{"id":2230808,"url":"http://patchwork.ozlabs.org/api/1.1/patches/2230808/?format=json","web_url":"http://patchwork.ozlabs.org/project/buildroot/patch/20260430045109.59810-1-bernd@kuhls.net/","project":{"id":27,"url":"http://patchwork.ozlabs.org/api/1.1/projects/27/?format=json","name":"Buildroot development","link_name":"buildroot","list_id":"buildroot.buildroot.org","list_email":"buildroot@buildroot.org","web_url":"","scm_url":"","webscm_url":""},"msgid":"<20260430045109.59810-1-bernd@kuhls.net>","date":"2026-04-30T04:51:09","name":"[1/1] package/gnutls: security bump to version 3.8.13","commit_ref":null,"pull_url":null,"state":"accepted","archived":false,"hash":"bad3840cbc7bdcdb6f72ccc1beee03709a95f861","submitter":{"id":86624,"url":"http://patchwork.ozlabs.org/api/1.1/people/86624/?format=json","name":"Bernd Kuhls","email":"bernd@kuhls.net"},"delegate":{"id":89618,"url":"http://patchwork.ozlabs.org/api/1.1/users/89618/?format=json","username":"juju","first_name":"Julien","last_name":"Olivain","email":"juju@cotds.org"},"mbox":"http://patchwork.ozlabs.org/project/buildroot/patch/20260430045109.59810-1-bernd@kuhls.net/mbox/","series":[{"id":502192,"url":"http://patchwork.ozlabs.org/api/1.1/series/502192/?format=json","web_url":"http://patchwork.ozlabs.org/project/buildroot/list/?series=502192","date":"2026-04-30T04:51:09","name":"[1/1] package/gnutls: security bump to version 3.8.13","version":1,"mbox":"http://patchwork.ozlabs.org/series/502192/mbox/"}],"comments":"http://patchwork.ozlabs.org/api/patches/2230808/comments/","check":"pending","checks":"http://patchwork.ozlabs.org/api/patches/2230808/checks/","tags":{},"headers":{"Return-Path":"<buildroot-bounces@buildroot.org>","X-Original-To":["incoming-buildroot@patchwork.ozlabs.org","buildroot@buildroot.org"],"Delivered-To":["patchwork-incoming-buildroot@legolas.ozlabs.org","buildroot@buildroot.org"],"Authentication-Results":["legolas.ozlabs.org;\n\tdkim=pass (2048-bit key;\n unprotected) header.d=buildroot.org header.i=@buildroot.org\n header.a=rsa-sha256 header.s=default header.b=OBJB14Ji;\n\tdkim-atps=neutral","legolas.ozlabs.org;\n spf=pass (sender SPF authorized) smtp.mailfrom=buildroot.org\n (client-ip=2605:bc80:3010::138; helo=smtp1.osuosl.org;\n envelope-from=buildroot-bounces@buildroot.org; receiver=patchwork.ozlabs.org)"],"Received":["from smtp1.osuosl.org (smtp1.osuosl.org [IPv6:2605:bc80:3010::138])\n\t(using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits)\n\t key-exchange x25519 server-signature ECDSA (secp384r1) server-digest SHA384)\n\t(No client certificate requested)\n\tby legolas.ozlabs.org (Postfix) with ESMTPS id 4g5hZt6RCbz1yHZ\n\tfor <incoming-buildroot@patchwork.ozlabs.org>;\n Thu, 30 Apr 2026 14:51:18 +1000 (AEST)","from localhost (localhost [127.0.0.1])\n\tby smtp1.osuosl.org (Postfix) with ESMTP id 42911849FA;\n\tThu, 30 Apr 2026 04:51:17 +0000 (UTC)","from smtp1.osuosl.org ([127.0.0.1])\n by localhost (smtp1.osuosl.org [127.0.0.1]) (amavis, port 10024) with ESMTP\n id OhhM_ldBRoTU; Thu, 30 Apr 2026 04:51:15 +0000 (UTC)","from lists1.osuosl.org (lists1.osuosl.org [140.211.166.142])\n\tby smtp1.osuosl.org (Postfix) with ESMTP id 62957849F4;\n\tThu, 30 Apr 2026 04:51:15 +0000 (UTC)","from smtp4.osuosl.org (smtp4.osuosl.org [IPv6:2605:bc80:3010::137])\n by lists1.osuosl.org (Postfix) with ESMTP id 061B6192\n for <buildroot@buildroot.org>; Thu, 30 Apr 2026 04:51:14 +0000 (UTC)","from localhost (localhost [127.0.0.1])\n by smtp4.osuosl.org (Postfix) with ESMTP id E02564217D\n for <buildroot@buildroot.org>; Thu, 30 Apr 2026 04:51:13 +0000 (UTC)","from smtp4.osuosl.org ([127.0.0.1])\n by localhost (smtp4.osuosl.org [127.0.0.1]) (amavis, port 10024) with ESMTP\n id ON9-017Kqefw for <buildroot@buildroot.org>;\n Thu, 30 Apr 2026 04:51:12 +0000 (UTC)","from dd20012.kasserver.com (dd20012.kasserver.com [85.13.140.57])\n by smtp4.osuosl.org (Postfix) with ESMTPS id E869D4217C\n for <buildroot@buildroot.org>; Thu, 30 Apr 2026 04:51:11 +0000 (UTC)","from fli4l.lan.fli4l (p54a1bb47.dip0.t-ipconnect.de [84.161.187.71])\n by dd20012.kasserver.com (Postfix) with ESMTPSA id 17470A4C0EA0\n for <buildroot@buildroot.org>; Thu, 30 Apr 2026 06:51:10 +0200 (CEST)","from bruckner.lan.fli4l ([192.168.1.1]:34988)\n by fli4l.lan.fli4l with esmtp (Exim 4.99.2)\n (envelope-from <bernd@kuhls.net>) id 1wIJMj-000000000HI-1Pbh\n for buildroot@buildroot.org; Thu, 30 Apr 2026 04:51:09 +0000"],"X-Virus-Scanned":["amavis at osuosl.org","amavis at osuosl.org"],"X-Comment":"SPF check N/A for local connections - client-ip=140.211.166.142;\n helo=lists1.osuosl.org; envelope-from=buildroot-bounces@buildroot.org;\n receiver=<UNKNOWN> ","DKIM-Filter":["OpenDKIM Filter v2.11.0 smtp1.osuosl.org 62957849F4","OpenDKIM Filter v2.11.0 smtp4.osuosl.org E869D4217C"],"DKIM-Signature":"v=1; a=rsa-sha256; c=relaxed/relaxed; d=buildroot.org;\n\ts=default; t=1777524675;\n\tbh=wXiAJyxr5Yk/likRwkNmdLxXJOx8W5cMFV9+yRDAr30=;\n\th=From:To:Date:Subject:List-Id:List-Unsubscribe:List-Archive:\n\t List-Post:List-Help:List-Subscribe:From;\n\tb=OBJB14JiJV6ibbJ/8DtLNz+55kN7efRPug817GcCX0CpDtkkEP+CA/rKD+vRg2/qG\n\t 6BuA4sXTaCIpW8CTI4b9cgFch/EgcgE2O1kSfQQ075K9SXe8anIB63SEnEHIQMzeYC\n\t ib1St6T/JzPjbdJtKLCQOmBFFrFC7BNh03oibwzuVM/Pf6uq6XmVmgAjjCM7fSEbo6\n\t oNN0kk9fzWBo6gHnNN8ULbUrYYXMpYrdgANAslsGVdaOqtwfO9Qf+2xAqd5zysdfaX\n\t pisnXDfrx8VRL/WeXDDOZYHeH2gNDQfF/JuuMWlnxDLzpEbx1EVse42hCZ4RPPhIej\n\t 7gXYjkdE07zzQ==","Received-SPF":"Pass (mailfrom) identity=mailfrom; client-ip=85.13.140.57;\n helo=dd20012.kasserver.com; envelope-from=bernd@kuhls.net;\n receiver=<UNKNOWN>","DMARC-Filter":"OpenDMARC Filter v1.4.2 smtp4.osuosl.org E869D4217C","From":"Bernd Kuhls <bernd@kuhls.net>","To":"buildroot@buildroot.org","Date":"Thu, 30 Apr 2026 06:51:09 +0200","Message-ID":"<20260430045109.59810-1-bernd@kuhls.net>","X-Mailer":"git-send-email 2.47.3","MIME-Version":"1.0","X-Spamd-Bar":"--","X-Mailman-Original-DKIM-Signature":"v=1; a=rsa-sha256; c=relaxed/relaxed;\n d=kuhls.net;\n s=kas202511301023; t=1777524670;\n bh=OVHobJnGs/ADuJgkWmSRaeX5U+0pru5mlxXYGR0XQXA=;\n h=From:To:Subject:Date:From;\n b=QtN41MBvgurDBYa3l03XTlQ8egXj2iOGXDi0sWSH5a7j1EVeRs7HaTm8dGwEUEhm7\n /5uebs3bAZBEMFYfps6v/mfluP6x5W4voSMxqAQJ0haF24IW6vHwf8QgMZ9MEurqfz\n EpqmOO2RUNlBFBjGQydRfmG4bzR2HRUadilbXMw1iwYihv/qd7FiGAkPYboD9YAT23\n YKxuRluYk+Z+LTRkwJ6yty83mJ7uu7aG+Dh2ghfVRDosaqsq3rnMpgpao7TmxN3i0X\n YOiMbrRmyj9dx/jzM+exy8tYRd5jRXZD05+KvxRUjZ4uF3JuBTHECb0C8Bs/R6GReR\n gAAA1Rss9Mb3A==","X-Mailman-Original-Authentication-Results":["smtp4.osuosl.org;\n dmarc=pass (p=none dis=none)\n header.from=kuhls.net","smtp4.osuosl.org;\n dkim=pass (2048-bit key) header.d=kuhls.net header.i=@kuhls.net\n header.a=rsa-sha256 header.s=kas202511301023 header.b=QtN41MBv"],"Subject":"[Buildroot] [PATCH 1/1] package/gnutls: security bump to version\n 3.8.13","X-BeenThere":"buildroot@buildroot.org","X-Mailman-Version":"2.1.30","Precedence":"list","List-Id":"Discussion and development of buildroot <buildroot.buildroot.org>","List-Unsubscribe":"<https://lists.buildroot.org/mailman/options/buildroot>,\n <mailto:buildroot-request@buildroot.org?subject=unsubscribe>","List-Archive":"<http://lists.buildroot.org/pipermail/buildroot/>","List-Post":"<mailto:buildroot@buildroot.org>","List-Help":"<mailto:buildroot-request@buildroot.org?subject=help>","List-Subscribe":"<https://lists.buildroot.org/mailman/listinfo/buildroot>,\n <mailto:buildroot-request@buildroot.org?subject=subscribe>","Content-Type":"text/plain; charset=\"us-ascii\"","Content-Transfer-Encoding":"7bit","Errors-To":"buildroot-bounces@buildroot.org","Sender":"\"buildroot\" <buildroot-bounces@buildroot.org>"},"content":"https://lists.gnupg.org/pipermail/gnutls-help/2026-April/004922.html\n\nFixes the following CVEs:\n\nCVE-2026-33845\nCVE-2026-33846\nCVE-2026-3832\nCVE-2026-3833\nCVE-2026-42009\nCVE-2026-42010\nCVE-2026-42011\nCVE-2026-42012\nCVE-2026-42013\nCVE-2026-42014\nCVE-2026-42015\nCVE-2026-5260\nCVE-2026-5419\n\nSigned-off-by: Bernd Kuhls <bernd@kuhls.net>\n---\n package/gnutls/gnutls.hash | 4 ++--\n package/gnutls/gnutls.mk   | 2 +-\n 2 files changed, 3 insertions(+), 3 deletions(-)","diff":"diff --git a/package/gnutls/gnutls.hash b/package/gnutls/gnutls.hash\nindex 209b6aa220..99a721d208 100644\n--- a/package/gnutls/gnutls.hash\n+++ b/package/gnutls/gnutls.hash\n@@ -1,6 +1,6 @@\n # Locally calculated after checking pgp signature\n-# https://www.gnupg.org/ftp/gcrypt/gnutls/v3.8/gnutls-3.8.12.tar.xz.sig\n-sha256  a7b341421bfd459acf7a374ca4af3b9e06608dcd7bd792b2bf470bea012b8e51  gnutls-3.8.12.tar.xz\n+# https://www.gnupg.org/ftp/gcrypt/gnutls/v3.8/gnutls-3.8.13.tar.xz.sig\n+sha256  ffed8ec1bf09c2426d4f14aae377de4753b53e537d685e604e99a8b16ca9c97e  gnutls-3.8.13.tar.xz\n # Locally calculated\n sha256  3972dc9744f6499f0f9b2dbf76696f2ae7ad8af9b23dde66d6af86c9dfb36986  COPYING\n sha256  20e50fe7aae3e56378ebf0417d9de904f55a0e61e4df315333e632a4d3555d95  COPYING.LESSERv2\ndiff --git a/package/gnutls/gnutls.mk b/package/gnutls/gnutls.mk\nindex 0844bfe50d..6411a7d621 100644\n--- a/package/gnutls/gnutls.mk\n+++ b/package/gnutls/gnutls.mk\n@@ -6,7 +6,7 @@\n \n # When bumping, make sure *all* --without-libfoo-prefix options are in GNUTLS_CONF_OPTS\n GNUTLS_VERSION_MAJOR = 3.8\n-GNUTLS_VERSION = $(GNUTLS_VERSION_MAJOR).12\n+GNUTLS_VERSION = $(GNUTLS_VERSION_MAJOR).13\n GNUTLS_SOURCE = gnutls-$(GNUTLS_VERSION).tar.xz\n GNUTLS_SITE = https://www.gnupg.org/ftp/gcrypt/gnutls/v$(GNUTLS_VERSION_MAJOR)\n GNUTLS_LICENSE = LGPL-2.1+ (core library)\n","prefixes":["1/1"]}