From: Bernd Kuhls <bernd@kuhls.net>
To: buildroot@buildroot.org
Subject: [Buildroot] [PATCH 1/1] package/libpcap: security bump version to 1.10.7
Date: Mon, 7 Sep 2026 13:04:54 +0200 [thread overview]
Message-ID: <20260907110454.1071513-1-bernd@kuhls.net> (raw)
https://github.com/the-tcpdump-group/libpcap/blob/libpcap-1.10.7/CHANGES
Fixes the following CVEs:
CVE-2026-0799: Access M[] safely in the BPF interpreter.
CVE-2026-31912: Mind the program bounds in pcap_offline_filter().
CVE-2026-31911: Fail opcodes safely in the BPF interpreter.
CVE-2026-6244: Avoid division by zero via pcap_offline_filter().
CVE-2026-6554: Limit "ja L" looping in pcap_offline_filter().
CVE-2026-18313: Fix a memory leak in rpcapd.
CVE-2026-18238: Fix RPCAP_MSG_PACKET validation.
Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
---
Gitlab pipelines passed:
https://gitlab.com/bkuhls/buildroot/-/commits/a136fab26ea3ead70f854ade16d2a9d29d01e2eb
package/libpcap/libpcap.hash | 4 ++--
package/libpcap/libpcap.mk | 2 +-
2 files changed, 3 insertions(+), 3 deletions(-)
diff --git a/package/libpcap/libpcap.hash b/package/libpcap/libpcap.hash
index 098b059fdb..87cc77338b 100644
--- a/package/libpcap/libpcap.hash
+++ b/package/libpcap/libpcap.hash
@@ -1,6 +1,6 @@
# Locally calculated after checking pgp signature
-# https://www.tcpdump.org/release/libpcap-1.10.6.tar.gz.sig
-sha256 872dd11337fe1ab02ad9d4fee047c9da244d695c6ddf34e2ebb733efd4ed8aa9 libpcap-1.10.6.tar.gz
+# https://www.tcpdump.org/release/libpcap-1.10.7.tar.gz.sig
+sha256 0b394ac90dbc0a9838ff97468e05c9c9a3e873dec2514cd58db65d859d296e31 libpcap-1.10.7.tar.gz
# Hash for license file:
sha256 8a54594d257e14a5260ac770f1633516cb51e3fc28c40136ce2697014eda7afd LICENSE
diff --git a/package/libpcap/libpcap.mk b/package/libpcap/libpcap.mk
index c4feee5766..a501ce2962 100644
--- a/package/libpcap/libpcap.mk
+++ b/package/libpcap/libpcap.mk
@@ -4,7 +4,7 @@
#
################################################################################
-LIBPCAP_VERSION = 1.10.6
+LIBPCAP_VERSION = 1.10.7
LIBPCAP_SITE = https://www.tcpdump.org/release
LIBPCAP_LICENSE = BSD-3-Clause
LIBPCAP_LICENSE_FILES = LICENSE
--
2.47.3
_______________________________________________
buildroot mailing list
buildroot@buildroot.org
https://lists.buildroot.org/mailman/listinfo/buildroot
next reply other threads:[~2026-09-07 11:05 UTC|newest]
Thread overview: 2+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-07 11:04 Bernd Kuhls [this message]
2026-09-07 18:27 ` [Buildroot] [PATCH 1/1] package/libpcap: security bump version to 1.10.7 Julien Olivain via buildroot
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260907110454.1071513-1-bernd@kuhls.net \
--to=bernd@kuhls.net \
--cc=buildroot@buildroot.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.