Fixes the following security vulnerability:
- CVE-2026-23865:
An integer overflow in the tt_var_load_item_variation_store function
of the Freetype library in versions 2.13.2 and 2.13.3 may allow for an
out of bounds read operation when parsing HVAR/VVAR/MVAR tables in
OpenType variable fonts. This issue is fixed in version 2.14.2.
For more information, see
- https://www.cve.org/CVERecord?id=CVE-2026-23865
- fc85a25584.patch
(cherry picked from commit 6c3933d14b)
Signed-off-by: Thomas Perale <thomas.perale@mind.be>
- CVE-2026-34743:
XZ Utils provide a general-purpose data-compression library plus
command-line tools. Prior to version 5.8.3, if lzma_index_decoder()
was used to decode an Index that contained no Records, the resulting
lzma_index was left in a state where where a subsequent
lzma_index_append() would allocate too little memory, and a buffer
overflow would occur. This issue has been patched in version 5.8.3.
For more information, see:
- https://www.cve.org/CVERecord?id=CVE-2026-34743
- https://security-tracker.debian.org/tracker/CVE-2026-34743
- c8c22869e7
(cherry picked from commit 7246352273)
Signed-off-by: Thomas Perale <thomas.perale@mind.be>
Commit [1] introduced a set of patches to fix CVE-2025-31115.
Since [2] the security patches neeed to reference the vulnerability with
the `CVE: ` trailer in the patch header.
This set of patch is no longer present on master branch with xz bump [3]
but hasn't been cherry picked to 2025.02.x branch.
[1] 06c6c49fe8 package/xz: add security patches fixing CVE-2025-31115
[2] 1167d0ff3d docs/manual: mention CVE trailer
[3] aaa50b0e61 package/xz: bump to version 5.8.1
Signed-off-by: Thomas Perale <thomas.perale@mind.be>
See the release notes: https://www.python.org/downloads/release/python-31213/
This fixes a handful of bugs and the following vulnerability:
- CVE-2024-6923:
There is a MEDIUM severity vulnerability affecting CPython. The
email module didn’t properly quote newlines for email headers when
serializing an email message allowing for header injection when an
email is serialized.
https://www.cve.org/CVERecord?id=CVE-2024-6923
This also includes a mitigation for a libexpat vulnerability:
- CVE-2025-59375:
libexpat in Expat before 2.7.2 allows attackers to trigger large
dynamic memory allocations via a small document that is submitted for
parsing.
https://www.cve.org/CVERecord?id=CVE-2025-59375
Signed-off-by: Titouan Christophe <titouan.christophe@mind.be>
(cherry picked from commit f862711b10)
Signed-off-by: Thomas Perale <thomas.perale@mind.be>
From the release notes:
https://github.com/redis/redis/blob/7.2.13/00-RELEASENOTES
================================================================================
Redis 7.2.13 Released Mon 23 Feb 2026 10:00:00 IST
================================================================================
SECURITY: There is a security fix in the release
* A user can manipulate data read by a connection by injecting \r\n sequences
into a Redis error reply
Signed-off-by: Titouan Christophe <titouan.christophe@mind.be>
(cherry picked from commit 29a4927157)
Signed-off-by: Thomas Perale <thomas.perale@mind.be>
Those target configurations marked as "secondary" will be tested with a
lower probability in autobuilders. The intent is to focus the Buildroot
development (and bugfixes) on mainstream configurations, while still
keeping some other, less common, configurations.
This commit marks the following CPU architectures as secondary:
BR2_arcle (ARC little endian)
BR2_armeb (ARM big endian)
BR2_aarch64_be (AArch64 big endian)
BR2_hppa (PA-RISC)
BR2_loongarch64
BR2_m68k
BR2_microblazeel (Microblaze AXI, little endian)
BR2_microblazebe (Microblaze non-AXI, big endian)
BR2_mips (MIPS, big endian)
BR2_mipsel (MIPS, little endian)
BR2_mips64 (MIPS64 big endian)
BR2_or1k (OpenRISC)
BR2_powerpc (PowerPC, big endian)
BR2_powerpc64 (PowerPC64, big endian)
BR2_s390x
BR2_sh (SuperH)
BR2_sparc
BR2_sparc64
BR2_xtensa
In the following CPU architecture, only specific configurations are
marked secondary:
In BR2_armeb (ARM little endian),
- armv4 cores (arm920t, arm922t, fa526/626, strongarm sa110/sa1100)
In BR2_riscv:
- all 32-bit configurations
- 64-bit no-MMU
In BR2_i386 (x86 32-bit),
- i486, i586 and X1000 CPU
There was no strict rule established to build this list of secondary
configurations. This list was built mainly from the observation of
which architecture/CPUs are still widely used in the field
(disregarding its age), the quality of their upstream support and
the general relevance in the Buildroot project.
Signed-off-by: Julien Olivain <ju.o@free.fr>
[Arnout: use !BR2_HIDE_SECONDARY_TARGET_OPTIONS instead of
BR2_SHOW_SECONDARY_TARGET_OPTIONS]
Signed-off-by: Arnout Vandecappelle <arnout@rnout.be>
(cherry picked from commit ddce0814a7)
[thomas: kept x1000 & i586 as primary]
Signed-off-by: Thomas Perale <thomas.perale@mind.be>
The option is currently unused, which leads to a check-symbol warning.
Suggested-by: Arnout Vandecappelle <arnout@rnout.be>
Signed-off-by: Julien Olivain <ju.o@free.fr>
[Arnout: squash two patches]
Signed-off-by: Arnout Vandecappelle <arnout@rnout.be>
(cherry picked from commit 4642f903cd)
Signed-off-by: Thomas Perale <thomas.perale@mind.be>
This avoids having to run b4 prep --set-prefixes 2025.02.x to add the
2025.02.x prefix to the patch subject.
You do need b4 0.11+ to make use of that.
Signed-off-by: Quentin Schulz <quentin.schulz@cherry.de>
Signed-off-by: Thomas Perale <thomas.perale@mind.be>
The master branch bumped libspdm in commit [1] that fixes the build
error that appeared with openssl bump [2].
The 2025.02.x branch remained on openssl 3.4 and didn't need a backport.
With the EOL of openssl 3.4 and 2025.02.x is moving to 3.5 this backport
is now necessary to build libspdm.
[1] a01c07f572 package/libspdm: bump version to 3.8.0
[2] 9868ca6ec9 package/libopenssl: bump version to 3.5.0
Signed-off-by: Thomas Perale <thomas.perale@mind.be>
Fixes a build error when pod2man is missing on the host:
pod2man ./tools/lsmac.pl >lsmac.1 || { rm -f lsmac.1 ; false ; }
/bin/sh: line 1: pod2man: command not found
Fixes:
https://autobuild.buildroot.net/results/999/9996e81429f90f4615755827ac182094d416c467/
Although the build error only occurs since 2026-03-05 it should be
backported to LTS branches because the last change to the buildroot
package dates back to 2024.
Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Julien Olivain <ju.o@free.fr>
(cherry picked from commit ec62109990)
Signed-off-by: Thomas Perale <thomas.perale@mind.be>
Buildroot commit 0645cb39e0 bumped the
package from 1.7 to 1.8.1.
Upstream included commit
f614f35e73
in version 1.8 to switch from pcre to pcre2 but the buildroot package
was not updated accordingly.
Pcre2 was already selected by pango -> libglib2 -> pcre2 so this bug was
never noticed.
Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Julien Olivain <ju.o@free.fr>
(cherry picked from commit e8466476c4)
Signed-off-by: Thomas Perale <thomas.perale@mind.be>
Buildroot commit 00317f0aff switched the
package from pcre to pcre2 but forgot update the Kconfig help text.
Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Julien Olivain <ju.o@free.fr>
(cherry picked from commit 60a95e04d4)
Signed-off-by: Thomas Perale <thomas.perale@mind.be>
See the release notes of intermediate versions:
- https://github.com/yhirose/cpp-httplib/releases/tag/v0.28.0
- https://github.com/yhirose/cpp-httplib/releases/tag/v0.29.0
- https://github.com/yhirose/cpp-httplib/releases/tag/v0.30.0
- https://github.com/yhirose/cpp-httplib/releases/tag/v0.30.1
- https://github.com/yhirose/cpp-httplib/releases/tag/v0.30.2
- https://github.com/yhirose/cpp-httplib/releases/tag/v0.31.0
- https://github.com/yhirose/cpp-httplib/releases/tag/v0.32.0
- https://github.com/yhirose/cpp-httplib/releases/tag/v0.33.0
- https://github.com/yhirose/cpp-httplib/releases/tag/v0.33.1
- https://github.com/yhirose/cpp-httplib/releases/tag/v0.34.0
- https://github.com/yhirose/cpp-httplib/releases/tag/v0.35.0
- https://github.com/yhirose/cpp-httplib/releases/tag/v0.36.0
- https://github.com/yhirose/cpp-httplib/releases/tag/v0.37.0
- https://github.com/yhirose/cpp-httplib/releases/tag/v0.37.1
- https://github.com/yhirose/cpp-httplib/releases/tag/v0.37.2
This fixes numerous vulnerabilities:
- CVE-2026-21428:
cpp-httplib is a C++11 single-file header-only cross platform
HTTP/HTTPS library. Prior to version 0.30.0, the ``write_headers``
function does not check for CR & LF characters in user supplied
headers, allowing untrusted header value to escape header lines. This
vulnerability allows attackers to add extra headers, modify request
body unexpectedly & trigger an SSRF attack. When combined with a
server that supports http1.1 pipelining (springboot, python twisted
etc), this can be used for server side request forgery (SSRF). Version
0.30.0 fixes this issue.
https://www.cve.org/CVERecord?id=CVE-2026-21428
- CVE-2026-22776:
cpp-httplib is a C++11 single-file header-only cross platform
HTTP/HTTPS library. Prior to version 0.30.1, a Denial of Service (DoS)
vulnerability exists in cpp-httplib due to the unsafe handling of
compressed HTTP request bodies (Content-Encoding: gzip, br, etc.). The
library validates the payload_max_length against the compressed data
size received from the network, but does not limit the size of the
decompressed data stored in memory.
https://www.cve.org/CVERecord?id=CVE-2026-22776
- CVE-2026-28434:
cpp-httplib is a C++11 single-file header-only cross platform
HTTP/HTTPS library. Prior to 0.35.0, when a request handler throws a
C++ exception and the application has not registered a custom
exception handler via set_exception_handler(), the library catches the
exception and writes its message directly into the HTTP response as a
header named EXCEPTION_WHAT. This header is sent to whoever made the
request, with no authentication check and no special configuration
required to trigger it. The behavior is on by default. A developer who
does not know to opt in to set_exception_handler() will ship a server
that leaks internal exception messages to any client. This
vulnerability is fixed in 0.35.0.
https://www.cve.org/CVERecord?id=CVE-2026-28434
- CVE-2026-28435:
cpp-httplib is a C++11 single-file header-only cross platform
HTTP/HTTPS library. Prior to 0.35.0, cpp-httplib (httplib.h) does not
enforce Server::set_payload_max_length() on the decompressed request
body when using HandlerWithContentReader (streaming ContentReader)
with Content-Encoding: gzip (or other supported encodings). A small
compressed payload can expand beyond the configured payload limit and
be processed by the application, enabling a payload size limit bypass
and potential denial of service (CPU/memory exhaustion). This
vulnerability is fixed in 0.35.0.
https://www.cve.org/CVERecord?id=CVE-2026-28435
- CVE-2026-29076:
cpp-httplib is a C++11 single-file header-only cross platform
HTTP/HTTPS library. Prior to version 0.37.0, cpp-httplib uses
std::regex (libstdc++) to parse RFC 5987 encoded filename* values in
multipart Content-Disposition headers. The regex engine in libstdc++
implements backtracking via deep recursion, consuming one stack frame
per input character. An attacker can send a single HTTP POST request
with a crafted filename* parameter that causes uncontrolled stack
growth, resulting in a stack overflow (SIGSEGV) that crashes the
server process. This issue has been patched in version 0.37.0.
https://www.cve.org/CVERecord?id=CVE-2026-29076
- CVE-2026-31870:
cpp-httplib is a C++11 single-file header-only cross platform
HTTP/HTTPS library. Prior to 0.37.1, when a cpp-httplib client uses
the streaming API (httplib::stream::Get, httplib::stream::Post, etc.),
the library calls std::stoull() directly on the Content-Length header
value received from the server with no input validation and no
exception handling. std::stoull throws std::invalid_argument for non-
numeric strings and std::out_of_range for values exceeding ULLONG_MAX.
Since nothing catches these exceptions, the C++ runtime calls
std::terminate(), which kills the process with SIGABRT. Any server the
client connects to — including servers reached via HTTP redirects,
third-party APIs, or man-in-the-middle positions can crash the client
application with a single HTTP response. No authentication is
required. No interaction from the end user is required. The crash is
deterministic and immediate. This vulnerability is fixed in 0.37.1.
https://www.cve.org/CVERecord?id=CVE-2026-31870
- CVE-2026-32627:
cpp-httplib is a C++11 single-file header-only cross platform
HTTP/HTTPS library. Prior to 0.37.2, when a cpp-httplib client is
configured with a proxy and set_follow_location(true), any HTTPS
redirect it follows will have TLS certificate and hostname
verification silently disabled on the new connection. The client will
accept any certificate presented by the redirect target — expired,
self-signed, or forged — without raising an error or notifying the
application. A network attacker in a position to return a redirect
response can fully intercept the follow-up HTTPS connection, including
any credentials or session tokens in flight. This vulnerability is
fixed in 0.37.2.
https://www.cve.org/CVERecord?id=CVE-2026-32627
Signed-off-by: Titouan Christophe <titouan.christophe@mind.be>
Signed-off-by: Julien Olivain <ju.o@free.fr>
(cherry picked from commit 8dad17ea06)
Signed-off-by: Thomas Perale <thomas.perale@mind.be>
Require host-pkgconf only for libtirpc is not enough because libmnl
requires as well.
Upstream added it since 20200515 commit
553ca8ea3b ("net/route: Add netlink based route change tests")
using it in m4/ltp-libmnl.m4.
Later, in 20210524 in commit
6e17e2ba13 ("configure: Improve error message on missing pkg-config")
configure.ac required it explicitly:
m4_ifndef([PKG_CHECK_EXISTS],
[m4_fatal([must install pkg-config or pkgconfig and pkg.m4 macro (usual dependency), see INSTALL])])
This fixes error:
checking pkg-config is at least version 0.9.0... ./configure: line 7419: br-mips64r6-el-hf-glibc/host/bin/pkg-config: No such file or directory
Signed-off-by: Petr Vorel <petr.vorel@gmail.com>
Signed-off-by: Julien Olivain <ju.o@free.fr>
(cherry picked from commit d421a5d278)
Signed-off-by: Thomas Perale <thomas.perale@mind.be>
Buildroot commit c9f7b876ee added a patch to
fix the vulnerability for rauc v1.13, but forgot to ignore the CVE in rauc.mk
Signed-off-by: Titouan Christophe <titouan.christophe@mind.be>
Signed-off-by: Thomas Perale <thomas.perale@mind.be>
Fixes the following vulnerability:
- CVE-2026-27135:
nghttp2 is an implementation of the Hypertext Transfer Protocol
version 2 in C. Prior to version 1.68.1, the nghttp2 library stops
reading the incoming data when user facing public API
`nghttp2_session_terminate_session` or
`nghttp2_session_terminate_session2` is called by the application.
They might be called internally by the library when it detects the
situation that is subject to connection error. Due to the missing
internal state validation, the library keeps reading the rest of the
data after one of those APIs is called. Then receiving a malformed
frame that causes FRAME_SIZE_ERROR causes assertion failure. nghttp2
v1.68.1 adds missing state validation to avoid assertion failure. No
known workarounds are available.
For more information, see:
- https://www.cve.org/CVERecord?id=CVE-2026-27135
- 5c7df8fa81
(cherry picked from commit 7d26ff6c14)
Signed-off-by: Thomas Perale <thomas.perale@mind.be>
As of glibc 2.43, faketime build was broken in buildroot because of a
missing const qualifier. A patch was applied to it in master to fix this
issue.
Sadly, due to a difference in faketime version between master (v0.9.12) and
2025.02.x (v0.9.10), the patch didn't apply properly in 2025.02.x.
Rebase the faketime patch on v0.9.10.
Fixes:
https://autobuild.buildroot.org/results/761/761250e8cbb2602abdc7752d182a44b6f7de5e11
Signed-off-by: Thomas Bonnefille <thomas.bonnefille@bootlin.com>
Signed-off-by: Thomas Perale <thomas.perale@mind.be>
Add a basic runtime test for memcached. The test starts memcached and
checks if it responds to a basic set/get request.
Signed-off-by: Franciszek Stachura <fbstachura@gmail.com>
Signed-off-by: Julien Olivain <ju.o@free.fr>
(cherry picked from commit aa2d71ac38)
Signed-off-by: Thomas Perale <thomas.perale@mind.be>
This fixes the following vulnerability:
RAUC bundles using the 'plain' format exceeding a payload size of 2 GiB
cause an integer overflow which results in a signature which covers only
the first few bytes of the payload. Given such a bundle with a legitimate
signature, an attacker can modify the part of the payload which is not
covered by the signature. Bundles using the recommended 'verity' or
'crypt' formats are not affected. They are supported from v1.5
(released 2020-12-14) and v1.7 (released 2022-06-03) respectively.
If all signed and published bundles were smaller than 2GiB,
the vulnerability cannot be exploited.
https://github.com/rauc/rauc/security/advisories/GHSA-6hj7-q844-m2hx
Signed-off-by: Titouan Christophe <titouan.christophe@mind.be>
(cherry picked from commit 6e4a136363)
Signed-off-by: Thomas Perale <thomas.perale@mind.be>