From 35b57a0787a07b71051a180ebe2ebaafca989ee7 Mon Sep 17 00:00:00 2001 From: Bernd Kuhls Date: Thu, 4 Jun 2026 20:53:41 +0200 Subject: [PATCH] package/libde265: security bump version to 1.1.1 MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit https://github.com/strukturag/libde265/releases/tag/v1.1.1 Fixes the following security problems: CVE TBD (GHSA-ccfw-29x7-rrx3) - Pixel accessor signed integer overflow causes heap OOB read/write CVE TBD (GHSA-j2qq-x2xq-g9wr) - SAO sequential filter heap buffer overflow via signed integer overflow This version bump includes upstream commit https://github.com/strukturag/libde265/commit/9ded37bda4e9fbc2570c0bd710ee407636bc4f34 which uses constexpr() and causes a build error caught by the Gitlab pipelines with the gcc-6-based bootlin-aarch64-glibc-old defconfig: /builds/bkuhls/buildroot/br-test-pkg/bootlin-aarch64-glibc-old/build/libde265-1.1.1/libde265/deblock.cc:594:14: error: expected ‘(’ before ‘constexpr’ if constexpr (sizeof(pixel_t)==1) { Therefore we need to raise the minimum gcc version according to https://gcc.gnu.org/projects/cxx-status.html#cxx17 to gcc 7. Signed-off-by: Bernd Kuhls Signed-off-by: Julien Olivain --- package/libde265/Config.in | 8 ++++++-- package/libde265/libde265.hash | 4 ++-- package/libde265/libde265.mk | 2 +- 3 files changed, 9 insertions(+), 5 deletions(-) diff --git a/package/libde265/Config.in b/package/libde265/Config.in index 2436beff41..ca91b0a226 100644 --- a/package/libde265/Config.in +++ b/package/libde265/Config.in @@ -1,6 +1,7 @@ config BR2_PACKAGE_LIBDE265 bool "libde265" depends on BR2_INSTALL_LIBSTDCPP + depends on BR2_TOOLCHAIN_GCC_AT_LEAST_7 # C++17 depends on BR2_TOOLCHAIN_HAS_THREADS help libde265 is an open source implementation of the h.265 video @@ -8,5 +9,8 @@ config BR2_PACKAGE_LIBDE265 https://github.com/strukturag/libde265 -comment "libde265 needs a toolchain w/ threads, C++" - depends on !BR2_TOOLCHAIN_HAS_THREADS || !BR2_INSTALL_LIBSTDCPP +comment "libde265 needs a toolchain w/ threads, C++, gcc >= 7" + depends on \ + !BR2_TOOLCHAIN_HAS_THREADS || \ + !BR2_INSTALL_LIBSTDCPP || \ + !BR2_TOOLCHAIN_GCC_AT_LEAST_7 diff --git a/package/libde265/libde265.hash b/package/libde265/libde265.hash index 71a0221089..0385364e2e 100644 --- a/package/libde265/libde265.hash +++ b/package/libde265/libde265.hash @@ -1,4 +1,4 @@ -# From https://github.com/strukturag/libde265/releases/tag/v1.1.0 -sha256 afc19dd28e2fc523de5952bba5224ee1d28e286c72436d2843df126cca1181fd libde265-1.1.0.tar.gz +# From https://github.com/strukturag/libde265/releases/tag/v1.1.1 +sha256 fd48a927e94ed74fc7ce8829d222b9d8599fcbfe8b6448ba66705babc56ab219 libde265-1.1.1.tar.gz # Locally computed sha256 02cc1585a20677992e0ba578fa692635dc193735f2691dc81de924b51c4e8020 COPYING diff --git a/package/libde265/libde265.mk b/package/libde265/libde265.mk index 2a10dce6d0..81ffb39501 100644 --- a/package/libde265/libde265.mk +++ b/package/libde265/libde265.mk @@ -4,7 +4,7 @@ # ################################################################################ -LIBDE265_VERSION = 1.1.0 +LIBDE265_VERSION = 1.1.1 LIBDE265_SITE = https://github.com/strukturag/libde265/releases/download/v$(LIBDE265_VERSION) LIBDE265_LICENSE = LGPL-3.0+ LIBDE265_LICENSE_FILES = COPYING