All of lore.kernel.org
 help / color / mirror / Atom feed
From: Joachim Wiberg <troglobit@gmail.com>
To: buildroot@buildroot.org
Cc: Fiona Klute <fiona.klute@gmx.de>,
	Joachim Wiberg <troglobit@gmail.com>,
	Thomas Petazzoni <thomas.petazzoni@bootlin.com>,
	Julien Olivain <ju.o@free.fr>
Subject: [Buildroot] [PATCH v2 1/2] package/lldpd: security bump to version 1.0.22
Date: Thu, 17 Sep 2026 18:05:42 +0200	[thread overview]
Message-ID: <20260917160543.243218-2-troglobit@gmail.com> (raw)
In-Reply-To: <20260914103020.3485030-1-troglobit@gmail.com>

https://github.com/lldpd/lldpd/releases/tag/1.0.22
https://github.com/lldpd/lldpd/releases/tag/1.0.21

Fixes CVE-2026-46433, an out-of-bound read access when removing the
VLAN tag.  1.0.21 fixes path traversal vulnerabilities and arbitrary
file deletion in the privileged process.

GPG signature verified with key AEF2348766F371C689A7360095A42FE8353525F9,
LICENSE hash unchanged.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
Signed-off-by: Julien Olivain <ju.o@free.fr>
---
 package/lldpd/lldpd.hash | 6 +++---
 package/lldpd/lldpd.mk   | 2 +-
 2 files changed, 4 insertions(+), 4 deletions(-)

diff --git a/package/lldpd/lldpd.hash b/package/lldpd/lldpd.hash
index f3cefe7b73..46f2b9b476 100644
--- a/package/lldpd/lldpd.hash
+++ b/package/lldpd/lldpd.hash
@@ -1,6 +1,6 @@
 # Locally computed after checking gpg key
-# https://media.luffy.cx/files/lldpd/lldpd-1.0.20.tar.gz.gpg
+# https://media.luffy.cx/files/lldpd/lldpd-1.0.22.tar.gz.gpg
 # using key AEF2348766F371C689A7360095A42FE8353525F9
-# gpg --verify lldpd-1.0.20.tar.gz.gpg lldpd-1.0.20.tar.gz
-sha256  61b8cb22d4879e68f7825a2fb8e1e92abb4aba4773977cf0258bc32ed9f55450  lldpd-1.0.20.tar.gz
+# gpg --verify lldpd-1.0.22.tar.gz.gpg lldpd-1.0.22.tar.gz
+sha256  9587940ed2314a86774c5499f3dfb13a8eb86232a62d243a83a1f09886848e03  lldpd-1.0.22.tar.gz
 sha256  0e96a5aea65f16e2239231ce4ab90497f8bc3bb8fe6abe9299aade4726ff7c8d  LICENSE
diff --git a/package/lldpd/lldpd.mk b/package/lldpd/lldpd.mk
index a3015e9e7d..f0cbc7e436 100644
--- a/package/lldpd/lldpd.mk
+++ b/package/lldpd/lldpd.mk
@@ -4,7 +4,7 @@
 #
 ################################################################################
 
-LLDPD_VERSION = 1.0.20
+LLDPD_VERSION = 1.0.22
 LLDPD_SITE = https://media.luffy.cx/files/lldpd
 LLDPD_DEPENDENCIES = \
 	$(if $(BR2_PACKAGE_CHECK),check) \
-- 
2.43.0

_______________________________________________
buildroot mailing list
buildroot@buildroot.org
https://lists.buildroot.org/mailman/listinfo/buildroot

  parent reply	other threads:[~2026-09-17 16:06 UTC|newest]

Thread overview: 16+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-14 10:30 [Buildroot] [PATCH 1/1] package/mrouted: bump to version 4.7 Joachim Wiberg
2026-09-17  7:44 ` Thomas Petazzoni via buildroot
2026-09-17 14:12   ` Joachim Wiberg
2026-09-17 15:08     ` Thomas Petazzoni via buildroot
2026-09-17 16:05 ` [Buildroot] [PATCH v2 0/2] " Joachim Wiberg
2026-09-17 16:10   ` Joachim Wiberg
2026-09-17 16:05 ` Joachim Wiberg [this message]
2026-09-17 16:11   ` [Buildroot] [PATCH v2 1/2] package/lldpd: security bump to version 1.0.22 Joachim Wiberg
2026-09-17 16:05 ` [Buildroot] [PATCH v2 2/2] package/lldpd: rework start script Joachim Wiberg
2026-09-17 16:12   ` Joachim Wiberg
2026-09-25 14:46   ` Raphaël Mélotte via buildroot
2026-09-20 20:04 ` [Buildroot] [PATCH v2 0/2] package/mrouted: bump to version 4.7 Joachim Wiberg
2026-09-20 20:04 ` [Buildroot] [PATCH v2 1/2] package/mrouted: fix invalid daemon path in S41mrouted Joachim Wiberg
2026-09-22 17:26   ` Julien Olivain via buildroot
2026-10-02 10:29   ` Raphaël Mélotte via buildroot
2026-09-20 20:04 ` [Buildroot] [PATCH v2 2/2] package/mrouted: bump to version 4.7 Joachim Wiberg

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260917160543.243218-2-troglobit@gmail.com \
    --to=troglobit@gmail.com \
    --cc=buildroot@buildroot.org \
    --cc=fiona.klute@gmx.de \
    --cc=ju.o@free.fr \
    --cc=thomas.petazzoni@bootlin.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.