Buildroot Archive on lore.kernel.org
 help / color / mirror / Atom feed
From: Arnout Vandecappelle via buildroot <buildroot@buildroot.org>
To: buildroot@buildroot.org, buildroot-lts-sponsors@buildroot.org,
	buildroot-users@buildroot.org
Subject: [Buildroot] Buildroot 2026.05.3 released
Date: Thu, 10 Sep 2026 21:43:14 +0200	[thread overview]
Message-ID: <buildroot-2026.05.3-announce-1789069201@buildroot.org> (raw)

Hi,

Buildroot is a simple tool for creating complete embedded Linux systems
(https://buildroot.org).

Buildroot 2026.05.3 is released - Go download it at:

https://buildroot.org/downloads/buildroot-2026.05.3.tar.gz

or

https://buildroot.org/downloads/buildroot-2026.05.3.tar.xz

Or get it from Git:

https://gitlab.com/buildroot.org/buildroot.git (2026.05.3 tag)

This is the last release of the 2026.05.x series. It is time to upgrade to
2026.08!

Buildroot 2026.05.3 is a bugfix release, fixing a number of important /
security related issues discovered since the 2026.05.2 release.

Important / security related fixes:

avro-c: (no CVE assigned)
dnsmasq: CVE-2026-12725, CVE-2026-12969
erlang: CVE-2026-21620, CVE-2026-23941, CVE-2026-23942, CVE-2026-23943,
  CVE-2026-28810, CVE-2026-32147, CVE-2026-42789, CVE-2026-42790
exiv2: CVE-2026-49275, CVE-2026-68546, CVE-2026-68547,
  GHSA-3695-mjv8-3r52, GHSA-9v3x-mhg4-wwv2, GHSA-fgw8-p7pr-37cp,
  GHSA-hxph-pv7w-8649, GHSA-jcgh-p9v3-pw6j, GHSA-vg6c-9f6h-4x5q
expat: CVE-2026-66046, CVE-2026-76641, CVE-2026-76956, CVE-2026-76957
glibc: CVE-2026-18374, CVE-2026-19499, CVE-2026-77117, CVE-2026-80489
go: CVE-2026-33818, CVE-2026-39821, CVE-2026-46600, CVE-2026-56853,
  CVE-2026-56858, CVE-2026-56859, CVE-2026-56860, CVE-2026-56862,
  CVE-2026-56864, CVE-2026-56865
haproxy: (no CVE assigned)
hostapd: CVE-2026-58374
libcurl: CVE-2026-13608, CVE-2026-18924, CVE-2026-19931,
  CVE-2026-80229, CVE-2026-80230, CVE-2026-80231, CVE-2026-80255,
  CVE-2026-82208, CVE-2026-82209
libde265: GHSA-mm7m-v26f-wf8x, GHSA-xp3h-6f5r-8cxp
libgit2: CVE-2026-5917
libheif: CVE-2026-84450, CVE-2026-84451, GHSA-24wx-9w62-c96w,
  GHSA-2jg2-4ch7-h545, GHSA-4h82-g446-83fm, GHSA-4jqm-2x34-6f6r,
  GHSA-73p7-m7gg-w2jv, GHSA-8857-r8x5-7499, GHSA-8fmq-r4pf-7m57,
  GHSA-9rj8-5mp5-26c9, GHSA-g89c-p67h-r497, GHSA-gh5q-69gg-c964,
  GHSA-hh47-fhqr-cj2r, GHSA-j264-xvrp-5v7q, GHSA-jc8f-p23p-5hjg,
  GHSA-mw6f-29j3-76f4, GHSA-p58j-h3vm-3fp5, GHSA-w7mc-p8jc-p853,
  GHSA-x8r2-mggj-j6wr, GHSA-x8xm-cm2c-cfc8, GHSA-xw34-mjcp-jqh8
libldns: CVE-2026-10846
libopenssl: CVE-2026-14456, CVE-2026-14457, CVE-2026-18798,
  CVE-2026-54874, CVE-2026-54876, CVE-2026-63072, CVE-2026-63073,
  CVE-2026-63074, CVE-2026-63075, CVE-2026-63076, CVE-2026-75803
libssh2: CVE-2025-15661, CVE-2026-66032, CVE-2026-66033,
  CVE-2026-66034, CVE-2026-66035
localedef: CVE-2026-18374, CVE-2026-19499, CVE-2026-77117,
  CVE-2026-80489
mongoose: CVE-2026-63626, CVE-2026-73251, CVE-2026-73252,
  CVE-2026-73260, CVE-2026-73261
nodejs: CVE-2026-56846, CVE-2026-56847, CVE-2026-56848, CVE-2026-56850,
  CVE-2026-58039, CVE-2026-58040, CVE-2026-58042, CVE-2026-58043,
  CVE-2026-58044, CVE-2026-58045
openvpn: CVE-2026-84732
proftpd: CVE-2026-44331
putty: (no CVE assigned)
python-avro: (no CVE assigned)
redis: CVE-2026-62356
rsyslog: CVE-2026-19654
udisks: CVE-2026-7867, GHSA-j42g-v9jw-6ph3
unbound: CVE-2026-14586, CVE-2026-32665, CVE-2026-40622,
  CVE-2026-40691, CVE-2026-41637, CVE-2026-42955, CVE-2026-44621,
  CVE-2026-44687, CVE-2026-44690, CVE-2026-46582, CVE-2026-50045,
  CVE-2026-50046, CVE-2026-50243, CVE-2026-50248, CVE-2026-50251,
  CVE-2026-50252, CVE-2026-52863, CVE-2026-54478, CVE-2026-55708,
  CVE-2026-55717, CVE-2026-55973, CVE-2026-55990, CVE-2026-55991,
  CVE-2026-56416, CVE-2026-56444
wget: CVE-2026-58469, CVE-2026-58470, CVE-2026-58471
wireshark: CVE-2026-15163, CVE-2026-15164, CVE-2026-15166,
  CVE-2026-15167, CVE-2026-15168, CVE-2026-15169, CVE-2026-15170,
  CVE-2026-15171, CVE-2026-15172, CVE-2026-15174, CVE-2026-76879,
  CVE-2026-76880, CVE-2026-76881, CVE-2026-76882, CVE-2026-76883,
  CVE-2026-76884, CVE-2026-76885, CVE-2026-76886, CVE-2026-76887,
  CVE-2026-76888, CVE-2026-76889, CVE-2026-76890, CVE-2026-76891,
  CVE-2026-76917, CVE-2026-76918, CVE-2026-76919, CVE-2026-76920,
  CVE-2026-76921, CVE-2026-76922, CVE-2026-76923, CVE-2026-76924,
  CVE-2026-76926, CVE-2026-76927, CVE-2026-76928, CVE-2026-76929

Toolchain:

- linux-headers: bump to 5.10.269, 5.15.220, 6.1.187, 6.6.156,
  6.12.109, 6.18.50
- powerpc: correctly track libquadmath

Infrastructure updates/fixes:

- Fix setting of stack size for FLAT binaries
- Various fixes to the runtime tests
- manual: document the LTS release cadence correctly
- manual: document move of patchwork to patchwork.buildroot.org

Updated defconfigs: qemu_xtensa_lx60*

Updated / fixed packages: avro-c, bind, bpftrace, clamav, collectd,
  dahdi-linux, dejavu, distribution-registry, dnsmasq, dpdk, dracut,
  enscript, erlang, exiv2, expat, gdb, glibc, go, haproxy, hostapd,
  igh-ethercat, jpeg-turbo, libbpf, libcurl, libde265, libgit2,
  libheif, libldns, libnfs, libopenssl, libssh2, libxkbcommon,
  libxml-parser-perl, libxml2, linux, linux-headers, linux-tools,
  localedef, mesa3d, mongoose, netsnmp, newt, nodejs, olsr, opencv4,
  openssh, openvpn, passt, perl, powerpc, proftpd, putty, python-avro,
  python-charset-normalizer, python-gobject, qt5knx, qt6, qt6base,
  qt6declarative, redis, rsyslog, taglib, toolchain-external-bootlin,
  uclibc, udisks, uhttpd, unbound, vim, webkitgtk, wget, wine,
  wireless-regdb, wireshark, xilinx-embeddedsw

For more details, see the CHANGES file:

https://gitlab.com/buildroot.org/buildroot/-/blob/2026.05.3/CHANGES

Users of the affected packages are strongly encouraged to upgrade.

Many thanks to all the people contributing to this release:

git shortlog -s -n 2026.05.2..

    21	Bernd Kuhls
    21	Thomas Petazzoni
     8	Stefan Müller
     7	Julien Olivain
     7	Romain Naour
     8	Titouan Christophe
     5	Giulio Benetti
     6	Thomas Perale
     4	Fengwei Tan
     4	Peter Korsgaard
     3	Robert P. J. Day
     3	Waldemar Brodkorb
     3	Yann E. MORIN
     2	Alsey Coleman Miller
     2	Arnout Vandecappelle
     2	Thomas Devoogdt
     1	Adam Ford
     1	Alessandro Rubini
     1	Alexis Lothoré
     1	Benjamin DeCamp
     2	Fiona Klute (Othermo GmbH)
     1	Franciszek Stachura
     1	Fred Lefranc
     1	Jimmy Durand Wesolowski
     1	Joseph Kogut
     1	Luca Ceresoli
     1	Marcus Hoffmann
     1	Martin Bachmann
     1	Neal Frager
     1	Nicolas Cavallari
     1	Raphaël Mélotte
     1	Roy Kollen Svendsen
     1	Sébastien Szymanski

Regards,
Arnout
_______________________________________________
buildroot mailing list
buildroot@buildroot.org
https://lists.buildroot.org/mailman/listinfo/buildroot

                 reply	other threads:[~2026-09-10 19:43 UTC|newest]

Thread overview: [no followups] expand[flat|nested]  mbox.gz  Atom feed

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=buildroot-2026.05.3-announce-1789069201@buildroot.org \
    --to=buildroot@buildroot.org \
    --cc=arnout@rnout.be \
    --cc=buildroot-lts-sponsors@buildroot.org \
    --cc=buildroot-users@buildroot.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox