From patchwork Thu Sep 10 06:00:28 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: auh@yoctoproject.org X-Patchwork-Id: 97830 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 02CC7C88E41 for ; Thu, 10 Sep 2026 06:00:33 +0000 (UTC) Received: from a27-192.smtp-out.us-west-2.amazonses.com (a27-192.smtp-out.us-west-2.amazonses.com [54.240.27.192]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.7458.1789020028921149251 for ; Wed, 09 Sep 2026 23:00:29 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@yoctoproject.org header.s=lvjh2tk576v2ro5mi6k4dt3mc6wpqbky header.b=nGZz6Q7z; dkim=pass header.i=@amazonses.com header.s=hsbnp7p3ensaochzwyq5wwmceodymuwv header.b=E1ZS3wtZ; spf=pass (domain: us-west-2.amazonses.com, ip: 54.240.27.192, mailfrom: 010101a089e73c93-b97aaf06-babe-4b15-8491-b0ae867b25fe-000000@us-west-2.amazonses.com) DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/simple; s=lvjh2tk576v2ro5mi6k4dt3mc6wpqbky; d=yoctoproject.org; t=1789020028; h=Content-Type:MIME-Version:From:To:Cc:Subject:Message-Id:Date; bh=s3m4uWSQUJF9BgxhMpr/nwzEPNB1S5ogrTAA2j9s8uU=; b=nGZz6Q7zuZXvFLKk2j0IFB5vWlND4nh38vJtyjCZJsgFNuND8SHjLci7HuuFsPu+ yosm+0in6RzMjvsvIAyZUZwvWHGiY4Rzz1S9IMgAJDMI+uWSjaJAW1XKV6i3sJ6F4rZ xcBbALfR9VBnnuEWtLp3nZxg9RZsMA7JfXIgo5Ys= DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/simple; s=hsbnp7p3ensaochzwyq5wwmceodymuwv; d=amazonses.com; t=1789020028; h=Content-Type:MIME-Version:From:To:Cc:Subject:Message-Id:Date:Feedback-ID; bh=s3m4uWSQUJF9BgxhMpr/nwzEPNB1S5ogrTAA2j9s8uU=; b=E1ZS3wtZ0/u7SxX50EkHRNKMD07Lo28qNq9GpG4GK+FOAOaEDsv/M356CyJLI25K OYCEStqDuKRQjAzCxzWVxjFCjmrJ27if1VrCTsUpoFesyCpbq20YoNL/V4V+VLT2/vl GjImgwJS8oKMa158gsDchlGePK0OTnL1zcJN9yQk= MIME-Version: 1.0 From: auh@yoctoproject.org To: Denys Dmytriyenko Cc: openembedded-core@lists.openembedded.org Subject: [AUH] xz: upgrading to 5.8.4 SUCCEEDED Message-ID: <010101a089e73c93-b97aaf06-babe-4b15-8491-b0ae867b25fe-000000@us-west-2.amazonses.com> Date: Thu, 10 Sep 2026 06:00:28 +0000 Feedback-ID: ::1.us-west-2.9np3MYPs3fEaOBysGKSlUD4KtcmPijcmS9Az2Hwf7iQ=:AmazonSES X-SES-Outgoing: 2026.09.10-54.240.27.192 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Thu, 10 Sep 2026 06:00:33 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/245535 Hello, this email is a notification from the Auto Upgrade Helper that the automatic attempt to upgrade the recipe(s) *xz* to *5.8.4* has Succeeded. Next steps: - apply the patch: git am 0001-xz-upgrade-5.8.3-5.8.4.patch - check the changes to upstream patches and summarize them in the commit message, - compile an image that contains the package - perform some basic sanity tests - amend the patch and sign it off: git commit -s --reset-author --amend - send it to the appropriate mailing list Alternatively, if you believe the recipe should not be upgraded at this time, you can fill RECIPE_NO_UPDATE_REASON in respective recipe file so that automatic upgrades would no longer be attempted. Please review the attached files for further information and build/update failures. Any problem please file a bug at https://bugzilla.yoctoproject.org/enter_bug.cgi?product=Automated%20Update%20Handler Regards, The Upgrade Helper -- >8 -- From 814fffc75f24ce9ab49ceae29ba4be2cae8ef9ba Mon Sep 17 00:00:00 2001 From: Upgrade Helper Date: Thu, 10 Sep 2026 06:00:21 +0000 Subject: [PATCH] xz: upgrade 5.8.3 -> 5.8.4 Source: NEWS 5.8.4 (2026-09-09) IMPORTANT: This includes a fix for a security issue that affects all XZ Utils versions since 5.0.0. This and a few other fixes have also been committed to the old stable branches (v5.2, v5.4, and v5.6) in the xz Git repository. Those fixes are marked below. No new 5.2.x, 5.4.x, or 5.6.x releases will be made. * liblzma: - lzma_alone_decoder(), lzma_lzip_decoder(), lzma_auto_decoder(), and lzma_microlzma_decoder(): Fix an invalid memory access after memory allocation has failed and the application reinitializes the existing decoder to decode a different file. This bug could at least result in a crash. This is tracked as GHSA-5qpq-xqfv-j9pg. CVE number is pending. (Also in v5.2, v5.4, and v5.6.) - lzma_stream_buffer_decode(): Fix wrong error code and, in debug builds, assertion failure. LZMA_BUF_ERROR could be returned with truncated inputs while LZMA_DATA_ERROR is the correct one in this function. (Also in v5.2, v5.4, and v5.6.) - Fix a performance issue in the typical use case of lzma_index_cat(). Internally liblzma calls it from lzma_file_info_decoder(), so that was affected too. The problem occurred if the input .xz file was created by concatenating a large number of .xz files. A crafted file could make "xz --list" very slow or effectively hang. Normal decompression doesn't use these functions and thus wasn't affected. (Also in v5.2, v5.4, and v5.6.) - Fix a theoretical integer overflow in lzma_index_cat(). (Also in v5.2, v5.4, and v5.6.) - Fix bogus memory usage report in lzma_index_decoder() when the .xz Index is obviously invalid. A huge bogus value could cause an integer overflow in lzma_file_info_decoder()'s memory usage reporting due to a missing overflow check, making lzma_memused() report an incorrect tiny value. This bug didn't affect the memory usage limiter in these two decoders; only the reporting via lzma_memused() was affected. (Also in v5.2, v5.4, and v5.6.) - Fix a too low memory usage report in lzma_index_decoder() if lzma_memused() is called after a part of the Index has already been decoded. The typical use case is to call lzma_memused() immediately after LZMA_MEMLIMIT_ERROR, which did work correctly. - Fix copying of check type in lzma_index_dup(). Calling lzma_index_checks() on the duplicated lzma_index returned return garbage a result. lzma_index_dup() is rarely used; liblzma doesn't use it internally and xz itself doesn't use it either. (Also in v5.2, v5.4, and v5.6.) - lzma_file_info_decoder() and lzma_index_decoder(): Reject an obviously- [Changelog truncated as it exceeds 3000 characters; the full changelog can be found in an attachment to the AUH email] --- meta/recipes-extended/xz/{xz_5.8.3.bb => xz_5.8.4.bb} | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) rename meta/recipes-extended/xz/{xz_5.8.3.bb => xz_5.8.4.bb} (97%) diff --git a/meta/recipes-extended/xz/xz_5.8.3.bb b/meta/recipes-extended/xz/xz_5.8.4.bb similarity index 97% rename from meta/recipes-extended/xz/xz_5.8.3.bb rename to meta/recipes-extended/xz/xz_5.8.4.bb index 0735696011..cfb0574f0d 100644 --- a/meta/recipes-extended/xz/xz_5.8.3.bb +++ b/meta/recipes-extended/xz/xz_5.8.4.bb @@ -30,7 +30,7 @@ LIC_FILES_CHKSUM = "file://COPYING;md5=d38d562f6112174de93a9677682231b2 \ SRC_URI = "https://github.com/tukaani-project/xz/releases/download/v${PV}/xz-${PV}.tar.gz \ file://run-ptest \ " -SRC_URI[sha256sum] = "3d3a1b973af218114f4f889bbaa2f4c037deaae0c8e815eec381c3d546b974a0" +SRC_URI[sha256sum] = "0014c7886930454fe8bd4228665b51af55eeae560ea135c9c4cd33f55b2591d9" UPSTREAM_CHECK_REGEX = "releases/tag/v(?P\d+(\.\d+)+)" UPSTREAM_CHECK_URI = "https://github.com/tukaani-project/xz/releases/"