Bernd Kuhls
29f8d1133d
package/libteam: add upstream patch to fix build with newer gcc
...
Fixes:
https://autobuild.buildroot.net/results/a4c/a4c4c4135cffe607269cc0fdb36e4b2c86e7fe33/
Signed-off-by: Bernd Kuhls <bernd@kuhls.net >
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
(cherry picked from commit fc98cd6b9c )
Signed-off-by: Thomas Perale <thomas.perale@mind.be >
2025-12-04 13:22:32 +01:00
Bernd Kuhls
5c51dbaeac
package/tor: bump version to 0.4.8.21
...
Release notes:
https://forum.torproject.org/t/stable-release-0-4-8-21/20817
https://gitlab.torproject.org/tpo/core/tor/-/raw/release-0.4.8/ReleaseNotes
"This release is a continuation of the previous one and addresses
additional Conflux-related issues identified through further testing
and feedback from relay operators.
We strongly recommend upgrading as soon as possible."
Signed-off-by: Bernd Kuhls <bernd@kuhls.net >
Signed-off-by: Julien Olivain <ju.o@free.fr >
(cherry picked from commit cb1f3579a2 )
Signed-off-by: Thomas Perale <thomas.perale@mind.be >
2025-12-04 13:22:12 +01:00
Bernd Kuhls
f10adb5d80
package/oprofile: add upstream patch to fix build with newer gcc
...
Fixes:
https://autobuild.buildroot.net/results/e12/e12de278cb7bb0ecc0d44dd9c69d3832ede946de/
Signed-off-by: Bernd Kuhls <bernd@kuhls.net >
Signed-off-by: Julien Olivain <ju.o@free.fr >
(cherry picked from commit cffb057b90 )
Signed-off-by: Thomas Perale <thomas.perale@mind.be >
2025-12-04 13:20:56 +01:00
Giulio Benetti
6ca40f2ccc
package/tmux: fix build failure due to type mismatch
...
Package tmux fails to build with:
compat/utf8proc.c: In function 'utf8proc_mbtowc':
compat/utf8proc.c:51:39: error: passing argument 3 of 'utf8proc_iterate' from incompatible pointer type [-Wincompatible-pointer-types]
51 | slen = utf8proc_iterate(s, n, pwc);
| ^~~
| |
| wchar_t * {aka long int *}
Add local patch already committed upstream to fix it.
Fixes:
https://autobuild.buildroot.net/results/651/6510cfb16d0c3f3772918cd3bde0542d0b59a230/
Signed-off-by: Giulio Benetti <giulio.benetti@benettiengineering.com >
Signed-off-by: Julien Olivain <ju.o@free.fr >
(cherry picked from commit 7cf46f0384 )
Signed-off-by: Thomas Perale <thomas.perale@mind.be >
2025-12-04 13:14:18 +01:00
Giulio Benetti
df847b57a2
package/sdl: fix build failure due to type mismatch
...
Add local patch to fix:
./src/stdlib/SDL_iconv.c: In function 'SDL_iconv':
./src/stdlib/SDL_iconv.c:50:29: error: passing argument 2 of 'iconv' from incompatible pointer type [-Wincompatible-pointer-types]
50 | retCode = iconv(cd, inbuf, inbytesleft, outbuf, outbytesleft);
| ^~~~~
| |
| const char **
Fixes:
https://autobuild.buildroot.net/results/cfb/cfb1f9a0137332cf080ce862722e4fe8ad275031/
Signed-off-by: Giulio Benetti <giulio.benetti@benettiengineering.com >
[Julien: add "Upstream:" tag in patch]
Signed-off-by: Julien Olivain <ju.o@free.fr >
(cherry picked from commit 03394b4989 )
Signed-off-by: Thomas Perale <thomas.perale@mind.be >
2025-12-04 13:13:06 +01:00
Bernd Kuhls
784ac62c94
package/swipl: bump version to 9.2.9
...
For change log since version 9.2.8, see:
https://www.swi-prolog.org/ChangeLog?branch=stable&from=9.2.8&to=9.2.9
Fixes:
https://autobuild.buildroot.net/results/158/1586997a84236b678249ac45b83b4e330e727f39/
Signed-off-by: Bernd Kuhls <bernd@kuhls.net >
[Julien: add link to change log]
Signed-off-by: Julien Olivain <ju.o@free.fr >
(cherry picked from commit 743bc22135 )
Signed-off-by: Thomas Perale <thomas.perale@mind.be >
2025-12-04 13:12:52 +01:00
Bernd Kuhls
11e5e88ad1
package/{neard, sdbusplus, thermald}: typo fixes
...
Signed-off-by: Bernd Kuhls <bernd@kuhls.net >
Signed-off-by: Julien Olivain <ju.o@free.fr >
(cherry picked from commit 559bb4dd7b )
Signed-off-by: Thomas Perale <thomas.perale@mind.be >
2025-12-04 13:12:28 +01:00
Marcus Hoffmann
9639e6c246
package/python-starlette: security bump to 0.50.0
...
Starlette 0.49.1 fixes the following security issue:
https://github.com/Kludex/starlette/security/advisories/GHSA-7f5h-v6xp-fcq8
Other changes:
* https://github.com/Kludex/starlette/releases/tag/0.49.0
* https://github.com/Kludex/starlette/releases/tag/0.49.1 (the security fix)
* https://github.com/Kludex/starlette/releases/tag/0.49.2
* https://github.com/Kludex/starlette/releases/tag/0.49.3
* https://github.com/Kludex/starlette/releases/tag/0.50.0
Signed-off-by: Marcus Hoffmann <buildroot@bubu1.eu >
Signed-off-by: Julien Olivain <ju.o@free.fr >
(cherry picked from commit 35d8a3a0ca )
Signed-off-by: Thomas Perale <thomas.perale@mind.be >
2025-12-04 13:11:46 +01:00
Marcus Hoffmann
aeae779ce7
package/python-starlette: bump to 0.48.0
...
Release Notes: https://github.com/Kludex/starlette/releases/tag/0.48.0
Github namespace changed, so change the link in Config.in.
Signed-off-by: Marcus Hoffmann <buildroot@bubu1.eu >
Signed-off-by: Julien Olivain <ju.o@free.fr >
(cherry picked from commit 62cfbc1409 )
Signed-off-by: Thomas Perale <thomas.perale@mind.be >
2025-12-04 13:11:39 +01:00
James Hilliard
e8828d1b78
package/python-starlette: bump to version 0.47.3
...
Signed-off-by: James Hilliard <james.hilliard1@gmail.com >
Signed-off-by: Julien Olivain <ju.o@free.fr >
(cherry picked from commit bb825488db )
Signed-off-by: Thomas Perale <thomas.perale@mind.be >
2025-12-04 13:11:28 +01:00
Julien Olivain
5588bdec02
package/gnutls: add patch to fix build with gcc < 11
...
Since Buildroot commit [1] (package/gnutls: security bump to
version 3.8.11), gnutls fails to build with gcc or host-gcc
version < 11, with error:
In file included from audit.h:22,
from audit.c:26:
crau/crau.h:255:23: error: missing binary operator before token "("
__has_c_attribute (__maybe_unused__)
This commit adds a patch fixing the issue.
[1] 81dbfe1c2a
Reported-by: Neal Frager <neal.frager@amd.com >
Reviewed-by: Neal Frager <neal.frager@amd.com >
Tested-by: Neal Frager <neal.frager@amd.com >
Signed-off-by: Julien Olivain <ju.o@free.fr >
(cherry picked from commit 5cd1fe636c )
Signed-off-by: Thomas Perale <thomas.perale@mind.be >
2025-12-03 17:22:45 +01:00
Bernd Kuhls
8215c5dea9
package/gnutls: security bump to version 3.8.11
...
Release notes:
https://lists.gnupg.org/pipermail/gnutls-help/2025-November/004906.html
Fixes CVE-2025-9820.
Signed-off-by: Bernd Kuhls <bernd@kuhls.net >
Signed-off-by: Julien Olivain <ju.o@free.fr >
(cherry picked from commit 81dbfe1c2a )
Signed-off-by: Thomas Perale <thomas.perale@mind.be >
2025-11-27 13:26:53 +01:00
Bernd Kuhls
001fe44400
package/libpng: security bump version to 1.6.51
...
Release notes:
https://raw.githubusercontent.com/pnggroup/libpng/v1.6.51/ANNOUNCE
Fixes CVE-2025-64505, CVE-2025-64506, CVE-2025-64720 & CVE-2025-65018.
Removed patch which is included in this release.
Signed-off-by: Bernd Kuhls <bernd@kuhls.net >
Signed-off-by: Julien Olivain <ju.o@free.fr >
(cherry picked from commit 08ad91052b )
Signed-off-by: Thomas Perale <thomas.perale@mind.be >
2025-11-27 13:26:05 +01:00
Thomas Perale
ac0a735d99
docs/manual: add information on CycloneDX
...
This patch adds information on how to generate a CycloneDX SBOM in
Buildroot. It also mentions how to track CVEs with that given SBOM.
Signed-off-by: Thomas Perale <thomas.perale@mind.be >
[Peter: reword slightly]
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
(cherry picked from commit e09bf9e951 )
Signed-off-by: Thomas Perale <thomas.perale@mind.be >
2025-11-26 09:44:11 +01:00
Thomas Perale
ef962fc4f6
DEVELOPERS: add Thomas Perale to cve-check & cve.py
...
Signed-off-by: Thomas Perale <thomas.perale@mind.be >
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
(cherry picked from commit 51558fa3ea )
Signed-off-by: Thomas Perale <thomas.perale@mind.be >
2025-11-26 09:41:40 +01:00
Thomas Perale
a43153651c
support/scripts/cve-check: add cve-check script
...
Enriches the input CycloneDX SBOM with vulnerability information and
analysis from the NVD database.
The NVD database is cloned using a mirror of it and the content is compared
locally. By default the path 'dl/buildroot-nvd' is used.
Example usage to analyse vulnerabilities of an input CycloneDX SBOM:
$ make show-info | utils/generate-cyclonedx | support/script/cve-check
The 'cve-check' can also be used to only enrich the vulnerabilities
present on the input SBOM with a set metadata (description, cvss,
references, ...) without applying an analysis.
With the following command the vulnerabilities ignored by Buildroot
present in the CycloneDX SBOM are enriched with description, cvss, etc
...
$ make show-info | utils/generate-cyclonedx | support/script/cve-check --enrich-only
Signed-off-by: Thomas Perale <thomas.perale@mind.be >
[Peter: fix minor flake8 issues]
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
(cherry picked from commit 6762c42e74 )
Signed-off-by: Thomas Perale <thomas.perale@mind.be >
2025-11-26 09:41:33 +01:00
Thomas Perale
eb2990afdd
support/scripts/cve.py: don't call download_nvd
...
This patch move the 'download_nvd' call to the 'pkg-stats' script
instead of automatically calling 'read_nvd_dir'.
Since the cve.py file can be used as a library it's up to the caller to
decide whether or not to update the NVD database.
Signed-off-by: Thomas Perale <thomas.perale@mind.be >
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
(cherry picked from commit 867017e736 )
Signed-off-by: Thomas Perale <thomas.perale@mind.be >
2025-11-26 09:41:24 +01:00
Bernd Kuhls
3dba17294d
package/openvpn: security bump version to 2.6.16
...
Fixes CVE-2025-13086.
Release notes:
https://sourceforge.net/p/openvpn/mailman/message/59261309/
Changelog:
https://github.com/OpenVPN/openvpn/blob/release/2.6/ChangeLog
https://github.com/OpenVPN/openvpn/blob/release/2.6/Changes.rst
Signed-off-by: Bernd Kuhls <bernd@kuhls.net >
Signed-off-by: Julien Olivain <ju.o@free.fr >
(cherry picked from commit 55d1f2825b )
Signed-off-by: Thomas Perale <thomas.perale@mind.be >
2025-11-26 09:40:54 +01:00
Scott Fan
09c7b76454
package/openvpn: bump version to 2.6.15
...
Release notes:
https://sourceforge.net/p/openvpn/mailman/message/59238233/
Changelog:
https://github.com/OpenVPN/openvpn/blob/release/2.6/ChangeLog
https://github.com/OpenVPN/openvpn/blob/release/2.6/Changes.rst
The COPYRIGHT.GPL was updated to latest version from FSF.
Signed-off-by: Scott Fan <fancp2007@gmail.com >
Signed-off-by: Julien Olivain <ju.o@free.fr >
(cherry picked from commit c368b33378 )
Signed-off-by: Thomas Perale <thomas.perale@mind.be >
2025-11-26 09:40:41 +01:00
Peter Korsgaard
372e377910
package/python-django: security bump to version 5.1.14
...
Fixed the following security issues:
CVE-2025-64458: Potential denial-of-service vulnerability in
HttpResponseRedirect and HttpResponsePermanentRedirect on Windows
CVE-2025-64459: Potential SQL injection via _connector keyword argument
https://docs.djangoproject.com/en/5.1/releases/5.1.14/
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
Signed-off-by: Julien Olivain <ju.o@free.fr >
(cherry picked from commit 779827f765 )
[thomas: bump to 5.1.14 instead]
Signed-off-by: Thomas Perale <thomas.perale@mind.be >
2025-11-26 09:38:41 +01:00
Bernd Kuhls
7fe0b46b98
DEVELOPERS: remove Julien Corjon, e-mail bounces
...
<corjon.j@ecagroup.com >: host ecagroup-com.mail.protection.outlook.com[52.101.166.0]
said: 550 5.4.1 Recipient address rejected: Access denied.
Signed-off-by: Bernd Kuhls <bernd@kuhls.net >
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
(cherry picked from commit 88c26c4814 )
Signed-off-by: Thomas Perale <thomas.perale@mind.be >
2025-11-26 09:32:38 +01:00
Yi Zheng
62a896350f
fs/squashfs: correct aarch64 conditional
...
BR_aarch64 is not defined. it seems should be BR2_aarch64
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
(cherry picked from commit d6d8b5823a )
Signed-off-by: Thomas Perale <thomas.perale@mind.be >
2025-11-26 09:32:14 +01:00
Bernd Kuhls
569b629875
DEVELOPERS: remove Bernd Kuhls from libdecor & libfreeglut
...
Signed-off-by: Bernd Kuhls <bernd@kuhls.net >
Signed-off-by: Julien Olivain <ju.o@free.fr >
(cherry picked from commit 5db55534af )
Signed-off-by: Thomas Perale <thomas.perale@mind.be >
2025-11-26 09:32:05 +01:00
Peter Korsgaard
8619092a26
package/luksmeta: security bump to version 10
...
Fixes the following security issue:
CVE-2025-11568: A data corruption vulnerability has been identified in the
luksmeta utility when used with the LUKS1 disk encryption format.
https://github.com/advisories/GHSA-pvmm-7c2r-wmp4
https://github.com/latchset/luksmeta/releases/tag/v10
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
Signed-off-by: Julien Olivain <ju.o@free.fr >
(cherry picked from commit 80764d7208 )
Signed-off-by: Thomas Perale <thomas.perale@mind.be >
2025-11-26 09:30:43 +01:00
Titouan Christophe
63b413c2b2
package/redis: bump to v7.2.12
...
See the release notes: https://github.com/redis/redis/releases/tag/7.2.12
Signed-off-by: Titouan Christophe <titouan.christophe@mind.be >
(cherry picked from commit 896e19a5c6 )
Signed-off-by: Thomas Perale <thomas.perale@mind.be >
2025-11-26 09:29:50 +01:00
Thomas Devoogdt
ee3fb3669b
package/openjdk{, -bin}: fix wrong version reporting
...
Before:
$ java --version
openjdk 17 2024-07-16
OpenJDK Runtime Environment (build 17+17)
OpenJDK 64-Bit Server VM (build 17+17, mixed mode)
After:
$ java --version
openjdk 17.0.12 2024-07-16
OpenJDK Runtime Environment (build 17.0.12+7)
OpenJDK 64-Bit Server VM (build 17.0.12+7, mixed mode)
Signed-off-by: Thomas Devoogdt <thomas.devoogdt@barco.com >
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
(cherry picked from commit 8ccee2be22 )
Signed-off-by: Thomas Perale <thomas.perale@mind.be >
2025-11-26 09:28:58 +01:00
Bernd Kuhls
7fa84318c8
package/libroxml: fix musl build errors
...
Fixes:
https://autobuild.buildroot.net/results/0ff/0ff4394319d2014884328c347ef495da327a562e/
Added Upstream tag to patch 0001.
Signed-off-by: Bernd Kuhls <bernd@kuhls.net >
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
(cherry picked from commit 1f973844d1 )
Signed-off-by: Thomas Perale <thomas.perale@mind.be >
2025-11-26 09:26:11 +01:00
Bernd Kuhls
0c2f8b1cab
package/perl-net-ssleay: requires DES support in openssl
...
Fixes:
https://autobuild.buildroot.net/results/953/953210ed672559e63a96da729182af00ca02c011/
The build error occurred already in 2024:
https://autobuild.buildroot.net/results/f93/f930c7b3219a57421c1b0a0ef3a4445c19b43e97/
so backporting this fix seems needed.
Signed-off-by: Bernd Kuhls <bernd@kuhls.net >
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
(cherry picked from commit 2479f5ba1e )
Signed-off-by: Thomas Perale <thomas.perale@mind.be >
2025-11-26 09:26:02 +01:00
Zoltan Gyarmati
774022bd86
DEVELOPERS: update Zoltan Gyarmati e-mail address
...
Signed-off-by: Zoltan Gyarmati <mr.zoltan.gyarmati@gmail.com >
[Julien: reword commit log title]
Signed-off-by: Julien Olivain <ju.o@free.fr >
(cherry picked from commit 75dc8e1842 )
Signed-off-by: Thomas Perale <thomas.perale@mind.be >
2025-11-26 09:25:42 +01:00
Peter Korsgaard
6b1d9ab4e7
utils/check-package: add a check for 'default n' in Config.in files
...
Boolean Config.in symbols default to 'n', so we typically do not add such
redundant lines.
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
Signed-off-by: Julien Olivain <ju.o@free.fr >
(cherry picked from commit 279cbbdb64 )
Signed-off-by: Thomas Perale <thomas.perale@mind.be >
2025-11-26 09:25:29 +01:00
Bernd Kuhls
c4de4c2a8f
DEVELOPERS: add Bernd Kuhls for postgresql
...
Signed-off-by: Bernd Kuhls <bernd@kuhls.net >
Signed-off-by: Julien Olivain <ju.o@free.fr >
(cherry picked from commit 273f6f3e4b )
Signed-off-by: Thomas Perale <thomas.perale@mind.be >
2025-11-26 09:24:04 +01:00
Bernd Kuhls
5c690a0d2c
package/postgresql: security bump to version 17.7
...
Release notes:
https://www.postgresql.org/about/news/postgresql-181-177-1611-1515-1420-and-1323-released-3171/
Fixes CVE-2025-12817 & CVE-2025-12818.
Signed-off-by: Bernd Kuhls <bernd@kuhls.net >
Signed-off-by: Julien Olivain <ju.o@free.fr >
(cherry picked from commit 1e8c666cd8 )
Signed-off-by: Thomas Perale <thomas.perale@mind.be >
2025-11-26 09:23:44 +01:00
Bernd Kuhls
35d3f91669
package/mongrel2: remove package
...
mongrel2 is incompatible with MbedTLS 3.6 and was removed from Debian
stable/testing:
https://tracker.debian.org/pkg/mongrel2
https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1075866
Upstream report from 2023 exists:
https://github.com/mongrel2/mongrel2/issues/359
but went unanswered, the last upstream commit was in Dec 2021:
https://github.com/mongrel2/mongrel2/commits/master/
Since no other package uses mongrel2 we can safely remove this
unmaintained package.
Fixes:
https://autobuild.buildroot.net/results/6c1/6c17827d21135886b1f4822174a4a963ca6325bf/
Signed-off-by: Bernd Kuhls <bernd@kuhls.net >
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
(cherry picked from commit c41af1dcc0 )
Signed-off-by: Thomas Perale <thomas.perale@mind.be >
2025-11-26 09:19:46 +01:00
Thomas Petazzoni
94dae0d30e
package/bctoolbox: remove package
...
bctoolbox was only needed as a dependency of linphone, as is anyway
bundled in more recent versions of linphone, making a separate package
unnecessary.
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com >
Signed-off-by: Bernd Kuhls <bernd@kuhls.net >
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
(cherry picked from commit 37d3a2dee3 )
Signed-off-by: Thomas Perale <thomas.perale@mind.be >
2025-11-26 09:17:02 +01:00
Thomas Petazzoni
96de5caea0
package/ortp: remove package
...
ortp was only needed as a dependency of linphone, as is anyway bundled
in more recent versions of linphone, making a separate package
unnecessary.
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com >
Signed-off-by: Bernd Kuhls <bernd@kuhls.net >
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
(cherry picked from commit 8a40f079ac )
Signed-off-by: Thomas Perale <thomas.perale@mind.be >
2025-11-26 09:14:12 +01:00
Thomas Petazzoni
c0efe9491a
package/mediastreamer: remove package
...
mediastreamer was only needed as a dependency of linphone, as is
anyway bundled in more recent versions of linphone, making a separate
package unnecessary.
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com >
Signed-off-by: Bernd Kuhls <bernd@kuhls.net >
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
(cherry picked from commit b02a4ca7d7 )
Signed-off-by: Thomas Perale <thomas.perale@mind.be >
2025-11-26 09:13:51 +01:00
Thomas Petazzoni
3b71b8e598
package/belr: remove package
...
belr was only needed as a dependency of linphone, as is anyway bundled
in more recent versions of linphone, making a separate package
unnecessary.
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com >
Signed-off-by: Bernd Kuhls <bernd@kuhls.net >
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
(cherry picked from commit f88cb527da )
Signed-off-by: Thomas Perale <thomas.perale@mind.be >
2025-11-26 09:13:19 +01:00
Thomas Petazzoni
e9d0303e36
package/belle-sip: remove package
...
belle-sip was only needed as a dependency of linphone, as is anyway
bundled in more recent versions of linphone, making a separate package
unnecessary.
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com >
Signed-off-by: Bernd Kuhls <bernd@kuhls.net >
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
(cherry picked from commit ffa6824417 )
Signed-off-by: Thomas Perale <thomas.perale@mind.be >
2025-11-26 09:12:26 +01:00
Thomas Petazzoni
4bccdb85f5
package/linphone: remove package
...
This package is no longer maintained in Buildroot: no maintainer in
DEVELOPERS file, and doesn't build since we bumped mbedtls to version
3.x in commit 3481a9643f , which first
appeared in 2025.05.
Also, upstream linphone has changed their strategy, and now their
specific dependencies (bctoolbox, belle-sip, etc.) are bundled in
linphone, so anyway the packaging needs to be adapted significantly.
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com >
Signed-off-by: Bernd Kuhls <bernd@kuhls.net >
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
(cherry picked from commit 90e4e80fc3 )
Signed-off-by: Thomas Perale <thomas.perale@mind.be >
2025-11-26 09:02:28 +01:00
Bernd Kuhls
dd4e9cae26
package/asterisk: security bump version to 22.5.2
...
Fixes the following security issues:
- CVE-2025-1131: Uncontrolled Search-Path Element in safe_asterisk script
may allow local privilege escalation
https://github.com/asterisk/asterisk/security/advisories/GHSA-v9q8-9j8m-5xwp
- CVE-2025-57767: A specifically malformed Authorization header in an
incoming SIP request can cause Asterisk to crash
https://github.com/asterisk/asterisk/security/advisories/GHSA-64qc-9x89-rx5j
- CVE-2025-49832: Remote DoS and possible RCE in
asterisk/res/res_stir_shaken/verification.c
https://github.com/asterisk/asterisk/security/advisories/GHSA-mrq5-74j5-f5cr
- CVE-2025-47780: cli_permissions.conf: deny option does not work for
disallowing shell commands
https://github.com/asterisk/asterisk/security/advisories/GHSA-c7p6-7mvq-8jq2
- CVE-2025-47779: Using malformed From header can forge identity with ";" or
NULL in name portion
https://github.com/asterisk/asterisk/security/advisories/GHSA-2grh-7mhv-fcfw
Signed-off-by: Bernd Kuhls <bernd@kuhls.net >
Acked-by: Titouan Christophe <titouan.christophe@mind.be >
[Peter: add additional CVEs]
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
(cherry picked from commit 02fd1d2b93 )
Signed-off-by: Thomas Perale <thomas.perale@mind.be >
2025-11-26 09:02:26 +01:00
Waldemar Brodkorb
db493966bf
package/asterisk: bump to 22.3.0
...
For a changelog see here:
https://downloads.asterisk.org/pub/telephony/asterisk/ChangeLog-22.3.0.md
Changes made by the package maintainer:
- add systemd service file
- run asterisk as non-root user asterisk
- build pjsip as bundled source code, but download it like
sound files
- remove unused configure options
- chan_alsa was removed upstream in commit
de3ce178ab0282445cf25161b49f3737ac2d20ff
See here for the reason behind using the bundled pjsip:
https://github.com/asterisk/asterisk/issues/671
Signed-off-by: Waldemar Brodkorb <wbx@openadk.org >
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com >
(cherry picked from commit f11b9db0b5 )
Signed-off-by: Thomas Perale <thomas.perale@mind.be >
2025-11-26 09:02:24 +01:00
James Hilliard
cf0813a931
package/tailscale: add missing config fixups
...
There are a number of kernel config fixups required for tailscale to
function properly, these are commonly enabled by default in various
kernel configs but lets make sure they are all enabled here as well.
Signed-off-by: James Hilliard <james.hilliard1@gmail.com >
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
(cherry picked from commit 766f6ddb7e )
Signed-off-by: Thomas Perale <thomas.perale@mind.be >
2025-11-26 09:02:21 +01:00
Bernd Kuhls
9479f98cfe
package/tor: bump version to 0.4.8.20
...
Release notes:
https://gitlab.torproject.org/tpo/core/tor/-/raw/release-0.4.8/ReleaseNotes
https://forum.torproject.org/t/stable-release-0-4-8-20/20781
Signed-off-by: Bernd Kuhls <bernd@kuhls.net >
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
(cherry picked from commit 1f23b6ea85 )
Signed-off-by: Thomas Perale <thomas.perale@mind.be >
2025-11-26 09:02:19 +01:00
Julien Olivain
3bc1b4c4c9
package/mariadb: security bump version to 10.11.15
...
For release notes since 10.11.11:
https://mariadb.com/docs/release-notes/community-server/10.11/10.11.12
https://mariadb.com/docs/release-notes/community-server/10.11/10.11.13
https://mariadb.com/docs/release-notes/community-server/10.11/10.11.14
https://mariadb.com/docs/release-notes/community-server/10.11/10.11.15
Note: the version 10.11.12 is documented as fixing the following CVEs:
https://www.cve.org/CVERecord?id=CVE-2025-30693
https://www.cve.org/CVERecord?id=CVE-2025-30722
https://www.cve.org/CVERecord?id=CVE-2023-52969
https://www.cve.org/CVERecord?id=CVE-2023-52970
https://www.cve.org/CVERecord?id=CVE-2023-52971
Also, since Buildroot commit [1] "package/libxml2: bump version to
2.15.1", MariaDB is failing to build. This new maintenance release
fixes this issue.
Fixes:
https://gitlab.com/buildroot.org/buildroot/-/jobs/11943845663
https://gitlab.com/buildroot.org/buildroot/-/jobs/12026402485
[1] a67cff491a
Signed-off-by: Julien Olivain <ju.o@free.fr >
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
(cherry picked from commit 235e365059 )
Signed-off-by: Thomas Perale <thomas.perale@mind.be >
2025-11-26 09:02:17 +01:00
Bernd Kuhls
338a746eb6
package/nbd: Fix build on musl + gcc14
...
Fixes:
https://autobuild.buildroot.net/results/1e8/1e88151bb3aad1c1769e12b4930a2c33cd1c6830/
Signed-off-by: Bernd Kuhls <bernd@kuhls.net >
Signed-off-by: Julien Olivain <ju.o@free.fr >
(cherry picked from commit 0f1a2e875e )
Signed-off-by: Thomas Perale <thomas.perale@mind.be >
2025-11-26 09:02:15 +01:00
Arnout Vandecappelle
2c3329faca
Makefile: update for 2025.02.8
...
Signed-off-by: Arnout Vandecappelle <arnout@rnout.be >
2025.02.8
2025-11-20 22:32:29 +01:00
Arnout Vandecappelle
20e8a08264
CHANGES: update for 2025.02.8
...
Signed-off-by: Arnout Vandecappelle <arnout@rnout.be >
2025-11-20 22:30:48 +01:00
Titouan Christophe
ecf0283409
{linux, linux-headers}: bump 6.12.x series
...
Update the latest kernel releases to:
- 6.12.57 -> 6.12.58
Signed-off-by: Titouan Christophe <titouan.christophe@mind.be >
2025-11-17 13:35:06 +01:00
Peter Korsgaard
6a398e42ec
package/pkg-download.mk: fix 'dereferencing' typo
...
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
Signed-off-by: Julien Olivain <ju.o@free.fr >
(cherry picked from commit ac4dc0b95a )
Signed-off-by: Thomas Perale <thomas.perale@mind.be >
2025-11-15 17:43:33 +01:00
Bernd Kuhls
590ccc69a1
package/python-flask-cors: remove license file
...
Upstream tarball does not contain a license file anymore since version
5.0.1 [1] which causes errors after buildroot commit
04cd135b26 which bumped the package
version from 5.0.0 to 6.0.1.
Fixes:
https://autobuild.buildroot.net/results/1eb/1eb9d68616793c9241bcb55bc2ea1929608c68bd/
[1] https://github.com/corydolphin/flask-cors/issues/382
Signed-off-by: Bernd Kuhls <bernd@kuhls.net >
Signed-off-by: Julien Olivain <ju.o@free.fr >
(cherry picked from commit 9f3e222e99 )
Signed-off-by: Thomas Perale <thomas.perale@mind.be >
2025-11-15 17:43:24 +01:00