From patchwork Tue Jul 28 22:21:36 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 8bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 93758 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id DC0BEC54F5B for ; Tue, 28 Jul 2026 22:22:15 +0000 (UTC) Received: from mail-wm1-f43.google.com (mail-wm1-f43.google.com [209.85.128.43]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.2697.1785277325636650819 for ; Tue, 28 Jul 2026 15:22:05 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=JMsnfvxw; spf=pass (domain: smile.fr, ip: 209.85.128.43, mailfrom: yoann.congal@smile.fr) Received: by mail-wm1-f43.google.com with SMTP id 5b1f17b1804b1-4954a2e73a9so2040015e9.3 for ; Tue, 28 Jul 2026 15:22:05 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1785277324; x=1785882124; darn=lists.openembedded.org; h=content-transfer-encoding:content-type:mime-version:references :in-reply-to:message-id:date:subject:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=PnAKHqrN0T8ya1Ewwi3FHRCPIc2yNoCL0REgkoh7WFc=; b=JMsnfvxw3KVhH5cKf5pCw2wmtN9RAbkiE+sSbooaIsQ2OZz6CYw1JcCPo6KS0KTa77 jo4ZCj29j08RVHLjoeQDa8PsVzq3GIbNU9FWn30K4Gbb3Wyh1bYZZkSdnqJ68DzOLZ8u /oofMYwiZ3Tm1gRcqU1fDgEbpPYx7DRhz2pJA= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1785277324; x=1785882124; h=content-transfer-encoding:content-type:mime-version:references :in-reply-to:message-id:date:subject:to:from:x-gm-gg :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to :content-type; bh=PnAKHqrN0T8ya1Ewwi3FHRCPIc2yNoCL0REgkoh7WFc=; b=P7bItzBYvZzS4rgRpHqe51LA9/F0kCIPx8vx/rehQMP1Qk3rk7AaIKdNFXPxX56Mgt n2eQ23Tay5VcJQRruWjAIJyxK1Tl9o6TFV3TGAZ14/QLbjpa7SQr90EDW1cuVzTAjWMz SLECsAeunmPTmFpz4FSKJFjCL9OuzC8ttWjfuLF/YvkpIfrHybfJEeCJEVNwDYqmPdeA xuFBhH2bQDfJsocpf/RfjmaFp7xDpkJ4gPIUdEmU4Z+1uvEtREaDez1Iw2Q9BeTsercH K79cVSE9ANWWV03B/oweNgqMQlUrgAhxLOjiTXsvRNqPWZXGqeVhDQ329Xm9jIH9BkV2 /zHw== X-Gm-Message-State: AOJu0YwZgYFio7wAFJSfQGgoQSzjJnOi8908l6pZ4XiyAGdvDoXC7yc2 ouWA8PSGLAT9ENBXjJz096Nms/yPDrebLIUjgxNwfDwd0gfNRFngz2RvFmGVX+keHS/Cyg9Wnih ohldGAp4= X-Gm-Gg: AR+sD10u8U5pZiYRTRcLIeaXm5x0J9zY2yUbRSx50ShTyso2DpmmX9a40VhQVqAV09R 5lsSHgMquXw7ju2k0jOmlkhYf2ey5LH27hwMlAi2hZsTTNRG40mq3bgsJXGvs/q+s2RPzXkZaQe V20lHsj09hhleKI7pCuvKiJvddJ0YWPQ0T9mbPVSdGZ03zbhN+TgH+cSU8cVb8ecbDu/ZDJP0G7 yf999iM1VH+/dpIYyuVw/aqW9zjxt1GgLnt9vvAdNCRq+Wvv1iXAWdRBw32fzDlYU7Jse0U6GR6 QAnbkgAPCc9Py47uxP8Hj4R076V2sMAMXCQSQxlc1eo1pIjoopozzXJJnoQhRHbYUlTzVmZPlTN IEZIPQZbJd3GH3i8qRsoBqDLRpShwmv1IPY9u5olnz9k542FDT6DCxKoUOA4MGppW7ocq4KqWPV UwqvyK3xnv7puZuar9hJ+6jjWM4CHbacO9aXQXZwSWILs67DGokDWRtpStGAjiSvnEIMSudJ52u Yf4Q4BKpYCZprrK8RdtTbwR7B0YthuXjxeQRvHI9l5sCoccCTXWiY5tPaYovS0k X-Received: by 2002:a05:600c:1f8c:b0:495:52a5:8829 with SMTP id 5b1f17b1804b1-496c642c7e2mr49745415e9.11.1785277323851; Tue, 28 Jul 2026 15:22:03 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-4976bd6da4asm7669405e9.1.2026.07.28.15.22.03 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Tue, 28 Jul 2026 15:22:03 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][scarthgap 01/19] libsolv: Fix CVE-2026-9149 Date: Wed, 29 Jul 2026 00:21:36 +0200 Message-ID: <6c39677193adf777b9abe22859842ec692bebdc3.1785277157.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Tue, 28 Jul 2026 22:22:15 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/242204 From: Shubham Pushpkar This patch applies the upstream fix as referenced in [1], using the CVE advisory shown in [2]. [1] https://github.com/openSUSE/libsolv/commit/210386037c892a720972ad35a3d8f7073b4d763b [2] https://nvd.nist.gov/vuln/detail/CVE-2026-9149 Signed-off-by: Shubham Pushpkar Signed-off-by: Yoann Congal (cherry picked from commit d3fc48836349e81369f5680d808d2e469fce626a) Signed-off-by: Deepak Rathore Signed-off-by: Yoann Congal --- .../libsolv/libsolv/CVE-2026-9149.patch | 152 ++++++++++++++++++ .../libsolv/libsolv_0.7.28.bb | 1 + 2 files changed, 153 insertions(+) create mode 100644 meta/recipes-extended/libsolv/libsolv/CVE-2026-9149.patch diff --git a/meta/recipes-extended/libsolv/libsolv/CVE-2026-9149.patch b/meta/recipes-extended/libsolv/libsolv/CVE-2026-9149.patch new file mode 100644 index 00000000000..11acf758b58 --- /dev/null +++ b/meta/recipes-extended/libsolv/libsolv/CVE-2026-9149.patch @@ -0,0 +1,152 @@ +From 175bd2008d3b3a4b54253bd6657cc46948360534 Mon Sep 17 00:00:00 2001 +From: Petr Písař +Date: Thu, 23 Apr 2026 18:04:24 +0200 +Subject: [PATCH 2/2] Cope with integer overflow in data size arithmetics in + repo_add_solv() + +When parsing solv files with maliciously large "maxsize" or "allsize" +data size, e.g. this maxsize value at offset 0x29--0x2E: + + 00000000 53 4f 4c 56 00 00 00 08 00 00 00 01 00 00 00 00 |SOLV............| + 00000010 00 00 00 00 00 00 00 00 00 00 00 01 00 00 00 01 |................| + 00000020 00 00 00 00 00 00 00 00 00 8f ff ff bf 77 86 8d |.............w..| + 00000030 20 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 | ...............| + 00000040 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 |................| + * + 00002030 00 |.| + 00002031 + +read_id() function will decode and return 4294959095 value, and a subsequent +assignment: + + int maxsize; + [...] + maxsize = read_id(&data, 0); + +will experience an integer overflow on plaforms where signed int has 4-byte +size (e.g. x86_64). + +The same flaw is possible at the next line: + + allsize = read_id(&data, 0); + +Subsequent arithmetics will interpreter the value as a very large negative +number, possibly doing wrong decisions: + + maxsize += 5; /* so we can read the next schema of an array */ + if (maxsize > allsize) + maxsize = allsize; + +and finally, the negative value passed to solv_calloc(): + + buf = solv_calloc(maxsize + DATA_READ_CHUNK + 4, 1); /* 4 extra bytes to detect overflows */ + +will be coerced to an unsigned type (size_t) leading to allocating a smaller +buffer then intended. Then writing to the small buffer will experience a heap +buffer overflow: + + l = maxsize; + if (l < DATA_READ_CHUNK) + l = DATA_READ_CHUNK; + if (l > allsize) + l = allsize; + if (!l || fread(buf, l, 1, data.fp) != 1) + +This flaw can be demostrated by passing that solv file to the dumpsolv tool which +will crash if compiled with ASAN: + + $ /tmp/b/tools/dumpsolv /tmp/vuln_1_101_1_negative_maxsize.solv + ================================================================= + ==17608==ERROR: AddressSanitizer: heap-buffer-overflow on address 0x7c0a2ede00b1 at pc 0x7fea30451468 b + p 0x7ffe07220a50 sp 0x7ffe07220220 + WRITE of size 8192 at 0x7c0a2ede00b1 thread T0 + #0 0x7fea30451467 in fread.part.0 (/lib64/libasan.so.8+0x51467) (BuildId: 80bfc4ae44fdec6ef5fecfb01 + e2b57d28660991c) + #1 0x7fea3028eef1 in repo_add_solv /home/test/libsolv/src/repo_solv.c:1034 + #2 0x0000004041cc in main /home/test/libsolv/tools/dumpsolv.c:471 + #3 0x7fea3003c680 in __libc_start_call_main (/lib64/libc.so.6+0x3680) (BuildId: c04494d63bca865bedf571a4075ef8867ccf9fa9) + #4 0x7fea3003c797 in __libc_start_main@GLIBC_2.2.5 (/lib64/libc.so.6+0x3797) (BuildId: c04494d63bca865bedf571a4075ef8867ccf9fa9) + #5 0x000000400694 in _start (/tmp/b/tools/dumpsolv+0x400694) (BuildId: 0a70b5b14e5cd81f90a309bb2ff3219dfbf30bb8) + + 0x7c0a2ede00b1 is located 0 bytes after 1-byte region [0x7c0a2ede00b0,0x7c0a2ede00b1) + allocated by thread T0 here: + #0 0x7fea304ef41f in malloc (/lib64/libasan.so.8+0xef41f) (BuildId: 80bfc4ae44fdec6ef5fecfb01e2b57d28660991c) + #1 0x7fea302e4b4c in solv_calloc /home/test/libsolv/src/util.c:77 + #2 0x7fea3028ee38 in repo_add_solv /home/test/libsolv/src/repo_solv.c:1025 + #3 0x0000004041cc in main /home/test/libsolv/tools/dumpsolv.c:471 + #4 0x7fea3003c680 in __libc_start_call_main (/lib64/libc.so.6+0x3680) (BuildId: c04494d63bca865bedf571a4075ef8867ccf9fa9) + #5 0x7fea3003c797 in __libc_start_main@GLIBC_2.2.5 (/lib64/libc.so.6+0x3797) (BuildId: c04494d63bca865bedf571a4075ef8867ccf9fa9) + #6 0x000000400694 in _start (/tmp/b/tools/dumpsolv+0x400694) (BuildId: 0a70b5b14e5cd81f90a309bb2ff3219dfbf30bb8) + + SUMMARY: AddressSanitizer: heap-buffer-overflow /home/test/libsolv/src/repo_solv.c:1034 in repo_add_solv + +This patch catches the integer overflow, sets an error and jumps to the end of +the function just after deallocation of the buffer (which would contain an +undefined pointer). This patch also handles a possible integer overflow at +"maxsize += 5" line. + +I originally wanted to replace read_id() with read_u32(), but +complemtary repowriter_write() function also stored the value as +a signed integer, so I guess the the Id type is inteded there. + +There are probably other ways how to fix it, like passing INT_MAX-5 +limit to read_id(), though the error message would be less +understandable. + +It's also possible to reject this patch with an explanation that loading +untrusted solv files is not supported. Though some kind of +fortification would be welcomed by people who debug solver problems +from reported solv files. + +Reported by Aisle Research. + +CVE: CVE-2026-9149 +Upstream-Status: Backport [https://github.com/openSUSE/libsolv/commit/210386037c892a720972ad35a3d8f7073b4d763b] + +(cherry picked from commit 210386037c892a720972ad35a3d8f7073b4d763b) +Signed-off-by: Shubham Pushpkar +--- + src/repo_solv.c | 14 ++++++++++++++ + 1 file changed, 14 insertions(+) + +diff --git a/src/repo_solv.c b/src/repo_solv.c +index 629ac683..00639aa0 100644 +--- a/src/repo_solv.c ++++ b/src/repo_solv.c +@@ -18,6 +18,7 @@ + #include + #include + #include ++#include + + #include "repo_solv.h" + #include "util.h" +@@ -1078,6 +1079,18 @@ repo_add_solv(Repo *repo, FILE *fp, int flags) + + maxsize = read_id(&data, 0); + allsize = read_id(&data, 0); ++ if (maxsize < 0 || allsize < 0) ++ { ++ data.error = pool_error(pool, SOLV_ERROR_CORRUPT, "negative data size in solv header"); ++ id = 0; ++ goto data_error; ++ } ++ if (maxsize > INT_MAX - 5) ++ { ++ data.error = pool_error(pool, SOLV_ERROR_OVERFLOW, "data size overflow in solv header"); ++ id = 0; ++ goto data_error; ++ } + maxsize += 5; /* so we can read the next schema of an array */ + if (maxsize > allsize) + maxsize = allsize; +@@ -1403,6 +1416,7 @@ printf("=> %s %s %p\n", pool_id2str(pool, keys[key].name), pool_id2str(pool, key + } + solv_free(buf); + ++data_error: + if (data.error) + { + /* free solvables */ +-- +2.35.6 diff --git a/meta/recipes-extended/libsolv/libsolv_0.7.28.bb b/meta/recipes-extended/libsolv/libsolv_0.7.28.bb index 63534dce260..4ad8a20e2f4 100644 --- a/meta/recipes-extended/libsolv/libsolv_0.7.28.bb +++ b/meta/recipes-extended/libsolv/libsolv_0.7.28.bb @@ -11,6 +11,7 @@ DEPENDS = "expat zlib zstd" SRC_URI = "git://github.com/openSUSE/libsolv.git;branch=master;protocol=https \ file://0001-utils-Conside-musl-when-wrapping-qsort_r.patch \ file://CVE-2026-9150.patch \ + file://CVE-2026-9149.patch \ " SRCREV = "c8dbb3a77c86600ce09d4f80a504cf4e78a3c359" From patchwork Tue Jul 28 22:21:37 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 93768 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id CE764C54F9C for ; Tue, 28 Jul 2026 22:22:16 +0000 (UTC) Received: from mail-wm1-f42.google.com (mail-wm1-f42.google.com [209.85.128.42]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.2802.1785277326039541951 for ; Tue, 28 Jul 2026 15:22:06 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=YG2vh6Nu; spf=pass (domain: smile.fr, ip: 209.85.128.42, mailfrom: yoann.congal@smile.fr) Received: by mail-wm1-f42.google.com with SMTP id 5b1f17b1804b1-493f75f7172so2414305e9.1 for ; Tue, 28 Jul 2026 15:22:05 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1785277324; x=1785882124; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=nT/p/ugL2UdURY1embxTI+oyyduUuhJkjzLc+1jMOQc=; b=YG2vh6NupWfiJhH/X8+BSZHD393+BZn1+2e2V0CaQ3/52P/x546MoM5PjbT91w4+JI Z2YvQUApxXTGUQlSQDqN+ibpSKl839k8wQXjqbkFJWbsqDWyk1OXL+HV+/O/ajOFXdvt ZALVSN8X4cajK8aoODqRlPcoto/T8OTxj+Qj0= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1785277324; x=1785882124; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=nT/p/ugL2UdURY1embxTI+oyyduUuhJkjzLc+1jMOQc=; b=BVGtG33cBMfXERZHh29FTMQR2irxTssNiC3rEEQaVThV6OhfwzejnrqG/ks4l3Fyrz r9X01inilAiuPAODcqIj25q3e1EkSQhMkCgYV/jbupBlXbc1vyCgLa3mpAAlAXmvVu7J lY3fdN9xawB6k6W36KzieIeFtTG8mD+dHs5B6N5WU1t/cLs7lf0/bnvjEtbanbZJAhnz gNN2tH76mmkYt6jyxBzNe0NDN3UbAv5mOc/2znbQadb+CS4tiO5ZrN/OuFb0lPrTbCDY J6T04B26PTdfavgwmzjH+0d+p8Zo6r662rQjZuiSHD8+h9Z55VFVvyxyrygDlHyMgvC6 t9Lg== X-Gm-Message-State: AOJu0YxziAvw3/jXAbdClbn6SlGb8U/GcwfxO3mQPv0vqRWts4nmtco1 4cclMH9SR/37bFWo6hAz0dAhXOQ8WthcYPVXwb4Qs/pGk1HyockcmSjNCi7HCGbJU7z3grkWjBk ohCqxneM= X-Gm-Gg: AR+sD10Zw+ukp+qS0txsxovIefanoNvPpOdKClxK0h4QvXFQ0Fmv2Ol/QDgteN9+ZRB QIwgaoxy1jQJYxlYOa1FcLj8YGoFH5yxjL/b2hxGAOE7NASFGU4J83OZ+Mh65cl2twfwyJY0JaI eKrkSOn1grwmHAYOwfJ/GIG4kfefSq6EUowdU2OQpJdOxce4OLEaMGKK+tF3ChG1W2VZXcHRgpy tYmMqe/iLCDkbwCJzYnYRFptI20Mkn9GCK6TYxCZE5hQpoh4+kWiYjlns29ygU+K6mUS0yaeSpp F1ZvG+OUpOVwbGOBIsTSgYh6TzNf8jcPBciNu5KhDBR7VQmOP4WHUkv9dWvfSk9N3JFsGiTTumb Hqz+oJGG5kmIVBIQxMQ+uO/9gKLubWkOmj7pBaj9GGGnAOc5fXswprHLraWG28JxD9uAhQNXNIW HMzQTTKsikevTslaYlQ+2oyFBABM7qC2n8YDm1L+dNV0HLg3nelHxZA2KH9DRmpVmZvKHtoPKu5 lNLuQ/9XOsCxUy8f18+M1jSfLKkajFfa8eH0dGzZlvY8mRs0yBsuYUMppHabfdw X-Received: by 2002:a05:600c:5298:b0:495:4df2:b8c1 with SMTP id 5b1f17b1804b1-496c659dd06mr41682355e9.35.1785277324316; Tue, 28 Jul 2026 15:22:04 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-4976bd6da4asm7669405e9.1.2026.07.28.15.22.03 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Tue, 28 Jul 2026 15:22:04 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][scarthgap 02/19] package.bbclass: hardcode emit_pkgdata to run last Date: Wed, 29 Jul 2026 00:21:37 +0200 Message-ID: <358a847c9dfaf56291f9eb5e2f150cae56044c7c.1785277157.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Tue, 28 Jul 2026 22:22:16 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/242205 From: AshishKumar Mishra Ensure emit_pkgdata runs after all PACKAGEFUNCS to allow layers to extend packaging behavior. Layers can now append custom functions via PACKAGEFUNCS += "func_name" and they will run before emit_pkgdata generates package metadata. Signed-off-by: AshishKumar Mishra Signed-off-by: Mathieu Dubois-Briand Signed-off-by: Richard Purdie (cherry picked from commit aa85baff9ebdd3f932811c3b43d1918c38373cb9) Signed-off-by: Yoann Congal --- meta/classes-global/package.bbclass | 7 +++++-- 1 file changed, 5 insertions(+), 2 deletions(-) diff --git a/meta/classes-global/package.bbclass b/meta/classes-global/package.bbclass index aa1eb5e901c..ffe3ed93eff 100644 --- a/meta/classes-global/package.bbclass +++ b/meta/classes-global/package.bbclass @@ -468,8 +468,7 @@ PACKAGEFUNCS += " \ package_do_shlibs \ package_do_pkgconfig \ read_shlibdeps \ - package_depchains \ - emit_pkgdata" + package_depchains" python do_package () { # Change the following version to cause sstate to invalidate the package @@ -561,9 +560,13 @@ python do_package () { for file in files: pkgfiles[pkg].append(walkroot + os.sep + file) + + # We want emit_pkgdata to run last, after everything for f in (d.getVar('PACKAGEFUNCS') or '').split(): bb.build.exec_func(f, d) + bb.build.exec_func("emit_pkgdata", d) + oe.qa.exit_if_errors(d) } From patchwork Tue Jul 28 22:21:38 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 8bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 93764 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 9AC0BC54FCC for ; Tue, 28 Jul 2026 22:22:16 +0000 (UTC) Received: from mail-wm1-f50.google.com (mail-wm1-f50.google.com [209.85.128.50]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.2803.1785277326493339454 for ; Tue, 28 Jul 2026 15:22:06 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=Hj6mXgDH; spf=pass (domain: smile.fr, ip: 209.85.128.50, mailfrom: yoann.congal@smile.fr) Received: by mail-wm1-f50.google.com with SMTP id 5b1f17b1804b1-490cf322ed0so1961705e9.1 for ; Tue, 28 Jul 2026 15:22:06 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1785277325; x=1785882125; darn=lists.openembedded.org; h=content-transfer-encoding:content-type:mime-version:references :in-reply-to:message-id:date:subject:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=Wgm6zDEnIcrvtFRU0zsVfZwzF+OQoueyIvkrqKs0K6U=; b=Hj6mXgDHoMFXAk2yPxTp5T9CDky+CW+8iV0Ex+5sy5wF1M3DROywqxgOysASFw5osY Ii/K8g8ngQyzlOjFwFbyDr3d0+B99TGQ/C3eXb8cXy4pUNGdmMegiESyM/XFGRBFi3E+ oCFYMnxquu9d5rMlqQfzOd+GYPELIo9tSGHtE= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1785277325; x=1785882125; h=content-transfer-encoding:content-type:mime-version:references :in-reply-to:message-id:date:subject:to:from:x-gm-gg :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to :content-type; bh=Wgm6zDEnIcrvtFRU0zsVfZwzF+OQoueyIvkrqKs0K6U=; b=Cegsbm4Ne875fvMHG3fTYWCm98Sx0nSnXoVzyX5WgjQvW8VTwyras5FXHKQ2GGYaBk moTvPzo2amSYIwQAy4VwKAMKaSJ7wqXUGArz+0GYA8W5G/LmLfcvFFLYdv4v+TpI2i94 odWIP3Fdt7VgU8Hn6bXdVNILkM015jheAJ8cR0yHVr4wjhRjJSKylfLW6iBf1uTYEdco NNe5cWhUnx9A01U/Fahx3yZLzFqPrQXqIMJmS9e+pxoNOByggR8U2J/p7dlvPsxaRr/m YpDGvX1e9N4FLOHbZeKiarU0YYUAZlVCVbS09dfMiP43qurRPN6G8ew74ZmCI32cPQGL Jukg== X-Gm-Message-State: AOJu0Yz/7k2WPSBfqNvVsEye6QL47W36tueBzUBRmUfXtxeaeap4dLe8 6xUgwB+NwsYyVoz5sn/kOTWhVim1cilXgMRECgP4vH5K98upuSMyn7NAs8mL7ZJDcCug5CnrL6r 2q70lIjk= X-Gm-Gg: AR+sD11D5zsJwJvySTPetstpCODumBg0oUu9bbOg/7cbO5gnBUrGe1E1L6q51JvuhKJ A758H/i4dKsCG5dq0NSxdUK7rQFMXEJjXN0PChspUZ0k3eLE1+MGq+tjY2oCLIIjc4ilFs0LPVv 8VXx4xieEe5fWKQQrd2WhdNX//7xZp46IHIn/ThA945D9OYdWUOpW9Rl5/8QCsS92UpfTkDfYNX 3BC3HyjhOYNatLCLDgMvHyf2BJ94A/hvnOk4sDoSBcuPs+heEUUnA8J6APLU4/kx9xNfDq7K2nX B3pIVRMNXoR0qhddEmwILnrupaA8sZbvBJVJO28g7xSA0AqKIq1fvcvyxcOst3RlwCTRQy3nmQ/ Yclc+S3KRcoithtHS7a4UI1flGY+Vny2FuAhGBZ8f9GpLqUeFsp8sB277LR2cUPUV+cvhDjBObV A+jU/YrhcHwg3equ5pQW5kQzoADUGUfbPvuq1NdGK+NOdUXG3gZQqJyM/mKx4fa8sXUvLszEtLE AaSIQoFW6yYOsxH/toTyRs55KHtqgIoI9715J6aemzpMS2nAv8O7NtjrZugU68u X-Received: by 2002:a05:600c:4e8c:b0:495:4730:15b2 with SMTP id 5b1f17b1804b1-496c6571ea4mr42379995e9.31.1785277324784; Tue, 28 Jul 2026 15:22:04 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-4976bd6da4asm7669405e9.1.2026.07.28.15.22.04 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Tue, 28 Jul 2026 15:22:04 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][scarthgap 03/19] gawk: Fix CVE-2026-40467 Date: Wed, 29 Jul 2026 00:21:38 +0200 Message-ID: <157c0642e924dc5f53064322ad8b8143a3621d6b.1785277157.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Tue, 28 Jul 2026 22:22:16 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/242206 From: Darsh Kelaiya This patch applies the upstream fix as referenced in [2], using the commit shown in [1]. [1] https://cgit.git.savannah.gnu.org/cgit/gawk.git/commit/?id=a2d18c74109e41bec29a23098eba2e00057286d8 [2] https://nvd.nist.gov/vuln/detail/CVE-2026-40467 Signed-off-by: Darsh Kelaiya Reviewed-by: Leonid Iziumtsev Signed-off-by: Yoann Congal --- .../gawk/gawk/CVE-2026-40467.patch | 63 +++++++++++++++++++ meta/recipes-extended/gawk/gawk_5.3.0.bb | 1 + 2 files changed, 64 insertions(+) create mode 100644 meta/recipes-extended/gawk/gawk/CVE-2026-40467.patch diff --git a/meta/recipes-extended/gawk/gawk/CVE-2026-40467.patch b/meta/recipes-extended/gawk/gawk/CVE-2026-40467.patch new file mode 100644 index 00000000000..d813db5f8b0 --- /dev/null +++ b/meta/recipes-extended/gawk/gawk/CVE-2026-40467.patch @@ -0,0 +1,63 @@ +From 22fd9e360251f70b34e9b46635b6d75bce49202f Mon Sep 17 00:00:00 2001 +From: "Arnold D. Robbins" +Date: Fri, 3 Apr 2026 12:02:11 +0300 +Subject: [PATCH] Small memory management fix in io.c. + +CVE: CVE-2026-40467 +Upstream-Status: Backport [https://cgit.git.savannah.gnu.org/cgit/gawk.git/commit/?id=a2d18c74109e41bec29a23098eba2e00057286d8] + +(cherry picked from commit a2d18c74109e41bec29a23098eba2e00057286d8) +Signed-off-by: Darsh Kelaiya +--- + ChangeLog | 6 ++++++ + io.c | 5 ++++- + 2 files changed, 10 insertions(+), 1 deletion(-) + +diff --git a/ChangeLog b/ChangeLog +index 2fa8b2f0..6bc88ebb 100644 +--- a/ChangeLog ++++ b/ChangeLog +@@ -1,3 +1,9 @@ ++2026-04-03 Arnold D. Robbins ++ ++ * io.c (do_getline_redir): Don't DEREF redir_exp too early. ++ Thanks to Michał Majchrowicz ++ for the report. ++ + 2023-11-02 Arnold D. Robbins + + * 5.3.0: Release tar ball made. +diff --git a/io.c b/io.c +index 44671ebd..4db4b21d 100644 +--- a/io.c ++++ b/io.c +@@ -2836,22 +2836,25 @@ do_getline_redir(int into_variable, enum redirval redirtype) + assert(redirtype != redirect_none); + redir_exp = TOP(); + rp = redirect(redir_exp, redirtype, & redir_error, false); +- DEREF(redir_exp); + decr_sp(); + if (rp == NULL) { + if (redir_error) { /* failed redirect */ + if (! do_traditional) + update_ERRNO_int(redir_error); + } ++ DEREF(redir_exp); + return make_number((AWKNUM) -1.0); + } else if ((rp->flag & RED_TWOWAY) != 0 && rp->iop == NULL) { + if (is_non_fatal_redirect(redir_exp->stptr, redir_exp->stlen)) { + update_ERRNO_int(EBADF); ++ DEREF(redir_exp); + return make_number((AWKNUM) -1.0); + } + (void) close_rp(rp, CLOSE_ALL); ++ DEREF(redir_exp); // we're about to die, but what the heck, release it anyway + fatal(_("getline: attempt to read from closed read end of two-way pipe")); + } ++ DEREF(redir_exp); + iop = rp->iop; + if (iop == NULL) /* end of input */ + return make_number((AWKNUM) 0.0); +-- +2.44.4 + diff --git a/meta/recipes-extended/gawk/gawk_5.3.0.bb b/meta/recipes-extended/gawk/gawk_5.3.0.bb index b1d1fe7ae47..56d7d7f76af 100644 --- a/meta/recipes-extended/gawk/gawk_5.3.0.bb +++ b/meta/recipes-extended/gawk/gawk_5.3.0.bb @@ -22,6 +22,7 @@ SRC_URI = "${GNU_MIRROR}/gawk/gawk-${PV}.tar.gz \ file://0001-m4-readline-add-missing-includes.patch \ file://run-ptest \ file://0001-Fix-some-C23-compilatio-issues.patch \ + file://CVE-2026-40467.patch \ " SRC_URI[sha256sum] = "378f8864ec21cfceaa048f7e1869ac9b4597b449087caf1eb55e440d30273336" From patchwork Tue Jul 28 22:21:39 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 8bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 93762 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 90548C54F5F for ; Tue, 28 Jul 2026 22:22:16 +0000 (UTC) Received: from mail-wm1-f51.google.com (mail-wm1-f51.google.com [209.85.128.51]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.2698.1785277326988080613 for ; Tue, 28 Jul 2026 15:22:07 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=cPIhzXjj; spf=pass (domain: smile.fr, ip: 209.85.128.51, mailfrom: yoann.congal@smile.fr) Received: by mail-wm1-f51.google.com with SMTP id 5b1f17b1804b1-49555a0e68bso1535055e9.2 for ; Tue, 28 Jul 2026 15:22:06 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1785277325; x=1785882125; darn=lists.openembedded.org; h=content-transfer-encoding:content-type:mime-version:references :in-reply-to:message-id:date:subject:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=87eIEN+8RqPPk5Qy+6VFck85eYscwVcE+eicST6hko4=; b=cPIhzXjjG1eNk2GSXr/5/6Khw48zbwbtpBiFQi5jiF7f4reJ9e5pxk7lYIiNAMZXtX F4PDSBIudsCsucEkJMWMFVlK6gFrcmXINIZVUg7hoyp6+4Ol1/GzFJa6sN1yx5eWeFVh ohhvXKiVExoNooxtxxvYoPrDFiCqog2JRkxKE= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1785277325; x=1785882125; h=content-transfer-encoding:content-type:mime-version:references :in-reply-to:message-id:date:subject:to:from:x-gm-gg :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to :content-type; bh=87eIEN+8RqPPk5Qy+6VFck85eYscwVcE+eicST6hko4=; b=domdv9JZA9uQ898FoZeJqZF5Q/NKIfyPE49Pbj8q3b2/VGUxRuM7RhylfZn+5x48jb tlKZ+v1dPleSLJJ8mYhug41+ETlGsYrfC5O6Ab3e3ZLjue6A+YqOpW2g0/Zinui/0xRo ripdF+IcJRG5j3Ls4x4PI9oy27nVW9s1ihHxJfEeRjrMEAAen7ZIC2tUXQky4Pt5ljKp tzeYIHSx8e3ML5Z/cGo+Zz4KbSMgf/Y/VWnHxf4Z+LKA0qzjEccwWmDQDNNXYehx8Nmy ajhuk2seqxYJ9J20D+W/xsPpbeOKZ/LVphHSSQFo8k77YMOl9jzZI2H4RX+/6CQIX15p yAkA== X-Gm-Message-State: AOJu0YxIePNzNDL5coUMyBfgSFlfds5iWIrfq7hrdU2TagpJjQkGWsQk OEA+ua1WJG7GfY5l+OakuMYKy39vDNsqVe1QLe7aK8eEPNTwBrDtYuhwlA+F/UAzi0dMtSgHSyY 8CGflQEg= X-Gm-Gg: AR+sD12Ee5Hf8V+2B3KIq5NIGB1vI9gZi5PQr2rdQCRSPM/WMhQomSdi3L/K4wUvO1K NYQVk3KwP9XsDeYZogUYurC1C8SqnWzVxK/VCu6ONGNAg/tZZ38u/K4IwhwaRYHKexP6iokT7ti PoKqIt6r2LTJGiTLYTA1Rriws2bWFopza9lzIHntft7omu2/4tsCcGGu+pMvgzhq0fMkH/+2gPn EHbUL9U1zoiC6AkWrYy8VbPUa7OjZuQZHvOQ7Men+KCNiVbO+S6UOVg0ARgwLZ9epb37BMCynrn F2hs6JScg5ENNU8gPNwsF4SJIo5B8H8PgEthtjtW7LQw1JGoR1sUO8fcPGiMHYFp5ZEqboi4bch tWXk0prz274TL9lAou5Ypu6m65ZqT3bGG4I8idxlBlfXZhiIwIZm3n8sfsNB+9AeyOg5tBCHX60 Tl2X1fg8ngcLIFlclAo+ZhAE5u1J8MA4Ho6iiaWDkvTr+jHQ1qbJMQJoV/mKe5y+lTkvwesfWvK mB1pXGv10GgVExiU92LEqe58q+WSoGLbw1YG1slREs0KYWt1Fr5NMfRfgK6Xhah X-Received: by 2002:a05:600c:c8d:b0:493:c8f7:3631 with SMTP id 5b1f17b1804b1-496c6575e33mr40445465e9.22.1785277325237; Tue, 28 Jul 2026 15:22:05 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-4976bd6da4asm7669405e9.1.2026.07.28.15.22.04 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Tue, 28 Jul 2026 15:22:04 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][scarthgap 04/19] gawk: Fix CVE-2026-40468 Date: Wed, 29 Jul 2026 00:21:39 +0200 Message-ID: X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Tue, 28 Jul 2026 22:22:16 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/242207 From: Darsh Kelaiya This patch applies the upstream fix as referenced in [2], using the commit shown in [1]. [1] https://cgit.git.savannah.gnu.org/cgit/gawk.git/commit/?id=062f2f2581b991362c046f7f2e238ffa34e6f8c7 [2] https://nvd.nist.gov/vuln/detail/CVE-2026-40468 Signed-off-by: Darsh Kelaiya Reviewed-by: Leonid Iziumtsev Signed-off-by: Yoann Congal --- .../gawk/gawk/CVE-2026-40468.patch | 65 +++++++++++++++++++ meta/recipes-extended/gawk/gawk_5.3.0.bb | 1 + 2 files changed, 66 insertions(+) create mode 100644 meta/recipes-extended/gawk/gawk/CVE-2026-40468.patch diff --git a/meta/recipes-extended/gawk/gawk/CVE-2026-40468.patch b/meta/recipes-extended/gawk/gawk/CVE-2026-40468.patch new file mode 100644 index 00000000000..607f641615b --- /dev/null +++ b/meta/recipes-extended/gawk/gawk/CVE-2026-40468.patch @@ -0,0 +1,65 @@ +From e281dfa04afc4660419ad69c9f24bc6b4067f8d8 Mon Sep 17 00:00:00 2001 +From: "Arnold D. Robbins" +Date: Sat, 4 Apr 2026 21:45:58 +0300 +Subject: [PATCH] Minor integer overflow fixes. + +CVE: CVE-2026-40468 +Upstream-Status: Backport [https://cgit.git.savannah.gnu.org/cgit/gawk.git/commit/?id=062f2f2581b991362c046f7f2e238ffa34e6f8c7] + +Backport Changes: +- Adapt the parse_escape() type change for gawk 5.3.0, where i is + declared int instead of long. + +(cherry picked from commit 062f2f2581b991362c046f7f2e238ffa34e6f8c7) +Signed-off-by: Darsh Kelaiya +--- + ChangeLog | 8 ++++++++ + builtin.c | 2 +- + node.c | 2 +- + 3 files changed, 10 insertions(+), 2 deletions(-) + +diff --git a/ChangeLog b/ChangeLog +index 6bc88ebb..e691b241 100644 +--- a/ChangeLog ++++ b/ChangeLog +@@ -1,3 +1,11 @@ ++2026-04-04 Arnold D. Robbins ++ ++ * builtin.c (do_sub): Make `sofar' be size_t to avoid ++ integer overflows. Thanks to Michał Majchrowicz ++ for the report. ++ * node.c (parse_escape): Change `i' to int64_t to avoid ++ overflows. Thanks to ASan with gcc -m32. ++ + 2026-04-03 Arnold D. Robbins + + * io.c (do_getline_redir): Don't DEREF redir_exp too early. +diff --git a/builtin.c b/builtin.c +index ba3459db..80ab6069 100644 +--- a/builtin.c ++++ b/builtin.c +@@ -2985,7 +2985,7 @@ do_sub(int nargs, unsigned int flags) + char *repl; + char *replend; + size_t repllen; +- int sofar; ++ size_t sofar; + int ampersands; + int matches = 0; + Regexp *rp; +diff --git a/node.c b/node.c +index f08a57d7..12a8fab4 100644 +--- a/node.c ++++ b/node.c +@@ -571,7 +571,7 @@ parse_escape(const char **string_ptr, const char **result, size_t *nbytes) + static char buf[MB_LEN_MAX]; + enum escape_results retval = ESCAPE_OK; + int c = *(*string_ptr)++; +- int i; ++ int64_t i; + int count; + int j; + const char *start; +-- +2.44.4 + diff --git a/meta/recipes-extended/gawk/gawk_5.3.0.bb b/meta/recipes-extended/gawk/gawk_5.3.0.bb index 56d7d7f76af..d79b0222a67 100644 --- a/meta/recipes-extended/gawk/gawk_5.3.0.bb +++ b/meta/recipes-extended/gawk/gawk_5.3.0.bb @@ -23,6 +23,7 @@ SRC_URI = "${GNU_MIRROR}/gawk/gawk-${PV}.tar.gz \ file://run-ptest \ file://0001-Fix-some-C23-compilatio-issues.patch \ file://CVE-2026-40467.patch \ + file://CVE-2026-40468.patch \ " SRC_URI[sha256sum] = "378f8864ec21cfceaa048f7e1869ac9b4597b449087caf1eb55e440d30273336" From patchwork Tue Jul 28 22:21:40 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 8bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 93763 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 71FBAC54F98 for ; Tue, 28 Jul 2026 22:22:16 +0000 (UTC) Received: from mail-wm1-f43.google.com (mail-wm1-f43.google.com [209.85.128.43]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.2699.1785277327924474457 for ; Tue, 28 Jul 2026 15:22:08 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=Q5LpasTB; spf=pass (domain: smile.fr, ip: 209.85.128.43, mailfrom: yoann.congal@smile.fr) Received: by mail-wm1-f43.google.com with SMTP id 5b1f17b1804b1-4954a9e8490so8137785e9.1 for ; Tue, 28 Jul 2026 15:22:07 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1785277326; x=1785882126; darn=lists.openembedded.org; h=content-transfer-encoding:content-type:mime-version:references :in-reply-to:message-id:date:subject:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=WoMtFwyJKRXi3ZVAsYGoeidbQte1M4RkxQ8enIPTVlM=; b=Q5LpasTBsuQikiS0GQ8Wp9GTfxklsdPqS2CmB6qd3EuRUpzxVEVUSy9Mt1zvnEjuND 4PDgGP8yJdG4CBvN1cQ057cEJFy8AizRP4bNM7MS2VDWm9qUO53CgH5wSTYSi8DTNTGL ABPiKe4XkCA7IRBhZmskAVRHgOyCAH4VMlnwk= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1785277326; x=1785882126; h=content-transfer-encoding:content-type:mime-version:references :in-reply-to:message-id:date:subject:to:from:x-gm-gg :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to :content-type; bh=WoMtFwyJKRXi3ZVAsYGoeidbQte1M4RkxQ8enIPTVlM=; b=QE2j8Q1fNeY9wGnJiMJ0QVuMSX+AVmOJIHOov3gjuZjBzRVRp4MMCcmMY/+QW6734w ICqKWQDmJ/65qPh/nmonSXVQXV1ZKlz7s8oMIof+ROsAbchUXhTaGkSH4efF3PAfriyz Gb8LnTbTfIk+MIZxGuFu1PV0odUPqtVyljmocOt29ueTN0hKyE4hsHAtV/W0eulpMqDa KVfR1thG2jZRiXTnNeNInPs5alKDh/GuTNOsLsUiT3rPR50dpCX1CyomzjZ/Z6z0Gh0i ksUQ7ppGRYo8sGOYplZikTA4K9ioBEbkGEaZemR0j5O/4mGiyXWMtzjK1LFcgRcpZzjQ ctQw== X-Gm-Message-State: AOJu0YzjB/LKc6dwzawdaIf7ZcQz75E1Yp0SpOAIIV8rHcifK9GEm8Cj 4mTLveHsADpEf8qfz1NqLQVK+djJQyIK5AQI3hIKykLFYHUo4LB9jAOtIp1/pWzaSmzUpbGi50z HLk7TYw8= X-Gm-Gg: AR+sD1231f1Dg6W9AC+JS3QZdAd3meQtRp6PEiRKlml27QyC+sARLxE4BHkj+i6GWhe Ew4RJ56/ZegQm4JcAGDPLJEMdMRJuzaeLQiN8d5Qg4wgqSPWMB8hUmU/TYs0PujF5ws+62SThKq qljU2pLtuiZNRnxNoPrl6zIfC/pBfRhWvzSjiZ28ABuFWsyx5eQeuvI3jQQ82h6EjytpMawh4kc ATbHFHs9DYK1vaJVRKo0b/t5ax15oRNroCaQW77jEZTuZzrwTzoC0JKG6tvomFSPuTzdSuXkTol BWsbhRICk8f+ZNdh/8CELZEFeIr7r1c8hjXgZpueV/+EpIL3Z5D98vXDP9jvRGWNsgUg7pQHTJk KP86E89+5OiJmFvGcF9Cqw8kG/cw1WYQ7hb6XEjIXBDUhGKL9TNnlNGlvPo+yvMsLgkfIDi9mDL QLKcgguPh9QjNO2pA15eHDbEb5V0gGypodP1y+FXNNpno9CWEdqX0LoRSTfEI4Ej0YQhzB/8bM9 rsVKWgPmUJoyh+Yf7T0dZETiCh2w/Q4MzdJY5cak9U7+9C82szMo6QJlkr2nGbG X-Received: by 2002:a05:600c:3b26:b0:495:6022:5a23 with SMTP id 5b1f17b1804b1-496c65988f8mr47249185e9.19.1785277326084; Tue, 28 Jul 2026 15:22:06 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-4976bd6da4asm7669405e9.1.2026.07.28.15.22.05 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Tue, 28 Jul 2026 15:22:05 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][scarthgap 05/19] gawk: Fix CVE-2026-40469 Date: Wed, 29 Jul 2026 00:21:40 +0200 Message-ID: <421a3d2166e922c5a8085be0aa9daab13920b613.1785277157.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Tue, 28 Jul 2026 22:22:16 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/242208 From: Darsh Kelaiya NVD [3] identifies upstream merge commit [2] as the fix. The CVE-specific change is its second parent [1], which adds 32-bit overflow checking in do_sub(). [1] https://cgit.git.savannah.gnu.org/cgit/gawk.git/commit/?id=aa7272a6e1184cdd21ab8f89200219abd8053eda [2] https://cgit.git.savannah.gnu.org/cgit/gawk.git/commit/?id=ae1b2d508f46913269a9e62aceda3636afe8147b [3] https://nvd.nist.gov/vuln/detail/CVE-2026-40469 Signed-off-by: Darsh Kelaiya Reviewed-by: Leonid Iziumtsev Signed-off-by: Yoann Congal --- .../gawk/gawk/CVE-2026-40469.patch | 90 +++++++++++++++++++ meta/recipes-extended/gawk/gawk_5.3.0.bb | 1 + 2 files changed, 91 insertions(+) create mode 100644 meta/recipes-extended/gawk/gawk/CVE-2026-40469.patch diff --git a/meta/recipes-extended/gawk/gawk/CVE-2026-40469.patch b/meta/recipes-extended/gawk/gawk/CVE-2026-40469.patch new file mode 100644 index 00000000000..49b6a23b012 --- /dev/null +++ b/meta/recipes-extended/gawk/gawk/CVE-2026-40469.patch @@ -0,0 +1,90 @@ +From f907980a3e7a58006b796308021c8410a24e0f3c Mon Sep 17 00:00:00 2001 +From: "Arnold D. Robbins" +Date: Mon, 6 Apr 2026 10:56:38 +0300 +Subject: [PATCH] Add overflow checking in do_sub for 32 bit systems. + +CVE: CVE-2026-40469 +Upstream-Status: Backport [https://cgit.git.savannah.gnu.org/cgit/gawk.git/commit/?id=aa7272a6e1184cdd21ab8f89200219abd8053eda] + +(cherry picked from commit aa7272a6e1184cdd21ab8f89200219abd8053eda) +Signed-off-by: Darsh Kelaiya +--- + ChangeLog | 9 +++++++++ + builtin.c | 25 ++++++++++++++++++++----- + 2 files changed, 29 insertions(+), 5 deletions(-) + +diff --git a/ChangeLog b/ChangeLog +index e691b241..74eea81f 100644 +--- a/ChangeLog ++++ b/ChangeLog +@@ -1,3 +1,12 @@ ++2026-04-06 Arnold D. Robbins ++ ++ * builtin.c (do_sub): Check for overflow in calculation of size ++ of result buffer by doing the math in 64 bits. This provides ++ a fatal message on 32 bit systems if overflow happens instead ++ of letting dynamic memory get corrupted and likely causing ++ a core dump. Thanks to Michał Majchrowicz ++ for the report and fix. ++ + 2026-04-04 Arnold D. Robbins + + * builtin.c (do_sub): Make `sofar' be size_t to avoid +diff --git a/builtin.c b/builtin.c +index 80ab6069..d63cf47b 100644 +--- a/builtin.c ++++ b/builtin.c +@@ -2998,11 +2998,13 @@ do_sub(int nargs, unsigned int flags) + long current; + bool lastmatchnonzero; + char *mb_indices = NULL; ++ const char *fname = NULL; // for fatal message, below + + if ((flags & GENSUB) != 0) { + double d; + NODE *glob_flag; + ++ fname = "gensub"; + check_exact_args(nargs, "gensub", 4); + + tmp = PEEK(3); +@@ -3033,11 +3035,9 @@ do_sub(int nargs, unsigned int flags) + } + DEREF(glob_flag); + } else { +- if ((flags & GSUB) != 0) { +- check_exact_args(nargs, "gsub", 3); +- } else { +- check_exact_args(nargs, "sub", 3); +- } ++ fname = ((flags & GSUB) != 0) ? "gsub" : "sub"; ++ ++ check_exact_args(nargs, fname, 3); + + /* take care of regexp early, in case re_update is fatal */ + +@@ -3153,6 +3153,21 @@ do_sub(int nargs, unsigned int flags) + * vary since ampersand is actual text of regexp match. + */ + ++ // 4/2026: This overflow check simply provides a fatal ++ // message instead of letting realloc() die later after ++ // a buffer overrun. It simply makes the user experience better, ++ // but does not prevent gawk from dying miserably. I suppose ++ // it's worth the trouble, but just barely. ++ ++ /* uint64_t so the product is 64-bit even on 32-bit ILP32 builds */ ++ uint64_t repl_contribution = ++ (uint64_t)(unsigned int)ampersands ++ * (uint64_t)(uintptr_t)(matchend - matchstart); ++ if (repl_contribution > (uint64_t)SIZE_MAX ++ || repl_contribution > (uint64_t)SIZE_MAX - (size_t)(matchend - text) ++ - repllen - 1) ++ fatal(_("%s: replacement expansion too large"), fname); ++ + /* + * add 1 to len to handle "empty" case where + * matchend == matchstart and we force a match on a single +-- +2.44.4 + diff --git a/meta/recipes-extended/gawk/gawk_5.3.0.bb b/meta/recipes-extended/gawk/gawk_5.3.0.bb index d79b0222a67..7bd34a3ff81 100644 --- a/meta/recipes-extended/gawk/gawk_5.3.0.bb +++ b/meta/recipes-extended/gawk/gawk_5.3.0.bb @@ -24,6 +24,7 @@ SRC_URI = "${GNU_MIRROR}/gawk/gawk-${PV}.tar.gz \ file://0001-Fix-some-C23-compilatio-issues.patch \ file://CVE-2026-40467.patch \ file://CVE-2026-40468.patch \ + file://CVE-2026-40469.patch \ " SRC_URI[sha256sum] = "378f8864ec21cfceaa048f7e1869ac9b4597b449087caf1eb55e440d30273336" From patchwork Tue Jul 28 22:21:41 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 93766 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id A72FDC54FCD for ; Tue, 28 Jul 2026 22:22:16 +0000 (UTC) Received: from mail-wm1-f48.google.com (mail-wm1-f48.google.com [209.85.128.48]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.2700.1785277328679736728 for ; Tue, 28 Jul 2026 15:22:08 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=EFLShdHy; spf=pass (domain: smile.fr, ip: 209.85.128.48, mailfrom: yoann.congal@smile.fr) Received: by mail-wm1-f48.google.com with SMTP id 5b1f17b1804b1-493f6de72faso2285025e9.0 for ; Tue, 28 Jul 2026 15:22:08 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1785277327; x=1785882127; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=lNSF8vR4SEtC8nkXG8yheeFTZK9XsRPhl3jMulqVQmE=; b=EFLShdHyd8U0gVSxtCT9sr9Lt+FxE3iZ/w+wtz3JMywtgEO8D0XDj+vxepSHXMLIde so3yfhE06fJMUWCgUD8XcX6CsNH3xR2fxIezePX2dJyBpUXbbfRntkKasweHiyAyySh6 ABdcSk6tuVYlWC+5EOFHaZ1vOCJrr8zsI5FJ0= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1785277327; x=1785882127; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=lNSF8vR4SEtC8nkXG8yheeFTZK9XsRPhl3jMulqVQmE=; b=tHI7SBEK6ckOwleF5IE1OYFT1D4iTQwXAYbGFlvmah9/fN64mkD5omtaxWKkAcG7t/ bEu5d25jURqbICb/MpjmFAnA5Ngl/O/5CqXAScZ6Ces8uHxJUImK8zzkZOYgeHcnIZp8 Fp/BfSuWwGfLxZ3K2Ex4bMnmDKB3zPEyefwuB2opXKYLeZMBgzd+58Le/lyvO55yAEaW eLT5mfLhwSiQ/e3ToUsBhL8Vgq/GhLCPvcpDJOGkAtuJ3Vg+iBm3Ms79GwY2FC1v7lQb XV1nyUCafh9UAvpi+RRPb8FxGqxSpBCNtNScqJrCFXbxeYAz7uKA/R/RseBbFqts7UiR OL+w== X-Gm-Message-State: AOJu0YzdjPXCj7MXFM1oEM+H7aVHl9wiuTvotQhAFsA59lI8XJ63jd2/ ds3qxxd3MT/fWWFnY5lqdT6nKEtXIcN282xyKshXpK+DnZme3kr+l2jz5K8qvQOKnqNJl/81Q/E RgmI4jsw= X-Gm-Gg: AR+sD12IcvoKQSNjBD2yOC9E67c7BgRWrRYFuswcq2Zaxusf7ft/JGt4jhDfLAIPO05 pCHyvF7A1Bs+Kn/nl6+a//5HHzXSfRprPKRyyQh5GlkS5lMmW6+st7nTLNN5XEgckl0Ylub0vnT 9mPzz4UGev+iAdr7Bwr6CXIiQi15trb4Qopvntg3Sm4G5g1Eks5ZbgSiFTLkpnJP86n5ehdLq78 Qhcp0Rcllp677FLYL1whH52hJ/X4KkcUE5RpWHEDE6/+PUNmeHuLdD31rXm6/KAPL9pxhDtNo7l qBUgbaTKIIvzDx0LI0zW5e5TdD435WX/89Rg6aVcpBgFV2K89d7O11W4ysoItACEXLTBy8/1NUf rPvPurSXVAuiexuDosJtLNGkce2Eu00VjS0sKy2py5NpjYTQBAa6Qtch0jXRodY5Mv19QiSV0TN Agj0dCRhkQ2BH+I0ms90OcFrxn9KkomXlxxZ7vPXEr9VczYdUIY5kvxq8AjQv2XQiPRWJJO8Rb7 uN+y5uAcHYmB9Rldo7oL6Rb7duzd/uPEZeFnUguKUUkSlO6Bfkzmr7yS7PPinbJ X-Received: by 2002:a05:600c:e549:20b0:492:6f5c:fd8c with SMTP id 5b1f17b1804b1-496c6585511mr30509595e9.15.1785277326935; Tue, 28 Jul 2026 15:22:06 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-4976bd6da4asm7669405e9.1.2026.07.28.15.22.06 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Tue, 28 Jul 2026 15:22:06 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][scarthgap 06/19] gawk: Fix CVE-2026-40553 Date: Wed, 29 Jul 2026 00:21:41 +0200 Message-ID: <1f60829da0b2ea7d9f3295ba3cfd3bba972872a2.1785277157.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Tue, 28 Jul 2026 22:22:16 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/242209 From: Darsh Kelaiya This patch applies the upstream fix as referenced in [3], using the commit shown in [1]. It also applies the corrective follow-up [2], which fixes the snprintf() truncation boundary check. Both commits are included in gawk 5.4.1, identified as the fixed release in [4]. [1] https://cgit.git.savannah.gnu.org/cgit/gawk.git/commit/?id=cca0366144336b49aaa7d5d949966ce8e2c70843 [2] https://cgit.git.savannah.gnu.org/cgit/gawk.git/commit/?id=bfa2e4b890a44100a99d26b54af385479528b12e [3] https://nvd.nist.gov/vuln/detail/CVE-2026-40553 [4] https://cert.pl/en/posts/2026/07/CVE-2026-40467/ Signed-off-by: Darsh Kelaiya Reviewed-by: Leonid Iziumtsev Signed-off-by: Yoann Congal --- .../gawk/gawk/CVE-2026-40553_p1.patch | 50 +++++++++++++++++++ .../gawk/gawk/CVE-2026-40553_p2.patch | 44 ++++++++++++++++ meta/recipes-extended/gawk/gawk_5.3.0.bb | 2 + 3 files changed, 96 insertions(+) create mode 100644 meta/recipes-extended/gawk/gawk/CVE-2026-40553_p1.patch create mode 100644 meta/recipes-extended/gawk/gawk/CVE-2026-40553_p2.patch diff --git a/meta/recipes-extended/gawk/gawk/CVE-2026-40553_p1.patch b/meta/recipes-extended/gawk/gawk/CVE-2026-40553_p1.patch new file mode 100644 index 00000000000..07b7df488a8 --- /dev/null +++ b/meta/recipes-extended/gawk/gawk/CVE-2026-40553_p1.patch @@ -0,0 +1,50 @@ +From aa39cac4bda6333be0f6253ecb7dfade26cb9641 Mon Sep 17 00:00:00 2001 +From: "Arnold D. Robbins" +Date: Wed, 15 Apr 2026 09:39:02 +0300 +Subject: [PATCH] Avoid buffer overflow in extension/readdir.c. + +CVE: CVE-2026-40553 +Upstream-Status: Backport [https://cgit.git.savannah.gnu.org/cgit/gawk.git/commit/?id=cca0366144336b49aaa7d5d949966ce8e2c70843] + +(cherry picked from commit cca0366144336b49aaa7d5d949966ce8e2c70843) +Signed-off-by: Darsh Kelaiya +--- + extension/ChangeLog | 6 ++++++ + extension/readdir.c | 6 +++++- + 2 files changed, 11 insertions(+), 1 deletion(-) + +diff --git a/extension/ChangeLog b/extension/ChangeLog +index 40ed6dd0..52a4c6ab 100644 +--- a/extension/ChangeLog ++++ b/extension/ChangeLog +@@ -1,3 +1,9 @@ ++2026-04-15 Arnold D. Robbins ++ ++ * readdir.c (ftype): Use snprintf() to check for buffer ++ overflow in the file name before calling stat(). Thanks to ++ Marcin Wyczechowski for the report. ++ + 2023-11-02 Arnold D. Robbins + + * 5.3.0: Release tar ball made. +diff --git a/extension/readdir.c b/extension/readdir.c +index 788e1d1e..b525fe21 100644 +--- a/extension/readdir.c ++++ b/extension/readdir.c +@@ -117,8 +117,12 @@ ftype(struct dirent *entry, const char *dirname) + #endif + char fname[PATH_MAX]; + struct stat sbuf; ++ int count; ++ ++ count = snprintf(fname, sizeof(fname), "%s/%s", dirname, entry->d_name); ++ if (count > sizeof(fname)) ++ return "u"; // buffer overflow. skip stat() call. + +- sprintf(fname, "%s/%s", dirname, entry->d_name); + if (stat(fname, &sbuf) == 0) { + if (S_ISBLK(sbuf.st_mode)) + return "b"; +-- +2.44.4 + diff --git a/meta/recipes-extended/gawk/gawk/CVE-2026-40553_p2.patch b/meta/recipes-extended/gawk/gawk/CVE-2026-40553_p2.patch new file mode 100644 index 00000000000..2f63572af0b --- /dev/null +++ b/meta/recipes-extended/gawk/gawk/CVE-2026-40553_p2.patch @@ -0,0 +1,44 @@ +From 8b08dcf6c784e7a98d08e9e63a8fda15040eee30 Mon Sep 17 00:00:00 2001 +From: "Arnold D. Robbins" +Date: Fri, 17 Apr 2026 11:48:19 +0300 +Subject: [PATCH] Small fix in extension/readdir.c. + +CVE: CVE-2026-40553 +Upstream-Status: Backport [https://cgit.git.savannah.gnu.org/cgit/gawk.git/commit/?id=bfa2e4b890a44100a99d26b54af385479528b12e] + +(cherry picked from commit bfa2e4b890a44100a99d26b54af385479528b12e) +Signed-off-by: Darsh Kelaiya +--- + extension/ChangeLog | 5 +++++ + extension/readdir.c | 2 +- + 2 files changed, 6 insertions(+), 1 deletion(-) + +diff --git a/extension/ChangeLog b/extension/ChangeLog +index 52a4c6ab..c8839357 100644 +--- a/extension/ChangeLog ++++ b/extension/ChangeLog +@@ -1,3 +1,8 @@ ++2026-04-15 Arnold D. Robbins ++ ++ * readdir.c (ftype): Use >= in check of snprintf() return ++ value. Thanks to Andrew Schorr . ++ + 2026-04-15 Arnold D. Robbins + + * readdir.c (ftype): Use snprintf() to check for buffer +diff --git a/extension/readdir.c b/extension/readdir.c +index b525fe21..6f9b6811 100644 +--- a/extension/readdir.c ++++ b/extension/readdir.c +@@ -120,7 +120,7 @@ ftype(struct dirent *entry, const char *dirname) + int count; + + count = snprintf(fname, sizeof(fname), "%s/%s", dirname, entry->d_name); +- if (count > sizeof(fname)) ++ if (count >= sizeof(fname)) + return "u"; // buffer overflow. skip stat() call. + + if (stat(fname, &sbuf) == 0) { +-- +2.44.4 + diff --git a/meta/recipes-extended/gawk/gawk_5.3.0.bb b/meta/recipes-extended/gawk/gawk_5.3.0.bb index 7bd34a3ff81..d71f655ba6e 100644 --- a/meta/recipes-extended/gawk/gawk_5.3.0.bb +++ b/meta/recipes-extended/gawk/gawk_5.3.0.bb @@ -25,6 +25,8 @@ SRC_URI = "${GNU_MIRROR}/gawk/gawk-${PV}.tar.gz \ file://CVE-2026-40467.patch \ file://CVE-2026-40468.patch \ file://CVE-2026-40469.patch \ + file://CVE-2026-40553_p1.patch \ + file://CVE-2026-40553_p2.patch \ " SRC_URI[sha256sum] = "378f8864ec21cfceaa048f7e1869ac9b4597b449087caf1eb55e440d30273336" From patchwork Tue Jul 28 22:21:42 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 93760 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 4123AC54F5D for ; Tue, 28 Jul 2026 22:22:16 +0000 (UTC) Received: from mail-wm1-f41.google.com (mail-wm1-f41.google.com [209.85.128.41]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.2804.1785277329689135086 for ; Tue, 28 Jul 2026 15:22:09 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=GYozNiVa; spf=pass (domain: smile.fr, ip: 209.85.128.41, mailfrom: yoann.congal@smile.fr) Received: by mail-wm1-f41.google.com with SMTP id 5b1f17b1804b1-4953de5be0aso2309915e9.0 for ; Tue, 28 Jul 2026 15:22:09 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1785277328; x=1785882128; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=IHy4snm+2Ap6hGsU5IBuSKkkDxY5ms1DSklRBEiH3h8=; b=GYozNiVaCQhJsPB6+slVGJjCums45mWKPK7HhKJjpnFtor7X5C046TsoUucz9vXdha Hmge9VKU2MJjdh8O9JY/rMRnYvScOzHIvCMjpo5ZgFr6h1vTuQ718z/bPA5iN9Ntd4G0 F2rZ3Ikh/PDaoJdY2UN8T/YW1Gxnwg1HWgHRA= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1785277328; x=1785882128; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=IHy4snm+2Ap6hGsU5IBuSKkkDxY5ms1DSklRBEiH3h8=; b=K90ZiL/joP+os1Jfl1UjKWodRYcZSpaHw392hsz2qEIQvlmDhYa8S8ZMhiWEmf60P/ 0Gtq3MzQvzRZk6Uz79XE1eHP92qEPlnHSDgSN+DPxGqJfLJDbjbEH5D2vQTFwRgXSRFK AY7m8dNdFQ8QN8sJDiMQYVDdvvCY1+HfNH7a6yMiKWlyjH7pSTFyi4hQPh9Tw9AvnHP9 SxmCci0TNHr9mE3i+h9s9Vc8MTkSfUZ/+WRW9uRg7qoIt1h2ZGhAtz1SMM/S3kC0X5Ye C2ca2sbeZjzGs87h2dDX7BRH9elonIPkZmFF4NmSmgrYJn/PDOIQS9KYR1yv34BDyxKw q40A== X-Gm-Message-State: AOJu0YwTTNDbuXKBsx6322oSK7eWae6GAVWtjC8a/BeNBsKcs3BqBLwl EhNSAfbFaukf9D70VLXx3YTRQQl4PesKqkfeYl0CY2T66UIVxH9jxfmUnVq7aFflDR3jK46a/B3 f/VSHsdo= X-Gm-Gg: AR+sD13I+8MqeChCANIovtpl7HXYTR3w++EFqjxsVqMmUD9P/i/0Jd9ZPbtQv0TQgMx iSQSJZ974TJqgvzTDs5z0Z0qVbO0rf8vzYZ3nfgn0FyuZ+xlMJBF0ZTNDhW3k7fzds+FROn/zbC fH1avfb5pKqNxcWsSsfBWFtbKkTPREyecnRZ6TBkqcCQBbvkSuyGFVXQUa2Bd1tPBr6PYSDiaC5 WArlvYssKcT4x68eG1E5Xdd0CxZn7J4miyGj1X+wJ9nX0rhTRArv4F6vR28RgeeEm1loHvqBHHV r8pQbFxslUsAoxN5+E4k/+UcezcaF+AmkXTjoVQUCZjxQB7mnoVPoIBCjmPdSp096m7btcMHrN7 XooIC/PdgPAQuFeIHMmi/QnzAuvBOzAi1aivAx0Vb0hOLw51hVQJkKZSV8dIaM5DbP8ZsNpVXYZ /Dg/PIOuB9RiFVMICwr/Nx8qez5cF12WT89KQXR+rFwXQKUciV9NeFjba2On5hEtglmtQG7pdvB WVi96jo2bepQV5+sxk0gfQzUkjLaQcbjD/9ChpAHw6NN251UQikYVP+YYqT8V4zMHiJyVXY89k= X-Received: by 2002:a05:600c:8b41:b0:493:a613:56b2 with SMTP id 5b1f17b1804b1-496c653e2a0mr47066205e9.8.1785277327908; Tue, 28 Jul 2026 15:22:07 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-4976bd6da4asm7669405e9.1.2026.07.28.15.22.07 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Tue, 28 Jul 2026 15:22:07 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][scarthgap 07/19] python3-cryptography: set CVE_PRODUCT Date: Wed, 29 Jul 2026 00:21:42 +0200 Message-ID: X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Tue, 28 Jul 2026 22:22:16 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/242210 From: mark.yang NVD lists it as cryptography.io:cryptography and CNA lists it as pyca:cryptography, so set both vendor:product pairs to match correctly and precisely. Suggested-by: Ross Burton Signed-off-by: mark.yang Signed-off-by: Mathieu Dubois-Briand Signed-off-by: Richard Purdie (cherry picked from commit b721019e0b2ccbaa8de267e14b282c48a5a3de8b) Signed-off-by: Himanshu Jadon Signed-off-by: Yoann Congal --- meta/recipes-devtools/python/python3-cryptography_42.0.5.bb | 2 ++ 1 file changed, 2 insertions(+) diff --git a/meta/recipes-devtools/python/python3-cryptography_42.0.5.bb b/meta/recipes-devtools/python/python3-cryptography_42.0.5.bb index c4573fa6891..10ce753eac3 100644 --- a/meta/recipes-devtools/python/python3-cryptography_42.0.5.bb +++ b/meta/recipes-devtools/python/python3-cryptography_42.0.5.bb @@ -65,4 +65,6 @@ FILES:${PN}-dbg += " \ ${PYTHON_SITEPACKAGES_DIR}/${SRCNAME}/hazmat/bindings/.debug \ " +CVE_PRODUCT = "cryptography.io:cryptography pyca:cryptography" + BBCLASSEXTEND = "native nativesdk" From patchwork Tue Jul 28 22:21:43 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 93759 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 2A90CC54F5C for ; Tue, 28 Jul 2026 22:22:16 +0000 (UTC) Received: from mail-wm1-f48.google.com (mail-wm1-f48.google.com [209.85.128.48]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.2702.1785277330226432052 for ; Tue, 28 Jul 2026 15:22:10 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=1rN9MWeb; spf=pass (domain: smile.fr, ip: 209.85.128.48, mailfrom: yoann.congal@smile.fr) Received: by mail-wm1-f48.google.com with SMTP id 5b1f17b1804b1-495590dde14so3459795e9.0 for ; Tue, 28 Jul 2026 15:22:10 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1785277328; x=1785882128; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=GoSksiwtMHerYcP+4wPmoPZOANXvr37gBJhQ+P6izEs=; b=1rN9MWebafVnNSxBLqQnsmVbkdqraLrZiX+KFzeSWnrUCCGOG6J/JuWY6F+J4yWWPC xIlElEpMNwWs4JplA6jc5G/WiLakkWEoqK81hcBwPZS5CraEFBe4AIrUZjvQIihLt2qk /W9YpQWf1DhSx8jk+lwuhSL8lNhHSCi1+wC6I= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1785277328; x=1785882128; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=GoSksiwtMHerYcP+4wPmoPZOANXvr37gBJhQ+P6izEs=; b=O/eiLcn8AwF8VCXo6H2f6oAVf4sgY5YtV5Hgc9GtsNk1Qhw5nlPMKAq74uGHufM18+ 6PWQ87zCIExMnlaqq8XsnoFhd7hdzNoJJ/hNWKO8l+789o3jhSmpJ9dciJITFlbdt2B8 WTKY9vGqcNdYyHNT9hwz6CJNrje7xNUNEHTBv+XEFQDOaS5tAy/T25sUUeIzPSGjcuc5 ZQRL7xOl7CauJumTe/TH7dtIydCCfdy+6G2bJDtUx1C1zTwJW7az04XxF8GupHvly9MO x/eB28OtbcaVFsjG96YGJNihMd5iDgiP3PDG0MJwJ6DVY1NWFD0x++IF1KB+NEzLFKiS GwPw== X-Gm-Message-State: AOJu0YxUByrgRDOCS6R5q0grVkS/9yrUxEI8p/Wij1Xug3OHKc/GJWlg JnhePXMwXCTH+Dh8iV8fg09yTNIz86j/+gZLRUTEXctQI/t0XIBuAZzzdLsNz/Fu0lEYfDteGxJ y6aAkKaE= X-Gm-Gg: AR+sD13i/igHZGUqWHDkM/HGyys7UmT9AtV86/q8cQeaXIqGRoNQYYpA05ANK0SyfBF fP29ChWYMoJVF4ftNWxLFSRr91FsVTSxzPy+TfyXdpYPzrJAXErZnrGg0pImJHQMqrf7Z88hii9 t6DSTN0voAsoy9RIlfJobCxlPycn8ewaYh45YP1PwT0RMVLcNNi+w91aXdn1RheMsE06peraG7b iGnk1E6RiSTyYj2SJFdF/goMP+SStFhwauZ5VKmSmG8eIuXwx8SAA2jnnp6Q8cf2FvGnqS2cGiP VlyfuEC/KQWXQxTZWIwXWqjNaWrK9O7p9H3L9ma65XzHiUie7M3ZX3Xlu3AQtJV1uAW8E1mwYLm V7N+o7NeIx+5qLhpTvZqFhglNygzo1In5Rhmnfzl9rQ54673JeMxJmKkI4nKFhbgu3QAN9EJC4D kQrJGovSln6sHpQH8HJD3ccFAGEN69nK0zB/JXMGwr+LClsC/lvOHk0hIkUCNe8gFbVrZJ2lAzZ ZZ/3yVIiRDbnI83/uFuyTxeH/k+v4vRSzGVWaZP62V3YZq4+RsOf08o1yI1rBuZCdVc0jwqPZg= X-Received: by 2002:a05:600c:5488:b0:496:c967:5f9c with SMTP id 5b1f17b1804b1-496c9675fa4mr30745405e9.33.1785277328510; Tue, 28 Jul 2026 15:22:08 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-4976bd6da4asm7669405e9.1.2026.07.28.15.22.08 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Tue, 28 Jul 2026 15:22:08 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][scarthgap 08/19] python3-ply: set CVE_PRODUCT Date: Wed, 29 Jul 2026 00:21:43 +0200 Message-ID: <069cda2549b0dd841914c5b860f138f6db8b3977.1785277157.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Tue, 28 Jul 2026 22:22:16 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/242211 From: mark.yang NVD registers ply as dabeaz:ply, so the default python:ply vendor prefix never matches and no CVEs are reported. Use the exact vendor:product pair. CVE-2025-56005 will then show as unpatched; no fixed release exists. Suggested-by: Paul Barker Signed-off-by: mark.yang Signed-off-by: Mathieu Dubois-Briand Signed-off-by: Richard Purdie (cherry picked from commit bb80fef9a76649fb1144408fbc7e2903439cd556) Signed-off-by: Himanshu Jadon Signed-off-by: Yoann Congal --- meta/recipes-devtools/python/python3-ply_3.11.bb | 2 ++ 1 file changed, 2 insertions(+) diff --git a/meta/recipes-devtools/python/python3-ply_3.11.bb b/meta/recipes-devtools/python/python3-ply_3.11.bb index a05bd6702dc..0855c871cf6 100644 --- a/meta/recipes-devtools/python/python3-ply_3.11.bb +++ b/meta/recipes-devtools/python/python3-ply_3.11.bb @@ -15,4 +15,6 @@ RDEPENDS:${PN}:class-target += "\ python3-shell \ " +CVE_PRODUCT = "dabeaz:ply" + BBCLASSEXTEND = "native nativesdk" From patchwork Tue Jul 28 22:21:44 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 93756 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 07692C54F57 for ; Tue, 28 Jul 2026 22:22:16 +0000 (UTC) Received: from mail-wr1-f45.google.com (mail-wr1-f45.google.com [209.85.221.45]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.2805.1785277330836646609 for ; Tue, 28 Jul 2026 15:22:11 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=N/fODEFb; spf=pass (domain: smile.fr, ip: 209.85.221.45, mailfrom: yoann.congal@smile.fr) Received: by mail-wr1-f45.google.com with SMTP id ffacd0b85a97d-47df43bfb07so146681f8f.1 for ; Tue, 28 Jul 2026 15:22:10 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1785277329; x=1785882129; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=upRRZV6qMKso5v9M7fyACNrWoe8tbEXajTDM+Llyl/Y=; b=N/fODEFbssJuxAxjqYrwLAVECuqhCPnXZx8v7qNXU83mUNiLTfpEpNNyK62CyAdKey UFoYUG+RCRGlqLydqiqK1FdBWWV87cXfo7BJ3dgtPbWqLa7T5SBdKCoU5Tt/dFX/FRbd mauX6GkvCcnwtAC76RzQZ0GX+aLFMfEV48/vc= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1785277329; x=1785882129; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=upRRZV6qMKso5v9M7fyACNrWoe8tbEXajTDM+Llyl/Y=; b=JLkAe5RlQcuPkHCBclEfgXOgfB0O6BqbA/UsxgjOXGAINCmf/9++zDNLJqQ7rbMt9m E0UA3+0jzDHD5ouGTIT+MEA6ijy+piWTHDPdvVKSRkvW2Vi20uha0dRyqUfhcmfphl6w V0bPtWeyXS1B79fGOLJQX8km4Y+Jst5Cy2qJXnM/vdyXfXnPkU5lErQJKtZe0yAojKZr 6HQlT1+zd/mUCDkmHb+V4U7VrAucdXbFG3zwAyhMh+t4gwOuFXsGvQ86WUC3UvA/cMMw ztvw187jMaLDGW5gl/cCXcAaoDTmJLk/HuRoxi3hwOhUSi34glgAfWZTAxt51tHtzr5y iLnA== X-Gm-Message-State: AOJu0YxA+zhuKF5ZKl0OUJt8caLCQwLZh0IeSp8atm+OiJ1yJTQmO4p9 /B/xqaHaiJ0QsPYefvZ2C13ccd401zAYujYH1a4rJweveiwkoSoRH05FP8AToBobE1JNC9bjuyk xRnWkPfM= X-Gm-Gg: AR+sD112Sx9Pz6og4ay4tJYoSOCbLz+9jpR+b9FjPgGRhp/FK0mc93+gtfJUOl1CQc9 fmgyxwGbhD406xlEue0Gl+bFMV2f+yYHuqhd0MvvUK+VRrjzEjTMCZjsGIZ6TvsTiu36MF8CoTc gN5E1BBM25V7WIM/sjjV7ftJC0VnT8gXqbueoHcZZ8t6k+7PVNlLzODABuYWrdQIdXHkTvLpSa8 4x4y3CXlZSyIEhHRNrBu1E5D2td6ezc7P2xz6pM80XGc+uia1PAp1WDJet098wV1IPLJP2PoKeD I1tZj0e+Db6SZr6OWgkMzvCVk8eSlYozZfV34h7mJxD4uhKKH3KwMiRM4F2CF5rvEudms9Gw6JJ f3R7XjNoUlEbjcI/QUGxUr1aujfoOybLgOACoAOHXK9OnAmL79M9HlIUY3H6Xf3A5sGfAgIY6IA 0Ep1+IsmeTvXGsPY4X65uWGfNuk1eV/jPfwY4PCB4+qgNEfYEf3EIpGxusqhfwsWm9xUr6ra88l XB7jocFfW2cHI1gKS1+NpgSf5KsPGsBkIjlDCxoZzySRLXCaSJAK1e75Wxhk2bVHiafRzpDej6p X-Received: by 2002:a05:600c:1c1c:b0:493:dcad:84da with SMTP id 5b1f17b1804b1-496c640fc12mr41164475e9.1.1785277328938; Tue, 28 Jul 2026 15:22:08 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-4976bd6da4asm7669405e9.1.2026.07.28.15.22.08 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Tue, 28 Jul 2026 15:22:08 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][scarthgap 09/19] python3-pyasn1: set CVE_PRODUCT Date: Wed, 29 Jul 2026 00:21:44 +0200 Message-ID: <4c2a8f74464cf3b7143bd9e978eef976aea6315e.1785277157.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Tue, 28 Jul 2026 22:22:16 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/242212 From: mark.yang The default python:pyasn1 does not match the NVD/CNA entries which use pyasn1 as vendor, so CVEs like CVE-2026-30922 are never reported. Use the exact pyasn1:pyasn1 pair. Note: Original commit was for python3-pyasn1_0.6.3.bb. This is adjusted for scarthgap where recipe version is python3-pyasn1_0.5.1.bb. Suggested-by: Ross Burton Signed-off-by: mark.yang Signed-off-by: Mathieu Dubois-Briand Signed-off-by: Richard Purdie (cherry picked from commit 4971337840e8855740409e8f5dadb3ab3661f033) Signed-off-by: Himanshu Jadon Signed-off-by: Yoann Congal --- meta/recipes-devtools/python/python3-pyasn1_0.5.1.bb | 1 + 1 file changed, 1 insertion(+) diff --git a/meta/recipes-devtools/python/python3-pyasn1_0.5.1.bb b/meta/recipes-devtools/python/python3-pyasn1_0.5.1.bb index 0519ba5edb0..3f2d444826f 100644 --- a/meta/recipes-devtools/python/python3-pyasn1_0.5.1.bb +++ b/meta/recipes-devtools/python/python3-pyasn1_0.5.1.bb @@ -1,3 +1,4 @@ inherit pypi setuptools3 require python-pyasn1.inc +CVE_PRODUCT = "pyasn1:pyasn1" From patchwork Tue Jul 28 22:21:45 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 8bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 93769 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 942CAC54F9B for ; Tue, 28 Jul 2026 22:22:16 +0000 (UTC) Received: from mail-wm1-f44.google.com (mail-wm1-f44.google.com [209.85.128.44]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.2806.1785277331411626286 for ; Tue, 28 Jul 2026 15:22:11 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=0ThiMbRc; spf=pass (domain: smile.fr, ip: 209.85.128.44, mailfrom: yoann.congal@smile.fr) Received: by mail-wm1-f44.google.com with SMTP id 5b1f17b1804b1-4954aff6088so2856325e9.3 for ; Tue, 28 Jul 2026 15:22:11 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1785277330; x=1785882130; darn=lists.openembedded.org; h=content-transfer-encoding:content-type:mime-version:references :in-reply-to:message-id:date:subject:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=fzAjLuH7Xl2HED2kj20v/zQCTIKEOJa5Cb0kE+8MTqk=; b=0ThiMbRcZW7pGuqZ1S336hk9wlK9ASNkWh1TMThHbB/47ty8KoPaEqefpSc5PHWcEI kqwBDt5pAZAelQ3UctEetEJvae0jzk1IumjpTu6D/Qa21lAoOY3jh5mMm+4vfCntC/tU +SxkBaKbhCVsDq3GVqFz/qPzQc1MHptnmvY7A= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1785277330; x=1785882130; h=content-transfer-encoding:content-type:mime-version:references :in-reply-to:message-id:date:subject:to:from:x-gm-gg :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to :content-type; bh=fzAjLuH7Xl2HED2kj20v/zQCTIKEOJa5Cb0kE+8MTqk=; b=ZzywlFdo1+z7guTitSSUO4IVT9ObMvtap2yqp3UPHanT13rgYEm7tWqYazsMyotCDC uU3teFu9aWcE9OjMiq18YAcA6Hfqjoz9RY3QCZSfOWi17CRH53+KBpN4Nm94WJTqmU1s tiRcrHCVajGEgbx8xw5E0h7ALUzyAcFG9aM7qPeX6zNQcFTffIH4B4c8+3c8W4StD6UH QWbBAAfTkThm/2TmjRQOWwj4uuf/LXyHT7WH0H/ye4OPwrMsjmBTQTxlMvtmsTb7uSFb 1p77QUljxWUf74HXczeelGiKVBHIdSM2wfThUtv/ysvjKFnq4gdhh7pKbB8n245UbWpo VkSg== X-Gm-Message-State: AOJu0Yx+6C+adot+iwS83xEUJG6e9xhM3u3khDphINfiFl3MorbHqa1E 5AWNp4lwS3Rm6KhdJx3Wy3IiZVNTxcy1Q/Ue85L6tm4PB1Y2C5EXhpxrIolYHQbb+9TMzYwv77U TrDV0jpg= X-Gm-Gg: AR+sD109HPMa4dpjICWaQr+xZySw9ech+DMTvkvpURBp9XFNnheZ8h5khu2Bz+VC9kV lw+U2Fu3VDlnCLuaSlAxXqO+w1iFaEKkMhdOhZqWoiQE5krBquKX0LoorbndVPq3i9JaxsUH1zL WVQf39OZ1Ti0I7j731OXXCT7K+IknI8Nu3KrMsa6ovPeeRjdscTndzIKFcZLnYLNglirXZLfJ0J pkQFJ3hQzO+ukhwA7LUXRK4ob9plXap2fMiuI3HMvX1K7ltC3UpXjydLv5kjXFFlPcNiaSnRSO2 wMbdlPqhV/tUVpMTsZq0dSUEy8NOCviLog/5cxZc4kIoLDla+n+bdspHfD3LE3hKe3DQw8lwSqQ RTL84bqCDBS+BOpDRrmuJUUrFdChh1ybLbiphNCP73HtGaGl2BoF8GLmXjuO8y4kBnRaULkZFNP H4yVFW7Jmr0usIUYLeJBgUYeQEK4rmhv+XpFa53bJB20r6dI2ah7U0lAKARjiFv1qsyUQkb90wb RhmlMX2K5Rf6ZOglnxGNB9HW6XjJrhnk0RucXA+gc/vgcafpKeM7ji6WJexLnts X-Received: by 2002:a05:600c:a00b:b0:495:515a:dad9 with SMTP id 5b1f17b1804b1-496c65a14b2mr47396765e9.37.1785277329512; Tue, 28 Jul 2026 15:22:09 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-4976bd6da4asm7669405e9.1.2026.07.28.15.22.09 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Tue, 28 Jul 2026 15:22:09 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][scarthgap 10/19] python3-setuptools: Fix CVE-2026-59890 Date: Wed, 29 Jul 2026 00:21:45 +0200 Message-ID: <0c89d54002ed0411ea34a926ccb80c4b6e4d858c.1785277157.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Tue, 28 Jul 2026 22:22:16 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/242213 From: Darsh Kelaiya This patch applies the upstream fix as referenced in [2], using the commit shown in [1]. [1] https://github.com/pypa/setuptools/commit/dd9f436a36486b4cb8a4c70a2321548b0be09b8f [2] https://nvd.nist.gov/vuln/detail/CVE-2026-59890 Signed-off-by: Darsh Kelaiya Signed-off-by: Yoann Congal --- .../python3-setuptools/CVE-2026-59890.patch | 194 ++++++++++++++++++ .../python/python3-setuptools_69.1.1.bb | 1 + 2 files changed, 195 insertions(+) create mode 100644 meta/recipes-devtools/python/python3-setuptools/CVE-2026-59890.patch diff --git a/meta/recipes-devtools/python/python3-setuptools/CVE-2026-59890.patch b/meta/recipes-devtools/python/python3-setuptools/CVE-2026-59890.patch new file mode 100644 index 00000000000..69f9bcf0d60 --- /dev/null +++ b/meta/recipes-devtools/python/python3-setuptools/CVE-2026-59890.patch @@ -0,0 +1,194 @@ +From d54dff79a9568c25551092711c7ebc28422006a4 Mon Sep 17 00:00:00 2001 +From: "Jason R. Coombs" +Date: Sat, 27 Jun 2026 10:46:34 -0400 +Subject: [PATCH] Normalize Unicode form when matching MANIFEST.in patterns + +FileList matched MANIFEST.in patterns against on-disk names byte-for-byte +with no Unicode normalization. On macOS APFS/HFS+, a file stored NFD and a +pattern authored NFC denote the same file but differ byte-for-byte, so an +exclude/global-exclude/recursive-exclude/prune rule could silently fail to +drop a non-ASCII-named file, publishing it in the sdist despite the rule. + +Normalize both the pattern and the candidate path to NFC before matching, +via a new unicode_utils.normalize() helper and a _NormalizedMatcher wrapper +around the compiled pattern in translate_pattern. + +Fixes GHSA-h35f-9h28-mq5c. + +CVE: CVE-2026-59890 +Upstream-Status: Backport [https://github.com/pypa/setuptools/commit/dd9f436a36486b4cb8a4c70a2321548b0be09b8f] + +Co-Authored-By: Claude Opus 4.8 +(cherry picked from commit dd9f436a36486b4cb8a4c70a2321548b0be09b8f) +Signed-off-by: Darsh Kelaiya +--- + newsfragments/+ghsa-h35f-9h28-mq5c.bugfix.rst | 7 +++ + setuptools/command/egg_info.py | 28 +++++++++++- + setuptools/tests/test_manifest.py | 45 +++++++++++++++++++ + setuptools/unicode_utils.py | 14 ++++++ + 4 files changed, 93 insertions(+), 1 deletion(-) + create mode 100644 newsfragments/+ghsa-h35f-9h28-mq5c.bugfix.rst + +diff --git a/newsfragments/+ghsa-h35f-9h28-mq5c.bugfix.rst b/newsfragments/+ghsa-h35f-9h28-mq5c.bugfix.rst +new file mode 100644 +index 000000000..42d6c4cfe +--- /dev/null ++++ b/newsfragments/+ghsa-h35f-9h28-mq5c.bugfix.rst +@@ -0,0 +1,7 @@ ++``MANIFEST.in`` matching (via ``FileList``) is now insensitive to Unicode ++normalization form. A pattern authored in one form (e.g. NFC, as typically ++saved by editors) now matches a file whose name is stored on disk in another ++(e.g. NFD, as produced by macOS APFS/HFS+). Previously an ``exclude``, ++``global-exclude``, ``recursive-exclude``, or ``prune`` rule could silently ++fail to drop a non-ASCII-named file from the source distribution, publishing ++it despite the exclusion -- see GHSA-h35f-9h28-mq5c. +diff --git a/setuptools/command/egg_info.py b/setuptools/command/egg_info.py +index 62d2feea9..e858708ee 100644 +--- a/setuptools/command/egg_info.py ++++ b/setuptools/command/egg_info.py +@@ -34,6 +34,27 @@ from ..warnings import SetuptoolsDeprecationWarning + PY_MAJOR = '{}.{}'.format(*sys.version_info) + + ++class _NormalizedMatcher: ++ """ ++ Wrap a compiled pattern so that matching is insensitive to Unicode ++ normalization form. ++ ++ File names walked from disk (NFD on macOS APFS/HFS+) and patterns from ++ ``MANIFEST.in`` (typically NFC) can denote the same file while differing ++ byte-for-byte. Normalizing both sides before matching keeps an exclusion ++ (or inclusion) from silently failing. See GHSA-h35f-9h28-mq5c. ++ """ ++ ++ def __init__(self, pattern: re.Pattern) -> None: ++ self._pattern = pattern ++ ++ def match(self, path): ++ return self._pattern.match(unicode_utils.normalize(path)) ++ ++ def search(self, path): ++ return self._pattern.search(unicode_utils.normalize(path)) ++ ++ + def translate_pattern(glob): # noqa: C901 # is too complex (14) # FIXME + """ + Translate a file path glob like '*.txt' in to a regular expression. +@@ -43,6 +64,11 @@ def translate_pattern(glob): # noqa: C901 # is too complex (14) # FIXME + """ + pat = '' + ++ # Normalize the pattern so it matches paths regardless of the Unicode ++ # normalization form used on disk (GHSA-h35f-9h28-mq5c). Candidate paths ++ # are normalized to the same form by ``_NormalizedMatcher``. ++ glob = unicode_utils.normalize(glob) ++ + # This will split on '/' within [character classes]. This is deliberate. + chunks = glob.split(os.path.sep) + +@@ -114,7 +140,7 @@ def translate_pattern(glob): # noqa: C901 # is too complex (14) # FIXME + pat += sep + + pat += r'\Z' +- return re.compile(pat, flags=re.MULTILINE | re.DOTALL) ++ return _NormalizedMatcher(re.compile(pat, flags=re.MULTILINE | re.DOTALL)) + + + class InfoCommon: +diff --git a/setuptools/tests/test_manifest.py b/setuptools/tests/test_manifest.py +index fbd21b197..1a7441fc3 100644 +--- a/setuptools/tests/test_manifest.py ++++ b/setuptools/tests/test_manifest.py +@@ -10,6 +10,7 @@ import io + import logging + from distutils import log + from distutils.errors import DistutilsTemplateError ++import unicodedata + + from setuptools.command.egg_info import FileList, egg_info, translate_pattern + from setuptools.dist import Distribution +@@ -158,6 +159,21 @@ def test_translated_pattern_mismatch(pattern_mismatch): + assert not translate_pattern(pattern).match(target) + + ++def test_translate_pattern_unicode_normalization(): ++ """ ++ Matching is insensitive to Unicode normalization form: a pattern authored ++ in one form matches a path stored on disk in another (and vice versa), so ++ that an exclusion cannot be bypassed by an NFC/NFD mismatch. ++ ++ Regression test for GHSA-h35f-9h28-mq5c. ++ """ ++ nfc = unicodedata.normalize('NFC', 'café.txt') # 'café.txt' composed ++ nfd = unicodedata.normalize('NFD', 'café.txt') # 'café.txt' decomposed ++ assert nfc != nfd # the two byte forms genuinely differ ++ assert translate_pattern(nfc).match(nfd) ++ assert translate_pattern(nfd).match(nfc) ++ ++ + class TempDirTestCase: + def setup_method(self, method): + self.temp_dir = tempfile.mkdtemp() +@@ -331,6 +347,35 @@ class TestManifestTest(TempDirTestCase): + files = default_files | set([ml('app/a.txt'), ml('app/b.txt'), ml('app/c.rst')]) + assert files == self.get_files() + ++ def test_global_exclude_unicode_normalization(self): ++ """ ++ A ``global-exclude`` authored NFC must drop a file whose on-disk name ++ is NFD: on macOS APFS/HFS+ the two are the same file, and even on ++ case/normalization-exact filesystems the decomposed name can be ++ committed and reach the build. Otherwise the file is published in the ++ sdist despite the exclusion. ++ ++ Regression test for GHSA-h35f-9h28-mq5c. ++ """ ++ nfc_name = unicodedata.normalize('NFC', 'café.txt') ++ nfd_name = unicodedata.normalize('NFD', 'café.txt') ++ assert nfc_name != nfd_name ++ # write the file under its decomposed (NFD) name ... ++ touch(os.path.join(self.temp_dir, 'app', nfd_name)) ++ # ... and exclude it with the composed (NFC) form. ++ self.make_manifest( ++ f""" ++ global-include *.txt ++ global-exclude {nfc_name} ++ """ ++ ) ++ leaked = { ++ f ++ for f in self.get_files() ++ if unicodedata.normalize('NFC', os.path.basename(f)) == nfc_name ++ } ++ assert not leaked, f"excluded file leaked into manifest: {leaked}" ++ + + class TestFileListTest(TempDirTestCase): + """ +diff --git a/setuptools/unicode_utils.py b/setuptools/unicode_utils.py +index d43dcc11f..311d4075a 100644 +--- a/setuptools/unicode_utils.py ++++ b/setuptools/unicode_utils.py +@@ -15,6 +15,20 @@ def decompose(path): + return path + + ++def normalize(text): ++ """ ++ Return *text* in a canonical Unicode form (NFC) so that names which are ++ visually identical but encoded differently compare equal. ++ ++ macOS APFS/HFS+ store file names in decomposed form (NFD), while patterns ++ in ``MANIFEST.in`` are typically authored composed (NFC). The two denote ++ the same file but differ byte-for-byte, so matching them directly lets an ++ exclusion silently fail. Normalizing both the walked path and the pattern ++ to a single form before matching avoids that (GHSA-h35f-9h28-mq5c). ++ """ ++ return unicodedata.normalize('NFC', text) if isinstance(text, str) else text ++ ++ + def filesys_decode(path): + """ + Ensure that the given path is decoded, +-- +2.44.4 diff --git a/meta/recipes-devtools/python/python3-setuptools_69.1.1.bb b/meta/recipes-devtools/python/python3-setuptools_69.1.1.bb index 00f83056dbf..9e7893f225f 100644 --- a/meta/recipes-devtools/python/python3-setuptools_69.1.1.bb +++ b/meta/recipes-devtools/python/python3-setuptools_69.1.1.bb @@ -15,6 +15,7 @@ SRC_URI += " \ file://CVE-2024-6345.patch \ file://CVE-2025-47273-pre1.patch \ file://CVE-2025-47273.patch \ + file://CVE-2026-59890.patch \ " SRC_URI[sha256sum] = "5c0806c7d9af348e6dd3777b4f4dbb42c7ad85b190104837488eab9a7c945cf8" From patchwork Tue Jul 28 22:21:46 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 93755 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id DB3C3C54F56 for ; Tue, 28 Jul 2026 22:22:15 +0000 (UTC) Received: from mail-wm1-f42.google.com (mail-wm1-f42.google.com [209.85.128.42]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.2807.1785277332387301047 for ; Tue, 28 Jul 2026 15:22:12 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=AwiWOqK8; spf=pass (domain: smile.fr, ip: 209.85.128.42, mailfrom: yoann.congal@smile.fr) Received: by mail-wm1-f42.google.com with SMTP id 5b1f17b1804b1-4954dff6536so1986185e9.0 for ; Tue, 28 Jul 2026 15:22:12 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1785277331; x=1785882131; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=l9QDBnORzfaqwAXmNpzJLvX56UhTLgj1utaLfcft/rU=; b=AwiWOqK8uMpnSxBydZyDtiEICqlLeSIn13DIuEKiFAJEyzJt9aTB6VeiTuFVm0nDTx JI103sIwXqt8gkj0YmNCp4nGeiZT4FkdYjqqumWIdX6BTfF5NcuTdkpieKVd54AoKTcL 46slw+ClUIhroTYNKx3NWK+iixnpmcGuOXBzk= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1785277331; x=1785882131; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=l9QDBnORzfaqwAXmNpzJLvX56UhTLgj1utaLfcft/rU=; b=Zczz6vwmgGU4RY9Ua8Ht8TowsUcHkFcONdnuypsDAziNh24Hcg96mPVlb4i8Qk2Lwj KlVuscoQtMpzeHAqcLINCPtlNJXbjl4IMXRASbDX4/pdeqXv4VP8ip6SasgQ77NzVkaW Ou4Kxn0SaMQs/Z7gau1vhfCngWzTA4ksfFRRFXltmL3gVGIf4ciiz/SMGy93t7lPlu5f e+CZXRNR7pi0JjZBAgRMtodd0BOCaX7lmlx9FouvFA3DWcG72xdK1xMQcV+Qqg3/CV03 0pnBp68jxSaY1bh/BXa7XTY9cBdm7qc2duHdBRhhjBR1L++7+7Fvo3lxbHr7vxdRYvlF TGPw== X-Gm-Message-State: AOJu0Yx4s0xoZIPwPnHJUuizuGVw6wuRejeniZq/XjWIH9CYjj3+aVqG 3CnxCA6wuGHAZCmcYkuGWpF6OjsGDOA2iGdQLeSygBS9KPkCsjMHL5YDuJ7/gqK260efjOzqrJb tbyfRmjk= X-Gm-Gg: AR+sD13beVXDuT+kbhXMLBcvIgGoZK9WQQ4xApuLpj8SEEE+C2eUZuSjVNfoEYuXEUs v9TndF7v8JPg5z6mhCmhD6NvP0OU+vJkAjj1vHmCiDm61kV3arqmEnrop70+ogGd9yeNeqUAp2k VTc5fp0ywXjKr0o/H/3Y1rqIcHpZX3xGH90XjN8evw+1d+5qk8d/JODblvYXFuC6yghOauW3y47 j4RFWL6v3yG9ZSTte198oGmbRxBeS+0JcEqLf/+tYuVV1C4DDLPprQdrBVTNieMeBwzx8pPiHYK PHyF6dKrZo/m5gXXWfDbW/B55umtaKJ2Gj2xfsHYFkFdqLJHkkJ36jD+g5DcgMQqtN2e4Hlw5wl FFjVa2V8JYFMPnZdIFwpmIuCJBKX4jEMoYA8C7Rqq5MMK85FebqCwNOLw/CseXACFFuFYpmLzW7 kondE0mqcLNYKKXnhstwHlIzNQexS+D2Klx0NEB/oIQ6rxa/TvV9MhCsR+ktbiC1Jp/+0msstIW E+jHg4t8ZZsMOqfPHDhAT8b55dA6CtrBsSpw1d4QTiMk+7mbtnYB9tBHeEP0Xz9GT/+NfvB5nU= X-Received: by 2002:a05:600c:8b55:b0:496:c977:3b6d with SMTP id 5b1f17b1804b1-496c9775067mr30949675e9.12.1785277330598; Tue, 28 Jul 2026 15:22:10 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-4976bd6da4asm7669405e9.1.2026.07.28.15.22.09 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Tue, 28 Jul 2026 15:22:09 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][scarthgap 11/19] vim: Security Fix for CVE-2026-28422 Date: Wed, 29 Jul 2026 00:21:46 +0200 Message-ID: <5568c80413e04ffe9a495b28fa1d067bd8cc3209.1785277157.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Tue, 28 Jul 2026 22:22:15 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/242214 From: Siddharth Doshi Picking patch as per [1], and same patch is mentioned in [2] References: [1] https://nvd.nist.gov/vuln/detail/CVE-2026-28422 [2] https://security-tracker.debian.org/tracker/CVE-2026-28422 Signed-off-by: Siddharth Doshi Signed-off-by: Yoann Congal --- .../vim/files/CVE-2026-28422.patch | 44 +++++++++++++++++++ meta/recipes-support/vim/vim.inc | 1 + 2 files changed, 45 insertions(+) create mode 100644 meta/recipes-support/vim/files/CVE-2026-28422.patch diff --git a/meta/recipes-support/vim/files/CVE-2026-28422.patch b/meta/recipes-support/vim/files/CVE-2026-28422.patch new file mode 100644 index 00000000000..89f219ccf60 --- /dev/null +++ b/meta/recipes-support/vim/files/CVE-2026-28422.patch @@ -0,0 +1,44 @@ +From fcf19885004325f5a52db6bd6893cb5b387799d3 Mon Sep 17 00:00:00 2001 +From: Christian Brabandt +Date: Tue, 24 Feb 2026 20:29:20 +0000 +Subject: [PATCH 01/17] patch 9.2.0078: [security]: stack-buffer-overflow in + build_stl_str_hl() + +Problem: A stack-buffer-overflow occurs when rendering a statusline + with a multi-byte fill character on a very wide terminal. + The size check in build_stl_str_hl() uses the cell width + rather than the byte length, allowing the subsequent fill + loop to write beyond the 4096-byte MAXPATHL buffer + (ehdgks0627, un3xploitable). +Solution: Update the size check to account for the byte length of + the fill character (using MB_CHAR2LEN). + +Github Advisory: +https://github.com/vim/vim/security/advisories/GHSA-gmqx-prf2-8mwf + +Signed-off-by: Christian Brabandt + +Upstream-Status: Backport [https://github.com/vim/vim/commit/4e5b9e31cb7484ad156fba995fdce3c9b075b5fd] +CVE: CVE-2026-28422 +Signed-off-by: Siddharth Doshi +--- + src/buffer.c | 3 ++- + 1 file changed, 2 insertions(+), 1 deletion(-) + +diff --git a/src/buffer.c b/src/buffer.c +index 0feafc590d..363dd0e04a 100644 +--- a/src/buffer.c ++++ b/src/buffer.c +@@ -5293,7 +5293,8 @@ build_stl_str_hl( + } + width = maxwidth; + } +- else if (width < maxwidth && outputlen + maxwidth - width + 1 < outlen) ++ else if (width < maxwidth && ++ outputlen + (maxwidth - width) * MB_CHAR2LEN(fillchar) + 1 < outlen) + { + // Find how many separators there are, which we will use when + // figuring out how many groups there are. +-- +2.44.4 + diff --git a/meta/recipes-support/vim/vim.inc b/meta/recipes-support/vim/vim.inc index d69a337b4e8..485eedb0615 100644 --- a/meta/recipes-support/vim/vim.inc +++ b/meta/recipes-support/vim/vim.inc @@ -36,6 +36,7 @@ SRC_URI = "git://github.com/vim/vim.git;branch=master;protocol=https \ file://CVE-2026-52858.patch \ file://CVE-2026-52859.patch \ file://CVE-2026-52860.patch \ + file://CVE-2026-28422.patch \ " PV .= ".1683" From patchwork Tue Jul 28 22:21:47 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 8bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 93757 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id D1842C54F51 for ; Tue, 28 Jul 2026 22:22:15 +0000 (UTC) Received: from mail-wm1-f44.google.com (mail-wm1-f44.google.com [209.85.128.44]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.2703.1785277332914562446 for ; Tue, 28 Jul 2026 15:22:13 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=TOxwMGo/; spf=pass (domain: smile.fr, ip: 209.85.128.44, mailfrom: yoann.congal@smile.fr) Received: by mail-wm1-f44.google.com with SMTP id 5b1f17b1804b1-49554ebb87dso2483385e9.3 for ; Tue, 28 Jul 2026 15:22:12 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1785277331; x=1785882131; darn=lists.openembedded.org; h=content-transfer-encoding:content-type:mime-version:references :in-reply-to:message-id:date:subject:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=TYg32YGImZscpQIf8KMycN99YW4sAFn0CT+mGPG/jBw=; b=TOxwMGo/dskpVNUkAyILf1kLlizhfZFbWZXR2ZZFDzDfN5OETCw0DYLK2eImeHi+Y0 e3pov1zueMdM8YhbNLYmIjf2FfuJ0WwZx8+E74wKsVo6ir0e1Oo/t2MUlloqIKyoNG8n fqfjAhRGFskr7kqdZ5QqhLln7T/6NYHTBRYhA= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1785277331; x=1785882131; h=content-transfer-encoding:content-type:mime-version:references :in-reply-to:message-id:date:subject:to:from:x-gm-gg :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to :content-type; bh=TYg32YGImZscpQIf8KMycN99YW4sAFn0CT+mGPG/jBw=; b=SAaG1j2xUImuk2rYN5yuvRaxr/qj1QEWYtFQLZDAbZ04r9tPft8xkDkr/X1DTsZI9L AsFwt7LnB3fIeY1YFgW34k8LKRQDQbZ/8kdOE+evPTIHj9SU67Pq3PDOa71MlNMAYkhS e0rr6kJGIOZczKrTvgwojcjC3uQ76RAoiwSPAbdLHrhkbrM3nTjS9uGv6tccNgpF7sFv LWe3qveuGPj7cUVfnhZKwEVPulWEJoaI5+8heQxmLr9DBES3cbAWtIzOeuNHQGyTZwej tclebQFqwEFJQSK2wChVxrzWukt23P5BZcV9NJ8iOgYKjGb0tICOonJwsm2acFspRMYo L4Yw== X-Gm-Message-State: AOJu0Yy3rxx6Z0YZdZSylw2O6qCe9Y8cPU4pLyWRzCSeEvjwcZpFYWGW O2xfnHOahkrjdHJF8rcc57mvfhx6lmsNAgDYZTckQ4oJtCM2dqLhx8xgX+7/M3OpeOHp9dF9bbU 7w/WoXLU= X-Gm-Gg: AR+sD12PlceKYoWKjvXsISlXHq3GvkIC6cTzsZmZs0fZ/retesN14N955tBEdkUWWyv smysYOZieiiYl105aG3VKBCz9HKQnZbueRQ0AOb6QEfzQ1H1uF9khYs9s6+CdbIntXqNLqfwpwl cQ+k7UJ//6kV9Yl2nzXcUfPnG/w25MA/ulvD2i5s4vetUlx9aYlrvbUJ2cF8VsrQdDl1rSdWBHy rZdJwXn3cX43bBljXo/kr56mqzCbkCIc7Slke8fIMdH6N8tgAMPB24kmNYnDu1INjzupG5LyRf0 h/36rotunPo44BHiJuO7OMU8tR4toyfmW6EJ3BHNv7lghmi/iqougv+6ezn0Nro1/FVgawr1LCF jZBtcvNRSiOkdpPNR1msJRjzHOsLk8j0EzvU66QOTXQn/iv+gbPUBb14TtQVejQ8+2bkxuzLUqH TF4VeJb3dVnVfo2T51CEWcDsmyhbn/kU4IaSft9kah4p47YuSMrTTosWk9XqMrrMPW0l5Ss25NZ 7Kxc8oJIDLTueF1Ggr0fOF/ZpezL4jbjXaibZu+IKanlkyaSFoO3dDhx06B41o8 X-Received: by 2002:a05:600c:1388:b0:496:c249:ddb7 with SMTP id 5b1f17b1804b1-496c653a69cmr44111875e9.6.1785277331128; Tue, 28 Jul 2026 15:22:11 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-4976bd6da4asm7669405e9.1.2026.07.28.15.22.10 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Tue, 28 Jul 2026 15:22:10 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][scarthgap 12/19] vim: Security Fix for CVE-2026-42307 Date: Wed, 29 Jul 2026 00:21:47 +0200 Message-ID: X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Tue, 28 Jul 2026 22:22:15 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/242215 From: Siddharth Doshi Picking patch as per [1], and same patch is mentioned in [2] References: [1] https://nvd.nist.gov/vuln/detail/CVE-2026-42307 [2] https://security-tracker.debian.org/tracker/CVE-2026-42307 Signed-off-by: Siddharth Doshi Signed-off-by: Yoann Congal --- .../vim/files/CVE-2026-42307.patch | 121 ++++++++++++++++++ meta/recipes-support/vim/vim.inc | 1 + 2 files changed, 122 insertions(+) create mode 100644 meta/recipes-support/vim/files/CVE-2026-42307.patch diff --git a/meta/recipes-support/vim/files/CVE-2026-42307.patch b/meta/recipes-support/vim/files/CVE-2026-42307.patch new file mode 100644 index 00000000000..03acd436a05 --- /dev/null +++ b/meta/recipes-support/vim/files/CVE-2026-42307.patch @@ -0,0 +1,121 @@ +From 936634660e3836e1a495965b48a0dc913e9d0deb Mon Sep 17 00:00:00 2001 +From: Christian Brabandt +Date: Tue, 21 Apr 2026 19:03:02 +0000 +Subject: [PATCH 02/17] patch 9.2.0383: [security]: runtime(netrw): + shell-injection via sftp: and file: URLs + +Problem: runtime(netrw): shell-injection via sftp: and file: URLs + (Joshua Rogers) +Solution: Escape temporary file names, harden filename suffix regex, + drop unused g:netrw_tmpfile_escape variable + +Supported by AI + +Signed-off-by: Christian Brabandt + +Upstream-Status: Backport [https://github.com/vim/vim/commit/405e2fb6d54d5653523809e2853d99d1c000a5fc] +CVE: CVE-2026-42307 +Signed-off-by: Siddharth Doshi +--- + runtime/doc/pi_netrw.txt | 4 ---- + runtime/doc/tags | 1 - + runtime/pack/dist/opt/netrw/autoload/netrw.vim | 16 +++++++++------- + runtime/pack/dist/opt/netrw/doc/netrw.txt | 4 ---- + 4 files changed, 9 insertions(+), 16 deletions(-) + +diff --git a/runtime/doc/pi_netrw.txt b/runtime/doc/pi_netrw.txt +index a86cac36ba..2d98a8407b 100644 +--- a/runtime/doc/pi_netrw.txt ++++ b/runtime/doc/pi_netrw.txt +@@ -2854,10 +2854,6 @@ your browsing preferences. (see also: |netrw-settings|) + such as listing, file removal, etc. + default: ssh + +- *g:netrw_tmpfile_escape* =' &;' +- escape() is applied to all temporary files +- to escape these characters. +- + *g:netrw_timefmt* specify format string to vim's strftime(). + The default, "%c", is "the preferred date + and time representation for the current +diff --git a/runtime/doc/tags b/runtime/doc/tags +index 300dfd18a6..7ce3b63075 100644 +--- a/runtime/doc/tags ++++ b/runtime/doc/tags +@@ -7863,7 +7863,6 @@ g:netrw_ssh_browse_reject pi_netrw.txt /*g:netrw_ssh_browse_reject* + g:netrw_ssh_cmd pi_netrw.txt /*g:netrw_ssh_cmd* + g:netrw_sshport pi_netrw.txt /*g:netrw_sshport* + g:netrw_timefmt pi_netrw.txt /*g:netrw_timefmt* +-g:netrw_tmpfile_escape pi_netrw.txt /*g:netrw_tmpfile_escape* + g:netrw_uid pi_netrw.txt /*g:netrw_uid* + g:netrw_use_noswf pi_netrw.txt /*g:netrw_use_noswf* + g:netrw_use_nt_rcp pi_netrw.txt /*g:netrw_use_nt_rcp* +diff --git a/runtime/pack/dist/opt/netrw/autoload/netrw.vim b/runtime/pack/dist/opt/netrw/autoload/netrw.vim +index 1c98104d00..805474616d 100644 +--- a/runtime/pack/dist/opt/netrw/autoload/netrw.vim ++++ b/runtime/pack/dist/opt/netrw/autoload/netrw.vim +@@ -378,7 +378,6 @@ else + call s:NetrwInit("g:netrw_glob_escape",'*[]?`{~$\') + endif + call s:NetrwInit("g:netrw_menu_escape",'.&? \') +-call s:NetrwInit("g:netrw_tmpfile_escape",' &;') + call s:NetrwInit("s:netrw_map_escape","<|\n\r\\\\"") + if has("gui_running") && (&enc == 'utf-8' || &enc == 'utf-16' || &enc == 'ucs-4') + let s:treedepthstring= "│ " +@@ -1799,14 +1798,14 @@ function netrw#NetRead(mode,...) + "......................................... + " NetRead: (sftp) NetRead Method #9 {{{3 + elseif b:netrw_method == 9 +- call netrw#os#Execute(s:netrw_silentxfer."!".g:netrw_sftp_cmd." ".netrw#os#Escape(g:netrw_machine.":".b:netrw_fname,1)." ".tmpfile) ++ call netrw#os#Execute(s:netrw_silentxfer."!".g:netrw_sftp_cmd." ".netrw#os#Escape(g:netrw_machine.":".b:netrw_fname,1)." ".netrw#os#Escape(tmpfile,1)) + let result = s:NetrwGetFile(readcmd, tmpfile, b:netrw_method) + let b:netrw_lastfile = choice + + "......................................... + " NetRead: (file) NetRead Method #10 {{{3 + elseif b:netrw_method == 10 && exists("g:netrw_file_cmd") +- call netrw#os#Execute(s:netrw_silentxfer."!".g:netrw_file_cmd." ".netrw#os#Escape(b:netrw_fname,1)." ".tmpfile) ++ call netrw#os#Execute(s:netrw_silentxfer."!".g:netrw_file_cmd." ".netrw#os#Escape(b:netrw_fname,1)." ".netrw#os#Escape(tmpfile,1)) + let result = s:NetrwGetFile(readcmd, tmpfile, b:netrw_method) + let b:netrw_lastfile = choice + +@@ -8927,14 +8926,17 @@ function s:GetTempfile(fname) + endif + + " use fname's suffix for the temporary file ++ " Restrict the suffix to word characters so shell metacharacters in a ++ " remote filename (e.g. sftp://host/foo.txt;id) cannot ride along into ++ " the tempfile name and out into a downstream shell command. + if a:fname != "" +- if a:fname =~ '\.[^./]\+$' ++ if a:fname =~ '\.\w\+$' + if a:fname =~ '\.tar\.gz$' || a:fname =~ '\.tar\.bz2$' || a:fname =~ '\.tar\.xz$' +- let suffix = ".tar".substitute(a:fname,'^.*\(\.[^./]\+\)$','\1','e') ++ let suffix = ".tar".substitute(a:fname,'^.*\(\.\w\+\)$','\1','e') + elseif a:fname =~ '.txz$' +- let suffix = ".txz".substitute(a:fname,'^.*\(\.[^./]\+\)$','\1','e') ++ let suffix = ".txz".substitute(a:fname,'^.*\(\.\w\+\)$','\1','e') + else +- let suffix = substitute(a:fname,'^.*\(\.[^./]\+\)$','\1','e') ++ let suffix = substitute(a:fname,'^.*\(\.\w\+\)$','\1','e') + endif + let tmpfile= substitute(tmpfile,'\.tmp$','','e') + let tmpfile .= suffix +diff --git a/runtime/pack/dist/opt/netrw/doc/netrw.txt b/runtime/pack/dist/opt/netrw/doc/netrw.txt +index 01a5bda597..144bab5fb3 100644 +--- a/runtime/pack/dist/opt/netrw/doc/netrw.txt ++++ b/runtime/pack/dist/opt/netrw/doc/netrw.txt +@@ -2854,10 +2854,6 @@ your browsing preferences. (see also: |netrw-settings|) + such as listing, file removal, etc. + default: ssh + +- *g:netrw_tmpfile_escape* =' &;' +- escape() is applied to all temporary files +- to escape these characters. +- + *g:netrw_timefmt* specify format string to vim's strftime(). + The default, "%c", is "the preferred date + and time representation for the current +-- +2.44.4 + diff --git a/meta/recipes-support/vim/vim.inc b/meta/recipes-support/vim/vim.inc index 485eedb0615..7a865f122ee 100644 --- a/meta/recipes-support/vim/vim.inc +++ b/meta/recipes-support/vim/vim.inc @@ -37,6 +37,7 @@ SRC_URI = "git://github.com/vim/vim.git;branch=master;protocol=https \ file://CVE-2026-52859.patch \ file://CVE-2026-52860.patch \ file://CVE-2026-28422.patch \ + file://CVE-2026-42307.patch \ " PV .= ".1683" From patchwork Tue Jul 28 22:21:48 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 93754 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id C118AC54F52 for ; Tue, 28 Jul 2026 22:22:15 +0000 (UTC) Received: from mail-wm1-f44.google.com (mail-wm1-f44.google.com [209.85.128.44]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.2704.1785277333468982522 for ; Tue, 28 Jul 2026 15:22:13 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=fHe2y44k; spf=pass (domain: smile.fr, ip: 209.85.128.44, mailfrom: yoann.congal@smile.fr) Received: by mail-wm1-f44.google.com with SMTP id 5b1f17b1804b1-4954d383e64so1997995e9.1 for ; Tue, 28 Jul 2026 15:22:13 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1785277332; x=1785882132; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=M7fbWxes3hFz9W759htSbTtYE/1tCHzdzaOl9kV3S88=; b=fHe2y44krPFLqXMBv+RqRuJN5PmGrlucDhDnDWToW2H74cFbFZoCfnGBoUXKYS9JUD J8uCjVAj5Y/NGtW07c2zLGY+DQSM5oHYqW7Nzv3saDcfOX9EUSud3Wk1Kn7waW6Ky+yZ I6sVYbWpK6JHZIYOHLbN4tKLlGnIp7VyuCk1k= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1785277332; x=1785882132; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=M7fbWxes3hFz9W759htSbTtYE/1tCHzdzaOl9kV3S88=; b=U577+r3EpMKTlp1TkcHzqRQsHqxSTP/KIdCZzqABehTzApZJm68B/YbC6PWK2s09Er +KlmzsLR3DndztXE9zAqOBvZu/0QrLgd45nGKS3IECCZdo/IKd05gnq9ux0H3WqpGFSM wV8OJOKUMFgFvo8yhLi7erfAOpVE5jUp9lHkk1c8J8dm85aiO7gpHC7XZU8NaZvc0QOY 6KRpByh8MweFdeCv32MPC5L5yQw3C/wjhKDoMsFaEwHdubh8qiszLWOHDviwGEw0pJVf yY2t1pLpOr5Tphj//mHNahKAmfzlEW10YGq6b8VEZTBENLzoUeMSSVwDWxoGxnHcMl4u DJfw== X-Gm-Message-State: AOJu0YyU5cF7qcCgHdUIIU77Nn1AHz6mAPbw9kRTouZ491lZut0mFOVx DZkvxylJh1gQ0kP9Sv/Z+se2W9p9JMS6mKF7uCn9oHvka7N7ZEjTxsz3kZGjFYlSrz9cGfDXivF yjSdUVls= X-Gm-Gg: AR+sD10iSIPduyCx7rK6c14+ycPdKSVN02ps82gG4DfInnHxUC63FnUeSNMA58vLeye QxUtADxI3KZLB/BIEtPHq5hyJ7tIv0BH7zqfMAj4doZhDAggqiQ9xtGIRClfBjXoTcclTiHePi7 MErIrtdRRxMm+t/SniLAxyqjrHYwMBZiZ7Vkjxyj+INqtYniLIj/Hk8g0lXNpR2eqKMPhA/i3eM YyjC80tJr4u/8MLBtN0UQ2dl5BIWnGam34jr7VWq9m14FQIHqjcYHVCFHLFOHQ3LJ59aJ5LaqJf HUesj3tVupRJwJWjEcHQ1dDP5sCLkW+X6qcd+JcmRdz5P5E9uVULceVHITFyL0abr8wS1dPkJLL MOMTkMmY/gH0wuQxUBT5Ouoe1UQkNzsCrPce3TuMdQqzuIn6t2f7N7ItVOKG55Dh7hk7+gxcaLj 5AiLF+GXj6fb2DFD32SvxB76M2xOWDe+lisHirJEWqRujT+yy71gyCvd7SS/tB1TZHkGBuDmh43 gTKmewddk0QRHju8S96hW8I4pu/h5bvromAi/d+praapKutbvA+KHpcEpB5DaPm X-Received: by 2002:a05:600c:4fd2:b0:493:e79e:da6b with SMTP id 5b1f17b1804b1-496c6590660mr50953625e9.21.1785277331737; Tue, 28 Jul 2026 15:22:11 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-4976bd6da4asm7669405e9.1.2026.07.28.15.22.11 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Tue, 28 Jul 2026 15:22:11 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][scarthgap 13/19] vim: Security Fix for CVE-2026-43961 Date: Wed, 29 Jul 2026 00:21:48 +0200 Message-ID: <333839503766bdb995092b09546922a3f4ec968e.1785277157.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Tue, 28 Jul 2026 22:22:15 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/242216 From: Siddharth Doshi Picking patch as per [1], and same patch is mentioned in [2] References: [1] https://github.com/vim/vim/commit/8af0f098c3a42a28661d0295364e [2] https://security-tracker.debian.org/tracker/CVE-2026-43961 Signed-off-by: Siddharth Doshi Signed-off-by: Yoann Congal --- .../vim/files/CVE-2026-43961.patch | 65 +++++++++++++++++++ meta/recipes-support/vim/vim.inc | 1 + 2 files changed, 66 insertions(+) create mode 100644 meta/recipes-support/vim/files/CVE-2026-43961.patch diff --git a/meta/recipes-support/vim/files/CVE-2026-43961.patch b/meta/recipes-support/vim/files/CVE-2026-43961.patch new file mode 100644 index 00000000000..f9e0fc0df4d --- /dev/null +++ b/meta/recipes-support/vim/files/CVE-2026-43961.patch @@ -0,0 +1,65 @@ +From f38c7cb2fcc9d5839386ea4722463ea921f0bbce Mon Sep 17 00:00:00 2001 +From: Christian Brabandt +Date: Thu, 14 May 2026 16:43:15 +0000 +Subject: [PATCH 03/17] patch 9.2.0480: [security]: runtime(netrw): code + injection via mf command + +Problem: [security]: runtime(netrw): code injection via mf command + (Christopher Lusk, Zdenek Dohnal) +Solution: Do not use string concatenation inside the filter() commands + (Zdenek Dohnal) + +Github Security Advisory: +https://github.com/vim/vim/security/advisories/GHSA-66hr-7p6x-x5j3 + +Signed-off-by: Christian Brabandt + +Upstream-Status: Backport [https://github.com/vim/vim/commit/8af0f098c3a42a28661d0295364e] +CVE: CVE-2026-43961 +Signed-off-by: Siddharth Doshi +--- + runtime/pack/dist/opt/netrw/autoload/netrw.vim | 7 +++---- + 1 file changed, 3 insertions(+), 4 deletions(-) + +diff --git a/runtime/pack/dist/opt/netrw/autoload/netrw.vim b/runtime/pack/dist/opt/netrw/autoload/netrw.vim +index 805474616d..e484de5c93 100644 +--- a/runtime/pack/dist/opt/netrw/autoload/netrw.vim ++++ b/runtime/pack/dist/opt/netrw/autoload/netrw.vim +@@ -5155,7 +5155,7 @@ function s:NetrwMarkFile(islocal,fname) + + else + " remove filename from buffer's markfilelist +- call filter(s:netrwmarkfilelist_{curbufnr},'v:val != a:fname') ++ call filter(s:netrwmarkfilelist_{curbufnr}, {_, v -> v !=# a:fname}) + if s:netrwmarkfilelist_{curbufnr} == [] + " local markfilelist is empty; remove it entirely + call s:NetrwUnmarkList(curbufnr,curdir) +@@ -5176,7 +5176,6 @@ function s:NetrwMarkFile(islocal,fname) + + else + " initialize new markfilelist +- + let s:netrwmarkfilelist_{curbufnr}= [] + call add(s:netrwmarkfilelist_{curbufnr},substitute(a:fname,'[|@]$','','')) + +@@ -5196,7 +5195,7 @@ function s:NetrwMarkFile(islocal,fname) + call add(s:netrwmarkfilelist,netrw#fs#ComposePath(b:netrw_curdir,a:fname)) + else + " remove new filename from global markfilelist +- call filter(s:netrwmarkfilelist,'v:val != "'.dname.'"') ++ call filter(s:netrwmarkfilelist, {_, v -> v !=# dname}) + if s:netrwmarkfilelist == [] + unlet s:netrwmarkfilelist + endif +@@ -7202,7 +7201,7 @@ function s:NetrwTreeDisplay(dir,depth) + " hide given patterns + let listhide= split(g:netrw_list_hide,',') + for pat in listhide +- call filter(w:netrw_treedict[dir],'v:val !~ "'.escape(pat,'\\').'"') ++ call filter(w:netrw_treedict[dir], {_, v -> v !~# pat}) + endfor + + elseif g:netrw_hide == 2 +-- +2.44.4 + diff --git a/meta/recipes-support/vim/vim.inc b/meta/recipes-support/vim/vim.inc index 7a865f122ee..2175c5f9a85 100644 --- a/meta/recipes-support/vim/vim.inc +++ b/meta/recipes-support/vim/vim.inc @@ -38,6 +38,7 @@ SRC_URI = "git://github.com/vim/vim.git;branch=master;protocol=https \ file://CVE-2026-52860.patch \ file://CVE-2026-28422.patch \ file://CVE-2026-42307.patch \ + file://CVE-2026-43961.patch \ " PV .= ".1683" From patchwork Tue Jul 28 22:21:49 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 93761 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 57930C54F5E for ; Tue, 28 Jul 2026 22:22:16 +0000 (UTC) Received: from mail-wm1-f50.google.com (mail-wm1-f50.google.com [209.85.128.50]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.2705.1785277334069454655 for ; Tue, 28 Jul 2026 15:22:14 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=UtjyhrJg; spf=pass (domain: smile.fr, ip: 209.85.128.50, mailfrom: yoann.congal@smile.fr) Received: by mail-wm1-f50.google.com with SMTP id 5b1f17b1804b1-4953de5be0aso2310155e9.0 for ; Tue, 28 Jul 2026 15:22:13 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1785277332; x=1785882132; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=sAhhuhBFGRONMIMxGwIdzNjmUhyogHsvHcBG1Zm+Gaw=; b=UtjyhrJgpY2THR+BGetMeNsRUVcn2+Da9u7rIBlvn4dvp5mQbxb3Kb3C+B3c0ohQLg qE71vb9DyUhffoSu6pZPMTkUG4FTwMBpBjcC3WmwZ1Mhcrjod+dL6xmghvd1DMh9ZZig mfFLGotSSIR7xYsxb4czCqFSOeQXDvWTLkXfs= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1785277332; x=1785882132; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=sAhhuhBFGRONMIMxGwIdzNjmUhyogHsvHcBG1Zm+Gaw=; b=aFhL6ZxknUDYfj2xQBi/TaM8bRdUJHzqRVVqaGiujedQk09kZBnDLYZFJiPG7NnTOW z3v+OG0swd7vo3QoPi1UVMoRVXs0VhfHYWSWL3c3JImfC5y0PP9Mi7yN+k8sZTlc5RrY LYk80nNw3wDEYeXa9UlLgKs4wkvWg30TUDta2L2XE8KO0pQTWm4TQoXU/k0kPMFM9J1H 7b1N4Ma3TFfoUtrGR3vVrZMXG16REBdY1hhw9vVDKtGwqU+GHRx3g2XxcY30bjdMSQov grNhQwG/qjuTQ8AB2RT9YSRYZPHc9VeKYwu7WkxFqfbsmdE5rSBoyUaqnxkUCQ5iMBa6 b4ug== X-Gm-Message-State: AOJu0YyjO60Vz/zdupW+RAtNV+E5QDX0Knd1RrBoJ94tqLKRfwUXgGIL 1WsnwnjV1SunO0Jv0buOcImQL5xNvW9gyfI2TAsHFsSnkwb5ZXyEqaxCYWA729PKcDakHEu+AyI xuVuchBg= X-Gm-Gg: AR+sD12FvLjDqV++yE21KpSuWkdbQalcvvZqsHMeg0Wb1CHmGchHHipQePtZR25hIm0 Tk/vJm7PBY4OOjyXKaHE2lPb4qKA3S/++wBh8I1NXMfgvXLW/g9WQbX1OZKGlTXyQg1iFjHy6DR gnbn+6UpevGuwdV48CMrhBmdqKjzndr+HUDYhfJuWOjCMfheOsk4G8xpVHXZWF2Ho+RxZzzWoQI wLWEVm4Pb+GNge3A6O4GIE22XNAtxTdDSe098+OyV9VTYMFp6Ojljc7vA1fQ4ZEeo5sl9FeyzmT 6fGcy3AkaX/yOi8Cmc8t4TyW8DJI4VHCN9HdJZYw1NlcP3J77ugx/4NRbj8OQENx20soAzrd9Uo 82EsH8BK5luupyIZQX7WVAYiFrNol6XD32UoLDxQJdXWfEXk1DbEUoKn+hTfFr0OTixr8U8B8Hm qOaEUyjpr83tiVpAdDtzaAKis90FsYCDHeL15bbZdlzZDHkAuSDWywI50Aw31ENxJe3+oaICLOT TRNZsSXBD0Ke8LAFGj7UovIDNnSPmOLNYYm0nGj9RnQUcEtf8aCBd/Gtw8LlvOG X-Received: by 2002:a05:600c:c173:b0:495:3e08:ad19 with SMTP id 5b1f17b1804b1-496c654d9dbmr44181015e9.9.1785277332324; Tue, 28 Jul 2026 15:22:12 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-4976bd6da4asm7669405e9.1.2026.07.28.15.22.11 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Tue, 28 Jul 2026 15:22:11 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][scarthgap 14/19] vim: Security Fix for CVE-2026-47162 Date: Wed, 29 Jul 2026 00:21:49 +0200 Message-ID: <2f2d13412852098c0a9c4d633d9f2f340d34b29b.1785277157.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Tue, 28 Jul 2026 22:22:16 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/242217 From: Siddharth Doshi Picking patch as per [1], and same patch is mentioned in [2] References: [1] https://nvd.nist.gov/vuln/detail/CVE-2026-47162 [2] https://security-tracker.debian.org/tracker/CVE-2026-47162 Signed-off-by: Siddharth Doshi Signed-off-by: Yoann Congal --- .../vim/files/CVE-2026-47162.patch | 39 +++++++++++++++++++ meta/recipes-support/vim/vim.inc | 1 + 2 files changed, 40 insertions(+) create mode 100644 meta/recipes-support/vim/files/CVE-2026-47162.patch diff --git a/meta/recipes-support/vim/files/CVE-2026-47162.patch b/meta/recipes-support/vim/files/CVE-2026-47162.patch new file mode 100644 index 00000000000..33f1ebbfd14 --- /dev/null +++ b/meta/recipes-support/vim/files/CVE-2026-47162.patch @@ -0,0 +1,39 @@ +From d254c3b584e19555f2aecc4886ae7c92c0acc199 Mon Sep 17 00:00:00 2001 +From: Christian Brabandt +Date: Sun, 17 May 2026 18:53:48 +0000 +Subject: [PATCH 04/17] patch 9.2.0495: [security]: runtime(netrw): code + injection via NetrwBookHistSave() + +Problem: [security]: runtime(netrw): code injection via + NetrwBookHistSave() +Solution: Properly quote the directory name using string() function + (Srinivas Piskala Ganesh Babu) + +Github Security Advisory: +https://github.com/vim/vim/security/advisories/GHSA-crm5-rh6j-2c7c + +Signed-off-by: Christian Brabandt + +Upstream-Status: Backport [https://github.com/vim/vim/commit/f08ab2f4d7d2947c8dd6c179ae08ee6146a2694b] +CVE: CVE-2026-47162 +Signed-off-by: Siddharth Doshi +--- + runtime/pack/dist/opt/netrw/autoload/netrw.vim | 2 +- + 1 file changed, 1 insertion(+), 1 deletion(-) + +diff --git a/runtime/pack/dist/opt/netrw/autoload/netrw.vim b/runtime/pack/dist/opt/netrw/autoload/netrw.vim +index e484de5c93..9014ca339b 100644 +--- a/runtime/pack/dist/opt/netrw/autoload/netrw.vim ++++ b/runtime/pack/dist/opt/netrw/autoload/netrw.vim +@@ -2921,7 +2921,7 @@ function s:NetrwBookHistSave() + while ( first || cnt != g:netrw_dirhistcnt ) + let lastline= lastline + 1 + if exists("g:netrw_dirhist_{cnt}") +- call setline(lastline,'let g:netrw_dirhist_'.cnt."='".g:netrw_dirhist_{cnt}."'") ++ call setline(lastline,'let g:netrw_dirhist_'.cnt.'='.string(g:netrw_dirhist_{cnt})) + endif + let first = 0 + let cnt = ( cnt - 1 ) % g:netrw_dirhistmax +-- +2.44.4 + diff --git a/meta/recipes-support/vim/vim.inc b/meta/recipes-support/vim/vim.inc index 2175c5f9a85..3fd0b66bf48 100644 --- a/meta/recipes-support/vim/vim.inc +++ b/meta/recipes-support/vim/vim.inc @@ -39,6 +39,7 @@ SRC_URI = "git://github.com/vim/vim.git;branch=master;protocol=https \ file://CVE-2026-28422.patch \ file://CVE-2026-42307.patch \ file://CVE-2026-43961.patch \ + file://CVE-2026-47162.patch \ " PV .= ".1683" From patchwork Tue Jul 28 22:21:50 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 93753 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 9E0B6C53219 for ; Tue, 28 Jul 2026 22:22:15 +0000 (UTC) Received: from mail-wr1-f54.google.com (mail-wr1-f54.google.com [209.85.221.54]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.2808.1785277334655703757 for ; Tue, 28 Jul 2026 15:22:14 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=0RjxGAEW; spf=pass (domain: smile.fr, ip: 209.85.221.54, mailfrom: yoann.congal@smile.fr) Received: by mail-wr1-f54.google.com with SMTP id ffacd0b85a97d-47f6609c657so188219f8f.2 for ; Tue, 28 Jul 2026 15:22:14 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1785277333; x=1785882133; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=2jD6oYCmCdWorxur2jvs8bkR/neLQzb1cFyadIjlDlM=; b=0RjxGAEWyZHnu91mdST0qyBUKNHhPLG9/IpwcKRpkRSTTQjGscuLRLkwneW/yCqTfw 5VVujMfkQ2jrGF3D9HSy3yX1De+zlLmFaHTGU1NadTRLqtmrMo+PD1HbIDayp+I4QWl+ /I1vUCO78YZg20Xeqv4CLf3vmySyMoOJqd63c= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1785277333; x=1785882133; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=2jD6oYCmCdWorxur2jvs8bkR/neLQzb1cFyadIjlDlM=; b=XMqeC4jVDV+M4p7sT1Tzk3GRoQVNO2WhsFol5zXWGDixqv4t/nZ+ycUjWFQkQLJpVK 5ZKM8lKKDG7ocSAsEj50Ku3U11IUgKLV4mKnGG/OH8jzl9oE0GY5ScXgK1ZfZl5r8/a1 +9GdmdIZ8yoqU6YS/kGkiWHg6X/x2TBYX7xaeMnwhdsffbPnd2fDyz2foSEfd1+pudMD dgVJAQi/YrjJMkesucr84zuB9GZtrKSkdm9VKCRPtsx+EQhT/C/JjqVsde8y3cJ5ogCX zYvjJEOyj2Qgih3NT0XgO8P7eghHSXYXYTH6aBDdYxcRFRxxDDkZcETiAGCcsZ6fP2HG nWaQ== X-Gm-Message-State: AOJu0YwyCH9YdOJ7sauqnJHQpBK0On83TEd6A4mjaVyz2f3NKG2Tb5Ak MtGbhEVMez8U8LXJUHp59dAXLkvfXV+UYq9yfY5oTAoeLIR/tuBb2+y0NUxuj76Oa3xbThEKZfK sJB2Awzc= X-Gm-Gg: AR+sD115KXCc/W9/HZFajRk+9PTaoTVnyvZf7USudiJ7eAr83uWewsfZ9i0E1TIwSZY aZV4faQJ2DVZQtJszO1KhGUVhtZoHmKKHcuB0NiDAqN9h1CLR0PRlk0ad9UoSjvHASjKCdQARlr 1uXOZg1tGckIJeiFfhTs8tk6oTF6oHiQEAy5wjpOqIwkVjxlDzg107nSY8fLhC1nNw3zAngutVs uSX6DTuGMBc7M0RRIqG0/AUq1Pf2sQOnmgahccZmOOV8clD/Eq7bbFEQB/Nc566JhCBcqKUuuUh Ssuyk/UaT2ElClVFi0fQPu2djP+5KuBtPkJPcmlIrXC0ZpJnvR2X1aUNFtk/ls3XOFcAhFsQQoi CWOxMqxoJG6oDKM8eXVZfCtE5poQKAHI3OM96Iqo42ggCrv//+xyIVsb128nBajszbEmmo+tti0 8BlVgjKJgva6Ff/mg6o077Coy1gcP1c0a36f1agx2DlBC8HfE5ZFgcnbXlsCIXyvBnPwbe4YXlc u0b8wkEyxF8wISeQRJSoNJccjgY3Hhu/I8FvNPwHi1JeBDNYjGsGwM8UKsJRIlN X-Received: by 2002:a05:600c:4704:b0:495:5d6d:d4f7 with SMTP id 5b1f17b1804b1-496c658ee8bmr45459875e9.24.1785277332943; Tue, 28 Jul 2026 15:22:12 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-4976bd6da4asm7669405e9.1.2026.07.28.15.22.12 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Tue, 28 Jul 2026 15:22:12 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][scarthgap 15/19] vim: Security Fix for CVE-2026-47167 Date: Wed, 29 Jul 2026 00:21:50 +0200 Message-ID: <4c3c569a7d9e19f7d613d01afd2ab793a4d35453.1785277157.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Tue, 28 Jul 2026 22:22:15 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/242218 From: Siddharth Doshi Picking patch as per [1], and same patch is mentioned in [2] References: [1] https://nvd.nist.gov/vuln/detail/CVE-2026-47167 [2] https://security-tracker.debian.org/tracker/CVE-2026-47167 Signed-off-by: Siddharth Doshi Signed-off-by: Yoann Congal --- .../vim/files/CVE-2026-47167.patch | 39 +++++++++++++++++++ meta/recipes-support/vim/vim.inc | 1 + 2 files changed, 40 insertions(+) create mode 100644 meta/recipes-support/vim/files/CVE-2026-47167.patch diff --git a/meta/recipes-support/vim/files/CVE-2026-47167.patch b/meta/recipes-support/vim/files/CVE-2026-47167.patch new file mode 100644 index 00000000000..f0e493290c2 --- /dev/null +++ b/meta/recipes-support/vim/files/CVE-2026-47167.patch @@ -0,0 +1,39 @@ +From e117fcc6f1c1973602c8e2c6529fba9ee1ce59b4 Mon Sep 17 00:00:00 2001 +From: Christian Brabandt +Date: Sun, 17 May 2026 19:39:24 +0000 +Subject: [PATCH 05/17] patch 9.2.0496: [security]: Code Injection in cucumber + filetype plugin + +Problem: [security]: Code Injection in cucumber filetype plugin + (Christopher Lusk) +Solution: Use rubys Regexp.new() with the untrusted pattern + +Github Security Advisory: +https://github.com/vim/vim/security/advisories/GHSA-4473-94jm-w5x9 + +Signed-off-by: Christian Brabandt + +Upstream-Status: Backport [https://github.com/vim/vim/commit/a65a52d684bc58535ad28a4ae824d22e76399934] +CVE: CVE-2026-47167 +Signed-off-by: Siddharth Doshi +--- + runtime/ftplugin/cucumber.vim | 3 ++- + 1 file changed, 2 insertions(+), 1 deletion(-) + +diff --git a/runtime/ftplugin/cucumber.vim b/runtime/ftplugin/cucumber.vim +index f4848d1c60..3361f1db4a 100644 +--- a/runtime/ftplugin/cucumber.vim ++++ b/runtime/ftplugin/cucumber.vim +@@ -96,7 +96,8 @@ function! s:stepmatch(receiver,target) + catch + endtry + if has("ruby") && pattern !~ '\\\@ X-Patchwork-Id: 93770 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 023DEC54FD1 for ; Tue, 28 Jul 2026 22:22:17 +0000 (UTC) Received: from mail-wm1-f41.google.com (mail-wm1-f41.google.com [209.85.128.41]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.2707.1785277335179755305 for ; Tue, 28 Jul 2026 15:22:15 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=RGMp3NPG; spf=pass (domain: smile.fr, ip: 209.85.128.41, mailfrom: yoann.congal@smile.fr) Received: by mail-wm1-f41.google.com with SMTP id 5b1f17b1804b1-4954aff6088so2856585e9.3 for ; Tue, 28 Jul 2026 15:22:14 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1785277333; x=1785882133; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=mMny7I5hrqIK2DR8XHQTY+qcbx3U6F/iogAnqWFtnGg=; b=RGMp3NPGwc6Cxt1EaTwO3yOlfjFnVUOEQepxCPvNXJCujnGIN5vuNg7rmNp6J6bB05 LuQodyyxtRlOmbYzNCeLSZqmkNhybahGvuzd9rXMZSr3JYYemvrQxCyHrO7mQwerL6jg 5w1R1Najqu2ZhqAaWUD0BoRniAb7ntcv2r/jo= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1785277333; x=1785882133; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=mMny7I5hrqIK2DR8XHQTY+qcbx3U6F/iogAnqWFtnGg=; b=tIGhCLjOF6Ql98XIllpKHSa+97FIHkjI1B8XtUVk2jvECbv2qiGiNIwpss/lIWFT86 lhLUfuJN1ndZdSTvn8zoFIwmKRTABZTvMEo2F6/46nDNlNaxlSGUs3o3qnIpG0EJHUCR E9G6te0bvhhMPLw/CfwStxNUtUXhH1XuDi/UkBN7I6iAg6K5l8yGP2Bli2vqLdIOloDZ 2Wt59hwIkYf4jYWbwiQOmICC7bvgtLUaCcYJeJEcBgu2rY+8yh8i6nJPyVXdo7qCdwgs WxFY1L4An4D8/PqUJX7ayigdP7WLIytFQERhVJWHpCi8g53cd3nn4J5fK/kpF3Ssgkq9 8Kqg== X-Gm-Message-State: AOJu0YyIcfYvAuyVXO9/ObKCJAATVsHbKDqHwT6lN2F1wMAwppD5zLU2 NC0XNaQq+g6ZADdbrkCrSjMHO+YJSGRO14lMex4/BPs5GJzOSpXMjB/+dvmjrRTEiONX4I1/X9C +2Au7dYM= X-Gm-Gg: AR+sD12W4C0RGIOIs5ah8VA0PHGu4nZW0fcFvUZG8LsYqWcFkAotpFG8fd1Tc8sP+S6 3LgG9Siq1XwYzP/7pmqyTGcV/sVhefwDUnijT7q5xnRfaMsflz/q6qwZt+J4d9hRAxTnFHIewIY RnKxMD8MF6zyx5Gvs01pkIIRhbZz4Lw7d9AHt8rDxm0ClDExyy8pEsQFE4BxyIYbhzI9aa2zlZh Il7bDzbQaDOS4MQi1oecyIsVCqS7W7MSJtATnMcdQ9uVG7Ovn5B008lt0yIvWQDcTvGWVWWb/O1 x7agkANIDJcTpf15YUpBpdheH4OrOx+OKFwlftEWdwsgPDY7KcU28K0jxmtvF+sF7fgPZKN6c6v N9JoVjwBQAwqXuR3K1IjA8eBwvRKvaPoknuL9yEgO0txWWlZmNcLL5HUDzOVQl802SpP14VB8zh hhp3pU1w6NB+DlRbiUVk1g/hhvqZd9c6oYcreFqLjt4tjQogGB9J0nZ8w0XFQ15pGPZIsWitdzy MYIIJQNwsy1Tyx22y3Tpi6SedbVAkXO5/MS7xk8KEcJfhosvaAW7Kp9TYlCPbA3 X-Received: by 2002:a05:600c:34d2:b0:495:5e07:649b with SMTP id 5b1f17b1804b1-496c6576533mr45705385e9.24.1785277333372; Tue, 28 Jul 2026 15:22:13 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-4976bd6da4asm7669405e9.1.2026.07.28.15.22.13 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Tue, 28 Jul 2026 15:22:13 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][scarthgap 16/19] sqlite3: fix CVE-2026-11822 and CVE-2026-11824 Date: Wed, 29 Jul 2026 00:21:51 +0200 Message-ID: <3de44d1dd09907f620ed349dba563c489a5cecb9.1785277157.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Tue, 28 Jul 2026 22:22:17 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/242219 From: Deepak Rathore This patch applies the upstream fix [1], which addresses memory corruption vulnerabilities in the SQLite FTS5 full-text search extension. The GitHub mirror commit [1] corresponds to the SQLite Fossil check-in shown in [2]. [1] https://github.com/sqlite/sqlite/commit/e0b995b2a62b78979eb65bb8dadfa912eaa8e62f [2] https://sqlite.org/src/info/061febcf41ca Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-11822 https://nvd.nist.gov/vuln/detail/CVE-2026-11824 Signed-off-by: Deepak Rathore Signed-off-by: Yoann Congal --- .../CVE-2026-11822_CVE-2026-11824.patch | 41 +++++++++++++++++++ meta/recipes-support/sqlite/sqlite3_3.45.3.bb | 1 + 2 files changed, 42 insertions(+) create mode 100644 meta/recipes-support/sqlite/sqlite3/CVE-2026-11822_CVE-2026-11824.patch diff --git a/meta/recipes-support/sqlite/sqlite3/CVE-2026-11822_CVE-2026-11824.patch b/meta/recipes-support/sqlite/sqlite3/CVE-2026-11822_CVE-2026-11824.patch new file mode 100644 index 00000000000..1764d5c6e2c --- /dev/null +++ b/meta/recipes-support/sqlite/sqlite3/CVE-2026-11822_CVE-2026-11824.patch @@ -0,0 +1,41 @@ +From ceece94b0040125a12192f6f23b1ec413871b04c Mon Sep 17 00:00:00 2001 +From: drh <> +Date: Mon, 11 May 2026 12:00:19 +0000 +Subject: [PATCH] Fix potential buffer overwrite that could occur in fts5 when + processing corrupt records. + +FossilOrigin-Name: 061febcf41ca4872a0f407951e1507209daca7895122b909a7806c60b6e200c4 + +CVE: CVE-2026-11822 CVE-2026-11824 +Upstream-Status: Backport [https://github.com/sqlite/sqlite/commit/e0b995b2a62b78979eb65bb8dadfa912eaa8e62f] + +Backport Changes: +- Applied the upstream fts5LeafRead() fix from ext/fts5/fts5_index.c + to sqlite3.c because the Yocto sqlite-autoconf source uses the + amalgamated SQLite layout. +- Omitted ext/fts5/test/fts5corruptA.test because this extracted + recipe source contains the SQLite autoconf/amalgamation layout and + does not carry the upstream Tcl test tree. +- Omitted Git mirror metadata files manifest and manifest.uuid because + they are not required for the security fix in this source layout. + +Signed-off-by: Deepak Rathore +--- + sqlite3.c | 2 +- + 1 file changed, 1 insertion(+), 1 deletion(-) + +diff --git a/sqlite3.c b/sqlite3.c +index fb42adcd7..6acf46a5b 100644 +--- a/sqlite3.c ++++ b/sqlite3.c +@@ -239694,7 +239694,7 @@ static void fts5DataRelease(Fts5Data *pData){ + static Fts5Data *fts5LeafRead(Fts5Index *p, i64 iRowid){ + Fts5Data *pRet = fts5DataRead(p, iRowid); + if( pRet ){ +- if( pRet->nn<4 || pRet->szLeaf>pRet->nn ){ ++ if( pRet->szLeaf<4 || pRet->szLeaf>pRet->nn ){ + p->rc = FTS5_CORRUPT; + fts5DataRelease(pRet); + pRet = 0; +-- +2.51.0 diff --git a/meta/recipes-support/sqlite/sqlite3_3.45.3.bb b/meta/recipes-support/sqlite/sqlite3_3.45.3.bb index 1b3ac83b58d..975f3bdab84 100644 --- a/meta/recipes-support/sqlite/sqlite3_3.45.3.bb +++ b/meta/recipes-support/sqlite/sqlite3_3.45.3.bb @@ -9,6 +9,7 @@ SRC_URI = "http://www.sqlite.org/2024/sqlite-autoconf-${SQLITE_PV}.tar.gz \ file://CVE-2025-6965.patch \ file://CVE-2025-7709.patch \ file://CVE-2025-70873.patch \ + file://CVE-2026-11822_CVE-2026-11824.patch \ " SRC_URI[sha256sum] = "b2809ca53124c19c60f42bf627736eae011afdcc205bb48270a5ee9a38191531" From patchwork Tue Jul 28 22:21:52 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 8bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 93767 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id EA0F7C54FCE for ; Tue, 28 Jul 2026 22:22:16 +0000 (UTC) Received: from mail-wr1-f43.google.com (mail-wr1-f43.google.com [209.85.221.43]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.2811.1785277335777683604 for ; Tue, 28 Jul 2026 15:22:16 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=fW8DKhMZ; spf=pass (domain: smile.fr, ip: 209.85.221.43, mailfrom: yoann.congal@smile.fr) Received: by mail-wr1-f43.google.com with SMTP id ffacd0b85a97d-472326ca506so258903f8f.2 for ; Tue, 28 Jul 2026 15:22:15 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1785277334; x=1785882134; darn=lists.openembedded.org; h=content-transfer-encoding:content-type:mime-version:references :in-reply-to:message-id:date:subject:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=m27sI871iMP7TIYq8oCrtYo14LVZJ5vLHEPwsJlwsdU=; b=fW8DKhMZxDqIVb1B51z0ivvD+/gIQyzC+StyOG6ge4Xtdlq7xVnBw0TukIdSnPT7lp v6dtB4CqYkglCxfTJ62JM9Z0PccOB0htP77IVFH/pLgxHCGf7ZuSIbn0RZfc5j9+oNvP VGSkPo3YTa9UtmJFH9GOUyxjoBoOX8VjQ1ujw= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1785277334; x=1785882134; h=content-transfer-encoding:content-type:mime-version:references :in-reply-to:message-id:date:subject:to:from:x-gm-gg :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to :content-type; bh=m27sI871iMP7TIYq8oCrtYo14LVZJ5vLHEPwsJlwsdU=; b=MOPulVg+QL5UVxl90xsrfLi3erTDNzo9TexDp2OS206vD97jMAslPBo857TGAoZMJZ oDLO2LHj4TAyNcVM7aHdlmSHQhwoOmosHnR8Y2aA6cfzrKzpFz73MIzSpFrDQtBBh2mi Z24w318GZnax3aaDvPydeEau80kicoPu7mT0SKDXKuwhpIRemmynHANLbo9AQJKh4ZSu QUEv68UtLtSTvHtoL7+W3isolTbZzJwoeX1ynF6xoavFC+3JrEH0IzvF1KkprMSTV/XX b6AmK9QlZGklbgKkoQdGiYaWZnAeRs+ipBEwqmqM0ImWmt41nS/ntpcc3HYqL80839P4 OXFw== X-Gm-Message-State: AOJu0YzgWnFGFKfdnVOKT9Vb1ZNDq7GBKxhQlSu7B950ghiMbqmIHyBI gd7XB9gnd7ItDzS5LQwtg7wlY8Jge2bxq+fJt2RivYVXouNkP/1R0LXJOJb2tX8JMVrYUAufqIH 1wTXTH30= X-Gm-Gg: AR+sD11gk20RrMA4PnBco1PbDXQbgIlzpuq//fy70qJjT6rMjS6fhKmyIiaZe53r+D8 D5zQvIH60R+AXynCgw1Nxx7/mo5lN4V3q/jLMJGL83r1edMqYM1KJYecLLcCw2EwECG+wz9CXQE hAzzxrpH9wBa8VekO5CUB35yUo1DnelgDEVy8GUi2oiQeEawyKZXhyvYyb8ybfIyxeukh6nq2O5 LD0lOmwg3ZAWNMSxjkVvwfdiF8wfR5WWEJ40zyOqK4qKGbDJ96kG8+0tiu0gaaGtXRoiQJ0Yd5j uKJ2rDlV+LPH868+O6Z7cCmotCkIXWMLgfoeZVWJZAevSiW34LsFKFTMAK9RcTTZipdW2ZhULsX biTgtQJq3Jn1FaSaADcBuUFntoYlEUlG7UqYvziVcOcIFR5GSIjkEu7nCVhDjh7+YZfxslf6x86 sRpRNuzZnKgofdSgaSJj1GRXHmkbyoS77xDuaBnwZCzY4gri3b6fPZQZepaPPhz4gXri2Jy7U2Y sSc8slPlGiXtOkN97jvLbKNmxiZUx7EyQfq24cEFoET0Lx/KbWA8uCh/dks+O/gW7U+QMeMyrg= X-Received: by 2002:a05:600c:4583:b0:496:c361:fb96 with SMTP id 5b1f17b1804b1-496c60bebd0mr43162955e9.0.1785277333871; Tue, 28 Jul 2026 15:22:13 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-4976bd6da4asm7669405e9.1.2026.07.28.15.22.13 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Tue, 28 Jul 2026 15:22:13 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][scarthgap 17/19] curl: add annotation for CVE-2026-10536 Date: Wed, 29 Jul 2026 00:21:52 +0200 Message-ID: <637ce45a66ff7125b98fc126321b31cb0cf6bf0f.1785277157.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Tue, 28 Jul 2026 22:22:16 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/242220 From: João Marcos Costa This CVE is detailed here: https://curl.se/docs/CVE-2026-10536.html and the fix essentially consolidates the fact that HTTP2 stream dependency is deprecated. While oe-core provides a PACKAGECONFIG to enable HTTP2, it is not actually used so the affected part of the code is not compiled. For instance, in the do_configure logs: """ (...) HTTP2: no (--with-nghttp2, --with-hyper) (...) """ Ignore this CVE unless 'nghttp2' is enabled. Signed-off-by: João Marcos Costa (Schneider Electric) Signed-off-by: Yoann Congal --- meta/recipes-support/curl/curl_8.7.1.bb | 1 + 1 file changed, 1 insertion(+) diff --git a/meta/recipes-support/curl/curl_8.7.1.bb b/meta/recipes-support/curl/curl_8.7.1.bb index 276526f01e5..3e48c58fa78 100644 --- a/meta/recipes-support/curl/curl_8.7.1.bb +++ b/meta/recipes-support/curl/curl_8.7.1.bb @@ -53,6 +53,7 @@ CVE_STATUS[CVE-2024-32928] = "ignored: CURLOPT_SSL_VERIFYPEER was disabled on go CVE_STATUS[CVE-2025-0725] = "not-applicable-config: gzip decompression of content-encoded HTTP responses with the `CURLOPT_ACCEPT_ENCODING` option, using zlib 1.2.0.3 or older" CVE_STATUS[CVE-2025-5025] = "${@bb.utils.contains('PACKAGECONFIG', 'openssl', 'not-applicable-config: applicable only with wolfssl','unpatched',d)}" CVE_STATUS[CVE-2025-10966] = "${@bb.utils.contains('PACKAGECONFIG', 'openssl', 'not-applicable-config: applicable only with wolfssl','unpatched',d)}" +CVE_STATUS[CVE-2026-10536] = "${@bb.utils.contains('PACKAGECONFIG', 'nghttp2', 'unpatched', 'not-applicable-config: applicable only with HTTP/2', d)}" inherit autotools pkgconfig binconfig multilib_header ptest From patchwork Tue Jul 28 22:21:53 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 93771 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 07699C54FD4 for ; Tue, 28 Jul 2026 22:22:17 +0000 (UTC) Received: from mail-wm1-f48.google.com (mail-wm1-f48.google.com [209.85.128.48]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.2708.1785277336196950718 for ; Tue, 28 Jul 2026 15:22:16 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=muUvgdxg; spf=pass (domain: smile.fr, ip: 209.85.128.48, mailfrom: yoann.congal@smile.fr) Received: by mail-wm1-f48.google.com with SMTP id 5b1f17b1804b1-49557167508so2752015e9.1 for ; Tue, 28 Jul 2026 15:22:15 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1785277334; x=1785882134; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=0Oac/VvdswcAYTGoKQ7LJScN7xzt668rZuQwaFDtCDc=; b=muUvgdxgVCtvUPisPyMwjd3Pys1AL2i+sSqWEUG39WmdT8U0SxtvNskgogJXlz+Y/8 M3yHPb/5bCpKC1P0DX/ro8iLTar5tddQgxXMIO/kjvPsacOMmntKIrOrLg0FElt/z/ZQ lBw6qP+pKlANqJkDJoUcbK5LwOdRCdUrzO4xQ= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1785277334; x=1785882134; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=0Oac/VvdswcAYTGoKQ7LJScN7xzt668rZuQwaFDtCDc=; b=Hp+OsFkcIHtZ1Qbxp1o7bnq5OuDj5hXl1m6Sf/hQnckpgBne/vHof+x4QXdSJv7e6A lkNLudgrLZ5P+R7GT2Rfb232W+jaPMlfAkjBAjB8z7gpwqe55wsX1nQ8tgwC79Vzw9WY Wy5iXirXzkO7X4xgUYtSPR24W+0frC+kGOZAJtmJUjUZ1g7GMDPOi16nSKD4W6Kh7ZD2 V4qDE297MZCV3/AVUmuxFE7kCH3CuVwVbXx5vnL4UN1Bij+SKiN04iGTgp8pp73HxEXr m4kponptn7EGm/mrI51DbB50W3kL8ShyCKzeE9pqLSHLHP7mfXjfgP0xPAVGGmIO2MqU KvVA== X-Gm-Message-State: AOJu0Yzr5rOXSG4qgrm1aCVrrMwnvZ+lJwiVJXVgG8ic33njwUUdQY6a D2yPRlquVI4pKFq+4OIGh2PjwRxHvJRwMUjC+RHnEB4UJTcxXNmCtMZkYCWSHbBFMwsGO485+wb 8Q5pqD/U= X-Gm-Gg: AR+sD13OU/kICoc4ojHlTU8JsIYXzTqoOrntyRU5guYdq0H4Ol9ualonJby0Vb5AMih jyZFvRbMLXAvUnIBwSwwSwJVwXtESOnyjVXFvsJIm2MMo2C+W4F+MLSk3BR7BVaX0jceezLaVgJ zcB2E+Ic79nHeP5rly2/K4i1uIr4LzXLVL5BdJUbTNLqoxzDECy/YjvzRNS8cS3MJYvMDVvTqmg zfOyZpOpxHvReWD3Ih/O6QX7Z+Z0ulbR5QihCLhRQiKj4hK2ijketGgN+6gHUtGdzkr2bKFya0U KRTSAdUHC490K+/cAmznjy40FEuZMWlq5OwPVBufvaJg6Ow7voFgD4HTFqJquEy9ZFlJMFfiVin U6M6aCVQDzJyQrKnr6zc8JGidcNlW0Mqsnu2Y88DT3+vXJ7sS1usaY/lzpVKRAif+O5V1kwpQuE g9aqEogaY+/F9V003vbyvry9TuT+VaJLnI+4UXnBHis9CW1uoUxzSvlfkOCw5XieDmbJRBUZiy+ HeN5ln3swl2StT72MP1i6EbtlXqfH1EhaOsKvBTN7TwkKCsINlrPKt6yx5EQ2CZ X-Received: by 2002:a05:600c:45d2:b0:495:5d5b:7533 with SMTP id 5b1f17b1804b1-496c642d775mr47584855e9.13.1785277334429; Tue, 28 Jul 2026 15:22:14 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-4976bd6da4asm7669405e9.1.2026.07.28.15.22.14 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Tue, 28 Jul 2026 15:22:14 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][scarthgap 18/19] cargo-update-recipe-crates: Don't fail for partially empty Cargo.lock Date: Wed, 29 Jul 2026 00:21:53 +0200 Message-ID: <59f1965358f59457857c920ed836998509450d9a.1785277157.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Tue, 28 Jul 2026 22:22:17 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/242221 From: Martin Schwan Do not fail if only some Cargo.lock files are empty. Only fail, if there are absolutely no dependencies found in any Cargo.lock. This fixes the following error message, which would occur with "bitbake -c update_crates python3-orjson": ERROR: python3-orjson-3.10.17-r0 do_update_crates: Execution of '.../python3-orjson/3.10.17/temp/run.do_update_crates.70693' failed with exit code 1 ERROR: Logfile of failure stored in: .../python3-orjson/3.10.17/temp/log.do_update_crates.70693 Log data follows: | DEBUG: Executing python function extend_recipe_sysroot | NOTE: Direct dependencies are ['.../sources/oe-core/../oe-core/meta/recipes-devtools/quilt/quilt-native_0.69.bb:do_populate_sysroot', 'virtual:native:.../sources/oe-core/../oe-core/meta/recipes-devtools/patch/patch_2.8.bb:do_populate_sysroot', 'virtual:native:.../sources/oe-core/../oe-core/meta/recipes-devtools/python/python3_3.13.9.bb:do_populate_sysroot'] | NOTE: Installed into sysroot: [] | NOTE: Skipping as already exists in sysroot: ['gettext-minimal-native', 'cmake-native', 'libtool-native', 'quilt-native', 'texinfo-dummy-native', 'openssl-native', 'expat-native', 'ncurses-native', 'util-linux-libuuid-native', 'zlib-native', 'libedit-native', 'make-native', 'patch-native', 'perl-native', 'python3-native', 'bzip2-native', 'xz-native', 'zstd-native', 'attr-native', 'gdbm-native', 'libffi-native', 'sqlite3-native'] | DEBUG: Python function extend_recipe_sysroot finished | DEBUG: Executing shell function do_update_crates | Traceback (most recent call last): | File "", line 41, in | File "", line 12, in get_crates | ValueError: Unable to find any candidate crates that use crates.io | | The above exception was the direct cause of the following exception: | | Traceback (most recent call last): | File "", line 43, in | ValueError: Cannot parse '.../python3-orjson/3.10.17/sources/orjson-3.10.17/include/cargo/simdutf8-0.1.5/Cargo.lock' | WARNING: exit code 1 from a shell command. ERROR: Task (.../sources/oe-core/../meta-openembedded/meta-python/recipes-devtools/python/python3-orjson_3.10.17.bb:do_update_crates) failed with exit code '1' Signed-off-by: Martin Schwan Signed-off-by: Mathieu Dubois-Briand Signed-off-by: Ross Burton Signed-off-by: Richard Purdie (cherry picked from commit 1ef39b3fa731fb121d338aea2b1ac004620063e0) Signed-off-by: Yoann Congal --- .../cargo-update-recipe-crates.bbclass | 16 +++++++--------- 1 file changed, 7 insertions(+), 9 deletions(-) diff --git a/meta/classes-recipe/cargo-update-recipe-crates.bbclass b/meta/classes-recipe/cargo-update-recipe-crates.bbclass index 8980137d02c..ac76fa3279a 100644 --- a/meta/classes-recipe/cargo-update-recipe-crates.bbclass +++ b/meta/classes-recipe/cargo-update-recipe-crates.bbclass @@ -36,7 +36,8 @@ def get_crates(f): crates_candidates = list(filter(lambda c: 'crates.io' in c.get('source', ''), crates['package'])) if not crates_candidates: - raise ValueError("Unable to find any candidate crates that use crates.io") + print("WARNING: Unable to find any candidate crates that use crates.io") + return None # Update crates uri and their checksum, to avoid name clashing on the checksum # we need to rename crates with name and version to have a unique key @@ -63,14 +64,11 @@ for root, dirs, files in os.walk('${CARGO_LOCK_SRC_DIR}'): continue for file in files: if file == 'Cargo.lock': - try: - cargo_lock_path = os.path.join(root, file) - crates += get_crates(os.path.join(root, file)) - except Exception as e: - raise ValueError("Cannot parse '%s'" % cargo_lock_path) from e - else: - found = True -if not found: + cargo_lock_path = os.path.join(root, file) + c = get_crates(cargo_lock_path) + if c is not None: + crates += c +if crates is None: raise ValueError("Unable to find any Cargo.lock in ${CARGO_LOCK_SRC_DIR}") open("${TARGET_FILE}", 'w').write(crates) EOF From patchwork Tue Jul 28 22:21:54 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 93772 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 034EFC53219 for ; Tue, 28 Jul 2026 22:22:27 +0000 (UTC) Received: from mail-wm1-f54.google.com (mail-wm1-f54.google.com [209.85.128.54]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.2709.1785277336704357967 for ; Tue, 28 Jul 2026 15:22:17 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=O1SkbSAi; spf=pass (domain: smile.fr, ip: 209.85.128.54, mailfrom: yoann.congal@smile.fr) Received: by mail-wm1-f54.google.com with SMTP id 5b1f17b1804b1-4954d29264cso1320635e9.2 for ; Tue, 28 Jul 2026 15:22:16 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1785277335; x=1785882135; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=RvDMqt6Vo0CCYf3BY+a/MyIX53jeROmtsYWAxrv91hU=; b=O1SkbSAi7tVcZWGhqTI5kClhXElhTGfL6C1GzLJPcdG/E/ZL8lSC1RAW6xWEWWLOnq tTLSeGfNlx3Cb/GibUeVXru1q/+esHaCivGyaztPhC8WxslG6BRlU2Qo3urLXWOXNHUS QJVzoRg2ib0NosvIAMPwEXy0JXvyFh6jW4XNA= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1785277335; x=1785882135; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=RvDMqt6Vo0CCYf3BY+a/MyIX53jeROmtsYWAxrv91hU=; b=XNrWzT6GtFfERAaZxsgGYe+QS4iQ8OP43BGBAfFmMq/74o9pydV0v0D/gMT4z5FUy5 z0FuoPGI07/XmKmEaQbEmLt0PTRHGBmkWc0WefWRf7mcooLTv/9ZFMPLBM3CN46bd8MI vJWxkj2C7xzscDrS5eIqbMHORZpaQjiWRrZYGWBxu8nJ1miuLruVxcazbSHARa0BcL08 /vxj8nvjCk/V7V8y8DtKdKxT7IsICpQXzmNqwllvEZ+XbVaO1BjY2iNfZxeDUVpEQapm ThBXCsw9PSQL9swHDntqAdN++g39zuOoN8RZLAk2r/XwZ5HMbBGrHa+P6lbNOt5dowre J8ow== X-Gm-Message-State: AOJu0Ywrej4epc/cAFzH6GeeCouGxYVlNNgDXFJYu10SAjhdZkGgBUdi Q5I9igwL4vlkD8ArmdmXX7qeCvaPGw1R/xdVywrPj5lXs4SJovutVQurNLEtvnTRcuanHk+0KQt R3p9jUHE= X-Gm-Gg: AR+sD11k98kmFCwGnfscHDxqidcGoXiBS7hufjr6x+8lndLF7U8/772BT0PV4P5Qj// 0OAdGXYNhtFFVHIBUe7jfjmDn3exoJ4jdMWtoVbXDAGsWeqRcIX5rIDH1GqkGqhHwrTs6vCWHnK VBALXXzcJHCsn3lBt1wdSQiLnxcZoJZnCKBjHthArUnuY9/lXXPrbU8v8J7zzG4zH0zGVKeVuBK AiDZgrmMjoSnPkJBA7EqFUwFDy6vmtwepA0TaP74/NvZLuF0c/g6cuhtNwLJy8EFNuNqB5Xn/m6 cEqMNBXRTi8x8bsKmSp3p7bzqoZZUyDhWK+VBqXfpJAI7jFirEbtD+OLD+WgFraLN4nzqKuvT3C 5rxyhvtiyQyjyLm2qmFENP6NHPpZhdy60kmC4nv9EDUKl/VsbskknSCVRUfO0M+NNtJX5+I33qB thBa+pmzGgUZIbMO/iUWgreKMjdaOQxYZ+ZbqEhuWHSv//sh9Ik8kLx0ujCQk6Xpj8KPP9115+j bH+znVyL7NARSis8O+XIaBo49bkEjrb/1PXgRFVuolQFbx28Jrl+HWUgyjH1aOC X-Received: by 2002:a05:600c:4f86:b0:496:c933:c276 with SMTP id 5b1f17b1804b1-496c933c2afmr33747345e9.25.1785277334930; Tue, 28 Jul 2026 15:22:14 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-4976bd6da4asm7669405e9.1.2026.07.28.15.22.14 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Tue, 28 Jul 2026 15:22:14 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][scarthgap 19/19] openssh: set status for CVE-2026-59998 Date: Wed, 29 Jul 2026 00:21:54 +0200 Message-ID: <543550522f831479f07d332a40ba343c53ae1065.1785277157.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Tue, 28 Jul 2026 22:22:27 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/242222 From: Devansh Patel Analysis: - CVE-2026-59998 concerns an undocumented limitation of GSSAPIStrictAcceptorCheck in Windows Active Directory environments [1]. - Upstream OpenSSH 10.4 only documents the existing behavior and provides no code remediation [2]. - The recipe disables Kerberos/GSSAPI by default. Mark the CVE not-applicable-config when PACKAGECONFIG lacks kerberos, and unpatched when kerberos is enabled. Reference: [1] https://nvd.nist.gov/vuln/detail/CVE-2026-59998 [2] https://github.com/openssh/openssh-portable/commit/8058c5bdb507591b79ec926221fbe6fcc296d432 Signed-off-by: Devansh Patel [YC: See previous version of this patch for context about ignoring vs this CVE vs patching: https://patchwork.yoctoproject.org/project/oe-core/patch/20260720175518.3546447-3-devanshp@cisco.com/#40497 ] Signed-off-by: Yoann Congal --- meta/recipes-connectivity/openssh/openssh_9.6p1.bb | 1 + 1 file changed, 1 insertion(+) diff --git a/meta/recipes-connectivity/openssh/openssh_9.6p1.bb b/meta/recipes-connectivity/openssh/openssh_9.6p1.bb index ba8aaad9bbb..b48e262c725 100644 --- a/meta/recipes-connectivity/openssh/openssh_9.6p1.bb +++ b/meta/recipes-connectivity/openssh/openssh_9.6p1.bb @@ -57,6 +57,7 @@ Red Hat Enterprise Linux 7 and when running in a Kerberos environment" CVE_STATUS[CVE-2008-3844] = "not-applicable-platform: Only applies to some distributed RHEL binaries." CVE_STATUS[CVE-2023-51767] = "upstream-wontfix: It was demonstrated on modified sshd and does not exist in upstream openssh https://bugzilla.mindrot.org/show_bug.cgi?id=3656#c1." CVE_STATUS[CVE-2026-3497] = "not-applicable-platform: Only affects GSSAPI Key Exchange patches used by some Linux distributions and does not exist in upstream openssh." +CVE_STATUS[CVE-2026-59998] = "${@bb.utils.contains('PACKAGECONFIG', 'kerberos', 'unpatched', 'not-applicable-config: GSSAPI/Kerberos support is disabled in the default OpenSSH configuration', d)}" PAM_SRC_URI = "file://sshd"