Re: [Buildroot] [PATCH] package/unrar: bump to version 7.2.7
Thomas Petazzoni via buildroot <[email protected]>
| Newsgroups | net.busybox.buildroot |
|---|---|
| Message-ID | <aoNuO__aQMnMl0ni@windsurf> |
Hello, On Mon, Jul 13, 2026 at 05:07:07PM +0530, Shubham Chakraborty wrote: > Upstream does not provide a per-release change log for the unrarsrc > tarball itself, only for WinRAR. Fixed from Repology/rarlab that > 7.2.7 is the latest unrarsrc release available at: > > - https://www.rarlab.com/rar/unrarsrc-7.2.7.tar.gz > - https://www.rarlab.com/WhatsNew.txt > > While at it, mark CVE-2022-30333 as ignored, since it was already > fixed upstream in 6.1.2 and is falsely flagged by buildroot autobuilder for this > package. > > Fixes CVE-2022-30333 (false positive, patched since 6.1.2/6.1.7). > - https://nvd.nist.gov/vuln/detail/CVE-2022-30333 > - https://security-tracker.debian.org/tracker/CVE-2022-30333 Where do you see as being flagged affecting unrar in Buildroot? The NVD database says this CVE affects versions up to 6.12. We're using 7.2.7, so we're not vulnerable. https://security.buildroot.org/master/component/unrar doesn't show any known vulnerability. Could you clarify? Best regards, Thomas -- Thomas Petazzoni, co-owner and CEO, Bootlin Embedded Linux and Kernel engineering and training https://bootlin.com _______________________________________________ buildroot mailing list [email protected] https://lists.buildroot.org/mailman/listinfo/buildroot