From patchwork Mon Sep 7 13:34:57 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 97526 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 1092CC79FAA for ; Mon, 7 Sep 2026 13:36:03 +0000 (UTC) Received: from mail-wr1-f46.google.com (mail-wr1-f46.google.com [209.85.221.46]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.34909.1788788153187247167 for ; Mon, 07 Sep 2026 06:35:53 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=y1F3DCzI; spf=pass (domain: smile.fr, ip: 209.85.221.46, mailfrom: yoann.congal@smile.fr) Received: by mail-wr1-f46.google.com with SMTP id ffacd0b85a97d-482f9309813so3166045f8f.1 for ; Mon, 07 Sep 2026 06:35:52 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1788788151; x=1789392951; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=TJ7ADLpE+vBXDdfqWOstwBnQtZFDBYhdHhqn2Lu2cTM=; b=y1F3DCzI2dNBJ9Pax4RnAzZmFgoXz45h++uqtfIAOGMNzIC62+dJTqmWpNB4AySUja ixhAcg/3mh56vMglCXkDJR6wYS6PS6H6jFfcVof8VWWnmGu4i54xdmpa5hfNH2dR5clY 2QftBmBQCoBWhD6EnGtHtZawUl26LhmfqMJV8= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1788788151; x=1789392951; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=TJ7ADLpE+vBXDdfqWOstwBnQtZFDBYhdHhqn2Lu2cTM=; b=rtW485gHL8ECWfJ++VgZSX9gLOpESBcCjmHMwSg6dISDBFcGKTeKEHFubiprAZCKNw flAW1CZs0DEnIp3LvGZ0U/P0LWxLqDslVgG0kj1Zzx36L9YcwBq1mNgo/OhCkIr10wIZ /9gmpwLGRubq9I8dFYqLE1K8hbV8kziICjf+255xHAemKJW1uUfelKumlRGH/+OvSxZq CJYfKwKg4kyb6tgUor+arVAeXmtwQebAK+aPaCDB4olrt5Hq8nPBlM3matenHjtqFJWp eXhVC3Vdhegq1ZkgG7zhAXMcokfKdp9Nlq1cGx6eW1H2g4f2WBq4Y+Et1wwUZs0RBl3z jtuQ== X-Gm-Message-State: AFuF++k7t0z82S7M5kwHzCdjnLjmco0tUfYajzqby0DhHPZjh6Jv4OmG foSxZNISI/gPqUpLYgKnK4yrgI1AuHGtZZpfEmEYO+UAQmLqCoNEy6CJEyXgEnR/5hRNY0cJwRF /1yH/vkw= X-Gm-Gg: AYBFou2zY3V0grvcaX7EYIcFQcmQJOKp7CrIwj7le/ztQR96tlCrYoKSXRUq63uhRhF kT9hm85UYr3LfVEQCqW9JFBhxjIZfW2GXB1yo2GIMMaUWboRWZlOlfqKFMqS5hEYSWF4TF0fD0g C2Dh6A007X0atd19QEP+DVoeMEb5IFBuMzcOZwN6j8YfoDogMNEMzke81iWIXpapDjvXvydwu2z V571p8eY2oRi7O+8SnGQsMvprayB8M/GwTJb5wbojB3H65QldZ/NUhyfUuJNjnyhWr406fQqpPX 8rumhCiglzJmMhHh3OQfOqIDZTfH9JCMEvQky2WF4DZxHgP5dRZ3vDRZgEn/OZNCGyiNgvSuH67 z+LAgyqYGxf1ouPcJzZTaJBA/UDaYZKQNf1eUI4yWbNdxvZKghWXrYl/xHDf6RBgFOMLWgT05a5 BoophWDWz+Vf4/8of1MoJZRXSrF834fWO5WGcu7Hct8L2FqmS4f8ew1tlRyHU6FnokUpY1UXFxj hhQjWASenchy8pkuDK0SHeVUsLwF9Zq3MxfUpX+1K2NWWDKradkn6mt1BO1DZhjQg== X-Received: by 2002:a5d:5d83:0:b0:485:8c16:5eec with SMTP id ffacd0b85a97d-4858c166045mr19547967f8f.38.1788788151372; Mon, 07 Sep 2026 06:35:51 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-48588394fa1sm27523836f8f.8.2026.09.07.06.35.51 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 07 Sep 2026 06:35:51 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][scarthgap 01/35] apt: mark CVE-2011-3374 as not-applicable-config Date: Mon, 7 Sep 2026 15:34:57 +0200 Message-ID: X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Mon, 07 Sep 2026 13:36:03 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/245259 From: Anil Dongare Details: https://security-tracker.debian.org/tracker/CVE-2011-3374 The vulnerability is a design-level flaw in the legacy apt-key utility regarding the global trust model of GPG keys. This is marked as not-applicable-config because apt-key net-update is disabled by default, and Debian vendor configuration does not define the archive keyring URI required to use that path. Ignore this CVE in this recipe due to this configuration. Signed-off-by: Anil Dongare Signed-off-by: Yoann Congal [YC: made commit title more precise. net-update is disabled by default here: https://salsa.debian.org/apt-team/apt/-/blob/2.6.1/cmdline/apt-key.in?ref_type=tags#L179 ] --- meta/recipes-devtools/apt/apt_2.6.1.bb | 3 +++ 1 file changed, 3 insertions(+) diff --git a/meta/recipes-devtools/apt/apt_2.6.1.bb b/meta/recipes-devtools/apt/apt_2.6.1.bb index 12915660b0f..8b48de3498b 100644 --- a/meta/recipes-devtools/apt/apt_2.6.1.bb +++ b/meta/recipes-devtools/apt/apt_2.6.1.bb @@ -38,6 +38,9 @@ UPSTREAM_CHECK_URI = "${DEBIAN_MIRROR}/main/a/apt/" # to express 'divisible by 4 plus 2' in regex (that I know of), let's hardcode a few. UPSTREAM_CHECK_REGEX = "[^\d\.](?P((2\.2)|(2\.6)|(3\.0)|(3\.4)|(3\.8)|(4\.2))(\.\d+)+)\.tar" +# Not applicable: Debian vendor configuration does not enable apt-key net-update. +CVE_STATUS[CVE-2011-3374] = "not-applicable-config: apt-key net-update is disabled by default and Debian vendor configuration has no archive keyring URI" + inherit cmake perlnative bash-completion useradd # User is added to allow apt to drop privs, will runtime warn without From patchwork Mon Sep 7 13:34:58 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 8bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 97542 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id D2E05C79FB4 for ; Mon, 7 Sep 2026 13:36:04 +0000 (UTC) Received: from mail-wr1-f49.google.com (mail-wr1-f49.google.com [209.85.221.49]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.35214.1788788153856218063 for ; Mon, 07 Sep 2026 06:35:54 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=XnAFjnOD; spf=pass (domain: smile.fr, ip: 209.85.221.49, mailfrom: yoann.congal@smile.fr) Received: by mail-wr1-f49.google.com with SMTP id ffacd0b85a97d-482e257a23aso2491246f8f.0 for ; Mon, 07 Sep 2026 06:35:53 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1788788152; x=1789392952; darn=lists.openembedded.org; h=content-transfer-encoding:content-type:mime-version:references :in-reply-to:message-id:date:subject:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=WA2w4IIXqEz3QXfiAw6TX2Sn4Bvw660heYrQsptOkl8=; b=XnAFjnODgrtxGOYOn2Yrr0yG6jlJIerLs//dIM5OeP7gUlf4OuJeoACrz46B0OfZIz fP5r35WCSI8AldmHdeqp8vuArGRqzby8c141GU1qJ56HwgukvjjoyIsSfsUDujK1BPGw 5xPAiPWQlf6uRUX7WIwYFisNaPvwDcthuwkD4= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1788788152; x=1789392952; h=content-transfer-encoding:content-type:mime-version:references :in-reply-to:message-id:date:subject:to:from:x-gm-gg :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to :content-type; bh=WA2w4IIXqEz3QXfiAw6TX2Sn4Bvw660heYrQsptOkl8=; b=Fy8pHZ3R7AP1stYEdm0lXTkeqz/dUIWV/J6/mfss1kb/eMbkYJFxmdNs1YUzZEwTc/ Ons1pQxu0klOmEiUh3QSsb7D4RtUFN4bQMMzG2KV6gScRi/ueVpYuhB6fFqvsVNTGWix lx41JI+qOojYGh9k7OOcHVq1j3MTzI+7WGmyFGGXRYu3WAqBH5+uohk4+ceTxyN7Tebj IhRSffCdaNNCZoXiWJi5IAVxRxv89mBHoZVA/C7h2YNQbQxli20UOyvWv6R35VqpGpvF B2die3C6Q9USGlyDHB9SrWQgePid7AkiiAs3bfcuClH4hK+EmL9GUtKkG9XrAaLLSMyd lw0A== X-Gm-Message-State: AFuF++ks7uBvKAANKWhtma9uAA7eviiuDpapnC+mSxJAMEyt8Iv5/3Dp mVMXd8OZyYa2unTiFKCxDEAvRSXjO4v0/EGgCh7nKT5R2A7/VGree9L2raE1v8xLgY21NCldm7B gEVEvnFw= X-Gm-Gg: AYBFou2L656J1C7DtbBbIapZT/Ft6a6wu257YBBoFRd20/9YS9XowaRag4BuF/9hk1h GIM6K+3LtwN/xeprchhcsmjRKk7vdoxWurLIVXPCtpFZhpl/5lrqgF5HVa+frwipEpqRhzqtGWP HVOiOzgeT7AYr/aMcew5dIHUJDtBAzPuSEvTvansyIutx6iYoKVL/6d/mG2KEnZv9fOBm5ni8VZ ajW40ZgS0UhgqvYRBly7lj+KtJGPz3n7g7pjwt8rYeFQrPUDhTMDd4VMOa6KpMrhXRjON9c5gGT QqPX18ZPciqLK3V+S4E0gxqMkA03kTlVOTyzr5aC9b6NOkpUy9zfbDCu5oYj/zlQ5dMLt3j2Q0L bd9C8dLn4mNf/Xqm+oVVKjfmTAlExrb6CthKGFXkBR7NLVpTv0SQbP9FEmZT9lwiCceExChsSfo 93lA3lYoNBn1qnxZ6QMk3pJOyzDEH0egLAKFcFmMuCfeM7BW8OmNr19N8g8j2UepiysIRvgeY0A qLiZrsiftSf7bxRWeYSeBzEI19xgcV8v2KSk/hhKenNipx7H6Rz3mc4Vux9gIM+ X-Received: by 2002:a05:6000:4010:b0:485:9393:76d5 with SMTP id ffacd0b85a97d-48593937803mr11916473f8f.18.1788788151846; Mon, 07 Sep 2026 06:35:51 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-48588394fa1sm27523836f8f.8.2026.09.07.06.35.51 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 07 Sep 2026 06:35:51 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][scarthgap 02/35] python3-idna: Fix CVE-2026-45409 Date: Mon, 7 Sep 2026 15:34:58 +0200 Message-ID: <09773d9d1b44dfe868913b6bb142a728529f62cb.1788787321.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Mon, 07 Sep 2026 13:36:04 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/245260 From: Hetvi Thakar This patch applies the complete upstream fix chain for CVE-2026-45409. Commit [1] introduces early domain-length rejection required by [2]. Commit [2] is the v3.14 fix identified by [5], and commit [3] extends the protection to per-label conversions and codec support to complete the v3.15 fix described in [4]. [1] https://github.com/kjd/idna/commit/c0dda4501df5 [2] https://github.com/kjd/idna/commit/628fef84d3ed [3] https://github.com/kjd/idna/commit/e1cb465b6376 [4] https://github.com/kjd/idna/security/advisories/GHSA-65pc-fj4g-8rjx [5] https://security-tracker.debian.org/tracker/CVE-2026-45409 Signed-off-by: Hetvi Thakar Signed-off-by: Yoann Congal --- .../python3-idna/CVE-2026-45409_p1.patch | 75 +++++++++++++++++++ .../python3-idna/CVE-2026-45409_p2.patch | 48 ++++++++++++ .../python3-idna/CVE-2026-45409_p3.patch | 72 ++++++++++++++++++ .../python/python3-idna_3.7.bb | 5 ++ 4 files changed, 200 insertions(+) create mode 100644 meta/recipes-devtools/python/python3-idna/CVE-2026-45409_p1.patch create mode 100644 meta/recipes-devtools/python/python3-idna/CVE-2026-45409_p2.patch create mode 100644 meta/recipes-devtools/python/python3-idna/CVE-2026-45409_p3.patch diff --git a/meta/recipes-devtools/python/python3-idna/CVE-2026-45409_p1.patch b/meta/recipes-devtools/python/python3-idna/CVE-2026-45409_p1.patch new file mode 100644 index 00000000000..02a8090b841 --- /dev/null +++ b/meta/recipes-devtools/python/python3-idna/CVE-2026-45409_p1.patch @@ -0,0 +1,75 @@ +From b34cd8399981324b361ae4f2b8e0eb77444ae0e3 Mon Sep 17 00:00:00 2001 +From: Kim Davies +Date: Sun, 10 May 2026 08:47:22 -0700 +Subject: [PATCH 1/3] Merge commit from fork + +CVE: CVE-2026-45409 +Upstream-Status: Backport [https://github.com/kjd/idna/commit/c0dda4501df5d91c3181ce6f962dc5de74e82cc1] + +Backport Changes: +- Omit the HISTORY.rst hunk because it documents the upstream 3.14 + release and is not applicable to the Scarthgap 3.7 source. + +(cherry picked from commit c0dda4501df5d91c3181ce6f962dc5de74e82cc1) +Signed-off-by: Hetvi Thakar +--- + idna/core.py | 14 ++++++++++++++ + tests/test_idna.py | 13 +++++++++++++ + 2 files changed, 27 insertions(+) + +diff --git a/idna/core.py b/idna/core.py +index 0dae61a..a549326 100644 +--- a/idna/core.py ++++ b/idna/core.py +@@ -340,6 +340,15 @@ def encode(s: Union[str, bytes, bytearray], strict: bool = False, uts46: bool = + raise IDNAError('should pass a unicode string to the function rather than a byte string.') + if uts46: + s = uts46_remap(s, std3_rules, transitional) ++ ++ # Reject inputs that exceed the maximum DNS domain length up-front. ++ # Each codepoint in a U-label contributes at least one octet to its ++ # A-label form, so any input longer than the domain limit cannot ++ # produce a valid A-domain. Short-circuiting here prevents per-label ++ # validation from being driven into quadratic time ++ if len(s) > 254: ++ raise IDNAError("Domain too long") ++ + trailing_dot = False + result = [] + if strict: +@@ -373,6 +382,11 @@ def decode(s: Union[str, bytes, bytearray], strict: bool = False, uts46: bool = + raise IDNAError('Invalid ASCII in A-label') + if uts46: + s = uts46_remap(s, std3_rules, False) ++ # See encode() for rationale; the same bound applies because every ++ # legal A-domain is at most 254 octets and every codepoint of a ++ # legal U-domain contributes at least one octet to its A-form. ++ if len(s) > 254: ++ raise IDNAError("Domain too long") + trailing_dot = False + result = [] + if not strict: +diff --git a/tests/test_idna.py b/tests/test_idna.py +index 81afb32..5001b48 100755 +--- a/tests/test_idna.py ++++ b/tests/test_idna.py +@@ -78,6 +78,19 @@ class IDNATests(unittest.TestCase): + self.assertFalse(idna.valid_label_length('a' * 64)) + self.assertRaises(idna.IDNAError, idna.encode, 'a' * 64) + ++ def test_oversized_input_rejected_promptly(self): ++ # GHSA-65pc-fj4g-8rjx: encode/decode must reject inputs that ++ # exceed the maximum DNS domain length before per-codepoint ++ # validation runs, so labels dominated by CONTEXTO codepoints ++ # cannot drive validation into quadratic time. ++ import time ++ ++ for payload in ("٠" * 8000, "・" * 8000 + "漢"): ++ start = time.perf_counter() ++ self.assertRaises(idna.IDNAError, idna.encode, payload) ++ self.assertRaises(idna.IDNAError, idna.decode, payload) ++ self.assertLess(time.perf_counter() - start, 1.0) ++ + def test_check_bidi(self): + + l = '\u0061' diff --git a/meta/recipes-devtools/python/python3-idna/CVE-2026-45409_p2.patch b/meta/recipes-devtools/python/python3-idna/CVE-2026-45409_p2.patch new file mode 100644 index 00000000000..a79e1e9c203 --- /dev/null +++ b/meta/recipes-devtools/python/python3-idna/CVE-2026-45409_p2.patch @@ -0,0 +1,48 @@ +From fabb538f1885a135e48a60de2e3c656d965e861d Mon Sep 17 00:00:00 2001 +From: Kim Davies +Date: Sun, 10 May 2026 12:44:47 -0700 +Subject: [PATCH 2/3] Use valid_string_length() for early oversized-input check + +CVE: CVE-2026-45409 +Upstream-Status: Backport [https://github.com/kjd/idna/commit/628fef84d3eda59321c21127e73dcd873db23ead] + +(cherry picked from commit 628fef84d3eda59321c21127e73dcd873db23ead) +Signed-off-by: Hetvi Thakar +--- + idna/core.py | 16 ++++++---------- + 1 file changed, 6 insertions(+), 10 deletions(-) + +diff --git a/idna/core.py b/idna/core.py +index a549326..4a9fc75 100644 +--- a/idna/core.py ++++ b/idna/core.py +@@ -341,12 +341,9 @@ def encode(s: Union[str, bytes, bytearray], strict: bool = False, uts46: bool = + if uts46: + s = uts46_remap(s, std3_rules, transitional) + +- # Reject inputs that exceed the maximum DNS domain length up-front. +- # Each codepoint in a U-label contributes at least one octet to its +- # A-label form, so any input longer than the domain limit cannot +- # produce a valid A-domain. Short-circuiting here prevents per-label +- # validation from being driven into quadratic time +- if len(s) > 254: ++ # Reject inputs that exceed the maximum DNS domain length up-front ++ # to avoid expensive computation on long inputs. ++ if not valid_string_length(s, trailing_dot=True): + raise IDNAError("Domain too long") + + trailing_dot = False +@@ -382,10 +379,9 @@ def decode(s: Union[str, bytes, bytearray], strict: bool = False, uts46: bool = + raise IDNAError('Invalid ASCII in A-label') + if uts46: + s = uts46_remap(s, std3_rules, False) +- # See encode() for rationale; the same bound applies because every +- # legal A-domain is at most 254 octets and every codepoint of a +- # legal U-domain contributes at least one octet to its A-form. +- if len(s) > 254: ++ # Reject inputs that exceed the maximum DNS domain length up-front ++ # to avoid expensive computation on long inputs. ++ if not valid_string_length(s, trailing_dot=True): + raise IDNAError("Domain too long") + trailing_dot = False + result = [] diff --git a/meta/recipes-devtools/python/python3-idna/CVE-2026-45409_p3.patch b/meta/recipes-devtools/python/python3-idna/CVE-2026-45409_p3.patch new file mode 100644 index 00000000000..2ebbd5c13de --- /dev/null +++ b/meta/recipes-devtools/python/python3-idna/CVE-2026-45409_p3.patch @@ -0,0 +1,72 @@ +From 22acbaae97c3698005e69555eb4ebccc168b2fff Mon Sep 17 00:00:00 2001 +From: metsw24-max +Date: Mon, 11 May 2026 20:59:30 +0530 +Subject: [PATCH 3/3] Enforce early length limits in check_label + +CVE: CVE-2026-45409 +Upstream-Status: Backport [https://github.com/kjd/idna/commit/e1cb465b6376f33306a26f467d197edbcd01c4b9] + +(cherry picked from commit e1cb465b6376f33306a26f467d197edbcd01c4b9) +Signed-off-by: Hetvi Thakar +--- + idna/core.py | 11 +++++++++++ + tests/test_idna.py | 24 ++++++++++++++++++++++++ + 2 files changed, 35 insertions(+) + +diff --git a/idna/core.py b/idna/core.py +index 4a9fc75..26bb9fa 100644 +--- a/idna/core.py ++++ b/idna/core.py +@@ -230,6 +230,17 @@ def check_label(label: Union[str, bytes, bytearray]) -> None: + label = label.decode('utf-8') + if len(label) == 0: + raise IDNAError('Empty Label') ++ # Reject oversized labels before per-codepoint validation runs. ++ # CONTEXTJ/CONTEXTO checks scan the whole label per codepoint, so an ++ # uncapped label drives validation into quadratic time ++ # (GHSA-65pc-fj4g-8rjx / CVE-2024-3651). encode()/decode() cap the ++ # whole-domain length; this cap protects direct callers of ++ # alabel/ulabel/check_label and the idna2008 incremental codec. ++ # Use the whole-domain bound rather than the per-label DNS bound so ++ # that UTS #46 lenient decoding of labels longer than 63 chars is ++ # preserved. ++ if not valid_string_length(label, trailing_dot=True): ++ raise IDNAError("Label too long") + + check_nfc(label) + check_hyphen_ok(label) +diff --git a/tests/test_idna.py b/tests/test_idna.py +index 5001b48..2dc0892 100755 +--- a/tests/test_idna.py ++++ b/tests/test_idna.py +@@ -91,6 +91,30 @@ class IDNATests(unittest.TestCase): + self.assertRaises(idna.IDNAError, idna.decode, payload) + self.assertLess(time.perf_counter() - start, 1.0) + ++ def test_oversized_label_rejected_promptly(self): ++ # The whole-domain cap in encode()/decode() does not cover direct ++ # callers of alabel/ulabel/check_label, nor the idna2008 ++ # incremental codec which calls alabel/ulabel per label. Without a ++ # per-label cap, a single oversized CONTEXTO-heavy label still ++ # drives validation into quadratic time. ++ import codecs ++ import time ++ ++ import idna.codec # noqa: F401 (register the idna2008 codec) ++ ++ payload = "・" * 8000 + "漢" ++ start = time.perf_counter() ++ self.assertRaises(idna.IDNAError, idna.check_label, payload) ++ self.assertRaises(idna.IDNAError, idna.alabel, payload) ++ self.assertRaises(idna.IDNAError, idna.ulabel, payload) ++ self.assertRaises( ++ idna.IDNAError, ++ codecs.getincrementalencoder("idna2008")().encode, ++ payload, ++ True, ++ ) ++ self.assertLess(time.perf_counter() - start, 1.0) ++ + def test_check_bidi(self): + + l = '\u0061' diff --git a/meta/recipes-devtools/python/python3-idna_3.7.bb b/meta/recipes-devtools/python/python3-idna_3.7.bb index e4213be5dfc..f8ca3df4f5f 100644 --- a/meta/recipes-devtools/python/python3-idna_3.7.bb +++ b/meta/recipes-devtools/python/python3-idna_3.7.bb @@ -3,6 +3,11 @@ HOMEPAGE = "https://github.com/kjd/idna" LICENSE = "BSD-3-Clause & Python-2.0 & Unicode-TOU" LIC_FILES_CHKSUM = "file://LICENSE.md;md5=204c0612e40a4dd46012a78d02c80fb1" +SRC_URI += " \ + file://CVE-2026-45409_p1.patch \ + file://CVE-2026-45409_p2.patch \ + file://CVE-2026-45409_p3.patch \ +" SRC_URI[sha256sum] = "028ff3aadf0609c1fd278d8ea3089299412a7a8b9bd005dd08b9f8285bcb5cfc" CVE_PRODUCT = "kjd:idna kjd:internationalized_domain_names_in_applications" From patchwork Mon Sep 7 13:34:59 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 97544 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 7D3E8C79FB1 for ; Mon, 7 Sep 2026 13:36:04 +0000 (UTC) Received: from mail-wr1-f54.google.com (mail-wr1-f54.google.com [209.85.221.54]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.34911.1788788154510097985 for ; Mon, 07 Sep 2026 06:35:54 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=XoduwlXg; spf=pass (domain: smile.fr, ip: 209.85.221.54, mailfrom: yoann.congal@smile.fr) Received: by mail-wr1-f54.google.com with SMTP id ffacd0b85a97d-484362f5c4aso4504515f8f.3 for ; Mon, 07 Sep 2026 06:35:54 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1788788153; x=1789392953; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=wPaCdSDPXSh4aYL7qq+zwwnXq9nOwriOhH57xaEmCmM=; b=XoduwlXgCX3MRTppLTtPGVOOObYi19Yfga8uD2Dc/b3ShptZHaPvin49reQBsyBHTv +Dj88uQWJr+x0H7wckkHFy6oFl13Sn82Kyufbr8yLOa5mDjPh0IqVLLB9oquqWxUxUIh PCp1OZHOBA9XJhI4XP8JEwCaALAc+7H50I4Vw= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1788788153; x=1789392953; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=wPaCdSDPXSh4aYL7qq+zwwnXq9nOwriOhH57xaEmCmM=; b=eTO2v+BoDh+gOOxQL0YXQYpfJkK1uuYsuCaoeakn1wf3WMHn1LIvKtUEySRWF188Td I1t+jZifPpgUdLvn40xv7t8ZTK0uLgm7AtvVtkdIkTKccqKot2OptgBexbrorl80720i Tswkii6Z5aiClT+YbTTnPmDsRKplGklXbL5OtMURkwiEJTfmYkJxNATk8JxWJ3r6aLp4 6UUcKWzphb7Ai0zSy8lhsD5McPJ5oKrPGZ8t8GOvFAQLPeGJPypf/DuAEy85cdy5ELZ8 NTNu9fyRSZo5/da4ZbupXAqs24gmcQNoXiYdFHgp3CdPtaNU2nj39/KQrn4Y03cRlKaK QBdQ== X-Gm-Message-State: AFuF++neS/JIzmX5XFNGrG4uhl6brh3EjTQ26IalA/tY434cf1GW6QaV TTD6dKeXgDd8LkDQW4ymcqJ9MP8GoErHQCn186Jvy8FzMbTgvCCGrHnKmdnDpkU9om4MSwl0IKz kMMCqT8U= X-Gm-Gg: AYBFou0KLY+oczA/qUbo9Y+8Q2aBSLuEyvd8+aUG5Otdq5mimoeHYt3ASTKKX0e3TPV lkNnROIPAOLh7IgCJtUuF1+50WVnN96BcFgwYBnmvqyIn69GRnNepZJHhQuMLrQUsVOkkwd6xfI I2kYSvs6uF5vZ9vT2ezvN+jItLMp/d1CQ9A7WJ3TEnXOWsugE+8oeWhI8q3VmOVfVLDS3puDXWA nE6WOREc2wVlLIa/ZqzuPLbV1lv8f2jbj+lhrBxL/4FBjBwglJ0CnlzH1yMulVdcZZoU6Kla9t0 0rsRGv+fA4lpZmH6YraoophbvvYi0Y/auEjPGcwUx7NyzdIJyR541wVQgKfOmgjZpJz8DN3puuS EYtOd/SYcVqdkarjeCiLnJcHtfV2XW6/MpERy/HrC7s3SX9SMdI/ar5PeUqBoWJ5RPh/w+96HG5 DKVurXwTYmZs4p/G7tLhHMy8pJVWXexobJEmrm3tmlP/5ZxtawwAvWrexuM3kORI757yifpEYWZ XbJ893+Fslz2tXJxHfrcPjcoObZu+MWmPRBj7/uQOiAogFJqJQJunZTr7Mz28iE X-Received: by 2002:a05:6000:491a:b0:47f:9254:d453 with SMTP id ffacd0b85a97d-4858704a9d7mr47047946f8f.8.1788788152655; Mon, 07 Sep 2026 06:35:52 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-48588394fa1sm27523836f8f.8.2026.09.07.06.35.51 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 07 Sep 2026 06:35:52 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][scarthgap 03/35] p11-kit: Fix CVE-2026-13757 Date: Mon, 7 Sep 2026 15:34:59 +0200 Message-ID: <1233224dcb13924b1366775a71fdf0ce72e3a589.1788787321.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Mon, 07 Sep 2026 13:36:04 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/245261 From: Vijay Anusuri Pick patch according to [2] [1] https://nvd.nist.gov/vuln/detail/cve-2026-13757 [2] https://ubuntu.com/security/CVE-2026-13757 Signed-off-by: Vijay Anusuri Signed-off-by: Yoann Congal --- .../p11-kit/files/CVE-2026-13757.patch | 265 ++++++++++++++++++ .../recipes-support/p11-kit/p11-kit_0.25.3.bb | 1 + 2 files changed, 266 insertions(+) create mode 100644 meta/recipes-support/p11-kit/files/CVE-2026-13757.patch diff --git a/meta/recipes-support/p11-kit/files/CVE-2026-13757.patch b/meta/recipes-support/p11-kit/files/CVE-2026-13757.patch new file mode 100644 index 00000000000..2f9aa080bb0 --- /dev/null +++ b/meta/recipes-support/p11-kit/files/CVE-2026-13757.patch @@ -0,0 +1,265 @@ +From 0eedd4ddd7c924f9cbb4ac496b3fda699435c3cf Mon Sep 17 00:00:00 2001 +From: Zoltan Fridrich +Date: Thu, 2 Jul 2026 10:54:47 +0200 +Subject: [PATCH] rpc: add recursion depth limit into RPC attribute parsing + (CVE-2026-13757) + +A DoS was possible when client sent request to a server with deeply +nested attributes causing stack exhaustion on the server. +This patch adds a recursion limit on all server entry points to +prevent such attacks. + +Signed-off-by: Zoltan Fridrich + +Upstream-Status: Backport [import from ubuntu p11-kit_0.25.3-4ubuntu2.2.debian.tar.xz +Upstream commit https://github.com/p11-glue/p11-kit/commit/0eedd4ddd7c924f9cbb4ac496b3fda699435c3cf] +CVE: CVE-2026-13757 +Signed-off-by: Vijay Anusuri +--- + p11-kit/rpc-message.c | 39 +++++++++++++++++++++++++++++++++----- + p11-kit/rpc-message.h | 10 +++++++++- + p11-kit/test-rpc-message.c | 39 ++++++++++++++++++++++++++++++++++++-- + p11-kit/test-rpc.c | 27 ++++++++++++++++++++++++++ + 4 files changed, 107 insertions(+), 8 deletions(-) + +diff --git a/p11-kit/rpc-message.c b/p11-kit/rpc-message.c +index 09d7f33..d6f0aad 100644 +--- a/p11-kit/rpc-message.c ++++ b/p11-kit/rpc-message.c +@@ -903,6 +903,15 @@ map_attribute_to_value_type (CK_ATTRIBUTE_TYPE type) + } + } + ++static bool ++p11_rpc_buffer_get_attribute_array_value_wrapper (p11_buffer *buffer, ++ size_t *offset, ++ void *value, ++ CK_ULONG *value_length) ++{ ++ return p11_rpc_buffer_get_attribute_array_value (buffer, offset, value, value_length, 0); ++} ++ + typedef struct { + p11_rpc_value_type type; + p11_rpc_value_encoder encode; +@@ -912,7 +921,7 @@ typedef struct { + static p11_rpc_attribute_serializer p11_rpc_attribute_serializers[] = { + { P11_RPC_VALUE_BYTE, p11_rpc_buffer_add_byte_value, p11_rpc_buffer_get_byte_value }, + { P11_RPC_VALUE_ULONG, p11_rpc_buffer_add_ulong_value, p11_rpc_buffer_get_ulong_value }, +- { P11_RPC_VALUE_ATTRIBUTE_ARRAY, p11_rpc_buffer_add_attribute_array_value, p11_rpc_buffer_get_attribute_array_value }, ++ { P11_RPC_VALUE_ATTRIBUTE_ARRAY, p11_rpc_buffer_add_attribute_array_value, p11_rpc_buffer_get_attribute_array_value_wrapper }, + { P11_RPC_VALUE_MECHANISM_TYPE_ARRAY, p11_rpc_buffer_add_mechanism_type_array_value, p11_rpc_buffer_get_mechanism_type_array_value }, + { P11_RPC_VALUE_DATE, p11_rpc_buffer_add_date_value, p11_rpc_buffer_get_date_value }, + { P11_RPC_VALUE_BYTE_ARRAY, p11_rpc_buffer_add_byte_array_value, p11_rpc_buffer_get_byte_array_value } +@@ -1142,7 +1151,8 @@ bool + p11_rpc_buffer_get_attribute_array_value (p11_buffer *buffer, + size_t *offset, + void *value, +- CK_ULONG *value_length) ++ CK_ULONG *value_length, ++ size_t depth) + { + uint32_t count, i; + CK_ATTRIBUTE *attr, temp; +@@ -1157,7 +1167,7 @@ p11_rpc_buffer_get_attribute_array_value (p11_buffer *buffer, + attr = value; + + for (i = 0; i < count; i++) { +- if (!p11_rpc_buffer_get_attribute (buffer, offset, attr)) ++ if (!p11_rpc_buffer_get_attribute_recursive (buffer, offset, attr, depth)) + return false; + if (value) + attr++; +@@ -1255,12 +1265,26 @@ bool + p11_rpc_buffer_get_attribute (p11_buffer *buffer, + size_t *offset, + CK_ATTRIBUTE *attr) ++{ ++ return p11_rpc_buffer_get_attribute_recursive (buffer, offset, attr, 0); ++} ++ ++bool ++p11_rpc_buffer_get_attribute_recursive (p11_buffer *buffer, ++ size_t *offset, ++ CK_ATTRIBUTE *attr, ++ size_t depth) + { + uint32_t type, length, decode_length; + unsigned char validity; + p11_rpc_attribute_serializer *serializer; + p11_rpc_value_type value_type; + ++ if (depth > P11_RPC_MAX_RECURSION_DEPTH) { ++ p11_debug ("recursion depth limit reached"); ++ return false; ++ } ++ + /* The attribute type */ + if (!p11_rpc_buffer_get_uint32 (buffer, offset, &type)) + return false; +@@ -1284,8 +1308,13 @@ p11_rpc_buffer_get_attribute (p11_buffer *buffer, + assert (value_type < ELEMS (p11_rpc_attribute_serializers)); + serializer = &p11_rpc_attribute_serializers[value_type]; + assert (serializer != NULL); +- if (!serializer->decode (buffer, offset, attr->pValue, &attr->ulValueLen)) +- return false; ++ if (value_type == P11_RPC_VALUE_ATTRIBUTE_ARRAY) { ++ if (!p11_rpc_buffer_get_attribute_array_value (buffer, offset, attr->pValue, &attr->ulValueLen, depth + 1)) ++ return false; ++ } else { ++ if (!serializer->decode (buffer, offset, attr->pValue, &attr->ulValueLen)) ++ return false; ++ } + if (!attr->pValue) { + decode_length = attr->ulValueLen; + attr->ulValueLen = length; +diff --git a/p11-kit/rpc-message.h b/p11-kit/rpc-message.h +index f171fc4..671a60d 100644 +--- a/p11-kit/rpc-message.h ++++ b/p11-kit/rpc-message.h +@@ -44,6 +44,8 @@ + #include "pkcs11.h" + #include "pkcs11x.h" + ++#define P11_RPC_MAX_RECURSION_DEPTH 8 ++ + /* The calls, must be in sync with array below */ + enum { + P11_RPC_CALL_ERROR = 0, +@@ -441,6 +443,11 @@ bool p11_rpc_buffer_get_attribute (p11_buffer *buffer, + size_t *offset, + CK_ATTRIBUTE *attr); + ++bool p11_rpc_buffer_get_attribute_recursive (p11_buffer *buffer, ++ size_t *offset, ++ CK_ATTRIBUTE *attr, ++ size_t depth); ++ + void p11_rpc_buffer_add_byte_value (p11_buffer *buffer, + const void *value, + CK_ULONG value_length); +@@ -468,7 +475,8 @@ bool p11_rpc_buffer_get_attribute_array_value + (p11_buffer *buffer, + size_t *offset, + void *value, +- CK_ULONG *value_length); ++ CK_ULONG *value_length, ++ size_t depth); + + void p11_rpc_buffer_add_mechanism_type_array_value + (p11_buffer *buffer, +diff --git a/p11-kit/test-rpc-message.c b/p11-kit/test-rpc-message.c +index 4c11ea5..f00f2f1 100644 +--- a/p11-kit/test-rpc-message.c ++++ b/p11-kit/test-rpc-message.c +@@ -594,11 +594,11 @@ test_attribute_array_value (void) + assert (!p11_buffer_failed (&buffer)); + + offset2 = offset; +- ret = p11_rpc_buffer_get_attribute_array_value(&buffer, &offset, NULL, &val_size); ++ ret = p11_rpc_buffer_get_attribute_array_value(&buffer, &offset, NULL, &val_size, 0); + assert_num_eq (true, ret); + + offset = offset2; +- ret = p11_rpc_buffer_get_attribute_array_value(&buffer, &offset, val, &val_size); ++ ret = p11_rpc_buffer_get_attribute_array_value(&buffer, &offset, val, &val_size, 0); + assert_num_eq (true, ret); + assert_num_eq (val[0].type, CKA_MODIFIABLE); + assert_num_eq (*(CK_BBOOL *)val[0].pValue, CK_TRUE); +@@ -806,6 +806,40 @@ test_message_write (void) + p11_buffer_uninit (&buffer); + } + ++static void ++test_attribute_recursion_limit (void) ++{ ++ bool ret; ++ p11_buffer buffer; ++ size_t offset = 0; ++ CK_BBOOL truev = CK_TRUE; ++ CK_ATTRIBUTE attrs_out; ++ CK_ATTRIBUTE attrs[P11_RPC_MAX_RECURSION_DEPTH + 2]; ++ for (size_t i = 0; i <= P11_RPC_MAX_RECURSION_DEPTH; i++) { ++ attrs[i].type = CKA_WRAP_TEMPLATE; ++ attrs[i].pValue = &attrs[i + 1]; ++ attrs[i].ulValueLen = sizeof (CK_ATTRIBUTE); ++ } ++ attrs[P11_RPC_MAX_RECURSION_DEPTH + 1].type = CKA_ENCRYPT; ++ attrs[P11_RPC_MAX_RECURSION_DEPTH + 1].pValue = &truev; ++ attrs[P11_RPC_MAX_RECURSION_DEPTH + 1].ulValueLen = sizeof (CK_BBOOL); ++ ++ ret = p11_buffer_init (&buffer, 0); ++ assert_num_eq (true, ret); ++ p11_rpc_buffer_add_attribute_array_value (&buffer, attrs, ELEMS(attrs)); ++ assert_num_eq (true, !p11_buffer_failed (&buffer)); ++ ++ /* Skip the array count */ ++ ret = p11_rpc_buffer_get_uint32(&buffer, &offset, NULL); ++ assert_num_eq (true, ret); ++ ++ /* Hit recursion limit */ ++ ret = p11_rpc_buffer_get_attribute(&buffer, &offset, &attrs_out); ++ assert_num_eq (false, ret); ++ ++ p11_buffer_uninit (&buffer); ++} ++ + #include "test-mock.c" + + static CK_MECHANISM_TYPE mechanisms[] = { +@@ -848,6 +882,7 @@ main (int argc, + p11_test (test_byte_array_value, "/rpc-message/byte-array-value"); + p11_test (test_mechanism_value, "/rpc-message/mechanism-value"); + p11_test (test_message_write, "/rpc-message/message-write"); ++ p11_test (test_attribute_recursion_limit, "/rpc-message/attribute-recursion-limit"); + + test_mock_add_tests ("/rpc-message", NULL); + +diff --git a/p11-kit/test-rpc.c b/p11-kit/test-rpc.c +index f214509..6059b89 100644 +--- a/p11-kit/test-rpc.c ++++ b/p11-kit/test-rpc.c +@@ -700,6 +700,32 @@ test_mechanism_unsupported (void *module) + teardown_mock_module (rpc_module); + } + ++static void ++test_recursion_limit (void *module) ++{ ++ CK_FUNCTION_LIST_PTR rpc_module; ++ CK_SESSION_HANDLE session; ++ CK_RV rv; ++ CK_BBOOL val; ++ CK_ATTRIBUTE attrs[P11_RPC_MAX_RECURSION_DEPTH + 2]; ++ for (size_t i = 0; i <= P11_RPC_MAX_RECURSION_DEPTH; i++) { ++ attrs[i].type = CKA_WRAP_TEMPLATE; ++ attrs[i].pValue = &attrs[i + 1]; ++ attrs[i].ulValueLen = sizeof (CK_ATTRIBUTE); ++ } ++ attrs[P11_RPC_MAX_RECURSION_DEPTH + 1].type = CKA_ENCRYPT; ++ attrs[P11_RPC_MAX_RECURSION_DEPTH + 1].pValue = &val; ++ attrs[P11_RPC_MAX_RECURSION_DEPTH + 1].ulValueLen = sizeof (CK_BBOOL); ++ ++ rpc_module = setup_test_rpc_module (&test_normal_vtable, module, &session); ++ ++ /* Hit recursion limit */ ++ rv = (rpc_module->C_GetAttributeValue) (session, MOCK_PUBLIC_KEY_PREFIX, attrs, 1); ++ assert_num_eq (rv, CKR_DEVICE_ERROR); ++ ++ teardown_mock_module (rpc_module); ++} ++ + #ifdef OS_UNIX + + static void +@@ -805,6 +831,7 @@ main (int argc, + p11_testx (test_get_slot_list_no_device, &mock_module_v3_no_slots, "/rpc3/get-slot-list-no-device"); + p11_testx (test_simultaneous_functions, &mock_module_v3_no_slots, "/rpc3/simultaneous-functions"); + p11_testx (test_mechanism_unsupported, &mock_module_v3, "/rpc3/mechanism-unsupported"); ++ p11_testx (test_recursion_limit, &mock_module_v3, "/rpc3/recursion-limit"); + + #ifdef OS_UNIX + p11_testx (test_fork_and_reinitialize, &mock_module_v3_no_slots, "/rpc3/fork-and-reinitialize"); +-- +2.43.0 + diff --git a/meta/recipes-support/p11-kit/p11-kit_0.25.3.bb b/meta/recipes-support/p11-kit/p11-kit_0.25.3.bb index 5921a46c88b..6c5b82e6bc9 100644 --- a/meta/recipes-support/p11-kit/p11-kit_0.25.3.bb +++ b/meta/recipes-support/p11-kit/p11-kit_0.25.3.bb @@ -12,6 +12,7 @@ DEPENDS:append = "${@' glib-2.0' if d.getVar('GTKDOC_ENABLED') == 'True' else '' SRC_URI = "gitsm://github.com/p11-glue/p11-kit;branch=master;protocol=https \ file://fix-parallel-build-failures.patch \ + file://CVE-2026-13757.patch \ " SRCREV = "917e02a3211dabbdea4b079cb598581dce84fda1" S = "${WORKDIR}/git" From patchwork Mon Sep 7 13:35:00 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 97532 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 6B9F2C79FB0 for ; Mon, 7 Sep 2026 13:36:04 +0000 (UTC) Received: from mail-wr1-f52.google.com (mail-wr1-f52.google.com [209.85.221.52]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.34912.1788788154946793998 for ; Mon, 07 Sep 2026 06:35:55 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=R3pXGIvZ; spf=pass (domain: smile.fr, ip: 209.85.221.52, mailfrom: yoann.congal@smile.fr) Received: by mail-wr1-f52.google.com with SMTP id ffacd0b85a97d-4858303de5dso4420596f8f.2 for ; Mon, 07 Sep 2026 06:35:54 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1788788153; x=1789392953; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=x+6t8ZaFdZbzG2cSApYkxSeK0IOMVKmI6B11ZOPBmd4=; b=R3pXGIvZUamiqpTJ6xHZFGypTFeP5F0zXwfGCA05/ur7akr1tNM7PNdzvKX1vb2CHR ucsAM/MJbNKDv/7OWAToFynxAzxW0myROL2maJgJGQ7IjlBWb7mKFMN+ln6JifQCZkLZ +lv1iBeAgR3RD8Yy7LJec2aa0JLP1hk4DlHgI= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1788788153; x=1789392953; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=x+6t8ZaFdZbzG2cSApYkxSeK0IOMVKmI6B11ZOPBmd4=; b=gCSo8tgglq5r37A5aOVp/JPPMp33o3pqUme4XJIAGAlXg4HFosFnI7mhSpNFHkToNX V7DSwx3f785s8/dneziWNrPBuCfWqt8QaZobzrGRgp/E69XQh7iSH6stqRJBLbLpvMsI M1YFolEl3xrVMjgtffGyc83QlJnjr9mMyPAZoNFEFhJwWJ27equr7k2oCtrkK+ZSGKnB 9I9NchxN9fhkQQKiwrBYMhe1Yn5GNebaHIvyfUzGIpZDBPD4a0+M7m410ndvPVA9mk4r qHm9uvFI3EUosxgW/WxpZce6e7/6mkdNrzSHUZSBvs10dudzcuokgHATReAfbGdyNeaO 5yrg== X-Gm-Message-State: AFuF++k7oajpzfVW6bx1ztz4fsieJzX1IUojKY6ErQmYuqfyU5kGBEyT Xwjdx+kc+UKbow8gWiuhBWgBBlzaieCllpgbIcAhKxdFVIn3StVM8XCl3WgJrolcK13iNjGdF0y u3St1kSY= X-Gm-Gg: AYBFou0bZ3/c86yITsTeb9RFl4geH8M08lJ15+PzK6g9HWOmpnXZnisU6jP4dmHkv/k Mk/D3F09mg2QE4Rz6r24jlAvLJ9lsRxiZiW324XpoDbhWdZ3wq02KQr5fx490Z8Bc0OQkdmtIel 7mQ0VLqjVSJ8LpzvK2MvBKffVqaepSYDiQxQWtlerHWy7FlLWI2KGTWxfvk7FaXYonl4l854meM 310KPQyQRzQ3JAdblm12PxyL+yZiHB3oGuPBBqpiHLf5j0vNZx96gyR/k+ahK+1l7drM+5JI7ku QWSyHckfxAd9shZbGdSi5TPOSivYWjQIM55XCbwg4eDyz+9YyZxtlsqCcODr9DqBP1oUNmEivH9 gDpN5r3z05ZFtuzzBrc/pdEmabmBWwvlSEVrlcVKfPFHDowDeWN8noSugkafH14swDVlcfToYTF yXc+lcFOnRZcuYLwxa/bCJiJLZKNVJWrQzKneXRwQFaq+mRoKI+AepETl3KvPyz54VFYNDCqR3a O5dtEQMFOxFOWECx1jmHjH9yFTiGnwyMai2+kbmoRpdaNwMXD5NU7AnE5Gtvwjx X-Received: by 2002:a05:6000:471a:b0:484:3311:3176 with SMTP id ffacd0b85a97d-485872899a7mr25937629f8f.23.1788788153174; Mon, 07 Sep 2026 06:35:53 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-48588394fa1sm27523836f8f.8.2026.09.07.06.35.52 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 07 Sep 2026 06:35:52 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][scarthgap 04/35] util-linux: Fix CVE-2026-3184 Date: Mon, 7 Sep 2026 15:35:00 +0200 Message-ID: <2b3600a80144dcf4ca2632b010c59e8df254a6f9.1788787321.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Mon, 07 Sep 2026 13:36:04 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/245262 From: Jaipaul Cheernam Reference: [1] https://nvd.nist.gov/vuln/detail/CVE-2026-3184 [2] https://github.com/util-linux/util-linux/commit/8b29aeb081e297e48c4c1ac53d88ae07e1331984 Signed-off-by: Jaipaul Cheernam Signed-off-by: Yoann Congal --- meta/recipes-core/util-linux/util-linux.inc | 1 + .../util-linux/util-linux/CVE-2026-3184.patch | 61 +++++++++++++++++++ 2 files changed, 62 insertions(+) create mode 100644 meta/recipes-core/util-linux/util-linux/CVE-2026-3184.patch diff --git a/meta/recipes-core/util-linux/util-linux.inc b/meta/recipes-core/util-linux/util-linux.inc index 753d032976d..f651dc2dab4 100644 --- a/meta/recipes-core/util-linux/util-linux.inc +++ b/meta/recipes-core/util-linux/util-linux.inc @@ -48,6 +48,7 @@ SRC_URI = "${KERNELORG_MIRROR}/linux/utils/util-linux/v${MAJOR_VERSION}/util-lin file://CVE-2025-14104-02.patch \ file://CVE-2026-27456.patch \ file://CVE-2026-13595.patch \ + file://CVE-2026-3184.patch \ " SRC_URI[sha256sum] = "7b6605e48d1a49f43cc4b4cfc59f313d0dd5402fa40b96810bd572e167dfed0f" diff --git a/meta/recipes-core/util-linux/util-linux/CVE-2026-3184.patch b/meta/recipes-core/util-linux/util-linux/CVE-2026-3184.patch new file mode 100644 index 00000000000..6dbfebe4b91 --- /dev/null +++ b/meta/recipes-core/util-linux/util-linux/CVE-2026-3184.patch @@ -0,0 +1,61 @@ +From 3fb64ddbffbc9442dca56eb6d4f263d525708b64 Mon Sep 17 00:00:00 2001 +From: Karel Zak +Date: Thu, 19 Feb 2026 12:20:28 +0100 +Subject: [PATCH] login: use original FQDN for PAM_RHOST + +When login -h is invoked, init_remote_info() strips the +local domain suffix from the hostname (FQDN to short name) before +storing it in cxt->hostname. This truncated value is then used for +PAM_RHOST, which can bypass pam_access host deny rules that match on +the FQDN. + +Preserve the original -h hostname in a new cmd_hostname field and use +it for PAM_RHOST, while keeping the truncated hostname for utmp/wtmp +and logging unchanged. + +Note, the real-world impact is low -- login -h is only used by legacy +telnet/rlogin daemons, and exploitation requires FQDN-specific +pam_access rules on a system still using these obsolete services. + +Reported-by: Asim Viladi Oglu Manizada +Signed-off-by: Karel Zak +(cherry picked from commit 8b29aeb081e297e48c4c1ac53d88ae07e1331984) + +CVE: CVE-2026-3184 +Upstream-Status: Backport [https://github.com/util-linux/util-linux/commit/8b29aeb081e297e48c4c1ac53d88ae07e1331984] + +Signed-off-by: Jaipaul Cheernam +--- + login-utils/login.c | 5 ++++- + 1 file changed, 4 insertions(+), 1 deletion(-) + +diff --git a/login-utils/login.c b/login-utils/login.c +index 321f9d6ce..0c5c805aa 100644 +--- a/login-utils/login.c ++++ b/login-utils/login.c +@@ -128,6 +128,7 @@ struct login_context { + char *thishost; /* this machine */ + char *thisdomain; /* this machine's domain */ + char *hostname; /* remote machine */ ++ char *cmd_hostname; /* remote machine as specified on command line */ + char hostaddress[16]; /* remote address */ + + pid_t pid; +@@ -906,7 +907,7 @@ static pam_handle_t *init_loginpam(struct login_context *cxt) + + /* hostname & tty are either set to NULL or their correct values, + * depending on how much we know. */ +- rc = pam_set_item(pamh, PAM_RHOST, cxt->hostname); ++ rc = pam_set_item(pamh, PAM_RHOST, cxt->cmd_hostname); + if (is_pam_failure(rc)) + loginpam_err(pamh, rc); + +@@ -1249,6 +1250,8 @@ static void init_remote_info(struct login_context *cxt, char *remotehost) + + get_thishost(cxt, &domain); + ++ cxt->cmd_hostname = xstrdup(remotehost); ++ + if (domain && (p = strchr(remotehost, '.')) && + strcasecmp(p + 1, domain) == 0) + *p = '\0'; From patchwork Mon Sep 7 13:35:01 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 97536 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 46733C79FAE for ; Mon, 7 Sep 2026 13:36:04 +0000 (UTC) Received: from mail-wm1-f47.google.com (mail-wm1-f47.google.com [209.85.128.47]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.34915.1788788155783143685 for ; Mon, 07 Sep 2026 06:35:56 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=WRTkhhJu; spf=pass (domain: smile.fr, ip: 209.85.128.47, mailfrom: yoann.congal@smile.fr) Received: by mail-wm1-f47.google.com with SMTP id 5b1f17b1804b1-49b0d78a801so36197875e9.2 for ; Mon, 07 Sep 2026 06:35:55 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1788788154; x=1789392954; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=OtJdt73GnRvVW/GyMU1Gfg48/Zab5ZYOQ5Yb/BZIlRQ=; b=WRTkhhJuVWiUVsPrwLfUV2XBwxb8+GkCalUytkC0k44he/gBUXamS+Hwit/edjCnTM lYho6YLXLplO4Pp/k8K6Ns6M/jrDebDvZzca3VaQq/S/GeCCGrN/cYfm2HC80WAefoqa XgDmHDUTTpve56mKge/hfwoHeM9quA7k0TgaU= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1788788154; x=1789392954; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=OtJdt73GnRvVW/GyMU1Gfg48/Zab5ZYOQ5Yb/BZIlRQ=; b=N2ZGupNUR+20MoRFSGSM6tpxzFtXnDT++D3UB2F0/e3dIwAXNHdijFdsCl1tHCldH0 K8TMXgyxpJhEkC55C3i1dmZQkbdkSGNwnomgl87MgLnKvXhd/EwmmHwwIRi9BnFJP9TV ybneTvbFZRpdTKAbYvEUrlOm+OsIZY8byCMvJNHjkXvxeX6Pon6gYIeum8tumj9EJY8m vTlUCjBO5YnXeeVTywWiKbJUg1zks/8B+2oVDcjmGpdlTZUtBNhUu4QtLym0vKnN5KVR wVV+ASK+dpKN8v06kuP3IIkz64VTl9mnjgoRV0kTkmP1nF2GJZahYxwhUeOXbfNWgSGr efMg== X-Gm-Message-State: AFuF++lg7fzWrIW8C6deDI4DEaRJCD1vYjxRkOp6NhzgqpzqrJXXFFS4 Mp261M+Ir/27WU1xwFBsEXWmt904bqqAa7aN9d9VsyDtZUdffABzo5cvOibmrNGd3kbG+tPd4zG A6AlIpQU= X-Gm-Gg: AYBFou1u38VK/R9kCOJpHIPKXl8yuv/kXj57oDabYcZkQQnE+3r2JIH2Tmm352R+yn0 pRfqtT3wIANI+jfn9CPIIexMsYjcyMumCY1XIRGKwlqAg2lHLQV40OOI7Gn1qgVtmShNHeFa5PZ OKtDHGIU/Eu1AH26qwkm9mSBpy7xFi45Ogx3J4ZTNdirKDfIXIoOB/adgePhOQBCPGs1/4JA2O2 /AIKkmS8Ccc+tXs6vadOFbxozyA8ZIdtwfboZ+0socTzg6tUGsU0EDBXCyoDQUx1kYWv1rR7iHC buASk6+s7HJGAccZzluv7YiStviv8bzQYiD49Xe3BGnBfJuat0ej5s6MnB49jDUehBlCjwERZAW /+6beVhub3T7auXzTpjqvsvYj4wgXpBSeqUg0a/o0WWoHp9T07ny/o4cuTEMk0Rpwv0ZNJdU+pi OEJxBVwguoAt5UnU9LyGzUez1Fs+/95SE2tGHUQEuRewxKeIhTOnPG9Who5p0YPXdoLpRHbx80s tf5NUMXTc4Q9eE/Cd4O0OdCgWjuj1oOyn9lwn4mlRtzJFjBnHY3c0t+XiuGheNe X-Received: by 2002:a05:600c:b93:b0:49d:17c5:8f7a with SMTP id 5b1f17b1804b1-49d17c58fa8mr1760505e9.18.1788788153621; Mon, 07 Sep 2026 06:35:53 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-48588394fa1sm27523836f8f.8.2026.09.07.06.35.53 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 07 Sep 2026 06:35:53 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][scarthgap 05/35] libxfont2: Fix CVE-2026-56001 Date: Mon, 7 Sep 2026 15:35:01 +0200 Message-ID: <78e09979d47a03846afa7c52758e6f24ac659627.1788787321.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Mon, 07 Sep 2026 13:36:04 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/245263 From: Vijay Anusuri Pick patch according to [2] [1] https://nvd.nist.gov/vuln/detail/CVE-2026-56001 [2] https://security-tracker.debian.org/tracker/CVE-2026-56001 Signed-off-by: Vijay Anusuri Signed-off-by: Yoann Congal --- .../xorg-lib/libxfont2/CVE-2026-56001.patch | 75 +++++++++++++++++++ .../xorg-lib/libxfont2_2.0.6.bb | 3 + 2 files changed, 78 insertions(+) create mode 100644 meta/recipes-graphics/xorg-lib/libxfont2/CVE-2026-56001.patch diff --git a/meta/recipes-graphics/xorg-lib/libxfont2/CVE-2026-56001.patch b/meta/recipes-graphics/xorg-lib/libxfont2/CVE-2026-56001.patch new file mode 100644 index 00000000000..831547df296 --- /dev/null +++ b/meta/recipes-graphics/xorg-lib/libxfont2/CVE-2026-56001.patch @@ -0,0 +1,75 @@ +From be0b08e2d354138d3222b4490e2a77c6ee42f778 Mon Sep 17 00:00:00 2001 +From: Peter Hutterer +Date: Mon, 1 Jun 2026 16:46:10 +1000 +Subject: [PATCH] bitscale: fix integer overflow in BitmapScaleBitmaps + bytestoalloc + +bytestoalloc is declared as unsigned int (32-bit). When the sum of +per-glyph byte counts exceeds 2^32, the value wraps around and calloc() +allocates a buffer that is too small. The subsequent ScaleBitmap loop +then writes past the end of the allocated buffer. + +Change bytestoalloc from unsigned int to size_t to match the actual +allocation size type, and add an explicit overflow check in the +accumulation loop to bail out if the total would exceed SIZE_MAX. + +This vulnerability was discovered by: +Anonymous working with TrendAI Zero Day Initiative + +CVE-2026-56001/ZDI-CAN-30558 + +Assisted-by: Claude:claude-opus-4-6 +Signed-off-by: Peter Hutterer +Part-of: + +Upstream-Status: Backport [https://gitlab.freedesktop.org/xorg/lib/libxfont/-/commit/be0b08e2d354138d3222b4490e2a77c6ee42f778] +CVE: CVE-2026-56001 +Signed-off-by: Vijay Anusuri +--- + src/bitmap/bitscale.c | 23 ++++++++++++++++++++--- + 1 file changed, 20 insertions(+), 3 deletions(-) + +diff --git a/src/bitmap/bitscale.c b/src/bitmap/bitscale.c +index e29ba96..7100138 100644 +--- a/src/bitmap/bitscale.c ++++ b/src/bitmap/bitscale.c +@@ -1460,7 +1460,7 @@ BitmapScaleBitmaps(FontPtr pf, /* scaled font */ + opci; + FontInfoPtr pfi; + int glyph; +- unsigned bytestoalloc = 0; ++ size_t bytestoalloc = 0; + int firstCol, lastCol, firstRow, lastRow; + + double xform[4], inv_xform[4]; +@@ -1487,8 +1487,25 @@ BitmapScaleBitmaps(FontPtr pf, /* scaled font */ + glyph = pf->glyph; + for (i = 0; i < nchars; i++) + { +- if ((pci = ACCESSENCODING(bitmapFont->encoding, i))) +- bytestoalloc += BYTES_FOR_GLYPH(pci, glyph); ++ if ((pci = ACCESSENCODING(bitmapFont->encoding, i))) { ++ size_t glyphsize = BYTES_FOR_GLYPH(pci, glyph); ++ if (bytestoalloc > SIZE_MAX - glyphsize) { ++ fprintf(stderr, ++ "Error: bitmap allocation overflow for scaled font\n"); ++ goto bail; ++ } ++ bytestoalloc += glyphsize; ++ } ++ } ++ ++ /* Reject unreasonably large bitmap allocations that could result ++ * from malicious fonts with extreme scale factors. 256 MiB is ++ * far beyond any legitimate scaled bitmap font. */ ++#define BITMAP_SCALE_MAX_ALLOC (256 * 1024 * 1024) ++ if (bytestoalloc > BITMAP_SCALE_MAX_ALLOC) { ++ fprintf(stderr, ++ "Error: scaled bitmap size %zu exceeds limit\n", bytestoalloc); ++ goto bail; + } + + /* Do we add the font malloc stuff for VALUE ADDED ? */ +-- +2.43.0 + diff --git a/meta/recipes-graphics/xorg-lib/libxfont2_2.0.6.bb b/meta/recipes-graphics/xorg-lib/libxfont2_2.0.6.bb index 535e7f629ee..1a0eb42681d 100644 --- a/meta/recipes-graphics/xorg-lib/libxfont2_2.0.6.bb +++ b/meta/recipes-graphics/xorg-lib/libxfont2_2.0.6.bb @@ -15,6 +15,9 @@ XORG_PN = "libXfont2" BBCLASSEXTEND = "native" +SRC_URI += "file://CVE-2026-56001.patch \ + " + SRC_URI[sha256sum] = "74ca20017eb0fb3f56d8d5e60685f560fc85e5ff3d84c61c4cb891e40c27aef4" PACKAGECONFIG ??= "${@bb.utils.filter('DISTRO_FEATURES', 'ipv6', d)}" From patchwork Mon Sep 7 13:35:02 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 97537 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id C7E15C79FB3 for ; Mon, 7 Sep 2026 13:36:04 +0000 (UTC) Received: from mail-wr1-f47.google.com (mail-wr1-f47.google.com [209.85.221.47]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.34917.1788788156193544416 for ; Mon, 07 Sep 2026 06:35:56 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=epl/Zsum; spf=pass (domain: smile.fr, ip: 209.85.221.47, mailfrom: yoann.congal@smile.fr) Received: by mail-wr1-f47.google.com with SMTP id ffacd0b85a97d-4843e397f74so4423639f8f.1 for ; Mon, 07 Sep 2026 06:35:55 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1788788154; x=1789392954; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=OHzutiS+Hcrbf9ghL+IcLImaWK37ghlcxIsKsOjjIRE=; b=epl/Zsum6pzi0P2bT65MzlwHcvMxWFi/ywHYyy+6ihcSjs4fgleBUlqQ2jHLSU9Pl6 a8Z6TGF/4gmTqCtQZuC7ZtCQXmqlQ2fXBP0qdrjfOLE/ZqDSHWpzIht2/PYWV07rw1g8 DBzFf4afTB21h2xKlZ4ULMAFhk0pF4O7zv0yM= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1788788154; x=1789392954; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=OHzutiS+Hcrbf9ghL+IcLImaWK37ghlcxIsKsOjjIRE=; b=KD96Y66NIK2f4XAPOTqPDalPAeRPbZkavxknrcsL/p3QWE/UIBH54K9J/NeyoIG58o z4wEU7Luc3BaYcheA6e4xk2STf60SGcXnJ1PPc3NGFRJXHIo15hfOVl//vdUwv5Ab1Qn 1NYW3y4PdOPnLAYWrG9G5jcu/pgjO8MgE2tOxUJUHFiYofMbwH2oRv08syw57QrNA4WE uXxUQjv5ZC4SIs/tchHS9L1MUKUn58uzAPPyhLaHeofwxsO4w1iBmTA4CY78csvg8EVO IlpxYyG4qxyml+NgtLqaULD4Ya3EuDMqDqJC4GSe/0oyLS0PLwDQWN5dpfz6Bj4xbdOJ 6LSQ== X-Gm-Message-State: AFuF++mKyTvhMxmOdOvn4f7SZT3QmULHetLofSNcfPpdrpVpncXZt2MP 7T+mhJVd5bCnqFMsUWIR3lhf47TuaBsr0ZFben0GcCpOT7wNI0AHmfFJOxRdLOLRDPjZKT5Pkkg ONxGlcC8= X-Gm-Gg: AYBFou16wWay6Jtke4xqn9UWXdrAUQrpVa4xtcXp0Vp228mi8o0vdYjRDiuyEAhbpQA Ssd7p7+tZBym0HAt8Xf9ZZZjQEZ/f0kufmaxjwBq7xOra70+xPCPDaZl8QBiBOzb4F3xO/M6Tbg u9X8UcyTKOjbLKzCGCW5jNPzmtM81fUqoxaGWJIozZ7XVLWI21mn6HUX+A/sbOhSh7LYZKELDOX Uq2n6kgBXmFXZYtCyJQVjxYqilatIFn8zvYGFX/CWZexLjJEBghLUQW3Dkko4H/rBmUJpuJlfsn 24PThSIC7ORL6Ao3Z3K07jZL/FCaEtGLt07X1c//qTQzl4Ov79f6FPKxZ6skM3NmNAxKsUlLyh/ O4DAsUtbhr1OGDmoRJfepyAzvTwbumRhz9kXNliocCDUbWtIihGbzpeNyw9QKfqESpAkZwBy0g+ bLKIGOHymqnxCThS9hXR/RzU30P21ZE6/P94YPbNsS/D9FovwXwLyKOV/jNscrwHBzUtlDREmKz AmB/XN5ZT1dpNMlm7IUEZv5SSRpAQRVn3t0/c/2v4/kIGWFlaed3x58H6/vCYTp X-Received: by 2002:a05:6000:460f:b0:485:8226:c69e with SMTP id ffacd0b85a97d-4858226c95cmr31169257f8f.29.1788788154403; Mon, 07 Sep 2026 06:35:54 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-48588394fa1sm27523836f8f.8.2026.09.07.06.35.53 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 07 Sep 2026 06:35:53 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][scarthgap 06/35] libxfont2: Fix CVE-2026-56002 Date: Mon, 7 Sep 2026 15:35:02 +0200 Message-ID: <1b47a4e636bbda15b00379ac7a732ffade7a6274.1788787321.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Mon, 07 Sep 2026 13:36:04 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/245264 From: Vijay Anusuri Pick patch according to [2] [1] https://nvd.nist.gov/vuln/detail/CVE-2026-56002 [2] https://security-tracker.debian.org/tracker/CVE-2026-56002 Signed-off-by: Vijay Anusuri Signed-off-by: Yoann Congal --- .../xorg-lib/libxfont2/CVE-2026-56002.patch | 138 ++++++++++++++++++ .../xorg-lib/libxfont2_2.0.6.bb | 1 + 2 files changed, 139 insertions(+) create mode 100644 meta/recipes-graphics/xorg-lib/libxfont2/CVE-2026-56002.patch diff --git a/meta/recipes-graphics/xorg-lib/libxfont2/CVE-2026-56002.patch b/meta/recipes-graphics/xorg-lib/libxfont2/CVE-2026-56002.patch new file mode 100644 index 00000000000..c0fbb008622 --- /dev/null +++ b/meta/recipes-graphics/xorg-lib/libxfont2/CVE-2026-56002.patch @@ -0,0 +1,138 @@ +From b4389e0b1d84a690b819bb27b1439968811a3674f Mon Sep 17 00:00:00 2001 +From: Peter Hutterer +Date: Mon, 1 Jun 2026 16:48:40 +1000 +Subject: [PATCH] pcfread: validate bitmap sizes and offsets against per-glyph + metrics + +pcfReadFont() uses bitmapSizes[] read directly from the PCF file to +allocate the repadded bitmap buffer. However, per-glyph metrics (also +from the file) control how much data RepadBitmap() writes. A malicious +PCF font can declare a small bitmapSizes[] value while having per-glyph +metrics that require more space, causing a heap buffer overflow. + +A similar issue happens with the encoding offsets: pcfReadFont reads +encoding offsets from the PCF file and uses them to index into the +metrics array without bounds checking. A crafted font can set an +encoding offset larger than nmetrics, causing an out-of-bounds pointer +that is later dereferenced when glyphs are accessed through the encoding +table. + +And the no-repad bitmap path (when PCF_GLYPH_PAD matches the requested +glyph pad) only validated that each glyph's offset was within the bitmap +buffer, but did not check that the full glyph extent (offset + +BYTES_PER_ROW * height) fits within the buffer. A crafted font with a +glyph offset near the end of a small bitmap buffer but large glyph +metrics causes a heap buffer over-read when the glyph is later rendered. + +This vulnerability was discovered by: + Anonymous working with TrendAI Zero Day Initiative + +CVE-2026-56002/ZDI-CAN-30559 + +Assisted-by: Claude:claude-opus-4-6 +Signed-off-by: Peter Hutterer +Part-of: + +Upstream-Status: Backport [https://gitlab.freedesktop.org/xorg/lib/libxfont/-/commit/b4389e0b1d84a690b819bb27b1439968811a3674] +CVE: CVE-2026-56002 +Signed-off-by: Vijay Anusuri +--- + src/bitmap/pcfread.c | 59 +++++++++++++++++++++++++++++++++++++++++--- + 1 file changed, 56 insertions(+), 3 deletions(-) + +diff --git a/src/bitmap/pcfread.c b/src/bitmap/pcfread.c +index 882318b..bcb82b8 100644 +--- a/src/bitmap/pcfread.c ++++ b/src/bitmap/pcfread.c +@@ -531,25 +531,74 @@ pcfReadFont(FontPtr pFont, FontFilePtr file, + int old, + new; + xCharInfo *metric; ++ int srcPad = PCF_GLYPH_PAD(format); + +- sizepadbitmaps = bitmapSizes[PCF_SIZE_TO_INDEX(glyph)]; +- padbitmaps = malloc(sizepadbitmaps); ++ /* Compute the actual required size from per-glyph metrics instead ++ * of trusting the file's bitmapSizes[] value, which may be smaller ++ * than the actual data written by RepadBitmap. */ ++ sizepadbitmaps = 0; ++ for (i = 0; i < nbitmaps; i++) { ++ int w, h, glyphBytes; ++ metric = &metrics[i].metrics; ++ w = metric->rightSideBearing - metric->leftSideBearing; ++ h = metric->ascent + metric->descent; ++ glyphBytes = BYTES_PER_ROW(w, glyph) * h; ++ if (glyphBytes < 0 || (glyphBytes > 0 && sizepadbitmaps > INT_MAX - glyphBytes)) { ++ pcfError("pcfReadFont(): bitmap size overflow\n"); ++ goto Bail; ++ } ++ sizepadbitmaps += glyphBytes; ++ } ++ padbitmaps = malloc(sizepadbitmaps ? sizepadbitmaps : 1); + if (!padbitmaps) { + pcfError("pcfReadFont(): Couldn't allocate padbitmaps (%d)\n", sizepadbitmaps); + goto Bail; + } + new = 0; + for (i = 0; i < nbitmaps; i++) { ++ int srcGlyphBytes; ++ + old = offsets[i]; + metric = &metrics[i].metrics; ++ ++ /* Validate source offset and source glyph size against the ++ * source bitmap buffer to prevent out-of-bounds reads. */ ++ srcGlyphBytes = BYTES_PER_ROW( ++ metric->rightSideBearing - metric->leftSideBearing, ++ srcPad) * (metric->ascent + metric->descent); ++ if (old < 0 || old > sizebitmaps || ++ srcGlyphBytes < 0 || srcGlyphBytes > sizebitmaps - old) { ++ pcfError("pcfReadFont(): bitmap offset/size out of bounds\n"); ++ free(padbitmaps); ++ goto Bail; ++ } ++ + offsets[i] = new; + new += RepadBitmap(bitmaps + old, padbitmaps + new, +- PCF_GLYPH_PAD(format), glyph, ++ srcPad, glyph, + metric->rightSideBearing - metric->leftSideBearing, + metric->ascent + metric->descent); + } + free(bitmaps); + bitmaps = padbitmaps; ++ } else { ++ /* Validate offsets and full glyph extents against bitmap buffer */ ++ for (i = 0; i < nbitmaps; i++) { ++ int glyphBytes; ++ xCharInfo *metric = &metrics[i].metrics; ++ ++ glyphBytes = BYTES_PER_ROW( ++ metric->rightSideBearing - metric->leftSideBearing, ++ glyph) * (metric->ascent + metric->descent); ++ if (offsets[i] >= (CARD32)sizebitmaps || ++ glyphBytes < 0 || ++ glyphBytes > sizebitmaps - (int)offsets[i]) { ++ pcfError("pcfReadFont(): bitmap offset/size out of bounds " ++ "(offset %u, size %d, total %d)\n", ++ offsets[i], glyphBytes, sizebitmaps); ++ goto Bail; ++ } ++ } + } + for (i = 0; i < nbitmaps; i++) + metrics[i].bits = bitmaps + offsets[i]; +@@ -624,6 +673,10 @@ pcfReadFont(FontPtr pFont, FontFilePtr file, + if (IS_EOF(file)) goto Bail; + if (encodingOffset == 0xFFFF) { + pFont->info.allExist = FALSE; ++ } else if (encodingOffset >= nmetrics) { ++ pcfError("pcfReadFont(): encoding offset %d out of range (nmetrics=%d)\n", ++ encodingOffset, nmetrics); ++ goto Bail; + } else { + if(!encoding[SEGMENT_MAJOR(i)]) { + encoding[SEGMENT_MAJOR(i)]= +-- +2.43.0 + diff --git a/meta/recipes-graphics/xorg-lib/libxfont2_2.0.6.bb b/meta/recipes-graphics/xorg-lib/libxfont2_2.0.6.bb index 1a0eb42681d..29e4d3298f0 100644 --- a/meta/recipes-graphics/xorg-lib/libxfont2_2.0.6.bb +++ b/meta/recipes-graphics/xorg-lib/libxfont2_2.0.6.bb @@ -16,6 +16,7 @@ XORG_PN = "libXfont2" BBCLASSEXTEND = "native" SRC_URI += "file://CVE-2026-56001.patch \ + file://CVE-2026-56002.patch \ " SRC_URI[sha256sum] = "74ca20017eb0fb3f56d8d5e60685f560fc85e5ff3d84c61c4cb891e40c27aef4" From patchwork Mon Sep 7 13:35:03 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 97535 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id D0936C79FAD for ; Mon, 7 Sep 2026 13:36:03 +0000 (UTC) Received: from mail-wr1-f48.google.com (mail-wr1-f48.google.com [209.85.221.48]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.34918.1788788156754088617 for ; Mon, 07 Sep 2026 06:35:57 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=wu5gj1Jp; spf=pass (domain: smile.fr, ip: 209.85.221.48, mailfrom: yoann.congal@smile.fr) Received: by mail-wr1-f48.google.com with SMTP id ffacd0b85a97d-48442ea8f59so3816707f8f.1 for ; Mon, 07 Sep 2026 06:35:56 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1788788155; x=1789392955; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=g7ejarHAFUsiH/iFGCoSR1x4CDnbVT2akNuYnbPDIcE=; b=wu5gj1Jpn3b61S54OQ0/YLRSE2VjKdB5Mhbyef22d55rP4Y/ivVmtVt9+CrXA8LiBd kR3yGYxEixBzvV9p2tkCuxpkksE/Madmsas9UipUzr9vIRvh7eEJ1clXSXTZgOguILdj 9hejTBJnbSDBUqXmC3afvXUQGiypSs0XqBefE= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1788788155; x=1789392955; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=g7ejarHAFUsiH/iFGCoSR1x4CDnbVT2akNuYnbPDIcE=; b=AzuVViNwcnB6tOhTR5y7nvIvijx3WLUoR4St5e1/xvd8VU+7clnEOa9cvCk4SpOWeh +3rKkeC8InxWsxy/EsDnPTK7dIh+KyVBb/cB4KY15AlF1JXWGhckxl7Xq/m4Q3uOfF3R ccN0CyCSEHFveRNjIcdA2Qq4YwsY7Uu2xt4ldyrsjGHiT8NyKITFqm6YWolbowLmyxIQ FKk7nPbkKVORLLfdcRD6zztocLxDQqU0rs/hgoxDDIGzTl5Rqls3oAJE+b1Yqig+3H4E tigK3KLQgKVnkUWXaXrsDT/OemuW7WSSj1JqdTYeYpUNblvXbwJQXUJQgKs2s0s8KNaG Jj1g== X-Gm-Message-State: AFuF++lsP+1GDNBE62X9z/dqQxKvfYS0WwvaIUlIEGM2gXezwwhWA1vR fyMFaou/CpaYrpG+zUG1ShMyiTBnAWrBtYwfKg/JgPABcvTddQsPs7jGzLXnCtsum4gB2q62N2O /UdYqLKA= X-Gm-Gg: AYBFou0d3dyolI/5N828Ucz2vQpEXaac1gGlnToywY8nli0AAt5sKhrRAUajGYJiQXn pIFrQ2v+66m4x2m7iD0JCzxPWcRw60NK8vSvQ39XQQUNkFp4tkTSZ7nJSVC7AkpWidXzY3U43ly G4wAxyHHgsjZT6nxnu2BBUq2g6LO38RvW9O01uleHiGvPnYmCkZSOANJT83OwcLhEiOio8FXprX 8FbRS5bL80+o2o9BybdUaM7AfU2CkNQ3e5jWq1bqkz/XNkYNh6HT6vlrwq+IJGlZ/erKSzgm5Lx w9gM8E8pRoOSxnJ3XGlQDWer5NGRUU8/J2nZav/TBB+lX1wqOCe+OQKriWloD940Ic9zp2xCmK9 vJDg5YqNTo14V30nqA+CIOCInQq3A3uaPDPAU2OVkf/RJ3In2D9lFCJv8dFzNJu6IgqCf3YIHYW RKgpifAIXZ/5Lq/C9ttd5zBPZOuQahkG2UN5wd2LHM/Iu5sOtUpYzNfPyQuqlSZQfusYtnvQ1k8 j+huJdbTQvdidTgnREGRl3qag/0SJI6QyteVkRsW0fhX9a3DdKZzDkyc4TNLCub X-Received: by 2002:adf:edc8:0:b0:482:e658:7a39 with SMTP id ffacd0b85a97d-4857e5171femr25364922f8f.11.1788788154948; Mon, 07 Sep 2026 06:35:54 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-48588394fa1sm27523836f8f.8.2026.09.07.06.35.54 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 07 Sep 2026 06:35:54 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][scarthgap 07/35] libxfont2: Fix CVE-2026-56003 Date: Mon, 7 Sep 2026 15:35:03 +0200 Message-ID: <0590e69f65ec1da5d545faec44fdfa8be8a03631.1788787321.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Mon, 07 Sep 2026 13:36:03 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/245265 From: Vijay Anusuri Pick patch according to [2] [1] https://nvd.nist.gov/vuln/detail/CVE-2026-56003 [2] https://security-tracker.debian.org/tracker/CVE-2026-56003 Signed-off-by: Vijay Anusuri Signed-off-by: Yoann Congal --- .../xorg-lib/libxfont2/CVE-2026-56003.patch | 114 ++++++++++++++++++ .../xorg-lib/libxfont2_2.0.6.bb | 1 + 2 files changed, 115 insertions(+) create mode 100644 meta/recipes-graphics/xorg-lib/libxfont2/CVE-2026-56003.patch diff --git a/meta/recipes-graphics/xorg-lib/libxfont2/CVE-2026-56003.patch b/meta/recipes-graphics/xorg-lib/libxfont2/CVE-2026-56003.patch new file mode 100644 index 00000000000..63208116d9b --- /dev/null +++ b/meta/recipes-graphics/xorg-lib/libxfont2/CVE-2026-56003.patch @@ -0,0 +1,114 @@ +From dff957a5158da038a282a59a31fe736702732939 Mon Sep 17 00:00:00 2001 +From: Peter Hutterer +Date: Mon, 1 Jun 2026 16:49:55 +1000 +Subject: [PATCH] bitscale: add bounds check to computeProps for property + buffer + +ComputeScaledProperties allocates a fixed-size property buffer of 70 +slots. computeProps iterates the source font's properties and writes 1 +slot for unscaled properties or 2 slots for scaledX/scaledY properties, +with no bounds check. A malicious font with many duplicate properties +matching fontPropTable entries can overflow the allocated buffer. + +Fix this by passing the remaining buffer capacity to computeProps and +checking it before each write. Properties that would exceed the buffer +are silently skipped. + +The function is also restructured to handle the buffer writes for +scaledX/scaledY inside the switch cases directly, rather than in a +separate block after the switch. This makes the control flow clearer and +ensures the bounds check covers all writes. + +This vulnerability was discovered by: +Anonymous working with TrendAI Zero Day Initiative + +CVE-2026-56003/ZDI-CAN-30560 + +Assisted-by: Claude:claude-opus-4-6 +Signed-off-by: Peter Hutterer +Part-of: + +Upstream-Status: Backport [https://gitlab.freedesktop.org/xorg/lib/libxfont/-/commit/dff957a5158da038a282a59a31fe736702732939] +CVE: CVE-2026-56003 +Signed-off-by: Vijay Anusuri +--- + src/bitmap/bitscale.c | 39 ++++++++++++++++++++------------------- + 1 file changed, 20 insertions(+), 19 deletions(-) + +diff --git a/src/bitmap/bitscale.c b/src/bitmap/bitscale.c +index 7100138..1fd15be 100644 +--- a/src/bitmap/bitscale.c ++++ b/src/bitmap/bitscale.c +@@ -511,7 +511,8 @@ static int + computeProps(FontPropPtr pf, char *wasStringProp, + FontPropPtr npf, char *isStringProp, + unsigned int nprops, double xfactor, double yfactor, +- double sXfactor, double sYfactor) ++ double sXfactor, double sYfactor, ++ int maxprops) + { + int n; + int count; +@@ -526,14 +527,26 @@ computeProps(FontPropPtr pf, char *wasStringProp, + + switch (t->type) { + case scaledX: +- npf->value = doround(xfactor * (double)pf->value); +- rawfactor = sXfactor; +- break; + case scaledY: +- npf->value = doround(yfactor * (double)pf->value); +- rawfactor = sYfactor; ++ if (count + 2 > maxprops) ++ continue; ++ npf->value = (t->type == scaledX) ++ ? doround(xfactor * (double)pf->value) ++ : doround(yfactor * (double)pf->value); ++ rawfactor = (t->type == scaledX) ? sXfactor : sYfactor; ++ npf->name = pf->name; ++ npf++; ++ count++; ++ npf->value = doround(rawfactor * (double)pf->value); ++ npf->name = rawFontPropTable[t - fontPropTable].atom; ++ npf++; ++ count++; ++ *isStringProp++ = *wasStringProp; ++ *isStringProp++ = *wasStringProp; + break; + case unscaled: ++ if (count + 1 > maxprops) ++ continue; + npf->value = pf->value; + npf->name = pf->name; + npf++; +@@ -543,18 +556,6 @@ computeProps(FontPropPtr pf, char *wasStringProp, + default: + break; + } +- if (t->type != unscaled) +- { +- npf->name = pf->name; +- npf++; +- count++; +- npf->value = doround(rawfactor * (double)pf->value); +- npf->name = rawFontPropTable[t - fontPropTable].atom; +- npf++; +- count++; +- *isStringProp++ = *wasStringProp; +- *isStringProp++ = *wasStringProp; +- } + } + return count; + } +@@ -671,7 +672,7 @@ ComputeScaledProperties(FontInfoPtr sourceFontInfo, /* the font to be scaled */ + n = NPROPS; + n += computeProps(sourceFontInfo->props, sourceFontInfo->isStringProp, + fp, isStringProp, sourceFontInfo->nprops, dx, dy, +- sdx, sdy); ++ sdx, sdy, nProps - NPROPS); + return n; + } + +-- +2.43.0 + diff --git a/meta/recipes-graphics/xorg-lib/libxfont2_2.0.6.bb b/meta/recipes-graphics/xorg-lib/libxfont2_2.0.6.bb index 29e4d3298f0..e0a951c3a4f 100644 --- a/meta/recipes-graphics/xorg-lib/libxfont2_2.0.6.bb +++ b/meta/recipes-graphics/xorg-lib/libxfont2_2.0.6.bb @@ -17,6 +17,7 @@ BBCLASSEXTEND = "native" SRC_URI += "file://CVE-2026-56001.patch \ file://CVE-2026-56002.patch \ + file://CVE-2026-56003.patch \ " SRC_URI[sha256sum] = "74ca20017eb0fb3f56d8d5e60685f560fc85e5ff3d84c61c4cb891e40c27aef4" From patchwork Mon Sep 7 13:35:04 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 97530 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id ADB80C79FAC for ; Mon, 7 Sep 2026 13:36:03 +0000 (UTC) Received: from mail-wr1-f42.google.com (mail-wr1-f42.google.com [209.85.221.42]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.34919.1788788157202117607 for ; Mon, 07 Sep 2026 06:35:57 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=yqh8oNmT; spf=pass (domain: smile.fr, ip: 209.85.221.42, mailfrom: yoann.congal@smile.fr) Received: by mail-wr1-f42.google.com with SMTP id ffacd0b85a97d-48584dc164fso3372652f8f.0 for ; Mon, 07 Sep 2026 06:35:56 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1788788155; x=1789392955; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=upndc3jtG6zuoJ2tRjcDWhb5064N6xIUNBjEFkdXOe4=; b=yqh8oNmToWvdegao1LltUA0zwgbhAsKAhz8xfklvQQL5pyuZ/QKs+XtQvfIyJthQCv +ZSVCS1UfR24ag/k+nxFaJ5gx8/wq23lADRZhHXq+d4Bo2EMc7kGb348npAFVlgbKDbG tHHjRbP7AshKrRo1RICFfsHmLNW0zm3HtzKN4= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1788788155; x=1789392955; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=upndc3jtG6zuoJ2tRjcDWhb5064N6xIUNBjEFkdXOe4=; b=sr01Ttvl7Njb+JiivT17icsXHKHZD8Gn0RkkF+0tswynN3s6nFqW/EKTUuAECZbfRy hdmcBEQA0Nhesd2dJzpt/Jm+Khq2mPEhcKl3LJ9Ew0ozBgHUqEALC5HT0FrpfC/tEczr OCNjNpz7IBsk5IsEt+WNt0FmBW1efoN4TrBtBpjQVvD47BjUgNGhf9ENLd/L/gvEQyyM dv2rU+wa6vf8+7zY8iaL+ZTHQLTavhqBdEm40GtJ3lUx563A1hJ/WddeadyAJz70UNAj autNYBjkBfnx8G7QF02QNhpfgCXYc/DCWEgUSAkm1hWrHJitro886oeqGW85+Z9oD/uL u68w== X-Gm-Message-State: AFuF++nKY59SpsAJUa38ErGd6PWNtXURhUFsBFJJKzbwa846DvpyxVvE WCEHkoiFnf5tnwBsjd2RbCoE0D321BebwQXsHaUwRJPvR+ZLQF4r8jUqckYJwLiaZIFibl/gZRc OevpK9po= X-Gm-Gg: AYBFou10tD4EvnKgD6AW05tgT3Ucsjv7ymg9Po1xOSA9nXC9u7CbGdf1rBelkcr9+M0 +C8ycjArLBL3uqoJu7ILSejxlCHMBD0AJWO0XOwLTaGQt+N79qs9mExBMxhlkNk26TT/RPTG0da 35cUvTgmKyrf5KdASwJ5LT8C+DalWYDxxX9y5vXaZ5WCSZ7dryvyBS6hwDg5oqeaFLj3Eu6y6CX jNnO8ZxyBQJC0f4Na2ym0LyrulZtFMhogGTWoyU0ty0fsQOgpT3D7kso/1PN1g4yAzN6MHIXe+j gVGRQkJayl33Bd6MWW0bkKQ88la6c4sgC7uv5Z+eCNyI4t2PqDC26w9TX9DaefqsLR/xd5muyZW 4eCBo0Sh1WtZdk28F4BQap+IqDG6vQnmAXDtfG9FAIkmRNQ19X8lvtf6H5ra0fBE0oH/zd+NwO7 bLy7RVVoQ0ULBGN0NsZ8bkLrgMDzNbUvVtFVcIS+AcDqCOGVyog/9+MCn+4l+gTQG7YuXl2e7tF 7CTubLNmG5K5Q3k2/xGvSFiOhzBP3/U5qHMAwJ5WksYzVPsjJpZg5tMLw4aDo9r X-Received: by 2002:a05:6000:4a0a:b0:485:8a46:704d with SMTP id ffacd0b85a97d-4858a46713emr22311882f8f.31.1788788155450; Mon, 07 Sep 2026 06:35:55 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-48588394fa1sm27523836f8f.8.2026.09.07.06.35.55 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 07 Sep 2026 06:35:55 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][scarthgap 08/35] libevent: use libtool to install test binaries Date: Mon, 7 Sep 2026 15:35:04 +0200 Message-ID: <9d8cfd0d991cc03afe26983abe16dcb5ca341898.1788787321.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Mon, 07 Sep 2026 13:36:03 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/245266 From: Ross Burton If libtool builds a binary it's best to use libtool to install it, as otherwise you might install a wrapper script or need to make assumptions about where libtool has put the real binary (as this isn't always .libs) Signed-off-by: Ross Burton Signed-off-by: Antonin Godard Signed-off-by: Richard Purdie (From OE-Core rev: 1dc0e5e240adf61561c899108d2fb5be71e648e4) Signed-off-by: Peter Marko Signed-off-by: Yoann Congal --- meta/recipes-support/libevent/libevent_2.1.12.bb | 8 ++------ 1 file changed, 2 insertions(+), 6 deletions(-) diff --git a/meta/recipes-support/libevent/libevent_2.1.12.bb b/meta/recipes-support/libevent/libevent_2.1.12.bb index 25388fb4d7f..be690fe94e9 100644 --- a/meta/recipes-support/libevent/libevent_2.1.12.bb +++ b/meta/recipes-support/libevent/libevent_2.1.12.bb @@ -52,12 +52,8 @@ do_install:append() { } do_install_ptest() { - install -d ${D}${PTEST_PATH}/test - for file in ${B}/test/.libs/regress ${B}/test/.libs/test* - do - install -m 0755 $file ${D}${PTEST_PATH}/test - done - + install -d ${D}${PTEST_PATH}/test + ${B}/libtool --mode=install install ${B}/test/regress ${D}${PTEST_PATH}/test/ # handle multilib sed -i s:@libdir@:${libdir}:g ${D}${PTEST_PATH}/run-ptest } From patchwork Mon Sep 7 13:35:05 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 97531 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 767DEC79FB2 for ; Mon, 7 Sep 2026 13:36:04 +0000 (UTC) Received: from mail-wr1-f47.google.com (mail-wr1-f47.google.com [209.85.221.47]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.34920.1788788157634500821 for ; Mon, 07 Sep 2026 06:35:57 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=DlFncPio; spf=pass (domain: smile.fr, ip: 209.85.221.47, mailfrom: yoann.congal@smile.fr) Received: by mail-wr1-f47.google.com with SMTP id ffacd0b85a97d-48441a2ba14so3128682f8f.1 for ; Mon, 07 Sep 2026 06:35:57 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1788788156; x=1789392956; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=tbJEenHJTgzjq8aKyuDVIPlbcVrK0u2r7YzPX8IT8+k=; b=DlFncPioMpMZWR2lNQF0fCISPPheNZg6lqdEh/gmCyiUESsWE74Gb/HqLWwpxiRaTJ gW91FuNESLWzLOxAoogHZ00vnbx0rvB4lyXFDG+7pcnkGnNlVfXzSu2BorkUw1CgBhX+ reGOwfqQRBpOHGPS1ZkSbycYd/QEZmMbzJS1Q= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1788788156; x=1789392956; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=tbJEenHJTgzjq8aKyuDVIPlbcVrK0u2r7YzPX8IT8+k=; b=HiJrrNGbqmihgR1lNkY8O6pA6f2Jml3ZKJUljFwMeHEm4rUn8Ecv6nDsampAcynn5m UTW6m4aIze/e++QmNNjawxcPmlF+K1EaC54i5hXbMd/YPNRa7xsUYQPRGvsczV0tcYff A4pNVxN0m7hIKKzVdyPp8fTul3z5n+X/dp5Kx4wrtDRhbUuz+H4c4FK6PO2RrrR2nSoE Be7OypixzhA9NmSXHl+jEaf/dfsy7Naio5bc/C5vcDyytoKIHTWAyYXPlLv2X7IjXRcm IU8lKGINoIEJKiR21jBUCU+GD7O9Loty2Y89p8jr16a9N47KFRwJnM+WHyNEzEF2JhNc B5uQ== X-Gm-Message-State: AFuF++lvKsAr8ANBHYprRZJ9jviGz24rkNalt038fpfCxphW7uUTvssJ EPfIq4kMqpiyI9lfGznyw+ScFqTu21qUjR0gwbinaYBf8WPctxtCn0RyA6MjRJub50/fQhGuCDl e0X8Mh0o= X-Gm-Gg: AYBFou0U70zpZCoNSm7B8sKAx7MO+7ij9jQTgNMcHYbLC/63ryVzECUigq9+t0HKuOt Cs4ZRK9ekvEUgdwPbGlsucEUtrwvQzZgk48hJMR7veD488jk76s3fxt3VDA0f9y6fHw9ybtSRVl x6MGzmdLZMWyWFNjfDqNzsQjO2Dwc+wJbk79yUJyYnVSjk2w3PtqlpiM6MAjjtG9o5/xXLKPzL5 LYm+0KTAlyFsYTLZsEcefgJZekEG85DOaKwDKpYAjuLFsXgQunvWAJ2EzJYNrC7YU2VoahWKB2f BcvW1eaQeh4rhbeZFZIVD40xK0/e0nwvNt8k+WF/GHU+Ft6hWzh6Oif5BMeUXaECWklWdM5klCS yeThuFTWru5G/BPp//REZTEK6GG+ptjC+B23RGFNJODj9HqmysbBsBbvFZX07ogbD0QQfg4Z09v xYHpXfneeemTBiQxQoApCY8AOMaD6OTlMg3bOscMLimErYzA7yLUUNeFtgcbcuFjD0UFNTvCGsh F4rOdGPdAaqHm6x7iyDhtLEr5sSfv+0Q+lSlItMhvsDRJAGSSOXVBSZJfMfhRxX X-Received: by 2002:a05:6000:46c8:b0:485:847f:fd8b with SMTP id ffacd0b85a97d-48587091978mr18364235f8f.5.1788788155886; Mon, 07 Sep 2026 06:35:55 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-48588394fa1sm27523836f8f.8.2026.09.07.06.35.55 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 07 Sep 2026 06:35:55 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][scarthgap 09/35] libevent: merge inherit statements Date: Mon, 7 Sep 2026 15:35:05 +0200 Message-ID: X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Mon, 07 Sep 2026 13:36:04 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/245267 From: Pratik Farkase Merge the separate inherit statements into a single one for improved readability and consistency with OE style. No functional change intended. Signed-off-by: Pratik Farkase Signed-off-by: Mathieu Dubois-Briand Signed-off-by: Ross Burton Signed-off-by: Richard Purdie (From OE-Core rev: 99792ab6ba188a7623804e587edf8de23690ad3f) Signed-off-by: Peter Marko Signed-off-by: Yoann Congal --- meta/recipes-support/libevent/libevent_2.1.12.bb | 4 +--- 1 file changed, 1 insertion(+), 3 deletions(-) diff --git a/meta/recipes-support/libevent/libevent_2.1.12.bb b/meta/recipes-support/libevent/libevent_2.1.12.bb index be690fe94e9..32c61768d93 100644 --- a/meta/recipes-support/libevent/libevent_2.1.12.bb +++ b/meta/recipes-support/libevent/libevent_2.1.12.bb @@ -28,13 +28,11 @@ S = "${WORKDIR}/${BPN}-${PV}-stable" PACKAGECONFIG ??= "" PACKAGECONFIG[openssl] = "--enable-openssl,--disable-openssl,openssl" -inherit autotools github-releases +inherit autotools github-releases ptest multilib_header # Needed for Debian packaging LEAD_SONAME = "libevent-2.1.so" -inherit ptest multilib_header - DEPENDS = "zlib" PACKAGES_DYNAMIC = "^${PN}-.*$" From patchwork Mon Sep 7 13:35:06 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 97533 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 3FF77C79FAB for ; Mon, 7 Sep 2026 13:36:03 +0000 (UTC) Received: from mail-wr1-f41.google.com (mail-wr1-f41.google.com [209.85.221.41]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.35218.1788788158233039711 for ; Mon, 07 Sep 2026 06:35:58 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=h/aBPXWl; spf=pass (domain: smile.fr, ip: 209.85.221.41, mailfrom: yoann.congal@smile.fr) Received: by mail-wr1-f41.google.com with SMTP id ffacd0b85a97d-48441a2ba14so3128696f8f.1 for ; Mon, 07 Sep 2026 06:35:58 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1788788156; x=1789392956; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=xswVtMGl/1YEgOeDkwnULUNZ/pbG6ZNlI87d1c/LffE=; b=h/aBPXWlHXe5nODJsfEo8TlaoTBruScPl3R204qsqj8XHVH8YwuG3Qe9uWKGEwFb0M Ox+yWKXXNgAU5nAFSbu77qw1BCIF575MpKbopFpLzBmEzZnLDagaRCM+jLqsi5T0c1WL AGDf/ZmLKXukFRhLoVvhMi/bxsvAFvAMNj2Fs= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1788788156; x=1789392956; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=xswVtMGl/1YEgOeDkwnULUNZ/pbG6ZNlI87d1c/LffE=; b=Pd7ozL9OxTS9kQrwGFvJ2zsPpiXO3CAaZC6ecqHkns4rlGZGlY5BtESKX7KoU1TSwN 4v61kVUhcLWAg1peMv41us59V933mJuF4kqSJjvp5oU5x/mp87+su4y0P/dcKaiXdYzq bm/jvzZuslTm1zKr4dZ/aFwf8h2qYIwBQDtlXMGNs9TbyqFZQmrCOeuDyuVPnlcDch0K ClAHQmjwauih+bVLfuubPUaO+/ymQ/phDN1+/4KFsCzGTaeH+XK+iMDWDPfoyPbRT/Cc MpwhVJ1NmmIDataJ0LFuvjp5gjP7z1BwEC9ClpAIRz5mdJpGTzzChhTntuu96Wab8Obj Kfag== X-Gm-Message-State: AFuF++k7VdVKRWCTgFYKYPA9VQOjQAbk4ZvwwqteCD5nR8eU2RRQsCQ9 +L3qDFLjyj3ThWRE5Ebug9qJh+DyLTkbBuLv+rR4fsHQ8esXyuPWGNeEC5F4iWcGvGafYk0YInd Wa76D62o= X-Gm-Gg: AYBFou30RX4xsQGCEU+LaHwiAJWtlzXq1KZSOSwZ3wuHB2VAYNUnFKqj1985F/BAv4t RtFwj/RYtx1D9HlWXvAo4j+/NabzV5+afmnYhPkCH1IR3SGWRAqBEsYc61nTLNNMEgnB9q/c35Z RwSzz5mmGjLYCS2sjAcnywuKUmFdXaoaLbHtb1l727dHB3U0qN+piH/+kyDMZ67dMI1jpdK3Uc8 z7+DX1ngGm4hAAP2cENMyN8hmGD0dA0vcDTGQ5mij10bIrOLuLe271jY+nN9cj3j0baYdD7z66Q cPw78rFAr7NeYlt/ldcucV/63IS6AWYq63Tvqn4hdiV44NtN9T5aXPpNaJV5e6uvfdHavFssR60 8q3NNaXI9pHB5LFyiZQYj2FUj3xs7bDPvmDd/Z8BGGGuPEdT4c0Fp4nq0eth7ZWF2aYzxIUEOiI Nx+n7jGBKPZ2f3/LPooUbHvxor2oh/lGVyOAuq5nOe+QwMAGBcWkaQZQ2TCMuJGSe9FkSst1z0j /VjRPrBkfW0YmPbeGa/kBL+I6Uh1gF2QJacTAxLqDyPZqz5Ob3q0tUWaD7q2nab X-Received: by 2002:a5d:5e09:0:b0:485:956a:1607 with SMTP id ffacd0b85a97d-485956a162emr10365016f8f.40.1788788156336; Mon, 07 Sep 2026 06:35:56 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-48588394fa1sm27523836f8f.8.2026.09.07.06.35.55 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 07 Sep 2026 06:35:56 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][scarthgap 10/35] libevent: upgrade 2.1.12 -> 2.1.13 Date: Mon, 7 Sep 2026 15:35:06 +0200 Message-ID: X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Mon, 07 Sep 2026 13:36:03 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/245268 From: Ross Burton Security Fixes (evtag, evrpc): Fix an out-of-bounds read in decode_tag_internal. (Found by Brubbish. GHSA-fj29-64w6-73h6) Fix an integer overflow in evtag_unmarshal_header. (Found by Brubbish. GHSA-45c6-qx49-89m8) Security Fixes (evhttp): Discard HTTP trailers, to prevent header smuggling attacks. (Found by sebastianosrt. GHSA-2gmv-p5m7-98p6) Restrict HTTP header parsing to prevent request smuggling. (Originally reported by xclow3n; and then by kodareef5, nstaller0490, AsafMeizneer, and yaotushaozhu. GHSA-q39v-w2g7-gr8j.) Treat CRLF and %00 more strictly in HTTP headers, to prevent parser mismatch attacks. (Reported by xclow3n and AsafMeizner. See GHSA-q39v-w2g7-gr8j, GHSA-jcwh-pvf2-73p2.) Fix a heap out-of-bound write that could occur when using AF_UNIX sockets and compiling libevent with -DNDEBUG. (Found by mat-mo. GHSA-cvq5-vrvr-j338) Security fixes (evbuffer, bufferevent): Fixed a dangling pointer in evbuffer_add_reference. (Found by DarkaMaul. GHSA-c2pj-cg4r-88c8) Security fixes (evdns): Fix an out-of-bounds write in dnsname_to_labels when building a DNS response of 2^16 bytes. (Found by sectroyer. GHSA-58rx-7448-jw47) Security fixes (example code): Avoid using strcpy() in sample/http-server.c. (Reported by sectroyer. GHSA-5rgj-2c58-7jrc.) Signed-off-by: Ross Burton Signed-off-by: Richard Purdie (From OE-Core rev: 9ae7030db6f5c415de94b6d85eaac418ae1e0f7b) Full release notes: * https://github.com/libevent/libevent/releases/tag/release-2.1.13-stable Removed github style user references. Signed-off-by: Peter Marko Signed-off-by: Yoann Congal --- ...s_dns.c-patch-out-tests-that-require-a-wo.patch | 8 ++++---- ...s.h-Increase-default-timeval-tolerance-50.patch | 10 +++++----- ...-util-monotonic_prc_fallback-as-retriable.patch | 11 ++++------- ...e-tests-are-marked-failed-only-when-all-a.patch | 9 +++------ .../libevent/Makefile-missing-test-dir.patch | 14 ++++++++++---- .../{libevent_2.1.12.bb => libevent_2.1.13.bb} | 2 +- 6 files changed, 27 insertions(+), 27 deletions(-) rename meta/recipes-support/libevent/{libevent_2.1.12.bb => libevent_2.1.13.bb} (95%) diff --git a/meta/recipes-support/libevent/libevent/0001-test-regress_dns.c-patch-out-tests-that-require-a-wo.patch b/meta/recipes-support/libevent/libevent/0001-test-regress_dns.c-patch-out-tests-that-require-a-wo.patch index 505153d285e..bab94a17ecd 100644 --- a/meta/recipes-support/libevent/libevent/0001-test-regress_dns.c-patch-out-tests-that-require-a-wo.patch +++ b/meta/recipes-support/libevent/libevent/0001-test-regress_dns.c-patch-out-tests-that-require-a-wo.patch @@ -1,4 +1,4 @@ -From 7c17967b8fd2d18b74a8934fd9bb8212ebd6a271 Mon Sep 17 00:00:00 2001 +From 3444b04844a0cd75050d16e9382427f0f431a948 Mon Sep 17 00:00:00 2001 From: Alexander Kanavin Date: Thu, 9 Jan 2020 13:22:46 +0100 Subject: [PATCH] test/regress_dns.c: patch out tests that require a working @@ -14,10 +14,10 @@ Signed-off-by: Alexander Kanavin 1 file changed, 4 deletions(-) diff --git a/test/regress_dns.c b/test/regress_dns.c -index d2084b7..a1a8f3b 100644 +index 9a8bff4..7449e94 100644 --- a/test/regress_dns.c +++ b/test/regress_dns.c -@@ -2394,8 +2394,6 @@ struct testcase_t dns_testcases[] = { +@@ -2459,8 +2459,6 @@ struct testcase_t dns_testcases[] = { { "reissue_disable_when_inactive", dns_reissue_disable_when_inactive_test, TT_FORK|TT_NEED_BASE|TT_NO_LOGS, &basic_setup, NULL }, { "inflight", dns_inflight_test, TT_FORK|TT_NEED_BASE, &basic_setup, NULL }, @@ -26,7 +26,7 @@ index d2084b7..a1a8f3b 100644 #ifdef EVENT__HAVE_SETRLIMIT { "bufferevent_connect_hostname_emfile", test_bufferevent_connect_hostname, TT_FORK|TT_NEED_BASE, &basic_setup, (char*)"emfile" }, -@@ -2405,8 +2403,6 @@ struct testcase_t dns_testcases[] = { +@@ -2470,8 +2468,6 @@ struct testcase_t dns_testcases[] = { { "disable_when_inactive_no_ns", dns_disable_when_inactive_no_ns_test, TT_FORK|TT_NEED_BASE|TT_NO_LOGS, &basic_setup, NULL }, diff --git a/meta/recipes-support/libevent/libevent/0002-test-regress.h-Increase-default-timeval-tolerance-50.patch b/meta/recipes-support/libevent/libevent/0002-test-regress.h-Increase-default-timeval-tolerance-50.patch index 0b20eda3c08..effb825f315 100644 --- a/meta/recipes-support/libevent/libevent/0002-test-regress.h-Increase-default-timeval-tolerance-50.patch +++ b/meta/recipes-support/libevent/libevent/0002-test-regress.h-Increase-default-timeval-tolerance-50.patch @@ -1,4 +1,4 @@ -From dff8fd27edb23bc1486809186c6a4fe1f75f2179 Mon Sep 17 00:00:00 2001 +From 64f2b035a1073c9f594036b46521e19dac029ec2 Mon Sep 17 00:00:00 2001 From: Yi Fan Yu Date: Thu, 22 Apr 2021 22:35:59 -0400 Subject: [PATCH] test/regress.h: Increase default timeval tolerance 50 ms -> @@ -11,7 +11,7 @@ related tests in arm64 QEMU. See: https://bugzilla.yoctoproject.org/show_bug.cgi?id=14163 (The root cause seems to be a heavy load) -Upstream-Status: Submitted [https://github.com/libevent/libevent/pull/1157] +Upstream-Status: Backport [https://github.com/libevent/libevent/pull/1157] Signed-off-by: Yi Fan Yu --- @@ -19,10 +19,10 @@ Signed-off-by: Yi Fan Yu 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/test/regress.h b/test/regress.h -index f06a7669..829af4a7 100644 +index 43cb4ea..21cfb5f 100644 --- a/test/regress.h +++ b/test/regress.h -@@ -127,7 +127,7 @@ int test_ai_eq_(const struct evutil_addrinfo *ai, const char *sockaddr_port, +@@ -123,7 +123,7 @@ int test_ai_eq_(const struct evutil_addrinfo *ai, const char *sockaddr_port, tt_int_op(labs(timeval_msec_diff((tv1), (tv2)) - diff), <=, tolerance) #define test_timeval_diff_eq(tv1, tv2, diff) \ @@ -30,4 +30,4 @@ index f06a7669..829af4a7 100644 + test_timeval_diff_leq((tv1), (tv2), (diff), 100) long timeval_msec_diff(const struct timeval *start, const struct timeval *end); - + diff --git a/meta/recipes-support/libevent/libevent/0003-test-mark-util-monotonic_prc_fallback-as-retriable.patch b/meta/recipes-support/libevent/libevent/0003-test-mark-util-monotonic_prc_fallback-as-retriable.patch index ddc19c495f1..aa0d4f9ef1b 100644 --- a/meta/recipes-support/libevent/libevent/0003-test-mark-util-monotonic_prc_fallback-as-retriable.patch +++ b/meta/recipes-support/libevent/libevent/0003-test-mark-util-monotonic_prc_fallback-as-retriable.patch @@ -1,20 +1,20 @@ -From d01a57a998798da977c470f3b8d6a457c1adb144 Mon Sep 17 00:00:00 2001 +From 9ad27391a97157eb8cee84a7e9cc3dc93df34cbb Mon Sep 17 00:00:00 2001 From: Azat Khuzhin Date: Sun, 19 Sep 2021 00:57:31 +0300 Subject: [PATCH] test: mark util/monotonic_prc_fallback as retriable Refs: #1193 -Upstream-Status: Backport +Upstream-Status: Backport [https://github.com/libevent/libevent/commit/04fcd7c6df158bb65261867de4b9ec8439696934] --- test/regress_util.c | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/test/regress_util.c b/test/regress_util.c -index 45caa2700a40..a9e80db20149 100644 +index fd149b3..10244d6 100644 --- a/test/regress_util.c +++ b/test/regress_util.c -@@ -1672,7 +1672,7 @@ struct testcase_t util_testcases[] = { +@@ -1674,7 +1674,7 @@ struct testcase_t util_testcases[] = { { "monotonic_res_fallback", test_evutil_monotonic_res, TT_OFF_BY_DEFAULT, &basic_setup, (void*)"fallback" }, { "monotonic_prc", test_evutil_monotonic_prc, 0, &basic_setup, (void*)"" }, { "monotonic_prc_precise", test_evutil_monotonic_prc, TT_RETRIABLE, &basic_setup, (void*)"precise" }, @@ -23,6 +23,3 @@ index 45caa2700a40..a9e80db20149 100644 { "date_rfc1123", test_evutil_date_rfc1123, 0, NULL, NULL }, { "evutil_v4addr_is_local", test_evutil_v4addr_is_local, 0, NULL, NULL }, { "evutil_v6addr_is_local", test_evutil_v6addr_is_local, 0, NULL, NULL }, --- -2.31.1 - diff --git a/meta/recipes-support/libevent/libevent/0004-test-retriable-tests-are-marked-failed-only-when-all-a.patch b/meta/recipes-support/libevent/libevent/0004-test-retriable-tests-are-marked-failed-only-when-all-a.patch index 26b707ad316..4cb2a6d7bc0 100644 --- a/meta/recipes-support/libevent/libevent/0004-test-retriable-tests-are-marked-failed-only-when-all-a.patch +++ b/meta/recipes-support/libevent/libevent/0004-test-retriable-tests-are-marked-failed-only-when-all-a.patch @@ -1,4 +1,4 @@ -From 36ebd92fa53c0097f1e2f9ec5aa5b5c6ec1b411d Mon Sep 17 00:00:00 2001 +From 59ab048f0fe32fb8d8e43214f93c32b53148419c Mon Sep 17 00:00:00 2001 From: Thomas Perrot Date: Wed, 29 Sep 2021 13:50:35 +0200 Subject: [PATCH] test: retriable tests are marked failed only when all @@ -15,7 +15,7 @@ Signed-off-by: Thomas Perrot 2 files changed, 7 insertions(+), 8 deletions(-) diff --git a/test/tinytest.c b/test/tinytest.c -index 85dfe74a720e..bf2882418eb6 100644 +index 85dfe74..bf28824 100644 --- a/test/tinytest.c +++ b/test/tinytest.c @@ -310,7 +310,8 @@ testcase_run_forked_(const struct testgroup_t *group, @@ -64,7 +64,7 @@ index 85dfe74a720e..bf2882418eb6 100644 switch (test_ret_err) { diff --git a/test/tinytest.h b/test/tinytest.h -index d321dd467542..c276b5339331 100644 +index d321dd4..c276b53 100644 --- a/test/tinytest.h +++ b/test/tinytest.h @@ -92,7 +92,7 @@ char *tinytest_format_hex_(const void *, unsigned long); @@ -76,6 +76,3 @@ index d321dd467542..c276b5339331 100644 void tinytest_set_aliases(const struct testlist_alias_t *aliases); --- -2.31.1 - diff --git a/meta/recipes-support/libevent/libevent/Makefile-missing-test-dir.patch b/meta/recipes-support/libevent/libevent/Makefile-missing-test-dir.patch index 8880bd04075..c54a2b7bb0f 100644 --- a/meta/recipes-support/libevent/libevent/Makefile-missing-test-dir.patch +++ b/meta/recipes-support/libevent/libevent/Makefile-missing-test-dir.patch @@ -1,4 +1,7 @@ -Fix missing test directory creation. +From c16d91420b94701065d3bdfdf96c41e0710c3bc8 Mon Sep 17 00:00:00 2001 +From: Andrej Valek +Date: Tue, 25 Apr 2017 08:11:48 +0200 +Subject: [PATCH] Fix missing test directory creation. GCC used in OE-core has "dependency tracking" disabled and libevent has problem with this. @@ -12,12 +15,15 @@ Workaround specific to our build system. Signed-off-by: Andrej Valek Signed-off-by: Pascal Bach +--- + test/include.am | 1 + + 1 file changed, 1 insertion(+) -diff --git a/libevent-2.1.8-stable/test/include.am b/libevent-2.1.8-stable/test/include.am -index eea249f..d323dff 100644 +diff --git a/test/include.am b/test/include.am +index 0437524..48c7307 100644 --- a/test/include.am +++ b/test/include.am -@@ -161,6 +161,7 @@ test_bench_httpclient_LDADD = $(LIBEVENT_GC_SECTIONS) libevent_core.la +@@ -162,6 +162,7 @@ test_bench_httpclient_LDADD = $(LIBEVENT_GC_SECTIONS) libevent_core.la test/regress.gen.c test/regress.gen.h: test/rpcgen-attempted test/rpcgen-attempted: test/regress.rpc event_rpcgen.py test/rpcgen_wrapper.sh diff --git a/meta/recipes-support/libevent/libevent_2.1.12.bb b/meta/recipes-support/libevent/libevent_2.1.13.bb similarity index 95% rename from meta/recipes-support/libevent/libevent_2.1.12.bb rename to meta/recipes-support/libevent/libevent_2.1.13.bb index 32c61768d93..b0de8637390 100644 --- a/meta/recipes-support/libevent/libevent_2.1.12.bb +++ b/meta/recipes-support/libevent/libevent_2.1.13.bb @@ -20,7 +20,7 @@ SRC_URI = "${GITHUB_BASE_URI}/download/release-${PV}-stable/${BP}-stable.tar.gz file://0004-test-retriable-tests-are-marked-failed-only-when-all-a.patch \ " -SRC_URI[sha256sum] = "92e6de1be9ec176428fd2367677e61ceffc2ee1cb119035037a27d346b0403bb" +SRC_URI[sha256sum] = "f7e9383b8c0baa81b687e5b5eecc01beefaf1b19b64151d95ed61647fe7a315c" UPSTREAM_CHECK_REGEX = "releases/tag/release-(?P.+)-stable" S = "${WORKDIR}/${BPN}-${PV}-stable" From patchwork Mon Sep 7 13:35:07 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 97528 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 1E968C79FA9 for ; Mon, 7 Sep 2026 13:36:03 +0000 (UTC) Received: from mail-wm1-f43.google.com (mail-wm1-f43.google.com [209.85.128.43]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.34921.1788788158656077410 for ; Mon, 07 Sep 2026 06:35:58 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=OSzqX9+i; spf=pass (domain: smile.fr, ip: 209.85.128.43, mailfrom: yoann.congal@smile.fr) Received: by mail-wm1-f43.google.com with SMTP id 5b1f17b1804b1-499ae1c6471so35013995e9.3 for ; Mon, 07 Sep 2026 06:35:58 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1788788157; x=1789392957; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=TLBvTd0pSoKjNKRcjCXhBuwa5ER4z6N9VpJSmtBA9mY=; b=OSzqX9+iyG8FH7IuxE49voTUe5xmyEiBl/jv/A+HXs7Uy2eHNnKaVa3DGd6q5E6svJ 2MrTrRUDUFvyQddaOmzkbdtCte4UV9UzyfpL5O7GbrOgGWZ9Msv3JHxIbaHBRL4JgpJI yVFr8XDu03DuC6rTZj/9Yi5wLrj48GjV4LZjM= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1788788157; x=1789392957; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=TLBvTd0pSoKjNKRcjCXhBuwa5ER4z6N9VpJSmtBA9mY=; b=dx1S5NTuNQO4Pfe6L9dtYfr3YUxM7XrFYR9wq/P1dz8YdtPJTXISgcoqNERYTpU+Qx kiA4XIe5A2VOKI5MlYxpYw6KkiPnFV7F/kLN1zwhVpNCaGNhA4ASuhr3JUrsZb3m5LuS lHlCW9tFm29de6HNpcQ3fTnCnMwaCeeEC8x4zKc5aO8l5cwkfQ+7aIxNniTnGlHfl+Re 1UobxTVMwsyXnaaDQmav7NT0l7skFFF8T4I4Ms1QTcDWK4wM32D8WnnW07iA5KsiDW0v BF1MjcuV7yQaHChFE7Rtb1gV/bH5wsiOEu99LNyT0iKMa/WrhvLzYbAwdAVPgYGJDqvf aJmA== X-Gm-Message-State: AFuF++nbW9whJjOV67jo4XIh4mSE0BcC1SRlCFyu6it6djCE+t692fll W4skgB52BZB3IOJoUEhyQdgC6inYJxoSJwozVAmO28YUNLVk46C5thtsHuNTMUuhHWUNyDx/nq9 sQYKhzRI= X-Gm-Gg: AYBFou0DXijQ1TjN1IS+vtjJ6Qb0e2PNPU9ZLhiKrEovbPBKNF/BqpTEBM9Lp8Tc9eK 4J7Ywf83/vVt7rDrBobMMRviaN485bnarwNJ/5L3MlkvgGmd5ULeis7tG+05WVWAchaZjbHpr1J Qrwt9PAOVyKi/ZcZjjTRuS032p1HPEjj94j2nf5N90k1d5lFRcEgiExxQmseKdoZ+ug7B9CcZej UyZRKUFVjMLoICcF3yAxyS+Ks2oKhyzhKp4TCZqfEAci/iQ5MbvRW4UdxfIsquEedrbiNHxjlhI r2qBK+tyTTkk4x89l9zrz5WPcumzJ9pRc/bh8rfrkQcwV6CpBCYfBDZCyX+24WYRrrk238A7Onw LZgtKjQvBJPn/QEmaiLOuET4bcOYvixhlTRn6j02NsjDaBuVfb8+gGRLR1rIPFh4wLhaD0x9hOE eZloV5kyzJIswbWMQh1GabaGAg5v1lEYcCCD695eOexKpy4Z0mSH0WK0zhsToBtwLOw6ab6oqTF a9RZPr4CtBRGR9d4rhOSoz2WptuxUIQ5Gi5Zpe0ziNfmxG9RNI8GOE6GuX58O6w X-Received: by 2002:a05:600c:6214:b0:49c:dca4:94c with SMTP id 5b1f17b1804b1-49cf825115bmr464814815e9.13.1788788156784; Mon, 07 Sep 2026 06:35:56 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-48588394fa1sm27523836f8f.8.2026.09.07.06.35.56 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 07 Sep 2026 06:35:56 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][scarthgap 11/35] libevent: set status for CVE-2026-63380 Date: Mon, 7 Sep 2026 15:35:07 +0200 Message-ID: <7447b6ffb1ef18cecd7d45d2e397018dfa54c78d.1788787321.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Mon, 07 Sep 2026 13:36:03 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/245269 From: Peter Marko Per [1] this only affects 2.2.1-alpha. Also [2] markes their versions as not-affected. [1] https://github.com/libevent/libevent/security/advisories/GHSA-3rpf-frgx-xq34 [2] https://security-tracker.debian.org/tracker/CVE-2026-63380 Signed-off-by: Peter Marko Signed-off-by: Yoann Congal --- meta/recipes-support/libevent/libevent_2.1.13.bb | 2 ++ 1 file changed, 2 insertions(+) diff --git a/meta/recipes-support/libevent/libevent_2.1.13.bb b/meta/recipes-support/libevent/libevent_2.1.13.bb index b0de8637390..22894cc3bea 100644 --- a/meta/recipes-support/libevent/libevent_2.1.13.bb +++ b/meta/recipes-support/libevent/libevent_2.1.13.bb @@ -55,3 +55,5 @@ do_install_ptest() { # handle multilib sed -i s:@libdir@:${libdir}:g ${D}${PTEST_PATH}/run-ptest } + +CVE_STATUS[CVE-2026-63380] = "fixed-version: only affects 2.2.1-alpha" From patchwork Mon Sep 7 13:35:08 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 97527 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 01D64C79FA7 for ; Mon, 7 Sep 2026 13:36:03 +0000 (UTC) Received: from mail-wr1-f52.google.com (mail-wr1-f52.google.com [209.85.221.52]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.34922.1788788159120239177 for ; Mon, 07 Sep 2026 06:35:59 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=DSmZMtR1; spf=pass (domain: smile.fr, ip: 209.85.221.52, mailfrom: yoann.congal@smile.fr) Received: by mail-wr1-f52.google.com with SMTP id ffacd0b85a97d-4843e397f74so4423674f8f.1 for ; Mon, 07 Sep 2026 06:35:58 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1788788157; x=1789392957; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=zJgZMLX8ZA+2Wl0d4BeoaQVShEvOpQ3k8owcn1Dmk4Q=; b=DSmZMtR141FptUyXeoRH3FF3FII9Y2B+PGI0p6Tjw+mO271hKJzAYq0hUQUmNY1mmr CDA/748ypzjixL9oDG5+NZXJiAOBj9JtK85YRvecMkCsyGdS3jtIXX0UUu6iqtP1vZ+6 bfJ8kNB7+5305plVarlv/h3bFcheaEu+khj0o= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1788788157; x=1789392957; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=zJgZMLX8ZA+2Wl0d4BeoaQVShEvOpQ3k8owcn1Dmk4Q=; b=TAALGbzgaWlAI9w+GwvIAjdn3nWJt5JXsh5jF6OpxKYfK50LSqtxeW7yzEfp2I6Wk5 Z3jhzp1gRrg+owzTiaoVGLqt+E09zHWdx5lOtcX0FMnk8emDiqUHZczJQBKAtK09A5dB /tCRlqeJvt/3nlAQE1MdQmT4b9aPHNY3/AU6T4KE2Pr+B+t10tvXkeY1/HTV5hs7E0pI NkWXgXv/iBBqIOI4zGI36kYs8Fh8xrN4yPEhKDAXxHcQmhD4+paEMfwSC45aR6s+dXQw VOpvg/8sIwSn4ZRPd1MJsgDeg6shKXWRKTPactaioHjNFkLt32cyJXV44OpD/6oAPyWx vP6w== X-Gm-Message-State: AFuF++lPd8xPPIKEPB3OgvuA96ItbnO/keOClMAkOPfHW2RUAVvwJO6G PeiC8zBN0ZuCeoX+1gytswiHXYKeDW97jWAFsfVDpsP5Cpf7yddFj3k/oRSbSHSTi4I18+C8OPV mWas3OIc= X-Gm-Gg: AYBFou0YNgFy591JGUsSOqDLBEQitmB/F+X8PXug6n3VTF3beVmJv6iRp0vvGSGP7t7 SQn0UU0N5FPYGlrpLnmQIQKeS8n12dywhvGBnVpEDApDDKCKWmfFS1TCbmlCRvLeh8OilQF40j+ /Cx+1b8Dyw3F4pqy1i7UR4WKIWEIG0PNIWkSPOUYLnK8CmL9Ljr4pDGfVG2ziHsEY+ZwxTukgvb Os3FMGvOakm1Iwh0tUTFiCbX6UonzZ0jaYtkgvDHWULWXb5DTcbR6bJOH9X/tPVyg/5+idlK+9h ly7GJ+R8FRTmQ+cuDwpYj8xF0Q1jC2jVpYt7whbXr2FwQE3iEDLYXbNYBmiYy02rTKeYfllmFEz oPcydyfN6baho8UplYAByCNg8tum7VIibdHfNKItXintaDaCw4+aVOf1skml9+Iqj31qwvhRZrc rKqwnGMXUlRps4dX7+/t/MGYm8riGl3xmtRiE2os4afeXOYzCk27FJmRZA/xYuGTmGxiwUlgtze wF141V87P+lzWiOTlqeL44brcbUz1/wiDAmQ7q8ONzK/B5Ql+z/G1sOIXKPxKXz X-Received: by 2002:a5d:4902:0:b0:484:4817:dcb8 with SMTP id ffacd0b85a97d-4857e51b03dmr28223957f8f.12.1788788157303; Mon, 07 Sep 2026 06:35:57 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-48588394fa1sm27523836f8f.8.2026.09.07.06.35.56 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 07 Sep 2026 06:35:56 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][scarthgap 12/35] alsa-lib: patch CVE-2026-56109 Date: Mon, 7 Sep 2026 15:35:08 +0200 Message-ID: <1f7cd9a1c65bfc1a4dbba3830d7092acf02174fd.1788787321.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Mon, 07 Sep 2026 13:36:03 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/245270 From: Peter Marko Pick patch listed in NVD CVE report. Signed-off-by: Peter Marko Signed-off-by: Yoann Congal --- .../alsa/alsa-lib/CVE-2026-56109.patch | 33 +++++++++++++++++++ .../alsa/alsa-lib_1.2.11.bb | 1 + 2 files changed, 34 insertions(+) create mode 100644 meta/recipes-multimedia/alsa/alsa-lib/CVE-2026-56109.patch diff --git a/meta/recipes-multimedia/alsa/alsa-lib/CVE-2026-56109.patch b/meta/recipes-multimedia/alsa/alsa-lib/CVE-2026-56109.patch new file mode 100644 index 00000000000..6189d46e5dc --- /dev/null +++ b/meta/recipes-multimedia/alsa/alsa-lib/CVE-2026-56109.patch @@ -0,0 +1,33 @@ +From 536dd6f8affdf5197c12a63a71c92a70b2833cc0 Mon Sep 17 00:00:00 2001 +From: Jaroslav Kysela +Date: Mon, 8 Jun 2026 14:33:19 +0200 +Subject: [PATCH] conf: add missing return value check in parse_def() + +A malformed configuration may cause SIGSEGV. + +Link: https://lore.kernel.org/alsa-devel/CAGt8pqBU0p2voB+qHxWGcNJrKHAcBhAyHUUBPLBN-Yj_SiV6MQ@mail.gmail.com/ +Reported-by: Luigino Camastra +Signed-off-by: Jaroslav Kysela + +CVE: CVE-2026-56109 +Upstream-Status: Backport [https://github.com/alsa-project/alsa-lib/commit/536dd6f8affdf5197c12a63a71c92a70b2833cc0] +Signed-off-by: Peter Marko +--- + src/conf.c | 4 ++++ + 1 file changed, 4 insertions(+) + +diff --git a/src/conf.c b/src/conf.c +index b0dd6298..e1dba23d 100644 +--- a/src/conf.c ++++ b/src/conf.c +@@ -1477,6 +1477,10 @@ static int parse_def(snd_config_t *parent, input_t *input, int skip, int overrid + endchr = ']'; + } + c = get_nonwhite(input); ++ if (c < 0) { ++ err = c; ++ goto __end; ++ } + if (c != endchr) { + if (n) + snd_config_delete(n); diff --git a/meta/recipes-multimedia/alsa/alsa-lib_1.2.11.bb b/meta/recipes-multimedia/alsa/alsa-lib_1.2.11.bb index e86239ff871..068a727c67a 100644 --- a/meta/recipes-multimedia/alsa/alsa-lib_1.2.11.bb +++ b/meta/recipes-multimedia/alsa/alsa-lib_1.2.11.bb @@ -12,6 +12,7 @@ LIC_FILES_CHKSUM = "file://COPYING;md5=a916467b91076e631dd8edb7424769c7 \ SRC_URI = "https://www.alsa-project.org/files/pub/lib/${BP}.tar.bz2 \ file://0001-topology-correct-version-script-path.patch \ file://CVE-2026-25068.patch \ + file://CVE-2026-56109.patch \ " SRC_URI[sha256sum] = "9f3f2f69b995f9ad37359072fbc69a3a88bfba081fc83e9be30e14662795bb4d" From patchwork Mon Sep 7 13:35:09 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 97525 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id CA5A0C79FA0 for ; Mon, 7 Sep 2026 13:36:02 +0000 (UTC) Received: from mail-wm1-f54.google.com (mail-wm1-f54.google.com [209.85.128.54]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.34923.1788788159809161177 for ; Mon, 07 Sep 2026 06:36:00 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=GHuFs8N2; spf=pass (domain: smile.fr, ip: 209.85.128.54, mailfrom: yoann.congal@smile.fr) Received: by mail-wm1-f54.google.com with SMTP id 5b1f17b1804b1-49d0da752ffso14227575e9.3 for ; Mon, 07 Sep 2026 06:35:59 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1788788158; x=1789392958; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=bBiyxr3t8s+9CHD++vKffwVgGF4TLdbPr4DszMESfck=; b=GHuFs8N2GU5nRMsfASnhFY5CiX1pR2bxjoJSvw76S4atBb4azplHJlz1BL4bwNO1Gj SrJWhl5Zu94wnsIwM2CYEqG/hFriT0uU4Lx9PZnDN5Sq5bY/HbrguyEfO6R4mxKOt/I5 NSE3ZmFIpTSpUWWuPMZhQitSyd+/0kaC7BWLk= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1788788158; x=1789392958; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=bBiyxr3t8s+9CHD++vKffwVgGF4TLdbPr4DszMESfck=; b=Q3gARktittoMyXtSyYMoyQdYiCnUQiRAwBzGDa8hRvXT5ytHLOOWb67+UyrxGnMvsY 77hdtW46haf2GJMp+y6vhOUQZN8SGrsvg1OwUZBXVhBcwFRaQs6Crstey8jAbq/AgqHt KVxcjys4N23ayJ9OxYLaaPJUtRdByqUS4+JSGnYYaH0K4LVzigDw85KIwK/OUfU1DwQ9 4SJ6nMFhCTSLj8SO/HgGjycjevmvooOTxl0GQjlOUv48ybKIirbz3OsegkT9E+wrBxmI 5vuMy98d+bOcrWqyB+vyO87QdK8VOU6F7oC3c22vI8Dhu0e1Mh5C+S1yLA1mEFiP6j3t eUaA== X-Gm-Message-State: AFuF++mIQuT9k3isFpDTw6leUH0IqnNB3s43jCkqFwSCvOFdUnmh0L81 AT2w1BK4PWNwCApbZCVBQYPQzZDyKBlXqxFd6JEOxlkCOOJPv0XyfTFm9xG+VKGNctyNd1HIGne R+DRKhRY= X-Gm-Gg: AYBFou0Z2gH9nEPMEmoFTEGciTghJwfjxIXMlsM+z9FyeJV39qvUpmMjICCt+JqcGcV dtU0YkBN99FNShBDWuK0WoYDMHva37AK2ryOKEL8dyDPxHHjWjD2U2NCEIzTBFqEugJVEsZpCsW n7PzdOM1KOp4lqOhLFOVxsBQbJZ10zGrJbYaOLsdzjcDNYQm88lRobQXuaFuJHKQ9KZOd/MPznG 4QqUT0UWusRYr3jCuY5rb5KEl/h1PJOv/1HjFh4OqmtT+bOEOl2PLPatd4Y7EEePsNvbkBi4Jq+ 2nLbuZzxUlEEWOaJLWb+BzhggDVvRdzNBNpacUyJ52MvPhwM7d+g2+hQd8U4S0+9kZlplYGJ5uw mtTrjbhkXoti+gRvCaX6l8OtQt7Wew+i2UJG49zSFSeSDsWigrrpRcHZnQYJOllB2xx6tnH8VFo cGHmX8eNRpvYs58fn1/nKE6qY8m1gPuQlbzBdY/k1smmbgn1haCMfEFtjJo4kv5NEk7M2nrh1QE GBrVFL/VyAEi4toM8t8pyCEoVEpSdc+28EA3THiErrYilrOGb+/KfCXRvpzmWzGNA== X-Received: by 2002:a05:600c:1f91:b0:49d:13f7:89d3 with SMTP id 5b1f17b1804b1-49d13f78a8cmr32901175e9.14.1788788158029; Mon, 07 Sep 2026 06:35:58 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-48588394fa1sm27523836f8f.8.2026.09.07.06.35.57 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 07 Sep 2026 06:35:57 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][scarthgap 13/35] gnutls: fix CVE-2026-42010 Date: Mon, 7 Sep 2026 15:35:09 +0200 Message-ID: <2b1ed475e021c0eb13014a170911e96b1b0aed28.1788787321.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Mon, 07 Sep 2026 13:36:02 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/245271 From: Jakub Szczudlo (Nokia) Backport patch to fix CVE-2026-42010. References: https://nvd.nist.gov/vuln/detail/CVE-2026-42010 Upstream fix: https://gitlab.com/gnutls/gnutls/-/commit/cb1833afd9b6309563211b1c0a7c291f52ca98d5 Tested with ptest Signed-off-by: Jakub Szczudlo Signed-off-by: Yoann Congal --- .../gnutls/gnutls/CVE-2026-42010.patch | 41 +++++++++++++++++++ meta/recipes-support/gnutls/gnutls_3.8.4.bb | 1 + 2 files changed, 42 insertions(+) create mode 100644 meta/recipes-support/gnutls/gnutls/CVE-2026-42010.patch diff --git a/meta/recipes-support/gnutls/gnutls/CVE-2026-42010.patch b/meta/recipes-support/gnutls/gnutls/CVE-2026-42010.patch new file mode 100644 index 00000000000..b94a32afffc --- /dev/null +++ b/meta/recipes-support/gnutls/gnutls/CVE-2026-42010.patch @@ -0,0 +1,41 @@ +From cb1833afd9b6309563211b1c0a7c291f52ca98d5 Mon Sep 17 00:00:00 2001 +From: Alexander Sosedkin +Date: Tue, 21 Apr 2026 19:26:10 +0200 +Subject: [PATCH] lib/auth/rsa_psk: fix binary PSK identity lookup + +A server looking up PSK username with a NUL-character in it +was wrongfully matching username truncated at a NUL-character. +Fix the check to compare up to the full username length. + +CVE: CVE-2026-42010 +Upstream-Status: Backport [https://gitlab.com/gnutls/gnutls/-/commit/cb1833afd9b6309563211b1c0a7c291f52ca98d5] + +Reported-by: Joshua Rogers of AISLE Research Team +Fixes: #1850 +Fixes: CVE-2026-42010 +Fixes: GNUTLS-SA-2026-04-29-4 +CVSS: 7.1 High CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N +Signed-off-by: Alexander Sosedkin +Signed-off-by: Peter Marko +Signed-off-by: Jakub Szczudlo +--- + lib/auth/rsa_psk.c | 3 +-- + 1 file changed, 1 insertion(+), 2 deletions(-) + +diff --git a/lib/auth/rsa_psk.c b/lib/auth/rsa_psk.c +index cc92b4aa96..27caf18769 100644 +--- a/lib/auth/rsa_psk.c ++++ b/lib/auth/rsa_psk.c +@@ -321,8 +321,7 @@ static int _gnutls_proc_rsa_psk_client_kx(gnutls_session_t session, + * filled in if the key is not found. + */ + ret = _gnutls_psk_pwd_find_entry(session, info->username, +- strlen(info->username), &pwd_psk, +- NULL); ++ info->username_len, &pwd_psk, NULL); + if (ret < 0) + return gnutls_assert_val(ret); + +-- +GitLab + diff --git a/meta/recipes-support/gnutls/gnutls_3.8.4.bb b/meta/recipes-support/gnutls/gnutls_3.8.4.bb index 0eabc517ce5..6f1c2f21723 100644 --- a/meta/recipes-support/gnutls/gnutls_3.8.4.bb +++ b/meta/recipes-support/gnutls/gnutls_3.8.4.bb @@ -46,6 +46,7 @@ SRC_URI = "https://www.gnupg.org/ftp/gcrypt/gnutls/v${SHRT_VER}/gnutls-${PV}.tar file://CVE-2026-42009_p1.patch \ file://CVE-2026-42009_p2.patch \ file://CVE-2026-3833.patch \ + file://CVE-2026-42010.patch \ " SRC_URI[sha256sum] = "2bea4e154794f3f00180fa2a5c51fe8b005ac7a31cd58bd44cdfa7f36ebc3a9b" From patchwork Mon Sep 7 13:35:10 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 97534 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 1A9DBC79FAF for ; Mon, 7 Sep 2026 13:36:04 +0000 (UTC) Received: from mail-wr1-f50.google.com (mail-wr1-f50.google.com [209.85.221.50]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.34925.1788788160395625091 for ; Mon, 07 Sep 2026 06:36:00 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=K1AGwhyM; spf=pass (domain: smile.fr, ip: 209.85.221.50, mailfrom: yoann.congal@smile.fr) Received: by mail-wr1-f50.google.com with SMTP id ffacd0b85a97d-4858595f997so2104456f8f.1 for ; Mon, 07 Sep 2026 06:36:00 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1788788159; x=1789392959; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=sayaQ8+5O3bjEsThTrUTG7Lsaz49elY49FYMUVYRRUs=; b=K1AGwhyM9PfoebP+hvNTH/pbQO/Qhvemmt4o7NcMIfCT8LFnBo2fIRp94T2KRn2cq2 bnqCTV0JRmrkXO7F+GHWKx/9FTj9v+rSdkRP3axi+d2IfaJGtDwFcwEWEKOQCHbowyRy cjuffi/a9vks1CFhtbuTY6JjCIiW5O7832PLw= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1788788159; x=1789392959; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=sayaQ8+5O3bjEsThTrUTG7Lsaz49elY49FYMUVYRRUs=; b=O7s91FZVdyb6kjIivraft3IMQrkDBQ8jwZxFGoXhklMZq2Im+6daOorXQeUCIYjE1I 24J+6Xn6rtFwaXaj3HWehiRqnGz/LAICMcRDOcyMl5q8kDnDvpcdPgQsvbPRuFttnmpW HdymP4umMrNfeSGfYFi53e2+o31lVQ9LppDxnRUWTPszcqn+n7FfPiK/W5gTGPpODmCB QODzNWzFhlJ6jPOWq0QUxFlnqhxhWQSxKmBaPl/WsnCCJpZ0zRjU45sAq5AXhsLfRj9I 5itVBVjDzc9gsjq8sG5tBjLfwZdqR3C4wKEzCIDpW2kNC1dbEUnu3s838IwCuIeNtYSw /Rkg== X-Gm-Message-State: AFuF++mJiVTZT/0ceVn72SjuPsZ0MTjDRci62CdQuxPicgupc15npYOO UxSgKNpvauDb9424pXF0vTLQ01VEqMjyBcs7EDPgzKBAKh/nzH7rh5+VmL6f8gEpca3vgWorUDf WSi7UzwM= X-Gm-Gg: AYBFou1PiEhgOUVecrV8SFcnXg677zDZomNvxa5/mjeiDy59YqPknW8rOSG2h5+gQng AbTddov+ZeHCJ8MaShuqAsCqgcIMJim3GlpYengyfz/ACi8dBUaPKO54G+dU81v/apUK43gne3Y fYImItDlw7tPlBiotvToj4PIda4FkBu/OzzzlhZEZE/bNKP1EAuA0foKkC13RBXBBAG9KIkuegG r6BdQ8tXzu58BRq5P6oKwWzfMwZsfHy8K/JIi9LyFPsiWDDAROvdFiBwEA1mMM/6Z1xN0rs1Hfm VUnzx1OQvLCIBzoxlzJzmRxp+6Y+m+G/CSspe4TO2CK1SGOa/1qUnXj7yFkCvP5f5cn6zZTeJcq Dv+TJu8/haYO73EZxIKTayayb1AVShbImoYQzyCFU1gmTMt6aPUlAGivZPh1jnS6Zk2B3DIr7va kDJqWWR1c/gJ5c3YGZu30qq7jryb8T/Xy45Sh/tQ9xFDnj0xcz/SfQewdluHZhckOqZTRzZAay4 wceK8Y6rlyxMiRXRGA9GjD9hj9f3i2TE7VO+O/Z+Ax4RLdH6KJ9iouvtz7dckEm X-Received: by 2002:a05:6000:420d:b0:485:8ebb:be1a with SMTP id ffacd0b85a97d-4858ebbbee4mr36055279f8f.4.1788788158624; Mon, 07 Sep 2026 06:35:58 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-48588394fa1sm27523836f8f.8.2026.09.07.06.35.58 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 07 Sep 2026 06:35:58 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][scarthgap 14/35] gnutls: fix for CVE-2026-42011 Date: Mon, 7 Sep 2026 15:35:10 +0200 Message-ID: <81e15180ec6df4785d05c52d074fbad859eafb61.1788787321.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Mon, 07 Sep 2026 13:36:04 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/245272 From: Jakub Szczudlo (Nokia) Backport patches to fix CVE-2026-42011 and extend test for it References: https://nvd.nist.gov/vuln/detail/CVE-2026-42011 Upstream fix: https://gitlab.com/gnutls/gnutls/-/commit/1dead2faec6320aaba321eb56f20d442df192b83 https://gitlab.com/gnutls/gnutls/-/commit/24713b8c63137ce0665b495d22ccce4f5ce05c84 Tested with ptest Signed-off-by: Jakub Szczudlo Signed-off-by: Yoann Congal --- .../gnutls/gnutls/CVE-2026-42011_p1.patch | 43 ++++++ .../gnutls/gnutls/CVE-2026-42011_p2.patch | 141 ++++++++++++++++++ meta/recipes-support/gnutls/gnutls_3.8.4.bb | 2 + 3 files changed, 186 insertions(+) create mode 100644 meta/recipes-support/gnutls/gnutls/CVE-2026-42011_p1.patch create mode 100644 meta/recipes-support/gnutls/gnutls/CVE-2026-42011_p2.patch diff --git a/meta/recipes-support/gnutls/gnutls/CVE-2026-42011_p1.patch b/meta/recipes-support/gnutls/gnutls/CVE-2026-42011_p1.patch new file mode 100644 index 00000000000..62a9714c6c6 --- /dev/null +++ b/meta/recipes-support/gnutls/gnutls/CVE-2026-42011_p1.patch @@ -0,0 +1,43 @@ +From 1dead2faec6320aaba321eb56f20d442df192b83 Mon Sep 17 00:00:00 2001 +From: Alexander Sosedkin +Date: Tue, 14 Apr 2026 17:41:30 +0200 +Subject: [PATCH 1/2] x509/name_constraints: fix intersecting empty constraints + +Permitted name constraints were wrongfully ignored +when prior CAs only had excluded name constraints, +resulting in a name constraint bypass. + +With this change, they are taken into account and propagate. + +CVE: CVE-2026-42011 +Upstream-Status: Backport [https://gitlab.com/gnutls/gnutls/-/commit/1dead2faec6320aaba321eb56f20d442df192b83] + +Reported-by: Haruto Kimura (Stella) +Fixes: #1824 +Fixes: CVE-2026-42011 +Fixes: GNUTLS-SA-2026-04-29-6 +CVSS: 4.8 Medium CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N + +Signed-off-by: Alexander Sosedkin +Signed-off-by: Jakub Szczudlo +--- + lib/x509/name_constraints.c | 3 --- + 1 file changed, 3 deletions(-) + +diff --git a/lib/x509/name_constraints.c b/lib/x509/name_constraints.c +index 04722bdf4..232d466c4 100644 +--- a/lib/x509/name_constraints.c ++++ b/lib/x509/name_constraints.c +@@ -723,9 +723,6 @@ static int name_constraints_node_list_intersect( + type_bitmask_t types_in_p1 = 0, types_in_p2 = 0; + static const unsigned char universal_ip[32] = { 0 }; + +- if (permitted->size == 0 || permitted2->size == 0) +- return GNUTLS_E_SUCCESS; +- + /* make sorted views of the arrays */ + ret = ensure_sorted(permitted); + if (ret < 0) { +-- +2.53.0 + diff --git a/meta/recipes-support/gnutls/gnutls/CVE-2026-42011_p2.patch b/meta/recipes-support/gnutls/gnutls/CVE-2026-42011_p2.patch new file mode 100644 index 00000000000..29eb6bda43a --- /dev/null +++ b/meta/recipes-support/gnutls/gnutls/CVE-2026-42011_p2.patch @@ -0,0 +1,141 @@ +From 24713b8c63137ce0665b495d22ccce4f5ce05c84 Mon Sep 17 00:00:00 2001 +From: Alexander Sosedkin +Date: Tue, 14 Apr 2026 17:49:50 +0200 +Subject: [PATCH 2/2] tests/name-constraints-merge: extend to cover #1824 + +CVE: CVE-2026-42011 +Upstream-Status: Backport [https://gitlab.com/gnutls/gnutls/-/commit/24713b8c63137ce0665b495d22ccce4f5ce05c84] + +Signed-off-by: Alexander Sosedkin +Signed-off-by: Jakub Szczudlo +--- + tests/name-constraints-merge.c | 113 +++++++++++++++++++++++++++++++++ + 1 file changed, 113 insertions(+) + +diff --git a/tests/name-constraints-merge.c b/tests/name-constraints-merge.c +index 70376aaa7..3ff8d6c60 100644 +--- a/tests/name-constraints-merge.c ++++ b/tests/name-constraints-merge.c +@@ -473,6 +473,119 @@ void doit(void) + gnutls_x509_name_constraints_deinit(nc1); + gnutls_x509_name_constraints_deinit(nc2); + ++ /* 6: test intersecting empty permitted with non-empty permitted ++ * NC1: excluded DNS excluded.example.org (empty permitted) ++ * NC2: permitted DNS permitted.example.org ++ * Expected result: ++ * permitted=[permitted.example.org], excluded=[excluded.example.org] ++ * unrelated.example.com is rejected ++ */ ++ suite = 6; ++ ++ ret = gnutls_x509_name_constraints_init(&nc1); ++ check_for_error(ret); ++ ++ ret = gnutls_x509_name_constraints_init(&nc2); ++ check_for_error(ret); ++ ++ set_name("excluded.example.org", &name); ++ ret = gnutls_x509_name_constraints_add_excluded(nc1, GNUTLS_SAN_DNSNAME, ++ &name); ++ check_for_error(ret); ++ ++ set_name("permitted.example.org", &name); ++ ret = gnutls_x509_name_constraints_add_permitted( ++ nc2, GNUTLS_SAN_DNSNAME, &name); ++ check_for_error(ret); ++ ++ ret = _gnutls_x509_name_constraints_merge(nc1, nc2); ++ check_for_error(ret); ++ ++ set_name("unrelated.example.com", &name); /* entirely unrelated */ ++ ret = gnutls_x509_name_constraints_check(nc1, GNUTLS_SAN_DNSNAME, ++ &name); ++ check_test_result(suite, ret, NAME_REJECTED, &name); /* #1814 */ ++ ++ set_name("permitted.example.org", &name); /* permitted, direct */ ++ ret = gnutls_x509_name_constraints_check(nc1, GNUTLS_SAN_DNSNAME, ++ &name); ++ check_test_result(suite, ret, NAME_ACCEPTED, &name); /* sanity */ ++ ++ set_name("sub.permitted.example.org", &name); /* permitted, subdomain */ ++ ret = gnutls_x509_name_constraints_check(nc1, GNUTLS_SAN_DNSNAME, ++ &name); ++ check_test_result(suite, ret, NAME_ACCEPTED, &name); /* sanity */ ++ ++ set_name("excluded.example.org", &name); /* excluded, direct */ ++ ret = gnutls_x509_name_constraints_check(nc1, GNUTLS_SAN_DNSNAME, ++ &name); ++ check_test_result(suite, ret, NAME_REJECTED, &name); /* sanity */ ++ ++ set_name("sub.excluded.example.org", &name); /* excluded, subdomain */ ++ ret = gnutls_x509_name_constraints_check(nc1, GNUTLS_SAN_DNSNAME, ++ &name); ++ check_test_result(suite, ret, NAME_REJECTED, &name); /* sanity */ ++ ++ gnutls_x509_name_constraints_deinit(nc1); ++ gnutls_x509_name_constraints_deinit(nc2); ++ ++ /* 7: test intersecting non-empty permitted with empty permitted ++ * (same as 6, but swapped to ensure order doesn't matter) ++ * NC1: permitted DNS permitted.example.org ++ * NC2: excluded DNS excluded.example.org (empty permitted) ++ * Expected result: ++ * permitted=[permitted.example.org], excluded=[excluded.example.org] ++ * unrelated.example.com is rejected ++ */ ++ suite = 7; ++ ++ ret = gnutls_x509_name_constraints_init(&nc1); ++ check_for_error(ret); ++ ++ ret = gnutls_x509_name_constraints_init(&nc2); ++ check_for_error(ret); ++ ++ set_name("permitted.example.org", &name); ++ ret = gnutls_x509_name_constraints_add_permitted( ++ nc1, GNUTLS_SAN_DNSNAME, &name); ++ check_for_error(ret); ++ ++ set_name("excluded.example.org", &name); ++ ret = gnutls_x509_name_constraints_add_excluded(nc2, GNUTLS_SAN_DNSNAME, ++ &name); ++ check_for_error(ret); ++ ++ ret = _gnutls_x509_name_constraints_merge(nc1, nc2); ++ check_for_error(ret); ++ ++ set_name("unrelated.example.com", &name); /* entirely unrelated */ ++ ret = gnutls_x509_name_constraints_check(nc1, GNUTLS_SAN_DNSNAME, ++ &name); ++ check_test_result(suite, ret, NAME_REJECTED, &name); /* #1814 */ ++ ++ set_name("permitted.example.org", &name); /* permitted, direct */ ++ ret = gnutls_x509_name_constraints_check(nc1, GNUTLS_SAN_DNSNAME, ++ &name); ++ check_test_result(suite, ret, NAME_ACCEPTED, &name); /* sanity */ ++ ++ set_name("sub.permitted.example.org", &name); /* permitted, subdomain */ ++ ret = gnutls_x509_name_constraints_check(nc1, GNUTLS_SAN_DNSNAME, ++ &name); ++ check_test_result(suite, ret, NAME_ACCEPTED, &name); /* sanity */ ++ ++ set_name("excluded.example.org", &name); /* excluded, direct */ ++ ret = gnutls_x509_name_constraints_check(nc1, GNUTLS_SAN_DNSNAME, ++ &name); ++ check_test_result(suite, ret, NAME_REJECTED, &name); /* sanity */ ++ ++ set_name("sub.excluded.example.org", &name); /* excluded, subdomain */ ++ ret = gnutls_x509_name_constraints_check(nc1, GNUTLS_SAN_DNSNAME, ++ &name); ++ check_test_result(suite, ret, NAME_REJECTED, &name); /* sanity */ ++ ++ gnutls_x509_name_constraints_deinit(nc1); ++ gnutls_x509_name_constraints_deinit(nc2); ++ + /* Test footer */ + + if (debug) +-- +2.53.0 + diff --git a/meta/recipes-support/gnutls/gnutls_3.8.4.bb b/meta/recipes-support/gnutls/gnutls_3.8.4.bb index 6f1c2f21723..2d88bc181de 100644 --- a/meta/recipes-support/gnutls/gnutls_3.8.4.bb +++ b/meta/recipes-support/gnutls/gnutls_3.8.4.bb @@ -47,6 +47,8 @@ SRC_URI = "https://www.gnupg.org/ftp/gcrypt/gnutls/v${SHRT_VER}/gnutls-${PV}.tar file://CVE-2026-42009_p2.patch \ file://CVE-2026-3833.patch \ file://CVE-2026-42010.patch \ + file://CVE-2026-42011_p1.patch \ + file://CVE-2026-42011_p2.patch \ " SRC_URI[sha256sum] = "2bea4e154794f3f00180fa2a5c51fe8b005ac7a31cd58bd44cdfa7f36ebc3a9b" From patchwork Mon Sep 7 13:35:11 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 97524 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 8C661C79F89 for ; Mon, 7 Sep 2026 13:36:02 +0000 (UTC) Received: from mail-wr1-f42.google.com (mail-wr1-f42.google.com [209.85.221.42]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.34926.1788788160929562076 for ; Mon, 07 Sep 2026 06:36:01 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=QSRMl+2N; spf=pass (domain: smile.fr, ip: 209.85.221.42, mailfrom: yoann.congal@smile.fr) Received: by mail-wr1-f42.google.com with SMTP id ffacd0b85a97d-48441a2ba1bso2546245f8f.1 for ; Mon, 07 Sep 2026 06:36:00 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1788788159; x=1789392959; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=PzGRD5qmzD4epxo/cFESLmiBb9azDplO9McuQDpMmNc=; b=QSRMl+2NgmP4bGokJ+bFme/R6g0LyA8dyAV1oSmxJqiL0untI5IQGMFvrSp26HI4mt hRptrl1vI8UJRoIDIg5R90uBrUVf2om8ySrGna8xqPnOPHy8c/qTOdIRZ+fQ90TXZOIR Vzj8MnmikdSi1JEg4QgEJxSzbaRAE1AgRaMsQ= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1788788159; x=1789392959; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=PzGRD5qmzD4epxo/cFESLmiBb9azDplO9McuQDpMmNc=; b=ddxhukbQrh60WDFVMpKZLFapm0jOqmSFy2fIFl/+Y+FVUcrITePkJbpwG4FsIuLNWL Jjf6G3CplNMW50DhqAd5ariu+MK8amJRGec4W8715xcV5fGc3DJVRCZ/5qzLZ81QzMeM zK6KD2b2kSKRDIjvWzLO1pC6kD4pZ/P1/cm/Cqmuxkzk2UuCTU8vJqhiH/N7qp8nSGBj V03MqLC/miQGNWQfAGCD3zaIibi5RmBr+pmbxh/XX5ZEZemypveIGhSNsHQOFMVN96zS 37ioFnDMwc68VlEhR2UIejyNJ5uG1++O1oYzGoxy0YHPbF1y8upNg34V7/InMQsAK3cR LmJA== X-Gm-Message-State: AFuF++nlp49dkPlqzmWvLD8FUi+KfFtlXkIYxX/3XpOGNcHuTXyrA/4V mokcEZ/2NICTOzI6w0Oqote3z+5Ow+/FZfEdMlvOmJpnlgy+9jR1bK9+n7adG5aMtoHkBd111G6 2QO2a+Lk= X-Gm-Gg: AYBFou1ZjNl/mxlvgjR/7RAx9hDFjklsbjvX9YyWZeLDW+l6Az3lnWiPTLhGzRaiQKB e9hWo5myOKm3XT5WmBMc3zwxyoY9krMmiS66PJnEbDArhlOzBEImN2bNEF7XRy1o2I9FbelKA6k 8F3iRShrPzNgilaOJ00U6Q9CsVfVv4ODdXcSMz8sIWqQWClU7yzuooYDiuIC6Dj/jjMEKedgDCX zeHf7xsmCy39qBd6fIl5b2o8KyeN04KRzJNKU5C/tN0Kq5iE+W1D9qAypnC6g3NdFqSLJY1agew 6/7ac/F6dfjphM2CjxlMEqXWKLt8BEmGdF8/fMO0k91ZA7CReRxdpMqA5xLIysfG+onJcVwri8Y V8s8CM0pSlRPk94bT8iDwnHz8a7TiQgaFpL0/92pIb0H2Q3pWY3ajOnKB5qJ0RWodX85/CiTn5i /4NINDeMuWA0J1OSvLbl1GfgR9d4OjddvtmdCTa5StKfNAvlHKd6t8192nOQaYzFI3JArLYuYdf nuTwZNXAbMWRSG4yQ3y6jNb5S9w9eFRvYvD6gF0146EQCGZRefInnv3JjSC0dLK X-Received: by 2002:a05:6000:4286:b0:484:416b:7590 with SMTP id ffacd0b85a97d-485872a3cfemr25873771f8f.10.1788788159130; Mon, 07 Sep 2026 06:35:59 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-48588394fa1sm27523836f8f.8.2026.09.07.06.35.58 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 07 Sep 2026 06:35:58 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][scarthgap 15/35] python3-babel: fix CVE_PRODUCT Date: Mon, 7 Sep 2026 15:35:11 +0200 Message-ID: <27c524d5c69993338612461831f7aec054eb4d00.1788787321.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Mon, 07 Sep 2026 13:36:02 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/245273 From: Tim Orling Recipe (PV): python3-babel (2.14.0) Before -> After: python:Babel -> pocoo:babel Newly caught CVEs: CVE-2021-42771 (locale .dat deserialization RCE) Status: patched (fixed 2.9.1) Note: The original commit targeted python3-babel_2.18.0.bb. This is adjusted for Scarthgap, where the recipe version is 2.14.0. AI-Generated: Claude Sonnet 5 Signed-off-by: Tim Orling Signed-off-by: Richard Purdie (cherry picked from commit 134175fa92b85e639dc4646d9a88eeaba0fae4d3) Signed-off-by: Devansh Patel Signed-off-by: Yoann Congal --- meta/recipes-devtools/python/python3-babel_2.14.0.bb | 2 ++ 1 file changed, 2 insertions(+) diff --git a/meta/recipes-devtools/python/python3-babel_2.14.0.bb b/meta/recipes-devtools/python/python3-babel_2.14.0.bb index cd40d4222bf..5185fb21f56 100644 --- a/meta/recipes-devtools/python/python3-babel_2.14.0.bb +++ b/meta/recipes-devtools/python/python3-babel_2.14.0.bb @@ -9,6 +9,8 @@ PYPI_PACKAGE = "Babel" inherit pypi setuptools3 +CVE_PRODUCT = "pocoo:babel" + CLEANBROKEN = "1" RDEPENDS:${PN} += " \ From patchwork Mon Sep 7 13:35:12 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 97523 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 45448C79F9E for ; Mon, 7 Sep 2026 13:36:02 +0000 (UTC) Received: from mail-wr1-f44.google.com (mail-wr1-f44.google.com [209.85.221.44]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.34927.1788788161505748401 for ; Mon, 07 Sep 2026 06:36:01 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=jSl85l8W; spf=pass (domain: smile.fr, ip: 209.85.221.44, mailfrom: yoann.congal@smile.fr) Received: by mail-wr1-f44.google.com with SMTP id ffacd0b85a97d-48444ec4fe2so2150252f8f.0 for ; Mon, 07 Sep 2026 06:36:01 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1788788160; x=1789392960; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=hkRY3tJ41NlrnUvTjKfEAHj/lfBCKuSlv55EBnWIoCY=; b=jSl85l8WnoOkpN3j1noyDZv9JklJxVNJJFu64YjQbJSDb/WY6S4g9MBf9Ps03M0FPG vQs7Xjo1q1I618LyHeNuOfpKf1ek5Lx+rOJi8b5VoAZRfnSvKTYZWxwpgfg7U4oU9IH1 HrgChjJnuTJJAr+6J7IWbALgVHweOVDQS+xgo= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1788788160; x=1789392960; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=hkRY3tJ41NlrnUvTjKfEAHj/lfBCKuSlv55EBnWIoCY=; b=TkNXoknRIbeXJEALE/6F5As6SEdf70PcqrMerr0BWMJAdMI1jw/7wiD7J24sUCR3M4 /9ANJ0pqHOTiqe7V5+63kXGDMwNmJWAJCu0saC97UJvQs5EqQVhUNLWQ3Yw31cryH8b5 ZWIaRxrsU4BCrdzekjs/ayUcZtyUdgX9hR4gLKIpgZGvqRpYZWAH7WYYohSCQkVaT19Q V3dy79y/BgIT3dcGOU6vTPkN9qvSzVYjx9obU5ygSK+I8d6gAMxl2EpoaPIc0HmdeTas JwXWP+erJdmHIW2nXB7kHYduEYDwZBaspq1bd/dw1hadfVwLACSZ2Bnw0aY9OQ5IvF/O r6PQ== X-Gm-Message-State: AFuF++n+vxzJzvWdihmckhzRiMO3gfkTUBJVevLeB3EGCNoQQFe8+rBM 7z3EUAPsroQf11ECuUeaECG/RgcqkyGvizJLPuLownrVwm5yNbacI1BVoyzY45Lxl/tS5Gz+kdY yssPkSRI= X-Gm-Gg: AYBFou1rP5mDan89Ied4xjVUMj6WIlixf4mgwLkZvYzyqYZTOwkjBmcznIHlS9NhKA7 +lUbK6PAM68deeXYv3sK1eU/az5L2xFDWvDPQAtyTsHFJwLsbAJWaiVZOaG73qFNnuRxwUsecB8 RchtgPUZ++Jtsy2CeTJlcBzsxA7v1QEjxGosZko8bSo1Y90H6da2rxgirOYWhYNv71MhPNEYkHB iZm6hqyvJFZIsLFR7wGqpFcRVAcULsyobyEBMavvOX87W/5rtELh+6FAR4eX0bnF4RuTDmmNmNO 5JUpv685EmvMnRZ2Ji2uTLpH5JKSMCjg4OMX9XKfnSyd4DmxlfcdfgcR5Bcvooz4Ys7HAznl+pM m+NdM0PKLIU/WBMcQC8IccJD4U44uEKXj30mdwD4/Q/GAuOvKKce1/gYbF7GAwghzHTgyOJLj7L OQ4XO1xycY2BV7UmjAbtJcAwEDaqaLBjI0J88Rm2dfcOpjiBP1jJvyQKlr2Fgo6ksyICOU0s4BR WMUPgaGjX/vfJC8rMc8Hi9UUfKm3bsuLiU5Mm+NT6JhWhrtS9hMDw+j/l5MKzodJg== X-Received: by 2002:adf:e19e:0:b0:482:dac8:cd0d with SMTP id ffacd0b85a97d-48587288cddmr48720283f8f.21.1788788159669; Mon, 07 Sep 2026 06:35:59 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-48588394fa1sm27523836f8f.8.2026.09.07.06.35.59 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 07 Sep 2026 06:35:59 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][scarthgap 16/35] python3-click: fix CVE_PRODUCT Date: Mon, 7 Sep 2026 15:35:12 +0200 Message-ID: <0aa95f67c7e0363b59faa9d9bb60ee7c2d09b137.1788787321.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Mon, 07 Sep 2026 13:36:02 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/245274 From: Tim Orling Recipe (PV): python3-click (8.1.7) Before -> After python:click -> palletsprojects:click Newly caught: CVE-2026-7246 (command injection in click.edit()) Status: unpatched (fixed 8.3.3) Note: The original commit targeted python3-click_8.4.2.bb. This is adjusted for Scarthgap, where the recipe version is 8.1.7. The unrelated DESCRIPTION cleanup from the original commit is intentionally omitted. AI-Generated: Claude Sonnet 5 Signed-off-by: Tim Orling Signed-off-by: Richard Purdie (cherry picked from commit 30357a26d7ce490725d1b0ac3375047d00595a5c) Signed-off-by: Devansh Patel Signed-off-by: Yoann Congal --- meta/recipes-devtools/python/python3-click_8.1.7.bb | 2 ++ 1 file changed, 2 insertions(+) diff --git a/meta/recipes-devtools/python/python3-click_8.1.7.bb b/meta/recipes-devtools/python/python3-click_8.1.7.bb index 7d91e1af838..b75d9108893 100644 --- a/meta/recipes-devtools/python/python3-click_8.1.7.bb +++ b/meta/recipes-devtools/python/python3-click_8.1.7.bb @@ -14,6 +14,8 @@ inherit pypi setuptools3 ptest SRC_URI += "file://run-ptest" +CVE_PRODUCT = "palletsprojects:click" + RDEPENDS:${PN}-ptest += " \ python3-pytest \ python3-terminal \ From patchwork Mon Sep 7 13:35:13 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 97540 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 507FAC79FB5 for ; Mon, 7 Sep 2026 13:36:05 +0000 (UTC) Received: from mail-wr2-f12.google.com (mail-wr2-f12.google.com [74.125.225.76]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.34929.1788788162001177338 for ; Mon, 07 Sep 2026 06:36:02 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=izwmranR; spf=pass (domain: smile.fr, ip: 74.125.225.76, mailfrom: yoann.congal@smile.fr) Received: by mail-wr2-f12.google.com with SMTP id ffacd0b85a97d-482f62ccdb1so69882f8f.1 for ; Mon, 07 Sep 2026 06:36:01 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1788788160; x=1789392960; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=xf08nSSbQ8EEQ+XAvAkwH80uulQFqSvs9TBEm7AsgvY=; b=izwmranR3S2X7OkllUqCVh3HDQVlJO3yYczqkVFSetvh8KC+WIXMPHjdKGi2zpCRyx N2exnqjPe3MJsfRshq2Goi59NPKuBboO2y3JSzof2cEjFzcJiJqWdGQXtrV1WvW6k8xY Dri5hsXpbUr32CgbFPfYweZcEIA63vKXU603E= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1788788160; x=1789392960; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=xf08nSSbQ8EEQ+XAvAkwH80uulQFqSvs9TBEm7AsgvY=; b=dmxx8neXIwPxNV4iSBx6mSRc5AJmI4rZ2yy5bhKDXA0IdsZfUiC175nkXxwTFh+xQZ zc56Ub1FgPf9z0KqHXKfOkFQCav8CBhnznGKsk1SgC2GI1g8BBlBdZUieNn5WLhYWxu7 w3thvxG6MYXmPokh63og2FkEpHIxQU0c8DE07KyXe0tev4Io8VZHu7NNi9TG3poTkmui m55xqi4oaw45QvC7nkPq6HMgM34qbbjsX0V344LMC1qQFacfsmyQPi34KRS5OpEuW7o5 KYhAzmWEMLbMms3K8I2kU6H6ueTTZ4QOXEW6aZY218udjrfqxaYrV0o7J/SjwvzLry7U yyMw== X-Gm-Message-State: AFuF++kplTIJgPojFzdeRbHYkInIMRtwEQh9NG75tz+OAHAq/EG+3cpZ 2qTWgftJT/Th6Yer/jZH197Zcxeh36PO1XuQ9Na6TY1MNd9Q7TU9eMQ/jgKUYLzovaY+eDEnLi0 vHaPY0KY= X-Gm-Gg: AYBFou3sd0c1KiE8rArsynB0doYGcrCKW2EGcjpuHYJufSxZk1pJY/fV85WNXr2PWL7 jEVtFl2LVOAv4LAZwzfBxMIdsTd6qLqWWqCH6oSBYzAmcHKYG7Y8RdvJlvmf7XbddfrUx68m2f0 o05Jor/7wuvMxeYoqAJQ+XFINPMgs7R748BY+jLat4DTRxjQAk/j2b7s/Q5NbQdgbkHF/a8ISug Ebjjlzw+amRb8sBU3iFVCYISoetujwmz/gwQsyNuF2AQNNyQi4yxhhmQnaTEsup+UeymS5GPxKx UcA3n8wQ6+pkOx647nCThEIwUE7kuylwTF5+qhbHNvH7vLy1siA+SsxPMkmuWWsMsoge1HcLNS6 cSgT4PNKe/SW6CJSiFeB77yjooDxXwiCf1mMvRLlJqIVAn7VyUgm2aqer+aq53Bl16N5gUNl5Vn OMe4j3CHd8iaPr/mrZ7jUFmBU2iNqmPMWr7NVZDonTC2qMLG6ZOpRtuGvaIOXdHqkI6msMHtBz4 GHi6GTsskiRNMLeE7mAa9lF1tMwD/avUlk/Dxy+rNkvLYXjm1y8gnaJJrSjtmUU X-Received: by 2002:adf:e944:0:b0:485:8ea0:da8c with SMTP id ffacd0b85a97d-485a242f46cmr1011569f8f.16.1788788160194; Mon, 07 Sep 2026 06:36:00 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-48588394fa1sm27523836f8f.8.2026.09.07.06.35.59 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 07 Sep 2026 06:35:59 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][scarthgap 17/35] python3-dbusmock: fix CVE_PRODUCT Date: Mon, 7 Sep 2026 15:35:13 +0200 Message-ID: X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Mon, 07 Sep 2026 13:36:05 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/245275 From: Tim Orling Recipe (PV): python3-dbusmock (0.31.1) Before -> After: python:python-dbusmock -> python-dbusmock_project:python-dbusmock Newly caught CVEs: CVE-2015-1326 (.pyc code exec via AddTemplate) Status: patched (fixed 0.15.1) Note: The original commit targeted python3-dbusmock_0.38.1.bb. This is adjusted for Scarthgap, where the recipe version is 0.31.1. AI-Generated: Claude Sonnet 5 Signed-off-by: Tim Orling Signed-off-by: Richard Purdie (cherry picked from commit 0405d7d4e476964239e1c27c987ec9c12372e95f) Signed-off-by: Devansh Patel Signed-off-by: Yoann Congal --- meta/recipes-devtools/python/python3-dbusmock_0.31.1.bb | 2 ++ 1 file changed, 2 insertions(+) diff --git a/meta/recipes-devtools/python/python3-dbusmock_0.31.1.bb b/meta/recipes-devtools/python/python3-dbusmock_0.31.1.bb index fc32c6bbb6c..4145ee8ea70 100644 --- a/meta/recipes-devtools/python/python3-dbusmock_0.31.1.bb +++ b/meta/recipes-devtools/python/python3-dbusmock_0.31.1.bb @@ -11,6 +11,8 @@ PYPI_PACKAGE = "python-dbusmock" inherit pypi python_setuptools_build_meta DEPENDS += "python3-setuptools-scm-native" +CVE_PRODUCT = "python-dbusmock_project:python-dbusmock" + RDEPENDS:${PN} += "\ python3-dbus \ python3-unittest \ From patchwork Mon Sep 7 13:35:14 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 97541 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 726A7C79FB7 for ; Mon, 7 Sep 2026 13:36:05 +0000 (UTC) Received: from mail-wm1-f46.google.com (mail-wm1-f46.google.com [209.85.128.46]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.35222.1788788162485907014 for ; Mon, 07 Sep 2026 06:36:02 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=iF0zkoTI; spf=pass (domain: smile.fr, ip: 209.85.128.46, mailfrom: yoann.congal@smile.fr) Received: by mail-wm1-f46.google.com with SMTP id 5b1f17b1804b1-49b8e527d63so42257195e9.2 for ; Mon, 07 Sep 2026 06:36:02 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1788788161; x=1789392961; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=MColx7J6XcM0MYgfPUh8PlP59JqdWIZBob2boqar3B0=; b=iF0zkoTIxMwFf0NLcvSueow27xgwNeOsqGCdjSnT5CRImGOkXod3BM99OIPTziDr4d Io/SK38wF3KEstZdeBnOo3AaXufP9k8hgahLPCSNmX9uyel6wOhwAV1zJK79HaPg4dPh RU9+lsUSmbszO0HhpDHzh76rmG1Q678lAiGpw= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1788788161; x=1789392961; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=MColx7J6XcM0MYgfPUh8PlP59JqdWIZBob2boqar3B0=; b=CivYABV+qt+3istgaywBFInZFRh6tqEcOV97IjU0XtSeysyeCGX6YxOWujkcz4MT7g 7i9dfsakc2sbWg0/E4DP2F+TEI301tQDTGSafu5W/OLqLKgHiEJCNyu7/wRY13i28n56 2h70Er0DaIU7/y6fpxfNKIvw/mMvENHro5oiIvtPXc8gHm5eJj9EAyGuOH+gdmCgDbER /AvZdgxhdftmR/nPSmeyMhaTy09Ee6AHwNvH0YVbtyG+8EQ6JnQPnZLbxR7OYlmZ/OXP gQ8C8pGaKWtT4L+3SKO0rdFiS5xjmwnn5g+iMRiIL/46TmbnY82F4O2FjGQJAOMcuBnc Z0NA== X-Gm-Message-State: AFuF++kSM8IdF05rKpytRZ4IsrWtijGSJuCQ1OyJuR2jQzSjlyalCgme hcPxLzO017Proy42X2bofa2xRq1lRfK7XoHCphCsRQL0LyJhO8HRPu4wEi0RNydbMdpP3jRezTt GIYfrTQ4= X-Gm-Gg: AYBFou1de2cEXyGBWySxVAAauXgjgMvkhGhTfWqtyCaadsVkWLTA54WPvpOH4+0/BUS 2lrvOK089NFD4cO+KdVzh+d+t8HwrYhUMcQ4ulb//XKzHbbVQH1S4i51auMDS56lSnaYNks8utw ynPde/R1s9kIef9flDoXNza3nhZdtfyvP2NBkW2FApyH4/SpMOCJwuOmnys8Hnr+j+FkHkPqoTM QILNfAst4LqEGgER4Pc6bxasm6305e8oMGztoY1R7hADusmYG4Es3eTEq/15N5HRs+I6jCw1W+0 YcxhZqJzRDJB9tF9gcsfMYmkxoctAUaDzrsv8DJ+VaxyytBqJeSurWcMyTjwoxlGYTZL/WvlFHT 8H9zKcDo5UKou5+VNl4jXqppskk8W+vgKMzzsSWuVqvuOGPxu00MVuWmXqaGt9QmDpRONl98sC/ AJ6/zwIGjifArW43kCEsmUkbAcXmIZzMw7ifFbE2tlLwYsKJwSryj0+yrijZYxGKaztFolZ4H3I yV8p5Aa3iuqxI1tHkiLK6TUAdgo3LOtQAruTD9B+ej+t/9wkedkHtZocf1T2FXN X-Received: by 2002:a05:600c:138a:b0:49c:fc6e:8cba with SMTP id 5b1f17b1804b1-49cfc6e8e34mr200530055e9.30.1788788160695; Mon, 07 Sep 2026 06:36:00 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-48588394fa1sm27523836f8f.8.2026.09.07.06.36.00 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 07 Sep 2026 06:36:00 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][scarthgap 18/35] python3-attrs: fix CVE_PRODUCT Date: Mon, 7 Sep 2026 15:35:14 +0200 Message-ID: X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Mon, 07 Sep 2026 13:36:05 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/245276 From: Tim Orling No new CVEs are caught, but attrs_project:attrs matches the upstream NVD dictionary CPE. The pypi.bbclass default "python:attrs" generates the wrong product identity for the packaged attrs source. This changes the generated product identity, but the Scarthgap cve-check database snapshot has no current CVE report delta. Note: The original commit targeted python3-attrs_26.1.0.bb. This is adjusted for Scarthgap, where the recipe version is 23.2.0. AI-Generated: Claude Sonnet 5 Signed-off-by: Tim Orling Signed-off-by: Mathieu Dubois-Briand Signed-off-by: Richard Purdie (cherry picked from commit bc07eddb82fe42ecf86e685450ec0b5c9d3a9ce1) Signed-off-by: Devansh Patel Signed-off-by: Yoann Congal --- meta/recipes-devtools/python/python3-attrs_23.2.0.bb | 2 ++ 1 file changed, 2 insertions(+) diff --git a/meta/recipes-devtools/python/python3-attrs_23.2.0.bb b/meta/recipes-devtools/python/python3-attrs_23.2.0.bb index e39b64306c2..99cae50e9be 100644 --- a/meta/recipes-devtools/python/python3-attrs_23.2.0.bb +++ b/meta/recipes-devtools/python/python3-attrs_23.2.0.bb @@ -7,6 +7,8 @@ SRC_URI[sha256sum] = "935dc3b529c262f6cf76e50877d35a4bd3c1de194fd41f47a2b7ae8f19 inherit pypi ptest python_hatchling +CVE_PRODUCT = "attrs_project:attrs" + SRC_URI += " \ file://0001-test_funcs-skip-test_unknown-for-pytest-8.patch \ file://0001-conftest.py-disable-deadline.patch \ From patchwork Mon Sep 7 13:35:15 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 97545 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 84111C79F89 for ; Mon, 7 Sep 2026 13:36:05 +0000 (UTC) Received: from mail-wm1-f45.google.com (mail-wm1-f45.google.com [209.85.128.45]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.34931.1788788163015793588 for ; Mon, 07 Sep 2026 06:36:03 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=yK4yKimO; spf=pass (domain: smile.fr, ip: 209.85.128.45, mailfrom: yoann.congal@smile.fr) Received: by mail-wm1-f45.google.com with SMTP id 5b1f17b1804b1-495590dde14so51172705e9.0 for ; Mon, 07 Sep 2026 06:36:02 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1788788161; x=1789392961; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=vjp3b/UMm5St/rUmHAgmWHzHBBqCUF4qFoxcnImb89A=; b=yK4yKimOweAW5oXk9u1kTDcPjf3EmfudA1YVQui2arn44gjdGMVoS3cH22XUprrQ7d WfeLNeyufdNb4n03wknXlidcNLogmmtJIyxZJmCojz9x8xGcLqgoX/V+FGNRR3bMM7wb uNTFPymteykQNPNapmXwUxAlNSfdMQzo7NKws= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1788788161; x=1789392961; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=vjp3b/UMm5St/rUmHAgmWHzHBBqCUF4qFoxcnImb89A=; b=G+uHvqEOwa43LV7ZdtXGYJc/628s029HjR0ftwrsvdBvf6MghE4HJivcYMg5hL/At/ H8xaD4QBgI4uKaVWIhStF2PmjZxKcslgn8pLM79133eVBUC9CpWgovKaoLjvMj7cootV FvfxjPqzK15ypPP3Noi7h/nVwwcczJNuk7T6YNwBT4jNbRxOpnbxNW3oY5YLkt1l+uOn 3RdKD2iNtb41wmKCVN1WPUOEs/DUVobEXjLILTrKKl9/58rIMdFMQOTK3jTDnnaPvzp7 UiLrRVuvKmaYcrLIsCzvzHNuI7mkr0PBHCpVY23bKFA7eMbQFAtrrjDd5ZztBkIR0yTr dmHw== X-Gm-Message-State: AFuF++mvyEnDmw5oikVYVksW8iZGDMDxe8bqU3lh7giqtzqLpyMn6naz G8nSs4702gAJ3PyizfJ03tECSkJDKkC5hZ3H4R0knaIFHfEvxsonNr2W9+yJojPk3rlNv/8vrXM yPN8GHCw= X-Gm-Gg: AYBFou173o2zBGRm7E8xa9jxBtiRDbEFf9mtkwg9a9+g3jnSxHA/cLiIaQoutCTEq0j LiqMuYh10aWLCcNJ5Q6FcgQU1DEe6nGv2S9RWSH+tFWsvPFUBYxjBfGoCIS+KUs+Xl0y6Kd+XAo baJD6e/hrB/67GLe0+ZEyIJnDe+pXvmKjDh+ESiRknQt8QvkZz8CLJhV8AWKqz0rP/B7aDJOr9r BCLwd8EVryNROYhK6eyhPF+9M+X8wyCMB4HRZ3FBrvomTpo0wsGZgedNrjgTOTQ6Prvt31KVDVX x/5XDDduqmurYNKv+Y9HqL+Cf30X1ncxUNznXpZj8hBlGQg2z7hwC6hINBD0L8F65mreHQSdKCX lnYCaZg/+Tm/05qxAruROwjEzhvcwTJoWRBl8oNg8vw3XjPFP1iEJdYzhUXy+woUin3hQ8Pybn7 ku9JT7MPj9T9ODmDODx503Uh+cSA+Rv5dKsbDlYmE+oGnfY9OrLRsZ0eqkHX8nOfS+3OHiYWIV3 zwEoLYhp5FK+xsB/YLKnpIXNHicFbDYlSPfZhcbDWOUwkz9Dfa3aQly9cylYbva X-Received: by 2002:a05:600c:6290:b0:499:8174:9f39 with SMTP id 5b1f17b1804b1-49cf7f3d239mr498819175e9.0.1788788161154; Mon, 07 Sep 2026 06:36:01 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-48588394fa1sm27523836f8f.8.2026.09.07.06.36.00 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 07 Sep 2026 06:36:00 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][scarthgap 19/35] python3-numpy: fix CVE_PRODUCT Date: Mon, 7 Sep 2026 15:35:15 +0200 Message-ID: <5e73d32ea99d8e909bfb861a9f9c291c39497233.1788787321.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Mon, 07 Sep 2026 13:36:05 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/245277 From: Tim Orling Without this change, 0 CVEs are reported. With this change, 8 Patched CVEs are reported: * CVE-2014-1858 * CVE-2014-1859 * CVE-2017-12852 * CVE-2019-6446 * CVE-2021-33430 * CVE-2021-34141 * CVE-2021-41495 * CVE-2021-41496 This can be verified with a query like: $ cat .../core-image-ptest-python3-numpy-*.rootfs.sbom-cve-check.yocto.json \ | jq '.package[] | select(.name == "python3-numpy") \ | .issue[] | {id: .id, status: .status}' Signed-off-by: Tim Orling Signed-off-by: Mathieu Dubois-Briand Signed-off-by: Richard Purdie (cherry picked from commit ad623e71fadeddcb0b70bba8fbf28c75a976e596) The current "python3-numpy" mapping has no matching NVD CPE or configuration identity, so eight source-aligned CVE records are missed. Use "numpy:numpy", the active NVD dictionary CPE and configuration identity for the packaged NumPy source. Note: The original commit targeted python3-numpy_2.5.2.bb. This is adjusted for Scarthgap, where the recipe version is 1.26.4. Signed-off-by: Devansh Patel Signed-off-by: Yoann Congal --- meta/recipes-devtools/python/python3-numpy_1.26.4.bb | 2 ++ 1 file changed, 2 insertions(+) diff --git a/meta/recipes-devtools/python/python3-numpy_1.26.4.bb b/meta/recipes-devtools/python/python3-numpy_1.26.4.bb index ccd08147af6..9164874445e 100644 --- a/meta/recipes-devtools/python/python3-numpy_1.26.4.bb +++ b/meta/recipes-devtools/python/python3-numpy_1.26.4.bb @@ -18,6 +18,8 @@ SRC_URI[sha256sum] = "2a02aba9ed12e4ac4eb3ea9421c420301a0c6460d9830d74a9df87efa4 GITHUB_BASE_URI = "https://github.com/numpy/numpy/releases" UPSTREAM_CHECK_REGEX = "releases/tag/v?(?P\d+(\.\d+)+)$" +CVE_PRODUCT = "numpy:numpy" + DEPENDS += "python3-cython-native" inherit ptest setuptools3 github-releases From patchwork Mon Sep 7 13:35:16 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 97538 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 62E32C79FB6 for ; Mon, 7 Sep 2026 13:36:05 +0000 (UTC) Received: from mail-wm1-f52.google.com (mail-wm1-f52.google.com [209.85.128.52]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.34933.1788788163484207661 for ; Mon, 07 Sep 2026 06:36:03 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=H4QIQPvE; spf=pass (domain: smile.fr, ip: 209.85.128.52, mailfrom: yoann.congal@smile.fr) Received: by mail-wm1-f52.google.com with SMTP id 5b1f17b1804b1-49b8e527d63so42257445e9.2 for ; Mon, 07 Sep 2026 06:36:03 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1788788162; x=1789392962; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=SAskPluaM8odMofqN25Egv6+LhpJZ8/Ov4RxtL79v/o=; b=H4QIQPvE/0StUr/CQTrxpVTzofgvWRk/3F7Veg1VfCLAodcOjGkdBCh/f0O69zzHm2 9kEuoocSOc3zm0qa/Lhb46koRcplir66esxSngU7qxWFKdBqfiut9vLQtuG+suX7bDdY pQT0+KfyRT+rRNDua20qZardYDPrt9TNT6P8I= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1788788162; x=1789392962; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=SAskPluaM8odMofqN25Egv6+LhpJZ8/Ov4RxtL79v/o=; b=bn9whNSuPk7lMd3akhNfYZEECaIko4Gw0yvuqIiqaFEXrERIhxGHwx3AuG7BXtsS63 v3Gt0xfWrxz1euJg2v4FXjAPnDPiJkPAMgKNHZWl7rZQCqJhiBOzbtgw179VkvZDdNm9 3puHT8OdDoL0d+QyYeHuTk05GxSxVK9Vd+1uugkv8TIRDZjPkz+seXw4Z1NZOF64PLM2 qeGrJAQnqYbOxGz3EXxnkq4WEoqAygcBSKhWujNbcAMWjVxpedAe+VVe/9XyIO9g7Zmq zM7wPN5asLmzwWEKOVj+U/vXF/XL6Rj0HCZ/aeW2gar5yBMDYzKidqhpzxQXWpJm0RTY nFsw== X-Gm-Message-State: AFuF++msvuK9Nj8yk7PuhrfW2lLlFXtoEBCAGaYLL1fXracCLexFVfvT tmdU3nWYiC9/qDcDsi9XlMgsxdF4QZFTLCE+r4DFjXDDnU5TCA5J5NUV5WuV+KOsnSR2rJXCf7+ IS1rfd4k= X-Gm-Gg: AYBFou2+nDxIVxLyVURF0bFX+OwMHoyQQA+bcqnr9LiEs7XPlP+LVDo+E4F8utOEqCu U+4cmJKz6VxBWkoYb3kD9kOqyBL54ENN0Zwk1wFbR4q5IEuMdAVhkbyucgV9l+qgFsLtUdj5YnC Rm4XQiIsAUDayz+6yxJKPH1Idf9SasG10iBk+E0i41fCQ6+cmR54CHSbcGM3v6bYV9qNswpF9/l YuInzXajBVl/jKTkI9ZSGvY1ZFjygZSE/UCAX4ipZhumuKrT2PrvwB4Ec3aTrpX/EfOrizFbBvZ wM+gL+td5ovHtN0YIw7K5ceBwkSKYrSSAiP0imKr+QZP4Rit+DGN1mh9K5OS2qMghb/nf7AwJ2H WPuVOLWN0aWv0AX5FdBcBXU4sVjWaaWrtFlsugylONsfMBCNTZPLJg/knHZu5TDFtmm9bNKq4Ng 8x8RCJDf/KUUpl5rjEzYJtivuLWbiEKhhCCoFtPa8IclbyFJcboMvKQuj5kbiN67cd3RmAHofyu E0yz3q1quCbQ28lFRGZphGqRc7Rz7RM0b6cQqgK7xrpN3mjgzJjtHN+QmthJ8y8 X-Received: by 2002:a05:600c:19d1:b0:49c:fc6e:8cbb with SMTP id 5b1f17b1804b1-49cfc6e8e05mr232009335e9.31.1788788161695; Mon, 07 Sep 2026 06:36:01 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-48588394fa1sm27523836f8f.8.2026.09.07.06.36.01 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 07 Sep 2026 06:36:01 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][scarthgap 20/35] python3-pycryptodome: fix CVE_PRODUCT Date: Mon, 7 Sep 2026 15:35:16 +0200 Message-ID: X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Mon, 07 Sep 2026 13:36:05 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/245278 From: Tim Orling With this change, 2 Patched CVEs are properly reported: * CVE-2018-15560 * CVE-2023-52323 Signed-off-by: Tim Orling Signed-off-by: Mathieu Dubois-Briand Signed-off-by: Richard Purdie (cherry picked from commit f8a88010edc6edbb168cbc31aa5df847a328661c) The current pypi default "python:pycryptodome" is deprecated and does not match current NVD configuration criteria. Use "pycryptodome:pycryptodome", the active NVD dictionary CPE and configuration identity for the packaged source, so two patched CVE records are reported. Note: The original commit targeted python3-pycryptodome_3.23.0.bb. This is adjusted for Scarthgap, where the recipe version is 3.20.0. Signed-off-by: Devansh Patel Signed-off-by: Yoann Congal --- meta/recipes-devtools/python/python3-pycryptodome_3.20.0.bb | 1 + 1 file changed, 1 insertion(+) diff --git a/meta/recipes-devtools/python/python3-pycryptodome_3.20.0.bb b/meta/recipes-devtools/python/python3-pycryptodome_3.20.0.bb index 6c93c205ac8..69bb6da44ef 100644 --- a/meta/recipes-devtools/python/python3-pycryptodome_3.20.0.bb +++ b/meta/recipes-devtools/python/python3-pycryptodome_3.20.0.bb @@ -3,3 +3,4 @@ inherit python_setuptools_build_meta SRC_URI[sha256sum] = "09609209ed7de61c2b560cc5c8c4fbf892f8b15b1faf7e4cbffac97db1fffda7" +CVE_PRODUCT = "pycryptodome:pycryptodome" From patchwork Mon Sep 7 13:35:17 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 8bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 97539 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 4C5BBC79F9E for ; Mon, 7 Sep 2026 13:36:05 +0000 (UTC) Received: from mail-wr1-f44.google.com (mail-wr1-f44.google.com [209.85.221.44]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.35223.1788788164155065280 for ; Mon, 07 Sep 2026 06:36:04 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=rJprwiI8; spf=pass (domain: smile.fr, ip: 209.85.221.44, mailfrom: yoann.congal@smile.fr) Received: by mail-wr1-f44.google.com with SMTP id ffacd0b85a97d-482f2ee53e7so2609711f8f.1 for ; Mon, 07 Sep 2026 06:36:03 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1788788162; x=1789392962; darn=lists.openembedded.org; h=content-transfer-encoding:content-type:mime-version:references :in-reply-to:message-id:date:subject:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=l1tdomWYWRCRpUy9fWq4QEfRsKWsA3sytjpkRYnudJY=; b=rJprwiI8QjTZ18QQrxIV6H/dBoOY1aN4dP9u3elRuxxtipAshPwWD0yX58rnlTIxpy lq3WUZxCa3p0ifpHZCbNepLpQGodxaIf9yvcbeXiqJsQzoIFquCHkL8jSPIY+XeaOuEw HUHA8Q+zZDmYDYxt3ULRMorfODvzFumX53Ilc= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1788788162; x=1789392962; h=content-transfer-encoding:content-type:mime-version:references :in-reply-to:message-id:date:subject:to:from:x-gm-gg :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to :content-type; bh=l1tdomWYWRCRpUy9fWq4QEfRsKWsA3sytjpkRYnudJY=; b=fZ18SE0v24s3VFSjTFHy0tSBQF2w36kVW5j1DMsynI9ewtdDdfv+a/Z+Ek9Aa1S12k PJv2zcycR3knxSPZsoO2E9+PQtpBEFYM86bfE0VGtS9qm7YRhKOytrpFNupD/h/eQJwt I3IbGW0fxKj9npz8UatnWDqo4/TNswkanbUXqRo20gBb1HoBreeXdvbtq36sawgly9Jk fTb5SLsmQrhniAs72r70OxKpqW7D5VnbA1ACyF/aIYLJ1EXX5Q9woeXYGrTx1lg6sf0+ tw9aFODAqa76+wz+aSwRYxzHlL0Nvm2xdUtc+HRdpBkwsBNPeR42HxpFBNnJgqIa82EY djrw== X-Gm-Message-State: AFuF++mZfQfM/S4ppPPFVp2yowinq65wI7WHDmapo5673RoNe01XYN8u 5lQBlrOkeTxGikcmqcvcBQNQvgJaMlxO50Z6VB/r8lu9TMjwrKAYefTCASx/yVi2CcaCSpQPijq eR7Q7QYs= X-Gm-Gg: AYBFou0p7ot5C1a/KOt9gL/ZByfIr8IEbVEpeUcZxziB3O0e87XdD48lOzGgH4SEU60 3T/gw7axnfddIXXZTOmy6d7Msm57t48KgXjAs9G3zAXBeHU4+sQib42hBJgOvhyh6GRUW4W5KVL RE1sguJ4S1zHRohqavn+BrK6uq56qpaZjdyeR88skKX83jXRG5IAOtxX78P3cKsf4cYgGMWbNnB Zcp+yII0POGZyuwgSUPFQEvi/y63TwFUaaKK7s59JichXOjsQ7NmZ7aIAzWZN3B3erGljH2Krhj cuPotyGF1FwE4p8kKxm2znxBuKG58WJWadIczikvLmjh+giCOBAu1uaJ8znxUDma8qcABI7jn9Q RX0Va3oJoEKt1aNO2McsmHjKDqv36MeSkymdkRqMHWP5wb9k/06JILIxHAqqJdxajV9LY7Iqplh tOUUmirzVD+Lls4DaJ74XtSu6VG04kf10M9hTFeQJH6LeQ4xxlzyBRRbimZcubbtQyy0EiOhaot VAH43+pCQKvXvbWoqbo0Zq7pmS8XQalx7n8Aefk8wz87e5m9LpCrQjS/JrJ7JU4 X-Received: by 2002:a05:6000:2c05:b0:485:8c17:9771 with SMTP id ffacd0b85a97d-4858c179a47mr21795352f8f.51.1788788162366; Mon, 07 Sep 2026 06:36:02 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-48588394fa1sm27523836f8f.8.2026.09.07.06.36.01 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 07 Sep 2026 06:36:01 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][scarthgap 21/35] python3-wheel: fix CVE_PRODUCT Date: Mon, 7 Sep 2026 15:35:17 +0200 Message-ID: <6125825144dac3f5aea440307e4b6b7e76d5333a.1788787321.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Mon, 07 Sep 2026 13:36:05 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/245279 From: Tim Orling The proper CVE_PRODUCT is "wheel_project:wheel". BEFORE: python:wheel -> 1 CVE AFTER: wheel_project:wheel -> 2 CVEs * Both are patched at 0.42.0. - CVE-2022-40898 — DoS in wheel CLI via malicious input. Affects <0.38.1. - CVE-2026-24049 — malicious wheel file can modify permissions of arbitrary files. Affects 0.40.0–<0.46.2; covered by the existing CVE-2026-24049.patch. Note: The original commit targeted python3-wheel_0.47.0.bb. This is adjusted for Scarthgap, where the recipe version is 0.42.0. AI-Generated: Claude Sonnet 5 Signed-off-by: Tim Orling Signed-off-by: Richard Purdie (cherry picked from commit fe55278e01bbe434452191109278b436bf008ebc) Signed-off-by: Devansh Patel Signed-off-by: Yoann Congal --- meta/recipes-devtools/python/python3-wheel_0.42.0.bb | 2 ++ 1 file changed, 2 insertions(+) diff --git a/meta/recipes-devtools/python/python3-wheel_0.42.0.bb b/meta/recipes-devtools/python/python3-wheel_0.42.0.bb index 934f258a93d..b3e4a08d859 100644 --- a/meta/recipes-devtools/python/python3-wheel_0.42.0.bb +++ b/meta/recipes-devtools/python/python3-wheel_0.42.0.bb @@ -8,6 +8,8 @@ SRC_URI[sha256sum] = "c45be39f7882c9d34243236f2d63cbd58039e360f85d0913425fbd7cee inherit python_flit_core pypi +CVE_PRODUCT = "wheel_project:wheel" + SRC_URI += "file://CVE-2026-24049.patch" BBCLASSEXTEND = "native nativesdk" From patchwork Mon Sep 7 13:35:18 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 97543 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 14FCDC79FB8 for ; Mon, 7 Sep 2026 13:36:06 +0000 (UTC) Received: from mail-wm1-f47.google.com (mail-wm1-f47.google.com [209.85.128.47]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.34935.1788788164729217858 for ; Mon, 07 Sep 2026 06:36:05 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=QGrEy8Su; spf=pass (domain: smile.fr, ip: 209.85.128.47, mailfrom: yoann.congal@smile.fr) Received: by mail-wm1-f47.google.com with SMTP id 5b1f17b1804b1-498028b3d5eso33834505e9.1 for ; Mon, 07 Sep 2026 06:36:04 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1788788163; x=1789392963; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=ggvz4lOSk8CReJPBkHQ62QocwWdiMoR0R3a1ZPXh//o=; b=QGrEy8SuFO8dSjOljqKXP3a7fZiCXGOqJumaqxGrNvUiIny/Ww79IZsRQNNnPAXnNv RinDeOXTaPWET9QFzW7Nmtmm/UqHg3B+6xGOP3ggqQRFHr+S45GQZAC3wnsoy575jPfu 4Zqt8BC3N9tLyF9lVUD1+y42Pb880syk28iFU= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1788788163; x=1789392963; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=ggvz4lOSk8CReJPBkHQ62QocwWdiMoR0R3a1ZPXh//o=; b=CK0/s2sJdBqYk77r4tnAxmGaoEC11+oJiWc7TChEK6ULDKAQbRTgjqeKwHVp5ZMMHq zh/KXOLhH/1NzOb5mmlsDRfX5vUq7Wc/POZb8PAh6Rfr8uennd7gAiC4rmUAdtrpkVdc Gq9ocYj+yPeXDCKfjRDye7kcwymGvZP1T8CNx1GhGwO9ONj7slwBxllzRc12LU7qGYGt vFxaMyhQATaoAoAKmGeN5Y9t9F74Q6Oxx5YrWa1WkuMJB27wMqcBZFki5pcMoZObacWB kfGQAGiDZhfa+FNI4lRII9NWSoM0M70NNkSiDHTOburl6J1zO8oIGPr8uamf9eDubHNn 2KRQ== X-Gm-Message-State: AFuF++lhE1Io0vmaOu/9kyN9AyBfLWuFC1GN0YKBvcDnk3ARYJ9nqI9B VHBUPcr2RL2evOAcwhOX5ph6Kod0kD4xcgJzz8+h3+0ZGlscUCcHF9gLgk0FDCf7J867TG3ZmEl XXJOWkrA= X-Gm-Gg: AYBFou32VK1XJJ8hOdE2Tiy3dMBFhG/riZXAR/fHIsCT5BfNEoTkWyv+jujtd4g//aS MZTCLXAuIFJrjQ8nnBu1EOiCFZ7xqsDsECLzx6pgky4Hl9n4Z/iUDIrAAD/O9CNIKpUMC3d4LcS ZralGUABXVHiI7yS3y/LQDouLOCygCLNBoN+CD7qjllQ/lTIglDTSjtw467KS2zpoGH6yR6k6tQ hJPUz7OrwrpKOdIMBmjL5I9rY/DxBc2n+f7vrKDOeacKuugg6jqtNbzmPkybwc0DTvco7e1aFYj x0OoeOOYJFzn3bfrl+SPugr8gtpkBBPM6WvAx+ijfKuT7rzVBjXt1O/xMaP8yUXSm2E8jxgolks feBrtuK7h+gSQlsw5IHrEy1A88IDra5ppnVr5SUp1bVHW4S+pwVAveejxQMVGoeHxhULmVHDaYi ZNK33Jyx6GrkaU+qkhpmbqFiy5dHMtpo2TspAZEwRZvSdfT4Dw40i0iR3euqpIQvywvDlZLe7y+ lZCARdpMPqRuEr86/znlmoQQ7cY/ten8VWu6Qpi3fxMItbSI3ooYedbo16kq6ghCCliBYeSpiI= X-Received: by 2002:a05:600c:3b02:b0:49c:fa21:1c7d with SMTP id 5b1f17b1804b1-49cfa211d76mr214829255e9.18.1788788162981; Mon, 07 Sep 2026 06:36:02 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-48588394fa1sm27523836f8f.8.2026.09.07.06.36.02 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 07 Sep 2026 06:36:02 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][scarthgap 22/35] python3-pycryptodomex: fix CVE_PRODUCT Date: Mon, 7 Sep 2026 15:35:18 +0200 Message-ID: X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Mon, 07 Sep 2026 13:36:06 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/245280 From: Tim Orling With this change, 1 Patched CVE is properly reported: * CVE-2023-52323 Signed-off-by: Tim Orling Signed-off-by: Mathieu Dubois-Briand Signed-off-by: Richard Purdie (cherry picked from commit c2a2ae48add874f41c5b60ca90ba3a26ebb0fe38) The current pypi default "python:pycryptodomex" has no matching NVD CPE or configuration identity. Use "pycryptodome:pycryptodomex", the active NVD dictionary CPE and configuration identity for the packaged distribution, so CVE-2023-52323 is properly reported as patched. Note: The original commit targeted python3-pycryptodomex_3.23.0.bb. This is adjusted for Scarthgap, where the recipe version is 3.20.0. Signed-off-by: Devansh Patel Signed-off-by: Yoann Congal --- meta/recipes-devtools/python/python3-pycryptodomex_3.20.0.bb | 2 ++ 1 file changed, 2 insertions(+) diff --git a/meta/recipes-devtools/python/python3-pycryptodomex_3.20.0.bb b/meta/recipes-devtools/python/python3-pycryptodomex_3.20.0.bb index 54578d28509..44f8d98d6a0 100644 --- a/meta/recipes-devtools/python/python3-pycryptodomex_3.20.0.bb +++ b/meta/recipes-devtools/python/python3-pycryptodomex_3.20.0.bb @@ -3,6 +3,8 @@ inherit python_setuptools_build_meta SRC_URI[sha256sum] = "7a710b79baddd65b806402e14766c721aee8fb83381769c27920f26476276c1e" +CVE_PRODUCT = "pycryptodome:pycryptodomex" + FILES:${PN}-tests = " \ ${PYTHON_SITEPACKAGES_DIR}/Cryptodome/SelfTest/ \ ${PYTHON_SITEPACKAGES_DIR}/Cryptodome/SelfTest/__pycache__/ \ From patchwork Mon Sep 7 13:35:19 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 97546 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 21695C79FB9 for ; Mon, 7 Sep 2026 13:36:06 +0000 (UTC) Received: from mail-wr1-f46.google.com (mail-wr1-f46.google.com [209.85.221.46]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.34937.1788788165189434682 for ; Mon, 07 Sep 2026 06:36:05 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=23/wrBE8; spf=pass (domain: smile.fr, ip: 209.85.221.46, mailfrom: yoann.congal@smile.fr) Received: by mail-wr1-f46.google.com with SMTP id ffacd0b85a97d-47ddf7b09e5so4042371f8f.1 for ; Mon, 07 Sep 2026 06:36:04 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1788788163; x=1789392963; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=0lZQ55LlAcjideiuuCoHKNsjNUJqE7a6d11RPmcQT4Q=; b=23/wrBE8ILFZbMi/RR0bwXLzrzKqeFYJkJARIYpXHufLMd8g4J293hOKMw/MnQJ9O4 TZBaAQiJyiXRbvb3HMKXCL/DUlT6CzFCKDyTeF/sEgxvvNMcQX6Z2+Y9YSxMyYZ1MSbH LI+9cEfaNNo1zcGeqhJuAUJSYH3QNA/ovPKN0= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1788788163; x=1789392963; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=0lZQ55LlAcjideiuuCoHKNsjNUJqE7a6d11RPmcQT4Q=; b=qnAd9qaGi43pjU8ijxMFaKGbOllo5ymOVQWOUV/rwJaDtd48id9TZsn1wf5csULDtT F1SEzrbhSXzw4jOHursZBeQOBtLqIE7RyJNvuf7TsVBaAIEz6ETyqbdGAaJAY6nv3wCo HSSTnpIQYPpyyPIHjwvuG2uTm00+I0hPiQPapWGPH/oV9H4Ntd3hInzGGWAa2be4yitV k6BfzonmFfAHQz/lkViX4vI+1vS8FKDJVX0OdTMN/jOcjtvX/Pj/UNP/qI3kahVQBwfc Tt9xaya5LvzwVLhOaAm2zgaZc2ep35K7wmmlvq7jfsQy9usNmB7zh4GYZaTnew2SDmCw 3fOw== X-Gm-Message-State: AFuF++lOFDljZP1GHM11bN9R3yYEK85nLTR6RcRRSYs6u6UwgiTZVpyx 60ie+7kaZCzTK3b5w1lJQGjcCSxAx04cRf3PcxnLYDJTkYLjSI26E7B7wm6dfs5XhOsicUqJw0m OUPBDBm0= X-Gm-Gg: AYBFou2buIMKusnY/Tk9zjXXqaH4ajUPmW88jDu3C81+CRFEWwOPAx6mOcL5gOgQNnJ reFO1nXOHaC46KtPyRKRfSoxzZTTOz7duTWxWB8/agfVlWZB7mYAhiHXKWVwr89GjpVzKL1YsAo rMDr0NBwj+jKDnU5i/IO3vZLkulTA8t4OSLSfPajL52oFG0Tp69rmMFAcTg9DbRbpuLbXzw/9u/ 89tOAMaLsJsEP5zEYTM6BB3IFKZI7UKOtt0DZowfkuxuQFuWe/2R+nHZp05+WLz7qFRpFHTSRJB lcrxxL6cX4sXQtHkxMswbQ6AgqddNfqPDpw9N8hdkV/TTTqQSb7RJKBgWLIbpSsVqgjwli8qY6r Mkk3nwYRgtAL4bOMFtFVBxn5K2xA4M+8ij6TB5tUSyHjm4KmnFdRG1OM4Ck1vALF3ddK8ExeVnL 4E18G0IPHNxBp/ag3Ww7Iz3ha29s9pUewsf8jbwJyDfkKLpDS0ahOPIxu8R/4FOmHL1MPX0eIlN AX0W+fRWALxZpgiJzXCBN6H9nGagggLWnVkMuDhQ3RxgYb0JoBkc72/3md8We7a X-Received: by 2002:a05:6000:644:b0:485:847f:fd89 with SMTP id ffacd0b85a97d-485870506d0mr26219195f8f.9.1788788163428; Mon, 07 Sep 2026 06:36:03 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-48588394fa1sm27523836f8f.8.2026.09.07.06.36.03 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 07 Sep 2026 06:36:03 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][scarthgap 23/35] python3-git: fix CVE-2026-42284 Date: Mon, 7 Sep 2026 15:35:19 +0200 Message-ID: <1582c80d83558b9f1e9c3137bd79ec3f0a5c643c.1788787321.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Mon, 07 Sep 2026 13:36:06 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/245281 From: Darsh Kelaiya This patch applies the upstream 3.1.47 backport for CVE-2026-42284. The upstream fix merge is referenced in [1], and the public CVE advisory is referenced in [2]. [1] https://github.com/gitpython-developers/GitPython/commit/da545232d0401fb9fb7660f9ff67991996674dda [2] https://nvd.nist.gov/vuln/detail/CVE-2026-42284 Signed-off-by: Darsh Kelaiya Signed-off-by: Yoann Congal [YC: See https://github.com/gitpython-developers/GitPython/pull/2130#issue-4299717224: The author links the fix to this advisory/CVE. ] --- .../python/python3-git/CVE-2026-42284.patch | 37 +++++++++++++++++++ .../python/python3-git_3.1.42.bb | 2 + 2 files changed, 39 insertions(+) create mode 100644 meta/recipes-devtools/python/python3-git/CVE-2026-42284.patch diff --git a/meta/recipes-devtools/python/python3-git/CVE-2026-42284.patch b/meta/recipes-devtools/python/python3-git/CVE-2026-42284.patch new file mode 100644 index 00000000000..456a455e53d --- /dev/null +++ b/meta/recipes-devtools/python/python3-git/CVE-2026-42284.patch @@ -0,0 +1,37 @@ +From dc3885fd7b4cee9ce4bf04d120e63ea00d905431 Mon Sep 17 00:00:00 2001 +From: "GPT 5.4" +Date: Tue, 21 Apr 2026 09:30:29 +0800 +Subject: [PATCH] Make sure that multi-options are checked after splitting them + with `shlex` + +CVE: CVE-2026-42284 +Upstream-Status: Backport [https://github.com/gitpython-developers/GitPython/commit/c9a26789d88b18f8b4620f37307df2976292d2a0] + +Backport Changes: +- Omit regression tests because the Scarthgap PyPI source + archive does not include the upstream test suite. + +Co-authored-by: Sebastian Thiel +(cherry picked from commit c9a26789d88b18f8b4620f37307df2976292d2a0) +Signed-off-by: Darsh Kelaiya +--- + git/repo/base.py | 4 ++-- + 1 file changed, 2 insertions(+), 2 deletions(-) + +diff --git a/git/repo/base.py b/git/repo/base.py +index f5069dbf..92ace3a0 100644 +--- a/git/repo/base.py ++++ b/git/repo/base.py +@@ -1271,8 +1271,8 @@ class Repo: + Git.check_unsafe_protocols(str(url)) + if not allow_unsafe_options: + Git.check_unsafe_options(options=list(kwargs.keys()), unsafe_options=cls.unsafe_git_clone_options) +- if not allow_unsafe_options and multi_options: +- Git.check_unsafe_options(options=multi_options, unsafe_options=cls.unsafe_git_clone_options) ++ if not allow_unsafe_options and multi: ++ Git.check_unsafe_options(options=multi, unsafe_options=cls.unsafe_git_clone_options) + + proc = git.clone( + multi, +-- +2.35.6 diff --git a/meta/recipes-devtools/python/python3-git_3.1.42.bb b/meta/recipes-devtools/python/python3-git_3.1.42.bb index 19885a58c74..c294b23112e 100644 --- a/meta/recipes-devtools/python/python3-git_3.1.42.bb +++ b/meta/recipes-devtools/python/python3-git_3.1.42.bb @@ -12,6 +12,8 @@ PYPI_PACKAGE = "GitPython" inherit pypi python_setuptools_build_meta +SRC_URI += "file://CVE-2026-42284.patch \ + " SRC_URI[sha256sum] = "2d99869e0fef71a73cbd242528105af1d6c1b108c60dfabd994bf292f76c3ceb" DEPENDS += " python3-gitdb" From patchwork Mon Sep 7 13:35:20 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 97548 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 2FDB9C79FA1 for ; Mon, 7 Sep 2026 13:36:16 +0000 (UTC) Received: from mail-wm1-f49.google.com (mail-wm1-f49.google.com [209.85.128.49]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.34938.1788788165908696517 for ; Mon, 07 Sep 2026 06:36:06 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=2IV/4mXw; spf=pass (domain: smile.fr, ip: 209.85.128.49, mailfrom: yoann.congal@smile.fr) Received: by mail-wm1-f49.google.com with SMTP id 5b1f17b1804b1-495437bb891so23826515e9.1 for ; Mon, 07 Sep 2026 06:36:05 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1788788164; x=1789392964; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=41IyYRHIoBuZPlBZsSTzyF6bV/Gbz4KPUjYfH27ZqS0=; b=2IV/4mXwwEJA19dapU2bNIdwTjxNthbH9guVnlbFWU0UqgW4G5/hqqImSjkkHNT4Oq AEYNRRnGKek2an6u5clFkh4uI+0o79OsB/oML2p8NXj2Sj+ZFLq75IQoUq58UNIn6jeu xRBFvmJ6skg/7L9ePnRkMa4k0MDJdLJ+6UEAw= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1788788164; x=1789392964; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=41IyYRHIoBuZPlBZsSTzyF6bV/Gbz4KPUjYfH27ZqS0=; b=dorUCz/4hVZij681ZOhBaqFTh8O4q1fpowpI9zoLHhTrqFMkYVjk6skCShRyCKVZwP fqM3TeTV8oYt952Myeocf6C7BStddjrg220YrfsuFsSuhwyo8IqE1TlvSQSggvhXI1fX 2mCN+NXQu4Uxe1GEt/VBM+IN61rxtAQBHv4aMO6qK5Wow4P6X3q8eFPApvRvLciWyt7R /hD8kyd2rz3+0mJkMDWQipa8I45M3Ixcyt+N4IeLoUzWxzLIEIXLaKLZ3nGFyLaeIiV4 4YIS2cYd98hcWlFCC8hJqG1PIE5U9Oq8NJKY+qFQxtCMYTsFnnpAvSqYQqUNEF6dXqlf MaxQ== X-Gm-Message-State: AFuF++m8v7lZW9eg4/dK01s48bZoD8Xai1ZuuRQCEvx3k+uWAgktQmpe XVskoqZh4IHMMErOAT6UtdoPzPytANPq+QP5wD1NxsnkNg73q1SKzCXxjR/19efg1scRuN1W+Kj qCmENOuQ= X-Gm-Gg: AYBFou2Iemo2yK6teCQdznIfm44zFgRW/lIbh3PfWHAM/fPSlV4DGtl/vkPSAnz3c80 nvBPn4v1q6qLwR5OqJQRHLKyvMxJt6vRRqsYUDVNTi9axr5gtHTP0FoJ8W1NwTSoEO68++AYB7x IjpLPSH0IooOz48CK+0SusvpKbJifTBGzpRCt6OaipbvGk5/iSrnfKLNxAKniBNqFZPJr9ojlPb wqyldNO7CUqjyUznkvGEDbAKwqK8IwcaQn59x0YHWFwhGA+UsTJ00BsDlBprdymuBLVDIBLgBkx OH5V4Uu9VhEgVD32kFP3FMqNk04eDH9KZLIqaxZplKSAbOprmV/NrX1C7nx+s9BwaX2SV4lGdNX CU/hj3uGizbEPBca5dmi43PEHnKl5IF+Qx4JDYvdyhwj34ZtZRst4RkW/L7VYA9sZ8fWzv+Fbh9 dbXKyo6rECwJgWNjYL31yC996pcdGJtyQ15+QFeo8jTGyedu5QqZg8EUsL1inwYPSE3ngRk+73Q KtG44zw76AcmZqyz3zonn3/ZB6hIrC3QTPkScdp7iznzRe9yeOYiFCmYVkcUh8I+eyXJaQkEvs= X-Received: by 2002:a05:600c:3648:b0:49c:f13d:ffed with SMTP id 5b1f17b1804b1-49cf5988c09mr200865095e9.17.1788788164019; Mon, 07 Sep 2026 06:36:04 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-48588394fa1sm27523836f8f.8.2026.09.07.06.36.03 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 07 Sep 2026 06:36:03 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][scarthgap 24/35] python3-git: fix CVE-2026-44243 Date: Mon, 7 Sep 2026 15:35:20 +0200 Message-ID: <0853d0c72e96a3c4e3a5329589a9aa151e2f2c46.1788787321.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Mon, 07 Sep 2026 13:36:16 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/245282 From: Darsh Kelaiya This patch applies the upstream 3.1.48 backport for CVE-2026-44243. The upstream fix merge is referenced in [1], and the public CVE advisory is referenced in [2]. The individual backported commits are referenced in [3] and [4]. [1] https://github.com/gitpython-developers/GitPython/commit/dbfa26476445169cdc9d64a539ba6959fd0a2643 [2] https://nvd.nist.gov/vuln/detail/CVE-2026-44243 [3] https://github.com/gitpython-developers/GitPython/commit/25ba54dd3fb374b8fade7de4be1ac2ac84722190 [4] https://github.com/gitpython-developers/GitPython/commit/4af8463cca31c2369312fcaa5309dfc30756c7b6 Signed-off-by: Darsh Kelaiya Signed-off-by: Yoann Congal --- .../python3-git/CVE-2026-44243_p1.patch | 136 ++++++++++++++++++ .../python3-git/CVE-2026-44243_p2.patch | 86 +++++++++++ .../python/python3-git_3.1.42.bb | 2 + 3 files changed, 224 insertions(+) create mode 100644 meta/recipes-devtools/python/python3-git/CVE-2026-44243_p1.patch create mode 100644 meta/recipes-devtools/python/python3-git/CVE-2026-44243_p2.patch diff --git a/meta/recipes-devtools/python/python3-git/CVE-2026-44243_p1.patch b/meta/recipes-devtools/python/python3-git/CVE-2026-44243_p1.patch new file mode 100644 index 00000000000..6c9af542b5e --- /dev/null +++ b/meta/recipes-devtools/python/python3-git/CVE-2026-44243_p1.patch @@ -0,0 +1,136 @@ +From fcd8d016816696780c0dc96dacbe48fc10df80f6 Mon Sep 17 00:00:00 2001 +From: "GPT 5.5" +Date: Tue, 28 Apr 2026 09:17:31 +0800 +Subject: [PATCH] prevent out-of-repo access when manipulating references. + +This previously made it possible to create, modify and delete files outside outside +of the repository, which is a problem if inputs aren't trusted. + +CVE: CVE-2026-44243 +Upstream-Status: Backport [https://github.com/gitpython-developers/GitPython/commit/25ba54dd3fb374b8fade7de4be1ac2ac84722190] + +Backport Changes: +- Omit regression tests because the Scarthgap PyPI source + archive does not include the upstream test suite. + +Co-authored-by: Sebastian Thiel +(cherry picked from commit 25ba54dd3fb374b8fade7de4be1ac2ac84722190) +Signed-off-by: Darsh Kelaiya +--- + git/refs/log.py | 2 +- + git/refs/remote.py | 5 +++-- + git/refs/symbolic.py | 37 +++++++++++++++++++++++++++++++------ + 3 files changed, 35 insertions(+), 9 deletions(-) + +diff --git a/git/refs/log.py b/git/refs/log.py +index e45798d8..29293f4a 100644 +--- a/git/refs/log.py ++++ b/git/refs/log.py +@@ -204,7 +204,7 @@ class RefLog(List[RefLogEntry], Serializable): + file though. + :param ref: SymbolicReference instance + """ +- return osp.join(ref.repo.git_dir, "logs", to_native_path(ref.path)) ++ return to_native_path(ref._get_validated_reflog_path(ref.repo, ref.path)) + + @classmethod + def iter_entries(cls, stream: Union[str, "BytesIO", mmap]) -> Iterator[RefLogEntry]: +diff --git a/git/refs/remote.py b/git/refs/remote.py +index 59d02a75..e50c54eb 100644 +--- a/git/refs/remote.py ++++ b/git/refs/remote.py +@@ -64,12 +64,13 @@ class RemoteReference(Head): + # are generally ignored in the refs/ folder. We don't though + # and delete remainders manually. + for ref in refs: ++ cls._check_ref_name_valid(ref.path) + try: +- os.remove(os.path.join(repo.common_dir, ref.path)) ++ os.remove(cls._get_validated_path(repo.common_dir, ref.path)) + except OSError: + pass + try: +- os.remove(os.path.join(repo.git_dir, ref.path)) ++ os.remove(cls._get_validated_path(repo.git_dir, ref.path)) + except OSError: + pass + # END for each ref +diff --git a/git/refs/symbolic.py b/git/refs/symbolic.py +index 31f959ac..d5c18290 100644 +--- a/git/refs/symbolic.py ++++ b/git/refs/symbolic.py +@@ -109,6 +109,32 @@ class SymbolicReference: + def abspath(self) -> PathLike: + return join_path_native(_git_dir(self.repo, self.path), self.path) + ++ @staticmethod ++ def _get_validated_path(base: PathLike, path: PathLike) -> str: ++ path = os.fspath(path) ++ base_path = os.path.realpath(os.fspath(base)) ++ abs_path = os.path.realpath(os.path.join(base_path, path)) ++ try: ++ common_path = os.path.commonpath([base_path, abs_path]) ++ except ValueError as e: ++ raise ValueError("Reference path %r escapes the repository" % path) from e ++ if os.path.normcase(common_path) != os.path.normcase(base_path): ++ raise ValueError("Reference path %r escapes the repository" % path) ++ return abs_path ++ ++ @classmethod ++ def _get_validated_ref_path(cls, repo: "Repo", path: PathLike) -> str: ++ """Return the absolute filesystem path for a ref after validating it.""" ++ cls._check_ref_name_valid(path) ++ ref_path = os.fspath(path) ++ return cls._get_validated_path(_git_dir(repo, ref_path), ref_path) ++ ++ @classmethod ++ def _get_validated_reflog_path(cls, repo: "Repo", path: PathLike) -> str: ++ """Return the absolute filesystem path for a reflog after validating it.""" ++ cls._check_ref_name_valid(path) ++ return cls._get_validated_path(os.path.join(repo.git_dir, "logs"), path) ++ + @classmethod + def _get_packed_refs_path(cls, repo: "Repo") -> str: + return os.path.join(repo.common_dir, "packed-refs") +@@ -442,7 +468,7 @@ class SymbolicReference: + # END handle non-existing + # END retrieve old hexsha + +- fpath = self.abspath ++ fpath = self._get_validated_ref_path(self.repo, self.path) + assure_directory_exists(fpath, is_file=True) + + lfd = LockedFD(fpath) +@@ -571,7 +597,7 @@ class SymbolicReference: + Alternatively the symbolic reference to be deleted. + """ + full_ref_path = cls.to_full_path(path) +- abs_path = os.path.join(repo.common_dir, full_ref_path) ++ abs_path = cls._get_validated_ref_path(repo, full_ref_path) + if os.path.exists(abs_path): + os.remove(abs_path) + else: +@@ -635,9 +661,8 @@ class SymbolicReference: + corresponding object and a detached symbolic reference will be created + instead. + """ +- git_dir = _git_dir(repo, path) + full_ref_path = cls.to_full_path(path) +- abs_ref_path = os.path.join(git_dir, full_ref_path) ++ abs_ref_path = cls._get_validated_ref_path(repo, full_ref_path) + + # Figure out target data. + target = reference +@@ -724,8 +749,8 @@ class SymbolicReference: + if self.path == new_path: + return self + +- new_abs_path = os.path.join(_git_dir(self.repo, new_path), new_path) +- cur_abs_path = os.path.join(_git_dir(self.repo, self.path), self.path) ++ new_abs_path = self._get_validated_ref_path(self.repo, new_path) ++ cur_abs_path = self._get_validated_ref_path(self.repo, self.path) + if os.path.isfile(new_abs_path): + if not force: + # If they point to the same file, it's not an error. +-- +2.35.6 diff --git a/meta/recipes-devtools/python/python3-git/CVE-2026-44243_p2.patch b/meta/recipes-devtools/python/python3-git/CVE-2026-44243_p2.patch new file mode 100644 index 00000000000..e14c284d122 --- /dev/null +++ b/meta/recipes-devtools/python/python3-git/CVE-2026-44243_p2.patch @@ -0,0 +1,86 @@ +From 2d1f681978b51ffff0db57cf89b0bcd6bffc7418 Mon Sep 17 00:00:00 2001 +From: "GPT 5.5" +Date: Tue, 28 Apr 2026 09:30:41 +0800 +Subject: [PATCH] address review feedback and CI failures + +Consolidate follow-up fixes from review and CI: + +- fix lint and mypy issues in reference log path handling +- validate remote reference paths before invoking git branch deletion +- add symlink escape coverage where realpath resolves symlinks +- ensure temporary test repositories release git resources during cleanup + +CVE: CVE-2026-44243 +Upstream-Status: Backport [https://github.com/gitpython-developers/GitPython/commit/4af8463cca31c2369312fcaa5309dfc30756c7b6] + +Backport Changes: +- Keep the 3.1.42 docstring layout and path coercion while + applying upstream validation documentation and return type. +- Omit regression test updates because the Scarthgap PyPI + source archive does not include the upstream test suite. + +Co-authored-by: Sebastian Thiel +(cherry picked from commit 4af8463cca31c2369312fcaa5309dfc30756c7b6) +Signed-off-by: Darsh Kelaiya +--- + git/refs/log.py | 3 ++- + git/refs/remote.py | 4 +++- + git/util.py | 2 +- + 3 files changed, 6 insertions(+), 3 deletions(-) + +diff --git a/git/refs/log.py b/git/refs/log.py +index 29293f4a..eef525e7 100644 +--- a/git/refs/log.py ++++ b/git/refs/log.py +@@ -21,7 +21,6 @@ from git.util import ( + file_contents_ro_filepath, + ) + +-import os.path as osp + + + # typing ------------------------------------------------------------------ +@@ -203,6 +202,8 @@ class RefLog(List[RefLogEntry], Serializable): + instance would be found. The path is not guaranteed to point to a valid + file though. + :param ref: SymbolicReference instance ++ :raise ValueError: ++ If `ref.path` is invalid or escapes the repository's reflog directory. + """ + return to_native_path(ref._get_validated_reflog_path(ref.repo, ref.path)) + +diff --git a/git/refs/remote.py b/git/refs/remote.py +index e50c54eb..70eada81 100644 +--- a/git/refs/remote.py ++++ b/git/refs/remote.py +@@ -59,12 +59,14 @@ class RemoteReference(Head): + kwargs are given for comparability with the base class method as we + should not narrow the signature. + """ ++ for ref in refs: ++ cls._check_ref_name_valid(ref.path) ++ + repo.git.branch("-d", "-r", *refs) + # The official deletion method will ignore remote symbolic refs - these + # are generally ignored in the refs/ folder. We don't though + # and delete remainders manually. + for ref in refs: +- cls._check_ref_name_valid(ref.path) + try: + os.remove(cls._get_validated_path(repo.common_dir, ref.path)) + except OSError: +diff --git a/git/util.py b/git/util.py +index 03d62ffc..5a136d18 100644 +--- a/git/util.py ++++ b/git/util.py +@@ -272,7 +272,7 @@ def join_path(a: PathLike, *p: PathLike) -> PathLike: + + if os.name == "nt": + +- def to_native_path_windows(path: PathLike) -> PathLike: ++ def to_native_path_windows(path: PathLike) -> str: + path = str(path) + return path.replace("/", "\\") + +-- +2.35.6 diff --git a/meta/recipes-devtools/python/python3-git_3.1.42.bb b/meta/recipes-devtools/python/python3-git_3.1.42.bb index c294b23112e..99f31791bd5 100644 --- a/meta/recipes-devtools/python/python3-git_3.1.42.bb +++ b/meta/recipes-devtools/python/python3-git_3.1.42.bb @@ -13,6 +13,8 @@ PYPI_PACKAGE = "GitPython" inherit pypi python_setuptools_build_meta SRC_URI += "file://CVE-2026-42284.patch \ + file://CVE-2026-44243_p1.patch \ + file://CVE-2026-44243_p2.patch \ " SRC_URI[sha256sum] = "2d99869e0fef71a73cbd242528105af1d6c1b108c60dfabd994bf292f76c3ceb" From patchwork Mon Sep 7 13:35:21 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 97555 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 8609EC79FA9 for ; Mon, 7 Sep 2026 13:36:16 +0000 (UTC) Received: from mail-wr1-f52.google.com (mail-wr1-f52.google.com [209.85.221.52]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.34939.1788788166401464706 for ; Mon, 07 Sep 2026 06:36:06 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=YnXt7dZL; spf=pass (domain: smile.fr, ip: 209.85.221.52, mailfrom: yoann.congal@smile.fr) Received: by mail-wr1-f52.google.com with SMTP id ffacd0b85a97d-48441a2ba1bso2546309f8f.1 for ; Mon, 07 Sep 2026 06:36:06 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1788788165; x=1789392965; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=JO5zvFE1+KfNIE2qhgM+i92/qrTMrFBIURJ7XUHqT8w=; b=YnXt7dZLr/iVn/7SHaDbqpwju+Q7MpOzuwSFmGHlJMqfBWRMz27J4ghaDjkFF/sbZS M3SK51rLtP8fqMlakGTcmZN+grQ7f/zBjUplwcG+MqXgbtFgPqMKVV55BaU6cZOuIyQo OCI/dZUzBd3K7p861WqUy0B8ZCym3/Z0HyXJ8= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1788788165; x=1789392965; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=JO5zvFE1+KfNIE2qhgM+i92/qrTMrFBIURJ7XUHqT8w=; b=D2HUdNQpRJfbq39ozVYieKjK5A0DLpStHCnAbpyIGjTB3Ka+a8+g2XxUqLJGHjGwPy RWHlRYPkb10s+L9R5Zdt0mzlt/tXZJzoPRWDlIWcuXYoc0moRu69wn6LSdciFV4HLDDl UMkkt69jn4ojMBwCgl9p6T+Ey8h7X/AtKWqj1T+r0OcC6pGOwTkWotVyZ6LsFNVwmIzD ne1l095WWv6ZJ8P3OzwJxNjlqyviVHx4/8LMuelX6yfksMn0iYy+C/NW3W42m5TNuXmz T+beYq5z/V5RARELAsaE0FQJJqtPaN7ys4WGt5gIt2sVjR9knL3HxBXr6EQ0QPfYf/d6 R92A== X-Gm-Message-State: AFuF++lK01lbzi6PfdLYzP7rI8xGFEDke6snxgKs+S5NLrDYEggT1V1p O9wIeVFZdJ2VDjLN7hTPCZT3vo9zs4B3H3xmEvJye9oNTqjshoIS+87BrSh8sI6bFfNfh+/O/OJ 01dKMQjM= X-Gm-Gg: AYBFou11ySsUWYRYxQnzsp0ILadXlfMK5d9uW8ZyZ4pCSKrXHPF1der/KQSZ1KONT4R EEylaahO9SQVg2epaCwGUZTMzqJ8yAeNH3aA0Ari8pO+RKQxw5Tf9liJ3evRZVj5gtRqJ1J8w/D Lsd9M66Gi9zVBrrdfAeCiwB/TiGdHSB6fLSo7aFr2M9EFX2uZQ2a9Rf1ypxfvdt5epU8nOkoN8l IbAei8fTBPFHJd9jub25+2PVeGMQY/PK63e5R0kj/63pF9AVGKqUrjrUTjD/ms7tnvuGjVV6jk3 F8Si3kdISwSA9wDq1mN1NPe+Pzkyb8l35kL7LABobnrno4hi5dEwCaShv39tmDupFOTU+Jad9i0 nRq8AdjMetDu+BzJQM9Yyxr3ZCHuFceUkY3eAy758rm0qgvfJ4+YX6/tKl9N8XYkss48uMeMrFe Yodp6K64NNhjO8jAOKuDH3sPcVmhR20SWr+scTY1gTQtWtVmWEVhx3RJCvzIJubErQH1Rm7Ifur U5V17Qfvq61erlutoyXO7lxz0/m48SgH64dZjqeCbLHWa+GGHuDjNwGuDF26LdB X-Received: by 2002:a05:6000:1a8c:b0:485:8ee5:5ffa with SMTP id ffacd0b85a97d-485a2c5f5c3mr911215f8f.38.1788788164566; Mon, 07 Sep 2026 06:36:04 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-48588394fa1sm27523836f8f.8.2026.09.07.06.36.04 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 07 Sep 2026 06:36:04 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][scarthgap 25/35] python3-git: fix CVE-2026-44244 Date: Mon, 7 Sep 2026 15:35:21 +0200 Message-ID: <9aaa23d4f6c04049fcdb532f6a83c654e8e6e15d.1788787321.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Mon, 07 Sep 2026 13:36:16 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/245283 From: Darsh Kelaiya This patch applies the upstream 3.1.49 backport for CVE-2026-44244. The upstream fix merge is referenced in [1], and the public CVE advisory is referenced in [2]. The individual backported commits are referenced in [3] and [4]. [1] https://github.com/gitpython-developers/GitPython/commit/b049a13105992f22376ad0c7ec945bf3bfb365ae [2] https://nvd.nist.gov/vuln/detail/CVE-2026-44244 [3] https://github.com/gitpython-developers/GitPython/commit/c417af469f9aa3da8dfef78f996c0fb8c5d1f4c2 [4] https://github.com/gitpython-developers/GitPython/commit/8e24503b42c1d63dd98e8b2e6a2f655bdd0821e3 Signed-off-by: Darsh Kelaiya Signed-off-by: Yoann Congal --- .../python3-git/CVE-2026-44244_p1.patch | 104 ++++++++++++++++++ .../python3-git/CVE-2026-44244_p2.patch | 30 +++++ .../python/python3-git_3.1.42.bb | 2 + 3 files changed, 136 insertions(+) create mode 100644 meta/recipes-devtools/python/python3-git/CVE-2026-44244_p1.patch create mode 100644 meta/recipes-devtools/python/python3-git/CVE-2026-44244_p2.patch diff --git a/meta/recipes-devtools/python/python3-git/CVE-2026-44244_p1.patch b/meta/recipes-devtools/python/python3-git/CVE-2026-44244_p1.patch new file mode 100644 index 00000000000..92aa9056225 --- /dev/null +++ b/meta/recipes-devtools/python/python3-git/CVE-2026-44244_p1.patch @@ -0,0 +1,104 @@ +From 19e86eacc9471f2c3ef6f6a55dcaed40e5e139a0 Mon Sep 17 00:00:00 2001 +From: "GPT 5.5" +Date: Wed, 29 Apr 2026 05:47:57 +0800 +Subject: [PATCH] reject control chars in written values in configuration + +Reject CR, LF, and NUL in GitConfigParser values before writing them +to git config files (which also is a deviation from Git which escapes them). + +GitConfigParser._write() serializes embedded newlines as indented +continuation lines by replacing "\n" with "\n\t". Git itself skips +leading whitespace before parsing config tokens, so an injected value +such as: + + foo + [core] + hooksPath=/tmp/hooks + +is written in a form where the indented "[core]" line is still parsed by +Git as a real section header. This lets attacker-controlled input passed +to config_writer().set_value() poison repository config, including +core.hooksPath, and redirect hook execution for later Git operations. + +Fail closed instead of stripping or normalizing these characters. Silent +normalization can hide unsanitized caller input, and GitPython does not +currently round-trip Git-style escaped values such as "\n" as embedded +newlines. + +Apply the validation to set_value(), add_value(), and the public set() +path so callers cannot bypass the safer helper API. Add regression tests +for the advisory payload and for CR, LF, NUL, and bytes values. + +This preserves existing read behavior for config files that already +contain multiline values while preventing GitPython from writing new +unsafe values. + +CVE: CVE-2026-44244 +Upstream-Status: Backport [https://github.com/gitpython-developers/GitPython/commit/c417af469f9aa3da8dfef78f996c0fb8c5d1f4c2] + +Backport Changes: +- Omit regression tests because the Scarthgap PyPI source + archive does not include the upstream test suite. + +Co-authored-by: Sebastian Thiel +(cherry picked from commit c417af469f9aa3da8dfef78f996c0fb8c5d1f4c2) +Signed-off-by: Darsh Kelaiya +--- + git/config.py | 24 ++++++++++++++++++++++-- + 1 file changed, 22 insertions(+), 2 deletions(-) + +diff --git a/git/config.py b/git/config.py +index 85f75419..ce307110 100644 +--- a/git/config.py ++++ b/git/config.py +@@ -841,6 +841,24 @@ class GitConfigParser(cp.RawConfigParser, metaclass=MetaParserBuilder): + return str(value) + return force_text(value) + ++ def _value_to_string_safe(self, value: Union[str, bytes, int, float, bool]) -> str: ++ value_str = self._value_to_string(value) ++ if re.search(r"[\r\n\x00]", value_str): ++ raise ValueError("Git config values must not contain CR, LF, or NUL") ++ return value_str ++ ++ @needs_values ++ @set_dirty_and_flush_changes ++ def set( ++ self, ++ section: str, ++ option: str, ++ value: Union[str, bytes, int, float, bool, None] = None, ++ ) -> None: ++ if value is not None: ++ value = self._value_to_string_safe(value) ++ return super().set(section, option, value) ++ + @needs_values + @set_dirty_and_flush_changes + def set_value(self, section: str, option: str, value: Union[str, bytes, int, float, bool]) -> "GitConfigParser": +@@ -855,9 +873,10 @@ class GitConfigParser(cp.RawConfigParser, metaclass=MetaParserBuilder): + a string. + :return: This instance + """ ++ value_str = self._value_to_string_safe(value) + if not self.has_section(section): + self.add_section(section) +- self.set(section, option, self._value_to_string(value)) ++ self.set(section, option, value_str) + return self + + @needs_values +@@ -875,9 +894,10 @@ class GitConfigParser(cp.RawConfigParser, metaclass=MetaParserBuilder): + to a string + :return: This instance + """ ++ value_str = self._value_to_string_safe(value) + if not self.has_section(section): + self.add_section(section) +- self._sections[section].add(option, self._value_to_string(value)) ++ self._sections[section].add(option, value_str) + return self + + def rename_section(self, section: str, new_name: str) -> "GitConfigParser": +-- +2.35.6 diff --git a/meta/recipes-devtools/python/python3-git/CVE-2026-44244_p2.patch b/meta/recipes-devtools/python/python3-git/CVE-2026-44244_p2.patch new file mode 100644 index 00000000000..fcc3a872752 --- /dev/null +++ b/meta/recipes-devtools/python/python3-git/CVE-2026-44244_p2.patch @@ -0,0 +1,30 @@ +From cf273ba3958ad02afa361167a0d0f82e1f4b5f4d Mon Sep 17 00:00:00 2001 +From: "GPT 5.5" +Date: Wed, 29 Apr 2026 06:39:02 +0800 +Subject: [PATCH] avoid duplicate validation in set_value + +CVE: CVE-2026-44244 +Upstream-Status: Backport [https://github.com/gitpython-developers/GitPython/commit/8e24503b42c1d63dd98e8b2e6a2f655bdd0821e3] + +Co-authored-by: Sebastian Thiel +(cherry picked from commit 8e24503b42c1d63dd98e8b2e6a2f655bdd0821e3) +Signed-off-by: Darsh Kelaiya +--- + git/config.py | 2 +- + 1 file changed, 1 insertion(+), 1 deletion(-) + +diff --git a/git/config.py b/git/config.py +index ce307110..7988f5d9 100644 +--- a/git/config.py ++++ b/git/config.py +@@ -876,7 +876,7 @@ class GitConfigParser(cp.RawConfigParser, metaclass=MetaParserBuilder): + value_str = self._value_to_string_safe(value) + if not self.has_section(section): + self.add_section(section) +- self.set(section, option, value_str) ++ super().set(section, option, value_str) + return self + + @needs_values +-- +2.35.6 diff --git a/meta/recipes-devtools/python/python3-git_3.1.42.bb b/meta/recipes-devtools/python/python3-git_3.1.42.bb index 99f31791bd5..e728e8bfa4c 100644 --- a/meta/recipes-devtools/python/python3-git_3.1.42.bb +++ b/meta/recipes-devtools/python/python3-git_3.1.42.bb @@ -15,6 +15,8 @@ inherit pypi python_setuptools_build_meta SRC_URI += "file://CVE-2026-42284.patch \ file://CVE-2026-44243_p1.patch \ file://CVE-2026-44243_p2.patch \ + file://CVE-2026-44244_p1.patch \ + file://CVE-2026-44244_p2.patch \ " SRC_URI[sha256sum] = "2d99869e0fef71a73cbd242528105af1d6c1b108c60dfabd994bf292f76c3ceb" From patchwork Mon Sep 7 13:35:22 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 97558 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 4FDA2C79F9E for ; Mon, 7 Sep 2026 13:36:47 +0000 (UTC) Received: from mail-lj1-f170.google.com (mail-lj1-f170.google.com [209.85.208.170]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.35239.1788788201948875186 for ; Mon, 07 Sep 2026 06:36:42 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=wLcuB9k/; spf=pass (domain: smile.fr, ip: 209.85.208.170, mailfrom: yoann.congal@smile.fr) Received: by mail-lj1-f170.google.com with SMTP id 38308e7fff4ca-3a1f628b1d1so27200461fa.0 for ; Mon, 07 Sep 2026 06:36:41 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1788788200; x=1789393000; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=p3HmJtj8tMVwUo0AE7DusgCGvnLMX3wtOum6N4o0RlQ=; b=wLcuB9k/VbaBjbfuL/4Fd/7GOzDp8Wyikdh9WPjtxQmSk/J6mTeZQZNmmA8ySAq/80 sanox9+XdHMSUDm9kRgo6QEE8s+0i9kP9fd9SrJL7atXimEgR3GDVEGcxv1j7dHAKFKO UE68N4OW20/oJ4enjtVdPDjMgf8M+vv6rcZ5U= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1788788200; x=1789393000; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=p3HmJtj8tMVwUo0AE7DusgCGvnLMX3wtOum6N4o0RlQ=; b=Qn7WE8O1DqA5xX6TgqkGLDVfr6VDXVRVPfR9YMcnFW/zMUpisOx4YDjhN8v4ySAfzf +JuboGjsmnos55P1cTzFHMbUuOv8BYHeiFdes5wjawtT8rAPAXr06RsROe5SqflsILTq QEB1KVFu+AB/auBHxcy9KNSaal5Hr7CoA+KcZ9jct9t9WrhuENLFwIlhwLFzq6TTqSAf ZwLfOd8ujVULtuNoGyy1Ph/tXAzYL/IrkRf4nGWx5X3892hCq7+J1QeAVdWJfahSQqs7 Lbd1WlZ7KScIOqNWuK12g6Oj7j8F9KO9jEz1uC/6RU4NrqOImUkgrU/411Bp2952bphg ZX8g== X-Gm-Message-State: AFuF++mNHb9e4k9P3s6MLx6CBlHRzJ9R3RIoNPMdbJCQu7f8/cse3Nfe 0kLmbODRjGdqQBXr9o/CMEu4ujlHYVsJiruL6dS5NN9GTUujDC1wre4e2C/gax1j3+xpu+F4mgM cvb69ax0= X-Gm-Gg: AYBFou0oL5N0N/zhowFLmkA8VCwBIuPlpTZnfqiKV2vFIx+3GXfiLDYjePKOv6Pd3WP e8iPiDFZAk03rodYqy9L9PM+pEG/iicAO1AFwInbWGXPI5+N/Gc94ScZIK4orl4xbEyWIp6KBsG vKm1SGgXlpRK0NE2AZsQy/G1sOYrFT16Mw7A1trlBHCy38vVEhfz+oqzgm/zjQLfWr9o030irqK o4vYcXtQ48CDC24Os8EWj1vFXamtCD3jJT2gX6lgBmbPEsPKryAMgSSp3Tc8KeaSh01MkPlK83G GKs5g6T+MDcllpWImc3MLoQwjIoYI+cWOg4VZ8dZS87FCTRe+pW4vfzQ8BNNIykbz54XGfe6JrL PhtfQpvuiextAXCL9puJjs8Ht/ZGpM1TaUmtk+j39S43Y3RxIdxlZd1Kmu5byVddx3L5pxvb6ph ii8x5Mg/nfa0qJq2PeNgL72UpIn+v4wBGuq4DkGU6dX6bw0ici6NnOZcby/qajIxdoMct9tXHt8 J/FfYRGCNyMmvPJZfhjcLIBTOI4hlYOTql0iDhSPXeD3BPJwnZ4acEAXn6K6UMD X-Received: by 2002:a05:600c:4513:b0:49d:17b7:fdda with SMTP id 5b1f17b1804b1-49d17b7fe34mr5112235e9.1.1788788165048; Mon, 07 Sep 2026 06:36:05 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-48588394fa1sm27523836f8f.8.2026.09.07.06.36.04 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 07 Sep 2026 06:36:04 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][scarthgap 26/35] expat: set CVE_STATUS for CVE-2026-72522 Date: Mon, 7 Sep 2026 15:35:22 +0200 Message-ID: X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Mon, 07 Sep 2026 13:36:47 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/245293 From: Jaipaul Cheernam CVE-2026-72522 is an out-of-bounds read and infinite loop vulnerability in Expat's *_toUtf16 functions caused by mis-classifying low surrogates as high surrogates. Our Yocto configuration is not affected by this vulnerability: - Expat is compiled with EXPAT_CHAR_TYPE=char (8-bit character representation). - Neither XML_UNICODE nor XML_UNICODE_WCHAR_T is defined. - The vulnerable *_toUtf16 functions are only invoked when Expat's internal character type is 16-bit (ushort or wchar_t). - In 8-bit mode, Expat handles conversion using *_toUtf8 functions even when parsing UTF-16 encoded XML inputs, rendering the vulnerable code path unreachable. Reference: [1] https://nvd.nist.gov/vuln/detail/CVE-2026-72522 [2] https://github.com/libexpat/libexpat/pull/1296/changes/8fbfb52fa88e040e8b0b7a9d39f260d6a9e8b6db Signed-off-by: Jaipaul Cheernam Signed-off-by: Yoann Congal [YC: EXPAT_CHAR_TYPE=char is the default and we do not change it] --- meta/recipes-core/expat/expat_2.6.4.bb | 3 +++ 1 file changed, 3 insertions(+) diff --git a/meta/recipes-core/expat/expat_2.6.4.bb b/meta/recipes-core/expat/expat_2.6.4.bb index 3387a7d7c1f..93f0622373e 100644 --- a/meta/recipes-core/expat/expat_2.6.4.bb +++ b/meta/recipes-core/expat/expat_2.6.4.bb @@ -99,3 +99,6 @@ do_install_ptest:class-target() { BBCLASSEXTEND += "native nativesdk" CVE_PRODUCT = "expat libexpat" + +CVE_STATUS[CVE-2026-72522] = "not-applicable-config: Needs Expat compiled with 16bit character support , Issue only affects firefox/Windows. \ +EXPAT_CHAR_TYPE:STRING=char is for Yocto builds" From patchwork Mon Sep 7 13:35:23 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 8bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 97552 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 38B4CC79FAD for ; Mon, 7 Sep 2026 13:36:17 +0000 (UTC) Received: from mail-wr1-f53.google.com (mail-wr1-f53.google.com [209.85.221.53]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.34940.1788788167507874367 for ; Mon, 07 Sep 2026 06:36:07 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=iNs5XsYR; spf=pass (domain: smile.fr, ip: 209.85.221.53, mailfrom: yoann.congal@smile.fr) Received: by mail-wr1-f53.google.com with SMTP id ffacd0b85a97d-482ea739de2so2399170f8f.0 for ; Mon, 07 Sep 2026 06:36:07 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1788788166; x=1789392966; darn=lists.openembedded.org; h=content-transfer-encoding:content-type:mime-version:references :in-reply-to:message-id:date:subject:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=qnMSyLhyHYgQP76hLyrZqxTNK0Nt4A7zDhxgFflgpC4=; b=iNs5XsYRwaOUYS6rsk34YcfjgnfLRgdcXJkcNDgdwC3Pr6gFz7LsKQNrnrcVBAFkAd 7SqPAd+nB23lalq57YLHuRudUIfDWuob9eScHdqOp1hjxVGKPOhRwU+JHoCiF/jc7X4Y bp0Oyj50mnVDJf4BMEsAEWy4ZQtD8+GrT3sfc= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1788788166; x=1789392966; h=content-transfer-encoding:content-type:mime-version:references :in-reply-to:message-id:date:subject:to:from:x-gm-gg :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to :content-type; bh=qnMSyLhyHYgQP76hLyrZqxTNK0Nt4A7zDhxgFflgpC4=; b=XljJec4PfOAoJdWjMecBnUZGOzIHad469vsgA4WSTJ3V91ErX9H/FmDVeQW5cD4Pa9 oVUxQMLU9+Loh58kC+YWBk4JGqbAU3g3lf+Rg0uNkfYssyJhHkgobEAzSQjWJe+/YC/+ ahumB+Mjiicfn358iD0XwjaR7qy2KPtvy65vVpSHEQs96CU1cjo2FxGaJKCsKn9+WZd4 aTHtmkXV2VOSJzoIHU8IRh5RJzJxo+y+hTG8IDstkqH/CsUfjhgpnM5TsKUpfNy3qrkX G4yI4YKlezJ45AkaCT0X4ehVRgd2g9hgLcWFY/DAW13r4JURPYe3l4tOml+SyZ0ybLl+ Kvlw== X-Gm-Message-State: AFuF++lupCSD5byVw+mJ8cKUQTHpLqZiIqmD3n9ZcWfkV5E0IFPDRrC+ TsdyqEtZjIuv3KL+DkM2xvRq+L0udeUsLkUIJEj7F+HA8At1JACWw+r9HCqnDb94qVIAxsPeHuF 5Za4h5BQ= X-Gm-Gg: AYBFou01Z1+fMPvulslX5B93goxVHvZDYL6w2sOGqzXha82RY1Ln6v2SWfyEB9n2YrK n9O9krenWniIaEdaOVx0DHMQLEpGLk/lffQ+TFXpA2UqufBY8gvPkJfhFUblC1FMk3eunSXcQuv 4XUVsGg4Xd5mlfempOa8UKElFpxDM+5ePPve7MtNPqFcY+j6bWA/pKONgIa8PWjQTRXoEWSA1qH 7iliEuCBdvb8e0x+PjLjzYnXgEjJaaQY+P4reYxPG0ApIs80jI14xA3DgQ9t9N9mnZhyDj7fveI X2YtL92AKa5lTW9Z5xdZ3FTDunKOml8nvPUZALfy2aekxIe/HmfJrZv5KShq95hO2OG6lU37yUr mMK0xH2GgOw8aGkIukbikv4Unj0jgDzjOVu53QoTiWB1wOoO4d7oAn6SmQP4uTqLd6mu02wcLjZ qo816TGUWHnVpaus0+U+fbPm5T+1Ici/2FlSpHkhIUq6HtzbrljEiIUb5zqu4jz6hLCjYh4ZFwT ui/Wy5r+1QHJJT6S0Wc9W51rQL7xsjtdA8h/yzNkqYB7cw5snlcJujnz8afZYEc X-Received: by 2002:a5d:4c8a:0:b0:484:338b:3bc1 with SMTP id ffacd0b85a97d-485872edfb5mr21283423f8f.27.1788788165665; Mon, 07 Sep 2026 06:36:05 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-48588394fa1sm27523836f8f.8.2026.09.07.06.36.05 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 07 Sep 2026 06:36:05 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][scarthgap 27/35] ovmf: fix tpm PACKAGECONFIG to use TPM2_ENABLE Date: Mon, 7 Sep 2026 15:35:23 +0200 Message-ID: X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Mon, 07 Sep 2026 13:36:17 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/245284 From: Eilís 'pidge' Ní Fhlannagáin The tpm PACKAGECONFIG passed "-D TPM_ENABLE=TRUE/FALSE", but ovmf renamed that macro to TPM2_ENABLE in edk2 commit 4de8d61bcec0 ("OvmfPkg: rework TPM configuration", first released in edk2-stable202202). Since then TPM_ENABLE has been an unknown macro that edk2 ignores, so TPM2 support was never compiled in, even for MACHINEs with 'tpm'/'tpm2' in MACHINE_FEATURES. Use TPM2_ENABLE (as defined in OvmfPkg/Include/Dsc/OvmfTpmDefines.dsc.inc and consumed by OvmfPkgX64.dsc) so the tpm PACKAGECONFIG actually enables TPM2 support. The same commit also added a separate TPM1_ENABLE macro (TPM 1.2 support, default TRUE), but its dsc.inc snippets are only included inside OvmfPkgX64.dsc's "!if $(TPM2_ENABLE) == TRUE" block, so it has no effect unless TPM2_ENABLE is TRUE. No separate PACKAGECONFIG knob is needed. Signed-off-by: Eilís 'pidge' Ní Fhlannagáin Signed-off-by: Mathieu Dubois-Briand Signed-off-by: Richard Purdie (cherry picked from commit d6b434455544e5922d75ba07a74490e6a6df7a0c) Signed-off-by: Yoann Congal --- meta/recipes-core/ovmf/ovmf_git.bb | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/meta/recipes-core/ovmf/ovmf_git.bb b/meta/recipes-core/ovmf/ovmf_git.bb index 4e6227f4849..06e96d3a089 100644 --- a/meta/recipes-core/ovmf/ovmf_git.bb +++ b/meta/recipes-core/ovmf/ovmf_git.bb @@ -13,7 +13,7 @@ PACKAGECONFIG ??= "" PACKAGECONFIG += "${@bb.utils.contains('MACHINE_FEATURES', 'tpm', 'tpm', '', d)}" PACKAGECONFIG += "${@bb.utils.contains('MACHINE_FEATURES', 'tpm2', 'tpm', '', d)}" PACKAGECONFIG[secureboot] = ",,," -PACKAGECONFIG[tpm] = "-D TPM_ENABLE=TRUE,-D TPM_ENABLE=FALSE,," +PACKAGECONFIG[tpm] = "-D TPM2_ENABLE=TRUE,-D TPM2_ENABLE=FALSE,," # GCC12 trips on it #see https://src.fedoraproject.org/rpms/edk2/blob/rawhide/f/0032-Basetools-turn-off-gcc12-warning.patch From patchwork Mon Sep 7 13:35:24 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 97553 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 2AF15C79FAC for ; Mon, 7 Sep 2026 13:36:17 +0000 (UTC) Received: from mail-wr1-f51.google.com (mail-wr1-f51.google.com [209.85.221.51]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.35226.1788788168056862977 for ; Mon, 07 Sep 2026 06:36:08 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=CSvyBHdQ; spf=pass (domain: smile.fr, ip: 209.85.221.51, mailfrom: yoann.congal@smile.fr) Received: by mail-wr1-f51.google.com with SMTP id ffacd0b85a97d-484374f54d0so2179799f8f.3 for ; Mon, 07 Sep 2026 06:36:07 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1788788166; x=1789392966; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=HMbHLFqC3ycXDimUwLrfX4/0UdR/L1eJNTjUnLxKvJQ=; b=CSvyBHdQJ9PC563W6uayX0b5cWh1Hz0P43eu0+sqH+MGqT5tXzsL1upxJHT3xQc2PX M/8baz3y7RKGLXziOSHXmGqWwkQEZtFWdem6lMFtT9j5BydpDCtXwwSXawB+vfIBa4cf 87EQ0QLTGY/Kd9magKOhbxT0MLCi+GcpXCDUU= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1788788166; x=1789392966; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=HMbHLFqC3ycXDimUwLrfX4/0UdR/L1eJNTjUnLxKvJQ=; b=pM7A/qvwfdJ/UNfgCXthA9BpXqQxpyxLAhKKAzOnae45TS3m6pSx1QnbPj10VKXqWa onwxqUHPLVWYM+WhTJENjZvtAhFYKhDRqSEt4B6GJgJNMBYFHHm1nrVSHkRchZPvEZi+ oz9Q02oUsx5dRy2lrjunHvhDAr4w4Pfd1rlVvRFEoMjEsyrkWVi/FqRXyE9NUtF9me3G 3axJsaTE/B45g5hw9ds32wovapMW4ZXKoKYL5d3L1GpZvdT9YBjoJlRLZGG9bWzVuRtO jbwNgFi1CpQrZTiQmAv1xXq7FBlW116VzxZq2fbDq48ofokUYh/py8bd08iEqxiB6vL3 9LYA== X-Gm-Message-State: AFuF++mbwI1zFKB4Xxu6eNsdP8hvvn7O1YWsqNV0SD2uGgtZLweE8Cd/ y3JA2LJ7f/xmRlaXIFVzYqBd4tv2GIvZ9GEqq7xDd5VdyVibevUEEMdhmLCbfdJE55FC66e4ILc RddYT3Ic= X-Gm-Gg: AYBFou1L73Jx1IdpkIBYB9XOPvb55b16uOkyYfnStNYWZ3dvD+vEWZWJ3csFkKY7ORq kvcT3jz+AzJISKBSe+iu9vGDC2HqvV/PZpbmnfjnxsWuKAtk5KIw/mrrSCx0I3fTLHnPfAt97qY QaUZ7b+tBCRuI9UxnfdXWgnVdm7sFU8b7ewrtzhouyB4D4kJCYdrH4HO7UwXF73XRIg9PCRVafH mo/9kJTLgPcltC23T/sniWfAFQ+AIR6o0bZGa5yLNcyyCWko3HX9Hrv83HlwUm5N5upvGc5jzbC LkB35edPWdjCn4GwyUBbmWsS5szngC9JGtF0BNDHliABgCU8qjQcTUf0sXhavtdEsUqmTYd5Rnc pB4fmeqaH0HyDmBYS147B7fIRqLW5/F0RcY6ise9rf+SIUFgnw82Rf9UMXNHaS6OAx23ryYbMHm SlF3k+VMZCkWb0+5cOZioN3dMP3B2Gt4X/nSnjuBZiDTvE/S2mT3jnv1pFAhEsTgHL7ygVAL+eg lAiswjyZtyE83JVeUdT7C3Ud5iKx1s4L8wMYKd71PMu7XDEZaFLY6nOTUTT+9gJ X-Received: by 2002:a05:6000:26c4:b0:485:847c:4c64 with SMTP id ffacd0b85a97d-4858729b6f7mr42772763f8f.28.1788788166240; Mon, 07 Sep 2026 06:36:06 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-48588394fa1sm27523836f8f.8.2026.09.07.06.36.05 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 07 Sep 2026 06:36:05 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][scarthgap 28/35] python3-mako: Fix CVE-2026-41205 Date: Mon, 7 Sep 2026 15:35:24 +0200 Message-ID: <0c13fdc7798a24dadb60b7dba60049558bf5c021.1788787321.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Mon, 07 Sep 2026 13:36:17 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/245285 From: Hetvi Thakar This patch applies the upstream fix as referenced in [2], using the commit shown in [1]. The backport makes Template URI normalization strip all leading slashes, preventing a double-slash URI from bypassing the path traversal check while keeping Mako at version 1.3.2. [1] https://github.com/sqlalchemy/mako/commit/e05ac61989a7fb9dd7dcde6cfd72dc48328719a3 [2] https://github.com/advisories/GHSA-v92g-xgxw-vvmm Signed-off-by: Hetvi Thakar Signed-off-by: Yoann Congal --- .../python/python3-mako/CVE-2026-41205.patch | 110 ++++++++++++++++++ .../python/python3-mako_1.3.2.bb | 2 + 2 files changed, 112 insertions(+) create mode 100644 meta/recipes-devtools/python/python3-mako/CVE-2026-41205.patch diff --git a/meta/recipes-devtools/python/python3-mako/CVE-2026-41205.patch b/meta/recipes-devtools/python/python3-mako/CVE-2026-41205.patch new file mode 100644 index 00000000000..0699654b532 --- /dev/null +++ b/meta/recipes-devtools/python/python3-mako/CVE-2026-41205.patch @@ -0,0 +1,110 @@ +From e05ac61989a7fb9dd7dcde6cfd72dc48328719a3 Mon Sep 17 00:00:00 2001 +From: Mike Bayer +Date: Tue, 14 Apr 2026 15:45:19 -0400 +Subject: [PATCH] Fix path traversal via double-slash URI prefix in + TemplateLookup + +The URI normalization in Template.__init__ stripped only a single +leading slash, while TemplateLookup.get_template() stripped all +leading slashes. A URI such as "//../../secret.txt" could bypass +the directory traversal check. Changed to use lstrip("/") so +both code paths handle leading slashes consistently. + +Fixes: #434 +Change-Id: I400b9a40aed956cc2b5826a9c8736f104e84f1a4 + +CVE: CVE-2026-41205 +Upstream-Status: Backport [https://github.com/sqlalchemy/mako/commit/e05ac61989a7fb9dd7dcde6cfd72dc48328719a3] + +(cherry picked from commit e05ac61989a7fb9dd7dcde6cfd72dc48328719a3) +Signed-off-by: Hetvi Thakar +--- + doc/build/unreleased/434.rst | 10 +++++++++ + mako/template.py | 4 +--- + test/test_lookup.py | 41 ++++++++++++++++++++++++++++++++++++ + 3 files changed, 52 insertions(+), 3 deletions(-) + create mode 100644 doc/build/unreleased/434.rst + +diff --git a/doc/build/unreleased/434.rst b/doc/build/unreleased/434.rst +new file mode 100644 +index 00000000..452265ad +--- /dev/null ++++ b/doc/build/unreleased/434.rst +@@ -0,0 +1,10 @@ ++.. change:: ++ :tags: bug, template ++ :tickets: 434 ++ ++ Fixed issue in :class:`.TemplateLookup` where a URI with a double-slash ++ prefix (e.g. ``//../../``) could bypass the directory traversal check in ++ :class:`.Template`, allowing reads of arbitrary files outside of the ++ template directory. The issue was caused by an inconsistency in how leading ++ slashes were stripped between :meth:`.TemplateLookup.get_template` and ++ :class:`.Template` initialization. +diff --git a/mako/template.py b/mako/template.py +index 82c7cba8..d8ebc949 100644 +--- a/mako/template.py ++++ b/mako/template.py +@@ -259,9 +259,7 @@ def __init__( + self.module_id = "memory:" + hex(id(self)) + self.uri = self.module_id + +- u_norm = self.uri +- if u_norm.startswith("/"): +- u_norm = u_norm[1:] ++ u_norm = self.uri.lstrip("/") + u_norm = os.path.normpath(u_norm) + if u_norm.startswith(".."): + raise exceptions.TemplateLookupException( +diff --git a/test/test_lookup.py b/test/test_lookup.py +index 6a797d7a..2f7cdf0b 100644 +--- a/test/test_lookup.py ++++ b/test/test_lookup.py +@@ -127,6 +127,47 @@ def test_dont_accept_relative_outside_of_root(self): + # this is OK since the .. cancels out + runtime._lookup_template(ctx, "foo/../index.html", index.uri) + ++ def test_dont_accept_relative_outside_of_root_via_double_slash(self): ++ """test that double-slash URI prefix can't bypass the ++ path traversal check""" ++ with tempfile.TemporaryDirectory() as base: ++ tmpl_dir = os.path.join(base, "app", "templates") ++ os.makedirs(tmpl_dir) ++ with open(os.path.join(tmpl_dir, "index.html"), "w") as f: ++ f.write("Hello") ++ ++ secret = os.path.join(base, "secrets", "creds.txt") ++ os.makedirs(os.path.dirname(secret)) ++ with open(secret, "w") as f: ++ f.write("SECRET_KEY=supersecret123") ++ ++ tl = lookup.TemplateLookup(directories=[tmpl_dir]) ++ rel = os.path.relpath(secret, tmpl_dir) ++ ++ # single-slash prefix should also be blocked ++ assert_raises_message( ++ exceptions.TemplateLookupException, ++ "cannot be relative outside of the root path", ++ tl.get_template, ++ "/" + rel, ++ ) ++ ++ # double-slash prefix must not bypass the check ++ assert_raises_message( ++ exceptions.TemplateLookupException, ++ "cannot be relative outside of the root path", ++ tl.get_template, ++ "//" + rel, ++ ) ++ ++ # triple-slash prefix must not bypass the check ++ assert_raises_message( ++ exceptions.TemplateLookupException, ++ "cannot be relative outside of the root path", ++ tl.get_template, ++ "///" + rel, ++ ) ++ + def test_checking_against_bad_filetype(self): + with tempfile.TemporaryDirectory() as tempdir: + tl = lookup.TemplateLookup(directories=[tempdir]) diff --git a/meta/recipes-devtools/python/python3-mako_1.3.2.bb b/meta/recipes-devtools/python/python3-mako_1.3.2.bb index 5b7df9192f8..617bf33443c 100644 --- a/meta/recipes-devtools/python/python3-mako_1.3.2.bb +++ b/meta/recipes-devtools/python/python3-mako_1.3.2.bb @@ -8,6 +8,8 @@ PYPI_PACKAGE = "Mako" inherit pypi python_setuptools_build_meta +SRC_URI += "file://CVE-2026-41205.patch \ + " SRC_URI[sha256sum] = "2a0c8ad7f6274271b3bb7467dd37cf9cc6dab4bc19cb69a4ef10669402de698e" RDEPENDS:${PN} = "python3-html \ From patchwork Mon Sep 7 13:35:25 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 97557 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 13248C79FAB for ; Mon, 7 Sep 2026 13:36:17 +0000 (UTC) Received: from mail-wr2-f12.google.com (mail-wr2-f12.google.com [74.125.225.76]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.35227.1788788169422906347 for ; Mon, 07 Sep 2026 06:36:09 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=r8KGqNSo; spf=pass (domain: smile.fr, ip: 74.125.225.76, mailfrom: yoann.congal@smile.fr) Received: by mail-wr2-f12.google.com with SMTP id ffacd0b85a97d-48449f62b93so83511f8f.0 for ; Mon, 07 Sep 2026 06:36:09 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1788788168; x=1789392968; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=etVd1x5VlPkjKGmGNtvZwAuNpO8Ko+ABsz/lhDKO3/0=; b=r8KGqNSoutjh9xySqKinTgedCritQSl2L+cjdqFlI1h52qTanXJ7bDyD71iw+2+s5x Xkm+Aqh43/+HH2ovuvoaUnknU7zzK3WNKRa+POyL0vYfksFwdDKy39hX1TL1pN0zJO79 gTRXmM5yz0INl69NPROlG9Fbl9bm2oossHV28= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1788788168; x=1789392968; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=etVd1x5VlPkjKGmGNtvZwAuNpO8Ko+ABsz/lhDKO3/0=; b=WOQiT1QqeLc/aWssNC8E69UWiqAnHghLJW4o7U3cvFAquVY/DSRlTlVCJ0EKZRaar7 1GA3WUJ2eQ8GE3q93pZm/Ady0FwU/X6BldF2nRnilo1QyR/y7NRvwONgMZp180BCOBzj jjpfaINhX9FUA0Ny9z15zC6rKgLWP5C6UuweDZjmrkZYdc99qM2ziyjRHJ6nE8Clvjy2 rQbG1gxsE6KxHIiGRRVxcLXySW6WHZBCaHwPg9wAdWv5mCfL0U4rCtmO1LX/4eOoHqDO GNMXrrXJf+zm2dlMUuna+6IIeI+UvQP3ZuIEawxmp2p8oc+wqyq0YRq3aBBxD1dgfyJy AUmA== X-Gm-Message-State: AFuF++lHb2xLX1O40lR+b34AfHhTTPR7MVPfFTPKB0ejBZfYZbVJrLiM u7PwoBHTsVAu9e73UFIswCzLgzUfr5V24TesWL6jyzL7CIkS1Hs78K6hxQOP2JYwyFRzqJQG3Cf khU+o5Ig= X-Gm-Gg: AYBFou1aDGYwY8fwAD2+XmTZWlw25x9baQLRXfwF83SsrfJR4OpZ/bYrcotx4JHuQUQ cTAm29DZ0WNk3LfW+YSibAGgLua3u7fz9uDY7dLUxYa0pwL6YbBnMEvhXj1m0O98NGm6eq3vgh+ AHdIE9R4SyVZHvQVFvPOZbiX9wHxEOE0a+h4VsiKtuazyqH9VeqsgUrcScd6t4r26QGmw2QPkQs vp76n6Ybwq9DzEScN/i0GwNsJkmADH3/uftLYfAJafy0slpJ/u8XDHCkAIaU1NgXFTtvM/Zo19H tZRBfVc0ZIg4l6iCrPAFRwOQlC7B5EtptVWTDED9+SSElomegsq7lRqxB8P5V8H6m8v4LjVTr+7 rhXAgmny0JAxgiN6srFnXphBdqQHvkDVOr6AQSMTedvkKBJBOF25+QkFpOUvYhP3brCY9s/20/P y+qf+QpXVrJ3zx4Mv3m704uGgR4gZwmwXqp4jLEFNFBwA335MQUh4ohiYx1aDLefOy1K0Ei0uc0 IAZ/z/YTgKccuYdJYV5wOwpz3y+iBU+3dPWH0TY1ZZAyxLnzte0P9BLkf3b5dVXQt/P/DvAgOg= X-Received: by 2002:a5d:66c1:0:b0:484:3311:257a with SMTP id ffacd0b85a97d-485a2418a3emr1022437f8f.14.1788788166947; Mon, 07 Sep 2026 06:36:06 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-48588394fa1sm27523836f8f.8.2026.09.07.06.36.06 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 07 Sep 2026 06:36:06 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][scarthgap 29/35] linux-yocto/6.6: update to v6.6.150 Date: Mon, 7 Sep 2026 15:35:25 +0200 Message-ID: <8d7664577ca7d2b0c420231aac5fd094b8bedfbf.1788787321.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Mon, 07 Sep 2026 13:36:17 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/245286 From: Bruce Ashfield Updating linux-yocto/6.6 to the latest korg -stable release that comprises the following commits: 6436c12a2ced8 Linux 6.6.150 6703dba1d14cb x86/bugs: Make Safe-RET robust against interrupt injection 4c34a21ff85ce Revert "x86/bugs: Make Safe-RET robust against interrupt injection" 80dfb0405055d Linux 6.6.149 608c8f5dccaaf x86/bugs: Make Safe-RET robust against interrupt injection aa0e49877a2e6 Linux 6.6.148 60283726f2845 KVM: SVM: Bump asid_generation on CPU online to avoid ASID collision after hotplug 299e2a6eb501c rxrpc: Disable IRQ, not BH, to take the lock for ->attend_link 410f8e562e37d udmabuf: Ensure to perform cache synchronisation in begin_cpu_udmabuf() 45bd023c7a4ec ASoC: mediatek: mt8195: Set ETDM1/2 IN/OUT to COMP_DUMMY() 62f61129621ce ASoC: mediatek: mt8195: Add platform entry for ETDM1_OUT_BE dai link 4b4a3e7ef7bb6 mm/damon/core: disallow overlapping input ranges for damon_set_regions() b585facbafbb5 mm/damon/core: validate ranges in damon_set_regions() 1d5ad6c5a2109 coredump: fix pidfs file refcount leak in umh_coredump_setup ce409086174b0 KVM: x86: Only reset TSC Deadline Timer in apic_timer_expired on KVM_RUN 40d790e0e7d01 KVM: Introduce vcpu->wants_to_run 9168176894332 fs/resctrl: Fix double-add of pseudo-locked region's RMID to free list 96ac6c08f2c19 net: ipa: fix SMEM state handle leaks in SMP2P init 6124bd7850736 net: macb: drop in-flight Tx SKBs on close 4cb4b4dd8853c ata: libata-core: Reject an invalid concurrent positioning ranges count 148d7ec0a3a98 octeontx2-pf: fix SQB pointer leak on init failure 9409e18ffe737 ipmi: fix refcount leak in i_ipmi_request() 07e82e2825e3b bootconfig: fix NULL-pointer arithmetic in xbc_snprint_cmdline() 3fb2d026fb0de bootconfig: move xbc_snprint_cmdline() to lib/bootconfig.c 3a4627d4cd977 bootconfig: do not put quotes on cmdline items unless necessary e9c5b03208507 octeontx2-af: cn10k: restrict VF LMTLINE sharing to its own PF 207d3ebf36f65 gpio: mt7621: avoid corruption of shared interrupt trigger state 2636d061bc237 net: ip6_tunnel: require CAP_NET_ADMIN in the device netns for changelink e57a4845b0da6 gpio: tegra: do not call pinctrl for GPIO direction f53dd26462b8e pinctrl: remove pinctrl_gpio_direction_output() 2e276b14b6d37 net: mana: Validate the packet length reported by the NIC 3cfaac77b3c32 locking/rt: Fix the incorrect RCU protection in rt_spin_unlock() 4714e95f5d61c wifi: libertas_tf: fix use-after-free in lbtf_free_adapter() 25acb6711da6f tracing/user_events: Fix use-after-free in user_event_mm_dup() 017ea3f38a2d6 workqueue: Add system_percpu_wq and system_dfl_wq e0d8c1d9232f0 workqueue: Factor out init_cpu_worker_pool() a5dd47ea3904d Input: ims-pcu - fix firmware leak in async update 5e7cd480fb691 firmware_loader: introduce __free() cleanup hanler ac99781115d37 dm-verity: make error counter atomic 949f14390fe48 dm-verity: avoid double increment of &use_bh_wq_enabled 45ead2e598cc8 ovl: use linked upper dentry in copy-up tmpfile a442c258320b6 NFS: Charge unstable writes by request size, not folio size 98e9a7bfd3a45 nfs: remove dead code for the old swap over NFS implementation 016ef0f6ca4bc i2c: imx: fix locked bus on SMBus block-read of 0 (atomic) 9d9c1f10f5642 i2c: imx: separate atomic, dma and non-dma use case e4908b3bed755 platform/x86: dell-laptop: fix missing cleanups in init error path 14b586152bb49 platform/x86: dell-smbios: Move request functions for reuse 2733b5dcb5a4b dmaengine: dw-edma-pcie: Reject devices without driver data ac710b2f4f2fe dmaengine: dw-edma: Fix confusing cleanup.h syntax 5cfa46154e0c9 dma: dw-edma: Fix build warning in dw_edma_pcie_probe() f12885fe1bdb0 taskstats: retain dead thread stats in TGID queries ee14a2d7f07e0 taskstats: fill_stats_for_tgid: use for_each_thread() d26f0b293b437 mtd: rawnand: Pause continuous reads at block boundaries f83ba55179c27 mtd: rawnand: Ensure all continuous terms are always in sync 9db680306555c mtd: rawnand: Add a helper for calculating a page index 8d94813696095 mm/mm_init: fix pageblock migratetype for ZONE_DEVICE compound pages fc2214723b45d SUNRPC: Return an error from xdr_buf_to_bvec() on overflow 18387968cff28 SUNRPC: Add helpers to convert xdr_buf byte ranges to scatterlists 844520b33c805 sunrpc: allocate a separate bvec array for socket sends 43ffd230b9cc1 NFSD: pass nfsd_file to nfsd_iter_read() 4fee43759b489 netfilter: nft_fib: reject fib expression on the netdev egress hook 7cd3fee7b361e netfilter: nf_tables: remove register tracking infrastructure 363e37bebbbd5 netfilter: nf_tables: Remove unused nft_reduce_is_readonly() e64a48c50a1ff netfilter: nf_conntrack_sip: validate skb_dst() before accessing it 0d713c11de5da netfilter: nf_conntrack_sip: remove net variable shadowing 5d4d93f9bfbc9 selinux: avoid sk_socket dereference in selinux_sctp_bind_connect() d787e4c3acdf7 lsm: infrastructure management of the sock security 047e813324eac netfilter: nft_set_pipapo: don't leak bad clone into future transaction 744dc9a47a845 netfilter: nft_set_pipapo: move cloning of match info to insert/removal path fad1685df350f netfilter: nft_set_pipapo: prepare pipapo_get helper for on-demand clone 840daa6bc4d12 netfilter: nft_set_pipapo: merge deactivate helper into caller 8e264996d95f9 netfilter: nft_set_pipapo: prepare walk function for on-demand clone 7583b0d84ca27 netfilter: nft_set_pipapo: make pipapo_clone helper return NULL dde6b54848a51 netfilter: nft_set_pipapo: move prove_locking helper around 385e2a9360cc6 netfilter: nft_set_pipapo: use GFP_KERNEL for insertions 233f357bf424a ASoC: mediatek: mt8183: Check runtime resume during probe 6e2ee6eacc3ec ASoC: mediatek: mt8192: Check runtime resume during probe 5f2ae0405ff50 ASoC: mediatek: mt8192-afe-pcm: Simplify probe() with local dev variable 074371b2d5b0e ASoC: mediatek: Use common mtk_afe_pcm_platform with common probe cb 21fc21eb477d8 ASoC: mediatek: mt8192-afe-pcm: Simplify with dev_err_probe() e63067d8f4bdb ASoC: mediatek: mt8192-afe-pcm: Convert to devm_pm_runtime_enable() 81051a495a9a2 ASoC: mediatek: mt8195: Remove afe-dai component and rework codec link fafb2e08741b2 fbdev: efifb: fix memory leak in efifb_probe() d2ac7ab193810 fbdev/efifb: Replace references to global screen_info by local pointer e2007df69e606 octeontx2-vf: clear stale mailbox IRQ state before request_irq() e60543f29ffb7 octeontx2-pf: clear stale mailbox IRQ state before request_irq() d205563ee9e1e octeontx2: Annotate mmio regions as __iomem fde25641cbddd VDUSE: avoid leaking information to userspace 680a38322b404 vduse: take out allocations from vduse_dev_alloc_coherent 0a0f90adebc0b vduse: remove unused vaddr parameter of vduse_domain_free_coherent 6b8d37b1998f0 vduse: Use fixed 4KB bounce pages for non-4KB page size c656e6a312322 rxrpc: Fix socket notification race dc31e0a74e34a rxrpc: Fix notification vs call-release vs recvmsg 77433b730970c rxrpc: Use irq-disabling spinlocks between app and I/O thread 95051b9f962a7 rxrpc: Don't need barrier for ->tx_bottom and ->acks_hard_ack 12876864f9de5 tipc: restrict socket queue dumps in enqueue tracepoints 03a0e49a2e38e fbcon: Use correct type for vc_resize() return value 43fbdd21723f8 fbcon: Rename struct fbcon_ops to struct fbcon_par 0337cdba0c477 rxrpc: serialize kernel accept preallocation with socket teardown 4a7e71d5bf93c rxrpc: Pull out certain app callback funcs into an ops table b9f12329ef221 afs: Turn the afs_addr_list address array into an array of structs 815a1eb356f2a afs: Annotate struct afs_addr_list with __counted_by c071d94d3fb9f serial: max310x: implement gpio_chip::get_direction() 10a9d4fde5478 serial: max310x: replace bare use of 'unsigned' with 'unsigned int' (checkpatch) a8367b6f84234 ALSA: hda: Fix cached processing coefficient verbs 2874c1ae0640c ALSA: hda: conexant: Remove mic bias threshold override 2ef69871b313a i2c: i801: fix hardware state machine corruption in error path 36eb77f14b4e6 audit: fix recursive locking deadlock in audit_dupe_exe() df550e88009a6 audit: use 'unsigned int' instead of 'unsigned' 26f32cae6496c audit: widen ino fields to u64 3ff7d33398419 VFS/audit: introduce kern_path_parent() for audit 6709fc381d53f i2c: davinci: Unregister cpufreq notifier on probe failure 16381bda90b26 fpga: dfl-afu: validate DMA mapping length in afu_dma_map_region() 0db56e7eae932 dma-buf/udmabuf: skip redundant cpu sync to fix cacheline EEXIST warning 583fa6925df3e udmabuf: Do not create malformed scatterlists 9ceebbd6f9eb5 iommu/amd: Don't split flush for amd_iommu_domain_flush_all() 5337eebdf8c5d bpf: Reject BPF_MAP_TYPE_INODE_STORAGE creation if BPF LSM is uninitialized d65e397a1fd6e bpf: drop bpf_lsm_getselfattr from hook list 2efa9f57d089a net: pcs: xpcs: fix SGMII state reading 80f7dac8c9f93 io_uring/rw: fix missing ERESTARTSYS conversion in read paths cafa53d3272c6 drm/amd/display: Fix dcn32 DTB DTO update breaking live pixel rate sources 67ce8034dc027 exfat: validate cluster allocation bits of the allocation bitmap 4462ac3d90e89 fscrypt: Avoid dynamic allocation in fscrypt_get_devices() a16eaaf7c0b0c openvswitch: fix GSO userspace truncation underflow b7cb5bf085547 ksmbd: validate ACE size against SID sub-authorities 6d9d7aa4a2c99 ksmbd: bound DACL dedup walk to copied ACEs f4fcd0c1a243d ksmbd: restore DACL size on check_add_overflow() to avoid malformed ACL e31fada514378 ksmbd: validate num_subauth when copying ACE in set_ntacl_dacl 8b386b6a24f61 net: qrtr: ns: Raise node count limit to 512 160d3f0d7a556 ipv6: ndisc: fix NULL deref in accept_untracked_na() ef40d94114693 i40e: remove read access to debugfs files 67bc3647e418e drm/amdgpu: fix aperture mapping leak bdfc7f1e0900e drm/amdgpu: invoke pm_genpd_remove() before freeing genpd 52f9a58829643 drm/amdgpu: fix division by zero with invalid uvd dimensions b1d05cc61dfa6 drm/dp_mst: Handle torn-down topology gracefully in drm_dp_mst_topology_queue_probe() bbbe6a2a8d8dc drm/amdgpu/vcn4: avoid rereading IB param length a07430abd556d drm/amdgpu/vce: fix integer overflow in image size 256d6f4803a93 drm/amdgpu/sdma4.4.2: replace BUG_ON() with WARN_ON() 6c8b9c1f03c71 drm/amdgpu/gfx9: replace BUG_ON() with WARN_ON() c59b57c2e0c8c drm/amdgpu/gfx9.4.3: replace BUG_ON() with WARN_ON() ab05af6c345bc drm/amdgpu/gfx8: drop unecessary BUG_ON() 96b6d68f2b5a2 drm/amdgpu/gfx11: replace BUG_ON() with WARN_ON() 793cdf17ddf9d drm/amdgpu/gfx10: replace BUG_ON() with WARN_ON() ff4fc24da7531 drm/amd/pm: make pp_features read-only when scpm is enabled 5bc8fc1d2ff80 vxlan: mdb: Fix source list corruption on a failed replace b07d87b31631e tipc: clear sock->sk on the failed-insert path in tipc_sk_create() e6493a4d1ee17 pppoe: reload header pointer after dev_hard_header() 36dc6d6964a3b mctp: serial: handle zero-length frames to prevent rx buffer overflow 5bbf0cd9b6a70 mac802154: llsec: reject frames shorter than the authentication tag bd7110f0caa32 mac802154: hold an interface reference across the scan worker 896a9512d0d83 ila: reload IPv6 header after pskb_may_pull in checksum adjust 0f33178ec690a ice: use READ_ONCE() to access cached PHC time 5c833074b549e ksmbd: defer destroy_previous_session() until after NTLM authentication 14995c4250f04 rbd: Reset positive result codes to zero in object map update path c674751ea5918 proc: Fix broken error paths for namespace links e054dcd990d81 net: hip04: fix RX buffer leak on build_skb failure 3f4fe26c20c30 net/x25: fix use-after-free in x25_kill_by_neigh() 23658b350b410 net/iucv: fix use-after-free of a severed iucv_path 8bb111f87ded6 net/af_iucv: fix NULL deref in afiucv_hs_callback_syn() 2abdacc927c92 geneve: require CAP_NET_ADMIN in the device netns for changelink eb3836eab4748 net: slip: serialize receive against buffer reallocation b3793d7dccb19 vxlan: require CAP_NET_ADMIN in the device netns for changelink 8d931a75a38b9 phonet: pep: fix use-after-free in pep_get_sb() ae045ad927c24 iommu/vt-d: Disallow SVA if page walk is not coherent 3d0dd138a06c7 ftrace: Add global mutex to serialize trace_parser access 330249609b707 fscrypt: Add missing superblock check in find_or_insert_direct_key() b98fad81f1202 fs: preserve ACL_DONT_CACHE state in forget_cached_acl() e4563e07ef5c9 binfmt_elf_fdpic: only honour the first PT_INTERP fc1010e7e0204 libceph: remove debugfs files before client teardown b8a9fb6bf806f libceph: reject zero bucket types in crush_decode 0591a15815b49 libceph: Reject monmaps advertising zero monitors 9d37aec9ffe4e libceph: refresh auth->authorizer_buf{,_len} after authorizer update c46d82c47afc9 libceph: guard missing CRUSH type name lookup 05c90e059269f libceph: Fix multiplication overflow in decode_new_up_state_weight() 340e0386aa39d libceph: bound get_version reply decode to front len 9081c71796724 ceph: fix pre-auth out-of-bounds read on snaptrace in ceph_handle_caps() fedeb4468987b sctp: don't free the ASCONF's own transport in DEL-IP processing 3422658308d16 mptcp: only set DATA_FIN when a mapping is present 3cb65da64af9a mptcp: decrement subflows counter on failed passive join 8e558bcaf1076 Revert "arm64: syscall: Ensure saved x0 is kept in-sync with tracer updates" 8000a5f4d1d19 arm64: syscall: Ensure saved x0 is kept in-sync with tracer updates bdf9de52c09e9 tracing/probes: Prevent out-of-bounds write in __trace_probe_log_err() da0a33d41409d tracing/probes: Fix potential underflow in LEN_OR_ZERO macro 707720ab00c81 tracing/probes: Avoid temporary buffer truncation in trace_probe_match_command_args() 08259252e0d36 tracing/eprobe: Fix exact system name matching in eprobe_dyn_event_match() f9e6dfe341fb3 tracing: Fix resource leak on mmiotrace trace_pipe close faaf951351842 tracing: Fix mmiotrace possible NULL dereferencing of hiter->dev ddcf2064d7ec5 intel_th: fix MSC output device reference leak 441559d4c595f mei: bus: access mei_device under device_lock on cleanup 1096397c31f6b serial: 8250_mid: Fix NULL function pointer dereference on DNV/ICX-D/SNR platforms 42710bb9946a0 serial: sc16is7xx: implement gpio get_direction() callback b061bb4dca49f comedi: comedi_parport: deal with premature interrupt fac60fefe8766 x86/boot/compressed: Disable jump tables 7344c84e32413 cdrom: fix stack out-of-bounds read in CDROMVOLCTRL 1d6e915400157 LoongArch: Fix oops during single-step debugging f8b7d5ba99ab0 platform/loongarch: laptop: Explicitly reset bl_powered state when suspend 0f19d54e2524f binfmt_misc: set have_execfd only once the interpreter is opened c62bb00caba66 exec: fix unsigned loop counter wrap in transfer_args_to_stack() 2894bd8c68e97 Bluetooth: RFCOMM: Fix session UAF in set_termios e4fa2c5c261d7 Bluetooth: hci_sync: Protect UUID list traversal e126aaf82380c staging: rtl8723bs: fix inverted HT40 secondary channel offset b9d9a4cd2e59d staging: rtl8723bs: fix OOB reads in rtw_get_wps_ie() b7d1d8cb1bdca wifi: brcmfmac: make release_scratchbuffers idempotent ef2ee5f820c3e wifi: mt76: mt7921: drop TXRX_NOTIFY on non-mmio buses f2a72f47c5fb4 wifi: mt76: mt7615: drop TXRX_NOTIFY on non-mmio buses 584c8954ad55f wifi: wilc1000: validate assoc response length before subtracting header eb42c3c8fd479 wifi: mwifiex: fix NULL dereference when the AP has HT-cap but no HT-oper d4558c1407821 wifi: ath6kl: fix OOB access from firmware ADDBA window size fb40d03ed792a ALSA: seq: close a re-opened queue timer in the destructor 450dbb3024199 media: vpif_capture: fix OF node reference imbalance a9cd0e8fb0b21 media: vivid: check for vb2_is_busy() when toggling caps 783f26368b7f5 media: vivid: add vivid_update_reduced_fps() d912d5b14356c media: vimc: fix reference leak on failed device registration 32623707968be media: vidtv: fix reference leak on failed device registration 697b81e9c4b5b media: vb2: use ssize_t for vb2_read/vb2_write 9a998cc1c3487 media: v4l2-ctrls: validate HEVC active reference counts ef78c8c02a46a media: v4l2-ctrls-request: add NULL check in v4l2_ctrl_request_complete() 4ecf0cc0cf590 media: ti: vpe: unwind v4l2 device registration on probe error cb0502d299784 media: tegra-video: vi: fix invalid u32 return value in format lookup 4872161e6fbe4 media: sun4i-csi: Return queued buffers on start_streaming() failure 37ff63c5d7119 media: stm32: dcmi: unregister notifier on probe failure 134c979dd721e media: saa7134: Fix a possible memory leak in saa7134_video_init1 465dc8e71d2db media: rtl2832_sdr: Return queued buffers on start_streaming() failure 9acd5bbbe1df8 media: rtl2832: fix use-after-free in rtl2832_remove() 4ca9c9f12b1bc media: radio-si476x: Unregister v4l2_device on probe failure f2f9fcacd8195 media: pwc: Return queued buffers on start_streaming() failure a56e7641e09bd media: pwc: Drain fill_buf on start_streaming() failure 46715fecc38a2 media: pci: dm1105: Free allocated workqueue 9ed0184435a16 media: nxp: imx8-isi: Fix scale factor calculation for hardware rounding 690cdda752f3d media: nxp: imx8-isi: Fix potential out-of-bounds issues ff5f7c2686dc4 media: nxp: imx8-isi: Fix missing v4l2_subdev_cleanup() in pipe init error path 1eee561d764d5 media: nxp: imx8-isi: Clean up already-initialized pipes on probe failure 549dd1afce2cf media: nxp: imx8-isi: Add missing v4l2_subdev_cleanup() in crossbar and pipe 1d58229b330b7 media: msi2500: Return queued buffers on start_streaming() failure c6cd08a71a630 media: meson: vdec: Fix memory leak in error path of vdec_open d59af4652d999 media: marvell-cam: fix missing pci_disable_device() on remove 8fbdca4c99f68 media: cx23885: add ioremap return check and cleanup a373f1a5137e9 media: cx231xx: fix devres lifetime 2ee8327c85b3a media: cedrus: skip invalid H.264 reference list entries e6db514875abc media: cedrus: Fix missing cleanup in error path d7bb9e62c0f28 media: cedrus: clean up media device on probe failure 8e1c938f08e79 media: cec: seco: unregister adapter on IR probe failure f522a7f05f21a media: aspeed: fix missing of_reserved_mem_device_release() on probe failure 877686a74ecdc media: airspy: Return queued buffers on start_streaming() failure 9f0ee411fc2d7 drm/vc4: Prevent shader BO mappings from becoming writable 5ff94e1279176 drm/vmwgfx: Validate vmw_surface_metadata::array_size 51eeef1949c11 drm/amdgpu: fix bo->pin leaking in amdgpu_bo_create_reserved ba8bf1dcbb447 drm/amd/display: set new_stream to NULL after release f02c9e1588d49 drm/amd/pm/ci: Don't disable MCLK DPM on Bonaire 0x6658 (R7 260X) 1615811cd365e drm/amdgpu: Fix VFCT bus number matching with soft filter edd2edaca52ad drm/i915/gem: Fix NULL deref in I915_CONTEXT_PARAM_SSEU f014702fbd48d drm/i915/gem: Do not leak siblings[] on proto context error 32c1a2afa90dd drm/i915: Return NULL on error in active_instance f6212bc1bbd93 drm/amdgpu/sdma5.0: replace BUG_ON() with WARN_ON() 01dfea84df919 drm/amdgpu/sdma5.2: replace BUG_ON() with WARN_ON() 2eb06c88426b6 drm/amdgpu/sdma6.0: replace BUG_ON() with WARN_ON() 9fc2a017c5d59 drm/virtio: bound EDID block reads to the response buffer f9922828a4ebd drm/amd/display: detect_link_and_local_sink: DP alt mode timeout path leaks prev_sink reference 790aeed9df5c1 drm/amd/display: Handle struct drm_plane_state.ignore_damage_clips 85eedff5f0c4a drm/amdkfd: Check bounds in allocate_event_notification_slot ec26f6cdcc0ee drm/radeon: fix r100_copy_blit for large BOs 3ed109a721761 drm/nouveau/acr: fix missing nvkm_done() in error path of nvkm_acr_oneinit() 4a27275d27597 drm/i915/gem: Add missing nospec on parallel submit slot 2473ac314387a drm/nouveau: fix reversed error cleanup order in ucopy functions 3f190956404da drm/amdgpu: validate CP_GFX_SHADOW chunk size in CS pass1 f0d81d85e7fff drm/amdgpu: Fix amdgpu_bo_move() when old_mem and new_mem are both GTT 4b606f32b38a6 drm/amdgpu/uvd: Place VCPU BO only in VRAM for UVD 4.x and older c3fae34d6cb0c drm/amdgpu/uvd: Fix forcing MSG, FB BOs into VCPU segment when it isn't at 0 (v2) bdf0508b1e678 drm/dp/mst: fix OOB reads on 2-byte fields in sideband reply parsers 53937a2787d29 drm/dp/mst: fix buffer overflows in sideband chunk accumulation 22d9f7fc1aaab drm/dp/mst: fix OOB reads in remote DPCD/I2C sideband reply parsers c18d46d9830c2 drm/bridge: cdns-dsi: Replace deprecated UNIVERSAL_DEV_PM_OPS() f14d66e4b5022 drm/rockchip: cdn-dp: add missing check in cdn_dp_config_video() ee762f684eefa bpf, sockmap: Fix cork use-after-free in tcp_bpf_sendmsg() 2cec93b60e36b ice: fix LAG recipe to profile association b05b6bd1abf49 net: ipv6: fix dif and sdif mismatch in raw6_icmp_error f110b4526f576 net/mlx5e: Reject unsupported CB Shaper TSA in ETS validation 0317492024148 net/mlx5e: Report zero bandwidth for non-ETS traffic classes 43c287ce77eaf net/mlx5: E-Switch, fix zero num_dest in prio_tag egress vlan rule 4b95e1f0d6e63 net: qrtr: restrict socket creation to the initial network namespace 9f55eab598de4 hinic: remove unused ethtool RSS user configuration buffers 5d3427016234e ppp: annotate data races in ppp_generic 97562e355e3da ppp: enable TX scatter-gather 1d03e26ef1d7f ppp: convert to percpu netstats c71962f300912 ppp: use IFF_NO_QUEUE in virtual interfaces 72e2ccfe39633 ipv4: icmp: fill flow parameters in icmp_route_lookup decoy lookup c34fbb0e85f0f octeontx2-vf: set TC flower flag on MCAM entry allocation e99309df721e3 net: stmmac: enable the MAC on link up for all supported speeds b664b326e1674 net: stmmac: reset residual action in L3L4 filters on delete ba351ae1028df net: stmmac: fix l3l4 filter rejecting unsupported offload requests f02334a9e378f tipc: fix u16 MTU truncation in media and bearer MTU validation 92492743e9573 iomap: correct the range of a partial dirty clear 667b6e52048ea vmxnet3: fix BUG_ON in vmxnet3_get_hdr_len() for Geneve packets ec2e157fc9678 sctp: auth: verify auth requirement when auth_chunk is NULL 4528678f70e07 net: dpaa: fix mode setting f72c312af6c78 net: hsr: fix memory leak on slave unregistration by removing synced VLANs 490011a38f437 net: bridge: vlan: fix vlan range dumps starting with pvid ec2f2f62e4386 amt: make the head writable before rewriting the L2 header 9005b221cb1f9 amt: re-read skb header pointers after every pull 137e4710da626 wifi: brcmfmac: fix 802.1X-SHA256 call trace warning 2b1882cf313ae wifi: mt76: mt7996: fix possible NULL-pointer deref in mt7996_mcu_sta_bfer_eht() 4fd85fd237350 wifi: mt76: mt7996: check pointer returned by mt76_connac_get_he_phy_cap() b09508dd7bc4a wifi: mt76: connac: fix possible NULL-pointer deref in mt76_connac_mcu_uni_bss_he_tlv() 23a2b98e754da wifi: mt76: mt7915: guard HE capability lookups f9c669d9f4cac tipc: fix infinite loop in __tipc_nl_compat_dumpit c0936c131a716 nexthop: initialize extack in nh_res_bucket_migrate() b3c733eaae7f3 gtp: check skb_pull_data() return in gtp1u_send_echo_resp() 54dfe30a562fd selftests: openvswitch: add config file 963b4ee31b1b0 selftests: af_unix: add USER_NS config eca8949e40612 selftest: af_unix: Add Kconfig file. def321ca6b32d tls: device: push pending open record on splice EOF b255d8cd6cc68 sctp: validate stream count in sctp_process_strreset_inreq() 649c6d37a38fb pds_core: check for workqueue allocation failure 646b58b543f3b pds_core: fix auxiliary device add/del races 37924f5c0e955 pds_core: order completion reads after the ownership check f79c7afdad473 pds_core: yield the CPU while waiting for the adminq to drain 5a365f1e42344 sctp: fix auth_chunk_list capacity check in sctp_auth_ep_add_chunkid a02c0ac672d95 amd-xgbe: fix MAC_AUTO_SW handling in CL37 AN 3794cfb80b550 pds_core: reject component parameter in legacy firmware update 70f70a4c419db wifi: mac80211: recalculate TIM when a station enters power save 3078d82e7fe90 iommu/intel: Fix out-of-bounds memset in dmar_latency_disable() 1e31d2394e0db iommu/amd: Bound the early ACPI HID map a3f47d7c75dda wifi: mwifiex: bound uAP association event IEs to the event buffer f4834132773f1 wan: wanxl: Only reset hardware after BAR mapping 6dbd428119cb1 nfp: Check resource mutex allocation 329589417214d wifi: mac80211: tear down new links on vif update error path ab7faf5a172eb iommu/amd: Wait for completion instead of returning early in iommu_completion_wait() 915012e923316 dpaa2-eth: put MAC endpoint device on disconnect 1f4ca61b7a93d dpaa2-switch: put MAC endpoint device on disconnect 1e2e2d9806944 rds: drop incoming messages that cross network namespace boundaries 2a4bad24ac529 bonding: fix devconf_all NULL dereference when IPv6 is disabled 80ec024d53a05 net/packet: avoid fanout hook re-registration after unregister 8de58bfa26e02 Bluetooth: btusb: validate Realtek vendor event length 112525534ab5c hwmon: occ: validate poll response sensor blocks 5b439f39f33ec smb: client: validate DFS referral PathConsumed 7e3abf8ace7f0 hwmon: (asus-ec-sensors) add missed handle for ENOMEM 12111669ba089 hwmon: (asus-ec-sensors) fix EC read intervals e73827d99021d hwmon: (asus-ec-sensors) fix looping over banks while reading from EC c035b1198906d usb: atm: ueagle-atm: reject descriptors that confuse probe and disconnect 0a070d5ad7986 wifi: iwlwifi: mvm: fix read in wake packet notification handler dafd46a720939 wifi: iwlwifi: mvm: validate SAR GEO response payload size 42a82b509a6d5 ASoC: cs35l56: Use complete_all() to signal init_completion 34c26cc9ab74c ASoC: cs35l56: Fix potential probe() deadlock cbd3a027f2488 ASoC: cs35l56: Don't use devres to unregister component 3958f6dab9f60 ASoC: bt-sco: fix duplicate DAPM widget names for wideband DAI 3ddb0d3e36507 ASoC: tas2781: bound firmware description string parsing 92bedc0455552 btrfs: free mapping node on duplicate reloc root insert 646c14273df83 btrfs: declare btrfs_ioctl_search_args_v2::buf as __u8 5acfa18de66b6 wifi: carl9170: fix buffer overflow in rx_stream failover path 7ed0dce8613c9 wifi: carl9170: fix OOB read from off-by-two in TX status handler f74e34e66379e wifi: carl9170: bound memcpy length in cmd callback to prevent OOB read 1c690f7c4c5b3 wifi: ath6kl: fix OOB read from firmware IE lengths in connect event 69ac7ba3a3df6 wifi: ath6kl: fix OOB read from firmware num_msg in TX complete handler b7d633c7c9232 firewire: net: Fix fragmented datagram reassembly d0833f2d44de6 wifi: ath12k: Flush the posted write after writing to PCIE_SOC_GLOBAL_RESET c78424ca50868 wifi: ath11k: Flush the posted write after writing to PCIE_SOC_GLOBAL_RESET 69a6a4f60b2da wifi: ath11k: fix potential buffer underflow in ath11k_hal_rx_msdu_list_get() 2e47b91b9b402 watchdog: pretimeout: Fix UAF in watchdog_unregister_governor() 185c0880397ae hwmon: (nzxt-smart2) Stop device IO before calling hid_hw_stop 0975c42ed2a3b hwmon: (corsair-cpro) Stop device IO before calling hid_hw_stop e6e1e0f3050d1 hwmon: (corsair-psu) Stop device IO before calling hid_hw_stop e517e207300ed wifi: ath11k: fix NULL pointer dereference in ath11k_hal_srng_access_begin 7f184ca38a908 wifi: ath9k: hif_usb: don't dereference hif_dev after re-arming firmware request 6192a3f77c97d usb: xhci-pci: Limit VIA VL805 DMA addressing to 36 bits f2ac9e32369b4 RISC-V: KVM: Serialize virtual interrupt pending state updates 9aa3b4223df5a Revert "drm/amd/display: Add missing kdoc for ALLM parameters" 7dc44840ca3cf crypto: rsa-pkcs1pad: Don't WARN on an empty digest d8d18d251049a USB: serial: option: add TDTECH MT5710-CN 1420c23c6d59d USB: serial: keyspan_pda: fix data loss on receive throttling ee57992c053a6 USB: serial: io_edgeport: cap received transmit credits f92bdb3df3b2e USB: serial: ftdi_sio: add support for E+H FXA291 4e116372b7a4f usb: gadget: uvc: clamp SEND_RESPONSE length to the response buffer 1a1d7158420df usb: gadget: udc: bdc: free IRQ and drain func_wake_notify before teardown e07751d0527cc usb: gadget: f_ncm: validate datagram bounds in ncm_unwrap_ntb() ec52db6cac5df USB: gadget: fsl-udc: fix device name leak on probe failure 29f3cd27ec350 USB: gadget: snps-udc: fix device name leak on probe failure 994afccfdcceb usb: gadget: printer: fix infinite loop in printer_read() 380b4bef46c2e usb: gadget: f_midi: cancel pending IN work before freeing the midi object e2b2740f1242b usb: gadget: dummy_hcd: prevent fifo_req reuse during giveback fc5cc9e194b96 usb: chipidea: fix usage_count leak when autosuspend_delay is negative 37691a2fe7646 USB: storage: add NO_ATA_1X quirk for Longmai USB Key e165a1d295e7e wifi: at76c50x-usb: avoid length underflow in at76_guess_freq() d6eee7cd078aa mpls: fix NULL deref in mpls_valid_fib_dump_req() on CONFIG_INET=n 0b4414e43e086 sctp: fix auth_hmacs array size in struct sctp_cookie 531dbb5bb98e5 net/sched: act_tunnel_key: Defer dst_release to RCU callback f6141a52180e6 drm/i915/selftests: Fix GT PM sort comparators 2c307126ed8e7 ksmbd: validate compound request size before reading StructureSize2 0f72fc9659d7f ksmbd: pin conn during async oplock break notification b8f591ee8b9f7 can: j1939: fix lockless local-destination check 7ffe529e71274 bpf, sockmap: Reject unhashed UDP sockets on sockmap update 315b7d610b93f powerpc/vtime: Initialize starttime at boot for native accounting 986cb66d37e57 powerpc/time: Prepare to stop elapsing in dynticks-idle b8c31ebdd22f1 sched/vtime: Get rid of generic vtime_task_switch() implementation 8506eaaa6481b drm/i915/gt: use correct selftest config symbol 437637f5ff3f5 smb/client: handle overlapping allocated ranges in fallocate 5a3945e8dea6c Bluetooth: hci_qca: Clear memdump state on invalid dump size b56f2ecafc08f Bluetooth: mgmt: hold reference for hci_conn in mgmt_pending_cmds 8bc83f9ef6789 Bluetooth: mgmt: fix locking in unpair_device/disconnect_sync 70354dbb5f72d Bluetooth: qca: fix NVM tag length underflow in TLV parser fd2049eec99e8 ALSA: usb-audio: Skip DSD quirk for Musical Fidelity M6s DAC 4c6e64cae2b2d ata: sata_dwc_460ex: fix infinite loop in NCQ tag completion bit-scanning 29f289ef8b5a0 ata: sata_dwc_460ex: fix clear_interrupt_bit() clearing all pending interrupts b99eafbc644b4 ata: sata_dwc_460ex: use platform_get_irq() fbe7df5d3a3ae ata: sata_dwc_460ex: enable SATA interrupts only after IRQ handler is registered 4dc0e63abf8bc net/iucv: take a reference on the socket found in afiucv_hs_rcv() 8150b5365f026 ipv4: fib: free fib_alias with kfree_rcu() on insert error path 4bb84e964ff0f ppp: defer channel free to an RCU grace period to fix pppol2tp RX UAF 91fdc18783459 firmware: arm_scmi: Rate-limit queue-full warnings in IRQ context 5143f863f864a ASoC: tas2562: fix deprecated 'shut-down' GPIO always cleared after lookup 0404b5b0f33b5 ASoC: cs42l43: Correct report for forced microphone jack 4cb0783d612ca ASoC: amd: ps: fix wrong ACP version string in pci_request_regions() 4b1add0fd9600 ASoC: meson: aiu: fifo-spdif: soft reset the S/PDIF datapath on start/stop 20c308d9a5772 wifi: cfg80211: bound element ID read when checking non-inheritance f50a2b9e57a75 wifi: brcmfmac: initialize SDIO data work before cleanup be9dfcb0654c1 wifi: mac80211: free AP_VLAN bc_buf SKBs outside IRQ lock a17f5d27cca22 wifi: cfg80211: reject unsupported PMSR FTM location requests 44ea65d779e2d wifi: cfg80211: validate PMSR FTM preamble range 642d8373c4c58 wifi: cfg80211: validate PMSR measurement type data 2d372cb06387b wifi: nl80211: validate nested MBSSID IE blobs fa9592ef7de11 wifi: nl80211: free RNR data on MBSSID mismatch 25c3b85af3fc4 wifi: p54: validate RX frame length in p54_rx_eeprom_readback() d497b7566e749 wifi: libertas: fix memory leak in helper_firmware_cb() 82c5a30a66e2a wifi: mac80211_hwsim: clamp virtio RX length before skb_put f75b9a2a9d833 wifi: ipw2100: fix potential memory leak in ipw2100_pci_init_one() 3368457b4871a wifi: cfg80211: cancel sched scan results work on unregister d9d9cc21cc900 xfrm: policy: preallocate inexact bins before xfrm_hash_rebuild reinsert df6856c2dda91 xfrm6: clear dst.dev on error to avoid double netdev_put in xfrm6_fill_dst() 2bc90b4535fd7 RDMA/irdma: Prevent overflows in memory contiguity checks 367958515c99f selftests/alsa: Fix memory leak in find_controls error path ffe21a3545b43 mtd: fix double free and WARN_ON in add_mtd_device() error paths 36e91a58397ca RDMA/siw: publish QP after initialization 8bf715284f08a RDMA/siw: Only check attrs->cap.max_send_wr in siw_create_qp 2fcf86887f9a5 RDMA/hns: Fix potential integer overflow in mhop hem cleanup 0e861c8a69671 RDMA/erdma: initialize ret for empty receive WR lists fb46d134e1b86 RDMA/irdma: Prevent rereg_mr for non-mem regions 0ccb86d5631ca RDMA/umem: Add helpers for umem dmabuf revoke lock 5f38a3ec57a7c RDMA/umem: Add pinned revocable dmabuf import interface 559b236086abc RDMA/umem: Move umem dmabuf revoke logic into helper function 76a3fb857bd2d RDMA/umem: Add ib_umem_dmabuf_get_pinned_and_lock helper dfb905d933d86 RDMA/umem: Introduce an option to revoke DMABUF umem 7cf6776ce4418 RDMA/umem: Add support for creating pinned DMABUF umem with a given dma device e33760e076105 RDMA/cma: Fix hardware address comparison length in netevent callback 86f5ea90f73bb firmware: arm_ffa: Fix NULL dereference in ffa_partition_info_get() b3d39b0379960 btrfs: fix root leak if its reloc root is unexpected in merge_reloc_roots() 33878ba25e263 btrfs: reject free space cache with more entries than pages 5e23b8ec04e26 mtd: nand: mtk-ecc: stop on ECC idle timeouts 9a797e0dc7667 mtd: mtdswap: remove debugfs stats file on teardown dfa535c94406c IB/mad: Drop unmatched RMPP responses before reassembly e9ea1f148a94a arm64: tegra: Fix CPU compatible string to cortex-a78ae on Tegra234 f97776607d0d3 Input: ims-pcu - fix logic error in packet reset 40bbbf2e91fd6 Input: ims-pcu - fix heap-buffer-overflow in ims_pcu_process_data() 6e3cb82fcd2f4 xprtrdma: Clear receive-side ownership pointers on release abeff53233b98 gpu: host1x: Fix use-after-free in host1x_bo_clear_cached_mappings 5592a207e158b accel/ivpu: Reject firmware log with size smaller than header 5b12de6229d66 dmaengine: sh: rz-dmac: Move interrupt request after everything is set up 0b05eca9589f6 can: isotp: serialize TX state transitions under so->rx_lock 0b811c4bbe3ec can: isotp: fix use-after-free race with concurrent NETDEV_UNREGISTER 18b45251e74e3 can: bcm: track a single source interface for ANYDEV timeout/throttle ops 5f246b96ab475 can: bcm: fix data race on rx_stamp/rx_ifindex in bcm_rx_handler() 60d8a7942f4ed can: bcm: fix stale rx/tx ops after device removal 84aa4807816e4 can: bcm: add missing device refcount for CAN filter removal 7d966cdee0069 can: bcm: validate frame length in bcm_rx_setup() for RTR replies 52f06e7603780 can: bcm: extend bcm_tx_lock usage for data and timer updates 8b2783172d92e can: bcm: fix CAN frame rx/tx statistics a7eb6db1cd3f7 can: bcm: add locking when updating filter and timer values 6f4be73880302 KVM: x86/mmu: Fix use-after-free on vendor module reload af56298e9d86e KVM: nVMX: Hide shadow VMCS right after VMCLEAR 35e77467610c4 KVM: x86: Check for invalid/obsolete root *after* making MMU pages available 1f140d2953901 seqlock: Allow UBSAN_ALIGNMENT to fail optimizing 69ae8730e657a seqlock: Allow KASAN to fail optimizing 4f292febac9bc seqlock: Cure some more scoped_seqlock() optimization fails c90b043ff068c platform/x86/amd/pmc: Avoid logging "(null)" for DMI values 55ec4d9ee783b platform/x86/amd/pmc: Don't log during intermediate wakeups 30e439a141d2c drm/virtio: fix deadlock in display_info_cb by removing hotplug from dequeue worker a715cf4de28eb selftests/bpf: Add tests for ld_{abs,ind} failure path in subprogs 37ad2bb11e9de bpf: Fix ld_{abs,ind} failure path analysis in subprogs b10a696411722 platform/x86/intel-uncore-freq: Fix current_freq_khz after CPU hotplug Signed-off-by: Bruce Ashfield Signed-off-by: Yoann Congal --- .../linux/linux-yocto-rt_6.6.bb | 6 ++-- .../linux/linux-yocto-tiny_6.6.bb | 6 ++-- meta/recipes-kernel/linux/linux-yocto_6.6.bb | 28 +++++++++---------- 3 files changed, 20 insertions(+), 20 deletions(-) diff --git a/meta/recipes-kernel/linux/linux-yocto-rt_6.6.bb b/meta/recipes-kernel/linux/linux-yocto-rt_6.6.bb index d252eb8c4a2..b8297fb8364 100644 --- a/meta/recipes-kernel/linux/linux-yocto-rt_6.6.bb +++ b/meta/recipes-kernel/linux/linux-yocto-rt_6.6.bb @@ -14,13 +14,13 @@ python () { raise bb.parse.SkipRecipe("Set PREFERRED_PROVIDER_virtual/kernel to linux-yocto-rt to enable it") } -SRCREV_machine ?= "27ed791688e060988fb39429477ee529093c9a01" -SRCREV_meta ?= "127bac58b21e8c3769d0cf2432f706f5605c4afb" +SRCREV_machine ?= "f673898aa832dc82d3f7b41e2b80576195be0c01" +SRCREV_meta ?= "9f45b4cc5cdbaac7468b31ef04b8d9d74a329a04" SRC_URI = "git://git.yoctoproject.org/linux-yocto.git;branch=${KBRANCH};name=machine;protocol=https \ git://git.yoctoproject.org/yocto-kernel-cache;type=kmeta;name=meta;branch=yocto-6.6;destsuffix=${KMETA};protocol=https" -LINUX_VERSION ?= "6.6.147" +LINUX_VERSION ?= "6.6.150" LIC_FILES_CHKSUM = "file://COPYING;md5=6bc538ed5bd9a7fc9398086aedcd7e46" diff --git a/meta/recipes-kernel/linux/linux-yocto-tiny_6.6.bb b/meta/recipes-kernel/linux/linux-yocto-tiny_6.6.bb index f50f5cd51e1..85adcac7676 100644 --- a/meta/recipes-kernel/linux/linux-yocto-tiny_6.6.bb +++ b/meta/recipes-kernel/linux/linux-yocto-tiny_6.6.bb @@ -8,7 +8,7 @@ require recipes-kernel/linux/linux-yocto.inc # CVE exclusions include recipes-kernel/linux/cve-exclusion_6.6.inc -LINUX_VERSION ?= "6.6.147" +LINUX_VERSION ?= "6.6.150" LIC_FILES_CHKSUM = "file://COPYING;md5=6bc538ed5bd9a7fc9398086aedcd7e46" DEPENDS += "${@bb.utils.contains('ARCH', 'x86', 'elfutils-native', '', d)}" @@ -17,8 +17,8 @@ DEPENDS += "openssl-native util-linux-native" KMETA = "kernel-meta" KCONF_BSP_AUDIT_LEVEL = "2" -SRCREV_machine ?= "18f147623b634b40b3bc5823ae03f049bb14fc84" -SRCREV_meta ?= "127bac58b21e8c3769d0cf2432f706f5605c4afb" +SRCREV_machine ?= "3595fedd1c011c6a9d7333fba206faccd23000d9" +SRCREV_meta ?= "9f45b4cc5cdbaac7468b31ef04b8d9d74a329a04" PV = "${LINUX_VERSION}+git" diff --git a/meta/recipes-kernel/linux/linux-yocto_6.6.bb b/meta/recipes-kernel/linux/linux-yocto_6.6.bb index 77274850c2b..56001ec3e75 100644 --- a/meta/recipes-kernel/linux/linux-yocto_6.6.bb +++ b/meta/recipes-kernel/linux/linux-yocto_6.6.bb @@ -18,25 +18,25 @@ KBRANCH:qemux86-64 ?= "v6.6/standard/base" KBRANCH:qemuloongarch64 ?= "v6.6/standard/base" KBRANCH:qemumips64 ?= "v6.6/standard/mti-malta64" -SRCREV_machine:qemuarm ?= "1790b505a65896a34abc5abe3109f9811f6f2960" -SRCREV_machine:qemuarm64 ?= "4da6f6f6201c34d32cf5ae6524f8de44d003f0ed" -SRCREV_machine:qemuloongarch64 ?= "402296b5e824b46fd4301eddc7c389b9f7fe1d82" -SRCREV_machine:qemumips ?= "254643819dbbde9f388d8d02b6d2550606b8e442" -SRCREV_machine:qemuppc ?= "c0e9acf672bff2c9001b96423b8ae5723d7f7190" -SRCREV_machine:qemuriscv64 ?= "402296b5e824b46fd4301eddc7c389b9f7fe1d82" -SRCREV_machine:qemuriscv32 ?= "402296b5e824b46fd4301eddc7c389b9f7fe1d82" -SRCREV_machine:qemux86 ?= "402296b5e824b46fd4301eddc7c389b9f7fe1d82" -SRCREV_machine:qemux86-64 ?= "402296b5e824b46fd4301eddc7c389b9f7fe1d82" -SRCREV_machine:qemumips64 ?= "830cb34f387303f99b95f1f3e3938794195ff1a6" -SRCREV_machine ?= "402296b5e824b46fd4301eddc7c389b9f7fe1d82" -SRCREV_meta ?= "127bac58b21e8c3769d0cf2432f706f5605c4afb" +SRCREV_machine:qemuarm ?= "eb3d4176015fb241f1d9ced0aedeb895b5c5b6a2" +SRCREV_machine:qemuarm64 ?= "7fb3f3439f9a37d1eb5c9b8852fcfd16e106d39c" +SRCREV_machine:qemuloongarch64 ?= "214397400c9747a170eabf91612d5ac3ccd25407" +SRCREV_machine:qemumips ?= "1b7be08de47be5e78d90ed8c3843a415293a72ed" +SRCREV_machine:qemuppc ?= "743a17db9981ac54b45c7e21aff83b9ec8d172ad" +SRCREV_machine:qemuriscv64 ?= "214397400c9747a170eabf91612d5ac3ccd25407" +SRCREV_machine:qemuriscv32 ?= "214397400c9747a170eabf91612d5ac3ccd25407" +SRCREV_machine:qemux86 ?= "214397400c9747a170eabf91612d5ac3ccd25407" +SRCREV_machine:qemux86-64 ?= "214397400c9747a170eabf91612d5ac3ccd25407" +SRCREV_machine:qemumips64 ?= "bd7dc237220c9d2525e8ec4783540b8762019d9d" +SRCREV_machine ?= "214397400c9747a170eabf91612d5ac3ccd25407" +SRCREV_meta ?= "9f45b4cc5cdbaac7468b31ef04b8d9d74a329a04" # set your preferred provider of linux-yocto to 'linux-yocto-upstream', and you'll # get the /base branch, which is pure upstream -stable, and the same # meta SRCREV as the linux-yocto-standard builds. Select your version using the # normal PREFERRED_VERSION settings. BBCLASSEXTEND = "devupstream:target" -SRCREV_machine:class-devupstream ?= "a1153c0deb44f75190f07677c0c6d61efd887246" +SRCREV_machine:class-devupstream ?= "6436c12a2ced865a3382b867e3882d08c2d2bf8d" PN:class-devupstream = "linux-yocto-upstream" KBRANCH:class-devupstream = "v6.6/base" @@ -44,7 +44,7 @@ SRC_URI = "git://git.yoctoproject.org/linux-yocto.git;name=machine;branch=${KBRA git://git.yoctoproject.org/yocto-kernel-cache;type=kmeta;name=meta;branch=yocto-6.6;destsuffix=${KMETA};protocol=https" LIC_FILES_CHKSUM = "file://COPYING;md5=6bc538ed5bd9a7fc9398086aedcd7e46" -LINUX_VERSION ?= "6.6.147" +LINUX_VERSION ?= "6.6.150" PV = "${LINUX_VERSION}+git" From patchwork Mon Sep 7 13:35:26 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 97556 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 3BDDAC79FAF for ; Mon, 7 Sep 2026 13:36:17 +0000 (UTC) Received: from mail-wm1-f46.google.com (mail-wm1-f46.google.com [209.85.128.46]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.34942.1788788169719965313 for ; Mon, 07 Sep 2026 06:36:10 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=hWgS4Ut4; spf=pass (domain: smile.fr, ip: 209.85.128.46, mailfrom: yoann.congal@smile.fr) Received: by mail-wm1-f46.google.com with SMTP id 5b1f17b1804b1-49b0d8bc2aaso45195495e9.0 for ; Mon, 07 Sep 2026 06:36:09 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1788788168; x=1789392968; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=z4xj6CUBLL89cd+2QpWxk8BubUeRO/3sfKWqy/SAiAY=; b=hWgS4Ut4gU0O7x0muUBMjT98MNxECFSE8RqKMkMDX2IPHhULEr66F5NoxQY/8bVZQ6 fiIMhS6Ooh7JJcMoyMfW56Bhv/xOkbFdQ/WmUnyaENuO615xivr2v7XQEDT5yDV35Im1 UDWLO7BJm7U0l4vakseEsu2CVN5zUK5ry8GL8= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1788788168; x=1789392968; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=z4xj6CUBLL89cd+2QpWxk8BubUeRO/3sfKWqy/SAiAY=; b=fwGO2aCQCZ5VGXx5PTXDlOobQTlvFkc63ArBrbSigvVxouUjQBKBeMuLSdOz/8qKII mOoOmysgFELVFTbZfRkjTEn6XWRh8EL2wxY3yNrWETnbNH3q0+38iG520FCZE55hgAC2 17/F9ywmlKRmlKK17JEzBAv0Xg+CsNKk2p9XGJu9W2qEiLiweFos7t84R0+dxr943mrK yBowcH/NPiYF/ytbkDyt6sEG1qFKMUO6zca/t5PJhbLr9OdjY+Y0f3uVUJhPevc3gF7f AoTXXx6AHFDJ0vxDxM83H0v+nmDBut1yL9ymXRDpr5ZeDNrgXwN0RtrkYcJsGZVpDwjO wKfw== X-Gm-Message-State: AFuF++lm5sAySWL7T7/vamIQSZ6clKni8BnIQJY1ceQYiSV6jTWBwHQv np7popifJplNg2BfCG7pWlVgqPTkiScHZkgPcwg4+ebKpc8103RN2vQxLzHdy9OAqBEB5vMi4vz 4DQzfpNs= X-Gm-Gg: AYBFou2v/Rh1RL7lDJ+hQ3b8TLb1p/vGg5bslFrFDPwiyrSEZun4EVNctrYaaBSbA5i +xsl4Ria+2DGMRglWmWA91HWRwUF6FLoq2Tjo1ciYgUA3il9sgO/qwpxF6U1RkZ0tJIvjp8v2h1 C/BR8h6ku9OF7TvmPK5HW1hF9t/kPZqwm/FI4mu/mn9KabgNb/hj25AntR0bUzXOhjuoVDgPktd QM8tu/D0jpm7AlwUernx3822waOl/qdv43YRp4+NdeHpMBQZLAvyWBZZSKIllCswMRv1BqXY3Vg J220SZKrrMVRbrXQUq1gqrZ9O62qy2VGKIpd2UAmGIaQBy2ZXE2V6VtDkErsEw4ksM7shsLlaUy wCdA0a3Q0RxT1NLSonHR9AIrAZODwxrBo/LqlTgDrh6VdbT4WWteRaIO0u5NqhMdnxHOxbSbggp XJGkT1NRd45qmEkJW37KEVbrlW9ITffo/EF84sRSzhu1LAbP+qvEonrYF55wW6UIDE7e8L80ibn R9jnVoXdoTdCOJ8Ghut3MAAdplQfxoDpp/pXhoPAzpoI59GOeaGfvHsiH2AqG9A X-Received: by 2002:a05:600c:c173:b0:49c:fc6c:be18 with SMTP id 5b1f17b1804b1-49cfc6cc0b8mr197972755e9.30.1788788167578; Mon, 07 Sep 2026 06:36:07 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-48588394fa1sm27523836f8f.8.2026.09.07.06.36.07 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 07 Sep 2026 06:36:07 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][scarthgap 30/35] linux-yocto/6.6: update to v6.6.151 Date: Mon, 7 Sep 2026 15:35:26 +0200 Message-ID: X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Mon, 07 Sep 2026 13:36:17 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/245287 From: Bruce Ashfield Updating linux-yocto/6.6 to the latest korg -stable release that comprises the following commits: d27334b2888c1 Linux 6.6.151 5b75a6e292b82 usb: typec: ucsi: Correct teardown ordering in ucsi_init() error path da302460e1516 drm/tegra: fbdev: Do not assign to struct drm_fb_helper.info dcaba7b281724 ALSA: hda: codecs: hdmi: disable keep-alive before audio format change 84351f1239034 drm/i915/hdcp: check streams[] bounds before overflow d7bec2276b606 drm/i915/hdcp: require monotonically increasing seq_num_v 214b63a6df022 drm/i915/hdcp: Move to using intel_display in intel_hdcp d1ba0459d8d0c drm/i915/hdcp: migrate away from kdev_to_i915() in bind/unbind b02ed4c9099a6 drm/i915/fbc: Extract intel_fbc_has_fences() c6eb2d615210b sctp: close UDP tunnel sockets during netns teardown d2c3760b45f2f mptcp: pm: userspace: fix use-after-free in get_local_id 6b6dcc679df19 mptcp: pm: use addr entry for get_local_id 19b0ae625755d mptcp: add mptcp_userspace_pm_lookup_addr helper 805b79892a92f mptcp: pm: avoid code duplication to lookup endp cb9c9ec479e0b ceph: fix refcount leak in ceph_readdir() 2cda8a74c91de ceph: print cluster fsid and client global_id in all debug logs c30406c39a665 libceph: add doutc and *_client debug macros support bf5c4a8b24acb can: isotp: fix timer drain order, wakeup handling and tx_gen ordering 1107f5959c035 can: use skb hash instead of private variable in headroom 66700c0719675 sctp: avoid auth_enable sysctl UAF during netns teardown ac649bd51e7fc sysctl: treewide: constify ctl_table_header::ctl_table_arg c268331845ee0 wifi: brcmfmac: drain bus_reset work on device removal 1335161f85026 wifi: brcmfmac: set F2 blocksize to 256 for BCM43752 b516ac892bcb3 wifi: brcmfmac: fix 43752 SDIO FWVID incorrectly labelled as Cypress (CYW) 64af6534a085f wifi: ath6kl: fix use-after-free in aggr_reset_state() 47ef04cd13d38 media: v4l2-fwnode: Fix subdev owner overwritten in v4l2_async_register_subdev_sensor() fa00d8070d85d media: v4l: async: Set owner for async sub-devices e38f054f0af98 netfilter: nf_tables: clone set on flush only d94b82d452ca2 rxrpc: Fix irq-disabled in local_bh_enable() f9fa11cdd5bf2 media: imx219: Fix maximum frame length in lines af4fd77d3430f media: i2c: imx219: Rename VTS to FRM_LENGTH b0f5471b0a69a media: i2c: imx219: Calculate crop rectangle dynamically cdeb114ed964c media: i2c: imx219: Group functions by purpose f2f85e5ff17e3 media: i2c: imx219: Drop IMX219_VTS_* macros bc24c30f403a2 media: i2c: imx219: Don't store the current mode in the imx219 structure 912762e93e6d2 media: i2c: imx219: Access height from active format in imx219_set_ctrl 6598ac1721c3a drm/i915/vrr: require valid min/max vfreq for VRR c8420f048c152 drm/i915/vrr: Check HAS_VRR() first in intel_vrr_is_capable() aa31b60d6c4ec drm/amdgpu: Respect placement requirements in amdgpu_gtt_mgr functions 926a4e2301060 drm/tegra: fbdev: Remove offset into framebuffer memory d6c50b6605db0 drm/fb-helper: Allocate and release fb_info in single place 07f8aaffee705 usb: typec: ucsi: Fix race condition and ordering in port unregistration c888e052a09ef usb: typec: ucsi: split connector lock classes 3a9e3344d1e51 usb: typec: ucsi: Only enable supported notifications 3118bb872c7df usb: gadget: f_tcm: synchronize delayed set_alt with teardown f5307073303ad drm: renesas: rzg2l_mipi_dsi: Increase reset deassertion delay 4c37112f1af90 drm: renesas: Move RZ/G2L MIPI DSI driver to rz-du eed56f105a7f7 usb: musb: omap2430: Do not put borrowed of_node in probe e56ccb286bc48 usb: musb: omap2430: clean up probe error handling bbd2a25bbb415 Revert "ia64: Make acpi_cpufreq_cpu_exit return void" 16da33cb36e66 gpio: pch: use raw_spinlock_t for the register lock 95f702e372964 firmware: stratix10-svc: fix memory leaks and list corruption bugs be106f7855f03 mm/huge_memory: unlock i_mmap_rwsem before releasing after-split folios 69cb5825d9988 mm/hugetlb: fix swap entry corruption when clearing uffd-wp at fork() 6277e85777710 iommu/sva: move x86 disable check before allocation 9de51b5dbcdfd ata: ahci: Make ahci_ignore_port() handle empty mask_port_map 0158829969820 ata: libahci_platform: Do not set mask_port_map when not needed 95b3f23d63249 HID: logitech-dj: Fix maxfield check in DJ short report validation b517ca5c6346f spi: spi-cadence: enable SPI_CONTROLLER_MUST_TX 4e0f669e2951b drm/vmwgfx: validate external BO copy bounds for both stride paths 1bbe7751f5eba drm/vmwgfx: use check_add_overflow for shader size+offset bound 036e16ada9538 drm/vmwgfx: bound DMA command body size against suffix pointer 2666cddf0dd21 drm/vmwgfx: validate DRAW_PRIMITIVES header size before division c1c22fca0a089 drm/vmwgfx: drop dma_buf reference on foreign-fd prime import 7eae011829f94 drm/vmwgfx: reject DX_BIND_QUERY without a DX context 21bbe38faee4a drm/vmwgfx: fix guest_memory_dirty bitfield clobbered as size 2040b7e39027c drm/amdkfd: hold event_mutex while checkpointing CRIU events dec688cfa18c3 drm/amdkfd: Handle invalid event type in CRIU event restore 8924e2594a15b drm/amdkfd: fix QID bit leak in pqm_create_queue() ce813614f63b0 drm/amdkfd: Fix missing authorization check in KFD_IOC_DBG_TRAP_DISABLE 668441cff9e05 drm/amdgpu: cap GTT size to physical RAM on APUs ef3fa445edc03 drm/amdgpu: restore UMD profile pstate after runtime resume 8112f0a9396e3 drm/mediatek: ovl_adaptor: balance component registrations f5802be65535f drm/vc4: Zero the tile state data array before each BIN job 2f2291a119e9a drm/vc4: Supply the overflow slot size in BPOS, not the whole bin BO size 13bd7cf63610a drm/dp: Read the PCON max FRL bandwidth only for HDMI DFPs 3c9d12561601f can: ctucanfd: mark error-active controller status valid 4c453560d3c29 can: ctucanfd: handle bus error interrupts 4a666e648c6bd can: ctucanfd: unmap BAR0 using base address bfc20e429de9b can: ctucanfd: use self-test mode for PRESUME_ACK 5bdd69e8301b1 can: ctucanfd: add missing MODULE_DEVICE_TABLE() 6067c878e38d0 can: peak_usb: validate uCAN receive record lengths 525640b93d3e5 can: peak_usb: peak_usb_start(): fix double free of transfer buffer on URB submit error 825c903ca3c98 can: peak_usb: add bounds check for USB channel index ae588e5b9cc26 can: softing: fw_parse(): validate firmware record spans 695aea154bb2d can: kvaser_usb_leaf: kvaser_usb_leaf_wait_cmd(): validate received command extents b954b108891e5 can: kvaser_usb: kvaser_usb_hydra_get_busparams(): fix memory leak in kvaser_usb_hydra_get_busparams() 30b0b76918834 can: j1939: use netdevice_tracker for j1939_{priv,session,ecu} tracking 194d67e92197e can: j1939: transport: j1939_session_fresh_new(): initialize receive buffer 5e2fd705c92e9 can: gs_usb: gs_usb_receive_bulk_callback(): resubmit URB on skb allocation failure 0ef136ba05210 can: etas_es58x: es58x_read_bulk_callback(): fix RX buffer leak on URB resubmit failure ce8125566b1d0 can: ems_usb: validate CPC message lengths 29bc050802ded can: c_can: c_can_chip_config(): keep controller in init mode until bittiming is configured a8a1f9ac3d763 i2c: imx: Cancel hrtimer before clearing slave pointer b9f6f4883b9ac i2c: imx: Fix slave registration race and error handling 14429dc1c756c i2c: jz4780: Cache host clock rate at probe to prevent CCF prepare_lock deadlock 2b760e8f0ead0 ice: fix memory leak in ice_lbtest_prepare_rings() 5dd5485189c07 ice: wait for reset completion in ice_resume() 736e972f3f8a3 net: openvswitch: fix skb leak on flow key update failure during ct 27b3eb4fc407e net: openvswitch: fix skb leak on flow key update failure during recirculation 0310d1fa7f9de net: openvswitch: fix potential UAF on meter attach failure 1f1a8ca58641b phy: zynqmp: keep SERDES scrambler and 8b/10b enabled for USB bf3985016cc09 phy: zynqmp: use read-modify-write for SERDES scrambler bypass 9a83affa2fa14 phy: zynqmp: fix L0_TM_DISABLE_SCRAMBLE_ENCODER mask dd25bd9b0f368 s390/zcrypt: Validate length for CCA ECC private key requests 406b317ea2b50 s390/zcrypt: Validate length for CCA AES cipher key requests b505dcc8307d6 s390/zcrypt: Fix wrong domain value verification with EP11 CPRBs aca18289c86f2 s390/dasd: Fix undersized format-check buffer e156c70c505c6 s390/dasd: Fix potential NULL pointer dereference 4e48168825818 s390/qeth: Check CAP_NET_ADMIN for private ioctls a92df2b3d7a33 power: supply: bq25890: fix the -10 C NTC lookup entry a57082657fa5b cpufreq: powernow-k8: Fix possible memory leak in powernowk8_cpu_init() 83467180e0579 gpio: pca953x: fix cache_only and IRQ state on restore_context() failure b7c2c5c886873 i2c: amd-mp2: Unregister callback on adapter add failure d20f04fb30bdf hwmon: (pmbus/core) notify on the hwmon device, not the i2c client c985e96fa3e3a hwmon: (npcm750-pwm-fan): stop fan timer on device detach 546221b86ceeb sctp: prevent peer transport count overflow 61baa5020b0af sctp: reject stale cookies with mismatched verification tags 49e5b25a0b74d scsi: scsi_debug: Fix REPORT ZONES alloc_len underflow OOB write 03bfd969f2f72 selftests/clone3: fix wild pointer access of getline due to missing init 7ecb40609362c selftests/mm: fix potential wild pointer access of getline due to missing init fc673c4eb23dd spi: qcom-qspi: Correct max DMA length to avoid 64K boundary failure 47cef9b4445d2 tracing/filters: Fix false positive match in regex_match_full() d61ee2a27dfd5 tracing: Check return value of __register_event() in trace_module_add_events() ee41b00858ca6 ublk: reset kernel-owned dev_info fields in ublk_ctrl_add_dev() 42887be7c4cf2 vxlan: use pskb_network_may_pull() in route_shortcircuit() d08e8ac13f2e2 vxlan: use neigh_ha_snapshot() in route_shortcircuit() cbb154b2d71ef vxlan: unclone skb head before modifying eth header in route_shortcircuit() 2355c8c26d2aa vxlan: re-fetch eth header after route_shortcircuit() 4b9601595e8b6 um: vector: fix use-after-free in vector_mmsg_rx() f020d756b3139 powerpc/ps3: Fix map failure path in dma_ioc0_map_pages() 6d98c70fe0ba8 net: ipv6: clear suppressed fib6 rule result 159ad90cb929c net: bridge: stop fast-leave after deleting a port group f978048326570 mm/page_reporting: use system_freezable_wq to fix UAF during suspend 1819f82dee766 binfmt_misc: reject a flag character as the field delimiter 25e5a3fe4f15e wifi: mwifiex: use the subframe length when parsing A-MSDU TDLS frames d7940bb6a8e7a tipc: avoid use-after-free in poll trace queue dumps 661ff9c0cfbe0 netfilter: ipset: do not update comments from kernel-side hash adds 5a42f162b8570 net/smc: fix socket use-after-free during link group termination 44af98cc7d5ef ipvs: do not propagate one-packet flag to synced conns 31089f4eab42e igbvf: Fix leak in TX DMA error cleanup 5c477b7a205fb e1000: fix memory leak in e1000_probe() dc390138a0a31 dmaengine: qcom: bam_dma: Fix command element mask field for BAM v1.6.0+ 56ac3e7c90f6b ALSA: usb-audio: Clamp frame size in implicit-feedback mode 3852974608f53 ALSA: usb-audio: Fix DMA buffer out-of-bounds write when fill_max is set 29a4c29943631 ALSA: usb-audio: fix OOB write in snd_usbmidi_akai_output() 49eccef6d6e1c ALSA: usb-audio: fix use-after-free in ump_to_endpoint() 3d3339f71807b ata: libata-eh: Increase STANDBY IMMEDIATE timeout 2f840c7980bcf ASoC: tas2562: fix broken entries in the volume lookup table f56d1aac72394 ASoC: tas2562: fix DVC coefficient write order e84d2e53a05c7 ALSA: ump: fix double free of out_cvts on rawmidi error e8b784a3f4fba ALSA: pcm: wake linked drain waiters on unlink 20aad5c443848 ALSA: lx6464es: fix period byte count for 16-bit streams 49bc7741cd276 ALSA: 6fire: Fix UAF at error handling during probe 487e437b8f092 bpf: lwt: Fix dst reference leak on reroute failure b7ad105d46acd Bluetooth: HIDP: validate numbered report payloads 46ca5ab39737d Bluetooth: HIDP: reject frames without a transaction header 86ed4dd6548cc Bluetooth: mgmt: fix UAF in pair command cancellation a9e7c2609b0cb Bluetooth: mgmt: fix pending command UAF in EIR updates c348057dc7066 Bluetooth: btmtk: Fix short read errors in btmtk_usb_uhw_reg_read() 45bf3df5b32e5 audit: fix potential use-after-free in audit_del_rule() 17099fad5ef92 audit: fix potential integer overflow in audit_log_n_string() 93942b5772e0e sctp: validate Adaptation Indication parameter length f00ef8efd4144 KVM: s390: pci: Validate AIBV and AISB before pinning guest pages 0a95abe964400 KVM: s390: pci: Fix NULL dereference on AIBV allocation failure 78d9648e7e960 KVM: s390: pci: Reject adapter interrupt forwarding if already enabled 6664a5aea4531 KVM: SVM: Update x2APIC MSR intercepts if AVIC is inhibited while L2 is active 451ee0f9ca1e1 tracing/probes: Reject $arg0 in meta argument expansion 421e447b53c70 mm/vmstat: fold stranded per-cpu node stats when a node comes online 62e1c2741a4d9 mm/hugetlb: fix list corruption in allocate_file_region_entries() 01504da375f5b mm/percpu-km: fix bitmap overflow and accounting in pcpu_create_chunk() a583806ae9697 pinctrl: bm1880: add missing select GENERIC_PINCONF e8b3d09aa8889 erofs: cap LZMA stream pool size 929f6396baade pinctrl: devicetree: don't free uninitialized dev_name on error path 9d5de82acf289 pinctrl: microchip-sgpio: add missing select REGMAP_MMIO c39643ad99fea rhashtable: clear stale iter->p on table restart 27210d433a8c5 ipv6: fib6: fix NULL deref in fib6_walk_continue() on multi-batch dump 67aaec2a1fdce ksmbd: fix use-after-free in __close_file_table_ids() fb27b7b7b7bb4 ksmbd: return success for deferred final close e382a4efeeae6 qede: sync udp_tunnel ports outside qede_lock in the recovery path 228757a2988c6 octeontx2-pf: Set correct sequence for carrier off and tx queue stop 272eafaf16258 net: dsa: mt7530: error out on failed reads in MT7531 PHY polling aecd00c33b509 accel/qaic: use sizeof(*trans_hdr) for transaction length check 481737704eee0 tracing/mmiotrace: Reset dropped_count in mmio_reset_data() 2ba4c5cc30313 can: isotp: check register_netdevice_notifier() error in module init 128fe7596adcd net: sxgbe: check descriptor ring allocation failures 3563e2486dcd5 net: sxgbe: free TX rings on RX allocation failure 8f7812821ed7a scsi: target: Clear cmd_cnt when initial counter enrollment fails 1b42d05f1c590 scsi: zfcp: Fix memory leak during adapter release by destroying gid_pn_req 107d3d6c17910 scsi: ufs: core: Cancel RTC work in active-active suspend 3c60a8b4037dc scsi: target: iblock: Fix wrong PR ops NULL check for PREEMPT/RELEASE ba99aed7bad80 net: phylink: put link_gpio if phylink_create fails 716d47531e740 Bluetooth: hci_sync: fix hci_conn_del() use in hci_le_create_conn_sync 64d1645f26aa4 Bluetooth: hci_conn: hold conn reference in abort_conn_sync() 759303b0012cc Bluetooth: hci_sync: make hci_cmd_sync_run_once return -EEXIST if exists c31be902ccbbb Bluetooth: btintel: Validate length before parsing diagnostics TLV 38a9a30614cc7 Bluetooth: ISO: fix timeout vs sync_timeout typo in check_bcast_qos fd4c1e301bdec Bluetooth: L2CAP: fix UAF in l2cap_le_connect_rsp cc1d39946d62b Bluetooth: ISO: clear iso_data always when detaching conn from hcon 68c5b240dba96 hwmon: (pmbus) Fix return value from pmbus_update_byte_data() ff558072d199c wifi: mac80211: validate individual TWT params before driver setup 961d80c6389d9 powerpc/boot: Fix treeboot-akebono CPU node lookup check 1792fcda01785 powerpc/boot: Fix treeboot-currituck CPU node lookup check 3382cf66522df powerpc/boot: Fix simpleboot CPU node lookup check ab8549d5b8f02 hwmon: (adt7470) Fix PWM auto temp state array and bounds check d328175045176 hwmon: (adt7470) Fix divide-by-zero TOCTOU crash in fan speed read c11d1bc785f2a hwmon: (adt7470) Use cached PWM frequency value 97fac8440c9ae hwmon: (adt7470) Fix swapped PWM3 and PWM4 auto mode masks 40a3117650f9d hwmon: (adt7470) Fix temperature alarm logic in hwmon_temp_read() 1a42bd72a6620 hwmon: (adt7470) Fix busy-loop and I2C flooding in update thread 0c89e5ae2655f hwmon: (adt7470) Fix cache updated before hardware write on I2C error f114a8aa7905a hwmon: (adt7470) Fix fans stuck in manual mode on I2C errors cf2dcde228456 forcedeth: fix UAF of txrx_stats in nv_remove b60702104b45d net: bridge: mrp: fix Option TLV length in MRP_Test frames 25b528816f5d8 hwmon: (nct6775-core) Prevent access to unsupported weight registers f5ecaa7ea7686 net: do not send ICMP/NDISC Redirects when peer allocation fails 70ad543ce81f3 hwmon: (nzxt-smart2) DMA-align output buffer 4eed33c7db5c0 hwmon: (lm90) Only report alarms if driver is ready 9a87dfaa05c3c hwmon: (nct6775-core) Fix number of temperature registers for NCT6116 a7b05d5eefc37 spi: spi-cadence: Move TX FIFO full busy-wait into FIFO 6b0fbc3fb7b71 spi: spi-cadence: supports transmission with bits_per_word of 16 and 32 593636dcdf20e smb: client: fix buffer leaks in SMB1 read and write e50a6523a6035 scsi: libsas: Fix HA resume deadlock and hisi_sas disk-wake race c97b5265cc477 scsi: libiscsi_tcp: Bound SCSI Response data segment to the connection buffer 7567f06abdefb scsi: libiscsi: Fix stale-data leak into the SCSI sense buffer 870b4535f958a pinctrl-amd: Don't clear S4 wake bits at probe 76dd48886eeeb rds: tcp: hold the RCU lock across ipv6_chk_addr() in rds_tcp_laddr_check() 8e48d7ab1e019 rds: Fix inet6_addr_lst NULL dereference when IPv6 is disabled b19b5d2e042c2 netfilter: nft_payload: fix mask build for partial field offload 35c53f9b7839a ipvs: do not mangle ICMP replies for non-first fragments cdc55d6ca3a8f ipvs: fix places with wrong packet offsets b3869d9b54e76 ipvs: fix the checksum validations d1c4acc119ea0 sched: Add task_struct->faults_disabled_mapping 24683fea1f06b netfilter: xt_hashlimit: validate hashtable supports XT_HASHLIMIT_RATE_MATCH 55fb23f8bd744 assoc_array: trim the final shortcut word using the current chunk end bd0f976ef89dc keys: make keyring key-chunk byte order agree with keyring_diff_objects() d1933e03e8c74 keys: fix out-of-bounds read in keyring_get_key_chunk() c28d2ae71b706 drm/mediatek: Check CRTC state before freeing 63eea41759fd6 netfilter: nf_conntrack_sip: widen NAT rewrite delta to s32 in sip_help_tcp() 8bba4129dc5c0 phy: zynqmp: fix runtime PM leak on probe allocation failure 599516163bb33 phy: zynqmp: fix clock error handling in xpsgtr_phy_init() badff0ff5b20a phy-zynqmp: Postpone getting clock rate until actually needed 18577e77c2c8a btrfs: zoned: fix deadlock between metadata writeback and transaction commit c031ef8093f41 ASoC: max98090: fix missing IS_ERR() before PTR_ERR() on mclk lookup b6f1706afb59f ASoC: max98095: fix missing IS_ERR() before PTR_ERR() on mclk lookup c1fadd611cc58 ata: ahci_ceva: fix error paths in ceva_ahci_platform_enable_resources() 55f3fc9c544c7 ahci: Introduce ahci_ignore_port() helper e43eb5d7cedf3 ata: libahci_platform: support non-consecutive port numbers ee53aae5d7d31 ata: sata_mv: accept 1 or 2 resources in platform probe 778ccbded2c87 dmaengine: idxd: fix fdev setup failure cleanup in idxd_cdev_open() 27806fe7b9701 dmaengine: sun6i-dma: Fix reclaim descriptors while terminating DMA 9ae18a4b22ac3 pinctrl: qcom: sc8280xp: Add missing wakeup entries for GPIO143/151 91b40862a0200 thunderbolt: Prevent XDomain delayed work use-after-free on disconnect 35283a7b3468c soc: qcom: ice: Allow explicit votes on 'iface' clock for ICE 1c8c6ac4d9f7d HID: logitech-dj: fix wrong detection of bad DJ_SHORT output report 968e84f5c0dca HID: logitech-dj: Prevent REPORT_ID_DJ_SHORT related user initiated OOB write b802ff2a0467d HID: logitech-dj: Standardise hid_report_enum variable nomenclature 299d5728a7312 gve: fix Rx queue stall on alloc failure 95651461cf77c net: mpls: initialize rtm_tos in mpls_getroute() 06a1273ce7213 netfilter: br_netfilter: Reallocate headroom if necessary in neigh_hh_bridge() da1f7306c8f28 netfilter: nf_conntrack_expect: restore helper propagation via expectation Signed-off-by: Bruce Ashfield Signed-off-by: Yoann Congal --- .../linux/linux-yocto-rt_6.6.bb | 6 ++-- .../linux/linux-yocto-tiny_6.6.bb | 6 ++-- meta/recipes-kernel/linux/linux-yocto_6.6.bb | 28 +++++++++---------- 3 files changed, 20 insertions(+), 20 deletions(-) diff --git a/meta/recipes-kernel/linux/linux-yocto-rt_6.6.bb b/meta/recipes-kernel/linux/linux-yocto-rt_6.6.bb index b8297fb8364..39fa0a56c2e 100644 --- a/meta/recipes-kernel/linux/linux-yocto-rt_6.6.bb +++ b/meta/recipes-kernel/linux/linux-yocto-rt_6.6.bb @@ -14,13 +14,13 @@ python () { raise bb.parse.SkipRecipe("Set PREFERRED_PROVIDER_virtual/kernel to linux-yocto-rt to enable it") } -SRCREV_machine ?= "f673898aa832dc82d3f7b41e2b80576195be0c01" -SRCREV_meta ?= "9f45b4cc5cdbaac7468b31ef04b8d9d74a329a04" +SRCREV_machine ?= "c0f2d7109571c01223cbd3738db96b5ea20ddc68" +SRCREV_meta ?= "b768be4d32d53a825349353e988ca5930e83f99c" SRC_URI = "git://git.yoctoproject.org/linux-yocto.git;branch=${KBRANCH};name=machine;protocol=https \ git://git.yoctoproject.org/yocto-kernel-cache;type=kmeta;name=meta;branch=yocto-6.6;destsuffix=${KMETA};protocol=https" -LINUX_VERSION ?= "6.6.150" +LINUX_VERSION ?= "6.6.151" LIC_FILES_CHKSUM = "file://COPYING;md5=6bc538ed5bd9a7fc9398086aedcd7e46" diff --git a/meta/recipes-kernel/linux/linux-yocto-tiny_6.6.bb b/meta/recipes-kernel/linux/linux-yocto-tiny_6.6.bb index 85adcac7676..7675e325422 100644 --- a/meta/recipes-kernel/linux/linux-yocto-tiny_6.6.bb +++ b/meta/recipes-kernel/linux/linux-yocto-tiny_6.6.bb @@ -8,7 +8,7 @@ require recipes-kernel/linux/linux-yocto.inc # CVE exclusions include recipes-kernel/linux/cve-exclusion_6.6.inc -LINUX_VERSION ?= "6.6.150" +LINUX_VERSION ?= "6.6.151" LIC_FILES_CHKSUM = "file://COPYING;md5=6bc538ed5bd9a7fc9398086aedcd7e46" DEPENDS += "${@bb.utils.contains('ARCH', 'x86', 'elfutils-native', '', d)}" @@ -17,8 +17,8 @@ DEPENDS += "openssl-native util-linux-native" KMETA = "kernel-meta" KCONF_BSP_AUDIT_LEVEL = "2" -SRCREV_machine ?= "3595fedd1c011c6a9d7333fba206faccd23000d9" -SRCREV_meta ?= "9f45b4cc5cdbaac7468b31ef04b8d9d74a329a04" +SRCREV_machine ?= "20c2ecb592178ed51039ae1a75a523c66c1eee5d" +SRCREV_meta ?= "b768be4d32d53a825349353e988ca5930e83f99c" PV = "${LINUX_VERSION}+git" diff --git a/meta/recipes-kernel/linux/linux-yocto_6.6.bb b/meta/recipes-kernel/linux/linux-yocto_6.6.bb index 56001ec3e75..7a273f9cc6f 100644 --- a/meta/recipes-kernel/linux/linux-yocto_6.6.bb +++ b/meta/recipes-kernel/linux/linux-yocto_6.6.bb @@ -18,25 +18,25 @@ KBRANCH:qemux86-64 ?= "v6.6/standard/base" KBRANCH:qemuloongarch64 ?= "v6.6/standard/base" KBRANCH:qemumips64 ?= "v6.6/standard/mti-malta64" -SRCREV_machine:qemuarm ?= "eb3d4176015fb241f1d9ced0aedeb895b5c5b6a2" -SRCREV_machine:qemuarm64 ?= "7fb3f3439f9a37d1eb5c9b8852fcfd16e106d39c" -SRCREV_machine:qemuloongarch64 ?= "214397400c9747a170eabf91612d5ac3ccd25407" -SRCREV_machine:qemumips ?= "1b7be08de47be5e78d90ed8c3843a415293a72ed" -SRCREV_machine:qemuppc ?= "743a17db9981ac54b45c7e21aff83b9ec8d172ad" -SRCREV_machine:qemuriscv64 ?= "214397400c9747a170eabf91612d5ac3ccd25407" -SRCREV_machine:qemuriscv32 ?= "214397400c9747a170eabf91612d5ac3ccd25407" -SRCREV_machine:qemux86 ?= "214397400c9747a170eabf91612d5ac3ccd25407" -SRCREV_machine:qemux86-64 ?= "214397400c9747a170eabf91612d5ac3ccd25407" -SRCREV_machine:qemumips64 ?= "bd7dc237220c9d2525e8ec4783540b8762019d9d" -SRCREV_machine ?= "214397400c9747a170eabf91612d5ac3ccd25407" -SRCREV_meta ?= "9f45b4cc5cdbaac7468b31ef04b8d9d74a329a04" +SRCREV_machine:qemuarm ?= "06b8a8a900edeb9770128b2e25e7814ff0638c72" +SRCREV_machine:qemuarm64 ?= "bcdc0007d72899e94de35713c4c18e0ad581f41b" +SRCREV_machine:qemuloongarch64 ?= "491a3d5683a61ca2a7911f748661cfad50b8d05c" +SRCREV_machine:qemumips ?= "9023f83c1acc4010d43c5891c641a671a12d264e" +SRCREV_machine:qemuppc ?= "a76593fcb6c3b2183877d531562237a9def7acc5" +SRCREV_machine:qemuriscv64 ?= "491a3d5683a61ca2a7911f748661cfad50b8d05c" +SRCREV_machine:qemuriscv32 ?= "491a3d5683a61ca2a7911f748661cfad50b8d05c" +SRCREV_machine:qemux86 ?= "491a3d5683a61ca2a7911f748661cfad50b8d05c" +SRCREV_machine:qemux86-64 ?= "491a3d5683a61ca2a7911f748661cfad50b8d05c" +SRCREV_machine:qemumips64 ?= "50376ca9492c97cc4d6d291d06e52db021aeb1f1" +SRCREV_machine ?= "491a3d5683a61ca2a7911f748661cfad50b8d05c" +SRCREV_meta ?= "b768be4d32d53a825349353e988ca5930e83f99c" # set your preferred provider of linux-yocto to 'linux-yocto-upstream', and you'll # get the /base branch, which is pure upstream -stable, and the same # meta SRCREV as the linux-yocto-standard builds. Select your version using the # normal PREFERRED_VERSION settings. BBCLASSEXTEND = "devupstream:target" -SRCREV_machine:class-devupstream ?= "6436c12a2ced865a3382b867e3882d08c2d2bf8d" +SRCREV_machine:class-devupstream ?= "d27334b2888c10d2b60c954c59b186182d833107" PN:class-devupstream = "linux-yocto-upstream" KBRANCH:class-devupstream = "v6.6/base" @@ -44,7 +44,7 @@ SRC_URI = "git://git.yoctoproject.org/linux-yocto.git;name=machine;branch=${KBRA git://git.yoctoproject.org/yocto-kernel-cache;type=kmeta;name=meta;branch=yocto-6.6;destsuffix=${KMETA};protocol=https" LIC_FILES_CHKSUM = "file://COPYING;md5=6bc538ed5bd9a7fc9398086aedcd7e46" -LINUX_VERSION ?= "6.6.150" +LINUX_VERSION ?= "6.6.151" PV = "${LINUX_VERSION}+git" From patchwork Mon Sep 7 13:35:27 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 97551 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 93811C79FAA for ; Mon, 7 Sep 2026 13:36:16 +0000 (UTC) Received: from mail-wr1-f51.google.com (mail-wr1-f51.google.com [209.85.221.51]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.35230.1788788169918749717 for ; Mon, 07 Sep 2026 06:36:10 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=SQY9z3Gt; spf=pass (domain: smile.fr, ip: 209.85.221.51, mailfrom: yoann.congal@smile.fr) Received: by mail-wr1-f51.google.com with SMTP id ffacd0b85a97d-484362f5c4aso4504773f8f.3 for ; Mon, 07 Sep 2026 06:36:09 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1788788168; x=1789392968; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=fhxCQ0JhLa+ziiL5np+9BJZT9LEeedqIjYH+gyte3NM=; b=SQY9z3GtJChJIKIUNRnLs0B932r5j9qZnnXQaTOIVUzxFdTfISCMpD5lVrsZCUxr/M /oAyqXgRXEr+Ci36JvtwC23I9cVOuaXAsCkNx6zs7gZdjBGwlU5GLUcbLc2B+6VcDzc6 VyV26EXQuqNv5RytmmLsbr/iRjW4eEtgddIFU= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1788788168; x=1789392968; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=fhxCQ0JhLa+ziiL5np+9BJZT9LEeedqIjYH+gyte3NM=; b=UWlz3h4Pgf0al95i71JI7ZQSa+pJqVz/S1N3TrUJGtAwGQNoS00KBVrFdxZ5Vg24Bl jvNO06DsLL+DzmT0NrTma5xhnFHwzoW1fxEire7V8hRnWAdofAd4hgxK5pcXtBbUWsFD oNZhG1DRoeyTKeqCzXTWXX0QezM5Jozm3+3nzSTb605D8GgCrwJcaChbkAfEwaqva8Wr YQNOzts4ziFbTKWE57lnHBcDXdDLP7CoDMLALdyNNavhFJ3IXx7xXAnuKJE0Xt9No57v M+zmZJ543bGC7RQ34OD8XmiN7iYgS3oOSxrWcSH8tNNPhTaBlgdeNMF7PLY02N/LMNgb ZOSQ== X-Gm-Message-State: AFuF++k/o+i6ucAqgwURw9oCp8Akb82LHxpeS7xoAJ/3v0SLsh9aEQnY djn32ZX74rPiJnvKTyRu1RwhYDIoCzAWtARXxO+wCJz4NqElX5+ghQ4s4ra4PIyuGRjhecuuDEX BZft3eVA= X-Gm-Gg: AYBFou0d24QvnSn3oZLSNO65z2qrscnM4ZnHN32QZ0tMHKLa61tOsidNMpp7aya4lm3 1c3WNaRMO1M2BikkHWESImXKYxRuIE8VIK7tUCdRilZ2KXitrbYEc6XnzM50a+70vCrvwm9Sha8 SsGIV2oEj3iFjkq0Sedp98vxPNayN60iLoem2LAt58xMEmsdFcqxwbriGefx6ikLy7Yh3WsgzsM 1yzy9js3CB/ljhRKRdiO/F6g38znAbwUwIocDI5p/Bg0sbrC+PZxqLvqqw7+JgoH1FF7Qrfahmj Jr4YzJOSiED+p10ugMsy1SY8qbuiBRVd9rciHL28q0jrulLtmW7HaL8y0AGvm1wzMdsnw7kjqf/ 2YKn3IEtoVxd3s1Ustl9ySbMO/LSfDiPVvDuWKT5novaCX/5Hxg4KetwlDGV/wo0a+rxSorhW3Z jvl39y4biIT3ORaaIF60JTO7QDgw2+sJEBE4sGXSC2xyav6eJ/22LMs5ViKtw9krFGD8UI/1sGh Xd61ZeH+pYZ6cIqvsrTB/1F3OmVVw8xN1gqZBIsuy7D2WKqsVlUBN9FdPnZwRrM X-Received: by 2002:a05:6000:41cb:b0:482:f61c:7cdd with SMTP id ffacd0b85a97d-48586e4a6bbmr48561335f8f.4.1788788168119; Mon, 07 Sep 2026 06:36:08 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-48588394fa1sm27523836f8f.8.2026.09.07.06.36.07 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 07 Sep 2026 06:36:07 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][scarthgap 31/35] linux-yocto/6.6: fix tiny build Date: Mon, 7 Sep 2026 15:35:27 +0200 Message-ID: X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Mon, 07 Sep 2026 13:36:16 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/245288 From: Bruce Ashfield Integrating the following commit(s) to linux-yocto/6.6: 1/1 [ Author: Bruce Ashfield Email: bruce.ashfield@gmail.com Subject: pinctrl: core: include gpio/driver.h for struct gpio_chip Date: Tue, 18 Aug 2026 14:34:22 -0400 Stable commit f53dd26462b8e ("pinctrl: remove pinctrl_gpio_direction_output()") [ upstream 45d2055b0067 ] changed pinctrl_gpio_direction_input/output() to take a struct gpio_chip * and dereference gc->base. Those functions are compiled unconditionally, but in 6.6 core.c the struct gpio_chip definition is only pulled in via "../gpio/gpiolib.h" under #ifdef CONFIG_GPIOLIB. Configurations with CONFIG_PINCTRL=y and CONFIG_GPIOLIB=n (e.g. linux-yocto-tiny on x86, built with --allnoconfig) therefore fail to build: drivers/pinctrl/core.c: error: invalid use of undefined type 'struct gpio_chip' Include directly so struct gpio_chip is always a complete type, matching how mainline core.c has included it since commit ec963d04ca865 ("pinctrl: provide new GPIO-to-pinctrl glue helpers"), present in 6.12/6.18 but not 6.6. Signed-off-by: Bruce Ashfield ] Signed-off-by: Bruce Ashfield Signed-off-by: Yoann Congal --- .../linux/linux-yocto-rt_6.6.bb | 4 ++-- .../linux/linux-yocto-tiny_6.6.bb | 4 ++-- meta/recipes-kernel/linux/linux-yocto_6.6.bb | 24 +++++++++---------- 3 files changed, 16 insertions(+), 16 deletions(-) diff --git a/meta/recipes-kernel/linux/linux-yocto-rt_6.6.bb b/meta/recipes-kernel/linux/linux-yocto-rt_6.6.bb index 39fa0a56c2e..1d4f95e42c8 100644 --- a/meta/recipes-kernel/linux/linux-yocto-rt_6.6.bb +++ b/meta/recipes-kernel/linux/linux-yocto-rt_6.6.bb @@ -14,8 +14,8 @@ python () { raise bb.parse.SkipRecipe("Set PREFERRED_PROVIDER_virtual/kernel to linux-yocto-rt to enable it") } -SRCREV_machine ?= "c0f2d7109571c01223cbd3738db96b5ea20ddc68" -SRCREV_meta ?= "b768be4d32d53a825349353e988ca5930e83f99c" +SRCREV_machine ?= "eaa4bfd4f99ab0f3cf46ec5a207b73e22fb1c3f9" +SRCREV_meta ?= "dd201eb6ec53179f45836d41610ca68c725d28e2" SRC_URI = "git://git.yoctoproject.org/linux-yocto.git;branch=${KBRANCH};name=machine;protocol=https \ git://git.yoctoproject.org/yocto-kernel-cache;type=kmeta;name=meta;branch=yocto-6.6;destsuffix=${KMETA};protocol=https" diff --git a/meta/recipes-kernel/linux/linux-yocto-tiny_6.6.bb b/meta/recipes-kernel/linux/linux-yocto-tiny_6.6.bb index 7675e325422..f2d6e5eef53 100644 --- a/meta/recipes-kernel/linux/linux-yocto-tiny_6.6.bb +++ b/meta/recipes-kernel/linux/linux-yocto-tiny_6.6.bb @@ -17,8 +17,8 @@ DEPENDS += "openssl-native util-linux-native" KMETA = "kernel-meta" KCONF_BSP_AUDIT_LEVEL = "2" -SRCREV_machine ?= "20c2ecb592178ed51039ae1a75a523c66c1eee5d" -SRCREV_meta ?= "b768be4d32d53a825349353e988ca5930e83f99c" +SRCREV_machine ?= "c51e01ecff210644b5d199a4edb30cb1a94a746f" +SRCREV_meta ?= "dd201eb6ec53179f45836d41610ca68c725d28e2" PV = "${LINUX_VERSION}+git" diff --git a/meta/recipes-kernel/linux/linux-yocto_6.6.bb b/meta/recipes-kernel/linux/linux-yocto_6.6.bb index 7a273f9cc6f..c1ac8e0a08f 100644 --- a/meta/recipes-kernel/linux/linux-yocto_6.6.bb +++ b/meta/recipes-kernel/linux/linux-yocto_6.6.bb @@ -18,18 +18,18 @@ KBRANCH:qemux86-64 ?= "v6.6/standard/base" KBRANCH:qemuloongarch64 ?= "v6.6/standard/base" KBRANCH:qemumips64 ?= "v6.6/standard/mti-malta64" -SRCREV_machine:qemuarm ?= "06b8a8a900edeb9770128b2e25e7814ff0638c72" -SRCREV_machine:qemuarm64 ?= "bcdc0007d72899e94de35713c4c18e0ad581f41b" -SRCREV_machine:qemuloongarch64 ?= "491a3d5683a61ca2a7911f748661cfad50b8d05c" -SRCREV_machine:qemumips ?= "9023f83c1acc4010d43c5891c641a671a12d264e" -SRCREV_machine:qemuppc ?= "a76593fcb6c3b2183877d531562237a9def7acc5" -SRCREV_machine:qemuriscv64 ?= "491a3d5683a61ca2a7911f748661cfad50b8d05c" -SRCREV_machine:qemuriscv32 ?= "491a3d5683a61ca2a7911f748661cfad50b8d05c" -SRCREV_machine:qemux86 ?= "491a3d5683a61ca2a7911f748661cfad50b8d05c" -SRCREV_machine:qemux86-64 ?= "491a3d5683a61ca2a7911f748661cfad50b8d05c" -SRCREV_machine:qemumips64 ?= "50376ca9492c97cc4d6d291d06e52db021aeb1f1" -SRCREV_machine ?= "491a3d5683a61ca2a7911f748661cfad50b8d05c" -SRCREV_meta ?= "b768be4d32d53a825349353e988ca5930e83f99c" +SRCREV_machine:qemuarm ?= "ed7cf749dcade8ded9fda05be53c235a446dcbff" +SRCREV_machine:qemuarm64 ?= "b96d2d770cab02b84c46606fa538ce027bee6b08" +SRCREV_machine:qemuloongarch64 ?= "5ae544e1312ed5b4ed130d22ff1f44333494c4c3" +SRCREV_machine:qemumips ?= "fcfa6f13ad7894cedda5f59124e7a6f6f0100a67" +SRCREV_machine:qemuppc ?= "89811e5148d2a4c925940684ad9126bd08de9799" +SRCREV_machine:qemuriscv64 ?= "5ae544e1312ed5b4ed130d22ff1f44333494c4c3" +SRCREV_machine:qemuriscv32 ?= "5ae544e1312ed5b4ed130d22ff1f44333494c4c3" +SRCREV_machine:qemux86 ?= "5ae544e1312ed5b4ed130d22ff1f44333494c4c3" +SRCREV_machine:qemux86-64 ?= "5ae544e1312ed5b4ed130d22ff1f44333494c4c3" +SRCREV_machine:qemumips64 ?= "b6dc41bac21f990565fffb211d470fdc97533291" +SRCREV_machine ?= "5ae544e1312ed5b4ed130d22ff1f44333494c4c3" +SRCREV_meta ?= "dd201eb6ec53179f45836d41610ca68c725d28e2" # set your preferred provider of linux-yocto to 'linux-yocto-upstream', and you'll # get the /base branch, which is pure upstream -stable, and the same From patchwork Mon Sep 7 13:35:28 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 97550 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 7B379C79FA7 for ; Mon, 7 Sep 2026 13:36:16 +0000 (UTC) Received: from mail-wr1-f53.google.com (mail-wr1-f53.google.com [209.85.221.53]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.34944.1788788170705966969 for ; Mon, 07 Sep 2026 06:36:11 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=SiJ+0Z/U; spf=pass (domain: smile.fr, ip: 209.85.221.53, mailfrom: yoann.congal@smile.fr) Received: by mail-wr1-f53.google.com with SMTP id ffacd0b85a97d-48436251906so4068616f8f.0 for ; Mon, 07 Sep 2026 06:36:10 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1788788169; x=1789392969; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=97bUQEP2eAKwUGTPuhdvhHBw6dGNqEgYayxwOookziE=; b=SiJ+0Z/Uv0grQl8R2/am0e6MlwMLchuN2BZ45v0gOPUZ2cW/MvQHuUgBigcshNjiRX i4nQJYQCRCbpXA+wBIFXkLfmQY96zFl+D8+x5GmvTROopCo7sKw9gVb6GscZOXFUbBWN +bHGB/5UFZA6T5/s64N/Zac7CYukHnDfX8Z4s= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1788788169; x=1789392969; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=97bUQEP2eAKwUGTPuhdvhHBw6dGNqEgYayxwOookziE=; b=gjiqn2ljmGBqKyuxLkLnRigmXWA5lcLHwuiG5JJ0pIO7uViq+GcjToJ+vCqv2bYc0V hoL3hBTguipnnwlxmvLjMVzWAVa1mSIGYX+sSO3isU7Ubq3ghM101mFO15PbJwzwtIG8 pce/bcskdAX7MSSEK+HmTNK7GFnvcRO5LV5JXiCivH0B12OhH6e34N9XHtyUPfMchsLG conHzVUGDctcx5uhndiZR3OGqD9qrnePvPyowz0HG8wdgqzBayXp6fEJ5WXsLMBkN4D2 XpeU5oN3B/7JjvSKOVgqncD2js+umoR5f/gbuq89K+Ie2UfCJMCGYBY0WeD6m9noOL54 97Zw== X-Gm-Message-State: AFuF++kP2AX7R8ZXtO4aW0A4J9vTfhMnXaE45pCoB4GQfurgru8oXLBG PM2cMzjginnAfoP4m4dFHh8JPFinBq3BLTGuQZHc5X1HANYnpBZAZ5ATNmhhkwamU91CTyZ7VA7 x0SlgnnI= X-Gm-Gg: AYBFou3A0dFw/rvwHcBu3uhOuPRM5Zb0v1BkG/kQOhy7RhDkEbGir6zOB5uB9UxkOqp lBwLKXVCSlmg83d2Xy29bGlbSO11JS84cadLWYv85ku9Rayh37p55rTX+8pLBGCR5g7u99c4bKk HtAZGUN0K9L13bsZktqGWD1W+tRmeB5v69TcmnKoeDbViEX/ZJnUkJxOKpIdQ8L25m+d5mRDz6V 55DTfueW+jJ1zbI9oj4TGi7BMHQ5yHWLrEE2ry548RRbTv7bjsNsVGLhMbt4zS3JPTu60/Kz+94 G5rnOhb2TngbSRId54vKS6nFQnYkHE38NfIIh3gDa6qwQVAg5iGXW9ezJzfTHQqS4SjaJVDjRbQ NNK1hebVFMa2VYrxQJG9jlOqfUMq+Bgs/vu5VSQ9vGFrGuZa/prKqh30ujgIen3nJEYqSC6/KE6 dN9E/ZYMoXfsxunRdSgXPRzAo2Ail/gEbeCzxic0Fi9lATuet9mRz2KtU0L1IvAA1JxQHDf4/2i uzMLSbMCOlRK+ag7lmTmA9XpVCyX/kVBrA9hhJHaln/sYDIo6oPwVOfggcmmAX0+aYnaTo5Oe8= X-Received: by 2002:a05:6000:26d3:b0:485:8393:2176 with SMTP id ffacd0b85a97d-485870902eamr40658661f8f.21.1788788168827; Mon, 07 Sep 2026 06:36:08 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-48588394fa1sm27523836f8f.8.2026.09.07.06.36.08 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 07 Sep 2026 06:36:08 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][scarthgap 32/35] libssh2: Fix CVE-2026-58051 Date: Mon, 7 Sep 2026 15:35:28 +0200 Message-ID: <19c481ffd3824512eb85845f04ae7b08b947b4f6.1788787321.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Mon, 07 Sep 2026 13:36:16 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/245289 From: Hetvi Thakar Backport the upstream fix for CVE-2026-58051 using the commit in [1]. The CVE advisory [2] describes an uninitialized publickey-list entry cleanup issue affecting libssh2 through 1.11.1. [1] https://github.com/libssh2/libssh2/commit/a9758da45a52bc8c630ec9493804d0c6ea30b24a [2] https://nvd.nist.gov/vuln/detail/CVE-2026-58051 Signed-off-by: Hetvi Thakar Signed-off-by: Yoann Congal --- .../libssh2/libssh2/CVE-2026-58051.patch | 34 +++++++++++++++++++ .../recipes-support/libssh2/libssh2_1.11.1.bb | 1 + 2 files changed, 35 insertions(+) create mode 100644 meta/recipes-support/libssh2/libssh2/CVE-2026-58051.patch diff --git a/meta/recipes-support/libssh2/libssh2/CVE-2026-58051.patch b/meta/recipes-support/libssh2/libssh2/CVE-2026-58051.patch new file mode 100644 index 00000000000..6be1e81d636 --- /dev/null +++ b/meta/recipes-support/libssh2/libssh2/CVE-2026-58051.patch @@ -0,0 +1,34 @@ +From 39ea6e1783afcbd72838eaf649999baa2c41ab12 Mon Sep 17 00:00:00 2001 +From: Viktor Szakats +Date: Mon, 29 Jun 2026 19:12:21 +0200 +Subject: [PATCH] publickey: fix potential arbitrary free in + `libssh2_publickey_list_fetch()` (#2127) + +Due to uninitialized list entry. + +Reported-and-patch-by: Behzod Abdullayev +Reported-by: Sharique Raza + +Follow-up to e15f5d97a04cc676ce117dd324fef85b046207a9 + +CVE: CVE-2026-58051 +Upstream-Status: Backport [https://github.com/libssh2/libssh2/commit/a9758da45a52bc8c630ec9493804d0c6ea30b24a] + +(cherry picked from commit a9758da45a52bc8c630ec9493804d0c6ea30b24a) +Signed-off-by: Hetvi Thakar +--- + src/publickey.c | 1 + + 1 file changed, 1 insertion(+) + +diff --git a/src/publickey.c b/src/publickey.c +index 9ff2e5cf..5af3b50a 100644 +--- a/src/publickey.c ++++ b/src/publickey.c +@@ -972,6 +972,7 @@ libssh2_publickey_list_fetch(LIBSSH2_PUBLICKEY * pkey, unsigned long *num_keys, + goto err_exit; + } + list = newlist; ++ memset(&list[keys], 0, sizeof(list[keys])); + } + if(pkey->version == 1) { + unsigned long comment_len; diff --git a/meta/recipes-support/libssh2/libssh2_1.11.1.bb b/meta/recipes-support/libssh2/libssh2_1.11.1.bb index d3f39050474..c2570f2a909 100644 --- a/meta/recipes-support/libssh2/libssh2_1.11.1.bb +++ b/meta/recipes-support/libssh2/libssh2_1.11.1.bb @@ -21,6 +21,7 @@ SRC_URI = "http://www.libssh2.org/download/${BP}.tar.gz \ file://CVE-2026-66034.patch \ file://CVE-2026-66035.patch \ file://CVE-2026-58050.patch \ + file://CVE-2026-58051.patch \ " SRC_URI[sha256sum] = "d9ec76cbe34db98eec3539fe2c899d26b0c837cb3eb466a56b0f109cabf658f7" From patchwork Mon Sep 7 13:35:29 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 97549 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 5E461C79F9E for ; Mon, 7 Sep 2026 13:36:16 +0000 (UTC) Received: from mail-wr1-f51.google.com (mail-wr1-f51.google.com [209.85.221.51]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.34946.1788788171072130481 for ; Mon, 07 Sep 2026 06:36:11 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=QsPYcqzZ; spf=pass (domain: smile.fr, ip: 209.85.221.51, mailfrom: yoann.congal@smile.fr) Received: by mail-wr1-f51.google.com with SMTP id ffacd0b85a97d-482dbe4d247so2024684f8f.2 for ; Mon, 07 Sep 2026 06:36:10 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1788788169; x=1789392969; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=LIwIqKdBsZiPxSu/Vjl8VWgjBW58eSHx7XZb+ki9teU=; b=QsPYcqzZ58dLM6tHTIVeqSEbD9SfJg2igRTQgj0ND7YcgtFxlhQU3xAQa4CI23Mb0T IshihYgUAr4/xudFPMoZr++yAgQ79omPvpeTkUOou077CUS1R8vLaNHb1naFZpQG2PkY 31KDM9+CkoTyWiZ0DtGDYRIHR+gv4uq0wK4Uw= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1788788169; x=1789392969; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=LIwIqKdBsZiPxSu/Vjl8VWgjBW58eSHx7XZb+ki9teU=; b=B5XlQiKumomD/ewTBhpXSwKGvtyDUASBoCV24RRbQf7JHazz9UnykQGCXpRzQGRZtI gHHryMKcGr+lJICeY6lqKzaU+6CrZk7Xz5ldaRfAUsiX6kyz8YTO8tL/GnLGRQGr6OIC lurKZMu+JdZGQGWnsY8fQK6C+7KZvMOPjSKxxribNfvpvJ0QrX9Qvs+g07mhpJjNuErH m7epWxQLdWeBDDL1XG6Wyxr2ZufVriXJAFz2zItS55tnUdUHXil0AE5Pa5DOpAvcCAmF cb9tfU7Y9/cRSOuvf+7tNvi0ca2piescPB21Nfund/e2YfDuV1S6uppzLT19M3lZKKod iIEw== X-Gm-Message-State: AFuF++lPfOL6gBI8ZNU7CjisJfHk9NswzxkSBzaVi5tYhiMs8bMCBoD4 i4EoK+rv2qDjyRWgIOV9W1cSSFn0L+R+E0hBvllohEy6tz4qySKnGkvq/6TZOGxcGPiYq2ETsq3 PK5iVTTE= X-Gm-Gg: AYBFou0CJlal6pD6Tu4jzkO7akGJGH3uldaaEyu/2ayeGQLHSd5R33Nq0WwGS9f/lg4 AceY5sELvkeQrsMZ9aaRuesXOgugoLjE7iGSiDzf0Sl9dRcjItvvws2yhKhru2eCVogcyqzSdpt xgybWRcF5S+SJP4KtOYkr/nmpgYvzqgPZWynWg3GHMt4ibUrmMzZpcYgiNOMewT5+WzJPvKnVuU 7u5SMyJ4Dbp3Msy9pduUBO3X38UK1appkanwAjkgK0i/UTCQEirhn08CzAM6HmEgJwGBrne0fGg qn4ZnRoBKEFagrHl/G071Hzn4OY0JZXzIprRo5eDlJDoNNMoPmZOzT06wXWSFNL5bw01m2KeDyY A+fgdU+8SfViBKcvMLnOMBoGuqGry2ZvFAGYyhUkURT8Ps3rPpQEP3YTpxnpDw3QkWKV13gXvfT ekaw6f6oAWBxUM2cJkb87InTfr5+WbY8c8Ce06l12olGPvcGoIDpPiYPGhLLvdaOGhggr06ywaU qqbSJEYjwBSCR4QAh22ml2rY0jHJK2WACfAOBI7R7obLeX9LFOXNXUbBNff+NCR X-Received: by 2002:a05:6000:491a:b0:47f:9254:d453 with SMTP id ffacd0b85a97d-4858704a9d7mr47051700f8f.8.1788788169386; Mon, 07 Sep 2026 06:36:09 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-48588394fa1sm27523836f8f.8.2026.09.07.06.36.09 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 07 Sep 2026 06:36:09 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][scarthgap 33/35] python3-git: fix CVE_PRODUCT Date: Mon, 7 Sep 2026 15:35:29 +0200 Message-ID: <0c9e81e2b248c15054c8a847f043aea994b8adbe.1788787321.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Mon, 07 Sep 2026 13:36:16 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/245290 From: Tim Orling Using the pypi.bbclass default CPE of python:GitPython detects no CVEs. With CVE_PRODUCT = "gitpython_project:gitpython" we properly detect 9 CVEs, with 4 unpatched. WARNING: python3-git-3.1.42-r0 do_cve_check: Found unpatched CVEs: CVE-2026-42215, CVE-2026-42284, CVE-2026-44243, CVE-2026-44244 Note: The original commit targeted python3-git_3.1.43.bb. This is adjusted for Scarthgap, where the recipe version is 3.1.42. Signed-off-by: Tim Orling Signed-off-by: Richard Purdie (cherry picked from commit 3a6af75a33b4e007f0d3a247b6a149e32d51e510) Signed-off-by: Devansh Patel Signed-off-by: Yoann Congal --- meta/recipes-devtools/python/python3-git_3.1.42.bb | 2 ++ 1 file changed, 2 insertions(+) diff --git a/meta/recipes-devtools/python/python3-git_3.1.42.bb b/meta/recipes-devtools/python/python3-git_3.1.42.bb index e728e8bfa4c..8c130cf63b4 100644 --- a/meta/recipes-devtools/python/python3-git_3.1.42.bb +++ b/meta/recipes-devtools/python/python3-git_3.1.42.bb @@ -10,6 +10,8 @@ LIC_FILES_CHKSUM = "file://LICENSE;md5=5279a7ab369ba336989dcf2a107e5c8e" PYPI_PACKAGE = "GitPython" +CVE_PRODUCT = "gitpython_project:gitpython" + inherit pypi python_setuptools_build_meta SRC_URI += "file://CVE-2026-42284.patch \ From patchwork Mon Sep 7 13:35:30 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 97554 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id F3B88C79FA0 for ; Mon, 7 Sep 2026 13:36:16 +0000 (UTC) Received: from mail-wm1-f50.google.com (mail-wm1-f50.google.com [209.85.128.50]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.35232.1788788171726196002 for ; Mon, 07 Sep 2026 06:36:12 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=XrjUso1t; spf=pass (domain: smile.fr, ip: 209.85.128.50, mailfrom: yoann.congal@smile.fr) Received: by mail-wm1-f50.google.com with SMTP id 5b1f17b1804b1-499ae1c6471so35017875e9.3 for ; Mon, 07 Sep 2026 06:36:11 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1788788170; x=1789392970; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=RdTkEA8KR7xRi0mq5K1fT3ITsXYBddIrXGOJwmCY4eU=; b=XrjUso1tc7gwUWWPH3K09ZzZZ+febnHGKmyQfiaR3hg637IzSdoKPJbWRqumPGcDl0 b+0ntgfXWCPxRoZj1KzPvV86cGqZX02FEKlEJtPtH9vhtPtsgsmcEwGvq7t/nAQxSpI6 NNxDOOHI0OMiqUfZgO2mZcg5O5xmm35e3+5YA= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1788788170; x=1789392970; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=RdTkEA8KR7xRi0mq5K1fT3ITsXYBddIrXGOJwmCY4eU=; b=ZlKRnot0No21AfUs5pdI0px1jndQ+dgoulhCFHvyMw6fqQSESoUuHOGUZeXMEu62Fx HGlvtPsCBeWFT8BXGX3MV+9Q41VJvlRhwpk1xAB7Au5+b+cH0iWY+yEEsneq/xMMjDyO b30hCIWFLVVr4wE0fB3L31rS/7S8FasGM+rp6vOukPqvPso3jiiFnAKMQS73/4BrylRz LmnSdeqdhmiQO1QN2IpjmgoYpEaaWLnIoIvG/6jCfLmXV40n45nLJAB6hmnJjw9qAYjR CeYAtvMLmkceqMrTVOStYVxLUKmd8+r3m8Bjja1qMVyg4m+hYDYZ4L6wjelwhVePex0b CFkw== X-Gm-Message-State: AFuF++ne0dZJGbF3h9PhXt4XX7IcpjCcSzGwGVeliEfwbgQDOpuCaOhL dCNOtKtxtwP7OMGrFRKjThBueifIIxEYeTid6Lhps3s1aJPVx8UU0Yxw5izN5dD6zT5VXr8RSp9 7G14Ua6s= X-Gm-Gg: AYBFou3gc8xyUgo6YZrSraEjIF/b5sres+JQ4u1PhJ8AkHu8jc2P/Cb+QmdcyUBcR2H TXKsi9vaS30jb/7n+xw8YWZoiDDslZseZew9iUQP/xbz49Sb4SAyhRIdYflA/IpEeb6LGPUh3Fl hoCGfLW16VZSdDw+NqcrvsKvX83xYw/5lwpeI8k08HDrApHrQlxOb/HHbDJgz0f74Q0o5XHS6/j wdbNnwDoiSMki8TkPyEzek3E87bGiIDC/RsKq6zIp9VSp5FC28Vv5A4/knXihb9G6upyTaKgSdH M3XvRe1f66U0H76UMPyxD+hGRAmIPAmE0yKgY+7kUDM5EwRto5Rtx5ekmiyLREUxrXXwtlo1XM8 5K1eNvWkpOoPUSaEAM5bejJwExV/0Nwmle15d9onVQLn9Diwmuy+jsNG/GORfgGbnKKG02+w0zg 4fyTzahZWVYa5OcZnFOG0/o2kuJdwVp5Y8D8/Ggq8vNLxOxZzSv0BEsKDIag9TofmWwDVsD0TmB PDNijAiCQcJa3tyhMJfKu/u1UzcwcJJEZKo0aAhOwAm/7lJi9m5wVPvUPIee5OT X-Received: by 2002:a05:600c:3d92:b0:49d:726:cc9f with SMTP id 5b1f17b1804b1-49d0726cd2emr271048805e9.5.1788788169831; Mon, 07 Sep 2026 06:36:09 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-48588394fa1sm27523836f8f.8.2026.09.07.06.36.09 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 07 Sep 2026 06:36:09 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][scarthgap 34/35] busybox: patch CVE-2024-58251 Date: Mon, 7 Sep 2026 15:35:30 +0200 Message-ID: <6c0b6e39336686590820dce96913f143a45edadf.1788787321.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Mon, 07 Sep 2026 13:36:16 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/245291 From: Peter Marko Pick patch applied by Debian [1]. I did not find any reference on busybox mailing list that this patch was submitted. Submitting patch for someone else would be inappropriate, and busybox is currently known to be very inactive, hence the unwanted Pending Upstream-Status status. Also note that the related busybox bugreport [2] is currently not public, so it is possible that it was submitted there. [1] https://sources.debian.org/patches/busybox/1:1.37.0-10.1/netstat-sanitize-argv0-for-p-CVE-2024-58251.patch/ [2] https://bugs.busybox.net/show_bug.cgi?id=15922 Signed-off-by: Peter Marko Signed-off-by: Mathieu Dubois-Briand Signed-off-by: Richard Purdie Signed-off-by: Chen Qi (cherry picked from commit 7261144785aa508377c995e52d7e2410a814f00b) Signed-off-by: Yoann Congal (cherry picked from commit 8f344d46b96fb16632501749dc39b97aa3e11836) Signed-off-by: Jaipaul Cheernam Signed-off-by: Yoann Congal --- .../busybox/busybox/CVE-2024-58251.patch | 51 +++++++++++++++++++ meta/recipes-core/busybox/busybox_1.36.1.bb | 1 + 2 files changed, 52 insertions(+) create mode 100644 meta/recipes-core/busybox/busybox/CVE-2024-58251.patch diff --git a/meta/recipes-core/busybox/busybox/CVE-2024-58251.patch b/meta/recipes-core/busybox/busybox/CVE-2024-58251.patch new file mode 100644 index 00000000000..713d345ca83 --- /dev/null +++ b/meta/recipes-core/busybox/busybox/CVE-2024-58251.patch @@ -0,0 +1,51 @@ +From: Valery Ushakov +Date: Thu, 21 Aug 2025 12:31:53 +0000 +Subject: netstat: CVE-2024-58251 - sanitize argv0 for -p +Bug-Debian: https://bugs.debian.org/1104009 + +Signed-off-by: Valery Ushakov + +CVE: CVE-2024-58251 +Upstream-Status: Pending +Signed-off-by: Peter Marko +--- + networking/netstat.c | 7 ++++++- + 1 file changed, 6 insertions(+), 1 deletion(-) + +diff --git a/networking/netstat.c b/networking/netstat.c +index 807800a62..d979f6079 100644 +--- a/networking/netstat.c ++++ b/networking/netstat.c +@@ -41,6 +41,7 @@ + + #include "libbb.h" + #include "inet_common.h" ++#include "unicode.h" + + //usage:#define netstat_trivial_usage + //usage: "[-"IF_ROUTE("r")"al] [-tuwx] [-en"IF_FEATURE_NETSTAT_WIDE("W")IF_FEATURE_NETSTAT_PRG("p")"]" +@@ -314,9 +315,12 @@ static int FAST_FUNC dir_act(struct recursive_state *state, + return FALSE; + cmdline_buf[n] = '\0'; + ++ /* don't write process-controlled argv[0] to the user's terminal as-is */ ++ const char *argv0base = printable_string(bb_basename(cmdline_buf)); ++ + /* go through all files in /proc/PID/fd and check whether they are sockets */ + strcpy(proc_pid_fname + len - (sizeof("cmdline")-1), "fd"); +- pid_slash_progname = concat_path_file(pid, bb_basename(cmdline_buf)); /* "PID/argv0" */ ++ pid_slash_progname = concat_path_file(pid, argv0base); /* "PID/argv0" */ + n = recursive_action(proc_pid_fname, + ACTION_RECURSE | ACTION_QUIET, + add_to_prg_cache_if_socket, +@@ -686,6 +690,7 @@ int netstat_main(int argc UNUSED_PARAM, char **argv) + unsigned opt; + + INIT_G(); ++ init_unicode(); + + /* Option string must match NETSTAT_xxx constants */ + opt = getopt32(argv, NETSTAT_OPTS); +-- +2.34.1 + diff --git a/meta/recipes-core/busybox/busybox_1.36.1.bb b/meta/recipes-core/busybox/busybox_1.36.1.bb index 60796de9ce2..70d984b7c6e 100644 --- a/meta/recipes-core/busybox/busybox_1.36.1.bb +++ b/meta/recipes-core/busybox/busybox_1.36.1.bb @@ -67,6 +67,7 @@ SRC_URI = "https://busybox.net/downloads/busybox-${PV}.tar.bz2;name=tarball \ file://CVE-2026-29004-01.patch \ file://CVE-2026-29004-02.patch \ file://CVE-2026-38754.patch \ + file://CVE-2024-58251.patch \ " SRC_URI:append:libc-musl = " file://musl.cfg " # TODO http://lists.busybox.net/pipermail/busybox/2023-January/090078.html From patchwork Mon Sep 7 13:35:31 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 97547 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 15DD2C79F89 for ; Mon, 7 Sep 2026 13:36:16 +0000 (UTC) Received: from mail-wm1-f46.google.com (mail-wm1-f46.google.com [209.85.128.46]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.34947.1788788172823754870 for ; Mon, 07 Sep 2026 06:36:13 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=me1qLNQA; spf=pass (domain: smile.fr, ip: 209.85.128.46, mailfrom: yoann.congal@smile.fr) Received: by mail-wm1-f46.google.com with SMTP id 5b1f17b1804b1-49cf4f81d86so28062615e9.2 for ; Mon, 07 Sep 2026 06:36:12 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1788788171; x=1789392971; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=B+vN2GVNUkGzAidY/yDE3Qqp+YMaxf+E2NrcvbjzwFc=; b=me1qLNQAg/ASnif2jVgoX1imDGfRjnUEfzouPWYQ/u2RGDr3SI4oKed9XK0cNb7zPp A37rG1CVbRNNB2DItNzh1KYd0qnUrX1tGlWvtPvE6/+KH8XVjnsvzVPDkfezUGyHnh5K j45tXgGuNZepiuawjgVHdBsqzT49Zl4qGOViE= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1788788171; x=1789392971; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=B+vN2GVNUkGzAidY/yDE3Qqp+YMaxf+E2NrcvbjzwFc=; b=XblNxHDTScNuev7AVfbYv6PR0iBxzPUeYdoGrB1OYK9VO6pJQYN7lcUPqxMMkl9o+X KhRmQ+17jm7wPl5gZER083HaBH7dz/w8t9wAQyd+paJQVAhM2pY3/1jLBmXVIhwhAXPe duF6diu4miFG7WnXxDvK8pdTMFIIIlYmHpgLRK/h6EKv121B9mIy+3Co4NjAG/9gFbnj w/Tplwmz382SbEbVeVVZvwSeble7Y8oDX+zHzK4Iib4CkbDsiPh62VdRhsOMfTRlw/iL GU6xcMboZPZ7QTP33Yj8lwn5lMaFvopn5AtDJjCewDJaCEkbGLKX61ytH/K50cGyvc0Q Jrwg== X-Gm-Message-State: AFuF++kjSQjvfN6bnl4iiCZz4al+J8v9M1UdI1wijv9gR2dTiimXhELI wuV9JWKRZKNDrD8YvZS4+7h7W5EYLB/gMqdWMgvtBi6OXuM0zJICwykfi6SPS6+6oel4w/h0quO bT+mFsDg= X-Gm-Gg: AYBFou1nRR+gB9xPhsDJDBpnEqs1D99ARUP5nGchbyXE8ghE3nAprAoLt8IEX2Gs5Hf vHBUVO+RGVCGeJzAv10baQ0Y1R5Z0CBg7n2x0MR5FuPGVgy0K0ANZvqivUyjxeaFXLh19Y84+BP mZdVQDq92tXaJY+nuw5MIp/fevvS8bJI+89uro99jLMLEJxX05wsVSIg4hwfrhQHedBNdQfwNgF Kft9xSN++Heuun382bMaA2jVWf6gMga+uw6TS5UKrW1hqtQf5RujS6K8WE4N1wgiz3prsk5h04g f/uNHIPIhOZp2x9yPvSfSFsqMBn8HOTBA79V+nLTZQIePqV2DJsZ6koaUh/P33rtjmM4PeK/mPm 5tYyDW5VnnT3BxhH53FM8Y6rHZZiHQJlLL+BFKElkxkJfmVLalMGZVkAwsDjv2NXYi0xjTv3Pi/ 0xi2lTc6cos+jpfpzmXKxUGBcF0moeF5ADtlj6dP19ZDXME3cWJLqEfH6zH9LVIeH4pULKOO+CH RxboGVKX3AgepomkN8DwNI+m4fihHTU5Vclfj/cpg9SWOr3jpje6iYu6PSfToNU X-Received: by 2002:a05:600c:190b:b0:49c:fc6c:be12 with SMTP id 5b1f17b1804b1-49cfc6cc0acmr175191675e9.24.1788788170992; Mon, 07 Sep 2026 06:36:10 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-48588394fa1sm27523836f8f.8.2026.09.07.06.36.09 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 07 Sep 2026 06:36:09 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][scarthgap 35/35] gnutls: Backport fix for CVE-2026-33846 Date: Mon, 7 Sep 2026 15:35:31 +0200 Message-ID: <5b4292b3fc1586709dcdc27d7cfa3d880e6f338a.1788787321.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Mon, 07 Sep 2026 13:36:16 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/245292 From: Roland Kovacs Backport patch [1] referenced in [2]. The difference in upstream and the backport is skipping of intermediate patch [3] which essentially just aliases `session->internals.handshake_recv_buffer -> recv_buf'. NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-33846 [1] https://gitlab.com/gnutls/gnutls/-/commit/65ab33fa54e34fba69d793735b7df3d383d1ff78 [2] https://security-tracker.debian.org/tracker/CVE-2026-33846 [3] https://gitlab.com/gnutls/gnutls/-/commit/9deffca528c23bbb218f5ec3bd4bb1bf4cbd1fc0 Signed-off-by: Roland Kovacs Signed-off-by: Yoann Congal --- .../gnutls/gnutls/CVE-2026-33846.patch | 66 +++++++++++++++++++ meta/recipes-support/gnutls/gnutls_3.8.4.bb | 1 + 2 files changed, 67 insertions(+) create mode 100644 meta/recipes-support/gnutls/gnutls/CVE-2026-33846.patch diff --git a/meta/recipes-support/gnutls/gnutls/CVE-2026-33846.patch b/meta/recipes-support/gnutls/gnutls/CVE-2026-33846.patch new file mode 100644 index 00000000000..81c928c872a --- /dev/null +++ b/meta/recipes-support/gnutls/gnutls/CVE-2026-33846.patch @@ -0,0 +1,66 @@ +From f83c50305b4186075aeea26c7d8d64fdad95f381 Mon Sep 17 00:00:00 2001 +From: Alexander Sosedkin +Date: Fri, 17 Apr 2026 18:21:36 +0200 +Subject: [PATCH] buffers: add more checks to DTLS reassembly + +Previously, gnutls didn't check that DTLS fragments claimed +a consistent message_length value. +Additionally, a crucial array size check was missing, +enabling an attacker to cause a heap overwrite. +The updated version rejects fragments with mismatching length +and adds a missing boundary check. + +Reported-by: Haruto Kimura (Stella) +Reported-by: Oscar Reparaz +Reported-by: Zou Dikai +Fixes: #1816 +Fixes: #1838 +Fixes: #1839 +Fixes: CVE-2026-33846 +Fixes: GNUTLS-SA-2026-04-29-1 +CVSS: 7.4 High CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H +CVSS: 7.5 High CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H +Signed-off-by: Alexander Sosedkin + +CVE: CVE-2026-33846 +Upstream-Status: Backport [https://gitlab.com/gnutls/gnutls/-/commit/65ab33fa54e34fba69d793735b7df3d383d1ff78] +Signed-off-by: Roland Kovacs +--- + lib/buffers.c | 21 +++++++++++++++++++++ + 1 file changed, 21 insertions(+) + +diff --git a/lib/buffers.c b/lib/buffers.c +index 672380b05..2934fd366 100644 +--- a/lib/buffers.c ++++ b/lib/buffers.c +@@ -1009,6 +1009,27 @@ static int merge_handshake_packet(gnutls_session_t session, + &session->internals.handshake_recv_buffer[pos], hsk); + + } else { ++ if (hsk->length != ++ session->internals.handshake_recv_buffer[pos].length) { ++ /* inconsistent across fragments */ ++ _gnutls_handshake_buffer_clear(hsk); ++ return gnutls_assert_val( ++ GNUTLS_E_UNEXPECTED_PACKET_LENGTH); ++ } ++ /* start_offset + data.length <= hsk->length <= max_length */ ++ if (hsk->length < hsk->start_offset + hsk->data.length) { ++ /* impossible claims, overflow requested */ ++ _gnutls_handshake_buffer_clear(hsk); ++ return gnutls_assert_val( ++ GNUTLS_E_UNEXPECTED_PACKET_LENGTH); ++ } ++ if (hsk->length > ++ session->internals.handshake_recv_buffer[pos].data.max_length) { ++ /* we don't have this much allocated, overflow guard */ ++ _gnutls_handshake_buffer_clear(hsk); ++ return gnutls_assert_val( ++ GNUTLS_E_UNEXPECTED_PACKET_LENGTH); ++ } + if (hsk->start_offset < + session->internals.handshake_recv_buffer[pos] + .start_offset && +-- +2.47.3 + diff --git a/meta/recipes-support/gnutls/gnutls_3.8.4.bb b/meta/recipes-support/gnutls/gnutls_3.8.4.bb index 2d88bc181de..0aa1eef513f 100644 --- a/meta/recipes-support/gnutls/gnutls_3.8.4.bb +++ b/meta/recipes-support/gnutls/gnutls_3.8.4.bb @@ -49,6 +49,7 @@ SRC_URI = "https://www.gnupg.org/ftp/gcrypt/gnutls/v${SHRT_VER}/gnutls-${PV}.tar file://CVE-2026-42010.patch \ file://CVE-2026-42011_p1.patch \ file://CVE-2026-42011_p2.patch \ + file://CVE-2026-33846.patch \ " SRC_URI[sha256sum] = "2bea4e154794f3f00180fa2a5c51fe8b005ac7a31cd58bd44cdfa7f36ebc3a9b"