[Buildroot] libmicrohttpd: unrelated CVEs

Yegor Yefremov via buildroot <[email protected]> Tue, 28 Jul 2026 11:58:37 +0200
Newsgroups net.busybox.buildroot
Message-ID <CAGm1_kv07Rcwy5km56rbWHQBmJauhDaCh2uwcnq5izC_pH-oaQ@mail.gmail.com>
Hi all,

when generating a SBOM (pkg-stats), libmicrohttpd lists two CVEs:

https://security-tracker.debian.org/tracker/CVE-2025-59777
https://security-tracker.debian.org/tracker/CVE-2025-62689

According to the description, only version 1.0.2 and earlier are impacted:

NULL pointer dereference vulnerability exists in GNU libmicrohttpd
v1.0.2 and earlier.

The problem was only triggered when --enable-experimental was
supplied. This is not the case with BR configuration.

Should LIBFOO_IGNORE_CVES be applied to both of them?

Best regards,
Yegor
_______________________________________________
buildroot mailing list
[email protected]
https://lists.buildroot.org/mailman/listinfo/buildroot