Re: [Buildroot] [PATCH] package/unrar: bump to version 7.2.7

Thomas Petazzoni via buildroot <[email protected]>
Newsgroups net.busybox.buildroot
Message-ID <aoNuO__aQMnMl0ni@windsurf>
Hello,

On Mon, Jul 13, 2026 at 05:07:07PM +0530, Shubham Chakraborty wrote:
> Upstream does not provide a per-release change log for the unrarsrc
> tarball itself, only for WinRAR. Fixed from Repology/rarlab that
> 7.2.7 is the latest unrarsrc release available at:
> 
>  - https://www.rarlab.com/rar/unrarsrc-7.2.7.tar.gz
>  - https://www.rarlab.com/WhatsNew.txt
> 
> While at it, mark CVE-2022-30333 as ignored, since it was already
> fixed upstream in 6.1.2 and is falsely flagged by buildroot autobuilder for this
> package.
> 
> Fixes CVE-2022-30333 (false positive, patched since 6.1.2/6.1.7).
>  - https://nvd.nist.gov/vuln/detail/CVE-2022-30333
>  - https://security-tracker.debian.org/tracker/CVE-2022-30333

Where do you see as being flagged affecting unrar in Buildroot? The
NVD database says this CVE affects versions up to 6.12. We're using
7.2.7, so we're not vulnerable.

https://security.buildroot.org/master/component/unrar doesn't show any
known vulnerability.

Could you clarify?

Best regards,

Thomas
-- 
Thomas Petazzoni, co-owner and CEO, Bootlin
Embedded Linux and Kernel engineering and training
https://bootlin.com
_______________________________________________
buildroot mailing list
[email protected]
https://lists.buildroot.org/mailman/listinfo/buildroot
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.