[Buildroot] Buildroot 2026.05.2 released

Arnout Vandecappelle via buildroot <[email protected]>
Newsgroups net.busybox.buildroot
Message-ID <[email protected]>
Hi,

Buildroot is a simple tool for creating complete embedded Linux systems
(https://buildroot.org).

Buildroot 2026.05.2 is released - Go download it at:

https://buildroot.org/downloads/buildroot-2026.05.2.tar.gz

or

https://buildroot.org/downloads/buildroot-2026.05.2.tar.xz

Or get it from Git:

https://gitlab.com/buildroot.org/buildroot.git (2026.05.2 tag)

Buildroot 2026.05.2 is a bugfix release, fixing a number of important /
security related issues discovered since the 2026.05.1 release.

Important / security related fixes:

apr-util: CVE-2025-49506, CVE-2026-32327, CVE-2026-34191,
  CVE-2026-34501, CVE-2026-34502
bind: CVE-2026-10723, CVE-2026-10822, CVE-2026-11331, CVE-2026-11605,
  CVE-2026-11622, CVE-2026-11721, CVE-2026-12617, CVE-2026-13204,
  CVE-2026-13321
botan: CVE-2026-32877, CVE-2026-32883, CVE-2026-32884, CVE-2026-34580,
  CVE-2026-34582
busybox: CVE-2024-58251
clamav: CVE-2025-8088, CVE-2026-20337, CVE-2026-20338, CVE-2026-20339,
  CVE-2026-20345, CVE-2026-20346, CVE-2026-20347, CVE-2026-20348
containerd: CVE-2026-35469, CVE-2026-46680, CVE-2026-47262,
  CVE-2026-53488
dracut: CVE-2026-6893
dropbear: (no CVE assigned)
exim: GCVE-25-2026-07-45-1, CVE-2026-66140, CVE-2026-66141
expat: CVE-2026-72522
glibc: CVE-2026-6368
go: CVE-2026-39822
intel-microcode: CVE-2025-31936, CVE-2025-31938, CVE-2025-35973,
  CVE-2026-20707, CVE-2026-20713, CVE-2026-20716, CVE-2026-20760,
  CVE-2026-20917
libarchive: (no CVE assigned)
libass: CVE-2026-61626, CVE-2026-61627
libgit2: CVE-2026-53583, CVE-2026-53584, CVE-2026-53585,
  CVE-2026-53586, CVE-2026-53587
libglib2: CVE-2025-13601, CVE-2025-14087, CVE-2025-14512,
  CVE-2026-1484, CVE-2026-1485, CVE-2026-1489, CVE-2026-15588,
  CVE-2026-58010, CVE-2026-58011, CVE-2026-58012, CVE-2026-58013,
  CVE-2026-58014, CVE-2026-58015
libheif: CVE-2026-62289, CVE-2026-62291, CVE-2026-62292,
  CVE-2026-62377, GHSA-46rp-pcq2-rpmr, GHSA-73p7-m7gg-w2jv,
  GHSA-9ww4-9v47-m7pj, GHSA-jc8f-p23p-5hjg, GHSA-xpw3-9rhw-482x
libmodsecurity: CVE-2026-52747, CVE-2026-52761
libssh: CVE-2026-15370, CVE-2026-59843, CVE-2026-59844, CVE-2026-59845,
  CVE-2026-59846, CVE-2026-59847, CVE-2026-59848, CVE-2026-59849,
  CVE-2026-59850
localedef: CVE-2026-6368
memcached: (no CVE assigned)
ntfs-3g: CVE-2026-42616, CVE-2026-42617, CVE-2026-42618,
  CVE-2026-46569, CVE-2026-46570, CVE-2026-46571, CVE-2026-46572,
  CVE-2026-56135, CVE-2026-56136
openssh: (no CVE assigned)
openvpn: CVE-2026-63649, CVE-2026-63650
perl: CVE-2026-13221, CVE-2026-57432, CVE-2026-8376
php: CVE-2026-17543, CVE-2026-17544, CVE-2026-7260, CVE-2026-9672
postgresql: CVE-2026-14662, CVE-2026-14663, CVE-2026-14664,
  CVE-2026-14666, CVE-2026-14668, CVE-2026-14669, CVE-2026-14670,
  CVE-2026-14671, CVE-2026-14672, CVE-2026-14673, CVE-2026-14676,
  CVE-2026-14677, CVE-2026-14678, CVE-2026-14679, CVE-2026-14680,
  CVE-2026-14681, CVE-2026-15741, CVE-2026-15742, CVE-2026-16238,
  CVE-2026-16239, CVE-2026-16241, CVE-2026-18024, CVE-2026-18408,
  CVE-2026-19385, CVE-2026-6464, CVE-2026-6469, CVE-2026-6470,
  CVE-2026-6471
python3: CVE-2026-0864, CVE-2026-11972, CVE-2026-12003, CVE-2026-15308,
  CVE-2026-4360
rsync: CVE-2026-53783, CVE-2026-53784, CVE-2026-53785, CVE-2026-53786,
  CVE-2026-53788, CVE-2026-53789, CVE-2026-53790, CVE-2026-53791,
  CVE-2026-53792, CVE-2026-53793, CVE-2026-53794, CVE-2026-53795,
  CVE-2026-53796, CVE-2026-53797, CVE-2026-53798, CVE-2026-53799,
  CVE-2026-53800, CVE-2026-53801, CVE-2026-53802, CVE-2026-53803,
  CVE-2026-70452, CVE-2026-70453, CVE-2026-70454, CVE-2026-70455,
  CVE-2026-70456, CVE-2026-70457, CVE-2026-70458, CVE-2026-70459,
  CVE-2026-70460, CVE-2026-70461, CVE-2026-70462, CVE-2026-70463,
  CVE-2026-70464
samba4: CVE-2026-58216, CVE-2026-58218, CVE-2026-58221, CVE-2026-58222,
  CVE-2026-58224, CVE-2026-6949
screen: (no CVE assigned)
ser2net: GHSA-cgh5-39mg-vhfr
socat: CVE-2026-56123
stunnel: CVE-2026-70367, CVE-2026-70368
syslog-ng: CVE-2026-39879
vim: CVE-2026-28417, CVE-2026-28418, CVE-2026-28419, CVE-2026-28420,
  CVE-2026-28421, CVE-2026-28422, CVE-2026-32249, CVE-2026-33412,
  CVE-2026-34714, CVE-2026-34982, CVE-2026-35177, CVE-2026-39881,
  CVE-2026-41411, CVE-2026-42307, CVE-2026-44656, CVE-2026-45130,
  CVE-2026-46483, CVE-2026-47162, CVE-2026-47167, CVE-2026-52858,
  CVE-2026-52859, CVE-2026-52860, CVE-2026-55693, CVE-2026-55892,
  CVE-2026-55895, CVE-2026-57451, CVE-2026-57452, CVE-2026-57453,
  CVE-2026-57455, CVE-2026-57456, CVE-2026-59856, CVE-2026-59857,
  CVE-2026-59858
wpa_supplicant: (no CVE assigned)
xlib_libXfont2: CVE-2026-56001, CVE-2026-56002, CVE-2026-56003
xserver_xorg-server: CVE-2026-55999, CVE-2026-56000
xwayland: CVE-2026-55999, CVE-2026-56000

Toolchain:

- gcc: fix mips/glibc build issue
- glibc: bump to 2.43-49-g8017bcfc4d
- linux-headers: bump to 5.10.265, 5.15.216, 6.1.183, 6.6.152,
  6.12.104, 6.18.45, 7.0.14
- toolchain-buildroot: drop Synopsys ARC specific versions
- toolchain-external: drop Synopsys ARC toolchain

Infrastructure updates/fixes:

- Add license information for skeleton packages
- Make docker image reproducible again
- New runtime tests for guile, libgpiod2, mdnsd, php, python-pydal

Updated defconfigs: freescale_imx91frdm, freescale_imx93frdm

Removed defconfigs: acmesystems_aria_g25_{128mb, 256mb},
  acmesystems_arietta_g25_{128mb, 256mb}, s6lx9_microboard, ts4900,
  ts5500

Removed packages: argparse, ts4900-fpga

Updated / fixed packages: amazon-ecr-credential-helper, apache,
  apr-util, arm-trusted-firmware, armadillo, at-spi2-core, atop, bind,
  binutils, bitcoin, botan, busybox, cantarell, cifs-utils, clamav,
  containerd, cramfs, dbus-broker, docker-credential-acr-env,
  docker-credential-gcr, dracut, dropbear, environment-setup, exim,
  expat, gcc, glibc, go, guile, gvfs, ifupdown-scripts, igt-gpu-tools,
  initscripts, intel-microcode, libarchive, libass, libcamera, libgee,
  libgit2, libglib2, libgpg-error, libgtk4, libgudev, libheif,
  libmicrohttpd, libmodsecurity, libnpupnp, libpeas, librsvg,
  libsecret, libsoup, libsoup3, libssh, libvpl, linux, linux-headers,
  localedef, mbedtls, memcached, mini-snmpd, mosquitto, nettle,
  network-manager, ntfs-3g, ogre, open62541, openblas, openssh,
  openvpn, optee-os, p11-kit, pahole, perl, php, postgresql,
  python-paho-mqtt, python-pydal, python-web2py, python3, quickjs,
  redis, rsync, rygel, samba4, screen, ser2net, socat, stunnel,
  syslog-ng, toolchain-external, uboot-tools, uclibc, ugetty,
  urandom-scripts, usbutils, vim, wpa_supplicant, xlib_libXfont2,
  xserver_xorg-server, xwayland, xz

For more details, see the CHANGES file:

https://gitlab.com/buildroot.org/buildroot/-/blob/2026.05.2/CHANGES

Users of the affected packages are strongly encouraged to upgrade.

Many thanks to all the people contributing to this release:

git shortlog -s -n 2026.05.1..

    42	Bernd Kuhls
    17	Fiona Klute (Othermo GmbH)
    16	Fiona Klute
     9	Yann E. MORIN
     8	Julien Olivain
     8	Waldemar Brodkorb
     7	Romain Naour
     7	Thomas Perale
     7	Titouan Christophe
     6	Thomas Petazzoni
     3	Francois Perrad
     3	Nicolas Cavallari
     3	Quentin Schulz
     2	Arnout Vandecappelle
     2	Dario Binacchi
     2	Franciszek Stachura
     2	Joachim Wiberg
     2	Yegor Yefremov
     1	Alexis Lothoré
     1	Alsey Coleman Miller
     1	Baruch Siach
     1	Bernard Gautier
     1	Christian Stewart
     1	Florian Larysch
     1	Frank Vanbever
     1	James Hilliard
     1	Jean-Michel Hautbois
     1	Laurent Pinchart
     1	Mattia Narducci
     1	Michael Nosthoff
     1	Michele Comignano
     1	Neal Frager via buildroot
     1	Pedro Aguilar
     1	Shubham Chakraborty

Regards,
Arnout
_______________________________________________
buildroot mailing list
[email protected]
https://lists.buildroot.org/mailman/listinfo/buildroot
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.