mirror of
https://gitlab.com/buildroot.org/buildroot.git
synced 2026-09-10 00:04:06 -09:00
ceb6f2d2346ababdf4ee6e204e8bdf4f295bbd1f
Based on the work of the OpenEmbedded community. This commit patches the
following vulnerabilities:
- CVE-2026-26157:
A flaw was found in BusyBox. Incomplete path sanitization in its
archive extraction utilities allows an attacker to craft malicious
archives that when extracted, and under specific conditions, may write
to files outside the intended directory. This can lead to arbitrary
file overwrite, potentially enabling code execution through the
modification of sensitive system files.
https://www.cve.org/CVERecord?id=CVE-2026-26157
- CVE-2026-26158:
A flaw was found in BusyBox. This vulnerability allows an attacker to
modify files outside of the intended extraction directory by crafting
a malicious tar archive containing unvalidated hardlink or symlink
entries. If the tar archive is extracted with elevated privileges,
this flaw can lead to privilege escalation, enabling an attacker to
gain unauthorized access to critical system files.
https://www.cve.org/CVERecord?id=CVE-2026-26158
Signed-off-by: Thomas Perale <thomas.perale@mind.be>
(alternative to commit 5a27004cff)
Signed-off-by: Titouan Christophe <titouan.christophe@mind.be>
…
Buildroot is a simple, efficient and easy-to-use tool to generate embedded Linux systems through cross-compilation. The documentation can be found in docs/manual. You can generate a text document with 'make manual-text' and read output/docs/manual/manual.text. Online documentation can be found at https://buildroot.org/docs.html To build and use the buildroot stuff, do the following: 1) run 'make menuconfig' 2) select the target architecture and the packages you wish to compile 3) run 'make' 4) wait while it compiles 5) find the kernel, bootloader, root filesystem, etc. in output/images You do not need to be root to build or run buildroot. Have fun! Buildroot comes with a basic configuration for a number of boards. Run 'make list-defconfigs' to view the list of provided configurations. Please feed suggestions, bug reports, insults, and bribes back to the buildroot mailing list: buildroot@buildroot.org You can also find us on #buildroot on OFTC IRC. If you would like to contribute patches, please read https://buildroot.org/manual.html#submitting-patches
Description
Languages
Makefile
62.5%
Python
19%
C
8.5%
Shell
6.1%
PHP
1.4%
Other
2.1%