From: Michael Fischer <mf@go-sys.de>
To: <buildroot@buildroot.org>
Cc: Michael Fischer <mf@go-sys.de>
Subject: [Buildroot] [PATCH] package/libconfuse: bump to version 3.4
Date: Tue, 8 Sep 2026 10:35:12 +0200 [thread overview]
Message-ID: <20260908083512.83180-1-mf@go-sys.de> (raw)
The backported fix is dropped, as 3.4 ships it:
0001-Fix-163-unterminated-username-used-with-getpwnam.patch
-> upstream commit d73777c2c356, released in 3.4
With the patch gone, LIBCONFUSE_IGNORE_CVES is no longer needed either.
3.4 also fixes three robustness defects that carry no CVE:
#180 isspace() argument fix, could crash the lexer
#182 stack exhaustion from deeply nested sections
#187 null dereference on an empty comment with CFGF_COMMENTS
Signed-off-by: Michael Fischer <mf@go-sys.de>
---
...rminated-username-used-with-getpwnam.patch | 43 -------------------
package/libconfuse/libconfuse.hash | 4 +-
package/libconfuse/libconfuse.mk | 5 +--
3 files changed, 2 insertions(+), 50 deletions(-)
delete mode 100644 package/libconfuse/0001-Fix-163-unterminated-username-used-with-getpwnam.patch
diff --git a/package/libconfuse/0001-Fix-163-unterminated-username-used-with-getpwnam.patch b/package/libconfuse/0001-Fix-163-unterminated-username-used-with-getpwnam.patch
deleted file mode 100644
index 44e15468ac..0000000000
--- a/package/libconfuse/0001-Fix-163-unterminated-username-used-with-getpwnam.patch
+++ /dev/null
@@ -1,43 +0,0 @@
-From d73777c2c3566fb2647727bb56d9a2295b81669b Mon Sep 17 00:00:00 2001
-From: Joachim Wiberg <troglobit@gmail.com>
-Date: Fri, 2 Sep 2022 16:12:46 +0200
-Subject: [PATCH] Fix #163: unterminated username used with getpwnam()
-
-Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
-
-CVE: CVE-2022-40320
-Upstream: https://github.com/libconfuse/libconfuse/commit/d73777c2c3566fb2647727bb56d9a2295b81669b
-Signed-off-by: Fabrice Fontaine <fontaine.fabrice@gmail.com>
----
- src/confuse.c | 10 ++++++----
- 1 file changed, 6 insertions(+), 4 deletions(-)
-
-diff --git a/src/confuse.c b/src/confuse.c
-index 6d1fdbd..05566b5 100644
---- a/src/confuse.c
-+++ b/src/confuse.c
-@@ -1894,18 +1894,20 @@ DLLIMPORT char *cfg_tilde_expand(const char *filename)
- passwd = getpwuid(geteuid());
- file = filename + 1;
- } else {
-- /* ~user or ~user/path */
-- char *user;
-+ char *user; /* ~user or ~user/path */
-+ size_t len;
-
- file = strchr(filename, '/');
- if (file == 0)
- file = filename + strlen(filename);
-
-- user = malloc(file - filename);
-+ len = file - filename - 1;
-+ user = malloc(len + 1);
- if (!user)
- return NULL;
-
-- strncpy(user, filename + 1, file - filename - 1);
-+ strncpy(user, &filename[1], len);
-+ user[len] = 0;
- passwd = getpwnam(user);
- free(user);
- }
diff --git a/package/libconfuse/libconfuse.hash b/package/libconfuse/libconfuse.hash
index bb968f7a52..19453828d8 100644
--- a/package/libconfuse/libconfuse.hash
+++ b/package/libconfuse/libconfuse.hash
@@ -1,5 +1,3 @@
-# From https://github.com/martinh/libconfuse/releases/download/v3.3/confuse-3.3.tar.xz.md5
-md5 a183cef2cecdd3783436ff8de500d274 confuse-3.3.tar.xz
# Locally computed
-sha256 1dd50a0320e135a55025b23fcdbb3f0a81913b6d0b0a9df8cc2fdf3b3dc67010 confuse-3.3.tar.xz
+sha256 36bfa3928f9c323914c7c8317e8722cb22f41db69d7c9d4c24b4689fa955445d confuse-3.4.tar.xz
sha256 dc3ff4b62f851dd2e94a151061ffeb7d28ddfc880a442068dc5283dbaa927306 LICENSE
diff --git a/package/libconfuse/libconfuse.mk b/package/libconfuse/libconfuse.mk
index fff684a55b..ac3866f746 100644
--- a/package/libconfuse/libconfuse.mk
+++ b/package/libconfuse/libconfuse.mk
@@ -4,7 +4,7 @@
#
################################################################################
-LIBCONFUSE_VERSION = 3.3
+LIBCONFUSE_VERSION = 3.4
LIBCONFUSE_SOURCE = confuse-$(LIBCONFUSE_VERSION).tar.xz
LIBCONFUSE_SITE = https://github.com/libconfuse/libconfuse/releases/download/v$(LIBCONFUSE_VERSION)
LIBCONFUSE_INSTALL_STAGING = YES
@@ -14,8 +14,5 @@ LIBCONFUSE_LICENSE_FILES = LICENSE
LIBCONFUSE_CPE_ID_VALID = YES
LIBCONFUSE_DEPENDENCIES = $(TARGET_NLS_DEPENDENCIES)
-# 0001-Fix-163-unterminated-username-used-with-getpwnam.patch
-LIBCONFUSE_IGNORE_CVES += CVE-2022-40320
-
$(eval $(autotools-package))
$(eval $(host-autotools-package))
--
2.43.0
_______________________________________________
buildroot mailing list
buildroot@buildroot.org
https://lists.buildroot.org/mailman/listinfo/buildroot
next reply other threads:[~2026-09-08 8:39 UTC|newest]
Thread overview: 2+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-08 8:35 Michael Fischer [this message]
2026-09-13 10:25 ` [Buildroot] [PATCH] package/libconfuse: bump to version 3.4 Fiona Klute via buildroot
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260908083512.83180-1-mf@go-sys.de \
--to=mf@go-sys.de \
--cc=buildroot@buildroot.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.