Openembedded Core Discussions
 help / color / mirror / Atom feed
From: Richard Purdie <richard.purdie@linuxfoundation.org>
To: openembedded-core@lists.openembedded.org
Subject: [PATCH 16/20] ppp: upgrade 2.5.3 -> 2.5.4
Date: Mon, 21 Sep 2026 08:06:52 +0100	[thread overview]
Message-ID: <20260921070656.521680-16-richard.purdie@linuxfoundation.org> (raw)
In-Reply-To: <20260921070656.521680-1-richard.purdie@linuxfoundation.org>

This is primarily a security release, fixing several vulnerabilities including CVE-2026-75883 and
CVE-2026-85495. For more details on this and other vulnerabilities fixed, see the github advisories at

https://github.com/ppp-project/ppp/security/advisories?state=published

These range in severity up to 6.8 (moderate). Many of the vulnerabilities are actually only of
concern if pppd is installed setuid-root, which some distros still do, though 'make install'
in this project does not install pppd setuid-root.

Other changes include:

    A new environment variable is defined for scripts, called PPP_SCRIPT_INSTANCE, which contains
    the original name of the script (e.g., ip-up). This can be useful when the name in argv[0]
    gets lost because the script is executed by an interpreter.

    New options 'strict-script-checks', 'nostrict-script-checks', 'strict-secrets-files' and
    'nostrict-secrets-files' have been added. The strict versions are the default, and the
    nostrict versions are privileged. 'strict-script-checks' enables checks on script files
    that are run as root (e.g., /etc/ppp/ip-up) to ensure that they are owned by root and not
    writable by group or other. 'strict-secrets-checks' enables checks on secrets files (such
    as /etc/ppp/chap-secrets) to ensure that they are not readable by group or other. Previously
    (and now with nostrict-secrets-checks) the check was done but only produced a warning; now by
    default pppd will refuse to use the file.

    For EAP-TLS and PEAP, the verification of the 'common name' in TLS certificates no longer
    stops the comparison at an embedded NUL character. The pppd man page now notes that the
    default verification mode is 'none' and that the 'suffix' verification mode doesn't check
    for a '.' in the common name before the matched suffix (this was the behaviour previously
    but the man page was incorrect).

    Many more options are now privileged, in particular all of the RADIUS plugin options, and
    almost all the options relating to EAP-TLS and PEAP.

    OpenSSL engine support in EAP-TLS is disabled by default, since engine support in OpenSSL 3 is
    deprecated. If you need it, use the --enable-openssl-engine flag to configure.

    Pppd can now run as non-root as long as it has the CAP_NET_ADMIN capability. In that case,
    scripts are run as the invoking user, the user can use privileged options (provided the pppd
    binary was not marked as setuid or with additional capabilities), and the ownership checks
    use the user's effective UID rather than 0.

    Various pppd options that take an integer argument now enforce sensible limits on the value.
    This aids in avoiding edge cases where vulnerabilities may lurk.

    EAP-SRP support has been removed. Previously it was disabled by default.

    Extra length checks have been added to ensure that the pppd code doesn't access outside the
    bounds of received packets, even when such accesses were harmless (i.e. within the bounds
    of the array that the received packet was stored in, and not affecting any result).

    Various other minor bug fixes and improvements, including man page updates.

Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
---
 meta/recipes-connectivity/ppp/{ppp_2.5.3.bb => ppp_2.5.4.bb} | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)
 rename meta/recipes-connectivity/ppp/{ppp_2.5.3.bb => ppp_2.5.4.bb} (98%)

diff --git a/meta/recipes-connectivity/ppp/ppp_2.5.3.bb b/meta/recipes-connectivity/ppp/ppp_2.5.4.bb
similarity index 98%
rename from meta/recipes-connectivity/ppp/ppp_2.5.3.bb
rename to meta/recipes-connectivity/ppp/ppp_2.5.4.bb
index 18157821690..6f7977ece37 100644
--- a/meta/recipes-connectivity/ppp/ppp_2.5.3.bb
+++ b/meta/recipes-connectivity/ppp/ppp_2.5.4.bb
@@ -25,7 +25,7 @@ SRC_URI = "https://download.samba.org/pub/${BPN}/${BP}.tar.gz \
            file://ppp@.service \
            "
 
-SRC_URI[sha256sum] = "ddda28dec8aca99a403ab6070d94ffd2b17d63e9a4c5509158e99e148f572d4f"
+SRC_URI[sha256sum] = "379a630a40d858a1347f6592d671791dde12101697a743ef9900012f3765be31"
 
 inherit autotools pkgconfig systemd
 


  parent reply	other threads:[~2026-09-21  7:07 UTC|newest]

Thread overview: 20+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-21  7:06 [PATCH 01/20] ffmpeg: upgrade 9.0.1 -> 9.0.2 Richard Purdie
2026-09-21  7:06 ` [PATCH 02/20] librsvg: upgrade 2.63.0 -> 2.63.2 Richard Purdie
2026-09-21  7:06 ` [PATCH 03/20] python3-dtschema: upgrade 2026.6 -> 2026.9 Richard Purdie
2026-09-21  7:23   ` Patchtest results for " patchtest
2026-09-21  7:06 ` [PATCH 04/20] python3-uv-build: upgrade 0.12.13 -> 0.12.17 Richard Purdie
2026-09-21  7:06 ` [PATCH 05/20] xxhash: upgrade 0.8.3 -> 0.8.4 Richard Purdie
2026-09-21  7:23   ` Patchtest results for " patchtest
2026-09-21  7:06 ` [PATCH 06/20] python3-hatchling: upgrade 1.32.0 -> 1.32.3 Richard Purdie
2026-09-21  7:06 ` [PATCH 07/20] python3-idna: upgrade 3.19 -> 3.20 Richard Purdie
2026-09-21  7:06 ` [PATCH 08/20] python3-pdm: upgrade 2.29.1 -> 2.29.2 Richard Purdie
2026-09-21  7:06 ` [PATCH 09/20] python3-wcwidth: upgrade 0.8.3 -> 0.8.4 Richard Purdie
2026-09-21  7:06 ` [PATCH 10/20] barebox-tools: upgrade 2026.08.0 -> 2026.09.0 Richard Purdie
2026-09-21  7:06 ` [PATCH 11/20] bind: upgrade 9.20.27 -> 9.20.29 Richard Purdie
2026-09-21  7:06 ` [PATCH 12/20] mesa: upgrade 26.2.2 -> 26.2.3 Richard Purdie
2026-09-21  7:06 ` [PATCH 13/20] python3-pdm-build-locked: upgrade 0.3.7 -> 0.3.8 Richard Purdie
2026-09-21  7:06 ` [PATCH 14/20] python3-vcs-versioning: upgrade 2.4.0 -> 2.4.1 Richard Purdie
2026-09-21  7:06 ` [PATCH 15/20] fastfloat: upgrade 8.2.10 -> 8.3.0 Richard Purdie
2026-09-21  7:06 ` Richard Purdie [this message]
2026-09-21  7:06 ` [PATCH 17/20] python3-urllib3: upgrade 2.7.0 -> 2.8.0 Richard Purdie
2026-09-21  7:06 ` [PATCH 18/20] ruby: upgrade 4.0.6 -> 4.0.7 Richard Purdie

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260921070656.521680-16-richard.purdie@linuxfoundation.org \
    --to=richard.purdie@linuxfoundation.org \
    --cc=openembedded-core@lists.openembedded.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox