mbox series

[meta-security,scarthgap,0/6] Assorted updates 01/19

Message ID cover.1768854779.git.scott.murray@konsulko.com
Headers show
Series Assorted updates 01/19 | expand

Message

Scott Murray Jan. 19, 2026, 8:39 p.m. UTC
This patch series rolls up the contributed patches from the past couple
weeks, plus backported lynis updates and a sssd update from myself.
These changes are queued on the scarthgap-next branch if you would like
to check them out to test yourself.  I intend to merge these to scarthgap
branch at end of day tomorrow (Eastern Time, Jan. 20) unless there are
objections.

Scott


Changes:

Marta Rybczynska (1):
  lynis: move to GitHub fetching

Michael Opdenacker (1):
  lynis: update to 3.1.5

Scott Murray (2):
  sssd: Upgrade to 2.9.7
  lynis: upgrade to 3.1.6

Vijay Anusuri (2):
  sssd: Upgrade 2.9.2 -> 2.9.5
  sssd: Fix for CVE-2025-11561

 .../0001-sssctl-add-error-analyzer.patch      | 42 +++++++++-------
 .../sssd/files/CVE-2025-11561.patch           | 50 +++++++++++++++++++
 .../sssd/files/drop_ntpdate_chk.patch         | 17 +++++--
 .../sssd/files/fix-ldblibdir.patch            |  9 +++-
 .../recipes-security/sssd/files/fix_gid.patch | 16 ++++--
 .../sssd/files/musl_fixup.patch               | 34 +++++++------
 .../recipes-security/sssd/files/no_gen.patch  | 18 ++++---
 .../sssd/{sssd_2.9.2.bb => sssd_2.9.7.bb}     |  3 +-
 .../lynis/{lynis_3.1.4.bb => lynis_3.1.6.bb}  |  6 +--
 9 files changed, 141 insertions(+), 54 deletions(-)
 create mode 100644 dynamic-layers/networking-layer/recipes-security/sssd/files/CVE-2025-11561.patch
 rename dynamic-layers/networking-layer/recipes-security/sssd/{sssd_2.9.2.bb => sssd_2.9.7.bb} (98%)
 rename recipes-compliance/lynis/{lynis_3.1.4.bb => lynis_3.1.6.bb} (87%)