All of lore.kernel.org
 help / color / mirror / Atom feed
From: Baruch Siach via buildroot <buildroot@buildroot.org>
To: Kadambini Nema <kadambini.nema@gmail.com>
Cc: buildroot@buildroot.org
Subject: Re: [Buildroot] [PATCH 1/1] package/dropbear: security bump to version 2025.88
Date: Fri, 09 May 2025 07:40:13 +0300	[thread overview]
Message-ID: <87a57mxuqa.fsf@tarshish> (raw)
In-Reply-To: <20250509041939.11656-1-kadambini.nema@gmail.com> (Kadambini Nema's message of "Thu, 8 May 2025 21:19:39 -0700")

Hi Kadambini Nema,

On Thu, May 08 2025, Kadambini Nema wrote:
> Fixes CVE-2025-47203.
> https://security-tracker.debian.org/tracker/CVE-2025-47203
>
> Release notes:
> https://github.com/mkj/dropbear/releases/tag/DROPBEAR_2025.88
> https://github.com/mkj/dropbear/releases/tag/DROPBEAR_2025.87

The 2025.87 release removed SHA-1 from the default build. See my comment
on Bernd's suggested 2025.87 bump patch:

  https://lore.kernel.org/all/874j02d3h7.fsf@tarshish/
  https://lore.kernel.org/all/20250309083216.824179-1-bernd@kuhls.net/

baruch

> Signed-off-by: Kadambini Nema <kadambini.nema@gmail.com>
> ---
>  package/dropbear/dropbear.hash | 2 +-
>  package/dropbear/dropbear.mk   | 2 +-
>  2 files changed, 2 insertions(+), 2 deletions(-)
>
> diff --git a/package/dropbear/dropbear.hash b/package/dropbear/dropbear.hash
> index cf2dd18d61..b18aca3aab 100644
> --- a/package/dropbear/dropbear.hash
> +++ b/package/dropbear/dropbear.hash
> @@ -1,5 +1,5 @@
>  # From https://matt.ucc.asn.au/dropbear/releases/SHA256SUM.asc
> -sha256  e78936dffc395f2e0db099321d6be659190966b99712b55c530dd0a1822e0a5e  dropbear-2024.86.tar.bz2
> +sha256  783f50ea27b17c16da89578fafdb6decfa44bb8f6590e5698a4e4d3672dc53d4  dropbear-2025.88.tar.bz2
>  
>  # License file, locally computed
>  sha256  a99ce657d790b761c132ee7e0de18edb437ae6361e536d991c6a12f36e770445  LICENSE
> diff --git a/package/dropbear/dropbear.mk b/package/dropbear/dropbear.mk
> index e043893aa1..c383212e76 100644
> --- a/package/dropbear/dropbear.mk
> +++ b/package/dropbear/dropbear.mk
> @@ -4,7 +4,7 @@
>  #
>  ################################################################################
>  
> -DROPBEAR_VERSION = 2024.86
> +DROPBEAR_VERSION = 2025.88
>  DROPBEAR_SITE = https://matt.ucc.asn.au/dropbear/releases
>  DROPBEAR_SOURCE = dropbear-$(DROPBEAR_VERSION).tar.bz2
>  DROPBEAR_LICENSE = MIT, BSD-2-Clause, Public domain

-- 
                                                     ~. .~   Tk Open Systems
=}------------------------------------------------ooO--U--Ooo------------{=
   - baruch@tkos.co.il - tel: +972.52.368.4656, http://www.tkos.co.il -
_______________________________________________
buildroot mailing list
buildroot@buildroot.org
https://lists.buildroot.org/mailman/listinfo/buildroot

  reply	other threads:[~2025-05-09  4:40 UTC|newest]

Thread overview: 4+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2025-05-09  4:19 [Buildroot] [PATCH 1/1] package/dropbear: security bump to version 2025.88 Kadambini Nema
2025-05-09  4:40 ` Baruch Siach via buildroot [this message]
2025-05-13  9:44   ` Peter Korsgaard
2025-05-18 14:39 ` Arnout Vandecappelle via buildroot

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=87a57mxuqa.fsf@tarshish \
    --to=buildroot@buildroot.org \
    --cc=baruch@tkos.co.il \
    --cc=kadambini.nema@gmail.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.