From patchwork Tue Sep 29 06:18:44 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: auh@yoctoproject.org X-Patchwork-Id: 99550 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 305F5C9832A for ; Tue, 29 Sep 2026 06:18:51 +0000 (UTC) Received: from a27-33.smtp-out.us-west-2.amazonses.com (a27-33.smtp-out.us-west-2.amazonses.com [54.240.27.33]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.1855.1790662724947967574 for ; Mon, 28 Sep 2026 23:18:45 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@yoctoproject.org header.s=lvjh2tk576v2ro5mi6k4dt3mc6wpqbky header.b=OOjS7/dD; dkim=pass header.i=@amazonses.com header.s=hsbnp7p3ensaochzwyq5wwmceodymuwv header.b=vSQmA2A8; spf=pass (domain: us-west-2.amazonses.com, ip: 54.240.27.33, mailfrom: 010101a0ebd0ca19-e8538a16-6229-4061-8bbb-a6dd3a79d435-000000@us-west-2.amazonses.com) DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/simple; s=lvjh2tk576v2ro5mi6k4dt3mc6wpqbky; d=yoctoproject.org; t=1790662724; h=Content-Type:MIME-Version:From:To:Subject:Message-Id:Date; bh=wNap3wlS9EQjeg9pCUMckh83fkPY9+R0j8irRW6VImg=; b=OOjS7/dDwiQM9E8YxS8yCXJXjiot3s1PBmcXXhxFm5h5Az7n7g97VeXdKlFpkBIO C6Aq55LZCRldf4vFyB7/H5rzmbjMuCXcfgT7eGPc1CGusTa4o8IELtPV9YEmn6/Seyo izjWYPd7fOpCynpVsA6AkQ9L/0a6mV9UuQ7/FAGg= DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/simple; s=hsbnp7p3ensaochzwyq5wwmceodymuwv; d=amazonses.com; t=1790662724; h=Content-Type:MIME-Version:From:To:Subject:Message-Id:Date:Feedback-ID; bh=wNap3wlS9EQjeg9pCUMckh83fkPY9+R0j8irRW6VImg=; b=vSQmA2A8bseeze8IK8nk0YO+3uTcNMmhwGcQFRBdWhhq2PIC1YGjUp3ZaLomIzNP r9sp0X4jDcHuAzEh4tRMUyqCBVxOXwANXgpvzHYaK6AVHllSO93BDvAf1UVmsCfREaU 6fz73Eot/aGxVzQQ2SsW1JXKa0jpy45cNCh3wdJk= MIME-Version: 1.0 From: auh@yoctoproject.org To: openembedded-core@lists.openembedded.org Subject: [AUH] libpcre2: upgrading to 10.49 SUCCEEDED Message-ID: <010101a0ebd0ca19-e8538a16-6229-4061-8bbb-a6dd3a79d435-000000@us-west-2.amazonses.com> Date: Tue, 29 Sep 2026 06:18:44 +0000 Feedback-ID: ::1.us-west-2.9np3MYPs3fEaOBysGKSlUD4KtcmPijcmS9Az2Hwf7iQ=:AmazonSES X-SES-Outgoing: 2026.09.29-54.240.27.33 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Tue, 29 Sep 2026 06:18:51 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/246837 Hello, this email is a notification from the Auto Upgrade Helper that the automatic attempt to upgrade the recipe(s) *libpcre2* to *10.49* has Succeeded. Next steps: - apply the patch: git am 0001-libpcre2-upgrade-10.48-10.49.patch - check the changes to upstream patches and summarize them in the commit message, - compile an image that contains the package - perform some basic sanity tests - amend the patch and sign it off: git commit -s --reset-author --amend - send it to the appropriate mailing list Alternatively, if you believe the recipe should not be upgraded at this time, you can fill RECIPE_NO_UPDATE_REASON in respective recipe file so that automatic upgrades would no longer be attempted. Please review the attached files for further information and build/update failures. Any problem please file a bug at https://bugzilla.yoctoproject.org/enter_bug.cgi?product=Automated%20Update%20Handler Regards, The Upgrade Helper -- >8 -- From 5aaa53e9188f5e46ed743d97a73d020055724357 Mon Sep 17 00:00:00 2001 From: Upgrade Helper Date: Tue, 29 Sep 2026 06:18:33 +0000 Subject: [PATCH] libpcre2: upgrade 10.48 -> 10.49 Version 10.49 28-September-2026 ------------------------------- This is a security-only release, to address GHSA-r9hj-j2rw-4q3m. Compared to 10.48, this release has only a minimal code change to prevent an out-of-bounds write with arbitrary data. An attacker-controlled regex pattern is required, and applications are only affected if using the pcre2_jit_stack_create() and pcre2_jit_stack_assign() APIs to provide a growable JIT stack, and then matching against a pattern with unusually high JIT stack usage, such as a large number of capturing groups. The implications of an out-of-bounds write could include arbitrary code execution. The issue is not a regression and affects releases 10.48 and earlier. --- .../libpcre/{libpcre2_10.48.bb => libpcre2_10.49.bb} | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) rename meta/recipes-support/libpcre/{libpcre2_10.48.bb => libpcre2_10.49.bb} (96%) diff --git a/meta/recipes-support/libpcre/libpcre2_10.48.bb b/meta/recipes-support/libpcre/libpcre2_10.49.bb similarity index 96% rename from meta/recipes-support/libpcre/libpcre2_10.48.bb rename to meta/recipes-support/libpcre/libpcre2_10.49.bb index d5daff03c0..8e0c44fb4c 100644 --- a/meta/recipes-support/libpcre/libpcre2_10.48.bb +++ b/meta/recipes-support/libpcre/libpcre2_10.49.bb @@ -19,7 +19,7 @@ SRC_URI = "${GITHUB_BASE_URI}/download/pcre2-${PV}/pcre2-${PV}.tar.bz2 \ GITHUB_BASE_URI = "https://github.com/PCRE2Project/pcre2/releases" UPSTREAM_CHECK_REGEX = "releases/tag/pcre2-(?P\d+(\.\d+)+)$" -SRC_URI[sha256sum] = "b6c68fdf6f3ac31388b50aa89ff0fc49c00c987c16e7b5146491d12003f2c8ed" +SRC_URI[sha256sum] = "53c156e1ba416a20da8e65395daa132da0d80e76910424caca3fcdae7831d384" CVE_PRODUCT = "pcre2"