mirror of
https://gitlab.com/buildroot.org/buildroot.git
synced 2026-09-28 21:11:41 -09:00
Fixes: CVE-2026-18321: https://nvd.nist.gov/vuln/detail/cve-2026-18321 - bump version to 1.2.5 (for details see [1]) - rebased 0001-wscript-remove-checks-for-bsd-string.h-fixes-host-co.patch - rebased 0002-disable-PIE-support.patch - removed 0003-ntpd-refclock_gpsd.c-Add-missing-time.h-for-strptim.patch (from upstream [2]) - moved 0004-refclock_gpsd-add-build-fix-for-gcc-14.x.patch to 0003-refclock_gpsd-add-build-fix-for-gcc-14.x.patch, rebased and enhanced as the original conflicts with upstream commit 5505260c ("Fix redefined _XOPEN_SOURCE warning in refclock_gpsd.c") [3] and leads to the following compile failure: ../../ntpd/refclock_gpsd.c:113:21: error: operator ‘<’ has no left operand 113 | #if _XOPEN_SOURCE < 700 | ^ [1] https://lists.ntpsec.org/pipermail/devel/2026-July/011029.html [2]5137c155d8[3]5505260cd1Signed-off-by: Peter Seiderer <ps.report@gmx.net> [Julien: mark commit as "security bump"] Signed-off-by: Julien Olivain <ju.o@free.fr>
76 lines
2.6 KiB
Diff
76 lines
2.6 KiB
Diff
From 01d75b8d4624883133964deedc4c83e20adbee82 Mon Sep 17 00:00:00 2001
|
|
From: Peter Seiderer <ps.report@gmx.net>
|
|
Date: Thu, 16 Dec 2021 23:27:35 +0100
|
|
Subject: [PATCH] wscript: remove checks for bsd/string.h, fixes host-compile
|
|
failure
|
|
|
|
Fixes the following host-compile failure while cross-compiling
|
|
in case target libbsd is found:
|
|
|
|
[2/2] Compiling build/host/ntpd/ntp_parser.tab.c
|
|
In file included from ../../include/ntp.h:15,
|
|
from .../build/ntpsec-1_2_1/ntpd/ntp_parser.y:16:
|
|
../../include/ntp_stdlib.h:20:10: fatal error: bsd/string.h: No such file or directory
|
|
20 | #include <bsd/string.h>
|
|
| ^~~~~~~~~~~~~~
|
|
compilation terminated.
|
|
|
|
Signed-off-by: Peter Seiderer <ps.report@gmx.net>
|
|
[Rebased on ntpsec-1.2.5]
|
|
Signed-off-by: Peter Seiderer <ps.report@gmx.net>
|
|
---
|
|
include/ntp_stdlib.h | 4 ----
|
|
wscript | 14 --------------
|
|
2 files changed, 18 deletions(-)
|
|
|
|
diff --git a/include/ntp_stdlib.h b/include/ntp_stdlib.h
|
|
index 80e4765cf..c6cb04d04 100644
|
|
--- a/include/ntp_stdlib.h
|
|
+++ b/include/ntp_stdlib.h
|
|
@@ -16,10 +16,6 @@
|
|
#include "ntp_malloc.h"
|
|
#include "ntp_syslog.h"
|
|
|
|
-#ifdef HAVE_BSD_STRING_H
|
|
-#include <bsd/string.h>
|
|
-#endif
|
|
-
|
|
#ifdef __GNUC__
|
|
#define NTP_PRINTF(fmt, args) __attribute__((__format__(__printf__, fmt, args)))
|
|
#else
|
|
diff --git a/wscript b/wscript
|
|
index 65592c997..ba8939aff 100644
|
|
--- a/wscript
|
|
+++ b/wscript
|
|
@@ -643,19 +643,6 @@ int main(int argc, char **argv) {
|
|
prerequisites=ft[1], use=ft[2],
|
|
mandatory=ft[3])
|
|
|
|
- # check for BSD versions outside of libc
|
|
- if not ctx.get_define("HAVE_STRLCAT"):
|
|
- ret = probe_function(ctx, function='strlcat',
|
|
- prerequisites=['bsd/string.h'])
|
|
- if ret:
|
|
- ctx.define("HAVE_STRLCAT", 1, comment="Using bsd/strlcat")
|
|
-
|
|
- if not ctx.get_define("HAVE_STRLCPY"):
|
|
- ret = probe_function(ctx, function='strlcpy',
|
|
- prerequisites=['bsd/string.h'])
|
|
- if ret:
|
|
- ctx.define("HAVE_STRLCPY", 1, comment="Using bsd/strlcpy")
|
|
-
|
|
# Nobody uses the symbol, but this seems like a good sanity check.
|
|
ctx.check_cc(header_name="stdbool.h", mandatory=True,
|
|
comment="Sanity check.")
|
|
@@ -674,7 +661,6 @@ int main(int argc, char **argv) {
|
|
optional_headers = (
|
|
"alloca.h",
|
|
("arpa/nameser.h", ["sys/types.h"]),
|
|
- "bsd/string.h", # bsd emulation
|
|
("ifaddrs.h", ["sys/types.h"]),
|
|
("linux/if_addr.h", ["sys/socket.h"]),
|
|
("linux/rtnetlink.h", ["sys/socket.h"]),
|
|
--
|
|
2.55.0
|
|
|