cx23885-firmware
maintainer TheChickenMan
· 1 votes
· scanned 2026-08-03 00:08:14.047287
LOW
View on AUR ↗
Why flagged
The package downloads firmware and a script from a personal domain to extract and install non-executable firmware files; the worst case of a swapped source is limited to firmware tampering, not code execution, and the source is plausibly project-specific.
Triggered rules
LOW
AI review downgraded a static finding
llm_review
The static rules flagged this MEDIUM, but an AI model (qwen/qwen3-235b-a22b-07-25) reviewed the full PKGBUILD and judged it LOW (confidence 95%): The package downloads firmware and a script from a personal domain to extract and install non-executable firmware files; the worst case of a swapped source is limited to firmware tampering, not code execution, and the source is plausibly project-specific.
1 higher static finding superseded - not the current verdict (shown for transparency)
MEDIUM
source=() URL on a non-standard host
source_untrusted_domain
One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).
-
PKGBUILD:11
source=('http://steventoth.net/linux/hvr1800/HVR-12x0-14x0-17x0_1_25_25271_WHQL.zip'
PKGBUILD
1 offending line(s) highlighted
1
# Maintainer: M.Reynolds <blackboxnetworkproject@gmail.com>
2
3
pkgname=cx23885-firmware
4
pkgver=2016.04.16
5
pkgrel=2
6
pkgdesc="Hauppauge hvr1800 tv-tuner card firmware."
7
arch=('any')
8
url="http://permalink.gmane.org/gmane.linux.drivers.video-input-infrastructure/46978"
9
license=('custom')
10
depends=('linux-firmware')
11
source=('http://steventoth.net/linux/hvr1800/HVR-12x0-14x0-17x0_1_25_25271_WHQL.zip'
12
'http://steventoth.net/linux/hvr1800/extract.sh'
13
'http://steventoth.net/linux/hvr1800/readme.txt')
14
sha256sums=('ccbe3bc8b8545ecf00cf3fc47af1b33f312a6f2e873a3e29ce1e8b82adef49d9'
15
'8c231e54c08920b144df44017db111835c557fca7c4082c412eb6fa9d413be5a'
16
'b6d27d2e6c6d1101556ede4539d672ba6b780462a171a2f9f445a09107228285')
17
18
build() {
19
cd "$srcdir"
20
sh extract.sh
21
}
22
23
package() {
24
cd "$srcdir"
25
26
_systemdbasedir="$pkgdir/usr/lib/firmware"
27
install -Dm644 v4l-cx23885-enc.fw "$_systemdbasedir/v4l-cx23885-enc.fw"
28
29
# The below file is owned by the package linux-firmware and so should not be extracted
30
# install -Dm644 v4l-cx23885-avcore-01.fw "$_systemdbasedir/v4l-cx23885-avcore-01.fw"
31
}
32
Scan history
| Scanned at (UTC) | Severity | Rules |
|---|---|---|
| 2026-08-03 00:08:14 | LOW | 2 |
| 2026-08-02 00:16:08 | LOW | 2 |
| 2026-08-01 00:11:18 | LOW | 2 |
| 2026-07-31 00:14:10 | LOW | 2 |
| 2026-07-30 00:17:23 | LOW | 2 |
| 2026-07-29 00:25:53 | LOW | 2 |
| 2026-07-28 00:07:28 | LOW | 2 |
| 2026-07-27 00:24:32 | LOW | 2 |
| 2026-07-26 00:07:32 | LOW | 2 |
| 2026-07-25 00:13:44 | LOW | 2 |
| 2026-07-24 00:02:28 | LOW | 2 |
| 2026-07-23 00:14:47 | LOW | 2 |
| 2026-07-22 00:29:32 | LOW | 2 |
| 2026-07-21 00:24:15 | LOW | 2 |
| 2026-07-20 00:19:49 | LOW | 2 |
| 2026-07-19 00:17:08 | LOW | 2 |
| 2026-07-18 00:14:48 | LOW | 2 |
| 2026-07-17 00:06:16 | LOW | 2 |
| 2026-07-16 00:05:41 | LOW | 2 |
| 2026-07-15 00:09:25 | LOW | 2 |