[Buildroot] libmicrohttpd: unrelated CVEs
Yegor Yefremov via buildroot <[email protected]> Tue, 28 Jul 2026 11:58:37 +0200
| Newsgroups | net.busybox.buildroot |
|---|---|
| Message-ID | <CAGm1_kv07Rcwy5km56rbWHQBmJauhDaCh2uwcnq5izC_pH-oaQ@mail.gmail.com> |
Hi all, when generating a SBOM (pkg-stats), libmicrohttpd lists two CVEs: https://security-tracker.debian.org/tracker/CVE-2025-59777 https://security-tracker.debian.org/tracker/CVE-2025-62689 According to the description, only version 1.0.2 and earlier are impacted: NULL pointer dereference vulnerability exists in GNU libmicrohttpd v1.0.2 and earlier. The problem was only triggered when --enable-experimental was supplied. This is not the case with BR configuration. Should LIBFOO_IGNORE_CVES be applied to both of them? Best regards, Yegor _______________________________________________ buildroot mailing list [email protected] https://lists.buildroot.org/mailman/listinfo/buildroot