Re: [Buildroot] [PATCH 1/1] package/dropbear: security bump version to 2026.93

Julien Olivain via buildroot <[email protected]>
Newsgroups net.busybox.buildroot
Message-ID <[email protected]>
On 21/07/2026 19:59, Bernd Kuhls wrote:
> https://matt.ucc.asn.au/dropbear/CHANGES
> 
> - Security: Fix a use-after-free in X11 forwarding that could possibly 
> lead
>   to memory corruption. This is vulnerable to authenticated users if 
> X11
>   forwarding is enabled. By default X11 forwarding is not built.
>   In 2026.89 the server is running as the authenticated user for X11
>   forwarding, in earlier versions it runs as root.
>   This removes X11 "single connection" which has probably never been 
> used.
>   Reported by @peter-pe
>   
> https://github.com/mkj/dropbear/commit/882f83806d5e133037cd28e954a878984ef7b9c4
> 
> Added patch to fix build errors which would be introduced by this bump:
> https://github.com/mkj/dropbear/commit/86baa66fc934bb55a911eacec28d93d86fb0e6f8
> 
> Signed-off-by: Bernd Kuhls <[email protected]>

Applied to master, thanks.
_______________________________________________
buildroot mailing list
[email protected]
https://lists.buildroot.org/mailman/listinfo/buildroot
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.