Re: [Buildroot] [PATCH] package/stunnel: security bump to 5.80
Titouan Christophe via buildroot <[email protected]>
| Newsgroups | net.busybox.buildroot |
|---|---|
| Message-ID | <[email protected]> |
On 9/08/26 15:04, Waldemar Brodkorb wrote: > Fixes following CVE's: > > CVE-2026-70368: Fixed an out-of-bounds memory > access triggered by logging attacker-controlled protocol messages longer > than 1,024 bytes (thanks to AISLE Research and Clemens Lang). > > CVE-2026-70367: Fixed a SOCKS server mode bypass of the localhost > destination filter using alternate local-address encodings and > interface-scoped IPv6 destinations (thanks to AISLE Research and Clemens > Lang). > > Complete Changelog is here: > https://www.stunnel.org/NEWS.html > > Signed-off-by: Waldemar Brodkorb <[email protected]> Applied to 2025.02.x and 2026.05.x, thanks ! _______________________________________________ buildroot mailing list [email protected] https://lists.buildroot.org/mailman/listinfo/buildroot