|
|
Log in / Subscribe / Register

SUSE alert openSUSE-SU-2026:21155-1 (hamlib)

From:  null@suse.de
To:  security-announce@lists.opensuse.org
Subject:  openSUSE-SU-2026:21155-1: moderate: Security update for hamlib
Date:  Tue, 30 Jun 2026 09:48:39 +0200
Message-ID:  <20260630074839.9707FFF4B@maintenance.suse.de>
Archive-link:  Article

openSUSE security update: security update for hamlib ------------------------------------------------------------- Announcement ID: openSUSE-SU-2026:21155-1 Rating: moderate References: * bsc#1268628 * bsc#1268629 Cross-References: * CVE-2026-54634 Affected Products: openSUSE Leap 16.0 ------------------------------------------------------------- An update that solves one vulnerability and has 2 bug fixes can now be installed. Description: This update for hamlib fixes the following issues: Changes in hamlib: - Update to 4.7.2: * Fix IC-7600/IC-7610 clock commands * Icom: Add CWR to modes eligible for DSP filtering * Kenwood: New model Hamgeek uSGX * Various fixes for Skywatcher, DX-SR8, FT-710, FTX-1, IC-705, X6100 * rigctld: Fix send_raw stack out-of-bounds write and uninitialized memory CVE-2026-54634 (boo#1268628) * rigctld: Fix stack/heap overflow primitive in read_string_generic + auth bypass in rigctld + weak password handling (boo#1268629) - Update to 4.7.1: * Various compiler and portability fixes * Fix rig port timeout * Fix various FTX-1 meter, level and CTCSS table * Add power off capability to Flrig backend * Add SWR to supported 'get levels' for K3/K4 * Add get_split_vfo to TS-850 backend * New simplecat backend * Fix and generalize clock handling for Icom radios * Fix Yaesu attenuator levels and LVL_KEYSPD reinitialization * Add new rig model Harris PRC-138 * Various FT-710 fixes, eespecially handling SH format and RX bandwidth * Ensure FT-710 simulator rejects RF command * Fix low power calculation for K3/K3S * Fix FTX-1 SH bandwidth command in set/get_mode - Update to 4.7.0: * Revamp Kenwood voice memory handler - Fixes TS-890S & TS-990S * libusb is now detected using the pkg-config facility. * Functions rig_get_conf, rot_get_conf, amp_get_conf deprecated use *_get_conf2() instead * rig_set_trn and rig_get_trn deprecated. * Many fixes for SWIG binding generation and improved Python support and testing * Fix AGC for IC-R75, fix AGC for all Icom rigs * New Drake R8 backend * New AF6SA WRC rotator backend * New Yaesu FTX-1 model support (alpha) * Update QRPLabs QMX backend for max serial rate of 230400 bps * Updates to Icom IC-F8101 * New rig model Icom ID-52A/W Plus * Fix memory leaks in rigctld and rigctltcp * Fix Skywatcher backend for firmware that doesn't echo commands * Additional Yaesu FTX-1 capabilities * Add extended commands for the IC-7300MK2-- * Revert updating FLRig model name * Add manual pages for rigctltcp, rigtestlibusb, rigtestmcast, and rigtestmcastrx * Pause building rigfreqwalk as the code does not align with the required commandline parameters * Developer visible changes, code moves and refactoring - Update to 4.6.5: * Update Kenwood CW buffer max message size, fix one byte buffer overrun * Fix segmentation Faults Patch instructions: To install this openSUSE security update use the suse recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 16.0 zypper in -t patch openSUSE-Leap-16.0-packagehub-350=1 Package List: - openSUSE Leap 16.0: hamlib-4.7.2-bp160.1.1 hamlib-devel-4.7.2-bp160.1.1 libhamlib++4-4.7.2-bp160.1.1 libhamlib4-4.7.2-bp160.1.1 lua-Hamliblua-4.7.2-bp160.1.1 perl-Hamlib-4.7.2-bp160.1.1 python3-Hamlib-4.7.2-bp160.1.1 tcl-Hamlib-4.7.2-bp160.1.1 References: * https://www.suse.com/security/cve/CVE-2026-54634.html


to post comments


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds