Commit Graph

83246 Commits

Author SHA1 Message Date
Bernd Kuhls
3577d1442e package/proftpd: security bump version to 1.3.9d
https://github.com/proftpd/proftpd/blob/v1.3.9d/NEWS

Version 1.3.9b fixes CVE-2026-44331.

Switched to sha256 tarball hash provided by upstream.

Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
2026-08-31 21:30:33 +02:00
Jimmy Durand Wesolowski
913512e302 package/openssh: ensure libxcrypt is enabled to provide a crypt() implementation
When OpenSSL is enabled, if DES support is enabled, OpenSSH uses
DES_crypt. However, without OpenSSL or its DES support, there is no
available crypt() implementation for OpenSSH libopenbsd-compat xcrypt()
function, resulting in the following error:

.../host/bin/i686-buildroot-linux-gnu-gcc -o sshd-auth sshd-auth.o
  auth2-methods.o auth-rhosts.o auth-passwd.o sshpty.o sshlogin.o
  servconf.o serverloop.o auth.o auth2.o auth-options.o session.o
  auth2-chall.o groupaccess.o auth-bsdauth.o auth2-hostbased.o
  auth2-kbdint.o auth2-none.o auth2-passwd.o auth2-pubkey.o
  auth2-pubkeyfile.o auth2-gss.o gss-serv.o gss-serv-krb5.o
  monitor_wrap.o auth-krb5.o audit.o audit-bsm.o audit-linux.o
  platform.o loginrec.o auth-pam.o auth-shadow.o auth-sia.o
  sandbox-null.o sandbox-rlimit.o sandbox-darwin.o
  sandbox-seccomp-filter.o sandbox-capsicum.o sandbox-solaris.o
  sftp-server.o sftp-common.o uidswap.o ssh-pkcs11-client.o
  ssh-sk-client.o -L. -Lopenbsd-compat/ -D_LARGEFILE_SOURCE
  -D_LARGEFILE64_SOURCE -D_FILE_OFFSET_BITS=64 -O2 -g0
  -D_FORTIFY_SOURCE=1 -Wl,-z,relro -Wl,-z,now -Wl,-z,noexecstack
  -fstack-protector-strong -pie -lssh -lopenbsd-compat
  -L.../host/bin/../i686-buildroot-linux-gnu/sysroot/usr/lib
  -lssl -lcrypto -lcrypto -lz
.../host/lib/gcc/i686-buildroot-linux-gnu/15.3.0/../../../../
  i686-buildroot-linux-gnu/bin/ld:
  openbsd-compat//libopenbsd-compat.a(xcrypt.o): in function `xcrypt':
xcrypt.c:(.text+0x51): undefined reference to `crypt'
.../host/lib/gcc/i686-buildroot-linux-gnu/15.3.0/../../../../
  i686-buildroot-linux-gnu/bin/ld:
openbsd-compat//libopenbsd-compat.a(xcrypt.o): in function `xcrypt':
xcrypt.c:(.text+0x51): undefined reference to `crypt' collect2: error:
ld returned 1 exit status make[2]: *** [Makefile:233: sshd-auth] Error
1 make[2]: *** Waiting for unfinished jobs....  collect2: error: ld
returned 1 exit status make[2]: *** [Makefile:230: sshd-session] Error
1 make[1]: *** [package/pkg-generic.mk:273:
.../build/openssh-10.4p1/.stamp_built]
Error 2 make: *** [Makefile:83: _all] Error 2

This commit enables BR2_PACKAGE_LIBXCRYPT with OpenSSH as long as
glibc is used. Since "sshd-auth" is compiled regardless of
BR2_PACKAGE_OPENSSH_SERVER, we need to enable it with BR2_PACKAGE_OPENSSH.

Signed-off-by: Jimmy Durand Wesolowski <jimmy.wesolowski@mobileye.com>
Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
2026-08-31 21:10:23 +02:00
Bernd Kuhls
4c504ef75d package/expat: security bump version to 2.8.4
https://github.com/libexpat/libexpat/blob/R_2_8_4/expat/Changes
https://blog.hartwork.org/posts/expat-2-8-4-released/

Fixes CVE-2026-66046, CVE-2026-76641, CVE-2026-76956 & CVE-2026-76957.

Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
2026-08-31 21:08:46 +02:00
Titouan Christophe via buildroot
cb18f3a74a package/vim: fix hash for README.txt
Buildroot commit 297f6f1921 updated vim.
However README.txt (used as part of the license hash check) has been updated
upstream in [1], without any corresponding hash change in Buildroot, leading
to build failure.

Fixes: https://gitlab.com/buildroot.org/buildroot/-/work_items/189

NB: This also affects 2025.02.x & 2026.05.x, so this patch
    should be applied there too.

[1] e7e21018fc

Signed-off-by: Titouan Christophe <titouan.christophe@mind.be>
Signed-off-by: Fiona Klute <fiona.klute@gmx.de>
2026-08-31 16:31:35 +02:00
Thomas Petazzoni
2eefcb245f docs/website: patchwork is now at patchwork.buildroot.org
patchwork.buildroot.org used to be a redirect to patchwork.ozlabs.org,
but we are now running our own instance, so let's adjust the links in
the website accordingly.

Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
2026-08-31 07:59:29 +02:00
Thomas Petazzoni
2d7d9d8200 docs/manual: patchwork is now at patchwork.buildroot.org
patchwork.buildroot.org used to be a redirect to patchwork.ozlabs.org,
but we are now running our own instance, so let's adjust the links in
the manual accordingly.

Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
2026-08-31 07:58:52 +02:00
Bernd Kuhls
911dc3a5d2 package/libldns: security bump version to 1.9.2
https://community.nlnetlabs.nl/t/ldns-1-9-1-released/3403
https://community.nlnetlabs.nl/t/ldns-1-9-2-released/3404
"Please do not install ldns version 1.9.1 as it has a wrong .so version.
 Install ldns version 1.9.2 instead."

Fixes CVE-2026-10846.

Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-08-30 22:38:46 +02:00
Bernd Kuhls
6bd5918183 package/freeswitch: security bump version to 1.11.3
https://github.com/signalwire/freeswitch/releases/tag/v1.11.3
"This is an important release containing critical security fixes and
 stability improvements. [...] We strongly encourage all users to
 upgrade to v1.11.3 as soon as possible."

Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-08-30 18:53:13 +02:00
Bernd Kuhls
be382f6061 package/{glibc, localedef}: security bump version to 2.44-36-g2d5421ffc
Fixes the following CVEs:

CVE-2026-19499:
63b53df549

CVE-2026-77117:
6f9b2bfa50

CVE-2026-80489:
cb61572ea3

Added GLIBC_IGNORE_CVES for CVE-2026-19542 which was forgotten in
buildroot commit 58f3137738.

Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-08-30 18:24:23 +02:00
Alessandro Rubini
e1ec936cf7 package/opencv: fix webp dependency
When BR2_PACKAGE_OPENCV4_WITH_WEBP=y we need to enable mux and demux
support in webp, otherwise the build of OpenCV fails as follows:

    CMake Error: The following variables are used in this project,
         but they are set to NOTFOUND.
    Please set them or make sure they are set and tested correctly
         in the CMake files:
    WEBP_DEMUX_LIBRARY
    linked by target "opencv_imgcodecs"
         in directory [...]/build/opencv4-4.13.0/modules/imgcodecs
    WEBP_MUX_LIBRARY
    linked by target "opencv_imgcodecs"
         in directory [...]/build/opencv4-4.13.0/modules/imgcodecs

The issue already exists in 2025.02.x.

Fixes:

  https://autobuild.buildroot.net/results/d3e0446a87d32469267e241866c4224143170f31/

Signed-off-by: Alessandro Rubini <rubini@gnudd.com>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
2026-08-29 23:32:51 +02:00
Robert P. J. Day
c529a2c286 docs/manual: post-image.sh/post-build.sh should use '-', not '_'
Even though it's only documentation, the form of the names of the
post-image.sh and post-build.sh scripts should be consistent with the
names of those scripts used in the code base, using hyphen, not
underscore.

Signed-off-by: Robert P. J. Day <rpjday@crashcourse.ca>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
2026-08-29 23:20:11 +02:00
Robert P. J. Day
dd2fb3de11 docs/manual: minor aesthetic cleanups in "Getting Buildroot"
Minor tweaks including proper capitalization.

Signed-off-by: Robert P. J. Day <rpjday@crashcourse.ca>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
2026-08-29 23:20:06 +02:00
Robert P. J. Day
59efb9037f docs/manual: update intro, make gender-neutral
Besides just updating a little terminology, remove the awkward
reference to "his" when referring to developers.

Signed-off-by: Robert P. J. Day <rpjday@crashcourse.ca>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
2026-08-29 23:20:01 +02:00
Alexis Lothoré via buildroot
bd5b267b1d package/openscap: fix build failure with dbus and musl
The openscap build can fail with the following error:

In file included from [...]/src/OVAL/probes/unix/linux/systemdunitproperty_probe.c:38:
[...]/src/OVAL/probes/unix/linux/systemdshared.h: In function ‘get_all_systemd_units’:
[...]/src/OVAL/probes/unix/linux/systemdshared.h:188:50: error: implicit declaration of function ‘basename’; did you mean ‘rename’? [-Wimplicit-function-declaration]
  188 |                 char *unit_name_s = oscap_strdup(basename(value.str));
      |                                                  ^~~~~~~~
      |                                                  rename
In file included from [...]/src/OVAL/probes/unix/linux/systemdunitdependency_probe.c:37:
[...]/src/OVAL/probes/unix/linux/systemdshared.h: In function ‘get_all_systemd_units’:
[...]/src/OVAL/probes/unix/linux/systemdshared.h:188:50: error: implicit declaration of function ‘basename’; did you mean ‘rename’? [-Wimplicit-function-declaration]
  188 |                 char *unit_name_s = oscap_strdup(basename(value.str));
      |                                                  ^~~~~~~~
      |                                                  rename

This error happens when:
- dbus is enabled in the configuration, making openscap build probes
  code
- the toolchain uses musl, which does not declare basename() in string.h
  the way glibc does

The build error can be reproduced with the following minimal defconfig:

  BR2_arm=y
  BR2_cortex_a9=y
  BR2_ARM_ENABLE_NEON=y
  BR2_ARM_ENABLE_VFP=y
  BR2_TOOLCHAIN_EXTERNAL=y
  BR2_TOOLCHAIN_EXTERNAL_BOOTLIN=y
  BR2_TOOLCHAIN_EXTERNAL_BOOTLIN_ARMV7_EABIHF_MUSL_BLEEDING_EDGE=y
  BR2_PACKAGE_DBUS=y
  BR2_PACKAGE_OPENSCAP=y

Backport the upstream fix to allow openscap to build with such
configuration. The custom patch can be removed once openscap is
re-released on its branch 1.3.x.

The issue affects master, 2026.05.x and 2025.02.x

Fixes: https://autobuild.buildroot.org/results/a874d4f34d36fa9f8566be90ad2d5facb99aec24/
Signed-off-by: Alexis Lothoré <alexis.lothore@bootlin.com>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
2026-08-29 23:13:21 +02:00
Alexis Lothoré via buildroot
5ea2135a56 package/erlang: fix link failure on odbcserver
host-erlang build can fail with the following error:

  make[5]: Nothing to be done for 'opt'.
   MAKE	opt
   CC	../priv/bin/x86_64-pc-linux-gnu/odbcserver
  /usr/bin/ld: ../priv/obj/x86_64-pc-linux-gnu/odbcserver.o: in function `encode_column_dyn':
  odbcserver.c:(.text+0x6b4): undefined reference to `ei_x_encode_tuple_header'
  /usr/bin/ld: odbcserver.c:(.text+0x6c2): undefined reference to `ei_x_encode_tuple_header'
  /usr/bin/ld: odbcserver.c:(.text+0x6d4): undefined reference to `ei_x_encode_ulong'
  /usr/bin/ld: odbcserver.c:(.text+0x6e7): undefined reference to `ei_x_encode_ulong'
  /usr/bin/ld: odbcserver.c:(.text+0x6fa): undefined reference to `ei_x_encode_ulong'
  /usr/bin/ld: odbcserver.c:(.text+0x708): undefined reference to `ei_x_encode_tuple_header'
  /usr/bin/ld: odbcserver.c:(.text+0x71b): undefined reference to `ei_x_encode_ulong'
  /usr/bin/ld: odbcserver.c:(.text+0x72e): undefined reference to `ei_x_encode_ulong'
  [...]

This can be reproduced with the following minimal defconfig (and
libei.so present on host, see details below):

  BR2_x86_64=y
  BR2_TOOLCHAIN_EXTERNAL=y
  BR2_PACKAGE_ERLANG=y

Those missing symbols are part of the erl_interface, exposed by libei.a.
host-erlang builds correctly libei.a _before_ odbcserver.c (it can be
found in lib/erl_interface/obj/x86_64-pc-linux-gnu/libei.a), but the
failure is actually due to the build command generated and used for
odbcserver.c, especially the link arguments:

  /usr/bin/gcc \
  [...]
  -o ../priv/bin/x86_64-pc-linux-gnu/odbcserver \
  ../priv/obj/x86_64-pc-linux-gnu/odbcserver.o \
  -L/usr/lib64 \
  -lodbc \
  -L/home/alexis/src/buildroot/erlang-master/build/host-erlang-custom/lib/erl_interface/obj/x86_64-pc-linux-gnu \
  -lpthread -lei

/usr/lib64 is searched before the path where libei.a has been built, so
if whether a valid libei.a or libei.so is found there, it shadows the
expected libei.a. In the build from which the logs above come, the
notable point is that the host system indeed have a valid libei.so, but
is completely unrelated to erl_interface; it rather exposes the Emulated
Input protocol aimed at Wayland stack; and so it obviously contains none
of the expected ei_* symbols.

Upstream has already identified and fixed the issue, the fix is already
released in versions >= 27.x.y. Erlang 26 (the version currently
packaged in buildroot), isn't supported anymore (only the three latest
releases are supported, see
https://github.com/erlang/otp/blob/master/SECURITY.md), so there won't
be any new minor update that will release this fix.

Pick and backport the fixing patch so that the current version packaged
in buildroot can still build.

Signed-off-by: Alexis Lothoré <alexis.lothore@bootlin.com>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
2026-08-29 23:09:58 +02:00
Peter Korsgaard
e6b06b8d9c Update for 2026.08-rc3
Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
2026.08-rc3
2026-08-29 21:08:24 +02:00
Neal Frager
dea4bf0eca configs/versal2_vek385_defconfig: remove useless atf console config
The VERSAL2_CONSOLE variable does not actually exist when building the atf
with plat=versal2. So the current VERSAL2_CONSOLE=cadence1 is not actually
doing anything. For this reason, the atf will print on its default console
which is UART0 or pl011_0.

The correct definition would be CONSOLE=pl011_1 in order to build the atf to
print on UART1 or pl011_1.

However, the git repo xparameters.h of the versal2_plm is not currently
enabling UART1 because the XPAR_XUARTPSV_NUM_INSTANCES is set to 1 including
the address defines only for UART0.
97f2baf7f6/lib/sw_apps/versal_plm/misc/versal_2ve_2vm/xparameters.h (L1519)

The problem with this is that the plm is not configuring UART1, so the atf
will crash at boot time, if it is built with CONSOLE=pl011_1 and the plm has
not already enabled UART1.

For now, we will remove the unnecessary config that is doing nothing.  The
versal2_vek385_defconfig is working, but users need to currently open two
console windows to see the boot log because the current config is the
following.

plm - console uart0
asufw - console uart0
atf - console uart0

optee-os - console uart1
u-boot - console uart1
Linux - console uart1

A patch has been submitted to the embeddedsw repo to fix the xparameters.h
file such that the plm will correctly enable UART1. Once this is applied, we
will configure the plm and atf to use UART1 with the versal2_vek385_defconfig.

Signed-off-by: Neal Frager <neal.frager@amd.com>
Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
2026-08-29 21:00:22 +02:00
Bernd Kuhls
7e13318329 {linux, linux-headers}: bump 6.12.x, 6.6.x, 6.1.x, 5.15.x, 5.10.x, 7.1.x, 6.18.x series
Update the latest kernel releases to:
 - 6.12.106 -> 6.12.107
 - 6.6.154 -> 6.6.155
 - 6.1.185 -> 6.1.186
 - 5.15.218 -> 5.15.219
 - 5.10.267 -> 5.10.268
 - 7.1.11 -> 7.1.12
 - 6.18.47 -> 6.18.48

Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
2026-08-29 20:29:30 +02:00
Bernd Kuhls
437a3632ca package/fetchmail: bump version to 6.6.7
https://sourceforge.net/p/fetchmail/mailman/message/59381086/
"Fetchmail 6.6.7 bugfix version has been released"

https://sourceforge.net/p/fetchmail/mailman/message/59350877/
"The 6.6.6 critical bug fix release of fetchmail is available"

Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
2026-08-29 20:25:48 +02:00
Bernd Kuhls
0fe2d74ffd package/libheif: security bump version to 1.23.2
https://github.com/strukturag/libheif/releases/tag/v1.23.2

Fixes the following CVEs:

(CVE numbers will be added upstream when assigned.)

CVE-2026-XXXXX (GHSA-g89c-p67h-r497)
 Heap buffer overflow in scale_nearest_neighbor() via duplicate alpha
 planes from nested iden/auxl items. (critical)

(GHSA-2jg2-4ch7-h545)
 Out-of-bounds read and write in derived-item and pixel-plane handling.
 Through iden and auxl item chains, a crafted file could attach pixel
 planes whose size differs from the image geometry; crop, scale, and
 plane-extraction code then indexed those planes with the wrong size.
 A working code-execution exploit was confirmed. Plane sizes are now
 validated wherever they are consumed. (critical)

CVE-2026-XXXXX (GHSA-24wx-9w62-c96w)
 brotli/zlib decompression of mime metadata and unci image data had no
 effective output-size limit, so a decompression bomb could exhaust
 memory. Decompressed output is now bounded by the security limits.
 (high)

CVE-2026-XXXXX (GHSA-x8xm-cm2c-cfc8)
 Chains of derived-image references (grid, iovl, iden) bypassed decode
 caching and memory limits, causing CPU and memory amplification. (high)

CVE-2026-XXXXX (GHSA-xw34-mjcp-jqh8)
 Sequence sample-timing initialization could produce non-terminating
 decode loops and unbounded memory, bypassing max_sequence_frames.
 (high)

CVE-2026-XXXXX (GHSA-j264-xvrp-5v7q)
 Out-of-bounds write in the unci encoder when
 heif_context_add_image_tile() is given a tile whose planes do not match
 its declared size. (high)

CVE-2026-XXXXX (GHSA-p58j-h3vm-3fp5)
 Heap out-of-bounds read in the inline-mask region API when
 mask_data_len does not match the region geometry. (medium)

Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
2026-08-29 20:24:48 +02:00
Thomas Petazzoni
83fc4aa55e package/collectd: fix build of virt plugin
Since the bump of libxml2 from 2.13.8 to 2.15.0 in Buildroot commit
d81922c1ef, the "virt" plugin of
collectd no longer builds:

src/virt.c:2208:49: error: expected ';', ',' or ')' before 'ATTRIBUTE_UNUSED'
 2208 | static void virt_eventloop_timeout_cb(int timer ATTRIBUTE_UNUSED,
      |                                                 ^~~~~~~~~~~~~~~~
src/virt.c: In function 'register_event_impl':
src/virt.c:2221:26: error: 'virt_eventloop_timeout_cb' undeclared (first use in this function)
 2221 |                          virt_eventloop_timeout_cb, NULL, NULL) < 0) {
      |                          ^~~~~~~~~~~~~~~~~~~~~~~~~
src/virt.c:2221:26: note: each undeclared identifier is reported only once for each function it appears in

This is due to the fact that the virt plugin code was incorrectly
using the ATTRIBUTE_UNUSED define, which was supposed to be an
internal define of libxml2. But it turns out that up to libxml2 2.14.0
and its commit 208f27f9641a59863ce1f7d4992df77f7eb0ea9d, this define
had been made publicly available. It could therefore mistakenly be
used by collectd's virt plugin... until libxml2 was upgraded.

We backport an upstream patch from collectd that fixes the issue.

Fixes:

  https://autobuild.buildroot.net/results/4c8463f0372560f4c3a20b0f67854460f0d1c400/

Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-08-28 13:28:47 +02:00
Thomas Petazzoni
e06cfae9cb support/testing: add bpftrace test
This commit adds a simple bpftrace test that ensures that not only it
builds fine, but it also runs properly on a minimal test scenario.

Assisted-by: GPT-5.6
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
[Julien:
 - reindent emulator.boot() options
 - add a call to "bpftrace --version"
]
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-08-28 11:47:12 +02:00
Thomas Petazzoni
cc25888c88 package/bpftrace: bump to version 0.26.1 to fix build with LLVM 22
Since Buildroot commit 25cb3813e7 which
bumped LLVM from 21.x to 22.x, the build of bpftrace is broken as
bpftrace 0.24.2 only supports LLVM up to 21.

We tried backporting the bpftrace patch that allows using LLVM up to
version 22 but the patch didn't apply cleanly but more importantly it
wasn't clear if this patch was sufficient. Therefore, we opt for
bumping bpftrace entirely to fix the issue.

Packaging changes:

- The new version of bpftrace no longer needs host-bison/host-flex,
  because bpftrace is now using a handwritten parser.

- Pass -DUSE_SYSTEM_LIBBPF:BOOL=ON to ensure the system libbpf version
  is used, and not the bundled version

- Now depends on kernel headers >= 5.10 because it needs CAP_BPF and
  CAP_PERFMON

Upstream changelog:
https://github.com/bpftrace/bpftrace/blob/v0.26.1/CHANGELOG.md

Fixes:

  https://autobuild.buildroot.net/results/a3e3fd696685864977c688aa11c2653357cf6207/

Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
[Julien: add link to upstream changelog]
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-08-28 11:47:12 +02:00
Thomas Petazzoni
e9c540ddd2 package/libbpf: update UAPI header installation work-around
bpftrace often needs very recent kernel headers, more recent than the
runtime version actually needed. We already had a workaround in
libbpf making sure that if the kernel headers are older than 6.1, we
would install the libbpf provided headers instead.

As we are about to update bpftrace to a newer version that uses
BPF_TRACE_KPROBE_SESSION, which was introduced in Linux 6.10, we need
to update this workaround accordingly and ensure that the libbpf
header is installed if the kernel headers are older than 6.10.

This is necessary for the update of bpftrace to 0.26.1.

Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-08-28 11:47:12 +02:00
Thomas Petazzoni
a51521cbe6 package/fluidsynth: fix download-while-configure since 2.5.7 bump
Since commit
566bdcb97f ("package/fluidsynth:
security bump to version 2.5.7"), fluidsynth tries to download some
"gcem" code during its configure step, which not only violates
Buildroot's policies, but also breaks the build if network is not
available during the build.

To fix this, we add an EXTRA_DOWNLOADS to grab gcem and extract it at
the right place. Some minor fix (submitted upstream) is needed to
ensure the FindGCEM.cmake logic properly finds that gcem is already in
the source tree.

Fixes:

  https://autobuild.buildroot.net/results/048df28f6ab97a16731e62d7f56c6eba565cda63/

Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-08-28 11:10:48 +02:00
Bernd Kuhls
6561717f18 package/php: bump version to 8.5.10
https://news-web.php.net/php.announce/504
"This is a bugfix release."

https://www.php.net/ChangeLog-8.php#8.5.10
https://github.com/php/php-src/blob/php-8.5.10/NEWS

Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-08-28 10:47:57 +02:00
Peter Korsgaard
211cfafa16 support/testing: add haproxy test
Based on the lighttpd test case.  Verify that we can download index.html
from haproxy in front of lighttpd.

Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-08-27 23:01:15 +02:00
Peter Korsgaard
94aa7f40b5 package/haproxy: needs signed overflow handling
haproxy has a runtime test to verify that it is built with -fwrapv:

haproxy
FATAL ERROR: invalid code detected -- cannot go further, please recompile!
The source code was miscompiled by the compiler, which usually indicates that
some of the CFLAGS needed to work around overzealous compiler optimizations
were overwritten at build time. Please do not force CFLAGS, and read Makefile
and INSTALL files to decide on the best way to pass your local build options.

Build options :
  TARGET  = custom
  CPU     = generic
  CC      = /home/peko/source/buildroot/output-haproxy/host/bin/arm-linux-gcc
  CFLAGS  = -D_LARGEFILE_SOURCE -D_LARGEFILE64_SOURCE -D_FILE_OFFSET_BITS=64 -O2 -g0 -D_FORTIFY_SOURCE=1 -D_LARGEFILE_SOURCE -D_LARGEFILE64_SOURCE -D_FILE_OFFSET_BITS=64 -O2 -g0 -D_FORTIFY_SOURCE=1
  OPTIONS = USE_THREAD=1 USE_DL=1
  DEBUG   = -DDEBUG_STRICT -DDEBUG_MEMORY_POOLS

Which comes from:
https://github.com/haproxy/haproxy/blob/v2.6.0/src/haproxy.c#L3008-L3037

So build it with -fwrapv to fix that.

Notice that this message also embeds the build path (through CC), breaking
reproducible builds.

Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-08-27 23:01:15 +02:00
Bernd Kuhls
e1ba84b9a7 {linux, linux-headers}: bump 6.12.x, 6.6.x, 6.1.x, 5.15.x, 5.10.x, 7.1.x, 6.18.x series
Update the latest kernel releases to:
 - 6.12.105 -> 6.12.106
 - 6.6.153 -> 6.6.154
 - 6.1.184 -> 6.1.185
 - 5.15.217 -> 5.15.218
 - 5.10.266 -> 5.10.267
 - 7.1.10 -> 7.1.11
 - 6.18.46 -> 6.18.47

Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-08-27 22:50:38 +02:00
Julien Olivain
6eaa34ecdf support/testing: wpa_supplicant: new runtime test
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-08-27 22:49:34 +02:00
Julien Olivain
4e62ac3a21 support/testing: quickjs: new runtime test
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-08-27 22:49:26 +02:00
Julien Olivain
bd4ac802e4 support/testing: fs: new cramfs runtime test
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-08-27 22:49:20 +02:00
Thomas Petazzoni
79554a4520 package/mesa3d: fix build issue with gcc < 13
Since upstream commit
e42e3193137d1b21e84b499336e7a8887b8a8689 ("intel: add Jay"), a C23
construct is used in the intel driver code:

enum jay_predication : uint8_t

This causes a build issue with GCC < 13:

In file included from ../src/intel/compiler/jay/jay_builder.h:12,
                 from ../src/intel/compiler/jay/jay_from_nir.c:23:
../src/intel/compiler/jay/jay_ir.h:582:22: error: expected identifier or ‘(’ before ‘:’ token
  582 | enum jay_predication : uint8_t {
      |                      ^
../src/intel/compiler/jay/jay_ir.h:637:25: error: field ‘predication’ has incomplete type
  637 |    enum jay_predication predication;
      |                         ^~~~~~~~~~~

We fix that by integrating a patch already available in
OpenEmbedded. It changes the code to not use the C23 construct.

This build issue was encountered on host-mesa3d while building an
allyespackageconfig configuration inside our standard Docker
container.

Buildroot commit
c073c97617 ("package/{mesa3d,
mesa3d-headers}: bump version to 26.1.0") that switched to mesa3d
26.1.0, which contains the problematic commit. Therefore 2026.05 is
affected, but not earlier Buildroot versions.

Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-08-27 22:42:55 +02:00
Thomas Petazzoni
34473e672b package/olsr: fix build with GCC >= 15
This commit introduces a patch, submitted upstream, that fixes the
build of OLSR with GCC >= 15.

Fixes:

  https://autobuild.buildroot.net/results/650edf74dec513ad540f80f4d3ef8c8222dfd711/

Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-08-27 22:40:08 +02:00
Thomas Petazzoni
d950fff290 package/perl: fix build issue with musl
perl does not build with musl due to memrchr() being unavailable. This
is caused by a perl-cross bug, which does function availability
detection with _GNU_SOURCE defined, but then does the build without
_GNU_SOURCE defined. At least OpenEmbedded and NixOS have faced the
same issue, and worked it around in slightly different ways.

On our side, we create a patch, which was submitted upstream, to solve
the issue.

This issue has been introduced in perl-cross commit b40c560f5d5e,
which was first merged in perl-cross release 1.4.1. From a Buildroot
perspective, we bumped from perl-cross 1.4 to 1.4.1 in commit
8a289667f5, which was merged
2023.05. And indeed the build failure can be reproduced even on our
LTS 2025.02.x, so the fix needs to be backported there.

It should be noted that even if the patch is against perl-cross, we
add it to package/perl/ directly, as patches in perl are applied after
perl has been extracted *and* perl-cross has been extracted on top.

Fixes:

  https://autobuild.buildroot.net/results/3e47ade0963642988fd8e1be9a6e8042700619ec/

Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-08-27 22:29:08 +02:00
Thomas Petazzoni
7538f675d7 package/bind: fix build with old host GCC since autoconf bump
Since the bump of autoconf to version 2.73 in Buildroot commit, the
build of target bind fails if the host compiler is too old, because
the bind build system tries to use -std=gnu23 when building host tools
which isn't supported by older GCC releases, causing:

checking whether the C compiler works... no
configure: error: in '/home/thomas/autobuild/instance-2/output-1/build/bind-9.20.26':
configure: error: C compiler cannot create executables
See 'config.log' for more details
make: *** [package/pkg-generic.mk:263: /home/thomas/autobuild/instance-2/output-1/build/bind-9.20.26/.stamp_configured] Error 77

To fix this, we backport a number of patches from autoconf-archive, to
fix the m4/ax_prog_cc_for_build.m4 macro file, so that it works with
autoconf 2.73.

OpenEmbedded has a similar fix:
https://git.openembedded.org/openembedded-core/tree/meta/recipes-connectivity/bind/bind/0001-m4-Backport-ax_prog_cc_for_build.m4-macros.patch
but did not backport as carefully the autoconf-archive commits (and
their commit message reverts to sudo).

The patches can be dropped when we update to a newer version of bind
that itself has an updated copy of the m4/ax_prog_cc_for_build.m4
file.

Fixes:

  https://autobuild.buildroot.net/results/13e07755101b7cae2f84eef173ef752f92842e71/

Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-08-27 22:23:42 +02:00
Romain Naour
240ea08d3f package/qt6: fix c++ static_assert issue
Since the last qt6 version bump to 6.11.1 [1], the TestQuazipQt6 fail to
build due to a c++ static_assert issue.

Backport a patch from v6.11.2 release.

Fixes:
https://gitlab.com/buildroot.org/buildroot/-/jobs/16060153667 (TestQuazipQt6)

[1] 05cd38635a

Signed-off-by: Romain Naour <romain.naour@smile.fr>
[Julien: fix link to qt6 version bump commit]
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-08-27 21:28:45 +02:00
Thomas Petazzoni
50a1dd2676 package/qt6/qt6declarative: fix select of host-qt6base network
The BR2_PACKAGE_QT6DECLARATIVE_QUICK option has some logic to select
network support in host-qt6base if network support is enabled in
qt6base. However, it turns out that this is actually required at the
top level BR2_PACKAGE_QT6DECLARATIVE option: as soon as network
support is available in qt6base, the qt6declarative build will assume
that qmlprofiler is available... but that requires network support in
host-qt6base.

This fixes the following build failure:

CMake Error at /home/thomas/autobuild/instance-2/output-1/build/qt6base-6.9.1/cmake/QtToolHelpers.cmake:784 (message):
  Failed to find the host tool "Qt6::qmlprofiler".  It is part of the
  Qt6QmlTools package, but the package did not contain the tool.  Make sure
  that the host module Qml was built with all features enabled (no explicitly
  disabled tools).
Call Stack (most recent call first):
  /home/thomas/autobuild/instance-2/output-1/build/qt6base-6.9.1/cmake/QtToolHelpers.cmake:83 (qt_internal_find_tool)
  tools/qmlprofiler/CMakeLists.txt:11 (qt_internal_add_tool)

Fixes:

  https://autobuild.buildroot.net/results/72c956fdf982382d2981c649c456d1edc2c9d6b2/

We did not trace back exactly since when the problem exists, but we
verified that the problem exists in 2025.02.x. It can be reproduced
with the following defconfig:

BR2_aarch64=y
BR2_TOOLCHAIN_EXTERNAL=y
BR2_TOOLCHAIN_EXTERNAL_BOOTLIN=y
BR2_TOOLCHAIN_EXTERNAL_BOOTLIN_AARCH64_GLIBC_STABLE=y
BR2_PACKAGE_QT6=y
BR2_PACKAGE_QT6BASE_NETWORK=y
BR2_PACKAGE_QT6DECLARATIVE=y

Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-08-27 19:55:57 +02:00
Thomas Petazzoni
29add67666 package/qt6/qt6declarative: move comment where it belongs
The commit "Enable host test module to ensure that qmltestrunner is
built" in qt6declarative's Config.in feels lonely under
BR2_PACKAGE_QT6DECLARATIVE. It's because it's actually related to a
select done in the sub-option BR2_PACKAGE_QT6DECLARATIVE_QUICK, so
move it there.

Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-08-27 19:55:57 +02:00
Romain Naour
b4949ce4c9 package/python-gobject: bump to 3.56
This version bump is required following the glib security version bump
to 2.88.3 [1] to fix a runtime issue due to GLib-2.0 backward
compatibility removal [2].

We prefer updating python-gobject to 3.56 stable release instead of
backporting complex commits from 3.55.x unstable release [3].

Fixes:
https://gitlab.com/buildroot.org/buildroot/-/jobs/16060152329 (TestFirewalldSysVInit)
https://gitlab.com/buildroot.org/buildroot/-/jobs/16060152332 (TestFirewalldSystemd)

[1] e313a2d259
[2] e02603d44d
[3] 74e4e0f40a

Runtime tested with TestGst1Python and TestFirewalld{Systemd,SysVInit}.

Cc: Fiona Klute <fiona.klute@gmx.de>
Signed-off-by: Romain Naour <romain.naour@smile.fr>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-08-27 19:55:18 +02:00
Romain Naour
803cac2271 support/testing: TestFirewalld{Systemd, SysVInit}: fix expected ouput
Since Firewalld v2.4.3 [1] firewall-cmd added a new log line while
waiting for dbus connection [2].

  [BRTEST# firewall-cmd --state
  Waiting on dbus connection...
  running

The line "Waiting on dbus connection..." is not always printed by
firewall-cmd, so we have to search explicitely for the expected
string to get a reproducible test result.

Update both TestFirewalld accordingly.

This change is required to fix:
https://gitlab.com/buildroot.org/buildroot/-/jobs/16060152329 (TestFirewalldSysVInit)
https://gitlab.com/buildroot.org/buildroot/-/jobs/16060152332 (TestFirewalldSystemd)

[1] 380dd8a348
[2] 5e1c37c966

Signed-off-by: Romain Naour <romain.naour@smile.fr>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-08-27 19:55:18 +02:00
Romain Naour
3bd3d5004d support/testing: TestPythonPy3Gobject: test glib 2.88 regression
In Glib >= 2.88, GLib.unix_signal_add has been moved to a separate
platform-specific library. This break backward compatibility from
GLib-2.0. A workaround has been applied to pygobject >= 3.55.3
74e4e0f40a

This issue currently break TestFirewalldSysVInit and
TestFirewalldSystemd runtime tests since the bump to glib 2.88.3 [1]:

https://gitlab.com/buildroot.org/buildroot/-/jobs/16060152329 (TestFirewalldSysVInit)
https://gitlab.com/buildroot.org/buildroot/-/jobs/16060152332 (TestFirewalldSystemd)

Break the test TestPythonPy3Gobject now in order to reproduce the same
issue than for Firewalld test.

[1] e313a2d259

Signed-off-by: Romain Naour <romain.naour@smile.fr>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-08-27 19:55:18 +02:00
Romain Naour
b4b1de1f7f support/testing: TestMdnsd: improve test reliability
The mdnsd runtime test can randomly fail on slow runners.

It's hard to reproduce locally (only one failure after a few attempts)
but we can reproduce it easily by removing the while loop entirely.

It means that the "sleep 1" is not used on the Gitlab runner.
The timestamp of the failed job seems to confirm that [1].

07:06:55    [BRTEST# while ! ifconfig eth0 | grep -q 'inet addr'; do sleep 1; done
07:06:55    [BRTEST# echo $?
07:06:55    0
07:06:55    [BRTEST# mquery -T _http._tcp |grep -F buildroot._http._tcp.local
07:06:55    [BRTEST# echo $?
07:06:55    1

So wait a bit for mdnsd to be ready.

Fixes:
https://gitlab.com/buildroot.org/buildroot/-/jobs/16060152862

Signed-off-by: Romain Naour <romain.naour@smile.fr>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-08-26 23:49:49 +02:00
Julien Olivain
23fd881bdb support/testing: php: fix test by switching to "Debian" filesystem layout
Buildroot commit [1] (package/apache: use "Debian" filesystem
layout to fix read-only rootfs) changed the filesystem layout.
This had the effect of installing files to different locations
and breaking the test_php runtime test.

This commit fixes the issue by updating the file paths to their
right locations. The "httpd.conf" was updated by following the
same recipe described in the comment (starting from a config
file as installed by the apache Buildroot package).

Fixes:
https://gitlab.com/buildroot.org/buildroot/-/jobs/16060152979

[1] 1006666f67

Signed-off-by: Julien Olivain <ju.o@free.fr>
Tested-by: Romain Naour <romain.naour@smile.fr>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-08-26 23:47:56 +02:00
Thomas Petazzoni
d21a1ac886 package/flex: fix build with old host GCC since autoconf bump
Since the bump of autoconf to version 2.73 in Buildroot commit [1], the
build of target flex fails if the host compiler is too old, because
the flex build system tries to use -std=gnu23 which isn't supported by
older GCC releases, causing:

gcc: error: unrecognized command-line option '-std=gnu23'; did you mean '-std=gnu2x'?
gcc: error: unrecognized command-line option '-std=gnu23'; did you mean '-std=gnu2x'?
make[3]: *** [Makefile:1162: stage1flex-buf.o] Error 1

(Indeed the *target* flex package does build some host tools using the
host GCC compiler.)

To fix this issue, we backport an upstream commit that isn't yet in
any flex release.

Fixes:

  https://autobuild.buildroot.net/results/aac730b57adb5b54964f1054de781750952ef7d4/

[1] a6e8c07a33

Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
[Julien: add link to commit]
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-08-26 23:44:29 +02:00
Thomas Petazzoni
f57da3c953 package/dahdi-linux: backport commits to fix build with recent kernels
Fixes build with kernels >= 6.15.

Fixes:

  https://autobuild.buildroot.net/results/ed73aa844a18cfc15e942ced4ae363c3d0d09015/

Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-08-26 23:06:42 +02:00
Thomas Petazzoni
d8dde961bc package/bind: fix thread dependency
In commit 54f96add94 ("package/bind:
security bump version to 9.20.24") the depends on
BR2_TOOLCHAIN_HAS_THREADS_NPTL was incorrectly downgraded to
BR2_TOOLCHAIN_HAS_THREADS:

-       depends on BR2_TOOLCHAIN_HAS_THREADS_NPTL # libuv
+       depends on BR2_TOOLCHAIN_HAS_THREADS # liburcu, libuv

This is wrong because libuv depends on
BR2_TOOLCHAIN_HAS_THREADS_NPTL. This causes unmet dependencies:

WARNING: unmet direct dependencies detected for BR2_PACKAGE_LIBUV
  Depends on [n]: BR2_TOOLCHAIN_HAS_THREADS_NPTL [=n] && BR2_USE_MMU [=y] && !BR2_STATIC_LIBS [=n] && BR2_TOOLCHAIN_HAS_SYNC_4 [=y] && BR2_TOOLCHAIN_GCC_AT_LEAST_4_9 [=y]
  Selected by [y]:
  - BR2_PACKAGE_BIND [=y] && BR2_USE_MMU [=y] && BR2_TOOLCHAIN_HAS_SYNC_4 [=y] && BR2_TOOLCHAIN_HAS_THREADS [=y] && BR2_INSTALL_LIBSTDCPP [=y] && !BR2_STATIC_LIBS [=n] && BR2_TOOLCHAIN_GCC_AT_LEAST_4_9 [=y] && BR2_PACKAGE_LIBURCU_ARCH_SUPPORTS [=y]

Fix that by switching back to the BR2_TOOLCHAIN_HAS_THREADS_NPTL
dependency.

Fixes: 54f96add94 ("package/bind: security bump version to 9.20.24")
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-08-26 22:58:39 +02:00
Thomas Perale
52ae04257a package/rsyslog: upstream patch CVE-2026-19654
- CVE-2026-19654:
    A unauthenticated remote peer may lead rsyslogd to crash due to a flaw
    in the optional imptcp module. A crafted input sequence during
    oversize-frame recovery can cause an invalid internal message length
    and terminate rsyslogd. No confidentiality or integrity impact,
    privilege escalation, or code execution has been identified. imtcp and
    the default imptcp framing modes are not affected.

For more information, see:
  - https://www.cve.org/CVERecord?id=CVE-2026-19654
  - 07b3c40a5a

Signed-off-by: Thomas Perale <thomas.perale@mind.be>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-08-26 22:51:41 +02:00
Thomas Perale
d0619dfc6b package/unbound: security bump to v1.25.2
See the changelog:

- https://nlnetlabs.nl/projects/unbound/download/#unbound-1-25-2

It fixes the following vulnerabilities:

- CVE-2026-14586: Assertion in libngtcp2 when under pressure in high
  concurrency DNS-over-QUIC environments.
- CVE-2026-32665: Remote DNS-over-QUIC denial of service due to
  `quic-size` budget bypass.
- CVE-2026-40691: Packet of death for DNSCrypt over TCP.
- CVE-2026-41637 Degradation of resolution service from improperly
  accounted client-terminated DNS-over-QUIC queries.
- CVE-2026-42955: Extra fix for CVE-2026-40622 to also clamp the TTL of
  A/AAAA records disallowing a one-time 'ghost domain' delegation
  renewal via glue records.
- CVE-2026-44621: Libunbound applications configured with
  'unwanted-reply-threshold' could eventually be abruptly terminated.
- CVE-2026-44687: Off-by-one error in 'harden-below-nxdomain' logic can
  shadow a stub/forward zone by a legitimate parent's NXDOMAIN.
- CVE-2026-44690: Cross-zone wildcard cache poisoning via RRSIG.labels
  manipulation.
- CVE-2026-46582: A wildcard replay, as another piece of data, triggers
  poisoning in the serve expired reply path.
- CVE-2026-50045: 'max-global-quota' reset by DNSSEC validation
  restarts.
- CVE-2026-50046: Possible heap use-after-free in an error path when a
  DoT forwarded query is jostled out.
- CVE-2026-50243: 'response-ip'/'rpz' can rewrite BOGUS answers instead
  of returning SERVFAIL.
- CVE-2026-50248: BOGUS configured primary hostname accepted for XFR in
  auth/rpz zones.
- CVE-2026-50251: Attacker supplied `0.0.0.0`/`::` glue triggers
  defensive full-cache flush.
- CVE-2026-50252: Possible cache poisoning attack by mapping source port
  population per thread.
- CVE-2026-52863: Memory corruption could lead to crash and denial of
  service.
- CVE-2026-54478: DNS Cookie bypass when combined with proxy-protocol
  use.
- CVE-2026-55708: Privacy/configuration issue when adding local data in
  views through 'unbound-control'.
- CVE-2026-55717: 'serve-expired-client-timeout' and 'response-ip' CNAME
  redirect could lead to a crash.
- CVE-2026-55973: 'dns-error-reporting: yes' leads to stack buffer
  overflow.
- CVE-2026-55990: Packet of death for a DNSCrypt misconfigured Unbound.
- CVE-2026-55991: Remote DNS-over-QUIC (DoQ) flow-control assertion
  failure in libngtcp2.
- CVE-2026-56416: Possible heap buffer overflow when validator
  canonicalizes RDATA that contains domain name.
- CVE-2026-56444: Degradation of resolution service when
  'discard-timeout' and 'serve-expired-client-timeout' are combined in
  unusual configuration.

Signed-off-by: Thomas Perale <thomas.perale@mind.be>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-08-26 22:44:23 +02:00
Titouan Christophe
02d8a41f09 package/{avro-c, python-avro}: security bump to v1.12.2
This release includes a broad round of hardening against malformed and
adversarial input across the Python SDK (bounding allocations and enforcing
decompression limits before trusting size fields read from the input).

See the release notes https://avro.apache.org/blog/2026/08/12/avro-1.12.2/

Also update the download url, because www-eu.apache.org/dist/...
is a redirection to downloads.apache.org/...

Signed-off-by: Titouan Christophe <titouan.christophe@mind.be>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-08-26 22:35:24 +02:00