Re: [Buildroot] [PATCH 1/1] package/fluidsynth: security bump to version 2.5.7
Peter Korsgaard <[email protected]>
| Newsgroups | net.busybox.buildroot |
|---|---|
| Message-ID | <[email protected]> |
>>>>> "Julien" == Julien Olivain via buildroot <[email protected]> writes: > For change log since v2.4.7, see: > https://github.com/FluidSynth/fluidsynth/releases > According to: > https://github.com/FluidSynth/fluidsynth/blob/master/doc/wiki/ChangeLog.md > FluidSynth 2.5.6 fixes: > CVE-2026-58264 - a heap-based buffer overrun in command handler (GHSA-mqmq-w63q-cj94) > CVE-2026-61714 - a heap-based buffer overflow in MIDI player (GHSA-976m-35rw-h3m6) > CVE-2026-61721 - a heap-based buffer overrun for DLS samples (GHSA-59ph-rx8r-8p4j) > CVE-2026-61723 - a DLS ptbl chunk integer overflow (GHSA-r4mc-v3p8-pv47) > CVE-2026-61722 - a DLS articulation chunk integer overflow (GHSA-hp72-35pr-6h6r) > CVE-2026-61720 - a SF2 DMOD chunk integer underflow (GHSA-rmc4-c8hw-455w) > FluidSynth 2.5.2 fixes: > CVE-2025-68617 - a heap-based use-after-free involving DLS files (GHSA-ffw2-xvvp-39ch) > SDL2 audio support was removed upstream in commit: > https://github.com/FluidSynth/fluidsynth/commit/89145b004a44a53e734b6bf82a73cef255baef5d > It was replaced by the newer SDL3. This commit reflects that change > (update option name and comments, add legacy option entry). > Also, dynamic library dependency was added in Buildroot commit: > https://gitlab.com/buildroot.org/buildroot/-/commit/111a1c7091aed6f9da03c2a095bcc2f50a1ad32c > This commot removes the duplicate dependency for SDL3. > FluidSynth also added a native DLS soundfont support in: > https://github.com/FluidSynth/fluidsynth/commit/c959f8d208bbad9e396dfb745285806b5a4c5a07 > It is enabled by default and uses C++17. This commit adds a new > option with a dependency on gcc >= 7. > The license option hash is also updated, after the FSF address > update in: > https://github.com/FluidSynth/fluidsynth/commit/db42fa333baf1cb7c60556ab75ad1e592c850f68 > Signed-off-by: Julien Olivain <[email protected]> > --- > Patch tested in: > https://gitlab.com/jolivain/buildroot/-/pipelines/2745501844 > Note to the LTS maintainers: > The CVEs fixed here are a bit hard to backport. > This new FluidSynth version also depends of a new SDL3 library. > I let you decide what to do (update the package in LTS, do nothing, > try to backport, or remove the package). What would be your opinion > in such a case? Committed, thanks. -- Bye, Peter Korsgaard _______________________________________________ buildroot mailing list [email protected] https://lists.buildroot.org/mailman/listinfo/buildroot