From patchwork Sat Sep 5 20:44:02 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 97351 X-Patchwork-Delegate: yoann.congal@smile.fr Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id EBE45C624DB for ; Sat, 5 Sep 2026 20:45:22 +0000 (UTC) Received: from mail-wr1-f48.google.com (mail-wr1-f48.google.com [209.85.221.48]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.2473.1788641112568369788 for ; Sat, 05 Sep 2026 13:45:12 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=ZD0O7RtC; spf=pass (domain: smile.fr, ip: 209.85.221.48, mailfrom: yoann.congal@smile.fr) Received: by mail-wr1-f48.google.com with SMTP id ffacd0b85a97d-4843e397f74so2721185f8f.1 for ; Sat, 05 Sep 2026 13:45:12 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1788641111; x=1789245911; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=vUaCmmByHnFYhHmZLBeKleEkc/heRtml1oAtp3CtyhU=; b=ZD0O7RtCP5DI/pRaqM634EpAdQvGr4KVjoWDc90GdMz8NkyvcbrGSxn1orCt2YTG0o FHWsu+EdDVfSl8kN0AjnjJbIKACCxNqRRnp0KBennHYpfX+DfHui8iev7lxcI2KeQk5x b6E1+8m85Kk+IzFn1tym/F5cGTP2fVNRJ+sm8= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1788641111; x=1789245911; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=vUaCmmByHnFYhHmZLBeKleEkc/heRtml1oAtp3CtyhU=; b=LO+FBxOi8MeRjBNIHgiSADaLpLCFXqkcxVPgg4eTuLpRAHce+I3ZajgZueDaMsPExU GXQCHAGDZD5caKbh0sQO0UGTCpZH/VCE/6QTnBWUMCUJA3ua96Tf/H6pX370Lflyv2EN PzBpCwdOOpDRCw6JmmuAAtalDs52sN054v8oNC4mLjziLFeUxmTUBwxHpa/YFKqEMzyA lIEhKrUAoGeApMZvGA9eD06MeHjmoXSg8NKA9vOKywm/kUUB6YQuvDozCVUqXHYYgleG 726tr0pRcSU0PCWSYIp7SZO5Xxzqv6QDyupZmbj+jh4ljLMzm5jH6PxKqA72o9GRtFqU H5kA== X-Gm-Message-State: AFuF++l28i93Pmo1VYjCysFwQiZvcf8OCwR1y064H6nGEj64RLwUnEGX J3o1xyfQElV4/11PhOoXa8zhQiMbccDlN9CnEQ3HaztFDeuo0MWZRO/g2jqwnBqNQT4Z5YkrM30 nYqzTT5w= X-Gm-Gg: AYBFou3fBlNCJDlTPYeqsKCoA135IgvWhNuRc90r0nbMuSL2xoV4s66/Be0DT99jK2L hz20/N4N7ywkGAdBj7yFwXUyQhtOZ3rrKfrX46IhwpBVl2tePG78aepDUYbr+2hYc8hPxQZAlKj ZtlnD+x0j2BBV98hPXc1LRAdb5h46zbh7KTKbZFs4CzLc96GEPX+/MDDyVZ+nxpJRzyyRfK+vgf RcwU/vgmKhNak3ZP1k6BRZA7ODkrDnMdUikPDbVs8S7BtVm0oKDNLPLC7NjtHJUXxaPUMH0/8ng ZSe1kKx93fkf2OIs7uQxBKkPfOMqsy70vRJ/oWQN1X71+TVOPu76K5QHimy4SMA0mG4zjOuAwcY Iti0PK3dzbn0UlmJbaVt4p9j7cnW8HWVkxV2C6qHnNkdrcmUFnDyNUhhdCaV3Pr8M8Yg5qLVTO4 zK1SMosheqAtQLOotee3RABEIXHFpK+9eIKVsnMiUkr7O5NU9TqIzwed5gjTM5tGqyu3bMSjsRu 57hh3fty4KZHgqnXM9TMWf2zP9rwKdIPnwoVDOsG2bmQAzd/X3SlHcove/sGvxyHw== X-Received: by 2002:a5d:64eb:0:b0:485:7d6d:e0e0 with SMTP id ffacd0b85a97d-485891dcff4mr14703018f8f.3.1788641110750; Sat, 05 Sep 2026 13:45:10 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa0048511f7ccf23d3ce.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:4851:1f7c:cf23:d3ce]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-485885bfdf6sm17069098f8f.34.2026.09.05.13.45.10 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sat, 05 Sep 2026 13:45:10 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][wrynose 01/40] apt: mark CVE-2011-3374 as fixed-version Date: Sat, 5 Sep 2026 22:44:02 +0200 Message-ID: <47af4352de3c92197afb57207be2b1bdfd8e5b33.1788629392.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Sat, 05 Sep 2026 20:45:22 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/245153 From: Devansh Patel CVE-2011-3374 affects the legacy apt-key net-update command [1]. Upstream removed apt-key in apt 2.9.19 [2]. OE-Core uses apt 3.0.3, so the vulnerable code is no longer present and cannot be restored by configuration. Mark the CVE as fixed-version. [1] https://security-tracker.debian.org/tracker/CVE-2011-3374 [2] https://salsa.debian.org/apt-team/apt/-/commit/a00fbbdb2 Signed-off-by: Devansh Patel Signed-off-by: Mathieu Dubois-Briand Signed-off-by: Richard Purdie (cherry picked from commit 5126e4792ddd8e6c721c47733d287633c234f2a9) Signed-off-by: Yoann Congal --- meta/recipes-devtools/apt/apt_3.0.3.bb | 3 +++ 1 file changed, 3 insertions(+) diff --git a/meta/recipes-devtools/apt/apt_3.0.3.bb b/meta/recipes-devtools/apt/apt_3.0.3.bb index 08b6bac2e4f..7c72f489a3f 100644 --- a/meta/recipes-devtools/apt/apt_3.0.3.bb +++ b/meta/recipes-devtools/apt/apt_3.0.3.bb @@ -34,6 +34,9 @@ UPSTREAM_CHECK_URI = "${DEBIAN_MIRROR}/main/a/apt/" # to express 'divisible by 4 plus 2' in regex (that I know of), let's hardcode a few. UPSTREAM_CHECK_REGEX = "[^\d\.](?P((2\.2)|(2\.6)|(3\.0)|(3\.4)|(3\.8)|(4\.2))(\.\d+)+)\.tar" +# apt-key, including the vulnerable net-update path, was removed in 2.9.19. +CVE_STATUS[CVE-2011-3374] = "fixed-version: apt-key was removed in 2.9.19" + inherit cmake perlnative bash-completion useradd # User is added to allow apt to drop privs, will runtime warn without From patchwork Sat Sep 5 20:44:03 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 97364 X-Patchwork-Delegate: yoann.congal@smile.fr Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id B8111C79FA7 for ; Sat, 5 Sep 2026 20:45:24 +0000 (UTC) Received: from mail-wr1-f43.google.com (mail-wr1-f43.google.com [209.85.221.43]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.2474.1788641112943504575 for ; Sat, 05 Sep 2026 13:45:13 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=HL0YZl7G; spf=pass (domain: smile.fr, ip: 209.85.221.43, mailfrom: yoann.congal@smile.fr) Received: by mail-wr1-f43.google.com with SMTP id ffacd0b85a97d-485843aeab8so2346526f8f.1 for ; Sat, 05 Sep 2026 13:45:12 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1788641111; x=1789245911; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=FqONaJBdzg15J+Mpp/68+AN2zDtGIVVL5VvvS2h9s1w=; b=HL0YZl7GiQILxAwnX7vek3I3mnhbKCVgV7FiMw+/PZYq98TJHibyswSLQPGuSHF6Ff MUGa5VmLfdioR2wcFaCGJ3m+X7rB4NGFhVkpKsu9+GAFKrNG3M1KV9HA2tA00IiRB/zT qIkpVY33RnmcgaApVO2vC43H5pr/zoyA1YNkI= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1788641111; x=1789245911; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=FqONaJBdzg15J+Mpp/68+AN2zDtGIVVL5VvvS2h9s1w=; b=CGo5puxVGY7wMXQ2vM16epb7ChEFi841l/nfuMHp3fH2LIUez8xenUhm5SM8MPgD+o hhS2Kdn8nQcUd2TU0IKYw5GnFjCFxbhpc6XkA/AgxU0HtFOmNCfrVg4bX7+w3yp1Sc0A flVaiTt+pUXIOboOMVJwJMLj1mwDKlcCVtgew/4sxJZiv6vjhKm9CP3Gfn0jdJYbVoq2 OYAuxi/ah40r4o+7Bj3xrmVA/hQ/pXbTnTaDSgZ2fwh4c8/T5e4t0y9Nkkuw7k9IufoQ sLa+9CDkZLjIeIjNG2/bG/58vlhkmmW4xQ0CRnnlkaLD7STEAGjMiFPw/YAhNVsFGXBK h+8g== X-Gm-Message-State: AFuF++khbuLjdTH5vTtnSdTGBDfZVr9dypEuPQNbBdgHtJgy3EDfk8O1 ZW1kCZ+FvXm2OdeYCqrQ9CrWrJ/DenAtOrl2ZFSUtTB5p53qspRMS7cedIqq3rg7hdV8R4RTtcN /Fa3jQR4= X-Gm-Gg: AYBFou2AfpdRGONpj0FOFuhLCnDW8EAPtZayCMh31/jvZ5YwUuRsTO0GPTy9oMM8bKh 99BUR7MK2MNyo9IWqIZLcTL6M4Z0aDtPdg4cxthwExyfY1cpwyYsCAtI/P0vjJEl715wJEWOYX+ nmyaOmANmT6PvM/CrZEJcv9TzMG6RZfy0S2DBCf9DipIV+kSkvshNwKW5XmMlBuchMW6IOXxGFO 5iSTNAkqaMDTE+0X0Lw7sjn96N8EbcpO1+iCXKMEuGzeO6ohwo8Ka54/33EBYR0/N60P54+n9bQ 9LLceNZycyKSf5HtOyraslh4jJa4IgNAThwTa3qPROt/4sjsow6fmVaMF+6t4iRK7Mo+wGU8Yb1 dYQhMz9h/g+jUFTZDrHk2wXHnAv2cdy/iNqI7IsNziz8w07O7KSwa9xR+z4evKTx8FW7clSscSq nGSCumjQwbzFeroP2y2YpqSDylnPEi3CNFky9Yb7EHUzYtfub9oUb8rYVYW7hjRmOhyIP4SHhlM Zd8l5wb6lhXtigUZeu1lV6xQNaKs0FnzFQT3QEWpS17ayuA48sESRanAjyCeUNoag== X-Received: by 2002:a05:6000:605:b0:485:8b66:f5 with SMTP id ffacd0b85a97d-4858b660161mr23048423f8f.18.1788641111218; Sat, 05 Sep 2026 13:45:11 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa0048511f7ccf23d3ce.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:4851:1f7c:cf23:d3ce]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-485885bfdf6sm17069098f8f.34.2026.09.05.13.45.10 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sat, 05 Sep 2026 13:45:10 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][wrynose 02/40] expat: set CVE_STATUS for CVE-2026-72522 Date: Sat, 5 Sep 2026 22:44:03 +0200 Message-ID: X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Sat, 05 Sep 2026 20:45:24 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/245154 From: Jaipaul Cheernam CVE-2026-72522 is an out-of-bounds read and infinite loop vulnerability in Expat's *_toUtf16 functions caused by mis-classifying low surrogates as high surrogates. Our Yocto configuration is not affected by this vulnerability: - Expat is compiled with EXPAT_CHAR_TYPE=char (8-bit character representation). - Neither XML_UNICODE nor XML_UNICODE_WCHAR_T is defined. - The vulnerable *_toUtf16 functions are only invoked when Expat's internal character type is 16-bit (ushort or wchar_t). - In 8-bit mode, Expat handles conversion using *_toUtf8 functions even when parsing UTF-16 encoded XML inputs, rendering the vulnerable code path unreachable. Reference: [1] https://nvd.nist.gov/vuln/detail/CVE-2026-72522 [2] https://github.com/libexpat/libexpat/pull/1296/changes/8fbfb52fa88e040e8b0b7a9d39f260d6a9e8b6db Signed-off-by: Jaipaul Cheernam Signed-off-by: Yoann Congal [YC: EXPAT_CHAR_TYPE=char is the default and we do not change it] --- meta/recipes-core/expat/expat_2.7.5.bb | 3 +++ 1 file changed, 3 insertions(+) diff --git a/meta/recipes-core/expat/expat_2.7.5.bb b/meta/recipes-core/expat/expat_2.7.5.bb index 890ee5b7d34..da35b8f9ff5 100644 --- a/meta/recipes-core/expat/expat_2.7.5.bb +++ b/meta/recipes-core/expat/expat_2.7.5.bb @@ -57,3 +57,6 @@ do_install_ptest:class-target() { BBCLASSEXTEND += "native nativesdk" CVE_PRODUCT = "expat libexpat" + +CVE_STATUS[CVE-2026-72522] = "not-applicable-config: Needs Expat compiled with 16bit character support , Issue only affects firefox/Windows. \ +EXPAT_CHAR_TYPE:STRING=char is for Yocto builds" From patchwork Sat Sep 5 20:44:04 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 97366 X-Patchwork-Delegate: yoann.congal@smile.fr Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 581BEC79FA9 for ; Sat, 5 Sep 2026 20:45:25 +0000 (UTC) Received: from mail-wr1-f45.google.com (mail-wr1-f45.google.com [209.85.221.45]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.2475.1788641114045279931 for ; Sat, 05 Sep 2026 13:45:14 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=ydhyF6GD; spf=pass (domain: smile.fr, ip: 209.85.221.45, mailfrom: yoann.congal@smile.fr) Received: by mail-wr1-f45.google.com with SMTP id ffacd0b85a97d-484362f5c4aso2712044f8f.3 for ; Sat, 05 Sep 2026 13:45:13 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1788641112; x=1789245912; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=/2Drm4PxIUmfGH73o6ApHVm7gx7ctk51h+EpN6bO1R0=; b=ydhyF6GD4cbAh4ay77a+6Cgtrnn1EoWyswo+93GRmHYA+4Go/1WDEAQ1QHWTMfwO5M SmJ6T5Eh6RaWjS2lufujiq3GDxAyeTWGbJag8bn0cjaVWhaOk7uo9DTVL2VGKMbLZ0Wl 7s9s+ztfW1Nj1LCRn4wDNtY2cVcv0PW2oImf0= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1788641112; x=1789245912; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=/2Drm4PxIUmfGH73o6ApHVm7gx7ctk51h+EpN6bO1R0=; b=YVwI28kTJX5AcVuLXtaRYWMdncGhxB/zizEouGWXBgfoJBTXPbwVXEXObkQPLCeqn4 +JJynuage7vjwO/5LGzTwhX7H3VPtsStYJgOX7kkKMQTH2yK8QEms1hvQt/tfYFQJyJf KeF/Mt7h5I8+MDOiSEhFxwyWp61/VqlvbK7Iv70ZB9JoOr9XGOcZoV8q3DyR1p6iYtKu Pnx9tfZ17+9KPg/rrWkBqWkyr7yUVcEMdiWTYqUBvdPpYXDxYbyEAxJZlITZwF+GN3AX HkblCMpxf2q088SeOLh/4NrP4zF3UzZo7q7rjBz5OTOtnm8Kr6vvz38opWY/OR+5Kx0J NEBA== X-Gm-Message-State: AFuF++mdMevoyrofbBfy6k1NlfylIipzcTRAcALHnRBLflMVWmbr/Zfv tiCH6o104dlgw1pwCfGKChXhVEF1ZYDloCcJ0jFUcXdKUIvxxrjQQJ3oNfiAWbqnU6Z1S/QcOa3 Zg3KJD7I= X-Gm-Gg: AYBFou1nETwYm7nniECZpNgLJb2pS6x72OYI0OwHKf6yzNEwhXBjVjiLsfbmlbuUxyL tjDNJ1najikiE2nez8DgsTR3NZmC0WShzKwVd47LUBKlZXsOL93vczMIUJJqqZsTjWVJbHFCtWx 9HuvWwCFBBAvaEdbruTRUuJWOVudf9l/xC1GqOpALPhlvo/+5fCHkUo2kS84ZUgWziBeMoey3xW ijM6O76Y9spQoutPmGC5skLaBrpfh3HGE+s3xOymZrwv9/zk0Y2MacMQ9NO2DkLjOW+WoIREvpB wX1GT6ifCgEfgViLzialdyMGPwSJ1GgtBxIbylnPYsv/juKHnclU1jRV9iYQaA1pUfaSiz391/O ouSsxI8xymtvLMT9l4udiRA3/ZogTKJfk00BCF/EX+54KswQ5FI3knL9D4E3hHWCJtW+1hLdMz7 +N5P4sEKRnCG540ghRTrtZH7qHaPo0CHdJ5jr4itdjpVGw/q4VRvMw6dEtQXc9jM6/Wyk6Eke3q X72Jzjpk+7eJ+Uv1Dzi4FRDhYhB0rnEzQWEQ/pUuxPboqlkMI3e2uPJBO7cOx4ltA== X-Received: by 2002:a5d:5f53:0:b0:484:49a9:10e3 with SMTP id ffacd0b85a97d-48586e494e6mr28382209f8f.1.1788641112287; Sat, 05 Sep 2026 13:45:12 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa0048511f7ccf23d3ce.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:4851:1f7c:cf23:d3ce]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-485885bfdf6sm17069098f8f.34.2026.09.05.13.45.11 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sat, 05 Sep 2026 13:45:11 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][wrynose 03/40] python3-git: fix CVE-2026-42284 Date: Sat, 5 Sep 2026 22:44:04 +0200 Message-ID: <0b31060413238a55e49caa932341903cceaf8022.1788629392.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Sat, 05 Sep 2026 20:45:25 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/245155 From: Darsh Kelaiya This patch applies the upstream fix as referenced in [2], using the commit shown in [1]. [1] https://github.com/gitpython-developers/GitPython/commit/c9a26789d88b18f8b4620f37307df2976292d2a0 [2] https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-x2qx-6953-8485 Signed-off-by: Darsh Kelaiya Signed-off-by: Yoann Congal [YC: See https://github.com/gitpython-developers/GitPython/pull/2130#issue-4299717224: The author links the fix to this advisory/CVE. ] --- .../python/python3-git/CVE-2026-42284.patch | 36 +++++++++++++++++++ .../python/python3-git_3.1.43.bb | 2 ++ 2 files changed, 38 insertions(+) create mode 100644 meta/recipes-devtools/python/python3-git/CVE-2026-42284.patch diff --git a/meta/recipes-devtools/python/python3-git/CVE-2026-42284.patch b/meta/recipes-devtools/python/python3-git/CVE-2026-42284.patch new file mode 100644 index 00000000000..3e5b9908a78 --- /dev/null +++ b/meta/recipes-devtools/python/python3-git/CVE-2026-42284.patch @@ -0,0 +1,36 @@ +From 01d579e1b0a3e78cf82695b84967d0c343cfdd0f Mon Sep 17 00:00:00 2001 +From: "GPT 5.4" +Date: Tue, 21 Apr 2026 09:30:29 +0800 +Subject: [PATCH] Make sure that multi-options are checked after splitting them + with `shlex` + +CVE: CVE-2026-42284 +Upstream-Status: Backport [https://github.com/gitpython-developers/GitPython/commit/c9a26789d88b18f8b4620f37307df2976292d2a0] + +Backport Changes: +- Omitted test/test_clone.py and test/test_submodule.py because the + PyPI 3.1.43 source used by the recipe does not ship the upstream + test tree. + +Co-authored-by: Sebastian Thiel +(cherry picked from commit c9a26789d88b18f8b4620f37307df2976292d2a0) +Signed-off-by: Darsh Kelaiya +--- + git/repo/base.py | 4 ++-- + 1 file changed, 2 insertions(+), 2 deletions(-) + +diff --git a/git/repo/base.py b/git/repo/base.py +index 51ea7690..8059fceb 100644 +--- a/git/repo/base.py ++++ b/git/repo/base.py +@@ -1365,8 +1365,8 @@ class Repo: + Git.check_unsafe_protocols(str(url)) + if not allow_unsafe_options: + Git.check_unsafe_options(options=list(kwargs.keys()), unsafe_options=cls.unsafe_git_clone_options) +- if not allow_unsafe_options and multi_options: +- Git.check_unsafe_options(options=multi_options, unsafe_options=cls.unsafe_git_clone_options) ++ if not allow_unsafe_options and multi: ++ Git.check_unsafe_options(options=multi, unsafe_options=cls.unsafe_git_clone_options) + + proc = git.clone( + multi, diff --git a/meta/recipes-devtools/python/python3-git_3.1.43.bb b/meta/recipes-devtools/python/python3-git_3.1.43.bb index 45c988117bd..bfbdd802893 100644 --- a/meta/recipes-devtools/python/python3-git_3.1.43.bb +++ b/meta/recipes-devtools/python/python3-git_3.1.43.bb @@ -12,6 +12,8 @@ PYPI_PACKAGE = "GitPython" inherit pypi python_setuptools_build_meta +SRC_URI += "file://CVE-2026-42284.patch \ + " SRC_URI[sha256sum] = "35f314a9f878467f5453cc1fee295c3e18e52f1b99f10f6cf5b1682e968a9e7c" DEPENDS += " python3-gitdb" From patchwork Sat Sep 5 20:44:05 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 97370 X-Patchwork-Delegate: yoann.congal@smile.fr Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 654D7C79FAA for ; Sat, 5 Sep 2026 20:45:25 +0000 (UTC) Received: from mail-wm1-f45.google.com (mail-wm1-f45.google.com [209.85.128.45]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.2576.1788641114632051824 for ; Sat, 05 Sep 2026 13:45:14 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=NI+j9hXL; spf=pass (domain: smile.fr, ip: 209.85.128.45, mailfrom: yoann.congal@smile.fr) Received: by mail-wm1-f45.google.com with SMTP id 5b1f17b1804b1-49a97714f5dso19396035e9.0 for ; Sat, 05 Sep 2026 13:45:14 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1788641113; x=1789245913; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=Vv9h/IlSN4vTtnJnJu5ZB7T9d3KWxEN4aLuBJg8M8co=; b=NI+j9hXLZSpIbMqQvpUvJlqdqOt8HvNKdl/ZZ8/wbWXG7d8bcLWfsl7cRvKI2b9jzV kjfy7w729Ad0f94nqiNSwutmWupr0liF+rphGvmObiQwrJst6AoVmy9KAABwfL5wsnlr kZA4x0sO3eEhb8SUDaRwHozOLQKvx9Zsyw7VA= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1788641113; x=1789245913; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=Vv9h/IlSN4vTtnJnJu5ZB7T9d3KWxEN4aLuBJg8M8co=; b=AHl8OUgXci4cQbsV0DDDUxh5GuACnKpx64WlT8XP9MJzdd6O3voPN9JLIdOl6fpkSr il7jaeCD24J9z1R1h91luJF/G0yA0wddD1mGEVhJyE4rtnKfb5ELBTAC/mO94DxTCgfQ 4mrztDnEUqzXzcI1arIisXy70GNx6Kgg37PjuuF7eyhiPpZQuX4T28+PqnkiZDIRMev4 t6kyHdMqMMHADdRnuxMV8GyntPf6nV6olrQYK7/sC6x9NavTcHsOjsODjU8TuDTJs10T T+In1B7JrlztuAaR696ZDf5feyiZJRMwf3Gj092CEigKrCO1FroF+Ra4WkfFKHWI9Mmt BwlQ== X-Gm-Message-State: AFuF++mTe5m9981WoQNGAfv1M9VsUe9igM5zMoBlbINMzWNf6+B/s2Te eDD8i3VHDM4uOp9HdSzaImIPfTU5cg13ykomVqIAnfQgImsBhcxidE846s835K7LFt32k5S2vAx bMFBBbog= X-Gm-Gg: AYBFou0pw5vqi4To/1LADpJZCepb6bhSJNU7w4XolQnr2bfIIbT7bBJao+E58rq+dfp 0IxIaPu+2Utr7DYLfqx2XlJl5z+cjD2NVIGIjDCueg1RBcnd+EJA7jTBiZC+kmAMJRRkhHWdL3o EYQaoarENL3qwr6N4yjbdIAz6Beqkq+ncsT1Ujg6Q/uxMuPMNMXdZP+h+ZfsqfdstGy0oATvKHv y7ErWYWuA8/uGlbWFpDw7rd9/b4ZztXaR1gac+DRbQ8F8cSrmTa/11r7XH9JTVGk9K4Djme+Vq0 hxLtzX7GnG537OB4VT7FRHdWFdyy1Fmb1jfAnMAivAzhQiJeKTtDKunpAgVhW7dfm7Jubstdrtj 20gNs6JJ1s75gHqSHhfy+Wz2dBgf4u8yUxAY49BvWjh+sh9NparQ3SXzYKM+hmysyJ69vxg1JuQ 3zrGUpAMenfdj9z79mDWWhFV4e/zCm5OG0dp/sRI964zbC6oTiTPU0NOf+UPGrWL/zYmr5SHke0 KGpuxrlSt6FfLcYPkoNywA+gpObdQV804pFPsa6v4tKkvt4TcDsxIJjqCRgXSdiBQ== X-Received: by 2002:a05:600c:4693:b0:49d:39:90ba with SMTP id 5b1f17b1804b1-49d00399d19mr69176135e9.3.1788641112718; Sat, 05 Sep 2026 13:45:12 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa0048511f7ccf23d3ce.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:4851:1f7c:cf23:d3ce]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-485885bfdf6sm17069098f8f.34.2026.09.05.13.45.12 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sat, 05 Sep 2026 13:45:12 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][wrynose 04/40] python3-git: fix CVE-2026-42215 Date: Sat, 5 Sep 2026 22:44:05 +0200 Message-ID: X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Sat, 05 Sep 2026 20:45:25 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/245156 From: Darsh Kelaiya This patch applies the upstream fix as referenced in [3], using the backported commits shown in [1] and [2]. [1] https://github.com/gitpython-developers/GitPython/commit/142195888e713542189533a52cdfc333f05c3af6 [2] https://github.com/gitpython-developers/GitPython/commit/43d92dec4683568d11495956dd556161f17c3ea8 [3] https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-rpm5-65cw-6hj4 Signed-off-by: Darsh Kelaiya Signed-off-by: Yoann Congal --- .../python3-git/CVE-2026-42215_p1.patch | 60 +++++++++++++++++++ .../python3-git/CVE-2026-42215_p2.patch | 45 ++++++++++++++ .../python/python3-git_3.1.43.bb | 2 + 3 files changed, 107 insertions(+) create mode 100644 meta/recipes-devtools/python/python3-git/CVE-2026-42215_p1.patch create mode 100644 meta/recipes-devtools/python/python3-git/CVE-2026-42215_p2.patch diff --git a/meta/recipes-devtools/python/python3-git/CVE-2026-42215_p1.patch b/meta/recipes-devtools/python/python3-git/CVE-2026-42215_p1.patch new file mode 100644 index 00000000000..0129250fdfc --- /dev/null +++ b/meta/recipes-devtools/python/python3-git/CVE-2026-42215_p1.patch @@ -0,0 +1,60 @@ +From dd5d1c4ddcc5d44faf4e71bcfa338f09db2022d6 Mon Sep 17 00:00:00 2001 +From: w +Date: Mon, 20 Apr 2026 23:29:50 -0400 +Subject: [PATCH] Block unsafe underscored git kwargs / Fix for + GHSA-rpm5-65cw-6hj4 + +CVE: CVE-2026-42215 +Upstream-Status: Backport [https://github.com/gitpython-developers/GitPython/commit/142195888e713542189533a52cdfc333f05c3af6] + +Backport Changes: +- Omitted test/test_clone.py, test/test_git.py, and + test/test_remote.py because the PyPI 3.1.43 source used by the + recipe does not ship the upstream test tree. + +(cherry picked from commit 142195888e713542189533a52cdfc333f05c3af6) +Signed-off-by: Darsh Kelaiya +--- + git/cmd.py | 21 +++++++++++++-------- + 1 file changed, 13 insertions(+), 8 deletions(-) + +diff --git a/git/cmd.py b/git/cmd.py +index 90fc39cd..2ecb8e66 100644 +--- a/git/cmd.py ++++ b/git/cmd.py +@@ -711,6 +711,12 @@ class Git(metaclass=_GitMeta): + f"The `{protocol}::` protocol looks suspicious, use `allow_unsafe_protocols=True` to allow it." + ) + ++ @classmethod ++ def _canonicalize_option_name(cls, option: str) -> str: ++ """Normalize an option or kwarg name for unsafe-option checks.""" ++ option_name = option.lstrip("-").split("=", 1)[0].split(None, 1)[0] ++ return dashify(option_name) ++ + @classmethod + def check_unsafe_options(cls, options: List[str], unsafe_options: List[str]) -> None: + """Check for unsafe options. +@@ -718,15 +724,14 @@ class Git(metaclass=_GitMeta): + Some options that are passed to ``git `` can be used to execute + arbitrary commands. These are blocked by default. + """ +- # Options can be of the form `foo`, `--foo bar`, or `--foo=bar`, so we need to +- # check if they start with "--foo" or if they are equal to "foo". +- bare_unsafe_options = [option.lstrip("-") for option in unsafe_options] ++ # Options can be of the form `foo`, `--foo`, `--foo bar`, or `--foo=bar`. ++ canonical_unsafe_options = {cls._canonicalize_option_name(option): option for option in unsafe_options} + for option in options: +- for unsafe_option, bare_option in zip(unsafe_options, bare_unsafe_options): +- if option.startswith(unsafe_option) or option == bare_option: +- raise UnsafeOptionError( +- f"{unsafe_option} is not allowed, use `allow_unsafe_options=True` to allow it." +- ) ++ unsafe_option = canonical_unsafe_options.get(cls._canonicalize_option_name(option)) ++ if unsafe_option is not None: ++ raise UnsafeOptionError( ++ f"{unsafe_option} is not allowed, use `allow_unsafe_options=True` to allow it." ++ ) + + class AutoInterrupt: + """Process wrapper that terminates the wrapped process on finalization. diff --git a/meta/recipes-devtools/python/python3-git/CVE-2026-42215_p2.patch b/meta/recipes-devtools/python/python3-git/CVE-2026-42215_p2.patch new file mode 100644 index 00000000000..a23fba8d819 --- /dev/null +++ b/meta/recipes-devtools/python/python3-git/CVE-2026-42215_p2.patch @@ -0,0 +1,45 @@ +From 3ee4db90229dbb1fbdc8572dc8219990d70db368 Mon Sep 17 00:00:00 2001 +From: w +Date: Tue, 21 Apr 2026 12:03:20 -0400 +Subject: [PATCH] git.cmd: harden unsafe option canonicalization and isolate + push test cases + +CVE: CVE-2026-42215 +Upstream-Status: Backport [https://github.com/gitpython-developers/GitPython/commit/43d92dec4683568d11495956dd556161f17c3ea8] + +Backport Changes: +- Omitted test/test_remote.py because the PyPI 3.1.43 source used + by the recipe does not ship the upstream test tree. + +(cherry picked from commit 43d92dec4683568d11495956dd556161f17c3ea8) +Signed-off-by: Darsh Kelaiya +--- + git/cmd.py | 15 ++++++++++++--- + 1 file changed, 12 insertions(+), 3 deletions(-) + +diff --git a/git/cmd.py b/git/cmd.py +index 372eac28..a1e77bdb 100644 +--- a/git/cmd.py ++++ b/git/cmd.py +@@ -713,9 +713,18 @@ class Git(metaclass=_GitMeta): + + @classmethod + def _canonicalize_option_name(cls, option: str) -> str: +- """Normalize an option or kwarg name for unsafe-option checks.""" +- option_name = option.lstrip("-").split("=", 1)[0].split(None, 1)[0] +- return dashify(option_name) ++ """Return the option name used for unsafe-option checks. ++ ++ Examples: ++ ``"--upload-pack=/tmp/helper"`` -> ``"upload-pack"`` ++ ``"upload_pack"`` -> ``"upload-pack"`` ++ ``"--config core.filemode=false"`` -> ``"config"`` ++ """ ++ option_name = option.lstrip("-").split("=", 1)[0] ++ option_tokens = option_name.split(None, 1) ++ if not option_tokens: ++ return "" ++ return dashify(option_tokens[0]) + + @classmethod + def check_unsafe_options(cls, options: List[str], unsafe_options: List[str]) -> None: diff --git a/meta/recipes-devtools/python/python3-git_3.1.43.bb b/meta/recipes-devtools/python/python3-git_3.1.43.bb index bfbdd802893..26d9a3f0633 100644 --- a/meta/recipes-devtools/python/python3-git_3.1.43.bb +++ b/meta/recipes-devtools/python/python3-git_3.1.43.bb @@ -13,6 +13,8 @@ PYPI_PACKAGE = "GitPython" inherit pypi python_setuptools_build_meta SRC_URI += "file://CVE-2026-42284.patch \ + file://CVE-2026-42215_p1.patch \ + file://CVE-2026-42215_p2.patch \ " SRC_URI[sha256sum] = "35f314a9f878467f5453cc1fee295c3e18e52f1b99f10f6cf5b1682e968a9e7c" From patchwork Sat Sep 5 20:44:06 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 97356 X-Patchwork-Delegate: yoann.congal@smile.fr Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 14C99C79F8B for ; Sat, 5 Sep 2026 20:45:23 +0000 (UTC) Received: from mail-wm1-f54.google.com (mail-wm1-f54.google.com [209.85.128.54]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.2579.1788641115130455148 for ; Sat, 05 Sep 2026 13:45:15 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=PB3iE++1; spf=pass (domain: smile.fr, ip: 209.85.128.54, mailfrom: yoann.congal@smile.fr) Received: by mail-wm1-f54.google.com with SMTP id 5b1f17b1804b1-49cf4f81d86so16969415e9.2 for ; Sat, 05 Sep 2026 13:45:14 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1788641113; x=1789245913; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=Iu7+4PItGjJNsqQawlPgRFCyy0wBWFk773fBTNrdYVI=; b=PB3iE++1jgecboLX7wlyJUNofuADlsZ/ufxrA+IdhdU7Q6Ds3fvjsXj/XoqHIXMV0E CZiANWUQHaAVFjVquREIEMXfOIAx4VKDoLPx7VMQLM0DYa3coS5tZioWZ4uFREqJx90W SBF5M8A1Vwpuj7+xJsfvj0wxI4Z+O68xztl5g= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1788641113; x=1789245913; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=Iu7+4PItGjJNsqQawlPgRFCyy0wBWFk773fBTNrdYVI=; b=H22DWZKP3ae5cqNxFx3RU68zx/iPdpCs9Y5M3hJiTyges7FE3ipaanIrzuArpFe03W KdjdEkDROBBp5HWP4iF8SWeZhCDrUv0moQqOomoSdU8KcpIhpSr4CWpe4GJOj3LfqjUJ YjjdCAlf6eowNokyx9BlkBxP9Emd28YTgfoMRVoM5IIxPuqW712vRM+oWf1gnCC+KMMx 0PiJ42D899F20Mvr25+oxYA4yVoOZPWetz5XEpqrgBju74mxtX1G3L0pcyoml5ON5VYH DGzZQQkQ2j0SM8OYTKmuQnCDHsHzHjysHuaNdt0jV+hPIn2NXhXTfkq/zww3pnmN6ad4 kFig== X-Gm-Message-State: AFuF++nEyFobRb24fNMYGPG/cs7mPSnX2TQgglGridgDCM7hLqVCOpPL qeq0CO+MtVfG8558LnQm+tRfoLFoV79SVq2PkuRAkXOHfOTTqY3EDaeihHYZyVCmqfEYdzRMvCg FQUAE3Ao= X-Gm-Gg: AYBFou3Qn06dPEHr10b7kv+rmGk6WPAZ17rIx4AolEGeDKOgQ37EJNfmaPks9sOoXcL muTqIvLMWjIm5Nbw9+0NQvuJfVcTA4Wc5fFCqVMwxL5dpCYSwuGgd4Rptpc7hDUP3pm9sTWC983 qM9g9pMALQf6qUp91zzo/2xA2WAFpNAYLz6xOSyoN4bEKny9q+OsI43H5pIm9dZS7dUF8iKXu7K Upg19pMzWcSzFHPcP0zdYprN23Rn+OWl89RfTHB7GQ0hl4CSDn5s04KyinsOiloNWI3NB1gCeUM dOzwhRrtFydDlKAg0oSBKJ8z7UvznroaKDC79qoKKrUiuFZfIlHnoA/Wm8flkaezHhMFY4pfuJH 7CKyjay6VclD2aYabXebhUXNULcNPyfdkDUDkjQThgrO8Gogz5vJhhYP7h99uD4Knbi2c1d1EYw zl/nfdTfb+1odj9JmBv9m/bUGp/7a0boNn/Aci/GjmkAM6WkvZaoA6+0zkSqGB9OQ9jX/QtYCLW FJ+e1OpHmE8bv515ht21/36jq1G4b+CuN/SzfVTutr+gkMgFcaUtAr9i9yaKoOkyw== X-Received: by 2002:a05:600c:a49:b0:49c:fc6c:be0c with SMTP id 5b1f17b1804b1-49cffdc3823mr78812195e9.18.1788641113200; Sat, 05 Sep 2026 13:45:13 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa0048511f7ccf23d3ce.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:4851:1f7c:cf23:d3ce]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-485885bfdf6sm17069098f8f.34.2026.09.05.13.45.12 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sat, 05 Sep 2026 13:45:12 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][wrynose 05/40] python3-git: fix CVE-2026-44243 Date: Sat, 5 Sep 2026 22:44:06 +0200 Message-ID: <241f21be5bdfc295945c278058ce92985a962fec.1788629392.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Sat, 05 Sep 2026 20:45:23 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/245157 From: Darsh Kelaiya This patch applies the upstream fix as referenced in [3], using all the backported commits shown in [1] and [2]. [1] https://github.com/gitpython-developers/GitPython/commit/25ba54dd3fb374b8fade7de4be1ac2ac84722190 [2] https://github.com/gitpython-developers/GitPython/commit/4af8463cca31c2369312fcaa5309dfc30756c7b6 [3] https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-7545-fcxq-7j24 Signed-off-by: Darsh Kelaiya Signed-off-by: Yoann Congal --- .../python3-git/CVE-2026-44243_p1.patch | 134 ++++++++++++++++++ .../python3-git/CVE-2026-44243_p2.patch | 83 +++++++++++ .../python/python3-git_3.1.43.bb | 2 + 3 files changed, 219 insertions(+) create mode 100644 meta/recipes-devtools/python/python3-git/CVE-2026-44243_p1.patch create mode 100644 meta/recipes-devtools/python/python3-git/CVE-2026-44243_p2.patch diff --git a/meta/recipes-devtools/python/python3-git/CVE-2026-44243_p1.patch b/meta/recipes-devtools/python/python3-git/CVE-2026-44243_p1.patch new file mode 100644 index 00000000000..7eaaf703db4 --- /dev/null +++ b/meta/recipes-devtools/python/python3-git/CVE-2026-44243_p1.patch @@ -0,0 +1,134 @@ +From 84b84e90d1ce0b35d627bee6c65f3218c72a53f5 Mon Sep 17 00:00:00 2001 +From: "GPT 5.5" +Date: Tue, 28 Apr 2026 09:17:31 +0800 +Subject: [PATCH] prevent out-of-repo access when manipulating references. + +This previously made it possible to create, modify and delete files outside outside +of the repository, which is a problem if inputs aren't trusted. + +CVE: CVE-2026-44243 +Upstream-Status: Backport [https://github.com/gitpython-developers/GitPython/commit/25ba54dd3fb374b8fade7de4be1ac2ac84722190] + +Backport Changes: +- Omitted test/test_refs.py because the PyPI 3.1.43 source used by + the recipe does not ship the upstream test tree. + +Co-authored-by: Sebastian Thiel +(cherry picked from commit 25ba54dd3fb374b8fade7de4be1ac2ac84722190) +Signed-off-by: Darsh Kelaiya +--- + git/refs/log.py | 2 +- + git/refs/remote.py | 5 +++-- + git/refs/symbolic.py | 37 +++++++++++++++++++++++++++++++------ + 3 files changed, 35 insertions(+), 9 deletions(-) + +diff --git a/git/refs/log.py b/git/refs/log.py +index 17e3a94b..88906758 100644 +--- a/git/refs/log.py ++++ b/git/refs/log.py +@@ -213,7 +213,7 @@ class RefLog(List[RefLogEntry], Serializable): + :param ref: + :class:`~git.refs.symbolic.SymbolicReference` instance + """ +- return osp.join(ref.repo.git_dir, "logs", to_native_path(ref.path)) ++ return to_native_path(ref._get_validated_reflog_path(ref.repo, ref.path)) + + @classmethod + def iter_entries(cls, stream: Union[str, "BytesIO", mmap]) -> Iterator[RefLogEntry]: +diff --git a/git/refs/remote.py b/git/refs/remote.py +index b4f4f7b3..8244470b 100644 +--- a/git/refs/remote.py ++++ b/git/refs/remote.py +@@ -63,12 +63,13 @@ class RemoteReference(Head): + # generally ignored in the refs/ folder. We don't though and delete remainders + # manually. + for ref in refs: ++ cls._check_ref_name_valid(ref.path) + try: +- os.remove(os.path.join(repo.common_dir, ref.path)) ++ os.remove(cls._get_validated_path(repo.common_dir, ref.path)) + except OSError: + pass + try: +- os.remove(os.path.join(repo.git_dir, ref.path)) ++ os.remove(cls._get_validated_path(repo.git_dir, ref.path)) + except OSError: + pass + # END for each ref +diff --git a/git/refs/symbolic.py b/git/refs/symbolic.py +index 510850b2..ba24f2c2 100644 +--- a/git/refs/symbolic.py ++++ b/git/refs/symbolic.py +@@ -109,6 +109,32 @@ class SymbolicReference: + def abspath(self) -> PathLike: + return join_path_native(_git_dir(self.repo, self.path), self.path) + ++ @staticmethod ++ def _get_validated_path(base: PathLike, path: PathLike) -> str: ++ path = os.fspath(path) ++ base_path = os.path.realpath(os.fspath(base)) ++ abs_path = os.path.realpath(os.path.join(base_path, path)) ++ try: ++ common_path = os.path.commonpath([base_path, abs_path]) ++ except ValueError as e: ++ raise ValueError("Reference path %r escapes the repository" % path) from e ++ if os.path.normcase(common_path) != os.path.normcase(base_path): ++ raise ValueError("Reference path %r escapes the repository" % path) ++ return abs_path ++ ++ @classmethod ++ def _get_validated_ref_path(cls, repo: "Repo", path: PathLike) -> str: ++ """Return the absolute filesystem path for a ref after validating it.""" ++ cls._check_ref_name_valid(path) ++ ref_path = os.fspath(path) ++ return cls._get_validated_path(_git_dir(repo, ref_path), ref_path) ++ ++ @classmethod ++ def _get_validated_reflog_path(cls, repo: "Repo", path: PathLike) -> str: ++ """Return the absolute filesystem path for a reflog after validating it.""" ++ cls._check_ref_name_valid(path) ++ return cls._get_validated_path(os.path.join(repo.git_dir, "logs"), path) ++ + @classmethod + def _get_packed_refs_path(cls, repo: "Repo") -> str: + return os.path.join(repo.common_dir, "packed-refs") +@@ -478,7 +504,7 @@ class SymbolicReference: + # END handle non-existing + # END retrieve old hexsha + +- fpath = self.abspath ++ fpath = self._get_validated_ref_path(self.repo, self.path) + assure_directory_exists(fpath, is_file=True) + + lfd = LockedFD(fpath) +@@ -623,7 +649,7 @@ class SymbolicReference: + Alternatively the symbolic reference to be deleted. + """ + full_ref_path = cls.to_full_path(path) +- abs_path = os.path.join(repo.common_dir, full_ref_path) ++ abs_path = cls._get_validated_ref_path(repo, full_ref_path) + if os.path.exists(abs_path): + os.remove(abs_path) + else: +@@ -686,9 +712,8 @@ class SymbolicReference: + symbolic reference. Otherwise it will be resolved to the corresponding object + and a detached symbolic reference will be created instead. + """ +- git_dir = _git_dir(repo, path) + full_ref_path = cls.to_full_path(path) +- abs_ref_path = os.path.join(git_dir, full_ref_path) ++ abs_ref_path = cls._get_validated_ref_path(repo, full_ref_path) + + # Figure out target data. + target = reference +@@ -780,8 +805,8 @@ class SymbolicReference: + if self.path == new_path: + return self + +- new_abs_path = os.path.join(_git_dir(self.repo, new_path), new_path) +- cur_abs_path = os.path.join(_git_dir(self.repo, self.path), self.path) ++ new_abs_path = self._get_validated_ref_path(self.repo, new_path) ++ cur_abs_path = self._get_validated_ref_path(self.repo, self.path) + if os.path.isfile(new_abs_path): + if not force: + # If they point to the same file, it's not an error. diff --git a/meta/recipes-devtools/python/python3-git/CVE-2026-44243_p2.patch b/meta/recipes-devtools/python/python3-git/CVE-2026-44243_p2.patch new file mode 100644 index 00000000000..04e83d36574 --- /dev/null +++ b/meta/recipes-devtools/python/python3-git/CVE-2026-44243_p2.patch @@ -0,0 +1,83 @@ +From 4ab42809cb34222b1c574c07e083a4008e97d8de Mon Sep 17 00:00:00 2001 +From: "GPT 5.5" +Date: Tue, 28 Apr 2026 09:30:41 +0800 +Subject: [PATCH] address review feedback and CI failures + +Consolidate follow-up fixes from review and CI: + +- fix lint and mypy issues in reference log path handling +- validate remote reference paths before invoking git branch deletion +- add symlink escape coverage where realpath resolves symlinks +- ensure temporary test repositories release git resources during cleanup + +CVE: CVE-2026-44243 +Upstream-Status: Backport [https://github.com/gitpython-developers/GitPython/commit/4af8463cca31c2369312fcaa5309dfc30756c7b6] + +Backport Changes: +- Omitted test/test_refs.py because the PyPI 3.1.43 source used by + the recipe does not ship the upstream test tree. + +Co-authored-by: Sebastian Thiel +(cherry picked from commit 4af8463cca31c2369312fcaa5309dfc30756c7b6) +Signed-off-by: Darsh Kelaiya +--- + git/refs/log.py | 4 +++- + git/refs/remote.py | 4 +++- + git/util.py | 2 +- + 3 files changed, 7 insertions(+), 3 deletions(-) + +diff --git a/git/refs/log.py b/git/refs/log.py +index 88906758..642b1825 100644 +--- a/git/refs/log.py ++++ b/git/refs/log.py +@@ -4,7 +4,6 @@ + __all__ = ["RefLog", "RefLogEntry"] + + from mmap import mmap +-import os.path as osp + import re + import time as _time + +@@ -212,6 +211,9 @@ class RefLog(List[RefLogEntry], Serializable): + + :param ref: + :class:`~git.refs.symbolic.SymbolicReference` instance ++ ++ :raise ValueError: ++ If `ref.path` is invalid or escapes the repository's reflog directory. + """ + return to_native_path(ref._get_validated_reflog_path(ref.repo, ref.path)) + +diff --git a/git/refs/remote.py b/git/refs/remote.py +index 8244470b..e16ae70f 100644 +--- a/git/refs/remote.py ++++ b/git/refs/remote.py +@@ -58,12 +58,14 @@ class RemoteReference(Head): + `kwargs` are given for comparability with the base class method as we + should not narrow the signature. + """ ++ for ref in refs: ++ cls._check_ref_name_valid(ref.path) ++ + repo.git.branch("-d", "-r", *refs) + # The official deletion method will ignore remote symbolic refs - these are + # generally ignored in the refs/ folder. We don't though and delete remainders + # manually. + for ref in refs: +- cls._check_ref_name_valid(ref.path) + try: + os.remove(cls._get_validated_path(repo.common_dir, ref.path)) + except OSError: +diff --git a/git/util.py b/git/util.py +index 8c1c2601..27b239ab 100644 +--- a/git/util.py ++++ b/git/util.py +@@ -289,7 +289,7 @@ def join_path(a: PathLike, *p: PathLike) -> PathLike: + + if sys.platform == "win32": + +- def to_native_path_windows(path: PathLike) -> PathLike: ++ def to_native_path_windows(path: PathLike) -> str: + path = str(path) + return path.replace("/", "\\") + diff --git a/meta/recipes-devtools/python/python3-git_3.1.43.bb b/meta/recipes-devtools/python/python3-git_3.1.43.bb index 26d9a3f0633..ef4f7fa18ca 100644 --- a/meta/recipes-devtools/python/python3-git_3.1.43.bb +++ b/meta/recipes-devtools/python/python3-git_3.1.43.bb @@ -15,6 +15,8 @@ inherit pypi python_setuptools_build_meta SRC_URI += "file://CVE-2026-42284.patch \ file://CVE-2026-42215_p1.patch \ file://CVE-2026-42215_p2.patch \ + file://CVE-2026-44243_p1.patch \ + file://CVE-2026-44243_p2.patch \ " SRC_URI[sha256sum] = "35f314a9f878467f5453cc1fee295c3e18e52f1b99f10f6cf5b1682e968a9e7c" From patchwork Sat Sep 5 20:44:07 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 97360 X-Patchwork-Delegate: yoann.congal@smile.fr Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id E012BC79FA2 for ; Sat, 5 Sep 2026 20:45:23 +0000 (UTC) Received: from mail-wr1-f49.google.com (mail-wr1-f49.google.com [209.85.221.49]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.2580.1788641115699713000 for ; Sat, 05 Sep 2026 13:45:16 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=OaPDzCWh; spf=pass (domain: smile.fr, ip: 209.85.221.49, mailfrom: yoann.congal@smile.fr) Received: by mail-wr1-f49.google.com with SMTP id ffacd0b85a97d-48441fa5c37so1537211f8f.3 for ; Sat, 05 Sep 2026 13:45:15 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1788641114; x=1789245914; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=V4F6lnvIt0soc68nFN+zdVKMBcP16kCA9MDhoYu4c24=; b=OaPDzCWhGJCuJWLvf46CpvZMmGeXZUUI80Ybu4duLRolpwszzxbthHtgEnJJCoCosG RFNm4XujC05HpOwI2b1TUp8FgeGZh/erDlk5clMLtTo12+S87u1gHXyir5/5okBvpYb1 mPXAkS1uoc4p8d/aftgzY9l4hXhR+PXeL7bjM= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1788641114; x=1789245914; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=V4F6lnvIt0soc68nFN+zdVKMBcP16kCA9MDhoYu4c24=; b=qN3ODH4Nk/KoYI1yOq9YUqfI7kxe6wxDLD8B+1GehzMuSfSKn/4I/VtkN4yhXyXWGk ZHrtkCAJkNSPd7BhnjIxt5LNxW55maUdM1tfMpJ0bE3UUbQgCO7IDzdlvUdoQJCqss+P PhdSehWMEvzrR0lo2wYq2OD6uMMcj5HWp8AdvT6Y226flZ76KiHKHh8cXWWyLpE7LqXV ZsiioenVntjBq71UTF7kfXBiAOl4FOpyOi3gG/S1R4MQAWgntRc5l8OLwh7IVtoE7Dvp 0OzOAMMhubwU/KccpnYmLbnYE+WEAUQiVvP+2jHrV7+ua5NRqarh4Lt9Q6xIRfiOmDcJ JDCA== X-Gm-Message-State: AFuF++n3ey65eL9fmIDwfuJuughqtcRjJx3gz95a31RW7Av1zJnmWq4e +o0by16JgJBUdQXzq9tqE8Yoe6sWWyX3fCJWxJQWPENik5llQt7EAJpyNF0Gs1vj9ZAV2/N15sU lopMrZk4= X-Gm-Gg: AYBFou0ZPxYPxxiIlmCPQXyt0/KkFA579FKkk2rE/vbYkR17cbUY6CNx6bI3YofewVP aGunocoK6lyN648YZN/7RCn8B7Hw4xH0cwyUWr2hmxAFT59kglNhFL52QtL4fl4NpPRe5U6YfQK NJLUwmh1C4/FVYWCVPsVntvarwA6HGvdPEVJHUhXFdQzQw3pJqxktfM58+AmAeY+T3atzZxYr7p MjVQP5Bn6H5+58MReNsH8bp/thUIVtbHykRGuHEFo6+m15lYoBptuMQxtxIkjEz04/VnWNZdFX2 P8vi9lf/rFuLvnHUjbBglbpkxOw3JLcmNEueDgKJH3Ncby09SRR6atRaURi6tLIjhBbNpFXHhOm b2KX0tbreyYPWwXv1h014Njl7nTYPfASfPZljYbmVzTjIF5A1VyonIgApV3EeIR3Ei3ejb2C7uG wyBxen9sHoOD6HDQzeThVY6urOM/RcMDW/NAZaryL7XMvlxGrxozkO6409A4u8tkE7FJHq+rCA0 M/WZqVny0MPYS7vGAQhAUX+OzFswt4cMuy99MA4t/bEwE9Fek+NHd7+7sYHerEQaw== X-Received: by 2002:a05:6000:2f87:b0:485:8a46:b3c1 with SMTP id ffacd0b85a97d-4858a46b520mr13415023f8f.41.1788641113867; Sat, 05 Sep 2026 13:45:13 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa0048511f7ccf23d3ce.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:4851:1f7c:cf23:d3ce]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-485885bfdf6sm17069098f8f.34.2026.09.05.13.45.13 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sat, 05 Sep 2026 13:45:13 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][wrynose 06/40] python3-git: fix CVE-2026-44244 Date: Sat, 5 Sep 2026 22:44:07 +0200 Message-ID: <4037ac7b4fd7add97ccf76e87b361190cb89503e.1788629392.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Sat, 05 Sep 2026 20:45:23 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/245158 From: Darsh Kelaiya This patch applies the upstream fix as referenced in [3], using all the backported commits shown in [1] and [2]. [1] https://github.com/gitpython-developers/GitPython/commit/c417af469f9aa3da8dfef78f996c0fb8c5d1f4c2 [2] https://github.com/gitpython-developers/GitPython/commit/8e24503b42c1d63dd98e8b2e6a2f655bdd0821e3 [3] https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-v87r-6q3f-2j67 Signed-off-by: Darsh Kelaiya Signed-off-by: Yoann Congal --- .../python3-git/CVE-2026-44244_p1.patch | 102 ++++++++++++++++++ .../python3-git/CVE-2026-44244_p2.patch | 28 +++++ .../python/python3-git_3.1.43.bb | 2 + 3 files changed, 132 insertions(+) create mode 100644 meta/recipes-devtools/python/python3-git/CVE-2026-44244_p1.patch create mode 100644 meta/recipes-devtools/python/python3-git/CVE-2026-44244_p2.patch diff --git a/meta/recipes-devtools/python/python3-git/CVE-2026-44244_p1.patch b/meta/recipes-devtools/python/python3-git/CVE-2026-44244_p1.patch new file mode 100644 index 00000000000..66ba5e96976 --- /dev/null +++ b/meta/recipes-devtools/python/python3-git/CVE-2026-44244_p1.patch @@ -0,0 +1,102 @@ +From 4ac5a1c848582f606655d03bfbc1243fe1754dc8 Mon Sep 17 00:00:00 2001 +From: "GPT 5.5" +Date: Wed, 29 Apr 2026 05:47:57 +0800 +Subject: [PATCH] reject control chars in written values in configuration + +Reject CR, LF, and NUL in GitConfigParser values before writing them +to git config files (which also is a deviation from Git which escapes them). + +GitConfigParser._write() serializes embedded newlines as indented +continuation lines by replacing "\n" with "\n\t". Git itself skips +leading whitespace before parsing config tokens, so an injected value +such as: + + foo + [core] + hooksPath=/tmp/hooks + +is written in a form where the indented "[core]" line is still parsed by +Git as a real section header. This lets attacker-controlled input passed +to config_writer().set_value() poison repository config, including +core.hooksPath, and redirect hook execution for later Git operations. + +Fail closed instead of stripping or normalizing these characters. Silent +normalization can hide unsanitized caller input, and GitPython does not +currently round-trip Git-style escaped values such as "\n" as embedded +newlines. + +Apply the validation to set_value(), add_value(), and the public set() +path so callers cannot bypass the safer helper API. Add regression tests +for the advisory payload and for CR, LF, NUL, and bytes values. + +This preserves existing read behavior for config files that already +contain multiline values while preventing GitPython from writing new +unsafe values. + +CVE: CVE-2026-44244 +Upstream-Status: Backport [https://github.com/gitpython-developers/GitPython/commit/c417af469f9aa3da8dfef78f996c0fb8c5d1f4c2] + +Backport Changes: +- Omitted test/test_config.py because the PyPI 3.1.43 source used + by the recipe does not ship the upstream test tree. + +Co-authored-by: Sebastian Thiel +(cherry picked from commit c417af469f9aa3da8dfef78f996c0fb8c5d1f4c2) +Signed-off-by: Darsh Kelaiya +--- + git/config.py | 24 ++++++++++++++++++++++-- + 1 file changed, 22 insertions(+), 2 deletions(-) + +diff --git a/git/config.py b/git/config.py +index 3ce9b123..d45cc31b 100644 +--- a/git/config.py ++++ b/git/config.py +@@ -863,6 +863,24 @@ class GitConfigParser(cp.RawConfigParser, metaclass=MetaParserBuilder): + return str(value) + return force_text(value) + ++ def _value_to_string_safe(self, value: Union[str, bytes, int, float, bool]) -> str: ++ value_str = self._value_to_string(value) ++ if re.search(r"[\r\n\x00]", value_str): ++ raise ValueError("Git config values must not contain CR, LF, or NUL") ++ return value_str ++ ++ @needs_values ++ @set_dirty_and_flush_changes ++ def set( ++ self, ++ section: str, ++ option: str, ++ value: Union[str, bytes, int, float, bool, None] = None, ++ ) -> None: ++ if value is not None: ++ value = self._value_to_string_safe(value) ++ return super().set(section, option, value) ++ + @needs_values + @set_dirty_and_flush_changes + def set_value(self, section: str, option: str, value: Union[str, bytes, int, float, bool]) -> "GitConfigParser": +@@ -883,9 +901,10 @@ class GitConfigParser(cp.RawConfigParser, metaclass=MetaParserBuilder): + :return: + This instance + """ ++ value_str = self._value_to_string_safe(value) + if not self.has_section(section): + self.add_section(section) +- self.set(section, option, self._value_to_string(value)) ++ self.set(section, option, value_str) + return self + + @needs_values +@@ -910,9 +929,10 @@ class GitConfigParser(cp.RawConfigParser, metaclass=MetaParserBuilder): + :return: + This instance + """ ++ value_str = self._value_to_string_safe(value) + if not self.has_section(section): + self.add_section(section) +- self._sections[section].add(option, self._value_to_string(value)) ++ self._sections[section].add(option, value_str) + return self + + def rename_section(self, section: str, new_name: str) -> "GitConfigParser": diff --git a/meta/recipes-devtools/python/python3-git/CVE-2026-44244_p2.patch b/meta/recipes-devtools/python/python3-git/CVE-2026-44244_p2.patch new file mode 100644 index 00000000000..43aea2fd565 --- /dev/null +++ b/meta/recipes-devtools/python/python3-git/CVE-2026-44244_p2.patch @@ -0,0 +1,28 @@ +From cfa5a26453544e93be3689101e710b6b07a6e2b0 Mon Sep 17 00:00:00 2001 +From: "GPT 5.5" +Date: Wed, 29 Apr 2026 06:39:02 +0800 +Subject: [PATCH] avoid duplicate validation in set_value + +CVE: CVE-2026-44244 +Upstream-Status: Backport [https://github.com/gitpython-developers/GitPython/commit/8e24503b42c1d63dd98e8b2e6a2f655bdd0821e3] + +Co-authored-by: Sebastian Thiel +(cherry picked from commit 8e24503b42c1d63dd98e8b2e6a2f655bdd0821e3) +Signed-off-by: Darsh Kelaiya +--- + git/config.py | 2 +- + 1 file changed, 1 insertion(+), 1 deletion(-) + +diff --git a/git/config.py b/git/config.py +index d45cc31b..1595d51f 100644 +--- a/git/config.py ++++ b/git/config.py +@@ -904,7 +904,7 @@ class GitConfigParser(cp.RawConfigParser, metaclass=MetaParserBuilder): + value_str = self._value_to_string_safe(value) + if not self.has_section(section): + self.add_section(section) +- self.set(section, option, value_str) ++ super().set(section, option, value_str) + return self + + @needs_values diff --git a/meta/recipes-devtools/python/python3-git_3.1.43.bb b/meta/recipes-devtools/python/python3-git_3.1.43.bb index ef4f7fa18ca..7534531fa37 100644 --- a/meta/recipes-devtools/python/python3-git_3.1.43.bb +++ b/meta/recipes-devtools/python/python3-git_3.1.43.bb @@ -17,6 +17,8 @@ SRC_URI += "file://CVE-2026-42284.patch \ file://CVE-2026-42215_p2.patch \ file://CVE-2026-44243_p1.patch \ file://CVE-2026-44243_p2.patch \ + file://CVE-2026-44244_p1.patch \ + file://CVE-2026-44244_p2.patch \ " SRC_URI[sha256sum] = "35f314a9f878467f5453cc1fee295c3e18e52f1b99f10f6cf5b1682e968a9e7c" From patchwork Sat Sep 5 20:44:08 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 97361 X-Patchwork-Delegate: yoann.congal@smile.fr Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 3A53CC79FA5 for ; Sat, 5 Sep 2026 20:45:24 +0000 (UTC) Received: from mail-wr1-f50.google.com (mail-wr1-f50.google.com [209.85.221.50]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.2477.1788641116188672438 for ; Sat, 05 Sep 2026 13:45:16 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=WsOpyMee; spf=pass (domain: smile.fr, ip: 209.85.221.50, mailfrom: yoann.congal@smile.fr) Received: by mail-wr1-f50.google.com with SMTP id ffacd0b85a97d-48436216a98so1433537f8f.0 for ; Sat, 05 Sep 2026 13:45:15 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1788641114; x=1789245914; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=RG+UGz8kXCbmcT8X6CUUhIu6t/5vULHBXWDs6krkAGU=; b=WsOpyMeeQU9RH2k02GVp6gFZ6WG81BiwR/eIdvlVIs936JRqlsrhQQpj++Z+bockxx GFpxduyKBZyGXUfyoe6r2L744sNNHMB9bnYZ2fXG1Ew1DbrlC4cPUfgJL7mLo8zrOtYw o8bFiM7SxTISyrvoALn73/sbSBTYXRBd5NEXQ= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1788641114; x=1789245914; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=RG+UGz8kXCbmcT8X6CUUhIu6t/5vULHBXWDs6krkAGU=; b=jFFPc4KyOtGz0IlkmoRUVleM6t2VmxYF8kWs9Jqmj6jkc/mSf051tzY6Lc+uQdHGys 2Iy8ml0xnW80bFWl6STZt/DO+17gWOuXLgRqebO2mBQHXGKQdERgzYlW2gYv0iOUcGOh uKnpasZPFJQYxRj3+Vw0deixIrebShjgs7xmdy8+mxt71gacgtSVgy/jlFv049AODJBf Xpeff9Etjhyqc/qHd5xFvdLTsIUZzb5boaJCwMi2keHaBAFaCbCiuWkYJXKzLRjb44Kt NXTtyc1wGyn62zUuKjAjUeCYi1mN378adZFZMfswe4h2UOH9Rtpn1FaE5SZAWz7edIKJ C17w== X-Gm-Message-State: AFuF++mD6VevpnAgzEwr5V7zBV3L34jp+fyEpkH2qud+UnBuHCBMNG1w /9h34eU4hYJJ4h41N8NuPRLSnpbeNV7/2GroJbN8qakygFZTZroSwmZCnEmRh7Bm8XyJZi8VmWt 80l4E7pk= X-Gm-Gg: AYBFou0eKOlaWuf+6UWlzCmLhoIrMR9vywBNIDzV47O4zziVO2pME/ZvvIz4DGz9ABs hgIOm9VYlCaC2c0+UGvrLg1Dxf+fmXFgajDd8tp7Mc9Bij0pybL+Kv2pAFxzvtMFNxhd09STUZF JfYAZo/ahcrFQs8fevhfLoiC4TUOUjbXyT54kQAuwu78Zv8kTeGlB3CEWe8QS3DBDCDcM9/2qFt qkbj8Dzo8HQU3kXVr5Nzx/DhKPNqo4dJMy6p2RbizYPM+UOmDqxhP3rMp4lwD57PsdMDGFu/Eeh i9XUc4gi/Uis1e3moG1rhOZBN5EHFOqQAGZGnKCWvInmCiaBnQLf+LIvn5SgWWyzDuDhx+EhRbo sKHy11bm1Slh/kIi2ntkMrpM0GMyQS4d9SFhJPzlvK35m2aQRU/caH5AV9vpbNMs4hSka2upP/V R69w2OGPiJaTH17dQQBZXPimhNKH1maGVqMTQ9hYFaaROdUSj2D6SjE0PmyvvEKpZ0MiCpo4nv/ BJ9KqX6exOrAsRfUrVe4/R0aBfuYtvOOm4qDjJcXjpdUhB08tuIbQBQA1EvgBJ6E72iqlKYlznr X-Received: by 2002:a05:6000:2887:b0:485:8c17:9776 with SMTP id ffacd0b85a97d-4858c179a5dmr11581527f8f.56.1788641114408; Sat, 05 Sep 2026 13:45:14 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa0048511f7ccf23d3ce.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:4851:1f7c:cf23:d3ce]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-485885bfdf6sm17069098f8f.34.2026.09.05.13.45.13 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sat, 05 Sep 2026 13:45:14 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][wrynose 07/40] python3-babel: fix CVE_PRODUCT Date: Sat, 5 Sep 2026 22:44:08 +0200 Message-ID: <9ac57f02e908cb8a110463ed7018ab0fbc8d3211.1788629392.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Sat, 05 Sep 2026 20:45:24 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/245159 From: Tim Orling Recipe (PV): python3-babel (2.18.0) Before -> After: python:babel -> pocoo:babel Newly caught CVEs: CVE-2021-42771 (locale .dat deserialization RCE) Status: patched (fixed 2.9.1) AI-Generated: Claude Sonnet 5 Signed-off-by: Tim Orling Signed-off-by: Richard Purdie (cherry picked from commit 134175fa92b85e639dc4646d9a88eeaba0fae4d3) Signed-off-by: Devansh Patel Signed-off-by: Yoann Congal --- meta/recipes-devtools/python/python3-babel_2.18.0.bb | 2 ++ 1 file changed, 2 insertions(+) diff --git a/meta/recipes-devtools/python/python3-babel_2.18.0.bb b/meta/recipes-devtools/python/python3-babel_2.18.0.bb index b0abb2c62e7..26847372bf3 100644 --- a/meta/recipes-devtools/python/python3-babel_2.18.0.bb +++ b/meta/recipes-devtools/python/python3-babel_2.18.0.bb @@ -7,6 +7,8 @@ SRC_URI[sha256sum] = "b80b99a14bd085fcacfa15c9165f651fbb3406e66cc603abf11c575093 inherit pypi setuptools3 +CVE_PRODUCT = "pocoo:babel" + S = "${UNPACKDIR}/babel-${PV}" CLEANBROKEN = "1" From patchwork Sat Sep 5 20:44:09 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 97363 X-Patchwork-Delegate: yoann.congal@smile.fr Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 8C695C79FA4 for ; Sat, 5 Sep 2026 20:45:24 +0000 (UTC) Received: from mail-wr1-f47.google.com (mail-wr1-f47.google.com [209.85.221.47]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.2581.1788641116659219036 for ; Sat, 05 Sep 2026 13:45:16 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=wEOjMgOP; spf=pass (domain: smile.fr, ip: 209.85.221.47, mailfrom: yoann.congal@smile.fr) Received: by mail-wr1-f47.google.com with SMTP id ffacd0b85a97d-484362f5c4aso2712072f8f.3 for ; Sat, 05 Sep 2026 13:45:16 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1788641115; x=1789245915; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=peBnaLETSgZdTDgcIoWdCy2eygQD2Kqw8OZuv73D87M=; b=wEOjMgOP8e8fz+WlMiEiWmObMNK3SRXMAo4ZNT5JEpny+AarSi7Bc4HmE0lnn/92UK 12HhFpzUPLa93ZX1fm6WnlrUY3Fm//QTjwRUQtF7eH6d0jQTOCmlfeCoO+gW7dwHhAw+ MHrGRXkkF04rK+2/F39ssIABpzXYKf76Ew2gA= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1788641115; x=1789245915; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=peBnaLETSgZdTDgcIoWdCy2eygQD2Kqw8OZuv73D87M=; b=sjF5nZ37jobAYxa0PlBLpKouCSB2IqEpfYOFc6DmYavXazmJDFdbL6ZAArGUhtm21c liL67Bn3Hf5zG+PxbLtGlXNuzDvqgDQPxVHYEBiQ5bR7a/GO4v8/UM7b+XlVd3ox8Y50 mYu2y5qhDFo0sjaNBcdAvgEklC+l94bqYv2UGd5WngY2F1NQ9ff4BGwpYZOoxD6Bt1MV ycNnILxIyx62HhaUWrsg+kUdrMLYkUcZxPuYAnacV7NhzRVfEsHiiY5vJoXl6Q+2G7nK ZeGwE4xBYU3iOk5Mw2CzVS+mgaKoEDaBKXFyK/pYcrhZVmOq9DYxNynUqeodlZRHYjpY riEA== X-Gm-Message-State: AFuF++kYYEuJErbERQWNd/K808QoiQK9rCNYl1o3iMb45mURt9o+1coQ bzDE/xSlN7qXjFyHFlR2mFNVtwqlIyM6AJ94FxuibRXVNtq3uMGa4u5mZZC0LAPV19m1rxTQqdz avatlytQ= X-Gm-Gg: AYBFou3A5D2/ULzl/5VSvDgBeio1HPGzh/gHOk0zu/HCoKuHOuqgz4bYMjHoCewEa30 1aVdz0Mrz01WcgclLmWQyG3CRDGMQItcN8Ni1F4hMK8YWSKKJGMLEkUs3kYNHl4fFNttKo91zA1 RayF0vV0T5fAy52rVguGa1HFZAN+waXNSZyEycHDCX/bZTuz/PqDU7RhygowD+A0WhrUbpE9nxS SsNnbkEqJwT+ze3ftkSE6Pdourxp8NqWo0Sq4FMb6qIDFxiCQvomRWgtkUr8/JTuElzo5qasatp iR2d9LJ8+3qOnvtzuAYTAAWDOW5vPg82naP/9r1tkiVEAZpogzwtdZYn52gm1w7QVjqm42CyWZz XuvIZ+xUoh9HLgXoqOedZj7nWXDjzMhqHFr3x+Fi1LUCcGFyFdE8G2DEUPFTDRtV5rwpVXIUwU1 zkmmX9hPacVL73kd8MzefZUwTBjkgQGgPej1oIDfRrSKtwdaWj28UsA8Flq/dVwdDpFSDSIhVqp V7atRa+xmaHaDlpa+sxpGHJyEEu/UL0BrWDePAYvlWiQjT86Im87Ody99y5mVoo7g== X-Received: by 2002:a05:6000:4302:b0:485:96ac:5a96 with SMTP id ffacd0b85a97d-48596ac5acbmr2675856f8f.16.1788641114941; Sat, 05 Sep 2026 13:45:14 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa0048511f7ccf23d3ce.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:4851:1f7c:cf23:d3ce]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-485885bfdf6sm17069098f8f.34.2026.09.05.13.45.14 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sat, 05 Sep 2026 13:45:14 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][wrynose 08/40] python3-pycryptodome: fix CVE_PRODUCT Date: Sat, 5 Sep 2026 22:44:09 +0200 Message-ID: <0101640bbeb3a093a5b62c230d06752d85836959.1788629392.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Sat, 05 Sep 2026 20:45:24 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/245160 From: Tim Orling With this change, 2 Patched CVEs are properly reported: * CVE-2018-15560 * CVE-2023-52323 Signed-off-by: Tim Orling Signed-off-by: Mathieu Dubois-Briand Signed-off-by: Richard Purdie (cherry picked from commit f8a88010edc6edbb168cbc31aa5df847a328661c) The current pypi default "python:pycryptodome" is deprecated and does not match current NVD configuration criteria. Use "pycryptodome:pycryptodome", the active NVD dictionary CPE and configuration identity for the packaged source, so two patched CVE records are reported. Signed-off-by: Devansh Patel Signed-off-by: Yoann Congal --- meta/recipes-devtools/python/python3-pycryptodome_3.23.0.bb | 1 + 1 file changed, 1 insertion(+) diff --git a/meta/recipes-devtools/python/python3-pycryptodome_3.23.0.bb b/meta/recipes-devtools/python/python3-pycryptodome_3.23.0.bb index 2528162ff8a..1b2a5edd38c 100644 --- a/meta/recipes-devtools/python/python3-pycryptodome_3.23.0.bb +++ b/meta/recipes-devtools/python/python3-pycryptodome_3.23.0.bb @@ -3,3 +3,4 @@ inherit python_setuptools_build_meta SRC_URI[sha256sum] = "447700a657182d60338bab09fdb27518f8856aecd80ae4c6bdddb67ff5da44ef" +CVE_PRODUCT = "pycryptodome:pycryptodome" From patchwork Sat Sep 5 20:44:10 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 97362 X-Patchwork-Delegate: yoann.congal@smile.fr Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id AD5BBC79FA6 for ; Sat, 5 Sep 2026 20:45:24 +0000 (UTC) Received: from mail-wr1-f44.google.com (mail-wr1-f44.google.com [209.85.221.44]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.2478.1788641117337472967 for ; Sat, 05 Sep 2026 13:45:17 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=MZRVlCGq; spf=pass (domain: smile.fr, ip: 209.85.221.44, mailfrom: yoann.congal@smile.fr) Received: by mail-wr1-f44.google.com with SMTP id ffacd0b85a97d-4858595f997so1316206f8f.1 for ; Sat, 05 Sep 2026 13:45:17 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1788641115; x=1789245915; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=JuGOWq1MTVGP1p0+5pl/wpq+KY5FNGxnNYoIY4Nl7LU=; b=MZRVlCGqHZA/3w1ZE+3QL/Jv/W1zSP5kQPJa1ZP1W59IZdgQnfU5Nn1a7ZrIvSxk2a pnduevGPXlgi63ZHf5GRD23FWRZvGC2KXDVCGC8oLTa6IOV9s1YfWw1vU8zyRLQMen3s oJ1Xr3ra8SWnt2B/9mGd1gDvBK2T7uVqncgOw= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1788641115; x=1789245915; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=JuGOWq1MTVGP1p0+5pl/wpq+KY5FNGxnNYoIY4Nl7LU=; b=bkEF+FkpfG936dR6kjE5RCvzT5J3m06ciE+LqHDvMacHhc5SDjIqaLkz2eEhvmkY1u ATsEuw/w0EctRLtJJHc7mgf2fOXbmURqsoeAwSllyD9A2xpbWHTxg4VSfx6OO6y2QZsm lFo49hZBXsaEG7qIvo2dGhamzKBinQ4XIyS5njtNTtrs1p6VhQQqc4HHGP5DG1OJhGVe ocq9T9GNt77DCJcpk5X5V1IqTI1roehyaTl+RdQA97DdWcvGT3T9250wU9D1tq9MJgK5 zJx0jJddncNqFz970BA8OxgrAwGEarBb7vCgKPVYCSZa3BmHbHeVPEqCbnQCXtPWyzd4 fbzw== X-Gm-Message-State: AFuF++kH7QLD51wH3JtJMkYzPBj9xZaC2/QGV2IOZ8NF1reqA5Zf3Vtc q0NDVTVcF6bI552IuuWjYP7/OD7HiwQi8bp2pK3cDn2bTSf8W8NHYbc1cfLFUAaDo1nK7D13k4r vlA0RJ6I= X-Gm-Gg: AYBFou2A5UkJxW+fnU0Jj8VceQFBT0JiaGOzDSMXrsguCq0T0V/Xi372fZG4qg9Yy6d CHHm1szXmrdv4eB2rxQE7sfTakiMdt7JYvtGWmggdFg7uqTpa05wj0dmXxvP1yX3WXRNAWQ0fV2 WuMcbvPvAKol4CBT+tp+6BVA7tswExTiFMNcrp18G43UfrdC53GTueSNskt7n0oqJjXPcn9+4aP G8+vzrqOslqGuzjKgfhmAvcHmz900e+0cu0O/QcIw9/7V1mXUOZIIoeRK1kvJTP0mJfovAg9QcJ 3QydIGo3q+F6DEO/9zm5HwqIB34FXr5luK037PYGeHwToxvNCgOcorduINWUj96JJXkVg966fuY cKd5apuirIhnYOUfHOur3TGft+VPCUvC/tt9kjImr5CABIcIqjD/1Mb9QAqX/J/lTtowA2+yayn 1eCfxZA11rdVeaGVFDbN2K8XleghhIwmH0qyzcSqTsK6zAPAngrxEOrmM4RU3MY0RSqf3Bv7GfY lxVsR9eMYwQ97oyU6LviXguK8UrVEXynZu6jbdQ1mI4Ebzw02pHX/brSmgX32whNQ== X-Received: by 2002:a05:6000:2999:10b0:482:ea08:8c97 with SMTP id ffacd0b85a97d-48587046b35mr21857689f8f.2.1788641115565; Sat, 05 Sep 2026 13:45:15 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa0048511f7ccf23d3ce.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:4851:1f7c:cf23:d3ce]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-485885bfdf6sm17069098f8f.34.2026.09.05.13.45.15 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sat, 05 Sep 2026 13:45:15 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][wrynose 09/40] python3-dbusmock: fix CVE_PRODUCT Date: Sat, 5 Sep 2026 22:44:10 +0200 Message-ID: <111182af459620f1d76705d7c511111ee9eeae66.1788629392.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Sat, 05 Sep 2026 20:45:24 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/245161 From: Tim Orling Recipe (PV): python3-dbusmock (0.38.1) Before -> After: python:python_dbusmock -> python-dbusmock_project:python-dbusmock Newly caught CVEs: CVE-2015-1326 (.pyc code exec via AddTemplate) Status: patched (fixed 0.15.1) AI-Generated: Claude Sonnet 5 Signed-off-by: Tim Orling Signed-off-by: Richard Purdie (cherry picked from commit 0405d7d4e476964239e1c27c987ec9c12372e95f) Signed-off-by: Devansh Patel Signed-off-by: Yoann Congal --- meta/recipes-devtools/python/python3-dbusmock_0.38.1.bb | 2 ++ 1 file changed, 2 insertions(+) diff --git a/meta/recipes-devtools/python/python3-dbusmock_0.38.1.bb b/meta/recipes-devtools/python/python3-dbusmock_0.38.1.bb index cbd74b4059e..ecec075f6f2 100644 --- a/meta/recipes-devtools/python/python3-dbusmock_0.38.1.bb +++ b/meta/recipes-devtools/python/python3-dbusmock_0.38.1.bb @@ -11,6 +11,8 @@ PYPI_PACKAGE = "python_dbusmock" inherit pypi python_setuptools_build_meta DEPENDS += "python3-setuptools-scm-native" +CVE_PRODUCT = "python-dbusmock_project:python-dbusmock" + RDEPENDS:${PN} += "\ python3-dbus \ python3-unittest \ From patchwork Sat Sep 5 20:44:11 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 8bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 97359 X-Patchwork-Delegate: yoann.congal@smile.fr Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 1447CC79FA3 for ; Sat, 5 Sep 2026 20:45:24 +0000 (UTC) Received: from mail-wr1-f47.google.com (mail-wr1-f47.google.com [209.85.221.47]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.2583.1788641117770358734 for ; Sat, 05 Sep 2026 13:45:18 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=yRBoH5nB; spf=pass (domain: smile.fr, ip: 209.85.221.47, mailfrom: yoann.congal@smile.fr) Received: by mail-wr1-f47.google.com with SMTP id ffacd0b85a97d-482ea739de2so1437623f8f.0 for ; Sat, 05 Sep 2026 13:45:17 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1788641116; x=1789245916; darn=lists.openembedded.org; h=content-transfer-encoding:content-type:mime-version:references :in-reply-to:message-id:date:subject:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=cLlvdmO5VyM64NwnGuTqUAnCT6np2mhc69Ct63Xr7gQ=; b=yRBoH5nB7zZuI8gfW7rBUbW0PqPhg0NwKC9Qaf/bGI+kqtmq2+3wyho1vKlsdDVy0b oBqT4HuqkUxp0p5yT7wf5D/3RNNK4e5GOzjqrw+quoUB68bTcm0M8P6PkvaZ5sTVDG/W LOaTVUntal4aXhoqZfx0DiF5KV1rSBdZGWAZE= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1788641116; x=1789245916; h=content-transfer-encoding:content-type:mime-version:references :in-reply-to:message-id:date:subject:to:from:x-gm-gg :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to :content-type; bh=cLlvdmO5VyM64NwnGuTqUAnCT6np2mhc69Ct63Xr7gQ=; b=iD/DRRbIGafClX3XJojDA03AOQCK62o+RIpqtWGPi6JY0vRuVW0BO1kT5FomCmDpuD lMNd4AE9OiwMCw97RffL56UMCGfK339W8n5syzCs65rlhrCa7uotSEK4LTKcnCPZSN0L HB2nHKGmonmpFp5BT5usg2QrOYjzvhPFATgzShAs4J7tfvMtqHITs/KZgNUKGddOdLSV hHVd8Y32iha7KYHDVBDLI+tfVY3Nu6a+KKV02UFaQxL4iJXxe7M6/uAGqhnze04RmwWu DzGx8AuY2EZfZcCiQAuaiH9UFPaTDakVYl4wVHukGHGa6Bh+/15HMXO0rGUKn7xBQbA+ dB1Q== X-Gm-Message-State: AFuF++m5bgPcfyUYRJYXr0VGBYQzbDdSYgplrRzT8d4K/gP9D/Q67U// 0yD+i6ypkDvJS+oYV3sPKV3J7M1ysUQC7Ts/RQLC6dyloBa08MupUgcktQ8klfYEKG+b6R5CC8d lJBfQSBg= X-Gm-Gg: AYBFou1MeQgF/joWzCcw4EEKKHEH6bdiVi4ebFis2eh0udoRUwmVyKsVp5aHUJ23DzI Peqrcc9SjpY3k3qGo1rraU7P73Sj3rkZ8+1GAbjCkQviJS0K8oZHJM300cyG9AAC7WM0iZyLIsc WSVjBZQRin5f3+iLYrP86dqv/md7TeBbYROifnHSCIhjRdbEgneUKbQvyg3XA24KgNn/GyrY/wm w3NbMEFE4O44XrdzcubNf8OWkh21m2z97OGnW6rAu6Kq9FMQYHZVPVpT7l/9CBtkBnSAuIzlZhO dQ5V7a2bUcL5Jc3PindUufmX9p8beKMP2H4/WX5qEe6UwVXyv9EkPJAtIL/inAc/89/gFULWv6D TUVtIIG5167ZsxelFe+O8jn6qCaMtAIqm2MWUQEVZGrkYxAYOKFkndV2lwcpBDJtAPxBOIaHpue vy8naXjqqfJhqcBMh7BP+31YX0JyG/T4SMC2sN6CQshpRDNiTMsmQT3IxN4LJ0CsRz4pDqyYcTA GGo5U4SCpsm/Q+V2Xmk0OiTisYP4KKW+zgOCMa0lZtnEjnAMDyIR1uo4002pVW/JYDp1nGmQitk X-Received: by 2002:a05:600c:34d0:b0:49c:fc6e:a3d3 with SMTP id 5b1f17b1804b1-49cfc6ea71amr103498065e9.18.1788641116025; Sat, 05 Sep 2026 13:45:16 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa0048511f7ccf23d3ce.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:4851:1f7c:cf23:d3ce]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-485885bfdf6sm17069098f8f.34.2026.09.05.13.45.15 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sat, 05 Sep 2026 13:45:15 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][wrynose 10/40] python3-wheel: fix CVE_PRODUCT Date: Sat, 5 Sep 2026 22:44:11 +0200 Message-ID: X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Sat, 05 Sep 2026 20:45:24 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/245162 From: Tim Orling The proper CVE_PRODUCT is "wheel_project:wheel". BEFORE: python:wheel -> 0 CVEs AFTER: wheel_project:wheel -> 2 CVEs * Already patched at 0.46.3. - CVE-2022-40898 — DoS in wheel CLI via malicious input. Affects <0.38.1. - CVE-2026-24049 — malicious wheel file can modify permissions of arbitrary files. Affects 0.40.0–<0.46.2. Note: The original commit targeted python3-wheel_0.47.0.bb. This is adjusted for Wrynose, where the recipe version is 0.46.3. AI-Generated: Claude Sonnet 5 Signed-off-by: Tim Orling Signed-off-by: Richard Purdie (cherry picked from commit fe55278e01bbe434452191109278b436bf008ebc) Signed-off-by: Devansh Patel Signed-off-by: Yoann Congal --- meta/recipes-devtools/python/python3-wheel_0.46.3.bb | 2 ++ 1 file changed, 2 insertions(+) diff --git a/meta/recipes-devtools/python/python3-wheel_0.46.3.bb b/meta/recipes-devtools/python/python3-wheel_0.46.3.bb index 2545e5496e9..7338e8edcd8 100644 --- a/meta/recipes-devtools/python/python3-wheel_0.46.3.bb +++ b/meta/recipes-devtools/python/python3-wheel_0.46.3.bb @@ -8,6 +8,8 @@ SRC_URI[sha256sum] = "e3e79874b07d776c40bd6033f8ddf76a7dad46a7b8aa1b2787a8308351 inherit python_flit_core pypi ptest-python-pytest +CVE_PRODUCT = "wheel_project:wheel" + RDEPENDS:${PN} += "python3-packaging" # One test is skipped but requires the "full" python3-flit, not just python3-flit-core From patchwork Sat Sep 5 20:44:12 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 97369 X-Patchwork-Delegate: yoann.congal@smile.fr Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 4B218C79FA8 for ; Sat, 5 Sep 2026 20:45:25 +0000 (UTC) Received: from mail-wr1-f50.google.com (mail-wr1-f50.google.com [209.85.221.50]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.2479.1788641118423131302 for ; Sat, 05 Sep 2026 13:45:18 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=TmfEuON6; spf=pass (domain: smile.fr, ip: 209.85.221.50, mailfrom: yoann.congal@smile.fr) Received: by mail-wr1-f50.google.com with SMTP id ffacd0b85a97d-4858303de5dso2674757f8f.2 for ; Sat, 05 Sep 2026 13:45:18 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1788641117; x=1789245917; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=GsPFdaWrb4UmpwJCIE5xLa7aS8XLzLljJ6Bam4ypQP4=; b=TmfEuON61qUQAETOaAdCj7hDauL6kiF8/WQbXVjljH9iexKhckk3frnr0VOCaTX3yi jBFelGq8tAD8iX+2c0aqsXhhmn5PA4vo/qEGMPFrV86v7Mjjy2TZnL/hyMSmbdanUjiJ 6rWNF6I1hWW5pTdPKRsg6csmDhb1XKNZw0mgI= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1788641117; x=1789245917; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=GsPFdaWrb4UmpwJCIE5xLa7aS8XLzLljJ6Bam4ypQP4=; b=ADmLYPsrbEIevm+j0v7+JWAOgrA3mgBGyPI6rlwceOtpSH/gQnVzJRmMEY5hL3SflI pf7hkkXgXSbG1m2a1T2X4UmjbfCt2fCHWBRAo/+OGygeeuCkmhOKwpasXsT7ltPU0+FX HdT+rD3c21loZtslPMRRt3hD6ttER8TM33pe3oSO9Op0Ciq0S8MTCCu6LghAGHu11IzI ksoDetu89k1gxtrFbySSXwUprdEqNr/1lbtNxvrVR4/OAgV2+KnMRhpri7TCzTGfPIIB 66zCmzhzIPeOanFz1fBGv2w4+TO6QuXxEELnhg5dATwAdiEEJXtkeyzKqhQQ0xYIUixr bg7A== X-Gm-Message-State: AFuF++keXn96ZpM5srb2A4Uv62TSwzpnXao3eYXeuSf//cZhGS3rAW3x yP6unxpddOp1mQNbuB2Mhn2+48jyW3cdjSLg5AD6pjCu0YQEEmtkbgqC0zOgfNGe3MmKNaT3x4D SZnamVZg= X-Gm-Gg: AYBFou1dyowxXd4xabqtlleuhvoQuVh5Bxg2Kj3QPWEbO3CSBLVyzgOvnBZ/cpgOah0 SyrNHOyOosrqCuNAOdEJ6IKFV36yeI+L8mMoHnw6mGeA+iMkiJWkkPsq2pJ4aFtcSksH5/AJi28 /in6c6ljkxr2EO5VsAKCq2mWlSjd+K1cL/Zs+tO7u61wvdWUJVVLvaoaaWfs86nssRR5aZLqtzF O0aNuCKSkWmzCCXsSyckfNSJYx8gswAi5zx6Rm5PyZ/E2DtOrGC6WIrxWYcZYKf6nG5XbA1Cm7l pTw4icHwZFTau/wC7ToNIxrtMDBP7P3dtOYyHfqc4Jor2gx89fYnM8+vk3OovQrIUTak/u27xI7 RuiPMHWky7D5kw26TwDc5sBIBURE1GiiTVe7H4ka/shpzpf6I2By7j2VyvoVDmxxuR2vtJlplM/ wuO3+Bvnoof1C6zvS1QVE/GEzMV9qXwZdsu5f+BLpv1IEyW2JpbWZLaH4a064wic9thOBKOaylt IhecQxZ0D7CqMLX3gi4yk/Dq0NtJ1Ra+/LFzzLUuZoY9Nu6o9gCyFx2lM44WJajFg== X-Received: by 2002:a05:6000:1a8d:b0:485:8c16:a32f with SMTP id ffacd0b85a97d-4858c16a6cemr11053288f8f.36.1788641116638; Sat, 05 Sep 2026 13:45:16 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa0048511f7ccf23d3ce.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:4851:1f7c:cf23:d3ce]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-485885bfdf6sm17069098f8f.34.2026.09.05.13.45.16 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sat, 05 Sep 2026 13:45:16 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][wrynose 11/40] python3-click: fix CVE_PRODUCT Date: Sat, 5 Sep 2026 22:44:12 +0200 Message-ID: X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Sat, 05 Sep 2026 20:45:25 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/245163 From: Tim Orling Recipe (PV): python3-click (8.3.1) Before -> After python:click -> palletsprojects:click Newly caught: CVE-2026-7246 (command injection in click.edit()) Status: unpatched (fixed 8.3.3) Note: The original commit targeted python3-click_8.4.2.bb. This is adjusted for Wrynose, where the recipe version is 8.3.1. The unrelated DESCRIPTION cleanup from the original commit is intentionally omitted. AI-Generated: Claude Sonnet 5 Signed-off-by: Tim Orling Signed-off-by: Richard Purdie (cherry picked from commit 30357a26d7ce490725d1b0ac3375047d00595a5c) Signed-off-by: Devansh Patel Signed-off-by: Yoann Congal --- meta/recipes-devtools/python/python3-click_8.3.1.bb | 2 ++ 1 file changed, 2 insertions(+) diff --git a/meta/recipes-devtools/python/python3-click_8.3.1.bb b/meta/recipes-devtools/python/python3-click_8.3.1.bb index 1f42fe1a50c..49204e96e1f 100644 --- a/meta/recipes-devtools/python/python3-click_8.3.1.bb +++ b/meta/recipes-devtools/python/python3-click_8.3.1.bb @@ -12,6 +12,8 @@ SRC_URI[sha256sum] = "12ff4785d337a1bb490bb7e9c2b1ee5da3112e94a8622f26a6c77f5d2f inherit pypi python_flit_core ptest-python-pytest +CVE_PRODUCT = "palletsprojects:click" + RDEPENDS:${PN}-ptest += " \ python3-pytest \ python3-terminal \ From patchwork Sat Sep 5 20:44:13 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 97357 X-Patchwork-Delegate: yoann.congal@smile.fr Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id D2308C79FA0 for ; Sat, 5 Sep 2026 20:45:23 +0000 (UTC) Received: from mail-wr1-f41.google.com (mail-wr1-f41.google.com [209.85.221.41]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.2480.1788641118856386337 for ; Sat, 05 Sep 2026 13:45:19 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=H4+8zg+M; spf=pass (domain: smile.fr, ip: 209.85.221.41, mailfrom: yoann.congal@smile.fr) Received: by mail-wr1-f41.google.com with SMTP id ffacd0b85a97d-48589798dbbso1758495f8f.3 for ; Sat, 05 Sep 2026 13:45:18 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1788641117; x=1789245917; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=w8Gq1byPeolX1gs0hZzV1XaLJ3QL9UqQZiP1qyGzU7o=; b=H4+8zg+MDeJEfGcEVtAqJMKWceeiM3RqaEn5Xv6jhxpBWXgs9Pnzqr2qaTrhVUUefL LWiadLXFStHAMfjh+SLsKmwnf91dI/3KEvF4Vm5U00G/jeXoIW5UT6G8f3ZAFf68/gXW SKR4Ihpvqf+Bv9QDX67JQSAG/d8ae5xdP50gE= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1788641117; x=1789245917; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=w8Gq1byPeolX1gs0hZzV1XaLJ3QL9UqQZiP1qyGzU7o=; b=P+3xqMQ99jrOQG3M2G813kCWqOrTfmjwtlgi+va240Lm1eFERLwrUVJXRRCpBTiZS7 7hNzXryeb/7H490SfRt/bBbda100o01VPtddj2L0fTo1emBpOhBTHmDBlurWqagWGtxe SNaN314U3CI17X9MaA08bk+wLB0pBS6yXaz2Syt5VFbmNbkh6xWP5IrpXwL2s/X8ZV2C pAkOyyP+iqVD5X12GWCMfBfzKNGQvNux3mlg2XmPAgDeGeqk6566dQUM8WK6APBWoQ46 +wt2VC8pFfuxWGfB9jRvSr5drGG9OTsnsYVB2wloC+lotUqwcUG8+oC9Hn67c+Zy/oL5 9Nfw== X-Gm-Message-State: AFuF++k2aZpwjbTESETIVbskt4xKB2vg/cUYr6OFUe2g3ZTpwrxwEUIK 2AFZNCDai+Qzzu+e2tg+B+2El7WvQQgOPeknN35KPA9etZDn2FBNx2XQ1uAbExaR3eZoWvFzcLx AI4VuxqM= X-Gm-Gg: AYBFou3BV5Nsvcl36zHPQbAskCWCkJwCYWuRVWHzir0RsOk9sCodpTs4miPsC99HP/s +4oJ66lIOL1+aQm+fH5cxHfD8Y3xgK0o1p5SgKi1lanRxr8K1OaQNpLePEK2WhlBCEISO9/OzVS uD4ML+39aP5lmwOUvFymUOL4OoRxsVsS12tWvj0Lm9zMrCNo5/DeHJe29fGBfwXxgAsWySjt9Vi 6dTmUdpsCsq9tSkvnqfbPDf/T/qWsFXmaTvok1tQJjvlvoSrv855g2hS6OSb8b8cglECFiOyXe8 /ilJONNbhUXOX7oYPMc2mtQHkHBKA0YhBTwg2bylpfjzaDKmH0ghHlafhLlX5rQjTQuvr2uqxpy uOsPZBa2cqiZumEyTmstHMBT91u2VcN5izLqi91mit1vgziZsQsV9grnLsqXcr3G2UiaYfre1pS NXpcQJcnmaXD6EbaUgd6aqrQDoxM3E8WVmCXEQ+4ys3KpBWsgmvWNXRQpqnZK8cAsJeeHpSJhPg J9i7hNxjnalK5nASQfGozwdmB9G5IN8hkefR98nGeKa7RpDSvF2u2vepBciRo1a+g== X-Received: by 2002:a05:6000:2f87:b0:485:8a46:705b with SMTP id ffacd0b85a97d-4858a4671c3mr12942642f8f.45.1788641117152; Sat, 05 Sep 2026 13:45:17 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa0048511f7ccf23d3ce.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:4851:1f7c:cf23:d3ce]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-485885bfdf6sm17069098f8f.34.2026.09.05.13.45.16 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sat, 05 Sep 2026 13:45:16 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][wrynose 12/40] python3-attrs: fix CVE_PRODUCT Date: Sat, 5 Sep 2026 22:44:13 +0200 Message-ID: X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Sat, 05 Sep 2026 20:45:23 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/245164 From: Tim Orling No new CVEs are caught, but attrs_project:attrs matches the upstream NVD dictionary CPE. The pypi.bbclass default "python:attrs" generates the wrong product identity for the packaged attrs source. This changes the generated product identity, but the Wrynose sbom-cve-check database snapshot has no current CVE report delta. Note: The original commit targeted python3-attrs_26.1.0.bb. This is adjusted for Wrynose, where the recipe version is 25.4.0. AI-Generated: Claude Sonnet 5 Signed-off-by: Tim Orling Signed-off-by: Mathieu Dubois-Briand Signed-off-by: Richard Purdie (cherry picked from commit bc07eddb82fe42ecf86e685450ec0b5c9d3a9ce1) Signed-off-by: Devansh Patel Signed-off-by: Yoann Congal --- meta/recipes-devtools/python/python3-attrs_25.4.0.bb | 2 ++ 1 file changed, 2 insertions(+) diff --git a/meta/recipes-devtools/python/python3-attrs_25.4.0.bb b/meta/recipes-devtools/python/python3-attrs_25.4.0.bb index 7bc581b8759..c3f5a155ca0 100644 --- a/meta/recipes-devtools/python/python3-attrs_25.4.0.bb +++ b/meta/recipes-devtools/python/python3-attrs_25.4.0.bb @@ -7,6 +7,8 @@ SRC_URI[sha256sum] = "16d5969b87f0859ef33a48b35d55ac1be6e42ae49d5e853b597db70c35 inherit pypi ptest-python-pytest python_hatchling +CVE_PRODUCT = "attrs_project:attrs" + DEPENDS += " \ python3-hatch-vcs-native \ python3-hatch-fancy-pypi-readme-native \ From patchwork Sat Sep 5 20:44:14 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 97365 X-Patchwork-Delegate: yoann.congal@smile.fr Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 04C3EC624DB for ; Sat, 5 Sep 2026 20:45:25 +0000 (UTC) Received: from mail-wr1-f43.google.com (mail-wr1-f43.google.com [209.85.221.43]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.2584.1788641119450615543 for ; Sat, 05 Sep 2026 13:45:19 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=Rpg3+yg3; spf=pass (domain: smile.fr, ip: 209.85.221.43, mailfrom: yoann.congal@smile.fr) Received: by mail-wr1-f43.google.com with SMTP id ffacd0b85a97d-4858595f997so1316220f8f.1 for ; Sat, 05 Sep 2026 13:45:19 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1788641118; x=1789245918; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=cihpcZCcpxBh3i0qK1Ewu84bv4i3hjMi8KksH7UkfBc=; b=Rpg3+yg3iR+Xmw1TnTs3MbpUNl18zrqQiEUzyMgl4a0zdhgbKCg84/Cc8TiB9uREyF f7Rl4Mknayh3atVsjJeEXDBLk2vMaroIYRd+sIWnDh6Zi7eqzu9GWoJdxrDypJHBNbMT dA2Euw2PaurpwjmHmWNomsrjJW5JnU1E+d/Rk= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1788641118; x=1789245918; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=cihpcZCcpxBh3i0qK1Ewu84bv4i3hjMi8KksH7UkfBc=; b=oEkvbcdPqfV8/xGqXjo+BOriQeqWyFacpH6Qv3kX7SgiqiByMEb0ISWVf87opgoZ3M D0G9i6ypUid6U7Yhx1MPKtPv42IKQ8fSpSsMlhjn2nYLta2iEs3aDSx081XPuDvdErem 6Xx6OnCmq9MKpoIUJsOycHNr+MKnBlzW0jGgNhAu7m3EFhoHYMWJc8mUcGpnpIhKeJ9j BF33SEr0FuECpU6bigyzhzTjJCsGV3hBLU9G9yk3aNF/XQSZbq5wKXIT4GBtiMXzGsjY f9iAUrYQ1xbpecUV3emzp9JaButVXHolFw4ZnpwpdEOD360HpkmtQLNyTCwiME1Ee817 upKg== X-Gm-Message-State: AFuF++kGXhEG2/EP8ecCRje7O6t+3rXlbnZ/rt9wjE9PC0J414IxfNgz 9weWQdEWLcLDsWmOyjGE8PZQ1K0xxjygnpWctn8iZ5TLVSv0ErR+kDJRxwZYlhAmlHbCFOnfB2H Ozbr8DQY= X-Gm-Gg: AYBFou38ZQL7l9O69HSj+3n2cMXPstslHXOX4Q2Ges4pjj9rhuNYoQEo8R9H0SKvC8a gQOGOE7BhP6MhE8dOde8U5UTvs59LZHolMtQZh8wAe6PABme+CcaVzkTeFnckT68b2EFYioaJHz pFdXu2Ze8L6ThReaDlKBaX6GfpWfNWIWTGR3pkD9MWJ2oD/mx0WsxA5bhIHNe/RWyo33G7QjqGq ZmRlZq3O8o/BBM7pKm2/UhTXAJ+lV0ks0ifMuCINMMKvp/iETC3ostAQIV3JbpAvWR2/0Ol5QdF thDH5BMtckJqU5ZvOOksuf95T9O8JGoXKBPrZlWmo5UaeMpKk3bI+amR3zXQxLMOiRwdUeKShka t6qwFCUqWW6dqixiTlGhoaBUeBiuKbzD9xE49HVnRJSGFPofm6Omyfga3t/4lUZFzieiPVnhg+I S/jpoXuZY47ipcdPIkx65Fp6yUPCG1nrfS8VblRmYs2X+GSBYLSQwkZthh2YYxJTgaBLeShhjdu jLqkJ8GwCGgKGkVG5kn+RTdKMMlN5hYycmFGYlb4tuz1kZ3IK7hEa4RsXYiO306/4elXm/NazD7 X-Received: by 2002:a05:6000:612:b0:485:8e19:1979 with SMTP id ffacd0b85a97d-4858e191d46mr19199921f8f.11.1788641117625; Sat, 05 Sep 2026 13:45:17 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa0048511f7ccf23d3ce.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:4851:1f7c:cf23:d3ce]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-485885bfdf6sm17069098f8f.34.2026.09.05.13.45.17 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sat, 05 Sep 2026 13:45:17 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][wrynose 13/40] python3-numpy: fix CVE_PRODUCT Date: Sat, 5 Sep 2026 22:44:14 +0200 Message-ID: <67ff6e69aa7ae4d83a636fd593a048fb2fb18536.1788629392.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Sat, 05 Sep 2026 20:45:25 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/245165 From: Tim Orling Without this change, 0 CVEs are reported. With this change, 8 Patched CVEs are reported: * CVE-2014-1858 * CVE-2014-1859 * CVE-2017-12852 * CVE-2019-6446 * CVE-2021-33430 * CVE-2021-34141 * CVE-2021-41495 * CVE-2021-41496 This can be verified with a query like: $ cat .../core-image-ptest-python3-numpy-*.rootfs.sbom-cve-check.yocto.json \ | jq '.package[] | select(.name == "python3-numpy") \ | .issue[] | {id: .id, status: .status}' Signed-off-by: Tim Orling Signed-off-by: Mathieu Dubois-Briand Signed-off-by: Richard Purdie (cherry picked from commit ad623e71fadeddcb0b70bba8fbf28c75a976e596) The current "python3-numpy" mapping has no matching NVD CPE or configuration identity, so eight source-aligned CVE records are missed. Use "numpy:numpy", the active NVD dictionary CPE and configuration identity for the packaged NumPy source. Note: The original commit targeted python3-numpy_2.5.2.bb. This is adjusted for Wrynose, where the recipe version is 2.4.3. Signed-off-by: Devansh Patel Signed-off-by: Yoann Congal --- meta/recipes-devtools/python/python3-numpy_2.4.3.bb | 2 ++ 1 file changed, 2 insertions(+) diff --git a/meta/recipes-devtools/python/python3-numpy_2.4.3.bb b/meta/recipes-devtools/python/python3-numpy_2.4.3.bb index 7521a93f990..f34723b2c26 100644 --- a/meta/recipes-devtools/python/python3-numpy_2.4.3.bb +++ b/meta/recipes-devtools/python/python3-numpy_2.4.3.bb @@ -18,6 +18,8 @@ SRC_URI[sha256sum] = "483a201202b73495f00dbc83796c6ae63137a9bdade074f7648b3e3261 GITHUB_BASE_URI = "https://github.com/numpy/numpy/releases" UPSTREAM_CHECK_REGEX = "releases/tag/v?(?P\d+(\.\d+)+)$" +CVE_PRODUCT = "numpy:numpy" + inherit pkgconfig ptest python_mesonpy github-releases cython S = "${UNPACKDIR}/numpy-${PV}" From patchwork Sat Sep 5 20:44:15 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 97358 X-Patchwork-Delegate: yoann.congal@smile.fr Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 8D918C79F9F for ; Sat, 5 Sep 2026 20:45:23 +0000 (UTC) Received: from mail-wr1-f42.google.com (mail-wr1-f42.google.com [209.85.221.42]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.2481.1788641120244335752 for ; Sat, 05 Sep 2026 13:45:20 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=RDpetFpw; spf=pass (domain: smile.fr, ip: 209.85.221.42, mailfrom: yoann.congal@smile.fr) Received: by mail-wr1-f42.google.com with SMTP id ffacd0b85a97d-482ea739de2so1437637f8f.0 for ; Sat, 05 Sep 2026 13:45:20 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1788641118; x=1789245918; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=se2riq49+3t+cwydmgR6nBbhPTMJKoFh7cP2Dv28azg=; b=RDpetFpw7hGGkOGMRKacP0joODMJqPrygrb1XOafHeiWg2D5rk7ygaDl/2kYvUW8zo /sBL6Lgxn5HAhi9jblvSqgifIK/10/2XBa5h3inkwT8KxUH7QNcH1zPHf02xVD36lf9H I+oglpvkpRpiAUmTp23hJ7d6JZYEq/zF3Eoc8= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1788641118; x=1789245918; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=se2riq49+3t+cwydmgR6nBbhPTMJKoFh7cP2Dv28azg=; b=TtfhG8X5L7rMZy5Rz9Df0ArRCNOz0vfyfZoOMxcqrgnjBkwnME4TPdRCxYozGquiFe jllmgiaMZJdigokuySHfcgP/6dCmA+rvfbxfyuyVuDefxsDz1OqkmM79a3w/4azNoWaC TRdLC4b8gOJzECeTwCDWSGt7oqZqSvpWUM38ukTTAZA723kFYNwKfG0rrsO+p7hvN5xR Y/ytwJCfDhJKnz73jll7+q0gGrGqwgIrXTgGwXcfoaR7Dn3bZ1I8QiePH7n2Kv3u+ocA sCFVX0fgUtMzMw2YjzfEW0EsfseOcywu1pBVDXI6/8vSFQe4Fgk3/gMHgZeDAAIr3953 MD6g== X-Gm-Message-State: AFuF++liUuCdoPruIpbwGDZuudrnuhmNnj2pC9sttlgRS227n81qI2qz /r02vd2a033r8dGNuQnEsyoFgZeAuVTq+9t4zTnWm1RvjPNiLl3pVzaU99+V0GWCG1/ClAwQEC9 azliPt0I= X-Gm-Gg: AYBFou1JyRIqJbBcD99IKVhkworJYs2n+ug2WlNRhBLCqwr4Pfax9EgMsueDUba4KTA eYAnP5BUmaSqa6soeffoKk0q2s2a4H8d5RKJSJXPEAocRMl8PPwHrN6HkhYGcy663TsN5At4t7t XSzFoNQN1+7f7em07NfnMSgyeF7uD6uAl5ZbMRmUjeBn7Ih9ZVTAnfQi5AMaF74G6xR9MI6khXm 2fyJ6rG+71gFqsTK31FdPkoUrJdcKO+Pw/amQiKrcS5QcKwodBnIdB1Vy3HGSc32nHXut62+df1 FKjmbGAOTp9f5lAmIAk+ZRXfhwM47r4aa6JBgTgv9ZlxNESxpb4lRNLzaNUL+dJAbmy6dQh8rKc iAaJqh7Sf2SIVIz+0FRgfxMoe2A3BI0VGlRSASt3wtU6Hz7V/M9ypxxedgXkTUkHUT+A61ia51V hOnelMB9iE1JsVr1fR8/bSrEXhzuIsUuQj7cj/8sRd31i/5+LKEEBLvrx2ODlpclE/eUgdm0aCE S2VrNQFQbIVyCOZoeIYW6zBginqQHFhrelOisJY8B2Jc2gVhmToYYX4Amh+qQS3DA== X-Received: by 2002:a05:6000:605:b0:485:8c16:a360 with SMTP id ffacd0b85a97d-4858c16a6abmr11531032f8f.56.1788641118523; Sat, 05 Sep 2026 13:45:18 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa0048511f7ccf23d3ce.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:4851:1f7c:cf23:d3ce]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-485885bfdf6sm17069098f8f.34.2026.09.05.13.45.17 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sat, 05 Sep 2026 13:45:18 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][wrynose 14/40] python3-pycryptodomex: fix CVE_PRODUCT Date: Sat, 5 Sep 2026 22:44:15 +0200 Message-ID: <540250a7b7b17058da2b48d870373f2d3e48aae0.1788629392.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Sat, 05 Sep 2026 20:45:23 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/245166 From: Tim Orling With this change, 1 Patched CVE is properly reported: * CVE-2023-52323 Signed-off-by: Tim Orling Signed-off-by: Mathieu Dubois-Briand Signed-off-by: Richard Purdie (cherry picked from commit c2a2ae48add874f41c5b60ca90ba3a26ebb0fe38) The current pypi default "python:pycryptodomex" has no matching NVD CPE or configuration identity. Use "pycryptodome:pycryptodomex", the active NVD dictionary CPE and configuration identity for the packaged distribution, so CVE-2023-52323 is properly reported as patched. Signed-off-by: Devansh Patel Signed-off-by: Yoann Congal --- meta/recipes-devtools/python/python3-pycryptodomex_3.23.0.bb | 2 ++ 1 file changed, 2 insertions(+) diff --git a/meta/recipes-devtools/python/python3-pycryptodomex_3.23.0.bb b/meta/recipes-devtools/python/python3-pycryptodomex_3.23.0.bb index 43dba3faa3c..148409c8d96 100644 --- a/meta/recipes-devtools/python/python3-pycryptodomex_3.23.0.bb +++ b/meta/recipes-devtools/python/python3-pycryptodomex_3.23.0.bb @@ -3,6 +3,8 @@ inherit python_setuptools_build_meta SRC_URI[sha256sum] = "71909758f010c82bc99b0abf4ea12012c98962fbf0583c2164f8b84533c2e4da" +CVE_PRODUCT = "pycryptodome:pycryptodomex" + FILES:${PN}-tests = " \ ${PYTHON_SITEPACKAGES_DIR}/Cryptodome/SelfTest/ \ ${PYTHON_SITEPACKAGES_DIR}/Cryptodome/SelfTest/__pycache__/ \ From patchwork Sat Sep 5 20:44:16 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 97353 X-Patchwork-Delegate: yoann.congal@smile.fr Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 58F4EC79F9E for ; Sat, 5 Sep 2026 20:45:23 +0000 (UTC) Received: from mail-wm1-f43.google.com (mail-wm1-f43.google.com [209.85.128.43]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.2585.1788641120755201210 for ; Sat, 05 Sep 2026 13:45:21 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=1yHUtZXy; spf=pass (domain: smile.fr, ip: 209.85.128.43, mailfrom: yoann.congal@smile.fr) Received: by mail-wm1-f43.google.com with SMTP id 5b1f17b1804b1-49b96837ca3so16520055e9.3 for ; Sat, 05 Sep 2026 13:45:20 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1788641119; x=1789245919; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=k2/svhinbBKAnJ/CikKl+Yz3TriGeCDvZpHs3CAyBGA=; b=1yHUtZXygCZGoRN7OzOGIlMDc+1mpxyalA9SPc2Dlc9tmoDiebG2GxPxq8XNcoIyXx X0i1OM9pkM/ecaS60FBPp9qddvSaLMBylfUnXv1SWxcKPrtgeblqEn/K7TZCI1vTIt1+ sOQlE9/6v6R9KNkswwFwnZHAfxtyUjxepsUUg= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1788641119; x=1789245919; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=k2/svhinbBKAnJ/CikKl+Yz3TriGeCDvZpHs3CAyBGA=; b=ey3sj6ocndkQLzIaGCXx1jTbiRQ6SeZB9eMuHDtExqGHnrTIl9v63n+Lyjq3C5HVDO eyfvF6sMLm9BXvGhoFP5Lm8bALMNux6lkOlzcuBVNrgnUO11EyaWt9CafvdcicDV6ghe bInkCIJ+EpDNpm1JUyDz5qMJzoV5X9pL9AwS3VaJdfzP4zPzxVhs3aN4rsRvBkQTbwUK 4sIavrHUy2qlNVqw0vUUm4PVI0+l/Z4B71PIs5Hxa9ds7kf940R/VmWYNcwNUy14yTYx BlrUB3XVnZ/J41+7BI3npgNVJV5h1p4O6wXBX+EfOOxSjl950sFPhT9eDJJZUBr0sd3M wCQQ== X-Gm-Message-State: AFuF++lOd6DRfWELD7iWdYYp07+RDPeLYjnBJqdlTuhXvd+eULI7mXCg KVAQGa9I7tFDyYl7sgfl0ryXtuIFY9MPILDEnmigPr0Ss4rT0gLQ8H+h/3twxjcggPsuCzTSs2j qY5LhL/Y= X-Gm-Gg: AYBFou2sgx54oyLdaoUnQn6ra0EDTXcZ5vzPljo08x1q8lMyv2YV8Ae2GpCSwFZDnk/ OekilLEaLm3P31MhJYBREaL0SXtP8O9Y4U1yU1TtJA3zHpLxWJH1RSIjCJfebcwFRv46WxjeALm D67iVX1N1E/eFEL0emP+NQEVntI97QzCYkz1ZarxIPvyxwccTSWYvQbajzXsl9mT6aGmjJ6aIWp LiFhTnPafqT8unWfnMIu+3hfi5XsrbsnlNfnDnJXFH98CH9mSJah601Mhbal9g62qAiz/nzLKEr UQtEUVk1ud+vogVTM0YVtQY2rW1OD57g2R8i4auDfU+onxQ3aAorxzKYecG2MXhw9UhRsKoTZcX vG56GbXD+F7SjUMx+JwLSGvBF62hB5KmQHXEx91PWyehpAsVBQetqNoXGzRfffReZo1ESr5RnsI ap2VwAH8U/gvYU/crPXIr16G4L2N6LXUaaQRWvqJJgOWQMAjhqdPiGM7wA9oqrJgaV5kbtMMvvF nWlDSLy2Ef1ttnI+WyIYWzqSX8BEWnRDrFNU0phx2SYjAz9JK1Ni2lu5arKWQGGJ+bwQIbLoR8K X-Received: by 2002:a05:600c:3ba5:b0:49c:dada:f581 with SMTP id 5b1f17b1804b1-49cf7f39c8bmr169968845e9.0.1788641118984; Sat, 05 Sep 2026 13:45:18 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa0048511f7ccf23d3ce.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:4851:1f7c:cf23:d3ce]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-485885bfdf6sm17069098f8f.34.2026.09.05.13.45.18 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sat, 05 Sep 2026 13:45:18 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][wrynose 15/40] python3-mako: upgrade 1.3.10 -> 1.3.12 Date: Sat, 5 Sep 2026 22:44:16 +0200 Message-ID: X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Sat, 05 Sep 2026 20:45:23 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/245167 From: Richard Purdie ChangeLog:https://docs.makotemplates.org/en/latest/changelog.html#change-1.3.12 (cherry picked from commit 439b05aa55a7d4d71b81ca93025de1b28d79b311) Signed-off-by: Richard Purdie Signed-off-by: Hetvi Thakar Signed-off-by: Yoann Congal --- .../python/{python3-mako_1.3.10.bb => python3-mako_1.3.12.bb} | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) rename meta/recipes-devtools/python/{python3-mako_1.3.10.bb => python3-mako_1.3.12.bb} (88%) diff --git a/meta/recipes-devtools/python/python3-mako_1.3.10.bb b/meta/recipes-devtools/python/python3-mako_1.3.12.bb similarity index 88% rename from meta/recipes-devtools/python/python3-mako_1.3.10.bb rename to meta/recipes-devtools/python/python3-mako_1.3.12.bb index 2d937dc184e..b2c1a8dad8d 100644 --- a/meta/recipes-devtools/python/python3-mako_1.3.10.bb +++ b/meta/recipes-devtools/python/python3-mako_1.3.12.bb @@ -8,7 +8,7 @@ PYPI_PACKAGE = "mako" inherit pypi python_setuptools_build_meta ptest-python-pytest -SRC_URI[sha256sum] = "99579a6f39583fa7e5630a28c3c1f440e4e97a414b80372649c0ce338da2ea28" +SRC_URI[sha256sum] = "9f778e93289bd410bb35daadeb4fc66d95a746f0b75777b942088b7fd7af550a" RDEPENDS:${PN} = "python3-html \ python3-markupsafe \ From patchwork Sat Sep 5 20:44:17 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 97355 X-Patchwork-Delegate: yoann.congal@smile.fr Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 2D1C7C79F9B for ; Sat, 5 Sep 2026 20:45:23 +0000 (UTC) Received: from mail-wr1-f45.google.com (mail-wr1-f45.google.com [209.85.221.45]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.2586.1788641121355697143 for ; Sat, 05 Sep 2026 13:45:21 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=qSiRKIVu; spf=pass (domain: smile.fr, ip: 209.85.221.45, mailfrom: yoann.congal@smile.fr) Received: by mail-wr1-f45.google.com with SMTP id ffacd0b85a97d-48436216a98so1433556f8f.0 for ; Sat, 05 Sep 2026 13:45:21 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1788641119; x=1789245919; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=pEIEe5rFUG0SDi7UQoEiByOf15liZ28Guhsl3xnBVws=; b=qSiRKIVuZsjBCecpi97eh7LvRMCe+BxOYZpEsj1O8UkmWVFfmR358FYrOOsYPS9Bt6 EewxARV1BcPuDyoWS2yAC31G/FCDikFotjW4RYvGlqp6vqRIzv3qWvizPGI0iUKH5DON z7KbvhUYagvW0grGFZv9POhqtOTbk1/V3kcik= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1788641119; x=1789245919; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=pEIEe5rFUG0SDi7UQoEiByOf15liZ28Guhsl3xnBVws=; b=qFCQlgF1LLafBQdReT/BEigoVFhyDwfmrrXkDsQG7SRpNzQ0cm/U9/fGtRTXpVhj/v KXK956Sod21KMT8+Z8N9wufGgIZjtDioH9/oQG+V2qEyZejQjpsQd3loaa5m8bJSH5IL fnXdtQilIZqfZ/u6CFiacKHu8TGGnI8Gi3BqcT6aG9Enhyb1R0YLxh6wVhJJzM7PrWD7 r4Zk4FqEgfiPEJaETyt+IS4WFya2s12ZSm/joHzrPHf3FG4rjXJGJiwzmqcLP46Pv4fs y3l02kX0+oRfikF7vq4xwYXX/GE1F+jmqPHjSuJ2GVBKnuOJ4g7+Rd4lGu4rD/erTaby 5X1w== X-Gm-Message-State: AFuF++nzsPUjUI69PkLQtiQ69pD4HGdxly5yWHUMIvQ6P+9XKfRp27Rc wNJ2U98b0qehLa2odA9+6FyoZtMaiJBhuw7pPuZ0hWk40k24p9HA5iMHscAlGhRcuKw+P36jvEJ ydmH5uCw= X-Gm-Gg: AYBFou0/9q2hmhcxZ1v/KQijgASJu+5dn5ywBRNhnwFRpdhul6QZ/PcOSQo3L6j6awI 8pimEEpd59FQE1aa0B7TRxQWSt1jpLGK72J9zhq1rGWH2bMZXOFwTlnmNL6h0QUeJB3EW6EkzoR EUOZGzVGoDsLtqYttj1G9eTW2+hV06ibG4YNcKvuzB88oif8+X9SBGWVumRh/y/IiNmKhpKLOXx 1/dCy6+CdHA6W8554oOGiPx1Dz6NnSRKCK/LgzyrPIM+s5hq6lK9dejkLRow1lmPZ+IhsZFb/4N l+jy5eJ0j3y1ncEhLsMXKjjVOjWJ+H1u1+4CYk0SPt+km9BwLFxI08QEuVEwIr/q/dX7Vz1JhH6 8F+F/mxlaO/c3gIfnl8OlAV8RwvoNfyPm1WPAjJfwqgERSQehvDkivsh6R2gX5YTtTDRcGL80WY u7lxRi/AxpVSirqJP/ewZMYNEWvIfnNYjX3WOwgJkaJ4jUw1MfCatxHhbxHszhOcsPvrsGqm2Ml Io6M32r369eJ38Zz9siv2/J5d2ka2I+YpDLik54fUvHQ+0t0gJANCkojFMYy3psWQ== X-Received: by 2002:adf:e19c:0:b0:485:8c17:976b with SMTP id ffacd0b85a97d-4858c1799f6mr12347667f8f.45.1788641119454; Sat, 05 Sep 2026 13:45:19 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa0048511f7ccf23d3ce.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:4851:1f7c:cf23:d3ce]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-485885bfdf6sm17069098f8f.34.2026.09.05.13.45.19 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sat, 05 Sep 2026 13:45:19 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][wrynose 16/40] gnutls: fix for CVE-2026-42011 Date: Sat, 5 Sep 2026 22:44:17 +0200 Message-ID: <292feb720935d42dab6729a1147c9d5ca9f65c7e.1788629392.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Sat, 05 Sep 2026 20:45:23 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/245168 From: Jakub Szczudlo (Nokia) Backport patches to fix CVE-2026-42011 and extend test for it References: https://nvd.nist.gov/vuln/detail/CVE-2026-42011 Upstream fix: https://gitlab.com/gnutls/gnutls/-/commit/1dead2faec6320aaba321eb56f20d442df192b83 https://gitlab.com/gnutls/gnutls/-/commit/24713b8c63137ce0665b495d22ccce4f5ce05c84 Tested with ptest Signed-off-by: Jakub Szczudlo Signed-off-by: Yoann Congal --- .../gnutls/gnutls/CVE-2026-42011_p1.patch | 43 ++++++ .../gnutls/gnutls/CVE-2026-42011_p2.patch | 141 ++++++++++++++++++ meta/recipes-support/gnutls/gnutls_3.8.12.bb | 2 + 3 files changed, 186 insertions(+) create mode 100644 meta/recipes-support/gnutls/gnutls/CVE-2026-42011_p1.patch create mode 100644 meta/recipes-support/gnutls/gnutls/CVE-2026-42011_p2.patch diff --git a/meta/recipes-support/gnutls/gnutls/CVE-2026-42011_p1.patch b/meta/recipes-support/gnutls/gnutls/CVE-2026-42011_p1.patch new file mode 100644 index 00000000000..62a9714c6c6 --- /dev/null +++ b/meta/recipes-support/gnutls/gnutls/CVE-2026-42011_p1.patch @@ -0,0 +1,43 @@ +From 1dead2faec6320aaba321eb56f20d442df192b83 Mon Sep 17 00:00:00 2001 +From: Alexander Sosedkin +Date: Tue, 14 Apr 2026 17:41:30 +0200 +Subject: [PATCH 1/2] x509/name_constraints: fix intersecting empty constraints + +Permitted name constraints were wrongfully ignored +when prior CAs only had excluded name constraints, +resulting in a name constraint bypass. + +With this change, they are taken into account and propagate. + +CVE: CVE-2026-42011 +Upstream-Status: Backport [https://gitlab.com/gnutls/gnutls/-/commit/1dead2faec6320aaba321eb56f20d442df192b83] + +Reported-by: Haruto Kimura (Stella) +Fixes: #1824 +Fixes: CVE-2026-42011 +Fixes: GNUTLS-SA-2026-04-29-6 +CVSS: 4.8 Medium CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N + +Signed-off-by: Alexander Sosedkin +Signed-off-by: Jakub Szczudlo +--- + lib/x509/name_constraints.c | 3 --- + 1 file changed, 3 deletions(-) + +diff --git a/lib/x509/name_constraints.c b/lib/x509/name_constraints.c +index 04722bdf4..232d466c4 100644 +--- a/lib/x509/name_constraints.c ++++ b/lib/x509/name_constraints.c +@@ -723,9 +723,6 @@ static int name_constraints_node_list_intersect( + type_bitmask_t types_in_p1 = 0, types_in_p2 = 0; + static const unsigned char universal_ip[32] = { 0 }; + +- if (permitted->size == 0 || permitted2->size == 0) +- return GNUTLS_E_SUCCESS; +- + /* make sorted views of the arrays */ + ret = ensure_sorted(permitted); + if (ret < 0) { +-- +2.53.0 + diff --git a/meta/recipes-support/gnutls/gnutls/CVE-2026-42011_p2.patch b/meta/recipes-support/gnutls/gnutls/CVE-2026-42011_p2.patch new file mode 100644 index 00000000000..29eb6bda43a --- /dev/null +++ b/meta/recipes-support/gnutls/gnutls/CVE-2026-42011_p2.patch @@ -0,0 +1,141 @@ +From 24713b8c63137ce0665b495d22ccce4f5ce05c84 Mon Sep 17 00:00:00 2001 +From: Alexander Sosedkin +Date: Tue, 14 Apr 2026 17:49:50 +0200 +Subject: [PATCH 2/2] tests/name-constraints-merge: extend to cover #1824 + +CVE: CVE-2026-42011 +Upstream-Status: Backport [https://gitlab.com/gnutls/gnutls/-/commit/24713b8c63137ce0665b495d22ccce4f5ce05c84] + +Signed-off-by: Alexander Sosedkin +Signed-off-by: Jakub Szczudlo +--- + tests/name-constraints-merge.c | 113 +++++++++++++++++++++++++++++++++ + 1 file changed, 113 insertions(+) + +diff --git a/tests/name-constraints-merge.c b/tests/name-constraints-merge.c +index 70376aaa7..3ff8d6c60 100644 +--- a/tests/name-constraints-merge.c ++++ b/tests/name-constraints-merge.c +@@ -473,6 +473,119 @@ void doit(void) + gnutls_x509_name_constraints_deinit(nc1); + gnutls_x509_name_constraints_deinit(nc2); + ++ /* 6: test intersecting empty permitted with non-empty permitted ++ * NC1: excluded DNS excluded.example.org (empty permitted) ++ * NC2: permitted DNS permitted.example.org ++ * Expected result: ++ * permitted=[permitted.example.org], excluded=[excluded.example.org] ++ * unrelated.example.com is rejected ++ */ ++ suite = 6; ++ ++ ret = gnutls_x509_name_constraints_init(&nc1); ++ check_for_error(ret); ++ ++ ret = gnutls_x509_name_constraints_init(&nc2); ++ check_for_error(ret); ++ ++ set_name("excluded.example.org", &name); ++ ret = gnutls_x509_name_constraints_add_excluded(nc1, GNUTLS_SAN_DNSNAME, ++ &name); ++ check_for_error(ret); ++ ++ set_name("permitted.example.org", &name); ++ ret = gnutls_x509_name_constraints_add_permitted( ++ nc2, GNUTLS_SAN_DNSNAME, &name); ++ check_for_error(ret); ++ ++ ret = _gnutls_x509_name_constraints_merge(nc1, nc2); ++ check_for_error(ret); ++ ++ set_name("unrelated.example.com", &name); /* entirely unrelated */ ++ ret = gnutls_x509_name_constraints_check(nc1, GNUTLS_SAN_DNSNAME, ++ &name); ++ check_test_result(suite, ret, NAME_REJECTED, &name); /* #1814 */ ++ ++ set_name("permitted.example.org", &name); /* permitted, direct */ ++ ret = gnutls_x509_name_constraints_check(nc1, GNUTLS_SAN_DNSNAME, ++ &name); ++ check_test_result(suite, ret, NAME_ACCEPTED, &name); /* sanity */ ++ ++ set_name("sub.permitted.example.org", &name); /* permitted, subdomain */ ++ ret = gnutls_x509_name_constraints_check(nc1, GNUTLS_SAN_DNSNAME, ++ &name); ++ check_test_result(suite, ret, NAME_ACCEPTED, &name); /* sanity */ ++ ++ set_name("excluded.example.org", &name); /* excluded, direct */ ++ ret = gnutls_x509_name_constraints_check(nc1, GNUTLS_SAN_DNSNAME, ++ &name); ++ check_test_result(suite, ret, NAME_REJECTED, &name); /* sanity */ ++ ++ set_name("sub.excluded.example.org", &name); /* excluded, subdomain */ ++ ret = gnutls_x509_name_constraints_check(nc1, GNUTLS_SAN_DNSNAME, ++ &name); ++ check_test_result(suite, ret, NAME_REJECTED, &name); /* sanity */ ++ ++ gnutls_x509_name_constraints_deinit(nc1); ++ gnutls_x509_name_constraints_deinit(nc2); ++ ++ /* 7: test intersecting non-empty permitted with empty permitted ++ * (same as 6, but swapped to ensure order doesn't matter) ++ * NC1: permitted DNS permitted.example.org ++ * NC2: excluded DNS excluded.example.org (empty permitted) ++ * Expected result: ++ * permitted=[permitted.example.org], excluded=[excluded.example.org] ++ * unrelated.example.com is rejected ++ */ ++ suite = 7; ++ ++ ret = gnutls_x509_name_constraints_init(&nc1); ++ check_for_error(ret); ++ ++ ret = gnutls_x509_name_constraints_init(&nc2); ++ check_for_error(ret); ++ ++ set_name("permitted.example.org", &name); ++ ret = gnutls_x509_name_constraints_add_permitted( ++ nc1, GNUTLS_SAN_DNSNAME, &name); ++ check_for_error(ret); ++ ++ set_name("excluded.example.org", &name); ++ ret = gnutls_x509_name_constraints_add_excluded(nc2, GNUTLS_SAN_DNSNAME, ++ &name); ++ check_for_error(ret); ++ ++ ret = _gnutls_x509_name_constraints_merge(nc1, nc2); ++ check_for_error(ret); ++ ++ set_name("unrelated.example.com", &name); /* entirely unrelated */ ++ ret = gnutls_x509_name_constraints_check(nc1, GNUTLS_SAN_DNSNAME, ++ &name); ++ check_test_result(suite, ret, NAME_REJECTED, &name); /* #1814 */ ++ ++ set_name("permitted.example.org", &name); /* permitted, direct */ ++ ret = gnutls_x509_name_constraints_check(nc1, GNUTLS_SAN_DNSNAME, ++ &name); ++ check_test_result(suite, ret, NAME_ACCEPTED, &name); /* sanity */ ++ ++ set_name("sub.permitted.example.org", &name); /* permitted, subdomain */ ++ ret = gnutls_x509_name_constraints_check(nc1, GNUTLS_SAN_DNSNAME, ++ &name); ++ check_test_result(suite, ret, NAME_ACCEPTED, &name); /* sanity */ ++ ++ set_name("excluded.example.org", &name); /* excluded, direct */ ++ ret = gnutls_x509_name_constraints_check(nc1, GNUTLS_SAN_DNSNAME, ++ &name); ++ check_test_result(suite, ret, NAME_REJECTED, &name); /* sanity */ ++ ++ set_name("sub.excluded.example.org", &name); /* excluded, subdomain */ ++ ret = gnutls_x509_name_constraints_check(nc1, GNUTLS_SAN_DNSNAME, ++ &name); ++ check_test_result(suite, ret, NAME_REJECTED, &name); /* sanity */ ++ ++ gnutls_x509_name_constraints_deinit(nc1); ++ gnutls_x509_name_constraints_deinit(nc2); ++ + /* Test footer */ + + if (debug) +-- +2.53.0 + diff --git a/meta/recipes-support/gnutls/gnutls_3.8.12.bb b/meta/recipes-support/gnutls/gnutls_3.8.12.bb index 3ad011742e4..e9059a4bc16 100644 --- a/meta/recipes-support/gnutls/gnutls_3.8.12.bb +++ b/meta/recipes-support/gnutls/gnutls_3.8.12.bb @@ -37,6 +37,8 @@ SRC_URI = "https://www.gnupg.org/ftp/gcrypt/gnutls/v${SHRT_VER}/gnutls-${PV}.tar file://CVE-2026-42009_p1.patch \ file://CVE-2026-42009_p2.patch \ file://CVE-2026-3833.patch \ + file://CVE-2026-42011_p1.patch \ + file://CVE-2026-42011_p2.patch \ " SRC_URI[sha256sum] = "a7b341421bfd459acf7a374ca4af3b9e06608dcd7bd792b2bf470bea012b8e51" From patchwork Sat Sep 5 20:44:18 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 97354 X-Patchwork-Delegate: yoann.congal@smile.fr Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id A7B58C79FA1 for ; Sat, 5 Sep 2026 20:45:23 +0000 (UTC) Received: from mail-wr1-f52.google.com (mail-wr1-f52.google.com [209.85.221.52]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.2482.1788641121731130944 for ; Sat, 05 Sep 2026 13:45:22 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=Zm7Vmwbl; spf=pass (domain: smile.fr, ip: 209.85.221.52, mailfrom: yoann.congal@smile.fr) Received: by mail-wr1-f52.google.com with SMTP id ffacd0b85a97d-485843aeab8so2346604f8f.1 for ; Sat, 05 Sep 2026 13:45:21 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1788641120; x=1789245920; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=GdblaBRcStVSPVGMVA49Pl395qgNwk97NwGXWp3CETI=; b=Zm7Vmwbl/SGOS08yYpI3jE17j2UyqSUlIsJ+YohMSg0TAWKki22PuqrzvQHcseWHtW uw3IUOgSokm0oQOKuTvnMFgR5k90XpKfAZei+39bk00OdvSzPwrsa6ZlgO2fiFrv+s9A joRzA27VGVF43uK+0TN6Xk/D4pmiARO/fwNoo= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1788641120; x=1789245920; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=GdblaBRcStVSPVGMVA49Pl395qgNwk97NwGXWp3CETI=; b=aefoVfDGw1PAWNlpuNxHJklp9OPOB7nVwuNNlXLjVed/zweQE5cHEVvoMFKMbTRWrU D0fajPWSwa5z3QmvcZdJKLvM5R2AruEEiQ9ZSitPtPtVzudm/vAjvMQBM8P4z9QH8zUa KY11bVv39IhNF5okJgisaXXnxY4fBFlMCT/wueBejrTAVKNWWgLBEq1PjRmE1YAZ786Y S7Wcos1XM6/7Wh+V1csNw7C/UTS5sPtH8RcFNJ9V/wHIoWhht5KeLRJ3XIxNBXMhTyVo PjvkOcrF9SueRO+/cPRUm7mukGENXkbkmsKKsFeKQYa8IaPrgpQ42X5XBURg0Pn2aaYs tT7w== X-Gm-Message-State: AFuF++lwRwWRf/I+bBLQfSFaMDweU4GH57ogtXNF5YaBmnX6dtbtsP8N qoLE+NxQ8BT6kcQ2siz9bRqAuRN5YQdVhAuzgCln5tfQi8P/ZsXJo3E8/ioqNJO8vCeMjG14Oqe lfilbi7U= X-Gm-Gg: AYBFou2UOGM9uXngkqi9drtNosP7LoxaGAZJkS2bxvlbtyvVJCf2EmQO7M/pNNMMgWi MCw9VV+Gob13sUDdy3kIVGLHkKgzpQazlJDQq6qvAlBF0Yb+jrY3mCT2GhorMxNzhYDY+8lHGFf y7+VngFzRqHd7ndQw1hPfKbZMwedIKo0EVNRw3BoxIxyl6hKSodTpR+z1Cl2DFTcynqReAU/07/ ZlZFReFuO3a0KBhnY+dRL9e26uK9Qs6t83KX3lHmLu1EK/PA7BVQsn6UxrL9mCdayOKq37hVw06 H53UHKZKNNmqYSKkNXA9509KowBjj3+b+DixvTkPSFYqbQJsYFPm9TOaXT+5IN5hq47URAHA0ih CnptrxEUqtnujsvF8yRNiVUy6ewv/3SHhu5KJ2/cRDypWsB5SyrimU/BEMqJ8DThoiXg2m9Gjks p1qoyRgE2TEV9JFwf6OEnYM3SiJ+H98sq6aCtyrF5DYeTSQuR1eGR2sSqD29OWbMeMZtd/5r2pu N+D+yuGFJegkA/ThDA0iX3NV3czSJoUNV5MxuL6LfiFVYzh4EIS7wiVDQEQ/Czo/A== X-Received: by 2002:a05:6000:29c9:b0:484:3314:eff6 with SMTP id ffacd0b85a97d-4858709b390mr23097541f8f.28.1788641119959; Sat, 05 Sep 2026 13:45:19 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa0048511f7ccf23d3ce.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:4851:1f7c:cf23:d3ce]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-485885bfdf6sm17069098f8f.34.2026.09.05.13.45.19 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sat, 05 Sep 2026 13:45:19 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][wrynose 17/40] gnutls: fix CVE-2026-42010 Date: Sat, 5 Sep 2026 22:44:18 +0200 Message-ID: X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Sat, 05 Sep 2026 20:45:23 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/245169 From: Jakub Szczudlo (Nokia) Backport patch to fix CVE-2026-42010. References: https://nvd.nist.gov/vuln/detail/CVE-2026-42010 Upstream fix: https://gitlab.com/gnutls/gnutls/-/commit/cb1833afd9b6309563211b1c0a7c291f52ca98d5 Tested with ptest Signed-off-by: Jakub Szczudlo Signed-off-by: Yoann Congal --- .../gnutls/gnutls/CVE-2026-42010.patch | 41 +++++++++++++++++++ meta/recipes-support/gnutls/gnutls_3.8.12.bb | 1 + 2 files changed, 42 insertions(+) create mode 100644 meta/recipes-support/gnutls/gnutls/CVE-2026-42010.patch diff --git a/meta/recipes-support/gnutls/gnutls/CVE-2026-42010.patch b/meta/recipes-support/gnutls/gnutls/CVE-2026-42010.patch new file mode 100644 index 00000000000..b94a32afffc --- /dev/null +++ b/meta/recipes-support/gnutls/gnutls/CVE-2026-42010.patch @@ -0,0 +1,41 @@ +From cb1833afd9b6309563211b1c0a7c291f52ca98d5 Mon Sep 17 00:00:00 2001 +From: Alexander Sosedkin +Date: Tue, 21 Apr 2026 19:26:10 +0200 +Subject: [PATCH] lib/auth/rsa_psk: fix binary PSK identity lookup + +A server looking up PSK username with a NUL-character in it +was wrongfully matching username truncated at a NUL-character. +Fix the check to compare up to the full username length. + +CVE: CVE-2026-42010 +Upstream-Status: Backport [https://gitlab.com/gnutls/gnutls/-/commit/cb1833afd9b6309563211b1c0a7c291f52ca98d5] + +Reported-by: Joshua Rogers of AISLE Research Team +Fixes: #1850 +Fixes: CVE-2026-42010 +Fixes: GNUTLS-SA-2026-04-29-4 +CVSS: 7.1 High CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N +Signed-off-by: Alexander Sosedkin +Signed-off-by: Peter Marko +Signed-off-by: Jakub Szczudlo +--- + lib/auth/rsa_psk.c | 3 +-- + 1 file changed, 1 insertion(+), 2 deletions(-) + +diff --git a/lib/auth/rsa_psk.c b/lib/auth/rsa_psk.c +index cc92b4aa96..27caf18769 100644 +--- a/lib/auth/rsa_psk.c ++++ b/lib/auth/rsa_psk.c +@@ -321,8 +321,7 @@ static int _gnutls_proc_rsa_psk_client_kx(gnutls_session_t session, + * filled in if the key is not found. + */ + ret = _gnutls_psk_pwd_find_entry(session, info->username, +- strlen(info->username), &pwd_psk, +- NULL); ++ info->username_len, &pwd_psk, NULL); + if (ret < 0) + return gnutls_assert_val(ret); + +-- +GitLab + diff --git a/meta/recipes-support/gnutls/gnutls_3.8.12.bb b/meta/recipes-support/gnutls/gnutls_3.8.12.bb index e9059a4bc16..51ef394dfcf 100644 --- a/meta/recipes-support/gnutls/gnutls_3.8.12.bb +++ b/meta/recipes-support/gnutls/gnutls_3.8.12.bb @@ -39,6 +39,7 @@ SRC_URI = "https://www.gnupg.org/ftp/gcrypt/gnutls/v${SHRT_VER}/gnutls-${PV}.tar file://CVE-2026-3833.patch \ file://CVE-2026-42011_p1.patch \ file://CVE-2026-42011_p2.patch \ + file://CVE-2026-42010.patch \ " SRC_URI[sha256sum] = "a7b341421bfd459acf7a374ca4af3b9e06608dcd7bd792b2bf470bea012b8e51" From patchwork Sat Sep 5 20:44:19 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 97352 X-Patchwork-Delegate: yoann.congal@smile.fr Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id EDB1FC79F99 for ; Sat, 5 Sep 2026 20:45:22 +0000 (UTC) Received: from mail-wr1-f51.google.com (mail-wr1-f51.google.com [209.85.221.51]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.2588.1788641122151588458 for ; Sat, 05 Sep 2026 13:45:22 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=DrDrVVJM; spf=pass (domain: smile.fr, ip: 209.85.221.51, mailfrom: yoann.congal@smile.fr) Received: by mail-wr1-f51.google.com with SMTP id ffacd0b85a97d-482e257a23aso1504918f8f.0 for ; Sat, 05 Sep 2026 13:45:21 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1788641120; x=1789245920; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=ZiT7YZXfHIFHuPywyyqdzsbOS+46Pmrh2L032t9SEtM=; b=DrDrVVJMKPGmv1H2cwTECaz3GhR+RLTLTO942Px2dcZzLfa0wkFt36/HJk0SB2tUgM qLKrEeh6v6OqratrhBjLtnJGADHfzZMO6hg9JtM1cNlPHEP/6pI8GMdyQZ7zG2M8Ex1Z 6t9LxuNA1vhtWCJ3uLWqAzmhMk2C98nVmO4vI= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1788641120; x=1789245920; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=ZiT7YZXfHIFHuPywyyqdzsbOS+46Pmrh2L032t9SEtM=; b=ZXMypk4BQqD1cpIQdjSxthy5mmQC1UH8/2OHu+8H8DjbSabtf54BKoAMv1vNUmdZ5w S8UtL/wF9EfREVMmWOoBj80O776+gMuIGCuX33R7gjChrMr+l22OwZ31MGviny90ToP1 84xqsWfNNNiCSJZ5ZpqCXQScjMeS3xnrcR605Qm4dwbGt2c2l99J+xZuKRfICDefFfDR 6Gk1ogQdI+n0GXenVl8e40xpiefSn5a3Wc8dCt43tRVXqS+R+Be3eBD2Y1aJEyY2z6x4 axNHj/IrIjqyFQPlABz0iu0PDL+6FS42/15E5ZtOm66hIDGk3SzaywFIn0sIL9p2O/w4 d2vQ== X-Gm-Message-State: AFuF++mj/3RAHZoNGfw/Y4Gk5QOLA71ApLKeNPKoj/wkHAx9NMmvl+VO D3Ww0L5nwiznqBphWgWXImk1lk4pIL6m9f4UZFvNzfN0VgFJvB2B0rva0ryHWEkmR1nwPWV/DgS qyS5aYFs= X-Gm-Gg: AYBFou0S4cXzCnbjOvbD82gamoTqMMli65RzTL+ML8oZT/0y693JH+kgqwugRaTf6FR WO3rp87pfmJCBopigv8TyT/5nYBNV/S57ugu63vwLb2y+w54CQ7o7sZLtLBPkZDTU2+c8vIbQSu sDIl5qhIEu7qt4Ki9iNAwNZ/8VQd6K2j0jGm5ld9cxbm62KaHUPXLiUFJeQFvrGTmiU+c0PglMu +KM8uAMBAMp0cLDbp7mokjnWN411i32rHTvdZEF9Op9Th8RwSOUSvCLx2nx6a4oheZhA5op+AU0 vkvCAHLB9sBcIanLB649gT5rm7q9UOtf/B4ly903SBUGGm5+yCec8R2FEAUUpZ+Bh5pH1FFQrxN 8CLc0Vwy4l/qvauEMdZ1/ph4951wGjC+vYZUtDvEHi2MGOritj6CPTt62YaKVZ4KuYEhr9HILb7 pDV8QnM4bGCZp65xpWd80W7Cm+vFneWH9TjNPwdK8bqO90/J66ZgfpN3qbO2YRjuH/Q6V0sl/TH Bc4PJVQhcaCnKd76bN1Ctch3QdlbtU49lcBg8bcoqKMUnHQ3N0RtLqGc4aXlBKjQg== X-Received: by 2002:a5d:584f:0:b0:485:9309:6f07 with SMTP id ffacd0b85a97d-4859309765fmr5662199f8f.26.1788641120420; Sat, 05 Sep 2026 13:45:20 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa0048511f7ccf23d3ce.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:4851:1f7c:cf23:d3ce]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-485885bfdf6sm17069098f8f.34.2026.09.05.13.45.20 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sat, 05 Sep 2026 13:45:20 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][wrynose 18/40] alsa-lib: patch CVE-2026-56109 Date: Sat, 5 Sep 2026 22:44:19 +0200 Message-ID: <93722085ad391a4b5ad5040352b1f920ed3ec24a.1788629392.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Sat, 05 Sep 2026 20:45:22 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/245170 From: Peter Marko Pick patch listed in NVD CVE report. Signed-off-by: Peter Marko Signed-off-by: Yoann Congal --- .../alsa/alsa-lib/CVE-2026-56109.patch | 33 +++++++++++++++++++ .../alsa/alsa-lib_1.2.15.3.bb | 1 + 2 files changed, 34 insertions(+) create mode 100644 meta/recipes-multimedia/alsa/alsa-lib/CVE-2026-56109.patch diff --git a/meta/recipes-multimedia/alsa/alsa-lib/CVE-2026-56109.patch b/meta/recipes-multimedia/alsa/alsa-lib/CVE-2026-56109.patch new file mode 100644 index 00000000000..c6ecc837f88 --- /dev/null +++ b/meta/recipes-multimedia/alsa/alsa-lib/CVE-2026-56109.patch @@ -0,0 +1,33 @@ +From 536dd6f8affdf5197c12a63a71c92a70b2833cc0 Mon Sep 17 00:00:00 2001 +From: Jaroslav Kysela +Date: Mon, 8 Jun 2026 14:33:19 +0200 +Subject: [PATCH] conf: add missing return value check in parse_def() + +A malformed configuration may cause SIGSEGV. + +Link: https://lore.kernel.org/alsa-devel/CAGt8pqBU0p2voB+qHxWGcNJrKHAcBhAyHUUBPLBN-Yj_SiV6MQ@mail.gmail.com/ +Reported-by: Luigino Camastra +Signed-off-by: Jaroslav Kysela + +CVE: CVE-2026-56109 +Upstream-Status: Backport [https://github.com/alsa-project/alsa-lib/commit/536dd6f8affdf5197c12a63a71c92a70b2833cc0] +Signed-off-by: Peter Marko +--- + src/conf.c | 4 ++++ + 1 file changed, 4 insertions(+) + +diff --git a/src/conf.c b/src/conf.c +index b0dd6298..e1dba23d 100644 +--- a/src/conf.c ++++ b/src/conf.c +@@ -1485,6 +1485,10 @@ static int parse_def(snd_config_t *parent, input_t *input, int skip, int overrid + endchr = ']'; + } + c = get_nonwhite(input); ++ if (c < 0) { ++ err = c; ++ goto __end; ++ } + if (c != endchr) { + if (n) + snd_config_delete(n); diff --git a/meta/recipes-multimedia/alsa/alsa-lib_1.2.15.3.bb b/meta/recipes-multimedia/alsa/alsa-lib_1.2.15.3.bb index 1ebb3569256..04976f3bf77 100644 --- a/meta/recipes-multimedia/alsa/alsa-lib_1.2.15.3.bb +++ b/meta/recipes-multimedia/alsa/alsa-lib_1.2.15.3.bb @@ -11,6 +11,7 @@ LIC_FILES_CHKSUM = "file://COPYING;md5=a916467b91076e631dd8edb7424769c7 \ SRC_URI = "https://www.alsa-project.org/files/pub/lib/${BP}.tar.bz2" SRC_URI += "file://CVE-2026-25068.patch" +SRC_URI += "file://CVE-2026-56109.patch" SRC_URI[sha256sum] = "7b079d614d582cade7ab8db2364e65271d0877a37df8757ac4ac0c8970be861e" inherit autotools pkgconfig From patchwork Sat Sep 5 20:44:20 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 97372 X-Patchwork-Delegate: yoann.congal@smile.fr Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id B135CC79F99 for ; Sat, 5 Sep 2026 20:45:25 +0000 (UTC) Received: from mail-wm1-f46.google.com (mail-wm1-f46.google.com [209.85.128.46]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.2589.1788641122992921408 for ; Sat, 05 Sep 2026 13:45:23 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=tHBrqPbn; spf=pass (domain: smile.fr, ip: 209.85.128.46, mailfrom: yoann.congal@smile.fr) Received: by mail-wm1-f46.google.com with SMTP id 5b1f17b1804b1-49ccfbe062eso19156525e9.3 for ; Sat, 05 Sep 2026 13:45:22 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1788641121; x=1789245921; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=2Vurr+h3btne9tUoump2FtIGhHAlDjLLHP21WwsjThY=; b=tHBrqPbnhJ2wzA85AGkz5emRN3apO+TktI8bFViG/Mq9+qPNBZdaDbQNTGx05nJB3Z Sdb61zL9iPPkZWL6FA8KaQzvF4nKwjPl3Lt1Tv8/8USOfI+sRucv80uo3/uT5eK/jn4Y bmn+3Pw2Q5uGJrjEGmRqxSO5G56yj0lUHC3gg= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1788641121; x=1789245921; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=2Vurr+h3btne9tUoump2FtIGhHAlDjLLHP21WwsjThY=; b=cW++QCxYGkTt0Q+yK+FGaCJ8hbzmecbQadsoThNibfBAEJnrOY/ttzuqBlmNa+hdS3 3q4nqe1Pr3/NqFSdLjEDskDl9Hj5CgAmOX4Mjo15oe0hTVTS9mYdkrctsFsNrq9Ym9LT nP+1ttlGk5XpF1Zy/6cp+1kduMD5oEMRLHFZYQk0I9DpqI4ljwr0n553OiC2VEgJhOpn hREG8EqLiVI085677VuPH4brEWtpjdIsgf4Y3znBxC5wDzKRS/qbIcLNZS8EQLvm7uv1 V9V9blBYpnITz6fg8sVi4CdiaUZJBug55rZAR/m68V58DDDClExn1XGvhV4Q8YF7OEKp 8lCA== X-Gm-Message-State: AFuF++l409cf9gIU8gvWuT03QxUvbgksDArek3Z9iaGN9LPYrFY74z9q fOmwuzPbRNQZgogUE9g3XylnuJLZlU8jbWRQJ2FW2+Iy+LJDg7zu1czZNJxacxCjhGaqSDN8ofJ tua1jkFg= X-Gm-Gg: AYBFou1PI4BwdgY3g4LmHXfUzELqT8Rw4rGY8kY/3yvF4bTmKlIw4yzUV7xCNZePPXG GY8NlDaz65godM4jsj7nnZbkqAXAV+b4rZM0tBaWD+gj88VgnsSJq6SNjLwxSSBbwx5ttJ2IpId YfI1EXUtb/ClrmJYKZ+lMS6Z0XxLqkbZlI1HC/oUFxA0Wjsn+buRtYzDwPtjKdsGGQaRzNR9nus aQ0wBfn1UVdge3K0LkHD0XhwdKsFoTDwNg5p+MG76Q0XULSCn+Gu0jPemC4+wLVqTZCnxi1MJfu C39ImNOCL1tVnQ3bzKko7sBQaxwZdis1sGCZOG4bVrJcG3FIvvaqwD8cSLF6OjZ2Aq6D35+St3v B1PAYIxYjsHzuB7v+l8NjLkvmsik70sFfA/u3gbOCeRbulcnUjOUEjhIAS9qqttBrxCkLhUpq6V gsYk/cABQTgtvkzicR5bD7SVBfVpJ++rp2E1SFU5+3dN74xylybLObiGCbePAgFLN0W5+v7f3Kx wBNS3JkhCi4kA5AJqJnYAdLERDT5uvXyegLV7nqdccH0jZ2pYahaxCFUddY5nTa0Q== X-Received: by 2002:a05:600c:190b:b0:49c:fa20:cbfd with SMTP id 5b1f17b1804b1-49cfa20cd63mr117548435e9.20.1788641121120; Sat, 05 Sep 2026 13:45:21 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa0048511f7ccf23d3ce.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:4851:1f7c:cf23:d3ce]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-485885bfdf6sm17069098f8f.34.2026.09.05.13.45.20 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sat, 05 Sep 2026 13:45:20 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][wrynose 19/40] libevent: upgrade 2.1.12 -> 2.1.13 Date: Sat, 5 Sep 2026 22:44:20 +0200 Message-ID: <97935c0f6b08f298d27d79b2b1914e45455f3860.1788629392.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Sat, 05 Sep 2026 20:45:25 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/245171 From: Ross Burton Security Fixes (evtag, evrpc): Fix an out-of-bounds read in decode_tag_internal. (Found by Brubbish. GHSA-fj29-64w6-73h6) Fix an integer overflow in evtag_unmarshal_header. (Found by Brubbish. GHSA-45c6-qx49-89m8) Security Fixes (evhttp): Discard HTTP trailers, to prevent header smuggling attacks. (Found by sebastianosrt. GHSA-2gmv-p5m7-98p6) Restrict HTTP header parsing to prevent request smuggling. (Originally reported by xclow3n; and then by kodareef5, nstaller0490, AsafMeizneer, and yaotushaozhu. GHSA-q39v-w2g7-gr8j.) Treat CRLF and %00 more strictly in HTTP headers, to prevent parser mismatch attacks. (Reported by xclow3n and AsafMeizner. See GHSA-q39v-w2g7-gr8j, GHSA-jcwh-pvf2-73p2.) Fix a heap out-of-bound write that could occur when using AF_UNIX sockets and compiling libevent with -DNDEBUG. (Found by mat-mo. GHSA-cvq5-vrvr-j338) Security fixes (evbuffer, bufferevent): Fixed a dangling pointer in evbuffer_add_reference. (Found by DarkaMaul. GHSA-c2pj-cg4r-88c8) Security fixes (evdns): Fix an out-of-bounds write in dnsname_to_labels when building a DNS response of 2^16 bytes. (Found by sectroyer. GHSA-58rx-7448-jw47) Security fixes (example code): Avoid using strcpy() in sample/http-server.c. (Reported by sectroyer. GHSA-5rgj-2c58-7jrc.) Signed-off-by: Ross Burton Signed-off-by: Richard Purdie (From OE-Core rev: 9ae7030db6f5c415de94b6d85eaac418ae1e0f7b) Full release notes: * https://github.com/libevent/libevent/releases/tag/release-2.1.13-stable Unpatched CVE statuses will get fixed with backport of latest cve-tooling. Removed github style user references. Signed-off-by: Peter Marko Signed-off-by: Yoann Congal --- ...s_dns.c-patch-out-tests-that-require-a-wo.patch | 8 ++++---- ...s.h-Increase-default-timeval-tolerance-50.patch | 10 +++++----- ...-util-monotonic_prc_fallback-as-retriable.patch | 11 ++++------- ...e-tests-are-marked-failed-only-when-all-a.patch | 9 +++------ .../libevent/Makefile-missing-test-dir.patch | 14 ++++++++++---- .../{libevent_2.1.12.bb => libevent_2.1.13.bb} | 2 +- 6 files changed, 27 insertions(+), 27 deletions(-) rename meta/recipes-support/libevent/{libevent_2.1.12.bb => libevent_2.1.13.bb} (95%) diff --git a/meta/recipes-support/libevent/libevent/0001-test-regress_dns.c-patch-out-tests-that-require-a-wo.patch b/meta/recipes-support/libevent/libevent/0001-test-regress_dns.c-patch-out-tests-that-require-a-wo.patch index 505153d285e..bab94a17ecd 100644 --- a/meta/recipes-support/libevent/libevent/0001-test-regress_dns.c-patch-out-tests-that-require-a-wo.patch +++ b/meta/recipes-support/libevent/libevent/0001-test-regress_dns.c-patch-out-tests-that-require-a-wo.patch @@ -1,4 +1,4 @@ -From 7c17967b8fd2d18b74a8934fd9bb8212ebd6a271 Mon Sep 17 00:00:00 2001 +From 3444b04844a0cd75050d16e9382427f0f431a948 Mon Sep 17 00:00:00 2001 From: Alexander Kanavin Date: Thu, 9 Jan 2020 13:22:46 +0100 Subject: [PATCH] test/regress_dns.c: patch out tests that require a working @@ -14,10 +14,10 @@ Signed-off-by: Alexander Kanavin 1 file changed, 4 deletions(-) diff --git a/test/regress_dns.c b/test/regress_dns.c -index d2084b7..a1a8f3b 100644 +index 9a8bff4..7449e94 100644 --- a/test/regress_dns.c +++ b/test/regress_dns.c -@@ -2394,8 +2394,6 @@ struct testcase_t dns_testcases[] = { +@@ -2459,8 +2459,6 @@ struct testcase_t dns_testcases[] = { { "reissue_disable_when_inactive", dns_reissue_disable_when_inactive_test, TT_FORK|TT_NEED_BASE|TT_NO_LOGS, &basic_setup, NULL }, { "inflight", dns_inflight_test, TT_FORK|TT_NEED_BASE, &basic_setup, NULL }, @@ -26,7 +26,7 @@ index d2084b7..a1a8f3b 100644 #ifdef EVENT__HAVE_SETRLIMIT { "bufferevent_connect_hostname_emfile", test_bufferevent_connect_hostname, TT_FORK|TT_NEED_BASE, &basic_setup, (char*)"emfile" }, -@@ -2405,8 +2403,6 @@ struct testcase_t dns_testcases[] = { +@@ -2470,8 +2468,6 @@ struct testcase_t dns_testcases[] = { { "disable_when_inactive_no_ns", dns_disable_when_inactive_no_ns_test, TT_FORK|TT_NEED_BASE|TT_NO_LOGS, &basic_setup, NULL }, diff --git a/meta/recipes-support/libevent/libevent/0002-test-regress.h-Increase-default-timeval-tolerance-50.patch b/meta/recipes-support/libevent/libevent/0002-test-regress.h-Increase-default-timeval-tolerance-50.patch index 0b20eda3c08..effb825f315 100644 --- a/meta/recipes-support/libevent/libevent/0002-test-regress.h-Increase-default-timeval-tolerance-50.patch +++ b/meta/recipes-support/libevent/libevent/0002-test-regress.h-Increase-default-timeval-tolerance-50.patch @@ -1,4 +1,4 @@ -From dff8fd27edb23bc1486809186c6a4fe1f75f2179 Mon Sep 17 00:00:00 2001 +From 64f2b035a1073c9f594036b46521e19dac029ec2 Mon Sep 17 00:00:00 2001 From: Yi Fan Yu Date: Thu, 22 Apr 2021 22:35:59 -0400 Subject: [PATCH] test/regress.h: Increase default timeval tolerance 50 ms -> @@ -11,7 +11,7 @@ related tests in arm64 QEMU. See: https://bugzilla.yoctoproject.org/show_bug.cgi?id=14163 (The root cause seems to be a heavy load) -Upstream-Status: Submitted [https://github.com/libevent/libevent/pull/1157] +Upstream-Status: Backport [https://github.com/libevent/libevent/pull/1157] Signed-off-by: Yi Fan Yu --- @@ -19,10 +19,10 @@ Signed-off-by: Yi Fan Yu 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/test/regress.h b/test/regress.h -index f06a7669..829af4a7 100644 +index 43cb4ea..21cfb5f 100644 --- a/test/regress.h +++ b/test/regress.h -@@ -127,7 +127,7 @@ int test_ai_eq_(const struct evutil_addrinfo *ai, const char *sockaddr_port, +@@ -123,7 +123,7 @@ int test_ai_eq_(const struct evutil_addrinfo *ai, const char *sockaddr_port, tt_int_op(labs(timeval_msec_diff((tv1), (tv2)) - diff), <=, tolerance) #define test_timeval_diff_eq(tv1, tv2, diff) \ @@ -30,4 +30,4 @@ index f06a7669..829af4a7 100644 + test_timeval_diff_leq((tv1), (tv2), (diff), 100) long timeval_msec_diff(const struct timeval *start, const struct timeval *end); - + diff --git a/meta/recipes-support/libevent/libevent/0003-test-mark-util-monotonic_prc_fallback-as-retriable.patch b/meta/recipes-support/libevent/libevent/0003-test-mark-util-monotonic_prc_fallback-as-retriable.patch index ddc19c495f1..aa0d4f9ef1b 100644 --- a/meta/recipes-support/libevent/libevent/0003-test-mark-util-monotonic_prc_fallback-as-retriable.patch +++ b/meta/recipes-support/libevent/libevent/0003-test-mark-util-monotonic_prc_fallback-as-retriable.patch @@ -1,20 +1,20 @@ -From d01a57a998798da977c470f3b8d6a457c1adb144 Mon Sep 17 00:00:00 2001 +From 9ad27391a97157eb8cee84a7e9cc3dc93df34cbb Mon Sep 17 00:00:00 2001 From: Azat Khuzhin Date: Sun, 19 Sep 2021 00:57:31 +0300 Subject: [PATCH] test: mark util/monotonic_prc_fallback as retriable Refs: #1193 -Upstream-Status: Backport +Upstream-Status: Backport [https://github.com/libevent/libevent/commit/04fcd7c6df158bb65261867de4b9ec8439696934] --- test/regress_util.c | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/test/regress_util.c b/test/regress_util.c -index 45caa2700a40..a9e80db20149 100644 +index fd149b3..10244d6 100644 --- a/test/regress_util.c +++ b/test/regress_util.c -@@ -1672,7 +1672,7 @@ struct testcase_t util_testcases[] = { +@@ -1674,7 +1674,7 @@ struct testcase_t util_testcases[] = { { "monotonic_res_fallback", test_evutil_monotonic_res, TT_OFF_BY_DEFAULT, &basic_setup, (void*)"fallback" }, { "monotonic_prc", test_evutil_monotonic_prc, 0, &basic_setup, (void*)"" }, { "monotonic_prc_precise", test_evutil_monotonic_prc, TT_RETRIABLE, &basic_setup, (void*)"precise" }, @@ -23,6 +23,3 @@ index 45caa2700a40..a9e80db20149 100644 { "date_rfc1123", test_evutil_date_rfc1123, 0, NULL, NULL }, { "evutil_v4addr_is_local", test_evutil_v4addr_is_local, 0, NULL, NULL }, { "evutil_v6addr_is_local", test_evutil_v6addr_is_local, 0, NULL, NULL }, --- -2.31.1 - diff --git a/meta/recipes-support/libevent/libevent/0004-test-retriable-tests-are-marked-failed-only-when-all-a.patch b/meta/recipes-support/libevent/libevent/0004-test-retriable-tests-are-marked-failed-only-when-all-a.patch index 26b707ad316..4cb2a6d7bc0 100644 --- a/meta/recipes-support/libevent/libevent/0004-test-retriable-tests-are-marked-failed-only-when-all-a.patch +++ b/meta/recipes-support/libevent/libevent/0004-test-retriable-tests-are-marked-failed-only-when-all-a.patch @@ -1,4 +1,4 @@ -From 36ebd92fa53c0097f1e2f9ec5aa5b5c6ec1b411d Mon Sep 17 00:00:00 2001 +From 59ab048f0fe32fb8d8e43214f93c32b53148419c Mon Sep 17 00:00:00 2001 From: Thomas Perrot Date: Wed, 29 Sep 2021 13:50:35 +0200 Subject: [PATCH] test: retriable tests are marked failed only when all @@ -15,7 +15,7 @@ Signed-off-by: Thomas Perrot 2 files changed, 7 insertions(+), 8 deletions(-) diff --git a/test/tinytest.c b/test/tinytest.c -index 85dfe74a720e..bf2882418eb6 100644 +index 85dfe74..bf28824 100644 --- a/test/tinytest.c +++ b/test/tinytest.c @@ -310,7 +310,8 @@ testcase_run_forked_(const struct testgroup_t *group, @@ -64,7 +64,7 @@ index 85dfe74a720e..bf2882418eb6 100644 switch (test_ret_err) { diff --git a/test/tinytest.h b/test/tinytest.h -index d321dd467542..c276b5339331 100644 +index d321dd4..c276b53 100644 --- a/test/tinytest.h +++ b/test/tinytest.h @@ -92,7 +92,7 @@ char *tinytest_format_hex_(const void *, unsigned long); @@ -76,6 +76,3 @@ index d321dd467542..c276b5339331 100644 void tinytest_set_aliases(const struct testlist_alias_t *aliases); --- -2.31.1 - diff --git a/meta/recipes-support/libevent/libevent/Makefile-missing-test-dir.patch b/meta/recipes-support/libevent/libevent/Makefile-missing-test-dir.patch index 8880bd04075..c54a2b7bb0f 100644 --- a/meta/recipes-support/libevent/libevent/Makefile-missing-test-dir.patch +++ b/meta/recipes-support/libevent/libevent/Makefile-missing-test-dir.patch @@ -1,4 +1,7 @@ -Fix missing test directory creation. +From c16d91420b94701065d3bdfdf96c41e0710c3bc8 Mon Sep 17 00:00:00 2001 +From: Andrej Valek +Date: Tue, 25 Apr 2017 08:11:48 +0200 +Subject: [PATCH] Fix missing test directory creation. GCC used in OE-core has "dependency tracking" disabled and libevent has problem with this. @@ -12,12 +15,15 @@ Workaround specific to our build system. Signed-off-by: Andrej Valek Signed-off-by: Pascal Bach +--- + test/include.am | 1 + + 1 file changed, 1 insertion(+) -diff --git a/libevent-2.1.8-stable/test/include.am b/libevent-2.1.8-stable/test/include.am -index eea249f..d323dff 100644 +diff --git a/test/include.am b/test/include.am +index 0437524..48c7307 100644 --- a/test/include.am +++ b/test/include.am -@@ -161,6 +161,7 @@ test_bench_httpclient_LDADD = $(LIBEVENT_GC_SECTIONS) libevent_core.la +@@ -162,6 +162,7 @@ test_bench_httpclient_LDADD = $(LIBEVENT_GC_SECTIONS) libevent_core.la test/regress.gen.c test/regress.gen.h: test/rpcgen-attempted test/rpcgen-attempted: test/regress.rpc event_rpcgen.py test/rpcgen_wrapper.sh diff --git a/meta/recipes-support/libevent/libevent_2.1.12.bb b/meta/recipes-support/libevent/libevent_2.1.13.bb similarity index 95% rename from meta/recipes-support/libevent/libevent_2.1.12.bb rename to meta/recipes-support/libevent/libevent_2.1.13.bb index 8bb6d90d705..431018f0f35 100644 --- a/meta/recipes-support/libevent/libevent_2.1.12.bb +++ b/meta/recipes-support/libevent/libevent_2.1.13.bb @@ -20,7 +20,7 @@ SRC_URI = "${GITHUB_BASE_URI}/download/release-${PV}-stable/${BP}-stable.tar.gz file://0004-test-retriable-tests-are-marked-failed-only-when-all-a.patch \ " -SRC_URI[sha256sum] = "92e6de1be9ec176428fd2367677e61ceffc2ee1cb119035037a27d346b0403bb" +SRC_URI[sha256sum] = "f7e9383b8c0baa81b687e5b5eecc01beefaf1b19b64151d95ed61647fe7a315c" UPSTREAM_CHECK_REGEX = "releases/tag/release-(?P.+)-stable" S = "${UNPACKDIR}/${BPN}-${PV}-stable" From patchwork Sat Sep 5 20:44:21 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 97367 X-Patchwork-Delegate: yoann.congal@smile.fr Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id CA8A4C79FAC for ; Sat, 5 Sep 2026 20:45:25 +0000 (UTC) Received: from mail-wr1-f41.google.com (mail-wr1-f41.google.com [209.85.221.41]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.2590.1788641123320811011 for ; Sat, 05 Sep 2026 13:45:23 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=toVlawPQ; spf=pass (domain: smile.fr, ip: 209.85.221.41, mailfrom: yoann.congal@smile.fr) Received: by mail-wr1-f41.google.com with SMTP id ffacd0b85a97d-47fe89fb333so1334651f8f.3 for ; Sat, 05 Sep 2026 13:45:23 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1788641121; x=1789245921; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=10nuvAhDMx3wwWeoSWDSjS9j62VcGKBKpFMqm3Fp1B0=; b=toVlawPQ/D7mVRlEdR7CQoiUTfMR6nWzRTOCpNtrfVdDwivpH7m4yr4bH0Hyzi4oOF A4vhZ8PQTpOcgpsvysZ55hMcDQwzCAwp4OAMnJe+s/X6aZ9OBtkbmGGXY5Qo+jRE1OLu auD7j0wn7X9eLX7xEuEC4B1IkgpU4HlkPZvmE= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1788641121; x=1789245921; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=10nuvAhDMx3wwWeoSWDSjS9j62VcGKBKpFMqm3Fp1B0=; b=GCgtAh+4+tuASHNPVgc/hJSrMwC9n1dwIdworpQBHwQLJ9jkNjlN4+XjYOmvqtrCIB 8UtiHD2LCdFr9XstFeBriL++8AyJgaUIfSCJXahIoJh+GMvk5J1kbSnFr6h20oWeS/vi 8jfgy79s1WBfy60P61zEOLR2LMvp1dcGFgtCSPL+F/DhwBPI1yg0xf3zZguy5WoitVaO y0UNmqQrIYZlTvToGRDWTNnes8q0G4tEojXW+jCCKmrgjxQppDln/fBlb6gM67P4KvSF HJ7eP+lQFBMqagfQEgmglZ1p75Uyl6jHvonMoCoo0WWRakE9Z3IPbJuPRyjhZdmv5Q6R xLNw== X-Gm-Message-State: AFuF++lyCXAtVSRECtK3g0LnZ1jRYtlQ+M/9diJXVRIzxKje86uW2dtj 6fWY0Sx4BLW/Jvx1vdqiRMdtRGNkQWad75sl8ZVaOMZYSOPjHh6lZCImAjGCpHGH1lM0iIxtzKN yKZW5YYs= X-Gm-Gg: AYBFou2wyEotVwMefPh8ZSQtcy0YXrzANk+Oqfnq98Q7CTRnMICR+Kpeb9fy06zxFww 9ko9+qx9RDhrxF/C725Q1ivOQMIyjcHrwxNW2Xvnh0NtIiEhBcXB2xnOZD6WMwmNdC8EnfzUxNT BeuUuSDdKvAWIBCS5TTJ1hR0ne0fCLp8D2Qiz8eYh9kWM7Vgu4NzsJnuSUoMXxoCtdGri70lVaX RJW0ld9fvMExC4oq1kXn2Fvcq9YTAP7z/gXcvbezdfE6HbM1STxfozDuKzzHSyPLcLtxML7AOC4 r86dojHb2FhzulLavWYbeJVCbKFlPp06dbh8glIOYJimafJA7fpXzFx3OFqhXdeTj7scDO7XZ8D LmulY0b5WRBq4YYQU3PEqDFPCbsOozfFLMB5LWfbNnn1VmNPU3jp4OoPtEBKOB/ZTgSX34F2FZG CRbyTBnoRmw5zAD3pFL237dQDkZ1v979PQFzYWKElIRH2ZKTYLhqJjL98+LMqlYrsgp3HOP7lEX yJTbn7izIpDbeQbiq8rjgc8EDQKJ5JCPO0RQDVkkoF2RRw1y9GFMx3iGP96D/Ykyw== X-Received: by 2002:a05:6000:4710:b0:485:8a47:5b83 with SMTP id ffacd0b85a97d-4858a475c60mr11730000f8f.32.1788641121650; Sat, 05 Sep 2026 13:45:21 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa0048511f7ccf23d3ce.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:4851:1f7c:cf23:d3ce]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-485885bfdf6sm17069098f8f.34.2026.09.05.13.45.21 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sat, 05 Sep 2026 13:45:21 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][wrynose 20/40] libevent: set status for CVE-2026-63380 Date: Sat, 5 Sep 2026 22:44:21 +0200 Message-ID: X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Sat, 05 Sep 2026 20:45:25 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/245172 From: Peter Marko Per [1] this only affects 2.2.1-alpha. Also [2] markes their versions as not-affected. [1] https://github.com/libevent/libevent/security/advisories/GHSA-3rpf-frgx-xq34 [2] https://security-tracker.debian.org/tracker/CVE-2026-63380 Signed-off-by: Peter Marko Signed-off-by: Yoann Congal --- meta/recipes-support/libevent/libevent_2.1.13.bb | 2 ++ 1 file changed, 2 insertions(+) diff --git a/meta/recipes-support/libevent/libevent_2.1.13.bb b/meta/recipes-support/libevent/libevent_2.1.13.bb index 431018f0f35..222d4fd5b3c 100644 --- a/meta/recipes-support/libevent/libevent_2.1.13.bb +++ b/meta/recipes-support/libevent/libevent_2.1.13.bb @@ -55,3 +55,5 @@ do_install_ptest() { # handle multilib sed -i s:@libdir@:${libdir}:g ${D}${PTEST_PATH}/run-ptest } + +CVE_STATUS[CVE-2026-63380] = "fixed-version: only affects 2.2.1-alpha" From patchwork Sat Sep 5 20:44:22 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 97368 X-Patchwork-Delegate: yoann.congal@smile.fr Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id DB28CC79FAB for ; Sat, 5 Sep 2026 20:45:25 +0000 (UTC) Received: from mail-wr1-f47.google.com (mail-wr1-f47.google.com [209.85.221.47]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.2483.1788641124383408759 for ; Sat, 05 Sep 2026 13:45:24 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=OHbkKHim; spf=pass (domain: smile.fr, ip: 209.85.221.47, mailfrom: yoann.congal@smile.fr) Received: by mail-wr1-f47.google.com with SMTP id ffacd0b85a97d-482e4998d28so1639603f8f.2 for ; Sat, 05 Sep 2026 13:45:24 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1788641123; x=1789245923; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=vtbwRHNefZ/g8bc7f3MjPzhux7YspU8IbHzmEaFLDZ0=; b=OHbkKHimNCPCgoliH1G/FAITacIIBI0Huf4jbHLC9IYzZ+JKrHtX75gFY7exNxzLzq 8z5/uA013+cWJuJWMfYSgvkHkA9rxTyzUIx0AcbWqUk7jzwmZ4TaiZQwawrbL0Xq726M 1FH3dc5a+XCwuoq3NiFpYzUaJXMd7lDxZHnX8= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1788641123; x=1789245923; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=vtbwRHNefZ/g8bc7f3MjPzhux7YspU8IbHzmEaFLDZ0=; b=SWosW8GaknZnElB1tzkOv22NDo2+m6ydv/H93NmPD3q6Zbm9Avp0L4xtSH2ROnvw67 n0LDYrEY5oI8oWxOXvy0o3BZh0dSlr+JDtEVhBeHHHNgw57yd9oKTeLmt3l2tBRNUMrg qlFfqzfpFiiPh+6TNW0MVP/KwnwK9FJjP0PKUI8N9EWybQ+I6sxsBipHSHtS6JCoRrNp 4vf/YzpIryc8WtqF6NV3CCqr/J3r8bG/PVPMXWnPCsP/T2wDsE7x9EIPbt5YajnIOMLc i/1XncgRxhOviQ6OJrmRxTu3aEPwS60+SceKCnOhQOTmlFobKu5nwUDHdX+8NJQnQroQ Zg4g== X-Gm-Message-State: AFuF++lojGQTfyScVb9CmhdVIhOxpvG4DFx6chZAafDSwzDDssWJXc4i 32vQyS5l172ZNiNfuWJaYJQPvaXARPPeOZvpTptgVWpt/+zHzrYqwUuI9JAkm3HeoOeEMCldl/c ebpAdqYY= X-Gm-Gg: AYBFou30sZ8/VAcK+0wLyxXZQqdZXqEX9U0j614/kGzv/w+b6BDFxoV/HF69OB3VRuQ 0JcvGRnCUnzVI/2/3uEHhX2YmHhAxzxQI849V/vb9IYicBEJ+ehmadEYjTi/pBxTZUDybQuImxa SqXfBS8Xcr/bpQSSSGvMp9ilCPzYrbM9spe2nYTdNneyoJ1QVK5aZ4wdsbzVJRDa+ERj1tUCnbI Cr2IgWCavFzlhzDCwgGyIwQmb/cA9uL6VbWpPOtsemP5QTW8wz14EbbLPRbDeKKKhxC2HM2rskK HE+GtzORrvF2baE2jqDkVJ5TEyD70BUmWC+V9madZR+scTAP0Ns6empB+uVgAvgkWNx8I08aoqL pkIbSD0QiKZJTA3H26WoQuh/7fpkWzfU6JoUNenxv9VqxZpMFUsVwo6j2G3JU9mjWEnou04g8Re A975om6k46uyKwuI7SaQ++ilqthpYWsT5IB36c8GhuHum4x05dpDVEajgO+JzopWAVGoOgkNXZ4 cQ0LMSn6J0IMcssMZt675WACO+xOL5lercLwJlxVNHysBa6y8UGXzMYJV2n3xRXmPpDxo2nmMvF X-Received: by 2002:a05:6000:25fe:b0:485:8cb8:b838 with SMTP id ffacd0b85a97d-4858cb8b900mr9651586f8f.7.1788641122609; Sat, 05 Sep 2026 13:45:22 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa0048511f7ccf23d3ce.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:4851:1f7c:cf23:d3ce]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-485885bfdf6sm17069098f8f.34.2026.09.05.13.45.21 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sat, 05 Sep 2026 13:45:22 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][wrynose 21/40] libxfont2: Fix CVE-2026-56001 Date: Sat, 5 Sep 2026 22:44:22 +0200 Message-ID: <5d9fe1c8aa1c403701ca029e9c89286a10131651.1788629392.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Sat, 05 Sep 2026 20:45:25 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/245173 From: Vijay Anusuri Pick patch according to [2] [1] https://nvd.nist.gov/vuln/detail/CVE-2026-56001 [2] https://security-tracker.debian.org/tracker/CVE-2026-56001 Signed-off-by: Vijay Anusuri Signed-off-by: Yoann Congal --- .../xorg-lib/libxfont2/CVE-2026-56001.patch | 75 +++++++++++++++++++ .../xorg-lib/libxfont2_2.0.7.bb | 3 + 2 files changed, 78 insertions(+) create mode 100644 meta/recipes-graphics/xorg-lib/libxfont2/CVE-2026-56001.patch diff --git a/meta/recipes-graphics/xorg-lib/libxfont2/CVE-2026-56001.patch b/meta/recipes-graphics/xorg-lib/libxfont2/CVE-2026-56001.patch new file mode 100644 index 00000000000..58a1881442c --- /dev/null +++ b/meta/recipes-graphics/xorg-lib/libxfont2/CVE-2026-56001.patch @@ -0,0 +1,75 @@ +From be0b08e2d354138d3222b4490e2a77c6ee42f778 Mon Sep 17 00:00:00 2001 +From: Peter Hutterer +Date: Mon, 1 Jun 2026 16:46:10 +1000 +Subject: [PATCH] bitscale: fix integer overflow in BitmapScaleBitmaps + bytestoalloc + +bytestoalloc is declared as unsigned int (32-bit). When the sum of +per-glyph byte counts exceeds 2^32, the value wraps around and calloc() +allocates a buffer that is too small. The subsequent ScaleBitmap loop +then writes past the end of the allocated buffer. + +Change bytestoalloc from unsigned int to size_t to match the actual +allocation size type, and add an explicit overflow check in the +accumulation loop to bail out if the total would exceed SIZE_MAX. + +This vulnerability was discovered by: +Anonymous working with TrendAI Zero Day Initiative + +CVE-2026-56001/ZDI-CAN-30558 + +Assisted-by: Claude:claude-opus-4-6 +Signed-off-by: Peter Hutterer +Part-of: + +Upstream-Status: Backport [https://gitlab.freedesktop.org/xorg/lib/libxfont/-/commit/be0b08e2d354138d3222b4490e2a77c6ee42f778] +CVE: CVE-2026-56001 +Signed-off-by: Vijay Anusuri +--- + src/bitmap/bitscale.c | 23 ++++++++++++++++++++--- + 1 file changed, 20 insertions(+), 3 deletions(-) + +diff --git a/src/bitmap/bitscale.c b/src/bitmap/bitscale.c +index 3f3c10e..5f465d1 100644 +--- a/src/bitmap/bitscale.c ++++ b/src/bitmap/bitscale.c +@@ -1456,7 +1456,7 @@ BitmapScaleBitmaps(FontPtr pf, /* scaled font */ + opci; + FontInfoPtr pfi; + int glyph; +- unsigned bytestoalloc = 0; ++ size_t bytestoalloc = 0; + int firstCol, lastCol, firstRow, lastRow; + + double xform[4], inv_xform[4]; +@@ -1483,8 +1483,25 @@ BitmapScaleBitmaps(FontPtr pf, /* scaled font */ + glyph = pf->glyph; + for (i = 0; i < nchars; i++) + { +- if ((pci = ACCESSENCODING(bitmapFont->encoding, i))) +- bytestoalloc += BYTES_FOR_GLYPH(pci, glyph); ++ if ((pci = ACCESSENCODING(bitmapFont->encoding, i))) { ++ size_t glyphsize = BYTES_FOR_GLYPH(pci, glyph); ++ if (bytestoalloc > SIZE_MAX - glyphsize) { ++ fprintf(stderr, ++ "Error: bitmap allocation overflow for scaled font\n"); ++ goto bail; ++ } ++ bytestoalloc += glyphsize; ++ } ++ } ++ ++ /* Reject unreasonably large bitmap allocations that could result ++ * from malicious fonts with extreme scale factors. 256 MiB is ++ * far beyond any legitimate scaled bitmap font. */ ++#define BITMAP_SCALE_MAX_ALLOC (256 * 1024 * 1024) ++ if (bytestoalloc > BITMAP_SCALE_MAX_ALLOC) { ++ fprintf(stderr, ++ "Error: scaled bitmap size %zu exceeds limit\n", bytestoalloc); ++ goto bail; + } + + /* Do we add the font malloc stuff for VALUE ADDED ? */ +-- +GitLab + diff --git a/meta/recipes-graphics/xorg-lib/libxfont2_2.0.7.bb b/meta/recipes-graphics/xorg-lib/libxfont2_2.0.7.bb index bf49d728b92..bc6990576fd 100644 --- a/meta/recipes-graphics/xorg-lib/libxfont2_2.0.7.bb +++ b/meta/recipes-graphics/xorg-lib/libxfont2_2.0.7.bb @@ -15,6 +15,9 @@ XORG_PN = "libXfont2" BBCLASSEXTEND = "native" +SRC_URI += "file://CVE-2026-56001.patch \ + " + SRC_URI[sha256sum] = "8b7b82fdeba48769b69433e8e3fbb984a5f6bf368b0d5f47abeec49de3e58efb" PACKAGECONFIG ??= "${@bb.utils.filter('DISTRO_FEATURES', 'ipv6', d)}" From patchwork Sat Sep 5 20:44:23 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 97371 X-Patchwork-Delegate: yoann.congal@smile.fr Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 12507C79FAD for ; Sat, 5 Sep 2026 20:45:26 +0000 (UTC) Received: from mail-wr1-f41.google.com (mail-wr1-f41.google.com [209.85.221.41]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.2485.1788641125034950482 for ; Sat, 05 Sep 2026 13:45:25 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=qUwSsBwX; spf=pass (domain: smile.fr, ip: 209.85.221.41, mailfrom: yoann.congal@smile.fr) Received: by mail-wr1-f41.google.com with SMTP id ffacd0b85a97d-4843e397f74so2721362f8f.1 for ; Sat, 05 Sep 2026 13:45:24 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1788641123; x=1789245923; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=g7SdUgbR55gNZ/UUsiD5jJMsuFXzfB86/xHoKD1AF+g=; b=qUwSsBwXPPNAc51xjSohZufozB69ONK7YkMwJYsVXBoAkISxxtQaOdyO+Halojyvac m2x0LKy0k/VBIOHraOwPS9u/qH5tmRDT4nq/z8PJTqIBz9LS7SiqyMaxmVkn37spx88r 5csmETgXFcf38vKNHgu52wLLBomQIPXkTGupc= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1788641123; x=1789245923; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=g7SdUgbR55gNZ/UUsiD5jJMsuFXzfB86/xHoKD1AF+g=; b=rYVQKheZuhv6XaXYrH8CwtsWG2BoaRJfBLiWVaLL40v0QnH2v5QFivwmj6ZlwdbSYn WOn8Bi/uI7puo/pLp2Za9qzA0K5CiqbbnMYI5T2PKMq9cffmp+5WzdQHBAn+qqgZrToZ IPnxfTRbzAFgFDAbTtgCYyr/RsigJQ7guRPOhqJmFmg8tFyJ4VpMQX54uZCuHdzQPPce 5k313J6q8OTLIVxhhIverRsc95XMAc78S5wPVZvTfX81NB+fhV6BdOcFDG6qKzLtTbd/ VY2Wvgs3bMWtFTwHrZ10G9wklA4JinJPcdzMAFwdaL8FKPcTnhy8Mv360Fg5dflz2fwB HUBw== X-Gm-Message-State: AFuF++kz+8Vw52ddn9hWPh0kpD+j4tUP+1eqvAXyfRYnxcUbeRGs4Vdw wKlDZNAxDG3u9gebdAGLBZnk8rsrS0dreK3imgXC9xzTQi0EHCAeFdTfp59cGSrvBTFirnAOmRV VGLBwpQI= X-Gm-Gg: AYBFou0OMbpDeh3TFKCPiJMfbQcpHP2tqlZ2IhGxIgWviXCqohojQr9Qoe3TamXFAVM WcV1fWqiYj/VfU1cecC8Pp5eN4R5xpCbRnd/vVWlFWhHJM3FGYR/zlkO92G0FMhpWF3G1deGZKY AwF9Bv9PPPjA+LNK5gWdoPJZeKDwJB5Ba3qbWtBoCrxUfxPz68rkbVh/OOowPfy/8rVXCVcdFqU kqMqr+XX9j7USvbMneOYuqfBxHuchj7L0K+4XpK7uJACaKOKyyaAh/HFAk3eoo5MTEuqTHxtL3Y BSG6Fnu8u4j0vmKewgUF3L3b0K3f5CqKhy9NsWT2wUQA8EJ/S4oUaGabT1ZSWIvIoRmHZnBlyPL zU/rJMRIAHFelVFS4xLACwURen2kc8sAhyD/JhyEHUbJQ/lIXOeHEh83mOpbLdYBzigoi4YL4AZ 2enCw8wobnf+KvlN6ODDvn61s4h8+RKpTE6v1EHl5jVciNUkx49uOuvce6Ad3I8ZfiJ/EGDHjjt SyZaZywrv+CwF67DmAHEDghnSR20biPHBeTt7JVXs8T9tPD2HeV9Cc+HeEB1DNxoA== X-Received: by 2002:a05:6000:4a19:b0:47f:ece1:1eca with SMTP id ffacd0b85a97d-485891dce97mr13415953f8f.1.1788641123160; Sat, 05 Sep 2026 13:45:23 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa0048511f7ccf23d3ce.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:4851:1f7c:cf23:d3ce]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-485885bfdf6sm17069098f8f.34.2026.09.05.13.45.22 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sat, 05 Sep 2026 13:45:22 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][wrynose 22/40] libxfont2: Fix CVE-2026-56002 Date: Sat, 5 Sep 2026 22:44:23 +0200 Message-ID: <0b2b52445ceb88e4cb42b3c03797c67f61fbb299.1788629392.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Sat, 05 Sep 2026 20:45:26 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/245174 From: Vijay Anusuri Pick patch according to [2] [1] https://nvd.nist.gov/vuln/detail/CVE-2026-56002 [2] https://security-tracker.debian.org/tracker/CVE-2026-56002 Signed-off-by: Vijay Anusuri Signed-off-by: Yoann Congal --- .../xorg-lib/libxfont2/CVE-2026-56002.patch | 138 ++++++++++++++++++ .../xorg-lib/libxfont2_2.0.7.bb | 1 + 2 files changed, 139 insertions(+) create mode 100644 meta/recipes-graphics/xorg-lib/libxfont2/CVE-2026-56002.patch diff --git a/meta/recipes-graphics/xorg-lib/libxfont2/CVE-2026-56002.patch b/meta/recipes-graphics/xorg-lib/libxfont2/CVE-2026-56002.patch new file mode 100644 index 00000000000..b2874c7c775 --- /dev/null +++ b/meta/recipes-graphics/xorg-lib/libxfont2/CVE-2026-56002.patch @@ -0,0 +1,138 @@ +From b4389e0b1d84a690b819bb27b1439968811a3674 Mon Sep 17 00:00:00 2001 +From: Peter Hutterer +Date: Mon, 1 Jun 2026 16:48:40 +1000 +Subject: [PATCH] pcfread: validate bitmap sizes and offsets against per-glyph + metrics + +pcfReadFont() uses bitmapSizes[] read directly from the PCF file to +allocate the repadded bitmap buffer. However, per-glyph metrics (also +from the file) control how much data RepadBitmap() writes. A malicious +PCF font can declare a small bitmapSizes[] value while having per-glyph +metrics that require more space, causing a heap buffer overflow. + +A similar issue happens with the encoding offsets: pcfReadFont reads +encoding offsets from the PCF file and uses them to index into the +metrics array without bounds checking. A crafted font can set an +encoding offset larger than nmetrics, causing an out-of-bounds pointer +that is later dereferenced when glyphs are accessed through the encoding +table. + +And the no-repad bitmap path (when PCF_GLYPH_PAD matches the requested +glyph pad) only validated that each glyph's offset was within the bitmap +buffer, but did not check that the full glyph extent (offset + +BYTES_PER_ROW * height) fits within the buffer. A crafted font with a +glyph offset near the end of a small bitmap buffer but large glyph +metrics causes a heap buffer over-read when the glyph is later rendered. + +This vulnerability was discovered by: + Anonymous working with TrendAI Zero Day Initiative + +CVE-2026-56002/ZDI-CAN-30559 + +Assisted-by: Claude:claude-opus-4-6 +Signed-off-by: Peter Hutterer +Part-of: + +Upstream-Status: Backport [https://gitlab.freedesktop.org/xorg/lib/libxfont/-/commit/b4389e0b1d84a690b819bb27b1439968811a3674] +CVE: CVE-2026-56002 +Signed-off-by: Vijay Anusuri +--- + src/bitmap/pcfread.c | 59 +++++++++++++++++++++++++++++++++++++++++--- + 1 file changed, 56 insertions(+), 3 deletions(-) + +diff --git a/src/bitmap/pcfread.c b/src/bitmap/pcfread.c +index 7c2e7e1..a385331 100644 +--- a/src/bitmap/pcfread.c ++++ b/src/bitmap/pcfread.c +@@ -532,25 +532,74 @@ pcfReadFont(FontPtr pFont, FontFilePtr file, + int old, + new; + xCharInfo *metric; ++ int srcPad = PCF_GLYPH_PAD(format); + +- sizepadbitmaps = bitmapSizes[PCF_SIZE_TO_INDEX(glyph)]; +- padbitmaps = malloc(sizepadbitmaps); ++ /* Compute the actual required size from per-glyph metrics instead ++ * of trusting the file's bitmapSizes[] value, which may be smaller ++ * than the actual data written by RepadBitmap. */ ++ sizepadbitmaps = 0; ++ for (i = 0; i < nbitmaps; i++) { ++ int w, h, glyphBytes; ++ metric = &metrics[i].metrics; ++ w = metric->rightSideBearing - metric->leftSideBearing; ++ h = metric->ascent + metric->descent; ++ glyphBytes = BYTES_PER_ROW(w, glyph) * h; ++ if (glyphBytes < 0 || (glyphBytes > 0 && sizepadbitmaps > INT_MAX - glyphBytes)) { ++ pcfError("pcfReadFont(): bitmap size overflow\n"); ++ goto Bail; ++ } ++ sizepadbitmaps += glyphBytes; ++ } ++ padbitmaps = malloc(sizepadbitmaps ? sizepadbitmaps : 1); + if (!padbitmaps) { + pcfError("pcfReadFont(): Couldn't allocate padbitmaps (%d)\n", sizepadbitmaps); + goto Bail; + } + new = 0; + for (i = 0; i < nbitmaps; i++) { ++ int srcGlyphBytes; ++ + old = offsets[i]; + metric = &metrics[i].metrics; ++ ++ /* Validate source offset and source glyph size against the ++ * source bitmap buffer to prevent out-of-bounds reads. */ ++ srcGlyphBytes = BYTES_PER_ROW( ++ metric->rightSideBearing - metric->leftSideBearing, ++ srcPad) * (metric->ascent + metric->descent); ++ if (old < 0 || old > sizebitmaps || ++ srcGlyphBytes < 0 || srcGlyphBytes > sizebitmaps - old) { ++ pcfError("pcfReadFont(): bitmap offset/size out of bounds\n"); ++ free(padbitmaps); ++ goto Bail; ++ } ++ + offsets[i] = new; + new += RepadBitmap(bitmaps + old, padbitmaps + new, +- PCF_GLYPH_PAD(format), glyph, ++ srcPad, glyph, + metric->rightSideBearing - metric->leftSideBearing, + metric->ascent + metric->descent); + } + free(bitmaps); + bitmaps = padbitmaps; ++ } else { ++ /* Validate offsets and full glyph extents against bitmap buffer */ ++ for (i = 0; i < nbitmaps; i++) { ++ int glyphBytes; ++ xCharInfo *metric = &metrics[i].metrics; ++ ++ glyphBytes = BYTES_PER_ROW( ++ metric->rightSideBearing - metric->leftSideBearing, ++ glyph) * (metric->ascent + metric->descent); ++ if (offsets[i] >= (CARD32)sizebitmaps || ++ glyphBytes < 0 || ++ glyphBytes > sizebitmaps - (int)offsets[i]) { ++ pcfError("pcfReadFont(): bitmap offset/size out of bounds " ++ "(offset %u, size %d, total %d)\n", ++ offsets[i], glyphBytes, sizebitmaps); ++ goto Bail; ++ } ++ } + } + for (i = 0; i < nbitmaps; i++) + metrics[i].bits = bitmaps + offsets[i]; +@@ -625,6 +674,10 @@ pcfReadFont(FontPtr pFont, FontFilePtr file, + if (IS_EOF(file)) goto Bail; + if (encodingOffset == 0xFFFF) { + pFont->info.allExist = FALSE; ++ } else if (encodingOffset >= nmetrics) { ++ pcfError("pcfReadFont(): encoding offset %d out of range (nmetrics=%d)\n", ++ encodingOffset, nmetrics); ++ goto Bail; + } else { + if(!encoding[SEGMENT_MAJOR(i)]) { + encoding[SEGMENT_MAJOR(i)]= +-- +GitLab + diff --git a/meta/recipes-graphics/xorg-lib/libxfont2_2.0.7.bb b/meta/recipes-graphics/xorg-lib/libxfont2_2.0.7.bb index bc6990576fd..e004ac044c2 100644 --- a/meta/recipes-graphics/xorg-lib/libxfont2_2.0.7.bb +++ b/meta/recipes-graphics/xorg-lib/libxfont2_2.0.7.bb @@ -16,6 +16,7 @@ XORG_PN = "libXfont2" BBCLASSEXTEND = "native" SRC_URI += "file://CVE-2026-56001.patch \ + file://CVE-2026-56002.patch \ " SRC_URI[sha256sum] = "8b7b82fdeba48769b69433e8e3fbb984a5f6bf368b0d5f47abeec49de3e58efb" From patchwork Sat Sep 5 20:44:24 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 97374 X-Patchwork-Delegate: yoann.congal@smile.fr Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id DE05BC79F99 for ; Sat, 5 Sep 2026 20:45:35 +0000 (UTC) Received: from mail-wr1-f48.google.com (mail-wr1-f48.google.com [209.85.221.48]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.2486.1788641125713735317 for ; Sat, 05 Sep 2026 13:45:26 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=s5m8D7TF; spf=pass (domain: smile.fr, ip: 209.85.221.48, mailfrom: yoann.congal@smile.fr) Received: by mail-wr1-f48.google.com with SMTP id ffacd0b85a97d-482e067e908so1906861f8f.2 for ; Sat, 05 Sep 2026 13:45:25 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1788641124; x=1789245924; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=ou8UrQDyHYN6DIZguPWnk/xvJIGs7s20t5LrRsbfaWo=; b=s5m8D7TF/4lZMz5od450EBMvoU6s0nV4I5CvvPX+xRShoHGlFdPITHdeN54jcKaSEc OawH4RLbfE9AG8PSivl7A0bRtIXkyiC5H1jruDaeYqlja7nvJYGQ/c0AmET+HYaQVapX fCeRHSj0wjA62mrniUl0QHCsqMv8jkwid3Jzo= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1788641124; x=1789245924; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=ou8UrQDyHYN6DIZguPWnk/xvJIGs7s20t5LrRsbfaWo=; b=RdqY+A3sYBR9xVdCYSMtL+O+Ab5S2gprD/1nTK93wKIuqpzErWEy7IcIUEBdOzn5lM XVTQtBKKqNnJcQNisTRpNwCsuwe+0FLiKR01xO4MnS8CwjYN9A3BcVPnVCrftbK3EXNI zTjxEkXKwqDzuZuFfX4ZwsvCtMXjsMOtEMD8Bfv9FRz0KRebCOATjP0PqJiOiw0habOR GXYaXGY1teW2R42hrykHamfJd7JJxIZ2MIfXU7y99ouHbBuHTW4y2efCB7BllMRUG3Lu LSJh/cl9pyx4g8x8v00bet4G/xv3L2GIscdbmiYZzTUW+0KTqmWNhg/Fp933zh8Kobjv 0Vkg== X-Gm-Message-State: AFuF++lGKrJ3uJ4opUOskIs2ZOs8sauuPky+cz1QSqzSPs4ZPDfXjWj0 fAYTAwzYuRYZvs24Wx4imNwqa/jBBvlnMsRzuwPGbsdscgbrSbCrA9vno30AwEMHd9W92eWf7T3 mWfQ0uho= X-Gm-Gg: AYBFou1fsdAP9ih70EMfOAcRZCmicGgjzjXKfWBuH2xSFL9dn6KQcvVLfsdMtQxb7cp ho+EGMumvGA8VhlxoaIXgRyD5nrfkZd2nBWBhXAOih+IWvHza9TCZlIQhf1t51CJAlin8CghARe W/eSIBEvJ6yEBXXXYNGCiZlwnocdY8D+X1sjJFvKx5boIPt7tLjGvKeHD4S/PKs2bTW/R14d9O9 YEeAbsNMOG8nBjLqEClpA4ilembrA1M4IOS2Ml/UEm7iMXCAAi6oROkLcrN+Vf/rPHophqZwlaK EgFQG/DgYv8uKS5+gVjzKbgJXlA4VMQDwuOPV1QnmAXC/tAbyT31FUHdBnKZDLwmAgmFxgJnlyp id5CIV2b2kjN9mSn+uTr/TGmZOS14TCElZo/ujEBS67ofq/9e1/nueAcpVqMNlv3UBkFS5ReUNN 97F3iT+ZK5bFaRqDyZpcWeHP33M1gFZ/Tt1LO93DMQgk+HsVHJtKgQ4l9BLiaN/gKCbrZhBLUFd +sjS9ShGbOH6WYvnSbgJ4O/hsIfN02v7gtTA+8nn8UdSUcg3F0NLztM2EvQthZAcYiOzVGwyGxL X-Received: by 2002:a5d:64e1:0:b0:485:8f42:e8cd with SMTP id ffacd0b85a97d-4858f42ec28mr7294915f8f.3.1788641123888; Sat, 05 Sep 2026 13:45:23 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa0048511f7ccf23d3ce.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:4851:1f7c:cf23:d3ce]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-485885bfdf6sm17069098f8f.34.2026.09.05.13.45.23 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sat, 05 Sep 2026 13:45:23 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][wrynose 23/40] libxfont2: Fix CVE-2026-56003 Date: Sat, 5 Sep 2026 22:44:24 +0200 Message-ID: <2dc809afdf8105a87f6cd9c2f1bf8dfab01426bc.1788629392.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Sat, 05 Sep 2026 20:45:35 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/245175 From: Vijay Anusuri Pick patch according to [2] [1] https://nvd.nist.gov/vuln/detail/CVE-2026-56003 [2] https://security-tracker.debian.org/tracker/CVE-2026-56003 Signed-off-by: Vijay Anusuri Signed-off-by: Yoann Congal --- .../xorg-lib/libxfont2/CVE-2026-56003.patch | 114 ++++++++++++++++++ .../xorg-lib/libxfont2_2.0.7.bb | 1 + 2 files changed, 115 insertions(+) create mode 100644 meta/recipes-graphics/xorg-lib/libxfont2/CVE-2026-56003.patch diff --git a/meta/recipes-graphics/xorg-lib/libxfont2/CVE-2026-56003.patch b/meta/recipes-graphics/xorg-lib/libxfont2/CVE-2026-56003.patch new file mode 100644 index 00000000000..dacfa9d638b --- /dev/null +++ b/meta/recipes-graphics/xorg-lib/libxfont2/CVE-2026-56003.patch @@ -0,0 +1,114 @@ +From dff957a5158da038a282a59a31fe736702732939 Mon Sep 17 00:00:00 2001 +From: Peter Hutterer +Date: Mon, 1 Jun 2026 16:49:55 +1000 +Subject: [PATCH] bitscale: add bounds check to computeProps for property + buffer + +ComputeScaledProperties allocates a fixed-size property buffer of 70 +slots. computeProps iterates the source font's properties and writes 1 +slot for unscaled properties or 2 slots for scaledX/scaledY properties, +with no bounds check. A malicious font with many duplicate properties +matching fontPropTable entries can overflow the allocated buffer. + +Fix this by passing the remaining buffer capacity to computeProps and +checking it before each write. Properties that would exceed the buffer +are silently skipped. + +The function is also restructured to handle the buffer writes for +scaledX/scaledY inside the switch cases directly, rather than in a +separate block after the switch. This makes the control flow clearer and +ensures the bounds check covers all writes. + +This vulnerability was discovered by: +Anonymous working with TrendAI Zero Day Initiative + +CVE-2026-56003/ZDI-CAN-30560 + +Assisted-by: Claude:claude-opus-4-6 +Signed-off-by: Peter Hutterer +Part-of: + +Upstream-Status: Backport [https://gitlab.freedesktop.org/xorg/lib/libxfont/-/commit/dff957a5158da038a282a59a31fe736702732939] +CVE: CVE-2026-56003 +Signed-off-by: Vijay Anusuri +--- + src/bitmap/bitscale.c | 39 ++++++++++++++++++++------------------- + 1 file changed, 20 insertions(+), 19 deletions(-) + +diff --git a/src/bitmap/bitscale.c b/src/bitmap/bitscale.c +index 5f465d1..ec57f55 100644 +--- a/src/bitmap/bitscale.c ++++ b/src/bitmap/bitscale.c +@@ -507,7 +507,8 @@ static int + computeProps(FontPropPtr pf, char *wasStringProp, + FontPropPtr npf, char *isStringProp, + unsigned int nprops, double xfactor, double yfactor, +- double sXfactor, double sYfactor) ++ double sXfactor, double sYfactor, ++ int maxprops) + { + int n; + int count; +@@ -522,14 +523,26 @@ computeProps(FontPropPtr pf, char *wasStringProp, + + switch (t->type) { + case scaledX: +- npf->value = doround(xfactor * (double)pf->value); +- rawfactor = sXfactor; +- break; + case scaledY: +- npf->value = doround(yfactor * (double)pf->value); +- rawfactor = sYfactor; ++ if (count + 2 > maxprops) ++ continue; ++ npf->value = (t->type == scaledX) ++ ? doround(xfactor * (double)pf->value) ++ : doround(yfactor * (double)pf->value); ++ rawfactor = (t->type == scaledX) ? sXfactor : sYfactor; ++ npf->name = pf->name; ++ npf++; ++ count++; ++ npf->value = doround(rawfactor * (double)pf->value); ++ npf->name = rawFontPropTable[t - fontPropTable].atom; ++ npf++; ++ count++; ++ *isStringProp++ = *wasStringProp; ++ *isStringProp++ = *wasStringProp; + break; + case unscaled: ++ if (count + 1 > maxprops) ++ continue; + npf->value = pf->value; + npf->name = pf->name; + npf++; +@@ -539,18 +552,6 @@ computeProps(FontPropPtr pf, char *wasStringProp, + default: + break; + } +- if (t->type != unscaled) +- { +- npf->name = pf->name; +- npf++; +- count++; +- npf->value = doround(rawfactor * (double)pf->value); +- npf->name = rawFontPropTable[t - fontPropTable].atom; +- npf++; +- count++; +- *isStringProp++ = *wasStringProp; +- *isStringProp++ = *wasStringProp; +- } + } + return count; + } +@@ -667,7 +668,7 @@ ComputeScaledProperties(FontInfoPtr sourceFontInfo, /* the font to be scaled */ + n = NPROPS; + n += computeProps(sourceFontInfo->props, sourceFontInfo->isStringProp, + fp, isStringProp, sourceFontInfo->nprops, dx, dy, +- sdx, sdy); ++ sdx, sdy, nProps - NPROPS); + return n; + } + +-- +GitLab + diff --git a/meta/recipes-graphics/xorg-lib/libxfont2_2.0.7.bb b/meta/recipes-graphics/xorg-lib/libxfont2_2.0.7.bb index e004ac044c2..de6418b11a5 100644 --- a/meta/recipes-graphics/xorg-lib/libxfont2_2.0.7.bb +++ b/meta/recipes-graphics/xorg-lib/libxfont2_2.0.7.bb @@ -17,6 +17,7 @@ BBCLASSEXTEND = "native" SRC_URI += "file://CVE-2026-56001.patch \ file://CVE-2026-56002.patch \ + file://CVE-2026-56003.patch \ " SRC_URI[sha256sum] = "8b7b82fdeba48769b69433e8e3fbb984a5f6bf368b0d5f47abeec49de3e58efb" From patchwork Sat Sep 5 20:44:25 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 97386 X-Patchwork-Delegate: yoann.congal@smile.fr Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 642F4C79FA7 for ; Sat, 5 Sep 2026 20:45:37 +0000 (UTC) Received: from mail-wm1-f43.google.com (mail-wm1-f43.google.com [209.85.128.43]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.2591.1788641126193946377 for ; Sat, 05 Sep 2026 13:45:26 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=Xx72ybeN; spf=pass (domain: smile.fr, ip: 209.85.128.43, mailfrom: yoann.congal@smile.fr) Received: by mail-wm1-f43.google.com with SMTP id 5b1f17b1804b1-49b8ce9b733so16598955e9.1 for ; Sat, 05 Sep 2026 13:45:25 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1788641124; x=1789245924; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=spGuQHW1dLggawfE9WDcF7r5TZVSjiHtmd3Nsle3jYA=; b=Xx72ybeNu8mafK25Snh5v/IY8Svd06in73vR/mKVWQxmriFh8v5juBGzM94MeSAt9A Ht6RVd0Gytro7HcBfTb1n3OnVsZtiV93pPZ9oOg2i+rC8hCuJqJyR2yc1F7QQNUwNgJk nEn4RC3kBCqT/02r0GwkOG8zkHFKXrjjfDw3c= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1788641124; x=1789245924; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=spGuQHW1dLggawfE9WDcF7r5TZVSjiHtmd3Nsle3jYA=; b=MsA15zQv84IAfBfzzXALFStjSh0hswomaITWNBQyIjpa1Eiy6gUpxmlt1MqPER7QVc Tn+O4bG0hQZCpGq9c58dStGCDwGcGvpSco6OLb+BY0naKaRU7vXwWuD/WLZ5bY7XV/2v CIAZLOxhoiCjzDvxTpTEuqYt/sPEgJiNL72QWoyv5eQHXvdmEVbaVsRCNG/EctcMZhOZ qtcKpiZkenH/4L6KXFYcirfAVezJVFukA/Ty37U5OFxgcflXX5CD2qBwky4+sT0jQra0 +FRew6Vg8Bl/f6ZE111MKdsbxkqdCj3bBwj8reO2b3TRnypsE4QVlIGoWJ17+YbtthTE yidQ== X-Gm-Message-State: AFuF++lywWu7XAj3AiJUF8qiJSg1g8hoLDDEjHMSsWmcPFEt9iECs3Eq GCAaFLlyXR4I9FhBxe+kU27ppR5VdXVbTx3yde6iuicDoZtj3Oj2k6C4TwZdsUwTRM8sRDbyXmV jkD77GBM= X-Gm-Gg: AYBFou1g7ebMxnSFlizJwTHrgC0uLmxgFtPf635qhQoSO1z1mILZqFgXMDlLRY3vBsO uCAaqo9TmFqwv25QHmm5O8jd0ByZdS0Oyz6AMx0NaTdS9Ee229RJH8ZyLMdXat6x2yOobNB2Zn/ qVvaaRgeHuIkXOWncbzNC8/2oDfxECI5ib90QWcY2YRXvd0R0gbiwZQTtCDXHyYIOBQ1UpZjpNE gWNE4UxkweAPSdIuWXafCa6zV3rpkaDIA9c9xsceVs2UCL+jQyxEcxEGhWRCzRQeamAMQliG0dR zteS63L1pznFawDxNTUib3iJgSkAJBOutERPwoTU6RcgUOV3Amez3u8DJKbuRAGs7o7+Qh68Mje fU5OgbClmwo5PfZrlcMfKCHNntWYvMm0bi+lWwRKmVjhImce/0Zkys2HPWAxntOwvdXXbuDrmfQ QwoV76Byj2LpFeePqd2i/mOlTD7Yfu/eR9CV3JRfF1eh8Qt2jfmxl06nAl4ipO/ujEYfo/Zp1tE 602cu9qw3oF/OWDBFToB5TvvPx3c4NmjAuJ2Hbaej1Y9lj4N+WvgJ/RDcc3sHfa8A== X-Received: by 2002:a05:600c:1d1c:b0:49d:91d:d192 with SMTP id 5b1f17b1804b1-49d091dd358mr22839225e9.5.1788641124410; Sat, 05 Sep 2026 13:45:24 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa0048511f7ccf23d3ce.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:4851:1f7c:cf23:d3ce]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-485885bfdf6sm17069098f8f.34.2026.09.05.13.45.23 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sat, 05 Sep 2026 13:45:24 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][wrynose 24/40] util-linux: Fix CVE-2026-3184 Date: Sat, 5 Sep 2026 22:44:25 +0200 Message-ID: <4aa5df104fd606fa21173ab7cd91d41ac40eaad3.1788629392.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Sat, 05 Sep 2026 20:45:37 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/245176 From: Jaipaul Cheernam Reference: [1] https://nvd.nist.gov/vuln/detail/CVE-2026-3184 [2] https://github.com/util-linux/util-linux/commit/8b29aeb081e297e48c4c1ac53d88ae07e1331984 Signed-off-by: Jaipaul Cheernam Signed-off-by: Yoann Congal --- meta/recipes-core/util-linux/util-linux.inc | 1 + .../util-linux/util-linux/CVE-2026-3184.patch | 61 +++++++++++++++++++ 2 files changed, 62 insertions(+) create mode 100644 meta/recipes-core/util-linux/util-linux/CVE-2026-3184.patch diff --git a/meta/recipes-core/util-linux/util-linux.inc b/meta/recipes-core/util-linux/util-linux.inc index aec8721ca32..fdc62acc748 100644 --- a/meta/recipes-core/util-linux/util-linux.inc +++ b/meta/recipes-core/util-linux/util-linux.inc @@ -20,6 +20,7 @@ SRC_URI = "${KERNELORG_MIRROR}/linux/utils/util-linux/v${MAJOR_VERSION}/util-lin file://0001-lsfd-mkfds-foreign-sockets-skip-when-lacking-sock_di.patch \ file://0001-ts-kill-decode-use-RTMIN-from-kill-L-instead-of-hard.patch \ file://0001-tests-script-Disable-size-option-test.patch \ + file://CVE-2026-3184.patch \ " SRC_URI[sha256sum] = "f586e35d320ff537aab3ffeca37e9ecd482ccbe013590db4429a414d8aa6a728" diff --git a/meta/recipes-core/util-linux/util-linux/CVE-2026-3184.patch b/meta/recipes-core/util-linux/util-linux/CVE-2026-3184.patch new file mode 100644 index 00000000000..6dbfebe4b91 --- /dev/null +++ b/meta/recipes-core/util-linux/util-linux/CVE-2026-3184.patch @@ -0,0 +1,61 @@ +From 3fb64ddbffbc9442dca56eb6d4f263d525708b64 Mon Sep 17 00:00:00 2001 +From: Karel Zak +Date: Thu, 19 Feb 2026 12:20:28 +0100 +Subject: [PATCH] login: use original FQDN for PAM_RHOST + +When login -h is invoked, init_remote_info() strips the +local domain suffix from the hostname (FQDN to short name) before +storing it in cxt->hostname. This truncated value is then used for +PAM_RHOST, which can bypass pam_access host deny rules that match on +the FQDN. + +Preserve the original -h hostname in a new cmd_hostname field and use +it for PAM_RHOST, while keeping the truncated hostname for utmp/wtmp +and logging unchanged. + +Note, the real-world impact is low -- login -h is only used by legacy +telnet/rlogin daemons, and exploitation requires FQDN-specific +pam_access rules on a system still using these obsolete services. + +Reported-by: Asim Viladi Oglu Manizada +Signed-off-by: Karel Zak +(cherry picked from commit 8b29aeb081e297e48c4c1ac53d88ae07e1331984) + +CVE: CVE-2026-3184 +Upstream-Status: Backport [https://github.com/util-linux/util-linux/commit/8b29aeb081e297e48c4c1ac53d88ae07e1331984] + +Signed-off-by: Jaipaul Cheernam +--- + login-utils/login.c | 5 ++++- + 1 file changed, 4 insertions(+), 1 deletion(-) + +diff --git a/login-utils/login.c b/login-utils/login.c +index 321f9d6ce..0c5c805aa 100644 +--- a/login-utils/login.c ++++ b/login-utils/login.c +@@ -128,6 +128,7 @@ struct login_context { + char *thishost; /* this machine */ + char *thisdomain; /* this machine's domain */ + char *hostname; /* remote machine */ ++ char *cmd_hostname; /* remote machine as specified on command line */ + char hostaddress[16]; /* remote address */ + + pid_t pid; +@@ -906,7 +907,7 @@ static pam_handle_t *init_loginpam(struct login_context *cxt) + + /* hostname & tty are either set to NULL or their correct values, + * depending on how much we know. */ +- rc = pam_set_item(pamh, PAM_RHOST, cxt->hostname); ++ rc = pam_set_item(pamh, PAM_RHOST, cxt->cmd_hostname); + if (is_pam_failure(rc)) + loginpam_err(pamh, rc); + +@@ -1249,6 +1250,8 @@ static void init_remote_info(struct login_context *cxt, char *remotehost) + + get_thishost(cxt, &domain); + ++ cxt->cmd_hostname = xstrdup(remotehost); ++ + if (domain && (p = strchr(remotehost, '.')) && + strcasecmp(p + 1, domain) == 0) + *p = '\0'; From patchwork Sat Sep 5 20:44:26 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 97390 X-Patchwork-Delegate: yoann.congal@smile.fr Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id DB46EC79FAA for ; Sat, 5 Sep 2026 20:45:37 +0000 (UTC) Received: from mail-wm1-f43.google.com (mail-wm1-f43.google.com [209.85.128.43]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.2487.1788641126805165538 for ; Sat, 05 Sep 2026 13:45:27 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=pp0EUcbV; spf=pass (domain: smile.fr, ip: 209.85.128.43, mailfrom: yoann.congal@smile.fr) Received: by mail-wm1-f43.google.com with SMTP id 5b1f17b1804b1-49557167508so26652575e9.1 for ; Sat, 05 Sep 2026 13:45:26 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1788641125; x=1789245925; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=uNpfDTk6jCsyMjtCm8h3eRnhz4E3GmkhsoGYq4542eE=; b=pp0EUcbVAkLKbhddOwAD+DfvakVNf2RwNsu3aRR+VZtmOrSwRiOt6S9YIIqMKzUKqv WSTifAPdgTTodNEMBWeLZarcs2v4dagnb44XjZwrr4/d+e4EV2LcyJ+ZEp27y4lLP3Tm M48F2ZeEpXv+jsc7NZudVHXfU/PLkxqxU4uLQ= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1788641125; x=1789245925; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=uNpfDTk6jCsyMjtCm8h3eRnhz4E3GmkhsoGYq4542eE=; b=mTi2djmH523b90x/CZmQ9cgWffexcQ5JyZHRhuiLbyGr4Cve4bTLgKmnrePJY2V43d gD0uQnFTT/N1rexRU/P+jikPJTDoJ+l41td75R1U8G+v/KVfJKHwqy0ieSbe4L0hjjuy 6ADbvm7J+h+c2dPsZrKuAfSf0mnJfrZ91kpIZOILKdlUh50l3tZkjnuhIw3rOlQwtq3f 3ehhjyCWvM8Gb1y7eB83OvfBEyYCeDf3+sj7E78ZKV1YhwgHhpxo3bBVANTRyy/+4yQC jyYQm7axMdjjqxAHeL3AIWNx/FdnFdC8t208ubn4Z1W1/x1bRR9inTCtFheEy9acNqTh S7Mw== X-Gm-Message-State: AFuF++nrcRhdPX/hItja/aY2Dfegi1Q3ZoafRO1mnl92bgLN+ygSG2qR GEeg7+G5pmQDuIwmExRexO0vYjFhOpbwfn6gk2MQBepfZKz6gLRusy71K59NlOq056PmCUt3MqD Y7yNgUCU= X-Gm-Gg: AYBFou3lX8bJQpwXHsx2DT+GIPp7kSl2VUYGMq7hc4dWPb/u8m9hvNRV+VUpQzXVfpk BoRQq2uHc4rLM6y46DHBx6urhNbni15AXMNQ3fMSNoom36N9V1ZrcQV4spk9SZkfM0EtX9rPf/I fyl+lJecePNAsVoviVnu1AoK7iAeUEutqidwEFA5GSER9SYDMw/xvEmZyjwvH3Uzgbu+rdt9KY8 i48Wxswjd+KiOhQdAqyJBfl1vb2JjP8DQQm6CrGxEVdjavbnaxgV6UB+rNgw33kO9iNv4x2PjN/ 6naUq8y3ff3UUXK/g+sKTzBJsBQ2yUTM+IV/CnJQPsN9OA9l8kFMQoamBAN6nMEK+oP7RZfmEiY b432BSr7pzLXo+bD1rYeBuWKUXZLlp10yvxuwP6bchG5nHKClRJhCLu3zrGWkB6LLsrKrlG/sx7 Ib3kKTOfjdC3Mnr3J2yadfXI+zpz802NQQ8SoUEFRFel7IFDRnb1ezJzdcCEv8OGA76AUjH12Yr 7EiCwPuSP75pen/UjzbK98sudDM3XEDLIocxJphqkARlLsUnDZAehwK579EZHTUEg== X-Received: by 2002:a05:600d:6450:10b0:49c:ffaf:95a1 with SMTP id 5b1f17b1804b1-49cffaf95c3mr128571975e9.1.1788641124888; Sat, 05 Sep 2026 13:45:24 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa0048511f7ccf23d3ce.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:4851:1f7c:cf23:d3ce]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-485885bfdf6sm17069098f8f.34.2026.09.05.13.45.24 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sat, 05 Sep 2026 13:45:24 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][wrynose 25/40] python3: upgrade 3.14.6 -> 3.14.7 Date: Sat, 5 Sep 2026 22:44:26 +0200 Message-ID: <8ed4aeb3e72e4d643801adba289123b2378705bb.1788629392.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Sat, 05 Sep 2026 20:45:37 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/245177 From: Jaipaul Cheernam Release notes: [1] Removed patches included in this release. Removed obsolete CVE_STATUS entries. [1] https://docs.python.org/3/whatsnew/changelog.html#python-3-14-7-final (From OE-Core rev: 1e7832f8de0a07a2c7c6e239b31b82d47ccb915c) Signed-off-by: Jaipaul Cheernam Signed-off-by: Richard Purdie Signed-off-by: Peter Marko Signed-off-by: Yoann Congal --- ...shebang-overflow-on-python-config.py.patch | 6 +- ...e-stdin-I-O-errors-same-way-as-maste.patch | 4 +- ...-use-prefix-value-from-build-configu.patch | 7 +- ...-qemu-wrapper-when-gathering-profile.patch | 9 +-- ...est_sysconfig-for-posix_user-purelib.patch | 4 +- .../0001-prefer-valid-entrypoints.patch | 2 +- ...g.py-use-platlibdir-also-for-purelib.patch | 4 +- ...le.py-correct-the-test-output-format.patch | 6 +- .../python/python3/CVE-2026-11940.patch | 67 ------------------- .../python/python3/CVE-2026-11972.patch | 61 ----------------- .../python/python3/makerace.patch | 6 +- .../python/python3/valid-dists.patch | 2 +- .../{python3_3.14.6.bb => python3_3.14.7.bb} | 7 +- 13 files changed, 24 insertions(+), 161 deletions(-) delete mode 100644 meta/recipes-devtools/python/python3/CVE-2026-11940.patch delete mode 100644 meta/recipes-devtools/python/python3/CVE-2026-11972.patch rename meta/recipes-devtools/python/{python3_3.14.6.bb => python3_3.14.7.bb} (98%) diff --git a/meta/recipes-devtools/python/python3/0001-Avoid-shebang-overflow-on-python-config.py.patch b/meta/recipes-devtools/python/python3/0001-Avoid-shebang-overflow-on-python-config.py.patch index c2106f94370..7a605383647 100644 --- a/meta/recipes-devtools/python/python3/0001-Avoid-shebang-overflow-on-python-config.py.patch +++ b/meta/recipes-devtools/python/python3/0001-Avoid-shebang-overflow-on-python-config.py.patch @@ -1,4 +1,4 @@ -From 6b111a328c1c57b1580d63894b2b5d337316f6d4 Mon Sep 17 00:00:00 2001 +From 3f2df0e1fce8c7425998dade00d084f1b101a982 Mon Sep 17 00:00:00 2001 From: Paulo Neves Date: Tue, 7 Jun 2022 16:16:41 +0200 Subject: [PATCH] Avoid shebang overflow on python-config.py @@ -16,10 +16,10 @@ Upstream-Status: Denied [distribution] 1 file changed, 2 insertions(+) diff --git a/Makefile.pre.in b/Makefile.pre.in -index 9ec3a71..f7d5382 100644 +index e946018..345ed29 100644 --- a/Makefile.pre.in +++ b/Makefile.pre.in -@@ -2829,6 +2829,8 @@ python-config: $(srcdir)/Misc/python-config.in Misc/python-config.sh +@@ -2835,6 +2835,8 @@ python-config: $(srcdir)/Misc/python-config.in Misc/python-config.sh @ # Substitution happens here, as the completely-expanded BINDIR @ # is not available in configure sed -e "s,@EXENAME@,$(EXENAME)," < $(srcdir)/Misc/python-config.in >python-config.py diff --git a/meta/recipes-devtools/python/python3/0001-Lib-pty.py-handle-stdin-I-O-errors-same-way-as-maste.patch b/meta/recipes-devtools/python/python3/0001-Lib-pty.py-handle-stdin-I-O-errors-same-way-as-maste.patch index d9072a36f7b..532adfe69a9 100644 --- a/meta/recipes-devtools/python/python3/0001-Lib-pty.py-handle-stdin-I-O-errors-same-way-as-maste.patch +++ b/meta/recipes-devtools/python/python3/0001-Lib-pty.py-handle-stdin-I-O-errors-same-way-as-maste.patch @@ -1,4 +1,4 @@ -From 129ee75863081d9e3418acca3df1e47667f671ad Mon Sep 17 00:00:00 2001 +From 9cd44429215352eb2753e0fd8e25fef24f714006 Mon Sep 17 00:00:00 2001 From: Alexander Kanavin Date: Thu, 16 Sep 2021 16:35:37 +0200 Subject: [PATCH] Lib/pty.py: handle stdin I/O errors same way as master I/O @@ -29,7 +29,7 @@ Signed-off-by: Alexander Kanavin 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/Lib/pty.py b/Lib/pty.py -index 1d97994..fa8821b 100644 +index 4b25ac3..d6aac07 100644 --- a/Lib/pty.py +++ b/Lib/pty.py @@ -149,7 +149,10 @@ def _copy(master_fd, master_read=_read, stdin_read=_read): diff --git a/meta/recipes-devtools/python/python3/0001-Lib-sysconfig.py-use-prefix-value-from-build-configu.patch b/meta/recipes-devtools/python/python3/0001-Lib-sysconfig.py-use-prefix-value-from-build-configu.patch index 285580195b4..60391e726bd 100644 --- a/meta/recipes-devtools/python/python3/0001-Lib-sysconfig.py-use-prefix-value-from-build-configu.patch +++ b/meta/recipes-devtools/python/python3/0001-Lib-sysconfig.py-use-prefix-value-from-build-configu.patch @@ -1,4 +1,4 @@ -From e3c6e770e73e1329958db0a73883e42b01763ae3 Mon Sep 17 00:00:00 2001 +From b5aad6a9b6c5add7a85861aed8aa030c1ad3d52f Mon Sep 17 00:00:00 2001 From: Alexander Kanavin Date: Fri, 17 Nov 2023 14:26:32 +0100 Subject: [PATCH] Lib/sysconfig.py: use prefix value from build configuration @@ -18,7 +18,7 @@ Signed-off-by: Trevor Gamblin 1 file changed, 5 insertions(+), 5 deletions(-) diff --git a/Lib/sysconfig/__init__.py b/Lib/sysconfig/__init__.py -index 2ecbff222fe..cec54cb23dc 100644 +index 0a8bcc0..a2341f2 100644 --- a/Lib/sysconfig/__init__.py +++ b/Lib/sysconfig/__init__.py @@ -538,12 +538,12 @@ def _init_config_vars(): @@ -39,6 +39,3 @@ index 2ecbff222fe..cec54cb23dc 100644 _CONFIG_VARS['implementation'] = _get_implementation() _CONFIG_VARS['implementation_lower'] = _get_implementation().lower() _CONFIG_VARS['abiflags'] = abiflags --- -2.51.0 - diff --git a/meta/recipes-devtools/python/python3/0001-Makefile.pre-use-qemu-wrapper-when-gathering-profile.patch b/meta/recipes-devtools/python/python3/0001-Makefile.pre-use-qemu-wrapper-when-gathering-profile.patch index e25797f57ec..c7f14cad1e0 100644 --- a/meta/recipes-devtools/python/python3/0001-Makefile.pre-use-qemu-wrapper-when-gathering-profile.patch +++ b/meta/recipes-devtools/python/python3/0001-Makefile.pre-use-qemu-wrapper-when-gathering-profile.patch @@ -1,4 +1,4 @@ -From e7a8a7385f561f214054cf95f0a22bfa064eee0b Mon Sep 17 00:00:00 2001 +From d6f77e3a934616d1f6c083b7144c50a32e08b70a Mon Sep 17 00:00:00 2001 From: Alexander Kanavin Date: Wed, 30 Jan 2019 12:41:04 +0100 Subject: [PATCH] Makefile.pre: use qemu wrapper when gathering profile data @@ -15,10 +15,10 @@ Signed-off-by: Trevor Gamblin 1 file changed, 1 insertion(+), 2 deletions(-) diff --git a/Makefile.pre.in b/Makefile.pre.in -index 3bd4495f95b..8e8fc60bc76 100644 +index 526d500..a7e536d 100644 --- a/Makefile.pre.in +++ b/Makefile.pre.in -@@ -857,8 +857,7 @@ profile-run-stamp: +@@ -861,8 +861,7 @@ profile-run-stamp: # enabled. $(MAKE) profile-gen-stamp # Next, run the profile task to generate the profile information. @@ -28,6 +28,3 @@ index 3bd4495f95b..8e8fc60bc76 100644 $(LLVM_PROF_MERGER) # Remove profile generation binary since we are done with it. $(MAKE) clean-retain-profile --- -2.39.5 - diff --git a/meta/recipes-devtools/python/python3/0001-Update-test_sysconfig-for-posix_user-purelib.patch b/meta/recipes-devtools/python/python3/0001-Update-test_sysconfig-for-posix_user-purelib.patch index 6a62c6dc5b9..5509b7475a9 100644 --- a/meta/recipes-devtools/python/python3/0001-Update-test_sysconfig-for-posix_user-purelib.patch +++ b/meta/recipes-devtools/python/python3/0001-Update-test_sysconfig-for-posix_user-purelib.patch @@ -1,4 +1,4 @@ -From 5bf5aa6eae1fa3eed66893e51a1858ab481426b4 Mon Sep 17 00:00:00 2001 +From c608cb4b3c8c31f1aa25ad1264ff58733fb99769 Mon Sep 17 00:00:00 2001 From: Wentao Zhang Date: Mon, 20 Mar 2023 13:39:52 +0800 Subject: [PATCH] Update test_sysconfig for posix_user purelib @@ -22,7 +22,7 @@ Signed-off-by: Wentao Zhang 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/Lib/test/test_sysconfig.py b/Lib/test/test_sysconfig.py -index 1ade492..4e94889 100644 +index 1fe4b68..383142a 100644 --- a/Lib/test/test_sysconfig.py +++ b/Lib/test/test_sysconfig.py @@ -434,7 +434,7 @@ class TestSysConfig(unittest.TestCase, VirtualEnvironmentMixin): diff --git a/meta/recipes-devtools/python/python3/0001-prefer-valid-entrypoints.patch b/meta/recipes-devtools/python/python3/0001-prefer-valid-entrypoints.patch index 1250dc9ff04..ae3698fac47 100644 --- a/meta/recipes-devtools/python/python3/0001-prefer-valid-entrypoints.patch +++ b/meta/recipes-devtools/python/python3/0001-prefer-valid-entrypoints.patch @@ -1,4 +1,4 @@ -From ef33ac27e3ac1b9cb159d7eec0ad1af120cd9dc1 Mon Sep 17 00:00:00 2001 +From 8d7fcf04c6513841c7985e64b746b1ef5de0c426 Mon Sep 17 00:00:00 2001 From: Ross Burton Date: Fri, 17 Apr 2026 16:53:42 +0100 Subject: [PATCH] prefer valid entrypoints diff --git a/meta/recipes-devtools/python/python3/0001-sysconfig.py-use-platlibdir-also-for-purelib.patch b/meta/recipes-devtools/python/python3/0001-sysconfig.py-use-platlibdir-also-for-purelib.patch index b9c68a98d70..7807827d9aa 100644 --- a/meta/recipes-devtools/python/python3/0001-sysconfig.py-use-platlibdir-also-for-purelib.patch +++ b/meta/recipes-devtools/python/python3/0001-sysconfig.py-use-platlibdir-also-for-purelib.patch @@ -1,4 +1,4 @@ -From bbcb17dc1ed283f41c8cd94d39f70898f0c45583 Mon Sep 17 00:00:00 2001 +From c10d1b295a9fb93836830cce441da3f22e5c7cd7 Mon Sep 17 00:00:00 2001 From: Alexander Kanavin Date: Sun, 12 Sep 2021 21:44:36 +0200 Subject: [PATCH] sysconfig.py: use platlibdir also for purelib @@ -13,7 +13,7 @@ Signed-off-by: Alexander Kanavin 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/Lib/sysconfig/__init__.py b/Lib/sysconfig/__init__.py -index 80aef34..f8e1c7d 100644 +index faf8273..0a8bcc0 100644 --- a/Lib/sysconfig/__init__.py +++ b/Lib/sysconfig/__init__.py @@ -29,7 +29,7 @@ _INSTALL_SCHEMES = { diff --git a/meta/recipes-devtools/python/python3/0001-test_locale.py-correct-the-test-output-format.patch b/meta/recipes-devtools/python/python3/0001-test_locale.py-correct-the-test-output-format.patch index 201271b0c07..a60d082e2f4 100644 --- a/meta/recipes-devtools/python/python3/0001-test_locale.py-correct-the-test-output-format.patch +++ b/meta/recipes-devtools/python/python3/0001-test_locale.py-correct-the-test-output-format.patch @@ -1,4 +1,4 @@ -From c1f3cf625c0f011060ddaa2a4096f6aa13dd1ee6 Mon Sep 17 00:00:00 2001 +From f0ac5b479b99bfb7f5e937a941b31a596f4caafc Mon Sep 17 00:00:00 2001 From: Mingli Yu Date: Mon, 5 Aug 2019 15:57:39 +0800 Subject: [PATCH] test_locale.py: correct the test output format @@ -31,10 +31,10 @@ Signed-off-by: Mingli Yu 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/Lib/test/test_locale.py b/Lib/test/test_locale.py -index da4bd79..fd9e67d 100644 +index f918435..1910a43 100644 --- a/Lib/test/test_locale.py +++ b/Lib/test/test_locale.py -@@ -500,7 +500,7 @@ class TestRealLocales(unittest.TestCase): +@@ -499,7 +499,7 @@ class TestRealLocales(unittest.TestCase): self.skipTest('test needs Turkish locale') loc = locale.getlocale(locale.LC_CTYPE) if verbose: diff --git a/meta/recipes-devtools/python/python3/CVE-2026-11940.patch b/meta/recipes-devtools/python/python3/CVE-2026-11940.patch deleted file mode 100644 index 05a5802c396..00000000000 --- a/meta/recipes-devtools/python/python3/CVE-2026-11940.patch +++ /dev/null @@ -1,67 +0,0 @@ -From e24b4e95524fbe8cd0f46aa3292e8040f0e07c83 Mon Sep 17 00:00:00 2001 -From: "Miss Islington (bot)" - <31488909+miss-islington@users.noreply.github.com> -Date: Tue, 23 Jun 2026 15:58:47 +0200 -Subject: [PATCH 1/2] gh-151558: Fix symlink escape via `tarfile` - hardlink-extraction fallback (GH-151559) - -CVE: CVE-2026-11940 -Upstream-Status: Backport [https://github.com/python/cpython/commit/27dd970bf6b17ebca7c8ed486a40ab043ed7af8f] - -Signed-off-by: Benjamin Robin ---- - Lib/tarfile.py | 3 +++ - Lib/test/test_tarfile.py | 24 ++++++++++++++++++++++++ - 2 files changed, 27 insertions(+) - -diff --git a/Lib/tarfile.py b/Lib/tarfile.py -index e6734db24f64..63f23490e8a1 100644 ---- a/Lib/tarfile.py -+++ b/Lib/tarfile.py -@@ -2782,6 +2782,9 @@ def makelink_with_filter(self, tarinfo, targetpath, - "makelink_with_filter: if filter_function is not None, " - + "extraction_root must also not be None") - try: -+ filter_function( -+ unfiltered.replace(name=tarinfo.name, deep=False), -+ extraction_root) - filtered = filter_function(unfiltered, extraction_root) - except _FILTER_ERRORS as cause: - raise LinkFallbackError(tarinfo, unfiltered.name) from cause -diff --git a/Lib/test/test_tarfile.py b/Lib/test/test_tarfile.py -index d974c7d46ec1..0fc7413be8db 100644 ---- a/Lib/test/test_tarfile.py -+++ b/Lib/test/test_tarfile.py -@@ -4344,6 +4344,30 @@ def test_sneaky_hardlink_fallback(self): - self.expect_file("boom", symlink_to='../../link_here') - self.expect_file("c", symlink_to='b') - -+ @symlink_test -+ def test_sneaky_hardlink_fallback_deep(self): -+ # (CVE-2026-11940) -+ with ArchiveMaker() as arc: -+ arc.add("a/b/s", symlink_to=os.path.join("..", "escape")) -+ arc.add("s", hardlink_to=os.path.join("a", "b", "s")) -+ -+ with self.check_context(arc.open(), 'data'): -+ e = self.expect_exception( -+ tarfile.LinkFallbackError, -+ "link 's' would be extracted as a copy of " -+ + "'a/b/s', which was rejected") -+ self.assertIsInstance(e.__cause__, -+ tarfile.LinkOutsideDestinationError) -+ -+ for filter in 'tar', 'fully_trusted': -+ with self.subTest(filter), self.check_context(arc.open(), filter): -+ if not os_helper.can_symlink(): -+ self.expect_file("a/") -+ self.expect_file("a/b/") -+ else: -+ self.expect_file("a/b/s", symlink_to=os.path.join('..', 'escape')) -+ self.expect_file("s", symlink_to=os.path.join('..', 'escape')) -+ - @symlink_test - def test_exfiltration_via_symlink(self): - # (CVE-2025-4138) --- -2.54.0 diff --git a/meta/recipes-devtools/python/python3/CVE-2026-11972.patch b/meta/recipes-devtools/python/python3/CVE-2026-11972.patch deleted file mode 100644 index 12a79754feb..00000000000 --- a/meta/recipes-devtools/python/python3/CVE-2026-11972.patch +++ /dev/null @@ -1,61 +0,0 @@ -From 2d256d4bfd654bdcaf2d96733799be73b8ff8f69 Mon Sep 17 00:00:00 2001 -From: Petr Viktorin -Date: Tue, 23 Jun 2026 15:13:30 +0200 -Subject: [PATCH 2/2] gh-151981: Make tarfile._Stream.seek break at EOF - (GH-151982) - -Co-authored-by: Stan Ulbrych - -CVE: CVE-2026-11972 -Upstream-Status: Backport [https://github.com/python/cpython/commit/f50bf13566189c8d0ce5a814f33eff3d89951896] - -Signed-off-by: Benjamin Robin ---- - Lib/tarfile.py | 4 +++- - Lib/test/test_tarfile.py | 16 ++++++++++++++++ - 2 files changed, 19 insertions(+), 1 deletion(-) - -diff --git a/Lib/tarfile.py b/Lib/tarfile.py -index 63f23490e8a1..399f906efdff 100644 ---- a/Lib/tarfile.py -+++ b/Lib/tarfile.py -@@ -524,7 +524,9 @@ def seek(self, pos=0): - if pos - self.pos >= 0: - blocks, remainder = divmod(pos - self.pos, self.bufsize) - for i in range(blocks): -- self.read(self.bufsize) -+ data = self.read(self.bufsize) -+ if not data: -+ break - self.read(remainder) - else: - raise StreamError("seeking backwards is not allowed") -diff --git a/Lib/test/test_tarfile.py b/Lib/test/test_tarfile.py -index 0fc7413be8db..045377d620cc 100644 ---- a/Lib/test/test_tarfile.py -+++ b/Lib/test/test_tarfile.py -@@ -4786,6 +4786,22 @@ def valueerror_filter(tarinfo, path): - with self.check_context(arc.open(errorlevel='boo!'), filtererror_filter): - self.expect_exception(TypeError) # errorlevel is not int - -+ @support.subTests('format', [tarfile.GNU_FORMAT, tarfile.PAX_FORMAT]) -+ def test_getmembers_big_size(self, format): -+ # gh-151981: A loop in seek() for streaming files tried to read the -+ # declared number of blocks even at EOF -+ tinfo = tarfile.TarInfo("huge-file") -+ tinfo.size = 1 << 64 -+ bio = io.BytesIO() -+ # Write header without data -+ bio.write(tinfo.tobuf(format)) -+ -+ # Reset & try to get contents -+ bio.seek(0) -+ with tarfile.open(fileobj=bio, mode="r|") as tar: -+ with self.assertRaises(tarfile.ReadError): -+ tar.getmembers() -+ - - class OverwriteTests(archiver_tests.OverwriteTests, unittest.TestCase): - testdir = os.path.join(TEMPDIR, "testoverwrite") --- -2.54.0 diff --git a/meta/recipes-devtools/python/python3/makerace.patch b/meta/recipes-devtools/python/python3/makerace.patch index b29ea56cc34..248a521118c 100644 --- a/meta/recipes-devtools/python/python3/makerace.patch +++ b/meta/recipes-devtools/python/python3/makerace.patch @@ -1,4 +1,4 @@ -From 2b458b4e1bcd57e3f135d3f0e715f64b98b27906 Mon Sep 17 00:00:00 2001 +From b41557f570ff4451c477669d6ca5bfacabe21c66 Mon Sep 17 00:00:00 2001 From: Richard Purdie Date: Tue, 13 Jul 2021 23:19:29 +0100 Subject: [PATCH] python3: Fix make race @@ -17,10 +17,10 @@ Signed-off-by: Richard Purdie 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/Makefile.pre.in b/Makefile.pre.in -index be1b9ea..9ec3a71 100644 +index a7e536d..e946018 100644 --- a/Makefile.pre.in +++ b/Makefile.pre.in -@@ -2735,7 +2735,7 @@ COMPILEALL_OPTS=-j0 +@@ -2741,7 +2741,7 @@ COMPILEALL_OPTS=-j0 TEST_MODULES=@TEST_MODULES@ .PHONY: libinstall diff --git a/meta/recipes-devtools/python/python3/valid-dists.patch b/meta/recipes-devtools/python/python3/valid-dists.patch index 38b6ebc5cb1..7fe18254e50 100644 --- a/meta/recipes-devtools/python/python3/valid-dists.patch +++ b/meta/recipes-devtools/python/python3/valid-dists.patch @@ -1,4 +1,4 @@ -From a65c29adc027b3615154cab73aaedd58a6aa23da Mon Sep 17 00:00:00 2001 +From 66874ce1a9f21b4b00dc85919734d58e6243ca29 Mon Sep 17 00:00:00 2001 From: "Jason R. Coombs" Date: Tue, 23 Jul 2024 08:36:16 -0400 Subject: [PATCH] Prioritize valid dists to invalid dists when retrieving by diff --git a/meta/recipes-devtools/python/python3_3.14.6.bb b/meta/recipes-devtools/python/python3_3.14.7.bb similarity index 98% rename from meta/recipes-devtools/python/python3_3.14.6.bb rename to meta/recipes-devtools/python/python3_3.14.7.bb index 0a9e82d445f..b798f1c3697 100644 --- a/meta/recipes-devtools/python/python3_3.14.6.bb +++ b/meta/recipes-devtools/python/python3_3.14.7.bb @@ -35,14 +35,12 @@ SRC_URI = "http://www.python.org/ftp/python/${PV}/Python-${PV}.tar.xz \ file://0001-Skip-flaky-test_default_timeout-tests.patch \ file://0001-test_only_active_thread-skip-problematic-test.patch \ file://0001-prefer-valid-entrypoints.patch \ - file://CVE-2026-11940.patch \ - file://CVE-2026-11972.patch \ " SRC_URI:append:class-native = " \ file://0001-Lib-sysconfig.py-use-prefix-value-from-build-configu.patch \ " -SRC_URI[sha256sum] = "143b1dddefaec3bd2e21e3b839b34a2b7fb9842272883c576420d605e9f30c63" +SRC_URI[sha256sum] = "3b48dac8fb59f62eaa67ac83c1eb12bda1b7a08406dd286e252c11a66be27f81" # exclude pre-releases for both python 2.x and 3.x UPSTREAM_CHECK_REGEX = "[Pp]ython-(?P\d+(\.\d+)+).tar" @@ -532,5 +530,4 @@ py3_sysroot_cleanup () { rm -rf ${SYSROOT_DESTDIR}${libdir}/python${PYTHON_MAJMIN}/test } -CVE_STATUS[CVE-2026-6019] = "cpe-stable-backport: backported to v3.14.5" -CVE_STATUS[CVE-2026-7210] = "cpe-stable-backport: backported to v3.14.6" + From patchwork Sat Sep 5 20:44:27 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 97388 X-Patchwork-Delegate: yoann.congal@smile.fr Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 116CCC79FAB for ; Sat, 5 Sep 2026 20:45:38 +0000 (UTC) Received: from mail-wr1-f48.google.com (mail-wr1-f48.google.com [209.85.221.48]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.2592.1788641127211499975 for ; Sat, 05 Sep 2026 13:45:27 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=kUSyIbAm; spf=pass (domain: smile.fr, ip: 209.85.221.48, mailfrom: yoann.congal@smile.fr) Received: by mail-wr1-f48.google.com with SMTP id ffacd0b85a97d-4843e397f74so2721378f8f.1 for ; Sat, 05 Sep 2026 13:45:26 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1788641125; x=1789245925; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=0y3cfvENInITWUxZ2xGPwa2XH8s9cBLy5S0TdjeRqsA=; b=kUSyIbAmR2vOaMWsUfJrWs6ABV+JVL8t/Vrt3DHE66Y1KoESXwe/0O5kByQDhTPTbm 6WIDvRWf03lNFzyLk+4QLgQIHnigWE0BDSwqEhrG8cndnAC8t4rKnmiFquPI5fmBsZMO U6EpFuPzdArthTMqPZxMCIObRBBg9j81kVBU4= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1788641125; x=1789245925; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=0y3cfvENInITWUxZ2xGPwa2XH8s9cBLy5S0TdjeRqsA=; b=Y87MVtHXUa3m2SeBHAStHT6287VsbrE1RUjKMUGOObdGm/UgeBcaRsBQd0MI2m9r/b rFBg1w/YzmO6f8lYLrdv2ka91tMFAe2VvzMxNRPJbhWza6eVpMW0y1RZFegEFC2IF/sX mb6Cd/2Zs2bGKOYDyGz2TbDXrNtWb8Kkf21PoiBC8SwzXPd5KOkJ6vlFfIFFOVKQ4yEo /G4CXdVqsOskciPKG5mMUu9JD+s48hHoxx5rtfYSm5Aw6iYvesyr5PNmPEkQKfwy+LOQ 3H+ysTlTewQf+vNCQQWqFarIevQYYCBw59BmKfhwXvAOWggOFNm1w+VgtNclW0teIqER vmZQ== X-Gm-Message-State: AFuF++kK/R409ILiEBAQJyAH/E0aL3g5TrpRzXFHX+5auADsDhVKnDZs IlGQwgiJklZmLtMWlFzpBaIBBPRTA9TymsVtTyrUR6OjwRbxcEghFclMxy28Ko8AI6fzh8tvlxk AKJPLoGw= X-Gm-Gg: AYBFou164U3K5OJaD7LdyoLxr3fl19ikUKkSca8Yzjj/i74VCRYnleyWBzbuCx1Vrts s1kwFgGD+PEgA6V22+lY4fOA+4SjVK7u6JN1zOAGadWYSat2CuZZlqwRXZGFdGjohgOch4HFMLG dNcqY0S09uw2R0oFCHqjhHHWzFlAVlGTl/oTT0lScjTnZbCJoN14blWhzUV01BaLdXax38oo4uk o+QH+PRERlZGhx2/xlXAey27f72ihqtg7K38B/L950Mn/6/3hIjmv02D4BATE20DuVvN7TSAaaR UC3UfgXfGS5zg0VDmm3K6zV/aq9N1WoOEVC9+XSdoo5EPq0gUPqlW2sUNjUtxBqFxpBAh9D0kfS 4bN81PioIYjnxC5nkN72ryc4v2x2KF4KPMgpgYUBLZM+iuKGh7h5b9pCJ6D7RhilEq10qQMMKxn IrC6lQqM0qVVMFqEcY4HR0DTKK25yK/ITy0dRRpcC1AwlP0mBaPf2T7upYHqXA48zaKxCmX6zly tMucvHZrs1FfwBUGzij8mp6+jPfekgYD6cwMvy3apSlgpZaeLqJheJCmgSHoYdREg== X-Received: by 2002:a05:6000:4106:b0:485:8a07:3f0b with SMTP id ffacd0b85a97d-4858a074201mr13903253f8f.0.1788641125359; Sat, 05 Sep 2026 13:45:25 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa0048511f7ccf23d3ce.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:4851:1f7c:cf23:d3ce]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-485885bfdf6sm17069098f8f.34.2026.09.05.13.45.25 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sat, 05 Sep 2026 13:45:25 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][wrynose 26/40] volatile-binds: order systemd-timesyncd after /var/lib Date: Sat, 5 Sep 2026 22:44:27 +0200 Message-ID: <6a4192ca81c40c4b0a9d74e586b6a97934c37917.1788629392.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Sat, 05 Sep 2026 20:45:38 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/245178 From: Esa Jaaskela systemd-timesyncd stores its clock file under /var/lib/systemd/timesync, so it can fail to save state if it starts before the volatile /var/lib is mounted. Add it to the Before= and WantedBy= entries already used for systemd-random-seed.service. (cherry picked from commit 1b8d8c25e46f1df7079545f4297496426fd9d371) Signed-off-by: Esa Jaaskela Signed-off-by: Richard Purdie Signed-off-by: Patrick Vogelaar Signed-off-by: Yoann Congal --- meta/recipes-core/volatile-binds/volatile-binds.bb | 9 +++++---- 1 file changed, 5 insertions(+), 4 deletions(-) diff --git a/meta/recipes-core/volatile-binds/volatile-binds.bb b/meta/recipes-core/volatile-binds/volatile-binds.bb index 857bcc93ff1..613e750c17c 100644 --- a/meta/recipes-core/volatile-binds/volatile-binds.bb +++ b/meta/recipes-core/volatile-binds/volatile-binds.bb @@ -57,10 +57,11 @@ ${@d.getVar('VOLATILE_BINDS').replace("\\n", "\n")} END if [ -e "$var_lib_servicefile" ]; then - # As the seed is stored under /var/lib, ensure that this service runs - # after the volatile /var/lib is mounted. - sed -i -e "/^Before=/s/\$/ systemd-random-seed.service/" \ - -e "/^WantedBy=/s/\$/ systemd-random-seed.service/" \ + # The random seed and the timesyncd clock file are stored under + # /var/lib, so ensure that those services run after the volatile + # /var/lib is mounted. + sed -i -e "/^Before=/s/\$/ systemd-random-seed.service systemd-timesyncd.service/" \ + -e "/^WantedBy=/s/\$/ systemd-random-seed.service systemd-timesyncd.service/" \ "$var_lib_servicefile" fi } From patchwork Sat Sep 5 20:44:28 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 97377 X-Patchwork-Delegate: yoann.congal@smile.fr Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 023CEC79F8B for ; Sat, 5 Sep 2026 20:45:36 +0000 (UTC) Received: from mail-wr1-f44.google.com (mail-wr1-f44.google.com [209.85.221.44]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.2593.1788641127830276032 for ; Sat, 05 Sep 2026 13:45:28 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=bXDbkPST; spf=pass (domain: smile.fr, ip: 209.85.221.44, mailfrom: yoann.congal@smile.fr) Received: by mail-wr1-f44.google.com with SMTP id ffacd0b85a97d-485888b3c3dso2281438f8f.2 for ; Sat, 05 Sep 2026 13:45:27 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1788641126; x=1789245926; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=vphCVum9TrrHSjClpI3w/58hSkZLC3UiB5fHdoyy8dI=; b=bXDbkPSTW2YMQOcFVMDisnI2VmtPjGm8hJKXVYa4Sr+C+eNGS/O1rPG1RtmQ5n5ozA 7VBnM1VAEImz12VnKIg04C8HHU+0kp5spyOcfDRpgknnuubdnFda6BbheL6RX9VsQmFf 5VHCRKpxhASi0cyf3dkerfxC3tnm+RYNhg5kk= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1788641126; x=1789245926; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=vphCVum9TrrHSjClpI3w/58hSkZLC3UiB5fHdoyy8dI=; b=BGVcojqsOPVedNqId9fQc2bS0pDGNuiJmA9FwGcu6RtDeS2cO/rtwLwgTk2EbpUh0O 6n5H79oi2O/dPuTZzxI7wSlPNnwKiQ1xOoKPIN/968h0H5Ry+JH7GxTPTfJCKuxGxLd/ C+UzS69eVWeVbcmCiMupjTLiU8MKG7R2sc+S5d3uJD/XOd7JaD5pscfh8UhSqAuVmOOR FhqtPcbjZsqqIJgdjuy6QGJDgdti/rGWbhytWE3XvjGeHviuXTdgSC3iOAsridUnVsyX 4tINumpnTy2t0lhOp27Om74fxeqyOEYA66rj/othQIJ3s3oOnJ4lrpd1eH25mfiqBcvb M/Xg== X-Gm-Message-State: AFuF++lxO7zcaojPVVWcWsWCcmMtEKbj46AujHHlpW/05LJ7gKAW2gJj Evyja1NgoGAyVyKb5SJgvOGsAEdCGB/gvMd5jsDlMA/rPBc6VXlH02V/lpTpIfjr9a09Nu8dIm9 cGppVVkE= X-Gm-Gg: AYBFou2NssdoAT2yiJOAnMIjSZ06magfMaAU+essDQoX24H33Z2gTAx1gHSfi5zZwbx RWjFvv5hYI7v6nkUAptJJE+flaK9gMla+fN8fHZa5Nw8FVFTI6NOOyniyVYsYgjpY3zNlfMgvZ7 aN8wdhErzubik21mlpRKJGUZ6hbdBaAao5RyOf8+WIgnXU069EcN4IqxYnBwsKx0gOvX6J+Hc3t 7Mo9chTWhJ2wAqz0jvwBmwXf2DQPU4KMq8l0Rdmt3xEWwlSuOAp9EMuBMfF9ZL18f1YEN4cHzOg NPU9sfQZAw80x9k1W1ul0IHJxJ+f270WmCvUZ/kQe8c9ACn70jG14YHd5THluK/MzSMaQz1sqFR nK4CrlcuScBCHZwc5zm8vXeBVT76zrewfFL63zXqlkIaJWOGFZKwe/sQgIh/6cP1pw8p3lcWiGa spFIzkp5ot6iM3tHvavl/W6y6siv6Aj61qD0/CxP84YJ3Doll47xZbQOUng5XX/1LompZeIAafy kCNrr8NmQlSsMTipoErk9vTmLOIZ2sjYh65telfc5xhSNl7p3CCdU0/cEx/v++xkA== X-Received: by 2002:a05:6000:41d7:b0:485:8c16:5efd with SMTP id ffacd0b85a97d-4858c16611emr10144882f8f.55.1788641125955; Sat, 05 Sep 2026 13:45:25 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa0048511f7ccf23d3ce.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:4851:1f7c:cf23:d3ce]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-485885bfdf6sm17069098f8f.34.2026.09.05.13.45.25 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sat, 05 Sep 2026 13:45:25 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][wrynose 27/40] go: upgrade 1.26.5 -> 1.26.6 Date: Sat, 5 Sep 2026 22:44:28 +0200 Message-ID: X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Sat, 05 Sep 2026 20:45:36 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/245179 From: Peter Marko Upgrade to latest 1.26.x release [1]: $ git --no-pager log --oneline go1.26.5..go1.26.6 1ea5a71ad8 (tag: go1.26.6) [release-branch.go1.26] go1.26.6 115eb476aa [release-branch.go1.26] cmd/vendor: fix CVE-2026-56865 in x/mod 9f6980fd5c [release-branch.go1.26] cmd/vendor: fix CVE-2026-56864 in x/mod 6ec908dd24 [release-branch.go1.26] encoding/asn1: enforce maximum recursion depth 9918f26ab3 [release-branch.go1.26] encoding/xml: fix depth processing in (*Decoder).unmarshal 33ecb966ca [release-branch.go1.26] html/template: fix JavaScript regexp tracking 128893dbf9 [release-branch.go1.26] net/url: avoid quadratic complexity in resolvePath 13c194062c [release-branch.go1.26] cmd/compile: do not elide riscv64 sign extension of unsigned values 52e5e2f22a [release-branch.go1.26] cmd/compile: fix time traveling proofs in prove db38ee7121 [release-branch.go1.26] cmd/compile: fix prove to generate Const64 for 64bits slicemasks f5bf46f361 [release-branch.go1.26] cmd/compile: fix mips64le bigger than 32bits pointer offsets f8d4fa6213 [release-branch.go1.26] runtime: fix frame pointer adjustment around injected calls efc79671b1 [release-branch.go1.26] cmd/compile: do not home mul/div results in HI/LO 605fd48711 [release-branch.go1.26] crypto/tls: add fips140ems GODEBUG setting to disable EMS enforcement 100fb8f023 [release-branch.go1.26] cmd/link: quote PE .def library name 4d522f275f [release-branch.go1.26] cmd/compile: tighten mergelocals address use analysis 0e8a244fe5 [release-branch.go1.26] all: update x/net 019fcb0152 [release-branch.go1.26] cmd/compile: don't require Heapaddr for heap vars in dead code b6432317a1 [release-branch.go1.26] crypto/tls: do not count handshake messages as state-advancing post-handshake ae63e27897 [release-branch.go1.26] runtime: fix uninitialized 7th argument in mach_vm_region_trampoline 88bf57924f [release-branch.go1.26] runtime: don't emit write barrier for code pointers in itabInit 4238449188 [release-branch.go1.26] os: strip trailing slashes in RemoveAll on Plan 9 28f27d64cf [release-branch.go1.26] os: properly handle trailing / in Root.MkdirAll cc312256f8 [release-branch.go1.26] runtime: be sure to scan small frame introduced by (*sigctxt).pushCall 07a0bbba1b [release-branch.go1.26] os: don't expect an error from Root.ReadFile from a directory on NetBSD a42fec40ab [release-branch.go1.26] all: update x/net 5bbd22ff78 [release-branch.go1.26] net/http: apply header timeout to server's unencrypted HTTP/2 check Fixes CVE-2026-56865, CVE-2026-56864, CVE-2026-56859, CVE-2026-56853, CVE-2026-56860, CVE-2026-46600, CVE-2026-56862, CVE-2026-56858, CVE-2026-39821 and CVE-2026-33818. Release information: [2] [1] https://github.com/golang/go/compare/go1.26.5...go1.26.6 [2] https://groups.google.com/g/golang-announce/c/94pEornpRlI (From OE-Core rev: cae8a33abfda172e65166811eeb1bc7ad2d129a3) Signed-off-by: Peter Marko Signed-off-by: Richard Purdie Signed-off-by: Peter Marko Signed-off-by: Yoann Congal --- meta/recipes-devtools/go/{go-1.26.5.inc => go-1.26.6.inc} | 2 +- ...o-binary-native_1.26.5.bb => go-binary-native_1.26.6.bb} | 6 +++--- ...cross-canadian_1.26.5.bb => go-cross-canadian_1.26.6.bb} | 0 .../go/{go-cross_1.26.5.bb => go-cross_1.26.6.bb} | 0 .../go/{go-crosssdk_1.26.5.bb => go-crosssdk_1.26.6.bb} | 0 .../go/{go-runtime_1.26.5.bb => go-runtime_1.26.6.bb} | 0 meta/recipes-devtools/go/{go_1.26.5.bb => go_1.26.6.bb} | 0 7 files changed, 4 insertions(+), 4 deletions(-) rename meta/recipes-devtools/go/{go-1.26.5.inc => go-1.26.6.inc} (90%) rename meta/recipes-devtools/go/{go-binary-native_1.26.5.bb => go-binary-native_1.26.6.bb} (80%) rename meta/recipes-devtools/go/{go-cross-canadian_1.26.5.bb => go-cross-canadian_1.26.6.bb} (100%) rename meta/recipes-devtools/go/{go-cross_1.26.5.bb => go-cross_1.26.6.bb} (100%) rename meta/recipes-devtools/go/{go-crosssdk_1.26.5.bb => go-crosssdk_1.26.6.bb} (100%) rename meta/recipes-devtools/go/{go-runtime_1.26.5.bb => go-runtime_1.26.6.bb} (100%) rename meta/recipes-devtools/go/{go_1.26.5.bb => go_1.26.6.bb} (100%) diff --git a/meta/recipes-devtools/go/go-1.26.5.inc b/meta/recipes-devtools/go/go-1.26.6.inc similarity index 90% rename from meta/recipes-devtools/go/go-1.26.5.inc rename to meta/recipes-devtools/go/go-1.26.6.inc index a4302b2790a..fa6b0a50a14 100644 --- a/meta/recipes-devtools/go/go-1.26.5.inc +++ b/meta/recipes-devtools/go/go-1.26.6.inc @@ -16,4 +16,4 @@ SRC_URI += "\ file://0009-go-Filter-build-paths-on-staticly-linked-arches.patch \ file://0010-cmd-go-clear-GOROOT-for-func-ldShared-when-trimpath-.patch \ " -SRC_URI[main.sha256sum] = "495be4bc87176ac567392e5b4116abd98466d33d7b49d41e764ccc6976b2dc42" +SRC_URI[main.sha256sum] = "a0721c54c688901448d77ad9b3ec7ea7c474730755ff891382e92ecb93ff2cb1" diff --git a/meta/recipes-devtools/go/go-binary-native_1.26.5.bb b/meta/recipes-devtools/go/go-binary-native_1.26.6.bb similarity index 80% rename from meta/recipes-devtools/go/go-binary-native_1.26.5.bb rename to meta/recipes-devtools/go/go-binary-native_1.26.6.bb index 97a8270be2d..2913fb65151 100644 --- a/meta/recipes-devtools/go/go-binary-native_1.26.5.bb +++ b/meta/recipes-devtools/go/go-binary-native_1.26.6.bb @@ -9,9 +9,9 @@ PROVIDES = "go-native" # Checksums available at https://go.dev/dl/ SRC_URI = "https://dl.google.com/go/go${PV}.${BUILD_GOOS}-${BUILD_GOARCH}.tar.gz;name=go_${BUILD_GOTUPLE}" -SRC_URI[go_linux_amd64.sha256sum] = "5c2c3b16caefa1d968a94c1daca04a7ca301a496d9b086e17ad77bb81393f053" -SRC_URI[go_linux_arm64.sha256sum] = "fe4789e92b1f33358680864bbe8704289e7bb5fc207d80623c308935bd696d49" -SRC_URI[go_linux_ppc64le.sha256sum] = "c5d60e2b303bb612f20cd82786594b64874e73b35134025e27d3390bf284ae43" +SRC_URI[go_linux_amd64.sha256sum] = "708effb774be8237570d0add163225abbdfaf4fca28b2611df167beba4feef89" +SRC_URI[go_linux_arm64.sha256sum] = "d0507e9e9d7fe012aae570108cbd76c15de879e17130ab8cb90d4d7445cb1f2e" +SRC_URI[go_linux_ppc64le.sha256sum] = "232b65543a42eda95df6a63f76235c1795bb535eba5c74e509faec71bc648388" UPSTREAM_CHECK_URI = "https://golang.org/dl/" UPSTREAM_CHECK_REGEX = "go(?P\d+(\.\d+)+)\.linux" diff --git a/meta/recipes-devtools/go/go-cross-canadian_1.26.5.bb b/meta/recipes-devtools/go/go-cross-canadian_1.26.6.bb similarity index 100% rename from meta/recipes-devtools/go/go-cross-canadian_1.26.5.bb rename to meta/recipes-devtools/go/go-cross-canadian_1.26.6.bb diff --git a/meta/recipes-devtools/go/go-cross_1.26.5.bb b/meta/recipes-devtools/go/go-cross_1.26.6.bb similarity index 100% rename from meta/recipes-devtools/go/go-cross_1.26.5.bb rename to meta/recipes-devtools/go/go-cross_1.26.6.bb diff --git a/meta/recipes-devtools/go/go-crosssdk_1.26.5.bb b/meta/recipes-devtools/go/go-crosssdk_1.26.6.bb similarity index 100% rename from meta/recipes-devtools/go/go-crosssdk_1.26.5.bb rename to meta/recipes-devtools/go/go-crosssdk_1.26.6.bb diff --git a/meta/recipes-devtools/go/go-runtime_1.26.5.bb b/meta/recipes-devtools/go/go-runtime_1.26.6.bb similarity index 100% rename from meta/recipes-devtools/go/go-runtime_1.26.5.bb rename to meta/recipes-devtools/go/go-runtime_1.26.6.bb diff --git a/meta/recipes-devtools/go/go_1.26.5.bb b/meta/recipes-devtools/go/go_1.26.6.bb similarity index 100% rename from meta/recipes-devtools/go/go_1.26.5.bb rename to meta/recipes-devtools/go/go_1.26.6.bb From patchwork Sat Sep 5 20:44:29 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 97381 X-Patchwork-Delegate: yoann.congal@smile.fr Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id BA34BC79FA3 for ; Sat, 5 Sep 2026 20:45:36 +0000 (UTC) Received: from mail-wr1-f44.google.com (mail-wr1-f44.google.com [209.85.221.44]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.2594.1788641128417533333 for ; Sat, 05 Sep 2026 13:45:28 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=sj+eTAGI; spf=pass (domain: smile.fr, ip: 209.85.221.44, mailfrom: yoann.congal@smile.fr) Received: by mail-wr1-f44.google.com with SMTP id ffacd0b85a97d-482dbe4d247so1316797f8f.2 for ; Sat, 05 Sep 2026 13:45:28 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1788641127; x=1789245927; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=tZUASDP1ecdzK849cYk5+mUdR+TRMCCbueKhxx0fvwQ=; b=sj+eTAGIUjDvda6gHtyF0xPrwXYmDoPjsTKx6GU7p5SrKdH+Y/4i1tveYpbjePeimW dymqRt49I+lb6NKnOcdrfIfl4SZnoMgPwFIeA0gsu4zhf0u4tG08/4h++rLCL/90lnOE cLAmZGOKJvLZBSJ7pziGwY+hkuzj+mtjxHSYk= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1788641127; x=1789245927; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=tZUASDP1ecdzK849cYk5+mUdR+TRMCCbueKhxx0fvwQ=; b=QQ2sgKbYWpwfLpme06Xx8H/C/49sd+kkEko9NZbs0zT+6JUUa5n3VoXHdLVvcMRk6M ohlcn/4szlWXZUjGf23FiQtSMozIUoJCI36w6/ag6koKQ38HtQywdN3XjHqtDmQGmNtS UwaiCrQSobOlQd8enJ78hUp5mzxC75VWCYE1uOJfzsf1/2HHV5EGU0QgVVtM7k2iqb2u IycSevISE2Cv1buwsWHSCqQYhXl5rZwtznylXTs6lbdZwJAQ6YMf4DxK3zO12AqkZUkh SwHes5B90+jp5IT3oXnGV3zPVZ+yTOdXWhoz/gHMvwlBKz6NxE7EVldiwwr0ojR/UO0D YemQ== X-Gm-Message-State: AFuF++lDE0VHe1Oyo9yukTzkwD+koJaO4lrt11mYGDzeeqWBNdWKp7SX CpQywOoN4yqbJbLVGs5jVAvpdBMw1hKuT8D/EdumdVQUKNhTJ8GEkyMhx9x5vM1wBCHZjTk1fIH tRGpxfV0= X-Gm-Gg: AYBFou1TELjtDCy44CFWFsf8FoNRQmAbfpGqokKgb9y6uOKL48BOb9IF/lAyPN4vBa2 IuymX5haidITU8u3fFzg2kbdgdD3ZejMaFMr82cQ9cpcC0z8EaoCwSO6cX5Gr4KVOIkLPWpze9o CWtzH94INE7w45/oMFQ5r4ssTssnIYr9NNgRbeYtU6/SQ6jPvl6CEQauDyb+Aq2DpEmu1VYBWWL 3+01pxL1coS+EOTHWCHpN+iZ/4E7P/qytY6TFdOVWE38G00xL1LhROsQJpLwmgLhJBlJ8rKrOE0 WMrIZtM/Se4e4CMABztXh4bXpUpEhZHO2nCbvqRxgYqS+sUM7gYqLdWOFMS0DJ57FIFkIZgZ483 4DPLVQHfvz8jOQqgyFO29UYsI5GHMb5zNT36TAuZmRLUHft+S0Yvcwwpg9xh7ysE80a0Xt0BmTy HkI5yh0Jahs8IeK1vlBvupVZYFXJ/0zx8Hk5SF+AjDbZYEeXMEZsFnhXCEP13ukvI2EhV5NGEB7 TVRVg8JrnrpXVc7vZfL/B+hPAMYDMQwxx9WkrZTHaWzWg5L8B1tyeYo7k69+WyksQ== X-Received: by 2002:a05:6000:26d3:b0:485:8393:2176 with SMTP id ffacd0b85a97d-485870902eamr25564543f8f.21.1788641126607; Sat, 05 Sep 2026 13:45:26 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa0048511f7ccf23d3ce.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:4851:1f7c:cf23:d3ce]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-485885bfdf6sm17069098f8f.34.2026.09.05.13.45.26 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sat, 05 Sep 2026 13:45:26 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][wrynose 28/40] python3: add missing pyc files to core Date: Sat, 5 Sep 2026 22:44:29 +0200 Message-ID: X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Sat, 05 Sep 2026 20:45:36 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/245180 From: Tafil Avdyli Recently _ast_unparse, _py_warnings and annotationlib were added to core. The corresponding .pyc files were omitted, resulting them to be generated on the target. Fixes: 01982411b5cc ("python3: add _py_warnings, annotationlib to core") Fixes: 9dfe1e7722fc ("python3: add _ast_unparse to core") (cherry picked from commit 300a0ba0bc96b66be63f8c4324342ed1a9ef3c73) Signed-off-by: Tafil Avdyli Signed-off-by: Mathieu Dubois-Briand Signed-off-by: Richard Purdie Signed-off-by: Tafil Avdyli Signed-off-by: Yoann Congal --- meta/recipes-devtools/python/python3/python3-manifest.json | 3 +++ 1 file changed, 3 insertions(+) diff --git a/meta/recipes-devtools/python/python3/python3-manifest.json b/meta/recipes-devtools/python/python3/python3-manifest.json index 11ce2c97d2d..5d46e4e8b9b 100644 --- a/meta/recipes-devtools/python/python3/python3-manifest.json +++ b/meta/recipes-devtools/python/python3/python3-manifest.json @@ -324,16 +324,19 @@ ], "cached": [ "${libdir}/python${PYTHON_MAJMIN}/__pycache__/__future__.*.pyc", + "${libdir}/python${PYTHON_MAJMIN}/__pycache__/_ast_unparse.*.pyc", "${libdir}/python${PYTHON_MAJMIN}/__pycache__/_bootlocale.*.pyc", "${libdir}/python${PYTHON_MAJMIN}/__pycache__/_collections_abc.*.pyc", "${libdir}/python${PYTHON_MAJMIN}/__pycache__/_colorize.*.pyc", "${libdir}/python${PYTHON_MAJMIN}/__pycache__/_compression.*.pyc", "${libdir}/python${PYTHON_MAJMIN}/__pycache__/_markupbase.*.pyc", "${libdir}/python${PYTHON_MAJMIN}/__pycache__/_opcode_metadata.*.pyc", + "${libdir}/python${PYTHON_MAJMIN}/__pycache__/_py_warnings.*.pyc", "${libdir}/python${PYTHON_MAJMIN}/__pycache__/_sitebuiltins.*.pyc", "${libdir}/python${PYTHON_MAJMIN}/__pycache__/_sysconfigdata*.*.pyc", "${libdir}/python${PYTHON_MAJMIN}/__pycache__/_weakrefset.*.pyc", "${libdir}/python${PYTHON_MAJMIN}/__pycache__/abc.*.pyc", + "${libdir}/python${PYTHON_MAJMIN}/__pycache__/annotationlib.*.pyc", "${libdir}/python${PYTHON_MAJMIN}/__pycache__/argparse.*.pyc", "${libdir}/python${PYTHON_MAJMIN}/__pycache__/ast.*.pyc", "${libdir}/python${PYTHON_MAJMIN}/__pycache__/bisect.*.pyc", From patchwork Sat Sep 5 20:44:30 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 97383 X-Patchwork-Delegate: yoann.congal@smile.fr Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id F298FC79FA4 for ; Sat, 5 Sep 2026 20:45:36 +0000 (UTC) Received: from mail-wr1-f46.google.com (mail-wr1-f46.google.com [209.85.221.46]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.2489.1788641128904343822 for ; Sat, 05 Sep 2026 13:45:29 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=UMhOc0m8; spf=pass (domain: smile.fr, ip: 209.85.221.46, mailfrom: yoann.congal@smile.fr) Received: by mail-wr1-f46.google.com with SMTP id ffacd0b85a97d-4858c1c4b4eso1169215f8f.2 for ; Sat, 05 Sep 2026 13:45:28 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1788641127; x=1789245927; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=mdoz18gLtnFEsc3LKcgVihEFic+zpaDiK+ToosIdRKY=; b=UMhOc0m8Tib5P0j40a3XX+E+dZGr+jioYar/O1km/reNnZ+AtzUNUVjqZejzV6egO9 Imn3kxOdOB1Wl4KrIimeAT10+9YtblQajFA7LRxNvvL6nXbcT/Xh9VvYlGfiWo7CO5ZL qAebqL0DxpUkZN7a979wnvDQVFKv4oI40ZJeY= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1788641127; x=1789245927; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=mdoz18gLtnFEsc3LKcgVihEFic+zpaDiK+ToosIdRKY=; b=JQtrAduTCaVjKRjcHtyFK0NCDW0zzBgnbpOJbGjkKpzHvtMnwT/uAhe7hxjGolTB30 npFGlfsH2yYSwdJJdU36OUOL80WzLA8W2VsvMv9e54BJgC1vnE7OuVwrOmIo+3h3XZ3j eluesL8+GStPM4YlkPp9vLcFRsjEKI2kcwynJm7yAqhthTNeYypJqHjyhfCa+OTaNr9U +Cq+iepto/gJieaz0mahHafy7bXgfSn3tmzGYXO1+HJud+Pe7Nm/66zox5vDS8X8erTr MwmFEVUMirgSHMXDaOJqv0WhKDn5Lr0rZIMbZy+NA5VjVh2yp1UAVGLLgFY7jf+6ciaa 2NeQ== X-Gm-Message-State: AFuF++lfLGpewpvZNO+ViCdYkqOiWeoU/0jMEd7Pf/kiJ0FAlm2fearl f3b5YoPf3voMwyU6wrF6kDn1w9VTx1/R5u9E1BkedI1NQ7iBsivLhwBuxmzkX2AVyJuh5oNuCB0 GkVHgLSU= X-Gm-Gg: AYBFou1qPMer3ONtVQV78qzQLc+pHopYNsau7i1iqT/aD1ywQ2btnF5L9LMM3ExPTIX j7xVw41mNnfFVqKzcP9ZXbkBQoHi+z1cF6lxVpLMeWv1K4SLqT5l6aybyYA7tH0dAkqzuKYPi9P N6K8QWmXwtoFeF1in0dsW8AFWc7pd2EqPGKozRTNPIzJK8YLyUX/BawgOFiFAVBOpsA+24pPLGc MX93ehHqxPYdUCK+AqlGrmYxoPWBYGmvxHlCfS/VOC+v2r7BZDnl8vrfz9sj7qCsLujDR/ACwTz MFBzDd0kFLO/pU0OB60sn7W6Ek8ppQjLM1OM8fqDNX04KsdajzQLS+bYZgWt6x8KSn/Mer/BQfu 890qxtSm5jno7ablKsgNyRCdcM9wdhnHLbd6t4K7bo1qeGoyQ3NZqGba0nhGwPqMBy5loArzBaS KeJVwY3NIdgRzmOH/QyS8kUwXCBVGmMM4DxuJnUl0+9A0MevAjyQiafFfji0dBeQGn7wUTH/BSh MTDZFZFVRa35i/kp1Rp5wl5j+6mq9PlnKiFGUs+4ZCjAC7q4INXZ5RWUYVu4UweYA0= X-Received: by 2002:a05:6000:4010:b0:485:9393:76d5 with SMTP id ffacd0b85a97d-48593937803mr3947104f8f.18.1788641127115; Sat, 05 Sep 2026 13:45:27 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa0048511f7ccf23d3ce.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:4851:1f7c:cf23:d3ce]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-485885bfdf6sm17069098f8f.34.2026.09.05.13.45.26 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sat, 05 Sep 2026 13:45:26 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][wrynose 29/40] python3: fix stringold cache files Date: Sat, 5 Sep 2026 22:44:30 +0200 Message-ID: X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Sat, 05 Sep 2026 20:45:36 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/245181 From: Tafil Avdyli In the 3.14.0 upgrade the stringold package updated to the string module directory but did not update the cache files. This resulted on targets to generate `string/__pycache__/__init__.cpython-314.pyc`. The packaging of the cache files can be only separated with a manual edit but breaks do_create_manifest. Instead follow other packages and bundle `string/__pycache__` in files. Fixes: 56318067ab3e ("python3: upgrade 3.13.11 -> 3.14.0") (cherry picked from commit 90e44d557d9897bd5c73018825d74eb338273b58) Signed-off-by: Tafil Avdyli Signed-off-by: Mathieu Dubois-Briand Signed-off-by: Richard Purdie Signed-off-by: Tafil Avdyli Signed-off-by: Yoann Congal --- .../recipes-devtools/python/python3/python3-manifest.json | 8 +++----- 1 file changed, 3 insertions(+), 5 deletions(-) diff --git a/meta/recipes-devtools/python/python3/python3-manifest.json b/meta/recipes-devtools/python/python3/python3-manifest.json index 5d46e4e8b9b..008d41e5654 100644 --- a/meta/recipes-devtools/python/python3/python3-manifest.json +++ b/meta/recipes-devtools/python/python3/python3-manifest.json @@ -1047,12 +1047,10 @@ "core" ], "files": [ - "${libdir}/python${PYTHON_MAJMIN}/string/__init__.py", - "${libdir}/python${PYTHON_MAJMIN}/string/templatelib.py" + "${libdir}/python${PYTHON_MAJMIN}/string", + "${libdir}/python${PYTHON_MAJMIN}/string/__pycache__" ], - "cached": [ - "${libdir}/python${PYTHON_MAJMIN}/__pycache__/string.*.pyc" - ] + "cached": [] }, "syslog": { "summary": "Python syslog interface", From patchwork Sat Sep 5 20:44:31 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 97385 X-Patchwork-Delegate: yoann.congal@smile.fr Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 35FDFC79FA5 for ; Sat, 5 Sep 2026 20:45:37 +0000 (UTC) Received: from mail-wr1-f41.google.com (mail-wr1-f41.google.com [209.85.221.41]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.2595.1788641129488541024 for ; Sat, 05 Sep 2026 13:45:29 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=HMjI8syj; spf=pass (domain: smile.fr, ip: 209.85.221.41, mailfrom: yoann.congal@smile.fr) Received: by mail-wr1-f41.google.com with SMTP id ffacd0b85a97d-4843efcbdb2so1099938f8f.2 for ; Sat, 05 Sep 2026 13:45:29 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1788641128; x=1789245928; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=RAfZf/u4qIXHyL82JIK1P5zwhgtgiwbUgqBAsrFHe2U=; b=HMjI8syj78SR2gTTM/gah5JvN87BzlwgEWfD71NdFULVyX+yWFmZvRX/TeyUYr1gPQ 8atAiL/P6nj/b8txfllOFloCYPmd/hKzOJejBQ3/dPQZEDe+oRnU735kVShc95IGAWgQ /P/7CPhv/eWpN3FiGbZdHYC/V4jQGYxCuZtW8= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1788641128; x=1789245928; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=RAfZf/u4qIXHyL82JIK1P5zwhgtgiwbUgqBAsrFHe2U=; b=Ogn4Ja6gqVfJn1Np4rw/YTvMVBkEzTJpxLd88nLZ2GdRNuEdwIFjixhlEn6Y337F5X knkTDsfsvH3Zc7DiSJ7yZ/7oEmTmC6uxWh4J0h/OtG1USgA0adX0JTZdKcUQZBrIaG1i zwmRec3lCRY5Y8jYggh1rswKAD5wdEiQU/i4enl/LTHZfxxqVV8wpWFCu47LnqBTYWlb zGrVa+HHQDxheudWJrC7gH2LtQfKDTAZmrhScFcza0JlhIRKm4MCsKXDZmv5Lu/KZj2l ZPTjrqy822PWY5BTjEmn3/CdjC19hm437E20/R+9XxHzvgghMq7C21AeOpj/c1FL8LkO rGYQ== X-Gm-Message-State: AFuF++ljgVhyGatVF/ntuSBkECQkdU4oJmmQGsJ/CVO0lY529w2n+Nz1 6cry7AY7bXujFyqB19UehdH0RQGbbYX+0UpoGNlQpHff9IZQVkaIdeNdCrLJ+TLzMXGq86uZ502 m8j1YDW4= X-Gm-Gg: AYBFou0wZksnP21r4ac68DyTkfYavwEtX3DTLKl2YyLCwdF4PjqSkK0la5sQi/TXw5l CtuEGd3hkXsCDefpsHbrOjBgAAazlie3iMIL/vQk8QlyTUfjckfcSd835uqfFx7OshQrFrWhV23 cNCFy+piPMoQpFlOsTPztijHbJA3erqQE9S7r5gc1yQoUxiAQI6CJp132g/2+c3FuOFfk3zClvq O4I30ZqAQEOtuWRQyLKIJdnr2qG8SyyDyaI6H4BBHjXajTqr6w2/THv9ZYbjkFVN7ASU33PbMDA Bp9ruc2JvXz+D5I9kWNhEhpIk5p7rM8/WqvudKEXoYrvfW+XmjDN4oUbvBRBzH8rdcr8DIOonVb SvqSQFCCvb1yeTjpiBTktYXbtMTwAp8nunAt1YQIWf9X2s0er/TURTh0kr+R6eQAL5rcOP/4XEZ VuuDLC0mEi6dtSelReAnYA6Y7T6ujRwAedFTbwXox22x3f6sDmZz6x3IlkZEx3/imdSs+x0o5TC h33MkVzhh9r/ToiSXZyiwuWZeZkNnQkm405TONjFJHqBdPI4hSfRiJoR5/NYJakoA== X-Received: by 2002:a05:6000:4b0f:b0:484:3647:d977 with SMTP id ffacd0b85a97d-485872df445mr15346298f8f.27.1788641127786; Sat, 05 Sep 2026 13:45:27 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa0048511f7ccf23d3ce.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:4851:1f7c:cf23:d3ce]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-485885bfdf6sm17069098f8f.34.2026.09.05.13.45.27 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sat, 05 Sep 2026 13:45:27 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][wrynose 30/40] python3-git: fix CVE_PRODUCT Date: Sat, 5 Sep 2026 22:44:31 +0200 Message-ID: <7ceb739a42260adc216aff61e3d5fe296154ee6c.1788629392.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Sat, 05 Sep 2026 20:45:37 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/245182 From: Tim Orling Using the pypi.bbclass default CPE of python:GitPython detects no CVEs. With CVE_PRODUCT = "gitpython_project:gitpython" we properly detect 9 CVEs, with 4 unpatched. WARNING: core-image-full-cmdline-1.0-r0 do_sbom_cve_check: python3-git-3.1.43: Found unpatched CVEs: CVE-2026-42215, CVE-2026-42284, CVE-2026-44243, CVE-2026-44244 (cherry picked from commit 3a6af75a33b4e007f0d3a247b6a149e32d51e510) Signed-off-by: Tim Orling Signed-off-by: Richard Purdie Signed-off-by: Devansh Patel Signed-off-by: Yoann Congal --- meta/recipes-devtools/python/python3-git_3.1.43.bb | 2 ++ 1 file changed, 2 insertions(+) diff --git a/meta/recipes-devtools/python/python3-git_3.1.43.bb b/meta/recipes-devtools/python/python3-git_3.1.43.bb index 7534531fa37..ebb5e4b442a 100644 --- a/meta/recipes-devtools/python/python3-git_3.1.43.bb +++ b/meta/recipes-devtools/python/python3-git_3.1.43.bb @@ -10,6 +10,8 @@ LIC_FILES_CHKSUM = "file://LICENSE;md5=5279a7ab369ba336989dcf2a107e5c8e" PYPI_PACKAGE = "GitPython" +CVE_PRODUCT = "gitpython_project:gitpython" + inherit pypi python_setuptools_build_meta SRC_URI += "file://CVE-2026-42284.patch \ From patchwork Sat Sep 5 20:44:32 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 97384 X-Patchwork-Delegate: yoann.congal@smile.fr Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 56063C79FA6 for ; Sat, 5 Sep 2026 20:45:37 +0000 (UTC) Received: from mail-wr1-f45.google.com (mail-wr1-f45.google.com [209.85.221.45]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.2596.1788641130080495228 for ; Sat, 05 Sep 2026 13:45:30 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=k+hFOQp9; spf=pass (domain: smile.fr, ip: 209.85.221.45, mailfrom: yoann.congal@smile.fr) Received: by mail-wr1-f45.google.com with SMTP id ffacd0b85a97d-485843aeab8so2346677f8f.1 for ; Sat, 05 Sep 2026 13:45:29 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1788641128; x=1789245928; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=1Nuy8dWkn8fl8+oMdwhPZYfIZs6HVlQpH6ZKqVpHSHM=; b=k+hFOQp9+mOmRtRJJuqTNwvq8tVaIqxD0GnaIHhhwTsa0gl4qao0Xplc0XjltB3sge ji6EmPNmIYUNGgKgFrUpoOHXUrDoT6unsaFj6vjITa0DAHOPSaQWr5Bon6p4UqatWGlT q8jEL46I/WEuEiEK4cAYd01mUk4t5naW8rmvE= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1788641128; x=1789245928; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=1Nuy8dWkn8fl8+oMdwhPZYfIZs6HVlQpH6ZKqVpHSHM=; b=UL3ydumcVkiFrV3QYrvRI+zhaxJW7nzfR48oZR7ivnciQSwa3075yoiSXqAQArbPx5 zhi5yD9/Sm4/UXZGMYpsnSiNG/v7U2sVOIRfW67NGKf5oRDpS6ZUMofJ5HASltclEn+G C7Txn72JrJW5U69KmgtLpVyqbP+yu9guPvM/F8i1bLy7UR1NNL0EB/06g1Tzx1m2sAhy 0YUfPdjfcz0gEdlr28MSzuTkas/tUm+8p9Ya8MtFitWA37bZbKcwqZ/X2HxMz2X8ENIl KXTR4nD6r5pNU9N7B87ZpJEDBqMEur8qgkz9Suiid4UYauOXX8mIhNsgzua/ivLA+KAN nVTQ== X-Gm-Message-State: AFuF++kYb3JwGsJ+iTqkcQo7vXHlY12MIdH4Qtor4kSki0A7k/0HXHW/ 80dRUBu7vLV6R/+AErYOramcud5x10+D/Oqu8/Q+KLH+15CSKm8Cr28h+12unyL3rcVlFdCZ2kx 2CRsGpL0= X-Gm-Gg: AYBFou0Y2v/NXxHzlM4foJBU9Y/4rHciQvDwMdF8htjhOxYF0d0UxGp650mMgK0EQF1 AB0+0C1HIYYKTa0SWkgUs7MbsyInFgie4OVDIUQviiNOLTC9F3anepMQQcm+sqFFraTnE+Btyh3 CivVlfJ8Df1y58qYR5znFPTsnGcJTJw2Lr7FpQmeFqeNLZrDoj/GaRZ/R4XHC/RxHt7UyRI5SZp fTzUkztj6NwyGxiyjpMid12NJ84w2BwZair976aIggpp6YSBFHKkxH/FrsCPdmaRoK7Ls+1KsJi G2vyIvzfLLIN+n8ARgIlsWQlqh6fZ+efF4ZBmpNNsQOxmMy+SHn7tYrj0xxkAxca+vUGlurEJYI YP3cgP3DibjVSGrxfZOy4Ku8BznvabPphCRp+GkaRni2YQVFhS7bUnFy2o+maePZvv/I2iK2r75 wQwSqrzhOB2VA6lKys4xV+g12Vu2Yzn/wn7wDvifmUAfLptOmpoFyVUbQsXrosqutnOkculFlpI e3871s4t6kJ5N0TRaGAc1KAJJZdsAdC2JZE7Hl/smEQFZF5GuxE3oqh0UFKcPeUER7yf3YsFUMN +Q== X-Received: by 2002:a5d:5889:0:b0:485:8b5c:da26 with SMTP id ffacd0b85a97d-4858b5ce16cmr23827162f8f.11.1788641128361; Sat, 05 Sep 2026 13:45:28 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa0048511f7ccf23d3ce.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:4851:1f7c:cf23:d3ce]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-485885bfdf6sm17069098f8f.34.2026.09.05.13.45.27 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sat, 05 Sep 2026 13:45:27 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][wrynose 31/40] binutils: stable 2.46 branch updates Date: Sat, 5 Sep 2026 22:44:32 +0200 Message-ID: <77f7ea9abe58ecf0af7aafa53f195ac2582cedec.1788629392.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Sat, 05 Sep 2026 20:45:37 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/245183 From: Sowmya Sathram Below commits from the binutils-2.46 stable branch are updated on top of the 2.46.1 release. 046eeeef472 x86: Check XMM destination when optimizing 128-bit VPBROADCASTQ 2c77fbc7007 PR 34204 dlltool SEGVs with --exclude-symbols 38093d82a3e Re-enable development on the 2.46 branch Test Results: Before After Diff No. of expected passes 327 327 0 No. of untested testcases 5 5 0 No. of unsupported tests 9 9 0 Signed-off-by: Sowmya Sathram Signed-off-by: Hemanth Kumar M D Signed-off-by: Yoann Congal --- meta/recipes-devtools/binutils/binutils-2.46.inc | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/meta/recipes-devtools/binutils/binutils-2.46.inc b/meta/recipes-devtools/binutils/binutils-2.46.inc index cae7c1c872e..f798d6f1a00 100644 --- a/meta/recipes-devtools/binutils/binutils-2.46.inc +++ b/meta/recipes-devtools/binutils/binutils-2.46.inc @@ -23,7 +23,7 @@ CVE_STATUS[CVE-2025-69651] = "disputed: observed behavior only in pre-release co CVE_STATUS[CVE-2025-69649] = "fixed-version: Fixed from version 2.46" CVE_STATUS[CVE-2025-69652] = "fixed-version: Fixed from version 2.46" -SRCREV ?= "5e56594815854de5eca35c7c04b11705d0f19c02" +SRCREV ?= "a9c090db342ac76f10bc47258ef8e58f7eaca748" BINUTILS_GIT_URI ?= "git://sourceware.org/git/binutils-gdb.git;branch=${SRCBRANCH};protocol=https" SRC_URI = "\ ${BINUTILS_GIT_URI} \ From patchwork Sat Sep 5 20:44:33 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 97382 X-Patchwork-Delegate: yoann.congal@smile.fr Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id D8E18C79FA2 for ; Sat, 5 Sep 2026 20:45:36 +0000 (UTC) Received: from mail-wr1-f47.google.com (mail-wr1-f47.google.com [209.85.221.47]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.2597.1788641130604695354 for ; Sat, 05 Sep 2026 13:45:30 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=mj/u1gpe; spf=pass (domain: smile.fr, ip: 209.85.221.47, mailfrom: yoann.congal@smile.fr) Received: by mail-wr1-f47.google.com with SMTP id ffacd0b85a97d-4858be8b509so856357f8f.0 for ; Sat, 05 Sep 2026 13:45:30 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1788641129; x=1789245929; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=GzSu0jJ5tpDrT7/M/mmNM1x/Pl6+dpq00Efm5Zzz2GA=; b=mj/u1gpeVpJ4Bc4iOwjVAVomGEf/73hK7TrTqweW3EYYoSBx03S4cuMuiP9GRzEoW1 npvIFhXW7u3WyGm1zG3OmdY83GZd56fGRsCkevl4yFIoJCW15/a/ha1wFNn89fJNPbrQ yPVe8Ae40xqrlA4fObKezJbZ9Qmlf9Ve/eZTU= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1788641129; x=1789245929; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=GzSu0jJ5tpDrT7/M/mmNM1x/Pl6+dpq00Efm5Zzz2GA=; b=Bq9Bki62Zt/6/lbHQjEhtKZeh6wzV39naSacyDhhLexY4OK17DxxgAD/PlaZgNZC1E dMpwKzldTQ8XlyZtOM/ovnTyV4w11UHqQrda2WC61C9O1dwU4L8EZ2/zCskhXqYjrieU lw97Fg3CGUA81O11UYYGi8ROc084cQ5KVGpeaXJHqHFfCKNL2guVi4Gb/UM5VX/e2qpk ZsFHd5WEGmF6vXyQOBT7ltbklsxxK088+FzKnNNEbk6lM4IMLLZ622X9DjzHjJ36MhZZ A/bmFcHGSCGUuET7uCp4mNn8GIrlSxM2M0P/2PWrvXnBeaW8QmKN3toXzq8/KwyfLBLO 0QuQ== X-Gm-Message-State: AFuF++nO47ol6fMXD8vdJmQleV47CI/9d49eeaX+L7WPHvslkwOQNeKj dXImg8VQaJSAJLu+RLHLVOrIzTqgskT3iOrRA0n1TwOP6rj5086kGIVsqTiTyUjNm61OODluH+i VxdT2mEo= X-Gm-Gg: AYBFou1pOmm5pj3HXorpZ1fG6TWYOvyJCVjVPq8MwFe+xdO2qfb7xd4goox0FDcjiWD BVcmASSUKUUdZQkwa6dLKOqCPrSz/tKzxGze2f1C/nbjgYZOOcrDC+6FQOWz73xupEFX/DOvhIq mqfuTjKvO6ZHaHpEenHl9+G40GDXHw0Uh+E4WIkAxyuM1UE0sBqTi3R3Pbj4yW8jja9Tb5vhoMU QlcAnOv5Kh3eKtfWVmG8rd1VleBPpnYTgiJc5cYrW4FmY4cFs1EGBbqcyp5EQa1eqOnGLBdFOOn IxzLj9io2vKKSnrL4KTzf8reQzgnOjVWPibzY8sRWutlrftWl/ILBABy3G/lL8tKBpMYaxFNvJ+ XKTd++XRVo6MmcR2gnq/AXj6ZJZcd0lh/kWBJmNHbMBC7Du4wdVli/cWZ/i6ItkHReHI4RnmXCq UvGsTIFGZ0N/0IxOAihROy2m/DXfoNQJ2lFeiFlARz3oc3ub2bPuWejZuX2EFRfvaWkBs4DfSlG tENFEUf/9Y97dRg+bZDOwu2zu8+gqDvXXXDU/tF3uBi64j/1VHG2pF4gdd6W7FgjA== X-Received: by 2002:a05:6000:98a:b0:484:3311:af37 with SMTP id ffacd0b85a97d-48587298f26mr17138004f8f.26.1788641128767; Sat, 05 Sep 2026 13:45:28 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa0048511f7ccf23d3ce.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:4851:1f7c:cf23:d3ce]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-485885bfdf6sm17069098f8f.34.2026.09.05.13.45.28 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sat, 05 Sep 2026 13:45:28 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][wrynose 32/40] python3-click: upgrade 8.3.1 -> 8.3.3 Date: Sat, 5 Sep 2026 22:44:33 +0200 Message-ID: <1ec888a66235821af9cc0b087953af7d58bdc78f.1788629392.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Sat, 05 Sep 2026 20:45:36 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/245184 From: Richard Purdie Upgrade Click to 8.3.3, the first upstream release containing the fix for CVE-2026-7246. The fix avoids constructing an editor shell command and passes the editor and filename as separate argv elements. Signed-off-by: Richard Purdie (cherry picked from commit 002ede0d89b43cfbe15651ea6c3d504626be24df) Signed-off-by: Darsh Kelaiya Signed-off-by: Yoann Congal [YC: Changelog: https://click.palletsprojects.com/en/stable/changes/#version-8-3-3 ] --- .../python/{python3-click_8.3.1.bb => python3-click_8.3.3.bb} | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) rename meta/recipes-devtools/python/{python3-click_8.3.1.bb => python3-click_8.3.3.bb} (91%) diff --git a/meta/recipes-devtools/python/python3-click_8.3.1.bb b/meta/recipes-devtools/python/python3-click_8.3.3.bb similarity index 91% rename from meta/recipes-devtools/python/python3-click_8.3.1.bb rename to meta/recipes-devtools/python/python3-click_8.3.3.bb index 49204e96e1f..9e80f8aff0f 100644 --- a/meta/recipes-devtools/python/python3-click_8.3.1.bb +++ b/meta/recipes-devtools/python/python3-click_8.3.3.bb @@ -8,7 +8,7 @@ HOMEPAGE = "http://click.pocoo.org/" LICENSE = "BSD-3-Clause" LIC_FILES_CHKSUM = "file://LICENSE.txt;md5=1fa98232fd645608937a0fdc82e999b8" -SRC_URI[sha256sum] = "12ff4785d337a1bb490bb7e9c2b1ee5da3112e94a8622f26a6c77f5d2fc6842a" +SRC_URI[sha256sum] = "398329ad4837b2ff7cbe1dd166a4c0f8900c3ca3a218de04466f38f6497f18a2" inherit pypi python_flit_core ptest-python-pytest From patchwork Sat Sep 5 20:44:34 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 8bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 97389 X-Patchwork-Delegate: yoann.congal@smile.fr Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id CE2ABC79FA8 for ; Sat, 5 Sep 2026 20:45:37 +0000 (UTC) Received: from mail-wr1-f45.google.com (mail-wr1-f45.google.com [209.85.221.45]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.2598.1788641131209828790 for ; Sat, 05 Sep 2026 13:45:31 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=n5/95yRT; spf=pass (domain: smile.fr, ip: 209.85.221.45, mailfrom: yoann.congal@smile.fr) Received: by mail-wr1-f45.google.com with SMTP id ffacd0b85a97d-4858c1c4b4eso1169224f8f.2 for ; Sat, 05 Sep 2026 13:45:30 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1788641129; x=1789245929; darn=lists.openembedded.org; h=content-transfer-encoding:content-type:mime-version:references :in-reply-to:message-id:date:subject:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=GwECAu0RkEXnL/dgGAGcF9OflepRBoBMHwCmrY2sa4E=; b=n5/95yRTJAnU5ugaiWTg3i+CAftV3lKHsqmErDuZOjYMjeuP4gXr9k8hkYFet/f3h6 M7MP+Np6r/7bZQHDjxAboBuAVIrUxW45KOGSlZZbR8OtxAGyYgf6S9g5iVF+oaFRrgOO z3TTPYn/pbKI3TxrZMTA7C9kZO4E0gYpdFdF8= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1788641129; x=1789245929; h=content-transfer-encoding:content-type:mime-version:references :in-reply-to:message-id:date:subject:to:from:x-gm-gg :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to :content-type; bh=GwECAu0RkEXnL/dgGAGcF9OflepRBoBMHwCmrY2sa4E=; b=G3p1iYrKkUlwt7m4nFnKncaaEV2NpDiX/LUFxogTSoN3ZUnKpqcrmfbVVyYP8kdREc 5SCpN1zUWSwZsvaJ17hK5OUrawjK3Mp+R+Kgxx7YjimWYWL9OOU9qyWjESTfABwuKYxx IwAiwcOCHRn/a51V9E7g/AUKynVdjHxzEXEWdFdDM1CbO9dr/96EPPtV80cL4ZlqCdFC GMkpyKQP15/iM7ItEqGgtDm8Fj7V1uWLD3KG8tB7TM5Zy0O4/6PUPqmURmczWaA2NyqT 3SZo9L8GivSX/6+oM6UmJpmKBKgBoFZFDaH5EDEW3U/pRbkJplbwvcfW8yCHjVFVAML9 Bogw== X-Gm-Message-State: AFuF++mVqejQ8vpV4+8DGnXSV9qMe3i2YB3O/KNlYmX+m5sxyK4MWRDO QyU47OgPoDFISOpsW/CROqj9iOX4bMLaC6gb46NlS0lMwED0eHWxoYVUtkKvnPNw8T7mf7+Nwns yuLD/3BA= X-Gm-Gg: AYBFou0accwlpkHGX87zNRaHt8OnZ4dnC9VqYmMtN0ToS57y00AIStnbyTNP9qDdOoi bBgUjGaTTPp/a+5f6KPG6xvIBK6OBC6oWcgMgGe3Z2Rm77+xnKOk4t7k6Rbj33O5jOx93rRjCnT PI1rm4ksLLwL0hiAelMP/Z1QzmMdE6Xwg7BwPYYMTaAO4ZwI4N02rbSh2DMkw0xSL0fC4FT2V3Z Tw7okFBfm5xi/Dze64RyGurIr2dc9cc5r8ZCGGPzjXHYn1FHAYhrsHZyNxlCL4WKtAo558zn0YQ vPa0k8Yp4E6btSZACl7aSw2hgYjna2Xi8mmChBfnXuCkVYVSxYuVkcMELFR28us70kIlecYoY/u LCB+R3DdYJCcNdNe84gGeCH8Uxi72338OdEp10n8V/dUNaf55XYN9z86MHrN6GRQDW4OjTRj6bD C+D7KwY/xGjo60Tj8Vifyw5TVUe5U9huUQASJQ8n9B226yu1PEW5LX/hebWLVefB51fbqmlAGtA Bhm+aP8szVO/OqkTApyNJL5lJzyKn8pQYvpVMscolXWRFIUgeck8iwAZZb8ZmNKyKM= X-Received: by 2002:adf:e198:0:b0:485:8a46:b3b8 with SMTP id ffacd0b85a97d-4858a46b5e5mr14218687f8f.32.1788641129319; Sat, 05 Sep 2026 13:45:29 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa0048511f7ccf23d3ce.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:4851:1f7c:cf23:d3ce]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-485885bfdf6sm17069098f8f.34.2026.09.05.13.45.28 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sat, 05 Sep 2026 13:45:28 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][wrynose 33/40] python3-idna: Fix CVE-2026-45409 Date: Sat, 5 Sep 2026 22:44:34 +0200 Message-ID: <2438f1d257581e9841475cd108c7a6957cd201e8.1788629392.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Sat, 05 Sep 2026 20:45:37 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/245185 From: Hetvi Thakar This patch applies the upstream 3.15 backport for CVE-2026-45409. The upstream fix commit series is referenced in [1], and the public CVE advisory is referenced in [2]. The individual backported commit links are recorded in the embedded patch headers. Backport Changes: - Omitted the first commit's HISTORY.rst release entry because it conflicts with the 3.11 history and is not required for the fix. [1] https://github.com/kjd/idna/compare/v3.13...v3.15 [2] https://github.com/advisories/GHSA-65pc-fj4g-8rjx Signed-off-by: Hetvi Thakar Signed-off-by: Yoann Congal --- .../python3-idna/CVE-2026-45409_p1.patch | 75 +++++++++++++++++++ .../python3-idna/CVE-2026-45409_p2.patch | 48 ++++++++++++ .../python3-idna/CVE-2026-45409_p3.patch | 72 ++++++++++++++++++ .../python/python3-idna_3.11.bb | 4 + 4 files changed, 199 insertions(+) create mode 100644 meta/recipes-devtools/python/python3-idna/CVE-2026-45409_p1.patch create mode 100644 meta/recipes-devtools/python/python3-idna/CVE-2026-45409_p2.patch create mode 100644 meta/recipes-devtools/python/python3-idna/CVE-2026-45409_p3.patch diff --git a/meta/recipes-devtools/python/python3-idna/CVE-2026-45409_p1.patch b/meta/recipes-devtools/python/python3-idna/CVE-2026-45409_p1.patch new file mode 100644 index 00000000000..8c103635cf1 --- /dev/null +++ b/meta/recipes-devtools/python/python3-idna/CVE-2026-45409_p1.patch @@ -0,0 +1,75 @@ +From 6c647e3d5d9daca452ae74fc10d50f20e998e444 Mon Sep 17 00:00:00 2001 +From: Kim Davies +Date: Sun, 10 May 2026 08:47:22 -0700 +Subject: [PATCH] Merge commit from fork + +CVE: CVE-2026-45409 +Upstream-Status: Backport [https://github.com/kjd/idna/commit/c0dda4501df5d91c3181ce6f962dc5de74e82cc1] + +Backport Changes: +- Omitted HISTORY.rst because its 3.14 release entry conflicts with the 3.11 + history and is not required for the security fix. + +(cherry picked from commit c0dda4501df5d91c3181ce6f962dc5de74e82cc1) +Signed-off-by: Hetvi Thakar +--- + idna/core.py | 14 ++++++++++++++ + tests/test_idna.py | 13 +++++++++++++ + 2 files changed, 27 insertions(+) + +diff --git a/idna/core.py b/idna/core.py +index 8177bf7..ce995c9 100644 +--- a/idna/core.py ++++ b/idna/core.py +@@ -377,6 +377,15 @@ def encode( + raise IDNAError("should pass a unicode string to the function rather than a byte string.") + if uts46: + s = uts46_remap(s, std3_rules, transitional) ++ ++ # Reject inputs that exceed the maximum DNS domain length up-front. ++ # Each codepoint in a U-label contributes at least one octet to its ++ # A-label form, so any input longer than the domain limit cannot ++ # produce a valid A-domain. Short-circuiting here prevents per-label ++ # validation from being driven into quadratic time ++ if len(s) > 254: ++ raise IDNAError("Domain too long") ++ + trailing_dot = False + result = [] + if strict: +@@ -415,6 +424,11 @@ def decode( + raise IDNAError("Invalid ASCII in A-label") + if uts46: + s = uts46_remap(s, std3_rules, False) ++ # See encode() for rationale; the same bound applies because every ++ # legal A-domain is at most 254 octets and every codepoint of a ++ # legal U-domain contributes at least one octet to its A-form. ++ if len(s) > 254: ++ raise IDNAError("Domain too long") + trailing_dot = False + result = [] + if not strict: +diff --git a/tests/test_idna.py b/tests/test_idna.py +index b59f5e5..ff24ebf 100755 +--- a/tests/test_idna.py ++++ b/tests/test_idna.py +@@ -80,6 +80,19 @@ class IDNATests(unittest.TestCase): + self.assertFalse(idna.valid_label_length("a" * 64)) + self.assertRaises(idna.IDNAError, idna.encode, "a" * 64) + ++ def test_oversized_input_rejected_promptly(self): ++ # GHSA-65pc-fj4g-8rjx: encode/decode must reject inputs that ++ # exceed the maximum DNS domain length before per-codepoint ++ # validation runs, so labels dominated by CONTEXTO codepoints ++ # cannot drive validation into quadratic time. ++ import time ++ ++ for payload in ("٠" * 8000, "・" * 8000 + "漢"): ++ start = time.perf_counter() ++ self.assertRaises(idna.IDNAError, idna.encode, payload) ++ self.assertRaises(idna.IDNAError, idna.decode, payload) ++ self.assertLess(time.perf_counter() - start, 1.0) ++ + def test_check_bidi(self): + la = "\u0061" + r = "\u05d0" diff --git a/meta/recipes-devtools/python/python3-idna/CVE-2026-45409_p2.patch b/meta/recipes-devtools/python/python3-idna/CVE-2026-45409_p2.patch new file mode 100644 index 00000000000..07b5b148f58 --- /dev/null +++ b/meta/recipes-devtools/python/python3-idna/CVE-2026-45409_p2.patch @@ -0,0 +1,48 @@ +From 44713e1252442331fd49dfca00cd42bc27859198 Mon Sep 17 00:00:00 2001 +From: Kim Davies +Date: Sun, 10 May 2026 12:44:47 -0700 +Subject: [PATCH] Use valid_string_length() for early oversized-input check + +CVE: CVE-2026-45409 +Upstream-Status: Backport [https://github.com/kjd/idna/commit/628fef84d3eda59321c21127e73dcd873db23ead] + +(cherry picked from commit 628fef84d3eda59321c21127e73dcd873db23ead) +Signed-off-by: Hetvi Thakar +--- + idna/core.py | 16 ++++++---------- + 1 file changed, 6 insertions(+), 10 deletions(-) + +diff --git a/idna/core.py b/idna/core.py +index ce995c9..db19bda 100644 +--- a/idna/core.py ++++ b/idna/core.py +@@ -378,12 +378,9 @@ def encode( + if uts46: + s = uts46_remap(s, std3_rules, transitional) + +- # Reject inputs that exceed the maximum DNS domain length up-front. +- # Each codepoint in a U-label contributes at least one octet to its +- # A-label form, so any input longer than the domain limit cannot +- # produce a valid A-domain. Short-circuiting here prevents per-label +- # validation from being driven into quadratic time +- if len(s) > 254: ++ # Reject inputs that exceed the maximum DNS domain length up-front ++ # to avoid expensive computation on long inputs. ++ if not valid_string_length(s, trailing_dot=True): + raise IDNAError("Domain too long") + + trailing_dot = False +@@ -424,10 +421,9 @@ def decode( + raise IDNAError("Invalid ASCII in A-label") + if uts46: + s = uts46_remap(s, std3_rules, False) +- # See encode() for rationale; the same bound applies because every +- # legal A-domain is at most 254 octets and every codepoint of a +- # legal U-domain contributes at least one octet to its A-form. +- if len(s) > 254: ++ # Reject inputs that exceed the maximum DNS domain length up-front ++ # to avoid expensive computation on long inputs. ++ if not valid_string_length(s, trailing_dot=True): + raise IDNAError("Domain too long") + trailing_dot = False + result = [] diff --git a/meta/recipes-devtools/python/python3-idna/CVE-2026-45409_p3.patch b/meta/recipes-devtools/python/python3-idna/CVE-2026-45409_p3.patch new file mode 100644 index 00000000000..f7302a94170 --- /dev/null +++ b/meta/recipes-devtools/python/python3-idna/CVE-2026-45409_p3.patch @@ -0,0 +1,72 @@ +From bd119cd4055324ece8a9bb1ef5413e3ad581b0ed Mon Sep 17 00:00:00 2001 +From: metsw24-max +Date: Mon, 11 May 2026 20:59:30 +0530 +Subject: [PATCH] Enforce early length limits in check_label + +CVE: CVE-2026-45409 +Upstream-Status: Backport [https://github.com/kjd/idna/commit/e1cb465b6376f33306a26f467d197edbcd01c4b9] + +(cherry picked from commit e1cb465b6376f33306a26f467d197edbcd01c4b9) +Signed-off-by: Hetvi Thakar +--- + idna/core.py | 11 +++++++++++ + tests/test_idna.py | 24 ++++++++++++++++++++++++ + 2 files changed, 35 insertions(+) + +diff --git a/idna/core.py b/idna/core.py +index db19bda..254f090 100644 +--- a/idna/core.py ++++ b/idna/core.py +@@ -247,6 +247,17 @@ def check_label(label: Union[str, bytes, bytearray]) -> None: + label = label.decode("utf-8") + if len(label) == 0: + raise IDNAError("Empty Label") ++ # Reject oversized labels before per-codepoint validation runs. ++ # CONTEXTJ/CONTEXTO checks scan the whole label per codepoint, so an ++ # uncapped label drives validation into quadratic time ++ # (GHSA-65pc-fj4g-8rjx / CVE-2024-3651). encode()/decode() cap the ++ # whole-domain length; this cap protects direct callers of ++ # alabel/ulabel/check_label and the idna2008 incremental codec. ++ # Use the whole-domain bound rather than the per-label DNS bound so ++ # that UTS #46 lenient decoding of labels longer than 63 chars is ++ # preserved. ++ if not valid_string_length(label, trailing_dot=True): ++ raise IDNAError("Label too long") + + check_nfc(label) + check_hyphen_ok(label) +diff --git a/tests/test_idna.py b/tests/test_idna.py +index ff24ebf..9832c39 100755 +--- a/tests/test_idna.py ++++ b/tests/test_idna.py +@@ -93,6 +93,30 @@ class IDNATests(unittest.TestCase): + self.assertRaises(idna.IDNAError, idna.decode, payload) + self.assertLess(time.perf_counter() - start, 1.0) + ++ def test_oversized_label_rejected_promptly(self): ++ # The whole-domain cap in encode()/decode() does not cover direct ++ # callers of alabel/ulabel/check_label, nor the idna2008 ++ # incremental codec which calls alabel/ulabel per label. Without a ++ # per-label cap, a single oversized CONTEXTO-heavy label still ++ # drives validation into quadratic time. ++ import codecs ++ import time ++ ++ import idna.codec # noqa: F401 (register the idna2008 codec) ++ ++ payload = "・" * 8000 + "漢" ++ start = time.perf_counter() ++ self.assertRaises(idna.IDNAError, idna.check_label, payload) ++ self.assertRaises(idna.IDNAError, idna.alabel, payload) ++ self.assertRaises(idna.IDNAError, idna.ulabel, payload) ++ self.assertRaises( ++ idna.IDNAError, ++ codecs.getincrementalencoder("idna2008")().encode, ++ payload, ++ True, ++ ) ++ self.assertLess(time.perf_counter() - start, 1.0) ++ + def test_check_bidi(self): + la = "\u0061" + r = "\u05d0" diff --git a/meta/recipes-devtools/python/python3-idna_3.11.bb b/meta/recipes-devtools/python/python3-idna_3.11.bb index eb875729345..1a852561a46 100644 --- a/meta/recipes-devtools/python/python3-idna_3.11.bb +++ b/meta/recipes-devtools/python/python3-idna_3.11.bb @@ -3,6 +3,10 @@ HOMEPAGE = "https://github.com/kjd/idna" LICENSE = "BSD-3-Clause & Python-2.0 & Unicode-TOU" LIC_FILES_CHKSUM = "file://LICENSE.md;md5=18a4795c19833413a7e2f1cb3cd3b143" +SRC_URI += "file://CVE-2026-45409_p1.patch \ + file://CVE-2026-45409_p2.patch \ + file://CVE-2026-45409_p3.patch \ + " SRC_URI[sha256sum] = "795dafcc9c04ed0c1fb032c2aa73654d8e8c5023a7df64a53f39190ada629902" inherit pypi python_flit_core ptest-python-pytest From patchwork Sat Sep 5 20:44:35 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 97380 X-Patchwork-Delegate: yoann.congal@smile.fr Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id B4C18C79FA0 for ; Sat, 5 Sep 2026 20:45:36 +0000 (UTC) Received: from mail-wm1-f52.google.com (mail-wm1-f52.google.com [209.85.128.52]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.2599.1788641131746810588 for ; Sat, 05 Sep 2026 13:45:32 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=wzon7MKw; spf=pass (domain: smile.fr, ip: 209.85.128.52, mailfrom: yoann.congal@smile.fr) Received: by mail-wm1-f52.google.com with SMTP id 5b1f17b1804b1-4995b0343c1so30172505e9.3 for ; Sat, 05 Sep 2026 13:45:31 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1788641130; x=1789245930; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=5IPfQtq77qUGLHy4MUOX6IxPRTtEGeGxHY5VvWIAS4Q=; b=wzon7MKwQp2lCkgcRcQIgkGx+PJjr1COM01DkZyFqzQAIMAyOg/ZABfIC0wgKrbg4z wEuk7vGEZuzhAioU2JGjjvHjsGwMyMGNYq9g2KQGf+EpamgPwLFFbeymTIBrXbfIkBXl 88bDsivIqN24lEB1hLM/FPTEw6TMU1jaB6ecs= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1788641130; x=1789245930; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=5IPfQtq77qUGLHy4MUOX6IxPRTtEGeGxHY5VvWIAS4Q=; b=M2fftvG8EFKVM04JM7476k6vV2z/2Ga4ZqvxOXXDy5hnVw3cQXKNp+W2p/2bVrJpDG YJhrsOSGDeeDs9lOAl8+BpMeuhRtNuJx1yO98JGLGxhfZPELsTKzmcptqMPlWhdbzjs2 6SMOXzne5lU/JOQMYXhyybpII1sTO7JlmM1+efdSjSIO6OEvEjY97v/SftvxY/oYnKl+ phZuW17DtG2z1oMIBxcEkjAr7F7JhvzOFLkPwzOUyPSLsrOkzZWkGmHKa4j7jkvzsIn5 29jz/LM1QEGV7efx1KDNEPzppsT7Iy9OtUI3r/Ru2sFmAxdpVlQFii2+yvTgXLUARhv/ d8vA== X-Gm-Message-State: AFuF++m/v/mByIQNpDdTSZTjqaoV8rIzb8oQXN+yDnFkp1ZA/higMHIl e9tDn0emRYG0fezc2Z0H2bO4mRnMfjRF4NpzeRGHZBm0IdJ3xu15TWTpB/58ru5gvJVjFXn/z9/ V6PS5Gg0= X-Gm-Gg: AYBFou3ppZjxS1UdkmwK9CJwaKgIL5ptHMDZ7JLW+ysJPvV2d7SvTjBDDJY0pQ/zzGK THtEmCmXy6dGS89o7Hj803823UxVxHKkfKSmf6iZdxhMy1axcjfEsLrA90Ho2XDClIQ6FzWnUEq Nr5c9t0Gdxehwwp2zZKgMAInZrn7T66k290krHhi2FwAzhWeDaDVpnQnVyqSzUoW5lFtcV5itme b7xXSlQRrBqNgoDax8eRXA77jPIeaeDLp4YcRyfG4+7yoYEQ1SSBimgIfNr6U9fjydYxi62UX5c RcUEp5YsoS66/855j2cBifwqNwxByF+telw/jl9Q7vQTPB5VsIZYsvoCS8R2tVseVn2yPwBQckc SuEVZBfP1d9f18gejsdAVph6LSTFkOLRy7JejTEQ19ZBNPJ4CugiSlryiGJNqN/cN/gy0pHe5yu H80ybmwTXF4xteliqs1d+wiEMhlxz1sm1/PKVSnOdZvwXXSorcqv0XBeZwaa8PyPC6CDGtBlJnP GpLC9j5Bkp3Tb3gi5pHsF79y3w76XIGjeyuzFIeqjFVJx0VneZYW86S/SA/Dur80Q== X-Received: by 2002:a05:600c:1551:b0:49c:fa21:1c89 with SMTP id 5b1f17b1804b1-49cfa211d5fmr124123515e9.30.1788641129895; Sat, 05 Sep 2026 13:45:29 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa0048511f7ccf23d3ce.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:4851:1f7c:cf23:d3ce]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-485885bfdf6sm17069098f8f.34.2026.09.05.13.45.29 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sat, 05 Sep 2026 13:45:29 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][wrynose 34/40] perl: fix CVE-2026-42496 and CVE-2026-42497 Date: Sat, 5 Sep 2026 22:44:35 +0200 Message-ID: <7bda2b9dc01abaa39c56301acd230affe51b6537.1788629392.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Sat, 05 Sep 2026 20:45:36 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/245186 From: Abhishek Bachiphale Archive::Tar before 3.08 passes the tar header's linkname directly to symlink()/link() in _make_special_file() without validating absolute paths or '..' segments. This allows a crafted tar archive to create symlinks or hardlinks targeting paths outside the extraction directory, leading to arbitrary file read/write. Backport patch to fix CVE-2026-42496 and CVE-2026-42497. Reference: [https://nvd.nist.gov/vuln/detail/CVE-2026-42496] [https://nvd.nist.gov/vuln/detail/CVE-2026-42497] Upstream Patch: [https://github.com/jib/archive-tar-new/commit/17c873492a05eddc0de18c1485e0b2cccd5a9158] Signed-off-by: Abhishek Bachiphale Signed-off-by: Yoann Congal [YC: in perl, the fix was integrated with https://github.com/Perl/perl5/commit/560820ab273deb6b27408c8e5c2f34d72b1c3bbb (v5.43.11) ] --- .../perl/files/CVE-2026-42496.patch | 99 +++++++++++++++++++ meta/recipes-devtools/perl/perl_5.42.0.bb | 1 + 2 files changed, 100 insertions(+) create mode 100644 meta/recipes-devtools/perl/files/CVE-2026-42496.patch diff --git a/meta/recipes-devtools/perl/files/CVE-2026-42496.patch b/meta/recipes-devtools/perl/files/CVE-2026-42496.patch new file mode 100644 index 00000000000..ae370340cf5 --- /dev/null +++ b/meta/recipes-devtools/perl/files/CVE-2026-42496.patch @@ -0,0 +1,99 @@ +From edde2083c6e93e42b979068af5529710b5e2a7ab Mon Sep 17 00:00:00 2001 +From: Stig Palmquist +Date: Thu, 21 May 2026 19:59:21 +0100 +Subject: [PATCH] Validate symlink and hardlink linkname in SECURE MODE + +Archive::Tar before 3.08 passes the tar header's linkname directly to +symlink()/link() in _make_special_file() without validating absolute +paths or '..' segments. This allows a crafted tar archive to create +symlinks or hardlinks targeting paths outside the extraction directory, +leading to arbitrary file read/write. + +Add validation in SECURE EXTRACT MODE (the default) to reject: +- Symlink/hardlink targets with absolute paths +- Symlink/hardlink targets containing '..' path traversal + +Adjusted patch paths from upstream Archive::Tar standalone repository +(lib/Archive/Tar.pm) to match perl5 source tree layout +(cpan/Archive-Tar/lib/Archive/Tar.pm). + +Upstream-Status: Backport [https://github.com/jib/archive-tar-new/commit/17c873492a05eddc0de18c1485e0b2cccd5a9158] + +CVE: CVE-2026-42496 +CVE: CVE-2026-42497 + +Signed-off-by: Chris 'BinGOs' Williams +Signed-off-by: Abhishek Bachiphale +--- + cpan/Archive-Tar/lib/Archive/Tar.pm | 30 +++++++++++++++++++++++++ + cpan/Archive-Tar/t/04_resolved_issues.t | 2 ++ + 2 files changed, 32 insertions(+) + +diff --git a/cpan/Archive-Tar/lib/Archive/Tar.pm b/cpan/Archive-Tar/lib/Archive/Tar.pm +index 2df0931..733feef 100644 +--- a/cpan/Archive-Tar/lib/Archive/Tar.pm ++++ b/cpan/Archive-Tar/lib/Archive/Tar.pm +@@ -954,6 +954,19 @@ sub _make_special_file { + my $err; + + if( $entry->is_symlink ) { ++ if( !$INSECURE_EXTRACT_MODE ) { ++ my $linkname = $entry->linkname; ++ if( File::Spec->file_name_is_absolute($linkname) ) { ++ $self->_error( qq[Symlink '] . $entry->full_path . ++ qq[' has absolute target. Not extracting under SECURE EXTRACT MODE] ); ++ return; ++ } ++ if( grep { $_ eq '..' } File::Spec->splitdir($linkname) ) { ++ $self->_error( qq[Symlink '] . $entry->full_path . ++ qq[' target attempts traversal. Not extracting under SECURE EXTRACT MODE] ); ++ return; ++ } ++ } + my $fail; + if( ON_UNIX ) { + symlink( $entry->linkname, $file ) or $fail++; +@@ -967,6 +980,23 @@ sub _make_special_file { + $entry->linkname .q[' failed] if $fail; + + } elsif ( $entry->is_hardlink ) { ++ if( !$INSECURE_EXTRACT_MODE ) { ++ my $linkname = $entry->linkname; ++ if( File::Spec->file_name_is_absolute($linkname) ) { ++ $self->_error( qq[Hardlink '] . $entry->full_path . ++ qq[' has absolute target '$linkname'. Not extracting ] . ++ qq[under SECURE EXTRACT MODE: extraction itself chmods ] . ++ qq[the shared inode.] ); ++ return; ++ } ++ if( grep { $_ eq '..' } File::Spec->splitdir($linkname) ) { ++ $self->_error( qq[Hardlink '] . $entry->full_path . ++ qq[' target '$linkname' attempts traversal. Not ] . ++ qq[extracting under SECURE EXTRACT MODE: extraction ] . ++ qq[itself chmods the shared inode.] ); ++ return; ++ } ++ } + my $fail; + if( ON_UNIX ) { + link( $entry->linkname, $file ) or $fail++; +diff --git a/cpan/Archive-Tar/t/04_resolved_issues.t b/cpan/Archive-Tar/t/04_resolved_issues.t +index b3566a1..08d339a 100644 +--- a/cpan/Archive-Tar/t/04_resolved_issues.t ++++ b/cpan/Archive-Tar/t/04_resolved_issues.t +@@ -220,6 +220,7 @@ if ($^O ne 'msys') # symlink tests fail on Windows/msys2 + } + + { #use case 1 - in memory extraction ++ local $Archive::Tar::INSECURE_EXTRACT_MODE=1; + my $t=Archive::Tar->new; + $t->read( $archname ); + my $r = eval{ $t->extract }; +@@ -231,6 +232,7 @@ if ($^O ne 'msys') # symlink tests fail on Windows/msys2 + + { #use case 2 - iter extraction + #$DB::single = 2; ++ local $Archive::Tar::INSECURE_EXTRACT_MODE=1; + my $next=Archive::Tar->iter( $archname, 1 ); + my $failed = 0; + #use Data::Dumper; diff --git a/meta/recipes-devtools/perl/perl_5.42.0.bb b/meta/recipes-devtools/perl/perl_5.42.0.bb index 8716f1f2572..3469258f727 100644 --- a/meta/recipes-devtools/perl/perl_5.42.0.bb +++ b/meta/recipes-devtools/perl/perl_5.42.0.bb @@ -21,6 +21,7 @@ SRC_URI = "https://www.cpan.org/src/5.0/perl-${PV}.tar.gz;name=perl \ file://CVE-2026-13221.patch \ file://CVE-2026-57432-01.patch \ file://CVE-2026-57432-02.patch \ + file://CVE-2026-42496.patch \ " SRC_URI:append:class-native = " \ file://perl-configpm-switch.patch \ From patchwork Sat Sep 5 20:44:36 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 97387 X-Patchwork-Delegate: yoann.congal@smile.fr Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id A7AF2C79FA9 for ; Sat, 5 Sep 2026 20:45:37 +0000 (UTC) Received: from mail-wr1-f48.google.com (mail-wr1-f48.google.com [209.85.221.48]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.2600.1788641132281020534 for ; Sat, 05 Sep 2026 13:45:32 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=q65lSRsv; spf=pass (domain: smile.fr, ip: 209.85.221.48, mailfrom: yoann.congal@smile.fr) Received: by mail-wr1-f48.google.com with SMTP id ffacd0b85a97d-48441a2ba14so1927243f8f.1 for ; Sat, 05 Sep 2026 13:45:32 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1788641130; x=1789245930; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=TH+pDBfmQmOHZapKeEsv9RuadGN3fgUqaecmPz+wPIY=; b=q65lSRsv/XDwTZv52vfUODGFUx2GnrR+nuYdfqQhZ3zseAQh7QheElKDgF8vvHE7ko gkppIkm/cmyLMHfEF4bwqHqn64T1UvI5CxW7USfmfOdVY6Tae374xdCHNQeRUHtf1UKV 9KAMdiajkXB+S4XXcZnCoaXx3Q1JnN6Ssu9fs= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1788641130; x=1789245930; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=TH+pDBfmQmOHZapKeEsv9RuadGN3fgUqaecmPz+wPIY=; b=cnJCsTJK0V5ZfK1Nd5XxNu6aysZTdWObrK5NhlC5JxvMXMVjw1k7BHmuD3ldw+fILE OV5NRafq4To+BPQILgSc/95yXL0bTERsmH2pfKHwdQDm0NbZPYViK7XwWqhjGIAMpsAh fNhqi9l7wDsywQu+Px0DBoQOaC5RSWgorjHAsD/CF2d2Entn9WcnbX0cHtz8ox2tsDJG SIEFO0Wq3RatfgdrXjh5BCt6abQ62HNnZml9FDB/ERwUzVjP/AvsiCd4FFysbk6UXmCH nEMW3enNQV4VCl5UDOpMcMYHCoMhlSU00U7wjtfZteJ6M/7hmN1GpDIXj589N69nIgG6 Jb5w== X-Gm-Message-State: AFuF++kYANXW7dsj+abZxn/9DrMPPmp5H+DgKmcKSC1ScQTJh5xdDxnu hPqTCmBlJT811tsQr9bQfiDAoUPPFtueBkSq3AAebbwGuFSfsYA0PxtZdB2Sa78mYAXkYlHsRBt LTdlvXFQ= X-Gm-Gg: AYBFou2JMvYfil4w2bk6LWjXSMEZdNRzu4Y99E8aujBvEOeJ7b/z6jpw9tt/HU0uVw1 AX1FIlKse3+QvE9Wb2I7N/MTUrad7mT6G3j6y55UY65WmFT+vMhx6fwF/cW7+4Mkzcr3xX0/BEY 4cEJTQ0ZlKyyTBBpEfe09s5JEQ9nMRYZwfSIc5q9oE+wguAh2MLNYLKXJ0ET2+oXXhb5Vq8Qx+3 g1nkBL7K/9znL1xhZDMmBsP22KXv/p6UTDaAxABuQOLzixg8pjNDtY8Lztb2wQmFmKROBjwzu33 n1Mv1kMFMwq8jJExLeO8h45cOcjK1BtnflhsD5WW++iqvhVs8Smby1MyXY5/SCeyLZi4w2tiB+n 1RIUSXhEtMkkZXyBiDBIUxj8c7hY22oadKc9AWKZ2e5iXDEHBpCgL0sFRHG2SadLtZ8tHX/AFnB YiGvm55AnSFVy/RHiPbWhsmhtkNV+/6gPo8jmuf39ANXsrPZz41X152sE10lXbdngaeYnAX/64B HSYLREyK0abRRQ3CmLuj0wNLgc3CWS+hftaKd7MVrXOabk9qLo4m/0D4yva+CmCog== X-Received: by 2002:a05:6000:470c:b0:485:8a46:705c with SMTP id ffacd0b85a97d-4858a4671b8mr12233156f8f.46.1788641130532; Sat, 05 Sep 2026 13:45:30 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa0048511f7ccf23d3ce.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:4851:1f7c:cf23:d3ce]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-485885bfdf6sm17069098f8f.34.2026.09.05.13.45.29 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sat, 05 Sep 2026 13:45:30 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][wrynose 35/40] libssh2: Fix CVE-2026-58051 Date: Sat, 5 Sep 2026 22:44:36 +0200 Message-ID: <6e2a6bb91130873b08ff845a28620a8efaa436cb.1788629392.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Sat, 05 Sep 2026 20:45:37 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/245187 From: Hetvi Thakar Backport the upstream fix for CVE-2026-58051 using the commit in [1]. The CVE advisory [2] describes an uninitialized publickey-list entry cleanup issue affecting libssh2 through 1.11.1. [1] https://github.com/libssh2/libssh2/commit/a9758da45a52bc8c630ec9493804d0c6ea30b24a [2] https://nvd.nist.gov/vuln/detail/CVE-2026-58051 Signed-off-by: Hetvi Thakar Signed-off-by: Yoann Congal --- .../libssh2/libssh2/CVE-2026-58051.patch | 34 +++++++++++++++++++ .../recipes-support/libssh2/libssh2_1.11.1.bb | 1 + 2 files changed, 35 insertions(+) create mode 100644 meta/recipes-support/libssh2/libssh2/CVE-2026-58051.patch diff --git a/meta/recipes-support/libssh2/libssh2/CVE-2026-58051.patch b/meta/recipes-support/libssh2/libssh2/CVE-2026-58051.patch new file mode 100644 index 00000000000..68f71efe68e --- /dev/null +++ b/meta/recipes-support/libssh2/libssh2/CVE-2026-58051.patch @@ -0,0 +1,34 @@ +From 8cb6cf1244e8d62175bf5df32a400f00ddadb40d Mon Sep 17 00:00:00 2001 +From: Viktor Szakats +Date: Mon, 29 Jun 2026 19:12:21 +0200 +Subject: [PATCH] publickey: fix potential arbitrary free in + `libssh2_publickey_list_fetch()` (#2127) + +Due to uninitialized list entry. + +Reported-and-patch-by: Behzod Abdullayev +Reported-by: Sharique Raza + +Follow-up to e15f5d97a04cc676ce117dd324fef85b046207a9 + +CVE: CVE-2026-58051 +Upstream-Status: Backport [https://github.com/libssh2/libssh2/commit/a9758da45a52bc8c630ec9493804d0c6ea30b24a] + +(cherry picked from commit a9758da45a52bc8c630ec9493804d0c6ea30b24a) +Signed-off-by: Hetvi Thakar +--- + src/publickey.c | 1 + + 1 file changed, 1 insertion(+) + +diff --git a/src/publickey.c b/src/publickey.c +index 9c9fa618..87bc894f 100644 +--- a/src/publickey.c ++++ b/src/publickey.c +@@ -972,6 +972,7 @@ libssh2_publickey_list_fetch(LIBSSH2_PUBLICKEY * pkey, unsigned long *num_keys, + goto err_exit; + } + list = newlist; ++ memset(&list[keys], 0, sizeof(list[keys])); + } + if(pkey->version == 1) { + unsigned long comment_len; diff --git a/meta/recipes-support/libssh2/libssh2_1.11.1.bb b/meta/recipes-support/libssh2/libssh2_1.11.1.bb index 52684ae74ef..3c72f844adf 100644 --- a/meta/recipes-support/libssh2/libssh2_1.11.1.bb +++ b/meta/recipes-support/libssh2/libssh2_1.11.1.bb @@ -21,6 +21,7 @@ SRC_URI = "http://www.libssh2.org/download/${BP}.tar.gz \ file://CVE-2026-66034.patch \ file://CVE-2026-66035.patch \ file://CVE-2026-58050.patch \ + file://CVE-2026-58051.patch \ " SRC_URI[sha256sum] = "d9ec76cbe34db98eec3539fe2c899d26b0c837cb3eb466a56b0f109cabf658f7" From patchwork Sat Sep 5 20:44:37 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 8bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 97378 X-Patchwork-Delegate: yoann.congal@smile.fr Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 620A0C79F9F for ; Sat, 5 Sep 2026 20:45:36 +0000 (UTC) Received: from mail-wr1-f41.google.com (mail-wr1-f41.google.com [209.85.221.41]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.2601.1788641132889087385 for ; Sat, 05 Sep 2026 13:45:33 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=qNQEKKwX; spf=pass (domain: smile.fr, ip: 209.85.221.41, mailfrom: yoann.congal@smile.fr) Received: by mail-wr1-f41.google.com with SMTP id ffacd0b85a97d-47ddf7b09e5so2354021f8f.1 for ; Sat, 05 Sep 2026 13:45:32 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1788641131; x=1789245931; darn=lists.openembedded.org; h=content-transfer-encoding:content-type:mime-version:references :in-reply-to:message-id:date:subject:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=0lbuPJlbwk0W+pIPWoMp2eIz4AMkovX9g4eeqwyPWBo=; b=qNQEKKwXGCIB2Jb/E86Ap5dtiZW/ng7eexb2O9dqZLxnmXaQP7jntzUGB8KdhLoScK i8uL+EgLYXhrT9szb+UiPcrIJI2I6UGtuP4FUiPRC9GtQYdQlude5t5Rb0YOFeTYUhg8 wcnDrTfEIetet6w+6MOaF6cHVWOzjW82SZIec= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1788641131; x=1789245931; h=content-transfer-encoding:content-type:mime-version:references :in-reply-to:message-id:date:subject:to:from:x-gm-gg :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to :content-type; bh=0lbuPJlbwk0W+pIPWoMp2eIz4AMkovX9g4eeqwyPWBo=; b=dCTCT+FIYrPaFpToklv+2blf6fHt0I5xckwHplrVNadkcGlUg59AQLywWf1v83hQ70 1r7gs5+OPQDvpQb8kFWNna7hM8FEJXPdXiMTu8qjT94KEauseZ5NNf8Mjx9jI1Qje+TQ 2OC+w8o3JTsdGyNb69ynw9u7vZqpDXqI5mLpd0gOPKRs5/yOk8nAAEnHUhhK1H818h9X 20HNDn2soF9HyJC7hr/S3NpAfLa7loLLWT/3dQKxgzzRiX5U319SdfZaNV9lK8GFt0rN 8+YUSOSfZN3Nmcxt5WBlvIyr8NOXYohAzxXDCAlLtQVKyytGW7Y9OWDe3dPtdbWZ++tK p9Xg== X-Gm-Message-State: AFuF++mSSL63aD83J+8+kOa8TSRFGx22aBlPHWvaHPzTXtsFwfKbHmUp VYGH1RLx1CBSw+t1X+AjNgOHrlnE2ydp/vI1IDfOowkR9gPXTwGOymuGUUWfXAP3A6cJZP5czA+ QkonoQro= X-Gm-Gg: AYBFou27z+3XYltkt8EcbpWDjr+dSLJ64eBdV5XG4fyYGR1IApPhtuhhdroPpSt+JsB bmSFG84Tgb3ZB3yQECSx7go3Z1bsak//l+bHTzW6g6//jKhhX7W7Y3zosKG5zcU53e6qi9UCVnp vN3NhtYIe8ZK08RHugzwVkk67aUt6d1MpJKJB29VBnU20wFcckfXU5BPO0L/PhFVlDdqF4B+Qj+ yzR49IBAAZYxHgMynCF5pTD8mQk4EnEFjqS2x6451MG/bUIOtDYJKCdJFO1lj75EB3790d/A6QC NeAavGbFnfBJ4iXpUfpFcpdLQ+5QeZGHYcp3DQcB2js4E3qTQ1c8uKrB9f99FV5EYtAzdDbhgw8 XrXdGcsJYXiGmhi/XrOX0DZx385dVnFAD3m+H7zvs3S6u5qklolyQIxmNcFf5cWdx23R0bcYUmn C65Ta4VUuO8QBHQqriNzAFtJ6xo3qiZbMoAe8nFiae6/UPJ50+oDYE+xyzAp13HdnclanfDnoac MCvnSthkf5KApEy52yuir//lCLiO5MnCADCOqBIjRK58TpUzPrDXvMMiZAMvbxQow== X-Received: by 2002:a05:6000:2c11:b0:485:8c16:a340 with SMTP id ffacd0b85a97d-4858c16a82bmr11739028f8f.53.1788641131083; Sat, 05 Sep 2026 13:45:31 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa0048511f7ccf23d3ce.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:4851:1f7c:cf23:d3ce]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-485885bfdf6sm17069098f8f.34.2026.09.05.13.45.30 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sat, 05 Sep 2026 13:45:30 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][wrynose 36/40] python3-cryptography: backport stray file install fix Date: Sat, 5 Sep 2026 22:44:37 +0200 Message-ID: X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Sat, 05 Sep 2026 20:45:36 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/245188 From: Deepak Rathore Maturin 1.12 changed the handling of include entries from pyproject.toml. With the current cryptography metadata, files like CHANGELOG.rst, CONTRIBUTING.rst, docs and tests can be installed under site-packages instead of being kept only in the source archive. That can cause image install conflicts when packages such as python3-pyrad and python3-pyexpect are installed with python3-cryptography, because those packages also install top-level docs or tests directories under site-packages. Backport the upstream cryptography fix which marks these entries as sdist-only. The files remain available from the source tree, so the existing ptest install path which copies tests from ${S} is not changed. Signed-off-by: Deepak Rathore Signed-off-by: Yoann Congal --- .../python/python3-cryptography.bb | 1 + ...lling-stray-files-into-site-packages.patch | 55 +++++++++++++++++++ 2 files changed, 56 insertions(+) create mode 100644 meta/recipes-devtools/python/python3-cryptography/0002-Fix-installing-stray-files-into-site-packages.patch diff --git a/meta/recipes-devtools/python/python3-cryptography.bb b/meta/recipes-devtools/python/python3-cryptography.bb index 7f9bde15d03..c6561deb3c4 100644 --- a/meta/recipes-devtools/python/python3-cryptography.bb +++ b/meta/recipes-devtools/python/python3-cryptography.bb @@ -14,6 +14,7 @@ require python3-cryptography-common.inc SRC_URI[sha256sum] = "e4cfd68c5f3e0bfdad0d38e023239b96a2fe84146481852dffbcca442c245aa5" SRC_URI += "file://0001-pyproject.toml-remove-benchmark-disable-option.patch \ + file://0002-Fix-installing-stray-files-into-site-packages.patch \ file://check-memfree.py \ file://run-ptest \ " diff --git a/meta/recipes-devtools/python/python3-cryptography/0002-Fix-installing-stray-files-into-site-packages.patch b/meta/recipes-devtools/python/python3-cryptography/0002-Fix-installing-stray-files-into-site-packages.patch new file mode 100644 index 00000000000..a04861f1868 --- /dev/null +++ b/meta/recipes-devtools/python/python3-cryptography/0002-Fix-installing-stray-files-into-site-packages.patch @@ -0,0 +1,55 @@ +From af53f00da0538e7d64625eea9f4ec850a2b7dd2e Mon Sep 17 00:00:00 2001 +From: =?UTF-8?q?Micha=C5=82=20G=C3=B3rny?= +Date: Sun, 15 Feb 2026 18:01:37 +0100 +Subject: [PATCH] Fix installing stray files into site-packages (#14319) +MIME-Version: 1.0 +Content-Type: text/plain; charset=UTF-8 +Content-Transfer-Encoding: 8bit + +Fix the `include` pattern in `pyproject.toml` not to install stray files +such as `CHANGELOG.rst`, `CONTRIBUTING.rst`, `docs` and `tests` straight +into site-packages. Apparently Maturin did not install them before due +to a bug, but it was fixed in maturin 1.12.0, leading to the files being +suddenly installed. + +Originally reported as https://bugs.gentoo.org/970090. + +Upstream-Status: Backport [https://github.com/pyca/cryptography/commit/43eb178ee3aae8d0060221118437b03c23570a41] + +Signed-off-by: Michał Górny +(cherry picked from commit 43eb178ee3aae8d0060221118437b03c23570a41) +Signed-off-by: Deepak Rathore +--- + pyproject.toml | 8 ++++---- + 1 file changed, 4 insertions(+), 4 deletions(-) + +diff --git a/pyproject.toml b/pyproject.toml +index 75bfcbb94..8ee43d17a 100644 +--- a/pyproject.toml ++++ b/pyproject.toml +@@ -106,10 +106,10 @@ module-name = "cryptography.hazmat.bindings._rust" + locked = true + sdist-generator = "git" + include = [ +- "CHANGELOG.rst", +- "CONTRIBUTING.rst", ++ { path = "CHANGELOG.rst", format = "sdist" }, ++ { path = "CONTRIBUTING.rst", format = "sdist" }, + +- "docs/**/*", ++ { path = "docs/**/*", format = "sdist" }, + + { path = "src/_cffi_src/**/*.py", format = "sdist" }, + { path = "src/_cffi_src/**/*.c", format = "sdist" }, +@@ -121,7 +121,7 @@ include = [ + { path = "src/rust/**/Cargo.lock", format = "sdist" }, + { path = "src/rust/**/*.rs", format = "sdist" }, + +- "tests/**/*.py", ++ { path = "tests/**/*.py", format = "sdist" }, + ] + exclude = [ + "vectors/**/*", +-- +2.35.6 + From patchwork Sat Sep 5 20:44:38 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 97376 X-Patchwork-Delegate: yoann.congal@smile.fr Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 491A4C79F9E for ; Sat, 5 Sep 2026 20:45:36 +0000 (UTC) Received: from mail-wr1-f42.google.com (mail-wr1-f42.google.com [209.85.221.42]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.2602.1788641133431196767 for ; Sat, 05 Sep 2026 13:45:33 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=fEtDsmb2; spf=pass (domain: smile.fr, ip: 209.85.221.42, mailfrom: yoann.congal@smile.fr) Received: by mail-wr1-f42.google.com with SMTP id ffacd0b85a97d-4858c1c4b4eso1169232f8f.2 for ; Sat, 05 Sep 2026 13:45:33 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1788641132; x=1789245932; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=qiyMUp7aE57l+IaeoyKuHD5rAQkPgP9PzNaiSU4hMfs=; b=fEtDsmb2k7+nYiGMKwCGQU49qVavhIA8v14T2AMmeh//LPYg2+10fGPX+lpEwDm/nh /0mgAwRp5OIBxrSsq6EKfh0W0UfF7Sz14w6yd9FgaH4gU8NI7PN2P9EcbPrOpQm9v5LX IbUiTTyWVHNDJqwjKMLR/Pu8uhzd+aXhfoz3g= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1788641132; x=1789245932; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=qiyMUp7aE57l+IaeoyKuHD5rAQkPgP9PzNaiSU4hMfs=; b=ofFu8h0deD6MMcsUYYF+vRXbvOCVFSmU41RAFItGMGDTH1gXAoHkXxNTCMhB7NpZ0C 49cGYB8m3jOE5nr+eEylP8uLUCYpdgNTjOUM6c/T2XVDtCjX0ojW/u6X2BPF7UoMn2gM XdVKiFb3r7l53RiDlvarR843vwJUyDw0fW9Wgq8Ja538Cu2hVeblah3dgea8QYsQpzNL BMC3fawXrtRvnwguCFMfVA3okARm7hvruTRouDlCqhZMPXrSpt5ngYfKCwLavYIaVsde aASE2gXNIa/2ncV/manadTiO+N12GODfJd1sLt9Ls+CM7pG+DJpY3qdVCjeIaVj8NkSC rATw== X-Gm-Message-State: AFuF++lDpId4R7E+5dt2yM6Ni/4Gfip8dofvygvI1a3nPV2kiJ4Bf4Lq ky9aYsRne89DPkPBt6aMrWdBbUppL24JhipznFB/e0e01lg0xy22emWls7ctmiJc9EH1wYu2VQS 8k0hdItc= X-Gm-Gg: AYBFou2/t2QSRP5cnHcnq/8DCFxx2UmnqLa+h83HKpVmcfoAw0S4FpsFXNtXSTzEfFC /FRN+fHXW4EbrR3ASKQXzJpcUqpMkG/aGSUjqCD/I2WJ2UExVhNeBMdZA6yH+a5CQCaEAzzEn34 DPJiHSLHysrUIEIs7E5emgItgePhmprEPiTQVPxVTTYzzQEJVGMAHjSSI2UkmpVZpHj7/UD8r5k 4ycveL/lK3kHVtxOUWSrUhn6pnc8jpM1csgXlvVPXt2ueyPLY3TZEp1vE3Q2hL7NxJQZWd+jGj5 AuIJHHnpMccmh69YEt77wYdwJdDkFe6H/iutj1w/Hn6GNtTSH8I1x1ohw3s01zsmZteGSJHImoH XNk5+nQH7Ok6nY1r3YwYS+sVUTi//k9Oq46DrjjQyU7OGN4jbQCjb4FQNRXxVNuRrw6ZRo2NQYc oMIIxvnoRqFXZ8yBK8DZJk3EYveK3Xc2ZXW1ca0mUHXFkVj7zm5xc4ZtCu5h7HovAirjycP+yXI McvW1OmRcZoIe12pTnoImQ+YOjEhLINYjDiw6GKMEcXyqpjW8yn+c5vm64Xr1X8fv7JH+o23j4P X-Received: by 2002:a05:6000:26d3:b0:482:fe64:1717 with SMTP id ffacd0b85a97d-48587097606mr14874577f8f.7.1788641131691; Sat, 05 Sep 2026 13:45:31 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa0048511f7ccf23d3ce.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:4851:1f7c:cf23:d3ce]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-485885bfdf6sm17069098f8f.34.2026.09.05.13.45.31 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sat, 05 Sep 2026 13:45:31 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][wrynose 37/40] qemu: guard RESOLVE_CACHED strace flag Date: Sat, 5 Sep 2026 22:44:38 +0200 Message-ID: X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Sat, 05 Sep 2026 20:45:36 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/245189 From: Deepak Rathore qemu-native build can fail on build hosts which have an older linux/openat2.h header. The header is new enough to enable HAVE_OPENAT2_H, but it does not have RESOLVE_CACHED because that flag was added later in kernel 5.12. In that case linux-user/strace.c tries to use RESOLVE_CACHED and build fails with: error: 'RESOLVE_CACHED' undeclared here This is mainly seen with qemu-native because it is built for the host and can pick the host kernel UAPI header. The buildtools header may have RESOLVE_CACHED, but native build still has to be safe with older host headers also. Add the upstream QEMU fix which checks RESOLVE_CACHED before using it. This does not change anything on newer hosts. On older hosts QEMU just does not print this one strace flag because the local header does not know about it. Signed-off-by: Deepak Rathore Signed-off-by: Yoann Congal --- meta/recipes-devtools/qemu/qemu.inc | 1 + ...-if-RESOLVE_CACHED-flag-is-defined-b.patch | 38 +++++++++++++++++++ 2 files changed, 39 insertions(+) create mode 100644 meta/recipes-devtools/qemu/qemu/0012-linux-user-Check-if-RESOLVE_CACHED-flag-is-defined-b.patch diff --git a/meta/recipes-devtools/qemu/qemu.inc b/meta/recipes-devtools/qemu/qemu.inc index 60a5c62fe9f..cc8f2ecdfad 100644 --- a/meta/recipes-devtools/qemu/qemu.inc +++ b/meta/recipes-devtools/qemu/qemu.inc @@ -41,6 +41,7 @@ SRC_URI = "https://download.qemu.org/${BPN}-${PV}.tar.xz \ file://CVE-2026-0665.patch \ file://CVE-2025-14876_p1.patch \ file://CVE-2025-14876_p2.patch \ + file://0012-linux-user-Check-if-RESOLVE_CACHED-flag-is-defined-b.patch \ " # file index at download.qemu.org isn't reliable: https://gitlab.com/qemu-project/qemu-web/-/issues/9 UPSTREAM_CHECK_URI = "https://www.qemu.org" diff --git a/meta/recipes-devtools/qemu/qemu/0012-linux-user-Check-if-RESOLVE_CACHED-flag-is-defined-b.patch b/meta/recipes-devtools/qemu/qemu/0012-linux-user-Check-if-RESOLVE_CACHED-flag-is-defined-b.patch new file mode 100644 index 00000000000..f23557dc9b9 --- /dev/null +++ b/meta/recipes-devtools/qemu/qemu/0012-linux-user-Check-if-RESOLVE_CACHED-flag-is-defined-b.patch @@ -0,0 +1,38 @@ +From 09e077b87eed754cc0aac0f54d193d49f978c93f Mon Sep 17 00:00:00 2001 +From: Frank Chang +Date: Thu, 12 Feb 2026 17:54:49 +0800 +Subject: [PATCH] linux-user: Check if RESOLVE_CACHED flag is defined before + using it + +Upstream-Status: Backport [https://gitlab.com/qemu-project/qemu/-/commit/7ac4bded6af90a15a9562515743a789236b062d1] + +openat2.h was introduced in Linux kernel 5.6. However, RESOLVE_CACHED +flag was only added in kernel 5.12 and later. Therefore, we need to check +if RESOLVE_CACHED flag is defined before using it. + +Signed-off-by: Frank Chang +Reviewed-by: Helge Deller +Signed-off-by: Helge Deller +(cherry picked from commit 7ac4bded6af90a15a9562515743a789236b062d1) +Signed-off-by: Deepak Rathore +--- + linux-user/strace.c | 2 ++ + 1 file changed, 2 insertions(+) + +diff --git a/linux-user/strace.c b/linux-user/strace.c +index 758c5d32b6..a903b414fd 100644 +--- a/linux-user/strace.c ++++ b/linux-user/strace.c +@@ -1125,7 +1125,9 @@ UNUSED static const struct flags openat2_resolve_flags[] = { + FLAG_GENERIC(RESOLVE_NO_SYMLINKS), + FLAG_GENERIC(RESOLVE_BENEATH), + FLAG_GENERIC(RESOLVE_IN_ROOT), ++#ifdef RESOLVE_CACHED + FLAG_GENERIC(RESOLVE_CACHED), ++#endif + #endif + FLAG_END, + }; +-- +2.35.6 + From patchwork Sat Sep 5 20:44:39 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 97375 X-Patchwork-Delegate: yoann.congal@smile.fr Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 2828AC79F9B for ; Sat, 5 Sep 2026 20:45:36 +0000 (UTC) Received: from mail-wr1-f53.google.com (mail-wr1-f53.google.com [209.85.221.53]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.2490.1788641134047282172 for ; Sat, 05 Sep 2026 13:45:34 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=UtwTz8gh; spf=pass (domain: smile.fr, ip: 209.85.221.53, mailfrom: yoann.congal@smile.fr) Received: by mail-wr1-f53.google.com with SMTP id ffacd0b85a97d-48441a2ba14so1927263f8f.1 for ; Sat, 05 Sep 2026 13:45:33 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1788641132; x=1789245932; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=j4mrVTQ3kkDRbNpc7wX5UtBm1FlJvcEOL/ytwamFGwc=; b=UtwTz8ghPj8a6MgtIXRqFC38VHM7OcwlWJVYLmdR0ZUGwvF3tG0Kf4mvfNxAhrJPMR iL1Oqi15g2B1MQHhLW2oh+4r0yVwFUogWwckRdlO96eEgsiBUDeKOWzUSBVYJBBfIBf0 2hB4Zpjhntx2AAKAVs8g1NKse/r6sgeMcWCQY= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1788641132; x=1789245932; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=j4mrVTQ3kkDRbNpc7wX5UtBm1FlJvcEOL/ytwamFGwc=; b=S6nayGU32YGfbcRqO8R9sd/wDziyvcyTxtERjGzZkKAZjYuyJrSgjR86wtu5D/LWQ8 CKKMc33MhSoMnrCZVBmeDa1DNOC9aSchQpQzv5a9ejhoNR0CwMwRm43S1QAt7OdeesHh MK38BgE2h1NDIbFO62Uo8TP1G+ZSOE4C7zwaOZvk4ya2s7tKue8PQ+fJ63mEMNzt17zX XAAx12SH8C8OYfHzfUVe7qTBFkXmJfb7eCT6rGDV50x2vi/2qqRXKQRMiVBFyupxI9S9 MZ7CgjS7Ri7r3bKnLjC6VhzQPLxDMRDx6dxlaVsEhnM72TwsEFnEfcwuqrkPyuaHfWpY FZTA== X-Gm-Message-State: AFuF++m1vVXbTFap6maxURZCG8xf/S06bBgmbeYHjpakfVS7vqmiID1d y609BcyD+d41gVc02LJmG1MKgNGckFiRdMOiNv63MNJ2zA+pEvTUyXHicPMLlp6FnbazmyqbyOa uXEVwUdw= X-Gm-Gg: AYBFou3QsroMJ6n71YfYSO//+HBceiw5FSy4fI+Fx8/MLTdpLoiwKw5K/RpFPJKg1Mc TAW48DGe1PX126/uBzC1uymXsC49n61sLAk9UYosBeRxlUVY376hgT7xBNmUcC8bT2eBgZ/LZrC WUPkI85EsOYxALVlMZxHx3fmRWpDFhBxOXOnMqc9yyFOcWeF//nfSGRIWBh0C2FkMZFlz7HEqIc 3zFIymoJboOHhb+dW49O1XhfsD8546QX4EQ9rbxvryNgavAvJvJ2FVpVJf/pBuURMvSOrzH/IVC Ak+TkRYkQ0V6HZA5rw3AvaOTa4owve0v+yz8bAzHJS5hvu/iBejDJS5lcEftQd2a0Qw5ql2UL0D FHE9m9LaiXQNX5+JoYESii+5MkK97iiSnmY0sizyDSuqa14mJ6kHY/FRKulVdZGLnNFzreJQtrP htFtqmRxw41UuC8wzZTBi37muaZpaWxmmcvI9RQBMAhuU7gwyOkos5AD1siMwEmGxHgYTtjBshg OdqJgIxXx+DKynYhLv5hxAbzY97hUqgJXEd+DTLlA7OYLVS4qto7dKEflJPajsBdA== X-Received: by 2002:a5d:5e91:0:b0:483:3695:6ea6 with SMTP id ffacd0b85a97d-485872c1debmr17461515f8f.20.1788641132209; Sat, 05 Sep 2026 13:45:32 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa0048511f7ccf23d3ce.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:4851:1f7c:cf23:d3ce]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-485885bfdf6sm17069098f8f.34.2026.09.05.13.45.31 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sat, 05 Sep 2026 13:45:31 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][wrynose 38/40] util-linux: set status for CVE-2026-13595 Date: Sat, 5 Sep 2026 22:44:39 +0200 Message-ID: <6d98aed110fe0f6671cd22833f4e64106e9034dd.1788629392.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Sat, 05 Sep 2026 20:45:36 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/245190 From: Peter Marko Per [1] this bas backported to 2.41.5. [1] https://security-tracker.debian.org/tracker/CVE-2026-13595 Signed-off-by: Peter Marko Signed-off-by: Yoann Congal [YC: Fixed the inequality in the comment, commit message and [1] tell ">= 2.41.5". ] --- meta/recipes-core/util-linux/util-linux.inc | 2 ++ 1 file changed, 2 insertions(+) diff --git a/meta/recipes-core/util-linux/util-linux.inc b/meta/recipes-core/util-linux/util-linux.inc index fdc62acc748..09916594b0a 100644 --- a/meta/recipes-core/util-linux/util-linux.inc +++ b/meta/recipes-core/util-linux/util-linux.inc @@ -26,3 +26,5 @@ SRC_URI = "${KERNELORG_MIRROR}/linux/utils/util-linux/v${MAJOR_VERSION}/util-lin SRC_URI[sha256sum] = "f586e35d320ff537aab3ffeca37e9ecd482ccbe013590db4429a414d8aa6a728" CVE_PRODUCT = "util-linux" + +CVE_STATUS[CVE-2026-13595] = "cpe-stable-backport: Fixed from version >=2.41.5" From patchwork Sat Sep 5 20:44:40 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 8bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 97379 X-Patchwork-Delegate: yoann.congal@smile.fr Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 9CE93C79FA1 for ; Sat, 5 Sep 2026 20:45:36 +0000 (UTC) Received: from mail-wr1-f51.google.com (mail-wr1-f51.google.com [209.85.221.51]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.2603.1788641134488076305 for ; Sat, 05 Sep 2026 13:45:34 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=0YVsRLMy; spf=pass (domain: smile.fr, ip: 209.85.221.51, mailfrom: yoann.congal@smile.fr) Received: by mail-wr1-f51.google.com with SMTP id ffacd0b85a97d-4858595f997so1316267f8f.1 for ; Sat, 05 Sep 2026 13:45:34 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1788641133; x=1789245933; darn=lists.openembedded.org; h=content-transfer-encoding:content-type:mime-version:references :in-reply-to:message-id:date:subject:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=B8zvxlYBP6bLdNlwJl0Qhl1D1dCY1m6pvsd1zB6ApiM=; b=0YVsRLMyz0NSLG08s5EQhSbXBWI//up03RvEa06tKemByzbZjh0CmqPA4fVwOoWTsg UyciL76fbiIA4T0UFHyQcBurcy2qPNYzQB3aETrR3xghC/jHteySTgfga1S1z4puvaoF lSVWjU1A7pMpwgA2Uo5uJ5hJgOZmIBUQu64/Y= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1788641133; x=1789245933; h=content-transfer-encoding:content-type:mime-version:references :in-reply-to:message-id:date:subject:to:from:x-gm-gg :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to :content-type; bh=B8zvxlYBP6bLdNlwJl0Qhl1D1dCY1m6pvsd1zB6ApiM=; b=j37TKrwTDtmPNneNmBRVQBoHogLyhiT9mokOnFqkTbsJ2d3bAoBPLfpb0iqet30UcG E+dAkVLcJVqwWshikZnlJDYxUkxR53E+1B3c2AdpVve1ElUJrkkZnn1ZKFaI7gry65lJ 3xoQ5urz/sN7XafjTzDfui9e6mAhWYp9LZcKYLIEKeTQmFA/8cV39YqbVx86FGP8YtS0 S9F/mp6UjSjAizYX+gMBVNzAUbUDUBj9+ovwRUrNdnKuG29QEH1M1Onc8Kdf58f6tHOF ihFYZthuoVfgBNarzUC3iHM/HIpCOesr3Fv7d+aEj0Dcq3A28mp4QzYeCMeL92AAg+Rb vyEg== X-Gm-Message-State: AFuF++lXQYWwnIJar/eW2mY2N35fbz+sD5XWP2D+Lfgm63/fdmKfFTXk Rg2PHoglljTXrWh/Zp1TVAG2i1JaAZQVU3YMewBh6lOaOuefgFIYS5P6qVVbrG144pCtz1i7FOG GuCOM8zc= X-Gm-Gg: AYBFou0mS5S8+PORJ3/LLXWAORW8eML6eyDldCZ7IJmoCd17kR58Af4fPJizORZrNu/ KqvHVIOcMUkH2xDkySO/LVcTOk9682cYB9xACT5sJHCwWwpAuyh8RbbpN+19+eARwrHqpjtC9vo MBgx/63H9jjnZ3toJz1iBL9Mt1gMx3prrzkLHI9BaKSJgQ8TuY9cI1SYYNpbkvZvmhgLw4b/NUo PRTMCyycXyvxji9DPfpPUSE4D1YMlFZZq2F71oI5DcNG832BYKSGIke6HWgFsCDbnv3Lol4x40p WryCla5Qa5Ve4F1ORvDjS5jLnMDsbx1LEBtG1o5pVVy1SjzkFOyJ5BI/blbcHR5wk9Up4T/2ipB +8HLSf6TD4cKGZHcW57hNZDgoKO+cH4e4mMk6w7WQsAcsJFcZgNKctLVfh8H/E8dHZ533qrfVl9 YuLfx9Zx5aRZtRuDB6RNXr51pXVZWCFd2jGls8ePlLK4oDGYBlBM/83XGIEgCwk9Qj+VsgdXmpZ MaH1Zz6a8jGcf+IBfUJ2fsPjY70S7qhDFfL+8JehkExuIBUBYKGGNE2qEEI7DqRYDEiU5Q9Et0N X-Received: by 2002:a05:6000:1acb:b0:485:8b5d:96d with SMTP id ffacd0b85a97d-4858b5d0d2dmr21292312f8f.19.1788641132695; Sat, 05 Sep 2026 13:45:32 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa0048511f7ccf23d3ce.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:4851:1f7c:cf23:d3ce]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-485885bfdf6sm17069098f8f.34.2026.09.05.13.45.32 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sat, 05 Sep 2026 13:45:32 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][wrynose 39/40] go: upgrade 1.26.6 -> 1.26.7 Date: Sat, 5 Sep 2026 22:44:40 +0200 Message-ID: X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Sat, 05 Sep 2026 20:45:36 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/245191 From: Peter Marko Upgrade to latest 1.26.x release [1]: $ git --no-pager log --oneline go1.26.6..go1.26.7 e3336a22ad (tag: go1.26.7) [release-branch.go1.26] go1.26.7 50e5b59e9c [release-branch.go1.26] net/http: clear ReadHeaderTimeout after accepting an unencrypted h2 conn 98e6631a5a [release-branch.go1.26] cmd/internal/moddeps: restore tests This minor release includes a fix to address a breakage affecting unencrypted HTTP/2 (h2c) connections caused by a security patch included in last week’s release. See go.dev/issue/80876 for details. Release information: [2] [1] https://github.com/golang/go/compare/go1.26.6...go1.26.7 [2] https://groups.google.com/g/golang-announce/c/qA6Vpj2UA-4 Signed-off-by: Peter Marko Signed-off-by: Richard Purdie (From OE-Core rev: e6739374b865cae8d6f105c7a600a52736579c25) Signed-off-by: Peter Marko Signed-off-by: Yoann Congal --- meta/recipes-devtools/go/{go-1.26.6.inc => go-1.26.7.inc} | 2 +- ...o-binary-native_1.26.6.bb => go-binary-native_1.26.7.bb} | 6 +++--- ...cross-canadian_1.26.6.bb => go-cross-canadian_1.26.7.bb} | 0 .../go/{go-cross_1.26.6.bb => go-cross_1.26.7.bb} | 0 .../go/{go-crosssdk_1.26.6.bb => go-crosssdk_1.26.7.bb} | 0 .../go/{go-runtime_1.26.6.bb => go-runtime_1.26.7.bb} | 0 meta/recipes-devtools/go/{go_1.26.6.bb => go_1.26.7.bb} | 0 7 files changed, 4 insertions(+), 4 deletions(-) rename meta/recipes-devtools/go/{go-1.26.6.inc => go-1.26.7.inc} (90%) rename meta/recipes-devtools/go/{go-binary-native_1.26.6.bb => go-binary-native_1.26.7.bb} (80%) rename meta/recipes-devtools/go/{go-cross-canadian_1.26.6.bb => go-cross-canadian_1.26.7.bb} (100%) rename meta/recipes-devtools/go/{go-cross_1.26.6.bb => go-cross_1.26.7.bb} (100%) rename meta/recipes-devtools/go/{go-crosssdk_1.26.6.bb => go-crosssdk_1.26.7.bb} (100%) rename meta/recipes-devtools/go/{go-runtime_1.26.6.bb => go-runtime_1.26.7.bb} (100%) rename meta/recipes-devtools/go/{go_1.26.6.bb => go_1.26.7.bb} (100%) diff --git a/meta/recipes-devtools/go/go-1.26.6.inc b/meta/recipes-devtools/go/go-1.26.7.inc similarity index 90% rename from meta/recipes-devtools/go/go-1.26.6.inc rename to meta/recipes-devtools/go/go-1.26.7.inc index fa6b0a50a14..fed87015b2c 100644 --- a/meta/recipes-devtools/go/go-1.26.6.inc +++ b/meta/recipes-devtools/go/go-1.26.7.inc @@ -16,4 +16,4 @@ SRC_URI += "\ file://0009-go-Filter-build-paths-on-staticly-linked-arches.patch \ file://0010-cmd-go-clear-GOROOT-for-func-ldShared-when-trimpath-.patch \ " -SRC_URI[main.sha256sum] = "a0721c54c688901448d77ad9b3ec7ea7c474730755ff891382e92ecb93ff2cb1" +SRC_URI[main.sha256sum] = "0ed24eac755105085b89fe9cabc2742b91a0ad7b94b59d3ad364918ebc8956ad" diff --git a/meta/recipes-devtools/go/go-binary-native_1.26.6.bb b/meta/recipes-devtools/go/go-binary-native_1.26.7.bb similarity index 80% rename from meta/recipes-devtools/go/go-binary-native_1.26.6.bb rename to meta/recipes-devtools/go/go-binary-native_1.26.7.bb index 2913fb65151..753f1b13bb5 100644 --- a/meta/recipes-devtools/go/go-binary-native_1.26.6.bb +++ b/meta/recipes-devtools/go/go-binary-native_1.26.7.bb @@ -9,9 +9,9 @@ PROVIDES = "go-native" # Checksums available at https://go.dev/dl/ SRC_URI = "https://dl.google.com/go/go${PV}.${BUILD_GOOS}-${BUILD_GOARCH}.tar.gz;name=go_${BUILD_GOTUPLE}" -SRC_URI[go_linux_amd64.sha256sum] = "708effb774be8237570d0add163225abbdfaf4fca28b2611df167beba4feef89" -SRC_URI[go_linux_arm64.sha256sum] = "d0507e9e9d7fe012aae570108cbd76c15de879e17130ab8cb90d4d7445cb1f2e" -SRC_URI[go_linux_ppc64le.sha256sum] = "232b65543a42eda95df6a63f76235c1795bb535eba5c74e509faec71bc648388" +SRC_URI[go_linux_amd64.sha256sum] = "ffb5f8de10c62550dfddab66b36b57030721e0a44a3218e9e1181d7b59f121ca" +SRC_URI[go_linux_arm64.sha256sum] = "5a4ec883379d51ee9ce1040d5e87f8d35e20387574dd8c947feb01eabc3c1b37" +SRC_URI[go_linux_ppc64le.sha256sum] = "22d3b362d557175fd16b79651cab0cad64f8aaaedca745f66d16f44d56bc5de1" UPSTREAM_CHECK_URI = "https://golang.org/dl/" UPSTREAM_CHECK_REGEX = "go(?P\d+(\.\d+)+)\.linux" diff --git a/meta/recipes-devtools/go/go-cross-canadian_1.26.6.bb b/meta/recipes-devtools/go/go-cross-canadian_1.26.7.bb similarity index 100% rename from meta/recipes-devtools/go/go-cross-canadian_1.26.6.bb rename to meta/recipes-devtools/go/go-cross-canadian_1.26.7.bb diff --git a/meta/recipes-devtools/go/go-cross_1.26.6.bb b/meta/recipes-devtools/go/go-cross_1.26.7.bb similarity index 100% rename from meta/recipes-devtools/go/go-cross_1.26.6.bb rename to meta/recipes-devtools/go/go-cross_1.26.7.bb diff --git a/meta/recipes-devtools/go/go-crosssdk_1.26.6.bb b/meta/recipes-devtools/go/go-crosssdk_1.26.7.bb similarity index 100% rename from meta/recipes-devtools/go/go-crosssdk_1.26.6.bb rename to meta/recipes-devtools/go/go-crosssdk_1.26.7.bb diff --git a/meta/recipes-devtools/go/go-runtime_1.26.6.bb b/meta/recipes-devtools/go/go-runtime_1.26.7.bb similarity index 100% rename from meta/recipes-devtools/go/go-runtime_1.26.6.bb rename to meta/recipes-devtools/go/go-runtime_1.26.7.bb diff --git a/meta/recipes-devtools/go/go_1.26.6.bb b/meta/recipes-devtools/go/go_1.26.7.bb similarity index 100% rename from meta/recipes-devtools/go/go_1.26.6.bb rename to meta/recipes-devtools/go/go_1.26.7.bb From patchwork Sat Sep 5 20:44:41 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 97373 X-Patchwork-Delegate: yoann.congal@smile.fr Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id D95CCC624DB for ; Sat, 5 Sep 2026 20:45:35 +0000 (UTC) Received: from mail-wr1-f50.google.com (mail-wr1-f50.google.com [209.85.221.50]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.2491.1788641134903325643 for ; Sat, 05 Sep 2026 13:45:35 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=LD6X9jPK; spf=pass (domain: smile.fr, ip: 209.85.221.50, mailfrom: yoann.congal@smile.fr) Received: by mail-wr1-f50.google.com with SMTP id ffacd0b85a97d-48444ec4fe2so1304212f8f.0 for ; Sat, 05 Sep 2026 13:45:34 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1788641133; x=1789245933; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=x0yitZs4H+Ik2mW9eCj5VL4Hhdb7oYNeIQa2KAAFIP0=; b=LD6X9jPKTN0I07M5muLIQ6IJiVqIYCG5TRjHcsgvx91Rq+5/UUPF8Z68YqXiw0j4xT u7FhR46O8HGyQ486+0ZifoA7sOIWG1/E+1IR/7TQv6m1qyqme05JHsy9PGnYTdROiv+Y AfFa86AkEBLPch4KwbpwpVxVSALkiZa9qC+Kg= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1788641133; x=1789245933; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=x0yitZs4H+Ik2mW9eCj5VL4Hhdb7oYNeIQa2KAAFIP0=; b=PCuYmU1GOGdUrNnK6VWzuM6yg3VX7dw+PMHTfe9m5ruM4OG/VlCOS6TIywLFDgMw6V mWNYhLZ43D5z4ModC7aqElUZd2pf/zub5wqTw7wa2o2aen+JI1XZQiXDexw9uRaI2Wx4 rLO8zAon9SDOmgocNry5x1EWycMJ5lcj3NiTwku/V1GHIt/l2p8tuDKsErP1jW4hoSUs ncFRkrhOHw9BC4hZvgYo38UM6ouFflY8248L9PCapirYbUeYdHUJyv273gVjkGJSPUUF vDI9P6LATFsX9t2GchCt0fntdlxUo5ctfP1FP+V7HfwSCFw2/62NLswKIH3Rs020mR/R TW/A== X-Gm-Message-State: AFuF++naivOhry3oNMO0ejoZztzzFhefiGF9tYTb6CF1JhIBl89wN8cW vQdCybMsLs67lYVtdBcmXagXITR21YD0Cd9ZWz4VM6kqk6y0rgfbCheTVSG1yC23Nq6z4y4QweK vi5NMvUg= X-Gm-Gg: AYBFou2BMkRGla1eO6gSpjb95GKOw1gv0D/DhdEP2CtRNR/4ud0VE/xX83IIvXyAd6K QhQjiGB9kdwXKbGcjhJgZ2M6JvmeD06UM5JJiyifUhQOrdJraf1hkCIQlg97OPk1Jlk5x3vpHPg CxDTjUCxfBvrKe9S8JIZipzdOekYH8BQO+soO+ic/f8062vjhxD4SybGafBita4F7BFi5GXYKgM WO/jFbApJfFd8jhU3pmaF46qMSZpF4B1nQ5ynbiR25/BKA+g4uVwvEASatu+/Xa5AzPq0F4xRN3 j/gtk6j8ORATZDcrNJvdN3z5NcJZrvLcFSmZACCXbZ3hFD7aIt9gqqutP+UAN7j8o+ULBhPwg5e tTIKrUzuQ9Zi3uHFQ+koCMG54zPudWCreC4Camh89AY3qnyVOnPbiFZcnG2J5Olf817D316Aa95 uvvwHdTZ+2Mjf6elWpJeKOnXoDlOMidslQE7HHdMWn6VbBUFpGbIEvv3heAyULVu598xda2Nh57 ySn8bwsb7LhzH5CpOivQFaOlOK8hYYxDD0+cqjzCCueUcqI/5zHdLscmaqRgtjhGMY= X-Received: by 2002:a05:6000:468a:b0:484:3310:710e with SMTP id ffacd0b85a97d-48587291a2cmr21967361f8f.26.1788641133151; Sat, 05 Sep 2026 13:45:33 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa0048511f7ccf23d3ce.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:4851:1f7c:cf23:d3ce]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-485885bfdf6sm17069098f8f.34.2026.09.05.13.45.32 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sat, 05 Sep 2026 13:45:32 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][wrynose 40/40] scripts/install-buildtools: Update to 6.0.3 Date: Sat, 5 Sep 2026 22:44:41 +0200 Message-ID: <31def396136be047e10c507a50264aad52ba6b0f.1788629392.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Sat, 05 Sep 2026 20:45:35 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/245192 From: Yoann Congal Update to the 6.0.3 release of the 6.0 series for buildtools Signed-off-by: Yoann Congal --- scripts/install-buildtools | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/scripts/install-buildtools b/scripts/install-buildtools index b59cfbb8705..e1af05fca33 100755 --- a/scripts/install-buildtools +++ b/scripts/install-buildtools @@ -57,8 +57,8 @@ logger = scriptutils.logger_create(PROGNAME, stream=sys.stdout) DEFAULT_INSTALL_DIR = os.path.join(os.path.split(scripts_path)[0],'buildtools') DEFAULT_BASE_URL = 'https://downloads.yoctoproject.org/releases/yocto' -DEFAULT_RELEASE = 'yocto-6.0.2' -DEFAULT_INSTALLER_VERSION = '6.0.2' +DEFAULT_RELEASE = 'yocto-6.0.3' +DEFAULT_INSTALLER_VERSION = '6.0.3' DEFAULT_BUILDDATE = '202110XX' # Python version sanity check