Buildroot Archive on lore.kernel.org
 help / color / mirror / Atom feed
* [Buildroot] Buildroot 2025.02.18 released
@ 2026-09-10 19:19 Arnout Vandecappelle via buildroot
  2026-09-11  5:59 ` Peter Korsgaard
  0 siblings, 1 reply; 4+ messages in thread
From: Arnout Vandecappelle via buildroot @ 2026-09-10 19:19 UTC (permalink / raw)
  To: buildroot, buildroot-lts-sponsors, buildroot-users

[-- Warning: decoded text below may be mangled, UTF-8 assumed --]
[-- Attachment #1: Type: text/plain, Size: 5565 bytes --]

Hi,

Buildroot is a simple tool for creating complete embedded Linux systems
(https://buildroot.org).

Buildroot 2025.02.18 is released - Go download it at:

https://buildroot.org/downloads/buildroot-2025.02.18.tar.gz

or

https://buildroot.org/downloads/buildroot-2025.02.18.tar.xz

Or get it from Git:

https://gitlab.com/buildroot.org/buildroot.git (2025.02.18 tag)

Buildroot 2025.02.18 is a bugfix release, fixing a number of important /
security related issues discovered since the 2025.02.17 release.

Important / security related fixes:

avro-c: (no CVE assigned)
clamav: CVE-2026-20031, CVE-2026-20213, CVE-2026-20214, CVE-2026-20215,
  CVE-2026-20216, CVE-2026-20217, CVE-2026-20243, CVE-2026-20244,
  CVE-2026-20339, CVE-2026-20345, CVE-2026-20346, CVE-2026-20347,
  CVE-2026-20348
dnsmasq: CVE-2026-12725, CVE-2026-12969
erlang: CVE-2026-21620, CVE-2026-23941, CVE-2026-23942, CVE-2026-23943,
  CVE-2026-28810, CVE-2026-32147, CVE-2026-42789, CVE-2026-42790
exiv2: CVE-2026-49275, CVE-2026-68546, CVE-2026-68547,
  GHSA-3695-mjv8-3r52, GHSA-9v3x-mhg4-wwv2, GHSA-fgw8-p7pr-37cp,
  GHSA-hxph-pv7w-8649, GHSA-jcgh-p9v3-pw6j, GHSA-vg6c-9f6h-4x5q
expat: CVE-2026-66046, CVE-2026-76641, CVE-2026-76956, CVE-2026-76957
glibc: CVE-2026-18374, CVE-2026-19499, CVE-2026-5435, CVE-2026-6238,
  CVE-2026-6368, CVE-2026-6791, CVE-2026-77117, CVE-2026-80489
go: CVE-2026-33818, CVE-2026-39821, CVE-2026-46600, CVE-2026-56853,
  CVE-2026-56858, CVE-2026-56859, CVE-2026-56860, CVE-2026-56862,
  CVE-2026-56864, CVE-2026-56865
haproxy: (no CVE assigned)
hostapd: CVE-2026-58374
libcurl: CVE-2026-13608, CVE-2026-18924, CVE-2026-19931,
  CVE-2026-80229, CVE-2026-80230, CVE-2026-80231, CVE-2026-80255,
  CVE-2026-82208, CVE-2026-82209
libde265: GHSA-mm7m-v26f-wf8x, GHSA-xp3h-6f5r-8cxp
libgit2: CVE-2026-5917
libheif: CVE-2026-84450, CVE-2026-84451, GHSA-24wx-9w62-c96w,
  GHSA-2jg2-4ch7-h545, GHSA-4h82-g446-83fm, GHSA-4jqm-2x34-6f6r,
  GHSA-73p7-m7gg-w2jv, GHSA-8857-r8x5-7499, GHSA-8fmq-r4pf-7m57,
  GHSA-9rj8-5mp5-26c9, GHSA-g89c-p67h-r497, GHSA-gh5q-69gg-c964,
  GHSA-hh47-fhqr-cj2r, GHSA-j264-xvrp-5v7q, GHSA-jc8f-p23p-5hjg,
  GHSA-mw6f-29j3-76f4, GHSA-p58j-h3vm-3fp5, GHSA-w7mc-p8jc-p853,
  GHSA-x8r2-mggj-j6wr, GHSA-x8xm-cm2c-cfc8, GHSA-xw34-mjcp-jqh8
libldns: CVE-2026-10846
libopenssl: CVE-2026-14456, CVE-2026-14457, CVE-2026-18798,
  CVE-2026-54874, CVE-2026-63072, CVE-2026-63073, CVE-2026-63074,
  CVE-2026-63075, CVE-2026-63076, CVE-2026-75803
libssh2: CVE-2025-15661, CVE-2026-66032, CVE-2026-66033,
  CVE-2026-66034, CVE-2026-66035
libxml2: CVE-2026-11979
localedef: CVE-2026-18374, CVE-2026-19499, CVE-2026-5435,
  CVE-2026-6238, CVE-2026-6368, CVE-2026-6791, CVE-2026-77117,
  CVE-2026-80489
mongoose: CVE-2026-63626, CVE-2026-73251, CVE-2026-73252,
  CVE-2026-73260, CVE-2026-73261
nodejs: CVE-2026-56846, CVE-2026-56847, CVE-2026-56848, CVE-2026-56850,
  CVE-2026-58039, CVE-2026-58040, CVE-2026-58042, CVE-2026-58043,
  CVE-2026-58044, CVE-2026-58045
openvpn: CVE-2026-84732
proftpd: CVE-2026-44331
python-avro: (no CVE assigned)
redis: (no CVE assigned)
rsyslog: CVE-2026-19654
udisks: CVE-2026-7867
unbound: CVE-2026-14586, CVE-2026-32665, CVE-2026-40622,
  CVE-2026-40691, CVE-2026-41637, CVE-2026-42955, CVE-2026-44621,
  CVE-2026-44687, CVE-2026-44690, CVE-2026-46582, CVE-2026-50045,
  CVE-2026-50046, CVE-2026-50243, CVE-2026-50248, CVE-2026-50251,
  CVE-2026-50252, CVE-2026-52863, CVE-2026-54478, CVE-2026-55708,
  CVE-2026-55717, CVE-2026-55973, CVE-2026-55990, CVE-2026-55991,
  CVE-2026-56416, CVE-2026-56444
wget: CVE-2026-58469, CVE-2026-58470, CVE-2026-58471

Toolchain:

- linux-headers: bump to 5.10.269, 5.15.220, 6.1.187, 6.6.156, 6.12.109
- powerpc: correctly track libquadmath

Infrastructure updates/fixes:

- Various fixes to the runtime tests
- manual: document move of patchwork to patchwork.buildroot.org
- manual: document the LTS release cadence correctly
- Fix setting of stack size for FLAT binaries

Updated defconfigs: qemu_xtensa_lx60*

Updated / fixed packages: avro-c, bind, clamav, collectd, dejavu,
  dnsmasq, dpdk, dracut, erlang, exiv2, expat, gcc-bare-metal, gdb,
  glibc, go, haproxy, hostapd, libcurl, libde265, libgit2, libheif,
  libldns, libopenssl, libssh2, libxkbcommon, libxml-parser-perl,
  libxml2, linux, linux-headers, linux-tools, localedef, mongoose,
  mosquitto, newt, nodejs, opencv4, openssh, openvpn, perl, powerpc,
  proftpd, python-avro, python-charset-normalizer, qt5knx,
  qt6declarative, redis, rsyslog, taglib, uclibc, udisks, unbound, vim,
  webkitgtk, wget, wine, wireless-regdb

For more details, see the CHANGES file:

https://gitlab.com/buildroot.org/buildroot/-/blob/2025.02.18/CHANGES

Users of the affected packages are strongly encouraged to upgrade.

Many thanks to all the people contributing to this release:

git shortlog -s -n 2025.02.17..

    28	Titouan Christophe
    13	Thomas Petazzoni
    12	Bernd Kuhls
     9	Stefan Müller
     7	Thomas Perale
     5	Julien Olivain
     4	Peter Korsgaard
     4	Waldemar Brodkorb
     3	Robert P. J. Day
     3	Romain Naour
     3	Thomas Devoogdt
     2	Alsey Coleman Miller
     2	Arnout Vandecappelle
     2	Raphaël Mélotte
     1	Adam Ford
     1	Alessandro Rubini
     1	Alexis Lothoré
     1	Benjamin DeCamp
     1	Fengwei Tan
     1	Fiona Klute (othermo GmbH)
     1	Franciszek Stachura
     1	Fred Lefranc
     1	Giulio Benetti
     1	Jimmy Durand Wesolowski
     1	Luca Ceresoli
     1	Marcus Hoffmann
     1	Martin Bachmann
     1	Nicolas Cavallari
     1	Sébastien Szymanski
     1	Yann E. MORIN

Regards,
Arnout

[-- Attachment #2: Type: text/plain, Size: 150 bytes --]

_______________________________________________
buildroot mailing list
buildroot@buildroot.org
https://lists.buildroot.org/mailman/listinfo/buildroot

^ permalink raw reply	[flat|nested] 4+ messages in thread

* Re: [Buildroot] Buildroot 2025.02.18 released
  2026-09-10 19:19 [Buildroot] Buildroot 2025.02.18 released Arnout Vandecappelle via buildroot
@ 2026-09-11  5:59 ` Peter Korsgaard
  2026-09-11  7:05   ` Arnout Vandecappelle via buildroot
  0 siblings, 1 reply; 4+ messages in thread
From: Peter Korsgaard @ 2026-09-11  5:59 UTC (permalink / raw)
  To: Arnout Vandecappelle, buildroot

>>>>> "Arnout" == Arnout Vandecappelle via buildroot <buildroot@buildroot.org> writes:

Hi,

Thanks for doing the release! Some minor comments:

 > Important / security related fixes:
..
 > glibc: CVE-2026-18374, CVE-2026-19499, CVE-2026-5435, CVE-2026-6238,
 >   CVE-2026-6368, CVE-2026-6791, CVE-2026-77117, CVE-2026-80489
..
 > localedef: CVE-2026-18374, CVE-2026-19499, CVE-2026-5435,
 >   CVE-2026-6238, CVE-2026-6368, CVE-2026-6791, CVE-2026-77117,
 >   CVE-2026-80489

I don't think it makes a lot of sense to list the glibc security fixes
twice, just like we wouldn't list mesa3d security fixes for
mesa3d-headers. Maybe adjust your script to filter out packages setting
a custom _DL_SUBDIR?


 > Toolchain:

 > - linux-headers: bump to 5.10.269, 5.15.220, 6.1.187, 6.6.156, 6.12.109
 > - powerpc: correctly track libquadmath

..

 > Updated / fixed packages: avro-c, bind, clamav, collectd, dejavu,
 >   dnsmasq, dpdk, dracut, erlang, exiv2, expat, gcc-bare-metal, gdb,
 >   glibc, go, haproxy, hostapd, libcurl, libde265, libgit2, libheif,
 >   libldns, libopenssl, libssh2, libxkbcommon, libxml-parser-perl,
 >   libxml2, linux, linux-headers, linux-tools, localedef, mongoose,
 >   mosquitto, newt, nodejs, opencv4, openssh, openvpn, perl, powerpc,

We do not have a "powerpc" package, so I guess that was somehow in
relation to the toolchain change?

-- 
Bye, Peter Korsgaard
_______________________________________________
buildroot mailing list
buildroot@buildroot.org
https://lists.buildroot.org/mailman/listinfo/buildroot

^ permalink raw reply	[flat|nested] 4+ messages in thread

* Re: [Buildroot] Buildroot 2025.02.18 released
  2026-09-11  5:59 ` Peter Korsgaard
@ 2026-09-11  7:05   ` Arnout Vandecappelle via buildroot
  2026-09-11  7:42     ` Peter Korsgaard
  0 siblings, 1 reply; 4+ messages in thread
From: Arnout Vandecappelle via buildroot @ 2026-09-11  7:05 UTC (permalink / raw)
  To: Peter Korsgaard, buildroot



On 11/09/2026 07:59, Peter Korsgaard wrote:
>>>>>> "Arnout" == Arnout Vandecappelle via buildroot <buildroot@buildroot.org> writes:
> 
> Hi,
> 
> Thanks for doing the release! Some minor comments:
> 
>   > Important / security related fixes:
> ..
>   > glibc: CVE-2026-18374, CVE-2026-19499, CVE-2026-5435, CVE-2026-6238,
>   >   CVE-2026-6368, CVE-2026-6791, CVE-2026-77117, CVE-2026-80489
> ..
>   > localedef: CVE-2026-18374, CVE-2026-19499, CVE-2026-5435,
>   >   CVE-2026-6238, CVE-2026-6368, CVE-2026-6791, CVE-2026-77117,
>   >   CVE-2026-80489
> 
> I don't think it makes a lot of sense to list the glibc security fixes
> twice, just like we wouldn't list mesa3d security fixes for
> mesa3d-headers. Maybe adjust your script to filter out packages setting
> a custom _DL_SUBDIR?

  I actually do that manually - it will be much easier to drop localedef.

>   > Toolchain:
> 
>   > - linux-headers: bump to 5.10.269, 5.15.220, 6.1.187, 6.6.156, 6.12.109
>   > - powerpc: correctly track libquadmath
> 
> ..
> 
>   > Updated / fixed packages: avro-c, bind, clamav, collectd, dejavu,
>   >   dnsmasq, dpdk, dracut, erlang, exiv2, expat, gcc-bare-metal, gdb,
>   >   glibc, go, haproxy, hostapd, libcurl, libde265, libgit2, libheif,
>   >   libldns, libopenssl, libssh2, libxkbcommon, libxml-parser-perl,
>   >   libxml2, linux, linux-headers, linux-tools, localedef, mongoose,
>   >   mosquitto, newt, nodejs, opencv4, openssh, openvpn, perl, powerpc,
> 
> We do not have a "powerpc" package, so I guess that was somehow in
> relation to the toolchain change?
  Heh, indeed, I didn't realize that by writing "powerpc: ..." my script would 
interpret it as a package name...


  Regards,
  Arnout
_______________________________________________
buildroot mailing list
buildroot@buildroot.org
https://lists.buildroot.org/mailman/listinfo/buildroot

^ permalink raw reply	[flat|nested] 4+ messages in thread

* Re: [Buildroot] Buildroot 2025.02.18 released
  2026-09-11  7:05   ` Arnout Vandecappelle via buildroot
@ 2026-09-11  7:42     ` Peter Korsgaard
  0 siblings, 0 replies; 4+ messages in thread
From: Peter Korsgaard @ 2026-09-11  7:42 UTC (permalink / raw)
  To: Arnout Vandecappelle; +Cc: buildroot

>>>>> "Arnout" == Arnout Vandecappelle <arnout@rnout.be> writes:

Hi,

 >> I don't think it makes a lot of sense to list the glibc security
 >> fixes
 >> twice, just like we wouldn't list mesa3d security fixes for
 >> mesa3d-headers. Maybe adjust your script to filter out packages setting
 >> a custom _DL_SUBDIR?

 >  I actually do that manually - it will be much easier to drop localedef.

OK, also good.

 >> We do not have a "powerpc" package, so I guess that was somehow in
 >> relation to the toolchain change?
 >  Heh, indeed, I didn't realize that by writing "powerpc: ..." my
 >  script would interpret it as a package name...

Maybe only consider patches under package/ for that? That is how I do it.

-- 
Bye, Peter Korsgaard
_______________________________________________
buildroot mailing list
buildroot@buildroot.org
https://lists.buildroot.org/mailman/listinfo/buildroot

^ permalink raw reply	[flat|nested] 4+ messages in thread

end of thread, other threads:[~2026-09-11  7:42 UTC | newest]

Thread overview: 4+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-09-10 19:19 [Buildroot] Buildroot 2025.02.18 released Arnout Vandecappelle via buildroot
2026-09-11  5:59 ` Peter Korsgaard
2026-09-11  7:05   ` Arnout Vandecappelle via buildroot
2026-09-11  7:42     ` Peter Korsgaard

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox