mbox

[00/49] Wrynose pull request

Message ID cover.1787738715.git.anuj.mittal@oss.qualcomm.com
State New
Headers show

Pull-request

https://git.openembedded.org/meta-openembedded-contrib anujm/wrynose

Message

Anuj Mittal Aug. 26, 2026, 10:09 a.m. UTC
Please merge these changes in wrynose. Tested locally and on autobuilder.

https://autobuilder.yoctoproject.org/valkyrie/#/builders/81/builds/1749

The following changes since commit 6bf0d8ad57b33950bab4c7f6c037e1ccb6f6e2eb:

  sdbus-c++-libsystemd: add .git to github repository url (2026-08-07 08:21:30 +0530)

are available in the Git repository at:

  https://git.openembedded.org/meta-openembedded-contrib anujm/wrynose
  https://git.openembedded.org/meta-openembedded-contrib/log/?h=anujm/wrynose

for you to fetch changes up to 14282a02be9c74a1276a7cda7d6c89e054699a11:

  libhtml-tree-perl, libmodule-build-tiny-perl: Drop obsolete TMPDIR scrubbing (2026-08-26 07:13:01 +0530)

----------------------------------------------------------------

Abhishek Bachiphale (1):
  poppler: fix CVE-2026-10118

Ankur Tyagi (12):
  mpd: fix build error with libupnp v1.14.30 onwards
  thin-provisioning-tools: upgrade 1.3.1 -> 1.3.3
  hiredis: upgrade 1.3.0 -> 1.3.1
  postfix: upgrade 3.10.12 -> 3.10.13
  firewalld: upgrade 2.2.1 -> 2.2.3
  file-roller: upgrade 44.5 -> 44.7
  gnome-software: upgrade 50.0 -> 50.3
  gdm: upgrade 50.1 -> 50.2
  gvfs: upgrade 1.60.1 -> 1.60.2
  cjose: upgrade 0.6.2.7 -> 0.6.2.8
  swagger-ui: upgrade 5.32.11 -> 5.32.12
  swagger-ui: upgrade 5.32.13 -> 5.32.14

Darsh Kelaiya (10):
  python3-aiohttp: fix CVE-2026-34993
  python3-aiohttp: fix CVE-2026-47265
  python3-aiohttp: fix CVE-2026-50269
  python3-aiohttp: fix CVE-2026-54274
  python3-aiohttp: fix CVE-2026-54275
  python3-aiohttp: fix CVE-2026-54276
  python3-aiohttp: fix CVE-2026-54277
  python3-aiohttp: fix CVE-2026-54278
  python3-aiohttp: fix CVE-2026-54279
  python3-aiohttp: fix CVE-2026-54280

Deepak Rathore (1):
  redis: avoid LTO for clang builds

Devansh Patel (3):
  python3-filelock: set CVE_PRODUCT
  python3-web3: add CVE_PRODUCT mapping
  python3-httplib2: correct CVE_PRODUCT mapping

Hetvi Thakar (9):
  python3-pyjwt: Fix CVE-2026-48522
  python3-pyjwt: Fix CVE-2026-48523
  python3-pyjwt: Fix CVE-2026-48524
  python3-pyjwt: Fix CVE-2026-48525
  python3-pyjwt: Fix CVE-2026-48526
  python3-twisted: Fix CVE-2026-42304
  python3-ujson: Fix CVE-2026-54911
  python3-web3: Fix CVE-2026-40072
  libssh: upgrade 0.11.4 -> 0.11.5

Khem Raj (4):
  libsdl3-image: upgrade 3.4.2 -> 3.4.4
  python3-psycopg: upgrade 3.3.3 -> 3.3.4
  samba: upgrade 4.23.8 -> 4.23.11
  libhtml-tree-perl, libmodule-build-tiny-perl: Drop obsolete TMPDIR
    scrubbing

Omkar Patil (1):
  openvpn: fix CVE-2026-13117

Preeti Sachan (1):
  libfastjson: fix rsyslogd segfault crash at load

Rouven Rastetter (1):
  vboxguestdrivers: Provide target kernel version

Tugrul Kukul (1):
  jq: fix CVE-2026-39956

Vijay Anusuri (1):
  giflib: Fix CVE-2026-26740

Wang Mingyu (4):
  python3-httplib2: upgrade 0.31.2 -> 0.32.0
  libsdl3: upgrade 3.4.4 -> 3.4.8
  gvfs: upgrade 1.60.0 -> 1.60.1
  swagger-ui: upgrade 5.32.12 -> 5.32.13

 ...ile-roller_44.5.bb => file-roller_44.7.bb} |   5 +-
 .../gdm/{gdm_50.1.bb => gdm_50.2.bb}          |   2 +-
 ...oftware_50.0.bb => gnome-software_50.3.bb} |   5 +-
 .../gvfs/{gvfs_1.60.0.bb => gvfs_1.60.2.bb}   |   2 +-
 .../musicpd/mpd/0001-upnp-allow-1.14.30.patch |  45 +
 .../recipes-multimedia/musicpd/mpd_0.24.9.bb  |   1 +
 ...{firewalld_2.2.1.bb => firewalld_2.2.3.bb} |   2 +-
 .../{samba_4.23.8.bb => samba_4.23.11.bb}     |   2 +-
 ...{postfix_3.10.12.bb => postfix_3.10.13.bb} |   2 +-
 .../openvpn/openvpn/CVE-2026-13117.patch      |  46 +
 .../recipes-support/openvpn/openvpn_2.7.0.bb  |   1 +
 .../giflib/giflib/CVE-2026-26740.patch        |  40 +
 .../recipes-devtools/giflib/giflib_6.1.2.bb   |   1 +
 .../jq/jq/CVE-2026-39956.patch                |  55 ++
 meta-oe/recipes-devtools/jq/jq_1.8.1.bb       |   1 +
 ...copg_3.3.3.bb => python3-psycopg_3.3.4.bb} |   2 +-
 .../{hiredis_1.3.0.bb => hiredis_1.3.1.bb}    |   4 +-
 meta-oe/recipes-extended/redis/redis_8.0.6.bb |   4 +
 .../rsyslog/libfastjson_1.2304.0.bb           |   1 +
 ...-image_3.4.2.bb => libsdl3-image_3.4.4.bb} |   2 +-
 .../{libsdl3_3.4.4.bb => libsdl3_3.4.8.bb}    |   2 +-
 .../{cjose_0.6.2.7.bb => cjose_0.6.2.8.bb}    |   2 +-
 .../{libssh_0.11.4.bb => libssh_0.11.5.bb}    |   4 +-
 .../poppler/poppler/CVE-2026-10118.patch      |  46 +
 .../poppler/poppler_25.12.0.bb                |   1 +
 .../thin-provisioning-tools-crates.inc        | 196 ++--
 ....1.bb => thin-provisioning-tools_1.3.3.bb} |   2 +-
 .../vboxguestdrivers_7.2.8.bb                 |   4 +-
 .../libhtml/libhtml-tree-perl_5.07.bb         |   7 -
 .../libmodule-build-tiny-perl_0.048.bb        |   7 -
 .../python/files/CVE-2026-40072.patch         | 861 ++++++++++++++++++
 .../python/files/CVE-2026-42304_p1.patch      | 299 ++++++
 .../python/files/CVE-2026-42304_p2.patch      |  30 +
 .../python/files/CVE-2026-42304_p3.patch      |  33 +
 .../python/files/CVE-2026-42304_p4.patch      | 318 +++++++
 .../python/files/CVE-2026-42304_p5.patch      | 218 +++++
 .../python/files/CVE-2026-42304_p6.patch      |  23 +
 .../python/files/CVE-2026-48522.patch         | 126 +++
 .../python/files/CVE-2026-48523.patch         | 115 +++
 .../python/files/CVE-2026-48524.patch         | 125 +++
 .../python/files/CVE-2026-48525.patch         | 146 +++
 .../python/files/CVE-2026-48526.patch         | 126 +++
 .../python3-aiohttp/CVE-2026-34993.patch      | 478 ++++++++++
 .../python3-aiohttp/CVE-2026-47265.patch      |  64 ++
 .../python3-aiohttp/CVE-2026-50269.patch      |  81 ++
 .../python3-aiohttp/CVE-2026-54274.patch      | 182 ++++
 .../python3-aiohttp/CVE-2026-54275.patch      | 115 +++
 .../python3-aiohttp/CVE-2026-54276.patch      | 287 ++++++
 .../python3-aiohttp/CVE-2026-54277.patch      | 249 +++++
 .../python3-aiohttp/CVE-2026-54278.patch      | 182 ++++
 .../python3-aiohttp/CVE-2026-54279.patch      | 295 ++++++
 .../python3-aiohttp/CVE-2026-54280.patch      | 138 +++
 .../python/python3-aiohttp_3.13.5.bb          |  13 +
 .../python/python3-filelock_3.25.2.bb         |   2 +
 ...2_0.31.2.bb => python3-httplib2_0.32.0.bb} |   4 +-
 .../python/python3-pyjwt_2.12.1.bb            |   7 +
 .../python/python3-twisted_25.5.0.bb          |   8 +
 .../python/python3-ujson/CVE-2026-54911.patch | 253 +++++
 .../python/python3-ujson_5.12.1.bb            |   2 +
 .../python/python3-web3_7.12.1.bb             |   3 +
 ...er-ui_5.32.11.bb => swagger-ui_5.32.14.bb} |   4 +-
 61 files changed, 5161 insertions(+), 120 deletions(-)
 rename meta-gnome/recipes-gnome/file-roller/{file-roller_44.5.bb => file-roller_44.7.bb} (82%)
 rename meta-gnome/recipes-gnome/gdm/{gdm_50.1.bb => gdm_50.2.bb} (96%)
 rename meta-gnome/recipes-gnome/gnome-software/{gnome-software_50.0.bb => gnome-software_50.3.bb} (86%)
 rename meta-gnome/recipes-gnome/gvfs/{gvfs_1.60.0.bb => gvfs_1.60.2.bb} (97%)
 create mode 100644 meta-multimedia/recipes-multimedia/musicpd/mpd/0001-upnp-allow-1.14.30.patch
 rename meta-networking/dynamic-layers/meta-python/recipes-connectivity/firewalld/{firewalld_2.2.1.bb => firewalld_2.2.3.bb} (99%)
 rename meta-networking/recipes-connectivity/samba/{samba_4.23.8.bb => samba_4.23.11.bb} (99%)
 rename meta-networking/recipes-daemons/postfix/{postfix_3.10.12.bb => postfix_3.10.13.bb} (99%)
 create mode 100644 meta-networking/recipes-support/openvpn/openvpn/CVE-2026-13117.patch
 create mode 100644 meta-oe/recipes-devtools/giflib/giflib/CVE-2026-26740.patch
 create mode 100644 meta-oe/recipes-devtools/jq/jq/CVE-2026-39956.patch
 rename meta-oe/recipes-devtools/python/{python3-psycopg_3.3.3.bb => python3-psycopg_3.3.4.bb} (85%)
 rename meta-oe/recipes-extended/hiredis/{hiredis_1.3.0.bb => hiredis_1.3.1.bb} (91%)
 rename meta-oe/recipes-graphics/libsdl3/{libsdl3-image_3.4.2.bb => libsdl3-image_3.4.4.bb} (90%)
 rename meta-oe/recipes-graphics/libsdl3/{libsdl3_3.4.4.bb => libsdl3_3.4.8.bb} (97%)
 rename meta-oe/recipes-support/cjose/{cjose_0.6.2.7.bb => cjose_0.6.2.8.bb} (88%)
 rename meta-oe/recipes-support/libssh/{libssh_0.11.4.bb => libssh_0.11.5.bb} (90%)
 create mode 100644 meta-oe/recipes-support/poppler/poppler/CVE-2026-10118.patch
 rename meta-oe/recipes-support/thin-provisioning-tools/{thin-provisioning-tools_1.3.1.bb => thin-provisioning-tools_1.3.3.bb} (97%)
 create mode 100644 meta-python/recipes-devtools/python/files/CVE-2026-40072.patch
 create mode 100644 meta-python/recipes-devtools/python/files/CVE-2026-42304_p1.patch
 create mode 100644 meta-python/recipes-devtools/python/files/CVE-2026-42304_p2.patch
 create mode 100644 meta-python/recipes-devtools/python/files/CVE-2026-42304_p3.patch
 create mode 100644 meta-python/recipes-devtools/python/files/CVE-2026-42304_p4.patch
 create mode 100644 meta-python/recipes-devtools/python/files/CVE-2026-42304_p5.patch
 create mode 100644 meta-python/recipes-devtools/python/files/CVE-2026-42304_p6.patch
 create mode 100644 meta-python/recipes-devtools/python/files/CVE-2026-48522.patch
 create mode 100644 meta-python/recipes-devtools/python/files/CVE-2026-48523.patch
 create mode 100644 meta-python/recipes-devtools/python/files/CVE-2026-48524.patch
 create mode 100644 meta-python/recipes-devtools/python/files/CVE-2026-48525.patch
 create mode 100644 meta-python/recipes-devtools/python/files/CVE-2026-48526.patch
 create mode 100644 meta-python/recipes-devtools/python/python3-aiohttp/CVE-2026-34993.patch
 create mode 100644 meta-python/recipes-devtools/python/python3-aiohttp/CVE-2026-47265.patch
 create mode 100644 meta-python/recipes-devtools/python/python3-aiohttp/CVE-2026-50269.patch
 create mode 100644 meta-python/recipes-devtools/python/python3-aiohttp/CVE-2026-54274.patch
 create mode 100644 meta-python/recipes-devtools/python/python3-aiohttp/CVE-2026-54275.patch
 create mode 100644 meta-python/recipes-devtools/python/python3-aiohttp/CVE-2026-54276.patch
 create mode 100644 meta-python/recipes-devtools/python/python3-aiohttp/CVE-2026-54277.patch
 create mode 100644 meta-python/recipes-devtools/python/python3-aiohttp/CVE-2026-54278.patch
 create mode 100644 meta-python/recipes-devtools/python/python3-aiohttp/CVE-2026-54279.patch
 create mode 100644 meta-python/recipes-devtools/python/python3-aiohttp/CVE-2026-54280.patch
 rename meta-python/recipes-devtools/python/{python3-httplib2_0.31.2.bb => python3-httplib2_0.32.0.bb} (76%)
 create mode 100644 meta-python/recipes-devtools/python/python3-ujson/CVE-2026-54911.patch
 rename meta-webserver/recipes-devtools/swagger-ui/{swagger-ui_5.32.11.bb => swagger-ui_5.32.14.bb} (85%)