Commit Graph

77281 Commits

Author SHA1 Message Date
Peter Korsgaard
9a1aaec3f3 package/screen: security bump to version 5.0.1
Fixes the following security issues:

CVE-2025-46805: do NOT send signals with root privileges
CVE-2025-46804: avoid file existence test information leaks
CVE-2025-46803: apply safe PTY default mode of 0620
CVE-2025-46802: prevent temporary 0666 mode on PTYs in attacher
CVE-2025-23395: reintroduce lf_secreopen() for logfile

https://lists.gnu.org/archive/html/info-gnu/2025-05/msg00002.html

For more details, see:
https://security.opensuse.org/2025/05/12/screen-security-issues.html

Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2025-05-16 13:40:17 +02:00
El Mehdi YOUNES
3615b2cd04 package: update all hashes after cargo3 switch
This updates all SHA256 hashes for Rust packages that previously used
cargo2.tar.gz archives, following the switch to cargo3 naming in my last
patch.

Signed-off-by: El Mehdi YOUNES <elmehdi.younes@smile.fr>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
2025-05-16 13:26:33 +02:00
El Mehdi YOUNES
b80278613e package/pkg-download: switch from cargo2 to cargo3
Starting from rust 1.84.0 (cargo 1.84.0), published crates now always
include a Cargo.lock file. Originally it was only included for packages
that have executables or examples for use with cargo install. see [1]

This behaviour change alters the contents of the .tar.gz archives,
which causes SHA256 hash mistmatches when trying to build Rust packages.

Example build failure with bat-0.24.0:

ERROR: while checking hashes from package/bat/bat.hash
ERROR: bat-0.24.0-cargo2.tar.gz has wrong sha256 hash:
ERROR: expected: 45fcdd6076dc1b45698a7b6c0f4d1f5d9ae676f3ca3b155402ad24680d5b4df6
ERROR: got     : 28b302b1aa325221796d4ebb25bacab19a8927ef32f4d56a965b32a7b1c102fc

After using the ne hash to download the new archive tar.gz, we have the
difference between the old archive and the new one using diffoscope:
│ │ --rw-r--r--   0        0        0     1529 2023-10-11 17:14:12.000000 bat-0.24.0/VENDOR/bincode/.cargo-checksum.json
│ │ +-rw-r--r--   0        0        0     1609 2023-10-11 17:14:12.000000 bat-0.24.0/VENDOR/bincode/.cargo-checksum.json
│ │ +-rw-r--r--   0        0        0     1766 2023-10-11 17:14:12.000000 bat-0.24.0/VENDOR/bincode/Cargo.lock
│ │  -rw-r--r--   0        0        0     1388 2023-10-11 17:14:12.000000 bat-0.24.0/VENDOR/bincode/Cargo.toml

We can see that Cargo.lock has been added.

To avoid hash mismatch issues and to clearly mark archives generated
with the new Cargo behavior, we migrate the naming from 'cargo2.tar.gz'
to 'cargo3.tar.gz'.

We did not find any alternative to disable this new cargo-publish
behavior, so this change is necessary to allow updating the hashes of
Cargo-fetched packages.

[1] https://github.com/rust-lang/cargo/pull/14815
https://doc.rust-lang.org/nightly/cargo/CHANGELOG.html

Signed-off-by: El Mehdi YOUNES <elmehdi.younes@smile.fr>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
2025-05-16 13:26:32 +02:00
El Mehdi YOUNES
072f3bc8c6 package/rust: bump to version 1.86.0
bump rust from version 1.82.0 to 1.86.0
releases:
https://github.com/rust-lang/rust/releases

Signed-off-by: El Mehdi YOUNES <elmehdi.younes@smile.fr>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
2025-05-16 13:26:32 +02:00
El Mehdi YOUNES
740204bf9a package/rust: fix bootstrap with Rust≥1.83
Rust includes an option `download-ci-llvm` in config.toml that enables
downloading prebuilt LLVM binaries from Rust's CI infrastructure instead
of building LLVM from source. This option helps speed up the bootstrap
process and is enabled by default starting from Rust 1.83.

However, starting from commit [1] the bootstrap process performs
a strict check via the function
check_incompatible_options_for_ci_llvm().

This validation, implemented in the function
check_incompatible_options_for_ci_llvm(), checks for any incompatible
custom options such as `llvm.ldflags`, `llvm.cflags`, `targets`, etc.

If any of these are set locally and differ from the values used to build
the CI-provided LLVM, the build fails immediately with the error:

      ERROR: Setting `llvm.ldflags` is incompatible with
             `llvm.download-ci-llvm`.

Buildroot explicitly sets `llvm.ldflags` in rust.mk to ensure proper
host linking during the build of host-rust. Removing this setting may
introduce portability or reliability issues across toolchains.

To address the issue without compromising the build environment, this
patch disables the use of CI-provided LLVM by setting:

      [llvm]
      download-ci-llvm = false

This follows the recommendation from the Rust bootstrap script itself.

Note: this is a temporary workaround to restore compatibility with Rust
≥1.83. Other solutions will be investigated to avoid disabling the use
of prebuilt LLVM in the future, while preserving Buildroot’s reproducible
build setup.

[1] 9df7680ecf

Signed-off-by: El Mehdi YOUNES <elmehdi.younes@smile.fr>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
2025-05-16 13:26:31 +02:00
Julien Olivain
e9911873aa configs/freescale_imx*: bump BSP components to lf-6.12.3-1.0.0
This commit U-Boot, Linux kernel and ATF (when applicable) to the
NXP BSP lf-6.12.3-1.0.0 versions.

Custom hashes are also updated accordingly.

Signed-off-by: Julien Olivain <ju.o@free.fr>
2025-05-16 12:49:35 +02:00
Sébastien Szymanski
2f13e813c0 package/freescale-imx/imx-sc-firmware: bump version to 1.18.0
This version is aligned with NXP Linux BSP version "lf-6.12.3-1.0.0".

License hashes changed because the LA_OPT_NXP_Software_License changed
from "v57 July 2024" to "v58 November 2024".

Signed-off-by: Sébastien Szymanski <sebastien.szymanski@armadeus.com>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2025-05-16 12:49:35 +02:00
Sébastien Szymanski
33778c8552 package/freescale-imx/imx-vpu-hantro-daemon: bump version to 1.5.0
This version is aligned with NXP Linux BSP version "lf-6.12.3-1.0.0".

Signed-off-by: Sébastien Szymanski <sebastien.szymanski@armadeus.com>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2025-05-16 12:49:35 +02:00
Sébastien Szymanski
4fe6235126 package/freescale-imx/imx-vpu-hantro: bump version to 1.36.0
This version is aligned with NXP Linux BSP version "lf-6.12.3-1.0.0".

License hashes changed because the LA_OPT_NXP_Software_License changed
from "v57 July 2024" to "v58 November 2024".

Signed-off-by: Sébastien Szymanski <sebastien.szymanski@armadeus.com>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2025-05-16 12:49:35 +02:00
Sébastien Szymanski
05b20d572c package/freescale-imx/imx-gpu-viv: bump version to 6.4.11.p3.0
This version is aligned with NXP Linux BSP version "lf-6.12.3-1.0.0".

License hashes changed because the LA_OPT_NXP_Software_License changed
from "v57 July 2024" to "v58 November 2024".
The Vivante.icd file is now in gpu-core/etc/OpenCL/vendors/ and there is
a new directory "vulkan" in gpu-core/etc/. Copy both OpenCL and vulkan
directories to /etc/.

Signed-off-by: Sébastien Szymanski <sebastien.szymanski@armadeus.com>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2025-05-16 12:49:35 +02:00
Sébastien Szymanski
9d0e9e07a8 package/freescale-imx/firmware-ele-imx: bump to version 2.0.1
This version is aligned with NXP Linux BSP version "lf-6.12.3-1.0.0".

License hashes changed because the LA_OPT_NXP_Software_License changed
from "v57 July 2024" to "v58 November 2024".

Signed-off-by: Sébastien Szymanski <sebastien.szymanski@armadeus.com>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2025-05-16 12:49:35 +02:00
Sébastien Szymanski
20246264e5 package/freescale-imx/imx-gpu-g2d: bump version to 6.4.11.p3.0
This version is aligned with NXP Linux BSP version "lf-6.12.3-1.0.0".

License hashes changed because the LA_OPT_NXP_Software_License changed
from "v57 July 2024" to "v58 November 2024".

Signed-off-by: Sébastien Szymanski <sebastien.szymanski@armadeus.com>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2025-05-16 12:49:35 +02:00
Sébastien Szymanski
15c91ed9b5 package/freescale-imx/firmware-imx: bump version to 8.27
This version is aligned with NXP Linux BSP version "lf-6.12.3-1.0.0".

License hashes changed because the LA_OPT_NXP_Software_License changed
from "v57 July 2024" to "v58 November 2024".

Signed-off-by: Sébastien Szymanski <sebastien.szymanski@armadeus.com>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2025-05-16 12:49:35 +02:00
Patrik Olsson
506c9b8e0d configs/friendlyarm_nanopi_r3s: bump TF-A, U-Boot and Linux versions
- TF-A to version v2.12 (LTS)
- U-Boot to version v2025.04
- Linux kernel to version 6.14.6

Signed-off-by: Patrik Olsson <johan.patrik.olsson@gmail.com>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2025-05-16 12:41:55 +02:00
Patrik Olsson
42357f0b13 configs/friendlyarm_nanopi_r3s: use Bootlin toolchain
This moves the defconfig to the Bootlin glibc stable external toolchain
as per[1].

[1]: https://elinux.org/Buildroot:DeveloperDaysELCE2024#Rules_for_defconfigs

Signed-off-by: Patrik Olsson <johan.patrik.olsson@gmail.com>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2025-05-16 12:41:55 +02:00
Fiona Klute (WIWA)
a32a1e9a84 package/rauc: enable JSON output in host package
JSON output is useful for building integrations, e.g. reading bundle
information into other tools.

Host-json-glib is very small / fast to build compared to the other
dependencies, so enable it unconditionally.

Signed-off-by: Fiona Klute (WIWA) <fiona.klute@gmx.de>
[Peter: unconditionally enable JSON support]
Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
2025-05-16 12:36:50 +02:00
Kadambini Nema
a127b7e999 package/openssh: bump to version 10.0p1
Release notes:
https://www.openssh.com/txt/release-10.0

Install sshd-auth.
6072e4c938

Also, the release note of 10.0p1 states it is a security update for
CVE-2025-32728. This commit is not marked as security bump, because the
security fix is already present in Buildroot since commit [1]. For this
reason, this commit also removes the package patches and the
_IGNORE_CVES variable.

[1] 211e822d43

Signed-off-by: Kadambini Nema <kadambini.nema@gmail.com>
[Julien:
 - remove the "security" mention commit title
 - remove local patches and _IGNORE_CVES
 - add info in commit log
]
Signed-off-by: Julien Olivain <ju.o@free.fr>
2025-05-16 12:08:05 +02:00
Julien Olivain
00b2d74dbb package/kexec: bump to version 2.0.31
For release announce, see:
https://lists.infradead.org/pipermail/kexec/2025-April/032608.html

Signed-off-by: Julien Olivain <ju.o@free.fr>
Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
2025-05-16 11:49:56 +02:00
Julien Olivain
634b2c5253 package/fluidsynth: bump to version 2.4.5
For change log since v2.4.3, see:
https://github.com/FluidSynth/fluidsynth/releases/tag/v2.4.4
https://github.com/FluidSynth/fluidsynth/releases/tag/v2.4.5

Signed-off-by: Julien Olivain <ju.o@free.fr>
Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
2025-05-16 11:48:02 +02:00
Cherniaev Andrei
4e95062f82 package/pkg-meson: use buildroot-build for build directory
Fixes https://gitlab.com/buildroot.org/buildroot/-/issues/64

Some source tarballs (E.G.  libopenh264) may already contain a build/
subdir, so switch to the more unique bildroot-build for the build directory,
similar to how it is done for cmake.

Signed-off-by: Cherniaev Andrei <dungeonlords789@naver.com>
Co-Authored-By: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
[Peter: reword commit text]
Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
2025-05-16 11:42:56 +02:00
Titouan Christophe
211e822d43 package/openssh: apply security patch for CVE-2025-32728 (sshd)
Fixes:
https://www.cve.org/CVERecord?id=CVE-2025-32728

Signed-off-by: Titouan Christophe <titouan.christophe@mind.be>
[Julien: add link to CVE in commit log]
Signed-off-by: Julien Olivain <ju.o@free.fr>
2025-05-16 11:19:36 +02:00
Kadambini Nema
aaa50b0e61 package/xz: bump to version 5.8.1
Update hash of the COPYING file. (Notes about old releases was removed)

Release notes:
https://github.com/tukaani-project/xz/releases/tag/v5.8.1
https://github.com/tukaani-project/xz/releases/tag/v5.8.0

Also, the release note of v5.8.1 states it is a security update for
CVE-2025-31115. This commit is not marked as security bump, because the
security fix is already present in Buildroot since commit [1]. For this
reason, this commit also removes the package patches and the
XZ_IGNORE_CVES variable.

[1] 38494a0a61

Signed-off-by: Kadambini Nema <kadambini.nema@gmail.com>
[Julien:
 - remove the "security" mention commit title
 - remove local patches and XZ_IGNORE_CVES
 - add info in commit log
]
Signed-off-by: Julien Olivain <ju.o@free.fr>
2025-05-16 10:55:25 +02:00
Peter Korsgaard
d9182a7556 docs/website/download.html: update for 2025.02.1
Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
2025-05-16 10:25:31 +02:00
Julien Olivain
6ad8090920 configs/freescale_t1040d4rdb: bump linux kernel to 6.12.27
Since commit [1] "package/binutils: make 2.43 the default version",
the freescale_t1040d4rdb_defconfig fails to build the Linux
kernel, with the error:

    arch/powerpc/boot/util.S: Assembler messages:
    arch/powerpc/boot/util.S:49: Error: junk at end of line, first unrecognized character is `0'
    arch/powerpc/boot/util.S:54: Error: syntax error; found `b', expected `,'
    arch/powerpc/boot/util.S:54: Error: junk at end of line: `b'

This commit fixes the issue by updating the Linux kernel to the latest
LTS version.

Fixes:
https://gitlab.com/buildroot.org/buildroot/-/jobs/9967089767

[1] 360fd01de2

Signed-off-by: Julien Olivain <ju.o@free.fr>
Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
2025-05-16 10:15:47 +02:00
Julien Olivain
889d47baef configs/freescale_p1025twr: bump linux kernel to 6.12.27
Since commit [1] "package/binutils: make 2.43 the default version",
the freescale_p1025twr_defconfig fails to build the Linux
kernel, with the error:

    arch/powerpc/boot/util.S: Assembler messages:
    arch/powerpc/boot/util.S:49: Error: junk at end of line, first unrecognized character is `0'
    arch/powerpc/boot/util.S:54: Error: syntax error; found `b', expected `,'
    arch/powerpc/boot/util.S:54: Error: junk at end of line: `b'

This commit fixes the issue by updating the Linux kernel to the latest
LTS version.

Fixes:
https://gitlab.com/buildroot.org/buildroot/-/jobs/9967089759

[1] 360fd01de2

Signed-off-by: Julien Olivain <ju.o@free.fr>
Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
2025-05-16 10:15:22 +02:00
Julien Olivain
8bfdd3305e package/libsndfile: update project home page url
The libsndfile package homepage url [1] points to an old site in which
the last update is for version 1.0.28 (April 2 2017). This site does
not seem to be maintained anymore.

This commit updates the libsndfile homepage url to [2].

[1] http://www.mega-nerd.com/libsndfile/
[2] https://libsndfile.github.io/libsndfile/

Signed-off-by: Julien Olivain <ju.o@free.fr>
Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
2025-05-16 10:14:35 +02:00
Thomas Devoogdt
84d9cf3abe package/fluent-bit: bump to 4.0.2
News:
- https://fluentbit.io/announcements/v4.0.1/
- https://fluentbit.io/announcements/v4.0.2/

Other remarks:
- Drop the FLB_UNICODE_ENCODER option, as it is no longer needed. [1]

- Added support for FLB_OUT_PGSQL.

- Compile against the buildroot provided zstd package. [2]

- Dropped some patches as they are obsolete. (We use the buildroot packages for them.)
   - 0003-lib-nghttp2-CMakeLists.txt-do-not-require-a-CXX-comp.patch
   - 0004-lib-luajit-cmake-CMakeLists.txt-do-not-require-a-CXX.patch
   - 0006-lib-zstd-only-enable-CXX-support-if-tests-are-requir.patch

- Synced the other patches with their upstream equivalent.

[1] 92de130cea
[2] 5f409f55ec

Signed-off-by: Thomas Devoogdt <thomas@devoogdt.com>
Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
2025-05-16 09:46:01 +02:00
Thomas Perale
a4249a2024 package/libraw: security bump to version 0.21.4
Fixes the following security issues:

- CVE-2025-43961: metadata/tiff.cpp has an out-of-bounds read in the
    Fujifilm 0xf00c tag parser.

For more information, see:
  - https://nvd.nist.gov/vuln/detail/CVE-2025-43961
  - 66fe663e02

- CVE-2025-43962: phase_one_correct in decoders/load_mfbacks.cpp has
    out-of-bounds reads for tag 0x412 processing

For more information, see:
  - https://nvd.nist.gov/vuln/detail/CVE-2025-43962
  - 66fe663e02

- CVE-2025-43963: phase_one_correct in decoders/load_mfbacks.cpp allows
    out-of-buffer access

For more information, see:
  - https://nvd.nist.gov/vuln/detail/CVE-2025-43963
  - be26e7639e

- CVE-2025-43964: tag 0x412 processing in phase_one_correct in
    decoders/load_mfbacks.cpp does not enforce minimum w0 and w1 values.

For more information, see:
  - https://nvd.nist.gov/vuln/detail/CVE-2025-43964
  - a50dc3f112

For more details on the version bump, see the release notes:
  - https://github.com/LibRaw/LibRaw/releases/tag/0.21.4
  - https://github.com/LibRaw/LibRaw/releases/tag/0.21.3
  - https://github.com/LibRaw/LibRaw/compare/0.21.2...0.21.4

Signed-off-by: Thomas Perale <thomas.perale@mind.be>
Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
2025-05-15 07:51:32 +02:00
Marcus Hoffmann
c722fa1cf2 package/python-django: bump to 5.2.1
Django 5.2 is a new LTS series. Release notes and announcement:

https://docs.djangoproject.com/en/5.2/releases/5.2/
https://www.djangoproject.com/weblog/2025/apr/02/django-52-released/

Signed-off-by: Marcus Hoffmann <buildroot@bubu1.eu>
Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
2025-05-14 15:03:38 +02:00
Marcus Hoffmann
09299c5b0c package/python-django: security bump to 5.1.9
Fixes CVE-2025-32873 [1].
Django also updates setuptools[2], so we can remove the --skip-dependency-check
flag and need to update the package archive capitalization accordingly.

[1] https://www.djangoproject.com/weblog/2025/may/07/security-releases/
[2] bbf376bbc8

Signed-off-by: Marcus Hoffmann <buildroot@bubu1.eu>
Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
2025-05-14 14:57:57 +02:00
Julien Olivain
38494a0a61 package/xz: add security patches fixing CVE-2025-31115
This commit adds four upstream patches fixing the CVE-2025-31115
vulnerability. The reason there is four patches instead of one is to
exactly follow the advisory recommendation [1], which proposes the
patch [2]. This patch is in fact a concatenation of four commits. In
Buildroot, we track package patches as formatted by git, with extra
"Upstream:" headers. The patch [2] was split here in four for a
clearer traceability.

With the addition of those patches, the XZ_IGNORE_CVES is set
accordingly.

Fixes:
https://www.cve.org/CVERecord?id=CVE-2025-31115

[1] https://github.com/tukaani-project/xz/security/advisories/GHSA-6cc8-p5mm-29w2
[2] https://tukaani.org/xz/xz-cve-2025-31115.patch

Signed-off-by: Julien Olivain <ju.o@free.fr>
Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
2025-05-14 14:44:37 +02:00
Kadambini Nema
0a645c7592 package/protobuf-c: bump to version 1.5.2
Release notes:
https://github.com/protobuf-c/protobuf-c/releases/tag/v1.5.2

Signed-off-by: Kadambini Nema <kadambini.nema@gmail.com>
Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
2025-05-14 07:19:46 +02:00
Marcus Hoffmann
8701d138ed package/python-uvicorn: bump to version 0.34.2
Signed-off-by: Marcus Hoffmann <buildroot@bubu1.eu>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2025-05-13 23:01:10 +02:00
Bernd Kuhls
b3388c2556 package/intel-microcode: security bump version to 20250512
Release notes:
https://github.com/intel/Intel-Linux-Processor-Microcode-Data-Files/releases/tag/microcode-20250512

CVE-2025-24495:
https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01322.html

CVE-2024-28956:
https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01153.html

CVE-2024-43420:
https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01247.html

CVE-2025-20103:
https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01244.html

"Note: INTEL-SA-01244 and INTEL-SA-01247 will be published on May 13th 2025"

Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2025-05-13 22:40:57 +02:00
Bernd Kuhls
140f8fc628 package/dhcp: fix build with gcc-15.x
Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2025-05-13 22:37:30 +02:00
Bernd Kuhls
778da2b719 package/dbus-glib: bump version to 0.114
For change log, see [1].

A notable change is that this release fixes GCC 15 build issues
and some deprecation warnings.

Updated license files and hashes due to upstream commit [2].
There is not an actual license change.

[1] https://gitlab.freedesktop.org/dbus/dbus-glib/-/blob/dbus-glib-0.114/NEWS
[2] ad08ba0c6b

Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Florian Larysch <fl@n621.de>
Tested-by: Florian Larysch <fl@n621.de>
[Julien: add extra info in the commit log]
Signed-off-by: Julien Olivain <ju.o@free.fr>
2025-05-13 22:31:05 +02:00
Bernd Kuhls
999fb19d4b package/unixodbc: fix build with gcc-15.x
Inspired by
https://gitweb.gentoo.org/repo/gentoo.git/commit/dev-db/unixODBC?id=b5629b3aefd8633d378beea7e955d66ce709bebe

Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2025-05-13 22:09:52 +02:00
Bernd Kuhls
4dfe97dde4 package/libsndfile: Add upstream commits to fix build with gcc-15.x
Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2025-05-13 22:01:50 +02:00
Bernd Kuhls
467aa8cd56 package/netcat-openbsd: bump version to 1.229
Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2025-05-13 21:29:28 +02:00
Bernd Kuhls
c1d422edde package/berkeleydb: fix build with gcc-15.x
Inspired by
c250c61cc3

"GCC 15 defaults to C23.  The last release of this package was over a
 decade ago, and it is no longer maintained, therefore it should not be
 expected to compile to the latest standards."

Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2025-05-13 21:19:00 +02:00
Giulio Benetti
5ae5c0ef41 package/harfbuzz: bump to version 11.2.1
Release Notes:
https://github.com/harfbuzz/harfbuzz/releases/tag/11.2.1

Signed-off-by: Giulio Benetti <giulio.benetti@benettiengineering.com>
Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
2025-05-13 19:02:22 +02:00
Julien Olivain
7cb93a3804 package/connman: update homepage url
The old connman homepage url [1] now redirects to an Intel open source
software portal which no longer contains the connman project.

The project is now hosted at [2]. For reference, the upstream
commit [3] removed references to [1].

This commit updates the Config.in homepage url to [2].

[1] https://01.org/connman
[2] https://git.kernel.org/pub/scm/network/connman/connman.git
[3] https://git.kernel.org/pub/scm/network/connman/connman.git/commit/?id=7d35eba0b93580c7dae5763b517ea5571dc4a273

Signed-off-by: Julien Olivain <ju.o@free.fr>
Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
2025-05-13 18:56:24 +02:00
Dario Binacchi
a8cfe9986c package/connman: fix CVE-2025-32366
In ConnMan through 1.44, parse_rr in dnsproxy.c has a memcpy length
that depends on an RR RDLENGTH value (i.e., *rdlen=ntohs(rr->rdlen)
and memcpy(response+offset,*end,*rdlen)). Here, rdlen may be larger
than the amount of remaining packet data in the current state of
parsing. As a result, values of stack memory locations may be sent
over the network in a response.

Fixes:
https://www.cve.org/CVERecord?id=CVE-2025-32366

Signed-off-by: Dario Binacchi <dario.binacchi@amarulasolutions.com>
Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
2025-05-13 18:49:31 +02:00
Kadambini Nema
915a351e2f package/dropbear: security bump to version 2025.88
Fixes CVE-2025-47203.
https://security-tracker.debian.org/tracker/CVE-2025-47203

Release notes:
https://github.com/mkj/dropbear/releases/tag/DROPBEAR_2025.88

Signed-off-by: Kadambini Nema <kadambini.nema@gmail.com>
Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
2025-05-13 11:39:24 +02:00
Bernd Kuhls
05fb4526f9 package/dropbear: bump version to 2025.87
Changelog: https://matt.ucc.asn.au/dropbear/CHANGES

Upstream disabled sha1 by default:
f3465a34eb

Add the options to DROPBEAR_ENABLE_LEGACY_CRYPTO hook.

Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Reviewed-by: Baruch Siach <baruch@tkos.co.il>
Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
2025-05-13 11:36:22 +02:00
Dario Binacchi
a7ea1e658d board/bsh/imx6ulz-bsh-smm-m2: flash U-Boot
Fix the board flashing by adding the bootloader, which I had mistakenly
forgotten to include in the script.

Fixes: 322e8d8451 ("configs/imx6ulz_bsh_smm_m2_defconfig: new defconfig")
Signed-off-by: Dario Binacchi <dario.binacchi@amarulasolutions.com>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2025-05-12 23:00:50 +02:00
Dario Binacchi
d64ae92968 configs/imx6ulz_bsh_smm_m2: bump Linux to 6.12.28
The patch bumps the Linux kernel to version 6.12.28

Signed-off-by: Dario Binacchi <dario.binacchi@amarulasolutions.com>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2025-05-12 23:00:47 +02:00
Dario Binacchi
6c4da559cc package/connman: fix CVE-2025-32743
In ConnMan through 1.44, the lookup string in ns_resolv in dnsproxy.c
can be NULL or an empty string when the TC (Truncated) bit is set in
a DNS response. This allows attackers to cause a denial of service
(application crash) or possibly execute arbitrary code, because those
lookup values lead to incorrect length calculations and incorrect
memcpy operations.

Fixes:
https://www.cve.org/CVERecord?id=CVE-2025-32743

Signed-off-by: Dario Binacchi <dario.binacchi@amarulasolutions.com>
[Julien: add link to cve]
Signed-off-by: Julien Olivain <ju.o@free.fr>
2025-05-12 22:36:26 +02:00
Dario Binacchi
ce9a64b5d1 package/connman: bump to version 1.44
Release notes:

- ver 1.44:
  * Fix issue with handling oFono context integration.
  * Fix issue with handling web context for online detection.
  * Fix issue with handling flags used when deleting routes.
  * Fix issue with handling PAC proxy integration.

- ver 1.43:
  * Fix issue with device creation when using LTE.
  * Fix issue with regulatory domain when powering up.
  * Fix issue with resolving ISO3166 code from timezone data.
  * Fix issue with handling DNS proxy zero termination of buffers.
  * Fix issue with handling DHCP packet length in L3 mode.
  * Fix issue with handling DHCP upper length checks.
  * Fix issue with handling IPv6 and URL parsing.
  * Fix issue with handling online check updates.
  * Fix issue with handling proxy method and WISPr.
  * Fix issue with handling default gateway setup.
  * Add support for low-priority default routes.

Signed-off-by: Dario Binacchi <dario.binacchi@amarulasolutions.com>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2025-05-12 22:31:41 +02:00
Marcus Hoffmann
96ae6c41e7 package/python-click: bump to 8.2.0
Update package help text to reflect upstream project description.

Signed-off-by: Marcus Hoffmann <buildroot@bubu1.eu>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2025-05-12 22:10:43 +02:00