{"id":2228975,"url":"http://patchwork.ozlabs.org/api/1.1/patches/2228975/?format=json","web_url":"http://patchwork.ozlabs.org/project/buildroot/patch/20260427153731.3792798-1-peter@korsgaard.com/","project":{"id":27,"url":"http://patchwork.ozlabs.org/api/1.1/projects/27/?format=json","name":"Buildroot development","link_name":"buildroot","list_id":"buildroot.buildroot.org","list_email":"buildroot@buildroot.org","web_url":"","scm_url":"","webscm_url":""},"msgid":"<20260427153731.3792798-1-peter@korsgaard.com>","date":"2026-04-27T15:37:30","name":"package/liburiparser: security bump to version 1.0.1","commit_ref":null,"pull_url":null,"state":"accepted","archived":false,"hash":"c5a5b440923c08a2db19f6d7640b4501bf3c2dc4","submitter":{"id":42365,"url":"http://patchwork.ozlabs.org/api/1.1/people/42365/?format=json","name":"Peter Korsgaard","email":"peter@korsgaard.com"},"delegate":{"id":89618,"url":"http://patchwork.ozlabs.org/api/1.1/users/89618/?format=json","username":"juju","first_name":"Julien","last_name":"Olivain","email":"juju@cotds.org"},"mbox":"http://patchwork.ozlabs.org/project/buildroot/patch/20260427153731.3792798-1-peter@korsgaard.com/mbox/","series":[{"id":501679,"url":"http://patchwork.ozlabs.org/api/1.1/series/501679/?format=json","web_url":"http://patchwork.ozlabs.org/project/buildroot/list/?series=501679","date":"2026-04-27T15:37:30","name":"package/liburiparser: security bump to version 1.0.1","version":1,"mbox":"http://patchwork.ozlabs.org/series/501679/mbox/"}],"comments":"http://patchwork.ozlabs.org/api/patches/2228975/comments/","check":"pending","checks":"http://patchwork.ozlabs.org/api/patches/2228975/checks/","tags":{},"headers":{"Return-Path":"<buildroot-bounces@buildroot.org>","X-Original-To":["incoming-buildroot@patchwork.ozlabs.org","buildroot@buildroot.org"],"Delivered-To":["patchwork-incoming-buildroot@legolas.ozlabs.org","buildroot@buildroot.org"],"Authentication-Results":["legolas.ozlabs.org;\n\tdkim=pass (2048-bit key;\n unprotected) header.d=buildroot.org header.i=@buildroot.org\n header.a=rsa-sha256 header.s=default header.b=svA5MlUn;\n\tdkim-atps=neutral","legolas.ozlabs.org;\n spf=pass (sender SPF authorized) smtp.mailfrom=buildroot.org\n (client-ip=2605:bc80:3010::138; helo=smtp1.osuosl.org;\n envelope-from=buildroot-bounces@buildroot.org; receiver=patchwork.ozlabs.org)"],"Received":["from smtp1.osuosl.org (smtp1.osuosl.org [IPv6:2605:bc80:3010::138])\n\t(using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits)\n\t key-exchange x25519 server-signature ECDSA (secp384r1) server-digest SHA384)\n\t(No client certificate requested)\n\tby legolas.ozlabs.org (Postfix) with ESMTPS id 4g474C3dskz1xvV\n\tfor <incoming-buildroot@patchwork.ozlabs.org>;\n Tue, 28 Apr 2026 01:37:47 +1000 (AEST)","from localhost (localhost [127.0.0.1])\n\tby smtp1.osuosl.org (Postfix) with ESMTP id E006081065;\n\tMon, 27 Apr 2026 15:37:43 +0000 (UTC)","from smtp1.osuosl.org ([127.0.0.1])\n by localhost (smtp1.osuosl.org [127.0.0.1]) (amavis, port 10024) with ESMTP\n id CxNJhP_17mFH; Mon, 27 Apr 2026 15:37:41 +0000 (UTC)","from lists1.osuosl.org (lists1.osuosl.org [140.211.166.142])\n\tby smtp1.osuosl.org (Postfix) with ESMTP id B8DF681046;\n\tMon, 27 Apr 2026 15:37:41 +0000 (UTC)","from smtp3.osuosl.org (smtp3.osuosl.org [IPv6:2605:bc80:3010::136])\n by lists1.osuosl.org (Postfix) with ESMTP id D81411B8\n for <buildroot@buildroot.org>; Mon, 27 Apr 2026 15:37:40 +0000 (UTC)","from localhost (localhost [127.0.0.1])\n by smtp3.osuosl.org (Postfix) with ESMTP id BD3C16062A\n for <buildroot@buildroot.org>; Mon, 27 Apr 2026 15:37:40 +0000 (UTC)","from smtp3.osuosl.org ([127.0.0.1])\n by localhost (smtp3.osuosl.org [127.0.0.1]) (amavis, port 10024) with ESMTP\n id beXD6mr90YZv for <buildroot@buildroot.org>;\n Mon, 27 Apr 2026 15:37:39 +0000 (UTC)","from sendmail.purelymail.com (sendmail.purelymail.com\n [34.202.193.197])\n by smtp3.osuosl.org (Postfix) with ESMTPS id 1296060629\n for <buildroot@buildroot.org>; Mon, 27 Apr 2026 15:37:38 +0000 (UTC)","by smtp.purelymail.com (Purelymail SMTP) with ESMTPSA id 1697742395;\n (version=TLSv1.3 cipher=TLS_AES_256_GCM_SHA384);\n Mon, 27 Apr 2026 15:37:34 +0000 (UTC)","from peko by dell.be.48ers.dk with local (Exim 4.98.2)\n (envelope-from <peko@dell.be.48ers.dk>) id 1wHO1d-0000000FugS-1pft;\n Mon, 27 Apr 2026 17:37:33 +0200"],"X-Virus-Scanned":["amavis at osuosl.org","amavis at osuosl.org"],"X-Comment":"SPF check N/A for local connections - client-ip=140.211.166.142;\n helo=lists1.osuosl.org; envelope-from=buildroot-bounces@buildroot.org;\n receiver=<UNKNOWN> ","DKIM-Filter":["OpenDKIM Filter v2.11.0 smtp1.osuosl.org B8DF681046","OpenDKIM Filter v2.11.0 smtp3.osuosl.org 1296060629"],"DKIM-Signature":"v=1; a=rsa-sha256; c=relaxed/relaxed; d=buildroot.org;\n\ts=default; t=1777304261;\n\tbh=FR8plrzKp9bs541dPSn7LiOId9bVbZ/HMHccA1ukK0o=;\n\th=From:To:Date:Subject:List-Id:List-Unsubscribe:List-Archive:\n\t List-Post:List-Help:List-Subscribe:Cc:From;\n\tb=svA5MlUnjs4IB9t0zR3VnTXNpcxtREbyDHQadX9ZuZI6lDAGf9b9XLArpZk4NINMF\n\t xaAD/r3KDpAE07mWIRRXlB2Orrhldk2L32reBSS1CDcUHP5LW0iZJEV6K7PZpIsouF\n\t gJ/xLz/kk3hUkwqtbh6ijTLpSUt4f6rNabZMg2ND1pYEt6AZEFKc/KshRAUUpoG24V\n\t QHGgXp33mu4iBwofCX7d8KHihETNtj3YcchibT9oUN5QTzdVr6PoAEv20SuZX7XfJ7\n\t 7UIsKTWEssUisp9gWK53ukXVvgf19c9+OWM6rhIDzvUWLdHls6IfuXKZBS4LvEGHs3\n\t qQuBtyoVTb2ZQ==","Received-SPF":"Pass (mailfrom) identity=mailfrom; client-ip=34.202.193.197;\n helo=sendmail.purelymail.com; envelope-from=peko@korsgaard.com;\n receiver=<UNKNOWN>","DMARC-Filter":"OpenDMARC Filter v1.4.2 smtp3.osuosl.org 1296060629","Feedback-ID":"21632:4007:null:purelymail","X-Pm-Original-To":"buildroot@buildroot.org","From":"Peter Korsgaard <peter@korsgaard.com>","To":"buildroot@buildroot.org","Date":"Mon, 27 Apr 2026 17:37:30 +0200","Message-ID":"<20260427153731.3792798-1-peter@korsgaard.com>","X-Mailer":"git-send-email 2.47.3","MIME-Version":"1.0","X-MIME-Autoconverted":"from 8bit to quoted-printable by Purelymail","X-Mailman-Original-DKIM-Signature":"a=rsa-sha256;\n b=k0laftofhcnIxK6NcVx04k+GELs2KcCy3feis4xbVpLqY9VCDfI8vene+27Qto51WB7mjL7V0R/DTKz+8ki3tOkal1JzhOI5tQi7oy74NBnv5csr0UCvVqjhlRTy7TUvrFWAek9qPxOWQw7yzoAgg2HfghmX44bvo4poSSemFWLX5yiBS4bsudzrYsizwoDSi2YI6N2BQmQJ73fgDjt5kSjxWAkmPvLg+I2wpHS6JPYIfG2o6rGLyNMXspO8ejB20k5daqBa6Te18hR2HpUddAqWs5uUkp6ElS3afHufeYEyDnpYVseeYwdBT/6A2Byc2gqKQ/NQ1bIHqpDVwuZpTw==;\n s=purelymail2; d=purelymail.com; v=1;\n bh=8FDYUvXnd94sIdBOiOieaBqel/iR+y46n6IvM36FvYA=;\n h=Feedback-ID:Received:Received:From:To:Subject:Date;","X-Mailman-Original-Authentication-Results":["smtp3.osuosl.org;\n dmarc=none (p=none dis=none)\n header.from=korsgaard.com","smtp3.osuosl.org;\n dkim=pass (2048-bit key,\n unprotected) header.d=purelymail.com header.i=@purelymail.com\n header.a=rsa-sha256 header.s=purelymail2 header.b=k0laftof","purelymail.com; auth=pass"],"Subject":"[Buildroot] [PATCH] package/liburiparser: security bump to version\n 1.0.1","X-BeenThere":"buildroot@buildroot.org","X-Mailman-Version":"2.1.30","Precedence":"list","List-Id":"Discussion and development of buildroot <buildroot.buildroot.org>","List-Unsubscribe":"<https://lists.buildroot.org/mailman/options/buildroot>,\n <mailto:buildroot-request@buildroot.org?subject=unsubscribe>","List-Archive":"<http://lists.buildroot.org/pipermail/buildroot/>","List-Post":"<mailto:buildroot@buildroot.org>","List-Help":"<mailto:buildroot-request@buildroot.org?subject=help>","List-Subscribe":"<https://lists.buildroot.org/mailman/listinfo/buildroot>,\n <mailto:buildroot-request@buildroot.org?subject=subscribe>","Cc":"Bernd Kuhls <bernd@kuhls.net>","Content-Type":"text/plain; charset=\"us-ascii\"","Content-Transfer-Encoding":"7bit","Errors-To":"buildroot-bounces@buildroot.org","Sender":"\"buildroot\" <buildroot-bounces@buildroot.org>"},"content":"Fixes the following vulnerability:\n\nCVE-2026-42371: integer overflow in text range comparison\nhttps://github.com/uriparser/uriparser/pull/298\n\nFor details, see the announcement:\nhttps://www.openwall.com/lists/oss-security/2026/04/27/2\n\nSigned-off-by: Peter Korsgaard <peter@korsgaard.com>\n---\n package/liburiparser/liburiparser.hash | 4 ++--\n package/liburiparser/liburiparser.mk   | 2 +-\n 2 files changed, 3 insertions(+), 3 deletions(-)","diff":"diff --git a/package/liburiparser/liburiparser.hash b/package/liburiparser/liburiparser.hash\nindex f8d7124b7f..c18df8eb98 100644\n--- a/package/liburiparser/liburiparser.hash\n+++ b/package/liburiparser/liburiparser.hash\n@@ -1,4 +1,4 @@\n-# From https://github.com/uriparser/uriparser/releases/tag/uriparser-1.0.0\n-sha256  154a3f649d80a78d5095fc461ec032ffb45f5ed3619edec923ac68cff29a088d  uriparser-1.0.0.tar.xz\n+# From https://github.com/uriparser/uriparser/releases/tag/uriparser-1.0.1\n+sha256  acd18cfb14d1851705f863f7a625be693fb3971fb85d4996faa21147f0315fcb  uriparser-1.0.1.tar.xz\n # Locally calculated\n sha256  287f09e6546a9610f949f89e8fb937cacfeabd7bfaa8c8a0c18312193bf04ad3  COPYING.BSD-3-Clause\ndiff --git a/package/liburiparser/liburiparser.mk b/package/liburiparser/liburiparser.mk\nindex 731739e582..d8dcc22063 100644\n--- a/package/liburiparser/liburiparser.mk\n+++ b/package/liburiparser/liburiparser.mk\n@@ -4,7 +4,7 @@\n #\n ################################################################################\n \n-LIBURIPARSER_VERSION = 1.0.0\n+LIBURIPARSER_VERSION = 1.0.1\n LIBURIPARSER_SOURCE = uriparser-$(LIBURIPARSER_VERSION).tar.xz\n LIBURIPARSER_SITE = https://github.com/uriparser/uriparser/releases/download/uriparser-$(LIBURIPARSER_VERSION)\n LIBURIPARSER_LICENSE = BSD-3-Clause\n","prefixes":[]}