-by: Adrian Perez de Castro <aperez@igalia.com>
[Julien: fix _LINUX_CONFIG_FIXUPS by adding the missing "_LINUX"]
Signed-off-by: Julien Olivain <ju.o@free.fr>
(cherry picked from commit 4cb6193d2e)
Signed-off-by: Thomas Perale <thomas.perale@mind.be>
2026-09-16 11:45:33 +02:00
Thomas Perale
029c492e87 package/{binutils, gpsd, micropython, net-tools, util-linux, x11vnc, libfreeglut, libfreeimage, libical, proftpd, sylpheed, mupdf}: fix CVE patch information
Prior to improving check-package to verify that the comment preceding
a <pkg>_IGNORE_CVES entry mentions an existing patch, and that the
patch itself contains a CVE: tag, we fix all problematic cases that
currently exist in Buildroot:

- In the case of binutils: the CVE was only applicable to binutils
  2.43/2.44, and the oldest version now supported is 2.45, so the
  patch doesn't exist anymore in Buildroot
- For x11vnc, fix a typo in the patch name
- Similarly for micropython, the patches were dropped in [1] along with
  the version bump
- Add missing 'CVE:' tag to net-tools patch 0001
- edk2 add missing CVE trailer
- libfreeglut add missing CVE trailer
- libfreeimage correct reference to patch
- libical add missing CVE trailer
- proftpd correct reference to patch
- sylpheed add missing CVE trailer

[1] 28eeca9a98 package/micropython: bump to version 1.28.0

Signed-off-by: Titouan Christophe <titouan.christophe@mind.be>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
(cherry picked from commit 636f69ab45)
[thomas: adapt to 2025.02.x]
Signed-off-by: Thomas Perale <thomas.perale@mind.be>
2026-09-16 11:44:35 +02:00
Titouan Christophe
c4c6602343 utils/checkpackagelib: add new check MissingCVEPatch
To indicate that a patch fixes a vulnerability in Buildroot, the convention is:
1. In the patch file, add a tag 'CVE: <cve id>'
2. In <pkg>.mk, and an entry to <PKG>_IGNORE_CVES, and add a comment above
   that new entry to reference the patch file(s)

However, as packages get bumped and their patches are added, removed or
rebased; it happens that IGNORE_CVES get outdated. One important issue is
marking a CVE as ignored, while the corresponding patch is not in Buildroot.

To detect such cases, add a new checker to checkpackagelib that finds
occurences of:

    # 000x-some-patch.patch
    PKG_IGNORE_CVES += CVE-XXXX-YYYY

For each one of them, ensure that the mentioned patch files actually exist
and contain the `CVE: ...` tag.

Assisted-by: Claude:claude-opus-4.8
Signed-off-by: Titouan Christophe <titouan.christophe@mind.be>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
(cherry picked from commit b00ac4e346)
Signed-off-by: Thomas Perale <thomas.perale@mind.be>
2026-09-16 11:43:59 +02:00
Bernd Kuhls
81d6597a2c package/pcre2: security bump to version 10.48
https://github.com/PCRE2Project/pcre2/releases/tag/pcre2-10.48

Fixes the following security issues:

(Security fix for specific API usage, GHSA-2p8c-ff85-vh9x)
 If pcre2_jit_compile() is called with options for some match modes, and
 then pcre2_match() is used to perform a match for a different match
 mode, an out-of-bounds read can occur if the match is attempted against
 invalid UTF input.

(Security fix for pattern conversion, GHSA-q8g2-wprr-34m9)
 If pcre2_convert() is called on untrusted input on platforms with
 32-bit size_t, an out-of-bounds heap write can occur.

(Security fix, GHSA-3r4p-g7gg-ppmf) Fixed an out-of-bounds write in DFA
 matching when using a heap limit; also fixed possible integer overflows
 which could cause under-allocation of the workspace.

(Security fix, GHSA-fmgr-6ggq-9859) Added bounds checks for several
 integer overflows while compiling patterns on 32-bit CPUs, which could
 cause under-allocation followed by out-of-bounds writes.

(Security fix, GHSA-9qww-pwc4-77qq) Applied lower buffer bound to
 prevent two out-of-bounds reads while scanning backwards through
 invalid UTF data with PCRE2_MATCH_INVALID_UTF.

(Security fix for specific API usage, #937) Fixed a leak and later
 invalid free when calling the fast-path pcre2_jit_match() function with
 a match data object previously used with pcre2_match() and
 PCRE2_COPY_MATCHED_SUBJECT.

(Low-severity security fix, GHSA-q7rw-r7qq-2hx6) Fixed exposure of two
 uninitialised bytes from malloc() via pcre2_serialize_encode().

Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Julien Olivain <ju.o@free.fr>
(cherry picked from commit 664db5d62c)
Signed-off-by: Thomas Perale <thomas.perale@mind.be>
2026-09-16 11:22:25 +02:00
Bernd Kuhls
3f9399577b package/pcre2: bump version to 10.47
Release notes:
https://github.com/PCRE2Project/pcre2/releases/tag/pcre2-10.47

Updated license hash due to upstream commits:
4f5a2ada2e
1fffb0d44e
d8a9f2fe55

Added license file for sljit:
d8a9f2fe55

Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Julien Olivain <ju.o@free.fr>
(cherry picked from commit 1023741fb1)
Signed-off-by: Thomas Perale <thomas.perale@mind.be>
2026-09-16 11:21:55 +02:00
Bernd Kuhls
6b9d6f0d50 package/tor: security bump version to 0.4.9.12
https://gitlab.torproject.org/tpo/core/tor/-/blob/tor-0.4.9.12/ReleaseNotes
https://forum.torproject.org/t/security-release-0-4-9-12/22096

Fixes TROVE-2026-032, TROVE-2026-033, TROVE-2026-034, TROVE-2026-035,
TROVE-2026-036, TROVE-2026-042 & TROVE-2026-043.

Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Julien Olivain <ju.o@free.fr>
(cherry picked from commit 95649c547b)
Signed-off-by: Thomas Perale <thomas.perale@mind.be>
2026-09-16 10:26:01 +02:00
Bernd Kuhls
9f58ad72cb package/turbolua: security bump version to 2.1.5
https://github.com/kernelsauce/turbo/releases/tag/v2.1.5

https://github.com/kernelsauce/turbo/releases/tag/v2.1.4
Security fixes:

HTTP header injection: header values were only checked for a literal
 \r\n, so a lone \r or \n could still split a header. Now rejected on
 either character.

Transfer-Encoding requests are now rejected with 501 instead of silently
 mishandled, closing a request smuggling avenue.

A real default request body size cap (128 MB) with a 413 response,
 previously unbounded.

Secure cookie signature now binds the cookie name, so a value signed for
 one cookie can no longer be replayed under a different name.
 Verification failures return the default value instead of raising.

Constant-time comparison for the secure cookie HMAC, previously a
 timing-leaky ==.

util.secure_random_bytes reads real OS entropy (/dev/urandom,
 BCryptGenRandom on Windows) for WebSocket masks and util.rand_str,
 previously math.random.

WebSocket: unmasked client frames are rejected per RFC 6455, and
 fragmented message reassembly is capped to max_buffer_size to close a
 memory exhaustion path.

StaticFileHandler decodes the request path before the traversal check,
 closing a bypass.

Fixed a 32-byte-per-malformed-request memory leak in the C header parser
 wrapper (found via libFuzzer).

Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Julien Olivain <ju.o@free.fr>
(cherry picked from commit 15a422cee1)
Signed-off-by: Thomas Perale <thomas.perale@mind.be>
2026-09-16 10:25:44 +02:00
Bernd Kuhls
a9b3d724c8 package/i2pd: needs chacha support in libopenssl
/home/thomas/autobuild/instance-2/output-1/build/i2pd-2.59.0/libi2pd/Crypto.cpp:661:49:
 error: 'EVP_chacha20_poly1305' was not declared in this scope; did you
 mean 'SN_chacha20_poly1305'?

The code was added upstream in 2018:
58c92b8405

The build error could be reproduced with i2pd version 2.22.0 added to
buildroot with commit 1035e80aaa so a
backport to LTS branches should be considered.

Fixes:
https://autobuild.buildroot.net/results/bd8/bd8616f04df2e1b9e18d1e16921979a852bd566f/

Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
(cherry picked from commit 5b076d3755)
Signed-off-by: Thomas Perale <thomas.perale@mind.be>
2026-09-16 10:25:18 +02:00
Bernd Kuhls
09fb13df0c package/libpcap: security bump version to 1.10.7
https://github.com/the-tcpdump-group/libpcap/blob/libpcap-1.10.7/CHANGES

Fixes the following CVEs:

CVE-2026-0799: Access M[] safely in the BPF interpreter.
CVE-2026-31912: Mind the program bounds in pcap_offline_filter().
CVE-2026-31911: Fail opcodes safely in the BPF interpreter.
CVE-2026-6244: Avoid division by zero via pcap_offline_filter().
CVE-2026-6554: Limit "ja L" looping in pcap_offline_filter().
CVE-2026-18313: Fix a memory leak in rpcapd.
CVE-2026-18238: Fix RPCAP_MSG_PACKET validation.

Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Julien Olivain <ju.o@free.fr>
(cherry picked from commit 446c0f85b8)
Signed-off-by: Thomas Perale <thomas.perale@mind.be>
2026-09-16 10:23:41 +02:00
Titouan Christophe
6ca95aa837 {linux, linux-headers}: bump 5.{10,15}, 6.{1,6,12} series
Update the latest kernel releases:
    - 5.10.269 -> 5.10.270
    - 5.15.220 -> 5.15.221
    - 6.1.187 -> 6.1.188
    - 6.6.156 -> 6.6.157
    - 6.12.109 -> 6.12.110

Signed-off-by: Titouan Christophe <titouan.christophe@mind.be>
Signed-off-by: Thomas Perale <thomas.perale@mind.be>
2026-09-16 10:05:53 +02:00
Titouan Christophe
9b7dbd6849 package/openvpn: add patches for CVE-2026-84732
This fix has been released in OpenVPN 2.7.7, but is not available yet for
OpenVPN 2.6 series (which is included in Buildroot 2025.02.x)

(alternative to commit 25b8142ef7)
Signed-off-by: Titouan Christophe <titouan.christophe@mind.be>
Signed-off-by: Thomas Perale <thomas.perale@mind.be>
2026-09-15 14:22:53 +02:00
Thomas Perale
9deebc2273 Revert "package/openvpn: add patches for CVE-2026-84732"
Commit 1afe223d4c was wrongly applied.
This commit was the v1 of a series that as since been superseeded and
fixed.

Revert this commit to correctly apply the patch that fix
CVE-2026-84732.

Signed-off-by: Thomas Perale <thomas.perale@mind.be>
2026-09-15 14:22:49 +02:00
Arnout Vandecappelle
d030e36bbc Makefile: Update for 2025.02.18
Signed-off-by: Arnout Vandecappelle <arnout@rnout.be>
2025.02.18
2026-09-10 21:14:22 +02:00
Arnout Vandecappelle
0f81c9d8cd CHANGES: Update for 2025.02.18
Signed-off-by: Arnout Vandecappelle <arnout@rnout.be>
2026-09-10 20:58:02 +02:00