From patchwork Fri Oct 2 11:23:30 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Adolf Belka X-Patchwork-Id: 10303 Return-Path: Received: from mail01.ipfire.org (mail01.haj.ipfire.org [172.28.1.202]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange x25519) (Client CN "mail01.haj.ipfire.org", Issuer "YR2" (not verified)) by web04.haj.ipfire.org (Postfix) with ESMTPS id 4hx5yF1GFvz3x51 for ; Fri, 02 Oct 2026 11:23:49 +0000 (UTC) Received: from mail02.haj.ipfire.org (mail02.haj.ipfire.org [172.28.1.201]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange x25519) (Client CN "mail02.haj.ipfire.org", Issuer "YE1" (not verified)) by mail01.ipfire.org (Postfix) with ESMTPS id 4hx5yC4jbJz85R for ; Fri, 02 Oct 2026 11:23:47 +0000 (UTC) Received: from mail02.haj.ipfire.org (localhost [IPv6:::1]) by mail02.haj.ipfire.org (Postfix) with ESMTP id 4hx5y80ldxz37Jj for ; Fri, 02 Oct 2026 11:23:44 +0000 (UTC) X-Original-To: development@lists.ipfire.org Received: from mail01.ipfire.org (mail01.haj.ipfire.org [172.28.1.202]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange x25519) (Client CN "mail01.haj.ipfire.org", Issuer "YR2" (not verified)) by mail02.haj.ipfire.org (Postfix) with ESMTPS id 4hx5y31NL1z37Fw for ; Fri, 02 Oct 2026 11:23:39 +0000 (UTC) Received: from [127.0.0.1] (localhost [127.0.0.1]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange x25519 server-signature RSA-PSS (4096 bits) server-digest SHA256) (No client certificate requested) by mail01.ipfire.org (Postfix) with ESMTPSA id 4hx5y13y2Lz82P; Fri, 02 Oct 2026 11:23:37 +0000 (UTC) DKIM-Signature: v=1; a=ed25519-sha256; c=relaxed/relaxed; d=ipfire.org; s=202003ed25519; t=1790940217; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=ojH/hyAultmDy7oQa9d9d3vLrdJPiBTaCfoO+KWYauY=; b=iAh9tXfP529FtkVMZ78J3vqyksuJAXG4jJviI/dG1lEu3e44pji3qE0ekOMPGftBbXmGHe rmX2qmO+4SpJaMAQ== DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=ipfire.org; s=202003rsa; t=1790940217; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=ojH/hyAultmDy7oQa9d9d3vLrdJPiBTaCfoO+KWYauY=; b=DWQpoAgT/4rJ6Bpcz5EjZUacUCee20tz2RCfPOH0zClipeeSrJRXq4Bm4FS9zGOpOGkAh0 5AoyGHPMmCEFI3L49URwueG5CnpIjL6f089Z0SSFn1jEOAY2TfoxQQjUvRtZNNDGse6+9d kBynU+tpLRTIBF5OPMXhhIq9I8zAEui+qB6vLXWDwcbz4SAappJS2jqP6Rl42JmCjWqkrh d8qR9dxhYvwHc7C+U8qRker6/nBnXzVAjw0msksKzIsNkH79aTOwSOgJB1Ku4tmQAyS5+E vx37HYfCHwyALzhim22gHDsTtfi2DVJgkOA/gUfEfDfjoNgrcXAqI2824SRXTg== From: Adolf Belka To: development@lists.ipfire.org Cc: Adolf Belka Subject: [PATCH] swtpm: Update to version 0.10.2 Date: Fri, 2 Oct 2026 13:23:30 +0200 Message-ID: <20261002112330.3568361-13-adolf.belka@ipfire.org> In-Reply-To: <20261002112330.3568361-1-adolf.belka@ipfire.org> References: <20261002112330.3568361-1-adolf.belka@ipfire.org> Precedence: list List-Id: List-Subscribe: , List-Unsubscribe: , List-Post: List-Help: Sender: Mail-Followup-To: MIME-Version: 1.0 - Update from version 0.10.1 to 0.10.2 - No change in rootfile - 1 CVE fix - Changelog 0.10.2 - swtpm: - Fix length check in SWTPM_NVRAM_CheckHeader() (CVE-2026-75900) - Properly check for truncation following snprintf call - selinux: - Fix policy loading with 3.11 SElinux toolchain (bsc#1271417) - Add SELinux policy for virtqemud_t swtpm_t setsched process and unix socket interactions. - tests: - Retry NVWrite command after 0x922 return code and inc lockout counter - Extend regex to allow for optional RSA-4096 keys Signed-off-by: Adolf Belka --- lfs/swtpm | 12 ++++++------ 1 file changed, 6 insertions(+), 6 deletions(-) diff --git a/lfs/swtpm b/lfs/swtpm index 1547610a2..c2474f935 100644 --- a/lfs/swtpm +++ b/lfs/swtpm @@ -1,7 +1,7 @@ ############################################################################### # # # IPFire.org - A linux based firewall # -# Copyright (C) 2007-2025 IPFire Team # +# Copyright (C) 2007-2026 IPFire Team # # # # This program is free software: you can redistribute it and/or modify # # it under the terms of the GNU General Public License as published by # @@ -26,7 +26,7 @@ include Config SUMMARY = Libtpms-based TPM emulator with socket, character device, and Linux CUSE interface. -VER = 0.10.1 +VER = 0.10.2 THISAPP = swtpm-$(VER) DL_FILE = $(THISAPP).tar.gz @@ -34,7 +34,7 @@ DL_FROM = $(URL_IPFIRE) DIR_APP = $(DIR_SRC)/$(THISAPP) TARGET = $(DIR_INFO)/$(THISAPP) PROG = swtpm -PAK_VER = 2 +PAK_VER = 3 DEPS = libtpms @@ -48,7 +48,7 @@ objects = $(DL_FILE) $(DL_FILE) = $(DL_FROM)/$(DL_FILE) -$(DL_FILE)_BLAKE2 = fa282338a975b4e3067e444ae5781744b3c153f482377a11b5c71072ed519709d561f6759e478a008813946da2f03c0650259d9f1ca17afd07892cd37f46529e +$(DL_FILE)_BLAKE2 = bcbfeac547616395a7513323f24b6bcf2de8ca176ecf5f5c2db85f96d093b9eee5fe3cd493c6ba5a7710629ad95ce99f52b9dd7b8cd28021f1ff4562badccb69 install : $(TARGET) @@ -84,8 +84,8 @@ $(TARGET) : $(patsubst %,$(DIR_DL)/%,$(objects)) -mkdir -pv $(DIR_APP) cd $(DIR_APP) && autoreconf -vfi cd $(DIR_APP) && ./configure \ - --prefix=/usr \ - --disable-hardening + --prefix=/usr \ + --disable-hardening cd $(DIR_APP) && make $(MAKETUNING) cd $(DIR_APP) && make install @rm -rf $(DIR_APP)