{"id":2219776,"url":"http://patchwork.ozlabs.org/api/1.0/patches/2219776/?format=json","project":{"id":27,"url":"http://patchwork.ozlabs.org/api/1.0/projects/27/?format=json","name":"Buildroot development","link_name":"buildroot","list_id":"buildroot.buildroot.org","list_email":"buildroot@buildroot.org","web_url":"","scm_url":"","webscm_url":""},"msgid":"<20260404102846.794428-1-titouan.christophe@mind.be>","date":"2026-04-04T10:28:46","name":"[for,2025.02.x] package/rauc: ignore CVE-2026-34155","commit_ref":null,"pull_url":null,"state":"new","archived":false,"hash":"99b57bb4437347b8ab4f1b52447dfafa3d9b77e1","submitter":{"id":90763,"url":"http://patchwork.ozlabs.org/api/1.0/people/90763/?format=json","name":"Titouan Christophe","email":"titouan.christophe@mind.be"},"delegate":null,"mbox":"http://patchwork.ozlabs.org/project/buildroot/patch/20260404102846.794428-1-titouan.christophe@mind.be/mbox/","series":[{"id":498714,"url":"http://patchwork.ozlabs.org/api/1.0/series/498714/?format=json","date":"2026-04-04T10:28:46","name":"[for,2025.02.x] package/rauc: ignore CVE-2026-34155","version":1,"mbox":"http://patchwork.ozlabs.org/series/498714/mbox/"}],"check":"pending","checks":"http://patchwork.ozlabs.org/api/patches/2219776/checks/","tags":{},"headers":{"Return-Path":"<buildroot-bounces@buildroot.org>","X-Original-To":["incoming-buildroot@patchwork.ozlabs.org","buildroot@buildroot.org"],"Delivered-To":["patchwork-incoming-buildroot@legolas.ozlabs.org","buildroot@buildroot.org"],"Authentication-Results":["legolas.ozlabs.org;\n\tdkim=pass (2048-bit key;\n unprotected) header.d=buildroot.org header.i=@buildroot.org\n header.a=rsa-sha256 header.s=default header.b=pUzd4qvP;\n\tdkim-atps=neutral","legolas.ozlabs.org;\n spf=pass (sender SPF authorized) smtp.mailfrom=buildroot.org\n (client-ip=2605:bc80:3010::136; helo=smtp3.osuosl.org;\n envelope-from=buildroot-bounces@buildroot.org; receiver=patchwork.ozlabs.org)"],"Received":["from smtp3.osuosl.org (smtp3.osuosl.org [IPv6:2605:bc80:3010::136])\n\t(using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits)\n\t key-exchange x25519 server-signature ECDSA (secp384r1) server-digest SHA384)\n\t(No client certificate requested)\n\tby legolas.ozlabs.org (Postfix) with ESMTPS id 4fnsJd11mqz1xtJ\n\tfor <incoming-buildroot@patchwork.ozlabs.org>;\n Sat, 04 Apr 2026 21:29:05 +1100 (AEDT)","from localhost (localhost [127.0.0.1])\n\tby smtp3.osuosl.org (Postfix) with ESMTP id 14699608A0;\n\tSat,  4 Apr 2026 10:29:02 +0000 (UTC)","from smtp3.osuosl.org ([127.0.0.1])\n by localhost (smtp3.osuosl.org [127.0.0.1]) (amavis, port 10024) with ESMTP\n id jxjkrxts5E3V; Sat,  4 Apr 2026 10:29:00 +0000 (UTC)","from lists1.osuosl.org (lists1.osuosl.org [140.211.166.142])\n\tby smtp3.osuosl.org (Postfix) with ESMTP id 2E9E960633;\n\tSat,  4 Apr 2026 10:29:00 +0000 (UTC)","from smtp1.osuosl.org (smtp1.osuosl.org [140.211.166.138])\n by lists1.osuosl.org (Postfix) with ESMTP id D955BF2\n for <buildroot@buildroot.org>; Sat,  4 Apr 2026 10:28:57 +0000 (UTC)","from localhost (localhost [127.0.0.1])\n by smtp1.osuosl.org (Postfix) with ESMTP id D0D9381360\n for <buildroot@buildroot.org>; Sat,  4 Apr 2026 10:28:54 +0000 (UTC)","from smtp1.osuosl.org ([127.0.0.1])\n by localhost (smtp1.osuosl.org [127.0.0.1]) (amavis, port 10024) with ESMTP\n id 6ZdaSmlKSPkG for <buildroot@buildroot.org>;\n Sat,  4 Apr 2026 10:28:54 +0000 (UTC)","from mail-ej1-x629.google.com (mail-ej1-x629.google.com\n [IPv6:2a00:1450:4864:20::629])\n by smtp1.osuosl.org (Postfix) with ESMTPS id 25CB78135C\n for <buildroot@buildroot.org>; Sat,  4 Apr 2026 10:28:52 +0000 (UTC)","by mail-ej1-x629.google.com with SMTP id\n a640c23a62f3a-b9c62fc8debso214710366b.0\n for <buildroot@buildroot.org>; Sat, 04 Apr 2026 03:28:51 -0700 (PDT)","from dragon.home ([2a02:a03f:73a7:c001:1291:d1ff:fe92:3b5a])\n by smtp.gmail.com with ESMTPSA id\n a640c23a62f3a-b9c3c99f80esm286538666b.18.2026.04.04.03.28.48\n (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256);\n Sat, 04 Apr 2026 03:28:48 -0700 (PDT)"],"X-Virus-Scanned":["amavis at osuosl.org","amavis at osuosl.org"],"X-Comment":"SPF check N/A for local connections - client-ip=140.211.166.142;\n helo=lists1.osuosl.org; envelope-from=buildroot-bounces@buildroot.org;\n receiver=<UNKNOWN> ","DKIM-Filter":["OpenDKIM Filter v2.11.0 smtp3.osuosl.org 2E9E960633","OpenDKIM Filter v2.11.0 smtp1.osuosl.org 25CB78135C"],"DKIM-Signature":"v=1; a=rsa-sha256; c=relaxed/relaxed; d=buildroot.org;\n\ts=default; t=1775298540;\n\tbh=y3w0ukh2VpiKudLqBZ0WvAIRIpaKHA3z25EvEngl/z4=;\n\th=To:Cc:Date:Subject:List-Id:List-Unsubscribe:List-Archive:\n\t List-Post:List-Help:List-Subscribe:From:Reply-To:From;\n\tb=pUzd4qvPbCC8PokVfARSt3w6RTEy+XFE1I8BXH1wXZOQ1ymfxxMHciNTyowK/pkkm\n\t +xzO1rnU23oxgu0bOrDbqtNTLeIn2d2OzvO4wBtUcSg2qmqRcU5xoJKPLifbl4zuio\n\t BhJSqxGlZtm9jhHX9GeEOoKY9ezW25s6G2xPiFw+ORNMiDmM4mC+rm6rDr5HvzKW07\n\t NSEfuHo+Y1xGPizdNOmvhZITF4HErcc+cCBLCQzIiX033G9DnNu14BrhhOk136s4z2\n\t 8ET2jy7gd+AQRD6IrQUCkSc2nftmy2f5CO2bWetbRvBzwSj3YG24iClSsRV58Gryy+\n\t tfhuE4HsuqEpA==","Received-SPF":"Pass (mailfrom) identity=mailfrom;\n client-ip=2a00:1450:4864:20::629; helo=mail-ej1-x629.google.com;\n envelope-from=titouan.christophe@essensium.com; receiver=<UNKNOWN>","DMARC-Filter":"OpenDMARC Filter v1.4.2 smtp1.osuosl.org 25CB78135C","X-Google-DKIM-Signature":"v=1; a=rsa-sha256; c=relaxed/relaxed;\n d=1e100.net; s=20251104; t=1775298530; x=1775903330;\n h=content-transfer-encoding:mime-version:message-id:date:subject:cc\n :to:from:x-gm-gg:x-gm-message-state:from:to:cc:subject:date\n :message-id:reply-to;\n bh=r5oG79mSv/q7T19cNl8m3OcONsGrPkMgtLOeBId1kVA=;\n b=kyfImgoG7cI4nHX6NnnzNIY6nxklluSRw+UD9zanJpVi9Gjm9cvOgy77dMMDuHbbng\n ZqU55hnKcNU64k0NumtwOP98z6FeqF6a3aoZLxDDuPeokv+801v8N6Fajbz8pYKz6Xp/\n qc39aQTwuAVxrJORp2kGacXRR1C5KEVW+mHfWEuuYqxRL0nkToqBVp/yxIknadGuvFfO\n uip3mBFZbbT0U5wxZYZ5QFs7SbKbXNhayicxyVNs5do4M/nnIuzSqDctqBN6rWRx/WED\n hMtgpJrMpiPslLCtavp0hC3Mlk45Q/N9FvTpjhXYuSjL5oukNDfDH8wZa8jEYkL83i76\n qiLw==","X-Gm-Message-State":"AOJu0YwRE5bDog/8wUj9l8h/VrRqVSfOZq5vNulNGiHf50tpYj77PTEQ\n 47RYbqnE8T903iOQRgos1uieB+X2z8JyicsYOXJe5ld1t+OP+ktKvQD8vlbtfB/04HpyCuWncw2\n GTNUp6x4=","X-Gm-Gg":"AeBDieuWM+o9j/CAi2i8FHVc+iFSR9wsUB6AI/B0c+kYpy6HdLn0iLNtaBdk7kHoS4U\n DS8lywDzwzTvkdEK/RGHXOJhnEFma9kEECbWgHauI6pQF3CsF/j7+utWSToRxWXPh8smiNf1f+K\n cJmk0sCNATJNzx6KCqHjLW1K/+b/jl1227aLtbfG/8zo+ykNIBWt8UQS4mXws5oePUGvrK/RlRj\n 7LvvVpZ+5kGNP0DLoRUvWCJrLuleyz3ChH9Hv1t8MoyWMGjXXtM0pF+9KP7CCginR+5zXuIvtw9\n vsAsUw6ziFv5ZE21hqPVC0RiEUOrwUc05i+eVF2K2dQLUuvcJ2SwyIHaY8oRfH0LdCqrOutKjg/\n xOZCjLFLOwBVeHygzWWUV1JZve2p84qLJ/+w7KgceCOMBJjQtlQ4T7LXShv9pt8REfUoruI5czH\n hRDNJnD4DhfUSZIngiwOfCWLydSssZ2G6InmJm","X-Received":"by 2002:a17:907:c19:b0:b98:6c41:a798 with SMTP id\n a640c23a62f3a-b9c6743b213mr310140266b.20.1775298529204;\n Sat, 04 Apr 2026 03:28:49 -0700 (PDT)","To":"buildroot@buildroot.org","Cc":"thomas.perale@mind.be","Date":"Sat,  4 Apr 2026 12:28:46 +0200","Message-ID":"<20260404102846.794428-1-titouan.christophe@mind.be>","X-Mailer":"git-send-email 2.53.0","MIME-Version":"1.0","X-Mailman-Original-DKIM-Signature":"v=1; a=rsa-sha256; c=relaxed/relaxed;\n d=mind.be; s=google; t=1775298530; x=1775903330; darn=buildroot.org;\n h=content-transfer-encoding:mime-version:message-id:date:subject:cc\n :to:from:from:to:cc:subject:date:message-id:reply-to;\n bh=r5oG79mSv/q7T19cNl8m3OcONsGrPkMgtLOeBId1kVA=;\n b=WLqI1G59II6057uvZ6Xd1az3P66Qoqy08oy3IlsJP5NdsDIytyo4x32edI+htxtPtr\n YbwE3wEd1TDx0nZ1FuJwxGDYYic4VHQGCozSgWRNLsnJNHNOlwgWquqdgmIRXKS1AwU4\n BOyIOo2ECTIisRoUgWf+ujRHyFPZljuaYf0l4XsPYnknUiBQAYr+TBGAK8JhXZ1cvVep\n yDnPxiVL8Fhhlo2PVNWufZeZA8iN7re7XKOuwUaMcOkq+mi76Z1nybFbDoICuNyuLHau\n i5qFo3rKvPUwkTsMgJP+uQVPSHubFVMS0N3gfsu4ueysfhUuRtvpb1vlTHcQ7Y+2XWgl\n 1APg==","X-Mailman-Original-Authentication-Results":["smtp1.osuosl.org;\n dmarc=pass (p=quarantine dis=none)\n header.from=mind.be","smtp1.osuosl.org;\n dkim=pass (2048-bit key,\n unprotected) header.d=mind.be header.i=@mind.be header.a=rsa-sha256\n header.s=google header.b=WLqI1G59"],"Subject":"[Buildroot] [PATCH for 2025.02.x] package/rauc: ignore\n CVE-2026-34155","X-BeenThere":"buildroot@buildroot.org","X-Mailman-Version":"2.1.30","Precedence":"list","List-Id":"Discussion and development of buildroot <buildroot.buildroot.org>","List-Unsubscribe":"<https://lists.buildroot.org/mailman/options/buildroot>,\n <mailto:buildroot-request@buildroot.org?subject=unsubscribe>","List-Archive":"<http://lists.buildroot.org/pipermail/buildroot/>","List-Post":"<mailto:buildroot@buildroot.org>","List-Help":"<mailto:buildroot-request@buildroot.org?subject=help>","List-Subscribe":"<https://lists.buildroot.org/mailman/listinfo/buildroot>,\n <mailto:buildroot-request@buildroot.org?subject=subscribe>","From":"Titouan Christophe via buildroot <buildroot@buildroot.org>","Reply-To":"Titouan Christophe <titouan.christophe@mind.be>","Content-Type":"text/plain; charset=\"us-ascii\"","Content-Transfer-Encoding":"7bit","Errors-To":"buildroot-bounces@buildroot.org","Sender":"\"buildroot\" <buildroot-bounces@buildroot.org>"},"content":"Buildroot commit c9f7b876ee5bac0ee7344e5ecb7bd3ac0d5aab76 added a patch to\nfix the vulnerability for rauc v1.13, but forgot to ignore the CVE in rauc.mk\n\nSigned-off-by: Titouan Christophe <titouan.christophe@mind.be>\n---\n package/rauc/rauc.mk | 3 +++\n 1 file changed, 3 insertions(+)","diff":"diff --git a/package/rauc/rauc.mk b/package/rauc/rauc.mk\nindex 92f58c6139..f8fbb5fdd0 100644\n--- a/package/rauc/rauc.mk\n+++ b/package/rauc/rauc.mk\n@@ -13,6 +13,9 @@ RAUC_CPE_ID_VENDOR = pengutronix\n RAUC_DEPENDENCIES = host-pkgconf openssl libglib2\n RAUC_CONF_OPTS += -Dtests=false\n \n+# 0001-fix-cve-2026-34155.patch\n+RAUC_IGNORE_CVES += CVE-2026-34155\n+\n ifeq ($(BR2_PACKAGE_RAUC_DBUS),y)\n RAUC_CONF_OPTS += -Dservice=true\n RAUC_DEPENDENCIES += dbus\n","prefixes":["for","2025.02.x"]}