Patch Detail
get:
Show a patch.
patch:
Update a patch.
put:
Update a patch.
GET /api/patches/2217153/?format=api
{ "id": 2217153, "url": "http://patchwork.ozlabs.org/api/patches/2217153/?format=api", "web_url": "http://patchwork.ozlabs.org/project/buildroot/patch/20260327175743.1982788-1-bernd@kuhls.net/", "project": { "id": 27, "url": "http://patchwork.ozlabs.org/api/projects/27/?format=api", "name": "Buildroot development", "link_name": "buildroot", "list_id": "buildroot.buildroot.org", "list_email": "buildroot@buildroot.org", "web_url": "", "scm_url": "", "webscm_url": "", "list_archive_url": "", "list_archive_url_format": "", "commit_url_format": "" }, "msgid": "<20260327175743.1982788-1-bernd@kuhls.net>", "list_archive_url": null, "date": "2026-03-27T17:57:43", "name": "[1/1] package/libpng: security bump to version 1.6.56", "commit_ref": null, "pull_url": null, "state": "accepted", "archived": false, "hash": "cb00edac74cbd1e90243052533e9d9ec7d51d0f8", "submitter": { "id": 86624, "url": "http://patchwork.ozlabs.org/api/people/86624/?format=api", "name": "Bernd Kuhls", "email": "bernd@kuhls.net" }, "delegate": { "id": 89618, "url": "http://patchwork.ozlabs.org/api/users/89618/?format=api", "username": "juju", "first_name": "Julien", "last_name": "Olivain", "email": "juju@cotds.org" }, "mbox": "http://patchwork.ozlabs.org/project/buildroot/patch/20260327175743.1982788-1-bernd@kuhls.net/mbox/", "series": [ { "id": 497814, "url": "http://patchwork.ozlabs.org/api/series/497814/?format=api", "web_url": "http://patchwork.ozlabs.org/project/buildroot/list/?series=497814", "date": "2026-03-27T17:57:43", "name": "[1/1] package/libpng: security bump to version 1.6.56", "version": 1, "mbox": "http://patchwork.ozlabs.org/series/497814/mbox/" } ], "comments": "http://patchwork.ozlabs.org/api/patches/2217153/comments/", "check": "pending", "checks": "http://patchwork.ozlabs.org/api/patches/2217153/checks/", "tags": {}, "related": [], "headers": { "Return-Path": "<buildroot-bounces@buildroot.org>", "X-Original-To": [ "incoming-buildroot@patchwork.ozlabs.org", "buildroot@buildroot.org" ], "Delivered-To": [ "patchwork-incoming-buildroot@legolas.ozlabs.org", "buildroot@buildroot.org" ], "Authentication-Results": [ "legolas.ozlabs.org;\n\tdkim=pass (2048-bit key;\n unprotected) header.d=buildroot.org header.i=@buildroot.org\n header.a=rsa-sha256 header.s=default header.b=HjT2ROMb;\n\tdkim-atps=neutral", "legolas.ozlabs.org;\n spf=pass (sender SPF authorized) smtp.mailfrom=buildroot.org\n (client-ip=2605:bc80:3010::137; helo=smtp4.osuosl.org;\n envelope-from=buildroot-bounces@buildroot.org; receiver=patchwork.ozlabs.org)" ], "Received": [ "from smtp4.osuosl.org (smtp4.osuosl.org [IPv6:2605:bc80:3010::137])\n\t(using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits)\n\t key-exchange x25519 server-signature ECDSA (secp384r1) server-digest SHA384)\n\t(No client certificate requested)\n\tby legolas.ozlabs.org (Postfix) with ESMTPS id 4fj7f86xshz1y1P\n\tfor <incoming-buildroot@patchwork.ozlabs.org>;\n Sat, 28 Mar 2026 04:57:52 +1100 (AEDT)", "from localhost (localhost [127.0.0.1])\n\tby smtp4.osuosl.org (Postfix) with ESMTP id 676C241165;\n\tFri, 27 Mar 2026 17:57:50 +0000 (UTC)", "from smtp4.osuosl.org ([127.0.0.1])\n by localhost (smtp4.osuosl.org [127.0.0.1]) (amavis, port 10024) with ESMTP\n id 5GBbVQJiZoUf; Fri, 27 Mar 2026 17:57:48 +0000 (UTC)", "from lists1.osuosl.org (lists1.osuosl.org [140.211.166.142])\n\tby smtp4.osuosl.org (Postfix) with ESMTP id F03284115C;\n\tFri, 27 Mar 2026 17:57:47 +0000 (UTC)", "from smtp3.osuosl.org (smtp3.osuosl.org [IPv6:2605:bc80:3010::136])\n by lists1.osuosl.org (Postfix) with ESMTP id 486CD2AA\n for <buildroot@buildroot.org>; Fri, 27 Mar 2026 17:57:46 +0000 (UTC)", "from localhost (localhost [127.0.0.1])\n by smtp3.osuosl.org (Postfix) with ESMTP id 39EE060F9F\n for <buildroot@buildroot.org>; Fri, 27 Mar 2026 17:57:46 +0000 (UTC)", "from smtp3.osuosl.org ([127.0.0.1])\n by localhost (smtp3.osuosl.org [127.0.0.1]) (amavis, port 10024) with ESMTP\n id V73AOE-j0-bW for <buildroot@buildroot.org>;\n Fri, 27 Mar 2026 17:57:45 +0000 (UTC)", "from dd20012.kasserver.com (dd20012.kasserver.com [85.13.140.57])\n by smtp3.osuosl.org (Postfix) with ESMTPS id 466C060F9E\n for <buildroot@buildroot.org>; Fri, 27 Mar 2026 17:57:45 +0000 (UTC)", "from fli4l.lan.fli4l (p5b3a0ba3.dip0.t-ipconnect.de [91.58.11.163])\n by dd20012.kasserver.com (Postfix) with ESMTPSA id 6C43BA4C00AA\n for <buildroot@buildroot.org>; Fri, 27 Mar 2026 18:57:43 +0100 (CET)", "from bruckner.lan.fli4l ([192.168.1.1]:54926)\n by fli4l.lan.fli4l with esmtp (Exim 4.99.1)\n (envelope-from <bernd@kuhls.net>) id 1w6BRH-000000001UI-0Jy1\n for buildroot@buildroot.org; Fri, 27 Mar 2026 17:57:43 +0000" ], "X-Virus-Scanned": [ "amavis at osuosl.org", "amavis at osuosl.org" ], "X-Comment": "SPF check N/A for local connections - client-ip=140.211.166.142;\n helo=lists1.osuosl.org; envelope-from=buildroot-bounces@buildroot.org;\n receiver=<UNKNOWN> ", "DKIM-Filter": [ "OpenDKIM Filter v2.11.0 smtp4.osuosl.org F03284115C", "OpenDKIM Filter v2.11.0 smtp3.osuosl.org 466C060F9E" ], "DKIM-Signature": "v=1; a=rsa-sha256; c=relaxed/relaxed; d=buildroot.org;\n\ts=default; t=1774634268;\n\tbh=0wTKcmkpGll/+Xb+iYNKgycCiLznhPZLyp2N1iabsFU=;\n\th=From:To:Date:Subject:List-Id:List-Unsubscribe:List-Archive:\n\t List-Post:List-Help:List-Subscribe:From;\n\tb=HjT2ROMbl7YKyoT+C2bvPjcnUOrCt/xS+YmrrY0IXXm0HSpzpOv/qghcoSz1rw2Zw\n\t /aSwrYIoCMQd7YNovQrjzG+NGK4VV+rRMxHdkxMGVDzhbPHHeJNlk5Nn5ivsy68y9+\n\t S42KsFHeJUbwnhmaav8MyXrsf3ne1xu6ruu50VW51iPty8lBxAQclOBJBRNtwIbRh4\n\t RTbA1r9Bo3ud52qfhc0oujM/i50wuxzzxU7/9ddX9Ha09TtFxQ5jcLzjWMOLbRoGZG\n\t BMJqx+SeqhdZlW3jPa2apixovwNYAfo1uqdP/1mVutkK1/uXwnt8gLJIoFpSXoYj/a\n\t kt7WimT81U4PQ==", "Received-SPF": "Pass (mailfrom) identity=mailfrom; client-ip=85.13.140.57;\n helo=dd20012.kasserver.com; envelope-from=bernd@kuhls.net;\n receiver=<UNKNOWN>", "DMARC-Filter": "OpenDMARC Filter v1.4.2 smtp3.osuosl.org 466C060F9E", "From": "Bernd Kuhls <bernd@kuhls.net>", "To": "buildroot@buildroot.org", "Date": "Fri, 27 Mar 2026 18:57:43 +0100", "Message-ID": "<20260327175743.1982788-1-bernd@kuhls.net>", "X-Mailer": "git-send-email 2.47.3", "MIME-Version": "1.0", "X-Spamd-Bar": "-", "X-Mailman-Original-DKIM-Signature": "v=1; a=rsa-sha256; c=relaxed/relaxed;\n d=kuhls.net;\n s=kas202511301023; t=1774634263;\n bh=2NgSX+Z73bFEveYb/fdix/s3jFBFS3XPW1ex7AoZvJw=;\n h=From:To:Subject:Date:From;\n b=fGB8kATNCbFAfLeXaK6h1D2nwSglSJNAn+n0yb/s83d8FtbJM+0i7YTThacx3pmml\n yhLaYejWb/XoIRZ09lZyXlaZDvZYP0Oc9MEucW8uqaHAsLxdvbANKnDtjD0Xj34nBb\n 4l3FcC21hDG+fPR01IKub889zpMwSoxLnC0mwV8SxXNJsSyvU9/wq2TxowKAQBrhNU\n 4Ux7c/Zzatf0zUkBugOA3nTuGzB76VlUHBu6MJcVfw1B8bEUbK0UnjUH8z1NCrVkxo\n 8fWDJGNleADDvMYjrb5x6Gdv2dViVOEkS/q8pSm5042OOEdM6Y5QbgeR3i+DOE/kcu\n /BaNvLhnrd+AQ==", "X-Mailman-Original-Authentication-Results": [ "smtp3.osuosl.org;\n dmarc=pass (p=none dis=none)\n header.from=kuhls.net", "smtp3.osuosl.org;\n dkim=pass (2048-bit key,\n unprotected) header.d=kuhls.net header.i=@kuhls.net header.a=rsa-sha256\n header.s=kas202511301023 header.b=fGB8kATN" ], "Subject": "[Buildroot] [PATCH 1/1] package/libpng: security bump to version\n 1.6.56", "X-BeenThere": "buildroot@buildroot.org", "X-Mailman-Version": "2.1.30", "Precedence": "list", "List-Id": "Discussion and development of buildroot <buildroot.buildroot.org>", "List-Unsubscribe": "<https://lists.buildroot.org/mailman/options/buildroot>,\n <mailto:buildroot-request@buildroot.org?subject=unsubscribe>", "List-Archive": "<http://lists.buildroot.org/pipermail/buildroot/>", "List-Post": "<mailto:buildroot@buildroot.org>", "List-Help": "<mailto:buildroot-request@buildroot.org?subject=help>", "List-Subscribe": "<https://lists.buildroot.org/mailman/listinfo/buildroot>,\n <mailto:buildroot-request@buildroot.org?subject=subscribe>", "Content-Type": "text/plain; charset=\"us-ascii\"", "Content-Transfer-Encoding": "7bit", "Errors-To": "buildroot-bounces@buildroot.org", "Sender": "\"buildroot\" <buildroot-bounces@buildroot.org>" }, "content": "Fixes the following security vulnerabilities:\n\nCVE-2026-33416 (high):\nUse-after-free via pointer aliasing in `png_set_tRNS` and `png_set_PLTE`.\n\nCVE-2026-33636 (high):\nOut-of-bounds read/write in the palette expansion on ARM Neon.\n\nFor more details, see the advisories:\nhttps://github.com/pnggroup/libpng/security/advisories/GHSA-m4pc-p4q3-4c7j\nhttps://github.com/pnggroup/libpng/security/advisories/GHSA-wjr5-c57x-95m2\n\nRelease notes:\nhttps://github.com/pnggroup/libpng/blob/v1.6.56/ANNOUNCE\n\nSigned-off-by: Bernd Kuhls <bernd@kuhls.net>\n---\n package/libpng/libpng.hash | 6 +++---\n package/libpng/libpng.mk | 2 +-\n 2 files changed, 4 insertions(+), 4 deletions(-)", "diff": "diff --git a/package/libpng/libpng.hash b/package/libpng/libpng.hash\nindex 7901f82c3a..ae28eee087 100644\n--- a/package/libpng/libpng.hash\n+++ b/package/libpng/libpng.hash\n@@ -1,5 +1,5 @@\n-# From https://sourceforge.net/projects/libpng/files/libpng16/1.6.55/\n-sha1 13f7bedf27009e59961f823cc779a5f9f5341a91 libpng-1.6.55.tar.xz\n+# From https://sourceforge.net/projects/libpng/files/libpng16/1.6.56/\n+sha1 71eb3636e60b6ea66f2f670cdf1f7160b7a1fa8b libpng-1.6.56.tar.xz\n # Locally computed:\n-sha256 d925722864837ad5ae2a82070d4b2e0603dc72af44bd457c3962298258b8e82d libpng-1.6.55.tar.xz\n+sha256 f7d8bf1601b7804f583a254ab343a6549ca6cf27d255c302c47af2d9d36a6f18 libpng-1.6.56.tar.xz\n sha256 bdb0a645ea18c60507d0368379b1ac5474b92255fcc2d115e07486a7672ba526 LICENSE\ndiff --git a/package/libpng/libpng.mk b/package/libpng/libpng.mk\nindex 01c1cbbec7..7c5bc35a77 100644\n--- a/package/libpng/libpng.mk\n+++ b/package/libpng/libpng.mk\n@@ -4,7 +4,7 @@\n #\n ################################################################################\n \n-LIBPNG_VERSION = 1.6.55\n+LIBPNG_VERSION = 1.6.56\n LIBPNG_SERIES = 16\n LIBPNG_SOURCE = libpng-$(LIBPNG_VERSION).tar.xz\n LIBPNG_SITE = https://downloads.sourceforge.net/project/libpng/libpng$(LIBPNG_SERIES)/$(LIBPNG_VERSION)\n", "prefixes": [ "1/1" ] }