From patchwork Tue Jul 6 09:15:01 2021 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Heiko Thiery X-Patchwork-Id: 1501094 Return-Path: X-Original-To: incoming-buildroot@patchwork.ozlabs.org Delivered-To: patchwork-incoming-buildroot@bilbo.ozlabs.org Authentication-Results: ozlabs.org; spf=pass (sender SPF authorized) smtp.mailfrom=busybox.net (client-ip=140.211.166.138; helo=smtp1.osuosl.org; envelope-from=buildroot-bounces@busybox.net; receiver=) Authentication-Results: ozlabs.org; dkim=fail reason="signature verification failed" (2048-bit key; unprotected) header.d=gmail.com header.i=@gmail.com header.a=rsa-sha256 header.s=20161025 header.b=qhgTiPbN; dkim-atps=neutral Received: from smtp1.osuosl.org (smtp1.osuosl.org [140.211.166.138]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256) (No client certificate requested) by ozlabs.org (Postfix) with ESMTPS id 4GJxjS5hqCz9sWq for ; Tue, 6 Jul 2021 19:15:22 +1000 (AEST) Received: from localhost (localhost [127.0.0.1]) by smtp1.osuosl.org (Postfix) with ESMTP id A54EE8341E; Tue, 6 Jul 2021 09:15:19 +0000 (UTC) X-Virus-Scanned: amavisd-new at osuosl.org Received: from smtp1.osuosl.org ([127.0.0.1]) by localhost (smtp1.osuosl.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 7vwNKwGnJ3mx; Tue, 6 Jul 2021 09:15:18 +0000 (UTC) Received: from ash.osuosl.org (ash.osuosl.org [140.211.166.34]) by smtp1.osuosl.org (Postfix) with ESMTP id 0137C83417; Tue, 6 Jul 2021 09:15:18 +0000 (UTC) X-Original-To: buildroot@lists.busybox.net Delivered-To: buildroot@osuosl.org Received: from smtp3.osuosl.org (smtp3.osuosl.org [140.211.166.136]) by ash.osuosl.org (Postfix) with ESMTP id B78501BF2F4 for ; Tue, 6 Jul 2021 09:15:16 +0000 (UTC) Received: from localhost (localhost [127.0.0.1]) by smtp3.osuosl.org (Postfix) with ESMTP id B38A760692 for ; Tue, 6 Jul 2021 09:15:16 +0000 (UTC) X-Virus-Scanned: amavisd-new at osuosl.org Authentication-Results: smtp3.osuosl.org (amavisd-new); dkim=pass (2048-bit key) header.d=gmail.com Received: from smtp3.osuosl.org ([127.0.0.1]) by localhost (smtp3.osuosl.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id AHhaVzaPxYbR for ; Tue, 6 Jul 2021 09:15:15 +0000 (UTC) X-Greylist: whitelisted by SQLgrey-1.8.0 Received: from mail-wr1-x42d.google.com (mail-wr1-x42d.google.com [IPv6:2a00:1450:4864:20::42d]) by smtp3.osuosl.org (Postfix) with ESMTPS id BB3866063C for ; Tue, 6 Jul 2021 09:15:15 +0000 (UTC) Received: by mail-wr1-x42d.google.com with SMTP id q17so4809037wrv.2 for ; Tue, 06 Jul 2021 02:15:15 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025; h=from:to:cc:subject:date:message-id:mime-version :content-transfer-encoding; bh=q/UyvSScQR9zqSG1VDPUfWq1X/tEQiU1w+KkHYXQcEM=; b=qhgTiPbNVq8rqPxfyniMgOpOOz6jEjBOUJrCtLcWy46uVNi5fhDRtjvX7ED841vBXp hvA1Zjf++Q4rAL8g7NHq95gzT08pIynOueMlwhdmMf2CKHPWovWKap+ubjeUCVMC6F/M hM5D6JWiE5GlWDPAmAmsEauPr5AHpgXpLg0M9vkEARjMmYSQI2sRqr8npsO9OHGbBKxN XctsXkJa7TWhylwtcVfg8cinaLKQdn+GNpsNmfsfY5CxH/WBbGtOHFkj8v11NK1URdJO FguCuc/9FeF1p0WnrYUrBnCa5HGQTTgYNrESnO3M6YsVQROBQ25eGsQh0c1NuGo4kOlB 5M6w== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:from:to:cc:subject:date:message-id:mime-version :content-transfer-encoding; bh=q/UyvSScQR9zqSG1VDPUfWq1X/tEQiU1w+KkHYXQcEM=; b=f7+/3lc2DLgZU2iR+n2w5tlB86fRG4e9c37yHESEC5/YlO8zCYswFu5Y9bg2d753Lz 1sRoGvFAP8AXuIvDjmCw/RpBdugA3HDoP1S9Ohhi/3Df0GLUo8V7lWXtUwkGxXuWTZQC 1fIeiC6kt1dDSe2eo+vcNwC2Gvr/eM1YUe6uHMzBSx0ndnY9xFB16Cd6gKXJgxAz3kLs zILBXAPOYH1ILb2eVvfEgw8JlX4c6Fyzk30O2ZApVT1j3emneEu2f5t3C/QVzxpMjbMh KavoDLpdXi3oQv7pPAWaGjnOn+Mj5mdGWHO6GB2+lU4LNHW154FpvLlF5pIP3Y+3VYuw C2hg== X-Gm-Message-State: AOAM532chpDTPm6dTOtwQs/vin0MB0E8JebMAajxOXpNsreqiM+KRyL6 +gA1Bf2V9u6BW3Uf+a+/XqgZwclkSz2ryw== X-Google-Smtp-Source: ABdhPJwSc0JQIAiWGR5PU2T2+dBqqEoYErGHS8l8aStxWB65vYbuoG/BQbvgkK7OWpLGm/yzjq/PQg== X-Received: by 2002:adf:fe12:: with SMTP id n18mr20077878wrr.219.1625562913730; Tue, 06 Jul 2021 02:15:13 -0700 (PDT) Received: from hthiery.kontron.local ([213.135.10.150]) by smtp.gmail.com with ESMTPSA id s7sm16333850wrp.97.2021.07.06.02.15.12 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Tue, 06 Jul 2021 02:15:13 -0700 (PDT) From: Heiko Thiery To: buildroot@buildroot.org Date: Tue, 6 Jul 2021 11:15:01 +0200 Message-Id: <20210706091500.3236-1-heiko.thiery@gmail.com> X-Mailer: git-send-email 2.30.0 MIME-Version: 1.0 Subject: [Buildroot] [PATCH] package/linuxptp: security bump version to 3.1.1 X-BeenThere: buildroot@busybox.net X-Mailman-Version: 2.1.29 Precedence: list List-Id: Discussion and development of buildroot List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Cc: Heiko Thiery , Petr Kulhavy Errors-To: buildroot-bounces@busybox.net Sender: "buildroot" This fixes the following CVEs: - CVE-2021-3570 linuxptp: missing length check of forwarded messages - CVE-2021-3571 linuxptp: wrong length of one-step follow-up in transparent clock See mailing list post for details: https://sourceforge.net/p/linuxptp/mailman/message/37315519/ Signed-off-by: Heiko Thiery --- package/linuxptp/linuxptp.hash | 8 ++++---- package/linuxptp/linuxptp.mk | 2 +- 2 files changed, 5 insertions(+), 5 deletions(-) diff --git a/package/linuxptp/linuxptp.hash b/package/linuxptp/linuxptp.hash index 4f8a1f89fc..a5479b0ebc 100644 --- a/package/linuxptp/linuxptp.hash +++ b/package/linuxptp/linuxptp.hash @@ -1,9 +1,9 @@ -# From https://sourceforge.net/projects/linuxptp/files/v3.0/ -sha1 9a3869dbd322252c9a6bc0dbdfe8941586810a7f linuxptp-3.1.tgz -md5 2264cb69c9af947028835c12c89a7572 linuxptp-3.1.tgz +# From https://sourceforge.net/projects/linuxptp/files/v3.1.1/ +sha1 f905eabc6fd0f03c6a353f9c4ba188a3bd1b774c linuxptp-3.1.1.tgz +md5 3b79ab5e77c5b5cf06bc1c8350d405bb linuxptp-3.1.1.tgz # Locally computed: -sha256 f58f5b11cf14dc7c4f7c9efdfb27190e43d02cf20c3525f6639edac10528ce7d linuxptp-3.1.tgz +sha256 94d6855f9b7f2d8e9b0ca6d384e3fae6226ce6fc012dbad02608bdef3be1c0d9 linuxptp-3.1.1.tgz # Hash for license file: sha256 8177f97513213526df2cf6184d8ff986c675afb514d4e68a404010521b880643 COPYING diff --git a/package/linuxptp/linuxptp.mk b/package/linuxptp/linuxptp.mk index f91be921af..da23631d20 100644 --- a/package/linuxptp/linuxptp.mk +++ b/package/linuxptp/linuxptp.mk @@ -4,7 +4,7 @@ # ################################################################################ -LINUXPTP_VERSION = 3.1 +LINUXPTP_VERSION = 3.1.1 LINUXPTP_SOURCE = linuxptp-$(LINUXPTP_VERSION).tgz LINUXPTP_SITE = http://downloads.sourceforge.net/linuxptp LINUXPTP_LICENSE = GPL-2.0+