Re: [Buildroot] [PATCH] package/unrar: bump to version 7.2.7
Shubham Chakraborty <[email protected]>
| Newsgroups | net.busybox.buildroot |
|---|---|
| Message-ID | <CABvxksxYWcRQHZospOPy=dCRWqWkp6Cf2J8FpsDnqZZ0ObNY4Q@mail.gmail.com> |
Hi Thomas, The Buildroot autobuilder reports that CVE-2022-30333 affects unrar in the stable branches (specifically 2026.05.x, 2026.02.x, and 2025.02.x), as shown in the automated emails. Best regards, Shubham Chakraborty On Tue, 18 Aug 2026, 1:56 am Thomas Petazzoni, <[email protected]> wrote: > Hello, > > On Mon, Jul 13, 2026 at 05:07:07PM +0530, Shubham Chakraborty wrote: > > Upstream does not provide a per-release change log for the unrarsrc > > tarball itself, only for WinRAR. Fixed from Repology/rarlab that > > 7.2.7 is the latest unrarsrc release available at: > > > > - https://www.rarlab.com/rar/unrarsrc-7.2.7.tar.gz > > - https://www.rarlab.com/WhatsNew.txt > > > > While at it, mark CVE-2022-30333 as ignored, since it was already > > fixed upstream in 6.1.2 and is falsely flagged by buildroot autobuilder > for this > > package. > > > > Fixes CVE-2022-30333 (false positive, patched since 6.1.2/6.1.7). > > - https://nvd.nist.gov/vuln/detail/CVE-2022-30333 > > - https://security-tracker.debian.org/tracker/CVE-2022-30333 > > Where do you see as being flagged affecting unrar in Buildroot? The > NVD database says this CVE affects versions up to 6.12. We're using > 7.2.7, so we're not vulnerable. > > https://security.buildroot.org/master/component/unrar doesn't show any > known vulnerability. > > Could you clarify? > > Best regards, > > Thomas > -- > Thomas Petazzoni, co-owner and CEO, Bootlin > Embedded Linux and Kernel engineering and training > https://bootlin.com > _______________________________________________ buildroot mailing list [email protected] https://lists.buildroot.org/mailman/listinfo/buildroot