Go to file
Peter Korsgaard 7c3e9fbe12 package/{glibc, localedef}: security bump to 2.36-117
Fixes the following security issues:

CVE-2023-4527: If the system is configured in no-aaaa mode via
/etc/resolv.conf, getaddrinfo is called for the AF_UNSPEC address
family, and a DNS response is received over TCP that is larger than
2048 bytes, getaddrinfo may potentially disclose stack contents via
the returned address data, or crash.

CVE-2023-4806: When an NSS plugin only implements the
_gethostbyname2_r and _getcanonname_r callbacks, getaddrinfo could use
memory that was freed during buffer resizing, potentially causing a
crash or read or write to arbitrary memory.

CVE-2023-5156: The fix for CVE-2023-4806 introduced a memory leak when
an application calls getaddrinfo for AF_INET6 with AI_CANONNAME,
AI_ALL and AI_V4MAPPED flags set.

Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
Reviewed-by: Romain Naour <romain.naour@smile.fr>
Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
2023-09-30 16:15:44 +02:00
arch arch/Config.in.x86: drop AVX512 from alderlake 2023-08-30 12:54:00 +02:00
board board/orangepi*: update links in readme files 2023-09-24 23:15:39 +02:00
boot boot/grub2: backport fixes for numerous CVEs 2023-09-13 22:26:17 +02:00
configs configs/freescale_imx6qsabresd_defconfig: fix defconfig 2023-09-13 20:55:07 +02:00
docs docs/manual: add section to explain how to give credits to a sponsor 2023-09-26 09:55:31 +02:00
fs fs/cpio: allow users to provide their own dracut modules 2023-02-06 22:46:35 +01:00
linux {linux, linux-headers}: bump 4.{14, 19}.x / 5.{4, 10, 15}.x / 6.{1, 4}.x series 2023-09-30 12:23:51 +02:00
package package/{glibc, localedef}: security bump to 2.36-117 2023-09-30 16:15:44 +02:00
support Update for 2023.02.5 2023-09-27 13:52:12 +02:00
system system: Warn if systemd is used with kernel < 4.15 2023-02-07 22:51:26 +01:00
toolchain toolchain/helpers.mk: strengthen uClibc locale check 2023-09-14 10:28:28 +02:00
utils utils/getdeveloperlib.py: handle file removal 2023-09-15 19:50:55 +02:00
.checkpackageignore package/bluez5_utils: fix SysV init script 2023-03-20 10:03:40 +01:00
.clang-format .clang-format: initial import from Linux 5.15.6 2022-01-01 15:01:13 +01:00
.defconfig
.flake8
.gitignore
.gitlab-ci.yml support/misc/gitlab-ci.yml.in: retry a job only if it failed due to a runner issue 2023-09-13 21:28:23 +02:00
.shellcheckrc utils/check-package: improve shellcheck reproducibility 2022-07-25 23:52:47 +02:00
CHANGES Update for 2023.02.5 2023-09-27 13:52:12 +02:00
Config.in package/sam-ba: drop 32bit host lib requirement 2023-08-31 00:25:17 +02:00
Config.in.legacy Config.in.legacy: add missing binutils 2.36.x entry 2023-05-02 13:20:44 +02:00
COPYING
DEVELOPERS DEVELOPERS: sort entries of Neal Frager 2023-08-31 13:10:53 +02:00
Makefile Update for 2023.02.5 2023-09-27 13:52:12 +02:00
Makefile.legacy
README

Buildroot is a simple, efficient and easy-to-use tool to generate embedded
Linux systems through cross-compilation.

The documentation can be found in docs/manual. You can generate a text
document with 'make manual-text' and read output/docs/manual/manual.text.
Online documentation can be found at http://buildroot.org/docs.html

To build and use the buildroot stuff, do the following:

1) run 'make menuconfig'
2) select the target architecture and the packages you wish to compile
3) run 'make'
4) wait while it compiles
5) find the kernel, bootloader, root filesystem, etc. in output/images

You do not need to be root to build or run buildroot.  Have fun!

Buildroot comes with a basic configuration for a number of boards. Run
'make list-defconfigs' to view the list of provided configurations.

Please feed suggestions, bug reports, insults, and bribes back to the
buildroot mailing list: buildroot@buildroot.org
You can also find us on #buildroot on OFTC IRC.

If you would like to contribute patches, please read
https://buildroot.org/manual.html#submitting-patches