From patchwork Sat Oct 3 06:22:28 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: auh@yoctoproject.org X-Patchwork-Id: 99911 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 60FEBCA5FC1 for ; Sat, 3 Oct 2026 06:22:39 +0000 (UTC) Received: from a27-193.smtp-out.us-west-2.amazonses.com (a27-193.smtp-out.us-west-2.amazonses.com [54.240.27.193]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.1163.1791008549765439734 for ; Fri, 02 Oct 2026 23:22:29 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@yoctoproject.org header.s=lvjh2tk576v2ro5mi6k4dt3mc6wpqbky header.b=Ts5/BCNz; dkim=pass header.i=@amazonses.com header.s=hsbnp7p3ensaochzwyq5wwmceodymuwv header.b=HZ7c15iD; spf=pass (domain: us-west-2.amazonses.com, ip: 54.240.27.193, mailfrom: 010101a1006da796-758bc284-7c22-4dfb-beeb-7a85c2beb726-000000@us-west-2.amazonses.com) DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/simple; s=lvjh2tk576v2ro5mi6k4dt3mc6wpqbky; d=yoctoproject.org; t=1791008548; h=Content-Type:MIME-Version:From:To:Subject:Message-Id:Date; bh=8ZoQLG1SVKkihKIGyzEleYF00mtCJVws7zluoHx/vu8=; b=Ts5/BCNzdb0zg/g82+PfhMDPdRvOcIvMUh+CRloGLonPDrZmXqnsH0c+fl1d90pp wOpB8ezCdmPMxmK3S8Sc3hIsI4EwDClFmVqSzvDpnQlcWnOk6VC2EAbfVZrIBi2z830 u8Gw/Fcy3UTDwknGEZEkWwE/xOSJ3cxDDxMlh7ZQ= DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/simple; s=hsbnp7p3ensaochzwyq5wwmceodymuwv; d=amazonses.com; t=1791008548; h=Content-Type:MIME-Version:From:To:Subject:Message-Id:Date:Feedback-ID; bh=8ZoQLG1SVKkihKIGyzEleYF00mtCJVws7zluoHx/vu8=; b=HZ7c15iDRZWsguMmkZyNwAWZ3yORT4ONQYyWCfUFSaBPjovFa3p7jHOsWJtPxcl1 MvdEm9fX+hGuThFF+homUnjati0O5yjTLjQsEodrjghO+i6ooLEhcnfjD4mgezzsaCo uAapirlMoeM/+fdPWgiyXFOWN0MR9HZXjk9i06pI= MIME-Version: 1.0 From: auh@yoctoproject.org To: openembedded-core@lists.openembedded.org Subject: [AUH] libpng: upgrading to 1.6.59 SUCCEEDED Message-ID: <010101a1006da796-758bc284-7c22-4dfb-beeb-7a85c2beb726-000000@us-west-2.amazonses.com> Date: Sat, 3 Oct 2026 06:22:28 +0000 Feedback-ID: ::1.us-west-2.9np3MYPs3fEaOBysGKSlUD4KtcmPijcmS9Az2Hwf7iQ=:AmazonSES X-SES-Outgoing: 2026.10.03-54.240.27.193 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Sat, 03 Oct 2026 06:22:39 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/247146 Hello, this email is a notification from the Auto Upgrade Helper that the automatic attempt to upgrade the recipe(s) *libpng* to *1.6.59* has Succeeded. Next steps: - apply the patch: git am 0001-libpng-upgrade-1.6.58-1.6.59.patch - check the changes to upstream patches and summarize them in the commit message, - compile an image that contains the package - perform some basic sanity tests - amend the patch and sign it off: git commit -s --reset-author --amend - send it to the appropriate mailing list Alternatively, if you believe the recipe should not be upgraded at this time, you can fill RECIPE_NO_UPDATE_REASON in respective recipe file so that automatic upgrades would no longer be attempted. Please review the attached files for further information and build/update failures. Any problem please file a bug at https://bugzilla.yoctoproject.org/enter_bug.cgi?product=Automated%20Update%20Handler Regards, The Upgrade Helper -- >8 -- From 083c6a33018a5a34bb398a04cb673056dec99f0c Mon Sep 17 00:00:00 2001 From: Upgrade Helper Date: Sat, 3 Oct 2026 05:43:30 +0000 Subject: [PATCH] libpng: upgrade 1.6.58 -> 1.6.59 Version 1.6.59 [September 28, 2026] Fixed CVE-2026-46675 (medium severity): Use-after-free of zlib input in `png_read_end` after incomplete zTXt, iTXt or iCCP decompression. (Reported independently by Ze Sheng and .) Fixed a regression introduced in version 1.6.47 that caused libpng to reject hIST chunks in their correct position, after PLTE. (Contributed by Yuki Sekiguchi.) Prevented a double free of `png_struct` members after an allocation failure. (Contributed by Anthony Hurtado.) Applied fixes and updates to the CMake build. Adopted the REUSE Specification for licensing the CI files. --- ...0001-tests-stream-per-test-results-to-stdout.patch | 11 ++++------- .../libpng/{libpng_1.6.58.bb => libpng_1.6.59.bb} | 2 +- 2 files changed, 5 insertions(+), 8 deletions(-) rename meta/recipes-multimedia/libpng/{libpng_1.6.58.bb => libpng_1.6.59.bb} (97%) diff --git a/meta/recipes-multimedia/libpng/files/0001-tests-stream-per-test-results-to-stdout.patch b/meta/recipes-multimedia/libpng/files/0001-tests-stream-per-test-results-to-stdout.patch index 139495d211..0c5e742bc1 100644 --- a/meta/recipes-multimedia/libpng/files/0001-tests-stream-per-test-results-to-stdout.patch +++ b/meta/recipes-multimedia/libpng/files/0001-tests-stream-per-test-results-to-stdout.patch @@ -1,4 +1,4 @@ -From e0898e243cbef677a862612f04b6bca2b07c2453 Mon Sep 17 00:00:00 2001 +From 22ec13788d1003de4b4f89eaaf47f28fe61523b2 Mon Sep 17 00:00:00 2001 From: Trevor Gamblin Date: Wed, 12 Aug 2026 12:22:54 -0400 Subject: [PATCH] tests: stream per-test results to stdout @@ -34,7 +34,7 @@ Signed-off-by: Trevor Gamblin create mode 100755 test-driver-tee diff --git a/Makefile.am b/Makefile.am -index eb7078158..a2e64fbe6 100644 +index fa5bbeb..8092616 100644 --- a/Makefile.am +++ b/Makefile.am @@ -111,6 +111,12 @@ TESTS =\ @@ -50,7 +50,7 @@ index eb7078158..a2e64fbe6 100644 endif # man pages -@@ -165,7 +171,7 @@ pkgconfig_DATA = libpng@PNGLIB_MAJOR@@PNGLIB_MINOR@.pc +@@ -216,7 +222,7 @@ pkgconfig_DATA = libpng@PNGLIB_MAJOR@@PNGLIB_MINOR@.pc # not done in the source directory! EXTRA_DIST= \ ANNOUNCE AUTHORS CHANGES INSTALL LICENSE README TODO TRADEMARK \ @@ -61,7 +61,7 @@ index eb7078158..a2e64fbe6 100644 CMakeLists.txt example.c libpng-manual.txt diff --git a/test-driver-tee b/test-driver-tee new file mode 100755 -index 000000000..a6d5aa027 +index 0000000..a6d5aa0 --- /dev/null +++ b/test-driver-tee @@ -0,0 +1,167 @@ @@ -232,6 +232,3 @@ index 000000000..a6d5aa027 +# time-stamp-time-zone: "UTC0" +# time-stamp-end: "; # UTC" +# End: --- -2.55.0 - diff --git a/meta/recipes-multimedia/libpng/libpng_1.6.58.bb b/meta/recipes-multimedia/libpng/libpng_1.6.59.bb similarity index 97% rename from meta/recipes-multimedia/libpng/libpng_1.6.58.bb rename to meta/recipes-multimedia/libpng/libpng_1.6.59.bb index 928b010c9c..4dbd769cf7 100644 --- a/meta/recipes-multimedia/libpng/libpng_1.6.58.bb +++ b/meta/recipes-multimedia/libpng/libpng_1.6.59.bb @@ -15,7 +15,7 @@ SRC_URI = "${SOURCEFORGE_MIRROR}/${BPN}/${BPN}${LIBV}/${BP}.tar.xz \ file://0001-tests-stream-per-test-results-to-stdout.patch \ " -SRC_URI[sha256sum] = "28eb403f51f0f7405249132cecfe82ea5c0ef97f1b32c5a65828814ae0d34775" +SRC_URI[sha256sum] = "d80dd2a38a37f803cb9b6ac7b14bd6e74ddc3b654780a8380bdf93523fdb4389" MIRRORS += "${SOURCEFORGE_MIRROR}/project/${BPN}/${BPN}${LIBV}/ ${SOURCEFORGE_MIRROR}/project/${BPN}/${BPN}${LIBV}/older-releases/"