All of lore.kernel.org
 help / color / mirror / Atom feed
From: Joachim Wiberg <troglobit@gmail.com>
To: buildroot@buildroot.org
Cc: Fiona Klute <fiona.klute@gmx.de>,
	Thomas Petazzoni <thomas.petazzoni@bootlin.com>,
	Julien Olivain <ju.o@free.fr>
Subject: Re: [Buildroot] [PATCH v2 1/2] package/lldpd: security bump to version 1.0.22
Date: Thu, 17 Sep 2026 18:11:53 +0200	[thread overview]
Message-ID: <4a5cbe52b2fe626cfafd978465a5e9ce5d4c353e.camel@gmail.com> (raw)
In-Reply-To: <20260917160543.243218-2-troglobit@gmail.com>


[-- Attachment #1.1: Type: text/plain, Size: 2192 bytes --]

Oups,

this has already been merged, please ignore.

Sorry for the noise this creates! I somehow messed up my patch queue.

/Joachim

On Thu, 2026-09-17 at 18:05 +0200, Joachim Wiberg wrote:
> https://github.com/lldpd/lldpd/releases/tag/1.0.22
> https://github.com/lldpd/lldpd/releases/tag/1.0.21
> 
> Fixes CVE-2026-46433, an out-of-bound read access when removing the
> VLAN tag.  1.0.21 fixes path traversal vulnerabilities and arbitrary
> file deletion in the privileged process.
> 
> GPG signature verified with key
> AEF2348766F371C689A7360095A42FE8353525F9,
> LICENSE hash unchanged.
> 
> Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
> Signed-off-by: Julien Olivain <ju.o@free.fr>
> ---
>  package/lldpd/lldpd.hash | 6 +++---
>  package/lldpd/lldpd.mk   | 2 +-
>  2 files changed, 4 insertions(+), 4 deletions(-)
> 
> diff --git a/package/lldpd/lldpd.hash b/package/lldpd/lldpd.hash
> index f3cefe7b73..46f2b9b476 100644
> --- a/package/lldpd/lldpd.hash
> +++ b/package/lldpd/lldpd.hash
> @@ -1,6 +1,6 @@
>  # Locally computed after checking gpg key
> -# https://media.luffy.cx/files/lldpd/lldpd-1.0.20.tar.gz.gpg
> +# https://media.luffy.cx/files/lldpd/lldpd-1.0.22.tar.gz.gpg
>  # using key AEF2348766F371C689A7360095A42FE8353525F9
> -# gpg --verify lldpd-1.0.20.tar.gz.gpg lldpd-1.0.20.tar.gz
> -sha256 
> 61b8cb22d4879e68f7825a2fb8e1e92abb4aba4773977cf0258bc32ed9f55450 
> lldpd-1.0.20.tar.gz
> +# gpg --verify lldpd-1.0.22.tar.gz.gpg lldpd-1.0.22.tar.gz
> +sha256 
> 9587940ed2314a86774c5499f3dfb13a8eb86232a62d243a83a1f09886848e03 
> lldpd-1.0.22.tar.gz
>  sha256 
> 0e96a5aea65f16e2239231ce4ab90497f8bc3bb8fe6abe9299aade4726ff7c8d 
> LICENSE
> diff --git a/package/lldpd/lldpd.mk b/package/lldpd/lldpd.mk
> index a3015e9e7d..f0cbc7e436 100644
> --- a/package/lldpd/lldpd.mk
> +++ b/package/lldpd/lldpd.mk
> @@ -4,7 +4,7 @@
>  #
>  #####################################################################
> ###########
>  
> -LLDPD_VERSION = 1.0.20
> +LLDPD_VERSION = 1.0.22
>  LLDPD_SITE = https://media.luffy.cx/files/lldpd
>  LLDPD_DEPENDENCIES = \
>  	$(if $(BR2_PACKAGE_CHECK),check) \


[-- Attachment #1.2: This is a digitally signed message part --]
[-- Type: application/pgp-signature, Size: 833 bytes --]

[-- Attachment #2: Type: text/plain, Size: 150 bytes --]

_______________________________________________
buildroot mailing list
buildroot@buildroot.org
https://lists.buildroot.org/mailman/listinfo/buildroot

  reply	other threads:[~2026-09-17 16:12 UTC|newest]

Thread overview: 16+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-14 10:30 [Buildroot] [PATCH 1/1] package/mrouted: bump to version 4.7 Joachim Wiberg
2026-09-17  7:44 ` Thomas Petazzoni via buildroot
2026-09-17 14:12   ` Joachim Wiberg
2026-09-17 15:08     ` Thomas Petazzoni via buildroot
2026-09-17 16:05 ` [Buildroot] [PATCH v2 0/2] " Joachim Wiberg
2026-09-17 16:10   ` Joachim Wiberg
2026-09-17 16:05 ` [Buildroot] [PATCH v2 1/2] package/lldpd: security bump to version 1.0.22 Joachim Wiberg
2026-09-17 16:11   ` Joachim Wiberg [this message]
2026-09-17 16:05 ` [Buildroot] [PATCH v2 2/2] package/lldpd: rework start script Joachim Wiberg
2026-09-17 16:12   ` Joachim Wiberg
2026-09-25 14:46   ` Raphaël Mélotte via buildroot
2026-09-20 20:04 ` [Buildroot] [PATCH v2 0/2] package/mrouted: bump to version 4.7 Joachim Wiberg
2026-09-20 20:04 ` [Buildroot] [PATCH v2 1/2] package/mrouted: fix invalid daemon path in S41mrouted Joachim Wiberg
2026-09-22 17:26   ` Julien Olivain via buildroot
2026-10-02 10:29   ` Raphaël Mélotte via buildroot
2026-09-20 20:04 ` [Buildroot] [PATCH v2 2/2] package/mrouted: bump to version 4.7 Joachim Wiberg

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=4a5cbe52b2fe626cfafd978465a5e9ce5d4c353e.camel@gmail.com \
    --to=troglobit@gmail.com \
    --cc=buildroot@buildroot.org \
    --cc=fiona.klute@gmx.de \
    --cc=ju.o@free.fr \
    --cc=thomas.petazzoni@bootlin.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.