Files
buildroot/package/swupdate
Giulio Benetti 0c6595aaac package/swupdate: security bump to version 2026.05
Fixes:
* CVE-2023-7216 [1]
  A path traversal vulnerability was found in the CPIO utility. This
  issue could allow a remote unauthenticated attacker to trick a user into
  opening a specially crafted archive. During the extraction process, the
  archiver could follow symlinks outside of the intended directory, which
  could be utilized to run arbitrary commands on the target system.
* CVE-2026-28525 [2]
  SWUpdate contains an integer underflow vulnerability in the multipart
  upload parser in mongoose_multipart.c that allows unauthenticated
  attackers to cause a denial of service by sending a crafted HTTP POST
  request to /upload with a malformed multipart boundary and controlled
  TCP stream timing. Attackers can trigger an integer underflow in the
  mg_http_multipart_continue_wait_for_chunk() function when the buffer
  length falls within a specific range, causing an out-of-bounds heap read
  that writes data beyond the allocated receive buffer to a local IPC
  socket.

For full release notes, see:
https://github.com/sbabic/swupdate/releases/tag/2026.05

Remove patch that has been merged upstream for this release.

[1] https://github.com/advisories/GHSA-v9vx-4mxw-76j2
[2] https://github.com/advisories/GHSA-hggv-rg65-qf4h

Signed-off-by: Giulio Benetti <giulio.benetti@benettiengineering.com>
Signed-off-by: Marcus Hoffmann <buildroot@bubu1.eu>
2026-06-15 21:49:01 +02:00
..