mbox

[00/14] Scarthgap pull request

Message ID cover.1790775073.git.anuj.mittal@oss.qualcomm.com
State New, archived
Headers show

Pull-request

https://git.openembedded.org/meta-openembedded-contrib anujm/scarthgap

Message

Anuj Mittal Sept. 30, 2026, 2:06 p.m. UTC
Please review and merge these changes in scarthgap. Tested on autobuilder
and locally:

https://autobuilder.yoctoproject.org/valkyrie/#/builders/81/builds/1836

The following changes since commit b5874ea07d69919d9b40d59f2c2f0bbd24bc3259:

  libssh: Fix CVE-2026-59850 (2026-09-02 10:39:59 +0530)

are available in the Git repository at:

  https://git.openembedded.org/meta-openembedded-contrib anujm/scarthgap
  https://git.openembedded.org/meta-openembedded-contrib/log/?h=anujm/scarthgap

for you to fetch changes up to 0f00f8b9a21950640da8c5707343e5540133f86e:

  vboxguestdrivers: fix vboxvideo build on kernels lacking drm_fb_helper_alloc_info (2026-09-29 16:10:23 +0530)

----------------------------------------------------------------

Anuj Mittal (1):
  vboxguestdrivers: fix vboxvideo build on kernels lacking
    drm_fb_helper_alloc_info

Benjamin Robin (Schneider Electric) (2):
  libwebsockets: update to version 4.3.10
  libwebsockets: fix CVE-2026-19773

Deepak Rathore (1):
  rsyslog: Fix CVE-2026-19654

Himani Ramesh Barde (1):
  postfix: fix build on hosts with Linux 7.x kernel

Hitendra Prajapati (1):
  python3-pillow: fix CVE-2026-42311

Jason Schonberg (1):
  php: upgrade 8.2.33 -> 8.2.34

Peter Marko (3):
  msgpack-c: patch CVE-2026-72854
  recipes: correct homepage
  polkit: patch CVE-2026-4897 and CVE-2026-85498

Rohini Sangam (2):
  python3-pillow: Security fix for CVE-2026-59198
  python3-pillow: Security fix for CVE-2026-59204

Viswanath Kraleti (1):
  libfastjson: switch git branch from master to main

Yogita Urade (1):
  hdf5: Fix CVE-2026-17572

 ...kedefs-Account-for-linux-7.x-version.patch |  47 +++
 .../recipes-daemons/postfix/postfix_3.8.19.bb |   1 +
 .../libwebsockets/CVE-2025-11677.patch        | 161 --------
 .../libwebsockets/CVE-2025-11678.patch        | 128 -------
 .../libwebsockets/CVE-2026-19773.patch        |  32 ++
 ...ckets_4.3.3.bb => libwebsockets_4.3.10.bb} |   7 +-
 .../msgpack/msgpack-c/CVE-2026-72854.patch    | 127 +++++++
 .../msgpack/msgpack-c_6.0.0.bb                |   1 +
 .../php/{php_8.2.33.bb => php_8.2.34.bb}      |   2 +-
 .../polkit/files/CVE-2026-4897-01.patch       |  64 ++++
 .../polkit/files/CVE-2026-4897-02.patch       |  32 ++
 .../polkit/files/CVE-2026-85498.patch         |  38 ++
 meta-oe/recipes-extended/polkit/polkit_124.bb |   3 +
 .../rsyslog/libfastjson_1.2304.0.bb           |   2 +-
 .../rsyslog/CVE-2026-19654-regression.patch   |  56 +++
 .../rsyslog/rsyslog/CVE-2026-19654.patch      |  52 +++
 .../rsyslog/rsyslog_8.2402.0.bb               |   2 +
 .../hdf5/files/CVE-2026-17572.patch           | 272 +++++++++++++
 meta-oe/recipes-support/hdf5/hdf5_1.14.4-3.bb |   1 +
 ...-build-decide-if-drm_fb_helper_alloc.patch |  54 +++
 .../vboxguestdrivers_7.0.14.bb                |   9 +-
 .../python/python3-beautifulsoup4_4.12.3.bb   |   2 +-
 .../python/python3-colorzero_2.0.bb           |   2 +-
 .../python/python3-flask-login_0.6.3.bb       |   2 +-
 .../python/python3-flask-mail_0.9.1.bb        |   2 +-
 .../python/python3-flask-user_0.6.19.bb       |   2 +-
 .../python3-pillow/CVE-2026-42311.patch       | 356 ++++++++++++++++++
 .../python3-pillow/CVE-2026-59198.patch       |  60 +++
 .../python3-pillow/CVE-2026-59204.patch       |  37 ++
 .../python/python3-pillow_10.3.0.bb           |   3 +
 .../python/python3-pyexpect_1.0.22.bb         |   2 +-
 31 files changed, 1257 insertions(+), 302 deletions(-)
 create mode 100644 meta-networking/recipes-daemons/postfix/files/0001-makedefs-Account-for-linux-7.x-version.patch
 delete mode 100644 meta-oe/recipes-connectivity/libwebsockets/libwebsockets/CVE-2025-11677.patch
 delete mode 100644 meta-oe/recipes-connectivity/libwebsockets/libwebsockets/CVE-2025-11678.patch
 create mode 100644 meta-oe/recipes-connectivity/libwebsockets/libwebsockets/CVE-2026-19773.patch
 rename meta-oe/recipes-connectivity/libwebsockets/{libwebsockets_4.3.3.bb => libwebsockets_4.3.10.bb} (94%)
 create mode 100644 meta-oe/recipes-devtools/msgpack/msgpack-c/CVE-2026-72854.patch
 rename meta-oe/recipes-devtools/php/{php_8.2.33.bb => php_8.2.34.bb} (99%)
 create mode 100644 meta-oe/recipes-extended/polkit/files/CVE-2026-4897-01.patch
 create mode 100644 meta-oe/recipes-extended/polkit/files/CVE-2026-4897-02.patch
 create mode 100644 meta-oe/recipes-extended/polkit/files/CVE-2026-85498.patch
 create mode 100644 meta-oe/recipes-extended/rsyslog/rsyslog/CVE-2026-19654-regression.patch
 create mode 100644 meta-oe/recipes-extended/rsyslog/rsyslog/CVE-2026-19654.patch
 create mode 100644 meta-oe/recipes-support/hdf5/files/CVE-2026-17572.patch
 create mode 100644 meta-oe/recipes-support/vboxguestdrivers/vboxguestdrivers/0001-vboxvideo-let-the-build-decide-if-drm_fb_helper_alloc.patch
 create mode 100644 meta-python/recipes-devtools/python/python3-pillow/CVE-2026-42311.patch
 create mode 100644 meta-python/recipes-devtools/python/python3-pillow/CVE-2026-59198.patch
 create mode 100644 meta-python/recipes-devtools/python/python3-pillow/CVE-2026-59204.patch

Comments

Khem Raj Oct. 1, 2026, 2:13 a.m. UTC | #1
Merged now, thanks Anuj

On Wed, Sep 30, 2026 at 7:06 AM Anuj Mittal via lists.openembedded.org
<anuj.mittal=oss.qualcomm.com@lists.openembedded.org> wrote:

> Please review and merge these changes in scarthgap. Tested on autobuilder
> and locally:
>
> https://autobuilder.yoctoproject.org/valkyrie/#/builders/81/builds/1836
>
> The following changes since commit
> b5874ea07d69919d9b40d59f2c2f0bbd24bc3259:
>
>   libssh: Fix CVE-2026-59850 (2026-09-02 10:39:59 +0530)
>
> are available in the Git repository at:
>
>   https://git.openembedded.org/meta-openembedded-contrib anujm/scarthgap
>
> https://git.openembedded.org/meta-openembedded-contrib/log/?h=anujm/scarthgap
>
> for you to fetch changes up to 0f00f8b9a21950640da8c5707343e5540133f86e:
>
>   vboxguestdrivers: fix vboxvideo build on kernels lacking
> drm_fb_helper_alloc_info (2026-09-29 16:10:23 +0530)
>
> ----------------------------------------------------------------
>
> Anuj Mittal (1):
>   vboxguestdrivers: fix vboxvideo build on kernels lacking
>     drm_fb_helper_alloc_info
>
> Benjamin Robin (Schneider Electric) (2):
>   libwebsockets: update to version 4.3.10
>   libwebsockets: fix CVE-2026-19773
>
> Deepak Rathore (1):
>   rsyslog: Fix CVE-2026-19654
>
> Himani Ramesh Barde (1):
>   postfix: fix build on hosts with Linux 7.x kernel
>
> Hitendra Prajapati (1):
>   python3-pillow: fix CVE-2026-42311
>
> Jason Schonberg (1):
>   php: upgrade 8.2.33 -> 8.2.34
>
> Peter Marko (3):
>   msgpack-c: patch CVE-2026-72854
>   recipes: correct homepage
>   polkit: patch CVE-2026-4897 and CVE-2026-85498
>
> Rohini Sangam (2):
>   python3-pillow: Security fix for CVE-2026-59198
>   python3-pillow: Security fix for CVE-2026-59204
>
> Viswanath Kraleti (1):
>   libfastjson: switch git branch from master to main
>
> Yogita Urade (1):
>   hdf5: Fix CVE-2026-17572
>
>  ...kedefs-Account-for-linux-7.x-version.patch |  47 +++
>  .../recipes-daemons/postfix/postfix_3.8.19.bb |   1 +
>  .../libwebsockets/CVE-2025-11677.patch        | 161 --------
>  .../libwebsockets/CVE-2025-11678.patch        | 128 -------
>  .../libwebsockets/CVE-2026-19773.patch        |  32 ++
>  ...ckets_4.3.3.bb => libwebsockets_4.3.10.bb} |   7 +-
>  .../msgpack/msgpack-c/CVE-2026-72854.patch    | 127 +++++++
>  .../msgpack/msgpack-c_6.0.0.bb                |   1 +
>  .../php/{php_8.2.33.bb => php_8.2.34.bb}      |   2 +-
>  .../polkit/files/CVE-2026-4897-01.patch       |  64 ++++
>  .../polkit/files/CVE-2026-4897-02.patch       |  32 ++
>  .../polkit/files/CVE-2026-85498.patch         |  38 ++
>  meta-oe/recipes-extended/polkit/polkit_124.bb |   3 +
>  .../rsyslog/libfastjson_1.2304.0.bb           |   2 +-
>  .../rsyslog/CVE-2026-19654-regression.patch   |  56 +++
>  .../rsyslog/rsyslog/CVE-2026-19654.patch      |  52 +++
>  .../rsyslog/rsyslog_8.2402.0.bb               |   2 +
>  .../hdf5/files/CVE-2026-17572.patch           | 272 +++++++++++++
>  meta-oe/recipes-support/hdf5/hdf5_1.14.4-3.bb |   1 +
>  ...-build-decide-if-drm_fb_helper_alloc.patch |  54 +++
>  .../vboxguestdrivers_7.0.14.bb                |   9 +-
>  .../python/python3-beautifulsoup4_4.12.3.bb   |   2 +-
>  .../python/python3-colorzero_2.0.bb           |   2 +-
>  .../python/python3-flask-login_0.6.3.bb       |   2 +-
>  .../python/python3-flask-mail_0.9.1.bb        |   2 +-
>  .../python/python3-flask-user_0.6.19.bb       |   2 +-
>  .../python3-pillow/CVE-2026-42311.patch       | 356 ++++++++++++++++++
>  .../python3-pillow/CVE-2026-59198.patch       |  60 +++
>  .../python3-pillow/CVE-2026-59204.patch       |  37 ++
>  .../python/python3-pillow_10.3.0.bb           |   3 +
>  .../python/python3-pyexpect_1.0.22.bb         |   2 +-
>  31 files changed, 1257 insertions(+), 302 deletions(-)
>  create mode 100644
> meta-networking/recipes-daemons/postfix/files/0001-makedefs-Account-for-linux-7.x-version.patch
>  delete mode 100644
> meta-oe/recipes-connectivity/libwebsockets/libwebsockets/CVE-2025-11677.patch
>  delete mode 100644
> meta-oe/recipes-connectivity/libwebsockets/libwebsockets/CVE-2025-11678.patch
>  create mode 100644
> meta-oe/recipes-connectivity/libwebsockets/libwebsockets/CVE-2026-19773.patch
>  rename meta-oe/recipes-connectivity/libwebsockets/{libwebsockets_4.3.3.bb
> => libwebsockets_4.3.10.bb} (94%)
>  create mode 100644
> meta-oe/recipes-devtools/msgpack/msgpack-c/CVE-2026-72854.patch
>  rename meta-oe/recipes-devtools/php/{php_8.2.33.bb => php_8.2.34.bb}
> (99%)
>  create mode 100644
> meta-oe/recipes-extended/polkit/files/CVE-2026-4897-01.patch
>  create mode 100644
> meta-oe/recipes-extended/polkit/files/CVE-2026-4897-02.patch
>  create mode 100644
> meta-oe/recipes-extended/polkit/files/CVE-2026-85498.patch
>  create mode 100644
> meta-oe/recipes-extended/rsyslog/rsyslog/CVE-2026-19654-regression.patch
>  create mode 100644
> meta-oe/recipes-extended/rsyslog/rsyslog/CVE-2026-19654.patch
>  create mode 100644 meta-oe/recipes-support/hdf5/files/CVE-2026-17572.patch
>  create mode 100644
> meta-oe/recipes-support/vboxguestdrivers/vboxguestdrivers/0001-vboxvideo-let-the-build-decide-if-drm_fb_helper_alloc.patch
>  create mode 100644
> meta-python/recipes-devtools/python/python3-pillow/CVE-2026-42311.patch
>  create mode 100644
> meta-python/recipes-devtools/python/python3-pillow/CVE-2026-59198.patch
>  create mode 100644
> meta-python/recipes-devtools/python/python3-pillow/CVE-2026-59204.patch
>
> --
> 2.55.0
>
>
> -=-=-=-=-=-=-=-=-=-=-=-
> Links: You receive all messages sent to this group.
> View/Reply Online (#130524):
> https://lists.openembedded.org/g/openembedded-devel/message/130524
> Mute This Topic: https://lists.openembedded.org/mt/121508685/1997914
> Group Owner: openembedded-devel+owner@lists.openembedded.org
> Unsubscribe: https://lists.openembedded.org/g/openembedded-devel/unsub [
> raj.khem@gmail.com]
> -=-=-=-=-=-=-=-=-=-=-=-
>
>