From patchwork Mon Jul 20 17:22:34 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 92906 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id D98FDC44535 for ; Mon, 20 Jul 2026 17:23:36 +0000 (UTC) Received: from mail-wm1-f41.google.com (mail-wm1-f41.google.com [209.85.128.41]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.2860.1784568209396906807 for ; Mon, 20 Jul 2026 10:23:29 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=inP2rwce; spf=pass (domain: smile.fr, ip: 209.85.128.41, mailfrom: yoann.congal@smile.fr) Received: by mail-wm1-f41.google.com with SMTP id 5b1f17b1804b1-4953e04ef16so45661065e9.2 for ; Mon, 20 Jul 2026 10:23:29 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1784568207; x=1785173007; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=u+S/M6E9ZsSbNA5umVfH02NMG3UPG1WL/VtqSiCH8gc=; b=inP2rwceHE1VeZw+XqtcXyjoZdauBgfIO4k5VKVKOK8n8g1rH8JJiVgRQJtPWPa7Ey UQW3xAPd0PH/oYMSW0tkg5iQH2BWb0r3lmZOyNl+4Ien92wwU9Df03WXPjMc/PDjDGLc HI2HkPCam28esLday+HnUw6DdeBpP2YkhLx0E= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1784568207; x=1785173007; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=u+S/M6E9ZsSbNA5umVfH02NMG3UPG1WL/VtqSiCH8gc=; b=Xo+8v1P0W4tKnsmS7Kv0i8WTR481Jkpf0bb6iGgDlKMhHhQhcLEVY09ElGdVxrXEUe BpZkxdlPIIxov6SXKEgLFFRBmXmno0cr1o7u3N4NsEWLyliXNsFGqC60A4KfmIRyBWma igjySEOe4QrlouW8u3QYKEhUwXhWYi8juRFyx641rE8awwasn8TeFr21m057ii+f/bHt 6tqn+by2fsTfZTnZ5z+mWZ2oXHasSSwOKtQQYWtIMk6qilJa6Ia8f4h51+rF7rSVfpb1 toYdRfCAqHarI24GBsN9MQCLS2uQ/mtGF3/Iy7WjLNHo30pDDsZByOBS9kqraCz4oz3N LGWg== X-Gm-Message-State: AOJu0Yz4HNd3zbhhbOBc/Orkj64fylHevFN98wXAMqY9/M66bYzMKLDR 8I5pf2zNwls/TpoCwZANSk2cd2qyjtB7ABIlITRc9u5W8Hx6XeAeMX084s3tFONwZyVF5GmmmjE r8QEHM/8= X-Gm-Gg: AfdE7ck9uO95U3/xynzfquiEn3m1gTm9cuUjsNDj8yqQkFHVwIiK9aZQIchjCOvwdAl nHNIgG4j430J96YQt+5znfWPvUx0idFhxct6jNpJfB2HIKF3ffDfFYLgz58+enuj30KybWhLHKt EbSjh4R2yTml2w96w0HP0YWQDWfsOB7guo2ndzKLIXYvq845FfdrYKDdWU7x+YqS8I6vYwfLIfL WEiywL1M6UJaoS1Qmnr72IjCYGW397pSawLJvXmri0srBO2iy1Rf94vrF9LUX7o+oILMZ4Hmi4p y/0bJ5ImrZPUDXBOJAZ3l7uhdCcVbTUKrXFfmlm11r7jb1YHrX9nmGbgqG4TA5uMUYUT1AiQXDW S+me0a1f863r4h0CB3DI4vWL6UMAlHzB4PAjDo3X8c2U/lRSQmeMUruJvGOpzQGx12hdCkGX7l0 Zcx2Ia82QuvZ/z8Gyb3gmEHZg56TLpjumQCwv+CG/lgDyGeEEimUUomTuFkFDyJmvtRqVXF9NXB UOt8GrL X-Received: by 2002:a05:600c:3112:b0:495:472c:208d with SMTP id 5b1f17b1804b1-4954a41307cmr153992175e9.38.1784568206912; Mon, 20 Jul 2026 10:23:26 -0700 (PDT) Received: from localhost.localdomain (2a02-8440-b501-5b7b-2580-caa3-ecc1-dea5.rev.sfr.net. [2a02:8440:b501:5b7b:2580:caa3:ecc1:dea5]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-49563eee22esm36508575e9.1.2026.07.20.10.23.26 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 20 Jul 2026 10:23:26 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][scarthgap 01/33] create-spdx-image-3.0: correct SSTATE_SKIP_CREATION key for do_create_image_sbom_spdx Date: Mon, 20 Jul 2026 19:22:34 +0200 Message-ID: <4acdac4caaed1179ff52c4ff3064f014d08a4664.1784567958.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Mon, 20 Jul 2026 17:23:36 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/241435 From: Eric Meyers The override was "task-create-image-sbom" but BitBake derives it as "task-create-image-sbom-spdx" (do_ stripped, underscores to hyphens), so the skip was never applied. The task then cached an ${IMAGE_NAME}-stamped SBOM in sstate, letting a stale spdx.json be restored via setscene. A later do_sbom_cve_check would compute the current IMAGE_NAME and fail with "No such file or directory" on the missing timestamped SBOM. Correct the key so the image SBOM is always regenerated, never restored from sstate. Signed-off-by: Eric Meyers Cc: Joshua Watt Signed-off-by: Mathieu Dubois-Briand Signed-off-by: Richard Purdie (cherry picked from commit 45302ff5cfaf91ece74d4065acf710507f27da15) Signed-off-by: Benjamin Robin (Schneider Electric) Signed-off-by: Yoann Congal --- meta/classes-recipe/create-spdx-image-3.0.bbclass | 2 +- meta/classes-recipe/nospdx.bbclass | 2 +- 2 files changed, 2 insertions(+), 2 deletions(-) diff --git a/meta/classes-recipe/create-spdx-image-3.0.bbclass b/meta/classes-recipe/create-spdx-image-3.0.bbclass index e0f1766bb76..c516e954565 100644 --- a/meta/classes-recipe/create-spdx-image-3.0.bbclass +++ b/meta/classes-recipe/create-spdx-image-3.0.bbclass @@ -71,7 +71,7 @@ python do_create_image_sbom_spdx() { } addtask do_create_image_sbom_spdx after do_create_rootfs_spdx do_create_image_spdx before do_build SSTATETASKS += "do_create_image_sbom_spdx" -SSTATE_SKIP_CREATION:task-create-image-sbom = "1" +SSTATE_SKIP_CREATION:task-create-image-sbom-spdx = "1" do_create_image_sbom_spdx[sstate-inputdirs] = "${SPDXIMAGEDEPLOYDIR}" do_create_image_sbom_spdx[sstate-outputdirs] = "${DEPLOY_DIR_IMAGE}" do_create_image_sbom_spdx[stamp-extra-info] = "${MACHINE_ARCH}" diff --git a/meta/classes-recipe/nospdx.bbclass b/meta/classes-recipe/nospdx.bbclass index b20e28218be..913b213a654 100644 --- a/meta/classes-recipe/nospdx.bbclass +++ b/meta/classes-recipe/nospdx.bbclass @@ -10,4 +10,4 @@ deltask do_create_spdx_runtime deltask do_create_package_spdx deltask do_create_rootfs_spdx deltask do_create_image_spdx -deltask do_create_image_sbom +deltask do_create_image_sbom_spdx From patchwork Mon Jul 20 17:22:35 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 92907 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id C8584C44534 for ; Mon, 20 Jul 2026 17:23:36 +0000 (UTC) Received: from mail-wr1-f51.google.com (mail-wr1-f51.google.com [209.85.221.51]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.2883.1784568209788604924 for ; Mon, 20 Jul 2026 10:23:30 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=YBZkhntD; spf=pass (domain: smile.fr, ip: 209.85.221.51, mailfrom: yoann.congal@smile.fr) Received: by mail-wr1-f51.google.com with SMTP id ffacd0b85a97d-47c6e9a694bso5777484f8f.1 for ; Mon, 20 Jul 2026 10:23:29 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1784568208; x=1785173008; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=7kGv2rQZTt4Xu26Tv273nNGbbyH0hMk0AMfE3Rb2vyE=; b=YBZkhntDmjzOOovSqjVQ/3QiL7d8Vifr7gcyNON5xZBOrOlgSqF8HZ28HiNdGtShkf KbpRf1CaZefP+hJ8S5vDMrvqVpKnCZi4PbL54YDwhADpGvlxW483utYKacC3wRSUbccG jeTYPbf+pCGl1PACkIOte9eXKCksqwsUV1yhQ= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1784568208; x=1785173008; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=7kGv2rQZTt4Xu26Tv273nNGbbyH0hMk0AMfE3Rb2vyE=; b=plEA1VIh7pRg9czXQIhAhWZc1bu55cCACClsOsvQhHxbLqc3MmQaPfjngeYdtJYpXc ABJGvO2ICOf5T7xDN4brfvw1Yu4MeZ54bCqKtAyZtga6zu1YF1CPfFOATHFE3Yb0g4Ub MYEM6QFwE1EGvwXRBCBvM8k3QSVZ5LYp1+CnJTebyk3mjdWwIHSJBQ7gzdYiMMydXyZI 0rStEuoVrUg5uijz4HA2NfQRnlFHumkeA8sXfEDnFh8qojChBVxQ9zgdHyY/uDKWSkgR dyzr5JzWYnEzWa0ff5MkzWp9dDmUlDlNzo5/twPsPVScXS8J4kjqlSTP/tEPRE+3NIgn niEA== X-Gm-Message-State: AOJu0YyAiUx26+ni3ihi1PaU+fxveocaCglrH5pZL05BOavOzkvKj0Dp BN9Yjg/88dPBWzF1eGgQlTAW9Chb1laL7PF+yGHFuAA8kdPslH39xr8wbPUILvuyYNDwLPFA/ZD tIUJshUQ= X-Gm-Gg: AfdE7cmdvCb7Xw/J567DhndB7ZHsAuYJpGrGuD10Pt3jzgU0fdVL4oggf8YPIOuHLYN gyBCf5hEztaGeqRDTjKGL3gc0zLHknlBQRKQkGKyy36/XWoVKjUHy0Ocv5EXe79BsDcZP6ZwIbP IekxPUQmgCJ9OeduTUm7hDSmdCi+mPn2Qs392r0z+QD1UStEdgfCbyWyO48kJ82pbDTfBdcuV57 9gMlvOANtbnsBavCBYCQvxtEkUCdgy2Xg6fSkkIvvFAbmcPhSnzsDAB48YY0noKJhpjJi1iuqwa +17TfrmsjjhEYv/GRY32wd8dVGfIWQX6koqjPP+EbI2VQFFjRCm5Yfmhty1rUXGzcgQmQhjlxPJ 6tU/1fDilWld7c13yBvn2Bp+VJETmDTW4nlP9SBhLqrPki++QPjKoeGsI7UR45i+5n09Lh8/LCe 8ANmWkhSaveeG+RpoASwMVwwu36GtV8IEh/klH6J0wxeS0nz3eTrZwmTx8mLdiWcBycj0FYrfVY 8xvCXeo X-Received: by 2002:a05:600c:190b:b0:493:c77c:108a with SMTP id 5b1f17b1804b1-4954aa1a10amr160775265e9.36.1784568207780; Mon, 20 Jul 2026 10:23:27 -0700 (PDT) Received: from localhost.localdomain (2a02-8440-b501-5b7b-2580-caa3-ecc1-dea5.rev.sfr.net. [2a02:8440:b501:5b7b:2580:caa3:ecc1:dea5]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-49563eee22esm36508575e9.1.2026.07.20.10.23.27 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 20 Jul 2026 10:23:27 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][scarthgap 02/33] glibc: stable 2.39 branch updates Date: Mon, 20 Jul 2026 19:22:35 +0200 Message-ID: <2afc207fb9d2b720912a5eedb0f368e40f5a236e.1784567958.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Mon, 20 Jul 2026 17:23:36 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/241436 From: Jaipaul Cheernam git log --oneline ce65d944e38a20cb70af2a48a4b8aa5d8fabe1cc..be1e627cd72db31161a3b4ce1c8114674f0895eb be1e627cd7 Linux: Only define OPEN_TREE_* macros in if undefined (bug 33921) 98bc06a361 include: isolate __O_CLOEXEC flag for sys/mount.h and fcntl.h 3e13579841 Use pending character state in IBM1390, IBM1399 character sets (CVE-2026-4046) 0dc95ae109 elf: parse /proc/self/maps as the last resort to find the gap for tst-link-map-contiguous-ldso 9344c796f7 resolv: Check hostname for validity (CVE-2026-4438) 5663ab0b83 resolv: Count records correctly (CVE-2026-4437) c53cd6e738 posix: Run tst-wordexp-reuse-mem test 2760e4c5ed iconvdata: Fix invalid pointer arithmetic in ANSI_X3.110 module ba29a36aa3 posix: Fix invalid flags test for p{write,read}v2 60b039bf6a socket: Add new test for shutdown Testing Results: Before After Diff PASS 4892 4896 +4 XPASS 4 4 0 FAIL 371 372 +1 XFAIL 16 16 0 UNSUPPORTED 224 224 0 Changes in testcases: testcase-name before after posix/tst-wordexp-reuse-mem(new) - PASS (native) [Note: posix/tst-wordexp-reuse-mem is a new test added by this uplift (c53cd6e738). It fails under QEMU user-mode because the test-wrapper cannot support LD_PRELOAD and MALLOC_TRACE needed for mtrace. Running natively with LD_PRELOAD=libc_malloc_debug.so confirms the test passes with no memory leaks. nptl/tst-getpid3 is a flaky test under QEMU user-mode (passes 7/10 re-runs). No nptl code was changed in this uplift.] Signed-off-by: Jaipaul Cheernam Signed-off-by: Yoann Congal --- meta/recipes-core/glibc/glibc-version.inc | 2 +- meta/recipes-core/glibc/glibc_2.39.bb | 3 ++- 2 files changed, 3 insertions(+), 2 deletions(-) diff --git a/meta/recipes-core/glibc/glibc-version.inc b/meta/recipes-core/glibc/glibc-version.inc index 03a8e5d01e3..5d57dafed0a 100644 --- a/meta/recipes-core/glibc/glibc-version.inc +++ b/meta/recipes-core/glibc/glibc-version.inc @@ -1,6 +1,6 @@ SRCBRANCH ?= "release/2.39/master" PV = "2.39+git" -SRCREV_glibc ?= "ce65d944e38a20cb70af2a48a4b8aa5d8fabe1cc" +SRCREV_glibc ?= "be1e627cd72db31161a3b4ce1c8114674f0895eb" SRCREV_localedef ?= "cba02c503d7c853a38ccfb83c57e343ca5ecd7e5" GLIBC_GIT_URI ?= "git://sourceware.org/git/glibc.git;protocol=https" diff --git a/meta/recipes-core/glibc/glibc_2.39.bb b/meta/recipes-core/glibc/glibc_2.39.bb index 7958d64eed1..f6be1b5fc93 100644 --- a/meta/recipes-core/glibc/glibc_2.39.bb +++ b/meta/recipes-core/glibc/glibc_2.39.bb @@ -18,7 +18,8 @@ easier access for another. 'ASLR bypass itself is not a vulnerability.'" CVE_STATUS_GROUPS += "CVE_STATUS_STABLE_BACKPORTS" CVE_STATUS_STABLE_BACKPORTS = "CVE-2024-2961 CVE-2024-33599 CVE-2024-33600 CVE-2024-33601 CVE-2024-33602 CVE-2025-0395 \ - CVE-2025-4802 CVE-2025-5702 CVE-2025-8058 CVE-2025-15281 CVE-2026-0861 CVE-2026-0915" + CVE-2025-4802 CVE-2025-5702 CVE-2025-8058 CVE-2025-15281 CVE-2026-0861 CVE-2026-0915 \ + CVE-2026-4046 CVE-2026-4437 CVE-2026-4438" CVE_STATUS_STABLE_BACKPORTS[status] = "cpe-stable-backport: fix available in used git hash" DEPENDS += "gperf-native bison-native" From patchwork Mon Jul 20 17:22:36 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 92904 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id B04E5C44532 for ; Mon, 20 Jul 2026 17:23:36 +0000 (UTC) Received: from mail-wm1-f43.google.com (mail-wm1-f43.google.com [209.85.128.43]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.2884.1784568210238721983 for ; Mon, 20 Jul 2026 10:23:30 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=veMeGcj0; spf=pass (domain: smile.fr, ip: 209.85.128.43, mailfrom: yoann.congal@smile.fr) Received: by mail-wm1-f43.google.com with SMTP id 5b1f17b1804b1-4955adb04e8so11201865e9.2 for ; Mon, 20 Jul 2026 10:23:30 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1784568208; x=1785173008; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=U+KpHUrZddeP3xTR1+NXLyDohs/Yl4q62Ouiixjfg78=; b=veMeGcj0YV6Q/UcxG69/sw6TyjfC0LPIi8o5zQ09reCzFbWTliwqIFl1LIyuq8ohJX uF65ncTCvJTMvn4pZzWoV/+jR0l2qCJ7let+8v7SFCJhQ6Q+9qjagNdxyhEtETmr/DZa q8RgvuMxE3XxDxT0+tmfjjfnE9iHU61A6EXC0= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1784568208; x=1785173008; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=U+KpHUrZddeP3xTR1+NXLyDohs/Yl4q62Ouiixjfg78=; b=sGdsa6R1rgTYpQXoTUm7A1XkPhFRxTTiAtd4Mq8+bg72DjFUrlEh86CW9DNJLaqRmX Ls+ZZfm5NW4TXTcl4dPYnus3pchloXF8EHKYskGNKdiwAnH3SJU667oDO6Px3BE0NJWs HGpsPmxFAJfLtnbCkmpJW6CMGu/+Wkg7MeO1ByKo+r/f9pS6hQ06/qnwjDDfzlxXocYC L0XFXdjd4NhU1BXpsGdsBwkDIg2GDWn4KSc8zin8JhgmtolGQadBepxcgTj7p2trNcoo rnzIbd+MelUoCT2lw5uR8tvI0YY5ebdCLHkO9LK5HgvjHJvq6vYOeGkh7I6BHvRsOhJT 2mSA== X-Gm-Message-State: AOJu0YyDk5TcM/ren8ycMhld5BeNVRJcAVBKz9zbcZvpdf/kEZ7BHdYp 17DqlYeKtRSZwfqLHQOOzhsFW97YpQfGucyLNdybouCdO5F15dzVuGjtE4Iqf+1zslNkDebFUpB 8980oZsE= X-Gm-Gg: AfdE7clTccMVg8+yEXpktIYwM1//3muQCHMBJ2DSr0qU8cUfYRI3zBwXUbZ3c9EOfcV oCAu/YpM1FSJDl9Lj0bTNyvkZm+Xsc3KUT5kv8YEl2uXI2eb9a81Qk8ReCR3IN/uBqTVxIXxP6L USavXbHqAZmU9godaN2KFW/H3vYeoUeJQDcxf5knhQICNpHrch5oSAdNwovmKkyv/kppTZpew+2 +q2Mr8qmm9L0CTrjqwuZ5taS4Iyb/Y3IYA2OnlL/HidC13G6AfU/TzBz8TwPu54aA4OWrVqxzAv UkXBmiD5fgHi3jEd41x3D/+CjkWjntEtmv1ZXxSp/KhSNWA6aULTFp8OePeBbADIhS0cI0QHDKx fY0kssI77Z6thrC2mnLK/nq0g1WUnC+IO/kGgBi9abDDgMa139jkDMlbdGTNH7Y5ulMOrZrgyiC axlExtjX0LbzwN4ByPgx25HflgVq4dwvcigO0eCpIPDhXHdxrtIkR8ejrpxrZ89rdw+kwPJLvjN mz6d0P2 X-Received: by 2002:a7b:cb95:0:b0:493:eccb:8cb2 with SMTP id 5b1f17b1804b1-4954a514021mr125227855e9.30.1784568208351; Mon, 20 Jul 2026 10:23:28 -0700 (PDT) Received: from localhost.localdomain (2a02-8440-b501-5b7b-2580-caa3-ecc1-dea5.rev.sfr.net. [2a02:8440:b501:5b7b:2580:caa3:ecc1:dea5]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-49563eee22esm36508575e9.1.2026.07.20.10.23.27 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 20 Jul 2026 10:23:28 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][scarthgap 03/33] bind: Upgrade 9.18.44 -> 9.18.49 Date: Mon, 20 Jul 2026 19:22:36 +0200 Message-ID: X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Mon, 20 Jul 2026 17:23:36 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/241437 From: Ashishkumar Parmar This upgrade fixes CVE-2026-1519, CVE-2026-3039, CVE-2026-3592, CVE-2026-5946 and CVE-2026-5950. Changelog ========= https://downloads.isc.org/isc/bind9/9.18.49/doc/arm/html/notes.html The 9.18.45 changelog includes a Python 3.10 requirement change for ISC's upstream system test suite, but OE-Core's bind recipe does not enable or package that test suite and does not inherit ptest. This change is therefore not part of the target build, installed packages, runtime dependencies, or runtime behavior. Signed-off-by: Ashishkumar Parmar Signed-off-by: Yoann Congal --- .../bind/{bind_9.18.44.bb => bind_9.18.49.bb} | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) rename meta/recipes-connectivity/bind/{bind_9.18.44.bb => bind_9.18.49.bb} (97%) diff --git a/meta/recipes-connectivity/bind/bind_9.18.44.bb b/meta/recipes-connectivity/bind/bind_9.18.49.bb similarity index 97% rename from meta/recipes-connectivity/bind/bind_9.18.44.bb rename to meta/recipes-connectivity/bind/bind_9.18.49.bb index d424edcb4e2..723a09e7395 100644 --- a/meta/recipes-connectivity/bind/bind_9.18.44.bb +++ b/meta/recipes-connectivity/bind/bind_9.18.49.bb @@ -20,7 +20,7 @@ SRC_URI = "https://ftp.isc.org/isc/bind9/${PV}/${BPN}-${PV}.tar.xz \ file://0001-avoid-start-failure-with-bind-user.patch \ " -SRC_URI[sha256sum] = "81f5035a25c576af1a93f0061cf70bde6d00a0c7bd1274abf73f5b5389a6f82d" +SRC_URI[sha256sum] = "c43ce4548ebed788cd9df63658a7de105ceafba43fcd63fa352b1093e525cd24" UPSTREAM_CHECK_URI = "https://ftp.isc.org/isc/bind9/" # follow the ESV versions divisible by 2 From patchwork Mon Jul 20 17:22:37 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 92905 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 83DE3C44533 for ; Mon, 20 Jul 2026 17:23:36 +0000 (UTC) Received: from mail-wm1-f45.google.com (mail-wm1-f45.google.com [209.85.128.45]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.2885.1784568210843168990 for ; Mon, 20 Jul 2026 10:23:31 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=v/uKK0L7; spf=pass (domain: smile.fr, ip: 209.85.128.45, mailfrom: yoann.congal@smile.fr) Received: by mail-wm1-f45.google.com with SMTP id 5b1f17b1804b1-4954a32cf1eso13778155e9.3 for ; Mon, 20 Jul 2026 10:23:30 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1784568209; x=1785173009; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=PsW6Sfb8LaCJr5IPnq11VaXoxQdSt6l788orTKIuY1k=; b=v/uKK0L7J0dF+7lW7fdq+pz06FBePn0n7ycyzQRbI9MNAc89aKpnyGCYhhjKGlexoT FWnu7AI2ivOJtBrUm9XGRtkGV5rTpSSVS2wWWCfOu7rocILK5KA/tautuDcdshAe3NXw EaTDekpeegM46hwhFIrnSEdqS1j7XxLt4nyKw= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1784568209; x=1785173009; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=PsW6Sfb8LaCJr5IPnq11VaXoxQdSt6l788orTKIuY1k=; b=RM74/VI7ADmqdGKfPYEMCGchX9jFtRVMUf/76w+k2BZELrjeKk6u64CP8rKkL7BVBv fjzyW6OxqYPDwSIJTXCGMKwcyZ7fhztCUlLS9y57pnBdEAYKPpRTPzogigPdxMoGfXI5 cjxrzzWylGGaztHuDgYN1m+fLtdDcyyF5woKbLMst8hed/+gqvGP8nxPGPpg/zvvyzRe rmUnnFLn2L6jOs3dDdsjcTQa8v6g3KD9YNM9TK16O4esZlxHnRmxuH9zkDt/7QGQ78oE 56JrmWMenChnxXqXGsncazoCxrPXdge51s7yb4nmnnc9CXDIq4I3zpLpriAuX/hc8icz 8u1g== X-Gm-Message-State: AOJu0Yy6Sljl3M4RXsFzq7ttAPVFGynv2zG+zKKo8p0hwi5+vv0j8LHw 1M5pl/sXTb/MZb8CBBnXC/nzzRcJeP5WABtbYCHzOJUKgiRFFz4XocfzmL3b5/N5hkl67Gr6eZz CvSPwdmE= X-Gm-Gg: AfdE7cncy/QVPo8s4pkUEK67WT1w6ftDb7zp05H6ZBuobcDpP3eCNe1vQdNotmcIGLW teWM4KHjpOyxw+koCTgmCkE5P2UsFwXaO/tLwJFks7hbljmLftaQ2zHS6+5FqLygGtd/5sm2YIT TEve0LjWM3aEEtBjWGG6VgK7Tlaxnj75+WPqHmsrXBboIKvwIJP5zNs5Yjcv56c5D6JLDnhw0UY XIWPPiZNdiIYL5MMaTBMPfTOh6QyZae/HTrwiKqmD7rXtJ3i+4sR9ZlsdX9u8sAuAIObSmiYDi8 X5QlJ0cJkdBTXpqxCJ3hd+gbebmZzttPPLKygwui4cZD+XO/TBG22Li66G1yS5V6pY5g/Lqd0sy MxG0NTr4taGWFg348lyJoK43pco9XR1cKKC0OOGDtwKpOTBi9SGxi/gy3rZ6l0HpQIfWC3MD0dJ b6ZztA4SFRgpgCmQmUmpQALidXcg8Z51RxgBAdxO3PVoehJYeh09TiWy9bi53w0Z73hxeZinehq rzX00zv X-Received: by 2002:a05:600c:b96:b0:495:4b00:1bab with SMTP id 5b1f17b1804b1-4954b001c39mr163910245e9.21.1784568209022; Mon, 20 Jul 2026 10:23:29 -0700 (PDT) Received: from localhost.localdomain (2a02-8440-b501-5b7b-2580-caa3-ecc1-dea5.rev.sfr.net. [2a02:8440:b501:5b7b:2580:caa3:ecc1:dea5]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-49563eee22esm36508575e9.1.2026.07.20.10.23.28 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 20 Jul 2026 10:23:28 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][scarthgap 04/33] binutils: fix CVE-2025-69649, and CVE-2025-69652 Date: Mon, 20 Jul 2026 19:22:37 +0200 Message-ID: <86dd1306e350c4cd3b36a39254d6f17587960a60.1784567958.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Mon, 20 Jul 2026 17:23:36 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/241438 From: Roland Kovacs CVE-2025-69649: Null pointer dereference in readelf before 2.46 results in segfault when processing a crafted ELF binary with malformed header fields. No evidence of memory corruption beyond the null pointer dereference, nor any possibility of code execution, was observed. CVE-2025-69652: Null pointer dereference in readelf when processing a crafted ELF binary with malformed DWARF abbrev or debug information which leads to SIGABORT. No evidence of memory corruption or code execution was observed; the impact is limited to denial of service. Signed-off-by: Roland Kovacs [YC: patches are referenced in the NVD database: https://nvd.nist.gov/vuln/detail/CVE-2025-69649 https://nvd.nist.gov/vuln/detail/CVE-2025-69652 ] Signed-off-by: Yoann Congal --- .../binutils/binutils-2.42.inc | 2 + .../binutils/binutils/CVE-2025-69649.patch | 44 +++++++++++++++++++ .../binutils/binutils/CVE-2025-69652.patch | 39 ++++++++++++++++ 3 files changed, 85 insertions(+) create mode 100644 meta/recipes-devtools/binutils/binutils/CVE-2025-69649.patch create mode 100644 meta/recipes-devtools/binutils/binutils/CVE-2025-69652.patch diff --git a/meta/recipes-devtools/binutils/binutils-2.42.inc b/meta/recipes-devtools/binutils/binutils-2.42.inc index 3ed80a82924..c93f51e3ee2 100644 --- a/meta/recipes-devtools/binutils/binutils-2.42.inc +++ b/meta/recipes-devtools/binutils/binutils-2.42.inc @@ -74,6 +74,8 @@ SRC_URI = "\ file://0030-CVE-2025-11840.patch \ file://CVE-2025-69644-CVE-2025-69647.patch \ file://CVE-2025-69648.patch \ + file://CVE-2025-69649.patch \ + file://CVE-2025-69652.patch \ file://CVE-2026-6846.patch \ " S = "${WORKDIR}/git" diff --git a/meta/recipes-devtools/binutils/binutils/CVE-2025-69649.patch b/meta/recipes-devtools/binutils/binutils/CVE-2025-69649.patch new file mode 100644 index 00000000000..8852ba4cb58 --- /dev/null +++ b/meta/recipes-devtools/binutils/binutils/CVE-2025-69649.patch @@ -0,0 +1,44 @@ +From 37c8055eed3178a46417045dda63db7af21fd046 Mon Sep 17 00:00:00 2001 +From: Alan Modra +Date: Mon, 8 Dec 2025 15:58:33 +1030 +Subject: [PATCH] PR 33697, fuzzer segfault + + PR 33697 + * readelf.c (process_relocs): Don't segfault on no sections. + +CVE: CVE-2025-69649 +Upstream-Status: Backport [https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=66a3492ce68e1ae45b2489bd9a815c39ea5d7f66] + +Note: + The difference between this patch on v2.42 and upstream v2.46 is due to + the loop body printing the relocations in-line, which then in commit + 8e8d0b63ff15896cc2c228c01f18dfcf2a4a9305 have been factored out to a + separate 'display_relocations()' function. + + See: [https://sourceware.org/git/?p=binutils-gdb.git;a=blobdiff;f=binutils/readelf.c;h=fa0de3a7e0d9c2acc18fe047a7019e09f1ce3894;hp=c1006480b7bc3e83dd87fb20d215342375614af9;hb=8e8d0b63ff15896cc2c228c01f18dfcf2a4a9305;hpb=31c21e2c13d85793b525f74aa911eb28700ed89c] + +Signed-off-by: Roland Kovacs +--- + binutils/readelf.c | 6 +++--- + 1 file changed, 3 insertions(+), 3 deletions(-) + +diff --git a/binutils/readelf.c b/binutils/readelf.c +index 5e4ad6ea6ad..8c1987ffaec 100644 +--- a/binutils/readelf.c ++++ b/binutils/readelf.c +@@ -8961,9 +8961,9 @@ process_relocs (Filedata * filedata) + size_t i; + bool found = false; + +- for (i = 0, section = filedata->section_headers; +- i < filedata->file_header.e_shnum; +- i++, section++) ++ section = filedata->section_headers; ++ if (section != NULL) ++ for (i = 0; i < filedata->file_header.e_shnum; i++, section++) + { + if ( section->sh_type != SHT_RELA + && section->sh_type != SHT_REL +-- +2.34.1 + diff --git a/meta/recipes-devtools/binutils/binutils/CVE-2025-69652.patch b/meta/recipes-devtools/binutils/binutils/CVE-2025-69652.patch new file mode 100644 index 00000000000..a3380ae4206 --- /dev/null +++ b/meta/recipes-devtools/binutils/binutils/CVE-2025-69652.patch @@ -0,0 +1,39 @@ +From cb4f8fe24cc86a9f050be4cf9c619940f632ea6a Mon Sep 17 00:00:00 2001 +From: Alan Modra +Date: Mon, 8 Dec 2025 16:04:44 +1030 +Subject: [PATCH] PR 33701, abort in byte_get_little_endian + + PR 33701 + * dwarf.c (process_debug_info): Set debug_info_p NULL when + DEBUG_INFO_UNAVAILABLE. + +CVE: CVE-2025-69652 +Upstream-Status: Backport [https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=44b79abd0fa12e7947252eb4c6e5d16ed6033e01] + +Signed-off-by: Roland Kovacs +--- + binutils/dwarf.c | 8 +++++--- + 1 file changed, 5 insertions(+), 3 deletions(-) + +diff --git a/binutils/dwarf.c b/binutils/dwarf.c +index 615e051b2bf..13b11b46e41 100644 +--- a/binutils/dwarf.c ++++ b/binutils/dwarf.c +@@ -4222,9 +4222,11 @@ process_debug_info (struct dwarf_section * section, + break; + } + +- debug_info *debug_info_p = +- (debug_information && unit < alloc_num_debug_info_entries) +- ? debug_information + unit : NULL; ++ debug_info *debug_info_p = NULL; ++ if (debug_information ++ && num_debug_info_entries != DEBUG_INFO_UNAVAILABLE ++ && unit < alloc_num_debug_info_entries) ++ debug_info_p = debug_information + unit; + + assert (!debug_info_p + || (debug_info_p->num_loc_offsets +-- +2.34.1 + From patchwork Mon Jul 20 17:22:38 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 92902 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 83DABC44531 for ; Mon, 20 Jul 2026 17:23:36 +0000 (UTC) Received: from mail-wm1-f52.google.com (mail-wm1-f52.google.com [209.85.128.52]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.2863.1784568211680527463 for ; Mon, 20 Jul 2026 10:23:32 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=33ihnpVH; spf=pass (domain: smile.fr, ip: 209.85.128.52, mailfrom: yoann.congal@smile.fr) Received: by mail-wm1-f52.google.com with SMTP id 5b1f17b1804b1-4953e04ef16so45661465e9.2 for ; Mon, 20 Jul 2026 10:23:31 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1784568210; x=1785173010; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=kPsPMNe0u5wdCYSACX4YP0bnD1tZ3B7jLVpoAzlzaVw=; b=33ihnpVHdUfOU1VNheFYXZrna4D5Z3CqKCVzY+AazxoqU1cfxorbvzqzmDVPJYMoKv zTlOYKhqzSQr5ALXClMp7o8EHhBuJ8s+EzXi4ldhjZ3JvzhW3SiBTIRF/vXtFgUSAzKq Kca1XGrEG2zFT3N+J0mnxW7n6/XAT0Txj1mQE= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1784568210; x=1785173010; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=kPsPMNe0u5wdCYSACX4YP0bnD1tZ3B7jLVpoAzlzaVw=; b=GLJjOV8i/6w8kEKSTELmrB47fmfaoF/ms58ny4AkE9w8q6WewPE1LDXMPGWJHSrjkp PlEv04wEwxAPs/ulXkkQ6NwML9DnKKrrYkJofrhV7KO2AxgjZfOfnc+VY4mMQDeUQHNY qy7IQUcn+7tKEt4SePlL9iS+rlL2YpRyxQR5Mgtgy4Y7svldfhOoHEhUlQZkW6tgMYJr P87GF2587s7wbc/4nK+hgusTmnpsg47jusilx+/Bl2Q+vUMQaSjzeu3oIYG1sWxbzbUj UWYdQItMTtc3k++qFMnYiWZ6p8rgjxqpsvdjL3+37YoSG9FiBV1DOsWtsOIjurjHDa/4 M+dQ== X-Gm-Message-State: AOJu0YxWD7v4JSkvTU3aCwuypzPIqwg5klrlgPEKv0MBDkQRojnoKNZE KLJRGIzDnHBlzO4X4YgflFC+X8FB+jykQTuRCj9LPVk64uvrD1pVEvRrTRFI0jBeGRpmT7tTm5a 9a1A3frs= X-Gm-Gg: AfdE7ckzi18gvtxc3htnHUsTDo15Xw6ctZGVi3qAb0OzIc5BRSY/z4FSdMjUoHaobMo ROW+uwbFt70zqZQrrahhltdzRjs/GZtEzie7kzS4JPaY+lC7cMx+6cWMhyRgoYQ2b14FXLVkQay q9G0sFxgtdKVmwdASemcEfYNLrVVYMmFX07LKXg+13EY5pLBxeH2oXbNbxsRX1gh5YT/LgkHIwu WLrUCijTGWW/SQsBoTgx+ftk2H+F5HEznChFA9vefWcNq0XkwBUZyscS9Sl7DI52BdkIPUzsCvf w6iXrJ5AZ6Fzrk2CmiDjuBpppRuooq02rq5bkAzPfagS/UQCn+1II49ndEIuAUxYcnEulWJjYt+ 1ujm2whi2G7/iNbjy98S+Jr2uDVi3qzQjk8jbE2ipFlnp9XdYU5Qy0c2NHWOGH2g+DFU+g73CWh yuNKgafwkf4dp5sDTLMfXlNxRZdv0/GkbwhpkyH3wnCa8A2AOJBrpU+iGP2x0Xvde7qsm4z9nyh kej+zFs X-Received: by 2002:a05:600c:3506:b0:492:6447:7a7f with SMTP id 5b1f17b1804b1-4954a3d0070mr173853315e9.6.1784568209628; Mon, 20 Jul 2026 10:23:29 -0700 (PDT) Received: from localhost.localdomain (2a02-8440-b501-5b7b-2580-caa3-ecc1-dea5.rev.sfr.net. [2a02:8440:b501:5b7b:2580:caa3:ecc1:dea5]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-49563eee22esm36508575e9.1.2026.07.20.10.23.29 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 20 Jul 2026 10:23:29 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][scarthgap 05/33] binutils: fix CVE-2025-69645 Date: Mon, 20 Jul 2026 19:22:38 +0200 Message-ID: X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Mon, 20 Jul 2026 17:23:36 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/241439 From: Roland Kovacs Binutils objdump contains a denial-of-service vulnerability when processing a crafted binary with malformed DWARF debug information. A logic error in the handling of DWARF compilation units can result in an invalid offset_size value being used inside byte_get_little_endian, leading to an abort (SIGABRT). A local attacker can trigger the crash by supplying a malicious input file. Signed-off-by: Roland Kovacs [YC: The patch is referenced on the NVD page: https://nvd.nist.gov/vuln/detail/CVE-2025-69645 ] Signed-off-by: Yoann Congal --- .../binutils/binutils-2.42.inc | 1 + .../binutils/binutils/CVE-2025-69645.patch | 135 ++++++++++++++++++ 2 files changed, 136 insertions(+) create mode 100644 meta/recipes-devtools/binutils/binutils/CVE-2025-69645.patch diff --git a/meta/recipes-devtools/binutils/binutils-2.42.inc b/meta/recipes-devtools/binutils/binutils-2.42.inc index c93f51e3ee2..d455acd7863 100644 --- a/meta/recipes-devtools/binutils/binutils-2.42.inc +++ b/meta/recipes-devtools/binutils/binutils-2.42.inc @@ -77,5 +77,6 @@ SRC_URI = "\ file://CVE-2025-69649.patch \ file://CVE-2025-69652.patch \ file://CVE-2026-6846.patch \ + file://CVE-2025-69645.patch \ " S = "${WORKDIR}/git" diff --git a/meta/recipes-devtools/binutils/binutils/CVE-2025-69645.patch b/meta/recipes-devtools/binutils/binutils/CVE-2025-69645.patch new file mode 100644 index 00000000000..78d2d62a507 --- /dev/null +++ b/meta/recipes-devtools/binutils/binutils/CVE-2025-69645.patch @@ -0,0 +1,135 @@ +From 3fe207e0625a76c8cba932e435762bfb5f544131 Mon Sep 17 00:00:00 2001 +From: Alan Modra +Date: Sun, 30 Nov 2025 12:51:54 +1030 +Subject: [PATCH] PR 33637, abort in byte_get + +When DWARF5 support was added to binutils in commit 77145576fadc, +the loop over CUs in process_debug_info set do_types when finding a +DW_UT_type unit, in order to process the signature and type offset +entries. Unfortunately that broke debug_information/debug_info_p +handling, which previously was allocated and initialised for each unit +in .debug_info. debug_info_p was NULL when processing a DWARF4 +.debug_types section. After the 77145576fadc change it was possible +for debug_infp_p to be non-NULL but point to zeroed data, in +particular a zeroed offset_size. A zero for offset_size led to the +byte_get_little_endian abort triggered by the fuzzer testcase. + +I haven't investigated whether there is any need for a valid +offset_size when processing a non-fuzzed DWARF4 .debug_types section. +Presumably we'd have found that out in the last 6 years if that was +the case. We don't want to change debug_information[] for +.debug_types! + + PR 33637 + * dwarf.c (process_debug_info): Don't change DO_TYPES flag bit + depending on cu_unit_type. Instead test cu_unit_type along + with DO_TYPES to handle signature and type_offset for a type + unit. Move find_cu_tu_set_v2 call a little later. + +CVE: CVE-2025-69645 +Upstream-Status: Backport [https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=cdb728d4da6184631989b192f1022c219dea7677] + +Note: + Backported patch differs from upstream as commit + 1f7e70ddd2c49dd5442b8873dd6ef29b0a10fdc3 is not cherry-picked + just to introduce `do_flags` instead of the separate `do_type` + and `do_loc` booleans for it to apply cleanly. + +Signed-off-by: Roland Kovacs +--- + binutils/dwarf.c | 18 ++++++------------ + 1 file changed, 6 insertions(+), 12 deletions(-) + +diff --git a/binutils/dwarf.c b/binutils/dwarf.c +index 615e051b2bf..836872f1b26 100644 +--- a/binutils/dwarf.c ++++ b/binutils/dwarf.c +@@ -3865,8 +3865,6 @@ process_debug_info (struct dwarf_section * section, + + SAFE_BYTE_GET_AND_INC (compunit.cu_version, hdrptr, 2, end_cu); + +- this_set = find_cu_tu_set_v2 (cu_offset, do_types); +- + if (compunit.cu_version < 5) + { + compunit.cu_unit_type = DW_UT_compile; +@@ -3876,8 +3874,6 @@ process_debug_info (struct dwarf_section * section, + else + { + SAFE_BYTE_GET_AND_INC (compunit.cu_unit_type, hdrptr, 1, end_cu); +- do_types = (compunit.cu_unit_type == DW_UT_type); +- + SAFE_BYTE_GET_AND_INC (compunit.cu_pointer_size, hdrptr, 1, end_cu); + } + +@@ -3891,6 +3887,7 @@ process_debug_info (struct dwarf_section * section, + SAFE_BYTE_GET_AND_INC (dwo_id, hdrptr, 8, end_cu); + } + ++ this_set = find_cu_tu_set_v2 (cu_offset, do_types); + if (this_set == NULL) + { + abbrev_base = 0; +@@ -3947,8 +3944,6 @@ process_debug_info (struct dwarf_section * section, + + SAFE_BYTE_GET_AND_INC (compunit.cu_version, hdrptr, 2, end_cu); + +- this_set = find_cu_tu_set_v2 (cu_offset, do_types); +- + if (compunit.cu_version < 5) + { + compunit.cu_unit_type = DW_UT_compile; +@@ -3958,13 +3953,12 @@ process_debug_info (struct dwarf_section * section, + else + { + SAFE_BYTE_GET_AND_INC (compunit.cu_unit_type, hdrptr, 1, end_cu); +- do_types = (compunit.cu_unit_type == DW_UT_type); +- + SAFE_BYTE_GET_AND_INC (compunit.cu_pointer_size, hdrptr, 1, end_cu); + } + + SAFE_BYTE_GET_AND_INC (compunit.cu_abbrev_offset, hdrptr, offset_size, end_cu); + ++ this_set = find_cu_tu_set_v2 (cu_offset, do_types); + if (this_set == NULL) + { + abbrev_base = 0; +@@ -3996,7 +3990,7 @@ process_debug_info (struct dwarf_section * section, + compunit.cu_pointer_size = offset_size; + } + +- if (do_types) ++ if (do_types || compunit.cu_unit_type == DW_UT_type) + { + SAFE_BYTE_GET_AND_INC (signature, hdrptr, 8, end_cu); + SAFE_BYTE_GET_AND_INC (type_offset, hdrptr, offset_size, end_cu); +@@ -4011,7 +4005,7 @@ process_debug_info (struct dwarf_section * section, + if ((do_loc || do_debug_loc || do_debug_ranges || do_debug_info) + && num_debug_info_entries == 0 + && alloc_num_debug_info_entries > unit +- && ! do_types) ++ && !do_types) + { + free_debug_information (&debug_information[unit]); + memset (&debug_information[unit], 0, sizeof (*debug_information)); +@@ -4042,7 +4036,7 @@ process_debug_info (struct dwarf_section * section, + printf (_(" Abbrev Offset: %#" PRIx64 "\n"), + compunit.cu_abbrev_offset); + printf (_(" Pointer Size: %d\n"), compunit.cu_pointer_size); +- if (do_types) ++ if (do_types || compunit.cu_unit_type == DW_UT_type) + { + printf (_(" Signature: %#" PRIx64 "\n"), signature); + printf (_(" Type Offset: %#" PRIx64 "\n"), type_offset); +@@ -4319,7 +4313,7 @@ process_debug_info (struct dwarf_section * section, + we need to process .debug_loc and .debug_ranges sections. */ + if ((do_loc || do_debug_loc || do_debug_ranges || do_debug_info) + && num_debug_info_entries == 0 +- && ! do_types) ++ && !do_types) + { + if (num_units > alloc_num_debug_info_entries) + num_debug_info_entries = alloc_num_debug_info_entries; +-- +2.34.1 + From patchwork Mon Jul 20 17:22:39 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 92901 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 73D84C44515 for ; Mon, 20 Jul 2026 17:23:36 +0000 (UTC) Received: from mail-wm1-f50.google.com (mail-wm1-f50.google.com [209.85.128.50]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.2889.1784568212582325799 for ; Mon, 20 Jul 2026 10:23:32 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=0MHaZY00; spf=pass (domain: smile.fr, ip: 209.85.128.50, mailfrom: yoann.congal@smile.fr) Received: by mail-wm1-f50.google.com with SMTP id 5b1f17b1804b1-4955484387cso11946155e9.1 for ; Mon, 20 Jul 2026 10:23:32 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1784568211; x=1785173011; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=DvDt2ob8KOS81MJnpZKizThYjAR1r+YK0bL1FmpSsJA=; b=0MHaZY004lI6+0ktfZGrll8mDc2z+NSrpu1Fl6nq69MXrVIksSilassqLfd0+UeZoU zyP9KRVVaQ9vkVpwBJ5jL8K7xuivzdqpXnZ0hOXuRZw3inoDNZFzHm0qszPft/kSHT9l fmQdU8Kwam/C171AcKyuf51KXnrVjmQ90SMSk= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1784568211; x=1785173011; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=DvDt2ob8KOS81MJnpZKizThYjAR1r+YK0bL1FmpSsJA=; b=jXwzGOtUI1gYL1ZRViTsEk3hmW9GukmJWtGIIcrYuwrlo2dA5T2ZLGX0RdaCz+6h8w 5/OgiPPQKaGEwaqAIGA0Rf8661CrYWZzzUwDGOwEE81afSw8LjgfvzDZtzmOOL7Cm3g3 1YWIhWTnzGLtQMjNKqmI/R7Okinwy2RT+gDXPGbPrqA4ZqSdbklfFJtmWtq5VmPpD2wu dCk1YmcU6xYDngycHs2wFFGDZHkmqDw++RA6ABTFllY/73tDFUxnQJ+TdMvDXaGZMN+S FzT/69ICX2OU/2xBNzHdUdmG7ZUgSp5leTmk2vTHqrc64GsRjgscypqJUDGc2HKXKAD/ fgKg== X-Gm-Message-State: AOJu0Yx2QlDjoCFZUCeYRBQioiORx7T2ieIT91EKXG4LKDSeNXE7qxRA 6gecOXH+K10wgVnv1FRJjs/41cAF2C6ZP2qbFyP7lVIIOKJh5dqwYqs4MFS54sVuyyD5toMrjAW JXVuEo/k= X-Gm-Gg: AfdE7cmAafhXFyjtGLAUG17gT06AGZWQgC9EBlj4EgN3XbWzPOETj5Bx32u4lUZlpFV us2xzBeiUSlctKAJ8QAhTtpSzy4dtmw/V+juVBmBElVzVV4kJhUgmr8K8+5437pkXPnXJEZzG5o IDwLPOHXfPgIH02JsaNw9YDzH93hJiRxzZUxly5WLgftjJ+EZBf2SsGsGaFOXy0ECqJGokWDZeS kFyHb8K1sTJNFYtsYaGWDtkV0zKkNh4YHbjlSDFHF+BUyNol2Ut/rf//GuOG3Z48HvHpCxu7Ka+ 9Fy0KUr1U34nSMwuwlkn5xgqIizI+l/X87AVBpiKaWauVDCpBj4tvcPM6pVAKkrwq5Ty6qQAC7q dGW/t1IbbU7vZXJRs9i2IXVq92GxEVdgME5pjNVfsoZ3Vb5/WrI6/dLsTHUipJkTQdAUQNa/JKf /XS6V9JAGADMzOuUPGeG1I2iUsDkuIlTcatL8mUapfl8xaqR5NXKdx87xRf6f0VaWuKCqVAvnt1 KuEZ49w X-Received: by 2002:a05:600c:b8d:b0:493:a613:56b2 with SMTP id 5b1f17b1804b1-4954a3d0d5fmr177688545e9.8.1784568210695; Mon, 20 Jul 2026 10:23:30 -0700 (PDT) Received: from localhost.localdomain (2a02-8440-b501-5b7b-2580-caa3-ecc1-dea5.rev.sfr.net. [2a02:8440:b501:5b7b:2580:caa3:ecc1:dea5]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-49563eee22esm36508575e9.1.2026.07.20.10.23.30 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 20 Jul 2026 10:23:30 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][scarthgap 06/33] python3: Simplify ptest exclusion list Date: Mon, 20 Jul 2026 19:22:39 +0200 Message-ID: <649b6848ccd4aa3842b2b42b03058511e4f07ce3.1784567958.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Mon, 20 Jul 2026 17:23:36 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/241440 From: Mathieu Dubois-Briand Makes the exclusion list a bit more readable, avoiding very long sed expression lines. [Kris Gavvala]: this commit was modified to fit scarthgap. the original commit expects to skip test_timerfd_TFD_TIMER_ABSTIME, test_date_locale2 and test_null_dlsym. These tests were not being skipped on scarthgap so were removed from the backport. Signed-off-by: Mathieu Dubois-Briand Signed-off-by: Richard Purdie Signed-off-by: Kris Gavvala (cherry picked from commit d9a44e7390d7c8f2c2b73572825a6f8ceeb729ac) Signed-off-by: Yoann Congal --- meta/recipes-devtools/python/python3_3.12.13.bb | 15 +++++++++++++-- 1 file changed, 13 insertions(+), 2 deletions(-) diff --git a/meta/recipes-devtools/python/python3_3.12.13.bb b/meta/recipes-devtools/python/python3_3.12.13.bb index 06dbc8e892d..b31dd3d743c 100644 --- a/meta/recipes-devtools/python/python3_3.12.13.bb +++ b/meta/recipes-devtools/python/python3_3.12.13.bb @@ -256,8 +256,19 @@ do_install:append:class-nativesdk () { create_wrapper ${D}${bindir}/python${PYTHON_MAJMIN} TERMINFO_DIRS='${sysconfdir}/terminfo:/etc/terminfo:/usr/share/terminfo:/usr/share/misc/terminfo:/lib/terminfo' PYTHONNOUSERSITE='1' } -do_install_ptest:append:class-target:libc-musl () { - sed -i -e 's|SKIPPED_TESTS=|SKIPPED_TESTS="-x test__locale -x test_c_locale_coercion -x test_locale -x test_os test_re -x test__xxsubinterpreters -x test_threading"|' ${D}${PTEST_PATH}/run-ptest + +SKIPPED_TESTS:append:class-target:libc-musl = " \ + -x test__locale \ + -x test_c_locale_coercion \ + -x test_locale \ + -x test_os test_re \ + -x test__xxsubinterpreters \ + -x test_threading \ +" + + +do_install_ptest:append () { + sed -i -e "s|SKIPPED_TESTS=|SKIPPED_TESTS=\"${SKIPPED_TESTS}\"|" ${D}${PTEST_PATH}/run-ptest } SYSROOT_PREPROCESS_FUNCS:append:class-target = " provide_target_config_script" From patchwork Mon Jul 20 17:22:40 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 92900 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 57114C44530 for ; Mon, 20 Jul 2026 17:23:36 +0000 (UTC) Received: from mail-wr1-f49.google.com (mail-wr1-f49.google.com [209.85.221.49]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.2890.1784568213222188665 for ; Mon, 20 Jul 2026 10:23:33 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=OIH3bD3T; spf=pass (domain: smile.fr, ip: 209.85.221.49, mailfrom: yoann.congal@smile.fr) Received: by mail-wr1-f49.google.com with SMTP id ffacd0b85a97d-47c6e9a694bso5777516f8f.1 for ; Mon, 20 Jul 2026 10:23:33 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1784568211; x=1785173011; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=W7Y/gwdbyqY4Qm5qX21/aHZlgsYnTkjg0TiJBq0cf6U=; b=OIH3bD3T6QrZV6DpNDCvSyLTMLTegslt5EJ4QY7ew62MCQ/pQY5tKsUrANCsdY9JNl X3U6qbQiQVUKSaMGaRvHmHvIsa41FzaVPApivaOE97E66Y9B2YZTgMkMTNkFRcuwiOIA kQFSJH2ofTwDFixd0NGVaKSXbutB8cbfPrZZQ= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1784568211; x=1785173011; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=W7Y/gwdbyqY4Qm5qX21/aHZlgsYnTkjg0TiJBq0cf6U=; b=ASD9poIl9TYPd42lVR/pAc8Nf0YrGrbG2D2Gt52t7ZtW2E3svg2/FPYfwOyCaFOPh6 L8DoOa7GQxX6H1w3+Jge4/i5vcRnysJFlWLkavNw2YZHM0DcIkVkNruW2CXCn9cOOl5B bXoiAbCtLvG2zlIOEaE9hkowjAh7UJ9kWcMbV4T/KTxeEMO6rwfvQQV+KnMzyMosv5HS W5f/jZzPhHLb9+BgFV+JbZGYkn7glJe0p+CbMzI3/FnlrzrSqHqzDZ2TnT6zbCmFhYfT 6JMITL6nbcZgr61aFtqN21UypqLnQvoTAvCOWLYG2FgZZaw6C+4h54uXdLXWGa9GAnQc bj6g== X-Gm-Message-State: AOJu0YwdNbiezO+TElKfteXJRv95LUdTlJKg4+OyvU4AHNVJMdmZWIVl K3kwZtludv7VZYBn0HH+d5LaE+MW5Eco5QjtYoK6eBCBT2NJFPDwC9z38z9tcIkGpKKmBsjHqQl B9cVfgu8= X-Gm-Gg: AfdE7cl2ypegiEQGqlLyHAZ+2OI6S0lqFDW98b7F7hELfM2cVznW4Ra2cF1fZdGdwBu /oSUccg+rD4SxI8etYx6EnHTELoZ6qGw03FQnvlq4z1RdMpe1Ty/LmdcUVVBOdKdj5DsgDO7zf1 hcONg657fTO0PSM+ZxrsquIzAcHl8Kd97e6Ktl469mCLgi0znl7XQXVPhEpvQjL7AVWiAanwbxF hE/O9j+ePDeyxj2yqP4GmSeFVCoaPgua2nhFOtpGMrUK9Rj9u2oaP2XLLUXckEIjgxofGVZ7CRD c5kNoKQ1vrDUyaE4qTsHksbVYrUBh0ic24QwxFVNxe9obMAmPFxeV0LnOylxaPPtms8c5zihEno bJd0fq7nNljtX7cxH2MuTdH88/R98rmTnzk7qtDsYNc67tjvNH7xHg7/n5QgjYWJXmYOdRxz7Wf sEdMfnYydrbfFuFjUA3D+22Q4ALd7Sgc+bDQMTrYf2vbM4PVpi0BCAT3hGYK122QvkSnj70ILbq uoURZRm X-Received: by 2002:a05:600c:2908:b0:493:bb6b:5bb5 with SMTP id 5b1f17b1804b1-4954a3dcc67mr131714295e9.13.1784568211424; Mon, 20 Jul 2026 10:23:31 -0700 (PDT) Received: from localhost.localdomain (2a02-8440-b501-5b7b-2580-caa3-ecc1-dea5.rev.sfr.net. [2a02:8440:b501:5b7b:2580:caa3:ecc1:dea5]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-49563eee22esm36508575e9.1.2026.07.20.10.23.30 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 20 Jul 2026 10:23:31 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][scarthgap 07/33] python3: skiptest tracemalloc_track_race Date: Mon, 20 Jul 2026 19:22:40 +0200 Message-ID: <09adf3945b681bbc9eaa89cdad8fbb17191fd7d3.1784567958.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Mon, 20 Jul 2026 17:23:36 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/241441 From: Kris Gavvala In python3 ptests, tracemalloc_track_race fails with a segfault. To avoid ptest failures for now, skip the test. Fixes [YOCTO #16182] Upstream Issue: https://github.com/python/cpython/issues/143143 Signed-off-by: Kris Gavvala Signed-off-by: Mathieu Dubois-Briand Signed-off-by: Richard Purdie (cherry picked from commit 7504490ba5e6ce0317dd12bdb961542062f05830) Signed-off-by: Yoann Congal --- meta/recipes-devtools/python/python3_3.12.13.bb | 5 +++++ 1 file changed, 5 insertions(+) diff --git a/meta/recipes-devtools/python/python3_3.12.13.bb b/meta/recipes-devtools/python/python3_3.12.13.bb index b31dd3d743c..d74bdc158b6 100644 --- a/meta/recipes-devtools/python/python3_3.12.13.bb +++ b/meta/recipes-devtools/python/python3_3.12.13.bb @@ -256,6 +256,11 @@ do_install:append:class-nativesdk () { create_wrapper ${D}${bindir}/python${PYTHON_MAJMIN} TERMINFO_DIRS='${sysconfdir}/terminfo:/etc/terminfo:/usr/share/terminfo:/usr/share/misc/terminfo:/lib/terminfo' PYTHONNOUSERSITE='1' } +# Fails with segfault +# Bugzilla YP 16182 (test_tracemalloc_track_race) +SKIPPED_TESTS = " \ + --ignore test.test_tracemalloc.TestCAPI.test_tracemalloc_track_race \ +" SKIPPED_TESTS:append:class-target:libc-musl = " \ -x test__locale \ From patchwork Mon Jul 20 17:22:41 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 92899 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 2B207C4452E for ; Mon, 20 Jul 2026 17:23:36 +0000 (UTC) Received: from mail-wm1-f53.google.com (mail-wm1-f53.google.com [209.85.128.53]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.2891.1784568213942135877 for ; Mon, 20 Jul 2026 10:23:34 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=ZjlXcdf6; spf=pass (domain: smile.fr, ip: 209.85.128.53, mailfrom: yoann.congal@smile.fr) Received: by mail-wm1-f53.google.com with SMTP id 5b1f17b1804b1-4954dff6536so19614325e9.0 for ; Mon, 20 Jul 2026 10:23:33 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1784568212; x=1785173012; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=VGgkXohXiYrebipYU2/cg0oI5VWRYzLm9h4fMotMqVY=; b=ZjlXcdf6AiNSOjNwSpdBDtLXjViMIauIxzZ1kYsKEkxkaUv2O0D8nkvNHXlgIWmOSt qq6rprquNFvVNJuzrWP/KesvFKA+sFXxRiygCuxmSJLaVK97dPRqSmDAGkMlCtrdQS4M SnIssrLr4eCpipPhIWu6Qccg3Zh9ClwIWIwzc= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1784568212; x=1785173012; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=VGgkXohXiYrebipYU2/cg0oI5VWRYzLm9h4fMotMqVY=; b=R8OPIOJVRUAPYQIcZ2Ld38EePhwVa/mNxk+jGNTmqYcfbP2Kgoq9FdCtLeGoeQE3bn 8VQWLEyVTxoIPn2nzjNKO78FWtNA1tXa8RWPXaLJKBtD3DVtyC+lFNISaUrXc/0o7CK8 RyhbKGas7HB+E3Gi2xOfrjNwtILLaMOq9/bfIhimmb5dUMyOhVVf+RE03qIKPdZSN8ny xpdAQtxFHedWZfgTOtGJLCz7T157N6ThFUVVCfTzRA6HlJ6E0EZyN12K8cOo2HsN9192 Mq050bM+b7Pso1DkQQ+Xd52/FzWbDrbYMDsTsfIR48eIWBnvZ8L4Pv3H6Id8Vzkb5R+y u8wQ== X-Gm-Message-State: AOJu0YyRhPUCo9fqm3IdPBcNJnTHc5Pny04EDlV0iCTETj6IcJnoA0m0 AlzG58WsFBKWuQO/TxIcSmKaIvXh3M25vlhtmVcdgTXDg5eRYxEurxAN6DtznFh9jA7KrctilEH oSAdFpOs= X-Gm-Gg: AfdE7cmTrEUm77Wi8A3AxynR3/6A+jRGFXGF20KApR0EZEe76j8b/s3QQ0ZimatPrHn cmKXHGcFYSW98ARVK3wIfAXLhb3ZndfjQ4K3kHKDf5tUIlAIyFsxpXn9zU/nkgy175GAW6a3TyI MM1iHJEkKf1tSd96ffXEb8d5V0wdi3GHgG1Z3WS47Fii3HYtI2GuStFKpWgHNHYmJdHt3eapX8u ybk3R0QKgVjxhKI08R8vt4LB5Sw0TNaik7p8r+aZ8UP95qsRrhmYyIiJG/yJI+4fy3p3O7oRfUo IoqD0UkLWQXyi7QiDLZJ2iWzWrecGH9WXVH4wdFKitS4Vl1GAnqN8Gy8iRTYFtOXHe6fg4+VFWZ SE5xDUoa13kt8oe/HlMYSPN3yuayiN0PoAfRjKya4pYwfT2hPIFNRUnbTxnajjV10qrMyLLndP5 Wp8eytrBuWMJb3A1UC+zITRp6stSObGM52hND7mPlT+5xzrs+rY2X0vyNBDs/JTc1DHu+t/WCfz TzfjHO1 X-Received: by 2002:a05:600c:1c04:b0:492:3e69:a86f with SMTP id 5b1f17b1804b1-4954a3cff64mr184467975e9.1.1784568212094; Mon, 20 Jul 2026 10:23:32 -0700 (PDT) Received: from localhost.localdomain (2a02-8440-b501-5b7b-2580-caa3-ecc1-dea5.rev.sfr.net. [2a02:8440:b501:5b7b:2580:caa3:ecc1:dea5]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-49563eee22esm36508575e9.1.2026.07.20.10.23.31 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 20 Jul 2026 10:23:31 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][scarthgap 08/33] python3: fix CVE-2026-11940 Date: Mon, 20 Jul 2026 19:22:41 +0200 Message-ID: X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Mon, 20 Jul 2026 17:23:36 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/241442 From: Benjamin Robin (Schneider Electric) tarfile.extractall() with the 'data' or 'tar' filter could be bypassed by a crafted archive where a hardlink references a symlink stored at a deeper name than the hardlink itself. Signed-off-by: Benjamin Robin (Schneider Electric) Signed-off-by: Yoann Congal --- .../python/python3/CVE-2026-11940.patch | 66 +++++++++++++++++++ .../python/python3_3.12.13.bb | 1 + 2 files changed, 67 insertions(+) create mode 100644 meta/recipes-devtools/python/python3/CVE-2026-11940.patch diff --git a/meta/recipes-devtools/python/python3/CVE-2026-11940.patch b/meta/recipes-devtools/python/python3/CVE-2026-11940.patch new file mode 100644 index 00000000000..0851138ae89 --- /dev/null +++ b/meta/recipes-devtools/python/python3/CVE-2026-11940.patch @@ -0,0 +1,66 @@ +From 91a9bd79cdbab8f8518c4a5e669b3f19680a2f31 Mon Sep 17 00:00:00 2001 +From: Stan Ulbrych +Date: Tue, 23 Jun 2026 14:31:38 +0100 +Subject: [PATCH] gh-151558: Fix symlink escape via `tarfile` + hardlink-extraction fallback (GH-151559) + +CVE: CVE-2026-11940 +Upstream-Status: Backport [https://github.com/python/cpython/commit/27dd970bf6b17ebca7c8ed486a40ab043ed7af8f] + +Signed-off-by: Benjamin Robin +--- + Lib/tarfile.py | 3 +++ + Lib/test/test_tarfile.py | 24 ++++++++++++++++++++++++ + 2 files changed, 27 insertions(+) + +diff --git a/Lib/tarfile.py b/Lib/tarfile.py +index 59d3f6e5cce1..83226e907e4b 100755 +--- a/Lib/tarfile.py ++++ b/Lib/tarfile.py +@@ -2650,6 +2650,9 @@ def makelink_with_filter(self, tarinfo, targetpath, + "makelink_with_filter: if filter_function is not None, " + + "extraction_root must also not be None") + try: ++ filter_function( ++ unfiltered.replace(name=tarinfo.name, deep=False), ++ extraction_root) + filtered = filter_function(unfiltered, extraction_root) + except _FILTER_ERRORS as cause: + raise LinkFallbackError(tarinfo, unfiltered.name) from cause +diff --git a/Lib/test/test_tarfile.py b/Lib/test/test_tarfile.py +index 759fa03ead70..29719d95b6c1 100644 +--- a/Lib/test/test_tarfile.py ++++ b/Lib/test/test_tarfile.py +@@ -4080,6 +4080,30 @@ def test_sneaky_hardlink_fallback(self): + self.expect_file("boom", symlink_to='../../link_here') + self.expect_file("c", symlink_to='b') + ++ @symlink_test ++ def test_sneaky_hardlink_fallback_deep(self): ++ # (CVE-2026-11940) ++ with ArchiveMaker() as arc: ++ arc.add("a/b/s", symlink_to=os.path.join("..", "escape")) ++ arc.add("s", hardlink_to=os.path.join("a", "b", "s")) ++ ++ with self.check_context(arc.open(), 'data'): ++ e = self.expect_exception( ++ tarfile.LinkFallbackError, ++ "link 's' would be extracted as a copy of " ++ + "'a/b/s', which was rejected") ++ self.assertIsInstance(e.__cause__, ++ tarfile.LinkOutsideDestinationError) ++ ++ for filter in 'tar', 'fully_trusted': ++ with self.subTest(filter), self.check_context(arc.open(), filter): ++ if not os_helper.can_symlink(): ++ self.expect_file("a/") ++ self.expect_file("a/b/") ++ else: ++ self.expect_file("a/b/s", symlink_to=os.path.join('..', 'escape')) ++ self.expect_file("s", symlink_to=os.path.join('..', 'escape')) ++ + @symlink_test + def test_exfiltration_via_symlink(self): + # (CVE-2025-4138) +-- +2.54.0 diff --git a/meta/recipes-devtools/python/python3_3.12.13.bb b/meta/recipes-devtools/python/python3_3.12.13.bb index d74bdc158b6..e4907154119 100644 --- a/meta/recipes-devtools/python/python3_3.12.13.bb +++ b/meta/recipes-devtools/python/python3_3.12.13.bb @@ -44,6 +44,7 @@ SRC_URI = "http://www.python.org/ftp/python/${PV}/Python-${PV}.tar.xz \ file://CVE-2026-6019_p2.patch \ file://CVE-2025-13462.patch \ file://CVE-2026-4224.patch \ + file://CVE-2026-11940.patch \ " SRC_URI:append:class-native = " \ From patchwork Mon Jul 20 17:22:42 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 92897 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 1DD87C4452D for ; Mon, 20 Jul 2026 17:23:36 +0000 (UTC) Received: from mail-wm1-f51.google.com (mail-wm1-f51.google.com [209.85.128.51]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.2864.1784568214492846149 for ; Mon, 20 Jul 2026 10:23:34 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=oeZrIS0P; spf=pass (domain: smile.fr, ip: 209.85.128.51, mailfrom: yoann.congal@smile.fr) Received: by mail-wm1-f51.google.com with SMTP id 5b1f17b1804b1-495437bb891so32970895e9.1 for ; Mon, 20 Jul 2026 10:23:34 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1784568213; x=1785173013; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=JFcPRDtEdNR6eDOdkKmZReiJSlJjUT6YoqNWETaggb8=; b=oeZrIS0PtJ9RpfIUQ4VsE8b2GM/apwdxNwWd/7xb1XTEPPF8vCX6jTgx1VMvW4TLI+ CzdHb1Oon+rmTkFHtgnfdvg/uDSXOG6a3NW37j7NySIzB1YZdfdQbZkBEvVOLSaU8X8/ ftiiBlNDoGXpIYXX4cx5fxh2c8PCetYhqgBMM= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1784568213; x=1785173013; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=JFcPRDtEdNR6eDOdkKmZReiJSlJjUT6YoqNWETaggb8=; b=qLrwmg5UapO+aRtWloYH2696UnuQWq7YZWDF8w9hLyfiyioz/kgGbggN5K6xtLoxST mJf7L8vpGr31rTmH623LjY4yWaUZfrCAOm6LNOt3pTdW8pfzqKDKb5WOrtybuFWGjzpT 5xrqCkDhB8grDswZHk1D8KHhzo3Tc+iWoUWk1CtcUilffPXRmRu645uZ6nDCpU0kQ+uC Js6PcWDNR1KR3waKHPfF7/iQIXLyJOUz2d62VGDF3roRtgjGfPSX0xl68Z4a3oUbi601 PwkZnCNqEZ5vzZuQrP143UA/kKMpFy8jE9NbbsKgjNnoywMWVA5CVDbj24ZlThVdP1OO jw3A== X-Gm-Message-State: AOJu0YxMnpyguSFadZGnFhtoxxZr3mmVWH1d5TtSqhDaEuVWL2UEpXC8 YkdF9JrWxuWbcquzHur/1tiq4Zi1etDxvSVz+3f4uXbPaKexT+VZmcfaim8/savN8o1F8008fDu HpLooFos= X-Gm-Gg: AfdE7cnbs87W/ECfuKjYvIhykUKKI1wHhavK9ENQdatmMKVJI+85Oz2+GsXqLIaPQj0 QSjLkVZmYIyePpA+Pduqjs29t9bUT75nmn720HX6qPjesIjPi7+4bJGO4cnnzvjhoV1ea6f+nVm /Ptf4cYTkY33C1s88CPNUWi/OOlro7yZ8Vq3NxKo0dkxR+B6c2MzkROAxZxqAw8jsOg292gLZ/d km3QDm6cvegWt86sokSXfzl2+lLJGUz1pQm60DUrr0uPlNKsGBiZV01B2bf8RcLFxYw6XPuq11W MRrAoOAB9jvT9qt/0uBjLbpOjtl/nwWdW8DV2Pprxjjc0vJNksmKkD3BzSGTEf4liu4/S8tDx3A OG/qhd0mA/Ucx7ilXJwXp2v05YoH/kUGNGwCXa5/lAoXqYBGQNEhxpXgMKqBikTOGGECKhO8pa5 WVS/M6K5GXPgMf1m/bcLkh7nhdHGnIGTsAZ2r/OP2BNL4L8YvlMPnHjrNw73+xTHz4GYFryhoRo UIohEZDT9RpBoyVL3I= X-Received: by 2002:a05:600c:35d1:b0:495:3a52:71b1 with SMTP id 5b1f17b1804b1-4954aa1a34fmr143748485e9.5.1784568212758; Mon, 20 Jul 2026 10:23:32 -0700 (PDT) Received: from localhost.localdomain (2a02-8440-b501-5b7b-2580-caa3-ecc1-dea5.rev.sfr.net. [2a02:8440:b501:5b7b:2580:caa3:ecc1:dea5]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-49563eee22esm36508575e9.1.2026.07.20.10.23.32 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 20 Jul 2026 10:23:32 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][scarthgap 09/33] python3: fix CVE-2026-11972 Date: Mon, 20 Jul 2026 19:22:42 +0200 Message-ID: <9c066bcd634e7b938a10c64ef1eaf322a99ec434.1784567958.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Mon, 20 Jul 2026 17:23:36 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/241443 From: Benjamin Robin (Schneider Electric) When using the "tarfile" module with a file opened in "streaming mode" (mode="r|") the tarfile module did not properly handle EOF, making archive parsing take exponentially longer. Signed-off-by: Benjamin Robin (Schneider Electric) Signed-off-by: Mathieu Dubois-Briand Signed-off-by: Richard Purdie (cherry picked from commit bbd9c82298880ab61b9befea97dfe8a0a4943836) Signed-off-by: Yoann Congal --- .../python/python3/CVE-2026-11972.patch | 60 +++++++++++++++++++ .../python/python3_3.12.13.bb | 1 + 2 files changed, 61 insertions(+) create mode 100644 meta/recipes-devtools/python/python3/CVE-2026-11972.patch diff --git a/meta/recipes-devtools/python/python3/CVE-2026-11972.patch b/meta/recipes-devtools/python/python3/CVE-2026-11972.patch new file mode 100644 index 00000000000..36334f247e6 --- /dev/null +++ b/meta/recipes-devtools/python/python3/CVE-2026-11972.patch @@ -0,0 +1,60 @@ +From a83ebdb495a9cbd28a03675acdeda235fade90b3 Mon Sep 17 00:00:00 2001 +From: Petr Viktorin +Date: Tue, 23 Jun 2026 15:13:30 +0200 +Subject: [PATCH] gh-151981: Make tarfile._Stream.seek break at EOF (GH-151982) + +Co-authored-by: Stan Ulbrych + +CVE: CVE-2026-11972 +Upstream-Status: Backport [https://github.com/python/cpython/commit/f50bf13566189c8d0ce5a814f33eff3d89951896] + +Signed-off-by: Benjamin Robin +--- + Lib/tarfile.py | 4 +++- + Lib/test/test_tarfile.py | 16 ++++++++++++++++ + 2 files changed, 19 insertions(+), 1 deletion(-) + +diff --git a/Lib/tarfile.py b/Lib/tarfile.py +index 83226e907e4b..c0007a78f700 100755 +--- a/Lib/tarfile.py ++++ b/Lib/tarfile.py +@@ -516,7 +516,9 @@ def seek(self, pos=0): + if pos - self.pos >= 0: + blocks, remainder = divmod(pos - self.pos, self.bufsize) + for i in range(blocks): +- self.read(self.bufsize) ++ data = self.read(self.bufsize) ++ if not data: ++ break + self.read(remainder) + else: + raise StreamError("seeking backwards is not allowed") +diff --git a/Lib/test/test_tarfile.py b/Lib/test/test_tarfile.py +index 29719d95b6c1..8aeb2e1b1b9a 100644 +--- a/Lib/test/test_tarfile.py ++++ b/Lib/test/test_tarfile.py +@@ -4480,6 +4480,22 @@ def valueerror_filter(tarinfo, path): + with self.check_context(arc.open(errorlevel='boo!'), filtererror_filter): + self.expect_exception(TypeError) # errorlevel is not int + ++ @support.subTests('format', [tarfile.GNU_FORMAT, tarfile.PAX_FORMAT]) ++ def test_getmembers_big_size(self, format): ++ # gh-151981: A loop in seek() for streaming files tried to read the ++ # declared number of blocks even at EOF ++ tinfo = tarfile.TarInfo("huge-file") ++ tinfo.size = 1 << 64 ++ bio = io.BytesIO() ++ # Write header without data ++ bio.write(tinfo.tobuf(format)) ++ ++ # Reset & try to get contents ++ bio.seek(0) ++ with tarfile.open(fileobj=bio, mode="r|") as tar: ++ with self.assertRaises(tarfile.ReadError): ++ tar.getmembers() ++ + + class OverwriteTests(archiver_tests.OverwriteTests, unittest.TestCase): + testdir = os.path.join(TEMPDIR, "testoverwrite") +-- +2.54.0 diff --git a/meta/recipes-devtools/python/python3_3.12.13.bb b/meta/recipes-devtools/python/python3_3.12.13.bb index e4907154119..72daee1d0ea 100644 --- a/meta/recipes-devtools/python/python3_3.12.13.bb +++ b/meta/recipes-devtools/python/python3_3.12.13.bb @@ -45,6 +45,7 @@ SRC_URI = "http://www.python.org/ftp/python/${PV}/Python-${PV}.tar.xz \ file://CVE-2025-13462.patch \ file://CVE-2026-4224.patch \ file://CVE-2026-11940.patch \ + file://CVE-2026-11972.patch \ " SRC_URI:append:class-native = " \ From patchwork Mon Jul 20 17:22:43 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 92898 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 1B49FC44520 for ; Mon, 20 Jul 2026 17:23:36 +0000 (UTC) Received: from mail-wm1-f52.google.com (mail-wm1-f52.google.com [209.85.128.52]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.2866.1784568215279355773 for ; Mon, 20 Jul 2026 10:23:35 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=YxVDkBMS; spf=pass (domain: smile.fr, ip: 209.85.128.52, mailfrom: yoann.congal@smile.fr) Received: by mail-wm1-f52.google.com with SMTP id 5b1f17b1804b1-4955de8797cso7666125e9.3 for ; Mon, 20 Jul 2026 10:23:35 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1784568213; x=1785173013; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=EKnZ3ozTblM0tAoDSBQWwjCMkG7GAm7qfTq2xZkPOP4=; b=YxVDkBMScrPGV6+KwuhvYDD7lXmbe4iV9F5n9b7bIR4XaQhk9ooqc2AcfBApQmZzJv NVQs0F/QGgbUxWTccn0JZ/nn+AXMadXR8RoICWneMt0oNbfFLKMF+COHggZdqdACnO/m KdCJqcxzzxAdJG19hQEIlnzoWh8jgmRwwpNYQ= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1784568213; x=1785173013; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=EKnZ3ozTblM0tAoDSBQWwjCMkG7GAm7qfTq2xZkPOP4=; b=fTHKQtWbGuRHbGrds5qMezQyBRG/hizlEXJlMv6iU1Dm9rNjvkX0Q4jzhZIKDdlMaH Fb1GYKdzrGsMRJcdJpplV75DMHkfI4qh8oLbR7NBSchDEscTy5SDJT6/2x0HJPnrXN/2 4MInMJB8NkH3MgtY0HCA9QHrfPNJjsxMrMa2Idd3yIrHLFznkobCNJkIJqpeIL8WI/Dm rrzMJ/ix/oSwn/YtVKo5zFA2e2UEr1pYEq8ExXpzF5fRPUjJ2OvnDe3vMY5qwoxXpUks 3dGM+9TjeHn9jdPnboNQfp3T5AkhOkuLcmYO2uXQUIDhMfjGDmnGWJNsMxPtYHLLn7Kt aoKw== X-Gm-Message-State: AOJu0YyS+OmHgCxOWZiSACsEMwzjOT/8CVEST3t6JRSOpf+yKt8TLstg hc2mjaNThG0XDpWOeQQoDaKaSUwJKtXDlnlLnx26USs8e5M3Soam+Gd1LG2+nMp1vmo5KLYRYyV DTTEJIxA= X-Gm-Gg: AfdE7cltOgWat/TTpcB7e34i4gpauSyyQKdPPecKXQj4iyvPTyzWtAHKEREWqsxPohe lMXdroPQ/abUTciwbrG4xMfru4FgV0W9nrZHZNVxjKqG+UjmW2D8cS9vUhbG1uJff2Y6dtE0usT GuXbOvMj7u0seieLSXSDfJSw717VUPDJT8Zfr12C1rFC8gAiD51bSjUZsJPPo021Yc1rRvuFYMV nhBUfaLidDLMjYdO/rp8HgSp09/TL0q5If10ym51NsLEalr0mQuIE5LV2f8GlQEt1w5SKI64Nzc saOGYlwG0/zdQjgQa54MH0H0gqAbJS8stFAis9jG1QZneE/n6VdPiQVOAExAdikRy23xslwPzNi S/M8LMaiY6vyuZ1eaLDfc1PzJ29pymUjZpSSspzmoMG7Fol0Rf33UBiIdf2xle0r/3/lK6H804Z z+BudYrcEeIubRUu4eBBNCvRdTDU2T/ktCgsjDBsLlH7S9YEa+t7augpKzxgkTKbND4BdbXKyBp 6Q96PQm X-Received: by 2002:a05:600c:1554:b0:495:3de8:33a6 with SMTP id 5b1f17b1804b1-4954a3dc7bcmr187274065e9.16.1784568213458; Mon, 20 Jul 2026 10:23:33 -0700 (PDT) Received: from localhost.localdomain (2a02-8440-b501-5b7b-2580-caa3-ecc1-dea5.rev.sfr.net. [2a02:8440:b501:5b7b:2580:caa3:ecc1:dea5]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-49563eee22esm36508575e9.1.2026.07.20.10.23.32 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 20 Jul 2026 10:23:33 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][scarthgap 10/33] python3: fix CVE-2026-9669 Date: Mon, 20 Jul 2026 19:22:43 +0200 Message-ID: <226831c16d13133e89d3405b5e2298bb6571bed6.1784567958.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Mon, 20 Jul 2026 17:23:36 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/241444 From: Benjamin Robin (Schneider Electric) bz2.BZ2Decompressor objects could be reused after a decompression error. If an application caught the resulting OSError and retried with the same decompressor, crafted input could cause the decompressor to resume from an invalid internal state and perform out-of-bounds writes to a stack buffer. This could crash the process when processing untrusted data. This CVE has a CVSS 4.0 score of 8.2. The patch (5755d0f08394) is referenced in the CVEList database. Signed-off-by: Benjamin Robin (Schneider Electric) Signed-off-by: Yoann Congal --- .../python/python3/CVE-2026-9669.patch | 96 +++++++++++++++++++ .../python/python3_3.12.13.bb | 1 + 2 files changed, 97 insertions(+) create mode 100644 meta/recipes-devtools/python/python3/CVE-2026-9669.patch diff --git a/meta/recipes-devtools/python/python3/CVE-2026-9669.patch b/meta/recipes-devtools/python/python3/CVE-2026-9669.patch new file mode 100644 index 00000000000..266c8beef05 --- /dev/null +++ b/meta/recipes-devtools/python/python3/CVE-2026-9669.patch @@ -0,0 +1,96 @@ +From 5b412e1f7bdb3e0667b2bc8b216ad216d59d8373 Mon Sep 17 00:00:00 2001 +From: Stan Ulbrych +Date: Mon, 8 Jun 2026 11:55:32 +0200 +Subject: [PATCH] gh-150599: Prevent bz2 decompressor reuse after errors + (GH-150600) + +CVE: CVE-2026-9669 +Upstream-Status: Backport [https://github.com/python/cpython/commit/5755d0f083949ff3c5bf3a37e673e24e306b036e] + +Signed-off-by: Benjamin Robin +--- + Lib/test/test_bz2.py | 15 +++++++++++++++ + Modules/_bz2module.c | 18 +++++++++++++++--- + 2 files changed, 30 insertions(+), 3 deletions(-) + +diff --git a/Lib/test/test_bz2.py b/Lib/test/test_bz2.py +index cb730a1a46e2..dcbf6a298264 100644 +--- a/Lib/test/test_bz2.py ++++ b/Lib/test/test_bz2.py +@@ -958,6 +958,21 @@ def test_failure(self): + # Previously, a second call could crash due to internal inconsistency + self.assertRaises(Exception, bzd.decompress, self.BAD_DATA * 30) + ++ def test_decompress_after_data_error(self): ++ data = bytes.fromhex( ++ "425a6839314159265359000000000000007fffff000000000000000000000000" ++ "00000000000000000000000000000000000000e0370000000000000000000000" ++ "000000000000000000000000000000000000000000000000000083f3" ++ ) ++ bzd = BZ2Decompressor() ++ with self.assertRaisesRegex(OSError, "Invalid data stream"): ++ bzd.decompress(data) ++ # Previously, a second call could crash due to internal inconsistency ++ self.assertFalse(bzd.needs_input) ++ self.assertFalse(bzd.eof) ++ with self.assertRaisesRegex(ValueError, "previous error"): ++ bzd.decompress(b'\x00' * 18) ++ + @support.refcount_test + def test_refleaks_in___init__(self): + gettotalrefcount = support.get_attribute(sys, 'gettotalrefcount') +diff --git a/Modules/_bz2module.c b/Modules/_bz2module.c +index 97bd44b4ac96..0b0916142f57 100644 +--- a/Modules/_bz2module.c ++++ b/Modules/_bz2module.c +@@ -114,6 +114,7 @@ typedef struct { + typedef struct { + PyObject_HEAD + bz_stream bzs; ++ int bzerror; + char eof; /* T_BOOL expects a char */ + PyObject *unused_data; + char needs_input; +@@ -453,8 +454,11 @@ decompress_buf(BZ2Decompressor *d, Py_ssize_t max_length) + + d->bzs_avail_in_real += bzs->avail_in; + +- if (catch_bz2_error(bzret)) ++ if (catch_bz2_error(bzret)) { ++ d->bzerror = bzret; ++ d->needs_input = 0; + goto error; ++ } + if (bzret == BZ_STREAM_END) { + d->eof = 1; + break; +@@ -621,10 +625,17 @@ _bz2_BZ2Decompressor_decompress_impl(BZ2Decompressor *self, Py_buffer *data, + PyObject *result = NULL; + + ACQUIRE_LOCK(self); +- if (self->eof) ++ if (self->eof) { + PyErr_SetString(PyExc_EOFError, "End of stream already reached"); +- else ++ } ++ else if (self->bzerror) { ++ // Re-entering BZ2_bzDecompress() after an error can write out of bounds. ++ PyErr_SetString(PyExc_ValueError, ++ "Decompressor is unusable after a previous error"); ++ } ++ else { + result = decompress(self, data->buf, data->len, max_length); ++ } + RELEASE_LOCK(self); + return result; + } +@@ -658,6 +669,7 @@ _bz2_BZ2Decompressor_impl(PyTypeObject *type) + return NULL; + } + ++ self->bzerror = 0; + self->needs_input = 1; + self->bzs_avail_in_real = 0; + self->input_buffer = NULL; +-- +2.54.0 diff --git a/meta/recipes-devtools/python/python3_3.12.13.bb b/meta/recipes-devtools/python/python3_3.12.13.bb index 72daee1d0ea..de174f7bfdc 100644 --- a/meta/recipes-devtools/python/python3_3.12.13.bb +++ b/meta/recipes-devtools/python/python3_3.12.13.bb @@ -46,6 +46,7 @@ SRC_URI = "http://www.python.org/ftp/python/${PV}/Python-${PV}.tar.xz \ file://CVE-2026-4224.patch \ file://CVE-2026-11940.patch \ file://CVE-2026-11972.patch \ + file://CVE-2026-9669.patch \ " SRC_URI:append:class-native = " \ From patchwork Mon Jul 20 17:22:44 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 92908 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id EA850C44536 for ; Mon, 20 Jul 2026 17:23:37 +0000 (UTC) Received: from mail-wm1-f42.google.com (mail-wm1-f42.google.com [209.85.128.42]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.2869.1784568216325678844 for ; Mon, 20 Jul 2026 10:23:36 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=aYA2jH9d; spf=pass (domain: smile.fr, ip: 209.85.128.42, mailfrom: yoann.congal@smile.fr) Received: by mail-wm1-f42.google.com with SMTP id 5b1f17b1804b1-4955adb04e8so11202705e9.2 for ; Mon, 20 Jul 2026 10:23:36 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1784568214; x=1785173014; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=iYgjVOrWsXhvBDvkj2S7izmW+6Wn48H51ZpGpSauhEY=; b=aYA2jH9dzq6TAnZVIP/OucUp4ywcw/8g4evtFBg7CmA0O3ILqOlR90ic94s6jXfuAU oVdOYL0eWwquNi3rvn272pdTUznsD3nYpA1u7G+9aj4z6MlYzRWujYSPwzVY4KjcboKC EKeYxGjZz8RUZNnGjQpv4aCODRExnDDdKq3ZY= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1784568214; x=1785173014; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=iYgjVOrWsXhvBDvkj2S7izmW+6Wn48H51ZpGpSauhEY=; b=m3qGJRhACNZ3MyCtU3a1bGDRg4KZn4FGUEj+ryjAGs9nk6vmTmqjqcLopWlZfROM6j J2yG987XmV1+J8VrxV7ksBCtJoyqVeenwZRfVB0c06wWmgev9hxXIew7qlECvoqSgm6P E8vX7tcB1FTawUzd+ycvMruDopWRTrO5470FsSmLBDilJxYi9O1xGREusuD3qe6xRiuo 3ouN1QMYzu8CG68i0zvnQ1AKdkSiXP2sFJHzXOGKB7XYJ8hgn6vnAAv8newP40cT7n2m b8LarjjRxxxhpNxm7EjbNE4VNvT/RrK+vRARwvrsIJusfNJ/IjmGhYa5CFNL0BeMGNwK vtMg== X-Gm-Message-State: AOJu0YyZ5mr8LUMFNtF6nO2tlBxYRQNjOVfLIy8PalpeydgYeZZbg6sH dpafvVrlfJ4b9odYE8kgXnzG27aOsCbF4IgxNyYu2xyMR7I9aGiL/5W4GJmbw79ATw70F1ZOFf5 +1M9+rGI= X-Gm-Gg: AfdE7cnqGyeRfsdEbBTRvCt5TO5/ivf/uILxvy5UHZs96iUp7SrwH0PHknm9SIfJhG6 akxjjBYhwUagENQMB8k9V4PutfwA1P4s3seja9v6aI4mqjly76LB83Coh3C5Fi0z++irJ7Q8KkU dCVDfOX9fXPdOmCzoi10dhA09CgI223eMppQQb585Z/bYxKyu/n9IKR/XFFuMlkUi0wOz5KViEa Soco4EgOcYqzXCtuwfYJzCzIQTDCCLs9jc9CKXQ9DKmjZnb80AdQF+tx5JPheG5F/05HeHjt/t+ 2S5Is0U5IZTKfmV/kF9AEZdmWnJy+htK8aYjF0wO0dDlKZpFQgd+ZzM5bWwpburqhaHrFUANCGD uluCLGFy5B6lbb1xg/rmhng6wbSO80sxbVpw55hOZI5j6iW2oLsXPWqQZFt3hOXe+9FfXvYmY66 SgdZljD2HGqN1Un0hWoWXptQpwOzwBHWCNv/gObnojXiDWyDNAy7tUMLjC+k5UXF1Pl2VIVlAov r8XWSzo X-Received: by 2002:a05:600c:4585:b0:495:3eb2:b763 with SMTP id 5b1f17b1804b1-4954a50c51bmr162749635e9.21.1784568214549; Mon, 20 Jul 2026 10:23:34 -0700 (PDT) Received: from localhost.localdomain (2a02-8440-b501-5b7b-2580-caa3-ecc1-dea5.rev.sfr.net. [2a02:8440:b501:5b7b:2580:caa3:ecc1:dea5]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-49563eee22esm36508575e9.1.2026.07.20.10.23.33 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 20 Jul 2026 10:23:34 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][scarthgap 11/33] bzip2: Fix CVE-2026-42250 Date: Mon, 20 Jul 2026 19:22:44 +0200 Message-ID: <2ae360e0f03c70f376226f4cbb5fd7d61b7bae99.1784567958.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Mon, 20 Jul 2026 17:23:37 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/241445 From: Jaipaul Cheernam This patch applies the upstream fix as referenced in [1], using the commit shown in [2]. [1] https://nvd.nist.gov/vuln/detail/CVE-2026-42250 [2] https://sourceware.org/cgit/bzip2/commit/?id=35d122a3df8b0cc4082a4d89fdc6ee99f375fe67 Signed-off-by: Jaipaul Cheernam Signed-off-by: Richard Purdie (cherry picked from commit bf39a3c0497023e96de11444579ffef31f968bcd) Signed-off-by: Yoann Congal --- .../bzip2/bzip2/CVE-2026-42250.patch | 35 +++++++++++++++++++ meta/recipes-extended/bzip2/bzip2_1.0.8.bb | 1 + 2 files changed, 36 insertions(+) create mode 100644 meta/recipes-extended/bzip2/bzip2/CVE-2026-42250.patch diff --git a/meta/recipes-extended/bzip2/bzip2/CVE-2026-42250.patch b/meta/recipes-extended/bzip2/bzip2/CVE-2026-42250.patch new file mode 100644 index 00000000000..1679e744478 --- /dev/null +++ b/meta/recipes-extended/bzip2/bzip2/CVE-2026-42250.patch @@ -0,0 +1,35 @@ +From 71bf61d2e664c754ae5b1eb04018c8eaf5f99ae3 Mon Sep 17 00:00:00 2001 +From: Mark Wielaard +Date: Thu, 28 May 2026 16:15:45 +0200 +Subject: [PATCH] bzip2recover: Make sure to not process more than + BZ_MAX_HANDLED_BLOCKS + +There is an off-by-one in the check before calling tooManyBlocks. This +causes the scanning loop to run one more time and cause a possible +read or write one past the global bStart, bEnd, rbStart and rbEnd +buffers. There are no known exploits of this issue and you will need +to compile with something like gcc -fsanitize=address (ASAN +AddressSanitizer) to observe the faulty read/write. + +This has been assigned CVE-2026-42250. + +CVE: CVE-2026-42250 +Upstream-Status: Backport [https://sourceware.org/cgit/bzip2/commit/?id=35d122a3df8b0cc4082a4d89fdc6ee99f375fe67] +Signed-off-by: Jaipaul Cheernam +--- + bzip2recover.c | 2 +- + 1 file changed, 1 insertion(+), 1 deletion(-) + +diff --git a/bzip2recover.c b/bzip2recover.c +index a8131e0..4b1c219 100644 +--- a/bzip2recover.c ++++ b/bzip2recover.c +@@ -402,7 +402,7 @@ Int32 main ( Int32 argc, Char** argv ) + rbEnd[rbCtr] = bEnd[currBlock]; + rbCtr++; + } +- if (currBlock >= BZ_MAX_HANDLED_BLOCKS) ++ if (currBlock >= BZ_MAX_HANDLED_BLOCKS - 1) + tooManyBlocks(BZ_MAX_HANDLED_BLOCKS); + currBlock++; + diff --git a/meta/recipes-extended/bzip2/bzip2_1.0.8.bb b/meta/recipes-extended/bzip2/bzip2_1.0.8.bb index f9224908685..b661bc95465 100644 --- a/meta/recipes-extended/bzip2/bzip2_1.0.8.bb +++ b/meta/recipes-extended/bzip2/bzip2_1.0.8.bb @@ -26,6 +26,7 @@ SRC_URI = "https://sourceware.org/pub/${BPN}/${BPN}-${PV}.tar.gz \ file://configure.ac;subdir=${BP} \ file://Makefile.am;subdir=${BP} \ file://run-ptest \ + file://CVE-2026-42250.patch;subdir=${BP} \ " SRC_URI[md5sum] = "67e051268d0c475ea773822f7500d0e5" SRC_URI[sha256sum] = "ab5a03176ee106d3f0fa90e381da478ddae405918153cca248e682cd0c4a2269" From patchwork Mon Jul 20 17:22:45 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 92910 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 2F68CC44515 for ; Mon, 20 Jul 2026 17:23:47 +0000 (UTC) Received: from mail-wr1-f51.google.com (mail-wr1-f51.google.com [209.85.221.51]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.2896.1784568217152343516 for ; Mon, 20 Jul 2026 10:23:37 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=zsM9KzP+; spf=pass (domain: smile.fr, ip: 209.85.221.51, mailfrom: yoann.congal@smile.fr) Received: by mail-wr1-f51.google.com with SMTP id ffacd0b85a97d-4798bea72f9so5427706f8f.1 for ; Mon, 20 Jul 2026 10:23:36 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1784568215; x=1785173015; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=g7Vt+Fr6hLUkpdC3FPgwSW4OgJnM0Fa6s3BBQ17fONo=; b=zsM9KzP+y+HYMNZ+bB66VzQhA9kS0zcz7zvNrEyKHn5SWGDFOAyGdnWCjflB2YBUqb /+a2a5cth6N3Y2EOecYxVGSRo80L8sZO6e5OtK+8RjRfJJtRwfBK+Uo8neDi056mHWfl X3i/wkhUqO4zJ2PzYdO3dQG/nMKsaHLJwgKMM= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1784568215; x=1785173015; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=g7Vt+Fr6hLUkpdC3FPgwSW4OgJnM0Fa6s3BBQ17fONo=; b=CKjLaqJtgOjhhp0IV7thsPrC23nzjuaQjp9OyV9Pkf/GwoXFxFiZHEx4plhq49bkXW T6h1eCCVAYLZdZETpVUDJjkFfF9pjPoapX+ueK0+1ZnKoPzBitsDjjmh6oeyLkdjRkem rWhWXgsbap9hXxsDJ2umRf/CcZbcADFUhnOhKurTx/lt1QKHs0+W7pjsDFcpCJrkMgt5 2CUpCnUV/Y9HESI1sZN3vxc1PI4qFRHbURbCq8DBS4ia36jF7nXFKmrnZK/F1JuTH7JR 8QGmuG1ZBktvVAm80H1giwtNbZPvq1UukHzhGD3mCCkeT77yttoIKjMqhlmjDS10ZYvr Pkfw== X-Gm-Message-State: AOJu0YyFGMITMPfzxE0wkU8G0csWJPSMZRouBOP5QzmZ6EqFf1vr8I0H cCeJNz5zuCGiE9L3byzMzXMGvCW3jt3Vlwx4W1WXDy+XsjVwKp9w3Ajgmi1n+WmUllpQcEsP4cc Ox0ffgjE= X-Gm-Gg: AfdE7ck56/X9+2NuuMYwqz9ABaMlNRtvBwiThU3FrJUBx5XyrNKH9J0gnotziVlASGg wAIZvjEteqXe6HHjw7xd91gDtQ2IfNCD/76Z97UU4NtDtuR/yPaKqwZik0BpjkAgnsXMrex/7Hx 6Bgd3LteKK6A5+b6Ad9m1U8LCNou7kxHxu4HSdbT5fdWoW8/D2O5W0bimyeAIbZLD5WsqOaelqM FvUm6wG7Zo1DqzeRsYDi4CFKTxh8S3mxXhnLFoz/v9DOsCCEDFdwZ5tmpZ7S/HWFo2ZWBaRZ+7W o7oj1bHCy8L3Jn3ZbWXHQQ3S4luX187kLjA9fXCt0VdB5apD7i/UAWGXg90/QObzOQul9QBK5G0 fsBxEY4uyUlONvZL9ld2Q9kjDd7hMTJtMWlzai83EM9Nqj+fCR3r9A2MvnpyAd8F8wJZQ3OlHng A7oeieHCfUgws6YHqa2gv6bej3VVcWXC0iOOezNouepXEfFHWVeyHC6bRsSCeTSNgcholoOqYX9 HDJeqWJ X-Received: by 2002:a05:600c:4687:b0:495:5845:fb2 with SMTP id 5b1f17b1804b1-495584510afmr92476715e9.38.1784568215351; Mon, 20 Jul 2026 10:23:35 -0700 (PDT) Received: from localhost.localdomain (2a02-8440-b501-5b7b-2580-caa3-ecc1-dea5.rev.sfr.net. [2a02:8440:b501:5b7b:2580:caa3:ecc1:dea5]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-49563eee22esm36508575e9.1.2026.07.20.10.23.34 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 20 Jul 2026 10:23:34 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][scarthgap 12/33] bzip2: fix 'bzip2 --version > /tmp/aaa 2>&1' hang Date: Mon, 20 Jul 2026 19:22:45 +0200 Message-ID: <4e5d0d595f713a4a5cff72f389aa9cac07fe5d14.1784567958.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Mon, 20 Jul 2026 17:23:47 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/241446 From: Hongxu Jia According to [1] As of the current version 1.0.8, bzip2 --version will print version info but it will also continue compressing stdin: $ ./bzip2 --version bzip2, a block-sorting file compressor. Version 1.0.8, 13-Jul-2019. Copyright (C) 1996-2019 by Julian Seward. This program is free software; [...] bzip2: I won't write compressed data to a terminal. bzip2: For help, type: `bzip2 --help'. Debian (and its downstreams like Ubuntu) will patch this out [2], making the < /dev/null unnecessary, port a part of debian patch to fix the issue [1] https://stackoverflow.com/questions/59757176/why-using-dev-null-with-a-program-like-bzip2 [2] https://sources.debian.org/src/bzip2/1.0.8-6/debian/patches/20-legacy.patch/ Signed-off-by: Hongxu Jia Signed-off-by: Mathieu Dubois-Briand Signed-off-by: Richard Purdie (cherry picked from commit ae4fe4263ba9d372f9b9e80df4ec4697b51c1f9b) Signed-off-by: Jaipaul Cheernam Signed-off-by: Yoann Congal --- ...-fix-bzip2-version-tmp-aaa-will-hang.patch | 62 +++++++++++++++++++ meta/recipes-extended/bzip2/bzip2_1.0.8.bb | 1 + 2 files changed, 63 insertions(+) create mode 100644 meta/recipes-extended/bzip2/bzip2/0001-fix-bzip2-version-tmp-aaa-will-hang.patch diff --git a/meta/recipes-extended/bzip2/bzip2/0001-fix-bzip2-version-tmp-aaa-will-hang.patch b/meta/recipes-extended/bzip2/bzip2/0001-fix-bzip2-version-tmp-aaa-will-hang.patch new file mode 100644 index 00000000000..84206b2a4d0 --- /dev/null +++ b/meta/recipes-extended/bzip2/bzip2/0001-fix-bzip2-version-tmp-aaa-will-hang.patch @@ -0,0 +1,62 @@ +From a9dd6acbaca836fc4e943e69a31b2e7acda32045 Mon Sep 17 00:00:00 2001 +From: Hongxu Jia +Date: Wed, 13 Nov 2024 19:49:23 +0800 +Subject: [PATCH] fix 'bzip2 --version > /tmp/aaa 2>&1' hang + +According to [1] + +As of the current version 1.0.8, bzip2 --version will print version +info but it will also continue compressing stdin: + + $ ./bzip2 --version + bzip2, a block-sorting file compressor. Version 1.0.8, 13-Jul-2019. + + Copyright (C) 1996-2019 by Julian Seward. + + This program is free software; [...] + + bzip2: I won't write compressed data to a terminal. + bzip2: For help, type: `bzip2 --help'. + +Debian (and its downstreams like Ubuntu) will patch this out [2], +making the < /dev/null unnecessary: + +[1] https://stackoverflow.com/questions/59757176/why-using-dev-null-with-a-program-like-bzip2 +[2] https://sources.debian.org/src/bzip2/1.0.8-6/debian/patches/20-legacy.patch/ + +Upstream-Status: Submitted [bzip2-devel@sourceware.org] + +Signed-off-by: Hongxu Jia +--- + bzip2.c | 8 +++++--- + 1 file changed, 5 insertions(+), 3 deletions(-) + +diff --git a/bzip2.c b/bzip2.c +index d95d280..6ec9871 100644 +--- a/bzip2.c ++++ b/bzip2.c +@@ -1890,7 +1890,9 @@ IntNative main ( IntNative argc, Char *argv[] ) + case '8': blockSize100k = 8; break; + case '9': blockSize100k = 9; break; + case 'V': +- case 'L': license(); break; ++ case 'L': license(); ++ exit ( 0 ); ++ break; + case 'v': verbosity++; break; + case 'h': usage ( progName ); + exit ( 0 ); +@@ -1916,8 +1918,8 @@ IntNative main ( IntNative argc, Char *argv[] ) + if (ISFLAG("--keep")) keepInputFiles = True; else + if (ISFLAG("--small")) smallMode = True; else + if (ISFLAG("--quiet")) noisy = False; else +- if (ISFLAG("--version")) license(); else +- if (ISFLAG("--license")) license(); else ++ if (ISFLAG("--version")) { license(); exit ( 0 ); } else ++ if (ISFLAG("--license")) { license(); exit ( 0 ); } else + if (ISFLAG("--exponential")) workFactor = 1; else + if (ISFLAG("--repetitive-best")) redundant(aa->name); else + if (ISFLAG("--repetitive-fast")) redundant(aa->name); else +-- +2.34.1 + diff --git a/meta/recipes-extended/bzip2/bzip2_1.0.8.bb b/meta/recipes-extended/bzip2/bzip2_1.0.8.bb index b661bc95465..6c02dc3ed06 100644 --- a/meta/recipes-extended/bzip2/bzip2_1.0.8.bb +++ b/meta/recipes-extended/bzip2/bzip2_1.0.8.bb @@ -27,6 +27,7 @@ SRC_URI = "https://sourceware.org/pub/${BPN}/${BPN}-${PV}.tar.gz \ file://Makefile.am;subdir=${BP} \ file://run-ptest \ file://CVE-2026-42250.patch;subdir=${BP} \ + file://0001-fix-bzip2-version-tmp-aaa-will-hang.patch;subdir=${BP} \ " SRC_URI[md5sum] = "67e051268d0c475ea773822f7500d0e5" SRC_URI[sha256sum] = "ab5a03176ee106d3f0fa90e381da478ddae405918153cca248e682cd0c4a2269" From patchwork Mon Jul 20 17:22:46 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 92916 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id D12FBC44534 for ; Mon, 20 Jul 2026 17:23:47 +0000 (UTC) Received: from mail-wm1-f47.google.com (mail-wm1-f47.google.com [209.85.128.47]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.2897.1784568217941760168 for ; Mon, 20 Jul 2026 10:23:38 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=EIP5lMvI; spf=pass (domain: smile.fr, ip: 209.85.128.47, mailfrom: yoann.congal@smile.fr) Received: by mail-wm1-f47.google.com with SMTP id 5b1f17b1804b1-4953e04ef16so45662295e9.2 for ; Mon, 20 Jul 2026 10:23:37 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1784568216; x=1785173016; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=HF+gfoI0duFTXBwdA++ro7fQQ++CNS/hPiM7+1sQ4qA=; b=EIP5lMvIiDdGcphI7HvcnsqGaC6HUR/1GUF0gkOQYmAPIaC9dxVdT0su6PglWFB0pB bCpgx89TSDB/1MUFztMBZC9YunLN2N+gBCmNDSYuGGrATDQu+YQ9REHrD6BagDGyq7vs lBmJm+TRT4zq5em9hkh+ARnIGWi1F19uiBMpI= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1784568216; x=1785173016; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=HF+gfoI0duFTXBwdA++ro7fQQ++CNS/hPiM7+1sQ4qA=; b=eS0ScOGqglLSeKlU3h2RXEKxegBYdQsvRD2idY5aTd7CIn7PVwQJjPKSbohS0x0Nhp Xq6O2LEatlJFjQkl+iJf8RfVU9yqDpt/JDkrLT3Pptwlpdozn7jM4C55oS1eHJ0kicCN dmpaCZx87aSB3H0QbdLIw+Nf4qPaW+FwhTncrkRJ8PzDPTbQbo/3BQT83nN4EkgszqUn b6qzHe8uNFpBC6INc0DsrdFzk+J90uFr2uS/kAZdb/bf2SgXaMofjnipSQjfwrV+m+if Z8c7SKQPlzwAGY/Dqyg1wDQkpBsI8dRd0YNbI7c5b0QWkVlMaEan5AeVMdN7FPK/e+q6 KB0A== X-Gm-Message-State: AOJu0Yznn7Ht+DaTZQo5q7PNDJNKfwxu1koou0Z6qitQLkRTuOxnRGbZ sEtSFxb0wYgmWaIFQqjvsvjdmRxmg7ceRytmxwPQxMYUh3gQM9nhpxSi3p8Kx0F3+42DLzodR6+ 6KM/pcP4= X-Gm-Gg: AfdE7cki4Ku0N6SvKnMnnytufBnk2QThAXP7P2ptNsREpwd/odB/pA8jLuhmqZQ+rVM vmbgIpIC2SibR4dBSZfuyVpE2S41+X990lP1PCXERYqDpV700qWWEZQQKDOsZD/aq8FrvRRS8ll KHocH+JYIQQ4BZNnVzchP3eVjrxuA5IoekzXWffFE/40pc7LXgnzgvVhTXbGXEXmhsbfD2oo3+0 zVqEdO+SmEnk36rGQdRkaAweXUrT+ufbiEjHFx4VvXC7oXpZIFuULkUl1Tkh9sf+Jl1zb4LE0hW QeD+O6P0lMU/5D9M1ITn5s2I0c+BX6bO1VJDc+IFESfy2thAMrCzPO+QNwimhHY6HdnI16wKi7k YFBWCirGxZtX5kqqIlUgglyly+Z/aB+SLaRYR831EPLKNvhQlxYM1XW2yY+Hub4WGYCFE3QDt/z XLS7skJTuON7Xgbh4OM+nR23vTrTwuHjExKsB99DTDyS2H05ieTVTwsY19csMK/ae2tDlm7hiMd 8VOd0wJ X-Received: by 2002:a05:600c:45d5:b0:490:9782:3eb8 with SMTP id 5b1f17b1804b1-4954a40843dmr164165015e9.25.1784568216122; Mon, 20 Jul 2026 10:23:36 -0700 (PDT) Received: from localhost.localdomain (2a02-8440-b501-5b7b-2580-caa3-ecc1-dea5.rev.sfr.net. [2a02:8440:b501:5b7b:2580:caa3:ecc1:dea5]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-49563eee22esm36508575e9.1.2026.07.20.10.23.35 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 20 Jul 2026 10:23:35 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][scarthgap 13/33] dropbear: Disable DSS correctly Date: Mon, 20 Jul 2026 19:22:46 +0200 Message-ID: <56f5e0e276a5f39e5ae7fb9e61a4ef64aa51bd7e.1784567958.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Mon, 20 Jul 2026 17:23:47 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/241447 From: Mike Crowe Take upstream patch that stops sysoptions.h unconditionally turning DROPBEAR_DSS back on even when it has been disabled (which is the default). Signed-off-by: Mike Crowe Signed-off-by: Yoann Congal --- ...PBEAR_DSS-is-only-forced-for-fuzzing.patch | 30 +++++++++++++++++++ .../recipes-core/dropbear/dropbear_2022.83.bb | 1 + 2 files changed, 31 insertions(+) create mode 100644 meta/recipes-core/dropbear/dropbear/0001-Fix-so-DROPBEAR_DSS-is-only-forced-for-fuzzing.patch diff --git a/meta/recipes-core/dropbear/dropbear/0001-Fix-so-DROPBEAR_DSS-is-only-forced-for-fuzzing.patch b/meta/recipes-core/dropbear/dropbear/0001-Fix-so-DROPBEAR_DSS-is-only-forced-for-fuzzing.patch new file mode 100644 index 00000000000..250cbb7a6f0 --- /dev/null +++ b/meta/recipes-core/dropbear/dropbear/0001-Fix-so-DROPBEAR_DSS-is-only-forced-for-fuzzing.patch @@ -0,0 +1,30 @@ +From c7dfaebd5f6a4cde4198f4d2a7baabaa1f632274 Mon Sep 17 00:00:00 2001 +From: Matt Johnston +Date: Tue, 6 Dec 2022 22:34:11 +0800 +Subject: [PATCH] Fix so DROPBEAR_DSS is only forced for fuzzing + +Regression from 787391ea3b5af2acf5e3c83372510f0c79477ad7, +was missing fuzzing conditional + +Upstream-Status: Backport [https://github.com/mkj/dropbear/commit/c043efb47c3173072fa636ca0da0d19875d4511f] +Signed-off-by: Mike Crowe +--- + sysoptions.h | 2 ++ + 1 file changed, 2 insertions(+) + +diff --git a/sysoptions.h b/sysoptions.h +index fb6adc7..12db59c 100644 +--- a/sysoptions.h ++++ b/sysoptions.h +@@ -383,9 +383,11 @@ + #endif + + /* Fuzzing expects all key types to be enabled */ ++#if DROPBEAR_FUZZ + #if defined(DROPBEAR_DSS) + #undef DROPBEAR_DSS + #endif + #define DROPBEAR_DSS 1 ++#endif + + /* no include guard for this file */ diff --git a/meta/recipes-core/dropbear/dropbear_2022.83.bb b/meta/recipes-core/dropbear/dropbear_2022.83.bb index 93563aa3b47..d203fee34b3 100644 --- a/meta/recipes-core/dropbear/dropbear_2022.83.bb +++ b/meta/recipes-core/dropbear/dropbear_2022.83.bb @@ -28,6 +28,7 @@ SRC_URI = "http://matt.ucc.asn.au/dropbear/releases/dropbear-${PV}.tar.bz2 \ file://0001-Handle-arbitrary-length-paths-and-commands-in-multih.patch \ file://0001-cli-runopts.c-add-missing-DROPBEAR_CLI_PUBKEY_AUTH.patch \ file://0001-Avoid-unused-variable-with-DROPBEAR_CLI_PUBKEY_AUTH-.patch \ + file://0001-Fix-so-DROPBEAR_DSS-is-only-forced-for-fuzzing.patch \ file://CVE-2025-47203.patch \ file://CVE-2019-6111.patch \ " From patchwork Mon Jul 20 17:22:47 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 8bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 92919 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id C0C4DC44535 for ; Mon, 20 Jul 2026 17:23:47 +0000 (UTC) Received: from mail-wm1-f53.google.com (mail-wm1-f53.google.com [209.85.128.53]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.2898.1784568218676869037 for ; Mon, 20 Jul 2026 10:23:38 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=jr9Dds7/; spf=pass (domain: smile.fr, ip: 209.85.128.53, mailfrom: yoann.congal@smile.fr) Received: by mail-wm1-f53.google.com with SMTP id 5b1f17b1804b1-4954d383e64so17012325e9.1 for ; Mon, 20 Jul 2026 10:23:38 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1784568217; x=1785173017; darn=lists.openembedded.org; h=content-transfer-encoding:content-type:mime-version:references :in-reply-to:message-id:date:subject:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=YHEtEe7zaHqJApiyagDbgiIgLLHn6uuRrvv2cMYiya0=; b=jr9Dds7/uwmLQGE89vlhMzkauJG7p4j0+XjT7wRJkb/JcQz7cF3G39tOX5oYDDDdNt dm6doKDBpHM7eqeIZYBaX5dsRwZAGm11h80O8qcaxq62zo8Tk+zOfGUEpOuZd8IvPjVh dfcMuqeSSdOZAkLcmbjyEznAXoGCT+6UN2uMY= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1784568217; x=1785173017; h=content-transfer-encoding:content-type:mime-version:references :in-reply-to:message-id:date:subject:to:from:x-gm-gg :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to :content-type; bh=YHEtEe7zaHqJApiyagDbgiIgLLHn6uuRrvv2cMYiya0=; b=rhjWA1dEjWeP5TLAfNPJqwJyk33gBUJ7CRo8tVcr0lO5DqxXQai4Ff/Oxryd8OZhFw CS6/vKK1bWox5r5Lgd5F2jP3WcmTRGTDoEHwmruICIfl0qz8imhsws4/7JZFdyQOIPe9 tUQAq/VC0lHs72PqxX2Atx+rk8sVJu5cTMSRA/CUqb45nn3tPwRHqBeouSTppy6TheI/ gQPlGnyvfBScp5vBzw/WFfGEpzIVdf2l5fPBQPY43OEnlL6YoiGoYkCWHa8fLS4ISf3X zVjW9ctUQjRPD6YBwwxFp7kVM9qkfhZnZFY33um2tySlm0gzEDpGTPNqxE2dP+/8vxwS H9EA== X-Gm-Message-State: AOJu0YyFCleDBcyeS/IdyFchoDcOXfqbDifraDIdCOvOcC0aJJcUZW49 nLDxSSJ9aRQaGdm8hVtHYt438mIzYAGIi6ZzV8MH8NI/gnFz1In227BFHQqsCh17r7r1awaZ0vU Z/B6cdfw= X-Gm-Gg: AfdE7cmO1YftsLNxUGwCGDvw+gTMwLFue0qzLrREufXA8Z0BI0Eek/cG15pvT+Y+szj sZqjYy4JaH+CJVUlQkjAewc4RS8DVwvMCr5rx6DX+noqoQQtI+CLT50DXJJOnBfnVy6VRdGcNKp m/7D7tSPT1a3pt7pL1wvBbGGoERdhuq5bdK2LhfiCJIXZNqNeHfjd6JMGTquA7YK1JgpQwZUNcz +Py8BGiuBE4Y7vaf0N/jgLRpAESFIsguEi23d3PahjYdFKIiqkdr2ZNPapOhkoOiN2dth14jXsE NRuyBv+lWqu/fGIYtdKV1q6z0x9LslUzp4xFKZMOYcddJ1G6IkQFRclNoMYRNWVAL7dv9ko63Ru RzmhyktAcf0oyYEkBYWWnCdB9nA+5/gKUBwsnrKta4YErya+zgccbcJo5K+UW8M9aUUjpGrODO7 IKCZ2oMI5q8UHjEjafh5ccNad4bRSv5szqwkONFRVT5O0GmqhdD/Yaois71AiidkSNdxpK3T1un 1rCI1OC X-Received: by 2002:a05:600c:1c0b:b0:495:46dd:e238 with SMTP id 5b1f17b1804b1-4954a50ea30mr192977535e9.30.1784568216822; Mon, 20 Jul 2026 10:23:36 -0700 (PDT) Received: from localhost.localdomain (2a02-8440-b501-5b7b-2580-caa3-ecc1-dea5.rev.sfr.net. [2a02:8440:b501:5b7b:2580:caa3:ecc1:dea5]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-49563eee22esm36508575e9.1.2026.07.20.10.23.36 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 20 Jul 2026 10:23:36 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][scarthgap 14/33] socat: patch CVE-2026-56123 Date: Mon, 20 Jul 2026 19:22:47 +0200 Message-ID: <9d8f5eb7c10c17865b46ccaac03a71054c161219.1784567958.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Mon, 20 Jul 2026 17:23:47 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/241448 From: Peter Marko Pick the only commit in release 1.8.1.2. This release has a note for this CVE which was added by this commit. Drop change in VERSION file (as we're not upgrading). Resolve minor conflicts in CHANGES and test.sh. Since we're not running tests, it's not worth to pick next commit from 1.8.1.3 which is fixing test on non-bash shell systems. Signed-off-by: Peter Marko [YC: project git repo seem down. A mirror is here: https://third-party-mirror.googlesource.com/socat/+/d44cd1cc4fbb70a9ae9e71890024ae8367fcb912%5E%21/ ] Signed-off-by: Yoann Congal --- .../socat/files/CVE-2026-56123.patch | 150 ++++++++++++++++++ .../socat/socat_1.8.0.0.bb | 1 + 2 files changed, 151 insertions(+) create mode 100644 meta/recipes-connectivity/socat/files/CVE-2026-56123.patch diff --git a/meta/recipes-connectivity/socat/files/CVE-2026-56123.patch b/meta/recipes-connectivity/socat/files/CVE-2026-56123.patch new file mode 100644 index 00000000000..e2552a74451 --- /dev/null +++ b/meta/recipes-connectivity/socat/files/CVE-2026-56123.patch @@ -0,0 +1,150 @@ +From d44cd1cc4fbb70a9ae9e71890024ae8367fcb912 Mon Sep 17 00:00:00 2001 +From: Gerhard Rieger +Date: Thu, 25 Jun 2026 14:55:59 +0200 +Subject: [PATCH] Version 1.8.1.2 - fixed SOCKS5 client buffer overflow + (CVE-2026-56123) + +CVE: CVE-2026-56123 +Upstream-Status: Backport [repo.or.cz/socat.git/commitdiff/d44cd1cc4fbb70a9ae9e71890024ae8367fcb912] +Signed-off-by: Peter Marko +--- + CHANGES | 13 ++++++++++ + test.sh | 73 ++++++++++++++++++++++++++++++++++++++++++++++++++++ + xio-socks5.h | 4 +-- + 3 files changed, 88 insertions(+), 2 deletions(-) + +diff --git a/CHANGES b/CHANGES +index ba82024..3c2f230 100644 +--- a/CHANGES ++++ b/CHANGES +@@ -1,4 +1,17 @@ +  ++Security: ++ Socat security advisory 10 ++ CVE-2026-56123 ++ There was a possible heap overflow in the socks5 client code. It could ++ be triggered by connecting to a malicious socks5 server that expected ++ this connection and had knowledge about details of the client binary ++ code. ++ Only builds with C signed char (vs.unsigned char) are affected. ++ Thanks to Tristan Madani for finding and reporting this issue, and for ++ conveying the process. ++ Test: SOCKS5_OVERFL ++ ++ + ####################### V 1.8.0.0 + + Security: +diff --git a/test.sh b/test.sh +index 53bbb2a..467ac57 100755 +--- a/test.sh ++++ b/test.sh +@@ -601,6 +601,9 @@ rm -rf "$TD" || (echo "cannot rm $TD" >&2; exit 1) + mkdir -p "$TD" + #trap "rm -r $TD" 0 3 + ++BINDIR=$td/bin ++mkdir -p $BINDIR ++ + echo "Using temp directory $TD" + + case "$TESTS" in +@@ -19217,6 +19220,76 @@ fi # NUMCOND + esac + N=$((N+1)) + ++# Above tests introduced with 1.8.1.0 (none with 1.8.1.1) ++#============================================================================== ++# Below tests introduced with 1.8.1.2 ++ ++ ++# Test socks5 client buffer overflow (CVE-2026-56123) ++NAME=SOCKS5_OVERFL ++case "$TESTS" in ++*%$N%*|*%functions%*|*%bugs%*|*%security%*|*%socks5%*|*%socks%*|*%%*|*%%*|*%socket%*|*%$NAME%*) ++#*%internet%*|*%root%*|*%listen%*|*%fork%*|*%ip4%*|*%tcp4%*|*%bug%*|... ++TEST="$NAME: socks5 client buffer overflow" ++# Start a listener that emulates a malicious socks5 server, using a temporary ++# shell script; ++# connect using Socat with socks5 client; ++# when is terminates with rc=0 the test succeeded (not vulnerable) ++if ! eval $NUMCOND; then : ++# Check if this test can be performed meaningfully ++elif ! cond=$(checkconds \ ++ "" \ ++ "" \ ++ "" \ ++ "IP4 TCP LISTEN SHELL GOPEN SOCKS5" \ ++ "TCP4-LISTEN SHELL GOPEN SOCKS5" \ ++ "socksport" \ ++ "tcp4" ); then ++ $PRINTF "test $F_n $TEST... ${YELLOW}$cond${NORMAL}\n" $N ++ cant ++else ++ mkdir -p "$BINDIR" ++ tf="$td/test$N.stdout" ++ te="$td/test$N.stderr" ++ tdiff="$td/test$N.diff" ++ tsh="$BINDIR/test$N.sh" ++ cat >"$tsh" <<__EOF__ ++$ECHO -n "\\x05\\x00" ++relsleep 1 ++$ECHO -n "\\x05\\x00\\x00\\x03\\xfdAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA" ++__EOF__ ++ chmod a+x "$tsh" ++ newport tcp4 # -> PORT ++ CMD0="$TRACE $SOCAT $opts TCP4-LISTEN:$PORT SHELL:$tsh" ++ CMD1="$TRACE $SOCAT $opts /dev/null SOCKS5:$LOCALHOST4:17.34.51.68:85,socksport=$PORT" ++ printf "test $F_n $TEST... " $N ++ $CMD0 >/dev/null 2>"${te}0" & ++ pid0=$! ++ waittcp4port $PORT 1 ++ $CMD1 >"${tf}1" 2>"${te}1" ++ rc1=$? ++ kill $pid0 2>/dev/null; wait ++ if [ "$rc1" -ne 0 ]; then ++ $PRINTF "$FAILED (rc1=$rc1)\n" ++ echo "$CMD0 &" ++ cat "${te}0" >&2 ++ echo "$CMD1" ++ cat "${te}1" >&2 ++ failed ++ else ++ $PRINTF "$OK\n" ++ if [ "$VERBOSE" ]; then echo "$CMD0 &"; fi ++ if [ "$DEBUG" ]; then cat "${te}0" >&2; fi ++ if [ "$VERBOSE" ]; then echo "$CMD1"; fi ++ if [ "$DEBUG" ]; then cat "${te}1" >&2; fi ++ ok ++ fi ++fi # NUMCOND ++ ;; ++esac ++N=$((N+1)) ++ ++ + # end of common tests + + ################################################################################## +diff --git a/xio-socks5.h b/xio-socks5.h +index 4dab76b..d4712d2 100644 +--- a/xio-socks5.h ++++ b/xio-socks5.h +@@ -23,7 +23,7 @@ struct socks5_request { + uint8_t command; + uint8_t reserved; + uint8_t address_type; +- char dstdata[]; ++ unsigned char dstdata[]; + }; + + struct socks5_reply { +@@ -31,7 +31,7 @@ struct socks5_reply { + uint8_t reply; + uint8_t reserved; + uint8_t address_type; +- char dstdata[]; ++ unsigned char dstdata[]; + }; + + extern const struct addrdesc xioaddr_socks5_connect; diff --git a/meta/recipes-connectivity/socat/socat_1.8.0.0.bb b/meta/recipes-connectivity/socat/socat_1.8.0.0.bb index bb39730005a..156fd590aee 100644 --- a/meta/recipes-connectivity/socat/socat_1.8.0.0.bb +++ b/meta/recipes-connectivity/socat/socat_1.8.0.0.bb @@ -12,6 +12,7 @@ LIC_FILES_CHKSUM = "file://COPYING;md5=b234ee4d69f5fce4486a80fdaf4a4263 \ SRC_URI = "http://www.dest-unreach.org/socat/download/socat-${PV}.tar.bz2 \ file://0001-fix-compile-procan.c-failed.patch \ file://CVE-2024-54661.patch \ + file://CVE-2026-56123.patch \ " SRC_URI[sha256sum] = "e1de683dd22ee0e3a6c6bbff269abe18ab0c9d7eb650204f125155b9005faca7" From patchwork Mon Jul 20 17:22:48 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 92915 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id B2F16C44533 for ; Mon, 20 Jul 2026 17:23:47 +0000 (UTC) Received: from mail-wm1-f53.google.com (mail-wm1-f53.google.com [209.85.128.53]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.2870.1784568219126788617 for ; Mon, 20 Jul 2026 10:23:39 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=LnDnzUPP; spf=pass (domain: smile.fr, ip: 209.85.128.53, mailfrom: yoann.congal@smile.fr) Received: by mail-wm1-f53.google.com with SMTP id 5b1f17b1804b1-493f6de72faso28434545e9.0 for ; Mon, 20 Jul 2026 10:23:38 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1784568217; x=1785173017; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=BIlr+IYMMMmiNQ7BvA8ua5eFwJmEM+wH7ghMyOFCurs=; b=LnDnzUPPI8w0WLXPQr/A9MG5eBbwDdzxt8Lxky9hbKbNMhnPaNUYTDNoto0Wgtoju6 T7Pvj5ZzFxp/4122fidRcBOWbwhdtGemrO4n2P1g6MH3q0pX0VeDIps0fkbKpQJ5n7KN x/r+aOfTqptGrAEx4fZH2ORz2d0GzefNnK/AU= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1784568217; x=1785173017; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=BIlr+IYMMMmiNQ7BvA8ua5eFwJmEM+wH7ghMyOFCurs=; b=Ef/wpFnVDw78alREFenu56p3w/ki+mtToqv1lxrbekbj5QRyfk3EgJHbe+jSwPA05I ElDvH7fwxSy6Hg+gUUEKcPPjNSE7vvKxe/TfqMd9GFQ94Rh+WUA/MswdV4E+xZJU4QWs w5lqsrluZlOsZSyY9QqR1MgopbRALibSQS4/vH/r3WYoeQtNu3vjPlQEWgBft+QnAjI/ iD5iQtq8FM2Vq9PhhKW7h5JGskP/xdnDpD2M3shgCg7nnUCVsphQF32CgBxDPWOfGEgt v4rZwcdjg1vG7lT41fiJ7q/igIsIoKpbkKwyB+ZQvtZFksv9FkhPSU9k2wAXQpQrgaXT T2oA== X-Gm-Message-State: AOJu0Yxzep55swGyV8txK17Z+4oIs4FMGfuas4KuR0cPtRzYYIWBlWdb u1uWut1juPsHxaAuLG24K5MTSC2LOLRC/0iYOWaofgCc1XFnmRf1vRtl+jAev2P2Ke0H1QA9Y7c V8JqI5qE= X-Gm-Gg: AfdE7cn2r8CWk0vJ1zp7YbmU7R6kZxXhcVsaosYduuQVAvHWLiLz+9e6s3qx/wrkq/T /BGjGnk4GfzsRHkJGgmbLyIj9U6Zvma+8qoqL1GGmr95ZuR8/1C+pYgV3jDIVozXZU5VFKRO4VW J5VP6vhlxJ92OnnYFTtbi2i2Q0A1MVPuqnZ/rMYUgsr0ab9xUw4J3RaXLuJduYwwOuTtZd6QsU3 Fmm2b8G63zntPVAw+iIMN7CKkX+Y263WRMqSnfBs0KEDJqG9d832P0CuVPXwsSsJzgHagrvQLe7 xMB1gpvcjToDpiJejKBXeaF6EpX8yu8cG5ZfhNErAnyHVDCDmsB4lNv/Vi6LjAUj3nG6DFsSq9I 2fyoWCjtKET70DlMOauNeLvIGyqeBOPY47c65lG1+WFZ0kC6qWr7UEDy+2NggBVr305XVMJtkEj ahGKPlpB6erC1KCHMVb3DVmUvrnTe/MhdI1uM7d+YnMoKL9JqXRKbK4s27AONNeGg9mvUi9KJTK NuPk2Au X-Received: by 2002:a05:600c:3b88:b0:495:495f:bc30 with SMTP id 5b1f17b1804b1-4954a3391femr167251765e9.12.1784568217437; Mon, 20 Jul 2026 10:23:37 -0700 (PDT) Received: from localhost.localdomain (2a02-8440-b501-5b7b-2580-caa3-ecc1-dea5.rev.sfr.net. [2a02:8440:b501:5b7b:2580:caa3:ecc1:dea5]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-49563eee22esm36508575e9.1.2026.07.20.10.23.36 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 20 Jul 2026 10:23:37 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][scarthgap 15/33] vex: remove obsolete semicolon Date: Mon, 20 Jul 2026 19:22:48 +0200 Message-ID: X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Mon, 20 Jul 2026 17:23:47 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/241449 From: Peter Marko Usage of semicolon as separator in ROOTFS/IMAGE_*COMMAND was deprecated long time ago. Remove it. Signed-off-by: Peter Marko Signed-off-by: Mathieu Dubois-Briand Signed-off-by: Richard Purdie (From OE-Core rev: 311d418d22a609fb54b87bfc909bdd1861892228) Signed-off-by: Peter Marko Signed-off-by: Yoann Congal --- meta/classes/vex.bbclass | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/meta/classes/vex.bbclass b/meta/classes/vex.bbclass index 45a15348724..eac68ca6289 100644 --- a/meta/classes/vex.bbclass +++ b/meta/classes/vex.bbclass @@ -229,7 +229,7 @@ python vex_write_rootfs_manifest () { bb.plain("Image VEX JSON report stored in: %s" % manifest_name) } -ROOTFS_POSTPROCESS_COMMAND:prepend = "vex_write_rootfs_manifest; " +ROOTFS_POSTPROCESS_COMMAND:prepend = "vex_write_rootfs_manifest " do_rootfs[recrdeptask] += "do_generate_vex " do_populate_sdk[recrdeptask] += "do_generate_vex " From patchwork Mon Jul 20 17:22:49 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 92917 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 92724C4452E for ; Mon, 20 Jul 2026 17:23:47 +0000 (UTC) Received: from mail-wm1-f47.google.com (mail-wm1-f47.google.com [209.85.128.47]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.2873.1784568220517457057 for ; Mon, 20 Jul 2026 10:23:40 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=GrRzazM0; spf=pass (domain: smile.fr, ip: 209.85.128.47, mailfrom: yoann.congal@smile.fr) Received: by mail-wm1-f47.google.com with SMTP id 5b1f17b1804b1-49548aebcd8so21268755e9.3 for ; Mon, 20 Jul 2026 10:23:40 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1784568219; x=1785173019; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=9o08X+G13e3CPQ3dhVCRbaI29HN8mR7+803YGLWAKHU=; b=GrRzazM0wKRV/en0i3xy+q+hBrFfKRt3fT3OOyneL795SPbwYxHPdPZq+ICqzvFW0h AaSKx5o3wULy8EOd5XOXL5n4P97RI3AeOIDkMsDk8QHlPE3XMMrKV/lOPkw6q/qofoXK pyBc3aCQjFwkfWkaRY5dN5aI5FtNtonZ8m8uc= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1784568219; x=1785173019; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=9o08X+G13e3CPQ3dhVCRbaI29HN8mR7+803YGLWAKHU=; b=c99MbwCf2kEKuPjdJq5ZhDltPta5kqpm+GGl0TxtXfrQIQ0ldWyoSYl66leiotRSlM YkSacZ+R3EKrYA+E7OOoIMQIjP0RfmhDCK7J+ySmvWUupkeJRTAFot/fTPJP7jzt2YDt o0DoDkVVFxNTulge8Y9nWIunhBFClV3Xo/ikJ4vDfPJzY2lhNSenJW+KvIJIgN6qLqPF FtE9XoHhbVdnyiCJ7OO04dz5+/0/I0/cRzcqTO89aBJR0GZowfrl0L+bwodp2EY/debD JUjp0F3Vf2RTu6P+7B4QMjthDK178R3ds5RZG1Hrgf0k7Cpq3g9j2R/U2BDNI8JktkPJ WxWw== X-Gm-Message-State: AOJu0YzKDlLaVRceTyEQwuYn6fdhubQDzRcCUGKXoXhzWFZvP3HTn3RQ AnhwkP/zJ4fDuF5xamTPp7zzxA+yRK/Y/PFowDF8gM8DYJdUsmR8zIVOlVvEYOT58UyawmPMmDD 3430yECo= X-Gm-Gg: AfdE7cmgB3HwSeVzKfquFrNxO4KC4KuVIo7D9yWmXZh5Wv/DzEJ1qtIzerV2raWj6e+ BNd8hqsysasOpoWW2cHVzOjJKZnwGF1/naUUYKZF9vAN1BlVIdZRl7awZRDYUFoK1FQCemhtKFs XzCm4niI23A4Dt7QiitH7QMztL+19vdK+2a9pglGMtGbcU7tXY8ItkR0N7wPyJNTt2KMlVZIo9c K38zKuu+DdobivX719dainBGlKrBgeHHzBM8VbIEG7y42goz4zQJP0kHRMrcCh84ojOyC9bKxnH u3pr+KA8MAmEomA6OnrJE0hRsGd3x844c3OJZQIQr8XbAb/8sS70R37rY8fInnCnG5FJEshoAK+ jzp8s/uDZvfSBvWaZWZJIUoItAUJJ1nIKGnjbi/4lBJtWaKExb3Bj+qHtDk05cC6NWrIoQFDtcV wiL0eJ+c+C4a/+7iyVaziVAaNUopXQ0RKNWVNSgSyW2hYxGi9TjGQvtFMYTKbcFAFj7Twm+qTmN vwKGT/p X-Received: by 2002:a05:600c:a010:b0:495:5365:c0d9 with SMTP id 5b1f17b1804b1-4955365c1e7mr114382795e9.16.1784568218534; Mon, 20 Jul 2026 10:23:38 -0700 (PDT) Received: from localhost.localdomain (2a02-8440-b501-5b7b-2580-caa3-ecc1-dea5.rev.sfr.net. [2a02:8440:b501:5b7b:2580:caa3:ecc1:dea5]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-49563eee22esm36508575e9.1.2026.07.20.10.23.37 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 20 Jul 2026 10:23:38 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][scarthgap 16/33] rootfs: move tasks using image_list_installed_packages to postuninstall Date: Mon, 20 Jul 2026 19:22:49 +0200 Message-ID: <907a507bd0b1874b03222dd3ef1d98b30e088c34.1784567958.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Mon, 20 Jul 2026 17:23:47 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/241450 From: Peter Marko Since some packages can be uninstalled, any task querying installed packages should be run only after both installation and uninstallation is completed. Signed-off-by: Peter Marko Signed-off-by: Mathieu Dubois-Briand Signed-off-by: Richard Purdie (From OE-Core rev: c3097962ac925538e99b17b771c541950a8b8c26) Signed-off-by: Peter Marko Signed-off-by: Yoann Congal --- meta/classes-recipe/license_image.bbclass | 2 +- meta/classes/vex.bbclass | 2 +- 2 files changed, 2 insertions(+), 2 deletions(-) diff --git a/meta/classes-recipe/license_image.bbclass b/meta/classes-recipe/license_image.bbclass index b18a64d2bc3..e934c74d246 100644 --- a/meta/classes-recipe/license_image.bbclass +++ b/meta/classes-recipe/license_image.bbclass @@ -294,7 +294,7 @@ def get_deployed_files(man_file): dep_files.append(os.path.basename(f)) return dep_files -ROOTFS_POSTPROCESS_COMMAND:prepend = "write_package_manifest license_create_manifest " +ROOTFS_POSTUNINSTALL_COMMAND:prepend = "write_package_manifest license_create_manifest " do_rootfs[recrdeptask] += "do_populate_lic" python do_populate_lic_deploy() { diff --git a/meta/classes/vex.bbclass b/meta/classes/vex.bbclass index eac68ca6289..97213ea3497 100644 --- a/meta/classes/vex.bbclass +++ b/meta/classes/vex.bbclass @@ -229,7 +229,7 @@ python vex_write_rootfs_manifest () { bb.plain("Image VEX JSON report stored in: %s" % manifest_name) } -ROOTFS_POSTPROCESS_COMMAND:prepend = "vex_write_rootfs_manifest " +ROOTFS_POSTUNINSTALL_COMMAND:prepend = "vex_write_rootfs_manifest " do_rootfs[recrdeptask] += "do_generate_vex " do_populate_sdk[recrdeptask] += "do_generate_vex " From patchwork Mon Jul 20 17:22:50 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 8bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 92918 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 85DEEC44531 for ; Mon, 20 Jul 2026 17:23:47 +0000 (UTC) Received: from mail-wm1-f50.google.com (mail-wm1-f50.google.com [209.85.128.50]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.2875.1784568221500271973 for ; Mon, 20 Jul 2026 10:23:41 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=q47JMAB4; spf=pass (domain: smile.fr, ip: 209.85.128.50, mailfrom: yoann.congal@smile.fr) Received: by mail-wm1-f50.google.com with SMTP id 5b1f17b1804b1-49546c690ffso27067665e9.2 for ; Mon, 20 Jul 2026 10:23:41 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1784568220; x=1785173020; darn=lists.openembedded.org; h=content-transfer-encoding:content-type:mime-version:references :in-reply-to:message-id:date:subject:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=RkdYb1/khWfzkjOO8XfN9zeN59KzoW2uCXEI8TB1WkM=; b=q47JMAB4Hk5BBtSHwYgtXpAOzwM4RZvQWoM1k08srtnYqJnRq70hl3RahifAt6Jqsq 9cA7GbZdD+EE8KI6Ds10c9R1Bgcz8IHtYLo6v60Jh+dmw594thSBs33p9VczQBHp3GcV nuPq3+BoqC/XPqRWI2Fz3gj5CP4KcL9W6R+mM= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1784568220; x=1785173020; h=content-transfer-encoding:content-type:mime-version:references :in-reply-to:message-id:date:subject:to:from:x-gm-gg :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to :content-type; bh=RkdYb1/khWfzkjOO8XfN9zeN59KzoW2uCXEI8TB1WkM=; b=rh7tfjFD9fVU9UAlpypjLvW/kcyS1I7OapR/7VXzADOB1oZnzm2Rr2zhcttpYslJdK tuCMvLZ88rI8NgsC4vKM69KZgwzVAZRAPFvw7ZBVYyNb6xwOvEXQ7zTHXavGHT4i96Jz t1x9vzO+0grtTBuSl1YHzujY6nLdIxrOWaHwtGO86ZB25RqORq3b1N80Uk8yx2owiXbb DWeDuTiIKtOK8fwxBDndaikUb8pej7uXVfYWCQP+jeaWi0opNlET1jjQjJnOg9KTIaGm UZciq94knJAKPZPVRet+b3jVM002KIc0Ot2/VchhidmouHUGAlcC5HqV7p/LPLiVfhUi 7U2w== X-Gm-Message-State: AOJu0YzEMkLweN0BQnOv+Nn3kFTCiYqJZYbI2wppTN9FtDv7+KLGO4x1 G6OzriD96ed1ZCzww/ClO6wDhgsLjdn1cPFZE7ZmLQJAvbX2jNFuvGaix2O4gngKlo8FBbB9yAg BjWyv7IA= X-Gm-Gg: AfdE7cn2XkW/pHFomzKTSMsAXFhFtgn2wdcPFqYYijWzAFwZNDjvdRgbn2QRoMJ1ppw uchBLGwYAaw/RdjKYpVBaRKphyD4AIPUkiwIQjf1gqzzD9G8iFxUdSEaKNQM7y/T3Glef7hhglo P901LHUPh/Z6CNlLNg+8q9qH2WsruasdjOPB8WSlTMhdXd9+6zP1zHy0tzZbUtJqtVigvkNK3og mln4U6J46rD9TSr19U4jojhBHtM1L4QNN9KXfASAEuU2oEZebEYoyROQK3dLZfFFMaXQWeyWT94 y2nLdUU7akAN+cAZXIqih65/kKH2DExakulVa9rrqzWUXMey8Zwou6OB+cjNEd03Wa7aJkQYb0I WcOjcNVPGSKXNAMVmOCP+/XmvPBPtKdbK09aoEOvQkTbW/MokvteYysjGf2WCgA5jwT1OZOvXbE rzhJ2EN1gEXcrpz24bA7PteHZUUi6ScbO2rZNU2vethg9gcggHidqSL+C9oh4lZlPB9SHWA82dW 7dafLAY3Wk6qAvtnN8= X-Received: by 2002:a05:600c:3b20:b0:495:4f62:c9f5 with SMTP id 5b1f17b1804b1-4954f62ca61mr136230035e9.24.1784568219599; Mon, 20 Jul 2026 10:23:39 -0700 (PDT) Received: from localhost.localdomain (2a02-8440-b501-5b7b-2580-caa3-ecc1-dea5.rev.sfr.net. [2a02:8440:b501:5b7b:2580:caa3:ecc1:dea5]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-49563eee22esm36508575e9.1.2026.07.20.10.23.38 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 20 Jul 2026 10:23:39 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][scarthgap 17/33] gzip: fix CVE-2026-41992 Date: Mon, 20 Jul 2026 19:22:50 +0200 Message-ID: X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Mon, 20 Jul 2026 17:23:47 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/241451 From: Jaipaul Cheernam Backport upstream fix for a global buffer overflow in the LZH decompression logic (unlzh.c). The left[] and right[] global arrays shared across LZW and LZH decompression routines are not reinitialized between files processed in the same invocation, allowing an out-of-bounds read in the LZH decoder. Adapted for gzip 1.13: - Refreshed NEWS and THANKS hunks to match 1.13 release context. Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-41992 Signed-off-by: Jaipaul Cheernam Signed-off-by: Mathieu Dubois-Briand Signed-off-by: Richard Purdie (cherry picked from commit deaaaacabbf8d21fb9271e3f6f83055893510cff) Signed-off-by: Yoann Congal --- .../gzip/gzip-1.13/CVE-2026-41992.patch | 64 +++++++++++++++++++ meta/recipes-extended/gzip/gzip_1.13.bb | 1 + 2 files changed, 65 insertions(+) create mode 100644 meta/recipes-extended/gzip/gzip-1.13/CVE-2026-41992.patch diff --git a/meta/recipes-extended/gzip/gzip-1.13/CVE-2026-41992.patch b/meta/recipes-extended/gzip/gzip-1.13/CVE-2026-41992.patch new file mode 100644 index 00000000000..4db9a1c1afd --- /dev/null +++ b/meta/recipes-extended/gzip/gzip-1.13/CVE-2026-41992.patch @@ -0,0 +1,64 @@ +From 63dbf6b3b9e6e781df1a6a64e609b10e23969681 Mon Sep 17 00:00:00 2001 +From: Paul Eggert +Date: Wed, 15 Apr 2026 12:00:17 -0700 +Subject: =?UTF-8?q?gzip:=20don=E2=80=99t=20mishandle=20.lzh=20after=20.Z?= +MIME-Version: 1.0 +Content-Type: text/plain; charset=UTF-8 +Content-Transfer-Encoding: 8bit + +Problem reported by Michał Majchrowicz. +* unlzh.c (read_c_len): Clear left and right when n == 0. + +CVE: CVE-2026-41992 +Upstream-Status: Backport [https://cgit.git.savannah.gnu.org/cgit/gzip.git/commit/?id=63dbf6b3b9e6e781df1a6a64e609b10e23969681] +Signed-off-by: Jaipaul Cheernam +--- + NEWS | 4 ++++ + THANKS | 1 + + unlzh.c | 6 ++++++ + 3 files changed, 11 insertions(+) + +diff --git a/NEWS b/NEWS +index bdb7cc0..af2a08f 100644 +--- a/NEWS ++++ b/NEWS +@@ -14,6 +14,10 @@ GNU gzip NEWS -*- outline -*- + + ** Bug fixes + ++ A buffer overflow has been fixed when decompressing an .lzh file ++ after decompressing a .Z file. ++ [bug present since the beginning] ++ + 'gzip -d' no longer fails to report invalid compressed data + that uses a dictionary distance outside the input window. + [bug present since the beginning] +diff --git a/THANKS b/THANKS +index 4e545d9..a7d25e4 100644 +--- a/THANKS ++++ b/THANKS +@@ -186,6 +186,7 @@ Jamie Lokier u90jl@ecs.oxford.ac.uk + Richard Lloyd R.K.Lloyd@csc.liv.ac.uk + David J. MacKenzie djm@eng.umd.edu + John R MacMillan john@chance.gts.org ++Michał Majchrowicz mmajchrowicz@afine.com + Ron Male male@eso.mc.xerox.com + Jakub Martisko jamartis@redhat.com + Don R. Maszle maze@bea.lbl.gov +diff --git a/unlzh.c b/unlzh.c +index 3320196..a6cf109 100644 +--- a/unlzh.c ++++ b/unlzh.c +@@ -232,6 +232,12 @@ read_c_len () + c = getbits(CBIT); + for (i = 0; i < NC; i++) c_len[i] = 0; + for (i = 0; i < 4096; i++) c_table[i] = c; ++ ++ /* Needed in case LEFT and RIGHT are reused from a previous ++ LZW decompression. It may be overkill to clear all of both ++ arrays, but nobody has had time to analyze this carefully. */ ++ memzero(left, (2 * NC - 1) * sizeof *left); ++ memzero(right, (2 * NC - 1) * sizeof *left); + } else { + i = 0; + while (i < n) { diff --git a/meta/recipes-extended/gzip/gzip_1.13.bb b/meta/recipes-extended/gzip/gzip_1.13.bb index fd846b30a55..208220867a6 100644 --- a/meta/recipes-extended/gzip/gzip_1.13.bb +++ b/meta/recipes-extended/gzip/gzip_1.13.bb @@ -6,6 +6,7 @@ LICENSE = "GPL-3.0-or-later" SRC_URI = "${GNU_MIRROR}/gzip/${BP}.tar.gz \ file://run-ptest \ + file://CVE-2026-41992.patch \ " SRC_URI:append:class-target = " file://wrong-path-fix.patch" From patchwork Mon Jul 20 17:22:51 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 92912 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 791E9C44532 for ; Mon, 20 Jul 2026 17:23:47 +0000 (UTC) Received: from mail-wm1-f48.google.com (mail-wm1-f48.google.com [209.85.128.48]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.2876.1784568222621758237 for ; Mon, 20 Jul 2026 10:23:42 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=zkR8u1Di; spf=pass (domain: smile.fr, ip: 209.85.128.48, mailfrom: yoann.congal@smile.fr) Received: by mail-wm1-f48.google.com with SMTP id 5b1f17b1804b1-49556f97a9dso12149555e9.1 for ; Mon, 20 Jul 2026 10:23:42 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1784568221; x=1785173021; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=Ov5TYnmA/HgvEgQIi9ER4efMPmKbLLHsw/ZfVZlTcGE=; b=zkR8u1Dir/M9Lw62ALZ/aaWxvs+WgvImIrdY59+o/m4IzETyjQk317ymckOK4VzvOP zsLLeoqGD7wd8f2OWa0tFNe4Oq9iCDqlk3CzWH/LJNL72xKJOk+UOkjkrMCDBApm9H6Y wH7ekE9zvl7njJuWCNJRCDD3xE179BJzeE2EA= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1784568221; x=1785173021; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=Ov5TYnmA/HgvEgQIi9ER4efMPmKbLLHsw/ZfVZlTcGE=; b=O8lpPsdoBW5R4+tEHKWZAs0o2AW/k6rYRy8/1NPrNRBkd8yWfNO+g2BSl7HL8VTcdb TFAqPa9B1qDQceBN2UUROY/V23rSQPSoufgiyXr6Ytrefx5gMohkU1es1kHBBkB+opwK m/SAdQjmLsutJrU/pTGpY/wCjSPjJeQZSi1gkb+zPjwflWzxMLsdxhvDm016n0OldI02 FXVSOrPNwcCJWstYlq9WoD2wMNyCdIFQRPA47LDor1CX/vrQ7ZMU5wcTMnQ2Eu6vFQfE LrouK/hf/gaPnJvJn4rjWEFxx2Cs2bHG442R7/nScS4rTlxUnSd4gdWf5QUseUetbl2y IvGg== X-Gm-Message-State: AOJu0YyRyjXnA7lKo2GPI4PKY1aEXM9QC78RhudovRqPoCyQEMk7RcXd 2GWDTshNj2NZesGpERTolEgr7HcuJN4FtGPDEaov8WFSgs+L9AfPzIjP31HrgESXZoMEC4W5U5n j3Y8DGQ0= X-Gm-Gg: AfdE7clMB7eUzg9RKErs4gpmZgpveNgW9ovau6O1HQ30ELmYKlpBt7oQlhbNCUBvGBg LFt2UcyhefhVv+S5/rpTS7DelqGniw0ERbItfzMrMKPH/Y+wGG2pOf9bczwADukXz2v6HEvgWHW N37MoCUJ1RNvqp9oNlQG8MvLZ3JANrSXtmjuw+pUHH64kcDCHKcORCGW1YyM+iFIVmdgdhXFAHB 6eSJpCGnIJ8QqHJ4UfPVVxinY6RoA4uITZgBMxkXo4U5qRh7ZHuY2W7riMX+QAnptayKwZR5f3K 6SlUfHKtJ0Q6RDeS65i0UkHN0tvLvm4gU3TkTef7pp4hyM2vWQQ/7JxgFwmKwN98wt7pvKy7nsw xsO84td/CcS4c/TJ8grAz9mYZHrt7a6fOHzEsvNdTMtLgBIwYQkgQeZ/9EcfvHxK6nrCUuRGoj6 zqKu+OtXlOYzyqDio7FQkutPPB6imMUzbp1L0UlXHS+uRXNLyp+AjaBwT+lWP371LIvPcDm6AKs kNwH+I5 X-Received: by 2002:a05:600c:198b:b0:495:5044:d37d with SMTP id 5b1f17b1804b1-4955044d4e8mr120745045e9.19.1784568220804; Mon, 20 Jul 2026 10:23:40 -0700 (PDT) Received: from localhost.localdomain (2a02-8440-b501-5b7b-2580-caa3-ecc1-dea5.rev.sfr.net. [2a02:8440:b501:5b7b:2580:caa3:ecc1:dea5]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-49563eee22esm36508575e9.1.2026.07.20.10.23.39 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 20 Jul 2026 10:23:40 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][scarthgap 18/33] util-linux: fix CVE-2026-13595 Date: Mon, 20 Jul 2026 19:22:51 +0200 Message-ID: <4a4483ac57db5f7af928e588e7318fa183442c0f.1784567958.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Mon, 20 Jul 2026 17:23:47 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/241452 From: Deepak Rathore This patch applies the upstream stable/v2.41 backport for CVE-2026-13595. The upstream fix merge or commit is referenced in [1], and the public CVE advisory is referenced in [2]. The individual backported commit links are recorded in the embedded patch headers when the fix expands to multiple commits. [1] https://github.com/util-linux/util-linux/commit/132d9c8aa15a8efd0a23d8ca7ed8b98f365e84fa [2] https://access.redhat.com/security/cve/CVE-2026-13595 Signed-off-by: Deepak Rathore Signed-off-by: Yoann Congal --- meta/recipes-core/util-linux/util-linux.inc | 1 + .../util-linux/CVE-2026-13595.patch | 157 ++++++++++++++++++ 2 files changed, 158 insertions(+) create mode 100644 meta/recipes-core/util-linux/util-linux/CVE-2026-13595.patch diff --git a/meta/recipes-core/util-linux/util-linux.inc b/meta/recipes-core/util-linux/util-linux.inc index 83804196345..753d032976d 100644 --- a/meta/recipes-core/util-linux/util-linux.inc +++ b/meta/recipes-core/util-linux/util-linux.inc @@ -47,6 +47,7 @@ SRC_URI = "${KERNELORG_MIRROR}/linux/utils/util-linux/v${MAJOR_VERSION}/util-lin file://CVE-2025-14104-01.patch \ file://CVE-2025-14104-02.patch \ file://CVE-2026-27456.patch \ + file://CVE-2026-13595.patch \ " SRC_URI[sha256sum] = "7b6605e48d1a49f43cc4b4cfc59f313d0dd5402fa40b96810bd572e167dfed0f" diff --git a/meta/recipes-core/util-linux/util-linux/CVE-2026-13595.patch b/meta/recipes-core/util-linux/util-linux/CVE-2026-13595.patch new file mode 100644 index 00000000000..36e8658f69b --- /dev/null +++ b/meta/recipes-core/util-linux/util-linux/CVE-2026-13595.patch @@ -0,0 +1,157 @@ +From faf717ca4ed3b603eb213915fe15c6804c4b92d4 Mon Sep 17 00:00:00 2001 +From: Karel Zak +Date: Thu, 7 May 2026 12:50:48 +0200 +Subject: [PATCH] libblkid: fix use-after-free in nested partition probing + +The partitions list stores partitions in a contiguous array grown by +realloc(). When the array is reallocated to a new address, all +existing blkid_partition pointers (tab->parent, ls->next_parent, local +parent variables in nested probers) become dangling. + +Fix this by changing the storage from an array of structs to an array +of pointers, where each partition is individually allocated via +calloc(). This makes all blkid_partition pointers stable across +reallocations -- only the pointer array itself may move, which is +harmless since no code caches pointers into the pointer array. + +This eliminates the need for callers to re-fetch parent pointers after +every blkid_partlist_add_partition() call. + +CVE: CVE-2026-13595 +Upstream-Status: Backport [https://github.com/util-linux/util-linux/commit/132d9c8aa15a8efd0a23d8ca7ed8b98f365e84fa] + +Backport Changes: +- Scarthgap util-linux 2.39.3 still uses realloc() at this allocation site, + so this backport keeps realloc() and changes only the element size to + sizeof(*ls->parts) instead of adopting upstream's reallocarray() style. +- The commit text was adjusted from reallocarray() to realloc() to match the + target source context. + +Reported-by: Thai Duong +Signed-off-by: Karel Zak +(cherry picked from commit c0186f14fbdb02f64c8e0ba701ce727ea764ff4c) +(cherry picked from commit 132d9c8aa15a8efd0a23d8ca7ed8b98f365e84fa) +Signed-off-by: Deepak Rathore +--- + libblkid/src/partitions/partitions.c | 36 ++++++++++++++++++---------- + 1 file changed, 22 insertions(+), 14 deletions(-) + +diff --git a/libblkid/src/partitions/partitions.c b/libblkid/src/partitions/partitions.c +index 8ebf480f5..6089028a8 100644 +--- a/libblkid/src/partitions/partitions.c ++++ b/libblkid/src/partitions/partitions.c +@@ -197,7 +197,7 @@ struct blkid_struct_partlist { + + int nparts; /* number of partitions */ + int nparts_max; /* max.number of partitions */ +- blkid_partition parts; /* array of partitions */ ++ blkid_partition *parts; /* array of pointers to partitions */ + + struct list_head l_tabs; /* list of partition tables */ + }; +@@ -356,13 +356,16 @@ static void reset_partlist(blkid_partlist ls) + free_parttables(ls); + + if (ls->next_partno) { +- /* already initialized - reset */ +- int tmp_nparts = ls->nparts_max; +- blkid_partition tmp_parts = ls->parts; ++ /* already initialized - free individually allocated partitions */ ++ int i, tmp_nparts_max = ls->nparts_max; ++ blkid_partition *tmp_parts = ls->parts; ++ ++ for (i = 0; i < ls->nparts; i++) ++ free(ls->parts[i]); + + memset(ls, 0, sizeof(struct blkid_struct_partlist)); + +- ls->nparts_max = tmp_nparts; ++ ls->nparts_max = tmp_nparts_max; + ls->parts = tmp_parts; + } + +@@ -397,6 +400,7 @@ static void partitions_free_data(blkid_probe pr __attribute__((__unused__)), + void *data) + { + blkid_partlist ls = (blkid_partlist) data; ++ int i; + + if (!ls) + return; +@@ -404,6 +408,8 @@ static void partitions_free_data(blkid_probe pr __attribute__((__unused__)), + free_parttables(ls); + + /* deallocate partitions and partlist */ ++ for (i = 0; i < ls->nparts; i++) ++ free(ls->parts[i]); + free(ls->parts); + free(ls); + } +@@ -436,16 +442,18 @@ static blkid_partition new_partition(blkid_partlist ls, blkid_parttable tab) + /* Linux kernel has DISK_MAX_PARTS=256, but it's too much for + * generic Linux machine -- let start with 32 partitions. + */ +- void *tmp = realloc(ls->parts, (ls->nparts_max + 32) * +- sizeof(struct blkid_struct_partition)); ++ void *tmp = realloc(ls->parts, (ls->nparts_max + 32) * ++ sizeof(*ls->parts)); + if (!tmp) + return NULL; + ls->parts = tmp; + ls->nparts_max += 32; + } + +- par = &ls->parts[ls->nparts++]; +- memset(par, 0, sizeof(struct blkid_struct_partition)); ++ par = calloc(1, sizeof(struct blkid_struct_partition)); ++ if (!par) ++ return NULL; ++ ls->parts[ls->nparts++] = par; + + ref_parttable(tab); + par->tab = tab; +@@ -849,7 +857,7 @@ int blkid_probe_is_covered_by_pt(blkid_probe pr, + + /* check if the partition table fits into the device */ + for (i = 0; i < nparts; i++) { +- blkid_partition par = &ls->parts[i]; ++ blkid_partition par = ls->parts[i]; + + if (par->start + par->size > (pr->size >> 9)) { + DBG(LOWPROBE, ul_debug("partition #%d overflows " +@@ -861,7 +869,7 @@ int blkid_probe_is_covered_by_pt(blkid_probe pr, + + /* check if the requested area is covered by PT */ + for (i = 0; i < nparts; i++) { +- blkid_partition par = &ls->parts[i]; ++ blkid_partition par = ls->parts[i]; + + if (start >= par->start && end <= par->start + par->size) { + rc = 1; +@@ -960,7 +968,7 @@ blkid_partition blkid_partlist_get_partition(blkid_partlist ls, int n) + if (n < 0 || n >= ls->nparts) + return NULL; + +- return &ls->parts[n]; ++ return ls->parts[n]; + } + + blkid_partition blkid_partlist_get_partition_by_start(blkid_partlist ls, uint64_t start) +@@ -1072,7 +1080,7 @@ blkid_partition blkid_partlist_devno_to_partition(blkid_partlist ls, dev_t devno + * and an entry in partition table. + */ + for (i = 0; i < ls->nparts; i++) { +- blkid_partition par = &ls->parts[i]; ++ blkid_partition par = ls->parts[i]; + + if (partno != blkid_partition_get_partno(par)) + continue; +@@ -1088,7 +1096,7 @@ blkid_partition blkid_partlist_devno_to_partition(blkid_partlist ls, dev_t devno + DBG(LOWPROBE, ul_debug("searching by offset/size")); + + for (i = 0; i < ls->nparts; i++) { +- blkid_partition par = &ls->parts[i]; ++ blkid_partition par = ls->parts[i]; + + if ((uint64_t)blkid_partition_get_start(par) == start && + (uint64_t)blkid_partition_get_size(par) == size) From patchwork Mon Jul 20 17:22:52 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 8bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 92911 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 64662C44530 for ; Mon, 20 Jul 2026 17:23:47 +0000 (UTC) Received: from mail-wm1-f43.google.com (mail-wm1-f43.google.com [209.85.128.43]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.2879.1784568223538791403 for ; Mon, 20 Jul 2026 10:23:43 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=SGIE4Vwr; spf=pass (domain: smile.fr, ip: 209.85.128.43, mailfrom: yoann.congal@smile.fr) Received: by mail-wm1-f43.google.com with SMTP id 5b1f17b1804b1-49558ce01afso14150435e9.1 for ; Mon, 20 Jul 2026 10:23:43 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1784568222; x=1785173022; darn=lists.openembedded.org; h=content-transfer-encoding:content-type:mime-version:references :in-reply-to:message-id:date:subject:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=Z8nlBN7ahjCswgSCrCH4GXkguPBZV495W3nTc3ZXx7Q=; b=SGIE4VwrUrxVkqnPgK74D1tZBVnE0vh4ntYqJtdVm2sBCuE+rluTAkVHKuN5ZY/ft1 vBqyKRGdyA+zwAc1M9CwOPHXd0sxyubs62puhgsPKUpTANmWeAWl/Vciy0CpKuFJjPu8 jrERcJ0ixREZ4XcWssIqU5QPEU3bXcjPUnSvM= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1784568222; x=1785173022; h=content-transfer-encoding:content-type:mime-version:references :in-reply-to:message-id:date:subject:to:from:x-gm-gg :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to :content-type; bh=Z8nlBN7ahjCswgSCrCH4GXkguPBZV495W3nTc3ZXx7Q=; b=ECJIbhErj2m2vAgPuAyHM+awpDt7viwvb6Ce5BJre7eQuzED2e9cyQfTmoVg2vkKfV 948C21/EPiSr/s7dkjWzrP2UG14PanvEXXg8VOXzd1XXDJikh4mpDzCkQ8ZB3F163tuZ VeCVIsc0wWiGudcyl5Hp02BP+nFFg9AGfqgGJ60+mp0o35gaXGgmZJNlZIydeC+jbtSW 5PiULSH/w/ijmwumbhlfMCR2bBVff+pxI7YXGWXrWUWiCNugQNSThXppsrzdW4JyBhrb bA/KgdmmNLpDYKVS1UGDkFHfSYd+883hN/lkTAgcSoWP1L3DvYJ1zrBxE/jxfZLVtiDS dWEw== X-Gm-Message-State: AOJu0YyPq55Is35vYDN1lCBB/0M/MHmIJBKqPxiI+zkT4W4/6/Lsiv3w NPCPTsmY1p3/NUJQ0WtNydmGtRGRufPJ+Y6aVA3mEB1zuS+9VbR/Ig0h7D8p+/8RwQ4ZTOmcfhZ n/3sjWII= X-Gm-Gg: AfdE7ck/8hhBHrGPG6EVfU23vqDVTDRWgTNnhMW7Rt/xJdfgxovEff6uSY0vDw2zpdS jVVjpgTv/63k2E/lX5BQurrXCCTqqb6uFaCEqqKUmykKzHJYqGr7hqMZOA4xOYVd/KRCfEfP9q5 v1zr5cDfpirIESGf8gdjLyFTkT5UAFqYb2Ei3jtz9kqNVW8tr/AYNyOLpZJEHA+OQPmqpcWkTJf 59OrfABfleVuQk9nDihiiLjiftdeNyDgyTlvu51otDtbPebVhVVh2l0VV2n6LFByej45feTMI9i ZXg6SKAWcYDKE38hzjFzeGI3gPzdgwXBuSneGpxYzQoYUUR9oqo9b2F4OJ6PjF+3xTlaSMvtyFo bw9iSln2ljhSS7yIbAEkqHqF/e6FuB9UR07XiHYnfBeCBru2imw980DwCQXPppwom2w9xm1cM8n pua5SrZQx4ErNfL/Zxsdy0fvh/akhWzsw1piqJq/6XMx9heRXG6Dazo9kxrI0KORFqVYzI95Y0L YFl/K88 X-Received: by 2002:a05:600c:3590:b0:490:e5c1:b8b9 with SMTP id 5b1f17b1804b1-4954a8e3616mr166198165e9.0.1784568221690; Mon, 20 Jul 2026 10:23:41 -0700 (PDT) Received: from localhost.localdomain (2a02-8440-b501-5b7b-2580-caa3-ecc1-dea5.rev.sfr.net. [2a02:8440:b501:5b7b:2580:caa3:ecc1:dea5]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-49563eee22esm36508575e9.1.2026.07.20.10.23.41 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 20 Jul 2026 10:23:41 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][scarthgap 19/33] tzdata/tzcode-native: upgrade 2026b -> 2026c Date: Mon, 20 Jul 2026 19:22:52 +0200 Message-ID: <59c98bd008a9611be2fd87d869d23049cae7d759.1784567958.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Mon, 20 Jul 2026 17:23:47 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/241453 From: Vijay Anusuri This release contains the following changes: Briefly: Alberta moved to permanent -06 on 2026-06-18. Morocco moves to permanent +00 on 2026-09-20. More integer overflow bugs have been fixed in zic. Changes to future timestamps Alberta’s 2026-03-08 spring forward was its last foreseeable clock change, as it moved to permanent -06 thereafter. (Thanks to Roozbeh Pournader and others.) Model this with its traditional abbreviation CST. Although the change to permanent -06 legally took place on 2026-06-18, temporarily model the change to occur on 2026-11-01 at 02:00 instead, for the same reason we introduced a similarly temporary hack for British Columbia in 2026b. Although another TZDB release will likely be needed soon because Northwest Territories will likely follow Alberta, the legal formalities have not yet taken place. Morocco plans to move back to permanent UTC, without daylight saving time transitions, on 2026-09-20 at 02:00. This also affects Western Sahara. Changes to code zic no longer overflows integers when processing outlandish input like ‘Zone Ouch 0 - LMT 9223372036854775807’, ‘Zone Ouch 0 2562047788015215 LMT’, ‘Zone Ouch -2562047788015215:30:08 - LMT’, and ‘Zone Ouch -2562047788015215:30:08 - %%z’. This avoids undefined behavior in C. (Problems reported by Naveed Khan.) On platforms that have EFTYPE, tzalloc now fails with errno set to EFTYPE, not EINVAL, if it detects that the TZif file has an invalid format or is not a regular file. Formerly it did this only on NetBSD, and only when the file was not a regular file. Unprivileged programs no longer require TZif files to be regular files or reject relative names containing ".." components. This reverts to the more-permissive 2025b behavior, as the stricter behavior did not catch on in FreeBSD. zic now reports any failure to remove a temporary file when cleaning up after a previous failure. (Problem reported by Tom Lane.) Changes to commentary Northwest Territories is expected to move to permanent -06 prior to 2026-11-01 02:00, when clocks would otherwise fall back. (Thanks to Tim Parenti and James Bellaire.) Model this with its traditional abbreviation CST. Unfortunately the change is not yet official, so it is currently present only as comments that can be uncommented as needed. Changes to build procedure The undocumented ‘typecheck’ Makefile check rule has been removed. It stopped working in 2025a and evidently nobody noticed. The rule was superseded by ‘check_time_t_alternatives’ in 2013d. Ref: https://lists.iana.org/hyperkitty/list/tz-announce@iana.org/thread/NVHSX2PAQIT44U5FCCEVNJJYXQMMTJSA/ Signed-off-by: Vijay Anusuri Signed-off-by: Richard Purdie (cherry picked from commit 33a7e1170b0c8ba83cdb4c7d6d9f83f6c194baed) Signed-off-by: Vijay Anusuri Signed-off-by: Yoann Congal --- meta/recipes-extended/timezone/timezone.inc | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/meta/recipes-extended/timezone/timezone.inc b/meta/recipes-extended/timezone/timezone.inc index a4774370662..4271b306486 100644 --- a/meta/recipes-extended/timezone/timezone.inc +++ b/meta/recipes-extended/timezone/timezone.inc @@ -6,7 +6,7 @@ SECTION = "base" LICENSE = "PD & BSD-3-Clause" LIC_FILES_CHKSUM = "file://LICENSE;md5=c679c9d6b02bc2757b3eaf8f53c43fba" -PV = "2026b" +PV = "2026c" SRC_URI =" http://www.iana.org/time-zones/repository/releases/tzcode${PV}.tar.gz;name=tzcode;subdir=tz \ http://www.iana.org/time-zones/repository/releases/tzdata${PV}.tar.gz;name=tzdata;subdir=tz \ @@ -16,5 +16,5 @@ S = "${WORKDIR}/tz" UPSTREAM_CHECK_URI = "http://www.iana.org/time-zones" -SRC_URI[tzcode.sha256sum] = "37e9ed8427f5d3521c22fc58e293cbfb043d70eedf1003870b33f363f61ca344" -SRC_URI[tzdata.sha256sum] = "114543d9f19a6bfeb5bca43686aea173d38755a3db1f2eec112647ae92c6f544" +SRC_URI[tzcode.sha256sum] = "b1cffc3ace4c4c7cd0efba2f7add86ec3d0b79da48bcf03582671fd3c8feace8" +SRC_URI[tzdata.sha256sum] = "e4a178a4477f3d0ea77cc31828ff72aa38feff8d61aa13e7e99e142e9d902be4" From patchwork Mon Jul 20 17:22:53 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 8bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 92913 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 4EA22C4452D for ; Mon, 20 Jul 2026 17:23:47 +0000 (UTC) Received: from mail-wm1-f52.google.com (mail-wm1-f52.google.com [209.85.128.52]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.2880.1784568224516976374 for ; Mon, 20 Jul 2026 10:23:44 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=3qBPU0Yn; spf=pass (domain: smile.fr, ip: 209.85.128.52, mailfrom: yoann.congal@smile.fr) Received: by mail-wm1-f52.google.com with SMTP id 5b1f17b1804b1-49548e01d02so15407155e9.0 for ; Mon, 20 Jul 2026 10:23:44 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1784568223; x=1785173023; darn=lists.openembedded.org; h=content-transfer-encoding:content-type:mime-version:references :in-reply-to:message-id:date:subject:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=w8yKx3NEkUZZX9grGSpkLc5RarM9I2jYfTRIY/4RuGY=; b=3qBPU0YnG2HL2IWiLi+CAY3msgmXeSWrnHUoYzrxEAj+7HQmtA/Bn3kyhjYNkp+wWr zM0RHCEDM7e7VOEAt++2K254GtKYXY8uhar/ggH6SN14pA1LWT02mt9Hy+yVnTbZRT4R 96i+gweIVBnXjSHWpxuvYqtDU0aXUpYHRIDSg= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1784568223; x=1785173023; h=content-transfer-encoding:content-type:mime-version:references :in-reply-to:message-id:date:subject:to:from:x-gm-gg :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to :content-type; bh=w8yKx3NEkUZZX9grGSpkLc5RarM9I2jYfTRIY/4RuGY=; b=bvlXDtt4+EQaNOvcfjeduhTV4TsQvqV5YHq4SkYEXRVq0w+dHzHaLlI/p+U5WcQcJ+ gEvywfebz1VyfRtMNKMr+u9pik92+RJIr3KXYBPY0l6CXjrZ+6bXyVk3xWF5llJc0yAP Q+JKNtlWxDMfkyWead/JUIzimCeax/OEe+P+cc8iflW5BRRGLaGq7NQ3gvICW/IBQnd2 pcGHpcZSg58v9ob/1+jNIkFHOyduAs+DifUO0V51Cp2CyPwwpFuqvl/Y8fG9VK0tEKlk 9FETwWdXLxNcgIcLNL0C6suSlffRccB5ejMZ8ryGfhhuxlqS2xcSGX3Pgg1uSffyUlJW HmJw== X-Gm-Message-State: AOJu0Yw7+lvxLHMW5nnXXd2EDInKd8aU8E4l6yWXWTpBHvG0zC2Dlurj rKdtLfKLaKqQ0X7g5TdWCbfdV3hBFualdks+ZbptClxXVh+G6dCZALQOGj9+4eJLFJq0/Rn19JV N68tALCs= X-Gm-Gg: AfdE7cn47P1x8W8PBtTIB5CWXqjVHnacxHuECzVuU5yKNH2tVk1v/6yxlsn+roy09tW oguMZVhh2SyTVb0HyN4bsI8CWcW5lo00cRnw/3X8DkcOnyqSkNWLX9w3ucDCiDYFFzCkYdlhmyC h5p+RzpRZaeHq9TP2idiDmJvo868HCigTk6i1KidQERTNHQpQH1NXCAdv548dsj6mRCE2xuJPDk FW5QfJfnCuRQON2pUcl/s25hiVeMuaaxVzIKKlrrjzmZip7ncJXQ07b1j31Qt2YwIPA3vNC5J2b iMjJjjPo8RdQ4mvJK2iBFzIKO95695mDhvckES17V8BTLCA1aX0o5dCyoskc9IUXNXf8ZWLfc/A mgxiAX2BBR0WfSfilKAO5YnHT9qJgnGz8DqGx4QdHqRALqNrB0/SzOQRSdwULeb2n6xk7p9Xnub I7l5hObIC5ThA3YL8tkdl6wOKYZWGx458V8xC9sEEBJXqlrKQONWpYoxR4CImoHKsnj49WkByyj TlToiAC X-Received: by 2002:a05:600c:c178:b0:493:e46e:157d with SMTP id 5b1f17b1804b1-4954a40481dmr136850795e9.19.1784568222400; Mon, 20 Jul 2026 10:23:42 -0700 (PDT) Received: from localhost.localdomain (2a02-8440-b501-5b7b-2580-caa3-ecc1-dea5.rev.sfr.net. [2a02:8440:b501:5b7b:2580:caa3:ecc1:dea5]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-49563eee22esm36508575e9.1.2026.07.20.10.23.41 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 20 Jul 2026 10:23:42 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][scarthgap 20/33] expat: patch CVE-2026-41080 Date: Mon, 20 Jul 2026 19:22:53 +0200 Message-ID: <8865543e62d8619edb4165f3b530f91f85ab1fbb.1784567958.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Mon, 20 Jul 2026 17:23:47 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/241454 From: Peter Marko Pick github PR [1] mentioned in [2]. * 969af8f4654ce50d837bb9199a73d1d02d2c7e16..4ba09dc471b39a78d77e5179d0243186c0c4ff7a * dropped code which doesn't exist in 2.6.4 yet (github actions, map file) * resolved minor conflicts (formatting) * picked 2 additional commits to apply the code cleanly [1] https://github.com/libexpat/libexpat/pull/1183 [2] https://security-tracker.debian.org/tracker/CVE-2026-41080 Signed-off-by: Peter Marko [YC: See discussion : https://lore.kernel.org/openembedded-core/2030b4435c8bc81bb4452637c0517ac33ab94d20.camel@pbarker.dev/T/#m56c5da4033c2f3571027c2745431178064ea1b5d ] Signed-off-by: Yoann Congal --- .../expat/expat/CVE-2026-41080-01.patch | 50 ++ .../expat/expat/CVE-2026-41080-02.patch | 29 ++ .../expat/expat/CVE-2026-41080-03.patch | 467 ++++++++++++++++++ meta/recipes-core/expat/expat_2.6.4.bb | 3 + 4 files changed, 549 insertions(+) create mode 100644 meta/recipes-core/expat/expat/CVE-2026-41080-01.patch create mode 100644 meta/recipes-core/expat/expat/CVE-2026-41080-02.patch create mode 100644 meta/recipes-core/expat/expat/CVE-2026-41080-03.patch diff --git a/meta/recipes-core/expat/expat/CVE-2026-41080-01.patch b/meta/recipes-core/expat/expat/CVE-2026-41080-01.patch new file mode 100644 index 00000000000..0c6af75a5de --- /dev/null +++ b/meta/recipes-core/expat/expat/CVE-2026-41080-01.patch @@ -0,0 +1,50 @@ +From fe04a7f0ff8afe57ba33d919f368b1ba23bcda92 Mon Sep 17 00:00:00 2001 +From: Sebastian Pipping +Date: Sun, 30 Mar 2025 19:26:55 +0200 +Subject: [PATCH 1/3] lib/xmlparse.c: Address clang-tidy warning + misc-no-recursion + +CVE: CVE-2026-41080 +Upstream-Status: Backport [https://github.com/libexpat/libexpat/commit/fe04a7f0ff8afe57ba33d919f368b1ba23bcda92] +Signed-off-by: Peter Marko +--- + lib/xmlparse.c | 17 ++++++++++------- + 1 file changed, 10 insertions(+), 7 deletions(-) + +diff --git a/lib/xmlparse.c b/lib/xmlparse.c +index 9bc67f38..cb25c37b 100644 +--- a/lib/xmlparse.c ++++ b/lib/xmlparse.c +@@ -1243,9 +1243,10 @@ generate_hash_secret_salt(XML_Parser parser) { + + static unsigned long + get_hash_secret_salt(XML_Parser parser) { +- if (parser->m_parentParser != NULL) +- return get_hash_secret_salt(parser->m_parentParser); +- return parser->m_hash_secret_salt; ++ const XML_Parser rootParser = getRootParserOf(parser, NULL); ++ assert(! rootParser->m_parentParser); ++ ++ return rootParser->m_hash_secret_salt; + } + + static enum XML_Error +@@ -2321,12 +2322,14 @@ int XMLCALL + XML_SetHashSalt(XML_Parser parser, unsigned long hash_salt) { + if (parser == NULL) + return 0; +- if (parser->m_parentParser) +- return XML_SetHashSalt(parser->m_parentParser, hash_salt); ++ ++ const XML_Parser rootParser = getRootParserOf(parser, NULL); ++ assert(! rootParser->m_parentParser); ++ + /* block after XML_Parse()/XML_ParseBuffer() has been called */ +- if (parserBusy(parser)) ++ if (parserBusy(rootParser)) + return 0; +- parser->m_hash_secret_salt = hash_salt; ++ rootParser->m_hash_secret_salt = hash_salt; + return 1; + } + diff --git a/meta/recipes-core/expat/expat/CVE-2026-41080-02.patch b/meta/recipes-core/expat/expat/CVE-2026-41080-02.patch new file mode 100644 index 00000000000..953f93c68a9 --- /dev/null +++ b/meta/recipes-core/expat/expat/CVE-2026-41080-02.patch @@ -0,0 +1,29 @@ +From 7fb2c7a454edc9e2880073a27f899c31d9b078ce Mon Sep 17 00:00:00 2001 +From: Atrem Borovik +Date: Sat, 20 Dec 2025 13:22:16 +0300 +Subject: [PATCH 2/3] WASI: remove getpid + +CVE: CVE-2026-41080 +Upstream-Status: Backport [https://github.com/libexpat/libexpat/commit/7fb2c7a454edc9e2880073a27f899c31d9b078ce] +Signed-off-by: Peter Marko +--- + lib/xmlparse.c | 5 ++++- + 1 file changed, 4 insertions(+), 1 deletion(-) + +diff --git a/lib/xmlparse.c b/lib/xmlparse.c +index cb25c37b..1bafb948 100644 +--- a/lib/xmlparse.c ++++ b/lib/xmlparse.c +@@ -1228,8 +1228,11 @@ generate_hash_secret_salt(XML_Parser parser) { + # endif /* ! defined(_WIN32) && defined(XML_DEV_URANDOM) */ + /* .. and self-made low quality for backup: */ + ++ entropy = gather_time_entropy(); ++# if ! defined(__wasi__) + /* Process ID is 0 bits entropy if attacker has local access */ +- entropy = gather_time_entropy() ^ getpid(); ++ entropy ^= getpid(); ++# endif + + /* Factors are 2^31-1 and 2^61-1 (Mersenne primes M31 and M61) */ + if (sizeof(unsigned long) == 4) { diff --git a/meta/recipes-core/expat/expat/CVE-2026-41080-03.patch b/meta/recipes-core/expat/expat/CVE-2026-41080-03.patch new file mode 100644 index 00000000000..4d17f1a0b0e --- /dev/null +++ b/meta/recipes-core/expat/expat/CVE-2026-41080-03.patch @@ -0,0 +1,467 @@ +From b77ab600e1893fdcfc3868d0a46efcc87c87943d Mon Sep 17 00:00:00 2001 +From: Sebastian Pipping +Date: Wed, 8 Apr 2026 15:41:54 +0200 +Subject: [PATCH 3/3] [CVE-2026-41080] Improve protection against hash flooding + (fixes #47) + +Fixes #47 + +CVE: CVE-2026-41080 +Upstream-Status: Backport [https://github.com/libexpat/libexpat/pull/1183] +Signed-off-by: Peter Marko +--- + Changes | 16 ++++++ + doc/reference.html | 51 ++++++++++++++-- + lib/expat.h | 12 ++++ + lib/internal.h | 2 + + lib/xmlparse.c | 118 ++++++++++++++++++++++++++------------ + tests/basic_tests.c | 25 ++++++++ + 6 files changed, 181 insertions(+), 43 deletions(-) + +diff --git a/Changes b/Changes +index 4265d608..1d87d6a0 100644 +--- a/Changes ++++ b/Changes +@@ -30,6 +30,22 @@ + !!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!! + + Patches: ++ Security fixes: ++ #47 #1183 CVE-2026-41080 -- The existing hash flooding protection ++ (based on SipHash) only used 4 to 8 bytes of entropy for ++ a salt, when 16 bytes of salt are supported by the ++ implementation of SipHash used by Expat. Now full 16 bytes ++ of entropy are used to improve protection against hash ++ flooding attacks. ++ Existing API function XML_SetHashSalt is now deprecated ++ because of its limitations, and its use should be ++ considered a vulnerability. Please either use the new API ++ function XML_SetHashSalt16Bytes (with known-high-quality ++ entropy input only!) instead, or leave the derivation of ++ a 16-bytes hash salt from high quality entropy to Expat's ++ internal machinery (by *not* calling either of the two ++ XML_SetHashSalt* functions). ++ + Security fixes: + #1018 #1034 CVE-2025-59375 -- Disallow use of disproportional amounts of + dynamic memory from within an Expat parser (e.g. previously +diff --git a/doc/reference.html b/doc/reference.html +index 8f14b011..7f374f84 100644 +--- a/doc/reference.html ++++ b/doc/reference.html +@@ -174,7 +174,8 @@ interface.

+
  • XML_GetAttributeInfo
  • +
  • XML_SetEncoding
  • +
  • XML_SetParamEntityParsing
  • +-
  • XML_SetHashSalt
  • ++
  • XML_SetHashSalt (deprecated)
  • ++
  • XML_SetHashSalt16Bytes
  • +
  • XML_UseForeignDTD
  • +
  • XML_SetReturnNSTriplet
  • +
  • XML_DefaultCurrent
  • +@@ -2553,10 +2554,10 @@ The choices for code are: + no effect and will always return 0. + + +-

    XML_SetHashSalt

    ++

    XML_SetHashSalt (deprecated)

    +
    + int XMLCALL
    +-XML_SetHashSalt(XML_Parser p,
    ++XML_SetHashSalt(XML_Parser parser,
    +                 unsigned long hash_salt);
    + 
    +
    +@@ -2564,15 +2565,55 @@ Sets the hash salt to use for internal hash calculations. + Helps in preventing DoS attacks based on predicting hash + function behavior. In order to have an effect this must be called + before parsing has started. Returns 1 if successful, 0 when called +-after XML_Parse or XML_ParseBuffer. ++after XML_Parse or XML_ParseBuffer or when ++ parser is NULL. ++

    ++ Note: Function XML_SetHashSalt is ++ deprecated. Please use function XML_SetHashSalt16Bytes instead for better ++ security. XML_SetHashSalt only provides 4 to 8 bytes of entropy ++ (depending on the size of type unsigned long) while the SipHash ++ implementation used by Expat can leverage up to 16 bytes of entropy — at least ++ twice as much. Function XML_SetHashSalt16Bytes of Expat >=2.7.6 ++ (and where backported) matches the amount of entropy supported by SipHash. ++

    . +

    Note: This call is optional, as the parser will auto-generate +-a new random salt value if no value has been set at the start of parsing.

    ++a new random salt value internally if no value has been set by the start of parsing.

    +

    Note: One should not call XML_SetHashSalt with a + hash salt value of 0, as this value is used as sentinel value to indicate + that XML_SetHashSalt has not been called. Consequently + such a call will have no effect, even if it returns 1.

    +
    + ++

    ++ XML_SetHashSalt16Bytes ++

    ++ ++
    ++/* Added in Expat 2.7.6. */
    ++XML_Bool XMLCALL
    ++XML_SetHashSalt16Bytes(XML_Parser parser,
    ++                       const uint8_t entropy[16]);
    ++
    ++
    ++ Sets the hash salt to use for internal hash calculations. Helps in preventing DoS ++ attacks based on predicting hash function behavior. In order to have an effect ++ this must be called before parsing has started. Returns XML_TRUE if ++ successful, XML_FALSE when called after XML_Parse or ++ XML_ParseBuffer or when parser is NULL. ++

    ++ Note: Setting a salt that is not from a source of high quality ++ entropy (like getentropy(3)) will make the parser vulnerable to ++ hash flooding attacks. ++

    ++ ++

    ++ Note: This call is optional, as the parser will auto-generate a new ++ random salt value internally if no value has been set by the start of parsing. ++

    ++
    ++ +

    XML_UseForeignDTD

    +
    + enum XML_Error XMLCALL
    +diff --git a/lib/expat.h b/lib/expat.h
    +index df207e9e..b356e002 100644
    +--- a/lib/expat.h
    ++++ b/lib/expat.h
    +@@ -44,6 +44,7 @@
    + #ifndef Expat_INCLUDED
    + #define Expat_INCLUDED 1
    + 
    ++#  include  // for uint8_t
    + #include 
    + #include "expat_external.h"
    + 
    +@@ -916,10 +917,21 @@ XML_SetParamEntityParsing(XML_Parser parser,
    +    function behavior. This must be called before parsing is started.
    +    Returns 1 if successful, 0 when called after parsing has started.
    +    Note: If parser == NULL, the function will do nothing and return 0.
    ++   DEPRECATED since Expat 2.7.6.
    + */
    + XMLPARSEAPI(int)
    + XML_SetHashSalt(XML_Parser parser, unsigned long hash_salt);
    + 
    ++/* Sets the hash salt to use for internal hash calculations.
    ++   Helps in preventing DoS attacks based on predicting hash function behavior.
    ++   This must be called before parsing is started.
    ++   Returns XML_TRUE if successful, XML_FALSE when called after parsing has
    ++   started or when parser is NULL.
    ++   Added in Expat 2.7.6.
    ++*/
    ++XMLPARSEAPI(XML_Bool)
    ++XML_SetHashSalt16Bytes(XML_Parser parser, const uint8_t entropy[16]);
    ++
    + /* If XML_Parse or XML_ParseBuffer have returned XML_STATUS_ERROR, then
    +    XML_GetErrorCode returns information about the error.
    + */
    +diff --git a/lib/internal.h b/lib/internal.h
    +index 32faaa05..617d6454 100644
    +--- a/lib/internal.h
    ++++ b/lib/internal.h
    +@@ -113,6 +113,7 @@
    + #if defined(_WIN32)                                                            \
    +     && (! defined(__USE_MINGW_ANSI_STDIO)                                      \
    +         || (1 - __USE_MINGW_ANSI_STDIO - 1 == 0))
    ++#  define EXPAT_FMT_LLX(midpart) "%" midpart "I64x"
    + #  define EXPAT_FMT_ULL(midpart) "%" midpart "I64u"
    + #  if defined(_WIN64) // Note: modifiers "td" and "zu" do not work for MinGW
    + #    define EXPAT_FMT_PTRDIFF_T(midpart) "%" midpart "I64d"
    +@@ -122,6 +123,7 @@
    + #    define EXPAT_FMT_SIZE_T(midpart) "%" midpart "u"
    + #  endif
    + #else
    ++#  define EXPAT_FMT_LLX(midpart) "%" midpart "llx"
    + #  define EXPAT_FMT_ULL(midpart) "%" midpart "llu"
    + #  if ! defined(ULONG_MAX)
    + #    error Compiler did not define ULONG_MAX for us
    +diff --git a/lib/xmlparse.c b/lib/xmlparse.c
    +index 1bafb948..75a7e5d0 100644
    +--- a/lib/xmlparse.c
    ++++ b/lib/xmlparse.c
    +@@ -604,7 +604,7 @@ static ELEMENT_TYPE *getElementType(XML_Parser parser, const ENCODING *enc,
    + 
    + static XML_Char *copyString(const XML_Char *s, XML_Parser parser);
    + 
    +-static unsigned long generate_hash_secret_salt(XML_Parser parser);
    ++static struct sipkey generate_hash_secret_salt(void);
    + static XML_Bool startParsing(XML_Parser parser);
    + 
    + static XML_Parser parserCreate(const XML_Char *encodingName,
    +@@ -777,7 +777,8 @@ struct XML_ParserStruct {
    +   XML_Bool m_useForeignDTD;
    +   enum XML_ParamEntityParsing m_paramEntityParsing;
    + #endif
    +-  unsigned long m_hash_secret_salt;
    ++  struct sipkey m_hash_secret_salt_128;
    ++  XML_Bool m_hash_secret_salt_set;
    + #if XML_GE == 1
    +   ACCOUNTING m_accounting;
    +   MALLOC_TRACKER m_alloc_tracker;
    +@@ -1189,69 +1190,65 @@ gather_time_entropy(void) {
    + 
    + #endif /* ! defined(HAVE_ARC4RANDOM_BUF) && ! defined(HAVE_ARC4RANDOM) */
    + 
    +-static unsigned long
    +-ENTROPY_DEBUG(const char *label, unsigned long entropy) {
    ++static struct sipkey
    ++ENTROPY_DEBUG(const char *label, struct sipkey entropy_128) {
    +   if (getDebugLevel("EXPAT_ENTROPY_DEBUG", 0) >= 1u) {
    +-    fprintf(stderr, "expat: Entropy: %s --> 0x%0*lx (%lu bytes)\n", label,
    +-            (int)sizeof(entropy) * 2, entropy, (unsigned long)sizeof(entropy));
    ++    fprintf(stderr,
    ++            "expat: Entropy: %s --> [0x" EXPAT_FMT_LLX(
    ++                "016") ", 0x" EXPAT_FMT_LLX("016") "] (16 bytes)\n",
    ++            label, (unsigned long long)entropy_128.k[0],
    ++            (unsigned long long)entropy_128.k[1]);
    +   }
    +-  return entropy;
    ++  return entropy_128;
    + }
    + 
    +-static unsigned long
    +-generate_hash_secret_salt(XML_Parser parser) {
    +-  unsigned long entropy;
    +-  (void)parser;
    ++static struct sipkey
    ++generate_hash_secret_salt(void) {
    ++  struct sipkey entropy;
    + 
    +   /* "Failproof" high quality providers: */
    + #if defined(HAVE_ARC4RANDOM_BUF)
    +   arc4random_buf(&entropy, sizeof(entropy));
    +   return ENTROPY_DEBUG("arc4random_buf", entropy);
    + #elif defined(HAVE_ARC4RANDOM)
    +-  writeRandomBytes_arc4random((void *)&entropy, sizeof(entropy));
    ++  writeRandomBytes_arc4random(&entropy, sizeof(entropy));
    +   return ENTROPY_DEBUG("arc4random", entropy);
    + #else
    +   /* Try high quality providers first .. */
    + #  ifdef _WIN32
    +-  if (writeRandomBytes_rand_s((void *)&entropy, sizeof(entropy))) {
    ++  if (writeRandomBytes_rand_s(&entropy, sizeof(entropy))) {
    +     return ENTROPY_DEBUG("rand_s", entropy);
    +   }
    + #  elif defined(HAVE_GETRANDOM) || defined(HAVE_SYSCALL_GETRANDOM)
    +-  if (writeRandomBytes_getrandom_nonblock((void *)&entropy, sizeof(entropy))) {
    ++  if (writeRandomBytes_getrandom_nonblock(&entropy, sizeof(entropy))) {
    +     return ENTROPY_DEBUG("getrandom", entropy);
    +   }
    + #  endif
    + #  if ! defined(_WIN32) && defined(XML_DEV_URANDOM)
    +-  if (writeRandomBytes_dev_urandom((void *)&entropy, sizeof(entropy))) {
    ++  if (writeRandomBytes_dev_urandom(&entropy, sizeof(entropy))) {
    +     return ENTROPY_DEBUG("/dev/urandom", entropy);
    +   }
    + #  endif /* ! defined(_WIN32) && defined(XML_DEV_URANDOM) */
    +   /* .. and self-made low quality for backup: */
    + 
    +-  entropy = gather_time_entropy();
    ++  entropy.k[0] = 0;
    ++  entropy.k[1] = gather_time_entropy();
    + #  if ! defined(__wasi__)
    +   /* Process ID is 0 bits entropy if attacker has local access */
    +-  entropy ^= getpid();
    ++  entropy.k[1] ^= getpid();
    + #  endif
    + 
    +   /* Factors are 2^31-1 and 2^61-1 (Mersenne primes M31 and M61) */
    +   if (sizeof(unsigned long) == 4) {
    +-    return ENTROPY_DEBUG("fallback(4)", entropy * 2147483647);
    ++    entropy.k[1] *= 2147483647;
    ++    return ENTROPY_DEBUG("fallback(4)", entropy);
    +   } else {
    +-    return ENTROPY_DEBUG("fallback(8)",
    +-                         entropy * (unsigned long)2305843009213693951ULL);
    ++    entropy.k[1] *= 2305843009213693951ULL;
    ++    return ENTROPY_DEBUG("fallback(8)", entropy);
    +   }
    + #endif
    + }
    + 
    +-static unsigned long
    +-get_hash_secret_salt(XML_Parser parser) {
    +-  const XML_Parser rootParser = getRootParserOf(parser, NULL);
    +-  assert(! rootParser->m_parentParser);
    +-
    +-  return rootParser->m_hash_secret_salt;
    +-}
    +-
    + static enum XML_Error
    + callProcessor(XML_Parser parser, const char *start, const char *end,
    +               const char **endPtr) {
    +@@ -1320,8 +1316,10 @@ callProcessor(XML_Parser parser, const char *start, const char *end,
    + static XML_Bool /* only valid for root parser */
    + startParsing(XML_Parser parser) {
    +   /* hash functions must be initialized before setContext() is called */
    +-  if (parser->m_hash_secret_salt == 0)
    +-    parser->m_hash_secret_salt = generate_hash_secret_salt(parser);
    ++  if (parser->m_hash_secret_salt_set != XML_TRUE) {
    ++    parser->m_hash_secret_salt_128 = generate_hash_secret_salt();
    ++    parser->m_hash_secret_salt_set = XML_TRUE;
    ++  }
    +   if (parser->m_ns) {
    +     /* implicit context only set for root parser, since child
    +        parsers (i.e. external entity parsers) will inherit it
    +@@ -1609,7 +1607,9 @@ parserInit(XML_Parser parser, const XML_Char *encodingName) {
    +   parser->m_useForeignDTD = XML_FALSE;
    +   parser->m_paramEntityParsing = XML_PARAM_ENTITY_PARSING_NEVER;
    + #endif
    +-  parser->m_hash_secret_salt = 0;
    ++  parser->m_hash_secret_salt_128.k[0] = 0;
    ++  parser->m_hash_secret_salt_128.k[1] = 0;
    ++  parser->m_hash_secret_salt_set = XML_FALSE;
    + 
    + #if XML_GE == 1
    +   memset(&parser->m_accounting, 0, sizeof(ACCOUNTING));
    +@@ -1776,7 +1776,8 @@ XML_ExternalEntityParserCreate(XML_Parser oldParser, const XML_Char *context,
    +      from hash tables associated with either parser without us having
    +      to worry which hash secrets each table has.
    +   */
    +-  unsigned long oldhash_secret_salt;
    ++  struct sipkey oldhash_secret_salt_128;
    ++  XML_Bool oldhash_secret_salt_set;
    +   XML_Bool oldReparseDeferralEnabled;
    + 
    +   /* Validate the oldParser parameter before we pull everything out of it */
    +@@ -1822,7 +1823,8 @@ XML_ExternalEntityParserCreate(XML_Parser oldParser, const XML_Char *context,
    +      from hash tables associated with either parser without us having
    +      to worry which hash secrets each table has.
    +   */
    +-  oldhash_secret_salt = parser->m_hash_secret_salt;
    ++  oldhash_secret_salt_128 = parser->m_hash_secret_salt_128;
    ++  oldhash_secret_salt_set = parser->m_hash_secret_salt_set;
    +   oldReparseDeferralEnabled = parser->m_reparseDeferralEnabled;
    + 
    + #ifdef XML_DTD
    +@@ -1877,7 +1879,8 @@ XML_ExternalEntityParserCreate(XML_Parser oldParser, const XML_Char *context,
    +     parser->m_externalEntityRefHandlerArg = oldExternalEntityRefHandlerArg;
    +   parser->m_defaultExpandInternalEntities = oldDefaultExpandInternalEntities;
    +   parser->m_ns_triplets = oldns_triplets;
    +-  parser->m_hash_secret_salt = oldhash_secret_salt;
    ++  parser->m_hash_secret_salt_128 = oldhash_secret_salt_128;
    ++  parser->m_hash_secret_salt_set = oldhash_secret_salt_set;
    +   parser->m_reparseDeferralEnabled = oldReparseDeferralEnabled;
    +   parser->m_parentParser = oldParser;
    + #ifdef XML_DTD
    +@@ -2321,6 +2324,7 @@ XML_SetParamEntityParsing(XML_Parser parser,
    + #endif
    + }
    + 
    ++// DEPRECATED since Expat 2.7.6.
    + int XMLCALL
    + XML_SetHashSalt(XML_Parser parser, unsigned long hash_salt) {
    +   if (parser == NULL)
    +@@ -2332,10 +2336,46 @@ XML_SetHashSalt(XML_Parser parser, unsigned long hash_salt) {
    +   /* block after XML_Parse()/XML_ParseBuffer() has been called */
    +   if (parserBusy(rootParser))
    +     return 0;
    +-  rootParser->m_hash_secret_salt = hash_salt;
    ++
    ++  rootParser->m_hash_secret_salt_128.k[0] = 0;
    ++  rootParser->m_hash_secret_salt_128.k[1] = hash_salt;
    ++
    ++  if (hash_salt != 0) { // to remain backwards compatible
    ++    rootParser->m_hash_secret_salt_set = XML_TRUE;
    ++
    ++    if (sizeof(unsigned long) == 4)
    ++      ENTROPY_DEBUG("explicit(4)", rootParser->m_hash_secret_salt_128);
    ++    else
    ++      ENTROPY_DEBUG("explicit(8)", rootParser->m_hash_secret_salt_128);
    ++  }
    ++
    +   return 1;
    + }
    + 
    ++XML_Bool XMLCALL
    ++XML_SetHashSalt16Bytes(XML_Parser parser, const uint8_t entropy[16]) {
    ++  if (parser == NULL)
    ++    return XML_FALSE;
    ++
    ++  if (entropy == NULL)
    ++    return XML_FALSE;
    ++
    ++  const XML_Parser rootParser = getRootParserOf(parser, NULL);
    ++  assert(! rootParser->m_parentParser);
    ++
    ++  /* block after XML_Parse()/XML_ParseBuffer() has been called */
    ++  if (parserBusy(rootParser))
    ++    return XML_FALSE;
    ++
    ++  sip_tokey(&(rootParser->m_hash_secret_salt_128), entropy);
    ++
    ++  rootParser->m_hash_secret_salt_set = XML_TRUE;
    ++
    ++  ENTROPY_DEBUG("explicit(16)", rootParser->m_hash_secret_salt_128);
    ++
    ++  return XML_TRUE;
    ++}
    ++
    + enum XML_Status XMLCALL
    + XML_Parse(XML_Parser parser, const char *s, int len, int isFinal) {
    +   if ((parser == NULL) || (len < 0) || ((s == NULL) && (len != 0))) {
    +@@ -7837,8 +7877,10 @@ keylen(KEY s) {
    + 
    + static void
    + copy_salt_to_sipkey(XML_Parser parser, struct sipkey *key) {
    +-  key->k[0] = 0;
    +-  key->k[1] = get_hash_secret_salt(parser);
    ++  const XML_Parser rootParser = getRootParserOf(parser, NULL);
    ++  assert(! rootParser->m_parentParser);
    ++
    ++  *key = rootParser->m_hash_secret_salt_128;
    + }
    + 
    + static unsigned long FASTCALL
    +diff --git a/tests/basic_tests.c b/tests/basic_tests.c
    +index 023d9ce4..380caf19 100644
    +--- a/tests/basic_tests.c
    ++++ b/tests/basic_tests.c
    +@@ -204,6 +204,30 @@ START_TEST(test_hash_collision) {
    + END_TEST
    + #undef COLLIDING_HASH_SALT
    + 
    ++START_TEST(test_hash_salt_setter) {
    ++  const uint8_t entropy[16] = {'0', '1', '2', '3', '4', '5', '6', '7',
    ++                               '8', '9', 'a', 'b', 'c', 'd', 'e', 'f'};
    ++  XML_Parser parser = XML_ParserCreate(NULL);
    ++
    ++  // NULL parser should be rejected
    ++  assert_true(XML_SetHashSalt16Bytes(NULL, entropy) == XML_FALSE);
    ++
    ++  // NULL entropy should be rejected
    ++  assert_true(XML_SetHashSalt16Bytes(parser, NULL) == XML_FALSE);
    ++
    ++  // Setting should be allowed more than once
    ++  assert_true(XML_SetHashSalt16Bytes(parser, entropy) == XML_TRUE);
    ++  assert_true(XML_SetHashSalt16Bytes(parser, entropy) == XML_TRUE);
    ++
    ++  // But not after parsing has started
    ++  assert_true(XML_Parse(parser, "", 0, XML_FALSE /* isFinal */)
    ++              == XML_STATUS_OK);
    ++  assert_true(XML_SetHashSalt16Bytes(parser, entropy) == XML_FALSE);
    ++
    ++  XML_ParserFree(parser);
    ++}
    ++END_TEST
    ++
    + /* Regression test for SF bug #491986. */
    + START_TEST(test_danish_latin1) {
    +   const char *text = "\n"
    +@@ -6244,6 +6268,7 @@ make_basic_test_case(Suite *s) {
    +   tcase_add_test(tc_basic, test_bom_utf16_le);
    +   tcase_add_test(tc_basic, test_nobom_utf16_le);
    +   tcase_add_test(tc_basic, test_hash_collision);
    ++  tcase_add_test(tc_basic, test_hash_salt_setter);
    +   tcase_add_test(tc_basic, test_illegal_utf8);
    +   tcase_add_test(tc_basic, test_utf8_auto_align);
    +   tcase_add_test(tc_basic, test_utf16);
    diff --git a/meta/recipes-core/expat/expat_2.6.4.bb b/meta/recipes-core/expat/expat_2.6.4.bb
    index 151720a9e3c..f5c3e3fdd2f 100644
    --- a/meta/recipes-core/expat/expat_2.6.4.bb
    +++ b/meta/recipes-core/expat/expat_2.6.4.bb
    @@ -51,6 +51,9 @@ SRC_URI = "${GITHUB_BASE_URI}/download/R_${VERSION_TAG}/expat-${PV}.tar.bz2  \
                file://CVE-2026-32777-02.patch \
                file://CVE-2026-32778-01.patch \
                file://CVE-2026-32778-02.patch \
    +           file://CVE-2026-41080-01.patch \
    +           file://CVE-2026-41080-02.patch \
    +           file://CVE-2026-41080-03.patch \
                "
     
     GITHUB_BASE_URI = "https://github.com/libexpat/libexpat/releases/"
    
    From patchwork Mon Jul 20 17:22:54 2026
    Content-Type: text/plain; charset="utf-8"
    MIME-Version: 1.0
    Content-Transfer-Encoding: 7bit
    X-Patchwork-Submitter: Yoann Congal 
    X-Patchwork-Id: 92914
    Return-Path: 
    X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on
    	aws-us-west-2-korg-lkml-1.web.codeaurora.org
    Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org
     (localhost.localdomain [127.0.0.1])
    	by smtp.lore.kernel.org (Postfix) with ESMTP id 40940C44529
    	for ; Mon, 20 Jul 2026 17:23:47 +0000 (UTC)
    Received: from mail-wm1-f48.google.com (mail-wm1-f48.google.com
     [209.85.128.48])
     by mx.groups.io with SMTP id smtpd.msgproc02-g2.2882.1784568225643521369
     for ;
     Mon, 20 Jul 2026 10:23:46 -0700
    Authentication-Results: mx.groups.io;
     dkim=pass header.i=@smile.fr header.s=google header.b=i/ZxYqhL;
     spf=pass (domain: smile.fr, ip: 209.85.128.48,
     mailfrom: yoann.congal@smile.fr)
    Received: by mail-wm1-f48.google.com with SMTP id
     5b1f17b1804b1-4953e04ef16so45663405e9.2
            for ;
     Mon, 20 Jul 2026 10:23:45 -0700 (PDT)
    DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;
            d=smile.fr; s=google; t=1784568224; x=1785173024;
     darn=lists.openembedded.org;
            h=content-transfer-encoding:mime-version:references:in-reply-to
             :message-id:date:subject:to:from:from:to:cc:subject:date:message-id
             :reply-to:content-type;
            bh=yppjQ2ELVU4HEeeerX5zvNm7F5Dpu2rH6ipJQGxJfDM=;
            b=i/ZxYqhLJVK1JC8WblT2ByftJKpC22CT0cz7ryCNSDRP2cJBKcExKgHXCOyaot8AVs
             amGwZETWAwC+cqcMM5Zn1th8QLhjN+GohTqH4PfzHo1cux90c+3hHZIrFTlYC3g4qJub
             hZzMm8jIfTDj7TaFelQez1n4NfBt7VCWuPaFI=
    X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;
            d=1e100.net; s=20251104; t=1784568224; x=1785173024;
            h=content-transfer-encoding:mime-version:references:in-reply-to
             :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to
             :cc:subject:date:message-id:reply-to:content-type;
            bh=yppjQ2ELVU4HEeeerX5zvNm7F5Dpu2rH6ipJQGxJfDM=;
            b=HOLCtZ/IdjsiuYQPbZvhy2xyxtbLHmn/0ItPqENc5Mkxo1ycfVxZnwkPeaoRaRQ+IJ
             c1jtGuuHH1CDtamNzSDFAixt4T5SPjuwdVhekORnfu5y6+tMYjSf9gO1YauccvdJdhYb
             ylbM9hKSMx3ZdVFqEQlBvdE6VkL+0hXxUrebTpUGWN1/Q/3APmO+NXt7S84ePzBmumO1
             nO+9LxTYS76ZYjIYnegTgDv9/fUcdt/4lUlDa1BZHatLVaYyQRXRZnntiPWhYYjhdNZN
             pxIZ8kK776POLyc9OlMWLu0QXT6vN31nK5tHHRdU0uWjqrHZ6zmCHWUnk0JV9a4nDbue
             NWMw==
    X-Gm-Message-State: AOJu0Yzj2kqrOacl6Uxf5OTXN24uMCrj0SukWWMgNHMn4QfMoXMJUqa1
    	K71yzBpsP7k8jrW5YeulZL7/rPlf2r083ath1u7yrcFBSx3hxLF1QYD1qx3Fozh0ukywYHHd00e
    	WfWzhguo=
    X-Gm-Gg: AfdE7cmwtlQhrkkTO/yY0H3stciegIA4+xdxa1XhWC4kBT9sH68OgS1WQaTyQhIqsrk
    	p4bMZkQuZoysujkCc7mryIrkaYGPU/WID5m8yfO0Rpx9Zt0uJKMKgdvcpPUHiF+FflcZ+AZl9+6
    	X69BWcZ3nOX3ZQ0hwB5pQlA5jWT5IKYpTRFeNg2b6FY23LrQv0YSvmFDUKBxMtj2IzyEytG17dk
    	NuWcqL56QMx+28OvfpuueQyNCdw5sq8ko78l+eYSJ6yIYc3EyRV3qg3Bw9YET2PtBUrj7SFNZHO
    	BqnRLfFGW1KL8nhW0IfQOMDOLPYOdOmTu6btYpmg9aBKFqev7O5dno466ZWFB+c03/iVT0512w/
    	UW82aDTGATs2npKhyuFTD44XSZ7kmRlofrfPS8qnfrAKsJit0DjkAlUsDw0tHuyePeZspZW7Xny
    	3H8Ig71IbXOddGdIXeJCcUK0MAK2xUn2OEdaXZbGqmtTSs1SUPBbd8WIpcwM8WvnH59/DYwX3nY
    	qryU0BS
    X-Received: by 2002:a05:600c:4f44:b0:495:5b02:23a5 with SMTP id
     5b1f17b1804b1-4955b02253amr78129025e9.30.1784568223058;
            Mon, 20 Jul 2026 10:23:43 -0700 (PDT)
    Received: from localhost.localdomain
     (2a02-8440-b501-5b7b-2580-caa3-ecc1-dea5.rev.sfr.net.
     [2a02:8440:b501:5b7b:2580:caa3:ecc1:dea5])
            by smtp.gmail.com with ESMTPSA id
     5b1f17b1804b1-49563eee22esm36508575e9.1.2026.07.20.10.23.42
            for 
            (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256);
            Mon, 20 Jul 2026 10:23:42 -0700 (PDT)
    From: Yoann Congal 
    To: openembedded-core@lists.openembedded.org
    Subject: [OE-core][scarthgap 21/33] expat: patch CVE-2026-45186
    Date: Mon, 20 Jul 2026 19:22:54 +0200
    Message-ID: 
     <7a9e4a90bd7b1768bb07f9752d2c4847fe799f91.1784567958.git.yoann.congal@smile.fr>
    X-Mailer: git-send-email 2.47.3
    In-Reply-To: 
    References: 
    MIME-Version: 1.0
    List-Id: 
    X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com
     [45.33.107.173] by
     aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for
     ; Mon, 20 Jul 2026 17:23:47 -0000
    X-Groupsio-URL: 
     https://lists.openembedded.org/g/openembedded-core/message/241455
    
    From: Theo Gaige 
    
    Backport patches from [1] also mentioned in [2].
    
    [1] https://github.com/libexpat/libexpat/pull/1216
    [2] https://security-tracker.debian.org/tracker/CVE-2026-45186
    
    Signed-off-by: Theo Gaige 
    Reviewed-by: Bruno Vernay 
    Signed-off-by: Yoann Congal 
    ---
     .../expat/expat/CVE-2026-45186-01.patch       |  70 ++++
     .../expat/expat/CVE-2026-45186-02.patch       | 318 ++++++++++++++++++
     .../expat/expat/CVE-2026-45186-03.patch       |  46 +++
     .../expat/expat/CVE-2026-45186-04.patch       |  32 ++
     .../expat/expat/CVE-2026-45186-05.patch       |  32 ++
     .../expat/expat/CVE-2026-45186-06.patch       |  87 +++++
     .../expat/expat/CVE-2026-45186-07.patch       |  52 +++
     meta/recipes-core/expat/expat_2.6.4.bb        |   7 +
     8 files changed, 644 insertions(+)
     create mode 100644 meta/recipes-core/expat/expat/CVE-2026-45186-01.patch
     create mode 100644 meta/recipes-core/expat/expat/CVE-2026-45186-02.patch
     create mode 100644 meta/recipes-core/expat/expat/CVE-2026-45186-03.patch
     create mode 100644 meta/recipes-core/expat/expat/CVE-2026-45186-04.patch
     create mode 100644 meta/recipes-core/expat/expat/CVE-2026-45186-05.patch
     create mode 100644 meta/recipes-core/expat/expat/CVE-2026-45186-06.patch
     create mode 100644 meta/recipes-core/expat/expat/CVE-2026-45186-07.patch
    
    diff --git a/meta/recipes-core/expat/expat/CVE-2026-45186-01.patch b/meta/recipes-core/expat/expat/CVE-2026-45186-01.patch
    new file mode 100644
    index 00000000000..787006c0fdb
    --- /dev/null
    +++ b/meta/recipes-core/expat/expat/CVE-2026-45186-01.patch
    @@ -0,0 +1,70 @@
    +From 3020144133b2d860c44f4eeacf72e5f2843235a3 Mon Sep 17 00:00:00 2001
    +From: =?UTF-8?q?Berkay=20Eren=20=C3=9Cr=C3=BCn?= 
    +Date: Fri, 13 Mar 2026 13:26:45 +0100
    +Subject: [PATCH 1/7] Make "counting_start_element_handler" count default attrs
    +
    +(cherry picked from commit 0802a5892030610144b736dec6e2f63e8600fe85)
    +
    +CVE: CVE-2026-45186
    +Upstream-Status: Backport [https://github.com/libexpat/libexpat/pull/1216/commits/0802a5892030610144b736dec6e2f63e8600fe85]
    +Signed-off-by: Theo Gaige 
    +---
    + tests/basic_tests.c | 8 ++++----
    + tests/handlers.c    | 2 +-
    + tests/handlers.h    | 1 +
    + 3 files changed, 6 insertions(+), 5 deletions(-)
    +
    +diff --git a/tests/basic_tests.c b/tests/basic_tests.c
    +index 023d9ce..d6edb16 100644
    +--- a/tests/basic_tests.c
    ++++ b/tests/basic_tests.c
    +@@ -2439,9 +2439,9 @@ START_TEST(test_attributes) {
    +                          {XCS("id"), XCS("one")},
    +                          {NULL, NULL}};
    +   AttrInfo tag_info[] = {{XCS("c"), XCS("3")}, {NULL, NULL}};
    +-  ElementInfo info[] = {{XCS("doc"), 3, XCS("id"), NULL},
    +-                        {XCS("tag"), 1, NULL, NULL},
    +-                        {NULL, 0, NULL, NULL}};
    ++  ElementInfo info[] = {{XCS("doc"), 3, 0, XCS("id"), NULL},
    ++                        {XCS("tag"), 1, 0, NULL, NULL},
    ++                        {NULL, 0, 0, NULL, NULL}};
    +   info[0].attributes = doc_info;
    +   info[1].attributes = tag_info;
    + 
    +@@ -5496,7 +5496,7 @@ START_TEST(test_deep_nested_attribute_entity) {
    +            (long unsigned)(N_LINES - 1));
    + 
    +   AttrInfo doc_info[] = {{XCS("name"), XCS("deepText")}, {NULL, NULL}};
    +-  ElementInfo info[] = {{XCS("foo"), 1, NULL, NULL}, {NULL, 0, NULL, NULL}};
    ++  ElementInfo info[] = {{XCS("foo"), 1, 0, NULL, NULL}, {NULL, 0, 0, NULL, NULL}};
    +   info[0].attributes = doc_info;
    + 
    +   XML_Parser parser = XML_ParserCreate(NULL);
    +diff --git a/tests/handlers.c b/tests/handlers.c
    +index e658223..9ff7b35 100644
    +--- a/tests/handlers.c
    ++++ b/tests/handlers.c
    +@@ -137,7 +137,7 @@ counting_start_element_handler(void *userData, const XML_Char *name,
    +     fail("ID does not have the correct name");
    +     return;
    +   }
    +-  for (i = 0; i < info->attr_count; i++) {
    ++  for (i = 0; i < info->attr_count + info->default_attr_count; i++) {
    +     attr = info->attributes;
    +     while (attr->name != NULL) {
    +       if (! xcstrcmp(atts[0], attr->name))
    +diff --git a/tests/handlers.h b/tests/handlers.h
    +index ac4ca94..11d45eb 100644
    +--- a/tests/handlers.h
    ++++ b/tests/handlers.h
    +@@ -88,6 +88,7 @@ typedef struct attrInfo {
    + typedef struct elementInfo {
    +   const XML_Char *name;
    +   int attr_count;
    ++  int default_attr_count;
    +   const XML_Char *id_name;
    +   AttrInfo *attributes;
    + } ElementInfo;
    +-- 
    +2.43.0
    +
    diff --git a/meta/recipes-core/expat/expat/CVE-2026-45186-02.patch b/meta/recipes-core/expat/expat/CVE-2026-45186-02.patch
    new file mode 100644
    index 00000000000..fef531a4392
    --- /dev/null
    +++ b/meta/recipes-core/expat/expat/CVE-2026-45186-02.patch
    @@ -0,0 +1,318 @@
    +From ba12af3b3ffd98b9e31c3a01a20d392c89aa974e Mon Sep 17 00:00:00 2001
    +From: =?UTF-8?q?Berkay=20Eren=20=C3=9Cr=C3=BCn?= 
    +Date: Fri, 13 Mar 2026 13:27:31 +0100
    +Subject: [PATCH 2/7] test(attlist): Cover duplicate attribute names
    +
    +Co-authored-by: Sebastian Pipping 
    +(cherry picked from commit e569f47181c43dca5d262089e541ddf9a9c09927)
    +
    +CVE: CVE-2026-45186
    +Upstream-Status: Backport [https://github.com/libexpat/libexpat/pull/1216/commits/e569f47181c43dca5d262089e541ddf9a9c09927]
    +Signed-off-by: Theo Gaige 
    +---
    + tests/basic_tests.c | 282 ++++++++++++++++++++++++++++++++++++++++++++
    + 1 file changed, 282 insertions(+)
    +
    +diff --git a/tests/basic_tests.c b/tests/basic_tests.c
    +index d6edb16..907a458 100644
    +--- a/tests/basic_tests.c
    ++++ b/tests/basic_tests.c
    +@@ -2462,6 +2462,279 @@ START_TEST(test_attributes) {
    + }
    + END_TEST
    + 
    ++START_TEST(test_duplicate_cdata_attribute) {
    ++  /*
    ++  https://www.w3.org/TR/xml/#attdecls
    ++
    ++  Test the following statement from the linked specification:
    ++    When more than one definition is provided for the same attribute of a given
    ++    element type, the first declaration is binding and later declarations are
    ++    ignored.
    ++  */
    ++
    ++  const char *text
    ++      = "\n"
    ++        "]>\n"
    ++        "\n";
    ++  AttrInfo doc_info[] = {{XCS("attribute"), XCS("expected")}, {NULL, NULL}};
    ++  ElementInfo info[]
    ++      = {{XCS("doc"), 0, 1, NULL, doc_info}, {NULL, 0, 0, NULL, NULL}};
    ++
    ++  XML_Parser parser = XML_ParserCreate(NULL);
    ++  assert_true(parser != NULL);
    ++
    ++  ParserAndElementInfo parserAndElementInfos = {
    ++      parser,
    ++      info,
    ++  };
    ++
    ++  XML_SetStartElementHandler(parser, counting_start_element_handler);
    ++  XML_SetUserData(parser, &parserAndElementInfos);
    ++
    ++  if (_XML_Parse_SINGLE_BYTES(parser, text, (int)strlen(text), XML_TRUE)
    ++      != XML_STATUS_OK)
    ++    xml_failure(parser);
    ++
    ++  XML_ParserFree(parser);
    ++}
    ++END_TEST
    ++
    ++START_TEST(test_duplicate_id_attribute_1) {
    ++  /*
    ++  https://www.w3.org/TR/xml/#attdecls
    ++
    ++  Test the following statement from the linked specification:
    ++    When more than one definition is provided for the same attribute of a given
    ++    element type, the first declaration is binding and later declarations are
    ++    ignored.
    ++  */
    ++
    ++  const char *text
    ++      = "\n"
    ++        "]>\n"
    ++        "\n";
    ++  AttrInfo doc_info[] = {{XCS("identifier"), XCS("expected")}, {NULL, NULL}};
    ++  ElementInfo info[]
    ++      = {{XCS("doc"), 0, 1, NULL, doc_info}, {NULL, 0, 0, NULL, NULL}};
    ++
    ++  XML_Parser parser = XML_ParserCreate(NULL);
    ++  assert_true(parser != NULL);
    ++
    ++  ParserAndElementInfo parserAndElementInfos = {
    ++      parser,
    ++      info,
    ++  };
    ++
    ++  XML_SetStartElementHandler(parser, counting_start_element_handler);
    ++  XML_SetUserData(parser, &parserAndElementInfos);
    ++
    ++  if (_XML_Parse_SINGLE_BYTES(parser, text, (int)strlen(text), XML_TRUE)
    ++      != XML_STATUS_OK)
    ++    xml_failure(parser);
    ++
    ++  XML_ParserFree(parser);
    ++}
    ++END_TEST
    ++
    ++START_TEST(test_duplicate_id_attribute_2) {
    ++  /*
    ++  https://www.w3.org/TR/xml/#attdecls
    ++
    ++  Test the following statement from the linked specification:
    ++    When more than one definition is provided for the same attribute of a given
    ++    element type, the first declaration is binding and later declarations are
    ++    ignored.
    ++  */
    ++
    ++  const char *text
    ++      = "\n"
    ++        "]>\n"
    ++        "\n";
    ++  AttrInfo doc_info[] = {{NULL, NULL}};
    ++
    ++  ElementInfo info[]
    ++      = {{XCS("doc"), 0, 0, NULL, doc_info}, {NULL, 0, 0, NULL, NULL}};
    ++
    ++  XML_Parser parser = XML_ParserCreate(NULL);
    ++  assert_true(parser != NULL);
    ++
    ++  ParserAndElementInfo parserAndElementInfos = {
    ++      parser,
    ++      info,
    ++  };
    ++
    ++  XML_SetStartElementHandler(parser, counting_start_element_handler);
    ++  XML_SetUserData(parser, &parserAndElementInfos);
    ++
    ++  if (_XML_Parse_SINGLE_BYTES(parser, text, (int)strlen(text), XML_TRUE)
    ++      != XML_STATUS_OK)
    ++    xml_failure(parser);
    ++
    ++  XML_ParserFree(parser);
    ++}
    ++END_TEST
    ++
    ++START_TEST(test_duplicate_cdata_attribute_multiple_attlistdecl) {
    ++  /*
    ++  https://www.w3.org/TR/xml/#attdecls
    ++
    ++  Test the following statement from the linked specification:
    ++    When more than one AttlistDecl is provided for a given element type,
    ++    the contents of all those provided are merged.
    ++  */
    ++  const char *text = "\n"
    ++                     "  \n"
    ++                     "]>\n"
    ++                     "\n";
    ++  AttrInfo doc_info[] = {{XCS("attribute"), XCS("expected")}, {NULL, NULL}};
    ++  ElementInfo info[]
    ++      = {{XCS("doc"), 0, 1, NULL, doc_info}, {NULL, 0, 0, NULL, NULL}};
    ++
    ++  XML_Parser parser = XML_ParserCreate(NULL);
    ++  assert_true(parser != NULL);
    ++
    ++  ParserAndElementInfo parserAndElementInfos = {
    ++      parser,
    ++      info,
    ++  };
    ++
    ++  XML_SetStartElementHandler(parser, counting_start_element_handler);
    ++  XML_SetUserData(parser, &parserAndElementInfos);
    ++
    ++  if (_XML_Parse_SINGLE_BYTES(parser, text, (int)strlen(text), XML_TRUE)
    ++      != XML_STATUS_OK)
    ++    xml_failure(parser);
    ++
    ++  XML_ParserFree(parser);
    ++}
    ++END_TEST
    ++
    ++START_TEST(test_duplicate_cdata_attribute_multiple_attlistdecl_2) {
    ++  /*
    ++  https://www.w3.org/TR/xml/#attdecls
    ++
    ++  Test the following statement from the linked specification:
    ++    When more than one AttlistDecl is provided for a given element type,
    ++    the contents of all those provided are merged.
    ++  */
    ++  const char *text = "\n"
    ++                     "  \n"
    ++                     "  \n"
    ++                     "]>\n"
    ++                     "\n";
    ++  AttrInfo doc_info[] = {{XCS("attribute"), XCS("expected_doc")}, {NULL, NULL}};
    ++  AttrInfo tag_info[] = {{XCS("attribute"), XCS("expected_tag")}, {NULL, NULL}};
    ++  ElementInfo info[] = {{XCS("doc"), 0, 1, NULL, doc_info},
    ++                        {XCS("tag"), 0, 1, NULL, tag_info},
    ++                        {NULL, 0, 0, NULL, NULL}};
    ++
    ++  XML_Parser parser = XML_ParserCreate(NULL);
    ++  assert_true(parser != NULL);
    ++
    ++  ParserAndElementInfo parserAndElementInfos = {
    ++      parser,
    ++      info,
    ++  };
    ++
    ++  XML_SetStartElementHandler(parser, counting_start_element_handler);
    ++  XML_SetUserData(parser, &parserAndElementInfos);
    ++
    ++  if (_XML_Parse_SINGLE_BYTES(parser, text, (int)strlen(text), XML_TRUE)
    ++      != XML_STATUS_OK)
    ++    xml_failure(parser);
    ++
    ++  XML_ParserFree(parser);
    ++}
    ++END_TEST
    ++
    ++START_TEST(test_duplicate_cdata_attribute_multiple_attlistdecl_3) {
    ++  /*
    ++  https://www.w3.org/TR/xml/#attdecls
    ++
    ++  Test the following statement from the linked specification:
    ++    When more than one AttlistDecl is provided for a given element type,
    ++    the contents of all those provided are merged.
    ++  */
    ++  const char *text
    ++      = "\n"
    ++        "  \n"
    ++        "  \n"
    ++        "]>\n"
    ++        "\n";
    ++  AttrInfo doc_info[] = {{XCS("attribute"), XCS("expected_doc")},
    ++                         {XCS("second_attribute"), XCS("second_expected_doc")},
    ++                         {NULL, NULL}};
    ++  AttrInfo tag_info[] = {{XCS("attribute"), XCS("expected_tag")}, {NULL, NULL}};
    ++  ElementInfo info[] = {{XCS("doc"), 0, 2, NULL, doc_info},
    ++                        {XCS("tag"), 0, 1, NULL, tag_info},
    ++                        {NULL, 0, 0, NULL, NULL}};
    ++
    ++  XML_Parser parser = XML_ParserCreate(NULL);
    ++  assert_true(parser != NULL);
    ++
    ++  ParserAndElementInfo parserAndElementInfos = {
    ++      parser,
    ++      info,
    ++  };
    ++
    ++  XML_SetStartElementHandler(parser, counting_start_element_handler);
    ++  XML_SetUserData(parser, &parserAndElementInfos);
    ++
    ++  if (_XML_Parse_SINGLE_BYTES(parser, text, (int)strlen(text), XML_TRUE)
    ++      != XML_STATUS_OK)
    ++    xml_failure(parser);
    ++
    ++  XML_ParserFree(parser);
    ++}
    ++END_TEST
    ++
    ++START_TEST(test_duplicate_id_attribute_multiple_attlistdecl) {
    ++  /*
    ++  https://www.w3.org/TR/xml/#attdecls
    ++
    ++  Test the following statement from the linked specification:
    ++    When more than one AttlistDecl is provided for a given element type,
    ++    the contents of all those provided are merged.
    ++  */
    ++  const char *text = "\n"
    ++                     "  \n"
    ++                     "  \n"
    ++                     "]>\n"
    ++                     "\n";
    ++  AttrInfo doc_info[]
    ++      = {{XCS("identifier"), XCS("doc_identity")}, {NULL, NULL}};
    ++  AttrInfo tag_info[]
    ++      = {{XCS("identifier"), XCS("identifier_tag")}, {NULL, NULL}};
    ++  ElementInfo info[] = {{XCS("doc"), 1, 0, XCS("identifier"), doc_info},
    ++                        {XCS("tag"), 0, 1, NULL, tag_info},
    ++                        {NULL, 0, 0, NULL, NULL}};
    ++
    ++  XML_Parser parser = XML_ParserCreate(NULL);
    ++  assert_true(parser != NULL);
    ++
    ++  ParserAndElementInfo parserAndElementInfos = {
    ++      parser,
    ++      info,
    ++  };
    ++
    ++  XML_SetStartElementHandler(parser, counting_start_element_handler);
    ++  XML_SetUserData(parser, &parserAndElementInfos);
    ++
    ++  if (_XML_Parse_SINGLE_BYTES(parser, text, (int)strlen(text), XML_TRUE)
    ++      != XML_STATUS_OK)
    ++    xml_failure(parser);
    ++
    ++  XML_ParserFree(parser);
    ++}
    ++END_TEST
    ++
    + /* Test reset works correctly in the middle of processing an internal
    +  * entity.  Exercises some obscure code in XML_ParserReset().
    +  */
    +@@ -6325,6 +6598,15 @@ make_basic_test_case(Suite *s) {
    +   tcase_add_test__ifdef_xml_dtd(tc_basic, test_empty_foreign_dtd);
    +   tcase_add_test(tc_basic, test_set_base);
    +   tcase_add_test(tc_basic, test_attributes);
    ++  tcase_add_test(tc_basic, test_duplicate_cdata_attribute);
    ++  tcase_add_test(tc_basic, test_duplicate_id_attribute_1);
    ++  tcase_add_test(tc_basic, test_duplicate_id_attribute_2);
    ++  tcase_add_test(tc_basic, test_duplicate_cdata_attribute_multiple_attlistdecl);
    ++  tcase_add_test(tc_basic,
    ++                 test_duplicate_cdata_attribute_multiple_attlistdecl_2);
    ++  tcase_add_test(tc_basic,
    ++                 test_duplicate_cdata_attribute_multiple_attlistdecl_3);
    ++  tcase_add_test(tc_basic, test_duplicate_id_attribute_multiple_attlistdecl);
    +   tcase_add_test__if_xml_ge(tc_basic, test_reset_in_entity);
    +   tcase_add_test(tc_basic, test_resume_invalid_parse);
    +   tcase_add_test(tc_basic, test_resume_resuspended);
    +-- 
    +2.43.0
    +
    diff --git a/meta/recipes-core/expat/expat/CVE-2026-45186-03.patch b/meta/recipes-core/expat/expat/CVE-2026-45186-03.patch
    new file mode 100644
    index 00000000000..2afe6dbebc4
    --- /dev/null
    +++ b/meta/recipes-core/expat/expat/CVE-2026-45186-03.patch
    @@ -0,0 +1,46 @@
    +From 852ab610685b45c62017556c38096d941c154963 Mon Sep 17 00:00:00 2001
    +From: Sebastian Pipping 
    +Date: Mon, 20 Apr 2026 13:44:43 +0200
    +Subject: [PATCH 3/7] tests: Define .attributes the first time around
    +
    +(cherry picked from commit 05307d352a5aa858cdda57ec53a53b597b3a4a82)
    +
    +CVE: CVE-2026-45186
    +Upstream-Status: Backport [https://github.com/libexpat/libexpat/pull/1216/commits/05307d352a5aa858cdda57ec53a53b597b3a4a82]
    +Signed-off-by: Theo Gaige 
    +---
    + tests/basic_tests.c | 10 ++++------
    + 1 file changed, 4 insertions(+), 6 deletions(-)
    +
    +diff --git a/tests/basic_tests.c b/tests/basic_tests.c
    +index 907a458..b0178fc 100644
    +--- a/tests/basic_tests.c
    ++++ b/tests/basic_tests.c
    +@@ -2439,11 +2439,9 @@ START_TEST(test_attributes) {
    +                          {XCS("id"), XCS("one")},
    +                          {NULL, NULL}};
    +   AttrInfo tag_info[] = {{XCS("c"), XCS("3")}, {NULL, NULL}};
    +-  ElementInfo info[] = {{XCS("doc"), 3, 0, XCS("id"), NULL},
    +-                        {XCS("tag"), 1, 0, NULL, NULL},
    ++  ElementInfo info[] = {{XCS("doc"), 3, 0, XCS("id"), doc_info},
    ++                        {XCS("tag"), 1, 0, NULL, tag_info},
    +                         {NULL, 0, 0, NULL, NULL}};
    +-  info[0].attributes = doc_info;
    +-  info[1].attributes = tag_info;
    + 
    +   XML_Parser parser = XML_ParserCreate(NULL);
    +   assert_true(parser != NULL);
    +@@ -5769,8 +5767,8 @@ START_TEST(test_deep_nested_attribute_entity) {
    +            (long unsigned)(N_LINES - 1));
    + 
    +   AttrInfo doc_info[] = {{XCS("name"), XCS("deepText")}, {NULL, NULL}};
    +-  ElementInfo info[] = {{XCS("foo"), 1, 0, NULL, NULL}, {NULL, 0, 0, NULL, NULL}};
    +-  info[0].attributes = doc_info;
    ++  ElementInfo info[]
    ++      = {{XCS("foo"), 1, 0, NULL, doc_info}, {NULL, 0, 0, NULL, NULL}};
    + 
    +   XML_Parser parser = XML_ParserCreate(NULL);
    +   ParserAndElementInfo parserPlusElemenInfo = {parser, info};
    +-- 
    +2.43.0
    +
    diff --git a/meta/recipes-core/expat/expat/CVE-2026-45186-04.patch b/meta/recipes-core/expat/expat/CVE-2026-45186-04.patch
    new file mode 100644
    index 00000000000..f4c7733c70d
    --- /dev/null
    +++ b/meta/recipes-core/expat/expat/CVE-2026-45186-04.patch
    @@ -0,0 +1,32 @@
    +From 89c6acdcd919b64014b180fadec46b0d25760832 Mon Sep 17 00:00:00 2001
    +From: Sebastian Pipping 
    +Date: Mon, 13 Apr 2026 01:34:03 +0200
    +Subject: [PATCH 4/7] tests: Make counting_start_element_handler enforce
    + complete attribute lists
    +
    +(cherry picked from commit 4176aff73840711060913e0ac6aa1168d8ba5c8d)
    +
    +CVE: CVE-2026-45186
    +Upstream-Status: Backport [https://github.com/libexpat/libexpat/pull/1216/commits/4176aff73840711060913e0ac6aa1168d8ba5c8d]
    +Signed-off-by: Theo Gaige 
    +---
    + tests/handlers.c | 3 +++
    + 1 file changed, 3 insertions(+)
    +
    +diff --git a/tests/handlers.c b/tests/handlers.c
    +index 9ff7b35..5e72e8b 100644
    +--- a/tests/handlers.c
    ++++ b/tests/handlers.c
    +@@ -155,6 +155,9 @@ counting_start_element_handler(void *userData, const XML_Char *name,
    +     /* Remember, two entries in atts per attribute (see above) */
    +     atts += 2;
    +   }
    ++
    ++  // Self-test that the test case's list of expected attributes is complete
    ++  assert_true(atts[0] == NULL);
    + }
    + 
    + void XMLCALL
    +-- 
    +2.43.0
    +
    diff --git a/meta/recipes-core/expat/expat/CVE-2026-45186-05.patch b/meta/recipes-core/expat/expat/CVE-2026-45186-05.patch
    new file mode 100644
    index 00000000000..480f941cb6f
    --- /dev/null
    +++ b/meta/recipes-core/expat/expat/CVE-2026-45186-05.patch
    @@ -0,0 +1,32 @@
    +From d352c83afaa3945c964aba74cb60a00822af96d3 Mon Sep 17 00:00:00 2001
    +From: Sebastian Pipping 
    +Date: Sun, 8 Mar 2026 22:14:41 +0100
    +Subject: [PATCH 5/7] lib: Extract a constant for upcoming reuse
    +
    +(cherry picked from commit fb35f2d2040d114f355bae8a7450942533237530)
    +
    +CVE: CVE-2026-45186
    +Upstream-Status: Backport [https://github.com/libexpat/libexpat/pull/1216/commits/fb35f2d2040d114f355bae8a7450942533237530]
    +Signed-off-by: Theo Gaige 
    +---
    + lib/xmlparse.c | 3 ++-
    + 1 file changed, 2 insertions(+), 1 deletion(-)
    +
    +diff --git a/lib/xmlparse.c b/lib/xmlparse.c
    +index 9bc67f3..8d3e8db 100644
    +--- a/lib/xmlparse.c
    ++++ b/lib/xmlparse.c
    +@@ -7708,8 +7708,9 @@ dtdCopy(XML_Parser oldParser, DTD *newDtd, const DTD *oldDtd,
    +       newE->prefix = (PREFIX *)lookup(oldParser, &(newDtd->prefixes),
    +                                       oldE->prefix->name, 0);
    +     for (i = 0; i < newE->nDefaultAtts; i++) {
    ++      const XML_Char *const attributeName = oldE->defaultAtts[i].id->name;
    +       newE->defaultAtts[i].id = (ATTRIBUTE_ID *)lookup(
    +-          oldParser, &(newDtd->attributeIds), oldE->defaultAtts[i].id->name, 0);
    ++          oldParser, &(newDtd->attributeIds), attributeName, 0);
    +       newE->defaultAtts[i].isCdata = oldE->defaultAtts[i].isCdata;
    +       if (oldE->defaultAtts[i].value) {
    +         newE->defaultAtts[i].value
    +-- 
    +2.43.0
    +
    diff --git a/meta/recipes-core/expat/expat/CVE-2026-45186-06.patch b/meta/recipes-core/expat/expat/CVE-2026-45186-06.patch
    new file mode 100644
    index 00000000000..d39eb91f2f1
    --- /dev/null
    +++ b/meta/recipes-core/expat/expat/CVE-2026-45186-06.patch
    @@ -0,0 +1,87 @@
    +From a2c8ddb3d6f4df7af64e05bed4b3a4edeae33fd0 Mon Sep 17 00:00:00 2001
    +From: Sebastian Pipping 
    +Date: Sun, 8 Mar 2026 23:05:49 +0100
    +Subject: [PATCH 6/7] lib: Introduce ELEMENT_TYPE.defaultAttsNames
    +
    +(cherry picked from commit 7f0f1b9e70d937072d2e9e37ae9edf27784cc080)
    +
    +CVE: CVE-2026-45186
    +Upstream-Status: Backport [https://github.com/libexpat/libexpat/pull/1216/commits/7f0f1b9e70d937072d2e9e37ae9edf27784cc080]
    +Signed-off-by: Theo Gaige 
    +---
    + lib/xmlparse.c | 17 +++++++++++++++++
    + 1 file changed, 17 insertions(+)
    +
    +diff --git a/lib/xmlparse.c b/lib/xmlparse.c
    +index 8d3e8db..4a29c18 100644
    +--- a/lib/xmlparse.c
    ++++ b/lib/xmlparse.c
    +@@ -388,6 +388,7 @@ typedef struct {
    +   int nDefaultAtts;
    +   int allocDefaultAtts;
    +   DEFAULT_ATTRIBUTE *defaultAtts;
    ++  HASH_TABLE defaultAttsNames;
    + } ELEMENT_TYPE;
    + 
    + typedef struct {
    +@@ -3844,6 +3845,8 @@ storeAtts(XML_Parser parser, const ENCODING *enc, const char *attStr,
    +                                          sizeof(ELEMENT_TYPE));
    +     if (! elementType)
    +       return XML_ERROR_NO_MEMORY;
    ++    if (! elementType->defaultAttsNames.parser)
    ++      hashTableInit(&(elementType->defaultAttsNames), parser);
    +     if (parser->m_ns && ! setElementTypePrefix(parser, elementType))
    +       return XML_ERROR_NO_MEMORY;
    +   }
    +@@ -7549,6 +7552,7 @@ dtdReset(DTD *p, XML_Parser parser) {
    +     ELEMENT_TYPE *e = (ELEMENT_TYPE *)hashTableIterNext(&iter);
    +     if (! e)
    +       break;
    ++    hashTableDestroy(&(e->defaultAttsNames));
    +     if (e->allocDefaultAtts != 0)
    +       FREE(parser, e->defaultAtts);
    +   }
    +@@ -7590,6 +7594,7 @@ dtdDestroy(DTD *p, XML_Bool isDocEntity, XML_Parser parser) {
    +     ELEMENT_TYPE *e = (ELEMENT_TYPE *)hashTableIterNext(&iter);
    +     if (! e)
    +       break;
    ++    hashTableDestroy(&(e->defaultAttsNames));
    +     if (e->allocDefaultAtts != 0)
    +       FREE(parser, e->defaultAtts);
    +   }
    +@@ -7683,6 +7688,10 @@ dtdCopy(XML_Parser oldParser, DTD *newDtd, const DTD *oldDtd,
    +                                   sizeof(ELEMENT_TYPE));
    +     if (! newE)
    +       return 0;
    ++
    ++    if (! newE->defaultAttsNames.parser)
    ++      hashTableInit(&(newE->defaultAttsNames), parser);
    ++
    +     if (oldE->nDefaultAtts) {
    +       /* Detect and prevent integer overflow.
    +        * The preprocessor guard addresses the "always false" warning
    +@@ -7719,6 +7728,12 @@ dtdCopy(XML_Parser oldParser, DTD *newDtd, const DTD *oldDtd,
    +           return 0;
    +       } else
    +         newE->defaultAtts[i].value = NULL;
    ++
    ++      NAMED *const nameAddedOrFound = (NAMED *)lookup(
    ++          parser, &(newE->defaultAttsNames), attributeName, sizeof(NAMED));
    ++      if (! nameAddedOrFound) {
    ++        return 0;
    ++      }
    +     }
    +   }
    + 
    +@@ -8458,6 +8473,8 @@ getElementType(XML_Parser parser, const ENCODING *enc, const char *ptr,
    +                                sizeof(ELEMENT_TYPE));
    +   if (! ret)
    +     return NULL;
    ++  if (! ret->defaultAttsNames.parser)
    ++    hashTableInit(&(ret->defaultAttsNames), getRootParserOf(parser, NULL));
    +   if (ret->name != name)
    +     poolDiscard(&dtd->pool);
    +   else {
    +-- 
    +2.43.0
    +
    diff --git a/meta/recipes-core/expat/expat/CVE-2026-45186-07.patch b/meta/recipes-core/expat/expat/CVE-2026-45186-07.patch
    new file mode 100644
    index 00000000000..26c829b5220
    --- /dev/null
    +++ b/meta/recipes-core/expat/expat/CVE-2026-45186-07.patch
    @@ -0,0 +1,52 @@
    +From 0e4829f4be500ce687b37ec82f9650b86c8419c7 Mon Sep 17 00:00:00 2001
    +From: Sebastian Pipping 
    +Date: Sun, 8 Mar 2026 23:06:29 +0100
    +Subject: [PATCH 7/7] lib: Leverage ELEMENT_TYPE.defaultAttsNames for attribute
    + collision detection
    +
    +.. to resolve quadratic runtime behavior
    +
    +(cherry picked from commit 4cd4eb0683e04cd45a2ffc81a08ca2a2663994b5)
    +
    +CVE: CVE-2026-45186
    +Upstream-Status: Backport [https://github.com/libexpat/libexpat/pull/1216/commits/4cd4eb0683e04cd45a2ffc81a08ca2a2663994b5]
    +Signed-off-by: Theo Gaige 
    +---
    + lib/xmlparse.c | 14 ++++++++++----
    + 1 file changed, 10 insertions(+), 4 deletions(-)
    +
    +diff --git a/lib/xmlparse.c b/lib/xmlparse.c
    +index 4a29c18..b3f0b73 100644
    +--- a/lib/xmlparse.c
    ++++ b/lib/xmlparse.c
    +@@ -7177,10 +7177,10 @@ defineAttribute(ELEMENT_TYPE *type, ATTRIBUTE_ID *attId, XML_Bool isCdata,
    +   if (value || isId) {
    +     /* The handling of default attributes gets messed up if we have
    +        a default which duplicates a non-default. */
    +-    int i;
    +-    for (i = 0; i < type->nDefaultAtts; i++)
    +-      if (attId == type->defaultAtts[i].id)
    +-        return 1;
    ++    NAMED *const nameFound
    ++        = (NAMED *)lookup(parser, &(type->defaultAttsNames), attId->name, 0);
    ++    if (nameFound)
    ++      return 1;
    +     if (isId && ! type->idAtt && ! attId->xmlns)
    +       type->idAtt = attId;
    +   }
    +@@ -7227,6 +7227,12 @@ defineAttribute(ELEMENT_TYPE *type, ATTRIBUTE_ID *attId, XML_Bool isCdata,
    +   att->isCdata = isCdata;
    +   if (! isCdata)
    +     attId->maybeTokenized = XML_TRUE;
    ++
    ++  NAMED *const nameAddedOrFound = (NAMED *)lookup(
    ++      parser, &(type->defaultAttsNames), attId->name, sizeof(NAMED));
    ++  if (! nameAddedOrFound)
    ++    return 0;
    ++
    +   type->nDefaultAtts += 1;
    +   return 1;
    + }
    +-- 
    +2.43.0
    +
    diff --git a/meta/recipes-core/expat/expat_2.6.4.bb b/meta/recipes-core/expat/expat_2.6.4.bb
    index f5c3e3fdd2f..3581d94fac4 100644
    --- a/meta/recipes-core/expat/expat_2.6.4.bb
    +++ b/meta/recipes-core/expat/expat_2.6.4.bb
    @@ -54,6 +54,13 @@ SRC_URI = "${GITHUB_BASE_URI}/download/R_${VERSION_TAG}/expat-${PV}.tar.bz2  \
                file://CVE-2026-41080-01.patch \
                file://CVE-2026-41080-02.patch \
                file://CVE-2026-41080-03.patch \
    +           file://CVE-2026-45186-01.patch \
    +           file://CVE-2026-45186-02.patch \
    +           file://CVE-2026-45186-03.patch \
    +           file://CVE-2026-45186-04.patch \
    +           file://CVE-2026-45186-05.patch \
    +           file://CVE-2026-45186-06.patch \
    +           file://CVE-2026-45186-07.patch \
                "
     
     GITHUB_BASE_URI = "https://github.com/libexpat/libexpat/releases/"
    
    From patchwork Mon Jul 20 17:22:55 2026
    Content-Type: text/plain; charset="utf-8"
    MIME-Version: 1.0
    Content-Transfer-Encoding: 7bit
    X-Patchwork-Submitter: Yoann Congal 
    X-Patchwork-Id: 92909
    Return-Path: 
    X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on
    	aws-us-west-2-korg-lkml-1.web.codeaurora.org
    Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org
     (localhost.localdomain [127.0.0.1])
    	by smtp.lore.kernel.org (Postfix) with ESMTP id 227CDC44520
    	for ; Mon, 20 Jul 2026 17:23:47 +0000 (UTC)
    Received: from mail-wm1-f49.google.com (mail-wm1-f49.google.com
     [209.85.128.49])
     by mx.groups.io with SMTP id smtpd.msgproc02-g2.2883.1784568226289836482
     for ;
     Mon, 20 Jul 2026 10:23:46 -0700
    Authentication-Results: mx.groups.io;
     dkim=pass header.i=@smile.fr header.s=google header.b=hV8vkasc;
     spf=pass (domain: smile.fr, ip: 209.85.128.49,
     mailfrom: yoann.congal@smile.fr)
    Received: by mail-wm1-f49.google.com with SMTP id
     5b1f17b1804b1-4954df200ddso17967765e9.0
            for ;
     Mon, 20 Jul 2026 10:23:46 -0700 (PDT)
    DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;
            d=smile.fr; s=google; t=1784568224; x=1785173024;
     darn=lists.openembedded.org;
            h=content-transfer-encoding:mime-version:references:in-reply-to
             :message-id:date:subject:to:from:from:to:cc:subject:date:message-id
             :reply-to:content-type;
            bh=I+lP0RUz3fXrvfZTQAt8vcPdH4EHzwD240pTwFlDSgo=;
            b=hV8vkascvr+0dTjshwOjLQCrWCtU4TnS4/NFqCV9038Uo00cpn1hR43kRWDg4Rgrie
             9ikqWT57phPCipGCKDTizoYi7L+6KBYPqUltp1yPJE2eFLs2BH8gfbDCUR7nEq0XV+bN
             srHmp91nhfwyTlssHFEXke5/tQSMOYYidTcD0=
    X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;
            d=1e100.net; s=20251104; t=1784568224; x=1785173024;
            h=content-transfer-encoding:mime-version:references:in-reply-to
             :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to
             :cc:subject:date:message-id:reply-to:content-type;
            bh=I+lP0RUz3fXrvfZTQAt8vcPdH4EHzwD240pTwFlDSgo=;
            b=Yn6jII4UxWeyUepQ+ffOTGxdb6RZsnAL78jLZkvyn9tUqFTNLv0/+ARE7CiAfw7iPx
             BoLNA4ICGmCcSQAFFIZrpinH2eIoXy/vsExHs40lGcd5unbZKcQUbX6WGdSicji1c2VN
             GNrf879P+d9Rt0qjeNF7tMLtG/xqpPp8v7p1TCqrlr5diXNvig3QDskT7WQl4DqeV2WH
             IzzpqUGg3G/lyxarjXwn71Jh9sncJ90BfoMzgee0De+v5x7ImsaotxNYhGhKAxO9acW9
             AyjUE/Sk7DeH49X6jqYCQBRYrHYB7sNGj3SaPqoEVfEJeowiQ2oqhRb00rcNwsRINFWX
             Y9Qw==
    X-Gm-Message-State: AOJu0YxxYqggDq0SHJ6gKESncw9nDEqZVk9sWJUQjfgIbpZjSStA0Zd2
    	RCPWPt7sbAhtT1XcuoBRj+b0ea4rDw8uPJ6pVKVLq87VvO/ZSMUonKDY5Prinz4ZNDoj2DdFt6U
    	p/dfIjg8=
    X-Gm-Gg: AfdE7cmXMEsaaQw0lnAgmTPx3dQJ7Ixv3FwBl/o8vB5a+U3gl4sNQ8oRn4/g1NalFNq
    	vqRMfXQn+shy73iJ1INJ5QHuD/4m7Ks0+2h9Xf6aPSU1mqgBR42aFl2MlDZLR/Ls4cuoPVN6o1j
    	a1UAT/55ov2aTJ0TYVJgQf46Raq7fg2+3CFiWd2IUzTkB27FYtNUV5rzgcARlHjlJ49ZqFYEIt4
    	ekv3jvu1L9sPi9ULJfcplWw0TF4rZxUc3hxQNi0ELKGqVvhVQ2TmFyE1vaj/Q24zSmZTxELL+Zc
    	bnc31qyqnvXnWlksTiuzQ9URtOUpP1Z0Fn/avovWjmXdt5LSwKpJYgLdNcNlPdU8QRsXQG0jjUH
    	6hRoYFoovUVSJt+z1ij2bLyWj/KRAYbLaPdU75pQ3tgGFwdzADdEwqjaDFgItwh+8beLSb7hlH7
    	xaLwsYnoA1vVYRwm+CY46aYjMAzRZBDhOoEY6ZJnmkWZ4MdO6My0oARCtJ3s0AqMehgei3+HR0O
    	qC+S7bz
    X-Received: by 2002:a05:600c:3baa:b0:493:b730:8d78 with SMTP id
     5b1f17b1804b1-4954a514007mr208606355e9.31.1784568224409;
            Mon, 20 Jul 2026 10:23:44 -0700 (PDT)
    Received: from localhost.localdomain
     (2a02-8440-b501-5b7b-2580-caa3-ecc1-dea5.rev.sfr.net.
     [2a02:8440:b501:5b7b:2580:caa3:ecc1:dea5])
            by smtp.gmail.com with ESMTPSA id
     5b1f17b1804b1-49563eee22esm36508575e9.1.2026.07.20.10.23.43
            for 
            (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256);
            Mon, 20 Jul 2026 10:23:43 -0700 (PDT)
    From: Yoann Congal 
    To: openembedded-core@lists.openembedded.org
    Subject: [OE-core][scarthgap 22/33] libcap: Fix CVE-2026-4878
    Date: Mon, 20 Jul 2026 19:22:55 +0200
    Message-ID: 
     <0488c0247ea017e465608c3a68aa3777b34df327.1784567958.git.yoann.congal@smile.fr>
    X-Mailer: git-send-email 2.47.3
    In-Reply-To: 
    References: 
    MIME-Version: 1.0
    List-Id: 
    X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com
     [45.33.107.173] by
     aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for
     ; Mon, 20 Jul 2026 17:23:47 -0000
    X-Groupsio-URL: 
     https://lists.openembedded.org/g/openembedded-core/message/241456
    
    From: Hugo SIMELIERE (Schneider Electric) 
    
    Pick patch from [1] as mentioned in Debian report in [2].
    
    [1] https://git.kernel.org/pub/scm/libs/libcap/libcap.git/commit/?id=286ace1259992bd0c5d9016715833f2e148ac596
    [2] https://security-tracker.debian.org/tracker/CVE-2026-4878
    
    Signed-off-by: Hugo SIMELIERE (Schneider Electric) 
    Reviewed-by: Bruno VERNAY 
    Signed-off-by: Yoann Congal 
    ---
     .../libcap/files/CVE-2026-4878.patch          | 164 ++++++++++++++++++
     meta/recipes-support/libcap/libcap_2.69.bb    |   1 +
     2 files changed, 165 insertions(+)
     create mode 100644 meta/recipes-support/libcap/files/CVE-2026-4878.patch
    
    diff --git a/meta/recipes-support/libcap/files/CVE-2026-4878.patch b/meta/recipes-support/libcap/files/CVE-2026-4878.patch
    new file mode 100644
    index 00000000000..dcc63d93a54
    --- /dev/null
    +++ b/meta/recipes-support/libcap/files/CVE-2026-4878.patch
    @@ -0,0 +1,164 @@
    +From f17734c6b0f4fd102fe4f7e863cb1165f8ec66e2 Mon Sep 17 00:00:00 2001
    +From: "Andrew G. Morgan" 
    +Date: Thu, 12 Mar 2026 07:38:05 -0700
    +Subject: [PATCH] Address a potential TOCTOU race condition in cap_set_file().
    +
    +This issue was researched and reported by Ali Raza (@locus-x64). It
    +has been assigned CVE-2026-4878.
    +
    +The finding is that while cap_set_file() checks if a file is a regular
    +file before applying or removing a capability attribute, a small
    +window existed after that check when the filepath could be overwritten
    +either with new content or a symlink to some other file. To do this
    +would imply that the caller of cap_set_file() was directing it to a
    +directory over which a local attacker has write access, and performed
    +the operation frequently enough that an attacker had a non-negligible
    +chance of exploiting the race condition. The code now locks onto the
    +intended file, eliminating the race condition.
    +
    +CVE: CVE-2026-4878
    +Upstream-Status: Backport [https://git.kernel.org/pub/scm/libs/libcap/libcap.git/commit/?id=286ace1259992bd0c5d9016715833f2e148ac596]
    +
    +Signed-off-by: Andrew G. Morgan 
    +(cherry picked from commit 286ace1259992bd0c5d9016715833f2e148ac596)
    +Signed-off-by: Hugo SIMELIERE (Schneider Electric) 
    +---
    + libcap/cap_file.c  | 69 +++++++++++++++++++++++++++++++++++++++-------
    + progs/quicktest.sh | 14 +++++++++-
    + 2 files changed, 72 insertions(+), 11 deletions(-)
    +
    +diff --git a/libcap/cap_file.c b/libcap/cap_file.c
    +index 0bc07f7..f02bf9f 100644
    +--- a/libcap/cap_file.c
    ++++ b/libcap/cap_file.c
    +@@ -8,8 +8,13 @@
    + #define _DEFAULT_SOURCE
    + #endif
    + 
    ++#ifndef _GNU_SOURCE
    ++#define _GNU_SOURCE
    ++#endif
    ++
    + #include 
    + #include 
    ++#include 
    + #include 
    + #include 
    + 
    +@@ -322,26 +327,70 @@ int cap_set_file(const char *filename, cap_t cap_d)
    +     struct vfs_ns_cap_data rawvfscap;
    +     int sizeofcaps;
    +     struct stat buf;
    ++    char fdpath[64];
    ++    int fd, ret;
    ++
    ++    _cap_debug("setting filename capabilities");
    ++    fd = open(filename, O_RDONLY|O_NOFOLLOW);
    ++    if (fd >= 0) {
    ++	ret = cap_set_fd(fd, cap_d);
    ++	close(fd);
    ++	return ret;
    ++    }
    + 
    +-    if (lstat(filename, &buf) != 0) {
    +-	_cap_debug("unable to stat file [%s]", filename);
    ++    /*
    ++     * Attempting to set a file capability on a file the process can't
    ++     * read the content of. This is considered a non-standard use case
    ++     * and the following (slower) code is complicated because it is
    ++     * trying to avoid a TOCTOU race condition.
    ++     */
    ++
    ++    fd = open(filename, O_PATH|O_NOFOLLOW);
    ++    if (fd < 0) {
    ++	_cap_debug("cannot find file at path [%s]", filename);
    ++	return -1;
    ++    }
    ++    if (fstat(fd, &buf) != 0) {
    ++	_cap_debug("unable to stat file [%s] descriptor %d",
    ++		   filename, fd);
    ++	close(fd);
    + 	return -1;
    +     }
    +     if (S_ISLNK(buf.st_mode) || !S_ISREG(buf.st_mode)) {
    +-	_cap_debug("file [%s] is not a regular file", filename);
    ++	_cap_debug("file [%s] descriptor %d for non-regular file",
    ++		   filename, fd);
    ++	close(fd);
    + 	errno = EINVAL;
    + 	return -1;
    +     }
    + 
    +-    if (cap_d == NULL) {
    +-	_cap_debug("removing filename capabilities");
    +-	return removexattr(filename, XATTR_NAME_CAPS);
    ++    /*
    ++     * While the fd remains open, this named file is locked to the
    ++     * origin regular file. The size of the fdpath variable is
    ++     * sufficient to support a 160+ bit number.
    ++     */
    ++    if (snprintf(fdpath, sizeof(fdpath), "/proc/self/fd/%d", fd)
    ++	>= sizeof(fdpath)) {
    ++	_cap_debug("file descriptor too large %d", fd);
    ++	errno = EINVAL;
    ++	ret = -1;
    ++
    ++    } else if (cap_d == NULL) {
    ++	_cap_debug("dropping file caps on [%s] via [%s]",
    ++		   filename, fdpath);
    ++	ret = removexattr(fdpath, XATTR_NAME_CAPS);
    ++
    +     } else if (_fcaps_save(&rawvfscap, cap_d, &sizeofcaps) != 0) {
    +-	return -1;
    +-    }
    ++	_cap_debug("problem converting cap_d to vfscap format");
    ++	ret = -1;
    + 
    +-    _cap_debug("setting filename capabilities");
    +-    return setxattr(filename, XATTR_NAME_CAPS, &rawvfscap, sizeofcaps, 0);
    ++    } else {
    ++	_cap_debug("setting filename capabilities");
    ++	ret = setxattr(fdpath, XATTR_NAME_CAPS, &rawvfscap,
    ++		       sizeofcaps, 0);
    ++    }
    ++    close(fd);
    ++    return ret;
    + }
    + 
    + /*
    +diff --git a/progs/quicktest.sh b/progs/quicktest.sh
    +index 59e16b0..bb49d53 100755
    +--- a/progs/quicktest.sh
    ++++ b/progs/quicktest.sh
    +@@ -148,7 +148,19 @@ pass_capsh --caps="cap_setpcap=p" --inh=cap_chown --current
    + pass_capsh --strict --caps="cap_chown=p" --inh=cap_chown --current
    + 
    + # change the way the capability is obtained (make it inheritable)
    ++chmod 0000 ./privileged
    + ./setcap cap_setuid,cap_setgid=ei ./privileged
    ++if [ $? -ne 0 ]; then
    ++    echo "FAILED to set file capability"
    ++    exit 1
    ++fi
    ++chmod 0755 ./privileged
    ++ln -s privileged unprivileged
    ++./setcap -r ./unprivileged
    ++if [ $? -eq 0 ]; then
    ++    echo "FAILED by removing a capability from a symlinked file"
    ++    exit 1
    ++fi
    + 
    + # Note, the bounding set (edited with --drop) only limits p
    + # capabilities, not i's.
    +@@ -246,7 +258,7 @@ EOF
    +     pass_capsh --iab='!%cap_chown,^cap_setpcap,cap_setuid'
    +     fail_capsh --mode=PURE1E --iab='!%cap_chown,^cap_setuid'
    + fi
    +-/bin/rm -f ./privileged
    ++/bin/rm -f ./privileged ./unprivileged
    + 
    + echo "testing namespaced file caps"
    + 
    +-- 
    +2.43.0
    +
    diff --git a/meta/recipes-support/libcap/libcap_2.69.bb b/meta/recipes-support/libcap/libcap_2.69.bb
    index 03975b44a0a..43185f027ea 100644
    --- a/meta/recipes-support/libcap/libcap_2.69.bb
    +++ b/meta/recipes-support/libcap/libcap_2.69.bb
    @@ -16,6 +16,7 @@ SRC_URI = "${KERNELORG_MIRROR}/linux/libs/security/linux-privs/${BPN}2/${BPN}-${
                file://0001-ensure-the-XATTR_NAME_CAPS-is-defined-when-it-is-use.patch \
                file://0002-tests-do-not-run-target-executables.patch \
                file://CVE-2025-1390.patch \
    +           file://CVE-2026-4878.patch \
                "
     SRC_URI:append:class-nativesdk = " \
                file://0001-nativesdk-libcap-Raise-the-size-of-arrays-containing.patch \
    
    From patchwork Mon Jul 20 17:22:56 2026
    Content-Type: text/plain; charset="utf-8"
    MIME-Version: 1.0
    Content-Transfer-Encoding: 7bit
    X-Patchwork-Submitter: Yoann Congal 
    X-Patchwork-Id: 92921
    Return-Path: 
    X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on
    	aws-us-west-2-korg-lkml-1.web.codeaurora.org
    Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org
     (localhost.localdomain [127.0.0.1])
    	by smtp.lore.kernel.org (Postfix) with ESMTP id 0436BC44536
    	for ; Mon, 20 Jul 2026 17:23:48 +0000 (UTC)
    Received: from mail-wm1-f44.google.com (mail-wm1-f44.google.com
     [209.85.128.44])
     by mx.groups.io with SMTP id smtpd.msgproc01-g2.2902.1784568226887465504
     for ;
     Mon, 20 Jul 2026 10:23:47 -0700
    Authentication-Results: mx.groups.io;
     dkim=pass header.i=@smile.fr header.s=google header.b=GCYoB0ZE;
     spf=pass (domain: smile.fr, ip: 209.85.128.44,
     mailfrom: yoann.congal@smile.fr)
    Received: by mail-wm1-f44.google.com with SMTP id
     5b1f17b1804b1-49556f97a9dso12150065e9.1
            for ;
     Mon, 20 Jul 2026 10:23:46 -0700 (PDT)
    DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;
            d=smile.fr; s=google; t=1784568225; x=1785173025;
     darn=lists.openembedded.org;
            h=content-transfer-encoding:mime-version:references:in-reply-to
             :message-id:date:subject:to:from:from:to:cc:subject:date:message-id
             :reply-to:content-type;
            bh=sAO6CyqYgqRsvW8ITtRSfMMxQELK4vJtVHEotc4N/u4=;
            b=GCYoB0ZEGVIanLWc+gr2BW3df2pPzZoJ0Ft+/XcSbYx2RHAx392muo1xEB5nHgGZCx
             woNVAR0uq3LFgVpN0P5L/ExhuNxvO0wkUHtt+p2Xv7NQz4w3C1Ub+Paovm1JrddT816e
             5Sv8UWFzNp0TpE/5qlFxK1Uyo1xf6PlN/DPrU=
    X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;
            d=1e100.net; s=20251104; t=1784568225; x=1785173025;
            h=content-transfer-encoding:mime-version:references:in-reply-to
             :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to
             :cc:subject:date:message-id:reply-to:content-type;
            bh=sAO6CyqYgqRsvW8ITtRSfMMxQELK4vJtVHEotc4N/u4=;
            b=RyARFAL28TYCImVi7MnTODfdEkBNOUyCslHolO2X9dagOlgij62WlJIbKZaJkTjR5u
             8AMqJJktSsdrKJS1oeX4eLo5NXofqixlWTJdVmasTyxvx4PAR1eisk/+XL55nxNpKGXM
             ck6/dUoHjkGZE4QSsq2IawEtDj6hFLdyXJZRa8tQ4tRQ0nS1B44suqRSIsPOKBD6yR7a
             MAlcVudkA7qL44OmFZqcfhKpUL8brCiRFW5vF9ruGVCE4VokGsK+L3mJ7RQZdyw4SEbe
             oB8wGSaC5R5Yr3IoGi3stYyi2KBBriAeQba8vkd5zqeBgJSheESEYIdIj9kZcuZHMgO8
             rrfg==
    X-Gm-Message-State: AOJu0YybOOzm42I67PonvMqFWjZMEnk3MNoqW4HJrdTiX5xcafjJolak
    	UEKXn8fGcXe1YmpkSJNdJPElY0bF7sDHnbvEWzdCgIDdIGEIUsPlc3+7IZk3XHEjIsegLKAE52b
    	H/vmtp5Q=
    X-Gm-Gg: AfdE7clHO9cr3k59jn1IDpE2c83mMXOa3wJiyqsjGll50/g/+QkSx58MM7lX6qB0y3A
    	iI+qy+ptd4UYzDQrs8Oko5WJIn1cPkxC5CTkqkkDAje/JNhiWO5Ozho7apAadVHiEbYyf096TIP
    	zztIKNPjozadhkD2E9RE+a14VHVkLlY4soilmkerCbVk5NT/sd4zeJCOrHEdMvJ0HApK2fFV6MZ
    	zO2M3uq91ycUfOJx34MTT6/F81oRmes6aslUkLr5Sl3UeD3CEG+4fLUlCA25E9t9R1ZldQRRX0w
    	6knq9xfQSec7GpxfRwKH9x34QgVABKLxnTSufGESFcmjja0NdkuIQKwxxOBA1JTl39vcoxqAOny
    	KC5IvRZCLu8ZNGVdTSHKIUAMBtwVDu3wVwgNMl/V3IDeE2qpNUfL9Z0S+s/0wE2muGokfoQkpTR
    	m2h7u8DL7QPww4XbGeqQDf5goXtHb5C9u4QXNESkdd1akuSxFpbyvhmoDKCUmd3B3Z0ZEQyTET3
    	iwsx4sR
    X-Received: by 2002:a05:600c:6d82:b0:495:4072:4194 with SMTP id
     5b1f17b1804b1-4954a40c4acmr116040575e9.28.1784568225067;
            Mon, 20 Jul 2026 10:23:45 -0700 (PDT)
    Received: from localhost.localdomain
     (2a02-8440-b501-5b7b-2580-caa3-ecc1-dea5.rev.sfr.net.
     [2a02:8440:b501:5b7b:2580:caa3:ecc1:dea5])
            by smtp.gmail.com with ESMTPSA id
     5b1f17b1804b1-49563eee22esm36508575e9.1.2026.07.20.10.23.44
            for 
            (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256);
            Mon, 20 Jul 2026 10:23:44 -0700 (PDT)
    From: Yoann Congal 
    To: openembedded-core@lists.openembedded.org
    Subject: [OE-core][scarthgap 23/33] python3-urllib3: fix CVE-2026-44431
    Date: Mon, 20 Jul 2026 19:22:56 +0200
    Message-ID: 
     
    X-Mailer: git-send-email 2.47.3
    In-Reply-To: 
    References: 
    MIME-Version: 1.0
    List-Id: 
    X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com
     [45.33.107.173] by
     aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for
     ; Mon, 20 Jul 2026 17:23:48 -0000
    X-Groupsio-URL: 
     https://lists.openembedded.org/g/openembedded-core/message/241457
    
    From: Sudhir Dumbhare 
    
    Applies the upstream fix [1] referenced in [2] and addresses the
    sensitive-header redirect handling issue in proxied low-level urllib3 requests.
    
    [1] https://github.com/urllib3/urllib3/commit/5ec0de499b9166ca71c65ab04f2a7e4eb0d66fcc
    [2] https://ubuntu.com/security/CVE-2026-44431
    
    References:
    https://nvd.nist.gov/vuln/detail/CVE-2026-44431
    
    Signed-off-by: Sudhir Dumbhare 
    Signed-off-by: Yoann Congal 
    ---
     .../python3-urllib3/CVE-2026-44431.patch      | 163 ++++++++++++++++++
     .../python/python3-urllib3_2.2.2.bb           |   1 +
     2 files changed, 164 insertions(+)
     create mode 100644 meta/recipes-devtools/python/python3-urllib3/CVE-2026-44431.patch
    
    diff --git a/meta/recipes-devtools/python/python3-urllib3/CVE-2026-44431.patch b/meta/recipes-devtools/python/python3-urllib3/CVE-2026-44431.patch
    new file mode 100644
    index 00000000000..042b46f47a2
    --- /dev/null
    +++ b/meta/recipes-devtools/python/python3-urllib3/CVE-2026-44431.patch
    @@ -0,0 +1,163 @@
    +From d5517b0ab50030a8f389757b3ba648633c504cbc Mon Sep 17 00:00:00 2001
    +From: Illia Volochii 
    +Date: Thu, 7 May 2026 18:40:31 +0300
    +Subject: [PATCH] Merge commit from fork
    +
    +* Remove sensitive headers in proxy pools too
    +
    +* Add a changelog entry
    +
    +* Check retries history in tests
    +
    +CVE: CVE-2026-44431
    +Upstream-Status: Backport [https://github.com/urllib3/urllib3/commit/5ec0de499b9166ca71c65ab04f2a7e4eb0d66fcc]
    +
    +Co-authored-by: Copilot 
    +
    +---------
    +
    +Co-authored-by: Copilot 
    +(cherry picked from commit 5ec0de499b9166ca71c65ab04f2a7e4eb0d66fcc)
    +Signed-off-by: Sudhir Dumbhare 
    +---
    + changelog/GHSA-qccp-gfcp-xxvc.bugfix.rst      |  3 +
    + dummyserver/asgi_proxy.py                     |  1 +
    + src/urllib3/connectionpool.py                 | 12 ++++
    + .../test_proxy_poolmanager.py                 | 72 +++++++++++++++++++
    + 4 files changed, 88 insertions(+)
    + create mode 100644 changelog/GHSA-qccp-gfcp-xxvc.bugfix.rst
    +
    +diff --git a/changelog/GHSA-qccp-gfcp-xxvc.bugfix.rst b/changelog/GHSA-qccp-gfcp-xxvc.bugfix.rst
    +new file mode 100644
    +index 00000000..bac765ea
    +--- /dev/null
    ++++ b/changelog/GHSA-qccp-gfcp-xxvc.bugfix.rst
    +@@ -0,0 +1,3 @@
    ++Fixed HTTP pools created using ``ProxyManager.connection_from_url`` to strip
    ++sensitive headers specified in ``Retry.remove_headers_on_redirect`` when
    ++redirecting to a different host.
    +diff --git a/dummyserver/asgi_proxy.py b/dummyserver/asgi_proxy.py
    +index 107c5e0a..094807cd 100755
    +--- a/dummyserver/asgi_proxy.py
    ++++ b/dummyserver/asgi_proxy.py
    +@@ -52,6 +52,7 @@ class ProxyApp:
    +             client_response = await client.request(
    +                 method=scope["method"],
    +                 url=scope["path"],
    ++                params=scope["query_string"].decode(),
    +                 headers=list(scope["headers"]),
    +                 content=await _read_body(receive),
    +             )
    +diff --git a/src/urllib3/connectionpool.py b/src/urllib3/connectionpool.py
    +index a2c3cf60..f64ee2f8 100644
    +--- a/src/urllib3/connectionpool.py
    ++++ b/src/urllib3/connectionpool.py
    +@@ -898,6 +898,18 @@ class HTTPConnectionPool(ConnectionPool, RequestMethods):
    +                 body = None
    +                 headers = HTTPHeaderDict(headers)._prepare_for_method_change()
    + 
    ++            # Strip headers marked as unsafe to forward to the redirected location.
    ++            # Check remove_headers_on_redirect to avoid a potential network call within
    ++            # self.is_same_host() which may use socket.gethostbyname() in the future.
    ++            if retries.remove_headers_on_redirect and not self.is_same_host(
    ++                redirect_location
    ++            ):
    ++                new_headers = headers.copy()  # type: ignore[union-attr]
    ++                for header in headers:
    ++                    if header.lower() in retries.remove_headers_on_redirect:
    ++                        new_headers.pop(header, None)
    ++                headers = new_headers
    ++
    +             try:
    +                 retries = retries.increment(method, url, response=response, _pool=self)
    +             except MaxRetryError:
    +diff --git a/test/with_dummyserver/test_proxy_poolmanager.py b/test/with_dummyserver/test_proxy_poolmanager.py
    +index 397181a9..a0b11726 100644
    +--- a/test/with_dummyserver/test_proxy_poolmanager.py
    ++++ b/test/with_dummyserver/test_proxy_poolmanager.py
    +@@ -37,6 +37,7 @@ from urllib3.exceptions import (
    +     SSLError,
    + )
    + from urllib3.poolmanager import ProxyManager, proxy_from_url
    ++from urllib3.util.retry import RequestHistory
    + from urllib3.util.ssl_ import create_urllib3_context
    + from urllib3.util.timeout import Timeout
    + 
    +@@ -299,6 +300,77 @@ class TestHTTPProxyManager(HypercornDummyProxyTestCase):
    +             assert r._pool is not None
    +             assert r._pool.host != self.http_host_alt
    + 
    ++    _sensitive_headers = {
    ++        "Authorization": "foo",
    ++        "Proxy-Authorization": "bar",
    ++        "Cookie": "foo=bar",
    ++    }
    ++
    ++    @pytest.mark.parametrize(
    ++        "sensitive_headers",
    ++        (_sensitive_headers, {k.lower(): v for k, v in _sensitive_headers.items()}),
    ++        ids=("capitalized", "lowercase"),
    ++    )
    ++    def test_cross_host_redirect_remove_headers_via_proxy_manager(
    ++        self, sensitive_headers: dict[str, str]
    ++    ) -> None:
    ++        headers_url = f"{self.http_url_alt}/headers"
    ++        initial_url = f"{self.http_url}/redirect?target={headers_url}"
    ++        with proxy_from_url(self.proxy_url) as proxy_mgr:
    ++            r = proxy_mgr.request(
    ++                "GET", initial_url, headers=sensitive_headers, retries=1
    ++            )
    ++            assert r.status == 200
    ++            assert r.retries is not None
    ++            assert r.retries.history == (
    ++                RequestHistory(
    ++                    method="GET",
    ++                    url=initial_url,
    ++                    error=None,
    ++                    status=303,
    ++                    redirect_location=headers_url,
    ++                ),
    ++            )
    ++            data = r.json()
    ++            for header in sensitive_headers:
    ++                assert header not in data
    ++
    ++    @pytest.mark.parametrize(
    ++        "sensitive_headers",
    ++        (_sensitive_headers, {k.lower(): v for k, v in _sensitive_headers.items()}),
    ++        ids=("capitalized", "lowercase"),
    ++    )
    ++    def test_cross_host_redirect_remove_headers_via_pool(
    ++        self, sensitive_headers: dict[str, str]
    ++    ) -> None:
    ++        headers_url = f"{self.http_url_alt}/headers"
    ++        initial_url = f"{self.http_url}/redirect?target={headers_url}"
    ++        with proxy_from_url(self.proxy_url) as proxy_mgr:
    ++            pool = proxy_mgr.connection_from_url(self.http_url)
    ++            r = pool.urlopen(
    ++                "GET",
    ++                initial_url,
    ++                headers=sensitive_headers,
    ++                retries=1,
    ++                redirect=True,
    ++                assert_same_host=False,
    ++                preload_content=True,
    ++            )
    ++            assert r.status == 200
    ++            assert r.retries is not None
    ++            assert r.retries.history == (
    ++                RequestHistory(
    ++                    method="GET",
    ++                    url=initial_url,
    ++                    error=None,
    ++                    status=303,
    ++                    redirect_location=headers_url,
    ++                ),
    ++            )
    ++            data = r.json()
    ++            for header in sensitive_headers:
    ++                assert header not in data
    ++
    +     def test_cross_protocol_redirect(self) -> None:
    +         with proxy_from_url(self.proxy_url, ca_certs=DEFAULT_CA) as http:
    +             cross_protocol_location = f"{self.https_url}/echo?a=b"
    diff --git a/meta/recipes-devtools/python/python3-urllib3_2.2.2.bb b/meta/recipes-devtools/python/python3-urllib3_2.2.2.bb
    index f6ac8f89cad..b77dd5297d3 100644
    --- a/meta/recipes-devtools/python/python3-urllib3_2.2.2.bb
    +++ b/meta/recipes-devtools/python/python3-urllib3_2.2.2.bb
    @@ -12,6 +12,7 @@ SRC_URI += " \
         file://CVE-2025-66418.patch \
         file://CVE-2025-66471.patch \
         file://CVE-2026-21441.patch \
    +    file://CVE-2026-44431.patch \
     "
     
     RDEPENDS:${PN} += "\
    
    From patchwork Mon Jul 20 17:22:57 2026
    Content-Type: text/plain; charset="utf-8"
    MIME-Version: 1.0
    Content-Transfer-Encoding: 7bit
    X-Patchwork-Submitter: Yoann Congal 
    X-Patchwork-Id: 92920
    Return-Path: 
    X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on
    	aws-us-west-2-korg-lkml-1.web.codeaurora.org
    Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org
     (localhost.localdomain [127.0.0.1])
    	by smtp.lore.kernel.org (Postfix) with ESMTP id 0ECDDC44538
    	for ; Mon, 20 Jul 2026 17:23:48 +0000 (UTC)
    Received: from mail-wm1-f45.google.com (mail-wm1-f45.google.com
     [209.85.128.45])
     by mx.groups.io with SMTP id smtpd.msgproc01-g2.2903.1784568227444462386
     for ;
     Mon, 20 Jul 2026 10:23:47 -0700
    Authentication-Results: mx.groups.io;
     dkim=pass header.i=@smile.fr header.s=google header.b=0GxERII2;
     spf=pass (domain: smile.fr, ip: 209.85.128.45,
     mailfrom: yoann.congal@smile.fr)
    Received: by mail-wm1-f45.google.com with SMTP id
     5b1f17b1804b1-4955adb04e8so11203785e9.2
            for ;
     Mon, 20 Jul 2026 10:23:47 -0700 (PDT)
    DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;
            d=smile.fr; s=google; t=1784568226; x=1785173026;
     darn=lists.openembedded.org;
            h=content-transfer-encoding:mime-version:references:in-reply-to
             :message-id:date:subject:to:from:from:to:cc:subject:date:message-id
             :reply-to:content-type;
            bh=6P4b2xFrZA5PW9Wjq5jccZUu0E1JnecgpqDMNsDubsE=;
            b=0GxERII28CCX9M/cLYqPwFNgz2dt15CDSwuYQw3dvv8qHo7l1LGibhi54ocGZvSb3U
             OsOphThp/sJzUO32b+qaiKFmcfx3BYz4dSrbI23II6wcl2GI+AorCCTMUeYt6vvKkMET
             la6e8ihYqZBsG20vtzV4a+JvGDL4S9apmleL8=
    X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;
            d=1e100.net; s=20251104; t=1784568226; x=1785173026;
            h=content-transfer-encoding:mime-version:references:in-reply-to
             :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to
             :cc:subject:date:message-id:reply-to:content-type;
            bh=6P4b2xFrZA5PW9Wjq5jccZUu0E1JnecgpqDMNsDubsE=;
            b=OhpjC7tK9UuZAXu6G6QPPeS0UO7/IrdnhzNp01fvZzZMQfBwrZrIAlTmlAjjNqQQZq
             utu1Tq9q7pjkfx5tV7b8JQ6NZ9XMLonRqH4rmi81NYAQy9Ck5GrnzcKWiwqkHblzHZzr
             6lvhDmyzw/NNlv44jKbU7qByB6gEuyjq23zCRP+oVnhKyG7yMYh12tHCKQXl8K113dW3
             RzIUFnYNdREhs52prPd3KzsirNBPFRjks4FGZs9z6rBCWT2SxLgg4/etYsIKqSq9AoDi
             VLmGgVdCIStDTni1/PGzu8YwdJzb/Z2O1hDPdtSND+sVOWlapuPOPiAfKgvpBonJgtIW
             Wbqw==
    X-Gm-Message-State: AOJu0Yw0jDerS9UlAjMWz/Y2h6j9jax7sLe72GoPwtcwvawwkTDRmSSq
    	1I7EmClIgdar64PGwyWSSlkVz14DnakLaDVDcAr04LSwgjigzjDb7+s8ekxnZFwkj6Z77Xqn3OR
    	YU0nqqWg=
    X-Gm-Gg: AfdE7ckKNYf2aJge+31y5D1HCP2f+dyHS3OEtDm1TOjFkcXOvPWeTc1xJ6PXv7W7qBe
    	WWE+1mOJw4QWDaYTQ1/mfFEdfRD4cY3bH5BK6gvGdPWYP5REEXaenyf707JswYxU54GiDJzqP84
    	7pqTmnF25cLENIR8dLp7MWgmGTCc7PAPSCrX259ctW5m042ieGRlH92PaCRGo6obgE6jm7GwrI+
    	gUahm4fRxtxo7dZ1u/daezhbWXsZ9jANRjsEhzaZKDIUEeDxV5zEm9Pn2az7IfEnYf4ivNcxQ1O
    	sOvH+WHYUgWwNjTcXRg7LZH7611IfWcVZNMS4uSjpvzTtwSPF4YiBLQynP96JGBXScT97v6226i
    	/jTzQQaEgd4vq04YS7rnq6grRUbqI8kOqSZyf02Ka+AIZ2MMy0RLlda8XzlNkSeoEKMTVO39J2Y
    	osEqZznG3c/W/g/jSSHIPqUWMxBYBWAooDESw7RVEN9L/j78AW/yJVfleACx/9SBLomntoJHIoN
    	0f4TWgv
    X-Received: by 2002:a05:600c:3b8e:b0:495:4bf3:2150 with SMTP id
     5b1f17b1804b1-4954bf3216amr183618195e9.8.1784568225653;
            Mon, 20 Jul 2026 10:23:45 -0700 (PDT)
    Received: from localhost.localdomain
     (2a02-8440-b501-5b7b-2580-caa3-ecc1-dea5.rev.sfr.net.
     [2a02:8440:b501:5b7b:2580:caa3:ecc1:dea5])
            by smtp.gmail.com with ESMTPSA id
     5b1f17b1804b1-49563eee22esm36508575e9.1.2026.07.20.10.23.45
            for 
            (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256);
            Mon, 20 Jul 2026 10:23:45 -0700 (PDT)
    From: Yoann Congal 
    To: openembedded-core@lists.openembedded.org
    Subject: [OE-core][scarthgap 24/33] wic: Fix updating fstab for nvme devices
    Date: Mon, 20 Jul 2026 19:22:57 +0200
    Message-ID: 
     <09b3f0068398268f46670a685fc6df78adf757f7.1784567958.git.yoann.congal@smile.fr>
    X-Mailer: git-send-email 2.47.3
    In-Reply-To: 
    References: 
    MIME-Version: 1.0
    List-Id: 
    X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com
     [45.33.107.173] by
     aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for
     ; Mon, 20 Jul 2026 17:23:48 -0000
    X-Groupsio-URL: 
     https://lists.openembedded.org/g/openembedded-core/message/241458
    
    From: Aleksandar Nikolic 
    
    In case wks file references nvme, update_fstab() function will not add
    prefix 'p' before the partition number, as the if condition only takes
    mmcblk into consideration.
    
    In case of nvme0n1 this leads that following entries are added to fstab:
    
        /dev/nvme0n11
        /dev/nvme0n13
    
    instead of:
    
        /dev/nvme0n1p1
        /dev/nvme0n1p3
    
    The patch fixes this as it extends the if condition and adds prefix 'p' for
    both mmcblk and nvme.
    
    Upstream-Status: Backport [https://git.yoctoproject.org/wic/commit/?id=f20cda73b495b75ef399c331f59b0e2401a3e76a]
    Signed-off-by: Aleksandar Nikolic 
    Signed-off-by: Yoann Congal 
    ---
     scripts/lib/wic/plugins/imager/direct.py | 6 +++---
     1 file changed, 3 insertions(+), 3 deletions(-)
    
    diff --git a/scripts/lib/wic/plugins/imager/direct.py b/scripts/lib/wic/plugins/imager/direct.py
    index a1d152659b6..b06e6a8f236 100644
    --- a/scripts/lib/wic/plugins/imager/direct.py
    +++ b/scripts/lib/wic/plugins/imager/direct.py
    @@ -133,8 +133,8 @@ class DirectPlugin(ImagerPlugin):
                 elif part.use_label:
                     device_name = "LABEL=%s" % part.label
                 else:
    -                # mmc device partitions are named mmcblk0p1, mmcblk0p2..
    -                prefix = 'p' if  part.disk.startswith('mmcblk') else ''
    +                # mmc and nvme device partitions start with prefix 'p'
    +                prefix = 'p' if part.disk.startswith(('mmcblk', 'nvme')) else ''
                     device_name = "/dev/%s%s%d" % (part.disk, prefix, part.realnum)
     
                 opts = part.fsopts if part.fsopts else "defaults"
    @@ -266,7 +266,7 @@ class DirectPlugin(ImagerPlugin):
                     elif part.label and self.ptable_format != 'msdos':
                         return "PARTLABEL=%s" % part.label
                     else:
    -                    suffix = 'p' if part.disk.startswith('mmcblk') else ''
    +                    suffix = 'p' if part.disk.startswith(('mmcblk', 'nvme')) else ''
                         return "/dev/%s%s%-d" % (part.disk, suffix, part.realnum)
     
         def cleanup(self):
    
    From patchwork Mon Jul 20 17:22:58 2026
    Content-Type: text/plain; charset="utf-8"
    MIME-Version: 1.0
    Content-Transfer-Encoding: 7bit
    X-Patchwork-Submitter: Yoann Congal 
    X-Patchwork-Id: 92925
    Return-Path: 
    X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on
    	aws-us-west-2-korg-lkml-1.web.codeaurora.org
    Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org
     (localhost.localdomain [127.0.0.1])
    	by smtp.lore.kernel.org (Postfix) with ESMTP id 398A0C44529
    	for ; Mon, 20 Jul 2026 17:23:58 +0000 (UTC)
    Received: from mail-wm1-f48.google.com (mail-wm1-f48.google.com
     [209.85.128.48])
     by mx.groups.io with SMTP id smtpd.msgproc01-g2.2904.1784568228004449208
     for ;
     Mon, 20 Jul 2026 10:23:48 -0700
    Authentication-Results: mx.groups.io;
     dkim=pass header.i=@smile.fr header.s=google header.b=gJmKdj7G;
     spf=pass (domain: smile.fr, ip: 209.85.128.48,
     mailfrom: yoann.congal@smile.fr)
    Received: by mail-wm1-f48.google.com with SMTP id
     5b1f17b1804b1-4954afac04bso28554685e9.0
            for ;
     Mon, 20 Jul 2026 10:23:47 -0700 (PDT)
    DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;
            d=smile.fr; s=google; t=1784568226; x=1785173026;
     darn=lists.openembedded.org;
            h=content-transfer-encoding:mime-version:references:in-reply-to
             :message-id:date:subject:to:from:from:to:cc:subject:date:message-id
             :reply-to:content-type;
            bh=OJQooEbaZu/ch0pBfY9jld10bhvdE+/PH3eWlIwnxEs=;
            b=gJmKdj7GuFWqbmVhgkuUqp0E/M//PBWAc6Hu9n9Fk1MK3nDB2UTuT8oAcoA3rw0hBJ
             4Z/nMQfenDivb0Dm384f1x/Mg6AceS1yEbWGgqxgP9GBgsmiitvzXJlLptrHYJNBn7y2
             jsp6YXYM4uvA/ySOJ21ytBlTOnnzAU1xq2s2U=
    X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;
            d=1e100.net; s=20251104; t=1784568226; x=1785173026;
            h=content-transfer-encoding:mime-version:references:in-reply-to
             :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to
             :cc:subject:date:message-id:reply-to:content-type;
            bh=OJQooEbaZu/ch0pBfY9jld10bhvdE+/PH3eWlIwnxEs=;
            b=PiUlzMyrcLA107x35M/YOaWr8rex1axbGzBgUif8qqwpCuExf8Q0NZFd/cg/KUuedO
             Wb7qvPqRt/lUz3FIrqwS+wHx+nne/aluT8xV2XjumajJTBKFm5emAhJukubZfWuJFbyr
             9M5/L+Ox65316bT0q/AccbLIaQedeIPQCb+WKOsoQLy/gFewSbW9rlCHAAL5xhraooto
             a3LDCwd5R/0YJgQYcA7xKxwL36zhUvJrQKWDe6UOZ1+j3EMYhXUr/LhWIuuaPQ3nKYJJ
             SlrWVadxvtiNVTOmjdZ+LzxTI7oHXLNh+3VXJQR4Ba4uHU3UKLojNF8L+3xwv61VpinB
             5Aww==
    X-Gm-Message-State: AOJu0Ywup8hl8fzFrprfrluz3rWg/4KbKuowZq/lpHpjg5h8ep3VgAYT
    	t06Ex9mTZ93pZm+pFlnULW7KxQplQGZdNTe16jUW4rUnI7sIx6tY1uL8/ZPqSMYzHd2rKVsczGk
    	qHkeaaz0=
    X-Gm-Gg: AfdE7cl4VhsVxnWBJ4XBeGD504nSGi9HBuDcvlq6oM9iUpckC2bPDOcfZjF0uNB8iam
    	mMrsPs12/AW8uBCVpLI0Ox1H+8nDxJ5bsapeOs8LAaKsqCe7zO0MFsKuxc+3lSuO1Hpw3z+Iw61
    	Czmfk6f8CtzM75G+QImDiAOfmzbW36Q+68SzfsKXqCl3lASsyON5jqEDx0NN7wboNln2RmLlexT
    	4R7Fl/1fc7pHJEwtng6Ww07mJV9wlCCF48jTkDfKAI29QFbixN6M60SMg8RYOVOQIvKwCUinGtW
    	myATWVpQH8mhicN5WhTKyQHw4kvHOrqNmjgJSOoTJ9niPswSpFSsqpuvnXexUtU+9OdFtQoh33u
    	NQTFjJPUXSV+jQxtqcDqjt1iKl3t+azNWeU5oK0OouhjykMauLasNRduxpHoYJK4ZIk21edyB0B
    	ojDyHeC7YX61H2ZVY74gvYDRmSef30FJ8vEd9uXD0IRKb4tW2R0DOiGGbQ3AHfzmZi3QScUNGNt
    	+z9dWrR
    X-Received: by 2002:a05:600c:3512:b0:495:4572:21af with SMTP id
     5b1f17b1804b1-4954a3ef7dbmr161530355e9.9.1784568226223;
            Mon, 20 Jul 2026 10:23:46 -0700 (PDT)
    Received: from localhost.localdomain
     (2a02-8440-b501-5b7b-2580-caa3-ecc1-dea5.rev.sfr.net.
     [2a02:8440:b501:5b7b:2580:caa3:ecc1:dea5])
            by smtp.gmail.com with ESMTPSA id
     5b1f17b1804b1-49563eee22esm36508575e9.1.2026.07.20.10.23.45
            for 
            (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256);
            Mon, 20 Jul 2026 10:23:45 -0700 (PDT)
    From: Yoann Congal 
    To: openembedded-core@lists.openembedded.org
    Subject: [OE-core][scarthgap 25/33] openssh: set status for CVE-2026-3497
    Date: Mon, 20 Jul 2026 19:22:58 +0200
    Message-ID: 
     <51f07e58e3d40f6d83ba0ec7913a5ebe51fbf031.1784567958.git.yoann.congal@smile.fr>
    X-Mailer: git-send-email 2.47.3
    In-Reply-To: 
    References: 
    MIME-Version: 1.0
    List-Id: 
    X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com
     [45.33.107.173] by
     aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for
     ; Mon, 20 Jul 2026 17:23:58 -0000
    X-Groupsio-URL: 
     https://lists.openembedded.org/g/openembedded-core/message/241459
    
    From: Sudhir Dumbhare 
    
    Analysis:
     - CVE-2026-3497 affects downstream OpenSSH GSSAPI Key Exchange patches.
     - The vulnerable code uses sshpkt_disconnect() in the GSSAPI KEX server path.
     - Upstream OpenSSH/OE-Core does not carry the vulnerable GSSAPI key-exchange delta.
     - Hence ignoring the CVE for this version.
    
    Reference:
    https://nvd.nist.gov/vuln/detail/CVE-2026-3497
    https://github.com/advisories/ghsa-wcpp-3x59-h8vp
    https://ubuntu.com/security/CVE-2026-3497
    https://security-tracker.debian.org/tracker/CVE-2026-3497
    https://www.openwall.com/lists/oss-security/2026/03/12/3
    
    Signed-off-by: Sudhir Dumbhare 
    Signed-off-by: Mathieu Dubois-Briand 
    Signed-off-by: Richard Purdie 
    (cherry picked from commit c2bd43b373d65d717e606cab3793b8a64facd946)
    Signed-off-by: Yoann Congal 
    ---
     meta/recipes-connectivity/openssh/openssh_9.6p1.bb | 1 +
     1 file changed, 1 insertion(+)
    
    diff --git a/meta/recipes-connectivity/openssh/openssh_9.6p1.bb b/meta/recipes-connectivity/openssh/openssh_9.6p1.bb
    index 4193bc8a5b4..4ab3174924c 100644
    --- a/meta/recipes-connectivity/openssh/openssh_9.6p1.bb
    +++ b/meta/recipes-connectivity/openssh/openssh_9.6p1.bb
    @@ -49,6 +49,7 @@ Red Hat Enterprise Linux 7 and when running in a Kerberos environment"
     
     CVE_STATUS[CVE-2008-3844] = "not-applicable-platform: Only applies to some distributed RHEL binaries."
     CVE_STATUS[CVE-2023-51767] = "upstream-wontfix: It was demonstrated on modified sshd and does not exist in upstream openssh https://bugzilla.mindrot.org/show_bug.cgi?id=3656#c1."
    +CVE_STATUS[CVE-2026-3497] = "not-applicable-platform: Only affects GSSAPI Key Exchange patches used by some Linux distributions and does not exist in upstream openssh."
     
     PAM_SRC_URI = "file://sshd"
     
    
    From patchwork Mon Jul 20 17:22:59 2026
    Content-Type: text/plain; charset="utf-8"
    MIME-Version: 1.0
    Content-Transfer-Encoding: 8bit
    X-Patchwork-Submitter: Yoann Congal 
    X-Patchwork-Id: 92930
    Return-Path: 
    X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on
    	aws-us-west-2-korg-lkml-1.web.codeaurora.org
    Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org
     (localhost.localdomain [127.0.0.1])
    	by smtp.lore.kernel.org (Postfix) with ESMTP id AC675C44533
    	for ; Mon, 20 Jul 2026 17:23:58 +0000 (UTC)
    Received: from mail-wm1-f43.google.com (mail-wm1-f43.google.com
     [209.85.128.43])
     by mx.groups.io with SMTP id smtpd.msgproc01-g2.2906.1784568229481121908
     for ;
     Mon, 20 Jul 2026 10:23:49 -0700
    Authentication-Results: mx.groups.io;
     dkim=pass header.i=@smile.fr header.s=google header.b=Ic8NU5u/;
     spf=pass (domain: smile.fr, ip: 209.85.128.43,
     mailfrom: yoann.congal@smile.fr)
    Received: by mail-wm1-f43.google.com with SMTP id
     5b1f17b1804b1-493f75f7172so81812475e9.1
            for ;
     Mon, 20 Jul 2026 10:23:49 -0700 (PDT)
    DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;
            d=smile.fr; s=google; t=1784568228; x=1785173028;
     darn=lists.openembedded.org;
            h=content-transfer-encoding:content-type:mime-version:references
             :in-reply-to:message-id:date:subject:to:from:from:to:cc:subject:date
             :message-id:reply-to:content-type;
            bh=WMxXWjw9T8zIqfE6I80b7cT7Q0XlIp9bu0htX3JN1yI=;
            b=Ic8NU5u/mdh+VDte8/RBstcyI0+3GozSzf+Hv0hmWmwE8eJSsCd1H85Aco0qsQtzxF
             aw3M8j8kpKTeJ5DiQckRPSK1GrwFQOmH2ec5Oed5PmwlmwwVSQaXZ8pQNTgLwDnxcVw7
             MLseRf6GCFgYtqjrlrczNyW3aVyonFwS1Gy7o=
    X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;
            d=1e100.net; s=20251104; t=1784568228; x=1785173028;
            h=content-transfer-encoding:content-type:mime-version:references
             :in-reply-to:message-id:date:subject:to:from:x-gm-gg
             :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to
             :content-type;
            bh=WMxXWjw9T8zIqfE6I80b7cT7Q0XlIp9bu0htX3JN1yI=;
            b=YuVXu2MhjowJ0gQceyCvBTHVQYGQZW2lUn95kBOT2sZGBK7UTlHlTs3rj8LdDsuLml
             ey+RBOzQ3R3yqCDEHR31oGgNF8m6ohszmFc2a1tfwizO07oluFw8a3WrocFwabRxYCiS
             XS++NrhUzmnYeoBo/4NOqjcTBy+svSDyrEEJC13aW0hybsFZELX/aFULLnxYHeR/Yj8d
             vTC5g4hgP4JjjzJwfdfGn4eFD5OaPTUt5LnfY79x7JnlWlE+GtSdSExYYuUN1rv0tHqz
             wRMqnq3plWhkczvRtRsjAnljVj01Ty6zKdiPcI5oAumWgojFQi57weERXF0sTCbiDSDV
             KOaA==
    X-Gm-Message-State: AOJu0YyjUA5a3DB/ZpOzV4yOdK6qRmio8LwwFJzC8nR6VBZdl3BOGpVC
    	bM6TZoyrfbZW//l8RDOQ4w+Ur/6IaVicfIVhVuOPKZFM+PR0ElxcJBEBNW5WXpD7/wGBG2LFnIf
    	zmaJkfBg=
    X-Gm-Gg: AfdE7clU5Htg/41QMdfCbgw87wJKwwYxG0iRvZvt9ELyxy3kr5R2UtYcmLb8PIvmO+b
    	YYkd4r9jMXEf33xVbm+fTvJY8N87EZ1fwuw0+hCQJGzgI/p6fl96JsEVSqQRd0A3YiOomY0chig
    	YAkCErcnsuRXnBShuNRzXifMVR9+UsbBXZnP8OsdmtzsROyhMhPVKAtqGyTpuIpAUMFzLOQlQun
    	BKfr/CD7hccgalBS+vxyqpg4mk7J2DeOmnmI5br36wg3zEyQnOocVOoCSyj5dUTBiTj0qrudsYP
    	dJ7ATSPm6T2552FRVxKz63YB260eeUGtxhssfVKIFTbZgRdtDz5UTv6mGJ88JfxY+fsNgEH6d9A
    	aKFE3iPx5cPrrpmB6RvBduzF71vBeF5JMAz8jtJMVwQnCoZTML/+9uy43d0+0wQEtqymp+kcFDh
    	pYTmaA9J+KH2WaqaSPlD6qY8wtxVYSrSOkApwUPcl36MrJEFaZDGAITqU31c+HivF2NmthuG3Ag
    	T2FnmbiewOqLHzi88c=
    X-Received: by 2002:a05:600c:1989:b0:495:52db:7e8 with SMTP id
     5b1f17b1804b1-49552db09bfmr112929625e9.19.1784568227303;
            Mon, 20 Jul 2026 10:23:47 -0700 (PDT)
    Received: from localhost.localdomain
     (2a02-8440-b501-5b7b-2580-caa3-ecc1-dea5.rev.sfr.net.
     [2a02:8440:b501:5b7b:2580:caa3:ecc1:dea5])
            by smtp.gmail.com with ESMTPSA id
     5b1f17b1804b1-49563eee22esm36508575e9.1.2026.07.20.10.23.46
            for 
            (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256);
            Mon, 20 Jul 2026 10:23:46 -0700 (PDT)
    From: Yoann Congal 
    To: openembedded-core@lists.openembedded.org
    Subject: [OE-core][scarthgap 26/33] vim: Fix for
     CVE-2026-52858,CVE-2026-52859,CVE-2026-52860
    Date: Mon, 20 Jul 2026 19:22:59 +0200
    Message-ID: 
     <0509cae4e89d872bcd11d9d5757bffdf19ce45cc.1784567958.git.yoann.congal@smile.fr>
    X-Mailer: git-send-email 2.47.3
    In-Reply-To: 
    References: 
    MIME-Version: 1.0
    List-Id: 
    X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com
     [45.33.107.173] by
     aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for
     ; Mon, 20 Jul 2026 17:23:58 -0000
    X-Groupsio-URL: 
     https://lists.openembedded.org/g/openembedded-core/message/241460
    
    From: Hitendra Prajapati 
    
    Pick patch from [1], [2] & [3] also mentioned at NVD report in [4,5 & 6]
    
    [1] https://github.com/vim/vim/commit/4b850457e12e1a678dd209f2868154f7553cbf8d
    [2] https://github.com/vim/vim/commit/63680c6d3d52477817b49cd1a66e7aabe8a7aa19
    [3] https://github.com/vim/vim/commit/c8c63673bc4253212820626aeeb75999d9a539d2
    [4] https://nvd.nist.gov/vuln/detail/CVE-2026-52858
    [5] https://nvd.nist.gov/vuln/detail/CVE-2026-52859
    [6] https://nvd.nist.gov/vuln/detail/CVE-2026-52860
    
    Signed-off-by: Hitendra Prajapati 
    Signed-off-by: Yoann Congal 
    ---
     .../vim/files/CVE-2026-52858.patch            | 167 +++++++
     .../vim/files/CVE-2026-52859.patch            | 274 +++++++++++
     .../vim/files/CVE-2026-52860.patch            | 446 ++++++++++++++++++
     meta/recipes-support/vim/vim.inc              |   3 +
     4 files changed, 890 insertions(+)
     create mode 100644 meta/recipes-support/vim/files/CVE-2026-52858.patch
     create mode 100644 meta/recipes-support/vim/files/CVE-2026-52859.patch
     create mode 100644 meta/recipes-support/vim/files/CVE-2026-52860.patch
    
    diff --git a/meta/recipes-support/vim/files/CVE-2026-52858.patch b/meta/recipes-support/vim/files/CVE-2026-52858.patch
    new file mode 100644
    index 00000000000..7e036e45ea8
    --- /dev/null
    +++ b/meta/recipes-support/vim/files/CVE-2026-52858.patch
    @@ -0,0 +1,167 @@
    +From 4b850457e12e1a678dd209f2868154f7553cbf8d Mon Sep 17 00:00:00 2001
    +From: Christian Brabandt 
    +Date: Fri, 29 May 2026 19:05:53 +0000
    +Subject: [PATCH] patch 9.2.0561: [security]: possible code execution with
    + python3complete
    +
    +Problem:  [security]: possible code execution with python3complete
    +Solution: Disable execution of import/from statements
    +
    +Github Security Advisory:
    +https://github.com/vim/vim/security/advisories/GHSA-52mc-rq6p-rc7c
    +
    +Signed-off-by: Christian Brabandt 
    +
    +Upstream-Status: Backport [https://github.com/vim/vim/commit/4b850457e12e1a678dd209f2868154f7553cbf8d]
    +CVE: CVE-2026-52858
    +Signed-off-by: Hitendra Prajapati 
    +---
    + runtime/autoload/README.txt          |  1 +
    + runtime/autoload/python3complete.vim | 17 ++++++++++++++---
    + runtime/autoload/pythoncomplete.vim  | 17 ++++++++++++++---
    + runtime/doc/filetype.txt             | 15 ++++++++++++++-
    + 4 files changed, 43 insertions(+), 7 deletions(-)
    +
    +diff --git a/runtime/autoload/README.txt b/runtime/autoload/README.txt
    +index 3b18d3d..b225819 100644
    +--- a/runtime/autoload/README.txt
    ++++ b/runtime/autoload/README.txt
    +@@ -17,6 +17,7 @@ htmlcomplete.vim	HTML
    + javascriptcomplete.vim  Javascript
    + phpcomplete.vim		PHP
    + pythoncomplete.vim	Python
    ++python3complete.vim Python
    + rubycomplete.vim	Ruby
    + syntaxcomplete.vim	from syntax highlighting
    + xmlcomplete.vim		XML (uses files in the xml directory)
    +diff --git a/runtime/autoload/python3complete.vim b/runtime/autoload/python3complete.vim
    +index ea0a331..aba3412 100644
    +--- a/runtime/autoload/python3complete.vim
    ++++ b/runtime/autoload/python3complete.vim
    +@@ -14,6 +14,10 @@
    + "   i.e. "import url"
    + " Continue parsing on invalid line??
    + "
    ++" v 0.10 by Vim project
    ++"   * disables importing local modules, unless the global Vim variable
    ++"     g:pythoncomplete_allow_import is set to non-zero
    ++"
    + " v 0.9
    + "   * Fixed docstring parsing for classes and functions
    + "   * Fixed parsing of *args and **kwargs type arguments
    +@@ -132,11 +136,20 @@ class Completer(object):
    + 
    +     def evalsource(self,text,line=0):
    +         sc = self.parser.parse(text,line)
    ++        try: allow_imports = int(
    ++          vim.eval("get(g:, 'pythoncomplete_allow_import', 0)"))
    ++        except Exception:
    ++          allow_imports = 0
    +         src = sc.get_code()
    +         dbg("source: %s" % src)
    +         try: exec(src,self.compldict)
    +         except: dbg("parser: %s, %s" % (sys.exc_info()[0],sys.exc_info()[1]))
    +         for l in sc.locals:
    ++            # Executing import/from statements harvested from the buffer runs
    ++            # arbitrary package code; only do so when the user opted in.
    ++            if not allow_imports and (l.startswith('import')
    ++                                            or l.startswith('from ')):
    ++                continue
    +             try: exec(l,self.compldict)
    +             except: dbg("locals: %s, %s [%s]" % (sys.exc_info()[0],sys.exc_info()[1],l))
    + 
    +@@ -300,13 +313,11 @@ class Scope(object):
    +     def get_code(self):
    +         str = ""
    +         if len(self.docstr) > 0: str += '"""'+self.docstr+'"""\n'
    +-        for l in self.locals:
    +-            if l.startswith('import'): str += l+'\n'
    +         str += 'class _PyCmplNoType:\n    def __getattr__(self,name):\n        return None\n'
    +         for sub in self.subscopes:
    +             str += sub.get_code()
    +         for l in self.locals:
    +-            if not l.startswith('import'): str += l+'\n'
    ++            if not l.startswith('import') and not l.startswith('from '): str += l+'\n'
    + 
    +         return str
    + 
    +diff --git a/runtime/autoload/pythoncomplete.vim b/runtime/autoload/pythoncomplete.vim
    +index aa28bb7..1014776 100644
    +--- a/runtime/autoload/pythoncomplete.vim
    ++++ b/runtime/autoload/pythoncomplete.vim
    +@@ -12,6 +12,10 @@
    + "   i.e. "import url"
    + " Continue parsing on invalid line??
    + "
    ++" v 0.10 by Vim project
    ++"   * disables importing local modules, unless the global Vim variable
    ++"     g:pythoncomplete_allow_import is set to non-zero
    ++"
    + " v 0.9
    + "   * Fixed docstring parsing for classes and functions
    + "   * Fixed parsing of *args and **kwargs type arguments
    +@@ -146,11 +150,20 @@ class Completer(object):
    + 
    +     def evalsource(self,text,line=0):
    +         sc = self.parser.parse(text,line)
    ++        try: allow_imports = int(
    ++          vim.eval("get(g:, 'pythoncomplete_allow_import', 0)"))
    ++        except Exception:
    ++          allow_imports = 0
    +         src = sc.get_code()
    +         dbg("source: %s" % src)
    +         try: exec(src) in self.compldict
    +         except: dbg("parser: %s, %s" % (sys.exc_info()[0],sys.exc_info()[1]))
    +         for l in sc.locals:
    ++            # Executing import/from statements harvested from the buffer runs
    ++            # arbitrary package code; only do so when the user opted in.
    ++            if not allow_imports and (l.startswith('import')
    ++                                            or l.startswith('from ')):
    ++                continue
    +             try: exec(l) in self.compldict
    +             except: dbg("locals: %s, %s [%s]" % (sys.exc_info()[0],sys.exc_info()[1],l))
    + 
    +@@ -315,13 +328,11 @@ class Scope(object):
    +     def get_code(self):
    +         str = ""
    +         if len(self.docstr) > 0: str += '"""'+self.docstr+'"""\n'
    +-        for l in self.locals:
    +-            if l.startswith('import'): str += l+'\n'
    +         str += 'class _PyCmplNoType:\n    def __getattr__(self,name):\n        return None\n'
    +         for sub in self.subscopes:
    +             str += sub.get_code()
    +         for l in self.locals:
    +-            if not l.startswith('import'): str += l+'\n'
    ++            if not l.startswith('import') and not l.startswith('from '): str += l+'\n'
    + 
    +         return str
    + 
    +diff --git a/runtime/doc/filetype.txt b/runtime/doc/filetype.txt
    +index 597141d..c8572fe 100644
    +--- a/runtime/doc/filetype.txt
    ++++ b/runtime/doc/filetype.txt
    +@@ -739,7 +739,20 @@ By default the following options are set, in accordance with PEP8: >
    + To disable this behavior, set the following variable in your vimrc: >
    + 
    + 	let g:python_recommended_style = 0
    +-
    ++<
    ++Python omni-completion |compl-omni| is provided by python3complete.vim (or
    ++pythoncomplete.vim) for Vim builds with the |+python|/|+python3| interpreter.
    ++By default it does not inspect the import / from statements found in the
    ++buffer. This means completion of names defined in the buffer itself (classes,
    ++functions, variables) works, but completion of members of imported modules is
    ++not offered.
    ++
    ++To enable completion of imported module members, set: >
    ++	let g:pythoncomplete_allow_import = 1
    ++<
    ++WARNING: enabling this causes omni-completion to execute the import statements
    ++found in the buffer through Python's import machinery, which runs the imported
    ++modules' top-level code. Only enable this for code you trust.
    + 
    + QF QUICKFIX					    *qf.vim* *ft-qf-plugin*
    + 
    +-- 
    +2.34.1
    +
    diff --git a/meta/recipes-support/vim/files/CVE-2026-52859.patch b/meta/recipes-support/vim/files/CVE-2026-52859.patch
    new file mode 100644
    index 00000000000..472d7c06401
    --- /dev/null
    +++ b/meta/recipes-support/vim/files/CVE-2026-52859.patch
    @@ -0,0 +1,274 @@
    +From 63680c6d3d52477817b49cd1a66e7aabe8a7aa19 Mon Sep 17 00:00:00 2001
    +From: Christian Brabandt 
    +Date: Sat, 30 May 2026 16:34:40 +0000
    +Subject: [PATCH] patch 9.2.0565: [security]: out-of-bounds read in
    + update_snapshot()
    +
    +Problem:  Out-of-bounds read in update_snapshot() when a terminal cell
    +          fills all VTERM_MAX_CHARS_PER_CELL slots (a base character
    +          plus five combining marks): the loop over cell.chars[] has no
    +          upper bound and libvterm leaves the array unterminated when full, so
    +          it reads past the array and appends out-of-bounds values to a
    +          buffer sized for only VTERM_MAX_CHARS_PER_CELL characters.
    +Solution: Bound the loop with i < VTERM_MAX_CHARS_PER_CELL, mirroring
    +          the loop in handle_pushline() (Christian Brabandt).
    +
    +Signed-off-by: Christian Brabandt 
    +
    +Upstream-Status: Backport [https://github.com/vim/vim/commit/63680c6d3d52477817b49cd1a66e7aabe8a7aa19]
    +CVE: CVE-2026-52859
    +Signed-off-by: Hitendra Prajapati 
    +---
    + src/terminal.c                          |   3 +-
    + src/testdir/samples/combining_chars.txt | 200 ++++++++++++++++++++++++
    + src/testdir/test_terminal3.vim          |  15 ++
    + 3 files changed, 217 insertions(+), 1 deletion(-)
    + create mode 100644 src/testdir/samples/combining_chars.txt
    +
    +diff --git a/src/terminal.c b/src/terminal.c
    +index 78990ac..527f1b9 100644
    +--- a/src/terminal.c
    ++++ b/src/terminal.c
    +@@ -2080,7 +2080,8 @@ update_snapshot(term_T *term)
    + 			    int	    i;
    + 			    int	    c;
    + 
    +-			    for (i = 0; (c = cell.chars[i]) > 0 || i == 0; ++i)
    ++			    for (i = 0; i < VTERM_MAX_CHARS_PER_CELL &&
    ++				    ((c = cell.chars[i]) > 0 || i == 0); ++i)
    + 				ga.ga_len += utf_char2bytes(c == NUL ? ' ' : c,
    + 					     (char_u *)ga.ga_data + ga.ga_len);
    + 			}
    +diff --git a/src/testdir/samples/combining_chars.txt b/src/testdir/samples/combining_chars.txt
    +new file mode 100644
    +index 0000000..d9a3c17
    +--- /dev/null
    ++++ b/src/testdir/samples/combining_chars.txt
    +@@ -0,0 +1,200 @@
    ++á́́́́
    ++á́́́́
    ++á́́́́
    ++á́́́́
    ++á́́́́
    ++á́́́́
    ++á́́́́
    ++á́́́́
    ++á́́́́
    ++á́́́́
    ++á́́́́
    ++á́́́́
    ++á́́́́
    ++á́́́́
    ++á́́́́
    ++á́́́́
    ++á́́́́
    ++á́́́́
    ++á́́́́
    ++á́́́́
    ++á́́́́
    ++á́́́́
    ++á́́́́
    ++á́́́́
    ++á́́́́
    ++á́́́́
    ++á́́́́
    ++á́́́́
    ++á́́́́
    ++á́́́́
    ++á́́́́
    ++á́́́́
    ++á́́́́
    ++á́́́́
    ++á́́́́
    ++á́́́́
    ++á́́́́
    ++á́́́́
    ++á́́́́
    ++á́́́́
    ++á́́́́
    ++á́́́́
    ++á́́́́
    ++á́́́́
    ++á́́́́
    ++á́́́́
    ++á́́́́
    ++á́́́́
    ++á́́́́
    ++á́́́́
    ++á́́́́
    ++á́́́́
    ++á́́́́
    ++á́́́́
    ++á́́́́
    ++á́́́́
    ++á́́́́
    ++á́́́́
    ++á́́́́
    ++á́́́́
    ++á́́́́
    ++á́́́́
    ++á́́́́
    ++á́́́́
    ++á́́́́
    ++á́́́́
    ++á́́́́
    ++á́́́́
    ++á́́́́
    ++á́́́́
    ++á́́́́
    ++á́́́́
    ++á́́́́
    ++á́́́́
    ++á́́́́
    ++á́́́́
    ++á́́́́
    ++á́́́́
    ++á́́́́
    ++á́́́́
    ++á́́́́
    ++á́́́́
    ++á́́́́
    ++á́́́́
    ++á́́́́
    ++á́́́́
    ++á́́́́
    ++á́́́́
    ++á́́́́
    ++á́́́́
    ++á́́́́
    ++á́́́́
    ++á́́́́
    ++á́́́́
    ++á́́́́
    ++á́́́́
    ++á́́́́
    ++á́́́́
    ++á́́́́
    ++á́́́́
    ++á́́́́
    ++á́́́́
    ++á́́́́
    ++á́́́́
    ++á́́́́
    ++á́́́́
    ++á́́́́
    ++á́́́́
    ++á́́́́
    ++á́́́́
    ++á́́́́
    ++á́́́́
    ++á́́́́
    ++á́́́́
    ++á́́́́
    ++á́́́́
    ++á́́́́
    ++á́́́́
    ++á́́́́
    ++á́́́́
    ++á́́́́
    ++á́́́́
    ++á́́́́
    ++á́́́́
    ++á́́́́
    ++á́́́́
    ++á́́́́
    ++á́́́́
    ++á́́́́
    ++á́́́́
    ++á́́́́
    ++á́́́́
    ++á́́́́
    ++á́́́́
    ++á́́́́
    ++á́́́́
    ++á́́́́
    ++á́́́́
    ++á́́́́
    ++á́́́́
    ++á́́́́
    ++á́́́́
    ++á́́́́
    ++á́́́́
    ++á́́́́
    ++á́́́́
    ++á́́́́
    ++á́́́́
    ++á́́́́
    ++á́́́́
    ++á́́́́
    ++á́́́́
    ++á́́́́
    ++á́́́́
    ++á́́́́
    ++á́́́́
    ++á́́́́
    ++á́́́́
    ++á́́́́
    ++á́́́́
    ++á́́́́
    ++á́́́́
    ++á́́́́
    ++á́́́́
    ++á́́́́
    ++á́́́́
    ++á́́́́
    ++á́́́́
    ++á́́́́
    ++á́́́́
    ++á́́́́
    ++á́́́́
    ++á́́́́
    ++á́́́́
    ++á́́́́
    ++á́́́́
    ++á́́́́
    ++á́́́́
    ++á́́́́
    ++á́́́́
    ++á́́́́
    ++á́́́́
    ++á́́́́
    ++á́́́́
    ++á́́́́
    ++á́́́́
    ++á́́́́
    ++á́́́́
    ++á́́́́
    ++á́́́́
    ++á́́́́ጁ
    ++á́́́́ጁ
    ++á́́́́ጁ
    ++á́́́́ጁ
    ++á́́́́ጁ
    ++á́́́́ጁ
    ++á́́́́ጁ
    ++á́́́́ጁ
    ++á́́́́ጁ
    ++á́́́́ጁ
    +diff --git a/src/testdir/test_terminal3.vim b/src/testdir/test_terminal3.vim
    +index cb1946f..c02801e 100644
    +--- a/src/testdir/test_terminal3.vim
    ++++ b/src/testdir/test_terminal3.vim
    +@@ -1051,4 +1051,19 @@ func Test_terminal_max_combining_chars()
    +   exe buf . "bwipe!"
    + endfunc
    + 
    ++func Test_terminal_output_combining_chars()
    ++  CheckUnix
    ++  new
    ++  let cmd = "cat samples/combining_chars.txt"
    ++  let buf = term_start(cmd, {'curwin': 1, 'term_finish': 'open', 'term_rows': 10, 'term_cols': 30})
    ++  call WaitForAssert({-> assert_match('finished', term_getstatus(buf))})
    ++  call TermWait(buf)
    ++  let lines = getbufline(buf, 1, '$')
    ++  " get byte lengths to confirm combining chars present
    ++  let lens = map(copy(lines), 'len(v:val)')
    ++  let expected = repeat([11], 190) + repeat([14], 10)
    ++  call assert_equal(expected, lens)
    ++  bw!
    ++endfunc
    ++
    + " vim: shiftwidth=2 sts=2 expandtab
    +-- 
    +2.34.1
    +
    diff --git a/meta/recipes-support/vim/files/CVE-2026-52860.patch b/meta/recipes-support/vim/files/CVE-2026-52860.patch
    new file mode 100644
    index 00000000000..52a18415ce1
    --- /dev/null
    +++ b/meta/recipes-support/vim/files/CVE-2026-52860.patch
    @@ -0,0 +1,446 @@
    +From c8c63673bc4253212820626aeeb75999d9a539d2 Mon Sep 17 00:00:00 2001
    +From: Christian Brabandt 
    +Date: Thu, 4 Jun 2026 21:06:09 +0000
    +Subject: [PATCH] patch 9.2.0597: [security]: possible code execution with
    + python complete
    +
    +Problem:  [security]: another possible code execution with python complete
    +          (David Carliez)
    +Solution: Strip default expressions and annotations from generated
    +          source for pythoncomplete and python3complete.
    +
    +Github Security Advisory:
    +https://github.com/vim/vim/security/advisories/GHSA-65p9-mwwx-7468
    +
    +Signed-off-by: Christian Brabandt 
    +
    +Upstream-Status: Backport [https://github.com/vim/vim/commit/c8c63673bc4253212820626aeeb75999d9a539d2]
    +CVE: CVE-2026-52860
    +Signed-off-by: Hitendra Prajapati 
    +---
    + runtime/autoload/python3complete.vim        |  43 +++-
    + runtime/autoload/pythoncomplete.vim         |  43 +++-
    + src/testdir/Make_all.mak                    |   2 +
    + src/testdir/test_plugin_python3complete.vim | 224 ++++++++++++++++++++
    + 4 files changed, 304 insertions(+), 8 deletions(-)
    + create mode 100644 src/testdir/test_plugin_python3complete.vim
    +
    +diff --git a/runtime/autoload/python3complete.vim b/runtime/autoload/python3complete.vim
    +index aba3412..a031424 100644
    +--- a/runtime/autoload/python3complete.vim
    ++++ b/runtime/autoload/python3complete.vim
    +@@ -1,8 +1,8 @@
    + "python3complete.vim - Omni Completion for python
    + " Maintainer: 
    + " Previous Maintainer: Aaron Griffin 
    +-" Version: 0.9
    +-" Last Updated: 2022 Mar 30
    ++" Version: 0.10
    ++" Last Updated: 2026 Jun 04
    + "
    + " Roland Puntaier: this file contains adaptations for python3 and is parallel to pythoncomplete.vim
    + "
    +@@ -17,6 +17,11 @@
    + " v 0.10 by Vim project
    + "   * disables importing local modules, unless the global Vim variable
    + "     g:pythoncomplete_allow_import is set to non-zero
    ++"   * strip default values and annotations from function parameter lists
    ++"     before exec(), and whitelist class base lists to dotted names: the
    ++"     previous code passed buffer-supplied expressions to exec() which
    ++"     Python evaluates at definition time, allowing arbitrary code
    ++"     execution via crafted def/class headers
    + "
    + " v 0.9
    + "   * Fixed docstring parsing for classes and functions
    +@@ -100,6 +105,24 @@ warnings.simplefilter(action='ignore', category=FutureWarning)
    + 
    + import sys, tokenize, io, types
    + from token import NAME, DEDENT, NEWLINE, STRING
    ++import re
    ++
    ++# Used by Class.get_code(): a base class expression is only included in the
    ++# code passed to exec() if it is a pure dotted name (e.g. "Base", "mod.Base",
    ++# "pkg.sub.Cls").  Anything containing calls, subscripts, "=", ":" or other
    ++# operators is dropped, since exec()-ing it would evaluate buffer-supplied
    ++# expressions.  See the security note in the file header.
    ++_DOTTED_NAME_RE = re.compile(r'^[A-Za-z_]\w*(\s*\.\s*[A-Za-z_]\w*)*$')
    ++
    ++def _strip_param(p):
    ++    # Return the bare parameter name from a parameter spec harvested by
    ++    # _parenparse(), discarding any default value or annotation.  Default
    ++    # values and annotations would otherwise be evaluated by exec() at
    ++    # function-definition time.  Star prefixes ("*args", "**kw") and bare
    ++    # "*" / "/" are preserved as written.
    ++    p = p.split('=', 1)[0]
    ++    p = p.split(':', 1)[0]
    ++    return p.strip()
    + 
    + debugstmts=[]
    + def dbg(s): debugstmts.append(s)
    +@@ -347,7 +370,13 @@ class Class(Scope):
    +         return c
    +     def get_code(self):
    +         str = '%sclass %s' % (self.currentindent(),self.name)
    +-        if len(self.supers) > 0: str += '(%s)' % ','.join(self.supers)
    ++        # Only include base class expressions that are pure dotted names.
    ++        # Anything else (calls, subscripts, conditionals, ...) is dropped
    ++        # because exec() would evaluate it at class-definition time.  See
    ++        # the security note in the file header.
    ++        safe_supers = [s.strip() for s in self.supers
    ++                       if _DOTTED_NAME_RE.match(s.strip())]
    ++        if len(safe_supers) > 0: str += '(%s)' % ','.join(safe_supers)
    +         str += ':\n'
    +         if len(self.docstr) > 0: str += self.childindent()+'"""'+self.docstr+'"""\n'
    +         if len(self.subscopes) > 0:
    +@@ -364,8 +393,14 @@ class Function(Scope):
    +     def copy_decl(self,indent=0):
    +         return Function(self.name,self.params,indent, self.docstr)
    +     def get_code(self):
    ++        # Strip default values and annotations from each parameter before
    ++        # joining: exec() evaluates these at definition time and a hostile
    ++        # buffer could otherwise execute arbitrary code via crafted def
    ++        # headers.  See file header for details.
    ++        safe_params = [_strip_param(p) for p in self.params]
    ++        safe_params = [p for p in safe_params if p]
    +         str = "%sdef %s(%s):\n" % \
    +-            (self.currentindent(),self.name,','.join(self.params))
    ++            (self.currentindent(),self.name,','.join(safe_params))
    +         if len(self.docstr) > 0: str += self.childindent()+'"""'+self.docstr+'"""\n'
    +         str += "%spass\n" % self.childindent()
    +         return str
    +diff --git a/runtime/autoload/pythoncomplete.vim b/runtime/autoload/pythoncomplete.vim
    +index 1014776..39b1efd 100644
    +--- a/runtime/autoload/pythoncomplete.vim
    ++++ b/runtime/autoload/pythoncomplete.vim
    +@@ -1,8 +1,8 @@
    + "pythoncomplete.vim - Omni Completion for python
    + " Maintainer: 
    + " Previous Maintainer: Aaron Griffin 
    +-" Version: 0.9
    +-" Last Updated: 2020 Oct 9
    ++" Version: 0.10
    ++" Last Updated: 2026 Jun 04
    + "
    + " Changes
    + " TODO:
    +@@ -15,6 +15,11 @@
    + " v 0.10 by Vim project
    + "   * disables importing local modules, unless the global Vim variable
    + "     g:pythoncomplete_allow_import is set to non-zero
    ++"   * strip default values and annotations from function parameter lists
    ++"     before exec(), and whitelist class base lists to dotted names: the
    ++"     previous code passed buffer-supplied expressions to exec() which
    ++"     Python evaluates at definition time, allowing arbitrary code
    ++"     execution via crafted def/class headers
    + "
    + " v 0.9
    + "   * Fixed docstring parsing for classes and functions
    +@@ -95,6 +100,24 @@ function! s:DefPython()
    + python << PYTHONEOF
    + import sys, tokenize, cStringIO, types
    + from token import NAME, DEDENT, NEWLINE, STRING
    ++import re
    ++
    ++# Used by Class.get_code(): a base class expression is only included in the
    ++# code passed to exec() if it is a pure dotted name (e.g. "Base", "mod.Base",
    ++# "pkg.sub.Cls").  Anything containing calls, subscripts, "=", ":" or other
    ++# operators is dropped, since exec()-ing it would evaluate buffer-supplied
    ++# expressions.  See the security note in the file header.
    ++_DOTTED_NAME_RE = re.compile(r'^[A-Za-z_]\w*(\s*\.\s*[A-Za-z_]\w*)*$')
    ++
    ++def _strip_param(p):
    ++    # Return the bare parameter name from a parameter spec harvested by
    ++    # _parenparse(), discarding any default value or annotation.  Default
    ++    # values and annotations would otherwise be evaluated by exec() at
    ++    # function-definition time.  Star prefixes ("*args", "**kw") and bare
    ++    # "*" / "/" are preserved as written.
    ++    p = p.split('=', 1)[0]
    ++    p = p.split(':', 1)[0]
    ++    return p.strip()
    + 
    + debugstmts=[]
    + def dbg(s): debugstmts.append(s)
    +@@ -362,7 +385,13 @@ class Class(Scope):
    +         return c
    +     def get_code(self):
    +         str = '%sclass %s' % (self.currentindent(),self.name)
    +-        if len(self.supers) > 0: str += '(%s)' % ','.join(self.supers)
    ++        # Only include base class expressions that are pure dotted names.
    ++        # Anything else (calls, subscripts, conditionals, ...) is dropped
    ++        # because exec() would evaluate it at class-definition time.  See
    ++        # the security note in the file header.
    ++        safe_supers = [s.strip() for s in self.supers
    ++                       if _DOTTED_NAME_RE.match(s.strip())]
    ++        if len(safe_supers) > 0: str += '(%s)' % ','.join(safe_supers)
    +         str += ':\n'
    +         if len(self.docstr) > 0: str += self.childindent()+'"""'+self.docstr+'"""\n'
    +         if len(self.subscopes) > 0:
    +@@ -379,8 +408,14 @@ class Function(Scope):
    +     def copy_decl(self,indent=0):
    +         return Function(self.name,self.params,indent, self.docstr)
    +     def get_code(self):
    ++        # Strip default values and annotations from each parameter before
    ++        # joining: exec() evaluates these at definition time and a hostile
    ++        # buffer could otherwise execute arbitrary code via crafted def
    ++        # headers.  See file header for details.
    ++        safe_params = [_strip_param(p) for p in self.params]
    ++        safe_params = [p for p in safe_params if p]
    +         str = "%sdef %s(%s):\n" % \
    +-            (self.currentindent(),self.name,','.join(self.params))
    ++            (self.currentindent(),self.name,','.join(safe_params))
    +         if len(self.docstr) > 0: str += self.childindent()+'"""'+self.docstr+'"""\n'
    +         str += "%spass\n" % self.childindent()
    +         return str
    +diff --git a/src/testdir/Make_all.mak b/src/testdir/Make_all.mak
    +index 0d4aeb0..87545b7 100644
    +--- a/src/testdir/Make_all.mak
    ++++ b/src/testdir/Make_all.mak
    +@@ -247,6 +247,7 @@ NEW_TESTS = \
    + 	test_plugin_helptoc \
    + 	test_plugin_man \
    + 	test_plugin_matchparen \
    ++	test_plugin_python3complete \
    + 	test_plugin_tar \
    + 	test_plugin_termdebug \
    + 	test_plugin_tohtml \
    +@@ -520,6 +521,7 @@ NEW_TESTS_RES = \
    + 	test_plugin_helptoc.res \
    + 	test_plugin_man.res \
    + 	test_plugin_matchparen.res \
    ++	test_plugin_python3complete.res \
    + 	test_plugin_tar.res \
    + 	test_plugin_termdebug.res \
    + 	test_plugin_tohtml.res \
    +diff --git a/src/testdir/test_plugin_python3complete.vim b/src/testdir/test_plugin_python3complete.vim
    +new file mode 100644
    +index 0000000..e2b0c66
    +--- /dev/null
    ++++ b/src/testdir/test_plugin_python3complete.vim
    +@@ -0,0 +1,224 @@
    ++" Tests for the Python omni-completion plugin (runtime/autoload/python3complete.vim).
    ++"
    ++CheckFeature python3
    ++
    ++" Run omni-completion against the given buffer contents and assert that the
    ++" marker file was not created.  Pre-patch behaviour exec()s reconstructed
    ++" def/class headers, which evaluates the buffer-supplied expression and
    ++" creates the marker file.  Post-patch, the expressions are stripped.
    ++func s:CompleteAndExpectNoMarker(buffer_lines, marker_path, msg)
    ++  call delete(a:marker_path)
    ++  defer delete(a:marker_path)
    ++  let g:pythoncomplete_allow_import = 0
    ++  new
    ++  setfiletype python
    ++  call setline(1, a:buffer_lines)
    ++  call cursor(line('$'), col([line('$'), '$']))
    ++
    ++  " The PoC trigger -- direct invocation of the omnifunc with an empty base.
    ++  " This is the same path Vim takes for CTRL-X CTRL-O.
    ++  silent! call python3complete#Complete(0, '')
    ++
    ++  call assert_false(filereadable(a:marker_path),
    ++        \ a:msg . ' (marker ' . a:marker_path . ' was created)')
    ++
    ++  bwipe!
    ++  unlet! g:pythoncomplete_allow_import
    ++endfunc
    ++
    ++func Test_python3complete_no_exec_via_function_default()
    ++  let marker = tempname()
    ++  call s:CompleteAndExpectNoMarker([
    ++        \ 'def f(x=open(' . string(marker) . ', "w").close()):',
    ++        \ '    pass',
    ++        \ 'f.',
    ++        \ ], marker,
    ++        \ 'function default expression was evaluated during omni-completion')
    ++endfunc
    ++
    ++func Test_python3complete_no_exec_via_function_annotation()
    ++  let marker = tempname()
    ++  call s:CompleteAndExpectNoMarker([
    ++        \ 'def f(x: open(' . string(marker) . ', "w").close()):',
    ++        \ '    pass',
    ++        \ 'f.',
    ++        \ ], marker,
    ++        \ 'function annotation expression was evaluated during omni-completion')
    ++endfunc
    ++
    ++func Test_python3complete_no_exec_via_class_base()
    ++  let marker = tempname()
    ++  " "or object" gives the class a valid base after the side-effecting
    ++  " open().close() expression returns None.  Without "or object" the
    ++  " exec would raise TypeError, but the file would still be created
    ++  " before the exception -- the assertion would still hold.  Using
    ++  " "or object" keeps the buffer parseable as valid Python.
    ++  call s:CompleteAndExpectNoMarker([
    ++        \ 'class Foo(open(' . string(marker) . ', "w").close() or object):',
    ++        \ '    pass',
    ++        \ 'Foo.',
    ++        \ ], marker,
    ++        \ 'class base expression was evaluated during omni-completion')
    ++endfunc
    ++
    ++func Test_python3complete_no_exec_with_multiple_params()
    ++  " The strip must apply to every parameter, not just the first.
    ++  let marker = tempname()
    ++  call s:CompleteAndExpectNoMarker([
    ++        \ 'def f(a, b=1, c=open(' . string(marker) . ', "w").close(), d=2):',
    ++        \ '    pass',
    ++        \ 'f.',
    ++        \ ], marker,
    ++        \ 'non-first parameter default was evaluated during omni-completion')
    ++endfunc
    ++
    ++func Test_python3complete_no_exec_via_starargs_default()
    ++  " "*args" and "**kw" must still be preserved after stripping; ensure a
    ++  " default following them is also stripped.
    ++  let marker = tempname()
    ++  call s:CompleteAndExpectNoMarker([
    ++        \ 'def f(*args, key=open(' . string(marker) . ', "w").close(), **kw):',
    ++        \ '    pass',
    ++        \ 'f.',
    ++        \ ], marker,
    ++        \ 'keyword-only default after *args was evaluated during omni-completion')
    ++endfunc
    ++
    ++func Test_python3complete_normal_completion_still_works()
    ++  " Positive control: completion against a buffer with a legitimate class
    ++  " must still produce completion items.  The stripping logic should not
    ++  " break the normal completion path.
    ++  let g:pythoncomplete_allow_import = 0
    ++
    ++  new
    ++  setfiletype python
    ++  call setline(1, [
    ++        \ 'class MyHelper:',
    ++        \ '    def alpha(self): pass',
    ++        \ '    def beta(self): pass',
    ++        \ 'h = MyHelper()',
    ++        \ 'h.',
    ++        \ ])
    ++  call cursor(5, 3)
    ++
    ++  " First call returns the column to start completion at; second returns
    ++  " the list of completion items.
    ++  let start = python3complete#Complete(1, '')
    ++  call assert_true(start >= 0,
    ++        \ 'python3complete#Complete(1, "") returned ' . start)
    ++
    ++  let items = python3complete#Complete(0, '')
    ++  " Items should be a list (possibly empty if the parser can't resolve "h",
    ++  " but should not be a parse error from our stripping changes).
    ++  call assert_equal(type([]), type(items),
    ++        \ 'python3complete#Complete(0, "") did not return a list')
    ++
    ++  bwipe!
    ++  unlet! g:pythoncomplete_allow_import
    ++endfunc
    ++
    ++func Test_python3complete_inherited_completion_via_dotted_base()
    ++  " Positive control for the class-base whitelist: a dotted-name base class
    ++  " (the common, safe case) must still be carried into the reconstructed
    ++  " source so that completion on a subclass can resolve inherited members.
    ++  let g:pythoncomplete_allow_import = 0
    ++
    ++  new
    ++  setfiletype python
    ++  call setline(1, [
    ++        \ 'class Base:',
    ++        \ '    def shared(self): pass',
    ++        \ 'class Derived(Base):',
    ++        \ '    def own(self): pass',
    ++        \ 'd = Derived()',
    ++        \ 'd.',
    ++        \ ])
    ++  call cursor(6, 3)
    ++
    ++  let items = python3complete#Complete(0, '')
    ++  call assert_equal(type([]), type(items),
    ++        \ 'completion against a subclass with a dotted base did not return a list')
    ++
    ++  bwipe!
    ++  unlet! g:pythoncomplete_allow_import
    ++endfunc
    ++
    ++" Build a tiny Python module that creates a marker file as a side effect of
    ++" being imported, add its directory to sys.path, run omni-completion against
    ++" a buffer containing `import vimtest_marker_mod`, and report whether the
    ++" marker file was created.  Used by the two allow_import tests below.
    ++func s:RunImportCompletion(allow_import_value)
    ++  let g:pythoncomplete_allow_import = a:allow_import_value
    ++  let marker = tempname()
    ++  let module_dir = tempname()
    ++  call mkdir(module_dir, 'R')
    ++
    ++  call writefile([
    ++        \ 'open(' . string(marker) . ', "w").close()',
    ++        \ ], module_dir . '/vimtest_marker_mod.py')
    ++
    ++  defer delete(marker)
    ++
    ++  " Pass module_dir to Python via a g: variable so vim.eval() can read it.
    ++  let g:pythoncomplete_test_module_dir = module_dir
    ++  py3 << EOF
    ++import sys, vim
    ++_p = vim.eval('g:pythoncomplete_test_module_dir')
    ++if _p not in sys.path:
    ++    sys.path.insert(0, _p)
    ++# Drop any cached copy so the module body re-runs and the marker side
    ++# effect fires on import.
    ++sys.modules.pop('vimtest_marker_mod', None)
    ++EOF
    ++
    ++  new
    ++  setfiletype python
    ++  call setline(1, [
    ++        \ 'import vimtest_marker_mod',
    ++        \ 'vimtest_marker_mod.',
    ++        \ ])
    ++  call cursor(2, 2)
    ++
    ++  silent! call python3complete#Complete(0, '')
    ++
    ++  let ran = filereadable(marker)
    ++
    ++  bwipe!
    ++  unlet g:pythoncomplete_allow_import
    ++
    ++  " Teardown: restore sys.path, drop the cached module so a subsequent
    ++  " test run starts clean, clean up the temp module dir.
    ++  py3 << EOF
    ++import sys, vim
    ++_p = vim.eval('g:pythoncomplete_test_module_dir')
    ++if _p in sys.path:
    ++    sys.path.remove(_p)
    ++sys.modules.pop('vimtest_marker_mod', None)
    ++EOF
    ++  unlet g:pythoncomplete_test_module_dir
    ++  call delete(module_dir, 'rf')
    ++  call delete(marker)
    ++  unlet! g:pythoncomplete_allow_import
    ++
    ++  return ran
    ++endfunc
    ++
    ++func Test_python3complete_allow_import_off_blocks_imports()
    ++  " GHSA-52mc-rq6p-rc7c mitigation: with the default flag value (0), an
    ++  " `import` line harvested from the buffer must NOT be exec()'d.  The
    ++  " marker module's side effect (creating a file when its body runs) is
    ++  " the observable proof that the exec did or did not happen.
    ++  call assert_false(s:RunImportCompletion(0),
    ++        \ 'g:pythoncomplete_allow_import=0 did not block the buffer import')
    ++endfunc
    ++
    ++func Test_python3complete_allow_import_on_runs_imports()
    ++  " Symmetric positive control: with the flag set to non-zero, the harvested
    ++  " import IS exec()'d and the module loads.  Without this control the
    ++  " negative test above could pass for unrelated reasons (e.g. completion
    ++  " failing to parse the buffer at all).
    ++  call assert_true(s:RunImportCompletion(1),
    ++        \ 'g:pythoncomplete_allow_import=1 did not run the buffer import')
    ++endfunc
    ++
    ++" vim: shiftwidth=2 sts=2 expandtab
    +-- 
    +2.34.1
    +
    diff --git a/meta/recipes-support/vim/vim.inc b/meta/recipes-support/vim/vim.inc
    index 9a4b21f5305..d69a337b4e8 100644
    --- a/meta/recipes-support/vim/vim.inc
    +++ b/meta/recipes-support/vim/vim.inc
    @@ -33,6 +33,9 @@ SRC_URI = "git://github.com/vim/vim.git;branch=master;protocol=https \
                file://CVE-2026-45130.patch \
                file://CVE-2026-46483.patch \
                file://CVE-2026-28420.patch \
    +           file://CVE-2026-52858.patch \
    +           file://CVE-2026-52859.patch \
    +           file://CVE-2026-52860.patch \
                "
     
     PV .= ".1683"
    
    From patchwork Mon Jul 20 17:23:00 2026
    Content-Type: text/plain; charset="utf-8"
    MIME-Version: 1.0
    Content-Transfer-Encoding: 8bit
    X-Patchwork-Submitter: Yoann Congal 
    X-Patchwork-Id: 92929
    Return-Path: 
    X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on
    	aws-us-west-2-korg-lkml-1.web.codeaurora.org
    Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org
     (localhost.localdomain [127.0.0.1])
    	by smtp.lore.kernel.org (Postfix) with ESMTP id 98F40C44532
    	for ; Mon, 20 Jul 2026 17:23:58 +0000 (UTC)
    Received: from mail-wm1-f49.google.com (mail-wm1-f49.google.com
     [209.85.128.49])
     by mx.groups.io with SMTP id smtpd.msgproc02-g2.2886.1784568229781175492
     for ;
     Mon, 20 Jul 2026 10:23:50 -0700
    Authentication-Results: mx.groups.io;
     dkim=pass header.i=@smile.fr header.s=google header.b=FUeiiN2X;
     spf=pass (domain: smile.fr, ip: 209.85.128.49,
     mailfrom: yoann.congal@smile.fr)
    Received: by mail-wm1-f49.google.com with SMTP id
     5b1f17b1804b1-493b966dd74so44198705e9.3
            for ;
     Mon, 20 Jul 2026 10:23:49 -0700 (PDT)
    DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;
            d=smile.fr; s=google; t=1784568228; x=1785173028;
     darn=lists.openembedded.org;
            h=content-transfer-encoding:content-type:mime-version:references
             :in-reply-to:message-id:date:subject:to:from:from:to:cc:subject:date
             :message-id:reply-to:content-type;
            bh=9P3NumdHm6FJ9gxvy7Mds+RG1z9R30ElxoUBV3kaLw0=;
            b=FUeiiN2XXmY+rjQCJlXfkOHcLAvktJVPODDjPHsLSwY6adrIdUTfctfXDOdHbX+zxZ
             jsuvnc2ynZ9StDWQ8BsEUY7zcyX/8RLcH78xcv4UqFvwkH/+CHJx93Y3V39FNv8RCZF+
             Xugp3DGMbRDtt+IpIZcZd4oYHpSgFpRoPjB1g=
    X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;
            d=1e100.net; s=20251104; t=1784568228; x=1785173028;
            h=content-transfer-encoding:content-type:mime-version:references
             :in-reply-to:message-id:date:subject:to:from:x-gm-gg
             :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to
             :content-type;
            bh=9P3NumdHm6FJ9gxvy7Mds+RG1z9R30ElxoUBV3kaLw0=;
            b=JCwiOt7kCRtM+GiQsS90z02QIQ+6Alj0unw+kox86mlcCi1wsB3DakMAf+S5psdZKW
             K569Ei1a0X6Ghf+8jugHQw6VV12xwJcp0bP+xhuzFb3+EmfzMmCtanZeudr+cnwIL/um
             yLkLnI+F4GDBI0eOQY126sthTm/kCfF8VHP/NH7Oxmq3HHrT8C7m0qTM42nM/j6no8c7
             KRBhbWIljKRjCXuJXbglIVwwga8YBBFTh6Xt2B5lNPfdCXIDQWVVcKJfnfLIdEQBJGrW
             Wnq5y+TNg4GO+cyA33BxgEvK+Vfqt/1M5OT+Jpo6iSWGbIdraHmuCjrxreBoD8buYfeI
             OKgQ==
    X-Gm-Message-State: AOJu0YxToMmA4nnJeRiX8miolck2M4I6jZYeucSosWV/o7dqoNgZEB7I
    	wF/T64JtbvXTXQB4kZyyVca5Cq+c0Q9JR+QyLxNrJVnraxK02oUAAcEfhFg3p0+ml70YNEXK/j1
    	ZU3zH+nQ=
    X-Gm-Gg: AfdE7cmswignbG9z5Zw+r2kQYPBLUg4U7OEGI5xMWDy3PD3QbmD9df9rHmN+31D9AI2
    	0hXJCPP6qmkcbjn/t2M7Pa08NWbhv49y7WgZtFp7b20NpG2jn9uiFwx4Z1ZX0X1+JQdkcYX8Lk2
    	GSwPLsAfNFXSavX33ugBffau2E/GEWit5ibTp6mHJ4wvVQQDx1vXqYcL3zL2t7nI14AqHYoF6Kf
    	blcyMPvY87nDidJek+wGwwy1Ly+6/hJRZq7E1ueedODSwmJ773dmwOve9ysSM1ZPrWKuG5Xx636
    	tx5Vg+nEaW60cdbq/3Cu3/sbvRxKps+VkTKPl5TEbqctsmxtp/4T3W8lg9y23IjrL8KJUYBV3CV
    	aPxppyo8gJmthdiDloZ07fYWUssERrQNzVaU2xKeN9u7KhBhwEOLRyDB9UIKfp2bK8atAAMjOUH
    	d7nf3qWcX8s4XW8MHYuEdkR4BDbLKPwIInPkPhLoBKLSz0J/Uyidwdid/DilCu4T++iZCAWxQMu
    	1DYbuUfJBLouNYP2oY=
    X-Received: by 2002:a05:600c:4fc9:b0:493:e974:41ac with SMTP id
     5b1f17b1804b1-4954a3f3b28mr176208975e9.16.1784568227935;
            Mon, 20 Jul 2026 10:23:47 -0700 (PDT)
    Received: from localhost.localdomain
     (2a02-8440-b501-5b7b-2580-caa3-ecc1-dea5.rev.sfr.net.
     [2a02:8440:b501:5b7b:2580:caa3:ecc1:dea5])
            by smtp.gmail.com with ESMTPSA id
     5b1f17b1804b1-49563eee22esm36508575e9.1.2026.07.20.10.23.47
            for 
            (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256);
            Mon, 20 Jul 2026 10:23:47 -0700 (PDT)
    From: Yoann Congal 
    To: openembedded-core@lists.openembedded.org
    Subject: [OE-core][scarthgap 27/33] glib-2.0: fix CVE-2026-58016
    Date: Mon, 20 Jul 2026 19:23:00 +0200
    Message-ID: 
     <7f3c6a5a0448ffc862c7700a19759f47b2f414c5.1784567958.git.yoann.congal@smile.fr>
    X-Mailer: git-send-email 2.47.3
    In-Reply-To: 
    References: 
    MIME-Version: 1.0
    List-Id: 
    X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com
     [45.33.107.173] by
     aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for
     ; Mon, 20 Jul 2026 17:23:58 -0000
    X-Groupsio-URL: 
     https://lists.openembedded.org/g/openembedded-core/message/241461
    
    From: Benjamin Robin (Schneider Electric) 
    
    A flaw was found in GLib. A state confusion issue exists in
    g_dbus_node_info_new_for_xml() in the gio/gdbusintrospection.c file when
    processing malformed D-Bus introspection XML, specifically with a 
    element nested within other elements like , , 
    or . This issue can cause an unsigned integer overflow and lead to an
    out-of-bounds read, resulting in a denial of service.
    
    The CVE NVD entry is wrong, it indicates that the CVE is fixed in 2.88.1
    but the fix was realized in 2.89.0, see [1]. The fix is not present in 2.88.2.
    
    [1] https://gitlab.gnome.org/GNOME/glib/-/commit/c9da977c178fbfc0e4caf99f9fdf5dc433d6fcc2
    
    Signed-off-by: Benjamin Robin (Schneider Electric) 
    Signed-off-by: Mathieu Dubois-Briand 
    Signed-off-by: Richard Purdie 
    (cherry picked from commit d52f4d582cc71ada3c8ebe54be1a5b70278ea1ca)
    [YC: re-added the removed Signed-off-bys from the patches]
    Signed-off-by: Yoann Congal 
    ---
     .../glib-2.0/glib-2.0/CVE-2026-58016-1.patch  | 94 ++++++++++++++++++
     .../glib-2.0/glib-2.0/CVE-2026-58016-2.patch  | 98 +++++++++++++++++++
     meta/recipes-core/glib-2.0/glib-2.0_2.78.6.bb |  2 +
     3 files changed, 194 insertions(+)
     create mode 100644 meta/recipes-core/glib-2.0/glib-2.0/CVE-2026-58016-1.patch
     create mode 100644 meta/recipes-core/glib-2.0/glib-2.0/CVE-2026-58016-2.patch
    
    diff --git a/meta/recipes-core/glib-2.0/glib-2.0/CVE-2026-58016-1.patch b/meta/recipes-core/glib-2.0/glib-2.0/CVE-2026-58016-1.patch
    new file mode 100644
    index 00000000000..2c4b248b97b
    --- /dev/null
    +++ b/meta/recipes-core/glib-2.0/glib-2.0/CVE-2026-58016-1.patch
    @@ -0,0 +1,94 @@
    +From 38eee3870fbcf6bdf8e6b1281bc7a98d32b68521 Mon Sep 17 00:00:00 2001
    +From: Philip Withnall 
    +Date: Thu, 16 Apr 2026 15:27:37 +0100
    +Subject: [PATCH 1/2] gdbusintrospection: Fix XML parser state handling for
    +  element nesting
    +
    +The check for whether a `` element in D-Bus introspection XML was
    +nested correctly was broken. `` elements can only be at the top
    +level, or nested immediately within another `` element.
    +
    +Fix the check and add some unit tests for it.
    +
    +Spotted by linhlhq as #YWH-PGM9867-204. The fix is mine, and the unit test
    +uses example XML strings adapted from their report.
    +
    +Signed-off-by: Philip Withnall 
    +
    +Fixes: #3932
    +
    +CVE: CVE-2026-58016
    +Upstream-Status: Backport [https://gitlab.gnome.org/GNOME/glib/-/commit/c9da977c178fbfc0e4caf99f9fdf5dc433d6fcc2]
    +
    +Signed-off-by: Benjamin Robin 
    +---
    + gio/gdbusintrospection.c        |  2 +-
    + gio/tests/gdbus-introspection.c | 33 +++++++++++++++++++++++++++++++++
    + 2 files changed, 34 insertions(+), 1 deletion(-)
    +
    +diff --git a/gio/gdbusintrospection.c b/gio/gdbusintrospection.c
    +index c7be334ce2f7..6f722ee6153d 100644
    +--- a/gio/gdbusintrospection.c
    ++++ b/gio/gdbusintrospection.c
    +@@ -1272,7 +1272,7 @@ parser_start_element (GMarkupParseContext  *context,
    +   /* ---------------------------------------------------------------------------------------------------- */
    +   if (strcmp (element_name, "node") == 0)
    +     {
    +-      if (!(g_slist_length (stack) >= 1 || strcmp (stack->next->data, "node") != 0))
    ++      if (stack->next != NULL && strcmp (stack->next->data, "node") != 0)
    +         {
    +           g_set_error_literal (error,
    +                                G_MARKUP_ERROR,
    +diff --git a/gio/tests/gdbus-introspection.c b/gio/tests/gdbus-introspection.c
    +index 44cb7a96af45..daca313f77e7 100644
    +--- a/gio/tests/gdbus-introspection.c
    ++++ b/gio/tests/gdbus-introspection.c
    +@@ -299,6 +299,38 @@ test_extra_data (void)
    +   g_dbus_node_info_unref (info);
    + }
    +
    ++static void
    ++test_invalid (void)
    ++{
    ++  const struct
    ++    {
    ++      const char *xml;
    ++      GMarkupError expected_error_code;
    ++    }
    ++  vectors[] =
    ++    {
    ++      { "", G_MARKUP_ERROR_EMPTY },
    ++      { "", G_MARKUP_ERROR_INVALID_CONTENT },
    ++      { "", G_MARKUP_ERROR_INVALID_CONTENT },
    ++      { "", G_MARKUP_ERROR_INVALID_CONTENT },
    ++      { "", G_MARKUP_ERROR_INVALID_CONTENT },
    ++    };
    ++
    ++  for (size_t i = 0; i < G_N_ELEMENTS (vectors); i++)
    ++    {
    ++      GDBusNodeInfo *node;
    ++      GError *local_error = NULL;
    ++
    ++      g_test_message ("Testing parsing of %s gives an error", vectors[i].xml);
    ++
    ++      node = g_dbus_node_info_new_for_xml (vectors[i].xml, &local_error);
    ++      g_assert_error (local_error, G_MARKUP_ERROR, (int) vectors[i].expected_error_code);
    ++      g_assert_null (node);
    ++
    ++      g_clear_error (&local_error);
    ++    }
    ++}
    ++
    + /* ---------------------------------------------------------------------------------------------------- */
    +
    + int
    +@@ -316,6 +348,7 @@ main (int   argc,
    +   g_test_add_func ("/gdbus/introspection-generate", test_generate);
    +   g_test_add_func ("/gdbus/introspection-default-direction", test_default_direction);
    +   g_test_add_func ("/gdbus/introspection-extra-data", test_extra_data);
    ++  g_test_add_func ("/gdbus/introspection/invalid", test_invalid);
    +
    +   ret = session_bus_run ();
    +
    +--
    +2.54.0
    diff --git a/meta/recipes-core/glib-2.0/glib-2.0/CVE-2026-58016-2.patch b/meta/recipes-core/glib-2.0/glib-2.0/CVE-2026-58016-2.patch
    new file mode 100644
    index 00000000000..a61e35ad8a7
    --- /dev/null
    +++ b/meta/recipes-core/glib-2.0/glib-2.0/CVE-2026-58016-2.patch
    @@ -0,0 +1,98 @@
    +From a75052ceeebea434f271b670766acd5416bc83b9 Mon Sep 17 00:00:00 2001
    +From: Philip Withnall 
    +Date: Thu, 16 Apr 2026 15:08:10 +0100
    +Subject: [PATCH 2/2] gdbusintrospection: Add some assertions before array
    + dereferences
    +MIME-Version: 1.0
    +Content-Type: text/plain; charset=UTF-8
    +Content-Transfer-Encoding: 8bit
    +
    +The state handling inside the D-Bus introspection XML parser is
    +complicated, and it’s possible that these dereferences of the
    +`len - 1`th element might get reached when the array is empty.
    +
    +Make failures like that more debuggable by adding an assertion on the
    +length beforehand.
    +
    +Signed-off-by: Philip Withnall 
    +
    +Helps: #3932
    +
    +CVE: CVE-2026-58016
    +Upstream-Status: Backport [https://gitlab.gnome.org/GNOME/glib/-/commit/656ad4582cb1d7a7fa8bafe3ce8aec6aa3c17da0]
    +
    +Signed-off-by: Benjamin Robin 
    +---
    + gio/gdbusintrospection.c | 8 ++++++++
    + 1 file changed, 8 insertions(+)
    +
    +diff --git a/gio/gdbusintrospection.c b/gio/gdbusintrospection.c
    +index 6f722ee6153d..ed0d291f99f0 100644
    +--- a/gio/gdbusintrospection.c
    ++++ b/gio/gdbusintrospection.c
    +@@ -1110,6 +1110,7 @@ parse_data_get_annotation (ParseData *data,
    + {
    +   if (create_new)
    +     g_ptr_array_add (data->annotations, g_new0 (GDBusAnnotationInfo, 1));
    ++  g_assert (data->annotations->len > 0);
    +   return data->annotations->pdata[data->annotations->len - 1];
    + }
    +
    +@@ -1119,6 +1120,7 @@ parse_data_get_arg (ParseData *data,
    + {
    +   if (create_new)
    +     g_ptr_array_add (data->args, g_new0 (GDBusArgInfo, 1));
    ++  g_assert (data->args->len > 0);
    +   return data->args->pdata[data->args->len - 1];
    + }
    +
    +@@ -1128,6 +1130,7 @@ parse_data_get_out_arg (ParseData *data,
    + {
    +   if (create_new)
    +     g_ptr_array_add (data->out_args, g_new0 (GDBusArgInfo, 1));
    ++  g_assert (data->out_args->len > 0);
    +   return data->out_args->pdata[data->out_args->len - 1];
    + }
    +
    +@@ -1137,6 +1140,7 @@ parse_data_get_method (ParseData *data,
    + {
    +   if (create_new)
    +     g_ptr_array_add (data->methods, g_new0 (GDBusMethodInfo, 1));
    ++  g_assert (data->methods->len > 0);
    +   return data->methods->pdata[data->methods->len - 1];
    + }
    +
    +@@ -1146,6 +1150,7 @@ parse_data_get_signal (ParseData *data,
    + {
    +   if (create_new)
    +     g_ptr_array_add (data->signals, g_new0 (GDBusSignalInfo, 1));
    ++  g_assert (data->signals->len > 0);
    +   return data->signals->pdata[data->signals->len - 1];
    + }
    +
    +@@ -1155,6 +1160,7 @@ parse_data_get_property (ParseData *data,
    + {
    +   if (create_new)
    +     g_ptr_array_add (data->properties, g_new0 (GDBusPropertyInfo, 1));
    ++  g_assert (data->properties->len > 0);
    +   return data->properties->pdata[data->properties->len - 1];
    + }
    +
    +@@ -1164,6 +1170,7 @@ parse_data_get_interface (ParseData *data,
    + {
    +   if (create_new)
    +     g_ptr_array_add (data->interfaces, g_new0 (GDBusInterfaceInfo, 1));
    ++  g_assert (data->interfaces->len > 0);
    +   return data->interfaces->pdata[data->interfaces->len - 1];
    + }
    +
    +@@ -1173,6 +1180,7 @@ parse_data_get_node (ParseData *data,
    + {
    +   if (create_new)
    +     g_ptr_array_add (data->nodes, g_new0 (GDBusNodeInfo, 1));
    ++  g_assert (data->nodes->len > 0);
    +   return data->nodes->pdata[data->nodes->len - 1];
    + }
    +
    +--
    +2.54.0
    diff --git a/meta/recipes-core/glib-2.0/glib-2.0_2.78.6.bb b/meta/recipes-core/glib-2.0/glib-2.0_2.78.6.bb
    index b8212c9d12b..549584f3d8f 100644
    --- a/meta/recipes-core/glib-2.0/glib-2.0_2.78.6.bb
    +++ b/meta/recipes-core/glib-2.0/glib-2.0_2.78.6.bb
    @@ -47,6 +47,8 @@ SRC_URI = "${GNOME_MIRROR}/glib/${SHRT_VER}/glib-${PV}.tar.xz \
                file://CVE-2026-1489-02.patch \
                file://CVE-2026-1489-03.patch \
                file://CVE-2026-1489-04.patch \
    +           file://CVE-2026-58016-1.patch \
    +           file://CVE-2026-58016-2.patch \
                "
     SRC_URI:append:class-native = " file://relocate-modules.patch \
                                     file://0001-meson.build-do-not-enable-pidfd-features-on-native-g.patch \
    
    From patchwork Mon Jul 20 17:23:01 2026
    Content-Type: text/plain; charset="utf-8"
    MIME-Version: 1.0
    Content-Transfer-Encoding: 7bit
    X-Patchwork-Submitter: Yoann Congal 
    X-Patchwork-Id: 92926
    Return-Path: 
    X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on
    	aws-us-west-2-korg-lkml-1.web.codeaurora.org
    Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org
     (localhost.localdomain [127.0.0.1])
    	by smtp.lore.kernel.org (Postfix) with ESMTP id 83E72C44531
    	for ; Mon, 20 Jul 2026 17:23:58 +0000 (UTC)
    Received: from mail-wm1-f42.google.com (mail-wm1-f42.google.com
     [209.85.128.42])
     by mx.groups.io with SMTP id smtpd.msgproc02-g2.2887.1784568230362778133
     for ;
     Mon, 20 Jul 2026 10:23:50 -0700
    Authentication-Results: mx.groups.io;
     dkim=pass header.i=@smile.fr header.s=google header.b=M6EelP1j;
     spf=pass (domain: smile.fr, ip: 209.85.128.42,
     mailfrom: yoann.congal@smile.fr)
    Received: by mail-wm1-f42.google.com with SMTP id
     5b1f17b1804b1-493b966dd74so44198725e9.3
            for ;
     Mon, 20 Jul 2026 10:23:50 -0700 (PDT)
    DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;
            d=smile.fr; s=google; t=1784568228; x=1785173028;
     darn=lists.openembedded.org;
            h=content-transfer-encoding:mime-version:references:in-reply-to
             :message-id:date:subject:to:from:from:to:cc:subject:date:message-id
             :reply-to:content-type;
            bh=cvl40ylSj//ZYPWpz58sDO4+jy9TZukzrtBVAq5y9lo=;
            b=M6EelP1jcw+YcMq1KvR/f5nyf2+i5O+FFrWbC/jK7HlM0Fs2RNxjPMo5QpftT30GiC
             3fqw0aKfvey5iq96vJ45scl0nCHBomK3o3vEpO1O1mq/q84KIRArZC5GSko4ajzNwyy7
             3vGwPWTIcSZoVaYjDbLrfizmPzN4a8S9yfDy0=
    X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;
            d=1e100.net; s=20251104; t=1784568228; x=1785173028;
            h=content-transfer-encoding:mime-version:references:in-reply-to
             :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to
             :cc:subject:date:message-id:reply-to:content-type;
            bh=cvl40ylSj//ZYPWpz58sDO4+jy9TZukzrtBVAq5y9lo=;
            b=mZQEFxy/hI9Wcktyfj4Qh6JGiv3+xaVjqsZ5+ODa3QPVvKDZLX661cE7VNqXqqSYy3
             MX0rhrCADVw4oqs4n/F/yfZhpdztxdK8dQRGhiqj3CApokLKEq3fROASOjgUXPmC9qMC
             04+3nqneFMomDLtxaST0nw5cUvtxeLqiXkoejDilmorbTXMq4HSe72h2OJ3p/M953yon
             8aXNxTZ4iaw3klV58fHzSvAAEWKZjhQwXQwlfS0GhJgXHUuKGUHRIu9hodRUAXVGdugu
             jlmLjeypKUKNr1GjoFTSF2JgNkx8ZEW2NR2UTlnSky3JKTiOAtCVRsd1dCXSeYawcYva
             XQeQ==
    X-Gm-Message-State: AOJu0YyOIizfXGRYFhcePn4P5IvkSXXWnFH7rxuHOh00DJ8WicPn9dBP
    	IEmy6t3Q46kEKDCQg4m4BORpwtPZQPHh7MK4p7oKn1Pbqb4OSKj4ARUcK3cCVUtA1aqAmKKaHw3
    	nTTdjtsI=
    X-Gm-Gg: AfdE7cmobbhOqcrtjbKbxdSmmt3oIjj7aoVebDF03UWYBrNYO9zaHxUGIryN9pA2ES3
    	8VxJoJwHN0tRS333YGbX29nptiaeDDER+C91dkBvbFNs2MZHfzF3Nn7ORNCvcbbwIRiCKDkwy3M
    	wUuuN9ic1FmSYFIYx8YeVcliGi3h2BozQg9CG3YaLEGdgQbOtejEhp7ZHUuKVtWKpoM42I0G+fa
    	o37uIMneiGsMN6e7T18nj4R26jmcSSn5PE1uZ4TBcf98NfVldxcInnRDBggJ+4B+lQdR32sPe+J
    	AMDDI6ieXhnWU0p+77Y014p8tCSCE1eCz4yHJdRQW+UjRiYphHlNe8bp8+LDhyFjhiCe9Icwqkh
    	3V2qDKRGcVG6YT+z/IDnIoPiacYGIv48nnwcIEl5iR/9Wxa7OSH2irf+oyBoFyE75RNFM07OHqM
    	nqJU338p1yPyhJTuUzgyVKnOH30iZDL7C2+D9p8MMw/NswaWOjEWY04jmkEZGxHJemKOI36SvN/
    	rF6NHtw
    X-Received: by 2002:a05:600c:6212:b0:495:5375:2510 with SMTP id
     5b1f17b1804b1-495537526b4mr105901575e9.24.1784568228501;
            Mon, 20 Jul 2026 10:23:48 -0700 (PDT)
    Received: from localhost.localdomain
     (2a02-8440-b501-5b7b-2580-caa3-ecc1-dea5.rev.sfr.net.
     [2a02:8440:b501:5b7b:2580:caa3:ecc1:dea5])
            by smtp.gmail.com with ESMTPSA id
     5b1f17b1804b1-49563eee22esm36508575e9.1.2026.07.20.10.23.48
            for 
            (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256);
            Mon, 20 Jul 2026 10:23:48 -0700 (PDT)
    From: Yoann Congal 
    To: openembedded-core@lists.openembedded.org
    Subject: [OE-core][scarthgap 28/33] xmlto: update SRC_URI
    Date: Mon, 20 Jul 2026 19:23:01 +0200
    Message-ID: 
     
    X-Mailer: git-send-email 2.47.3
    In-Reply-To: 
    References: 
    MIME-Version: 1.0
    List-Id: 
    X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com
     [45.33.107.173] by
     aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for
     ; Mon, 20 Jul 2026 17:23:58 -0000
    X-Groupsio-URL: 
     https://lists.openembedded.org/g/openembedded-core/message/241462
    
    From: Ross Burton 
    
    xmlto was previously hosted on Fedora's pagure.io server, but this is
    being decomissioned. As xmlto isn't Fedora-specific the repository has
    migrated to codeberg.org.
    
    >From discussion with Michal Schorm :
    
      I became the new maintainer of the project upstream and after a
      discussion with Kevin Fenzi, migrated it to a new home on the
      codeberg.org: https://codeberg.org/xmlto/xmlto
    
    Signed-off-by: Ross Burton 
    Signed-off-by: Mathieu Dubois-Briand 
    Signed-off-by: Richard Purdie 
    (cherry picked from commit 0046c780bf612aa7946023f8993c45f0c0b65c08)
    Signed-off-by: Yoann Congal 
    ---
     meta/recipes-devtools/xmlto/xmlto_0.0.28.bb | 2 +-
     1 file changed, 1 insertion(+), 1 deletion(-)
    
    diff --git a/meta/recipes-devtools/xmlto/xmlto_0.0.28.bb b/meta/recipes-devtools/xmlto/xmlto_0.0.28.bb
    index d5a0e69849e..b7bfdb69bf0 100644
    --- a/meta/recipes-devtools/xmlto/xmlto_0.0.28.bb
    +++ b/meta/recipes-devtools/xmlto/xmlto_0.0.28.bb
    @@ -8,7 +8,7 @@ LIC_FILES_CHKSUM = "file://COPYING;md5=59530bdf33659b29e73d4adb9f9f6552"
     
     SRCREV = "6fa6a0e07644f20abf2596f78a60112713e11cbe"
     UPSTREAM_CHECK_COMMITS = "1"
    -SRC_URI = "git://pagure.io/xmlto.git;protocol=https;branch=master"
    +SRC_URI = "git://codeberg.org/xmlto/xmlto.git;protocol=https;branch=master"
     S = "${WORKDIR}/git"
     
     PV .= "+0.0.29+git"
    
    From patchwork Mon Jul 20 17:23:02 2026
    Content-Type: text/plain; charset="utf-8"
    MIME-Version: 1.0
    Content-Transfer-Encoding: 7bit
    X-Patchwork-Submitter: Yoann Congal 
    X-Patchwork-Id: 92924
    Return-Path: 
    X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on
    	aws-us-west-2-korg-lkml-1.web.codeaurora.org
    Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org
     (localhost.localdomain [127.0.0.1])
    	by smtp.lore.kernel.org (Postfix) with ESMTP id 64798C44530
    	for ; Mon, 20 Jul 2026 17:23:58 +0000 (UTC)
    Received: from mail-wm1-f47.google.com (mail-wm1-f47.google.com
     [209.85.128.47])
     by mx.groups.io with SMTP id smtpd.msgproc01-g2.2907.1784568230819479758
     for ;
     Mon, 20 Jul 2026 10:23:51 -0700
    Authentication-Results: mx.groups.io;
     dkim=pass header.i=@smile.fr header.s=google header.b=HB9S5xqk;
     spf=pass (domain: smile.fr, ip: 209.85.128.47,
     mailfrom: yoann.congal@smile.fr)
    Received: by mail-wm1-f47.google.com with SMTP id
     5b1f17b1804b1-495635a85d2so6239195e9.0
            for ;
     Mon, 20 Jul 2026 10:23:50 -0700 (PDT)
    DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;
            d=smile.fr; s=google; t=1784568229; x=1785173029;
     darn=lists.openembedded.org;
            h=content-transfer-encoding:mime-version:references:in-reply-to
             :message-id:date:subject:to:from:from:to:cc:subject:date:message-id
             :reply-to:content-type;
            bh=tu59LJJqXCreVJTXXGArLpUOZx3/D3UKy3zhMFY9Rh8=;
            b=HB9S5xqkXvM9ldfeVK0k3D+g84QrCjtYA2lQp5qAXyodwfehzZUtTrsRuKIBoJqLCK
             1sTr1YgY+VRPX6VIPbPXRlwPgbGjWMFTUC7K7LqN7FdKM3jRZAAO3WQb8GYNamYzq9jO
             VlCNR07WaUmB6ApCVdCAT+qEm99fu+DP/OP+U=
    X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;
            d=1e100.net; s=20251104; t=1784568229; x=1785173029;
            h=content-transfer-encoding:mime-version:references:in-reply-to
             :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to
             :cc:subject:date:message-id:reply-to:content-type;
            bh=tu59LJJqXCreVJTXXGArLpUOZx3/D3UKy3zhMFY9Rh8=;
            b=RpBiGQJsgFqAG5mw4Bjspr0jhZpYGxPyqhyrc4IcpYTAbOAkCdq6Net2IMJggCx+zV
             /WrrLX1ePwMASK6EDhGDDbEWStJH+rnr1QaR3mVJgdeLVffY5NGOAJZ5uW+oCw7x8Ynw
             rzUhfDP+rKtwSUVUeko4UzFH98N0fSKzn/8m1e0hFaVKm2P/ZMFEON+jMYpc/MqYEZ3x
             1PxMGWwj/02ysPFOSz7W52Vh/Ho9+udUmvq+F/hxjuNg437Vvxju4YFaFknKClLh5apm
             9fv/p7SeDuvobxrvvv9JQJ8kByrR8tLwkNcnsE9MKBfcCIp9Gss0AsfEH5zq9Qz2J6Ns
             XKuw==
    X-Gm-Message-State: AOJu0YyQsUn+kNCnUnnFIG9DYip2pIg3T+AYAJDH/+Py/6FxLXszs/IO
    	s0HldPPbZ9bD3WYw2F5kFBGcBbDkfdnu1SQcq5+JH/DN6YFGzPTP+WsuJDN/ye4QWtrl0Ljd4gq
    	NhoCu5pI=
    X-Gm-Gg: AfdE7cntRw8fUI+Rujm9q2E9iRuskqXVTy3jZs9Pg2A9GMF8aDuIf8YB8WdBvJbDn4O
    	AAclxlEXXsJN7SehEHlVQuqrYNvm46skc4NU8jpxFsYgqU4dSJUKjCtAW07VQ6jxx4EBbXgfkBR
    	xK7Ra2GykFAHWLxxeWg7J5AMNv2K4VaMwoX3r74hKZzDQkSQnH/SFafeSMj633KtJpyEOnvE5i2
    	zZAZcmiassK/A8nExyvqi2WZBLWXNQ3oX1C7+geT7bWPVa2LYLmMgMwyeHDC2rX2miTWaIkUT1N
    	/rJkiOM1NhmbYHljKhDVUaHv0ePY49PdHNaf7RSR/vBAbJjoFzfGYDT6E9cmIOhJ7d0m9WyIoyA
    	ILEFPx4+9/oHnl4xmJeM+SC607Ckoe27CSAKy8Okzu36YYMbWw8D5jjE5CUFITTZRgpr8a3L0nE
    	I/G9fOxcQ4pRMytdwS9E7IIyXcNDjfwOoAyQQ8YJ41xr/mIgC10DEhubSroMMVJbQPimCKIFxYk
    	IHcXw8l
    X-Received: by 2002:a05:600c:4e88:b0:495:636b:e519 with SMTP id
     5b1f17b1804b1-495636bea4dmr30733625e9.21.1784568229051;
            Mon, 20 Jul 2026 10:23:49 -0700 (PDT)
    Received: from localhost.localdomain
     (2a02-8440-b501-5b7b-2580-caa3-ecc1-dea5.rev.sfr.net.
     [2a02:8440:b501:5b7b:2580:caa3:ecc1:dea5])
            by smtp.gmail.com with ESMTPSA id
     5b1f17b1804b1-49563eee22esm36508575e9.1.2026.07.20.10.23.48
            for 
            (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256);
            Mon, 20 Jul 2026 10:23:48 -0700 (PDT)
    From: Yoann Congal 
    To: openembedded-core@lists.openembedded.org
    Subject: [OE-core][scarthgap 29/33] wireless-regdb: upgrade 2026.02.04 ->
     2026.03.18
    Date: Mon, 20 Jul 2026 19:23:02 +0200
    Message-ID: 
     
    X-Mailer: git-send-email 2.47.3
    In-Reply-To: 
    References: 
    MIME-Version: 1.0
    List-Id: 
    X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com
     [45.33.107.173] by
     aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for
     ; Mon, 20 Jul 2026 17:23:58 -0000
    X-Groupsio-URL: 
     https://lists.openembedded.org/g/openembedded-core/message/241463
    
    From: Ankur Tyagi 
    
    Signed-off-by: Ankur Tyagi 
    Signed-off-by: Richard Purdie 
    (cherry picked from commit 97a940bfdeaa3f9f4442a6fbb0fabe1ce5eaff69)
    Signed-off-by: Ankur Tyagi 
    [YC: Changelog:
    https://git.kernel.org/pub/scm/linux/kernel/git/wens/wireless-regdb.git/log/?qt=range&q=master-2026-02-04..master-2026-03-18
    "wireless-regdb: Replace M2Crypto with cryptography package" only
    impacts signing code that maintainers run.
    ]
    Signed-off-by: Yoann Congal 
    ---
     ...ireless-regdb_2026.02.04.bb => wireless-regdb_2026.03.18.bb} | 2 +-
     1 file changed, 1 insertion(+), 1 deletion(-)
     rename meta/recipes-kernel/wireless-regdb/{wireless-regdb_2026.02.04.bb => wireless-regdb_2026.03.18.bb} (94%)
    
    diff --git a/meta/recipes-kernel/wireless-regdb/wireless-regdb_2026.02.04.bb b/meta/recipes-kernel/wireless-regdb/wireless-regdb_2026.03.18.bb
    similarity index 94%
    rename from meta/recipes-kernel/wireless-regdb/wireless-regdb_2026.02.04.bb
    rename to meta/recipes-kernel/wireless-regdb/wireless-regdb_2026.03.18.bb
    index 2f7c8160434..a70e9dd0dae 100644
    --- a/meta/recipes-kernel/wireless-regdb/wireless-regdb_2026.02.04.bb
    +++ b/meta/recipes-kernel/wireless-regdb/wireless-regdb_2026.03.18.bb
    @@ -5,7 +5,7 @@ LICENSE = "ISC"
     LIC_FILES_CHKSUM = "file://LICENSE;md5=07c4f6dea3845b02a18dc00c8c87699c"
     
     SRC_URI = "https://www.kernel.org/pub/software/network/${BPN}/${BP}.tar.xz"
    -SRC_URI[sha256sum] = "0ff48a5cd9e9cfe8e815a24e023734919e9a3b7ad2f039243ad121cf5aabf6c6"
    +SRC_URI[sha256sum] = "5fc0000475d8c5368ccc5222827c16aef98b1eb6a69c9b5a3e7b7e98528945ac"
     
     inherit bin_package allarch
     
    
    From patchwork Mon Jul 20 17:23:03 2026
    Content-Type: text/plain; charset="utf-8"
    MIME-Version: 1.0
    Content-Transfer-Encoding: 7bit
    X-Patchwork-Submitter: Yoann Congal 
    X-Patchwork-Id: 92927
    Return-Path: 
    X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on
    	aws-us-west-2-korg-lkml-1.web.codeaurora.org
    Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org
     (localhost.localdomain [127.0.0.1])
    	by smtp.lore.kernel.org (Postfix) with ESMTP id 52027C4452D
    	for ; Mon, 20 Jul 2026 17:23:58 +0000 (UTC)
    Received: from mail-wr1-f41.google.com (mail-wr1-f41.google.com
     [209.85.221.41])
     by mx.groups.io with SMTP id smtpd.msgproc02-g2.2889.1784568231465534911
     for ;
     Mon, 20 Jul 2026 10:23:51 -0700
    Authentication-Results: mx.groups.io;
     dkim=pass header.i=@smile.fr header.s=google header.b=C679SxmX;
     spf=pass (domain: smile.fr, ip: 209.85.221.41,
     mailfrom: yoann.congal@smile.fr)
    Received: by mail-wr1-f41.google.com with SMTP id
     ffacd0b85a97d-471eeac43bfso9699853f8f.3
            for ;
     Mon, 20 Jul 2026 10:23:51 -0700 (PDT)
    DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;
            d=smile.fr; s=google; t=1784568230; x=1785173030;
     darn=lists.openembedded.org;
            h=content-transfer-encoding:mime-version:references:in-reply-to
             :message-id:date:subject:to:from:from:to:cc:subject:date:message-id
             :reply-to:content-type;
            bh=MCRovVGnOGwfD/CiXgpqwaGzJbs9CFRTDuY9AqGUuVs=;
            b=C679SxmX5F5dw2Ax/jncPUy4nIyAtKKnESb9C+b/7eAHgpNbfl4wIr76ALmcJgvnkk
             TDpKWQlLLssIrjVIL6o8zxZarzfx/VMRrCDUkQAz2AL20Ru03SPpwEGGXR5Z4HMpgonb
             WFXSfDDb5jBpD2JSo+0wY2Xr/hYdc16Qm0mmo=
    X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;
            d=1e100.net; s=20251104; t=1784568230; x=1785173030;
            h=content-transfer-encoding:mime-version:references:in-reply-to
             :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to
             :cc:subject:date:message-id:reply-to:content-type;
            bh=MCRovVGnOGwfD/CiXgpqwaGzJbs9CFRTDuY9AqGUuVs=;
            b=QlpYI4MKGp4Kq+p15kgI7YCvBRb/Ongvs6cd0Erxzjy8L0y91c1xDa4qSjWLsE/UGZ
             trqS42f9c+XNcz7Y7NyAP8zjguW9lgQqDEUQs3u72RVdiE+Lky+kgmKZ5lWqHJZ9ybR3
             GUePIxKPv534WV/AFL6goLl78mhw64jLW8oNVWCrMMCKLGTjLS6i4XO34v9ccXNT7Hv6
             R7LAbVd5OGbh9BGhjnNxVcQi/OlJeoHcGUjA94ccD48t+dttV80uYcVnyK4TBwIQ2k7l
             vZ1gBqcxxcnbZ3vqhMHokrC494H+AlMmZUXQSXrOvWD5RYCELAJZGBCwBAVkGd0GQoBO
             TJsw==
    X-Gm-Message-State: AOJu0Yx6U/lQ5Lp15Ry3xvjiErfPKtQt3em137yX16Ob62LZzNrHOVXV
    	/EigQssBm4yGxicnRdLoY+RlcYE0hxLhp4nmM82aLpz7yniP9DIETvDaAoamO6vVRE5MnZP5OGt
    	5aJQqVNI=
    X-Gm-Gg: AfdE7cmtQ+xvLtGaTUjzxpWQwd+87wj0YICSFG1FOOltyyAKw3OnhuJKflhnqPbh3Y7
    	0vBtWu2ebgFOTBJ0aFVc4emoJv+18+6ggU4Dt/qxELC3TcLaAkE497vriuK7iu0nR2TBlKQFC8g
    	Zz+Ww+mN9l9mtcfKWXEK2gGf3L+8byYHH7SKfdUjl8IKPg0wPYo2X+UJ5c1exyFDLgnZWwLVUqq
    	USzAUq8W/24OHRlQHwsND+djthskl5hcWZ51b9dUUGxl6XNxRtniZWmdxB1hcBmrjXUaiRp4Jqw
    	plNWz1vCwYnldV/K39/putJQu3jBCKn/CoY9Y5EKjXMglVgZJqZu6zTLdkztpkqCF14aZ8kL0uu
    	C/nbcVg42Kd4TD+1bfOEjvzV6UZPoMDktopHgS9Xxre5pZ1SHuKtHLCUoV7FXZoCQ5OUyOeIwIX
    	pWwSQJmjIZFLTdry5SbdzMa38DRbKBVu3Fn9b7wYO/76Sy4cuX4AGROGg92eQpgP+bAucO/5E4V
    	ta9RVDy
    X-Received: by 2002:a05:600c:3baa:b0:495:52a5:8815 with SMTP id
     5b1f17b1804b1-49552a588admr144693635e9.6.1784568229655;
            Mon, 20 Jul 2026 10:23:49 -0700 (PDT)
    Received: from localhost.localdomain
     (2a02-8440-b501-5b7b-2580-caa3-ecc1-dea5.rev.sfr.net.
     [2a02:8440:b501:5b7b:2580:caa3:ecc1:dea5])
            by smtp.gmail.com with ESMTPSA id
     5b1f17b1804b1-49563eee22esm36508575e9.1.2026.07.20.10.23.49
            for 
            (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256);
            Mon, 20 Jul 2026 10:23:49 -0700 (PDT)
    From: Yoann Congal 
    To: openembedded-core@lists.openembedded.org
    Subject: [OE-core][scarthgap 30/33] wireless-regdb: upgrade 2026.03.18 ->
     2026.05.30
    Date: Mon, 20 Jul 2026 19:23:03 +0200
    Message-ID: 
     
    X-Mailer: git-send-email 2.47.3
    In-Reply-To: 
    References: 
    MIME-Version: 1.0
    List-Id: 
    X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com
     [45.33.107.173] by
     aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for
     ; Mon, 20 Jul 2026 17:23:58 -0000
    X-Groupsio-URL: 
     https://lists.openembedded.org/g/openembedded-core/message/241464
    
    From: Ankur Tyagi 
    
    Signed-off-by: Ankur Tyagi 
    Signed-off-by: Richard Purdie 
    (cherry picked from commit 86e35bc1ab5fb2132b06b666fe73fc9bd6446ab6)
    Signed-off-by: Ankur Tyagi 
    [YC: Changelog:
    https://git.kernel.org/pub/scm/linux/kernel/git/wens/wireless-regdb.git/log/?qt=range&q=master-2026-03-18..master-2026-05-30
    ]
    Signed-off-by: Yoann Congal 
    ---
     ...ireless-regdb_2026.03.18.bb => wireless-regdb_2026.05.30.bb} | 2 +-
     1 file changed, 1 insertion(+), 1 deletion(-)
     rename meta/recipes-kernel/wireless-regdb/{wireless-regdb_2026.03.18.bb => wireless-regdb_2026.05.30.bb} (94%)
    
    diff --git a/meta/recipes-kernel/wireless-regdb/wireless-regdb_2026.03.18.bb b/meta/recipes-kernel/wireless-regdb/wireless-regdb_2026.05.30.bb
    similarity index 94%
    rename from meta/recipes-kernel/wireless-regdb/wireless-regdb_2026.03.18.bb
    rename to meta/recipes-kernel/wireless-regdb/wireless-regdb_2026.05.30.bb
    index a70e9dd0dae..e544b729656 100644
    --- a/meta/recipes-kernel/wireless-regdb/wireless-regdb_2026.03.18.bb
    +++ b/meta/recipes-kernel/wireless-regdb/wireless-regdb_2026.05.30.bb
    @@ -5,7 +5,7 @@ LICENSE = "ISC"
     LIC_FILES_CHKSUM = "file://LICENSE;md5=07c4f6dea3845b02a18dc00c8c87699c"
     
     SRC_URI = "https://www.kernel.org/pub/software/network/${BPN}/${BP}.tar.xz"
    -SRC_URI[sha256sum] = "5fc0000475d8c5368ccc5222827c16aef98b1eb6a69c9b5a3e7b7e98528945ac"
    +SRC_URI[sha256sum] = "8a27bfc081bafed8c24dd70fab0d96f098e5a0bfcd08d3da672595f225ab8993"
     
     inherit bin_package allarch
     
    
    From patchwork Mon Jul 20 17:23:04 2026
    Content-Type: text/plain; charset="utf-8"
    MIME-Version: 1.0
    Content-Transfer-Encoding: 7bit
    X-Patchwork-Submitter: Yoann Congal 
    X-Patchwork-Id: 92928
    Return-Path: 
    X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on
    	aws-us-west-2-korg-lkml-1.web.codeaurora.org
    Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org
     (localhost.localdomain [127.0.0.1])
    	by smtp.lore.kernel.org (Postfix) with ESMTP id 3EF68C4452E
    	for ; Mon, 20 Jul 2026 17:23:58 +0000 (UTC)
    Received: from mail-wm1-f51.google.com (mail-wm1-f51.google.com
     [209.85.128.51])
     by mx.groups.io with SMTP id smtpd.msgproc01-g2.2908.1784568231997676613
     for ;
     Mon, 20 Jul 2026 10:23:52 -0700
    Authentication-Results: mx.groups.io;
     dkim=pass header.i=@smile.fr header.s=google header.b=n9prhUw7;
     spf=pass (domain: smile.fr, ip: 209.85.128.51,
     mailfrom: yoann.congal@smile.fr)
    Received: by mail-wm1-f51.google.com with SMTP id
     5b1f17b1804b1-49546c690ffso27068745e9.2
            for ;
     Mon, 20 Jul 2026 10:23:51 -0700 (PDT)
    DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;
            d=smile.fr; s=google; t=1784568230; x=1785173030;
     darn=lists.openembedded.org;
            h=content-transfer-encoding:mime-version:references:in-reply-to
             :message-id:date:subject:to:from:from:to:cc:subject:date:message-id
             :reply-to:content-type;
            bh=LcjM3QIGZ88azbBEvxRrNQ6CF+nlAFxsDxani6ZKRC0=;
            b=n9prhUw7FGrbflSRbz4Avye4TwAa+tpV4eacQmr/jrcNr+7fx97kjCjJdqqw8GV7dL
             t/3SP5CduJs4AQxondaErwoSxMaLVRegPWF6s4wahyyy9G8n/MG3e3YF3bdWIVvMzQCs
             3uWWtI+d7JVSeW+CW1wug02H41FB/3cdgaDPA=
    X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;
            d=1e100.net; s=20251104; t=1784568230; x=1785173030;
            h=content-transfer-encoding:mime-version:references:in-reply-to
             :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to
             :cc:subject:date:message-id:reply-to:content-type;
            bh=LcjM3QIGZ88azbBEvxRrNQ6CF+nlAFxsDxani6ZKRC0=;
            b=clf3E7iKTUGUyi4ebIlt5KJH+i4GwTGbKTMhxeKcaHdllun6RlEo+kKrOqetlAbe4i
             QmRI5Q8kIl72OvJZpBGVbgbo+/bJNWLhEcj70bnOO/tk9jza605hnOb/Yr+/Z6e8BMMe
             aA8WZm/xyv4j90mtdcNS3lH8NTojc/52g6Grdgjh4bT4sg6Lv+miXGJMSxx8Xb4/yuj1
             Omrz5JdCYXq6YquvtwLQA0TxaA+lch9TGps0lSqxYTgRsBiGra8RC7DELvonUHUKTgmI
             mF3FiTBaM49LghtWCEEpKfrALFUf6R1bYfuHd76ULFe+K5NtrEl7ACU1upg6R3NUU3VC
             Hgmg==
    X-Gm-Message-State: AOJu0YwVHlfG06BriYf1iG1bJPTB7CvRzaoy6lyqj/WpMBmGhqmnHaXC
    	AO//s4wip9ebF8SSbtBiJAobHIaoHVOclG6yBwb0xbG3NWTnhwDcqVssmtgjOgLgtlF8WBw+zlk
    	/iX6z7jk=
    X-Gm-Gg: AfdE7cmI9Xzz9FxVh88fbLSKGdyFrJMMCJ6wAnLRTJaw2wkcBZ3ch1e4KTbsJCckuOn
    	w6FmMamRgaDNerdV//djTYA0BrGhNVqHIy0dk6DZQlUQmEG3C4sbj1kiDNSTSJgIN1FnPUO3L1c
    	DEJT1HNgxSg3J8bu3hWYkixqrO8w4G+2iIASvbCCJBYrdFaMTohLEx4vM86poxXljQVquIyY/Hn
    	ByduZseeuoT2ubl3sG03wjFknAarKHXDZ05GZxXPBY+Kga6u0t5Au5DLQb27MLr/yRbi3IpFOwP
    	HEOUWVxhS5aVCBqyWAKmT75CgXBWFR99dNCFN63SeVkO+Ss3uP+6EykDtHURP/VcT0DSymUJF7U
    	AkyDsQaQ+jsYPUvIrhIjGkKEqo1X2CeoH9LtxKgrFaW5DLW4gRIR/yMWq3/18zfYh1IQkGnI5zq
    	1fOlBoF+/1P/opgKR7QoYnur+wMuv93ZPepoTkoNgtFxHPBPiA+mCeWc2X07wpOzfsNkYz591qK
    	HGm3jv5TGMGVl2TtmY=
    X-Received: by 2002:a05:600c:4743:b0:495:406c:81d5 with SMTP id
     5b1f17b1804b1-4954a50b8b8mr177036935e9.28.1784568230182;
            Mon, 20 Jul 2026 10:23:50 -0700 (PDT)
    Received: from localhost.localdomain
     (2a02-8440-b501-5b7b-2580-caa3-ecc1-dea5.rev.sfr.net.
     [2a02:8440:b501:5b7b:2580:caa3:ecc1:dea5])
            by smtp.gmail.com with ESMTPSA id
     5b1f17b1804b1-49563eee22esm36508575e9.1.2026.07.20.10.23.49
            for 
            (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256);
            Mon, 20 Jul 2026 10:23:49 -0700 (PDT)
    From: Yoann Congal 
    To: openembedded-core@lists.openembedded.org
    Subject: [OE-core][scarthgap 31/33] ca-certificates: upgrade 20260223 ->
     20260601
    Date: Mon, 20 Jul 2026 19:23:04 +0200
    Message-ID: 
     
    X-Mailer: git-send-email 2.47.3
    In-Reply-To: 
    References: 
    MIME-Version: 1.0
    List-Id: 
    X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com
     [45.33.107.173] by
     aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for
     ; Mon, 20 Jul 2026 17:23:58 -0000
    X-Groupsio-URL: 
     https://lists.openembedded.org/g/openembedded-core/message/241465
    
    From: Ankur Tyagi 
    
    License-Update: ca-certificates-local example removed[1]
    
    [1] https://salsa.debian.org/debian/ca-certificates/-/commit/0ba2e089daf128206b0a13423ceede612bb60270
    
    Signed-off-by: Ankur Tyagi 
    Signed-off-by: Richard Purdie 
    (cherry picked from commit 366cfc1103661f98020d7b7c8d249f2b7f9432af)
    Signed-off-by: Ankur Tyagi 
    [YC: Changelog:
    https://metadata.ftp-master.debian.org/changelogs/main/c/ca-certificates/ca-certificates_20260601_changelog
    ]
    Signed-off-by: Yoann Congal 
    ---
     ...a-certificates_20260223.bb => ca-certificates_20260601.bb} | 4 ++--
     1 file changed, 2 insertions(+), 2 deletions(-)
     rename meta/recipes-support/ca-certificates/{ca-certificates_20260223.bb => ca-certificates_20260601.bb} (94%)
    
    diff --git a/meta/recipes-support/ca-certificates/ca-certificates_20260223.bb b/meta/recipes-support/ca-certificates/ca-certificates_20260601.bb
    similarity index 94%
    rename from meta/recipes-support/ca-certificates/ca-certificates_20260223.bb
    rename to meta/recipes-support/ca-certificates/ca-certificates_20260601.bb
    index 9cf6d5afc7d..b23f20a7828 100644
    --- a/meta/recipes-support/ca-certificates/ca-certificates_20260223.bb
    +++ b/meta/recipes-support/ca-certificates/ca-certificates_20260601.bb
    @@ -5,7 +5,7 @@ This derived from Debian's CA Certificates."
     HOMEPAGE = "http://packages.debian.org/sid/ca-certificates"
     SECTION = "misc"
     LICENSE = "GPL-2.0-or-later & MPL-2.0"
    -LIC_FILES_CHKSUM = "file://debian/copyright;md5=ae5b36b514e3f12ce1aa8e2ee67f3d7e"
    +LIC_FILES_CHKSUM = "file://debian/copyright;md5=dab7c7cea776d1a1648deb0052c72647"
     
     # This is needed to ensure we can run the postinst at image creation time
     DEPENDS = ""
    @@ -14,7 +14,7 @@ DEPENDS:class-nativesdk = "openssl-native"
     # Need rehash from openssl and run-parts from debianutils
     PACKAGE_WRITE_DEPS += "openssl-native debianutils-native"
     
    -SRC_URI[sha256sum] = "2fa2b00d4360f0d14ec51640ae8aea9e563956b95ea786e3c3c01c4eead42b56"
    +SRC_URI[sha256sum] = "7ab6301f7f34eef90a4d278647c260bc0762e0e14561f4649854cf4b0d4bea21"
     SRC_URI = "${DEBIAN_MIRROR}/main/c/ca-certificates/${BPN}_${PV}.tar.xz \
                file://0001-update-ca-certificates-don-t-use-Debianisms-in-run-p.patch \
                file://0003-update-ca-certificates-use-relative-symlinks-from-ET.patch \
    
    From patchwork Mon Jul 20 17:23:05 2026
    Content-Type: text/plain; charset="utf-8"
    MIME-Version: 1.0
    Content-Transfer-Encoding: 7bit
    X-Patchwork-Submitter: Yoann Congal 
    X-Patchwork-Id: 92922
    Return-Path: 
    X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on
    	aws-us-west-2-korg-lkml-1.web.codeaurora.org
    Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org
     (localhost.localdomain [127.0.0.1])
    	by smtp.lore.kernel.org (Postfix) with ESMTP id 2DEDDC44520
    	for ; Mon, 20 Jul 2026 17:23:58 +0000 (UTC)
    Received: from mail-wm1-f49.google.com (mail-wm1-f49.google.com
     [209.85.128.49])
     by mx.groups.io with SMTP id smtpd.msgproc01-g2.2909.1784568232537687556
     for ;
     Mon, 20 Jul 2026 10:23:52 -0700
    Authentication-Results: mx.groups.io;
     dkim=pass header.i=@smile.fr header.s=google header.b=amB0I0me;
     spf=pass (domain: smile.fr, ip: 209.85.128.49,
     mailfrom: yoann.congal@smile.fr)
    Received: by mail-wm1-f49.google.com with SMTP id
     5b1f17b1804b1-493f6de72faso28435845e9.0
            for ;
     Mon, 20 Jul 2026 10:23:52 -0700 (PDT)
    DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;
            d=smile.fr; s=google; t=1784568231; x=1785173031;
     darn=lists.openembedded.org;
            h=content-transfer-encoding:mime-version:references:in-reply-to
             :message-id:date:subject:to:from:from:to:cc:subject:date:message-id
             :reply-to:content-type;
            bh=YdqY19dUutz1p817DrPt8kbsZvEm9gbYlTmIyLX8nHQ=;
            b=amB0I0me85HwoAfbdUdJxYfU6CtjECQojf7wdYc+8YW1F8Smkau/NBNxmWdbmW1N1h
             wgBkIall6ZqaenZN0jkxmUrigr5+VALGDwuRg4hM46JIMXJdfuDw9C59d1gnZhvs5Z4E
             i+ql9VQjMicUaGcMmYq4f+trEX1++EwVc/FoY=
    X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;
            d=1e100.net; s=20251104; t=1784568231; x=1785173031;
            h=content-transfer-encoding:mime-version:references:in-reply-to
             :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to
             :cc:subject:date:message-id:reply-to:content-type;
            bh=YdqY19dUutz1p817DrPt8kbsZvEm9gbYlTmIyLX8nHQ=;
            b=TJUI79iuvY2gMq7cuDPcmOK+X031OyV8EVeldqfFQdrL0jxgnKfFFOBPZSeSoMEOoH
             q+jda2F+50E6rE+S2R15ie3IG2RCY4BWZXGyBTefm+30k0Mu6vgRbWPdg1xjidQ05cvM
             Y8iBbPfs1iiXQZs8rYJ13feKY5Ivntnw670l9Ln6+zUy882l/06841k+KgiN5a69/DiG
             KJH0FNpu81vUNpS8erCy21gTSDL2SkB1M5PrAR+k2hrYZvPzgVl16Zq8BEvaY+i00Twh
             pLKcVT7H0SfadGc6Dj2sN3U/HBnd5VCGNJ+aAap5MRjThG15/iMTRHHTrjQ198moPYyR
             J25Q==
    X-Gm-Message-State: AOJu0Yzvx4uw4IGw3wGSOebz55yEWiapXDl0jyCqFE2xtZbqpycifqW/
    	1fulMOgWSxwk/Nk0JxEVNPqlcxPwtoRTfIqyjaz5bWfVpVKwydGDjeHojvgGlCAFWTM7CB0+cfo
    	WpGSZvq4=
    X-Gm-Gg: AfdE7ckZ81Vg4wUVw3794LQEYLjvZQJF/jKF062A8vkQeTxDzKkjq8lL7u/gfX8XeiY
    	04HBEz1O/y2lEE3hn8GbEj/f9LiGJ0qFaRWImwj5ixbmVJY7+DsVdkwr2+RrZpIULXSbxFLFWbr
    	m875B4PE6MODQqAa1H9L691NTTuGUW0FHLoXDoYG0RwLRQG0pIFTCZUd3/F8Np+89g9QoePdKyL
    	HeTCdg/ctau7o05KdNKmKnnsGtSb/ERFqxUO/McoaBwbddZq+FgkKVNbVbP6gNtg6DQ7kEM0n5L
    	/AADYXrl+ssQV9P3rDNdF158MZzBWQ0pcvvaNXyMTa6tUPDqA6I/GegQjrv18slT1/YapqSfuJt
    	n7HV+mSB+IITJ+qgZFYCUsQQgxiQ7CskkdQrN8IpPTXbS5Zy+jfCskOaPR31lJFShY1Ar17pbep
    	/pyKI7LQzy+sFXdd9jZZxI+TwFaWede4i88ZUe3A/2oJJPMPzlK5I/cEu1o/sd7OHhn3sUENdoT
    	suX/LzA
    X-Received: by 2002:a05:600c:6289:b0:493:b4a3:5ab0 with SMTP id
     5b1f17b1804b1-4954a33dc26mr156197565e9.13.1784568230850;
            Mon, 20 Jul 2026 10:23:50 -0700 (PDT)
    Received: from localhost.localdomain
     (2a02-8440-b501-5b7b-2580-caa3-ecc1-dea5.rev.sfr.net.
     [2a02:8440:b501:5b7b:2580:caa3:ecc1:dea5])
            by smtp.gmail.com with ESMTPSA id
     5b1f17b1804b1-49563eee22esm36508575e9.1.2026.07.20.10.23.50
            for 
            (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256);
            Mon, 20 Jul 2026 10:23:50 -0700 (PDT)
    From: Yoann Congal 
    To: openembedded-core@lists.openembedded.org
    Subject: [OE-core][scarthgap 32/33] binutils: Add CVE-2025-69646 to "CVE:" tag
    Date: Mon, 20 Jul 2026 19:23:05 +0200
    Message-ID: 
     <6e6e0b5b8a6b743696b8447dc8f7f95e1b148459.1784567958.git.yoann.congal@smile.fr>
    X-Mailer: git-send-email 2.47.3
    In-Reply-To: 
    References: 
    MIME-Version: 1.0
    List-Id: 
    X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com
     [45.33.107.173] by
     aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for
     ; Mon, 20 Jul 2026 17:23:58 -0000
    X-Groupsio-URL: 
     https://lists.openembedded.org/g/openembedded-core/message/241466
    
    From: Harish Sadineni 
    
    Bugzilla bug 33641 (assigned CVE-2025-69648) has been resolved as a
    duplicate of bug 33638 (assigned CVE-2025-69646):
    
    https://sourceware.org/bugzilla/show_bug.cgi?id=33641
    
    The existing patch already fixes the issue associated with both CVEs.
    
    Update the "CVE:" tag to reference both identifiers.
    
    Signed-off-by: Harish Sadineni 
    Signed-off-by: Yoann Congal 
    ---
     meta/recipes-devtools/binutils/binutils/CVE-2025-69648.patch | 2 +-
     1 file changed, 1 insertion(+), 1 deletion(-)
    
    diff --git a/meta/recipes-devtools/binutils/binutils/CVE-2025-69648.patch b/meta/recipes-devtools/binutils/binutils/CVE-2025-69648.patch
    index e04d7ed6c21..e123273338c 100644
    --- a/meta/recipes-devtools/binutils/binutils/CVE-2025-69648.patch
    +++ b/meta/recipes-devtools/binutils/binutils/CVE-2025-69648.patch
    @@ -19,7 +19,7 @@ length field.
     	(display_debug_ranges): Check display_debug_rnglists_unit_header
     	return status.  Stop output on error.
     
    -CVE: CVE-2025-69648
    +CVE: CVE-2025-69648 CVE-2025-69646
     Upstream-Status: Backport [https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=598704a00cbac5e85c2bedd363357b5bf6fcee33]
     
     (cherry picked from commit 598704a00cbac5e85c2bedd363357b5bf6fcee33)
    
    From patchwork Mon Jul 20 17:23:06 2026
    Content-Type: text/plain; charset="utf-8"
    MIME-Version: 1.0
    Content-Transfer-Encoding: 7bit
    X-Patchwork-Submitter: Yoann Congal 
    X-Patchwork-Id: 92923
    Return-Path: 
    X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on
    	aws-us-west-2-korg-lkml-1.web.codeaurora.org
    Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org
     (localhost.localdomain [127.0.0.1])
    	by smtp.lore.kernel.org (Postfix) with ESMTP id 17E5AC44515
    	for ; Mon, 20 Jul 2026 17:23:58 +0000 (UTC)
    Received: from mail-wm1-f53.google.com (mail-wm1-f53.google.com
     [209.85.128.53])
     by mx.groups.io with SMTP id smtpd.msgproc02-g2.2891.1784568233498789083
     for ;
     Mon, 20 Jul 2026 10:23:53 -0700
    Authentication-Results: mx.groups.io;
     dkim=pass header.i=@smile.fr header.s=google header.b=UmORS7nt;
     spf=pass (domain: smile.fr, ip: 209.85.128.53,
     mailfrom: yoann.congal@smile.fr)
    Received: by mail-wm1-f53.google.com with SMTP id
     5b1f17b1804b1-49553515a8bso23594815e9.1
            for ;
     Mon, 20 Jul 2026 10:23:53 -0700 (PDT)
    DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;
            d=smile.fr; s=google; t=1784568232; x=1785173032;
     darn=lists.openembedded.org;
            h=content-transfer-encoding:mime-version:references:in-reply-to
             :message-id:date:subject:to:from:from:to:cc:subject:date:message-id
             :reply-to:content-type;
            bh=ZgwC8LKBh+//IUpP9CyEyVL6WwY3aeMnUh9z/aP2zy0=;
            b=UmORS7nt9JzVsAYGFcou3jUXPKu668pwXhqymAKQ3yhne+1I8SZ/BH6KfWQQz7pzyv
             a75wfKJ1wc7k1gjgflnFdO4vOewbT4TpgMPnqoO1UMI0jnL57wF3t5bgYrvwPivR4/m1
             G4ZcxwQKtbvbGIu0YwU+5dLeQ2u7t/mNPigbg=
    X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;
            d=1e100.net; s=20251104; t=1784568232; x=1785173032;
            h=content-transfer-encoding:mime-version:references:in-reply-to
             :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to
             :cc:subject:date:message-id:reply-to:content-type;
            bh=ZgwC8LKBh+//IUpP9CyEyVL6WwY3aeMnUh9z/aP2zy0=;
            b=WJ5GJaMct9qKhegrcrR6oTiqOVX6AsSDGkAfudbd5d67E/a5J9qcRSqXEaeeddE2zz
             Z7HnB2Mu76nPtcuIM0uQSNBHC98wIMSfPvgZ4eploAlPQPcrXTB685Dgx0bpVJvRQbQ7
             PVo6b5wt5QEemiKuAKErdXY91v2hTO90c/dYL2ID8dAD1CxqfRdVTYYmvjA8vN8R7TXo
             +wPL2UbsfCpQ0d8B6w9kO8LYjVqQ9lptQyZR18iLL+P3KWbL79f6KqSovc6uJ7ZAZZLw
             uGWdY9B8ObcBxxZ0Enh8UbqWp2FBbBGBACWdS5GTtalyqbhN6cNOeEaKFXl5LfOMAVwU
             TjZg==
    X-Gm-Message-State: AOJu0YyfNovlhoQ2hfFSkb5J8oSEII+LoD86YiV16oa6vfi0ULt0dBZE
    	u/HYr0s9k89RJ6ya8OuXZhvbAfTkNgb0uDvtzBUMp3Y1bsvltA9eu3lkNS4uvyste5Gvjuh818P
    	725CNkiY=
    X-Gm-Gg: AfdE7cn40jXaBDA8InRiafHZVPz0P6lzdbMIddXn3ro9o3tC1rhsXOqJk5nS+1uqvFU
    	1rZQW8JLCCW1D0v+fr+AfpUnMwRGc98rz/1H3AzNQ+UUUUX2rQRypy7I4d6zEyIAlfimBplmIjF
    	jCGs3oVSZbcp0VZXXdzK2zX1JmvIzSZwG9HQvN9VUivC8c06YHEBsP8sdIT8BHF7jyISIVNEMbs
    	9PnRA2Z83E2Is/kKo2bUj4AbG5ZBlAJ/mtP2JELyq84mYV4CoZkjfm06JUJ/rPkQzwr0bs33xQm
    	SDMa4DCJG9CHlES1CqQczwvQyMHFhyNiONLlzO8+zsgNX22gmyxyJOnoOnzYK9ubA/YvJzTaOzf
    	Bat9y78m21ljEJ3iaC3ZdmxxZSN9z04PW8Y4jKeGSCHpBxWaz0OADh3JcAji26Rom/sjfABdiAN
    	Y+1xAXhIlv3XDZGGhROjtPwbEQ5Noriyu4x4sovlZMY9lnl3iyEIiw2mLpes+MDxxdIeVI4oJGQ
    	yTFk2Tn
    X-Received: by 2002:a05:600c:6c91:b0:493:c337:db0e with SMTP id
     5b1f17b1804b1-4954a402d87mr112488715e9.18.1784568231682;
            Mon, 20 Jul 2026 10:23:51 -0700 (PDT)
    Received: from localhost.localdomain
     (2a02-8440-b501-5b7b-2580-caa3-ecc1-dea5.rev.sfr.net.
     [2a02:8440:b501:5b7b:2580:caa3:ecc1:dea5])
            by smtp.gmail.com with ESMTPSA id
     5b1f17b1804b1-49563eee22esm36508575e9.1.2026.07.20.10.23.50
            for 
            (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256);
            Mon, 20 Jul 2026 10:23:51 -0700 (PDT)
    From: Yoann Congal 
    To: openembedded-core@lists.openembedded.org
    Subject: [OE-core][scarthgap 33/33] glibc-testsuite: Do not generate SPDX
    Date: Mon, 20 Jul 2026 19:23:06 +0200
    Message-ID: 
     <9a7f92f2dce94876fa63ce8625d53444a9a706aa.1784567958.git.yoann.congal@smile.fr>
    X-Mailer: git-send-email 2.47.3
    In-Reply-To: 
    References: 
    MIME-Version: 1.0
    List-Id: 
    X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com
     [45.33.107.173] by
     aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for
     ; Mon, 20 Jul 2026 17:23:58 -0000
    X-Groupsio-URL: 
     https://lists.openembedded.org/g/openembedded-core/message/241467
    
    From: Joshua Watt 
    
    glibc-testsuite does not run on target or factor into the build supply
    chain, since its purpose is run tests in Qemu at build time
    
    Signed-off-by: Joshua Watt 
    Signed-off-by: Richard Purdie 
    (cherry picked from commit 32801348ca231978498612f3ebee121ca27459c1)
    [YC: See https://lore.kernel.org/all/20260708115052.71740-1-jaipaul.cheernam@est.tech/ ]
    Signed-off-by: Yoann Congal 
    ---
     meta/recipes-core/glibc/glibc-testsuite_2.39.bb | 1 +
     1 file changed, 1 insertion(+)
    
    diff --git a/meta/recipes-core/glibc/glibc-testsuite_2.39.bb b/meta/recipes-core/glibc/glibc-testsuite_2.39.bb
    index 2e076f4b0f4..e0e3e8ba847 100644
    --- a/meta/recipes-core/glibc/glibc-testsuite_2.39.bb
    +++ b/meta/recipes-core/glibc/glibc-testsuite_2.39.bb
    @@ -31,6 +31,7 @@ do_check:append () {
     }
     
     inherit nopackages
    +inherit nospdx
     deltask do_stash_locale
     deltask do_install
     deltask do_populate_sysroot