From patchwork Tue Oct 6 06:24:59 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: auh@yoctoproject.org X-Patchwork-Id: 100029 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 3A6A7CA6006 for ; Tue, 6 Oct 2026 06:25:06 +0000 (UTC) Received: from a27-31.smtp-out.us-west-2.amazonses.com (a27-31.smtp-out.us-west-2.amazonses.com [54.240.27.31]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.39325.1791267900698386649 for ; Mon, 05 Oct 2026 23:25:00 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@yoctoproject.org header.s=lvjh2tk576v2ro5mi6k4dt3mc6wpqbky header.b=f5oWrlR3; dkim=pass header.i=@amazonses.com header.s=hsbnp7p3ensaochzwyq5wwmceodymuwv header.b=lLQEGNrq; spf=pass (domain: us-west-2.amazonses.com, ip: 54.240.27.31, mailfrom: 010101a10fe30908-6cbd5714-0e99-4ebc-a5a0-9a4f9946ed59-000000@us-west-2.amazonses.com) DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/simple; s=lvjh2tk576v2ro5mi6k4dt3mc6wpqbky; d=yoctoproject.org; t=1791267899; h=Content-Type:MIME-Version:From:To:Cc:Subject:Message-Id:Date; bh=ImiRJn/CCsQEtntZS30Y7Cd6DdpCcyWWTeqNXd/k35I=; b=f5oWrlR3coj43CNnZkMb3spw7sZVDr6US9steGFktrZShvkKl0uxHRgrdcbgpgoI Oh/6+jkLp1BQi78FUB3Jc/mKGt/7P9mh3QitRfS2N8ml/5goW8D/g+im8FTqv/qFYNG gD/FoukKBeM24+TZR92Ib2E34uBLufpmWbna5xdM= DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/simple; s=hsbnp7p3ensaochzwyq5wwmceodymuwv; d=amazonses.com; t=1791267899; h=Content-Type:MIME-Version:From:To:Cc:Subject:Message-Id:Date:Feedback-ID; bh=ImiRJn/CCsQEtntZS30Y7Cd6DdpCcyWWTeqNXd/k35I=; b=lLQEGNrqcERgyeKJKrxJfUELvJqPcaslYeJBzlrrUXYyjzODK5YSOvjjKyska8m2 cnIBOUEkB18AxUXzQyyCK6n81Oj4CO0hrJQazqc2fqAKASmp37q/7cbMMagB8RN7d9v 2HnZMuTxonxaWPuMi4zHCVGuSs9e0B/yYDcV+Lkw= MIME-Version: 1.0 From: auh@yoctoproject.org To: Chen Qi Cc: openembedded-core@lists.openembedded.org Subject: [AUH] cups: upgrading to 2.4.20 SUCCEEDED Message-ID: <010101a10fe30908-6cbd5714-0e99-4ebc-a5a0-9a4f9946ed59-000000@us-west-2.amazonses.com> Date: Tue, 6 Oct 2026 06:24:59 +0000 Feedback-ID: ::1.us-west-2.9np3MYPs3fEaOBysGKSlUD4KtcmPijcmS9Az2Hwf7iQ=:AmazonSES X-SES-Outgoing: 2026.10.06-54.240.27.31 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Tue, 06 Oct 2026 06:25:06 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/247274 Hello, this email is a notification from the Auto Upgrade Helper that the automatic attempt to upgrade the recipe(s) *cups* to *2.4.20* has Succeeded. Next steps: - apply the patch: git am 0001-cups-upgrade-2.4.19-2.4.20.patch - check the changes to upstream patches and summarize them in the commit message, - compile an image that contains the package - perform some basic sanity tests - amend the patch and sign it off: git commit -s --reset-author --amend - send it to the appropriate mailing list Alternatively, if you believe the recipe should not be upgraded at this time, you can fill RECIPE_NO_UPDATE_REASON in respective recipe file so that automatic upgrades would no longer be attempted. Please review the attached files for further information and build/update failures. Any problem please file a bug at https://bugzilla.yoctoproject.org/enter_bug.cgi?product=Automated%20Update%20Handler Regards, The Upgrade Helper -- >8 -- From 2a57e57512aeed2f9e03af90da68a64b7eb2c99b Mon Sep 17 00:00:00 2001 From: Upgrade Helper Date: Tue, 6 Oct 2026 06:13:57 +0000 Subject: [PATCH] cups: upgrade 2.4.19 -> 2.4.20 v2.4.20 - 2026-10-05 -------------------- - SECURITY-5.7: The scheduler did not open temporary PPD files in exclusive mode (CVE-2026-55480) - SECURITY-5.5: The scheduler did not remove all job status attributes from a job creation request (GHSA-7j85-5r23-xhvh) - SECURITY-5.3: The scheduler did not validate the request language value (CVE-2026-61702) - SECURITY-4.6: Attribute names were not validated as proper keyword values (GHSA-w9hj-hq9p-m7f6) - SECURITY-4.3: The `cupsUTF32toUTF8` function incorrectly treated UTF-32 values as 64-bit (CVE-2026-87875) - SECURITY-4.1: Held jobs for temporary print queues could crash the scheduler (GHSA-qqm8-4q5h-jg55) - SECURITY-3.3: The backend did not sanitize IPP attribute strings (CVE-2026-55453) - SECURITY-3.3: The scheduler did not filter out group separators from job submissions (GHSA-wjc4-qhjr-5m5x) - SECURITY-3.0: Quota and policy operations did not treat usernames as case- sensitive (CVE-2026-87876) - SECURITY-3.0: The scheduler's startup permission checks were vulnerable to TOU attacks (GHSA-gj33-wxpv-6fgg) - SECURITY-2.5: The scheduler did not sanitize fax numbers (CVE-2026-55467) - SECURITY-2.5: The 'mailto' notifier did not sanitize the recipient address provided to the sendmail command (CVE-2026-105326) - SECURITY-2.3: The scheduler could crash when modifying a class (GHSA-pwg4-pv39-8c22) - Increased the size of the SNMP supply name buffer used by the network backends (Issue #1604) - The USB backend now clears a halt on USB errors (Issue #1606) - Updated a few character tests for signed char platforms (Issue #1623) - Updated dateTime parsing in IPP files (Issue #1710) - Now explicitly limit IPP attribute names to 255 bytes (Issue #1694) - Added validation of IPP "printer-state-reasons" and "printer-mandatory-job-attributes" attributes (Issue #1632) - Added missing Set-Printer-Attributes policy to cupsd.conf. - Removed problematic debug printfs from `dnssd` backend. - Fixed mapping of standard PPD/PWG/legacy media size names to the local PPD size name (Issue #1375) - Fixed handling of multiple PPD: keywords from filters (Issue #1562, related to CVE-2026-34980) - Fixed handling of Kerberos user@REALM identities for user validation and quotas when StripUserDomain is not enabled (Issue #1584) - Fixed raster error reporting overflow (Issue #1607) - Fixed `cupsRasterInterpretPPD` handling of bad numbers (Issue #1608) - Fixed SNMP hex string debug output (Issue #1610) - Fixed some web interface bugs (Issue #1611) - Fixed some compression issues in the rastertoepson and rastertohp drivers (Issue #1613) - Fixed MIME `char` rule handling (Issue #1614) - Fixed duplicate local printers (Issue #1531, Issue #1586, Issue #1593, Issue #1620) - Fixed PPD cache memory leak (Issue #1629, Issue #1344) - Fixed escaping of spaces in option values (Issue #1630) - Fixed potential buffer overflow in `cupsCopyDestConflicts` (Issue #1631) - Fixed backchannel parsing bug in `commandtops` filter (Issue #1637) - Fixed section parsing in the web help indexing code (Issue #1641) - Fixed potential buffer overrun in rastertolabel filter (Issue #1644) - Fixed potential buffer overrun in rastertohp filter (Issue #1650) - Fixed media selection with a mix of PPD and IPP options (Issue #1651) - Fixed potential access of deleted IPP Everywhere printer (Issue #1655) - Fixed limiting of PPD custom number output for large numbers (Issue #1656) - Fixed a potential output length bug in the rastertohp driver (Issue #1658) - Fixed a potential buffer underflow buf in the `ippAdd/SetStringf(v)` functions (Issue #1664) - Fixed handling of TLS system priorities (Issue #1677) - Fixed D-Bus notification policy definition (Issue #1691) - Fixed raster fallback for IPP Everywhere printers (Issue #1703) - Fixed potential SNMP OID side-channel overflow (Issue #1719) - Fixed potential scheduler printer use-after-free bug (Issue #1722) - Fixed several issues reported by Coverity - Fixed case-sensitive PPD keyword comparisons when filtering keyword updates from filters. - Fixed potential buffer overrun in `cupsDoAuthentication`. v2.4.19 - 2026-04-27 -------------------- - Fixed a regression in shared printing from non-local accounts (Issue #1557, related to CVE-2026-27447) v2.4.18 - 2026-04-22 -------------------- - Fixed cupsd crash if user does not exist (Issue #1555, related to CVE-2026-27447) v2.4.17 - 2026-04-17 -------------------- v2.4.16 - 2025-12-04 -------------------- v2.4.15 - 2025-11-27 -------------------- v2.4.14 - 2025-09-11 -------------------- v2.4.13 - 2025-09-11 -------------------- v2.4.12 - 2025-04-08 -------------------- v2.4.11 - 2024-09-30 -------------------- v2.4.10 - 2024-06-18 -------------------- v2.4.9 - 2024-06-11 ------------------- v2.4.8 - 2024-04-26 ------------------- v2.4.7 - 2023-09-20 ------------------- v2.4.6 - 2023-06-22 ------------------- v2.4.5 - 2023-06-13 ------------------- v2.4.4 - 2023-06-06 ------------------- v2.4.3 [Changelog truncated as it exceeds 5000 characters; the full changelog can be found in an attachment to the AUH email] --- .../recipes-extended/cups/cups/0001-use-echo-only-in-init.patch | 2 +- .../cups/cups/0002-don-t-try-to-run-generated-binaries.patch | 2 +- .../cups/0004-cups-fix-multilib-install-file-conflicts.patch | 2 +- meta/recipes-extended/cups/cups/libexecdir.patch | 2 +- meta/recipes-extended/cups/{cups_2.4.19.bb => cups_2.4.20.bb} | 2 +- 5 files changed, 5 insertions(+), 5 deletions(-) rename meta/recipes-extended/cups/{cups_2.4.19.bb => cups_2.4.20.bb} (51%) diff --git a/meta/recipes-extended/cups/cups/0001-use-echo-only-in-init.patch b/meta/recipes-extended/cups/cups/0001-use-echo-only-in-init.patch index e4b473aaf3..ca92548cbe 100644 --- a/meta/recipes-extended/cups/cups/0001-use-echo-only-in-init.patch +++ b/meta/recipes-extended/cups/cups/0001-use-echo-only-in-init.patch @@ -1,4 +1,4 @@ -From 575a890a818e8ddc95d22838480b62988ffcd639 Mon Sep 17 00:00:00 2001 +From 4b7e48fb41dce9c10a4c4f91dc9fabfb14b9f1d7 Mon Sep 17 00:00:00 2001 From: Saul Wold Date: Thu, 13 Dec 2012 19:03:52 -0800 Subject: [PATCH] use echo only in init diff --git a/meta/recipes-extended/cups/cups/0002-don-t-try-to-run-generated-binaries.patch b/meta/recipes-extended/cups/cups/0002-don-t-try-to-run-generated-binaries.patch index 378ef677a5..b79b8be307 100644 --- a/meta/recipes-extended/cups/cups/0002-don-t-try-to-run-generated-binaries.patch +++ b/meta/recipes-extended/cups/cups/0002-don-t-try-to-run-generated-binaries.patch @@ -1,4 +1,4 @@ -From 36fa890e4b30bf42318065fe3172ef92b2d3e313 Mon Sep 17 00:00:00 2001 +From 9818e95ed747752e37d792693d3bf971af765084 Mon Sep 17 00:00:00 2001 From: Koen Kooi Date: Sun, 30 Jan 2011 16:37:27 +0100 Subject: [PATCH] don't try to run generated binaries diff --git a/meta/recipes-extended/cups/cups/0004-cups-fix-multilib-install-file-conflicts.patch b/meta/recipes-extended/cups/cups/0004-cups-fix-multilib-install-file-conflicts.patch index 2728fc7e3c..7dd5920338 100644 --- a/meta/recipes-extended/cups/cups/0004-cups-fix-multilib-install-file-conflicts.patch +++ b/meta/recipes-extended/cups/cups/0004-cups-fix-multilib-install-file-conflicts.patch @@ -1,4 +1,4 @@ -From 53aeff85692ce3fd0ac325ec7dcdff31748ccee6 Mon Sep 17 00:00:00 2001 +From c9c54505f5c1f77d598e8e1baea09a3794a4f5d9 Mon Sep 17 00:00:00 2001 From: Kai Kang Date: Wed, 3 Oct 2018 00:27:11 +0800 Subject: [PATCH] cups: fix multilib install file conflicts diff --git a/meta/recipes-extended/cups/cups/libexecdir.patch b/meta/recipes-extended/cups/cups/libexecdir.patch index 4acff27e54..4fdc2d7da4 100644 --- a/meta/recipes-extended/cups/cups/libexecdir.patch +++ b/meta/recipes-extended/cups/cups/libexecdir.patch @@ -1,4 +1,4 @@ -From fab57dbafccee851b22b757f08fc3273ad78b8ae Mon Sep 17 00:00:00 2001 +From 97f71812d2553661ccac15eaf7fd354824339ef8 Mon Sep 17 00:00:00 2001 From: Ross Burton Date: Tue, 13 Jul 2021 12:56:30 +0100 Subject: [PATCH] Use $libexecdir instead of hardcoding $prefix/lib as this diff --git a/meta/recipes-extended/cups/cups_2.4.19.bb b/meta/recipes-extended/cups/cups_2.4.20.bb similarity index 51% rename from meta/recipes-extended/cups/cups_2.4.19.bb rename to meta/recipes-extended/cups/cups_2.4.20.bb index c4885b60bc..18ab74c783 100644 --- a/meta/recipes-extended/cups/cups_2.4.19.bb +++ b/meta/recipes-extended/cups/cups_2.4.20.bb @@ -2,4 +2,4 @@ require cups.inc LIC_FILES_CHKSUM = "file://LICENSE;md5=3b83ef96387f14655fc854ddc3c6bd57" -SRC_URI[sha256sum] = "820984b12a67f98705785aae2dd1347fe0ac097828001d4583ff64574aed6389" +SRC_URI[sha256sum] = "ab4d9cd7f3e58060091d2b24972223d6401675f11c49b65abf4f6ef31dea22ff"