Skip to content

telegram-desktop: fix cve-2026-107181 - #62956

Open
JkktBkkt wants to merge 1 commit into
void-linux:masterfrom
JkktBkkt:telegram-cve-fix
Open

JkktBkkt wants to merge 1 commit into
void-linux:masterfrom
JkktBkkt:telegram-cve-fix

Conversation

@JkktBkkt

@JkktBkkt JkktBkkt commented Oct 10, 2026 •

Copy link
Copy Markdown
Contributor

Testing the changes

  • I tested the changes in this PR: briefly

Local build testing

  • I built this PR locally for my native architecture, x86-64
  • I have not built this PR locally for other architectures, am relying on CI from this PR

As seen on https://bugs.gentoo.org/983963#c8, applying just this patch should fix the vulnerability, which means we can postpone packaging 7.2.9+ version of telegram-desktop (doing so is non-trivial due to new dependencies, attempted by ar-jan with LLM use: https://github.com/ar-jan/void-packages/tree/telegram730)

Credit to ar-jan for bringing this issue up.

@JkktBkkt

JkktBkkt commented Oct 10, 2026 •

Copy link
Copy Markdown
Contributor Author

I dropped the conditional nocross in (different wordsize of host and target machines) and was able to build for armv{6,7}l{,-musl} with no further changes necessary locally.

Unfortunately I do not have a way to properly test those resulting builds.

@JkktBkkt

JkktBkkt commented Oct 10, 2026 •

Copy link
Copy Markdown
Contributor Author

aarch64-musl failure is unrelated to changes in this PR and that build succeeded with previous push (when the nocross condition was still in the template, which doesn't apply to aarch64-musl builds on x86_64-musl host)
That run can be seen here: https://github.com/void-linux/void-packages/actions/runs/38069043307/job/114262516582

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant