Logo
componentcmake
Name
cmake
Version
3.28.3
Type
library
Description
Cross-platform, open-source make system
Licenses
BSD-3-Clause & BSD-1-Clause & MIT
PURL
-
CPE
cpe:2.3:*:cmake_project:cmake:3.28.3:*:*:*:*:*:*:*

Other Versions#


Project
Branch
Version
kirkstone
3.22.3
master
4.3.3

Patches#


#
Title
Author
Resolve
1
CMakeDetermineCompilerABI: Strip -pipe from compile flags
Philip Lorenz <philip.lorenz@bmw.de>
2
Disable use of ext2fs/ext2_fs.h by cmake's internal
Otavio Salvador <otavio@ossystems.com.br>
3
foreach: Explicitly skip replay without iterations
Tyler Yankee <tyler.yankee@kitware.com>
CVE-2025-9301
4
bootstrap: Fix compilation with gcc 16 devirtualization
Brad King <brad.king@kitware.com>
5
cppdap: include/dap/network.h: add <stdint.h> include for GCC
=?UTF-8?q?Christoph=20Gr=C3=BCninger?= <foss@grueninger.de>
6
CMakeLists.txt: disable USE_NGHTTP2
Changqing Li <changqing.li@windriver.com>
7
ctest: Allow arbitrary characters in test names of
John Drouhard <john@drouhard.dev>

Vulnerabilities#


Name
Analysis
Description
Patched
A vulnerability was determined in cmake 4.1.20250725-gb5cce23. This affects the function cmForEachFunctionBlocker::ReplayItems of the file cmForEachCommand.cxx. This manipulation causes reachable assertion. The attack needs to be launched locally. The exploit has been publicly disclosed and may be utilized. Patch name: 37e27f71bc356d880c908040cd0cb68fa2c371b8. It is suggested to install a patch to address this issue.