Re: [Buildroot] [PATCH 1/1] package/dropbear: security bump version to 2026.93
Julien Olivain via buildroot <[email protected]>
| Newsgroups | net.busybox.buildroot |
|---|---|
| Message-ID | <[email protected]> |
On 21/07/2026 19:59, Bernd Kuhls wrote: > https://matt.ucc.asn.au/dropbear/CHANGES > > - Security: Fix a use-after-free in X11 forwarding that could possibly > lead > to memory corruption. This is vulnerable to authenticated users if > X11 > forwarding is enabled. By default X11 forwarding is not built. > In 2026.89 the server is running as the authenticated user for X11 > forwarding, in earlier versions it runs as root. > This removes X11 "single connection" which has probably never been > used. > Reported by @peter-pe > > https://github.com/mkj/dropbear/commit/882f83806d5e133037cd28e954a878984ef7b9c4 > > Added patch to fix build errors which would be introduced by this bump: > https://github.com/mkj/dropbear/commit/86baa66fc934bb55a911eacec28d93d86fb0e6f8 > > Signed-off-by: Bernd Kuhls <[email protected]> Applied to master, thanks. _______________________________________________ buildroot mailing list [email protected] https://lists.buildroot.org/mailman/listinfo/buildroot