diff mbox series

[AUH] cups: upgrading to 2.4.20 SUCCEEDED

Message ID 010101a10fe30908-6cbd5714-0e99-4ebc-a5a0-9a4f9946ed59-000000@us-west-2.amazonses.com
State New
Headers show
Series [AUH] cups: upgrading to 2.4.20 SUCCEEDED | expand

Commit Message

auh@yoctoproject.org Oct. 6, 2026, 6:24 a.m. UTC
Hello,

this email is a notification from the Auto Upgrade Helper
that the automatic attempt to upgrade the recipe(s) *cups* to *2.4.20* has Succeeded.

Next steps:
    - apply the patch: git am 0001-cups-upgrade-2.4.19-2.4.20.patch
    - check the changes to upstream patches and summarize them in the commit message,
    - compile an image that contains the package
    - perform some basic sanity tests
    - amend the patch and sign it off: git commit -s --reset-author --amend
    - send it to the appropriate mailing list

Alternatively, if you believe the recipe should not be upgraded at this time,
you can fill RECIPE_NO_UPDATE_REASON in respective recipe file so that
automatic upgrades would no longer be attempted.

Please review the attached files for further information and build/update failures.
Any problem please file a bug at https://bugzilla.yoctoproject.org/enter_bug.cgi?product=Automated%20Update%20Handler

Regards,
The Upgrade Helper

-- >8 --
From 2a57e57512aeed2f9e03af90da68a64b7eb2c99b Mon Sep 17 00:00:00 2001
From: Upgrade Helper <auh@yoctoproject.org>
Date: Tue, 6 Oct 2026 06:13:57 +0000
Subject: [PATCH] cups: upgrade 2.4.19 -> 2.4.20

v2.4.20 - 2026-10-05
--------------------

- SECURITY-5.7: The scheduler did not open temporary PPD files in exclusive
  mode (CVE-2026-55480)
- SECURITY-5.5: The scheduler did not remove all job status attributes from a
  job creation request (GHSA-7j85-5r23-xhvh)
- SECURITY-5.3: The scheduler did not validate the request language value
  (CVE-2026-61702)
- SECURITY-4.6: Attribute names were not validated as proper keyword values
  (GHSA-w9hj-hq9p-m7f6)
- SECURITY-4.3: The `cupsUTF32toUTF8` function incorrectly treated UTF-32
  values as 64-bit (CVE-2026-87875)
- SECURITY-4.1: Held jobs for temporary print queues could crash the scheduler
  (GHSA-qqm8-4q5h-jg55)
- SECURITY-3.3: The backend did not sanitize IPP attribute strings
  (CVE-2026-55453)
- SECURITY-3.3: The scheduler did not filter out group separators from job
  submissions (GHSA-wjc4-qhjr-5m5x)
- SECURITY-3.0: Quota and policy operations did not treat usernames as case-
  sensitive (CVE-2026-87876)
- SECURITY-3.0: The scheduler's startup permission checks were vulnerable to
  TOU attacks (GHSA-gj33-wxpv-6fgg)
- SECURITY-2.5: The scheduler did not sanitize fax numbers (CVE-2026-55467)
- SECURITY-2.5: The 'mailto' notifier did not sanitize the recipient address
  provided to the sendmail command (CVE-2026-105326)
- SECURITY-2.3: The scheduler could crash when modifying a class
  (GHSA-pwg4-pv39-8c22)
- Increased the size of the SNMP supply name buffer used by the network backends
  (Issue #1604)
- The USB backend now clears a halt on USB errors (Issue #1606)
- Updated a few character tests for signed char platforms (Issue #1623)
- Updated dateTime parsing in IPP files (Issue #1710)
- Now explicitly limit IPP attribute names to 255 bytes (Issue #1694)
- Added validation of IPP "printer-state-reasons" and
  "printer-mandatory-job-attributes" attributes (Issue #1632)
- Added missing Set-Printer-Attributes policy to cupsd.conf.
- Removed problematic debug printfs from `dnssd` backend.
- Fixed mapping of standard PPD/PWG/legacy media size names to the local PPD
  size name (Issue #1375)
- Fixed handling of multiple PPD: keywords from filters (Issue #1562,
  related to CVE-2026-34980)
- Fixed handling of Kerberos user@REALM identities for user validation and
  quotas when StripUserDomain is not enabled (Issue #1584)
- Fixed raster error reporting overflow (Issue #1607)
- Fixed `cupsRasterInterpretPPD` handling of bad numbers (Issue #1608)
- Fixed SNMP hex string debug output (Issue #1610)
- Fixed some web interface bugs (Issue #1611)
- Fixed some compression issues in the rastertoepson and rastertohp drivers
  (Issue #1613)
- Fixed MIME `char` rule handling (Issue #1614)
- Fixed duplicate local printers (Issue #1531, Issue #1586, Issue #1593,
  Issue #1620)
- Fixed PPD cache memory leak (Issue #1629, Issue #1344)
- Fixed escaping of spaces in option values (Issue #1630)
- Fixed potential buffer overflow in `cupsCopyDestConflicts` (Issue #1631)
- Fixed backchannel parsing bug in `commandtops` filter (Issue #1637)
- Fixed section parsing in the web help indexing code (Issue #1641)
- Fixed potential buffer overrun in rastertolabel filter (Issue #1644)
- Fixed potential buffer overrun in rastertohp filter (Issue #1650)
- Fixed media selection with a mix of PPD and IPP options (Issue #1651)
- Fixed potential access of deleted IPP Everywhere printer (Issue #1655)
- Fixed limiting of PPD custom number output for large numbers (Issue #1656)
- Fixed a potential output length bug in the rastertohp driver (Issue #1658)
- Fixed a potential buffer underflow buf in the `ippAdd/SetStringf(v)` functions
  (Issue #1664)
- Fixed handling of TLS system priorities (Issue #1677)
- Fixed D-Bus notification policy definition (Issue #1691)
- Fixed raster fallback for IPP Everywhere printers (Issue #1703)
- Fixed potential SNMP OID side-channel overflow (Issue #1719)
- Fixed potential scheduler printer use-after-free bug (Issue #1722)
- Fixed several issues reported by Coverity
- Fixed case-sensitive PPD keyword comparisons when filtering keyword updates
  from filters.
- Fixed potential buffer overrun in `cupsDoAuthentication`.

v2.4.19 - 2026-04-27
--------------------

- Fixed a regression in shared printing from non-local accounts (Issue #1557,
  related to CVE-2026-27447)

v2.4.18 - 2026-04-22
--------------------

- Fixed cupsd crash if user does not exist (Issue #1555, related to
  CVE-2026-27447)

v2.4.17 - 2026-04-17
--------------------
v2.4.16 - 2025-12-04
--------------------
v2.4.15 - 2025-11-27
--------------------
v2.4.14 - 2025-09-11
--------------------
v2.4.13 - 2025-09-11
--------------------
v2.4.12 - 2025-04-08
--------------------
v2.4.11 - 2024-09-30
--------------------
v2.4.10 - 2024-06-18
--------------------
v2.4.9 - 2024-06-11
-------------------
v2.4.8 - 2024-04-26
-------------------
v2.4.7 - 2023-09-20
-------------------
v2.4.6 - 2023-06-22
-------------------
v2.4.5 - 2023-06-13
-------------------
v2.4.4 - 2023-06-06
-------------------
v2.4.3

[Changelog truncated as it exceeds 5000 characters;
the full changelog can be found in an attachment to the AUH email]
---
 .../recipes-extended/cups/cups/0001-use-echo-only-in-init.patch | 2 +-
 .../cups/cups/0002-don-t-try-to-run-generated-binaries.patch    | 2 +-
 .../cups/0004-cups-fix-multilib-install-file-conflicts.patch    | 2 +-
 meta/recipes-extended/cups/cups/libexecdir.patch                | 2 +-
 meta/recipes-extended/cups/{cups_2.4.19.bb => cups_2.4.20.bb}   | 2 +-
 5 files changed, 5 insertions(+), 5 deletions(-)
 rename meta/recipes-extended/cups/{cups_2.4.19.bb => cups_2.4.20.bb} (51%)
diff mbox series

Patch

diff --git a/meta/recipes-extended/cups/cups/0001-use-echo-only-in-init.patch b/meta/recipes-extended/cups/cups/0001-use-echo-only-in-init.patch
index e4b473aaf3..ca92548cbe 100644
--- a/meta/recipes-extended/cups/cups/0001-use-echo-only-in-init.patch
+++ b/meta/recipes-extended/cups/cups/0001-use-echo-only-in-init.patch
@@ -1,4 +1,4 @@ 
-From 575a890a818e8ddc95d22838480b62988ffcd639 Mon Sep 17 00:00:00 2001
+From 4b7e48fb41dce9c10a4c4f91dc9fabfb14b9f1d7 Mon Sep 17 00:00:00 2001
 From: Saul Wold <sgw@linux.intel.com>
 Date: Thu, 13 Dec 2012 19:03:52 -0800
 Subject: [PATCH] use echo only in init
diff --git a/meta/recipes-extended/cups/cups/0002-don-t-try-to-run-generated-binaries.patch b/meta/recipes-extended/cups/cups/0002-don-t-try-to-run-generated-binaries.patch
index 378ef677a5..b79b8be307 100644
--- a/meta/recipes-extended/cups/cups/0002-don-t-try-to-run-generated-binaries.patch
+++ b/meta/recipes-extended/cups/cups/0002-don-t-try-to-run-generated-binaries.patch
@@ -1,4 +1,4 @@ 
-From 36fa890e4b30bf42318065fe3172ef92b2d3e313 Mon Sep 17 00:00:00 2001
+From 9818e95ed747752e37d792693d3bf971af765084 Mon Sep 17 00:00:00 2001
 From: Koen Kooi <koen@dominion.thruhere.net>
 Date: Sun, 30 Jan 2011 16:37:27 +0100
 Subject: [PATCH] don't try to run generated binaries
diff --git a/meta/recipes-extended/cups/cups/0004-cups-fix-multilib-install-file-conflicts.patch b/meta/recipes-extended/cups/cups/0004-cups-fix-multilib-install-file-conflicts.patch
index 2728fc7e3c..7dd5920338 100644
--- a/meta/recipes-extended/cups/cups/0004-cups-fix-multilib-install-file-conflicts.patch
+++ b/meta/recipes-extended/cups/cups/0004-cups-fix-multilib-install-file-conflicts.patch
@@ -1,4 +1,4 @@ 
-From 53aeff85692ce3fd0ac325ec7dcdff31748ccee6 Mon Sep 17 00:00:00 2001
+From c9c54505f5c1f77d598e8e1baea09a3794a4f5d9 Mon Sep 17 00:00:00 2001
 From: Kai Kang <kai.kang@windriver.com>
 Date: Wed, 3 Oct 2018 00:27:11 +0800
 Subject: [PATCH] cups: fix multilib install file conflicts
diff --git a/meta/recipes-extended/cups/cups/libexecdir.patch b/meta/recipes-extended/cups/cups/libexecdir.patch
index 4acff27e54..4fdc2d7da4 100644
--- a/meta/recipes-extended/cups/cups/libexecdir.patch
+++ b/meta/recipes-extended/cups/cups/libexecdir.patch
@@ -1,4 +1,4 @@ 
-From fab57dbafccee851b22b757f08fc3273ad78b8ae Mon Sep 17 00:00:00 2001
+From 97f71812d2553661ccac15eaf7fd354824339ef8 Mon Sep 17 00:00:00 2001
 From: Ross Burton <ross.burton@arm.com>
 Date: Tue, 13 Jul 2021 12:56:30 +0100
 Subject: [PATCH] Use $libexecdir instead of hardcoding $prefix/lib as this
diff --git a/meta/recipes-extended/cups/cups_2.4.19.bb b/meta/recipes-extended/cups/cups_2.4.20.bb
similarity index 51%
rename from meta/recipes-extended/cups/cups_2.4.19.bb
rename to meta/recipes-extended/cups/cups_2.4.20.bb
index c4885b60bc..18ab74c783 100644
--- a/meta/recipes-extended/cups/cups_2.4.19.bb
+++ b/meta/recipes-extended/cups/cups_2.4.20.bb
@@ -2,4 +2,4 @@  require cups.inc
 
 LIC_FILES_CHKSUM = "file://LICENSE;md5=3b83ef96387f14655fc854ddc3c6bd57"
 
-SRC_URI[sha256sum] = "820984b12a67f98705785aae2dd1347fe0ac097828001d4583ff64574aed6389"
+SRC_URI[sha256sum] = "ab4d9cd7f3e58060091d2b24972223d6401675f11c49b65abf4f6ef31dea22ff"