Conversation
Collaborator
|
Xkbcommon hast a fix upstream |
Author
|
Updated libxkbcommon instead |
cscd98
force-pushed
the
opengltv-2026.02
branch
4 times, most recently
from
May 6, 2026 16:29
d4d09f9 to
0aafb74
Compare
https://github.com/apache/thrift/blob/v0.23.0/CHANGES.md Fixes the following CVEs: CVE-2026-41636: https://seclists.org/oss-sec/2026/q2/236 CVE-2026-41607: https://seclists.org/oss-sec/2026/q2/237 CVE-2026-41606: https://seclists.org/oss-sec/2026/q2/238 CVE-2026-41605: https://seclists.org/oss-sec/2026/q2/239 CVE-2026-41604: https://seclists.org/oss-sec/2026/q2/240 CVE-2026-41602: https://seclists.org/oss-sec/2026/q2/241 CVE-2026-41603: https://seclists.org/oss-sec/2026/q2/242 CVE-2025-48431: https://seclists.org/oss-sec/2026/q2/243 This commit also adds "Public Domain" in THRIFT_LICENSE, after upstream commit [1] added a new sha256 implementation with that license. The LICENSE file hash is also updated accordingly. [1] apache/thrift@1e5fa4b Signed-off-by: Bernd Kuhls <bernd@kuhls.net> Signed-off-by: Julien Olivain <ju.o@free.fr> (cherry picked from commit 6935bc7) Signed-off-by: Thomas Perale <thomas.perale@mind.be>
For more information on the version bump, see: - https://www.wireshark.org/docs/relnotes/wireshark-4.4.15.html Fixes the following vulnerabilities: CVE-2026-5409, CVE-2026-5408, CVE-2026-5406, CVE-2026-5407, CVE-2026-5299, CVE-2026-5401, CVE-2026-5404, CVE-2026-5403, CVE-2026-5405, CVE-2026-5654, CVE-2026-5657, CVE-2026-5656, CVE-2026-5653, CVE-2026-6538, CVE-2026-6537, CVE-2026-6535, CVE-2026-6534, CVE-2026-6533, CVE-2026-6532, CVE-2026-6531, CVE-2026-6530, CVE-2026-6529, CVE-2026-6527, CVE-2026-6524, CVE-2026-6523, CVE-2026-6521, CVE-2026-6520, CVE-2026-6519, CVE-2026-6522, CVE-2026-6870, CVE-2026-6869, CVE-2026-6868. Signed-off-by: Giulio Benetti <giulio.benetti@benettiengineering.com> Signed-off-by: Julien Olivain <ju.o@free.fr> (cherry picked from commit 1880965) Signed-off-by: Thomas Perale <thomas.perale@mind.be>
Signed-off-by: Giulio Benetti <giulio.benetti@benettiengineering.com> Signed-off-by: Julien Olivain <ju.o@free.fr> (cherry picked from commit d230af8) Signed-off-by: Thomas Perale <thomas.perale@mind.be>
https://github.com/agronholm/cbor2/blob/5.9.0/docs/versionhistory.rst Fixes CVE-2026-26209. Signed-off-by: Bernd Kuhls <bernd@kuhls.net> Signed-off-by: Julien Olivain <ju.o@free.fr> (cherry picked from commit b676a4f) Signed-off-by: Thomas Perale <thomas.perale@mind.be>
Signed-off-by: Bernd Kuhls <bernd@kuhls.net> Signed-off-by: Julien Olivain <ju.o@free.fr> (cherry picked from commit 8154103) Signed-off-by: Thomas Perale <thomas.perale@mind.be>
Signed-off-by: Bernd Kuhls <bernd@kuhls.net> Signed-off-by: Julien Olivain <ju.o@free.fr> (cherry picked from commit 4662c67) Signed-off-by: Thomas Perale <thomas.perale@mind.be>
https://github.com/jnwatson/py-lmdb/blob/py-lmdb_1.8.1/ChangeLog Signed-off-by: Bernd Kuhls <bernd@kuhls.net> Signed-off-by: Julien Olivain <ju.o@free.fr> (cherry picked from commit 6df8641) Signed-off-by: Thomas Perale <thomas.perale@mind.be>
https://github.com/jnwatson/py-lmdb/blob/py-lmdb_2.2.0/ChangeLog Version 2.1.0 fixes the following CVEs: - **CVE-2019-16224**: heap buffer overflow via `MDB_DUPFIXED` without `MDB_DUPSORT` in on-disk `md_flags`. (#429) - **CVE-2019-16225**: `SIGSEGV` from `P_DIRTY` flag set on mmap'd disk pages, causing `mdb_page_touch()` to skip copy-on-write. (#429) - **CVE-2019-16226**: out-of-bounds `memmove` in `mdb_node_del` via corrupt `mn_hi` making `NODEDSZ()` huge. (#429) - **CVE-2019-16227**: NULL pointer dereference of `mc_xcursor` when `F_DUPDATA` is set on a node in a non-DUPSORT database. (#429) - **CVE-2019-16228**: divide-by-zero from zero `mm_psize` in meta page header. (#429) Signed-off-by: Bernd Kuhls <bernd@kuhls.net> Signed-off-by: Julien Olivain <ju.o@free.fr> (cherry picked from commit 2286c4a) Signed-off-by: Thomas Perale <thomas.perale@mind.be>
https://github.com/pyasn1/pyasn1/blob/v0.6.3/CHANGES.rst Fixes CVE-2026-30922. Signed-off-by: Bernd Kuhls <bernd@kuhls.net> Signed-off-by: Julien Olivain <ju.o@free.fr> (cherry picked from commit 123136b) Signed-off-by: Thomas Perale <thomas.perale@mind.be>
https://github.com/psf/requests/releases/tag/v2.33.1 https://github.com/psf/requests/releases/tag/v2.33.0 Fixes CVE-2026-25645. Signed-off-by: Bernd Kuhls <bernd@kuhls.net> Signed-off-by: Julien Olivain <ju.o@free.fr> (cherry picked from commit b595f48) Signed-off-by: Thomas Perale <thomas.perale@mind.be>
While CVE-2019-6111 was already fixed in 2025.89, the version 2026.90 provided a follow up of that fix. Note that the author provided this note with this patch: > Note breaking change: "-r" is now disallowed when the target directory exists > (an additional change in Dropbear's version). If that's required an alternative > such as rsync could be used. Adapt your usage of dropbear accordingly. - CVE-2019-6111: An issue was discovered in OpenSSH 7.9. Due to the scp implementation being derived from 1983 rcp, the server chooses which files/directories are sent to the client. However, the scp client only performs cursory validation of the object name returned (only directory traversal attacks are prevented). A malicious scp server (or Man-in-The-Middle attacker) can overwrite arbitrary files in the scp client target directory. If recursive operation (-r) is performed, the server can manipulate subdirectories as well (for example, to overwrite the .ssh/authorized_keys file). For more information, see: https://www.cve.org/CVERecord?id=CVE-2019-6111 - CVE-2026-35385: In OpenSSH before 10.3, a file downloaded by scp may be installed setuid or setgid, an outcome contrary to some users' expectations, if the download is performed as root with -O (legacy scp protocol) and without -p (preserve mode). For more information, see: https://www.cve.org/CVERecord?id=CVE-2026-35385 [1] https://github.com/mkj/dropbear/releases/tag/DROPBEAR_2026.90 (cherry picked from commit 5b136c8) Signed-off-by: Thomas Perale <thomas.perale@mind.be>
https://github.com/jedisct1/libsodium/releases/tag/1.0.22-RELEASE https://github.com/jedisct1/libsodium/releases/tag/1.0.21-RELEASE Updated license hash due to copyright year bump: jedisct1/libsodium@80c6bab Switched to bz2 tarball provided by upstream. Signed-off-by: Bernd Kuhls <bernd@kuhls.net> Signed-off-by: Julien Olivain <ju.o@free.fr> (cherry picked from commit d4d46b2) Signed-off-by: Thomas Perale <thomas.perale@mind.be>
Add entry for package/dos2unix/ Signed-off-by: Shubham Chakraborty <chakrabortyshubham66@gmail.com> [Julien: reword commit title] Signed-off-by: Julien Olivain <ju.o@free.fr> (cherry picked from commit 9f3097b) Signed-off-by: Thomas Perale <thomas.perale@mind.be>
Buildroot commit 7643670 disabled parallel builds in 2012. Upstream fixed the problem in 2021: net-snmp/net-snmp@855e1c2 net-snmp/net-snmp@9ea3d8b with version 5.9.1 which was added to buildroot with commit 83b4337. Tested with -j100. Signed-off-by: Bernd Kuhls <bernd@kuhls.net> Signed-off-by: Julien Olivain <ju.o@free.fr> (cherry picked from commit ae4c2ba) Signed-off-by: Thomas Perale <thomas.perale@mind.be>
Fixes the following security issues: - CVE-2026-27654: Buffer overflow in ngx_http_dav_module when using the alias directive with WebDAV COPY or MOVE requests. - CVE-2026-27784 & CVE-2026-32647: Buffer overflows in ngx_http_mp4_module when processing specially crafted MP4 files. - CVE-2026-27651: NULL pointer dereference in the mail proxy module during CRAM-MD5 or APOP authentication retries. - CVE-2026-28753: DNS PTR record manipulation in auth_http or SMTP proxy. - CVE-2026-28755: OCSP certificate check bypass in the stream module. For a full list of changes, see: https://nginx.org/en/CHANGES-1.28 Signed-off-by: Shubham Chakraborty <chakrabortyshubham66@gmail.com> Signed-off-by: Marcus Hoffmann <buildroot@bubu1.eu> (cherry picked from commit 8008da2) Signed-off-by: Thomas Perale <thomas.perale@mind.be>
Parallel builds were disabled in 2016 by buildroot commit 781ce19. In 2020 upstream added two commits which fix parallel builds pjsip/pjproject@ddf48e2 pjsip/pjproject@7868364 to version 2.11 which was added to buildroot with commit 2c7ad66. Tested with -j100. Signed-off-by: Bernd Kuhls <bernd@kuhls.net> Reviewed-by: Luca Ceresoli <luca.ceresoli@bootlin.com> Signed-off-by: Marcus Hoffmann <buildroot@bubu1.eu> (cherry picked from commit 3ddeb7a) Signed-off-by: Thomas Perale <thomas.perale@mind.be>
https://github.com/pjsip/pjproject/releases/tag/2.17 Fixes the following CVEs: CVE-2026-25994, CVE-2026-26203, CVE-2026-26967, CVE-2026-29068, CVE-2026-28799, CVE-2026-32942, CVE-2026-32945, CVE-2026-33069, CVE-2026-34235, CVE-2026-40614, CVE-2026-40892, CVE-2026-41416, CVE-2026-41415, CVE-2026-42225. Signed-off-by: Bernd Kuhls <bernd@kuhls.net> Reviewed-by: Luca Ceresoli <luca.ceresoli@bootlin.com> Signed-off-by: Marcus Hoffmann <buildroot@bubu1.eu> (cherry picked from commit e1f7716) Signed-off-by: Thomas Perale <thomas.perale@mind.be>
https://github.com/pyca/pyopenssl/blob/26.1.0/CHANGELOG.rst Version 26.1.0 fixes CVE-2026-40475 Version 26.0.0 fixes CVE-2026-27459 & CVE-2026-27448. Signed-off-by: Bernd Kuhls <bernd@kuhls.net> Signed-off-by: Julien Olivain <ju.o@free.fr> (cherry picked from commit 7bcba84) Signed-off-by: Thomas Perale <thomas.perale@mind.be>
http://www.haproxy.org/download/2.6/src/CHANGELOG Signed-off-by: Bernd Kuhls <bernd@kuhls.net> Signed-off-by: Julien Olivain <ju.o@free.fr> (cherry picked from commit 85f1e9c) Signed-off-by: Thomas Perale <thomas.perale@mind.be>
Bugfix release with large number of (security) fixes.
For 6.2.26:
- a severe issue was found in the compression library (slz) where
specially crafted patterns with tune.bufsize above 17408 or
tune.maxrewrite below 964 (both non-default) could cause output
buffer overflows due to the overhead exceeding the promised
worst-case growth bound of 5 bytes and reach up to 1/16 of the
input contents. Given that the compression output is hardly
controllable, and the canaries at the end of the pools will catch
this at release time, the risk of exploitation by a hostile server
is close to zero, however it will cause repeated crashes if such a
crafted file is present on a server and regularly downloaded. A
workaround consists in keeping tune.maxrewrite at least 1/16 of
tune.bufsize or just not changing them since the defaults are safe.
A CVE was requested two weeks ago for this one, I'll mention it when
it arrives.
- HTTP/2 incomplete transfer detection was missing for HEADERS frames
carrying END_STREAM. When relayed to an HTTP/1.1 server that
responds before the end of the transfer, this can result in bytes
of the next request over the same connection to be ignored. Most of
the time it will cause the connection to be dropped due to an
unparsable request, but when combined with "http-reuse never", or
on totally idle servers, the client could expect the second request
to reuse the same connection and perform a content smuggling attack
that would allow to pass an unverified request to a server. For
those who can't upgrade, a temporary workaround is to disable
HTTP/2 by specifying "alpn http/1.1" on bind lines and adding
"disable-h2-upgrade" in HTTP frontends. A CVE will be requested for
this one.
- HTTP/1.1 bodyless messages announcing a non-null Content-Length did
not force close mode on the backend, potentially causing
desynchronisation between HAProxy and the server in conjunction
with other bugs.
- FCGI record length truncation with large bufsize (>=65544) could
enable request smuggling into PHP-FPM since the 16-bit
content_length field silently truncated to 65535 bytes.
- an unvalidated SNI name_len field in ClientHello could cause OOB
heap reads of up to 65KB via XXH3, smp_dup(), and log-format leaks
on any TCP frontend using req.ssl_sni, possibly causing crashes when
used.
- ECDSA JWT signatures with ES256/384/512 could cause a heap overflow
of ~14 bytes in the DER conversion before verification.
- Lua's httpclient headers conversion accepted more than 101 headers
without bound checking, causing a stack buffer overflow reachable
from any Lua action/task/service.
- peers dictionary cache updates accepted an unvalidated entry id as
array index, allowing OOB heap writes at attacker-controlled
offsets.
- Lua had a use-after-free of HTTP reason strings managed by Lua's GC
between set_status() and start_response(), potentially leaking
adjacent information from memory.
- the regsub sample function could leak ~9-50KB of stale heap data
when back-reference expansion overflowed the output buffer.
- SPOE decode_varint() had no iteration cap, allowing pointer
arithmetic to wrap and dereference memory ~64KB before the
allocation, causing SIGSEGV or parser confusion.
- in sample expressions, less common HTTP methods (PATCH etc.) are
represented by both an enum and a string. The string part was not
handled correctly in sample duplication functions, resulting in
their contents appearing empty when trying to fetch the method.
- QPACK varint decoding is now also limited to 62-bit, and had a risk
of 1-byte OOB reads on truncated streams, which could cause
incorrect header decoding.
- config: a few argument parsing errors in conditional expressions
used in ".if" could be misreported and even cause a crash during
the parsing. Also, a few keywords relying on warnif_misplaced_*
didn't check the return value and didn't count emitted warnings as
warnings.
For more details, see the announcement:
https://www.mail-archive.com/haproxy@formilux.org/msg47016.html
For 6.2.27:
A major issue were fixed by this release. It was related to the scheme-based
normalization. The presence of commas in Host header and authority was permitted
and would be used to compare the values, which then would differ when read via
hdr(host) which splits them on commas, and under certain circumstances, trigger
crashes (at least it did in the OSS-Fuzz environment when injecting the values
directly at the HTX layer). The issue was fixed. Remains the case of the comma
characters in authorities. Even though the spec permits commas in authorities
(not in domain names), there is currently no use case for this and it causes an
ambiguity with the historical use of hdr(host), so we preferred to just deny
them. The change was performed on the 3.4-dev10 and postponed for the next 3.3
release. It will probably be backported to lower versions too.
An issue in the FCGI multiplexer was fixed. The function responsible to emit
FCGI_PARAM records was not handling cases of full buffer in a consistent
way. The issue was quite limited, but the "http-send-name-header" option could
be silently ignored. The issue was fixed by reworking this function.
The scheme-based normalization was fixed to properly handle case of OPTIONS
requests. As stated in RFC9110#4.2.3, when the scheme-based normalization is
performed, an empty path must be normalized to "/", except for OPTIONS request.
Finally, a memory leak on error path (tools) and other minor issues were also
fixed.
For more details, see the announcement:
https://www.mail-archive.com/haproxy@formilux.org/msg47059.html
Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
Signed-off-by: Julien Olivain <ju.o@free.fr>
(cherry picked from commit 22f1e90)
Signed-off-by: Thomas Perale <thomas.perale@mind.be>
The CPE audiocoding:freeware_advanced_audio_decoder_2 hasn't received any new CVEs since 2018 while faad2_project:faad2 received 9 new cves [1]. See the full history in [2]. [1] https://nvd.nist.gov/vuln/detail/CVE-2023-38857 [2] https://security-tracker.debian.org/tracker/source-package/faad2 Signed-off-by: Thomas Perale <thomas.perale@mind.be> [Peter: set FAAD2_CPE_ID_VALID = YES for check-package] Signed-off-by: Peter Korsgaard <peter@korsgaard.com> (cherry picked from commit ab03ba7) Signed-off-by: Thomas Perale <thomas.perale@mind.be>
The CPE 'freedesktop:gst-plugins-good' is correct for this package [1]. Also used in conjunction of 'gstreamer:gstreamer', see the package vulnerability history [2]. [1] https://nvd.nist.gov/vuln/detail/CVE-2026-46470 [2] https://security-tracker.debian.org/tracker/source-package/gst-plugins-good1.0 Signed-off-by: Thomas Perale <thomas.perale@mind.be> Signed-off-by: Peter Korsgaard <peter@korsgaard.com> (cherry picked from commit 0c9ccb9) Signed-off-by: Thomas Perale <thomas.perale@mind.be>
The CPE 'python-ecdsa_project:python-ecdsa' hasn't received new CVE since 2019 while 'tlsfuzzer:ecdsa' received two [1][2]. See the package CVE history at [3]. [1] https://nvd.nist.gov/vuln/detail/CVE-2026-33936 [2] https://nvd.nist.gov/vuln/detail/CVE-2024-23342 [3] https://security-tracker.debian.org/tracker/source-package/python-ecdsa Signed-off-by: Thomas Perale <thomas.perale@mind.be> Signed-off-by: Peter Korsgaard <peter@korsgaard.com> (cherry picked from commit f3687eb) Signed-off-by: Thomas Perale <thomas.perale@mind.be>
The CPE 'sane-backends_project:sane-backends' only has a single CVE assigned in 2017 while 'sane-project:sane_backends' has 9 since 2017 [1]. See the package CVE history at [2]. [1] https://nvd.nist.gov/vuln/detail/CVE-2023-46047 [2] https://security-tracker.debian.org/tracker/source-package/sane-backends Signed-off-by: Thomas Perale <thomas.perale@mind.be> Signed-off-by: Peter Korsgaard <peter@korsgaard.com> (cherry picked from commit 41e76b3) Signed-off-by: Thomas Perale <thomas.perale@mind.be>
The 'hp:linux_imaging_and_printing_project' hasn't received any new CVE assignment since 2013, while 'hp:linux_imaging_and_printing' received 4 [1][2][3][4]. See the package vulnerability history at [5]. [1] https://nvd.nist.gov/vuln/detail/CVE-2015-0839 [2] https://nvd.nist.gov/vuln/detail/CVE-2020-6923 [3] https://nvd.nist.gov/vuln/detail/CVE-2026-8631 [4] https://nvd.nist.gov/vuln/detail/CVE-2026-8632 [5] https://security-tracker.debian.org/tracker/source-package/hplip Signed-off-by: Thomas Perale <thomas.perale@mind.be> Signed-off-by: Peter Korsgaard <peter@korsgaard.com> (cherry picked from commit 534ae54) Signed-off-by: Thomas Perale <thomas.perale@mind.be>
Advisory (no CVEs yet): https://lists.x.org/archives/xorg-announce/2026-June/003702.html Release notes: https://lists.x.org/archives/xorg-announce/2026-June/003704.html Signed-off-by: Bernd Kuhls <bernd@kuhls.net> Signed-off-by: Peter Korsgaard <peter@korsgaard.com> (cherry picked from commit 990c39b) Signed-off-by: Thomas Perale <thomas.perale@mind.be>
Fixes the following security issue: - CVE-2025-54388: Firewalld reload makes published container ports accessible from remote hosts GHSA-x4rx-4gw3-53p4 Signed-off-by: Peter Korsgaard <peter@korsgaard.com> Signed-off-by: Julien Olivain <ju.o@free.fr> (cherry picked from commit 831335a) Signed-off-by: Thomas Perale <thomas.perale@mind.be>
For consistency with docker-engine. Release notes: https://github.com/docker/cli/issues?q=is%3Aclosed+milestone%3A28.3.3 Signed-off-by: Peter Korsgaard <peter@korsgaard.com> Signed-off-by: Julien Olivain <ju.o@free.fr> (cherry picked from commit 50bc0b5) Signed-off-by: Thomas Perale <thomas.perale@mind.be>
https://seclists.org/oss-sec/2026/q2/801 Signed-off-by: Bernd Kuhls <bernd@kuhls.net> Signed-off-by: Peter Korsgaard <peter@korsgaard.com> (cherry picked from commit 9cba1cf) Signed-off-by: Thomas Perale <thomas.perale@mind.be>
https://www.php.net/ChangeLog-8.php#8.5.7 https://news-web.php.net/php.announce/493 https://github.com/php/php-src/blob/php-8.5.7/NEWS Fixes CVE-2026-44927 & CVE-2026-44928. Signed-off-by: Bernd Kuhls <bernd@kuhls.net> Signed-off-by: Julien Olivain <ju.o@free.fr> (cherry picked from commit 08f8c44) Signed-off-by: Thomas Perale <thomas.perale@mind.be>
https://mail.python.org/archives/list/security-announce@python.org/thread/4FU62L2M6RMMHT2QPGQNPEHHUND7CEX5/ Signed-off-by: Bernd Kuhls <bernd@kuhls.net> Signed-off-by: Julien Olivain <ju.o@free.fr> (cherry picked from commit 67ec0e9) Signed-off-by: Thomas Perale <thomas.perale@mind.be>
https://mail.python.org/archives/list/security-announce@python.org/thread/ITF2BAPBQEPYK3LDMPRSY435JGNHYNDP/ Signed-off-by: Bernd Kuhls <bernd@kuhls.net> Signed-off-by: Julien Olivain <ju.o@free.fr> (cherry picked from commit d4be78c) Signed-off-by: Thomas Perale <thomas.perale@mind.be>
https://github.com/strukturag/libde265/releases/tag/v1.1.1 Fixes the following security problems: CVE TBD (GHSA-ccfw-29x7-rrx3) - Pixel accessor signed integer overflow causes heap OOB read/write CVE TBD (GHSA-j2qq-x2xq-g9wr) - SAO sequential filter heap buffer overflow via signed integer overflow This version bump includes upstream commit strukturag/libde265@9ded37b which uses constexpr() and causes a build error caught by the Gitlab pipelines with the gcc-6-based bootlin-aarch64-glibc-old defconfig: /builds/bkuhls/buildroot/br-test-pkg/bootlin-aarch64-glibc-old/build/libde265-1.1.1/libde265/deblock.cc:594:14: error: expected ‘(’ before ‘constexpr’ if constexpr (sizeof(pixel_t)==1) { Therefore we need to raise the minimum gcc version according to https://gcc.gnu.org/projects/cxx-status.html#cxx17 to gcc 7. Signed-off-by: Bernd Kuhls <bernd@kuhls.net> Signed-off-by: Julien Olivain <ju.o@free.fr> (cherry picked from commit 35b57a0) Signed-off-by: Thomas Perale <thomas.perale@mind.be>
Fixes the following security issues: CVE-2026-23679: libusb before version 1.0.30 contains a NULL pointer dereference vulnerability that allows attackers to crash applications by supplying a malformed USB configuration descriptor where an interface claims bNumEndpoints greater than zero but is followed by a class-specific descriptor whose bLength exceeds the remaining buffer size, causing parse_interface() to return early without allocating the endpoint array. Attackers can exploit this flaw through libusb_get_active_config_descriptor or libusb_get_config_descriptor by providing crafted descriptors via virtualized USB passthrough, file-based descriptor parsing, or network sources, causing any application iterating over endpoints to dereference a NULL endpoint pointer and crash. https://nvd.nist.gov/vuln/detail/CVE-2026-23679 CVE-2026-47104: libusb before version 1.0.30 contains a one-byte out-of-bounds read vulnerability in parse_iad_array() in descriptor.c that allows attackers to trigger a denial of service by supplying a malformed USB descriptor whose bLength equals size minus one, causing the bounds check to use the original buffer size instead of the remaining size. Attackers in virtualized environments with USB passthrough can supply crafted descriptors through libusb_get_active_interface_association_descriptors or libusb_get_interface_association_descriptors to read one byte past the end of the malloc allocation, resulting in a denial of service. https://nvd.nist.gov/vuln/detail/CVE-2026-47104 For more details, see the announcement: https://sourceforge.net/p/libusb/mailman/message/59335553/ Signed-off-by: Peter Korsgaard <peter@korsgaard.com> Signed-off-by: Julien Olivain <ju.o@free.fr> (cherry picked from commit 907ebab) Signed-off-by: Thomas Perale <thomas.perale@mind.be>
When using a specific git repo and version for at91bootstrap3,
BR2_TARGET_AT91BOOTSTRAP3_LICENSE_FILES defaults to "LICENSES/MIT.txt".
However the git version we use (namely v3.10.3) does not provide this
file. Actually, it does not provide a license file at all. This causes
‘make legal-info’ to fail with:
>>> at91bootstrap3 v3.10.3 Collecting legal info
sha256sum: /builds/buildroot.org/buildroot/output/build/at91bootstrap3-v3.10.3/LICENSES/MIT.txt: No such file or directory
ERROR: while checking hashes from boot/at91bootstrap3/at91bootstrap3.hash
ERROR: LICENSES/MIT.txt has wrong sha256 hash:
ERROR: expected: 5a3809b1c2ba13b7242572322951311c584419f1f8516f665d6c06f0668d78de
ERROR: got :
ERROR: Incomplete download, or man-in-the-middle (MITM) attack
make[1]: *** [boot/at91bootstrap3/at91bootstrap3.mk:112: at91bootstrap3-legal-info] Error 1
Let's be explicit that there is no license file to check.
Fixes:
https://gitlab.com/buildroot.org/buildroot/-/jobs/14728913821 (at91sam9x5ek_mmc_dev_defconfig)
https://gitlab.com/buildroot.org/buildroot/-/jobs/14728913820 (at91sam9x5ek_mmc_defconfig)
https://gitlab.com/buildroot.org/buildroot/-/jobs/14728913819 (at91sam9x5ek_dev_defconfig)
https://gitlab.com/buildroot.org/buildroot/-/jobs/14728913818 (at91sam9x5ek_defconfig)
Signed-off-by: Romain Naour <romain.naour@smile.fr>
Signed-off-by: Julien Olivain <ju.o@free.fr>
(cherry picked from commit 1339bba)
Signed-off-by: Thomas Perale <thomas.perale@mind.be>
The used Linux kernel (4.4.144) does not contain the default license
files as those were only added in 4.16 with commit e00a844aca
("LICENSES: Add Linux syscall note exception"), so specify the correct
license file to fix:
make legal-info
..
cp: cannot stat '/path/to/output/build/linux-headers-custom/LICENSES/preferred/GPL-2.0': No such file or directory
And add the sha256sum to the .hash file.
Enable BR2_DOWNLOAD_FORCE_CHECK_HASHES.
Fixes:
https://gitlab.com/buildroot.org/buildroot/-/jobs/14728913808 (arcturus_ucp1020_defconfig)
Signed-off-by: Romain Naour <romain.naour@smile.fr>
Cc: Michael Durrant <mdurrant@ArcturusNetworks.com>
[Julien: remove .checkpackageignore entry to fix check-package error]
Signed-off-by: Julien Olivain <ju.o@free.fr>
(cherry picked from commit bbb1e2c)
Signed-off-by: Thomas Perale <thomas.perale@mind.be>
This driver fails to build because warnings are treated as errors but this is too strict, breaking the build. This used to be hidden by commit 6b56e0b ("linux: disable -Werror"), which was reverted in commit a966f5c ("Revert "linux: disable -Werror""), so fix it by explicitly passing -Wno-error. Fixes: https://autobuild.buildroot.org/results/df3763e74de4071331a41140fb5528523af9e374/ Signed-off-by: Giulio Benetti <giulio.benetti@benettiengineering.com> [Peter: add note about when issue was (re-)introduced] Signed-off-by: Peter Korsgaard <peter@korsgaard.com> (cherry picked from commit daf4962) Signed-off-by: Thomas Perale <thomas.perale@mind.be>
Author
|
@smx-smx Are you able to look at this PR please? 👍 |
Collaborator
|
I don't think any aarch64 stuff should be part of this PR |
Author
|
Removed, I will make it a separate PR once this is merged. |
Signed-off-by: Arnout Vandecappelle <arnout@rnout.be>
Signed-off-by: Arnout Vandecappelle <arnout@rnout.be>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
The current buildroot no longer compiles on Ubuntu 26.04.
I have updated the buildroot to most recent release which is tag 2026.02.3.
GCC 15 is now the default compiler for webOS config.
Linked runs:
https://github.com/cscd98/buildroot-nc4/actions/runs/28124552033
Tested by compiling both kodi and retroarch for a LG OLED running webOS 25 and 26.