* [Buildroot] [PATCH] package/openjpeg: bump version to 2.5.4
@ 2025-09-22 19:59 Peter Korsgaard
2025-09-22 20:22 ` Julien Olivain via buildroot
0 siblings, 1 reply; 2+ messages in thread
From: Peter Korsgaard @ 2025-09-22 19:59 UTC (permalink / raw)
To: buildroot; +Cc: Olivier Schonken, Angelo Compagnucci
And drop now included security patch. For details, see:
https://github.com/uclouvain/openjpeg/releases/tag/v2.5.4
Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
---
| 41 -------------------
package/openjpeg/openjpeg.hash | 2 +-
package/openjpeg/openjpeg.mk | 5 +--
3 files changed, 2 insertions(+), 46 deletions(-)
delete mode 100644 package/openjpeg/0001-check-for-error-after-parsing-header.patch
diff --git a/package/openjpeg/0001-check-for-error-after-parsing-header.patch b/package/openjpeg/0001-check-for-error-after-parsing-header.patch
deleted file mode 100644
index 9a02fbf3d4..0000000000
--- a/package/openjpeg/0001-check-for-error-after-parsing-header.patch
+++ /dev/null
@@ -1,41 +0,0 @@
-From f809b80c67717c152a5ad30bf06774f00da4fd2d Mon Sep 17 00:00:00 2001
-From: Sebastian Rasmussen <sebras@gmail.com>
-Date: Thu, 16 Jan 2025 02:13:43 +0100
-Subject: [PATCH] opj_jp2_read_header: Check for error after parsing header.
-
-Consider the case where the caller has not set the p_image
-pointer to NULL before calling opj_read_header().
-
-If opj_j2k_read_header_procedure() fails while obtaining the rest
-of the marker segment when calling opj_stream_read_data() because
-the data stream is too short, then opj_j2k_read_header() will
-never have the chance to initialize p_image, leaving it
-uninitialized.
-
-opj_jp2_read_header() will check the p_image value whether
-opj_j2k_read_header() suceeded or failed. This may be detected as
-an error in valgrind or ASAN.
-
-The fix is to check whether opj_j2k_read_header() suceeded before
-using the output argument p_image.
-
-Upstream: https://github.com/uclouvain/openjpeg/commit/f809b80c67717c152a5ad30bf06774f00da4fd2d
-CVE: CVE-2025-54874
-Signed-off-by: Thomas Perale <thomas.perale@mind.be>
----
- src/lib/openjp2/jp2.c | 2 +-
- 1 file changed, 1 insertion(+), 1 deletion(-)
-
-diff --git a/src/lib/openjp2/jp2.c b/src/lib/openjp2/jp2.c
-index 4df055a54..da5063186 100644
---- a/src/lib/openjp2/jp2.c
-+++ b/src/lib/openjp2/jp2.c
-@@ -2873,7 +2873,7 @@ OPJ_BOOL opj_jp2_read_header(opj_stream_private_t *p_stream,
- p_image,
- p_manager);
-
-- if (p_image && *p_image) {
-+ if (ret && p_image && *p_image) {
- /* Set Image Color Space */
- if (jp2->enumcs == 16) {
- (*p_image)->color_space = OPJ_CLRSPC_SRGB;
diff --git a/package/openjpeg/openjpeg.hash b/package/openjpeg/openjpeg.hash
index 1992d5ca6a..3fda2a243b 100644
--- a/package/openjpeg/openjpeg.hash
+++ b/package/openjpeg/openjpeg.hash
@@ -1,3 +1,3 @@
# Locally computed:
-sha256 368fe0468228e767433c9ebdea82ad9d801a3ad1e4234421f352c8b06e7aa707 openjpeg-2.5.3.tar.gz
+sha256 a695fbe19c0165f295a8531b1e4e855cd94d0875d2f88ec4b61080677e27188a openjpeg-2.5.4.tar.gz
sha256 a6af136f3e15038a666b61f376612a07d9a4e48cb7c01adbf3e33b3f14ab49b6 LICENSE
diff --git a/package/openjpeg/openjpeg.mk b/package/openjpeg/openjpeg.mk
index 7b1352c222..bc5d8143a6 100644
--- a/package/openjpeg/openjpeg.mk
+++ b/package/openjpeg/openjpeg.mk
@@ -4,16 +4,13 @@
#
################################################################################
-OPENJPEG_VERSION = 2.5.3
+OPENJPEG_VERSION = 2.5.4
OPENJPEG_SITE = $(call github,uclouvain,openjpeg,v$(OPENJPEG_VERSION))
OPENJPEG_LICENSE = BSD-2-Clause
OPENJPEG_LICENSE_FILES = LICENSE
OPENJPEG_CPE_ID_VENDOR = uclouvain
OPENJPEG_INSTALL_STAGING = YES
-# 0001-check-for-error-after-parsing-header.patch
-OPENJPEG_IGNORE_CVES += CVE-2025-54874
-
OPENJPEG_DEPENDENCIES += $(if $(BR2_PACKAGE_ZLIB),zlib)
OPENJPEG_DEPENDENCIES += $(if $(BR2_PACKAGE_LIBPNG),libpng)
OPENJPEG_DEPENDENCIES += $(if $(BR2_PACKAGE_TIFF),tiff)
--
2.39.5
_______________________________________________
buildroot mailing list
buildroot@buildroot.org
https://lists.buildroot.org/mailman/listinfo/buildroot
^ permalink raw reply related [flat|nested] 2+ messages in thread
* Re: [Buildroot] [PATCH] package/openjpeg: bump version to 2.5.4
2025-09-22 19:59 [Buildroot] [PATCH] package/openjpeg: bump version to 2.5.4 Peter Korsgaard
@ 2025-09-22 20:22 ` Julien Olivain via buildroot
0 siblings, 0 replies; 2+ messages in thread
From: Julien Olivain via buildroot @ 2025-09-22 20:22 UTC (permalink / raw)
To: Peter Korsgaard; +Cc: buildroot, Olivier Schonken, Angelo Compagnucci
On 22/09/2025 21:59, Peter Korsgaard wrote:
> And drop now included security patch. For details, see:
>
> https://github.com/uclouvain/openjpeg/releases/tag/v2.5.4
>
> Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
Applied to master, thanks.
_______________________________________________
buildroot mailing list
buildroot@buildroot.org
https://lists.buildroot.org/mailman/listinfo/buildroot
^ permalink raw reply [flat|nested] 2+ messages in thread
end of thread, other threads:[~2025-09-22 20:22 UTC | newest]
Thread overview: 2+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2025-09-22 19:59 [Buildroot] [PATCH] package/openjpeg: bump version to 2.5.4 Peter Korsgaard
2025-09-22 20:22 ` Julien Olivain via buildroot
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.