From patchwork Sat Dec 12 21:55:58 2020 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Fabrice Fontaine X-Patchwork-Id: 1415472 Return-Path: X-Original-To: incoming-buildroot@patchwork.ozlabs.org Delivered-To: patchwork-incoming-buildroot@bilbo.ozlabs.org Authentication-Results: ozlabs.org; spf=pass (sender SPF authorized) smtp.mailfrom=busybox.net (client-ip=140.211.166.136; helo=silver.osuosl.org; envelope-from=buildroot-bounces@busybox.net; receiver=) Authentication-Results: ozlabs.org; dmarc=fail (p=none dis=none) header.from=gmail.com Authentication-Results: ozlabs.org; dkim=fail reason="signature verification failed" (2048-bit key; unprotected) header.d=gmail.com header.i=@gmail.com header.a=rsa-sha256 header.s=20161025 header.b=l2fAvQaw; dkim-atps=neutral Received: from silver.osuosl.org (smtp3.osuosl.org [140.211.166.136]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ozlabs.org (Postfix) with ESMTPS id 4CthLm3ljkz9sRR for ; Sun, 13 Dec 2020 08:56:30 +1100 (AEDT) Received: from localhost (localhost [127.0.0.1]) by silver.osuosl.org (Postfix) with ESMTP id 89F5F20469; Sat, 12 Dec 2020 21:56:27 +0000 (UTC) X-Virus-Scanned: amavisd-new at osuosl.org Received: from silver.osuosl.org ([127.0.0.1]) by localhost (.osuosl.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id XHZCuIR2hQWq; Sat, 12 Dec 2020 21:56:24 +0000 (UTC) Received: from ash.osuosl.org (ash.osuosl.org [140.211.166.34]) by silver.osuosl.org (Postfix) with ESMTP id B95932035E; Sat, 12 Dec 2020 21:56:23 +0000 (UTC) X-Original-To: buildroot@lists.busybox.net Delivered-To: buildroot@osuosl.org Received: from hemlock.osuosl.org (smtp2.osuosl.org [140.211.166.133]) by ash.osuosl.org (Postfix) with ESMTP id 562861BF48C for ; Sat, 12 Dec 2020 21:56:22 +0000 (UTC) Received: from localhost (localhost [127.0.0.1]) by hemlock.osuosl.org (Postfix) with ESMTP id 5253987021 for ; Sat, 12 Dec 2020 21:56:22 +0000 (UTC) X-Virus-Scanned: amavisd-new at osuosl.org Received: from hemlock.osuosl.org ([127.0.0.1]) by localhost (.osuosl.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 7viWoW7khAtd for ; Sat, 12 Dec 2020 21:56:21 +0000 (UTC) X-Greylist: domain auto-whitelisted by SQLgrey-1.7.6 Received: from mail-wm1-f68.google.com (mail-wm1-f68.google.com [209.85.128.68]) by hemlock.osuosl.org (Postfix) with ESMTPS id 4D87D86FEC for ; Sat, 12 Dec 2020 21:56:21 +0000 (UTC) Received: by mail-wm1-f68.google.com with SMTP id q75so11831047wme.2 for ; Sat, 12 Dec 2020 13:56:21 -0800 (PST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025; h=from:to:cc:subject:date:message-id:mime-version :content-transfer-encoding; bh=O+eHTCxfZrA2npy6Xb5w1y24BacQ22c65Nlykrw7u20=; b=l2fAvQawI8hJNof48VFl0FFdB3FnH07A2HelzI5yp/VRWUWt2XPHBjAuI/1qF0JkQu Y/N9t61DrVMkBunsuLy+J8mC0pZrvUf3gjG42pnGy18Cc7peN2fGUnoRDOLTlgyg/w4P dt/uS3nrto0fQ3MSRnhuxBGOyVdH7yesHDQ2P30svnJ/Qc2OUUbZP4Hcqwdlw3b+Xvpw moHtot3hMoM3BKASfp62zMwDa9d80PxMo6RWMjeYrlmYVVMsVFB7AH6EaYitNEDeBjWo jhCqwBIEwmO7KBkLLa0aauLA/CAsS0QCbQXi+Ub9oFF0AcGIMV8f5xtyvOyh4sZ9V41b FK9Q== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:from:to:cc:subject:date:message-id:mime-version :content-transfer-encoding; bh=O+eHTCxfZrA2npy6Xb5w1y24BacQ22c65Nlykrw7u20=; b=F4c5EZAFjULj6eLlnqb7256nSl+HVyVTkEl0vtkq/TYtdraKJjBSlMQyAEHVDe4HvI pISooM8HCcraHXY4eugGe+G1OPPbUM1Sshdjxm9kJra0LSoB2EsLYAd/cl9f9uH/FNpJ vfUYTHbnEio6ovBMyH4gpDkPjTsGj7udwCngFJxyfiBdKJTalxlK3dZ55W9YDQJippyw JmVQqj31OuwjXu1ieSDKD4Nvuq746H61sjQ7etAM9+mnPScguejLfm5Auqg6lRbj6ZvG P6675glbgesEWETJJAf+1CvteRwpsERjcWRa5Tao3MKinH8KOXFRL1Uqk5o+qY8/56co biUw== X-Gm-Message-State: AOAM532tBZueC74/lZWFgeSxXR6rceF3E9Ag2s8e6PFzel3pOkLmPfhx b3WcIXArkjqG2McLc/jp1GoHdrQjAu0= X-Google-Smtp-Source: ABdhPJxuF3fdUYsW+6HfBZTwq4rNGw3C+l/qJQPMX3vDtjYIkWM/qXCM+mUVDPmITgC3571BhIzusg== X-Received: by 2002:a1c:2182:: with SMTP id h124mr20161351wmh.25.1607810179455; Sat, 12 Dec 2020 13:56:19 -0800 (PST) Received: from kali.home (2a01cb0881b76d00c2afd0dfa851d2b9.ipv6.abo.wanadoo.fr. [2a01:cb08:81b7:6d00:c2af:d0df:a851:d2b9]) by smtp.gmail.com with ESMTPSA id b4sm21773018wrr.30.2020.12.12.13.56.18 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sat, 12 Dec 2020 13:56:18 -0800 (PST) From: Fabrice Fontaine To: buildroot@buildroot.org Date: Sat, 12 Dec 2020 22:55:58 +0100 Message-Id: <20201212215558.29057-1-fontaine.fabrice@gmail.com> X-Mailer: git-send-email 2.29.2 MIME-Version: 1.0 Subject: [Buildroot] [PATCH 1/1] package/unbound: security bump to version 1.13.0 X-BeenThere: buildroot@busybox.net X-Mailman-Version: 2.1.29 Precedence: list List-Id: Discussion and development of buildroot List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Cc: Fabrice Fontaine , Stefan Ott Errors-To: buildroot-bounces@busybox.net Sender: "buildroot" This version has fixes to connect for UDP sockets, slowing down potential ICMP side channel leakage. The fix can be controlled with the option udp-connect: yes, it is enabled by default. Additionally CVE-2020-28935 is fixed, this solves a problem where the pidfile is altered by a symlink, and fails if a symlink is encountered. See https://nlnetlabs.nl/downloads/unbound/CVE-2020-28935.txt for more information. https://github.com/NLnetLabs/unbound/releases/tag/release-1.13.0 Signed-off-by: Fabrice Fontaine --- package/unbound/unbound.hash | 6 ++++-- package/unbound/unbound.mk | 2 +- 2 files changed, 5 insertions(+), 3 deletions(-) diff --git a/package/unbound/unbound.hash b/package/unbound/unbound.hash index c2c6ab7ff6..9ccea6eb88 100644 --- a/package/unbound/unbound.hash +++ b/package/unbound/unbound.hash @@ -1,3 +1,5 @@ +# From https://nlnetlabs.nl/downloads/unbound/unbound-1.13.0.tar.gz.sha256 +sha256 a954043a95b0326ca4037e50dace1f3a207a0a19e9a4a22f4c6718fc623db2a1 unbound-1.13.0.tar.gz + # Locally calculated -sha256 5b9253a97812f24419bf2e6b3ad28c69287261cf8c8fa79e3e9f6d3bf7ef5835 unbound-1.12.0.tar.gz -sha256 8eb9a16cbfb8703090bbfa3a2028fd46bb351509a2f90dc1001e51fbe6fd45db LICENSE +sha256 8eb9a16cbfb8703090bbfa3a2028fd46bb351509a2f90dc1001e51fbe6fd45db LICENSE diff --git a/package/unbound/unbound.mk b/package/unbound/unbound.mk index d60180b6ca..8b7d1e8e9f 100644 --- a/package/unbound/unbound.mk +++ b/package/unbound/unbound.mk @@ -4,7 +4,7 @@ # ################################################################################ -UNBOUND_VERSION = 1.12.0 +UNBOUND_VERSION = 1.13.0 UNBOUND_SITE = https://www.unbound.net/downloads UNBOUND_DEPENDENCIES = host-pkgconf expat libevent openssl UNBOUND_LICENSE = BSD-3-Clause