mbox

[wrynose,00/60] Patch review

Message ID cover.1791707817.git.yoann.congal@smile.fr
State Not Applicable, archived
Headers show

Pull-request

https://git.openembedded.org/openembedded-core-contrib stable/wrynose-review

Message

Yoann Congal Oct. 11, 2026, 8:39 a.m. UTC
Please review this set of changes for wrynose and have comments back by
end of day Tuesday, October 13.

Passed a-full on autobuilder:
https://autobuilder.yoctoproject.org/valkyrie/?#/builders/29/builds/4907
qemuarm-tc failed due to disk space issue on the autobuilder worker.
Retried in https://autobuilder.yoctoproject.org/valkyrie/?#/builders/42/builds/4782

The following changes since commit 0f03c732a0a2d0506b41b1abe60b3f368b2300dc:

  build-appliance-image: Update to wrynose head revisions (2026-09-30 11:06:32 +0100)

are available in the Git repository at:

  https://git.openembedded.org/openembedded-core-contrib stable/wrynose-review
  https://git.openembedded.org/openembedded-core-contrib/log/?h=stable/wrynose-review

for you to fetch changes up to d1d174cf7d58aae5f00281aafcebc2fe11e41200:

  libpcre2: patch CVE-2026-103111 (2026-10-10 23:41:04 +0200)

----------------------------------------------------------------

Alexander Kanavin (1):
  tzcode/tzdata: fix upstream version check

Babanpreet Singh (2):
  devtool: standard: fix update-recipe/finish --initial-rev override
  oeqa/selftest/devtool: cover update-recipe --initial-rev

Bhavesh R Maheshwari (2):
  ffmpeg: Fix for CVE-2026-66036
  ffmpeg: Fix for CVE-2026-66041

Darsh Kelaiya (1):
  python3-click: depend on python3-shell for shlex

Deepesh Varatharajan (1):
  glibc: stable 2.43 branch updates to 9cda6fc96ab

Frieder Schrempf (1):
  weston: fix VNC backend build with aml 1.0

Ghanshyam Banait (1):
  wget: fix CVE-2026-15146

Harish Sadineni (2):
  glibc: stable 2.43 branch updates to 562cd7badd
  qemuriscv.inc: default to fw_dynamic.elf as QEMU BIOS

Hetvi Thakar (5):
  openssh: fix CVE-2026-73283
  openssh: fix CVE-2026-73282
  openssh: fix CVE-2026-73281
  vim: set CVE_STATUS for CVE-2026-51400
  vim: set CVE_STATUS for CVE-2026-51401

Jaipaul Cheernam (1):
  bind: upgrade 9.20.26 -> 9.20.27

Jakub Szczudlo (Nokia) (5):
  gnutls: fix CVE-2026-42012
  gnutls: fix CVE-2026-42013
  gnutls: fix CVE-2026-42014
  gnutls: fix CVE-2026-42015
  gnutls: fix CVE-2026-5260

Lucas Stach (1):
  barebox: upgrade 2026.04.0 -> 2026.04.2

Peter Marko (32):
  glibc: set status for CVE-2011-0536 and CVE-2025-0577
  gnutls: set status for CVE-2023-0361
  libarchive: set status for CVE-2026-4424
  nfs-utils: set status for CVE-2025-12801
  openssl: set status for CVE-2015-3216
  ovmf: set status of CVE-2017-5731 and CVE-2019-14584
  ppp: set status for CVE-2020-15704
  pulseaudio: set status for CVE-2020-15710 and CVE-2020-16123
  graphene: set status for CVE-2026-81281
  openssh: set status for CVE-2026-55655
  openssh: set status for CVE-2026-55654
  xserver-xorg: set status for CVE-2026-55999 and CVE-2026-56000
  openssl: upgrade 3.5.8 -> 3.5.9
  glibc: set status for CVE-2026-86805 and CVE-2026-95818
  libpng: upgrade 1.6.56 -> 1.6.58
  libpng: upgrade 1.6.58 -> 1.6.59
  util-linux(-uuid): upgrade 2.41.5 -> 2.41.6
  libsolv: patch CVE-2026-48863
  expat: patch CVE-2026-66046 and CVE-2026-76641
  expat: patch CVE-2026-76956
  expat: patch CVE-2026-76957
  expat: patch CVE-2026-93990
  alsa-lib: patch CVE-2026-90781
  go: upgrade 1.26.8 -> 1.26.9
  libpcre2: patch CVE-2026-89162
  libpcre2: patch CVE-2026-89161
  libpcre2: patch CVE-2026-89156
  libpcre2: patch CVE-2026-89157
  libpcre2: patch CVE-2026-89160
  libpcre2: patch CVE-2026-89158
  libpcre2: patch CVE-2026-86145
  libpcre2: patch CVE-2026-103111

Peter Tatrai (1):
  systemd: fix mDNS hostname changes

Richard Purdie (1):
  bind: upgrade 9.20.27 -> 9.20.29

Ross Burton (2):
  gstreamer: skip test_queue:test_leaky_downstream test as it's flakey
  libaio: update SRC_URI

Vijay Anusuri (1):
  tzdata/tzcode-native: upgrade 2026c -> 2026d

 meta/conf/machine/include/riscv/qemuriscv.inc |   5 +-
 meta/lib/oeqa/selftest/cases/devtool.py       |  22 +
 meta/recipes-bsp/barebox/barebox-common.inc   |   4 +-
 ...1-avoid-start-failure-with-bind-user.patch |   2 +-
 ...kport-ax_prog_cc_for_build.m4-macros.patch |   2 +-
 ...d-V-and-start-log-hide-build-options.patch |   4 +-
 ...ching-for-json-headers-searches-sysr.patch |   4 +-
 .../recipes-connectivity/bind/bind/conf.patch |   2 +-
 ...t.d-add-support-for-read-only-rootfs.patch |   2 +-
 .../bind/make-etc-initd-bind-stop-work.patch  |   2 +-
 .../bind/{bind_9.20.26.bb => bind_9.20.29.bb} |   2 +-
 .../nfs-utils/nfs-utils_2.8.7.bb              |   2 +
 .../openssh/openssh/CVE-2026-73281.patch      |  80 +++
 .../openssh/openssh/CVE-2026-73282.patch      |  80 +++
 .../openssh/openssh/CVE-2026-73283.patch      |  42 ++
 .../openssh/openssh_10.3p1.bb                 |   5 +
 .../{openssl_3.5.8.bb => openssl_3.5.9.bb}    |   4 +-
 meta/recipes-connectivity/ppp/ppp_2.5.2.bb    |   1 +
 .../expat/expat/CVE-2026-66046-01.patch       | 107 ++++
 .../expat/expat/CVE-2026-66046-02.patch       |  90 +++
 .../expat/expat/CVE-2026-76641.patch          | 160 ++++++
 .../expat/expat/CVE-2026-76956.patch          |  26 +
 .../expat/expat/CVE-2026-76957-01.patch       | 121 ++++
 .../expat/expat/CVE-2026-76957-02.patch       |  85 +++
 .../expat/expat/CVE-2026-93990-01.patch       | 191 +++++++
 .../expat/expat/CVE-2026-93990-02.patch       | 328 +++++++++++
 meta/recipes-core/expat/expat_2.8.3.bb        |   8 +
 meta/recipes-core/glibc/glibc-version.inc     |   2 +-
 meta/recipes-core/glibc/glibc_2.43.bb         |   5 +
 meta/recipes-core/ovmf/ovmf_git.bb            |   2 +
 ...use-traffic-from-the-local-host-only.patch |  61 +++
 meta/recipes-core/systemd/systemd_259.5.bb    |   1 +
 ...2.41.5.bb => util-linux-libuuid_2.41.6.bb} |   0
 meta/recipes-core/util-linux/util-linux.inc   |   5 +-
 ...sing-fileutils.h-include-to-hook_idm.patch |  38 ++
 .../util-linux/CVE-2026-78408.patch           |  75 +++
 .../util-linux/CVE-2026-78410.patch           | 115 ++++
 ...l-linux_2.41.5.bb => util-linux_2.41.6.bb} |   0
 .../go/{go-1.26.8.inc => go-1.26.9.inc}       |   2 +-
 ...e_1.26.8.bb => go-binary-native_1.26.9.bb} |   6 +-
 ..._1.26.8.bb => go-cross-canadian_1.26.9.bb} |   0
 ...{go-cross_1.26.8.bb => go-cross_1.26.9.bb} |   0
 ...osssdk_1.26.8.bb => go-crosssdk_1.26.9.bb} |   0
 ...runtime_1.26.8.bb => go-runtime_1.26.9.bb} |   0
 ...ent-based-hash-generation-less-pedan.patch |   8 +-
 ...3-ld-add-soname-to-shareable-objects.patch |   6 +-
 ...d-go-make-GOROOT-precious-by-default.patch |   2 +-
 ...ut-build-specific-paths-from-linker-.patch |   4 +-
 .../go/{go_1.26.8.bb => go_1.26.9.bb}         |   0
 .../python/python3-click_8.3.3.bb             |   1 +
 .../recipes-extended/libaio/libaio_0.3.113.bb |   2 +-
 .../libarchive/libarchive_3.8.7.bb            |   1 +
 .../libsolv/libsolv/CVE-2026-48863.patch      |  25 +
 .../libsolv/libsolv_0.7.36.bb                 |   1 +
 meta/recipes-extended/timezone/timezone.inc   |   8 +-
 .../wget/wget/CVE-2026-15146.patch            | 126 +++++
 meta/recipes-extended/wget/wget_1.25.0.bb     |   1 +
 .../graphene/graphene_1.10.8.bb               |   1 +
 .../weston/0001-backend-vnc-Use-aml-v1.patch  |  24 +
 .../recipes-graphics/wayland/weston_15.0.0.bb |   3 +-
 .../xorg-xserver/xserver-xorg.inc             |   2 +
 .../alsa/alsa-lib/CVE-2026-90781.patch        |  41 ++
 .../alsa/alsa-lib_1.2.15.3.bb                 |   1 +
 .../ffmpeg/ffmpeg/CVE-2026-66036_p1.patch     | 120 ++++
 .../ffmpeg/ffmpeg/CVE-2026-66036_p2.patch     |  71 +++
 .../ffmpeg/ffmpeg/CVE-2026-66041.patch        |  60 ++
 .../recipes-multimedia/ffmpeg/ffmpeg_8.0.3.bb |   3 +
 .../gstreamer/gstreamer1.0/run-ptest          |   3 +
 .../libpng/files/CVE-2026-34757_p1.patch      | 518 ------------------
 .../libpng/files/CVE-2026-34757_p2.patch      | 481 ----------------
 .../{libpng_1.6.56.bb => libpng_1.6.59.bb}    |   7 +-
 .../pulseaudio/pulseaudio.inc                 |   2 +
 .../gnutls/gnutls/CVE-2026-42012-pre1.patch   |  69 +++
 .../gnutls/gnutls/CVE-2026-42012-pre2.patch   | 161 ++++++
 .../gnutls/gnutls/CVE-2026-42012.patch        |  48 ++
 .../gnutls/gnutls/CVE-2026-42013-pre1.patch   |  56 ++
 .../gnutls/gnutls/CVE-2026-42013.patch        |  74 +++
 .../gnutls/gnutls/CVE-2026-42014.patch        |  60 ++
 .../gnutls/gnutls/CVE-2026-42015.patch        |  43 ++
 .../gnutls/gnutls/CVE-2026-5260_p1.patch      |  69 +++
 .../gnutls/gnutls/CVE-2026-5260_p2.patch      |  33 ++
 meta/recipes-support/gnutls/gnutls_3.8.12.bb  |  10 +
 .../libpcre/libpcre2/CVE-2026-103111.patch    | 111 ++++
 .../libpcre/libpcre2/CVE-2026-86145.patch     | 158 ++++++
 .../libpcre/libpcre2/CVE-2026-89156.patch     | 275 ++++++++++
 .../libpcre/libpcre2/CVE-2026-89157.patch     |  61 +++
 .../libpcre/libpcre2/CVE-2026-89158.patch     | 208 +++++++
 .../libpcre/libpcre2/CVE-2026-89160.patch     | 225 ++++++++
 .../libpcre/libpcre2/CVE-2026-89161.patch     | 221 ++++++++
 .../libpcre/libpcre2/CVE-2026-89162.patch     |  88 +++
 .../recipes-support/libpcre/libpcre2_10.47.bb |   8 +
 meta/recipes-support/vim/vim.inc              |   3 +
 scripts/lib/devtool/standard.py               |   4 +
 93 files changed, 4160 insertions(+), 1040 deletions(-)
 rename meta/recipes-connectivity/bind/{bind_9.20.26.bb => bind_9.20.29.bb} (97%)
 create mode 100644 meta/recipes-connectivity/openssh/openssh/CVE-2026-73281.patch
 create mode 100644 meta/recipes-connectivity/openssh/openssh/CVE-2026-73282.patch
 create mode 100644 meta/recipes-connectivity/openssh/openssh/CVE-2026-73283.patch
 rename meta/recipes-connectivity/openssl/{openssl_3.5.8.bb => openssl_3.5.9.bb} (98%)
 create mode 100644 meta/recipes-core/expat/expat/CVE-2026-66046-01.patch
 create mode 100644 meta/recipes-core/expat/expat/CVE-2026-66046-02.patch
 create mode 100644 meta/recipes-core/expat/expat/CVE-2026-76641.patch
 create mode 100644 meta/recipes-core/expat/expat/CVE-2026-76956.patch
 create mode 100644 meta/recipes-core/expat/expat/CVE-2026-76957-01.patch
 create mode 100644 meta/recipes-core/expat/expat/CVE-2026-76957-02.patch
 create mode 100644 meta/recipes-core/expat/expat/CVE-2026-93990-01.patch
 create mode 100644 meta/recipes-core/expat/expat/CVE-2026-93990-02.patch
 create mode 100644 meta/recipes-core/systemd/systemd/0001-Revert-resolve-refuse-traffic-from-the-local-host-only.patch
 rename meta/recipes-core/util-linux/{util-linux-libuuid_2.41.5.bb => util-linux-libuuid_2.41.6.bb} (100%)
 create mode 100644 meta/recipes-core/util-linux/util-linux/0001-libmount-add-missing-fileutils.h-include-to-hook_idm.patch
 create mode 100644 meta/recipes-core/util-linux/util-linux/CVE-2026-78408.patch
 create mode 100644 meta/recipes-core/util-linux/util-linux/CVE-2026-78410.patch
 rename meta/recipes-core/util-linux/{util-linux_2.41.5.bb => util-linux_2.41.6.bb} (100%)
 rename meta/recipes-devtools/go/{go-1.26.8.inc => go-1.26.9.inc} (90%)
 rename meta/recipes-devtools/go/{go-binary-native_1.26.8.bb => go-binary-native_1.26.9.bb} (80%)
 rename meta/recipes-devtools/go/{go-cross-canadian_1.26.8.bb => go-cross-canadian_1.26.9.bb} (100%)
 rename meta/recipes-devtools/go/{go-cross_1.26.8.bb => go-cross_1.26.9.bb} (100%)
 rename meta/recipes-devtools/go/{go-crosssdk_1.26.8.bb => go-crosssdk_1.26.9.bb} (100%)
 rename meta/recipes-devtools/go/{go-runtime_1.26.8.bb => go-runtime_1.26.9.bb} (100%)
 rename meta/recipes-devtools/go/{go_1.26.8.bb => go_1.26.9.bb} (100%)
 create mode 100644 meta/recipes-extended/libsolv/libsolv/CVE-2026-48863.patch
 create mode 100644 meta/recipes-extended/wget/wget/CVE-2026-15146.patch
 create mode 100644 meta/recipes-graphics/wayland/weston/0001-backend-vnc-Use-aml-v1.patch
 create mode 100644 meta/recipes-multimedia/alsa/alsa-lib/CVE-2026-90781.patch
 create mode 100644 meta/recipes-multimedia/ffmpeg/ffmpeg/CVE-2026-66036_p1.patch
 create mode 100644 meta/recipes-multimedia/ffmpeg/ffmpeg/CVE-2026-66036_p2.patch
 create mode 100644 meta/recipes-multimedia/ffmpeg/ffmpeg/CVE-2026-66041.patch
 delete mode 100644 meta/recipes-multimedia/libpng/files/CVE-2026-34757_p1.patch
 delete mode 100644 meta/recipes-multimedia/libpng/files/CVE-2026-34757_p2.patch
 rename meta/recipes-multimedia/libpng/{libpng_1.6.56.bb => libpng_1.6.59.bb} (94%)
 create mode 100644 meta/recipes-support/gnutls/gnutls/CVE-2026-42012-pre1.patch
 create mode 100644 meta/recipes-support/gnutls/gnutls/CVE-2026-42012-pre2.patch
 create mode 100644 meta/recipes-support/gnutls/gnutls/CVE-2026-42012.patch
 create mode 100644 meta/recipes-support/gnutls/gnutls/CVE-2026-42013-pre1.patch
 create mode 100644 meta/recipes-support/gnutls/gnutls/CVE-2026-42013.patch
 create mode 100644 meta/recipes-support/gnutls/gnutls/CVE-2026-42014.patch
 create mode 100644 meta/recipes-support/gnutls/gnutls/CVE-2026-42015.patch
 create mode 100644 meta/recipes-support/gnutls/gnutls/CVE-2026-5260_p1.patch
 create mode 100644 meta/recipes-support/gnutls/gnutls/CVE-2026-5260_p2.patch
 create mode 100644 meta/recipes-support/libpcre/libpcre2/CVE-2026-103111.patch
 create mode 100644 meta/recipes-support/libpcre/libpcre2/CVE-2026-86145.patch
 create mode 100644 meta/recipes-support/libpcre/libpcre2/CVE-2026-89156.patch
 create mode 100644 meta/recipes-support/libpcre/libpcre2/CVE-2026-89157.patch
 create mode 100644 meta/recipes-support/libpcre/libpcre2/CVE-2026-89158.patch
 create mode 100644 meta/recipes-support/libpcre/libpcre2/CVE-2026-89160.patch
 create mode 100644 meta/recipes-support/libpcre/libpcre2/CVE-2026-89161.patch
 create mode 100644 meta/recipes-support/libpcre/libpcre2/CVE-2026-89162.patch

Comments

Marko, Peter Oct. 11, 2026, 10:19 a.m. UTC | #1
Please drop my libpcre2 series for now.

When trying to create this series for scarthgap and trying to resolve conflicts I found that pcre2 now committed to do "at least five years" of maintenance for each release.
https://github.com/PCRE2Project/pcre2/commit/0f85a365a7ab586a39089f4ecdc4f9f6857c043e#diff-599c7525a19150cfd62bfa7bafbf578487389804a4ec3964ffa60d322db9bbfdR22-R44

Release branches are available that we could use.
Checking contents of release/10.47 branch, it contains commits which I picked, however some are squashed with other ones indicating that my backport was not complete.
For example fix for CVE-2026-89156 now consists of two squashed commits where I picked only one.
https://github.com/PCRE2Project/pcre2/commit/5528f329f597eabbf1cfd5a1f3b4fa51a8c02d60
This requires further study before merging.

This also opens second question, similar to one recently asked for rsync very recently.
May I switch libpcre2 to gif fetcher and update to latest release branch hash instead of backporting commits?
Or should I rather pick (potentially all) commits from there?
I'd prefer to switch to the git fetcher.

Peter

> -----Original Message-----
> From: openembedded-core@lists.openembedded.org <openembedded-
> core@lists.openembedded.org> On Behalf Of Yoann Congal via
> lists.openembedded.org
> Sent: Sunday, October 11, 2026 10:40 AM
> To: openembedded-core@lists.openembedded.org
> Subject: [OE-core][wrynose 00/60] Patch review
> 
> Please review this set of changes for wrynose and have comments back by
> end of day Tuesday, October 13.
> 
> Passed a-full on autobuilder:
> https://autobuilder.yoctoproject.org/valkyrie/?#/builders/29/builds/4907
> qemuarm-tc failed due to disk space issue on the autobuilder worker.
> Retried in https://autobuilder.yoctoproject.org/valkyrie/?#/builders/42/builds/4782
> 
> The following changes since commit 0f03c732a0a2d0506b41b1abe60b3f368b2300dc:
> 
>   build-appliance-image: Update to wrynose head revisions (2026-09-30 11:06:32
> +0100)
> 
> are available in the Git repository at:
> 
>   https://git.openembedded.org/openembedded-core-contrib stable/wrynose-review
>   https://git.openembedded.org/openembedded-core-contrib/log/?h=stable/wrynose-
> review
> 
> for you to fetch changes up to d1d174cf7d58aae5f00281aafcebc2fe11e41200:
> 
>   libpcre2: patch CVE-2026-103111 (2026-10-10 23:41:04 +0200)
> 
> ----------------------------------------------------------------
> 
> Alexander Kanavin (1):
>   tzcode/tzdata: fix upstream version check
> 
> Babanpreet Singh (2):
>   devtool: standard: fix update-recipe/finish --initial-rev override
>   oeqa/selftest/devtool: cover update-recipe --initial-rev
> 
> Bhavesh R Maheshwari (2):
>   ffmpeg: Fix for CVE-2026-66036
>   ffmpeg: Fix for CVE-2026-66041
> 
> Darsh Kelaiya (1):
>   python3-click: depend on python3-shell for shlex
> 
> Deepesh Varatharajan (1):
>   glibc: stable 2.43 branch updates to 9cda6fc96ab
> 
> Frieder Schrempf (1):
>   weston: fix VNC backend build with aml 1.0
> 
> Ghanshyam Banait (1):
>   wget: fix CVE-2026-15146
> 
> Harish Sadineni (2):
>   glibc: stable 2.43 branch updates to 562cd7badd
>   qemuriscv.inc: default to fw_dynamic.elf as QEMU BIOS
> 
> Hetvi Thakar (5):
>   openssh: fix CVE-2026-73283
>   openssh: fix CVE-2026-73282
>   openssh: fix CVE-2026-73281
>   vim: set CVE_STATUS for CVE-2026-51400
>   vim: set CVE_STATUS for CVE-2026-51401
> 
> Jaipaul Cheernam (1):
>   bind: upgrade 9.20.26 -> 9.20.27
> 
> Jakub Szczudlo (Nokia) (5):
>   gnutls: fix CVE-2026-42012
>   gnutls: fix CVE-2026-42013
>   gnutls: fix CVE-2026-42014
>   gnutls: fix CVE-2026-42015
>   gnutls: fix CVE-2026-5260
> 
> Lucas Stach (1):
>   barebox: upgrade 2026.04.0 -> 2026.04.2
> 
> Peter Marko (32):
>   glibc: set status for CVE-2011-0536 and CVE-2025-0577
>   gnutls: set status for CVE-2023-0361
>   libarchive: set status for CVE-2026-4424
>   nfs-utils: set status for CVE-2025-12801
>   openssl: set status for CVE-2015-3216
>   ovmf: set status of CVE-2017-5731 and CVE-2019-14584
>   ppp: set status for CVE-2020-15704
>   pulseaudio: set status for CVE-2020-15710 and CVE-2020-16123
>   graphene: set status for CVE-2026-81281
>   openssh: set status for CVE-2026-55655
>   openssh: set status for CVE-2026-55654
>   xserver-xorg: set status for CVE-2026-55999 and CVE-2026-56000
>   openssl: upgrade 3.5.8 -> 3.5.9
>   glibc: set status for CVE-2026-86805 and CVE-2026-95818
>   libpng: upgrade 1.6.56 -> 1.6.58
>   libpng: upgrade 1.6.58 -> 1.6.59
>   util-linux(-uuid): upgrade 2.41.5 -> 2.41.6
>   libsolv: patch CVE-2026-48863
>   expat: patch CVE-2026-66046 and CVE-2026-76641
>   expat: patch CVE-2026-76956
>   expat: patch CVE-2026-76957
>   expat: patch CVE-2026-93990
>   alsa-lib: patch CVE-2026-90781
>   go: upgrade 1.26.8 -> 1.26.9
>   libpcre2: patch CVE-2026-89162
>   libpcre2: patch CVE-2026-89161
>   libpcre2: patch CVE-2026-89156
>   libpcre2: patch CVE-2026-89157
>   libpcre2: patch CVE-2026-89160
>   libpcre2: patch CVE-2026-89158
>   libpcre2: patch CVE-2026-86145
>   libpcre2: patch CVE-2026-103111
> 
> Peter Tatrai (1):
>   systemd: fix mDNS hostname changes
> 
> Richard Purdie (1):
>   bind: upgrade 9.20.27 -> 9.20.29
> 
> Ross Burton (2):
>   gstreamer: skip test_queue:test_leaky_downstream test as it's flakey
>   libaio: update SRC_URI
> 
> Vijay Anusuri (1):
>   tzdata/tzcode-native: upgrade 2026c -> 2026d
> 
>  meta/conf/machine/include/riscv/qemuriscv.inc |   5 +-
>  meta/lib/oeqa/selftest/cases/devtool.py       |  22 +
>  meta/recipes-bsp/barebox/barebox-common.inc   |   4 +-
>  ...1-avoid-start-failure-with-bind-user.patch |   2 +-
>  ...kport-ax_prog_cc_for_build.m4-macros.patch |   2 +-
>  ...d-V-and-start-log-hide-build-options.patch |   4 +-
>  ...ching-for-json-headers-searches-sysr.patch |   4 +-
>  .../recipes-connectivity/bind/bind/conf.patch |   2 +-
>  ...t.d-add-support-for-read-only-rootfs.patch |   2 +-
>  .../bind/make-etc-initd-bind-stop-work.patch  |   2 +-
>  .../bind/{bind_9.20.26.bb => bind_9.20.29.bb} |   2 +-
>  .../nfs-utils/nfs-utils_2.8.7.bb              |   2 +
>  .../openssh/openssh/CVE-2026-73281.patch      |  80 +++
>  .../openssh/openssh/CVE-2026-73282.patch      |  80 +++
>  .../openssh/openssh/CVE-2026-73283.patch      |  42 ++
>  .../openssh/openssh_10.3p1.bb                 |   5 +
>  .../{openssl_3.5.8.bb => openssl_3.5.9.bb}    |   4 +-
>  meta/recipes-connectivity/ppp/ppp_2.5.2.bb    |   1 +
>  .../expat/expat/CVE-2026-66046-01.patch       | 107 ++++
>  .../expat/expat/CVE-2026-66046-02.patch       |  90 +++
>  .../expat/expat/CVE-2026-76641.patch          | 160 ++++++
>  .../expat/expat/CVE-2026-76956.patch          |  26 +
>  .../expat/expat/CVE-2026-76957-01.patch       | 121 ++++
>  .../expat/expat/CVE-2026-76957-02.patch       |  85 +++
>  .../expat/expat/CVE-2026-93990-01.patch       | 191 +++++++
>  .../expat/expat/CVE-2026-93990-02.patch       | 328 +++++++++++
>  meta/recipes-core/expat/expat_2.8.3.bb        |   8 +
>  meta/recipes-core/glibc/glibc-version.inc     |   2 +-
>  meta/recipes-core/glibc/glibc_2.43.bb         |   5 +
>  meta/recipes-core/ovmf/ovmf_git.bb            |   2 +
>  ...use-traffic-from-the-local-host-only.patch |  61 +++
>  meta/recipes-core/systemd/systemd_259.5.bb    |   1 +
>  ...2.41.5.bb => util-linux-libuuid_2.41.6.bb} |   0
>  meta/recipes-core/util-linux/util-linux.inc   |   5 +-
>  ...sing-fileutils.h-include-to-hook_idm.patch |  38 ++
>  .../util-linux/CVE-2026-78408.patch           |  75 +++
>  .../util-linux/CVE-2026-78410.patch           | 115 ++++
>  ...l-linux_2.41.5.bb => util-linux_2.41.6.bb} |   0
>  .../go/{go-1.26.8.inc => go-1.26.9.inc}       |   2 +-
>  ...e_1.26.8.bb => go-binary-native_1.26.9.bb} |   6 +-
>  ..._1.26.8.bb => go-cross-canadian_1.26.9.bb} |   0
>  ...{go-cross_1.26.8.bb => go-cross_1.26.9.bb} |   0
>  ...osssdk_1.26.8.bb => go-crosssdk_1.26.9.bb} |   0
>  ...runtime_1.26.8.bb => go-runtime_1.26.9.bb} |   0
>  ...ent-based-hash-generation-less-pedan.patch |   8 +-
>  ...3-ld-add-soname-to-shareable-objects.patch |   6 +-
>  ...d-go-make-GOROOT-precious-by-default.patch |   2 +-
>  ...ut-build-specific-paths-from-linker-.patch |   4 +-
>  .../go/{go_1.26.8.bb => go_1.26.9.bb}         |   0
>  .../python/python3-click_8.3.3.bb             |   1 +
>  .../recipes-extended/libaio/libaio_0.3.113.bb |   2 +-
>  .../libarchive/libarchive_3.8.7.bb            |   1 +
>  .../libsolv/libsolv/CVE-2026-48863.patch      |  25 +
>  .../libsolv/libsolv_0.7.36.bb                 |   1 +
>  meta/recipes-extended/timezone/timezone.inc   |   8 +-
>  .../wget/wget/CVE-2026-15146.patch            | 126 +++++
>  meta/recipes-extended/wget/wget_1.25.0.bb     |   1 +
>  .../graphene/graphene_1.10.8.bb               |   1 +
>  .../weston/0001-backend-vnc-Use-aml-v1.patch  |  24 +
>  .../recipes-graphics/wayland/weston_15.0.0.bb |   3 +-
>  .../xorg-xserver/xserver-xorg.inc             |   2 +
>  .../alsa/alsa-lib/CVE-2026-90781.patch        |  41 ++
>  .../alsa/alsa-lib_1.2.15.3.bb                 |   1 +
>  .../ffmpeg/ffmpeg/CVE-2026-66036_p1.patch     | 120 ++++
>  .../ffmpeg/ffmpeg/CVE-2026-66036_p2.patch     |  71 +++
>  .../ffmpeg/ffmpeg/CVE-2026-66041.patch        |  60 ++
>  .../recipes-multimedia/ffmpeg/ffmpeg_8.0.3.bb |   3 +
>  .../gstreamer/gstreamer1.0/run-ptest          |   3 +
>  .../libpng/files/CVE-2026-34757_p1.patch      | 518 ------------------
>  .../libpng/files/CVE-2026-34757_p2.patch      | 481 ----------------
>  .../{libpng_1.6.56.bb => libpng_1.6.59.bb}    |   7 +-
>  .../pulseaudio/pulseaudio.inc                 |   2 +
>  .../gnutls/gnutls/CVE-2026-42012-pre1.patch   |  69 +++
>  .../gnutls/gnutls/CVE-2026-42012-pre2.patch   | 161 ++++++
>  .../gnutls/gnutls/CVE-2026-42012.patch        |  48 ++
>  .../gnutls/gnutls/CVE-2026-42013-pre1.patch   |  56 ++
>  .../gnutls/gnutls/CVE-2026-42013.patch        |  74 +++
>  .../gnutls/gnutls/CVE-2026-42014.patch        |  60 ++
>  .../gnutls/gnutls/CVE-2026-42015.patch        |  43 ++
>  .../gnutls/gnutls/CVE-2026-5260_p1.patch      |  69 +++
>  .../gnutls/gnutls/CVE-2026-5260_p2.patch      |  33 ++
>  meta/recipes-support/gnutls/gnutls_3.8.12.bb  |  10 +
>  .../libpcre/libpcre2/CVE-2026-103111.patch    | 111 ++++
>  .../libpcre/libpcre2/CVE-2026-86145.patch     | 158 ++++++
>  .../libpcre/libpcre2/CVE-2026-89156.patch     | 275 ++++++++++
>  .../libpcre/libpcre2/CVE-2026-89157.patch     |  61 +++
>  .../libpcre/libpcre2/CVE-2026-89158.patch     | 208 +++++++
>  .../libpcre/libpcre2/CVE-2026-89160.patch     | 225 ++++++++
>  .../libpcre/libpcre2/CVE-2026-89161.patch     | 221 ++++++++
>  .../libpcre/libpcre2/CVE-2026-89162.patch     |  88 +++
>  .../recipes-support/libpcre/libpcre2_10.47.bb |   8 +
>  meta/recipes-support/vim/vim.inc              |   3 +
>  scripts/lib/devtool/standard.py               |   4 +
>  93 files changed, 4160 insertions(+), 1040 deletions(-)
>  rename meta/recipes-connectivity/bind/{bind_9.20.26.bb => bind_9.20.29.bb} (97%)
>  create mode 100644 meta/recipes-connectivity/openssh/openssh/CVE-2026-
> 73281.patch
>  create mode 100644 meta/recipes-connectivity/openssh/openssh/CVE-2026-
> 73282.patch
>  create mode 100644 meta/recipes-connectivity/openssh/openssh/CVE-2026-
> 73283.patch
>  rename meta/recipes-connectivity/openssl/{openssl_3.5.8.bb => openssl_3.5.9.bb}
> (98%)
>  create mode 100644 meta/recipes-core/expat/expat/CVE-2026-66046-01.patch
>  create mode 100644 meta/recipes-core/expat/expat/CVE-2026-66046-02.patch
>  create mode 100644 meta/recipes-core/expat/expat/CVE-2026-76641.patch
>  create mode 100644 meta/recipes-core/expat/expat/CVE-2026-76956.patch
>  create mode 100644 meta/recipes-core/expat/expat/CVE-2026-76957-01.patch
>  create mode 100644 meta/recipes-core/expat/expat/CVE-2026-76957-02.patch
>  create mode 100644 meta/recipes-core/expat/expat/CVE-2026-93990-01.patch
>  create mode 100644 meta/recipes-core/expat/expat/CVE-2026-93990-02.patch
>  create mode 100644 meta/recipes-core/systemd/systemd/0001-Revert-resolve-
> refuse-traffic-from-the-local-host-only.patch
>  rename meta/recipes-core/util-linux/{util-linux-libuuid_2.41.5.bb => util-linux-
> libuuid_2.41.6.bb} (100%)
>  create mode 100644 meta/recipes-core/util-linux/util-linux/0001-libmount-add-
> missing-fileutils.h-include-to-hook_idm.patch
>  create mode 100644 meta/recipes-core/util-linux/util-linux/CVE-2026-78408.patch
>  create mode 100644 meta/recipes-core/util-linux/util-linux/CVE-2026-78410.patch
>  rename meta/recipes-core/util-linux/{util-linux_2.41.5.bb => util-linux_2.41.6.bb}
> (100%)
>  rename meta/recipes-devtools/go/{go-1.26.8.inc => go-1.26.9.inc} (90%)
>  rename meta/recipes-devtools/go/{go-binary-native_1.26.8.bb => go-binary-
> native_1.26.9.bb} (80%)
>  rename meta/recipes-devtools/go/{go-cross-canadian_1.26.8.bb => go-cross-
> canadian_1.26.9.bb} (100%)
>  rename meta/recipes-devtools/go/{go-cross_1.26.8.bb => go-cross_1.26.9.bb}
> (100%)
>  rename meta/recipes-devtools/go/{go-crosssdk_1.26.8.bb => go-
> crosssdk_1.26.9.bb} (100%)
>  rename meta/recipes-devtools/go/{go-runtime_1.26.8.bb => go-runtime_1.26.9.bb}
> (100%)
>  rename meta/recipes-devtools/go/{go_1.26.8.bb => go_1.26.9.bb} (100%)
>  create mode 100644 meta/recipes-extended/libsolv/libsolv/CVE-2026-48863.patch
>  create mode 100644 meta/recipes-extended/wget/wget/CVE-2026-15146.patch
>  create mode 100644 meta/recipes-graphics/wayland/weston/0001-backend-vnc-
> Use-aml-v1.patch
>  create mode 100644 meta/recipes-multimedia/alsa/alsa-lib/CVE-2026-90781.patch
>  create mode 100644 meta/recipes-multimedia/ffmpeg/ffmpeg/CVE-2026-
> 66036_p1.patch
>  create mode 100644 meta/recipes-multimedia/ffmpeg/ffmpeg/CVE-2026-
> 66036_p2.patch
>  create mode 100644 meta/recipes-multimedia/ffmpeg/ffmpeg/CVE-2026-66041.patch
>  delete mode 100644 meta/recipes-multimedia/libpng/files/CVE-2026-34757_p1.patch
>  delete mode 100644 meta/recipes-multimedia/libpng/files/CVE-2026-34757_p2.patch
>  rename meta/recipes-multimedia/libpng/{libpng_1.6.56.bb => libpng_1.6.59.bb} (94%)
>  create mode 100644 meta/recipes-support/gnutls/gnutls/CVE-2026-42012-
> pre1.patch
>  create mode 100644 meta/recipes-support/gnutls/gnutls/CVE-2026-42012-
> pre2.patch
>  create mode 100644 meta/recipes-support/gnutls/gnutls/CVE-2026-42012.patch
>  create mode 100644 meta/recipes-support/gnutls/gnutls/CVE-2026-42013-
> pre1.patch
>  create mode 100644 meta/recipes-support/gnutls/gnutls/CVE-2026-42013.patch
>  create mode 100644 meta/recipes-support/gnutls/gnutls/CVE-2026-42014.patch
>  create mode 100644 meta/recipes-support/gnutls/gnutls/CVE-2026-42015.patch
>  create mode 100644 meta/recipes-support/gnutls/gnutls/CVE-2026-5260_p1.patch
>  create mode 100644 meta/recipes-support/gnutls/gnutls/CVE-2026-5260_p2.patch
>  create mode 100644 meta/recipes-support/libpcre/libpcre2/CVE-2026-103111.patch
>  create mode 100644 meta/recipes-support/libpcre/libpcre2/CVE-2026-86145.patch
>  create mode 100644 meta/recipes-support/libpcre/libpcre2/CVE-2026-89156.patch
>  create mode 100644 meta/recipes-support/libpcre/libpcre2/CVE-2026-89157.patch
>  create mode 100644 meta/recipes-support/libpcre/libpcre2/CVE-2026-89158.patch
>  create mode 100644 meta/recipes-support/libpcre/libpcre2/CVE-2026-89160.patch
>  create mode 100644 meta/recipes-support/libpcre/libpcre2/CVE-2026-89161.patch
>  create mode 100644 meta/recipes-support/libpcre/libpcre2/CVE-2026-89162.patch