Thomas Petazzoni
bd05f6bd1f
package/gdb: allow selecting upstream releases on ARC
...
package/binutils and package/gcc both allow to use upstream versions
on ARC, but package/gdb allows using only the ARC version. Adjust the
packaging to align package/gdb with package/binutils and package/gcc,
so that upstream versions of gdb can be built for ARC.
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com >
Signed-off-by: Julien Olivain <ju.o@free.fr >
2025-08-07 23:00:41 +02:00
Peter Korsgaard
84a3a8f39a
package/libgpiod2: bump version to 2.2.2
...
Bugfix release. From NEWS:
- don't implicitly unquote unnamed lines in gpioinfo
- remove useless variable in reconfigure example
- don't let struct line_config balloon out of control and trigger an OOM
- drop python3-config check from configure.ac
https://git.kernel.org/pub/scm/libs/libgpiod/libgpiod.git/commit/?id=759d831aa8846a5d007cac250f78d74a514e1ec9
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
Acked-by: Boerge Struempfel <boerge.struempfel@gmail.com >
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2025-08-07 16:02:54 +02:00
Fabien Lehoussel
4b15707056
utils/generate-cyclonedx: sort dependencies
...
The SBOM is easier to read if the dependencies are sorted alphabetically.
Signed-off-by: Fabien Lehoussel <fabien.lehoussel@smile.fr >
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2025-08-07 16:02:03 +02:00
Dario Binacchi
1c7948af33
package/uuu: bump to version 1.5.219
...
Release notes:
https://github.com/nxp-imx/mfgtools/releases/tag/uuu_1.5.218
https://github.com/nxp-imx/mfgtools/releases/tag/uuu_1.5.219
This commit also removes the package patch included in this
new release.
Signed-off-by: Dario Binacchi <dario.binacchi@amarulasolutions.com >
[Julien: remove the package patch included in this new release]
Signed-off-by: Julien Olivain <ju.o@free.fr >
2025-08-07 03:02:51 +02:00
Angelo Compagnucci
945f4acbff
package/htpdate: bump to version 2.0.0
...
Changelog:
https://github.com/twekkel/htpdate/releases/tag/v2.0.0
LICENSE file hash changed because of the copyright year update.
Signed-off-by: Angelo Compagnucci <angelo.compagnucci@gmail.com >
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2025-08-06 21:59:19 +02:00
Thomas Perale
a008f3e7cb
package/flatcc: add CPE identifier
...
The cpe:2.3:a:flatcc_project:flatcc:*:*:*:*:*:*:*:*
valid for this package.
See https://nvd.nist.gov/products/cpe/detail/AA7FC7B6-537C-4735-B615-689D3A91C994
Signed-off-by: Thomas Perale <thomas.perale@mind.be >
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2025-08-06 21:51:26 +02:00
Fabien Lehoussel
9cbbc47762
utils/generate-cyclonedx: add project name and version options
...
Add options to customize the project name and version in the generated SBOM
metadata and set buildroot generate-cyclonedx as a tool in the metadata
section.
Signed-off-by: Fabien Lehoussel <fabien.lehoussel@smile.fr >
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2025-08-06 16:56:12 +02:00
Fabien Lehoussel
6098cc45d6
utils/generate-cyclonedx: move metadata section to top level
...
This makes it more readable and easier to quickly identify basic information.
Signed-off-by: Fabien Lehoussel <fabien.lehoussel@smile.fr >
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2025-08-06 16:38:26 +02:00
Aaron Sierra
2982fac48e
package/xinetd: fix build with musl
...
The ecvt(), fcvt(), and gcvt() functions from stdlib.h, used by the SIO
library packaged with the xinetd sources, are masked by _GNU_SOURCE in
musl libc.
Signed-off-by: Aaron Sierra <aaron@bubbl-tek.com >
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2025-08-06 15:18:54 +02:00
Julien Olivain
1375aabf74
package/fwts: bump to version 25.07.00
...
See release announce:
https://lists.ubuntu.com/archives/fwts-devel/2025-July/014057.html
Signed-off-by: Julien Olivain <ju.o@free.fr >
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2025-08-06 14:58:11 +02:00
Thomas Perale
7407f797a6
package/apache: update mirror url
...
While the 2.4.65 release of this package is available on
https://dlcdn.apache.org/httpd older version are removed from this
location in favour of https://archive.apache.org/dist/httpd .
In 2025.02.x branch the apache package hasn't been bumped to the latest
version yet so the following error started appearing on the autobuilder:
```
>>> apache 2.4.64 Downloading
wget -nd -t 3 --no-check-certificate -O '/workdir/instance-0/output-1/build/.httpd-2.4.64.tar.bz2.hfXgDB/output' 'https://dlcdn.apache.org/httpd/httpd-2.4.64.tar.bz2 '
WARNING: The certificate is NOT trusted. The certificate issuer is unknown.
[0] Downloading 'https://dlcdn.apache.org/httpd/httpd-2.4.64.tar.bz2 ' ...
HTTP ERROR response 404 [https://dlcdn.apache.org/httpd/httpd-2.4.64.tar.bz2 ]
make: *** [package/pkg-generic.mk:179: /workdir/instance-0/output-1/build/apache-2.4.64/.stamp_downloaded] Error 1
make: Leaving directory '/workdir/instance-0/buildroot'
```
To avoid running in the same error once the next package version is
released this patch update the site to the archive mirror with all the
releases.
Fixes: https://autobuild.buildroot.org/results/7a0/7a0982bcf9db4dcbcf4f6cf31b9f19571c061ee4/build-end.log
Signed-off-by: Thomas Perale <thomas.perale@mind.be >
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2025-08-06 14:57:07 +02:00
Thomas Perale
8083972a90
package/libssh: security bump to v0.11.2
...
For more information on the release see:
- https://git.libssh.org/projects/libssh.git/tag/?h=libssh-0.11.2
This fixes the following vulnerabilities:
- CVE-2025-4878
A vulnerability was found in libssh, where an uninitialized variable
exists under certain conditions in the privatekey_from_file()
function. This flaw can be triggered if the file specified by the
filename doesn't exist and may lead to possible signing failures or
heap corruption.
For more information, see:
- https://www.cve.org/CVERecord?id=CVE-2025-4878
- https://git.libssh.org/projects/libssh.git/commit/?id=697650caa97eaf7623924c75f9fcfec6dd423cd1
- https://git.libssh.org/projects/libssh.git/commit/?id=b35ee876adc92a208d47194772e99f9c71e0bedb
- CVE-2025-5318
A flaw was found in the libssh library. An out-of-bounds read can be
triggered in the sftp_handle function due to an incorrect comparison
check that permits the function to access memory beyond the valid
handle list and to return an invalid pointer, which is used in further
processing. This vulnerability allows an authenticated remote attacker
to potentially read unintended memory regions, exposing sensitive
information or affect service behavior.
For more information, see:
- https://www.cve.org/CVERecord?id=CVE-2025-5318
- https://www.libssh.org/security/advisories/CVE-2025-5318.txt
- CVE-2025-5351
A flaw was found in the key export functionality of libssh. The issue
occurs in the internal function responsible for converting
cryptographic keys into serialized formats. During error handling, a
memory structure is freed but not cleared, leading to a potential
double free issue if an additional failure occurs later in the
function. This condition may result in heap corruption or application
instability in low-memory scenarios, posing a risk to system
reliability where key export operations are performed.
For more information, see:
- https://www.cve.org/CVERecord?id=CVE-2025-5351
- CVE-2025-5372
A flaw was found in libssh versions built with OpenSSL versions older
than 3.0, specifically in the ssh_kdf() function responsible for key
derivation. Due to inconsistent interpretation of return values where
OpenSSL uses 0 to indicate failure and libssh uses 0 for success—the
function may mistakenly return a success status even when key
derivation fails. This results in uninitialized cryptographic key
buffers being used in subsequent communication, potentially
compromising SSH sessions' confidentiality, integrity, and
availability.
For more information, see:
- https://www.cve.org/CVERecord?id=CVE-2025-5372
- CVE-2025-5449
A flaw was found in the SFTP server message decoding logic of libssh.
The issue occurs due to an incorrect packet length check that allows
an integer overflow when handling large payload sizes on 32-bit
systems. This issue leads to failed memory allocation and causes the
server process to crash, resulting in a denial of service.
For more information, see:
- https://www.cve.org/CVERecord?id=CVE-2025-5449
- https://git.libssh.org/projects/libssh.git/commit/?h=stable-0.11&id=261612179f740bc62ba363d98b3bd5e5573a811f
- https://git.libssh.org/projects/libssh.git/commit/?h=stable-0.11&id=3443aec90188d6aab9282afc80a81df5ab72c4da
- https://git.libssh.org/projects/libssh.git/commit/?h=stable-0.11&id=5504ff40515439a5fecbb17da7483000c4d12eb7
- https://git.libssh.org/projects/libssh.git/commit/?h=stable-0.11&id=78485f446af9b30e37eb8f177b81940710d54496
- https://git.libssh.org/projects/libssh.git/commit/?h=stable-0.11&id=f79ec51b7fd519dbc5737a7ba826e3ed093f6ceb
- https://www.libssh.org/security/advisories/CVE-2025-5449.txt
- CVE-2025-5987
A flaw was found in libssh when using the ChaCha20 cipher with the
OpenSSL library. If an attacker manages to exhaust the heap space,
this error is not detected and may lead to libssh using a partially
initialized cipher context. This occurs because the OpenSSL error code
returned aliases with the SSH_OK code, resulting in libssh not
properly detecting the error returned by the OpenSSL library. This
issue can lead to undefined behavior, including compromised data
confidentiality and integrity or crashes.
For more information, see:
- https://www.cve.org/CVERecord?id=CVE-2025-5987
The patch 0001 is removed as it's now included upstream see [1].
[1] 093431f929
Signed-off-by: Thomas Perale <thomas.perale@mind.be >
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2025-08-06 14:54:36 +02:00
Bernd Kuhls
2fd520c8d5
package/glm: bump version to 1.0.1
...
Release notes: https://github.com/g-truc/glm/releases/tag/1.0.1
Signed-off-by: Bernd Kuhls <bernd@kuhls.net >
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2025-08-04 22:11:23 +02:00
Bernd Kuhls
2e4be3a5be
package/libmspack: bump version to 0.11alpha
...
Signed-off-by: Bernd Kuhls <bernd@kuhls.net >
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2025-08-04 22:10:37 +02:00
Bernd Kuhls
fd38935177
package/libdeflate: bump version to 1.24
...
Release notes:
https://github.com/ebiggers/libdeflate/blob/v1.24/NEWS.md
Switch _SITE to tarball provided by upstream.
Signed-off-by: Bernd Kuhls <bernd@kuhls.net >
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2025-08-04 22:08:40 +02:00
Bernd Kuhls
6b607a7744
package/libinput: bump version to 1.29.0
...
Release notes:
https://lists.freedesktop.org/archives/wayland-devel/2025-March/044026.html
https://lists.freedesktop.org/archives/wayland-devel/2025-April/044102.html
https://lore.freedesktop.org/wayland-devel/20250731092534.GA4100432@quokka/T/
Upstream changed mtdev into an optional dependency:
27f4b0ae74
Signed-off-by: Bernd Kuhls <bernd@kuhls.net >
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2025-08-04 22:02:10 +02:00
Bernd Kuhls
178cc76deb
package/meson: bump version to 1.8.3
...
Signed-off-by: Bernd Kuhls <bernd@kuhls.net >
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2025-08-04 22:01:54 +02:00
Bernd Kuhls
a2f53620e6
package/intel-vpl-gpu-rt: bump version to 25.3.1
...
Signed-off-by: Bernd Kuhls <bernd@kuhls.net >
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2025-08-04 21:40:01 +02:00
Bernd Kuhls
f3b09a3fa1
package/intel-mediadriver: bump version to 25.3.1
...
Signed-off-by: Bernd Kuhls <bernd@kuhls.net >
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2025-08-04 21:39:34 +02:00
Bernd Kuhls
41ed03172a
package/mtdev: bump version to 1.1.7
...
Signed-off-by: Bernd Kuhls <bernd@kuhls.net >
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2025-08-04 21:39:24 +02:00
Angelo Compagnucci
2c9e2e06e2
package/sshguard: bump to version 2.5.1
...
Changelog:
https://bitbucket.org/sshguard/sshguard/src/master/CHANGELOG.rst
Signed-off-by: Angelo Compagnucci <angelo.compagnucci@gmail.com >
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2025-08-04 21:37:59 +02:00
Angelo Compagnucci
d149e60033
package/python-pillow: security bump to version 11.3.0
...
Changelog:
https://pillow.readthedocs.io/en/stable/releasenotes/11.3.0.html
Fixes the following security issues:
CVE 2025-48379
Signed-off-by: Angelo Compagnucci <angelo.compagnucci@gmail.com >
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2025-08-04 21:33:28 +02:00
Florian Larysch
e6e930be67
package/pipewire: bump version to 1.2.8
...
Bugfix release for the 1.2.x series.
Release notes:
91a1ce183f/NEWS
Signed-off-by: Florian Larysch <fl@n621.de >
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2025-08-04 19:05:13 +02:00
Peter Seiderer
0343f03ce4
package/iwd: fix S40iwd check-package warnings
...
Fix fix S40iwd check-package warnings:
- package/iwd/S40iwd:3: Do not include path in DAEMON
(https://nightly.buildroot.org/#adding-packages-start-script )
- package/iwd/S40iwd:4: Incorrect PIDFILE value
(https://nightly.buildroot.org/#adding-packages-start-script )
Since this commit fixes lib_sysv.Variables check-package warnings
in S40iwd, this commit also removes the .checkpackageignore entry.
Signed-off-by: Peter Seiderer <ps.report@gmx.net >
[Julien: remove lib_sysv.Variables in .checkpackageignore]
Signed-off-by: Julien Olivain <ju.o@free.fr >
2025-08-03 17:44:00 +02:00
Peter Seiderer
a3569f03fc
package/iwd: bump version to 3.9
...
Changelog (see [1]):
ver 3.9:
Fix issue with Access Point mode and frequency unlocking.
Fix issue with network configuration and BSS retry logic.
Fix issue with handling busy notification from Access Point.
Fix issue with handling P-192, P-224 and P-521 for SAE.
ver 3.8:
Fix issue with handling unit tests and missing kernel features.
ver 3.7:
Fix issue with handling length of EncryptedSecurity.
Fix issue with handling empty affinities lists.
Fix issue with handling survey scanning results.
Fix issue with handling duplicate values in DPP URI.
ver 3.6:
Fix issue with handling blacklisting and roaming requests.
Fix issue with handling CQM thresholds for FullMAC devices.
Add support for PMKSA when using FullMAC devices.
ver 3.5:
Add support for option to disable blacklist handling.
Add support for option to disable SAE for broken drivers.
ver 3.4:
Add support for the Test Anything Protocol.
ver 3.3:
Fix issue with handling External Authentication.
ver 3.2:
Fix issue with GCC 15 and -std=c23 build errors.
Add support for using PMKSA over SAE if available.
Add support for HighUtilization/StationCount thresholds.
Add support for disabling Multicast RX option.
ver 3.1:
Fix issue with handling OWE transition BSS selection.
Fix issue with handling oper class 136 starting frequency.
[1] https://git.kernel.org/pub/scm/network/wireless/iwd.git/tree/ChangeLog?h=3.9
Signed-off-by: Peter Seiderer <ps.report@gmx.net >
Signed-off-by: Julien Olivain <ju.o@free.fr >
2025-08-03 17:40:04 +02:00
Peter Seiderer
e834d23cd7
package/ell: bump version to 0.79
...
Changelog (see [1]):
ver 0.79:
Fix issue with D-Bus client and watch removal handling.
Fix issue with D-Bus client and service name handling.
Fix issue with D-Bus proxy and filter rule handling.
ver 0.78:
Fix issue with random ECC scalar generation.
ver 0.77:
Add support for precheck feature for unit tests.
Add support for license variable for pkg-config.
ver 0.76:
Fix issue with random scalar generation.
ver 0.75:
Add support for converting OID octets to strings.
Add support for NIST P-224 cuve usage with ECDH.
Add support for NIST P-521 cuve usage with ECDH.
Add support for SHA-3 series of hashing algorithms.
ver 0.74:
Add support for NIST P-192 curve usage with ECDH.
Add support for SHA-224 based checksums and HMACs.
ver 0.73:
Fix issue with parsing hwdb.bin child structures.
ver 0.72:
Add support for the Test Anything Protocol.
ver 0.71:
Fix issue with GCC 15 and -std=c23 build errors.
ver 0.70:
Add support for helper function for safe memcpy.
[1] https://git.kernel.org/pub/scm/libs/ell/ell.git/tree/ChangeLog?h=0.79
Signed-off-by: Peter Seiderer <ps.report@gmx.net >
Signed-off-by: Julien Olivain <ju.o@free.fr >
2025-08-03 17:40:00 +02:00
Thomas Perale
014174f00d
package/sqlite: ignore CVE-2025-3277
...
The CVE-2025-3277 as been marked as a duplicate of CVE-2025-29087 by the
debian security tracker [1].
The CVE-2025-29087 has already been fixed in commit [2] so this patch
adds CVE-2025-3277 to the ignored CVEs.
[1] https://security-tracker.debian.org/tracker/CVE-2025-3277
[2] 835b5659ea package/sqlite: add patch to fix CVE-2025-29087
Signed-off-by: Thomas Perale <thomas.perale@mind.be >
Signed-off-by: Julien Olivain <ju.o@free.fr >
2025-08-03 17:35:01 +02:00
Bernd Kuhls
d6d1beddbc
package/libcec: bump version to 7.1.1
...
Changelog:
https://github.com/Pulse-Eight/libcec/blob/libcec-7.1.1/debian/changelog.in
Signed-off-by: Bernd Kuhls <bernd@kuhls.net >
Signed-off-by: Julien Olivain <ju.o@free.fr >
2025-08-03 17:29:18 +02:00
Bernd Kuhls
51b27bad91
{linux, linux-headers}: bump 6.{6, 12, 15}.x series
...
Signed-off-by: Bernd Kuhls <bernd@kuhls.net >
Signed-off-by: Julien Olivain <ju.o@free.fr >
2025-08-03 17:25:56 +02:00
Thomas Perale
4089677c2d
package/php: bump to v8.3.24
...
This is a bug fix release.
For more information, see:
- https://www.php.net/ChangeLog-8.php#PHP_8_3
- https://news-web.php.net/php.announce/466
Signed-off-by: Thomas Perale <thomas.perale@mind.be >
Signed-off-by: Julien Olivain <ju.o@free.fr >
2025-08-03 17:06:10 +02:00
Thomas Bonnefille
a01c07f572
package/libspdm: bump version to 3.8.0
...
For change log since 3.5.0, see:
https://github.com/DMTF/libspdm/releases
Following the upgrade of libopenssl to version 3.5.0 [1], the build
process for libspdm encountered issues due to the new openssl API.
It requires some modifications in the asn1.h file of libspdm.
This build error was addressed by a specific commit [2] in libspdm.
As Buildroot 2025.02 isn't impacted, this commit bumps libspdm to the
latest libspdm version to fix the build error.
This commit also updates the license hash, after a year update in:
e8a35c8d0d
[1]: 9868ca6ec9
[2]: 88797f83da
Fixes:
https://autobuild.buildroot.org/results/87b8805975ef132a58c40e622e2e023199f6ee2a/
Signed-off-by: Thomas Bonnefille <thomas.bonnefille@bootlin.com >
[Julien:
- add link to change log
- fix LICENSE.md hash
]
Signed-off-by: Julien Olivain <ju.o@free.fr >
2025-08-03 17:01:06 +02:00
Bernd Kuhls
64de9e5142
package/{mesa3d, mesa3d-headers}: bump version to 25.1.7
...
Release notes:
https://lists.freedesktop.org/archives/mesa-announce/2025-July/000814.html
Signed-off-by: Bernd Kuhls <bernd@kuhls.net >
Signed-off-by: Julien Olivain <ju.o@free.fr >
2025-08-03 16:51:42 +02:00
Thomas Perale
c68a14d73a
package/libxml2: add patch for CVE-2025-6170
...
This fixes the following vulnerability:
- CVE-2025-6170
A flaw was found in the interactive shell of the xmllint command-line
tool, used for parsing XML files. When a user inputs an overly long
command, the program does not check the input size properly, which can
cause it to crash. This issue might allow attackers to run harmful
code in rare configurations without modern protections.
For more information, see:
- https://www.cve.org/CVERecord?id=CVE-2025-6170
- c340e41950
Signed-off-by: Thomas Perale <thomas.perale@mind.be >
Signed-off-by: Julien Olivain <ju.o@free.fr >
2025-08-03 16:46:31 +02:00
Colin Foster
a28756bdee
package/rauc-hawkbit-updater: bump to version 1.4
...
For change log, see:
https://github.com/rauc/rauc-hawkbit-updater/releases/tag/v1.4
Signed-off-by: Colin Foster <colin.foster@in-advantage.com >
[Julien: add link to change log]
Signed-off-by: Julien Olivain <ju.o@free.fr >
2025-08-03 16:29:49 +02:00
Bernd Kuhls
f5101638b9
boot/syslinux: fix build with gcc-15.x
...
Fixes build error with gcc-15.x:
drivers/net/3c509-eisa.c:39:26: error: initialization of 'void (*)(void)'
from incompatible pointer type 'void (*)(struct nic *, struct eisa_device *)'
[-Wincompatible-pointer-types]
For a similar fix see https://bugzilla.suse.com/show_bug.cgi?id=1243225
Signed-off-by: Bernd Kuhls <bernd@kuhls.net >
Signed-off-by: Julien Olivain <ju.o@free.fr >
2025-07-31 16:04:45 +02:00
Thomas Petazzoni
2fbf98da7c
package/gcc: drop stale 13.3.0 patches
...
Commit 0b8b72d2fe bumped gcc 13.x from
13.3.0 to 13.4.0 but forgot to drop the gcc 13.3.0, so let's remove
those patches.
Cc: Kadambini Nema <kadambini.nema@gmail.com >
Fixes: 0b8b72d2fe
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com >
Signed-off-by: Julien Olivain <ju.o@free.fr >
2025-07-31 15:00:13 +02:00
Fabien Lehoussel
b2801c7bce
package/gcc/gcc-final: fix CPE identification
...
Fix the CPE (Common Platform Enumeration) identification in the
gcc-final package to ensure proper vulnerability tracking through the
NVD database:
https://nvd.nist.gov/products/cpe/search/results?keyword=cpe:2.3:a:gnu:gcc
Signed-off-by: Fabien Lehoussel <fabien.lehoussel@smile.fr >
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com >
2025-07-30 22:44:29 +02:00
Adrian Perez de Castro
2882cf4ae6
package/wpewebkit: security bump to version 2.48.3
...
This bumps WPE WebKit to the 2.48 stable series, skipping over 2.46.
WPE WebKit 2.48 and 2.46 highlights:
- https://wpewebkit.org/blog/2025-04-11-wpewebkit-2.48.html
- https://wpewebkit.org/blog/2024-wpewebkit-2.46.html
Release notes:
- https://wpewebkit.org/release/wpewebkit-2.48.3.html
- https://wpewebkit.org/release/wpewebkit-2.48.2.html
- https://wpewebkit.org/release/wpewebkit-2.48.1.html
- https://wpewebkit.org/release/wpewebkit-2.48.0.html
- https://wpewebkit.org/release/wpewebkit-2.46.7.html
- https://wpewebkit.org/release/wpewebkit-2.46.6.html
- https://wpewebkit.org/release/wpewebkit-2.46.5.html
- https://wpewebkit.org/release/wpewebkit-2.46.4.html
- https://wpewebkit.org/release/wpewebkit-2.46.3.html
- https://wpewebkit.org/release/wpewebkit-2.46.2.html
- https://wpewebkit.org/release/wpewebkit-2.46.1.html
- https://wpewebkit.org/release/wpewebkit-2.46.0.html
Fixes the following security issues:
- From https://wpewebkit.org/security/WSA-2025-0004.html
CVE-2025-24223, CVE-2025-31204, CVE-2025-31205, CVE-2025-31206,
CVE-2025-31215, CVE-2025-31257
- From https://wpewebkit.org/security/WSA-2025-0003.html
CVE-2024-54551, CVE-2025-24208, CVE-2025-24209, CVE-2025-24213,
CVE-2025-24216, CVE-2025-24264, CVE-2025-30427
- From https://wpewebkit.org/security/WSA-2025-0002.html
CVE-2024-44192, CVE-2024-54467, CVE-2025-24201
- From https://wpewebkit.org/security/WSA-2025-0001.html
CVE-2024-27856, CVE-2024-54543, CVE-2024-54658, CVE-2025-24143,
CVE-2025-24150, CVE-2025-24158, CVE-2025-24162
- From https://wpewebkit.org/security/WSA-2024-0008.html
CVE-2024-54479, CVE-2024-54502, CVE-2024-54505, CVE-2024-54508,
CVE-2024-54534
- From https://wpewebkit.org/security/WSA-2024-0007.html
CVE-2024-44308, CVE-2024-44309
- From https://wpewebkit.org/security/WSA-2024-0006.html
CVE-2024-44185, CVE-2024-44244, CVE-2024-44296
- From https://wpewebkit.org/security/WSA-2024-0005.html
CVE-2024-40866, CVE-2024-44187
As for build system changes, the minimum GCC requirement gets raised to
version 11 [1], the ENABLE_SPEECH_SYNTHESIS option is now enabled by
default [2] and needs handling, and Skia (bundled with the sources) is
now preferred on little-endian targets.
[1] 682ac4ba74
[2] 10381a8de9
Signed-off-by: Adrian Perez de Castro <aperez@igalia.com >
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com >
2025-07-30 22:07:23 +02:00
El Mehdi YOUNES
56adc0dacd
package/opencl-{clhpp,headers,icd-loader}: bump version to v2025.07.22
...
Synchronizes with OpenCL v3.0.19 specification release.
Releases:
https://github.com/KhronosGroup/OpenCL-Headers/releases/tag/v2025.07.22
https://github.com/KhronosGroup/OpenCL-ICD-Loader/releases/tag/v2025.07.22
https://github.com/KhronosGroup/OpenCL-CLHPP/releases/tag/v2025.07.22
Signed-off-by: El Mehdi YOUNES <elmehdi.younes@smile.fr >
[Julien: factorize package names in commit log title]
Signed-off-by: Julien Olivain <ju.o@free.fr >
2025-07-30 14:48:58 +02:00
Nathaniel Roach
6044cc5f26
package/sudo: Enable libxcrypt with glibc, allowing hashed passwords without PAM
...
Per https://gitlab.com/buildroot.org/buildroot/-/issues/27 , on glibc
builds without PAM, sudo will "fail" all password prompts.
It was found that it's simply checking the entered string against the
raw hash, because 'libcryp' isn't available. On glibc, we need libxcrypt,
so enable it and ensure sudo is built with it.
musl and uclibc do have crypt() functions, so this is not needed.
Relevant code from sudo:
https://github.com/sudo-project/sudo/blob/v1.9.17p1/plugins/sudoers/auth/passwd.c#L139
Signed-off-by: Nathaniel Roach <nroach44@nroach44.id.au >
Signed-off-by: Julien Olivain <ju.o@free.fr >
2025-07-30 03:07:41 +02:00
Petr Vorel
97cc946e2f
package/ltp-testsuite: Fix uclibc-ng build
...
Backport upstream fix.
Fixes:
https://autobuild.buildroot.org/results/f3e/f3e03b9a1a69988d6497f36c9d64a37a66e9ad20/
https://autobuild.buildroot.org/results/856/856365f467efc449faee1951250e63d8d4442bbc/
https://autobuild.buildroot.org/results/2ac/2ac08cecd6a505f1bac1a673efc280b3a8dcb23a/
https://autobuild.buildroot.org/results/59b/59b3ad33667b7e87c81e49dd434d5f494e189e0d/
https://autobuild.buildroot.org/results/b1a/b1a36f9971c97300670d8d772ace11e5fedceaaa/
Signed-off-by: Petr Vorel <petr.vorel@gmail.com >
Tested-By: Waldemar Brodkorb <wbx@openadk.org >
Signed-off-by: Julien Olivain <ju.o@free.fr >
2025-07-30 02:55:25 +02:00
Titouan Christophe
0c2769b9c3
package/rust: add CPE_ID_VENDOR
...
This gives a proper cpe-id string to the Rust buildroot package,
as it can be found in the NVD database:
https://nvd.nist.gov/products/cpe/search/results?keyword=cpe:2.3:a:rust-lang:rust
Signed-off-by: Titouan Christophe <titouan.christophe@mind.be >
Reviewed-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com >
Signed-off-by: Julien Olivain <ju.o@free.fr >
2025-07-30 01:39:45 +02:00
Stefan Nickl
f103e3696f
package/modem-manager: Add option to enable AT commands via D-Bus
...
Signed-off-by: Stefan Nickl <Stefan.Nickl@gmail.com >
Reviewed-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com >
Signed-off-by: Julien Olivain <ju.o@free.fr >
2025-07-30 01:33:53 +02:00
Dario Binacchi
9440bf5a62
package/armadillo: bump to version 14.6.1
...
Release notes:
https://arma.sourceforge.net/docs.html#changelog
Signed-off-by: Dario Binacchi <dario.binacchi@amarulasolutions.com >
Signed-off-by: Julien Olivain <ju.o@free.fr >
2025-07-30 01:29:59 +02:00
Dario Binacchi
b9a14eaff1
package/inih: bump to version 61
...
Release notes:
https://github.com/benhoyt/inih/releases/tag/r61
Signed-off-by: Dario Binacchi <dario.binacchi@amarulasolutions.com >
Signed-off-by: Julien Olivain <ju.o@free.fr >
2025-07-30 01:24:18 +02:00
Bernd Kuhls
0461043a51
linux: bump latest version to 6.16
...
Signed-off-by: Bernd Kuhls <bernd@kuhls.net >
Signed-off-by: Julien Olivain <ju.o@free.fr >
2025-07-29 01:20:41 +02:00
Bernd Kuhls
d9a1352e7d
{toolchain, linux-headers}: add support for 6.16 headers
...
And add (and default to) 6.16 to linux-headers.
Signed-off-by: Bernd Kuhls <bernd@kuhls.net >
Signed-off-by: Julien Olivain <ju.o@free.fr >
2025-07-29 01:20:38 +02:00
Giulio Benetti
d08c30697b
package/libnvme: bump to version 1.15
...
For release note, see:
https://github.com/linux-nvme/libnvme/releases/tag/v1.15
Signed-off-by: Giulio Benetti <giulio.benetti@benettiengineering.com >
Signed-off-by: Julien Olivain <ju.o@free.fr >
2025-07-29 01:17:55 +02:00
Giulio Benetti
034cd35fb4
package/harfbuzz: bump to version 11.3.3
...
Release Notes:
https://github.com/harfbuzz/harfbuzz/releases/tag/11.3.3
Signed-off-by: Giulio Benetti <giulio.benetti@benettiengineering.com >
Signed-off-by: Julien Olivain <ju.o@free.fr >
2025-07-29 01:13:37 +02:00
Thomas Perale
1fc0e90450
package/micropython: add patch for CVE-2024-8947
...
This fixes the following vulnerability:
- CVE-2024-8947
A vulnerability was found in MicroPython 1.22.2. It has been declared
as critical. Affected by this vulnerability is an unknown functionality
of the file py/objarray.c. The manipulation leads to use after free.
The attack can be launched remotely. The complexity of an attack is
rather high. The exploitation appears to be difficult. Upgrading to
version 1.23.0 is able to address this issue. It is recommended to
upgrade the affected component. In micropython objarray component, when
a bytes object is resized and copied into itself, it may reference
memory that has already been freed.
For more information, see:
- https://www.cve.org/CVERecord?id=CVE-2024-8947
- 4bed614e70
Signed-off-by: Thomas Perale <thomas.perale@mind.be >
Signed-off-by: Julien Olivain <ju.o@free.fr >
2025-07-29 01:07:48 +02:00