From patchwork Wed Sep 9 07:29:00 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 8bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 97667 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 41453C79FBD for ; Wed, 9 Sep 2026 07:30:01 +0000 (UTC) Received: from mail-wr1-f45.google.com (mail-wr1-f45.google.com [209.85.221.45]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.6426.1788938996192867364 for ; Wed, 09 Sep 2026 00:29:56 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=TIhbnW0n; spf=pass (domain: smile.fr, ip: 209.85.221.45, mailfrom: yoann.congal@smile.fr) Received: by mail-wr1-f45.google.com with SMTP id ffacd0b85a97d-482dd6ee390so6187177f8f.3 for ; Wed, 09 Sep 2026 00:29:55 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1788938994; x=1789543794; darn=lists.openembedded.org; h=content-transfer-encoding:content-type:mime-version:references :in-reply-to:message-id:date:subject:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=cD6YruT+rUtvzUAIwlFxaYubCHVgR3ZAr8lZ+Ven7II=; b=TIhbnW0n4+gw1yB6nKwLvkGZqgkIkXimji7xUP29RCW0tHIpQggzmqDzKczeikPLNl exw/p3qD/v/NHDTq97xGnpUla1Mp41DGQWNZ+WHAb4Cu8JDEUkFeQmMgcRVYUrF4/kqD 25ofO65hkCq76nPFSCPzrTkdNWzGQpYJgVnTY= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1788938994; x=1789543794; h=content-transfer-encoding:content-type:mime-version:references :in-reply-to:message-id:date:subject:to:from:x-gm-gg :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to :content-type; bh=cD6YruT+rUtvzUAIwlFxaYubCHVgR3ZAr8lZ+Ven7II=; b=iC7XrVqtiUIbNz4Td1q8r44LIv0UwUx2hRDyDwIVHPQ8q3PejNtxOfjHwQkfSnAyiH uGNutzLgpYq19mXNuKHUqEnDXanYtAlkT5Fo0MqnKWEHg0r3DQwdZ2dFz6CYiNEqYL2d afzK5I55nf87NqgPpojsBgt84GdZSAs2lFsHB3si9Ut/cgPWd5qFqHe1SEvvCgLFbLU8 YqiV8GTYIItEuxod3tVHHoueIQ4QUYPZB47VeCNnXWAChZUgK40oL7oi429e0EDFL3yg 3fVQN1qcToi0BWIci7kAny1HlQHaipJgC2AswY0W/kZsWRFqxOccalZjQ7+jF3zpRGix e65Q== X-Gm-Message-State: AFuF++n39RHKkSRBkTag17Ksd9NmpIjJ2FxXFVillHgulPgkGrXeKeN2 4W/ZykaAPg7m+zRqxtdrbo5JRSUPAk3cL2jxhhsUoe2j6k9TEC3Cl2Xr5AdDawnnywCR4jaonVY zfDeIscY= X-Gm-Gg: AYBFou36v0mwAKQG3M+BPggcc4RdJ+luqcc4bvoXjeSeU8Xfuw0iBjNK8dcsRpgqo8T QePDKXkkuczDeqMpC+iBgYaEF035pzwQzQwcpaLsUytDEd3iYsmzTXzkUk9ugiM0MSNs4DG0Wi7 NvtFzwbVMYYgxJSXHj/nvi9/xC64RfChbj9zE89XU1gXzHeAd8XYe1Zb3SEZG4ex+yAv7UfINeg HuKLs4MTqQV4VWTbQyDXJ6oufLehBQdtAEwteNgzFdA28fmjlOIoa4ukUty3uKq2FU1qPBxnX1w ghsRkEtTTxrp6Zih2HeJLBDFSAlwEdknrhFBqivT33QBAyA2fljEeC7LK6+wex9t/XwQ5ZjIjHS FsRUD9qYkCbvP45TkVF6imbjYhrtiKjo7q1C3EDpWtCnrebj14+ZMPC3GVVtDqYTASve/ZMQmfD KPH0JTy8ELk0siOJFa3fy4GyKnTIopY6axn+JNoeHqgE7d+tkzSKEwThx2g0lSZr6kHedWs5r4O KTx2Ez9FiBeYDqqNIXnQjGdt0z6lWGklUM22EKwn+iQHml6PVr+vhI3yiLRaJWjPtI0+wgge2A= X-Received: by 2002:a05:6000:24c8:b0:485:8c16:a33e with SMTP id ffacd0b85a97d-4858c16a715mr31386419f8f.51.1788938992082; Wed, 09 Sep 2026 00:29:52 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-4858ac2b4cdsm40624310f8f.16.2026.09.09.00.29.51 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 09 Sep 2026 00:29:51 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][wrynose 01/38] linux-yocto/6.18: update to v6.18.41 Date: Wed, 9 Sep 2026 09:29:00 +0200 Message-ID: X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Wed, 09 Sep 2026 07:30:01 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/245412 From: Bruce Ashfield Updating linux-yocto/6.18 to the latest korg -stable release that comprises the following commits: 2fe596715f840 Linux 6.18.41 6a7ecc25abe6f posix-cpu-timers: Prevent UAF caused by non-leader exec() race 9f7268928ac0c posix-timers: Expand timer_[re]arm() callbacks with a boolean return value 221fc2f4d0eda Linux 6.18.40 478c4d24193fe RDMA/bnxt_re: Avoid repeated requests to allocate WC pages b87cbd4d198ae RDMA/bnxt_re: Initialize dpi variable to zero 81e6faa5b6405 ksmbd: fix durable reconnect double-bind race in ksmbd_reopen_durable_fd 1badb6866482d perf callchain: Handle multiple address spaces 275eb39930947 seqlock: fix scoped_seqlock_read kernel-doc 453cb79a15641 perf inject: With --convert-callchain ignore the dummy event for dwarf stacks 2764d031efd6d PCI: Fix Resizable BAR restore order 2fb74141ec54e PCI: Fix BAR resize rollback path overwriting ret 7425e7d82cb93 perf symbol: Fix ENOENT case for filename__read_build_id a888f3d5970ff pinctrl: airoha: fix pinctrl function mismatch issue 267fdd9b6530c bpf: Reject BPF_MAP_TYPE_INODE_STORAGE creation if BPF LSM is uninitialized 779480ea79551 iommufd: Move vevent memory allocation outside spinlock 73b5d5cb1f5a1 iommufd: Propagate allocation failure in iommufd_veventq_deliver_fetch() ea7a76d7d614b KVM: arm64: nv: Re-translate VNCR before injecting abort 459adfc6cd35f KVM: arm64: Deduplicate ASID retrieval code 9d360fb820a3b samples/damon/mtier: fail early if address range parameters are invalid ec976851ad934 mm/damon/core: trace esz at first setup 3b91c35961fa5 mm/damon/core: always put unsuccessfully committed target pids ba37cd4d8a751 KVM: arm64: Fix propagation of TLBI level in kvm_pgtable_stage2_relax_perms() 19d9996435db8 KVM: arm64: Ensure level is always initialized when relaxing perms c3a3d39867190 btrfs: fix incorrect buffered IO fallback for append direct writes 998ee7f01ecfa btrfs: fix false IO failure after falling back to buffered write a4497a122e27f crypto: qat - fix restarting state leak on allocation failure 6c78081d047c5 btrfs: remove folio parameter from ordered io related functions 1a648c50a5057 btrfs: replace for_each_set_bit() with for_each_set_bitmap() 99d4ae3fbb5b1 btrfs: concentrate the error handling of submit_one_sector() 382fd8004cc60 crypto: atmel-sha204a - fail on hwrng registration error in probe path 952db4b985c79 usb: gadget: f_fs: Tie read_buffer lifetime to ffs_epfile 69faa3779250d usb: gadget: f_fs: initialize reset_work at allocation time 8a2fdbf92cdc7 functionfs: use spinlock for FFS_DEACTIVATED/FFS_CLOSING transitions 5fb0b09180a0f functionfs: switch to simple_remove_by_name() 4744f07f6bb7c functionfs: don't bother with ffs->ref in ffs_data_{opened,closed}() 901c036cf6254 functionfs: don't abuse ffs_data_closed() on fs shutdown c3e6860252102 new helper: simple_remove_by_name() 509b51327320b usb: atm: ueagle-atm: wait for pre-firmware load in .disconnect() b78826a657998 usb: atm: ueagle-atm: remove function entry/exit debug messages 6e5ef54b884f4 usb: atm: ueagle-atm: use dev_dbg() for 'device found' message 41a4e80d5af04 usb: dwc3: fix dwc3_readl() and dwc3_writel() calls in dwc3_ulpi_setup() e534790c4c272 usb: dwc3: Support USB3340x ULPI PHY high-speed negotiation. bce232923aa9e xfs: use bio_reuse in the zone GC code adadb181ad42a xfs: only log freed extents for the current RTG in zoned growfs 47c0e07433021 xfs: add a xfs_groups_to_rfsbs helper 57454944737f3 bpf: Allow LPM map access from sleepable BPF programs 8fccaeeb9e9c5 bpf: Consistently use bpf_rcu_lock_held() everywhere 0b92ad64d6e4b bpf: Keep dynamic inner array lookups nullable c447be8d88c30 bpf: Introduce struct bpf_map_desc in verifier dccb3c557879d bpf: Consistently use reg_state() for register access in the verifier 60eed44674295 xfs: initialize iomap->flags earlier in xfs_bmbt_to_iomap 607217f7ad419 hfs/hfsplus: fix u32 overflow in check_and_correct_requested_length 7676ea09beb5d hfs/hfsplus: prevent getting negative values of offset/length f9b4b03ccc9c6 proc: protect ptrace_may_access() with exec_update_lock (part 1) 07bf18dc63f78 seqlock: Change do_task_stat() to use scoped_seqlock_read() c897fd63762e0 seqlock: Introduce scoped_seqlock_read() 497c6bae51674 proc: protect ptrace_may_access() with exec_update_lock (FD links) 903d78e5aca77 proc: rename proc_setattr to proc_nochmod_setattr b56400364aed5 ksmbd: validate NTLMv2 response before updating session key 74c2f0ffb81c8 ksmbd: Use HMAC-MD5 library for NTLMv2 51c5f7e84cfed ksmbd: Use HMAC-SHA256 library for message signing and key generation bd27d9504d200 ksmbd: Use SHA-512 library for SMB3.1.1 preauth hash 427faaa52b0b3 ksmbd: track the connection owning a byte-range lock 6a37bc484f12e ksmbd: centralize ksmbd_conn final release to plug transport leak c7c884a1305aa ksmbd: fix path resolution in ksmbd_vfs_kern_path_create e205f3e7e8c31 ksmbd: use opener credentials for FSCTL mutations 90a93fb3230c9 cifs: SMB1 split: Add some #includes ff943e1f3d31f cifs: SMB1 split: Rename cifstransport.c 36da806f7fbae Bluetooth: L2CAP: Fix use-after-free in l2cap_sock_new_connection_cb() 6d0eeebe22ba7 Bluetooth: 6lowpan: fix cyclic locking warning on netdev unregister ef382a6baf0a9 media: nxp: imx8-isi: Fix use-after-free on remove 4278953ff0cd4 media: nxp: imx8-isi: use devm_pm_runtime_enable() to simplify code 49cd5ac6de8de crypto: qat - fix VF2PF work teardown race in adf_disable_sriov() 4b51ee8a40fe4 staging: rtl8723bs: fix OOB reads in rtw_get_sec_ie(), rtw_get_wapi_ie(), and rtw_get_wps_attr() 5d76bc296bb58 staging: rtl8723bs: fix spaces around binary operators 48323ebaeeeed staging: rtl8723bs: core: move constants to right side in comparison 73cc54326de45 PCI: Skip Resizable BAR restore on read error f33837a754473 PCI: Move Resizable BAR code to rebar.c 2242c75b63286 PCI: Add kerneldoc for pci_resize_resource() 4b5322f0002aa PCI: Fix restoring BARs on BAR resize rollback path c18646165f21f PCI: Free saved list without holding pci_bus_sem 534f20cdddc31 PCI: Try BAR resize even when no window was released dbb1d8507dd92 PCI: Change pci_dev variable from 'bridge' to 'dev' 0d1c263e6fd73 PCI/IOV: Adjust ->barsz[] when changing BAR size 0dfad346c293e PCI: imx6: Configure REF_USE_PAD before PHY reset for i.MX95 e53d54b92f0c2 PCI: imx6: Fix reference clock source selection for i.MX95 1228926e1e4d6 binder: cache secctx size before release zeroes it 79ac87bb1a4c8 binder: Use LIST_HEAD() to initialize on stack list head 7ed120b1a007b vfio/mlx5: Fix racy bitfields and tighten struct layout f8272331da877 ALSA: hda/tas2781: Cancel async firmware request at unbind 6438d0707087e firmware_loader: Add cancel helper for async requests 1ed7ff33cfc8c ALSA: scarlett2: Update offsets for 2i2 Gen 4 firmware 2417 ad5c5bdb0f580 ALSA: scarlett2: Allow selecting config_set by firmware version 2745574697ee4 iio: hid-sensor-rotation: Fix stale or zero output when reading raw values 7f680924c5c2b ACPI: NFIT: core: Fix possible deadlock and missing notifications cf5f93228e7ab ACPI: NFIT: core: Use devm_acpi_install_notify_handler() d57d2aae87b23 ACPI: bus: Introduce devm_acpi_install_notify_handler() 34f4d0e4e5065 ACPI: driver: Check ACPI_COMPANION() against NULL during probe 3b2628f7682ae ACPI: NFIT: core: Fix acpi_nfit_init() error cleanup 83f29da85dc9d crypto: xilinx-trng - Remove crypto_rng interface f84c0bae0e8dd mmc: sdhci-esdhc-imx: fix resume error handling 174dc8103ab7b mmc: sdhci-esdhc-imx: make non-fatal errors non-blocking in suspend 5b8f11cbe8ad5 mmc: sdhci-esdhc-imx: use pm_runtime_resume_and_get() in suspend 4f96903e2fd22 mmc: sdhci-esdhc-imx: disable irq during suspend to fix unhandled interrupt aa276aa6cbfbc mmc: sdhci-esdhc-imx: fix esdhc_change_pinstate() to allow default state restore 52990f6b57526 mmc: sdhci-esdhc-imx: restore DLL override for DDR modes on resume eefcd3ca245c1 mmc: sdhci-esdhc-imx: remove unnecessary mmc_card_wake_sdio_irq check for tuning save/restore c02237966c199 mmc: sdhci-of-dwcmshc: check bus clock enable result in the probe() method 8d94498cc4453 mmc: block: fix RPMB device unregister ordering cf7258f57d180 mtd: rawnand: lpc32xx_slc: fail DMA transfer on completion timeout 4b5de4007e5bf mtd: rawnand: lpc32xx_mlc: fail DMA transfers on timeout de2bc884d8870 mtd: rawnand: fsl_ifc: return errors for failed page reads bf9848a22a8e5 mmc: vub300: defer reset until cmd_mutex is unlocked 04ebd3766861f mtd: mchp23k256: use SPI match data for chip caps ac2d9f6b4f905 mtd: onenand: samsung: report DMA completion timeouts a59cfa165aee3 wifi: mwifiex: fix permanently busy scans after multiple roam iterations b8df3a993f690 wifi: mac80211: free ack status frame on TX header build failure 90576bd6921a9 wifi: ieee80211: validate MLE common info length 584657c5fc58d wifi: cfg80211: validate EHT MLE before MLD ID read 3c1e92f75e11a powerpc/spufs: fix out-of-bounds access in spufs_mem_mmap_access() 82753ac86cb3d reset: sunxi: fix memory region leak on ioremap failure 3fb7edd2018bb ipvs: reload ip header after head reallocation d4ec18f48ce78 ipvs: fix more places with wrong ipv6 transport offsets 39151f0708c84 memstick: ms_block: reject a card that reports too many blocks a75d2b5249e38 macsec: fix promiscuity refcount leak in macsec_dev_open() fd701fc0d0652 llc: fix SAP refcount leak when creating incoming sockets 6744ab60dfac5 Bluetooth: btrtl: validate firmware patch bounds dbd14f736be02 net: openvswitch: reject oversized nested action attrs 6926d13865aaa regulator: ltc3676: Fix incorrect IRQSTAT bit offsets 688bd4c6144d2 riscv: vdso: Do not use LTO for the vDSO 55b26abb1fa1e wifi: brcmfmac: cyw: fix heap overflow on a short auth frame bdc0b8bfdc142 wifi: mac80211: fix memory leak in ieee80211_register_hw() 65446b85595a4 wifi: mwifiex: fix roaming to different channel in host_mlme mode 816559409e340 wifi: rt2x00: avoid full teardown before work setup in probe 262da8b6ea03d net/mlx5: free mlx5_st_idx_data on final dealloc 9b8df4da2cf79 powerpc/pseries: fix memory leak on krealloc failure in papr_init afa0db5322c5f mmc: sdhci-esdhc-imx: restore pinctrl before restoring ios timing on resume d94160a5d1ac3 selftests/landlock: Fix screwed up pointers in the scoped_signal_test ba481c0b53760 selftests/landlock: Skip scoped_signal subtest with MSG_OOB if not available 4ff3960f35271 pmdomain: imx: Fix i.MX8MP VC8000E power up sequence 9a0464fcfae4f pmdomain: imx: Fix i.MX8MP power notifier c844b7d9a9586 cgroup/cpuset: rebind mm mempolicy to effective_mems, not mems_allowed 8131a91fe2dea selftests/rseq: Fix a building error for riscv arch 3dfec7490f3a2 s390/mm: Fix type mismatch in get_align_mask(). c6b4d454865a8 s390/diag: Add missing array_index_nospec() call to memtop_get_page_count() fad36954b2959 tracing/osnoise: Call synchronize_rcu() when unregistering eadd0c2c76aee riscv: Prevent NULL pointer dereference in machine_kexec_prepare() 38cc4867540ae drbd: reject data replies with an out-of-range payload size 91ec52dd2a5d9 ata: libata-core: Allow capacity transition to zero for locked drives 7a9a69641b68a ata: libata-core: Skip HPA resize for locked drives 52007bfdce531 fs/resctrl: Fix double-add of pseudo-locked region's RMID to free list 1155a9d0a2e0d fs/resctrl: Free mon_data structures on rdt_get_tree() failure ccdf1770a4ba2 cpu/hotplug: Fix NULL kobject warning in cpuhp_smt_enable() 5f5783c7806fc arm64: smp: Fix hot-unplug tearing by forcing unregistration 26b131b2d5b55 net: macb: drop in-flight Tx SKBs on close b2f426a9a2288 dibs: loopback: validate offset and size in move_data() 2cf10d0425622 macsec: don't read an unset MAC header in macsec_encrypt() 83fb4c2c5344f ipvs: reset full ip_vs_seq structs in ip_vs_conn_new 247d055504dcc ipvs: use parsed transport offset in SCTP state lookup 61a7ff4a62003 llc: fix SAP refcount leak in llc_ui_autobind() 685fb410d90e5 selftests: net: make busywait timeout clock portable 5df30f05db965 octeontx2-pf: fix SQB pointer leak on init failure 77caf2d6eba7c mac802154: remove interfaces with RCU list deletion f0745496f7c17 s390/monwriter: Reject buffer reuse with different data length a5a367756926d irqchip/irq-riscv-imsic-early: Fix fwnode leak on state setup failure 018d7ad26cb8b mm/compaction: handle free_pages_prepare() properly in compaction_free() 2faf0198168d2 riscv: probes: save original sp in rethook trampoline d8d4fa0c4f818 hwmon: (asus_atk0110) Check package count before accessing element 07f5eb6d268a3 net: wwan: iosm: bound device offsets in the MUX downlink decoder 1286a41563337 ata: pata_pxa: Fix DMA channel leak on probe error 1dce4f4bb3c1c net/mlx5: HWS, fix matcher leak on resize target setup failure 82fc886e244c7 orangefs: keep the readdir entry size 64-bit in fill_from_part() 2c76c01a505c1 tracing/probes: Fix double addition of offset for @+FOFFSET b4427ee3667c5 hwmon: (max1619) add missing 'select REGMAP' to Kconfig 6c52226072a3c fhandle: reject detached mounts in capable_wrt_mount() e2b7ee61989f2 net/sched: sch_taprio: Replace direct dequeue call with peek and qdisc_dequeue_peeked 5889064919a1e net/sched: sch_multiq: Replace direct dequeue call with peek and qdisc_dequeue_peeked 99a6f37b113c4 net: lan743x: Initialize eth_syslock spinlock before use ac58088d70b8a fsl/fman: Free init resources on KeyGen failure in fman_init() f0aad157576da hwmon: (occ) unregister sysfs devices outside occ lock 715cce38424fb net: liquidio: fix BAR resource leak on PF number failure 664480021f6a4 hwmon: (w83793) remove vrm sysfs file on probe failure c6c990f7208c9 hwmon: (w83627hf) remove VID sysfs files on error and remove 8dc6c7e8c9678 rtc: mpfs: fix counter upload completion condition 6e21d1253ef13 rtc: renesas-rtca3: Fix PIE clear polling condition in alarm setup error path 6c98ccdb9a096 bnx2x: fix potential memory leak in bnx2x_alloc_mem_bp() f5c5065963024 ipmi: fix refcount leak in i_ipmi_request() a66d45e0ce6d7 espintcp: use sk_msg_free_partial to fix partial send ddbb6e3dc9bb4 ipmi: Fix user refcount underflow in event delivery a65f49b6f7ece LoongArch: Fix missing dirty page tracking in {pte,pmd}_wrprotect() 20ac8131f8c90 LoongArch: Fix nr passing in set_direct_map_valid_noflush() 612cda6630f2e pwm: rzg2l-gpt: Fix period_ticks type from u32 to u64 4b73889941b95 selftests/bpf: Add simple strscpy() implementation da7f17c2d5bb4 KVM: TDX: Account all non-transient page allocations for per-TD structures d0cc2c74060be drm/xe/userptr: Stub notifier_lock helpers when DRM_GPUSVM=n 6cec36c795c03 net/sched: sch_teql: move rcu_read_lock()/spin_lock() from _bh variants 55da782eb4545 platform/x86/amd/pmc: Avoid logging "(null)" for DMI values 35267819b2507 gve: fix header buffer corruption with header-split and HW-GRO 2059c28bd725b ieee802154: ca8210: fix pointer truncation in kfifo on 64-bit cb5cca1d2a908 ieee802154: ca8210: fix cas_ctl leak on spi_async failure 314f21c9dd0dc ieee802154: allow legacy LLSEC ADD/DEL ops to pass strict validation 1905ebabe638c ieee802154: admin-gate legacy LLSEC dump operations 19c148cb82d11 octeontx2-af: Free BPID bitmap on setup failure 234cd54fc500f net: ip6_tunnel: require CAP_NET_ADMIN in the device netns for changelink 03d8843b143eb net: ip6_gre: require CAP_NET_ADMIN in the device netns for changelink 68cadc3698c7d net: ipip: require CAP_NET_ADMIN in the device netns for changelink 9571af2eec802 net: ip_vti: require CAP_NET_ADMIN in the device netns for changelink 0b2f9c908f930 net: ip6_vti: require CAP_NET_ADMIN in the device netns for changelink 6596baf804110 net: ena: clean up XDP TX queues when regular TX setup fails ab625256882e0 selftests: net: fix file owner for broadcast_ether_dst test b3d8354078461 net/sched: act_ct: preserve tc_skb_cb across defragmentation 3f85fcd520aa7 net: ixp4xx_hss: fix duplicate HDLC netdev allocation e89b8829693e6 net: wwan: t7xx: destroy DMA pool on CLDMA late init failure 121c5f31c3fb7 net: ethernet: ti: icssg: guard PA stat lookups 3118e97dae533 net: sit: require CAP_NET_ADMIN in the device netns for changelink 5d7bd8790309b gpios: palmas: add .get_direction() op d3b9026ef78da gpio: mt7621: avoid corruption of shared interrupt trigger state 4e16bc75c7502 gpio-f7188x: Add support for NCT6126D version B b6e040b5143cc gpio: mt7621: be sure IRQ domain is created before exposing GPIO chips ac761e66708d5 gpio: tegra: do not call pinctrl for GPIO direction 0630f2c3c16c0 gpio: mt7621: more robust management of IRQ domain teardown 6cb15b81ff545 cpu: hotplug: Bound hotplug states sysfs output f77117530fc3f cpu: hotplug: Preserve per instance callback errors afd147e59b32a selftests/ftrace: Drop invalid top-level local in test_ownership ea6a188ee805e posix-cpu-timers: Use u64 multiplication in update_rlimit_cpu() 633cadbc0b832 locking/rt: Fix the incorrect RCU protection in rt_spin_unlock() fcff712d0e3d1 wifi: libertas_tf: fix use-after-free in lbtf_free_adapter() b33ac2d39953e tracing/user_events: Fix use-after-free in user_event_mm_dup() ed3cc4218070d net/mlx5e: macsec: fix use-after-free of metadata_dst on RX SC delete 0e8115a7ed9a9 Input: ims-pcu - fix type confusion in CDC union descriptor parsing f516cba88bf95 Input: ims-pcu - fix race condition in reset_device sysfs callback 383934c249a98 Input: ims-pcu - fix potential infinite loop in CDC union descriptor parsing 9c964fc9507ae Input: ims-pcu - fix out-of-bounds read in ims_pcu_irq() debug logging 99c428d7ef644 Input: ims-pcu - fix firmware leak in async update 05ac85da12198 Input: ims-pcu - fix DMA mapping violation in line setup f28c5cabb2df0 Input: ims-pcu - add response length checks c8d3d83f2eaaf Input: ims-pcu - validate control endpoint type 6329d1af316a4 Input: ims-pcu - release data interface on disconnect 87e2f89dea078 Input: ims-pcu - only expose sysfs attributes on control interface 6aacc18004b1a Input: ims-pcu - fix use-after-free and double-free in disconnect df87532e92122 scsi: elx: efct: Fix I/O leak on unsupported additional CDB 9b871369cbb45 scsi: elx: efct: Fix refcount leak in efct_hw_io_abort() cb7bdae7fba40 scsi: target: core: Fix iSCSI ISID use-after-free in REGISTER AND MOVE 004ccd2d3b4ac scsi: target: Bound PR-OUT TransportID parsing to the received buffer f1516c56ac540 scsi: xen: scsiback: Free unsubmitted command instead of double-putting it 255fb7b0cdc94 scsi: xen: scsiback: Free the command tag on the TMR submit-failure path d0a8a6660d58e scsi: sg: Report request-table problems when any status is set ed08497977820 scsi: lpfc: Fix memory leak in lpfc_sli4_driver_resource_setup() d495b403d5b35 scsi: hpsa: Fix DMA mapping leak on IOACCEL2 reset path 257321a1c036d accel/ivpu: Reject firmware log with size smaller than header 4e370b5289624 accel/amdxdna: Fix use-after-free in amdxdna_gem_dmabuf_mmap() 7aa8f3dba5342 dma-fence: Make dma_fence_dedup_array() robust against 0-count input 089e05b644d5a dm-verity: make error counter atomic c8d743bb0e98a dm-verity: increase sprintf buffer size f15eaa3801f2f dm-verity: fix a possible NULL pointer dereference 2a0858cba1dab dm-verity: avoid double increment of &use_bh_wq_enabled 5dfd804263527 dm-integrity: don't increment hash_offset twice aa5113e7155f4 dm-integrity: fix a bug if the bio is out of limits 0c4e9bb1d4101 dm-integrity: fix leaking uninitialized kernel memory 92e3c93d60be1 dm_early_create: fix freeing used table on dm_resume failure ee458c3c18343 dm-stats: fix merge accounting 461d36b5ddafc dm-stats: fix dm_jiffies_to_msec64 1247615aadb74 dm-pcache: reject option groups without values e0b0163a65758 dm-log: fix a bitset_size overflow on 32bit machines d61c12573ed97 dm-ioctl: fix a possible overflow in list_version_get_info 021dab70eb37d dm-bufio: fix wrong count calculation in dm_bufio_issue_discard 1fcb5e29dd7a5 dm era: fix out-of-bounds memory access for non-zero start sector 7f76245960a33 dm thin metadata: fix metadata snapshot consistency on commit failure ac2136dc4441d dm thin metadata: fix superblock refcount leak on snapshot shadow failure 8a3c44a003176 net: sparx5: unregister blocking notifier on init failure ffd17a393921a block: fix IORING_URING_CMD_REISSUE flags check in blkdev_uring_cmd 2977b5fe401c1 block: fix race in blk_time_get_ns() returning 0 af382ffca93e5 block: remove redundant GD_NEED_PART_SCAN in add_disk_final() 0b6252afcd196 bpf: Add missing access_ok call to copy_user_syms c4f626ddf2350 bpf,fork: wipe ->bpf_storage before bailouts that access it 0993dc5fc619c bpf: Reset register bounds before narrowing retval range in check_mem_access() b06a4a397ac82 can: bcm: add missing rcu list annotations and operations 35f0ac19efb1a can: bcm: fix lockless bound/ifindex race and silent RX_SETUP failure cd830e0bc25ee can: bcm: defer rx_op deallocation to workqueue to fix thrtimer UAF 37beb16e08cae can: isotp: serialize TX state transitions under so->rx_lock 7bef39ba76eb7 can: isotp: fix use-after-free race with concurrent NETDEV_UNREGISTER b88a511308779 can: isotp: use unconditional synchronize_rcu() in isotp_release() 765ba1c91823a can: esd_usb: kill anchored URBs before freeing netdevs 5e4c8e08ce957 netdev-genl: report NAPI thread PID in the caller's pid namespace 26355295ce21c nvmet: fix refcount leak in nvmet_sq_create() 2944113ad5fbc nvmet-rdma: handle inline data with a nonzero offset 2eaa3ad450141 nvmet-auth: reject short AUTH_RECEIVE buffers 59cef6abc924a nvme-apple: Prevent shared tags across queues on Apple A11 0ffc032294a29 NFS: Charge unstable writes by request size, not folio size ebe0a55d954fa sctp: validate STALE_COOKIE cause length before reading staleness d44b828eb551b spi: uniphier: Fix completion initialization order before devm_request_irq() 9b092f9e6b34d time: Fix off-by-one in compat settimeofday() usec validation ada4b9a5087ea tpm: Make the TPM character devices non-seekable 95bdf3950d668 tpm: fix event_size output in tpm1_binary_bios_measurements_show 8ca2a19a987a7 xfrm: xfrm_interface: require CAP_NET_ADMIN in the device netns for changelink e0f688ccb20f1 xfrm: use compat translator only for u64 alignment mismatch 5b0c4c916f202 xfrm: nat_keepalive: avoid double free on send error 16d3ccdabb8de xen/gntdev: fix error handling in ioctl e497fef9ad7e9 ufs: core: tracing: Do not dereference pointers in TP_printk() 0ced34b4bbc04 tcp: Decrement tcp_md5_needed static branch 33a1bee413628 tcp: defer md5sig_info kfree past RCU grace period in tcp_connect bccae122dab8f ice: fix ice_init_link() error return preventing probe 8bd84316bbaf3 i2c: spacemit: fix spurious IRQ handling returning IRQ_HANDLED e6a395a71f465 i2c: mlxbf: Fix use-after-free in mlxbf_i2c_init_resource() 2f3f471a448a5 i2c: mediatek: fix WRRD for SoCs without auto_restart option 5d3240f42a667 i2c: imx: fix locked bus on SMBus block-read of 0 (IRQ) 6d2c973926d06 i2c: imx: fix locked bus on SMBus block-read of 0 (atomic) 500716a007b2e hwmon: (max6697) add missing 'select REGMAP_I2C' to Kconfig 1dcd7565e5909 hwmon: (ltc2992) add missing 'select REGMAP_I2C' to Kconfig 3cd6f93f3d593 ksmbd: fix integer overflow in set_file_allocation_info() 6cc1518357369 smb: client: use kvzalloc() for megabyte buffer in simple fallocate fe623f9515bb0 pkey: Move keytype check from pkey api to handler eafc5aca71564 platform/x86/amd/pmc: Don't log during intermediate wakeups e628d9169f9e1 platform/x86/amd/pmc: Add delay_suspend module parameter 27d16a19ae74f platform/x86/amd/pmc: Delay suspend for some Lenovo Laptops d8bc45c4c1a45 platform/x86/amd/pmc: Check for intermediate wakeup in function cea03d67db3a8 platform/x86: ISST: Restore SST-PP control to all domains 1e41ca4a7fba2 platform/x86: dell-laptop: fix missing cleanups in init error path ddbc4a8a4fe29 dmaengine: dw-edma: Add spinlock to protect DONE_INT_MASK and ABORT_INT_MASK 7926c1e4be863 dmaengine: tegra: Fix burst size calculation 933654508b2bc sunrpc: fix uninitialized xprt_create_args structure 934d1cd40e289 tpm: tpm2-sessions: wait for async KPP completion in tpm_buf_append_salt ba33b4f9d3423 tpm: tpm_tis_spi: Use wait_woken() in wait_for_tmp_stat() 781f28bd982cf tpm: restore timeout for key creation commands 36ca587f55a2c irqchip/crossbar: Use correct index in crossbar_domain_free() 0d078152fcab7 taskstats: retain dead thread stats in TGID queries 9ac007affa77c mtd: maps: vmu-flash: fix NULL pointer dereference in initialization 3fac46068fe4c openrisc: Fix jump_label smp syncing ff7bcc9d71bf4 mtd: rawnand: Pause continuous reads at block boundaries 0fd20c1905abc mtd: spi-nor: spansion: use die erase for multi-die devices only c0806df5cf806 mtd: spi-nor: swp: Improve locking user experience 433e5e70cdc1e s390/pkey: Check length in pkey_pckmo handler implementation 693bf91d4db13 s390/pkey: Check length in PKEY_VERIFYPROTK ioctl c9ef79e34bc1e fpga: microchip-spi: fix zero header_size OOB read in mpf_ops_parse_header() e5824d5b841d9 net: thunderbolt: Fix frags[] overflow by bounding frame_count fc74244e0cc25 bus: mhi: ep: Protect mhi_ep_handle_syserr() in the error path 3ebe0ee6527e8 bus: mhi: host: pci_generic: Fix the physical function check 012683accbb7d fpga: dfl: add bounds check in dfh_get_param_size() 2174c68f623b7 ocfs2: reject non-inline dinodes with i_size and zero i_clusters 5e512d370a01b ocfs2: reject dinodes whose i_rdev disagrees with the file type 4db3b6a2a8ecf ocfs2: reject dinodes with non-canonical i_mode type 499714de42ab4 ocfs2: add journal NULL check in ocfs2_checkpoint_inode() 671889c553ea5 ocfs2: fix UBSAN array-index-out-of-bounds in ocfs2_sum_rightmost_rec bd73971fad89d ocfs2: fix NULL h_transaction deref in ocfs2_assure_trans_credits d5d5a21fb33cd ocfs2: avoid moving extents to occupied clusters 4bbfcf9c7e46c mtd: rawnand: fix condition in 'nand_select_target()' a8874c34c4a97 net/9p: fix infinite loop in p9_client_rpc on fatal signal ace3a0c839f3b mtd: rawnand: pl353: fix probe resource allocation b6337e3687d3d ocfs2: use kzalloc for quota recovery bitmap allocation bf53557a96d4c openrisc: Add full instruction cache invalidate functions 8d263bae573dc scsi: sas: Skip opt_sectors when DMA reports no real optimization hint 83405848e4030 scsi: smartpqi: Use shost_to_hba() in pqi_scan_finished() a7bbf83dfebdc power: supply: bq257xx: Fix VSYSMIN clamping logic 8d610017c992d 9p: skip nlink update in cacheless mode to fix WARN_ON d8dcbbfa0d695 mtd: slram: remove failed entries from the device list 4e4beef747c68 kcov: use WRITE_ONCE() for selftest mode stores da5234df09416 mm/mm_init: fix uninitialized struct pages for ZONE_DEVICE 749e2051da3b0 powerpc/dt_cpu_ftrs: Set CPU_FTR_P11_PVR for Power11 and later processors 07ed8b1785480 fs/proc: fix KPF_KSM reported for all anonymous pages b6a6fb6803d52 proc: only bump parent nlink when registering directories 4d67bdef35c32 fs/proc/task_mmu: use huge_page_size() in pagemap_scan_hugetlb_entry() 43b987ed35be9 fs/proc/task_mmu: fix hugetlb self-deadlock in pagemap_scan_pte_hole() 40a04601a3f66 mm/damon/sysfs-schemes: put stats for scheme_add_dirs() internal error f18c561eb9c51 mm/damon/sysfs-schemes: fix dir put orders in access_pattern_add_dirs() f322955d9a1c3 riscv: cacheinfo: Fix node reference leak in populate_cache_leaves 1caee6e084a96 mips: sched: Fix CPUMASK_OFFSTACK memory corruption bd2e9be9ebb64 selftests/landlock: Test SCOPE_SIGNAL on the SIGIO/fowner pgid path 193e6471e985c power: supply: charger-manager: fix refcount leak in is_full_charged() 1f18aac263722 landlock: Fix LANDLOCK_SCOPE_SIGNAL bypass on the SIGIO path ff05a98150ebb ntfs3: fix out-of-bounds read in decompress_lznt f3624cc069195 ntfs3: validate split-point offset in indx_insert_into_buffer aaa1f956c0fc4 ntfs3: bound to_move in indx_insert_into_root before hdr_insert_head 0fad25687d4d3 ntfs3: cap RESTART_TABLE free-chain walker at rt->used be306b8d9143a fs/ntfs3: bound NTFS_DE view.data_off in UpdateRecordData{Root,Allocation} 908c9243ba309 fs/ntfs3: add depth limit to indx_find_buffer to prevent stack overflow 7adb38279812c fs/ntfs3: validate lcns_follow in log_replay conversion 50b5e83384e7f fs/ntfs3: bound attr_off in UpdateResidentValue against data_off d240cd98f5f7b fs/ntfs3: bound copy_lcns dp->page_lcns[] index in analysis pass 09fddd52c1b0c fs/ntfs3: bound DeleteIndexEntryAllocation memmove length ccd6b70798737 fs/ntfs3: fix syncing wrong inode on DIRSYNC cross-directory rename 640627f07c79b mm/damon/core: make charge_addr_from aware of end-address exclusivity 722e6c54bde63 mm/memory_hotplug: fix incorrect altmap passing in error path 1697d253f51cf mm/hugetlb: fix hugetlb cgroup rsvd charge/uncharge mismatch 9227b387eee50 power: supply: max17042: fix OF node reference imbalance a3d81de441233 power: supply: cpcap-battery: Fix missing nvmem_device_put() causing reference leak a39d281f207b9 mm/mm_init: fix pageblock migratetype for ZONE_DEVICE compound pages d3fd2d358df0c MIPS: DEC: Ensure 32-bit stack location for o32 prom_printf() 11a3bc25f2c30 MIPS: ip22-gio: fix device reference leak in probe 2c551f14f55e4 MIPS: ip22-gio: fix kfree() of static object 620a37ea7d626 MIPS: ip22-gio: fix gio device memory leak 51aad3d89a2dd remoteproc: qcom: Fix leak when custom dump_segments addition fails 69e18135e2a00 SUNRPC: Bound-check xdr_buf_to_bvec() stores before writing 46d59ff421824 lockd: Plug nlm_file refcount leak on cached nlm_do_fopen() failure 1161c4b5bd004 lockd: Plug nlm_file leak when nlm_do_fopen() fails 66014ab165cb0 sunrpc: harden rq_procinfo lifecycle to prevent double-free 65b23bec1fca6 sunrpc: wait for in-flight TLS handshake callback when cancel loses race 3f9ee75a97a76 sunrpc: pin svc_xprt across the asynchronous TLS handshake callback 30d490bb2c4cd nvdimm/btt: Free arena sub-allocations on discover_arenas() error path f4ca396bdd60b nvdimm/btt: Free arenas on btt_init() error paths 78955fdce8ff6 jbd2: fix integer underflow in jbd2_journal_initialize_fast_commit() 7199c78c3a3e3 Bluetooth: SCO: hold sk properly in sco_conn_ready 77eb0cf57009e Bluetooth: SCO: fix sleeping under spinlock in sco_conn_ready 96dd35f1942cd HID: playstation: validate num_touch_reports in DualShock 4 reports 88ba845468508 mfd: tps6586x: Fix OF node refcount d8e2f3e1bc207 cifs: invalidate cfid on unlink/rename/rmdir 3256c05d5a9db batman-adv: tt: prevent TVLV OOB check overflow d2b657c9653fc batman-adv: mcast: avoid OOB read of num_dests header a90f4fff90253 batman-adv: frag: fix primary_if leak on failed linearization c945f6007e785 batman-adv: clean untagged VLAN on netdev registration failure 8f54162e07d3e batman-adv: frag: free unfragmentable packet 2c989ab8e2054 batman-adv: fix VLAN priority offset 6a65ac8a81e90 batman-adv: tt: avoid request storms during pending request ee878decf9e57 batman-adv: dat: fix tie-break for candidate selection 9e16b6751a820 batman-adv: ensure minimal ethernet header on TX 8f76277d02176 batman-adv: dat: ensure accessible eth_hdr proto field e5e18886aadd3 batman-adv: bla: reacquire gw address after skb realloc 3b4c70c40f2e1 batman-adv: dat: acquire ARP hw source only after skb realloc b8afcf799b2cc batman-adv: access unicast_ttvn skb->data only after skb realloc 85a71a81854e0 batman-adv: retrieve ethhdr after potential skb realloc on RX e6b43acd34b21 batman-adv: gw: acquire ethernet header only after skb realloc fa1ebae4206e6 s390/perf_cpum_cf: Add missing array_index_nospec() to __hw_perf_event_init() 8514585aa9553 cpufreq: intel_pstate: Set non-turbo capacity to HWP_GUARANTEED_PERF() 221ee479a49fb cpufreq: schedutil: Fix uncleared need_freq_update on the .adjust_perf() path 5ab0eba9c8819 perf/x86/amd/lbr: Fix kernel address leakage 046f6244da9b6 perf/x86/amd/brs: Fix kernel address leakage 394e2bdf7594e x86/boot: Reject too long acpi_rsdp= values f7c67c97b37c1 x86/boot: Validate console=uart8250 baud rate to fix early boot hang 1a1d6e3ef6cf5 x86/video: Only fall back to vga_default_device() without screen info 19ffeb30fdfce tools/power/x86/intel-speed-select: Harden daemon pidfile open 16a42c88c4667 mfd: sm501: Fix reference leak on failed device registration 6dd51d84a9502 leds: uleds: Fix potential buffer overread 3a134c3fb5f0d selinux: fix incorrect execmem checks on overlayfs d61a80b17254b selinux: avoid sk_socket dereference in selinux_sctp_bind_connect() fc633a598206d selinux: check connect-related permissions on TCP Fast Open e9cdf741ffcb4 soc: fsl: qe: panic on ioremap() failure in qe_reset() c6854d9f4e1bd soc: ti: k3-ringacc: Fix access mode for k3_ringacc_ring_pop_tail_io/proxy c4d6442ac3ed0 gpu: host1x: Fix device reference leak in host1x_device_parse_dt() error path 1c4f67c89fd27 netfilter: bridge: fix stale prevhdr pointer in br_ip6_fragment() 679ced28a9dc2 netfilter: xt_nat: reject unsupported target families b2dbbedfa935c netfilter: ecache: fix inverted time_after() check 3cd9a5792cbea netfilter: nf_conncount: fix zone comparison in tuple dedup a58230f3a7c4f netfilter: nf_conntrack_reasm: guard mac_header adjustment after IPv6 defrag 2bcf2c5052fb5 netfilter: nf_nat_sip: reload possible stale data pointer 02b6b0e892aea netfilter: nft_set_pipapo: don't leak bad clone into future transaction 0ca505346c5e2 netfilter: nf_queue: pin bridge device while NFQUEUE holds fake dst 07f9ddbf5e799 netfilter: xt_cluster: reject template conntracks in hash match a1b672a3b5372 netfilter: nfnl_cthelper: apply per-class values when updating policies aff589556ed77 netfilter: nf_conntrack_irc: fix parse_dcc() off-by-one OOB read ca028334343a1 ASoC: qcom: q6apm: fix NULL pointer dereference in graph_callback e42d8322b67f2 ASoC: mediatek: mt8183: Release reserved memory on cleanup 4b068759d3087 ASoC: mediatek: mt8183: Check runtime resume during probe 51c367230e30e ASoC: mediatek: mt8192: Release reserved memory on cleanup e0f276f1918a2 ASoC: mediatek: mt8192: Check runtime resume during probe d3abaedf6a584 ASoC: SOF: ipc3-control: Validate size in snd_sof_update_control 121577383b5cf ASoC: SOF: ipc3-control: Fix heap overflow in bytes_ext put/get 4ebe2c3a7db63 fbdev: tridentfb: fix potential memory leak in trident_pci_probe() 009a8514745b1 fbdev: nvidia: fix potential memory leak in nvidiafb_probe() 58bc18e03481b fbdev: vesafb: fix memory leak in vesafb_probe() d81860691e4cf fbdev: carminefb: fix potential memory leak in alloc_carmine_fb() e1ca9b8559e0f fbdev: tdfxfb: fix potential memory leak in tdfxfb_probe() 12fe6a56506ed fbdev: uvesafb: fix potential memory leak in uvesafb_probe() ad54698255a4b fbdev: s3fb: fix potential memory leak in s3_pci_probe() 146b708bc75f1 fbdev: i740fb: fix potential memory leak in i740fb_probe() c2c795a320e7e fbdev: radeon: fix potential memory leak in radeonfb_pci_register() febb5b4f67ace fbdev: efifb: fix memory leak in efifb_probe() 9423e1f105270 fbdev: sm712: Fix operator precedence in big_swap macro d684ce2db92b1 fbdev: hecubafb: fix potential memory leak in hecubafb_probe() e8c9aae8c9508 fbdev: broadsheetfb: fix potential memory leak in broadsheetfb_probe() 6854cf33dddb2 fbdev: metronomefb: fix potential memory leak in metronomefb_probe() d5436e18e4fc2 KVM: arm64: nv: Inject SEA if guest VNCR isn't normal memory 4ead4def04659 KVM: arm64: nv: Inject SEA if kvm_translate_vncr() can't resolve PFN 5c50db5bcbb90 KVM: arm64: nv: Respect read-only PFN when mapping L1 VNCR 884b44256041e KVM: arm64: nv: Fix SPSR_EL2 restore in kvm_hyp_handle_mops() 09f35145f3a4a KVM: arm64: nv: Write ESR_EL2 for injected nested SError exceptions 5000bcae71c86 KVM: arm64: nv: Drop bogus WARN for write to ZCR_EL2 7099e7148f81c KVM: Move kvm_io_bus_get_dev() locking responsibilities to callers 7996013b85687 KVM: nVMX: Put vmcs12 pages if nested VM-Enter fails due to invalid guest state d1379888cc423 KVM: x86: Nullify irqfd->producer if updating IRTE for bypass fails 97542f15dc4cf KVM: x86: Ignore pending PV EOI if the vCPU has since disabled PV EOIs ba06690b28be9 KVM: SEV: Do not allow intra-host migration/mirroring of SNP VMs df72596278b0e KVM: s390: pci: Fix handling of AIF enable without AISB d19dca8194ebe KVM: arm64: vgic: Handle race between interrupt affinity change and LPI disabling 79fdd2aa774e4 KVM: arm64: vgic: Check the interrupt is still ours before migrating it 5fb75c5272950 KVM: s390: pci: Fix GISC refcount leak on AIF enable failure 9f8eaef40e955 powerpc/pseries/Kconfig: Enable CONFIG_VPA_PMU to be used with KVM 33d79ad6ecedf LoongArch: KVM: Return full old CSR value from kvm_emu_xchg_csr() f3efcef6648ba LoongArch: KVM: Fix FPU register width with user access API 45f2e6505fcf6 LoongArch: KVM: Check the return values for put_user() efe27b19a15c3 LoongArch: KVM: Check irq validity in kvm_vcpu_ioctl_interrupt() 199b570d7fca1 LoongArch: KVM: Validate irqchip index in irqfd routing 1ee200a1764f8 ARM: dts: stm32: stm32mp15x-mecio1-io: Move expander gpio-line-names to board files f550bf32b9a06 ARM: dts: stm32: stm32mp15x-mecio1-io: Fix expander gpio line typo 7da4d1a6b7400 ARM: dts: stm32: stm32mp15x-mecio1-io: Move gpio-line-names to board files 804821b69b2d1 ARM: dts: stm32: stm32mp15x-mecio1-io: Fix GPIO names typo c632a27f35cff arm64: dts: imx8ulp-evk: Correct Type-C int GPIO flags bd938c985ab34 ARM: dts: stm32: stm32mp15x-mecio1-io: Enable internal ADC reference ead9f10428c73 arm64: dts: ti: k3-am62a7-sk: Add bootph-all tag to vqmmc a98bda2305f3f ARM: dts: stm32: stm32mp15x-mecio1-io: Move divergent mecio1 ADC channels to board files 4fd52ac541ce1 ARM: dts: stm32: stm32mp15x-mecio1-io: Fix ADC sampling times 68f9773754f05 arm64: dts: rockchip: fix Ethernet PHY not found on PX30 Ringneck e2e3fb995175c arm64: dts: qcom: sdm630: describe adsp_mem region properly 508e55e81870d ARM: dts: imx6ul-var-som: fix warning for non-existent dc-supply property e8dc96a42571e arm64: dts: s32g3: Fix SWT8 watchdog address 89edae4161412 arm64: fpsimd: Fix type mismatch in sve_{save,load}_state() 5526d1997aea6 net: ife: require ETH_HLEN to be pullable in ife_decode() 908391d801b24 octeontx2-vf: clear stale mailbox IRQ state before request_irq() eebf439aa7a13 octeontx2-pf: clear stale mailbox IRQ state before request_irq() e62adb157c2ea net: atm: reject out-of-range traffic classes in QoS validation 22100a8f73d4a net: qrtr: fix 32-bit integer overflow in qrtr_endpoint_post() 61a55fa24a5d7 tipc: restrict socket queue dumps in enqueue tracepoints d34deef34c99b ASoC: SOF: topology: validate vendor array size before parsing 0c4fbdaca225b ASoC: SOF: ipc3-control: Fix TOCTOU in bytes_put and bytes_get 711d912b18763 ASoC: SOF: ipc3-control: Use overflow checks in control_update size calc fb4293173db2d ASoC: SOF: ipc4-control: Fix TOCTOU in sof_ipc4_bytes_put d8715b5a8fdb2 vduse: Fix race in vduse_dev_msg_sync and vduse_dev_read_iter 3a2b47d1b4b3d mlxsw: fix refcount leak in mlxsw_sp_vrs_lpm_tree_replace() 2d8b3c3e12997 mlxsw: fix refcount leak in mlxsw_sp_port_lag_join() b65e46eed9e52 idpf: add padding to PTP virtchnl structures 1627e7d5c9b09 smb: client: fix overflow in passthrough ioctl bounds check 327595e7c34e3 drm/xe: remove duplicate include 3de77d2f34c2b octeontx2-af: fix VF bringup affecting PF promiscuous state ee3f7566bcf33 net/mlx5: Fix L3 tunnel entropy refcount leak 1550b07bca2bb selftests/net: fix EVP_MD_CTX leak in tcp_mmap 346e2d666a29a regulator: core: regulator_lock_two() should test for EDEADLK not EDEADLOCK 14e03ecd3b1b5 dm era: fix NULL pointer dereference in metadata_open() 5b0427ba582d1 SUNRPC: pin upper rpc_clnt across the TLS connect_worker 13965a7b190f3 SUNRPC: release lower rpc_clnt if killed waiting for XPRT_LOCKED b784cd1c24d89 cifs: validate DFS referral string offsets df0e3e70f6995 s390/zcrypt: Remove the empty file 8f48cfe657409 ipvs: ensure inner headers in ICMP errors are in headroom 7510451a58c27 ipvs: fix PMTU for GUE/GRE tunnel ICMP errors d73f4249776dd ipvs: use parsed transport offset in TCP state lookup d340e351a0a74 ipvs: pass parsed transport offset to state handlers 238c612357b5a netfilter: nft_lookup: fix catchall element handling with inverted lookups f60ec3058a854 ipv4: igmp: Fix potential memory leaks in igmp_mod_timer() and igmp_stop_timer() 27506827a01f6 ipv4: igmp: annotate data-races around timer-related fields d269eb67d2e58 ipv4: igmp: annotate data-races around im->users 9ce741c22df4f ipv6: mcast: Fix potential UAF in MLD delayed work 75e984fe0cb9e ipv4: igmp: Fix potential UAF in igmp_gq_start_timer() 3bfcce441c552 gpio: mvebu: free generic chips on unbind 7cc438c99bba3 perf/x86/amd/core: Avoid enabling BRS from the SVM reload path 9579d625171a1 octeontx2-pf: check DMAC extraction support before filtering 7aa0e64fea778 net/sched: cake: reject overhead values that underflow length 72119397cdff6 net: mdio: select REGMAP_MMIO instead of depending on it 762116dfa7286 drm/v3d: Reject invalid indirect BO handle in indirect CSD setup 267809e2c56fb accel/amdxdna: Fix potential amdxdna_umap lifetime race 1cd434ac1c222 tracing: Make tracepoint_printk static as not exported 5e15cf51982f8 gpio: dwapb: Defer clock gating until noirq 6c736c5ccf4a3 gpio: dwapb: reduce allocation to single kzalloc d7b5497e0e45b gpio: dwapb: Use modern PM macros a3010b732d620 net: usb: lan78xx: disable VLAN filter in promiscuous mode e8a4c9fc437b1 net/tls: Consume empty data records in tls_sw_read_sock() b3eeb586f94c7 accel/amdxdna: Use unsigned long for nr_pages in amdxdna_hmm_register() ec5e96aee75d2 ring-buffer: Fix event length with forced 8-byte alignment 0c602cb8f148a Bluetooth: L2CAP: fix tx ident leak for commands without a response bfc9e7be289df Bluetooth: bpa10x: avoid OOB read of revision string in bpa10x_setup() b69b1ab121fe8 Bluetooth: ISO: exclude RFU bits from ISO_SDU_Length da4d8eea0c5f3 Bluetooth: sco: Fix a race condition in sco_sock_timeout() dfc8373893b18 Bluetooth: MGMT: Fix adv monitor add failure cleanup 23a83bac3356e Bluetooth: 6lowpan: hold L2CAP conn across debugfs control 026c236f0eefe amt: fix size calculation in amt_get_size() 3bfb96d9bc6a7 net/smc: fix UAF in smc_cdc_rx_handler() by pinning the socket 6f9b23eb92a89 net/sched: act_pedit: fix TOCTOU heap OOB write in tc offload 1b12612c367e4 net: qualcomm: rmnet: validate MAP frame length before ingress parsing b066420e57f34 qede: fix off-by-one in BD ring consumption on build_skb failure 1e71a40d10154 net: microchip: vcap: fix races on the shared Super VCAP block 5c7e3755abf66 net/mlx5e: Fix publication race for priv->channel_stats[] 60fddda7207d8 net/mlx5e: Fix HV VHCA stats agent registration race 420aabb32da43 net/mlx5e: Fix HV VHCA stats zero-sized buffer allocation 6a802de97a8bf net/mlx5: LAG, MPESW, Fix missing complete() on devcom error 4eef84b09a383 netfilter: xt_connmark: reject invalid shift parameters b29b67c729de0 netfilter: nft_set_rbtree: get command skips end element with open interval 3d441be2b1c5e netfilter: ip6tables: mark malformed IPv6 extension headers for hotdrop e702f6dd5d21e netfilter: xt_rateest: fix u64 truncation in xt_rateest_mt() a597a722fb71a netfilter: xt_u32: reject invalid shift counts 4a4a1d41c6e90 gue: validate REMCSUM private option length b153cfe84b134 net: usb: net1080: validate packet_len before pad-byte access in rx_fixup 66f57dc92aeb6 arm64/sysreg: Fix BWE field encoding in ID_AA64DFR2_EL1 a6185c21d5510 selftests/hid: Cover hid_bpf_get_data() size overflow 91ac1d7fd51e3 selftests/hid: Load only requested struct_ops maps 61a959b82f1ae HID: bpf: Fix hid_bpf_get_data() range check 4c65c3d9f660b arm64/mm: Optimize TLB flush in unmap_hotplug_[pmd|pud]_range() dd395744e4ed8 HID: core: Fix OOB read in hid_get_report for numbered reports d354e523c6f74 HID: picolcd: prevent NULL pointer dereference in picolcd_send_and_wait() 793b55c3f36f5 ata: libata-scsi: limit simulated SCSI command copy to response length 232a2f2fce9b9 ata: sata_gemini: unwind clocks on IDE pinctrl errors 86652704a7fd4 cifs: Fix missing credit release on failure in cifs_issue_read() c9170c83b0e0f uprobes/x86: Use proper mm_struct in __in_uprobe_trampoline 2265b2b1c5aaa x86/uprobes: Keep shadow stack in sync for emulated CALLs adc7dda728ca3 drm/xe/pf: Don't attempt to process FAST_REQ or EVENT relays a0a56b4480a0d drm/xe/hw_engine: Fix double-free of managed BO in error path f9a9abd7bbdab drm/xe/userptr: Hold notifier_lock for write on inject test path 78b1074966d29 drm/xe/pt: Fix NULL pointer dereference in xe_pt_zap_ptes_entry() a9b89752c2726 netfs: Fix folio state after ENOMEM whilst under writeback iteration 1bb33d959aabc netfs: Fix writeback error handling 7838131e296df netfs: Fix writethrough to use collection offload 8ab75e445c161 netfs: Fix netfs_create_write_req() to handle async cache object creation 1f38f65bf965f iomap: guard io_size EOF trim against concurrent truncate underflow 08b2145470667 ovl: fix comment about locking order abe3536a4bedc minix: avoid overflow in bitmap block count calculation ce6aced2e8554 afs: Fix unchecked-length string display in debug statement 158c5a0b1dfc0 afs: Fix the volume AFS_VOLUME_RM_TREE is set on 657449e5581a4 afs: Fix premature cell exposure through /afs 2ffb70a8a0198 afs: Fix lack of locking around modifications of net->cells_dyn_ino 8afb1a787a280 afs: Fix vllist leak 5492799ec5d27 afs: Fix missing NULL pointer check in afs_break_some_callbacks() 0acbc09d2aca0 afs: Fix callback service message parsers to pass through -EAGAIN 63d3f283858fa afs: Fix reinitialisation of the inode, in particular ->lock_work 5ea289ca751c4 afs: Fix misplaced inc of net->cells_outstanding b5bc1e5d5ce57 afs: Fix bulk lookup malfunction due to change in dir_emit() API 083a0ddc9cd49 afs: Remove erroneous seq |= 1 in volume lookup loop 6eb0d929202a3 afs: use kvfree() to free memory allocated by kvcalloc() aa24cec5b3470 afs: Fix double netfs initialisation in afs_root_iget() 8530206911fd6 afs: Fix error code in afs_extract_vl_addrs() a2038514e6937 fs: refuse O_TMPFILE creation with an unmapped fsuid or fsgid 374fd8122421f net/sched: hhf: clear heavy-hitter state on reset fba8e250ce5f3 net/sched: dualpi2: clear stale classification on filter miss a203f2c3892b1 pinctrl: meson: restore non-sleeping GPIO access 47120164c63d3 gpio: timberdale: Return -ENOMEM on dynamic memory allocation in probe 5a5ac2852cd32 ksmbd: fix use-after-free of fp->owner.name in durable handle owner check d020e7f27bf65 ksmbd: reject undersized DACLs before parsing ACEs 6b1304ce6cff0 net/sched: act_bpf: use rcu_dereference_bh() to read the filter a03387e1f6251 selftests: drv-net: tso: don't touch dangerous feature bits df9ffdceac053 cxgb4: Fix decode strings dump for T6 adapters 124440df267dc virtio_net: disable cb when NAPI is busy-polled a8323fb2ab6cd sctp: fix addr_wq_timer race in sctp_free_addr_wq() 4e8d498d32b6c irqchip/ts4800: Fix missing chained handler cleanup on remove c5d75800539bc irqchip/gic-v3-its: Fix OF node reference leak f0069a262bd41 tracing/probes: Make the $ prefix mandatory for comm access 62988204162fc tracing/fprobe: Fix NULL pointer dereference in fprobe_fgraph_entry() 898cb5a7c4154 tracing: eprobe: read the complete FILTER_PTR_STRING pointer e0881f5cc4d71 tracing/events: Fix to check the simple_tsk_fn creation f148f86c65b8f tracing/probes: Remove WARN_ON_ONCE from parse_btf_arg 3b51d6f07a199 tracing/eprobes: Allow use of BTF names to dereference pointers acbf1ecc22f3c drm/panthor: Interrupt group start/resumption if group_bind_locked() fails a9d098b346db5 drm/panthor: Fix a leak when a group is evicted before the tiler OOM is serviced 1497a438ea34a drm/panthor: Don't overrule pending immediate ticks in sched_resume_tick() dd0b2976b7c0f drm/panthor: Fix potential invalid pointer deref in group_process_tiler_oom() b4b3458ef88df bridge: stp: Fix a potential use-after-free when deleting a bridge 9b7d05cbaa601 net/sched: sch_teql: Introduce slaves_lock to avoid race condition and UAF ef940e042f329 net: gianfar: dispose irq mappings on probe failure and device removal 58ba00999898b net: libwx: fix VMDQ mask for 1-queue mode 86d379fcf1b79 net: phy: sfp: free mii_bus in sfp_i2c_mdiobus_destroy 0a7d9c7c5f1f2 usbnet: gl620a: fix out-of-bounds read in genelink_rx_fixup() d8a01d27873e0 ipv6: fib6: fix NULL deref in fib6_walk_continue() on multi-batch dump 83df3e2594cd7 eth: fbnic: don't cache shinfo across skb realloc 898ca04b096b9 hwmon: (aspeed-g6-pwm-tach) Guard fan RPM calculation against divide-by-zero 489291b6b5697 hwmon: (pmbus) Fix passing events to regulator core 36554592e2f5c hwmon: adm1275: Prevent reading uninitialized stack 1797eb92f0b39 ASoC: codecs: lpass-va-macro: Fix LPASS Codec Version for SC7280 f14c3926fee38 ASoC: codecs: lpass-va-macro: add SM6115 compatible 3d3638fe92137 MIPS: mm: Add check for highmem before removing memory block 4e9f4ca9dc73c MIPS: DEC: Ensure RTC platform device deregistration upon failure bca3100f55028 sctp: add INIT verification after cookie unpacking ad6215d76b644 sctp: fix SCTP_RESET_STREAMS stream list length limit 1681cc7974a61 net: enetc: check the number of BDs needed for xdp_frame b17751a2ebc4a qede: fix out-of-bounds check for cqe->len_list[] 8dba7a94a269b seg6: validate SRH length before reading fixed fields 8d501b1411548 net: pse-pd: scope pse_control regulator handle to kref lifetime e94d53a9ac22c gpio: htc-egpio: use managed gpiochip registration f4af803269ccd gpio: mvebu: fail probe if gpiochip registration fails 46dee20d30b70 riscv: Fix 32-bit call_on_irq_stack() frame pointer ABI 8e0b7f94fb394 ACPI: RIMT: Only defer the IOMMU configuration in init stage 776f70bafd45c spi: sh-msiof: abort transfers when reset times out d6cd34d17b951 tracing: probes: fix typo in a log message f28d7b5f1578a ALSA: FCP: Fix NULL pointer dereference in interface lookup d990a01b853e5 net: hns3: differentiate autoneg default values between copper and fiber 2d149a20275ac net: hns3: fix permanent link down deadlock after reset 92d05883ef337 net: hns3: refactor MAC autoneg and speed configuration 43a6c6fb6ec50 net: hns3: unify copper port ksettings configuration path de051b146022c selftests: tls: size splice_short pipe by page size 6727f580cf462 dt-bindings: net: renesas,ether: Drop example "ethernet-phy-ieee802.3-c22" fallback 9075efb9b2c1d net: udp_tunnel: prevent double queueing in udp_tunnel_nic_device_sync c1e7286d05318 ASoC: fsl_asrc_dma: fix eDMA maxburst misalignment with channel count 7a7c7263bbbc4 LoongArch: BPF: Fix off-by-one error in tail call ed295077a2214 LoongArch: BPF: Fix outdated tail call comments 0a8a729481c8e LoongArch: Move struct kimage forward declaration before use 2f3c0895fb20a net: ethernet: sunplus: spl2sw: fix phy_node refcount leak in remove b15a3cc68e245 net: sungem: fix probe error cleanup b84dd48f9da1e net: mvneta: re-enable percpu interrupt on resume e0ac054416bf4 octeontx2-af: Validate NIX maximum LFs correctly 9dc3cf8a35906 net: phy: realtek: Clear MDIO_AN_10GBT_CTRL_ADV10G bit 0c11a1da41a64 net: dsa: realtek: fix memory leak in rtl8366rb_setup_led() a69ccea6d7eb6 rtc: cmos: unregister HPET IRQ handler on probe failure 5fd1f0512748d rtc: ds1307: Fix off-by-one issue with wday for rx8130 d0bfd7004a87f smb/client: preserve errors from smb2_set_sparse() 5b6165d7ec384 ACPI: processor_idle: Mark LPI enter functions as __cpuidle ea43e7a231aa2 thermal: testing: zone: Flush work items during cleanup 4e62be1490d23 eth: fbnic: fix ordering of heartbeat vs ownership 123b559aa6bb6 ipv6: fix missing notification for ignore_routes_with_linkdown 419017dd2dda2 ipv6: fix state corruption during proxy_ndp sysctl restart ae58dbf1d78d7 ipv6: fix error handling in disable_policy sysctl 2bf70e0306f8d ipv6: fix error handling in forwarding sysctl b060606bc7e46 ipv6: fix error handling in ignore_routes_with_linkdown sysctl 56c26538f0e58 ipv6: fix error handling in disable_ipv6 sysctl 2140c2f3f2e7b net/sched: cls_api: Handle TC_ACT_CONSUMED in tcf_qevent_handle ff127c0aa5279 net: usb: lan78xx: restore VLAN and hash filters after link up a9e6707322ef2 veth: fix NAPI leak in XDP enable error path 4106295280670 net: dsa: sja1105: round up PTP perout pin duration 7557df1b60f20 net: do not acquire dev->tx_global_lock in netdev_watchdog_up() 03b743586a246 net, bpf: check master for NULL in xdp_master_redirect() a0904f7d27035 alpha/PCI: Fix __pci_mmap_fits() overflow for zero-length BARs 94defb18ac792 alpha/PCI: Add security_locked_down() check to pci_mmap_resource() 04117aea9bc11 NTB: epf: Fix doorbell bitmask and IRQ vector handling 56ec2a08d27b5 NTB: epf: Report 0-based doorbell vector via ntb_db_event() d2a41c85beb56 NTB: epf: Make db_valid_mask cover only real doorbell bits 60a6689b9a5df gpio: davinci: fix IRQ domain leak on devm_kzalloc failure 33e1875d6b5b5 netfilter: nft_compat: ebtables emulation must reject non-bridge targets d3e9a7e2ce9dc netfilter: nft_synproxy: stop bypassing the priv->info snapshot 329f2626ee5cb netfilter: nf_conncount: prevent connlimit drops for early confirmed ct a73e7ac3f3b69 netfilter: nf_nat: avoid invalid nat_net pointer use on failed nf_nat_init() 49fa1be621dde bpf: Disable xfrm_decode_session hook attachment 4d919c9b77099 md/raid5: avoid R5_Overlap races while breaking stripe batches 3db13f82ba314 md/raid5: use stripe state snapshot in break_stripe_batch_list() 828fad4fd418b ipv4: fib: Don't ignore error route in local/main tables. 630ce3806b706 eth: bnxt: improve the timing of stats c0057e5f762b9 eth: bnxt: rename ring_err_stats -> ring_drv_stats 33168db149d01 eth: bnxt: gather and report HW-GRO stats b0d0eb13a0441 ipv6: Fix null-ptr-deref in fib6_nh_mtu_change(). 77bb0bbfcc4e7 ksmbd: fix use-after-free of conn->preauth_info in concurrent SMB2 NEGOTIATE 1f6a4aec0d366 rtc: msc313: fix NULL deref in shared IRQ handler at probe 68115a7a336fc i40e: Fix i40e_debug() to use struct i40e_hw argument de80d04b13dec ice: dpll: fix memory leak in ice_dpll_init_info error paths eaffdd113f560 ice: dpll: set pointers to NULL after kfree in ice_dpll_deinit_info 854065a75e375 rtc: isl1208: Balance enable_irq_wake() with disable_irq_wake() on cleanup 4cc632fe63df8 ice: call netif_keep_dst() once when entering switchdev mode 04c082b7dc5bf ice: fix AQ error code comparison in ice_set_pauseparam() dd6d8e4412f80 ice: fix FDIR CTRL VSI resource leak in ice_reset_all_vfs() 9415a94cf6227 PCI: endpoint: pci-epf-ntb: Add check to detect 'db_count' value of 0 e1e7c72a2301d PCI: endpoint: pci-epf-vntb: Add check to detect 'db_count' value of 0 9cc0f8e63e8c3 drm/edid: fix OOB read in drm_parse_tiled_block() 5e4c4ab99abc9 gpiolib: initialize return value in gpiochip_set_multiple() 7550becf33014 power: sequencing: fix ABBA deadlock in pwrseq_device_unregister() 9697db03e0103 bpf: Fix effective prog array index with BPF_F_PREORDER 3bdfa0e435f31 bpf: zero-initialize the fib lookup flow struct b05337635be3c bpftool: Fix vmlinux BTF leak in cgroup commands 68b41e68a6229 bpf: Fix stack slot index in nospec checks aa33b44f70bfe rtc: ds1307: handle oscillator stop flag for ds1337/ds1339/ds3231 56e5f8a409f8c rtc: abx80x: fix the RTC_VL_CLR clearing all status flags 93f95538b611a dpaa2-switch: do not accept VLAN uppers while bridged ea24f911ead85 ipv6: ioam: fix type confusion of dst_entry a6450f7cfae57 ipv6: ndisc: fix NULL deref in accept_untracked_na() 2066e692ec7a1 net: airoha: Fix skb->priority underflow in airoha_dev_select_queue() 1d51aff78f078 net/sched: act_ct: fix nf_connlabels leak on two error paths a103cdb0681e7 net: emac: Fix NULL pointer dereference in emac_probe 2855ec137a224 octeontx2-pf: mcs: Fix mcs resources free on PF shutdown da603b606ceb3 octeontx2-pf: Clear stats of all resources when freeing resources 5636f0f3bd99b octeontx2-af: mcs: Fix unsupported secy stats read ceef83f0eaf9c net: ethernet: mtk_ppe: Fix rhashtable leak in mtk_ppe_init error paths a0c5fdeb5fa25 tipc: fix use-after-free of the discoverer in tipc_disc_rcv() 5dda4f164a633 net: marvell: prestera: initialize err in prestera_port_sfp_bind 9200c8149910d selftests/mm: fix exclusive_cow test fork() handling 55fc2f99d0979 selftests/mm: allow PUD-level entries in compound testcase of hmm tests c8add1d06512b selftests/mm: clarify alternate unmapping in compaction_test 0caa28e978941 selftests/mm: skip uffd-stress test when nr_pages_per_cpu is zero 471b62966c782 selftests/mm: ensure destination is hugetlb-backed in hugetlb-mremap 9dbfd514148dd selftest/mm: register existing mapping with userfaultfd in hugetlb-mremap a8673dbd3d4a0 selftests/mm: free dynamically allocated PMD-sized buffers in split_huge_page_test 31b28910abe34 selftests/mm: size tmpfs according to PMD page size in split_huge_page_test fff7d3ea3a4c4 selftests/mm: fix cgroup task placement and drop memory.current checks in hugetlb_reparenting_test.sh 8c65c58868ecc selftests/mm: fix hugetlb pathname construction in hugetlb_reparenting_test.sh 58cd8ff69e33c selftests/mm: restore default nr_hugepages value via exit trap in hugetlb_reparenting_test.sh b805de2abfa34 selftests/mm: restore default nr_hugepages value via exit trap in charge_reserved_hugetlb.sh 37e3e8a2c3bfd alloc_tag: fix use-after-free in /proc/allocinfo after module unload 502b3ae43f798 irqchip/crossbar: Fix parent domain resource leak 002ebbcc8414c mailbox: imx: Forward the timeout/ error in imx_mu_generic_tx() 7e23965d44f06 netfilter: nft_meta_bridge: fix NFT_META_BRI_IIFPVID stack leak d32e4301a0e5e netfilter: nf_reject: skip iphdr options when looking for icmp header 8e935c51b65d9 netfilter: nft_flow_offload: zero device address for non-ether case 4c61d28634fbf netfilter: flowtable: move path discovery infrastructure to its own file 13c6ba6e0f216 netfilter: nft_meta_bridge: add validate callback for get operations 5baa149abb41a netfilter: nft_payload: reject offsets exceeding 65535 bytes 12088da6add5b netfilter: ipset: make sure gc is properly stopped 8087bb360a936 netfilter: ipset: fix order of kfree_rcu() and rcu_assign_pointer() c4d257734e91b netfilter: ipset: Don't use test_bit() in lockless RCU readers in hash types a0afd353c2f7e netfilter: ipset: annotate "pos" for concurrent readers/writers 7228cc8ff6265 netfilter: ipset: Fix data race between add and dump in all hash types 6d92dbd73d19a md/raid1: free r1_bio when REQ_NOWAIT is set and read would block on retry 2c5384c40a4ce md/raid1: honor REQ_NOWAIT when waiting for behind writes 119903c320830 md: merge mddev serialize_policy into mddev_flags 2e414af05a7cf md: merge mddev faillast_dev into mddev_flags 9408c233a5bbe md: merge mddev has_superblock into mddev_flags 5464ee6442376 mac802154: Prevent overwrite return code in mac802154_perform_association() de3bd9809af75 ieee802154: fix kernel-infoleak in dgram_recvmsg() d22e278cd0679 ieee802154: Remove WARN_ON() in cfg802154_pernet_exit() f4860dd988b10 ieee802154: Avoid calling WARN_ON() on -ENOMEM in cfg802154_switch_netns() 5d17ebdf6c236 ieee802154: Restore initial state on failed device_rename() in cfg802154_switch_netns() 3b40ebc19ad02 ACPI: IPMI: Fix inverted interface check in ipmi_bmc_gone() 45465b0e01354 ACPI: resource: Amend kernel-doc style 7ae67f0e1c16b thermal: intel: Fix dangling resources on thermal_throttle_online() failure 679fd0bf4f8ab arm64/hw_breakpoint: reject unaligned watchpoints that would truncate BAS 4c16176fc11a6 ALSA: usb-audio: Kill MIDI 2.0 URBs before freeing endpoints a762b9865f494 selftests: vlan_bridge_binding: Fix flaky operational state check c6d3bcb0f934d flow_dissector: check device type before reading ETH_ADDRS 68af74ad696ce net: macb: add TX stall timeout callback to recover from lost TSTART write 112b5eff24e04 net: airoha: fix foe_check_time allocation size 5ffb2b4987cc9 devlink: Fix parent ref leak on tc-bw failure 02c884d9aaca3 devlink: Fix parent ref leak in devl_rate_node_create() 0dafdaaf8684b dpaa2-switch: fix VLAN upper check not rejecting bridge join c7fc9adf4e006 virtio-net: fix len check in receive_big() 0d95587d662a5 spi: rpc-if: Use correct device for hardware reinitialization on resume f37f2f804796e PCI: iproc: Restore .map_irq() for the platform bus driver 53c23d56b46b1 ALSA: usb-audio: qcom: clear opened when stream enable fails 25a867aa5e67a ALSA: usb-audio: qcom: reject stream disable with no active interface 207bb4ce8fe7d sctp: hold socket lock when dumping endpoints in sctp_diag a6cfb924ad74e net: psample: fix info leak in PSAMPLE_ATTR_DATA 3d45d40b872ae octeontx2-pf: Fix leak of SQ timestamp buffer on teardown 290ad0a548915 drm/amdgpu: initialize irq.lock spinlock earlier 96ac562a9ea30 drm/amdkfd: fix list_del corruption in kfd_criu_resume_svm 211bb9d8f17c4 drm/amd/display: Fix mem_type change detection for async flips 0e27d92f69b8e drm/amdkfd: Avoid double-unpin of DOORBELL/MMIO BOs on free 7bcd4ef375fa3 ASoC: tlv320aic3x: restrict CLKDIV bypass Q values in dual-rate mode ca297485271c6 perf dso: Set standard errno on decompression failure 05b11debdffe0 perf bpf: Validate array presence before casting BPF prog info pointers c8cb4a92eda6e perf cs-etm: Bounds-check CPU in cs_etm__get_queue() b389a5b215e35 perf cs-etm: Require full global header in auxtrace_info size check c13532ff67fae perf cs-etm: Validate num_cpu before metadata allocation 87d23f25b5e97 perf machine: Use snprintf() for guestmount path construction 6d99379c58f7f xfrm: validate selector family and prefixlen during match 7248ae02a9453 xfrm: annotate data-races around xfrm_policy_count[] and xfrm_policy_default[] a1a3360a0c44b xfrm: Fix xfrm state cache insertion race 1467ca02ddac4 ALSA: usb-audio: qcom: Free sideband sg_table objects 507a7b07f3fa3 i3c: master: Add missing runtime PM get in dev_nack_retry_count_store() 34cd92141a024 i3c: master: Update dev_nack_retry_count under maintenance lock 95028569589f4 spi: dw: fix wrong BAUDR setting after resume 355e51eeffc6b drm/xe: Fix wa_oob codegen recipe for external module builds 2024940522ef4 drm/i915: clear CRTC color blob pointers after dropping refs 1348bf64c1978 gpio: mlxbf3: fail probe if gpiochip registration fails 7d3532a0b11a2 perf cs-etm: Reject CPU IDs that would overflow signed comparison a56f29ad8aacf perf: Remove redundant kernel.h include f8898d2eb71ae perf bpf: Bounds-check array offsets in bpil_offs_to_addr() cafd80d81f08b perf bpf: Reject oversized BPF metadata events that truncate header.size 1935d213aeb23 perf bpf: Validate func_info_rec_size and sub_id in synthesize_bpf_prog_name() aea30b437ebd0 perf sched: Replace (void*)1 sentinel with proper runtime allocation bc27041e8971e perf hwmon: Fix fd check to accept fd 0 in hwmon_pmu__describe_items() 661f60a8a5cf8 perf tools: Use snprintf() for root_dir path construction 5d080b7324f07 perf dso: Set error code when open() fails on uncompressed fallback path debfcd673a6d1 perf dso: Fix heap overflow in dso__get_filename() on decompressed path 95bf4dbcd5022 perf tools: Fix uninitialized pathname on uncompressed fallback in filename__decompress() fa870f951793d perf tools: Add O_CLOEXEC to open() calls in DSO and ELF code 3ae7947101b97 perf tools: Don't read build-ids from non-regular files 2c19e40753ec1 perf symbols: Break infinite loop on zero-filled notes in sysfs__read_build_id() 137eabe3c18ff perf symbols: Validate p_filesz before use in filename__read_build_id() ca3393e258f63 perf symbols: Fix bswap copy-paste error for 32-bit ELF p_filesz f231387f3d2bb sparc: led: avoid trimming a newline from empty writes 17955f1995bf9 accel/ivpu: fix HWS command queue leak on registration failure 85873b1bd3664 apparmor: fix label can not be immediately before a declaration 38d3d33bf42c2 i3c: master: Prevent reuse of dynamic address on device add failure c4f2afcdc5470 i3c: master: Defer new-device registration out of DAA caller context 3891c061341fb i3c: master: Ensure Hot-Join operations are stopped on shutdown 57490b302b984 i3c: master: Consolidate Hot-Join DAA work in the core 0bd450d40f874 i3c: master: Move rstdaa error suppression fd32e8d4a2933 i3c: master: Add i3c_master_do_daa_ext() for post-hibernation address recovery b07a318afca16 i3c: master: Introduce optional Runtime PM support 882ee831366a1 i3c: master: Replace WARN_ON() with dev_err() in i3c_dev_free_ibi_locked() de2106d99b87a i3c: add sysfs entry and attribute for Device NACK Retry count 0d66830f302fd i3c: master: Make hot-join workqueue freezable to block hot-join during suspend eb9db96a5deb3 i3c: master: add WQ_PERCPU to alloc_workqueue users 45bbc1e1fe626 i3c: mipi-i3c-hci: Preserve RUN bit when aborting DMA ring d22ab94261c7b i3c: mipi-i3c-hci: Switch PIO data allocation to devm_kzalloc() 973fda38b124c i3c: mipi-i3c-hci: Allow for Multi-Bus Instances 5625b8767ce3e i3c: mipi-i3c-hci: Quieten initialization messages 2791dd42d41e3 apparmor: fix uninitialised pointer passed to audit_log_untrustedstring() fdf610a9a9e72 apparmor: don't audit files pointing to aa_null.dentry b58d240883dfe apparmor: put secmark label after secid lookup 66a6c61369d41 apparmor: aa_getprocattr free procattr leak on format failure 22dc9433d458c apparmor: fail policy unpack on accept2 allocation failure 3b918f6f52390 apparmor: Fix return in ns_mkdir_op 566d1ef98a711 apparmor: remove or add symlinks to rawdata according to export_binary fbfdb5a94a487 apparmor: fix NULL pointer dereference in unpack_pdb 57b1bd4486d56 apparmor: fix potential UAF in aa_replace_profiles b427061ca4983 apparmor: grab ns lock and refresh when looking up changehat child profiles 9111f76e8dc8c apparmor: fix rawdata_f_data implicit flex array ae02e603c0b39 apparmor: aa_label_alloc use aa_label_free on alloc failure d821601323456 apparmor: check label build before no_new_privs test ad965f36d2986 security/apparmor/apparmorfs.c: conditionally compile get_loaddata_common_ref() 045dbe89ac317 apparmor: fix refcount leak when updating the sk_ctx d8ea44f6090c0 apparmor: fix race in unix socket mediation when peer_path is used ef488d7429d23 apparmor: fix shadowing of plabel that prevents cache from being updated f79519f636059 Revert "PCI/MSI: Unmap MSI-X region on error" 514b84b1bf30f PCI: dwc: Avoid dwc_pcie_rasdes_debugfs_deinit() NULL dereference when no RAS DES capability 11016555d7510 phy: freescale: phy-fsl-imx8qm-lvds-phy: Fix missing pm_runtime_disable() on probe error path 872f9a63a108e PCI: mediatek: Use actual physical address instead of virt_to_phys() f77c490c45d46 PCI: mediatek: Fix possible truncation in mtk_pcie_parse_port() 9ca0a78a5d561 dt-bindings: phy: sc8280xp-qmp-pcie: Disallow bifurcation register on Purwa f1f5f8d334e91 perf symbols: Add bounds checks to read_build_id() note iteration in minimal build cc6cd3fe8b8b1 perf symbols: Add bounds checks to elf_read_build_id() note iteration a3e758e741228 perf bpf: Fix metadata leak in perf_env__add_bpf_info() on duplicate insert f593775fecf5a perf bpf: Fix map data leak in bpf_metadata_create() on alloc failure bafb6bfb346fe perf bpf: Add NULL check for btf__type_by_id() in synthesize_bpf_prog_name() fe4d8ad2e96f4 tools lib api: Fix mount_overload() snprintf truncation and toupper range b0385203a09f0 tools lib api: Fix filename__write_int() writing uninitialized stack data 41b3a92310450 perf tools: Use snprintf() in dso__read_running_kernel_build_id() fbaf9bdfc0917 perf hwmon: Guard label read against empty or failed reads d34b42ee0c74d perf symbols: Bounds-check descsz in sysfs__read_build_id() GNU fallback bc2fc12ce6e4d perf hwmon: Fix parse_hwmon_filename() strlcpy buffer overflow f830bb8d221f3 perf hwmon: Use scnprintf() in hwmon_pmu__for_each_event() 76dfa13a0acb1 perf hwmon: Fix off-by-one null termination on sysfs reads 56b17c84394f1 perf tools: Fix thread__set_comm_from_proc() on empty comm file f2e5262589d94 perf intel-pt: Fix snprintf size tracking bug in insn decoder 45e7900e1555c perf symbols: Bounds-check .gnu_debuglink section data 4f883ab5bc7b7 perf symbols: Fix signed overflow in sysfs__read_build_id() size check 490473192ac2f tools lib api: Fix missing null termination in filename__read_int/ull() 09962b811ef14 perf pmu: Fix perf_pmu__parse_scale/unit() OOB access on empty sysfs file a6eec54329b43 perf pmu: Fix pmu_id() heap underwrite on empty identifier file e274dfa05904f perf cs-etm: Queue context packets for frontend fa9eb50ddfea3 perf s390: Fix TEXTREL in Python extension by compiling as PIC b5a0a4a564d21 xprtrdma: Return sendctx slot after Send preparation failure 007b4da2f38dc xprtrdma: Repost Receive buffers for malformed replies 469b22376ee73 xprtrdma: Sanitize the reply credit grant after parsing d7a2870dde3bb xprtrdma: Fix bcall rep leak and unbounded peek 345652531400f xprtrdma: Resize reply buffers before reposting receives 47b3dc59e09e9 xprtrdma: Document and assert reply-handler invariants 7471e66373a44 xprtrdma: Check frwr_wp_create() during connect 28743571c17b5 xprtrdma: Initialize re_id before removal registration d0479c2b12974 xprtrdma: Fix ep kref imbalance on ADDR_CHANGE 6d52921f47020 perf hists: Fix snprintf() in hists__scnprintf_title() UID filter path 56ad33189ed5f perf bpf: Use scnprintf() in snprintf_hex() and synthesize_bpf_prog_name() c32fe40b0c745 perf sched: Fix idle-hist callchain display using wrong rb_first variant 77051ef66e4ad perf sched: Bounds-check prio before test_bit() in timehist 2e0dd50e5a4da PCI: rcar-host: Remove unused LIST_HEAD(res) b9e8406651dcc perf tools: Use perf_env__get_cpu_topology() in machine__resolve() 504028f561b19 perf tools: Use scnprintf() in cpu_map__snprint() to prevent overflow 2a8244988316a perf tools: Fix get_max_num() size_t underflow on empty sysfs file 3f4476a089a6d platform/x86/intel/vsec: Restore BAR fallback for header walk d6565e08166c8 platform/x86/intel/vsec: Return real error codes from registration path 4df30a4dc0e97 platform/x86/intel/vsec: Switch exported helpers from pci_dev to device 817ab332d37ce platform/x86/intel/vsec: Decouple add/link helpers from PCI e6523bcafeb61 platform/x86/intel/vsec: correct kernel-doc comments c0d97519c9dfb platform/x86:intel/pmc: Relocate lpm_req_guid to pmc_reg_map b95e1facc5b7f platform/x86:intel/pmc: Rename PMC index variable to pmc_idx 3e86797c0699d platform/x86:intel/pmc: Add support for multiple DMU GUIDs 4f129fc6f756f fs/ntfs3: resize log->one_page_buf when adopting on-disk page size d3491b23bc207 PCI: meson: Add missing remove callback a5c0ba31eef9e PCI: meson: Propagate devm_add_action_or_reset() failure f0aaa198e068b pwm: rzg2l-gpt: Add missing newlines to dev_err_probe() messages a57692ad365f3 PCI: mediatek: Fix operator precedence in PCIE_FTS_NUM_L0 macro f161ef7b0dd2f nfs: use nfsi->rwsem to protect traversal of the file lock list a6f147b23e361 NFSv4/flexfiles: honor FF_FLAGS_NO_IO_THRU_MDS in pg_get_mirror_count_write a70375f0b793e NFSv4/flexfiles: honor FF_FLAGS_NO_IO_THRU_MDS on fatal DS connect errors b694c7de94bc5 nfs: keep PG_UPTODATE clear after read errors in page groups f84949dd17847 NFSv4/pnfs: defer return_range callbacks until after inode unlock 53442c7d0c888 xprtrdma: Decouple req recycling from RPC completion becc90a04780a xprtrdma: Use sendctx DMA state for Send signaling e7ae0883c8c89 xprtrdma: Post receive buffers after RPC completion f043dd58fbd79 xprtrdma: Close lost-wakeup race in xprt_rdma_alloc_slot b7bc8e7f09ae4 xprtrdma: Avoid 250 ms delay on backlog wakeup 44b73b4b7eff7 pNFS/filelayout: fix cheking if a layout is striped f3f21b94cf980 sunrpc: Fix error handling in rpc_sysfs_xprt_switch_add_xprt_store() e8dc126e80395 clk: qcom: a53: Corrected frequency multiplier for 1152MHz c0e6bb2b0408f dmaengine: dma-axi-dmac: use DMA pool to manange DMA descriptor 9f1ef67c041ef dmaengine: dma-axi-dmac: Properly free struct axi_dmac_desc 329ec20a86091 dmaengine: Fix possible use after free 7d49f0ddaf5a4 dmaengine: qcom: gpi: set DMA_PRIVATE capability 8e2c460a8f0e4 mshv: add bounds check on vp_index in mshv_intercept_isr() eaf937b501fd0 clk: qcom: camcc-x1e80100: Add support for camera QDSS debug clocks 032692e4525a0 dt-bindings: clock: qcom: Add X1P42100 camera clock controller c7c8bab87d0df perf tools: Fix int16_t truncation of max_cpu_num in set_max_cpu_num() e16012f8f63d3 perf timechart: Fix cpu2y() OOB read on untrusted CPU index 330219fe8523f perf c2c: Fix use-after-free in he__get_c2c_hists() error path 01564c1a260f6 perf stat: Introduce perf_env__get_cpu_topology() to guard NULL env->cpu c05ba5b57505a perf mmap: Fix NULL deref in aio cleanup on alloc failure c4406dbe5d8f4 perf sched: Replace BUG_ON and add NULL checks in replay event helpers b1f7683632712 perf sched: Use thread__put() in free_idle_threads() 1517402d0a81c perf sched: Clean up idle_threads entry on init failure d6b586bb8f489 perf c2c: Bounds-check CPU IDs in setup_nodes() topology loop 2f9f7224e7691 perf c2c: Bounds-check CPU and node IDs before bitmap and array access 278e30717c356 perf stat: Bounds-check CPU index in topology aggregation callbacks 21a9b87ada08d perf mmap: Guard cpu__get_node() return in aio_bind() 652cea73b7b7b perf sched: Fix register_pid() overflow, strcpy, and BUG_ON 068e9b6a07bc0 perf sched: Cap max_cpu at MAX_CPUS in timehist sample processing 1d25a8418c890 perf tools: Add bounds check to cpu__get_node() 89489a31f4443 perf sched: Fix thread reference leak in latency_switch_event ea486d61b1663 perf tools: Guard test_bit from out-of-bounds sample CPU 18961e0f8966e perf annotate: Fix crashes on empty annotate windows 93f3e84fc74e6 perf: Fix off-by-one stack buffer overflow in kallsyms__parse() d78b16d078149 dt-bindings: dma: nvidia,tegra186-gpc-dma: Make reset optional a498063f95bdd dmaengine: imx-sdma: Refine spba bus searching in probe da40583823153 thunderbolt: debugfs: Fix margining error counter buffer leak 038a0f01dda59 drm/amd/display: Add missing kdoc for ALLM parameters c5388a957cf1d fs/ntfs3: fix mount failure on 64K page-size kernels a318932065883 fs/ntfs3: add bounds check to run_get_highest_vcn() 097fcf945d93a HID: logitech-hidpp: remove excess kernel-doc member in hidpp_scroll_counter 26fa946925a09 clk: at91: keep securam node alive while mapping it 0147c544cbc6e iio: tcs3472: power down chip on probe failure 1cddef80a180a iio: accel: mma8452: handle I2C read error(s) in mma8452_read() 9ac3675bf8757 iio: adc: xilinx-ams: fix out-of-bounds channel lookup in event handling 3d57672119525 iio: magnetometer: ak8975: fix potential kernel stack memory leak 6ec473b360342 iio: light: si1133: prevent race condition on timeout f835b69fbeaeb iio: light: si1133: reset counter to prevent race condition fd6b65ade1190 perf header: Sanity check HEADER_EVENT_DESC attr.size before swap be62602fe0797 PCI: qcom: Disable ASPM L0s for SA8775P de93ef83f99e8 powerpc tools perf: Initialize error code in auxtrace_record_init function 96c8f732cadf7 clk: renesas: rzg2l: Rename iterator in for_each_mod_clock() to avoid shadowing fdee9f207a48c gpib: fix double decrement of descriptor_busy in command_ioctl() 3d5e4cc0d9dce char: tlclk: fix use-after-free in tlclk_cleanup() d72ece584c448 gpib: Fix inappropriate ioctl error return 92f8b1d833834 perf test amd ibs: Fix incorrect kernel version check 2b2b1613b734b usb: host: max3421: Reject hub port requests for non-existent ports 02d03c61e8a7b usb: host: max3421: Fix shift-out-of-bounds in max3421_hub_control() 43078449ad623 staging: most: video: avoid double free on video register failure 45652323ce74b perf inject: Add --convert-callchain option 28ebd287a7fad perf build-id: Fix off-by-one bug when printing kernel/module build-id fc5ce5606db57 PCI: dwc: Fix signedness bug in fault injection test code 7d881615fb637 mailbox: mtk-adsp: fix UAF during device teardown 91353d63bbf61 mailbox: mpfs: fix check for syscon presence in mpfs_mbox_inbox_isr() e6bc4e127707d coresight: Fix source not disabled on idr_alloc_u32 failure 67d0475e78b39 soundwire: intel_ace2x: release bpt_stream when close it 5732869c70d42 clk: at91: sam9x7: Fix gmac_gclk clock definition f28906e7e32fd perf pmu: Skip test on Arm64 when #slots is zero 210c202c0576b phy: phy-can-transceiver: Check driver match and driver data against NULL 226feccaac818 clk: qcom: cmnpll: Account for reference clock divider 6abdf27fbcfb3 coresight: fix missing error code when trace ID is invalid 5bb87456dcd66 bus: mhi: ep: Fix potential deadlock in mhi_ep_reset_worker() 601a9b2e3b2fb rust: alloc: fix assert in `Vec::reserve` doc test b773c7161cea7 PCI: loongson: Do not ignore downstream devices on external bridges e1b79f77336d1 perf sched: Add missing mmap2 handler in timehist c788955b4a145 platform/x86: xo15-ebook: Fix wakeup source and GPE handling 2ce4d93768d2c x86/platform/olpc: xo15: Drop wakeup source on driver removal 1d495446ec7ac PCI: Check ROM header and data structure addr before accessing 78f264c0cb2ac PCI: Introduce named defines for PCI ROM 10021c2d33061 PCI/ASPM: Don't reconfigure ASPM entering low-power state 48dde5c56426c coresight: etm4x: Correct TRCVMIDCCTLR1 save and restore 65d87f28daec3 coresight: ete: Always save state on power down 1ac8f4c112aa9 coresight: etm4x: Remove the state_needs_restore flag a454f61747c97 soundwire: fix bug in sdw_add_element_group_count found by syzkaller d3896c944338c soundwire: don't program SDW_SCP_BUSCLOCK_SCALE on a unattached Peripheral c3ca7c6741af3 coresight: cti: Fix DT filter signals silently ignored fb940466fd4d3 perf debuginfo: Fix libdw API contract violations bb3d592c7d6c4 staging: nvec: fix use-after-free in nvec_rx_completed() 466c7f87de52d i3c: master: svc: Fix missed IBI after false SLVSTART on NPCM845 db2d8b6525bdd gpiolib: acpi: Only trigger ActiveBoth interrupts on boot 02e2dadd62eae eventpoll: Fix epoll_wait() report false negative f938bc8fde518 eventpoll: rename epi->next and txlist for clarity 430dac191905b eventpoll: wrap EP_UNACTIVE_PTR in typed sentinel helpers d8f88803152f0 eventpoll: extract ep_deliver_event() from ep_send_events() 4fd51f413d7b5 eventpoll: split ep_insert() into alloc + register stages 25e85dc040a6c eventpoll: rename attach_epitem() to ep_attach_file() baebd892f8a2c eventpoll: expand top-of-file overview / locking doc f04166c8677aa eventpoll: rename ep_remove_safe() back to ep_remove() 13bf9879b778b net/9p: fix race condition on rdma->state in trans_rdma.c 9c1c120471a67 9p: avoid returning ERR_PTR(0) from mkdir operations ae1f3460833d3 ocfs2: fix circular locking dependency in ocfs2_dio_end_io_write d35e4032f16d7 mfd: cs42l43: Sanity check firmware size 706fe1ce4f3a5 mfd: rsmu: Fix page register setup 35d3d6ff2bc1e ksmbd: fix use-after-free in same_client_has_lease() aa0c43c13c0bf RDMA/bnxt_re: Fail DBR related page allocation UAPIs if the feature is disabled 0fe155aa844e4 RDMA/bnxt_re: Move the UAPI methods to a dedicated file 95d46a8d3ba9f RDMA/bnxt_re: Avoid displaying the kernel pointer 104a7ff382a58 RDMA/bnxt_re: Free SRQ toggle page after firmware teardown 5a48dd5150d7c ionic: Fix check in ionic_get_link_ext_stats 4c55003566c0b net: ethernet: oa_tc6: Remove FCS size in RX frame 93e133b9193cb net: airoha: Fix always-true condition in PPE1 queue reservation loop d774cdbda6634 tcp: ipv6: clamp default adverting MSS to avoid GSO_BY_FRAGS (0xFFFF) 0d8a12d714312 tipc: fix UAF in tipc_l2_send_msg() db1616263a2c5 KEYS: Use acquire when reading state in keyring search 66919a6d72b9e powerpc/kexec: fix double get_cpu() imbalance in kexec_prepare_cpus 527cd14a416f2 powerpc/powernv: fix preempt count leak in pnv_kexec_wait_secondaries_down 73711688479df powerpc/perf: fix preempt count underflow in fsl_emb_pmu_del 92f38fe85198a MIPS: mm: Fix out-of-bounds write in maar_res_walk() fe09dd288722f bpf, sockmap: fix integer overflow in bpf_msg_pop_data() bounds check 81567d2b3f4dc sockmap: Fix use-after-free in udp_bpf_recvmsg() 073d957252696 net: remove addr_len argument of recvmsg() handlers 4e40056bb5c82 bpf, sockmap: reject overflowing copy + len in bpf_msg_push_data() 264d6a79c96ee udf: fix nls leak on udf_fill_super() failure 5e8627b7a7b7c bpf: Fix bpf_get/setsockopt to tos for ipv4-mapped ipv6 socket e803077769248 selftests/bpf: Initialize operation name before use 9f32d4c2de85f selftests/bpf: Fix typo in verify_umulti_link_info 74badb5e2b00a smb/client: always return a value for FS_IOC_GETFLAGS 21303c4a2b727 cifs: remove all cifs files before kill super 7a59146cb9ade ALSA: core: Fix unintuitive behavior of snd_power_ref_and_wait() 87d1eaffeec41 netfilter: nf_conncount: callers must hold rcu read lock 98a965cb1e767 ALSA: seq: avoid stale FIFO cells during resize 287d506d4e086 ALSA: seq: oss: Serialize readq reset state with q->lock f01fb6138f8eb kcm: use WRITE_ONCE() when changing lower socket callbacks 4d48c08a0bf6c net: airoha: Fix debugfs new-tuple display for IPv4 ROUTE entries dcac6e4221f39 net: airoha: Fix register index for Tx-fwd counter configuration 36edab340a067 net: bcmgenet: Use weighted round-robin TX DMA arbitration b91b241a4eefe landlock: Fix unmarked concurrent access to socket family 1bb02353e79f7 dpll: balance create/delete notifications in __dpll_pin_(un)register 77a1ea975c877 dpll: guard sync-pair removal on full pin unregister 8008ef973f012 dpll: emit per-dpll delete notifications in dpll_pin_on_pin_unregister() 6564ce3a2f9c2 dpll: send delete notification before unregister in on-pin rollback f1e1c6eb82482 dpll: fix stale iteration in dpll_pin_on_pin_unregister() 20575400fc1ba dpll: Enhance and consolidate reference counting logic ebe4bd3560a7a dpll: Support dynamic pin index allocation f7aebaee2961b net: wwan: t7xx: check skb_clone in control TX 34bd255dba321 net: ethernet: mtk_wed: debugfs: correct index in wed_amsdu_show() 1d072cc3ba433 octeontx2-af: npc: Fix size of entry2cntr_map 417bd36a085d7 bpf: Fix setting retval to -EPERM for cgroup hooks not returning errno 3d90b15fb1918 net/mlx5: Check max_macs devlink param value against max capability 8d5f4be134882 bpf: Run generic devmap egress prog on private skb 450e48271827b net/sched: sch_dualpi2: Add missing module alias 6d585d0dc6743 net: ethernet: mtk_wed: fix loading WO firmware for MT7986 446fe8ce699ce net: watchdog: fix refcount tracking races 697db22a9dcc4 net: mana: guard TX wq object destroy with INVALID_MANA_HANDLE check 62ce489acb428 net: mana: initialize gdma queue id to INVALID_QUEUE_ID bd851b10daee7 net/sched: sch_dualpi2: Do not call qdisc_tree_reduce_backlog during peek before restoring qlen 755108bb7a508 net/sched: sch_codel: Do not call qdisc_tree_reduce_backlog during peek before restoring qlen 0500af8630c32 net/sched: sch_fq_codel: Do not call qdisc_tree_reduce_backlog during peek before restoring qlen a05d638b60746 virtio_net: do not allow tunnel csum offload for non GSO packets ce311bd2e3659 tcp: clear sock_ops cb flags before force-closing a child socket 67cec2f1eb9e5 handshake: Require admin permission for DONE command d0503357653ee power: supply: core: fix supplied_from allocations 7f4aa81f5bb27 ASoC: adau1372: Clear PLL_EN on failed PLL lock without reset GPIO 0c22c00924359 iommu: Avoid copying the user array twice in the full-array copy helper 1c9246a199e19 spi: xilinx: use FIFO occupancy register to determine buffer size dae23c545eb5a ALSA: seq: Fix kernel heap address leak in bounce_error_event() 1749fef4bda0f ALSA: usb-audio: qcom: Guard sideband endpoint removal 2ba2373151936 crypto: rng - Free default RNG on module exit fb4d57b83356d crypto: cavium/cpt - fix DMA cleanup using wrong loop index 5f99a396f706a crypto: marvell/octeontx - fix DMA cleanup using wrong loop index 4941205f5fa39 cxl/test: Add check after kzalloc() memory in alloc_mock_res() a27481516d32f cxl/test: Unregister cxl_acpi in cxl_test_init() error path 7e401233f9bb7 tipc: reject inverted service ranges from peer bindings 3cfa3d8e0dc16 tipc: prevent snt_unacked underflow on CONN_ACK cebaefe1aceb6 tipc: require net admin for TIPCv2 netlink mutators 66dbb13eeb2fc net/sched: sch_hfsc: Don't make class passive twice 51a1d9836acc7 net: pfcp: allocate per-cpu tstats for PFCP netdevs ed8605c6f39b9 sctp: validate embedded address parameter length a090880c1f544 bridge: cfm: reject invalid CCM interval at configuration time bb4a5b3c91af3 net: fib_rules: Don't dump dying fib_rule in fib_rules_dump(). 0a8b5b74f0e6b net/sched: cls_flow: Dont expose folded kernel pointers 10e05634ddc19 net: dsa: qca8k: fix led devicename when using external mdio bus e098c9c6477df ASoC: tegra: tegra210_ahub: Validate written enum value 0f1510e84d7bf ASoC: fsl: fsl_audmix: Validate written enum values 9131e4b023e0d ASoC: codecs: hdac_hdmi: Validate written enum value cb527e063a32e ASoC: SOF: Intel: hda-sdw-bpt: select SND_SOF_SOF_HDA_SDW_BPT properly d3ff718c0c715 RDMA/mlx5: Release the HW‑provided UAR index rather than the SW one 4b87a2497276a RDMA/mlx5: Fix undefined shift of user RQ WQE size 1bc1487f7a7f5 RDMA/mlx5: Remove raw RSS QP restrack tracking f704db4b0318a RDMA/mlx5: Remove DCT restrack tracking 3a1687e0506be fs: efs: remove unneeded debug prints 7e694ac97591c Bluetooth: vhci: validate devcoredump state before side effects ec4d352747a62 Bluetooth: hci: validate codec capability element length 7f206a8d8d822 Bluetooth: btmtk: fix URB leak in alloc_mtk_intr_urb error path a0fd1086a57b9 Bluetooth: hci_core: Fix UAF in hci_unregister_dev() e8815ae9dcdc5 Bluetooth: hci_event: fix simultaneous discovery stuck in FINDING f1b4df9c260c5 Bluetooth: eir: Fix stack OOB write when prepending the Flags AD e284bb94ad451 Bluetooth: hci_qca: fix NULL pointer dereference in qca_dmp_hdr() for non-serdev device c86c861c64b58 s390/process: Fix kernel thread function pointer type 0eab19ab9cb1b ASoC: cs35l56: Fix possible uninitialized value in cs35l56_spi_system_reset() c83255f3cf22d arm64: dts: allwinner: a523: Add missing GPIO interrupt ad6963c3bb458 pinctrl: airoha: an7581: fix misprint in gpio19 pinconf 5985ddfd3e83f pinctrl: airoha: an7581: add missed gpio32 pin group db3cd694ded4c pinctrl: airoha: generalize pins/group/function/confs handling 0234e8fc296e7 pinctrl: sunxi: a523: Remove unneeded IRQ remuxing flag 46fbafe3d2d56 bpf: Tighten cgroup storage cookie checks for prog arrays d416dcefdbac9 vfio/qat: fix f_pos race in qat_vf_resume_write() 1201dbb260507 of: cpu: add check in __of_find_n_match_cpu_property() d2acea4f47475 cxl/test: Zero out LSA backing memory to avoid leaking to user 42a9a76f314ef cxl/test: Fix integer overflow in mock LSA bounds checks 91ad3088ee1b7 selftests/bpf: Fix bpf_iter/task_vma test f00f5c0dd5531 ext4: fix kernel BUG in ext4_write_inline_data_end c998a09c7144e bonding: 3ad: fix mux port state on oper down f0ada4846d11b bonding: 3ad: fix carrier when no usable slaves cb20a9b50efe0 bonding: 3ad: add lacp_strict configuration knob 47636f0a70b36 netlink: specs: rt-link: missed broadcast-neigh 6b2c271d2c394 tools: missed broadcast_neigh if_link uapi header 484b3b9aa7986 ext4: fix ERR_PTR(0) in ext4_mkdir() 88cb304c0be0c ASoC: cs35l56: Don't leave parent IRQ disabled if system_suspend fails 8b55e7ec116ca ASoC: cs35l56: Fix missing calls to wm_adsp2_remove() 3ef0cfa77a3d5 vdpa/octeon_ep: fix IRQ-to-ring mapping in interrupt handler 54556d5394382 vdpa/octeon_ep: Fix PF->VF mailbox data address calculation 86e0b37738dea tools/virtio: check mmap return value in vringh_test 321c73baf54d9 vhost/net: complete zerocopy ubufs only once 646614dcb1607 vduse: Requeue failed read to send_list head f9d9220234451 virtio_console: read size from config space during device init 79366023aa891 virtio: rtc: tear down old virtqueues before restore 1f5f94c6c6b2e vhost/vdpa: validate virtqueue index in mmap and fault paths a2d0a57538fd0 vduse: hold vduse_lock across IDR lookup in open path 3d56f3fb201ff ASoC: codecs: aw88261: fix incorrect masks for boost regs ecb9be4fc8be0 spi: meson-spifc: fix runtime PM leak on remove da6f86ff4f2dd NFSD: Handle layout stid in nfsd4_drop_revoked_stid() 37e85be551c4d IB/mlx4: Fill in the access_flags if IB_MR_REREG_ACCESS is not specified e6d83f877d5ab ASoC: sma1307: Fix uevent string leaks in fault worker 701ea71c17c92 igc: skip RX timestamp header for frame preemption verification 2aa37c8ef1092 btrfs: fix deadlock cloning inline extent when using flushoncommit f85410ebf20bb btrfs: annotate lockless read of defrag_bytes in should_nocow() 18285888cb41a btrfs: zoned: always set max_active_zones for zoned devices 943f5917c53ca Revert "btrfs: fix the file offset calculation inside btrfs_decompress_buf2page()" ba641829c11cb btrfs: zoned: don't account data relocation space-info in statfs free space bd5e90b0f5a09 hwmon: (it87) Clamp negative values to zero in set_fan() ebb579c5c0f0f vfs: add FS_USERNS_DELEGATABLE flag and set it for NFS de590cdf7efec fbdev: sm501fb: Fix buffer errors in OF binding code 0678fed27def9 wifi: ath12k: enable IEEE80211_VHT_EXT_NSS_BW_CAPABLE when NSS ratio is reported 47e5302722e09 gpio: mt7621: fix interrupt banks mapping on gpio chips 90a9c909c5b75 ALSA: aloop: Drop superfluous break 3b15d02be05e7 btrfs: fix invalid pointer dereference in __btrfs_run_delayed_refs() 7ec839c7c0bc1 wifi: mt76: mt7996: fix potential tx_retries underflow ad12fdaaed16c wifi: mt76: mt7925: fix potential tx_retries underflow 3b6e6fefa57f4 wifi: mt76: mt7921: fix potential tx_retries underflow 6b8e35685c18c wifi: mt76: mt7915: fix potential tx_retries underflow 6356a829a1edc wifi: mt76: fix argument to ieee80211_is_first_frag() 42f34c478fcdf wifi: mt76: mt7996: limit work in set_bitrate_mask 1a399103cacc9 wifi: mt76: mt7996: fix reading zeroed info->control.flags after mt76_tx_status_skb_add() dfb27e5dd9e4d wifi: mt76: mt7996: Fix possible NULL pointer dereference in mt7996_mac_write_txwi_80211() 06e65d6cf8049 wifi: mt76: mt7996: Fix possible token leak in mt7996_tx_prepare_skb() c386e90a7ce8d wifi: mt76: mt7925: validate skb length in testmode query 856fa6a21586f wifi: mt76: mt792x: skip MLD header rewrite for 802.3 encap TX a10e4959a73be wifi: mt76: mt7925: keep TX BA state in the primary WCID b8bf7c221b364 wifi: mt76: mt7925: fix stale pointer comparisons in change_vif_links bd3b91ff13006 wifi: mt76: mt7996: add missing max_remain_on_channel_duration c7a83899203ed wifi: mt76: use kfree_rcu for offchannel link in mt76_put_vif_phy_link 3f0ea6d14fa44 wifi: mt76: mt7925: clean up DMA on probe failure ce9d5a021cfca ARM: configs: Drop duplicated CONFIG_EXT4_FS c788617705c3a sched/fair: Fix cpu_util runnable_avg arithmetic a2e8b5264f92e hwspinlock: qcom: avoid uninitialized struct members bbd664b7c77f6 vmalloc: fix NULL pointer dereference in is_vm_area_hugepages() 648a3960e3664 pinctrl: mediatek: mt8167: Fix Schmitt trigger register offset of pins 34-39 44cff0737127b pinctrl: mediatek: mt8516: Fix Schmitt trigger register offset of pins 34-39 f775e7bda9a4f scsi: target: Remove tcm_loop target reset handling c2bd9fdb448d6 scsi: target: Fix hexadecimal CHAP_I handling 0404baeb9e430 pinctrl: qcom: Fix resolving register base address from device node 298821692d447 watchdog: unregister PM notifier on watchdog unregister 637ef4961470e configfs: fix lockless traversals of ->s_children f25d6e4ec4c25 firmware_loader: Fix recursive lock in device_cache_fw_images() 9e82497138abe ASoC: amd: acp-sdw-sof: Bound DAI link iteration 1279bdab5fa1f ASoC: amd: acp-sdw-legacy: Bound DAI link iteration e8d89baf92170 spi: ep93xx: fix double-free of zeropage on DMA setup failure e123f0ab02d05 IB/mlx5: Don't mangle the mr->pd inside the rereg callback fd284b12810e4 IB/mlx5: Pull the pdn out of the depths of the umr machinery 8119fe468b01f IB/mlx5: Remove unused mkc bits in mlx5r_umr_update_mr_page_shift() d4f84bfa089fe IB/mlx5: Properly support implicit ODP rereg_mr f5657d399b7ef IB/mlx5: Don't take the rereg_mr fallback without a new translation c213b71a2d416 btrfs: don't force DIO writes to be serialized 920dcf1cb8dae thermal: testing: reject missing command arguments dde04550fd6ff cpufreq: Documentation: fix conservative governor freq_step description 6cb635ad1006d ACPI: IPMI: Fix message kref handling on dead device b7474f4432dd9 bpf: Fix NULL pointer dereference in bpf_task_from_vpid() 84932636d020b powerpc/8xx: implement get_direction() in cpm1 8daa1a64711ed kunit:tool: Don't write to stdout when it should be disabled 8b0510cc3a4a0 bpf: Fix NMI/tracepoint re-entry deadlock on lru locks 74ac1ce1f4afd ALSA: seq: Clear variable event pointer on read c04e0cde2fa38 riscv: stacktrace: Remove bogus -0x4 offset in non-FP walk_stackframe 834d4cc067fa6 riscv: cpu_ops: Change return value type of cpu_is_stopped() to bool 4b2b6bc7f5ebe ALSA: seq: Fix partial userptr event expansion af8f0ea1f0a3a wifi: wcn36xx: fix OOB read from short trigger BA firmware response f03782f7f41f2 wifi: wcn36xx: fix OOB read from firmware count in PRINT_REG_INFO indication 1b5d8a248c3af wifi: wcn36xx: fix heap overflow from oversized firmware HAL response 495e7e832c670 bpf: Update transport_header when encapsulating UDP tunnel in lwt efe57b72196ae bpf: Check tail zero of bpf_prog_info 58513d6d12410 bpf: Check tail zero of bpf_map_info 2eb39de4962f8 bpf: Clear rb node linkage when freeing bpf_rb_root f6183983ce1ff RDMA/siw: Fix endpoint/socket association handling 04255bda8d795 arm64: dts: imx8mp-kontron: Fix GPIO for display power switch e6ab22200e449 arm64: dts: tqma8mpql-mba8mpxl: configure sai clock in audio codec as well f3ef944c55991 arm64: dts: lx2162a-clearfog: use rev2 SoC dtsi b5087fc4ef1f8 arm64: dts: imx95: Correct PCIe outbound address space configuration ab4b5a07e1c1a arm64: dts: imx8mp-kontron: Reduce EERAM SPI clock frequency f9173e0fc026c RDMA/irdma: Initialize iwmr->access during MR registration 54cab78df0375 RDMA/irdma: Fix OOB read during CQ MR registration 844a1ae78e220 ALSA: hda: fix Kconfig dependency of HD Audio PCI 47831b503ecb7 IB/cm: Fix av cm device leak on an error path in cm_init_av_by_path() fe5414d6b3995 RDMA/hfi1: Open-code rvt_set_ibdev_name() 77b4bfc1ce32a netfilter: conntrack: call nf_ct_gre_keymap_destroy() if master helper is pptp d53eecbca16f0 netfilter: conntrack: revert ct extension genid infrastructure e6665d36b37b4 x86/cpu: Remove obsolete aperfmperf_get_khz() declaration dd0d22fdae4cb ALSA: usb-audio: qcom: Initialize offload control return value 8ebc31b86dccd netfilter: synproxy: protect nf_ct_seqadj_init() with conntrack lock 5c9c67cf7a3d1 netfilter: synproxy: fix unaligned memory access in timestamp adjustment b171119082bab netfilter: synproxy: adjust duplicate timestamp options 4dbb71c046f72 netfilter: synproxy: drop packets if timestamp adjustment fails dce1e3cf735d1 netfilter: nfnetlink_cthelper: use {READ,WRITE}_ONCE for accessing helper flags 7b819a84f1d5f netfilter: nfnetlink_osf: fix mss parsing on big-endian architectures c3ebf67cf8a96 ocfs2: fix race between ocfs2_control_install_private() and ocfs2_control_release() a087b2d3411e7 ocfs2/dlm: require a ref for locking_state debugfs open 3fa7139b5f427 ocfs2: reject FITRIM ranges shorter than a cluster 0e389fc290c35 ocfs2: fix buffer head management in ocfs2_read_blocks() 3fe2d0d21c8ae lib: kunit_iov_iter: repeatedly call alloc_pages_bulk() bb44a7690a4d5 ocfs2: rebase copied fsdlm LVB pointers in locking_state 9af58d10d0d8c of: reserved_mem: avoid post-init UAF when alloc_reserved_mem_array() fails 9a030fcb4b192 drm/amdkfd: always resume_all after suspend_all b8d15e85596ad cxl/fwctl: Fix __fortify_panic b64120d54278e xfrm: fix NAT-related field inheritance in SA migration ac9e29b191a03 perf/x86/amd/uncore: Use Node ID to identify DF and UMC domains 58cbb1c2aadf8 perf/x86/intel/uncore: Fix discovery unit lookup for multi-die systems 4e18e9361aab0 perf/x86/amd/core: Always use the NMI latency mitigation f5102e0fc3c6d iommu/vt-d: Fix RB-tree corruption in probe error path 7f229d27bf27c vhost: fix vhost_get_avail_idx for a non empty ring 73f9f54d71749 bpftool: Use libbpf error code for flow dissector query 4beed798daf4d drm/amdgpu: set sub_block_index for mca ras sub-blocks e82d515092a0c ext4: fix fast commit wait/wake bit mapping on 64-bit 8cbd587e8cdb6 lockdep/selftests: Restore sched_rt_mutex state on PREEMPT_RT 8d5ed4810e479 lockdep/selftests: Restore migrate_disable() state on PREEMPT_RT c3b073a209a9b configfs_lookup(): don't leave ->s_dentry dangling on failure 778bb4939d457 riscv: dts: sophgo: sg2042: use hex for CPU unit address efe71fbced524 riscv: dts: sophgo: sg2044: use hex for CPU unit address 5a1168ba0a95b lib/test_meminit: use && for bools 3777588848520 tick/sched: Fix TOCTOU in nohz idle time fetch 5cf2c85b12312 bpf: Reject exclusive maps for bpf_map_elem iterators 0830287cc6cb7 driver core: Use system_percpu_wq instead of system_wq 5e406928404d6 nvme: fix FDP fdpcidx bounds check 36bdda0c86d51 sched: restore timer_slack_ns when resetting RT policy on fork ffa974b2f50ad ext2: fix ignored return value of generic_write_sync() 8d763babb2a2f mm/fake-numa: fix under-allocation detection in uniform split 61f1972972824 bpf: fix UAF by restoring RCU-delayed inode freeing in bpffs d81370c6c4f5f scsi: ufs: Fix wrong value printed in unexpected UPIU response case 846052542cfa6 scsi: pm8001: Fix error code in non_fatal_log_show() 0de14eae6de88 libbpf: Skip max_entries override on signed loaders abe383999640f libbpf: Skip initial_value override on signed loaders b6862b6a25c6a libbpf: Reject non-exclusive metadata maps in the signed loader 3a0f73d27a8d3 bpf: Reject exclusive maps as inner maps in map-in-map 91ca9eab008b9 scsi: Revert "scsi: Fix sas_user_scan() to handle wildcard and multi-channel scans" 5c53406098b59 nvdimm/btt: Handle preemption in BTT lane acquisition d292b30e1b746 x86/cpu: Keep the PROCESSOR_SELECT menu together 901802925ebed ARM: imx31: Fix IIM mapping leak in revision check 617a5a67ce016 ata: libata: Fix ata_exec_internal() cfcea221db933 wifi: ath12k: fix NULL deref in change_sta_links for unready link eb9b89baf3087 wifi: ath12k: fix incorrect HT/VHT/HE/EHT MCS reporting in monitor mode adf0eb748d21d HID: wiimote: Fix table layout and whitespace errors 2d642797dd1c1 ARM: imx3: Fix CCM node reference leak f0742d09eb6ba NFSD: Fix delegation reference leak in nfsd4_revoke_states 9e565962d999e ASoC: rsnd: Fix RSND_SOC_MASK width to single nibble 8ec64276ecd24 spi: atmel: fix DMA channel and bounce buffer leaks ab4d04bf8b2f3 ext4: fix LOGFLUSH shutdown ordering to allow ordered-mode data writeback 803087a16a4ea libbpf: Skip endianness swap when loader generation failed f3389fbaff1a1 libbpf: Skip hash computation when loader generation failed a441c0794ac28 selftests/bpf: add verification for BPF_PROG_QUERY attr size boundaries a7131340d0f95 bpf: fix BPF_PROG_QUERY OOB write and cgroup backward compat 5ac9e793ba258 raid1: fix nr_pending leak in REQ_ATOMIC bad-block error path b7313f23ea5a7 md/raid10: reset read_slot when reusing r10bio for discard e04e384274f83 rpmsg: use generic driver_override infrastructure 0e2f0833556c8 Drivers: hv: vmbus: use generic driver_override infrastructure d2cf52ba2803b cdx: use generic driver_override infrastructure b41923dbf6769 amba: use generic driver_override infrastructure ff4e38a37ba53 media: qcom: venus: relax encoder frame/blur step size on v6 bc7c166cc1012 media: qcom: venus: relax encoder frame/blur dimension steps on v4 ffe754288750a media: qcom: venus: drop extra padding in NV12 raw size calculation f8f48c851a0d2 Revert "media: venus: hfi_platform: Correct supported codecs for sc7280" 5420eebf3b3c1 RDMA/rxe: Copy WQE to local buffer in non-SRQ receive path 02558c86b6b76 RDMA/rxe: Fix TOCTOU heap overflow in get_srq_wqe 4779f435627b2 RDMA/umem: Add ib_umem_is_contiguous() stub for !CONFIG_INFINIBAND_USER_MEM bae436a78a058 arm64: dts: st: Fix SAI addresses on stm32mp251 5da012c605fd5 EDAC/{skx_common,skx}: Fix UBSAN shift-out-of-bounds in skx_get_dimm_info 9a84ced0243c7 EDAC/igen6: Fix call trace due to missing release() ed5c94cf4ee9e drm/msm/dp: Fix the ISR_* enum values bdaea74abcf0c drm/msm/dp: fix HPD state status bit shift value 6d536a9107172 sched/deadline: Reject debugfs dl_server writes for offline CPUs 4f3c17f14cf90 crypto: tegra - Return ENOMEM when input buffer allocation fails for ccm 5eac10c521396 crypto: tegra - Fix dma_free_coherent size error 5231093c08295 crypto: inside-secure/eip93 - Add check for devm_request_threaded_irq 8572232ed74f5 crypto: hisilicon/qm - disable error report before flr ce7a2e26e144f ocfs2: kill osb->system_file_mutex lock 3852478d34c7b ocfs2: don't BUG_ON an invalid journal dinode 070f356ea4f41 rapidio/tsi721: prevent a bad dereference in tsi721_db_dpc() 598ed7393a639 dax/kmem: account for partial discontiguous resource upon removal afdb92d9c374d arm64: tegra: Add #{address,size}-cells to Chromium-based /firmware e545fcba3660c ARM: tegra: Add #{address,size}-cells to Chromium-based /firmware c87339cc08aa0 libbpf: Fix UAF in strset__add_str() 39e8be33387e3 bpftool: Fix typo in struct_ops map FD generation for light skeleton ed7ba8d048a4c libbpf: Harden parse_vma_segs() path parsing 340936ebf5aec drm/nouveau/bios: specify correct display fuse register for Ampere and Ada 2ab7c96d8c3fb drm/tegra: Fix iommu_map_sgtable() return value check 79240eee5a400 gpu: host1x: Fix iommu_map_sgtable() return value check 142b34f7e329c drm/tegra: dc: Fix device node reference leak in tegra_dc_has_output() 8c0d3cf0d5108 gpu: host1x: Allow entries in BO caches to be freed 6b617b6ccb6eb drm/tegra: gr2d/gr3d: Contain PM in the gr*d_probe/gr*d_remove 40a2a91da02c4 drm/tegra: gr2d/gr3d: Initialize address register map before HOST1X client is registered 05d85fd32e4fe rtla/actions: Restore continue flag in actions_perform() b7ac7ba19a0b8 rtla: Introduce for_each_action() helper dc266f6c4e262 iommu/amd: Fix premature break in init_iommu_one() 10753da2d659d net/sched: cls_bpf: prevent unbounded recursion in offload rollback 0db1949084e85 ipv6: guard against possible NULL deref in __in6_dev_stats_get() dc1470299d11d workqueue: drop spurious '*' from print_worker_info() fn declaration 3e8aed5edaeeb nvme-pci: fix out-of-bounds access in nvme_setup_descriptor_pools 140d6fff4ed26 nvme-multipath: fix flex array size in struct nvme_ns_head cba2ee57fd302 nvmet-tcp: check return value of nvmet_tcp_set_queue_sock ba3209704b3cd nvmet-tcp: fix page fragment cache leak in error path 24639c4dc466e init/initramfs_test: wait_for_initramfs() before running eb9280ea8dbd2 pinctrl: cs42l43: Fix polarity on debounce 2739d234d8952 pinctrl: cs42l43: Fix leaked pm reference on error path 95e0b4bc29ab9 pinctrl: nuvoton: ma35d1: fix MFP register offset and pin table c418c956c21c9 selftests: Fix Makefile target for nsfs 11165fe2c5ea0 ALSA: seq: midi: Serialize output teardown with event_input 6dc781778b595 ALSA: seq: oss: Fix UAF at handling events with embedded SysEx data de236b813d8b4 ALSA: xen-front: Connect event channel after stream prepare 56694f00fbe10 ALSA: xen-front: Reset event channel state on stream clear 02f156309de0d mtd: spi-nor: Drop duplicate Kconfig dependency c4bb92b3ef54c mtd: spi-nor: debugfs: Fix the flags list 3880ee7c88d78 driver core: Guard deferred probe timeout extension with delayed_work_pending() 0a294feec21b6 driver core: Fix missing jiffies conversion in deferred_probe_extend_timeout() 2c12b0dfcedad mips: n64: add __iomem for writel call 8db227dd895a8 mips: ralink: mt7621: add missing __iomem 0c83d13f9b3f1 MIPS: DEC: Remove do_IRQ() call indirection c9a3ceeddc6ad MIPS: Fix big-endian stack argument fetching in o32 wrapper c9670fd84df12 PM: sleep: Use complete() in device_pm_sleep_init() 80f8e2302e639 pinctrl: meson: amlogic-a4: fix gpio output glitch 9420871183eab RDMA/counter: Fix incorrect port index in rdma_counter_init() error cleanup 66f44ec974ab3 RDMA/hns: Fix log flood after cmd_mbox failure 16138ea9833d6 RDMA/hns: Fix warning in poll cq direct mode f67fbbfc3beb8 IB/mlx4: Fix refcount leak in add_port() error path e59a6aa89e0fc RDMA/rxe: Fix a use-after-free problem in rxe_mmap 424d51d33c754 RDMA/irdma: Fix out-of-bounds write in irdma_copy_user_pgaddrs 7a551951ebeb5 pinctrl: spacemit: fix NULL check in spacemit_pin_set_config 394ed8ad05889 bus: sunxi-rsb: Always check register address validity 090f5fb1e3e23 RDMA/mana_ib: Use ib_get_eth_speed for reporting port speed c11039512df49 pwm: imx27: Fix variable truncation in .apply() 13db458099f28 cpufreq: conservative: Simplify frequency limit handling 3fcbfc50dd52f cpufreq: Documentation: fix sampling_down_factor range 376951c51cdd0 crypto: eip93 - fix reset ring register definition 4a6f5cc42c7bf of: dynamic: Fix overlayed devices not probing because of fw_devlink ae62edb00c0eb Revert "treewide: Fix probing of devices in DT overlays" 2df37ead6d84b driver core: Use mod_delayed_work to prevent lost deferred probe work 62c8cc825f49e device property: fix fwnode reference leak in fwnode_graph_get_endpoint_by_id() b0444205ba39e kernfs: fix suspicious RCU usage in kernfs_put() 29de8448174cf writeback: drop now-unnecessary rcu_barrier() in cgroup_writeback_umount() 2469039f0fd68 arm64: dts: qcom: lemans: Add eDP ref clock for eDP PHYs baa333b2700a7 tracing: Bound synthetic-field strings with seq_buf 09a2a7d041a78 arm64: dts: qcom: sm8750: Add power-domain and iface clk for ice node 4ba44339fd3ac arm64: dts: qcom: sm8650: Add power-domain and iface clk for ice node 3c808cac676c5 arm64: dts: qcom: sm8550: Add power-domain and iface clk for ice node 0d0ce8c7025ac arm64: dts: qcom: sm8450: Add power-domain and iface clk for ice node a8be1bc8d124f arm64: dts: qcom: kodiak: Add power-domain and iface clk for ice node dc36463b283d9 arm64: dts: qcom: sc7180: Add power-domain and iface clk for ice node a2303478e7301 arm64: dts: qcom: monaco: Add power-domain and iface clk for ice node b3e05859cb516 arm64: dts: qcom: lemans: Add power-domain and iface clk for ice node 11daac2817dca firmware: arm_scmi: Fix OOB in scmi_power_name_get() 15e7368de5842 media: rockchip: rga: fix too small buffer size a88f6da618e8b net/sched: sch_drr: annotate data-races around cl->deficit 276e731b1b577 nilfs2: Fix return in nilfs_mkdir 16bf3154f8a80 tools/nolibc: getopt: Fix potential out of bounds access c67c672047667 regulator: dt-bindings: mt6359: Drop regulator-name pattern restrictions 75c0bc011abdd bitops: use common function parameter names 407aeb8c1aee8 sysfs: clamp show() return value in sysfs_kf_read() bac3e70c2fb10 firmware: arm_scmi: Read sensor config as 32-bit value 1f60c3cc302d2 firmware: smccc: Fix Arm SMCCC SOC_ID name call 3024229e4a5af riscv: dts: spacemit: set console baud rate on Milk-V Jupiter 63aa7dda9a1ed staging: media: atomisp: fix loop shadowing in ia_css_stream_destroy() d57e67ea48e4d media: atomisp: gc2235: fix UAF and memory leak 2e3e4cc0dd349 media: atomisp: Fix memory leak in atomisp_fixed_pattern_table() 5d6f34dc4f056 arm64: dts: imx95-19x19-evk: Fix PCIe EP vpcie-supply 084d7d5668f30 arm64: dts: imx8qxp-mek: Remove unnecessary PCIe EP vpcie-supply 6a576739ce4c9 arm64: dts: imx8dxl-evk: Remove unnecessary PCIe EP properties 0da72a88dbbab firmware: arm_ffa: Honor partition info descriptor size 5e353d9497f95 selftests/mm: Fix resv_sz when parsing arm64 signal frame 6a357ceb21100 iommu/arm-smmu-qcom: Fix fastrpc compatible string in ACTLR client match table bcfc49f1bcf1b selftests/bpf: Fix test for refinement of single-value tnum e4d599a286b5a selftests/bpf: Reject unsupported -k option in vmtest.sh 7471006cd854d drm/syncobj: Fix memory leak in drm_syncobj_find_fence() be2c137f23d15 RDMA/hns: Initialize seqfile before creating file 65572fbd86033 RDMA/srpt: fix integer overflow in immediate data length check 5100febf8e9d6 RDMA/mlx5: Fix devx subscribe-event unwind NULL dereference ffa85a2c19793 RDMA/mlx5: Fix UMR XLT cleanup on ODP populate failure 2cd221fca036b RDMA/hns: Fix arithmetic overflow in calc_hem_config() 65e344925fa30 IB/mlx5: Fix transport-domain rollback and initialize lb mutex earlier b61af0268e3d1 ipv6: addrconf: bail out of dad_failure when state is no longer POSTDAD 5c1196b5a3bf3 net/sched: sch_htb: annotate data-races (I) d8cae30582f06 net/sched: sch_htb: do not change sch->flags in htb_dump() 68eae3592438d spi: hisi-kunpeng: Use dev_err_probe() for host registration failure 21650fe221ea9 crypto: ccp - Treat zero-length cert chain as query for blob lengths cb414aff28e18 scsi: hisi_sas: Add slave_destroy interface for v3 hw 8b42290df1765 net/sched: sch_hfsc: annotate data-races in hfsc_dump_class_stats() d29b9c38f6eb4 clk: scpi: Unregister child clock providers on remove 69bc4a3998742 thermal: hwmon: Fix critical temperature attribute removal a0f64cf8bfcb3 evm: terminate and bound the evm_xattrs read buffer 4c57df82af833 drm/hisilicon/hibmc: use clock to look up the PLL value 28b91fd2adc4f drm/hisilicon/hibmc: move display contrl config to hibmc_probe() 94ab8a6e02bae drm/hisilicon/hibmc: fix no showing when no connectors connected 689bb48c828ca drm/hisilicon/hibmc: add updating link cap in DP detect() 27af16a44f590 arm64: dts: qcom: sm8450: Fix ICE reg size 886fb63981a92 arm64: dts: qcom: kodiak: Fix ICE reg size 2e2e5888764ba clk: scmi: Fix clock rate rounding 8200ffd8259f0 rust: alloc: fix `Vec::extend_with` SAFETY comment 9fe7605c1c143 arm64: dts: mediatek: mt8192-asurada: Move PCIe DMA bounce buffer to host 02367b12b303a uaccess: fix ignored_trailing logic in copy_struct_to_user() e003f3a4be738 bpf: fix crash in bpf_[set|remove]_dentry_xattr for negative dentries 8960088511ca1 soc: mediatek: mtk-mmsys: Restore MT8167 routing masks lost during merge 0dd1cf48a4217 iommu/amd: Fix a stale comment about which legacy mode is user visible feb10ab7abc24 media: venus: scale MMCX power domain on SM8250 9e642727b97dd media: iris: scale MMCX power domain on SM8250 e725aedd26e96 media: qcom: camss: vfe: fix PIX subdev naming on VFE lite f9f1a2cd912da nilfs2: fix backing_dev_info reference leak 712714f818d83 dlm: fix add msg handle in send_queue ordered 4695cfab48f90 ARM: multi_v7_defconfig: Correct QCOM_RPMH and QCOM_RPMHPD 6acd2fbd00f9c crypto: asymmetric_keys - fix OOB read in pefile_digest_pe_contents 9b21d5bd33a7f crypto: ecrdsa - fix unknown OID check in ecrdsa_param_curve aac63bbea8fd5 crypto: atmel-sha204a - fix blocking and non-blocking rng logic c5c79d92da0f9 crypto: ccp - Fix snp_filter_reserved_mem_regions() off-by-one 25b0061adc1c1 crypto: ccp - Reverse the cleanup order in psp_dev_destroy() 46696b0b21234 OPP: Fix race between OPP addition and lookup 8fe4736532639 alarmtimer: Remove stale return description from alarm_handle_timer() 224d7300b5691 drm: renesas: rz-du: mipi_dsi: Fix return path on error 4a8cde6f7281e vxlan: Fix potential null-ptr-deref in vxlan_gro_prepare_receive(). 470984f1c2ed8 Revert "arm64: dts: imx8mp-kontron: Add support for reading SD_VSEL signal" 5f7777f0da030 Revert "arm64: dts: imx8mm-kontron: Add support for reading SD_VSEL signal" b9c6ad49a942d arm64: dts: imx8x-colibri: Correct SODIMM PAD settings a5e026d5b9487 arm64: dts: rockchip: fix rk809 interrupt pin on rk3566-roc-pc 6173c83d4d791 arm64: dts: rockchip: Add #{address,size}-cells to Chromium-based /firmware 2b553fcec1cd8 ARM: dts: rockchip: Add #{address,size}-cells to Chromium-based /firmware d003d9bb44da1 drm/panel: Clean up S6E3HA2 config dependencies and fill help text 76a4c3af3253d drm/gpuvm: take refcount on DRM device 02b001d89157a dt-bindings: vendor-prefixes: Add Displaytech Ltd. a402b3d093815 pinctrl: sunxi: fix regulator leak in sunxi_pmx_request() error path c599af2eacd66 dts: spacemit: set console baud rate on bpif3 796ff973077c7 lib/vsprintf: Fix to check field_width and precision 53baa6b90f499 crypto: qat - fix heartbeat error injection 928f758f8f214 memory: tegra: Wire up system sleep PM ops 2b2a17af8d8c7 media: v4l2-common: Add YUV24 format info 4534f70aa7042 media: cedrus: Fix failure to clean up hardware on probe failure facbb592e22dd watchdog: sprd_wdt: Remove redundant sprd_wdt_disable() on register failure 1917015aa0a1d watchdog: sama5d4_wdt: Fix WDDIS detection on SAM9X60 and SAMA7G5 d6e8d6b2f8f04 watchdog: sp5100_tco: Use EFCH MMIO for newer Hygon FCH 29fd4f4c73e2b Documentation/rv: Replace stale website link 19eb0ab0bdffb ARM: dts: am335x-sl50: Fix audio bitclock and frame master endpoint 5435fd3edcb11 wifi: ath9k: fix OOB access from firmware tx status queue ID 7c79be7e63447 pinctrl: mediatek: eint: Drop base from mtk_eint_chip_write_mask() a83e77d1e52c0 soc: xilinx: Shutdown and free rx mailbox channel fbeea02c3564d kconfig: fix potential NULL pointer dereference in conf_askvalue ad445de67359f wifi: rtw89: add bounds check on firmware mac_id in link lookup 01155ded5d4da wifi: rtw88: fix OOB read from firmware RX descriptor exceeding DMA buffer 7a1ab5fdcae89 wifi: rtw89: Correct data type for scan index to avoid infinite loop 1ef3d1338d94e wifi: rtw88: fix wrong pci_get_drvdata type in AER handlers aefc30e4a829c wifi: rtw89: fix wrong pci_get_drvdata type in AER handlers cc77f0d91e321 driver core: use READ_ONCE() for dev->driver in dev_has_sync_state() 543ed0f61d565 drm/amdkfd: Validate CRIU-restored IDs before idr_alloc 1638e178e4915 dt-bindings: pinctrl: nvidia,tegra234: Add missing required block cc6ef5ee7d88a arm64: tegra: Fix Tegra234 MGBE PTP clock 228db770fb086 wifi: cfg80211: fix grammar in MLO group key error message 123e1cd95ba54 arm64: dts: qcom: sdm845-mezzanine: Fix camss ports unit_address_vs_reg warning d8367ee271aba arm64: dts: qcom: sc8180x: Fix phy simple_bus_reg warning d72ae2c63b683 arm64: dts: qcom: ipq5424: Fix USB simple_bus_reg warnings 8f8233d544aca arm64: dts: rockchip: Fix gmac0 reset pin for NanoPi R5S 58d0b4c55cdfd arm64: dts: rockchip: fix Ethernet PHY not found on PX30 Cobra 6005cdd9f48fd Documentation: proc: fix section numbering in table of contents d10227f899c90 selftests/bpf: Use local type for bpf_fou_encap in test_tunnel_kern 595710e6838c3 selftests/bpf: Use local type for flow_offload_tuple_rhash in xdp_flowtable 2dfe817167af0 drm/amd/pm: remove trailing semicolon from AMDGPU_PM_POLICY_ATTR macro afea00ffcf41c dt-bindings: timer: Remove sifive,fine-ctr-bits property bc4737e55ec41 selftests/bpf: Fix off-by-one in bpf_cpumask_populate related selftest 392c03362c278 libbpf: Report error when a negative kprobe offset is specified 06dc892561f5a drm/radeon: fix memory leak in radeon_ring_restore() on lock failure d9dfa176899d4 drm/radeon: fix integer overflow in radeon_align_pitch() daf5d03ddb8cc drm/amdgpu: fix integer overflow in amdgpu_gem_align_pitch() 41a60487b5b04 drm/gpuvm: Do not prepare NULL objects 353f26c74660b drm/gpusvm: Reject VMAs with VM_IO or VM_PFNMAP when creating SVM ranges 626fa93d194db drm/tidss: Drop extra drm_mode_config_reset() call ab487bb0402af drm/rockchip: Test for imported buffers with drm_gem_is_imported() b3ec263a719e0 drm/rockchip: dw_dp: Fix null-ptr-deref in dw_dp_remove() 0d60b835bca42 drm/rockchip: dw_dp: Switch to drmm_kzalloc() 68dc52f308a17 accel/amdxdna: Fix leak when pinning ubuf pages 8e644d9a8c8dc clocksource/drivers/sun5i: Handle error returns from devm_reset_control_get_optional_exclusive() d50d320e88b4c openrisc: mm: Fix section mismatch between map_page and __set_fixmap 24186d6f9b07e fbcon: Use correct type for vc_resize() return value 6617df8c24631 fbcon: fix NULL pointer dereference for a console without vc_data 231414253b648 afs: Fix uncancelled rxrpc OOB message handler 8b4d1854295b0 afs: Fix further netns teardown to cancel the preallocation charger cc848a080f7a6 afs: handle CB.InitCallBackState3 requests without a server record 23b3d457d8387 afs: fix NULL pointer dereference in afs_get_tree() b83ecf80e28af afs: Fix netns teardown to cancel the preallocation charger 8cd8cf3052fff rxrpc: Fix double unlock in rxrpc_recvmsg() a89a13aea38ae rxrpc: Fix leak of connection from OOB challenge f9be514984471 rxrpc: Fix the reception of a reply packet before data transmission 8db6a2c95e369 rxrpc: Fix ACKALL packet handling 647e8e69c6ea3 rxrpc: Fix oob challenge leak in cleanup after notification failure 7940e5c535489 rxrpc: Fix rxrpc_rotate_tx_rotate() to check there's something to rotate 0fc5b37faec26 rxrpc: Fix potential infinite loop in rxrpc_recvmsg() 2b69b61057eb0 rxrpc: Fix leak of released call in recvmsg(MSG_PEEK) 0d643a46fdea6 rxrpc: Fix socket notification race 844b8525ce503 rxrpc: Fix UAF in rxgk_issue_challenge() 9ada3931beb37 rxrpc: Don't move a peeked OOB message onto the pending queue d3b642cf95d48 rxrpc: rxrpc_verify_data ensure rx_dec_buffer alloc 35a967ff8b24d rxrpc: serialize kernel accept preallocation with socket teardown 2ecd118fb6913 serial: 8250_omap: clear rx_running on zero-length DMA completes c37095c431c39 serial: max310x: implement gpio_chip::get_direction() d354716245192 serial: msm: Disable DMA for kernel console UART 03fd857c33456 dt-bindings: power: imx93: Add MIPI PHY power domain d97a6b4a5a4fb dt-bindings: media: sun4i-a10-video-engine: Add interconnect properties 79982331c1738 media: uvcvideo: Fix sequence number when no EOF 19cb644d0ca59 media: uvcvideo: Relax the constrains for interpolating the hw clock bf58be93c51ba media: uvcvideo: Do not add clock samples with small sof delta aed8111f2392d media: uvcvideo: Fix dev_sof filtering in hw timestamp 0f64f808fb4ee media: uvcvideo: Fix buffer sequence in frame gaps 1a9baac645769 media: uvcvideo: Avoid partial metadata buffers caf800e0cab94 media: uvcvideo: Use hw timestaming if the clock buffer is full 6b2c0cd5f9689 ALSA: hda/realtek: Fix speakers on Legion Pro 7 16ARX8H with codec SSID 17aa:38a7 2f33044aedd7a ALSA: hda: Fix cached processing coefficient verbs ae7f5b05d225c ALSA: hda: conexant: Remove mic bias threshold override 12e43f99242b0 ALSA: hda/realtek: Add quirk for TongFang X6xx45xU e0a71cbf0c190 af_unix: Drop all SCM attributes for SOCKMAP. 9b6c12e1a6be0 iommu/amd: Use maximum PPR log buffer size when SNP is enabled on Family 0x19 a4fb0954f3dc2 iommu/amd: Use maximum Event log buffer size when SNP is enabled on Family 0x19 62dde71ca2c8c exfat: preserve benign secondary entries during rename and move f3a0dd2d88e83 selftests/bpf: Add tests for stale delta leaking through id reassignment 985b8a0e52c58 selftests/bpf: Add tests for delta tracking when src_reg == dst_reg d75376fbc8563 bpf: Clear delta when clearing reg id for non-{add,sub} ops 19836e8145de9 selftests/bpf: Add a test cases for sync_linked_regs regarding zext propagation 07259d661c9d4 selftests/bpf: Add tests for improved linked register tracking 564e4ce9fb401 selftests: bpf: Add test for multiple syncs from linked register 3659deaf7bf69 media: uvcvideo: Fix deadlock if uvc_status_stop is called from async_ctrl.work c401492e01c7b crypto: sun4i-ss - Remove insecure and unused rng_alg 088ee46c18d99 nvmet-tcp: Fix potential UAF when ddgst mismatch 2ed3c9d955e8c nvmet-tcp: check INIT_FAILED before nvmet_req_uninit in digest error path 588718101e844 iommu/vt-d: Clear Present bit before tearing down scalable-mode context entry c646431865f4b KVM: arm64: Bound used_lrs when flushing the pKVM hyp vCPU d7860b682da55 crypto: algif_skcipher - force synchronous processing de5a46f3b2c8d tcp: Add preempt_{disable,enable}_nested() in reqsk_queue_hash_req(). e0caf7c3d49c7 smb/server: do not require delete access for non-replacing links bbf04810b2a06 nvme-pci: DMA unmap the correct regions in nvme_free_sgls 40e44eff5116d perf trace: Deal with compiler const checks 30bbd7e8999d1 perf trace: Don't change const char strings bc29e0699b35d perf diff: Constify strchr() return variables 292f32503eda3 perf list: Don't write to const memory d03adc7039c39 perf list: Signal changing const memory is ok 4283a813d7089 perf tp_pmu: Address const-correctness errors in recent glibcs 018533cfe83cf perf units: Constify variables storing the result of strchr() on const tables e7d3f92238a3d perf hwmon_pmu: Constify the variables returning bsearch() on const tables 5bcff7ce5c3b1 perf tools: Use const for variables receiving str{str,r?chr}() returns ee8ab4e8e7029 perf metricgroup: Constify variables storing the result of strchr() on const tables 8bac35a8fd98f perf trace-event: Constify variables storing the result of strchr() on const tables a816153dd8575 perf demangle-java: Constify variables storing the result of strchr() on const tables f8cb25b1d5ed2 perf session: Don't write to memory pointed to a const pointer 5f6d997641de9 perf bpf-event: Constify variables storing the result of strchr() on const tables 3b540ba9606bf perf tools: Switch printf("...%s", strerror(errno)) to printf("...%m") 659a56ba86a96 perf list: Remove unused 'sep' variable 33250aa5cfade perf jitdump: Constify variables storing the result of strchr() on const tables 972c65697792c perf time-utils: Constify variables storing the result of strchr() on const tables 9ae21594ee518 perf strlist: Remove dont_dupstr logic, used only once 110ce8fed0f8e perf strlist: Don't write to const memory Signed-off-by: Bruce Ashfield Signed-off-by: Richard Purdie (cherry picked from commit 197a98e6e4883e47335df4d8a742980ab0a2a6a4) Signed-off-by: Yoann Congal --- .../linux/linux-yocto-rt_6.18.bb | 6 ++--- .../linux/linux-yocto-tiny_6.18.bb | 6 ++--- meta/recipes-kernel/linux/linux-yocto_6.18.bb | 24 +++++++++---------- 3 files changed, 18 insertions(+), 18 deletions(-) diff --git a/meta/recipes-kernel/linux/linux-yocto-rt_6.18.bb b/meta/recipes-kernel/linux/linux-yocto-rt_6.18.bb index 9d44c803eb9..37570538857 100644 --- a/meta/recipes-kernel/linux/linux-yocto-rt_6.18.bb +++ b/meta/recipes-kernel/linux/linux-yocto-rt_6.18.bb @@ -15,13 +15,13 @@ python () { raise bb.parse.SkipRecipe("Set PREFERRED_PROVIDER_virtual/kernel to linux-yocto-rt to enable it") } -SRCREV_machine ?= "56572c42354027a50e261f16fe13b057604873e7" -SRCREV_meta ?= "2f71b0a288c307062fc60948ac793d8d51c685e2" +SRCREV_machine ?= "fa4de2c8b38ef83fd991db3b507630001104cac5" +SRCREV_meta ?= "24949c3ef490d79a73a821f688efdc2f562fc851" SRC_URI = "git://git.yoctoproject.org/linux-yocto.git;branch=${KBRANCH};name=machine;protocol=https \ git://git.yoctoproject.org/yocto-kernel-cache;type=kmeta;name=meta;branch=yocto-6.18;destsuffix=${KMETA};protocol=https" -LINUX_VERSION ?= "6.18.39" +LINUX_VERSION ?= "6.18.41" LIC_FILES_CHKSUM = "file://COPYING;md5=6bc538ed5bd9a7fc9398086aedcd7e46" diff --git a/meta/recipes-kernel/linux/linux-yocto-tiny_6.18.bb b/meta/recipes-kernel/linux/linux-yocto-tiny_6.18.bb index 7ff47505aa0..5addcaae07e 100644 --- a/meta/recipes-kernel/linux/linux-yocto-tiny_6.18.bb +++ b/meta/recipes-kernel/linux/linux-yocto-tiny_6.18.bb @@ -9,7 +9,7 @@ require recipes-kernel/linux/linux-yocto.inc include recipes-kernel/linux/cve-exclusion.inc include recipes-kernel/linux/cve-exclusion_6.18.inc -LINUX_VERSION ?= "6.18.39" +LINUX_VERSION ?= "6.18.41" LIC_FILES_CHKSUM = "file://COPYING;md5=6bc538ed5bd9a7fc9398086aedcd7e46" DEPENDS += "${@bb.utils.contains('ARCH', 'x86', 'elfutils-native', '', d)}" @@ -18,8 +18,8 @@ DEPENDS += "openssl-native util-linux-native" KMETA = "kernel-meta" KCONF_BSP_AUDIT_LEVEL = "2" -SRCREV_machine ?= "9eb7db1359675f27707b030ba228f381c10cd53e" -SRCREV_meta ?= "2f71b0a288c307062fc60948ac793d8d51c685e2" +SRCREV_machine ?= "06f4fd92efb65a6108294f43855ca32fe22cb96f" +SRCREV_meta ?= "24949c3ef490d79a73a821f688efdc2f562fc851" PV = "${LINUX_VERSION}+git" diff --git a/meta/recipes-kernel/linux/linux-yocto_6.18.bb b/meta/recipes-kernel/linux/linux-yocto_6.18.bb index 6111ae89daa..3ceba003fa4 100644 --- a/meta/recipes-kernel/linux/linux-yocto_6.18.bb +++ b/meta/recipes-kernel/linux/linux-yocto_6.18.bb @@ -17,25 +17,25 @@ KBRANCH:qemux86-64 ?= "v6.18/standard/base" KBRANCH:qemuloongarch64 ?= "v6.18/standard/base" KBRANCH:qemumips64 ?= "v6.18/standard/mti-malta" -SRCREV_machine:qemuarm ?= "78e0248ce3cecd33f63926cd1d54c64e163d076c" -SRCREV_machine:qemuarm64 ?= "9eb7db1359675f27707b030ba228f381c10cd53e" -SRCREV_machine:qemuloongarch64 ?= "9eb7db1359675f27707b030ba228f381c10cd53e" +SRCREV_machine:qemuarm ?= "fbf752dfa74a5be78586014f82002bca11063fa8" +SRCREV_machine:qemuarm64 ?= "06f4fd92efb65a6108294f43855ca32fe22cb96f" +SRCREV_machine:qemuloongarch64 ?= "06f4fd92efb65a6108294f43855ca32fe22cb96f" SRCREV_machine:qemumips ?= "62ea92a539f58803a222be98b81118403074206e" -SRCREV_machine:qemuppc ?= "9eb7db1359675f27707b030ba228f381c10cd53e" -SRCREV_machine:qemuriscv64 ?= "9eb7db1359675f27707b030ba228f381c10cd53e" -SRCREV_machine:qemuriscv32 ?= "9eb7db1359675f27707b030ba228f381c10cd53e" -SRCREV_machine:qemux86 ?= "9eb7db1359675f27707b030ba228f381c10cd53e" -SRCREV_machine:qemux86-64 ?= "9eb7db1359675f27707b030ba228f381c10cd53e" +SRCREV_machine:qemuppc ?= "06f4fd92efb65a6108294f43855ca32fe22cb96f" +SRCREV_machine:qemuriscv64 ?= "06f4fd92efb65a6108294f43855ca32fe22cb96f" +SRCREV_machine:qemuriscv32 ?= "06f4fd92efb65a6108294f43855ca32fe22cb96f" +SRCREV_machine:qemux86 ?= "06f4fd92efb65a6108294f43855ca32fe22cb96f" +SRCREV_machine:qemux86-64 ?= "06f4fd92efb65a6108294f43855ca32fe22cb96f" SRCREV_machine:qemumips64 ?= "9fb4ff0187c85426f21fd40d4c61b742800f65c4" -SRCREV_machine ?= "9eb7db1359675f27707b030ba228f381c10cd53e" -SRCREV_meta ?= "2f71b0a288c307062fc60948ac793d8d51c685e2" +SRCREV_machine ?= "06f4fd92efb65a6108294f43855ca32fe22cb96f" +SRCREV_meta ?= "24949c3ef490d79a73a821f688efdc2f562fc851" # set your preferred provider of linux-yocto to 'linux-yocto-upstream', and you'll # get the /base branch, which is pure upstream -stable, and the same # meta SRCREV as the linux-yocto-standard builds. Select your version using the # normal PREFERRED_VERSION settings. BBCLASSEXTEND = "devupstream:target" -SRCREV_machine:class-devupstream ?= "f89c296854b755a66657065c35b05406fc18264d" +SRCREV_machine:class-devupstream ?= "2fe596715f840d053aed5cee5455f701bdcd2b50" PN:class-devupstream = "linux-yocto-upstream" KBRANCH:class-devupstream = "v6.18/base" @@ -43,7 +43,7 @@ SRC_URI = "git://git.yoctoproject.org/linux-yocto.git;name=machine;branch=${KBRA git://git.yoctoproject.org/yocto-kernel-cache;type=kmeta;name=meta;branch=yocto-6.18;destsuffix=${KMETA};protocol=https" LIC_FILES_CHKSUM = "file://COPYING;md5=6bc538ed5bd9a7fc9398086aedcd7e46" -LINUX_VERSION ?= "6.18.39" +LINUX_VERSION ?= "6.18.41" PV = "${LINUX_VERSION}+git" From patchwork Wed Sep 9 07:29:01 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 97665 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 5ADF0C79FBB for ; Wed, 9 Sep 2026 07:30:00 +0000 (UTC) Received: from mail-wr2-f12.google.com (mail-wr2-f12.google.com [74.125.225.76]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.6305.1788938996070009099 for ; Wed, 09 Sep 2026 00:29:56 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=mZZUp4Tx; spf=pass (domain: smile.fr, ip: 74.125.225.76, mailfrom: yoann.congal@smile.fr) Received: by mail-wr2-f12.google.com with SMTP id ffacd0b85a97d-482f62ccdb1so659048f8f.1 for ; Wed, 09 Sep 2026 00:29:55 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1788938994; x=1789543794; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=Q0vextnbp1MkbeFszpEt30uw2gDeBbHnk1FrKVkG1TE=; b=mZZUp4TxNbvV4uhGL4LUkfO3yhvGaTf0DDVSTu6G74KOqCB+vHxd5+YO2LQEFXtOZz XAHDZu6FjOVZU+cFKdHiuxkkI4r0X3aoxo5Cej4Tnu3/6gzkhufNGjtEGn1O6V9oU4iJ rieJWMuLr4ZMUTIhEi4uk6yaVz0nAmXEJw3x0= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1788938994; x=1789543794; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=Q0vextnbp1MkbeFszpEt30uw2gDeBbHnk1FrKVkG1TE=; b=jFA+RYgmhTh+mLB1PuCjzQvy6kvpk3KkA9bGZQK2I3D/ekwjm3Pye36GVdhnwQaZ9d 3y75KldfEdgzz0RxqLoC1xtp/sPLTUfEhmx8cy75KtTVukIAKWbTlrG9WRJ+2BKZDH26 K24kgI+YCLMZIigQ40o1e0qSODqWZrNk5qWjQdf4p5ODlhXLPRJ+tdXXdN3CxIpoHEo6 vPpriTY25BlRX//S9ruQLb9YFNaWTCYEy7eIId0CbfhSDLKE0HEAKbjIgwJuheQHBvIa vOoFQSppLcjZAuSlorzRx0Sdlq5NG2KWaxHK8nWeeL8l2hDeauYVO57oSUa38phe7yL7 CoWQ== X-Gm-Message-State: AFuF++ntiyVDwqvhIeJh9Y1gJUvgHW7Qryvertv9CXRUGhunfhpEBNLA lU+sbwLDI/Jf+shPPLJL8cEC8h9e5+rPcw3mAh9hmabpOQ9+H3K2dQa4SVdT+JNAUs5ggb+mmm6 rxZxzvG0= X-Gm-Gg: AYBFou11XXxfjDHXe9Yrs+28eXrzI1PyIEQNTXbc1RBVAn9zZELWZSsXvfga4hpS502 2q70qDuZpINN5ipqHIQHl0tqSNI5FMt1FR3u4bDbK98wnNcJ3obXrXrzWm9RcquoRPD+s/jbhaB luKqaDtDOEu+YGIW5LLfZi9hNFutFvQWKJZsgGEDTYKmjKTl43M1sGBFGryekAd9gIfjBfs7hDa oZu/qHPWJCcofFaB5oilaw4Ke8MX+thmrS7nunC1EmhVmlPcO4+GVJyc0pdU+CG3Rllan5ik+Yp QARxnZwMTpu2eqmbHwnu31RUMIiEUoYNhXifeE8kLJlizjdJed0g8lSEtj6k/1FgTNrhPCi2CZl AzYSoqJgkaIXYBaLzW2ctAEG4uAyi/rTBjOMvMqTTw+j5lv4AzB4rRozt47su+mCYZaTnrGEWN4 3hpE/zC6bXMaPh9dZLGnASI2yNNL3mnboxhcGNKgu8H7qyAgxTtBnCKHsPM4nfGzJ5CwJg13vF+ /u0GBgxcx3FpNibvUZ/KAGDYCkstmjZAaqD6VjJLL8Mde65IWXkpZycwnTvMDTE3FC56uOQZkg= X-Received: by 2002:adf:e702:0:b0:485:86bf:654a with SMTP id ffacd0b85a97d-485a2434a80mr10073245f8f.19.1788938992888; Wed, 09 Sep 2026 00:29:52 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-4858ac2b4cdsm40624310f8f.16.2026.09.09.00.29.52 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 09 Sep 2026 00:29:52 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][wrynose 02/38] linux-yocto/6.18: update to v6.18.43 Date: Wed, 9 Sep 2026 09:29:01 +0200 Message-ID: <2a7528a090c4920ea90065630181f1ff4509c8e0.1788938909.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Wed, 09 Sep 2026 07:30:00 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/245410 From: Bruce Ashfield Updating linux-yocto/6.18 to the latest korg -stable release that comprises the following commits: 7b923c78b50d2 Linux 6.18.43 bfe7f9993467b x86/bugs: Make Safe-RET robust against interrupt injection 856a9b51680cb Linux 6.18.42 0f33b1c457c21 KVM: SVM: Bump asid_generation on CPU online to avoid ASID collision after hotplug 846ed916cfa0c gpu: Fix uninitialized buddy for built-in drivers bcb29986bbba8 net: stmmac: fix dwmac4 transmit performance regression a0d1a11b90a51 net/mlx5e: Fix NULL pointer dereference in ioctl module EEPROM query f282242906c12 usb: gadget: f_tcm: synchronize delayed set_alt with teardown aeebcfa8237c3 rust: device: avoid trailing ; in printing macros e94e820df37d4 rust: allow `suspicious_runtime_symbol_definitions` lint for Rust >= 1.98 6ce0db97fb37a mm/damon/core: disallow overlapping input ranges for damon_set_regions() 4b6f1d6d5d078 mm/damon/core: validate ranges in damon_set_regions() deead12d2e650 i3c: mipi-i3c-hci: Fix handling of shared IRQs during early initialization 811b581fae651 i3c: mipi-i3c-hci: Fix Hot-Join NACK 4fd5b33faf092 pmdomain: imx93-blk-ctrl: Extract PHY as shared domain for DSI/CSI c389893bb4037 pmdomain: imx93-blk-ctrl: convert to devm_* only dc8347f263b21 net: ipa: fix SMEM state handle leaks in SMP2P init 4c1e8ccd8655e ata: libata-core: Reject an invalid concurrent positioning ranges count 9466dc5e377f0 bootconfig: fix NULL-pointer arithmetic in xbc_snprint_cmdline() a88c2a70ea0ad bootconfig: move xbc_snprint_cmdline() to lib/bootconfig.c c73b8795b45f4 octeontx2-af: cn10k: restrict VF LMTLINE sharing to its own PF 4467fa514482b octeontx2-af: validate body pcifunc in rvu_mbox_handler_rep_event_notify ae5ae3d5bfaa6 net: mana: Optimize irq affinity for low vcpu configs 6d13eaa13341a net: mana: Validate the packet length reported by the NIC 7b7bb07efe41b fs/resctrl: Fix use-after-free during unmount d48cf914c739e fs/resctrl: Move RMID initialization to first mount 682d3c2cd20e0 fs/resctrl: Move allocation/free of closid_num_dirty_rmid[] 8c5925f0fa128 x86,fs/resctrl: Rename some L3 specific functions 696c34a1964f4 x86,fs/resctrl: Rename struct rdt_mon_domain and rdt_hw_mon_domain ad4ea2a169a48 fs/resctrl: Split L3 dependent parts out of __mon_event_count() 5b82af744e06c mmc: vub300: fix use-after-free on probe failure 73d397ab54f2a mmc: vub300: rename probe error labels 8ced1d242c34e dm: avoid leaking the caller's thread keyring via the table device file dd73cc92a55d7 cred: add kernel_cred() helper af7a4c2caa7a1 accel/amdxdna: reject command submission on devices without a submit op 62dae36be7a62 ovl: use linked upper dentry in copy-up tmpfile 043acb00e4edd dmaengine: dw-edma-pcie: Reject devices without driver data 277a035cda47d dmaengine: dw-edma: Fix confusing cleanup.h syntax 19360c25135fc mtd: maps: vmu-flash: fix fault in unaligned fixup b8271be34bce1 kho: make sure scratch size is always aligned by CMA_MIN_ALIGNMENT_BYTES 3d561f46fa784 mm/sparse-vmemmap: fix vmemmap accounting underflow 8af652cd99460 remoteproc: xlnx: Check remote core state 6fc1919a6f2ed cxl: Fix CXL_HEADERLOG_SIZE to match RAS Capability size 89b2ae039d188 cxl/pci: Remove CXL VH handling in CONFIG_PCIEAER_CXL conditional blocks from core/pci.c eeab775069920 cxl/pci: Remove unnecessary CXL RCH handling helper functions a64661dccb2eb cxl/pci: Remove unnecessary CXL Endpoint handling helper functions 5d964cb2b7bc8 SUNRPC: Return an error from xdr_buf_to_bvec() on overflow b50b2cb87e7ac SUNRPC: Add helpers to convert xdr_buf byte ranges to scatterlists a112b91dd6349 sunrpc: allocate a separate bvec array for socket sends 3120f21df3fb0 NFSD: pass nfsd_file to nfsd_iter_read() 6876f767b0490 pinctrl: renesas: rzg2l: Use -ENOTSUPP instead of -EOPNOTSUPP 7185c5262435b gpu/buddy: bail out of try_harder when alignment cannot be honoured 9634fd144cdc1 drm: drop lib from header search path. 65677f7a20c48 gpu: Move DRM buddy allocator one level up (part two) 09755dc62b026 netfilter: nf_conntrack_sip: validate skb_dst() before accessing it a1a94a00b8844 netfilter: nf_conntrack_sip: remove net variable shadowing d01c913febead netfilter: nft_fib: reject fib expression on the netdev egress hook beeda5bf78577 netfilter: nf_tables: remove register tracking infrastructure 1de827e24d0ad arm64: dts: qcom: hamoa: Fix OPP tables for all DisplayPort controllers 0d810ff7a6f65 arm64: dts: qcom: correct RBR opp entry 690fb82c4122f VDUSE: avoid leaking information to userspace 7764e9c727d58 vduse: take out allocations from vduse_dev_alloc_coherent db5c554b36d50 vduse: remove unused vaddr parameter of vduse_domain_free_coherent 82e48ad2a1326 vduse: return internal vq group struct as map token b1f38c3ec620a xfs: don't replace the wrong part of the cow fork 3bca70235a706 fuse-uring: fix race between registration and connection abortion 40879c39d6740 audit: fix recursive locking deadlock in audit_dupe_exe() 91b64f0be4163 audit: use 'unsigned int' instead of 'unsigned' eef6914f2b456 audit: widen ino fields to u64 c5772ced573ea landlock: Account all audit data allocations to user space a95b62759f3b9 landlock: Fix formatting 682a0066dde05 drm/amd/display: Fix DTB DTO updates breaking live pixel rate sources 81ea8e8221853 fscrypt: Avoid dynamic allocation in fscrypt_get_devices() 337022d9dfac4 ksmbd: validate ACE size against SID sub-authorities f1eba60db813e ksmbd: bound DACL dedup walk to copied ACEs 847ecd4eb3c11 ksmbd: restore DACL size on check_add_overflow() to avoid malformed ACL b6d3cc6a52441 ksmbd: validate num_subauth when copying ACE in set_ntacl_dacl 17e6b8c4319fa net: qrtr: ns: Raise node count limit to 512 7dd26adf7e7d4 ublk: wait on ublk_dev_ready() instead of ub->completion 5a15eaa50f92b drm/xe/uapi: Reject coh_none PAT index for CPU_ADDR_MIRROR 5488d3a69d205 dm-verity: fix buffer overflow in FEC calculation 3f31bde63f9ae dm-verity-fec: replace {MAX,MIN}_RSN with {MIN,MAX}_ROOTS d47281b9a4472 dm-verity-fec: fix reading parity bytes split across blocks (take 3) a556189c06756 dm-verity-fec: fix the size of dm_verity_fec_io::erasures 22400725de070 bpf: Fix same-register dst/src OOB read and pointer leak in sock_ops 15a7cb71a5748 drm/amdgpu: fix check in amdgpu_hmm_invalidate_gfx ab7b40c638e0d drm/amd/pm: fix smu13 power limit range calculation 6405c4e75b3bc drm/amdgpu: fix aperture mapping leak 08fee493e0261 drm/amdgpu: invoke pm_genpd_remove() before freeing genpd 68eab5a64ddbc drm/amdgpu: fix resource leak on ACP reset timeout ffb33d466a68c drm/amdgpu: fix division by zero with invalid uvd dimensions 8c6d84a54823c drm/dp_mst: Handle torn-down topology gracefully in drm_dp_mst_topology_queue_probe() bd868c077f675 drm/amdgpu/vcn4: avoid rereading IB param length 7eebef042c12d drm/amdgpu/vce: fix integer overflow in image size f7e9eeaccca54 drm/amdgpu/soc24: reset dGPU if suspend got aborted dc3f5da1ba8e2 drm/amdgpu/sdma4.4.2: replace BUG_ON() with WARN_ON() 76c977d396f12 drm/amdgpu/jpeg: fix jpeg_v5_0_1_is_idle detection 058373af59551 drm/amdgpu/jpeg: fix jpeg_v4_0_3_is_idle detection 042c047e8bc9c drm/amdgpu/gfx9: replace BUG_ON() with WARN_ON() 05aea3344c422 drm/amdgpu/gfx9.4.3: replace BUG_ON() with WARN_ON() f70bd5235d9ef drm/amdgpu/gfx8: drop unecessary BUG_ON() 987bedd3ea89d drm/amdgpu/gfx12: replace BUG_ON() with WARN_ON() dfd9bf09fd8fe drm/amdgpu/gfx11: replace BUG_ON() with WARN_ON() 7e22de67e545d drm/amdgpu/gfx10: replace BUG_ON() with WARN_ON() e75f71143b68b drm/amd/pm: make pp_features read-only when scpm is enabled ada47af5c215e drm/amd/pm: fix amdgpu_pm_info power display units 7b263cf1dd4c0 watchdog: s32g_wdt: remove incorrect options in watchdog_info struct 79370b573e92e vxlan: mdb: Fix source list corruption on a failed replace f60bac115d8dc vsock/virtio: collapse receive queue under memory pressure 5f5a41a48dbf9 tipc: clear sock->sk on the failed-insert path in tipc_sk_create() 234f9ffbd9b2c tcp: challenge ACK for non-exact RST in SYN-RECEIVED fadaff3f66e12 tcp: initialize standalone TCP-AO response padding 4a4f3aa6af205 rtase: Workaround for TX hang caused by hardware packet parsing 6866abf59976d pppoe: reload header pointer after dev_hard_header() 460b9f0609d26 ovpn: hold peer before scheduling keepalive work b08526bf0bbf8 ovpn: fix peer refcount leak in TCP error paths 100a23b1613e9 openvswitch: fix GSO userspace truncation underflow f80ba170d7b3a mctp: serial: handle zero-length frames to prevent rx buffer overflow f20dedce0429b mac802154: llsec: reject frames shorter than the authentication tag 59c1d5463b7bc mac802154: hold an interface reference across the scan worker 472aba2603ca7 ila: reload IPv6 header after pskb_may_pull in checksum adjust 919d0accf2600 ice: use READ_ONCE() to access cached PHC time 5e496f2b615ce ice: reject out-of-range ptype in ice_parser_profile_init 91e0249f3ef62 gve: fix Rx queue stall on alloc failure 18705cace0619 ksmbd: defer destroy_previous_session() until after NTLM authentication 6098b55f6a0cf smb: client: handle STATUS_STOPPED_ON_SYMLINK responses without a symlink target 34f2a2f32af57 rbd: Reset positive result codes to zero in object map update path 63d78b546eefc super: fix emergency thaw deadlock on frozen block devices e4406cbdd915f ice: fix PTP Call Trace during PTP release b3efb4744abf4 ptp: ptp_s390: Add missing facility check 9a8a247f0f17b s390/ptff: Export ptff_function_mask[] 4afc58ea75b96 proc: Fix broken error paths for namespace links 4056cc19071a3 net: pcs: xpcs: fix SGMII state reading 80d977f280b4e net: hip04: fix RX buffer leak on build_skb failure a4dfd46cc8f08 net: gro: fix double aggregation of flush-marked skbs ec6d91a1bf2eb net/x25: fix use-after-free in x25_kill_by_neigh() 40f9a124ebbe0 net/mlx5e: Use sender devcom for MPV master-up 900cd6d8119b7 net/iucv: fix use-after-free of a severed iucv_path 33736ff5e7c97 net/af_iucv: fix NULL deref in afiucv_hs_callback_syn() f8c498585d2a0 geneve: require CAP_NET_ADMIN in the device netns for changelink 5d07b178bef51 net: slip: serialize receive against buffer reallocation 730c7e5fea7f0 vxlan: require CAP_NET_ADMIN in the device netns for changelink a48a889b60f73 phonet: pep: fix use-after-free in pep_get_sb() 03157872da5ed net: stmmac: intel: skip SerDes reconfig when rate is unchanged 1b44a5f584bff iommu/vt-d: Disallow SVA if page walk is not coherent 7037e7bdcd26f iomap: fix out-of-bounds bitmap_set() with zero-length range f139498c5ebdd io_uring/rw: fix missing ERESTARTSYS conversion in read paths 65bf73bee1a4f ftrace: Add global mutex to serialize trace_parser access 95376fe9c145b fscrypt: Add missing superblock check in find_or_insert_direct_key() a019b074903b3 fs: preserve ACL_DONT_CACHE state in forget_cached_acl() c78e38745ff1b fs/super: fix emergency thaw double-unlock of s_umount 89b9121c3b016 binfmt_elf_fdpic: only honour the first PT_INTERP d309f8b52b34c ASoC: fsl_sai: Fix spurious BCLK on resume by clearing BYP c4d77740eca21 ASoC: fsl: imx-card: Skip sysclk reset for active DAIs in shutdown 1a644db2cf59f amt: fix use-after-free in AMT delayed works 8f5a3abc54ba2 libceph: remove debugfs files before client teardown 3b2f1937f5fce libceph: reject zero bucket types in crush_decode e67e8b694872c libceph: Reject monmaps advertising zero monitors 0060ec912292a libceph: refresh auth->authorizer_buf{,_len} after authorizer update 4716a64b7cc27 libceph: guard missing CRUSH type name lookup 1732d89dfcd74 libceph: Fix multiplication overflow in decode_new_up_state_weight() 4e7ebfaa0d14c libceph: bound get_version reply decode to front len 7d03e08b763fd ceph: fix writeback_count leak in write_folio_nounlock() a7c2dfa610a12 ceph: fix refcount leak in ceph_readdir() a4228b93706fb ceph: fix pre-auth out-of-bounds read on snaptrace in ceph_handle_caps() 3bf0e349cbb4f sctp: close UDP tunnel sockets during netns teardown be6aae9d1b91c sctp: avoid auth_enable sysctl UAF during netns teardown 85aca407c560a sctp: don't free the ASCONF's own transport in DEL-IP processing 3db217a4c2bdc mm/huge_memory: set PG_has_hwpoisoned only after new folio head is established ac7a6f61f56fe mm/kmemleak: fix checksum computation for per-cpu objects f2b2933599241 afs: Fix afs_edit_dir_remove() to get, not find, block 0 d64f6c02495f3 mptcp: pm: userspace: fix use-after-free in get_local_id 6cd3c3d631555 mptcp: only set DATA_FIN when a mapping is present 6c936b5ad557e mptcp: decrement subflows counter on failed passive join 35c4b274d4cc4 Revert "arm64: syscall: Ensure saved x0 is kept in-sync with tracer updates" 64ab0964c7db9 arm64: syscall: Ensure saved x0 is kept in-sync with tracer updates 9cd4b1a52eff3 arm64: make huge_ptep_get handled unaligned addresses 9025946adec9a tracing/probes: Prevent out-of-bounds write in __trace_probe_log_err() 3b3be8653c594 tracing/probes: Fix potential underflow in LEN_OR_ZERO macro 949ac1aeb37b8 tracing/probes: Avoid temporary buffer truncation in trace_probe_match_command_args() 6b5098d745811 tracing/eprobe: Fix exact system name matching in eprobe_dyn_event_match() b6a4575f22925 tracing: Fix union collision of module and refcnt for dynamic events cf5a82bef623b tracing: Fix resource leak on mmiotrace trace_pipe close 8464427e1c177 tracing: Fix mmiotrace possible NULL dereferencing of hiter->dev 1f2e7cd0ff976 tracing: Fix context switch counter truncation 1da310b94504d misc: nsm: pin the module while the device is open 8f068342096b0 misc: nsm: only unlock nsm_dev on post-lock error paths caba30eb8bd32 intel_th: fix MSC output device reference leak 59dd34854202d mei: bus: access mei_device under device_lock on cleanup 5118872357279 selftests: ntsync: correct CONFIG_NTSYNC name b2a3eeb57ba24 serial: 8250_mid: Fix NULL function pointer dereference on DNV/ICX-D/SNR platforms 4fae473b856b4 serial: sc16is7xx: implement gpio get_direction() callback 635be8b097f0c uio_hv_generic: Bind to FCopy device by default cf26dd2d84158 comedi: comedi_parport: deal with premature interrupt 9bb71b59e0aa3 x86/boot/compressed: Disable jump tables 4f2db41a09eba firmware: stratix10-svc: fix memory leaks and list corruption bugs 3ff7c1dbf722c rhashtable: clear stale iter->p on table restart d43c5c0c93552 cdrom: fix stack out-of-bounds read in CDROMVOLCTRL 4427a33faabb4 LoongArch: Retrieve CPU package ID from PPTT when available 38b025fcdc45b LoongArch: Move jump_label_init() before parse_early_param() 6ab0abb5a2e0c LoongArch: Fix oops during single-step debugging a94d6726ec868 LoongArch: Fix address space mismatch in kexec command line lookup c404b1f30b252 objtool/rust: add one more `noreturn` Rust function for Rust 1.99.0 8ccfb3b315a0e rust: allow `clippy::unwrap_or_default` globally 6db0c42c87c46 rust: time: fix as_micros_ceil() to round correctly for negative Delta 12be1d75e9b29 rust_binder: only print failure if error has source cc3bbff10b1a7 platform/loongarch: laptop: Explicitly reset bl_powered state when suspend 1cd4e9b7967da binfmt_misc: set have_execfd only once the interpreter is opened 2bc6bf70d4105 exec: fix unsigned loop counter wrap in transfer_args_to_stack() 780b04d09c941 Bluetooth: RFCOMM: Fix session UAF in set_termios a42f5536ea9c0 Bluetooth: hci_sync: Protect UUID list traversal 91eff666c9078 staging: rtl8723bs: fix inverted HT40 secondary channel offset 875479f18835a staging: rtl8723bs: fix OOB reads in rtw_get_wps_ie() 0dbaff14fd6a8 wifi: ath11k: fix refcount leak in ath11k_ahb_fw_resources_init() efe9de178e4b9 wifi: brcmfmac: set F2 blocksize to 256 for BCM43752 044fca8f45ba9 wifi: brcmfmac: make release_scratchbuffers idempotent 9cb72f67e1502 wifi: mt76: mt7925: drop TXRX_NOTIFY on non-mmio buses 263816e92e8d6 wifi: mt76: mt7921: drop TXRX_NOTIFY on non-mmio buses ab4d213393e84 wifi: mt76: mt7615: drop TXRX_NOTIFY on non-mmio buses e511e93abd6ee wifi: wilc1000: validate assoc response length before subtracting header 9375a4ea41216 wifi: mwifiex: fix NULL dereference when the AP has HT-cap but no HT-oper 18965470d41e6 wifi: ath6kl: fix use-after-free in aggr_reset_state() 58c6c8dc2e022 wifi: ath6kl: fix OOB access from firmware ADDBA window size 1395327a96614 ALSA: timer: don't re-enter an instance callback that is still running 426c0ff1c433d ALSA: timer: drain a slave's callback before its master detaches it 3bc4de57fc7d1 ALSA: hda: codecs: hdmi: disable keep-alive before audio format change 6a10025c7fd09 ALSA: seq: close a re-opened queue timer in the destructor 2ec8f95a08fed ALSA: hda/realtek: Fix speakers on Lunnen Ground 14 4091b216d11b3 media: vpif_capture: fix OF node reference imbalance 1349af7f87df5 media: vivid: fix cleanup bugs in vivid_init() 492c97cb50fea media: vivid: check for vb2_is_busy() when toggling caps 26e7a8ac286f3 media: vivid: add vivid_update_reduced_fps() 3780ad3810718 media: vimc: fix reference leak on failed device registration 86ece01fba2d5 media: vidtv: fix reference leak on failed device registration 16ae8c166e787 media: verisilicon: Export only needed pixels formats b88c929188e3c media: vb2: use ssize_t for vb2_read/vb2_write 072a883061a46 media: v4l2-subdev: Fail {enable,disable}_streams and s_streaming nicely cf9732fd6c4f2 media: v4l2-fwnode: Fix subdev owner overwritten in v4l2_async_register_subdev_sensor() 3068ab802fc98 media: v4l2-ctrls: validate HEVC active reference counts 836cfffb2ddbb media: v4l2-ctrls-request: add NULL check in v4l2_ctrl_request_complete() 7e6521dd747ec media: ti: vpe: unwind v4l2 device registration on probe error 127fc44e83256 media: tegra-video: vi: fix invalid u32 return value in format lookup 118c2f5d1d363 media: synopsys: hdmirx: Fix HPD lane hold time b5184b3f0e9d4 media: sun4i-csi: Return queued buffers on start_streaming() failure 931abe1deb65b media: stm32: dcmi: unregister notifier on probe failure ed342a86bb2f9 media: stm32-dcmipp: Return queued buffers on start_streaming() failure b7936e8cbec1b media: saa7134: Fix a possible memory leak in saa7134_video_init1 a7a141e4e93c8 media: rzg2l-cru: Skip ICnMC configuration when ICnSVC is used 894e83509c669 media: rtl2832_sdr: Return queued buffers on start_streaming() failure 2c71bda6edc63 media: rtl2832: fix use-after-free in rtl2832_remove() 64cb15878b35e media: radio-si476x: Unregister v4l2_device on probe failure a58d01a0ed397 media: qcom: camss: Fix RDI streaming for CSID GEN3 c39a1d9fde82b media: qcom: camss: Fix RDI streaming for CSID GEN2 4e451100b35ee media: qcom: camss: Fix RDI streaming for CSID 680 cb16b79a2be2c media: pwc: Return queued buffers on start_streaming() failure 9afd605dcd96c media: pwc: Drain fill_buf on start_streaming() failure 08ddfd628a2db media: pci: dm1105: Free allocated workqueue 4e077bcb5e1f6 media: nxp: imx8-isi: Fix scale factor calculation for hardware rounding 28ae75dba701d media: nxp: imx8-isi: Fix potential out-of-bounds issues 659a7cea0be80 media: nxp: imx8-isi: Fix missing v4l2_subdev_cleanup() in pipe init error path 4702afbd56f1d media: nxp: imx8-isi: Clean up already-initialized pipes on probe failure 9e61258fbc3cf media: nxp: imx8-isi: Add missing v4l2_subdev_cleanup() in crossbar and pipe 181a0aeefd56f media: nuvoton: npcm-video: fix memory leaks in probe and remove 2147acb948a94 media: nuvoton: npcm-video: fix error handling in npcm_video_init() 264b5380c4f8a media: msi2500: Return queued buffers on start_streaming() failure 1391b75bf0119 media: meson: vdec: Fix memory leak in error path of vdec_open 18e3b838e09d7 media: marvell-cam: fix missing pci_disable_device() on remove cf48e9db85652 media: iris: Fix use IRQF_NO_AUTOEN when requesting the IRQ d56044558a757 media: intel/ipu6: Improve DWC PHY HSFREQRANGE band selection for overlapping ranges 00a98fb2a6fb2 media: imx219: Fix maximum frame length in lines 7337c88205ed0 media: i2c: alvium: fix critical pointer access in alvium_ctrl_init c68c4ce72feb6 media: cx23885: add ioremap return check and cleanup f468b7ee5d633 media: cx231xx: fix devres lifetime f24ca8b53fe15 media: chips-media: wave5: Move src_buf Removal to finish_encode 9924cb548ee77 media: cedrus: skip invalid H.264 reference list entries 000e51afb6068 media: cedrus: Fix missing cleanup in error path 73504935e4365 media: cedrus: clean up media device on probe failure 6efe665356ec8 media: cec: seco: unregister adapter on IR probe failure 0459a4304cff8 media: aspeed: fix missing of_reserved_mem_device_release() on probe failure 391fe3e36e59f media: amlogic-c3: Add validations for ae and awb config 73bd277986537 media: airspy: Return queued buffers on start_streaming() failure a096a6aba6011 drm/v3d: Reach the GMP through the hub registers on V3D 7.x a2212fef8e187 drm/gpusvm: Fix MM reference leak in drm_gpusvm_range_evict 6deaa31720185 drm/vc4: Prevent shader BO mappings from becoming writable b1379f0c42b88 drm/vmwgfx: Validate vmw_surface_metadata::array_size 2b85e19792be4 drm/amd/display: Fix missing DCE check in dm_gpureset_toggle_interrupts() a38f2724eb93a drm/vc4: Shut down BO cache timer before teardown ee44ea4f7e309 drm/amd/display: Fix flip-done timeouts on mode1 reset ba7b6444097a7 drm/amdgpu: fix bo->pin leaking in amdgpu_bo_create_reserved fd2de80f28a07 drm/amdgpu: Disable PCIe dynamic speed switching on Ryzen Pinnacle Ridge 490ceacd2162d drm/amd/display: Fix backlight max_brightness to match exported range 9c0432044d34b drm/amd/display: Force PWM backlight on Lenovo Legion 5 15ARH05 51ea665c30c42 drm/amd/display: dce100: skip non-DP stream encoders for DP MST 0b9fa4272e24b drm/amd/display: consolidate DCN vblank/flip handling onto vupdate_no_lock 679f23f0a3606 drm/amd/display: set new_stream to NULL after release 123692ebc1ea7 drm/amd/pm/ci: Don't disable MCLK DPM on Bonaire 0x6658 (R7 260X) d8dc3a9e815d6 drm/amdgpu: Fix VFCT bus number matching with soft filter 312278b309191 drm/amdgpu: Release VFCT ACPI table reference e64b2f1e826af drm/panthor: return error on truncated firmware 22aa7fb4e7d0b drm/ttm: Account for NULL and handle pages in ttm_pool_backup b2d8b66c67393 drm/virtio: Don't detach GEM from a non-created context a4a1866d50c49 drm/gfx10: Program DB_RING_CONTROL e163c5a0946de drm/amd/pm: fix smu14 power limit range calculation e3bcd3bf7eeca drm/i915/mst: limit DP MST ESI service loop 726f27bca93e6 drm/i915/gem: Fix NULL deref in I915_CONTEXT_PARAM_SSEU 37951ce1567cc drm/i915/gem: Do not leak siblings[] on proto context error 1173190412fb9 drm/amdgpu: fix lifetime issue of amdgpu_vm_get_task_info_pasid() 5df5a59c32b46 drm/amd/amdgpu: disable ASPM on VI if pcie dpm is disabled 8b2da44446f9d drm/i915/bios: range check LFP Data Block panel_type2 cbec6a57959ab drm/i915: Return NULL on error in active_instance d20b5c139b290 drm/amdgpu/sdma5.0: replace BUG_ON() with WARN_ON() 09da54636bac1 drm/amdgpu/sdma5.2: replace BUG_ON() with WARN_ON() 51fd520871651 drm/amdgpu/sdma6.0: replace BUG_ON() with WARN_ON() 4c09483325360 drm/amdgpu/sdma7.0: replace BUG_ON() with WARN_ON() 3d2ef8d389495 drm/i915/hdcp: check streams[] bounds before overflow 1f876bd8adc79 drm/i915/hdcp: require monotonically increasing seq_num_v 35be0e2c6862a drm/virtio: bound EDID block reads to the response buffer 4ee77643e6194 drm/amd/display: detect_link_and_local_sink: DP alt mode timeout path leaks prev_sink reference 8a77ccf9cb992 drm/amd/display: Handle struct drm_plane_state.ignore_damage_clips abce3276c57e3 drm/amdkfd: fix 32-bit overflow in CWSR total size calculation fd1691ec62701 drm/amdkfd: Check bounds on CRIU restore queue type and mqd size 50319efb865f7 drm/amdkfd: Check bounds in allocate_event_notification_slot 14a631dca9df0 drm/amdkfd: Use kvcalloc to allocate arrays 6253bb56bb2eb drm/imagination: acquire vm_ctx->lock before mapping memory to GPU VM c45fafa69fe3f drm/imagination: fix error checking of pvr_vm_context_lookup() b983a35dad370 drm/imagination: Fix user array stride in pvr_set_uobj_array() c88fdbf3da26e drm/imagination: Fix double call to drm_sched_entity_fini() c1954c66662de drm/xe: Hold a dma-buf reference for imported BOs 038d0b80ab778 drm/xe: Fix PTE index in xe_vm_populate_pgtable() for chunked binds 90a8a938e0cae drm/xe: Return error on non-migratable faults requiring devmem 3e1f909556aa6 drm/radeon: fix r100_copy_blit for large BOs fbb9effc81683 drm/nouveau/acr: fix missing nvkm_done() in error path of nvkm_acr_oneinit() 45db277b2e1e3 drm/i915/gem: Add missing nospec on parallel submit slot 748d425e53c31 drm/displayid: fix Tiled Display Topology ID size 5452eb5c16630 drm/sysfb: Return errno code from drm_sysfb_get_visible_size() 154795885e8f0 drm/sysfb: Avoid possible truncation with calculating visible size 4e109faa9ea2b drm/nouveau: fix reversed error cleanup order in ucopy functions 315d2e5741a81 drm/amdgpu: validate CP_GFX_SHADOW chunk size in CS pass1 3fb10ec43c25a drm/amdgpu: Fix amdgpu_bo_move() when old_mem and new_mem are both GTT 9c2b01508831b drm/amdgpu/gfx9: Fix Ring and IB test fail after mode2 f835eda74cf65 drm/sysfb: Avoid truncating maximum stride 7daefc6d51952 drm/sysfb: Do not page-align visible size of the framebuffer ddba17b3dfa0e drm/amdgpu: check amdgpu_vm_bo_find() result in GET_MAPPING_INFO d068a2f53afc8 drm/amdgpu/uvd: Place VCPU BO only in VRAM for UVD 4.x and older b3a01cda0ae16 drm/amdgpu/uvd: Fix forcing MSG, FB BOs into VCPU segment when it isn't at 0 (v2) e28420e36542a drm/amdgpu/gfx: fix cleaner shader IB buffer overflow d5c70523cafa2 drm/dp/mst: fix OOB reads on 2-byte fields in sideband reply parsers e2c29d51c0f65 drm/imagination: Fit paired fragment job in the correct CCCB 1e5827839ad0c drm/dp/mst: fix buffer overflows in sideband chunk accumulation 533d9e2bede4a drm/dp/mst: fix OOB reads in remote DPCD/I2C sideband reply parsers c0384d6872f4d drm/bridge: cdns-dsi: Replace deprecated UNIVERSAL_DEV_PM_OPS() 943fa73ea0efa drm/imagination: Count paired job fence as dependency in prepare_job() 6ab29a8683572 drm/rockchip: analogix_dp: Add missing error check for platform_get_resource() 50cd8a7e98dd2 drm/rockchip: cdn-dp: add missing check in cdn_dp_config_video() 86ab4d93b3d47 drm/tidss: Fix missing drm_bridge_add() call 300a2d970a535 drm: renesas: rzg2l_mipi_dsi: Move rzg2l_mipi_dsi_set_display_timing() aa8ad3e0d1fe9 drm: renesas: rzg2l_mipi_dsi: Increase reset deassertion delay 786d690257ec7 bpf, sockmap: Fix cork use-after-free in tcp_bpf_sendmsg() 3a924139cf526 net: airoha: fix ETS channel derivation in airoha_tc_setup_qdisc_ets() 391a23c503856 mctp: check register_netdevice_notifier() error in mctp_device_init() 74ecebfbf1555 ptp: netc: explicitly clear TMR_OFF during initialization 16df2d154ec82 rds: tcp: unregister sysctl before tearing down listen socket 1db34097998cc ipv6: Change allocation flags to match rcu_read_lock section requirements 684d4d0bda95a ice: prevent tstamp ring allocation for non-PF VSI types a32604e8d9e2c ice: fix LAG recipe to profile association 3a81345467674 ice: allow creating VFs when !CONFIG_ICE_SWITCHDEV 5d54d603cf3e9 net: ipv6: fix dif and sdif mismatch in raw6_icmp_error e60e6009d3bae octeontx2-pf: tc: fix egress ratelimiting d612754a515cb net/mlx5e: Reject unsupported CB Shaper TSA in ETS validation a7e430349fc5e net/mlx5e: Report zero bandwidth for non-ETS traffic classes cdddc8188db46 net/mlx5: E-Switch, fix zero num_dest in prio_tag egress vlan rule 87b39a8c875ca net/mlx5: Fix MCIA register buffer overflow on 32 dword reads 5f2ef3d53d374 net/mlx5: Refactor EEPROM query error handling to return status separately 953d47cfe529a raw: annotate lockless match fields in raw_v4_match() 8150c48fb978e net: qrtr: restrict socket creation to the initial network namespace 0d57d43d7c4c6 hinic: remove unused ethtool RSS user configuration buffers 8fc45a2a7cc24 ppp: annotate data races in ppp_generic 19fe119dfa93f ipv4: icmp: fill flow parameters in icmp_route_lookup decoy lookup e037a41938c69 octeontx2-vf: set TC flower flag on MCAM entry allocation 15a1c5f2ed2ee net: gre: fix lltx regression for GRE tunnels with SEQ/CSUM 55515c1b1285a net: stmmac: enable the MAC on link up for all supported speeds 1bcb737fb884d net: stmmac: reset residual action in L3L4 filters on delete 370dde2b70e58 net: stmmac: fix l3l4 filter rejecting unsupported offload requests 55d2a8d184e24 net: stmmac: xgmac: fix l4 filter port overwrite on register update 40413da850363 net: stmmac: cores: remove many xxx_SHIFT definitions 4a3eea468a041 net: stmmac: socfpga: Add hardware supported cross-timestamp 01d45e6b2c500 net: stmmac: socfpga: Enable TBS support for Agilex5 dac8c2ab943a2 net: stmmac: socfpga: Agilex5 EMAC platform configuration d67136a931e5f net: stmmac: remove xstats.pcs_* members 9f27c4f0ae35b bpf: tcp: fix double sock release on batch realloc b43bb9ab60035 drm/tests: shmem: Set DMA mask to 64-bit in drm_gem_shmem 1b8fb5a20508b tipc: fix u16 MTU truncation in media and bearer MTU validation c8e4b2a567efb iomap: correct the range of a partial dirty clear 279339aa8bdcf drm/xe/vm: Fix SVM leak on resv obj alloc failure in xe_vm_create() d18d9b2c29a12 drm/xe/i2c: Allow per domain unique id 4fdb0f162ccdb vmxnet3: fix BUG_ON in vmxnet3_get_hdr_len() for Geneve packets 18957373920ca sctp: auth: verify auth requirement when auth_chunk is NULL ae0ec759865e0 net: dpaa: fix mode setting b5ded444621b6 net: hsr: fix memory leak on slave unregistration by removing synced VLANs 17bb59682b8e6 net: bridge: vlan: fix vlan range dumps starting with pvid 0a347ca1d6a2e amt: make the head writable before rewriting the L2 header ca0e8b661957f amt: re-read skb header pointers after every pull 9ec22c8113d8c ovl: check access to copy_file_range source with src mounter creds 31f5f7c959c3e ovl: port ovl_copyfile() to cred guard cde234a493f6d ovl: add override_creds cleanup guard extension for overlayfs 35f0b504394e0 cred: add scoped_with_kernel_creds() 3139b806923b1 drm/panel: s6e3ha8: fix unmet dependency on DRM_DISPLAY_HELPER 790da254031cc ovl: fix trusted xattr escape prefix matching 00ebbf030d8c4 wifi: brcmfmac: fix 802.1X-SHA256 call trace warning d5628f39fccc1 wifi: mt76: mt7996: fix possible NULL-pointer deref in mt7996_mcu_sta_bfer_eht() 95b0cf02731c7 wifi: mt76: mt7925: fix crash in reset link replay d14238523ca4c wifi: mt76: mt7996: check pointer returned by mt76_connac_get_he_phy_cap() 313343ab8cab7 wifi: mt76: mt7925: fix possible NULL-pointer deref in mt7925_mcu_bss_he_tlv() c058786b09cfa wifi: mt76: connac: fix possible NULL-pointer deref in mt76_connac_mcu_uni_bss_he_tlv() 871549814eb4d wifi: mt76: mt7915: guard HE capability lookups f1ee53e08fdd2 wifi: mt76: mt7925: guard link STA in decap offload cc4d2f8b984c2 ppp: annotate concurrent dev->stats accesses b52ff80948d1c ppp: don't store tx skb in the fastpath cb9d3e0b55699 ppp: enable TX scatter-gather e740e90ca8e7f tipc: fix infinite loop in __tipc_nl_compat_dumpit d536bf205c71f nexthop: initialize extack in nh_res_bucket_migrate() 961e9b1e33445 gtp: check skb_pull_data() return in gtp1u_send_echo_resp() 023c5e0d0294a selftests: drv-net: increase timeout fa065685c8a91 selftests: ovpn: increase timeout e2b3d426c7ee5 selftests: ovpn: add IPV6 and VETH configs 69eab5c4d9aa6 selftests: openvswitch: add config file 340c389fd3d5d selftests: af_unix: add USER_NS config fbd91910c5025 tls: device: push pending open record on splice EOF a8bd8c109da5a net: mctp i3c: clean up notifier and buses if driver register fails 1a10fe1aa9c01 sctp: validate stream count in sctp_process_strreset_inreq() c984a4184f810 pds_core: check for workqueue allocation failure cf0ed2ba202f5 pds_core: fix auxiliary device add/del races 0e87fe52b560f pds_core: order completion reads after the ownership check 3a831f40e88d3 pds_core: yield the CPU while waiting for the adminq to drain 9e0f80fac50ab pds_core: fix use-after-free on workqueue during remove 19ef775c91c6b pds_core: fix deadlock between reset thread and remove 11092d79eb2b7 sctp: fix auth_chunk_list capacity check in sctp_auth_ep_add_chunkid 2d34421bfa261 net: txgbe: fix FDIR filter leak on remove 245bfe72a5ad4 net: Call net_enable_timestamp() before failure in sk_clone(). 4122792923312 soreuseport: Clear sk_reuseport_cb before failure in sk_clone(). f97d199287689 amd-xgbe: fix MAC_AUTO_SW handling in CL37 AN e695cb9becbbb arm64: Correct value returned by ESR_ELx_FSC_ADDRSZ_nL() f5b8b8ccf9a4a pds_core: reject component parameter in legacy firmware update b5fcd1da05622 wifi: mac80211: recalculate TIM when a station enters power save d06fea9b85f03 iommu/intel: Fix out-of-bounds memset in dmar_latency_disable() e5ebe8544df1a iommu/amd: Bound the early ACPI HID map d21464d93f8ba wifi: mwifiex: bound uAP association event IEs to the event buffer a0980682d84d2 vhost-net: fix TX stall when vhost owns virtio-net header 59cbe6cfa0fa2 wan: wanxl: Only reset hardware after BAR mapping 3b1d4fc3b73ea nfp: Check resource mutex allocation 0f7eaeb950adb wifi: mac80211: tear down new links on vif update error path d053eb7e09e10 iommu/amd: Wait for completion instead of returning early in iommu_completion_wait() 76fc5604308a1 net: airoha: Fix DMA direction for NPU mailbox buffer f112df0744e2d dpaa2-eth: put MAC endpoint device on disconnect 46e3bed4b0710 net: airoha: Fix potential use-after-free in airoha_ppe_deinit() 26ac2d3602347 dpaa2-switch: put MAC endpoint device on disconnect c9165e199f569 rxrpc: fix io_thread race in rxrpc_wake_up_io_thread() b78547914bee5 gtp: parse extension headers before reading inner protocol 9591042533140 rds: drop incoming messages that cross network namespace boundaries 992dce02bdabb bonding: fix devconf_all NULL dereference when IPv6 is disabled 1bc55c29cd858 net/packet: avoid fanout hook re-registration after unregister 9f4f75df77c89 netlink: specs: rt-link: convert bridge port flag attributes to u8 4264dbc84ca0a net: phy: marvell: fix return code 8881daaafadbe Bluetooth: btusb: validate Realtek vendor event length 9d208de7a8f64 regulator: mt6358: use regmap helper to read fixed LDO calibration 538d862cc0dbd hwmon: occ: validate poll response sensor blocks 2f0f661998941 ovpn: use monotonic clock for peer keepalive timeouts 5b96227c0e8b2 ovpn: fix use after free in unlock_ovpn() 47cd68e050a63 selftests/net: ovpn: fix getaddrinfo memory leak in ovpn_parse_remote() c5bf6b39be235 ovpn: avoid putting unrelated P2P peer on socket release 2fdd6d196c656 smb: client: validate DFS referral PathConsumed d6959dd79088a hwmon: (asus-ec-sensors) add missed handle for ENOMEM dd6f730be95b5 hwmon: (asus-ec-sensors) fix EC read intervals 22e449c1dd543 hwmon: (asus-ec-sensors) fix looping over banks while reading from EC d5913f97b5b60 drivers/virt: pkvm: Fix end calculation in mmio_guard_ioremap_hook() d0a57f19fe286 usb: atm: ueagle-atm: reject descriptors that confuse probe and disconnect 2d5dec517b539 wifi: iwlwifi: mvm: fix read in wake packet notification handler eae7fdf7d4469 wifi: iwlwifi: validate payload length in iwl_pnvm_complete_fn 70a6de303c9b3 wifi: iwlwifi: fix pointer arithmetic in iwl_add_mcc_to_tas_block_list a076b0c457c71 wifi: iwlwifi: mvm: validate SAR GEO response payload size cdf895bfd8035 ASoC: cs35l56: Use complete_all() to signal init_completion 3c26e8bb14cc6 ASoC: cs35l56: Fix potential probe() deadlock 1ddb3e0e502a1 ASoC: cs35l56: Don't use devres to unregister component 9153fa1ee99bf ASoC: bt-sco: fix duplicate DAPM widget names for wideband DAI 08433c71f1598 ALSA: hda: cs35l41: validate and free ACPI mute object eca9fcf9f5d89 ASoC: sun4i-codec: Set quirks.playback_only for H616 codec 41ae2b7d37c3d ASoC: tas2781: bound firmware description string parsing 797dc567146c7 btrfs: free mapping node on duplicate reloc root insert 9304713b70e7e btrfs: don't propagate EXTENT_FLAG_LOGGING to split extent maps 39f196f64bd38 btrfs: fix u32 to s64 type conversion in dirty_metadata_bytes accounting f49ff44831d52 btrfs: declare btrfs_ioctl_search_args_v2::buf as __u8 4503829843353 wifi: carl9170: fix buffer overflow in rx_stream failover path fab6ff91d5b8c wifi: carl9170: fix OOB read from off-by-two in TX status handler 9aee949c68dc6 wifi: carl9170: bound memcpy length in cmd callback to prevent OOB read 33b5342d20806 wifi: ath6kl: fix OOB read from firmware IE lengths in connect event eb636fbc44314 wifi: ath6kl: fix OOB read from firmware num_msg in TX complete handler 0177e578d7a88 firewire: net: Fix fragmented datagram reassembly 51516fda914cc wifi: ath12k: Flush the posted write after writing to PCIE_SOC_GLOBAL_RESET 9a9b0ea72d8b9 wifi: ath11k: Flush the posted write after writing to PCIE_SOC_GLOBAL_RESET a154ca3c441a6 wifi: ath11k: fix potential buffer underflow in ath11k_hal_rx_msdu_list_get() 8681e5addf717 watchdog: airoha: Prevent division by zero when clock frequency is zero 7d1658b066de3 watchdog: pretimeout: Fix UAF in watchdog_unregister_governor() 305c23993e43d hwmon: (nzxt-kraken3) Stop device IO before calling hid_hw_stop 205cff797a947 hwmon: (nzxt-smart2) Stop device IO before calling hid_hw_stop f36e12cc8cfe9 hwmon: (gigabyte_waterforce) Stop device IO before calling hid_hw_stop 56d2deb644837 hwmon: (corsair-cpro) Stop device IO before calling hid_hw_stop ec477af3a7e8d hwmon: (corsair-psu) Stop device IO before calling hid_hw_stop e5394605f9a98 wifi: ath11k: fix NULL pointer dereference in ath11k_hal_srng_access_begin 48a69cedde738 wifi: ath9k: hif_usb: don't dereference hif_dev after re-arming firmware request 593072aae7fc8 selftests/bpf: Keep verifier_map_ptr exercising ops pointer access 938bcf99f53e8 selftests/bpf: Adjust verifier_map_ptr for the map's excl field fe7892d46921e usb: xhci-pci: Limit VIA VL805 DMA addressing to 36 bits 958624d638603 Revert "drm/amd/display: Add missing kdoc for ALLM parameters" 03eb7a8099474 RISC-V: KVM: Serialize virtual interrupt pending state updates 731acda5ba777 wifi: mwifiex: fix freeze for 60 seconds caused by request_firmware 0905b3ce1deb7 usb: typec: ucsi: Add duplicate detection to nvidia registration path fe8cde072293c usb: typec: ucsi: Detect and skip duplicate altmodes from buggy firmware 67d2626827e3c USB: serial: option: add TDTECH MT5710-CN 601f75671b8fb USB: serial: keyspan_pda: fix data loss on receive throttling cbe00048b69d6 USB: serial: io_edgeport: cap received transmit credits c1611c6744e3a USB: serial: ftdi_sio: add support for E+H FXA291 1f03658f3e9b2 usb: gadget: uvc: clamp SEND_RESPONSE length to the response buffer dcf3e2f164435 usb: gadget: udc: bdc: free IRQ and drain func_wake_notify before teardown 40c706a0224bd usb: gadget: f_ncm: validate datagram bounds in ncm_unwrap_ntb() 12b3edca90d4d USB: gadget: fsl-udc: fix dev_printk() device 66956a5a4258c USB: gadget: fsl-udc: fix device name leak on probe failure e5ecfb7767526 USB: gadget: snps-udc: fix device name leak on probe failure 4cde0b38cc0cb usb: gadget: printer: fix infinite loop in printer_read() f45089eaad0a0 usb: gadget: f_midi: cancel pending IN work before freeing the midi object e239ea91b4818 usb: gadget: dummy_hcd: prevent fifo_req reuse during giveback ace1a0adfc786 usb: chipidea: fix usage_count leak when autosuspend_delay is negative 8eca14198c202 USB: storage: add NO_ATA_1X quirk for Longmai USB Key 0950ac52426b0 usb: musb: omap2430: Do not put borrowed of_node in probe 7714fb896ed30 usb: core: port: Deattach Type-C connector on component unbind fb1b50ab69921 wifi: at76c50x-usb: avoid length underflow in at76_guess_freq() 217774e143d7b usb: core: sysfs: add lock to bos_descriptors_read() 5f6e7b32bd1fb mpls: fix NULL deref in mpls_valid_fib_dump_req() on CONFIG_INET=n a8d20ba0ab518 sctp: fix auth_hmacs array size in struct sctp_cookie fed1b1ddab41a net/sched: act_tunnel_key: Defer dst_release to RCU callback 51c2fcc4cd2e4 dpll: fix NULL pointer dereference in dpll_msg_add_pin_ref_sync() e666af5dcc905 tcp: fix TIME_WAIT socket reference leak on PSP policy failure 6875ee2bef48f accel/amdxdna: Fix use-after-free of mm_struct in job scheduler f6b522033bc83 drm/i915/selftests: Fix GT PM sort comparators c23abdb922c39 drm/i915/wm: clear the plane ddb_y entries on plane disable f0e337e7db67c ksmbd: validate compound request size before reading StructureSize2 6ecb252efa0b4 ksmbd: pin conn during async oplock break notification 5e5f298d0af64 drm/xe/wopcm: fix WOPCM size for LNL+ 35ba43b541117 drm/xe/vf: Fix VF CCS attach/detach race with in-flight BO moves c1b19d8556265 drm/xe/vf: Shadow buffer management for CCS read/write operations bf293b5bcff41 drm/xe/sa: Shadow buffer support in the sub-allocator pool 65129a03a8018 drm/xe: Allow the caller to pass guc_buf_cache size cfb66ad4aa8e5 can: j1939: fix lockless local-destination check 3f398d45f3c75 riscv: hwprobe: Avoid uninitialized read in hwprobe_get_cpus() 1d9a2f01b3c4e s390/checksum: Fix csum_partial() without vector facility 5b06cf93341fe drm/panthor: Check debugfs GEM lock initialization 250474c69bc3f bpf, sockmap: Reject unhashed UDP sockets on sockmap update c3e61df6fabca powerpc/vtime: Initialize starttime at boot for native accounting 5c3a1cede86fd powerpc/time: Prepare to stop elapsing in dynticks-idle c1bbd0a6906b8 powerpc/85xx: Add fsl,ifc to common device ids 00ba4bf879824 can: raw: add locking for raw flags bitfield 479425744b219 drm/i915/gt: use correct selftest config symbol 7e08ab7a061b1 smb/client: handle overlapping allocated ranges in fallocate cefb44c367b2b Bluetooth: hci_qca: Clear memdump state on invalid dump size d5b3b484b62bb Bluetooth: mgmt: hold reference for hci_conn in mgmt_pending_cmds ca58ad287bfc5 Bluetooth: mgmt: fix locking in unpair_device/disconnect_sync 83b7e67698d0b Bluetooth: hci_sync: extend conn_hash lookup critical sections 57059ff14d81d Bluetooth: MGMT: revalidate LOAD_CONN_PARAM queued update a087ed960fce5 Bluetooth: qca: fix NVM tag length underflow in TLV parser f4e23e661a259 ALSA: usb-audio: Skip DSD quirk for Musical Fidelity M6s DAC b133f007ba02c accel/ivpu: Fix wrong register read in LNL failure diagnostics 1842d45f461a7 ata: sata_dwc_460ex: fix infinite loop in NCQ tag completion bit-scanning d28920db56960 ata: sata_dwc_460ex: fix clear_interrupt_bit() clearing all pending interrupts 678d874e6ae11 ata: sata_dwc_460ex: use platform_get_irq() daa80b422ed92 ata: sata_dwc_460ex: enable SATA interrupts only after IRQ handler is registered c7a1509123720 scsi: core: wake eh reliably when using scsi_schedule_eh 2c77ed279c4bb udmabuf: Ensure to perform cache synchronisation in begin_cpu_udmabuf() c75a950e77356 net/iucv: take a reference on the socket found in afiucv_hs_rcv() cb8be318b4432 ipv4: fib: free fib_alias with kfree_rcu() on insert error path c9574b8a8edeb ppp: defer channel free to an RCU grace period to fix pppol2tp RX UAF 88f87cb4b52ed cpufreq: Make cpufreq_update_pressure() fall back to cpuinfo.max_freq 640a33e77f91b firmware: arm_scmi: Rate-limit queue-full warnings in IRQ context fb343716fad46 ASoC: tas2562: fix deprecated 'shut-down' GPIO always cleared after lookup 7f2cb99eaf53c ASoC: cs42l43: Correct report for forced microphone jack 9f393d8160435 ASoC: amd: ps: replace bitwise OR with logical OR in IRQ return check 3b2d32f528152 ASoC: amd: ps: fix wrong ACP version string in pci_request_regions() f33ad19e3e3d6 ASoC: amd: ps: disable MSI on resume in ACP PCI driver 4801f6690f984 ASoC: meson: aiu: fifo-spdif: soft reset the S/PDIF datapath on start/stop b39b08e6bee81 firmware: arm_ffa: Fix Endpoint Memory Access Descriptor offset calculation cf5708c9d78c9 firmware: arm_ffa: Fix out-of-bound writes in ffa_setup_and_transmit() 11ac7a5e75f51 wifi: cfg80211: bound element ID read when checking non-inheritance 5c342437ea44b wifi: brcmfmac: initialize SDIO data work before cleanup a424985c3ef2a wifi: mac80211: free AP_VLAN bc_buf SKBs outside IRQ lock 44eda4a8d1dcd wifi: mac80211: avoid non-S1G AID fallback for S1G assoc fbaa8c31ef940 wifi: cfg80211: reject unsupported PMSR FTM location requests cfbda103aeae6 wifi: cfg80211: validate PMSR FTM preamble range 0caf6416bfbb3 wifi: cfg80211: validate PMSR measurement type data 0b6efde0ed970 wifi: nl80211: constrain MBSSID TX link ID range f8c547e543e12 wifi: nl80211: validate nested MBSSID IE blobs f649dc9c5e657 wifi: cfg80211: derive S1G beacon TSF from S1G fields fb052a6e2fa86 wifi: nl80211: free RNR data on MBSSID mismatch 133684982dd0c wifi: cfg80211: convert pmsr_free_wk to wiphy_work to fix deadlock d38f5d868a0a4 wifi: p54: validate RX frame length in p54_rx_eeprom_readback() 2aa1789880fa5 wifi: mac80211: defer link RX stats percpu free to RCU 6cda91bbb8dc3 wifi: libertas: fix memory leak in helper_firmware_cb() 5baaa1042f71d wifi: mac80211: fix fils_discovery double free on alloc failure d62b55b7c7dc6 wifi: mac80211: fix unsol_bcast_probe_resp double free on alloc failure 6dc76371a9a36 wifi: mac80211_hwsim: clamp virtio RX length before skb_put e67dc2b8d5ac4 wifi: cfg80211: Fix an error handling path in cfg80211_wext_siwscan() f442e581a8893 wifi: ipw2100: fix potential memory leak in ipw2100_pci_init_one() 9293574ac208d wifi: cfg80211: cancel sched scan results work on unregister 7acc5ed2f3360 xfrm: policy: preallocate inexact bins before xfrm_hash_rebuild reinsert ff636d7b7cba6 xfrm6: clear dst.dev on error to avoid double netdev_put in xfrm6_fill_dst() d8aaf06b29f5a xfrm: iptfs: propagate SKBFL_SHARED_FRAG in iptfs_skb_add_frags() 9845a35986a65 xfrm: clear mode callbacks after failed mode setup 9e632a70f2044 RDMA/irdma: Prevent overflows in memory contiguity checks 124382a2a9756 selftests/alsa: Fix memory leak in find_controls error path f98ae09c727dc mtd: fix double free and WARN_ON in add_mtd_device() error paths fcc9d50022bcd RDMA/siw: publish QP after initialization e221dde026af2 RDMA/hns: Fix potential integer overflow in mhop hem cleanup d842ef03d9145 RDMA/mana_ib: initialize err for empty send WR lists 14e519f93a48c RDMA/erdma: initialize ret for empty receive WR lists ec675b4cdfd37 RDMA/irdma: Prevent user-triggered null deref on QP create 1cd56258fe1a0 RDMA/irdma: Remove redundant legacy_mode checks ca1c29f05274b RDMA/irdma: Prevent rereg_mr for non-mem regions dbb945b80a3a4 RDMA/umem: Add pinned revocable dmabuf import interface c4ef25de94d73 RDMA/cma: Fix hardware address comparison length in netevent callback d7fc6f351c478 xfrm: reject optional IPTFS templates in outbound policies 2907e9d0f05b5 sched_ext: Don't warn on core-sched forced idle in put_prev_task_scx() 57acd51928333 sched/ext: Avoid null ptr traversal when ->put_prev_task() is called with NULL next 996c5c19d5b5a firmware: arm_ffa: Fix NULL dereference in ffa_partition_info_get() 8edc925251780 btrfs: fallback to transaction csum tree on a commit root csum miss a84ca16ce07e7 btrfs: use bool type for btrfs_path members used as booleans 60a23d4ea169e btrfs: fix root leak if its reloc root is unexpected in merge_reloc_roots() 5e1b2ca6b3493 btrfs: reject free space cache with more entries than pages 0ac9c7d9ccfd7 mtd: nand: mtk-ecc: stop on ECC idle timeouts fdb53a9b26071 mtd: mtdswap: remove debugfs stats file on teardown 98d2d468b4faa IB/mad: Drop unmatched RMPP responses before reassembly 59114e0ff6e3a firmware: arm_ffa: Respect firmware advertised RX/TX buffer size limits 33e1b0d25ca0d xfrm: fix stale skb->prev after async crypto steals a GSO segment eae16fbc7ce20 xfrm: propagate -EINPROGRESS from validate_xmit_xfrm() 23bbb9eafec7a net: plumb drop reasons to __dev_queue_xmit() 4cc4d6fb08e75 net: dropreason: add SKB_DROP_REASON_RECURSION_LIMIT 4c22b4e3ff502 arm64: tegra: Fix CPU compatible string to cortex-a78ae on Tegra234 0b9858484d096 arm64: tegra: Remove fallback compatible for GPCDMA 903f2edc04770 fuse: fix writeback array overflow when max_pages is one afe9cda0862aa Input: ims-pcu - fix logic error in packet reset d03a740e087de Input: ims-pcu - fix heap-buffer-overflow in ims_pcu_process_data() 6cbed4be9a6ca xprtrdma: Clear receive-side ownership pointers on release 0892b427c4b8b crypto: tegra - Don't touch bo refcount in host1x bo pin/unpin 5f4de3c717d34 gpu: host1x: Fix use-after-free in host1x_bo_clear_cached_mappings ec9f66c91bffd dmaengine: sh: rz-dmac: Move interrupt request after everything is set up eca8b44d51fc6 can: bcm: track a single source interface for ANYDEV timeout/throttle ops 136de17f38630 can: bcm: fix data race on rx_stamp/rx_ifindex in bcm_rx_handler() 6be3e1fedf03e can: bcm: fix stale rx/tx ops after device removal b024c21c9066f can: bcm: add missing device refcount for CAN filter removal deb6a697cce3f can: bcm: validate frame length in bcm_rx_setup() for RTR replies bd46f55dec608 can: bcm: extend bcm_tx_lock usage for data and timer updates 8104bcdb2612f can: bcm: fix CAN frame rx/tx statistics 19b1994069dd2 can: bcm: add locking when updating filter and timer values ec9daa8fd1b6f KVM: x86/mmu: Fix use-after-free on vendor module reload 8001d2ce9d9bd KVM: nVMX: Hide shadow VMCS right after VMCLEAR dd50ad7935d57 KVM: x86: Only reset TSC Deadline Timer in apic_timer_expired on KVM_RUN f3477a6a4164f KVM: x86: Check for invalid/obsolete root *after* making MMU pages available 865dfe76c150b seqlock: Allow UBSAN_ALIGNMENT to fail optimizing 3958b1aeef43b seqlock: Allow KASAN to fail optimizing ec46baf830825 seqlock: Cure some more scoped_seqlock() optimization fails 8e39ed92d7c5c fs/proc/task_mmu: fix make_uffd_wp_huge_pte() prot-update race 89890a5fcefad drm/virtio: fix deadlock in display_info_cb by removing hotplug from dequeue worker f6410d18c1e2d netfilter: nf_tables: revert commit_mutex usage in reset path 0c8a9022f4c56 netfilter: nft_quota: use atomic64_xchg for reset cd968dcdec6ae netfilter: nft_counter: serialize reset with spinlock 55904f1a4689a selftests/bpf: Add tests for ld_{abs,ind} failure path in subprogs ce01a4e5cfac7 bpf: Fix ld_{abs,ind} failure path analysis in subprogs bffc0b27e457c platform/x86/intel-uncore-freq: Fix current_freq_khz after CPU hotplug Signed-off-by: Bruce Ashfield Signed-off-by: Richard Purdie (cherry picked from commit 24905528a09e7a6b2df9cba342b5f9ba6b8bcf3e) Signed-off-by: Yoann Congal --- .../linux/linux-yocto-rt_6.18.bb | 6 ++--- .../linux/linux-yocto-tiny_6.18.bb | 6 ++--- meta/recipes-kernel/linux/linux-yocto_6.18.bb | 24 +++++++++---------- 3 files changed, 18 insertions(+), 18 deletions(-) diff --git a/meta/recipes-kernel/linux/linux-yocto-rt_6.18.bb b/meta/recipes-kernel/linux/linux-yocto-rt_6.18.bb index 37570538857..edb3696b25e 100644 --- a/meta/recipes-kernel/linux/linux-yocto-rt_6.18.bb +++ b/meta/recipes-kernel/linux/linux-yocto-rt_6.18.bb @@ -15,13 +15,13 @@ python () { raise bb.parse.SkipRecipe("Set PREFERRED_PROVIDER_virtual/kernel to linux-yocto-rt to enable it") } -SRCREV_machine ?= "fa4de2c8b38ef83fd991db3b507630001104cac5" -SRCREV_meta ?= "24949c3ef490d79a73a821f688efdc2f562fc851" +SRCREV_machine ?= "f3301719a9aa0f6e52a9ef3f54f7339a4241f7b9" +SRCREV_meta ?= "7f630b9b05e171d09925e2f0edd84697ff826f93" SRC_URI = "git://git.yoctoproject.org/linux-yocto.git;branch=${KBRANCH};name=machine;protocol=https \ git://git.yoctoproject.org/yocto-kernel-cache;type=kmeta;name=meta;branch=yocto-6.18;destsuffix=${KMETA};protocol=https" -LINUX_VERSION ?= "6.18.41" +LINUX_VERSION ?= "6.18.43" LIC_FILES_CHKSUM = "file://COPYING;md5=6bc538ed5bd9a7fc9398086aedcd7e46" diff --git a/meta/recipes-kernel/linux/linux-yocto-tiny_6.18.bb b/meta/recipes-kernel/linux/linux-yocto-tiny_6.18.bb index 5addcaae07e..894267acdf1 100644 --- a/meta/recipes-kernel/linux/linux-yocto-tiny_6.18.bb +++ b/meta/recipes-kernel/linux/linux-yocto-tiny_6.18.bb @@ -9,7 +9,7 @@ require recipes-kernel/linux/linux-yocto.inc include recipes-kernel/linux/cve-exclusion.inc include recipes-kernel/linux/cve-exclusion_6.18.inc -LINUX_VERSION ?= "6.18.41" +LINUX_VERSION ?= "6.18.43" LIC_FILES_CHKSUM = "file://COPYING;md5=6bc538ed5bd9a7fc9398086aedcd7e46" DEPENDS += "${@bb.utils.contains('ARCH', 'x86', 'elfutils-native', '', d)}" @@ -18,8 +18,8 @@ DEPENDS += "openssl-native util-linux-native" KMETA = "kernel-meta" KCONF_BSP_AUDIT_LEVEL = "2" -SRCREV_machine ?= "06f4fd92efb65a6108294f43855ca32fe22cb96f" -SRCREV_meta ?= "24949c3ef490d79a73a821f688efdc2f562fc851" +SRCREV_machine ?= "73fd4709c133ba2ee6012cfb6a63eb908d1a5cc6" +SRCREV_meta ?= "7f630b9b05e171d09925e2f0edd84697ff826f93" PV = "${LINUX_VERSION}+git" diff --git a/meta/recipes-kernel/linux/linux-yocto_6.18.bb b/meta/recipes-kernel/linux/linux-yocto_6.18.bb index 3ceba003fa4..e510ff01aaf 100644 --- a/meta/recipes-kernel/linux/linux-yocto_6.18.bb +++ b/meta/recipes-kernel/linux/linux-yocto_6.18.bb @@ -17,25 +17,25 @@ KBRANCH:qemux86-64 ?= "v6.18/standard/base" KBRANCH:qemuloongarch64 ?= "v6.18/standard/base" KBRANCH:qemumips64 ?= "v6.18/standard/mti-malta" -SRCREV_machine:qemuarm ?= "fbf752dfa74a5be78586014f82002bca11063fa8" -SRCREV_machine:qemuarm64 ?= "06f4fd92efb65a6108294f43855ca32fe22cb96f" -SRCREV_machine:qemuloongarch64 ?= "06f4fd92efb65a6108294f43855ca32fe22cb96f" +SRCREV_machine:qemuarm ?= "6e4861d133214a07c0b2f3e6d8de190fa2734697" +SRCREV_machine:qemuarm64 ?= "73fd4709c133ba2ee6012cfb6a63eb908d1a5cc6" +SRCREV_machine:qemuloongarch64 ?= "73fd4709c133ba2ee6012cfb6a63eb908d1a5cc6" SRCREV_machine:qemumips ?= "62ea92a539f58803a222be98b81118403074206e" -SRCREV_machine:qemuppc ?= "06f4fd92efb65a6108294f43855ca32fe22cb96f" -SRCREV_machine:qemuriscv64 ?= "06f4fd92efb65a6108294f43855ca32fe22cb96f" -SRCREV_machine:qemuriscv32 ?= "06f4fd92efb65a6108294f43855ca32fe22cb96f" -SRCREV_machine:qemux86 ?= "06f4fd92efb65a6108294f43855ca32fe22cb96f" -SRCREV_machine:qemux86-64 ?= "06f4fd92efb65a6108294f43855ca32fe22cb96f" +SRCREV_machine:qemuppc ?= "73fd4709c133ba2ee6012cfb6a63eb908d1a5cc6" +SRCREV_machine:qemuriscv64 ?= "73fd4709c133ba2ee6012cfb6a63eb908d1a5cc6" +SRCREV_machine:qemuriscv32 ?= "73fd4709c133ba2ee6012cfb6a63eb908d1a5cc6" +SRCREV_machine:qemux86 ?= "73fd4709c133ba2ee6012cfb6a63eb908d1a5cc6" +SRCREV_machine:qemux86-64 ?= "73fd4709c133ba2ee6012cfb6a63eb908d1a5cc6" SRCREV_machine:qemumips64 ?= "9fb4ff0187c85426f21fd40d4c61b742800f65c4" -SRCREV_machine ?= "06f4fd92efb65a6108294f43855ca32fe22cb96f" -SRCREV_meta ?= "24949c3ef490d79a73a821f688efdc2f562fc851" +SRCREV_machine ?= "73fd4709c133ba2ee6012cfb6a63eb908d1a5cc6" +SRCREV_meta ?= "7f630b9b05e171d09925e2f0edd84697ff826f93" # set your preferred provider of linux-yocto to 'linux-yocto-upstream', and you'll # get the /base branch, which is pure upstream -stable, and the same # meta SRCREV as the linux-yocto-standard builds. Select your version using the # normal PREFERRED_VERSION settings. BBCLASSEXTEND = "devupstream:target" -SRCREV_machine:class-devupstream ?= "2fe596715f840d053aed5cee5455f701bdcd2b50" +SRCREV_machine:class-devupstream ?= "7b923c78b50d2ec52690c4353e5aad8302e80599" PN:class-devupstream = "linux-yocto-upstream" KBRANCH:class-devupstream = "v6.18/base" @@ -43,7 +43,7 @@ SRC_URI = "git://git.yoctoproject.org/linux-yocto.git;name=machine;branch=${KBRA git://git.yoctoproject.org/yocto-kernel-cache;type=kmeta;name=meta;branch=yocto-6.18;destsuffix=${KMETA};protocol=https" LIC_FILES_CHKSUM = "file://COPYING;md5=6bc538ed5bd9a7fc9398086aedcd7e46" -LINUX_VERSION ?= "6.18.41" +LINUX_VERSION ?= "6.18.43" PV = "${LINUX_VERSION}+git" From patchwork Wed Sep 9 07:29:02 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 97662 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id BA4BDC79FBC for ; Wed, 9 Sep 2026 07:30:00 +0000 (UTC) Received: from mail-wr1-f46.google.com (mail-wr1-f46.google.com [209.85.221.46]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.6429.1788938996413394407 for ; Wed, 09 Sep 2026 00:29:56 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=J82JwriG; spf=pass (domain: smile.fr, ip: 209.85.221.46, mailfrom: yoann.congal@smile.fr) Received: by mail-wr1-f46.google.com with SMTP id ffacd0b85a97d-48586861639so3427476f8f.0 for ; Wed, 09 Sep 2026 00:29:56 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1788938995; x=1789543795; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=/xByexk267SoBcCMljGk5XCJl4Sn9kaX8FCnLFkol4Y=; b=J82JwriGOk2MTdGfsiElQdnSeWI3ILgLVy3ip7AsSNv5MR7v3RrCLbZjjXwXdk6mG8 ccoWZk4eUGE5dW7q2TijhOUjd8a+AeXwtlehBHj6XGaO/IkqrapefwACrLRG5ojropy+ sRpS7sl6525zZo44mQ6czi0g4WSBK0XgM/qCw= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1788938995; x=1789543795; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=/xByexk267SoBcCMljGk5XCJl4Sn9kaX8FCnLFkol4Y=; b=jK9ocq3AG1L+Z4WvFIxbqZkhBFVqN+DRa+tawdCSQSs9wT8WZC56d44dA2tImCiLKm gDZjT+i6CYQ/+qCQ9sgJ/6z5IFkFDNRHHYmJNwmjOUtSISySD9E5DcFGtrzxQL2Iwi1c 03lU/2HsCPFW6v+cXjZNdsaat9Ojyzm6Ah249YcvWWEHZHFa9ISOUEthlt+ayilpJqtG 8/Fv05upcKI7YBpsAQ5Dtf0/z/KAeChzUZKhqt2VwNsr7j2iMtiFd+48hESDgRGXxlEW OH3H1IaBAeuzDdCleRnbCRcF0OJEqEtIYs2FREKI5Wsz7pbth2D9mtN0pBQXI/uMNacD PhZg== X-Gm-Message-State: AFuF++k7g7RUy6pr0GOPN6GE+cSCvw71vML6olOLG6v9INnL3/c24dzr zdFhkT3XwczrIde7oGNW+2+1UJvgJO+5gu39UdqM7GDW/QNJGo/daS4dX4xuMVSpPeNu8/GQ5oi NH5hrcmk= X-Gm-Gg: AYBFou012i2hBP551ZKMYlaZGSoMJZ9Vf3eecgtBUjxD5p4E68XSPCzVKRvcqLgKU+O a8xG0bREMFFdpAp165aqdid0EnnHQFYpjCDhll8JhjR+U8zsnftZ/4p99Pjrc62QNk8xlFBEfjT cBGZZIDpYhfaN8oi9GCtiNoG3bpgzA96+bIRUY9AhnChhOMVy3eCFFujk+2iuHXAe1IjzazCE3J QWZ4ZVjVaDNHN0KG9xAR0sSbcR3UHLZ/Awpwvh6ULhoZFMmdSmzCKe+ldb5WlGVXV/AHjiBzj7Y vjRmFiD3byrdH9ZqD1xDyp7h3y+fcrThjhQmZMPJmmsTihffRnet6HQoHwAv1rvVcQdbomwoYcN 8PiLTIM3W8QMxOSLYhhUh04Xky89AxOx7DxtfeP5MWUQc3Npp69NNmioMalhhCq6nVhv7pMjOku naaMHTr4V4HiZA4UrLVWi4ZC/5oIs+yUsBBt0EL9lFxMax8y4p28D8XWHncCKcqnm3MSZxkI+ES snP/xgmBxe/Ey/hvQ6tGJ8glRmr8ki4DNxHjZVL5xfXRWN3URhUYpp9wzU88AU3Gmrzed0UIVc= X-Received: by 2002:a05:6000:4918:b0:485:ad72:cd65 with SMTP id ffacd0b85a97d-485ad72cf0fmr2274517f8f.2.1788938993929; Wed, 09 Sep 2026 00:29:53 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-4858ac2b4cdsm40624310f8f.16.2026.09.09.00.29.53 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 09 Sep 2026 00:29:53 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][wrynose 03/38] linux-yocto/6.18: update to v6.18.44 Date: Wed, 9 Sep 2026 09:29:02 +0200 Message-ID: X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Wed, 09 Sep 2026 07:30:00 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/245411 From: Bruce Ashfield Updating linux-yocto/6.18 to the latest korg -stable release that comprises the following commits: 1efe5d048a391 Linux 6.18.44 358b5dcf1fd7f drm/tegra: fbdev: Do not assign to struct drm_fb_helper.info e7731507270c2 drm/fb-helper: Fix a locking bug in an error path 7bc7af179916b usb: typec: ucsi: Correct teardown ordering in ucsi_init() error path 10be509fa8fd9 can: isotp: fix timer drain order, wakeup handling and tx_gen ordering 0902f06a6c0bb can: use skb hash instead of private variable in headroom 157b1e3384d7d drm/xe/pt: Reset current_op in xe_pt_update_ops_init() b1a71151317c4 drm/xe: Add page reclamation info to device info 6107b64cfccef drm/xe: Stub out new pagefault layer 184de3d31f728 drm/xe: Use SVM range helpers in PT layer df1582c0a101e drm/i915/vrr: require valid min/max vfreq for VRR 894d4a7395662 drm/i915/vrr: Check HAS_VRR() first in intel_vrr_is_capable() 21976fe525849 drm/xe: Wait on external BO kernel fences in exec IOCTL b8ad916ba4e18 drm/exec: Remove the index parameter from drm_exec_for_each_locked_obj[_reverse] d256dac008d1d drm/xe/vm: Fix BO prefetch with CONSULT_MEM_ADVISE_PREF_LOC 8fa8b0a463729 drm/xe/vm: Prevent binding of purged buffer objects 1ba553ee0b521 drm/xe/bo: Add purgeable bo state tracking and field madv to xe_bo 0015b054b06d3 drm/xe: add xe_migrate_resolve wrapper and is_vram_resolve support 005b9b4431606 drm/xe/pat: Add helper to query compression enable status 3cb42a973f889 drm/amd/display: Exit idle optimizations before programming dbbe08d73b8bc drm/amd/display: check GRPH_FLIP status before sending event b485bfb455551 drm/xe/guc: Fix buffer overflow in steered register list allocation 30b2d0843a410 drm/amdgpu: Respect placement requirements in amdgpu_gtt_mgr functions e06c39cc1c48d drm/amdgpu: Fix context pstate override handling 4d49ca777cf1a drm/tegra: fbdev: Remove offset into framebuffer memory 3f58077457985 drm/fb-helper: Allocate and release fb_info in single place 165613191ad9d userfaultfd: prevent registration of special VMAs 02d378828af8b wifi: brcmfmac: drain bus_reset work on device removal d6f322d68abfd media: uapi: rkisp: Correct name version enum 5c6d5d2484cab media: qcom: camss: Fix RDI streaming for CSID 340 f730ee0ef8fac media: qcom: camss: csid-340: Fix unused variables 276420a86e75f media: chips-media: wave5: Support CBP profile 3f7b3728dd901 usb: typec: ucsi: Fix race condition and ordering in port unregistration 58d9caa64f9c6 usb: typec: ucsi: split connector lock classes 2bf24a7e190aa net/handshake: Drain pending requests at net namespace exit 6e7b52bd13948 net/handshake: Close the submit-side sock_hold race 68eba6519cbd6 net/handshake: hand off the pinned file reference to accept_doit b913801ad9b9a net/handshake: Take a long-lived file reference at submit 5ddfc47e1228d net/handshake: Fix null-ptr-deref in handshake_complete() 97e745b4ea055 net/handshake: convert handshake_nl_accept_doit() to FD_PREPARE() f00dd592abe77 file: ensure cleanup 10827847c40c1 file: add FD_{ADD,PREPARE}() 10065fb891651 mm/huge_memory: unlock i_mmap_rwsem before releasing after-split folios be11b4bf498a3 fs/proc/task_mmu: fix PAGEMAP_SCAN written state for unpopulated ptes 2b9a07002c2f2 mm/hugetlb: fix swap entry corruption when clearing uffd-wp at fork() fc0c76b0450f2 drm/xe/rtp: Ensure locking/ref counting for OA whitelists 9783d8662b565 drm/xe/oa: (De-)whitelist OA registers on OA stream open/release f5966d9006623 drm/xe/rtp: (De-)whitelist OA registers for all hwe's for a gt d43abc858f082 drm/xe/rtp: Toggle 'deny' bit to (de-)whitelist OA regs c2cfee9bf8d46 drm/xe/rtp: Save OA nonpriv registers to register save/restore lists 4bb92418e749f drm/xe/rtp: Generalize whitelist_apply_to_hwe cc716d3ac560f drm/xe/rtp: Keep track of non-OA nonpriv slots f73e97080debd drm/xe/rtp: Maintain OA whitelists separately 7982678fa21ed drm/xe/rtp: Add RING_FORCE_TO_NONPRIV_DENY to OA whitelists 542d3b9fa8ec6 drm/xe/rtp: Refactor OAG MMIO trigger register whitelisting 2b70bebc70948 HID: logitech-dj: Fix maxfield check in DJ short report validation 6be3dbe45b287 spi: spi-cadence: enable SPI_CONTROLLER_MUST_TX 042ca38779554 drm/vmwgfx: validate external BO copy bounds for both stride paths cfd163169af3b drm/vmwgfx: use check_add_overflow for shader size+offset bound 1eb4f796695be drm/vmwgfx: enforce cursor size limits for MOB cursors 96efee36453b6 drm/vmwgfx: avoid destroy_workqueue(NULL) on vkms init failure 7e40e6120fb23 drm/vmwgfx: bound DMA command body size against suffix pointer dc0be7662b7b0 drm/vmwgfx: validate DRAW_PRIMITIVES header size before division a8434b145b1e4 drm/vmwgfx: drop dma_buf reference on foreign-fd prime import b79e82ea18236 drm/vmwgfx: take fman->lock around fence list mutation in fifo_down 10460699c312e drm/vmwgfx: clamp dirty-page range with min, not max e479240a1e076 drm/vmwgfx: reject DX_BIND_QUERY without a DX context 282f261cb035e drm/vmwgfx: fix guest_memory_dirty bitfield clobbered as size 6a52f48157fa7 drm/amdkfd: hold event_mutex while checkpointing CRIU events 6189ceca5ce75 drm/amdkfd: Handle invalid event type in CRIU event restore 6dc0b4b39ed4f drm/amdkfd: fix uint32_t overflow in EOP ring buffer size alignment 5f0f2ddeac738 drm/amdkfd: fix QID bit leak in pqm_create_queue() 9e52212aff8ed drm/amdkfd: Fix missing authorization check in KFD_IOC_DBG_TRAP_DISABLE 02647d9834073 drm/amd/display: use proper context for logging 3c2ae9509717c drm/amd/display: Increase HDMI AV mute wait from 2 to 3 frames 1860818feb4db drm/amd/pm: fix torn gpu metrics reads 45ba7f091abf4 drm/amdgpu: cap GTT size to physical RAM on APUs d330ac90d85f3 drm/amdgpu: restore UMD profile pstate after runtime resume 18d21c9d04b00 drm/amdgpu: move debug_vm handling to amdgpu_cs_parser_fini 0f1ff05c58e17 drm/mediatek: ovl_adaptor: balance component registrations c835f2b0b7167 drm/panthor: validate firmware interface structure sizes 2a761b9be5863 drm/panthor: reject firmware sections with oversized data da898bb6faf32 drm/bridge: display-connector: Fix I2C adapter resource leak 57667eb7548fa drm/vc4: Zero the tile state data array before each BIN job 6cd5acf6f87c0 drm/vc4: Supply the overflow slot size in BPOS, not the whole bin BO size 58d2bb394e884 drm/dp: Read the PCON max FRL bandwidth only for HDMI DFPs e8b797940536c can: ctucanfd: mark error-active controller status valid 7d1619f56a75a can: ctucanfd: handle bus error interrupts 46fc5aecde5cd can: ctucanfd: unmap BAR0 using base address cae2880f8ffae can: ctucanfd: use self-test mode for PRESUME_ACK aa5e790bf185e can: ctucanfd: add missing MODULE_DEVICE_TABLE() 2427ef427bdd7 can: peak_usb: validate uCAN receive record lengths 92d0de80ca222 can: peak_usb: peak_usb_start(): fix double free of transfer buffer on URB submit error 1acab790b7cec can: peak_usb: add bounds check for USB channel index 2ee477e541a6d can: softing: fw_parse(): validate firmware record spans 185cb1fa38142 can: kvaser_usb_leaf: kvaser_usb_leaf_wait_cmd(): validate received command extents 2e90b2b406077 can: kvaser_usb: kvaser_usb_hydra_get_busparams(): fix memory leak in kvaser_usb_hydra_get_busparams() 54258ea8d61fc can: j1939: use netdevice_tracker for j1939_{priv,session,ecu} tracking 8604a3b81b9d0 can: j1939: transport: j1939_session_fresh_new(): initialize receive buffer 996eb21acdc9c can: gs_usb: gs_usb_receive_bulk_callback(): resubmit URB on skb allocation failure c311f17c261fd can: etas_es58x: es58x_read_bulk_callback(): fix RX buffer leak on URB resubmit failure 0b23144c59c12 can: ems_usb: validate CPC message lengths 26cf99713a96f can: c_can: c_can_chip_config(): keep controller in init mode until bittiming is configured affd62f5719a7 i2c: imx: Cancel hrtimer before clearing slave pointer 12a4f0950a158 i2c: imx: Fix slave registration race and error handling 7a5db225ab5a6 i2c: imx: mark I2C adapter when hardware is powered down 82233ff0e36df i2c: iproc: reset bus after timeout if START_BUSY is stuck 19b783335d62e i2c: jz4780: Cache host clock rate at probe to prevent CCF prepare_lock deadlock 40dd717445998 i2c: qcom-cci: drop custom suspend/resume and rely on runtime PM helpers d9b5419df0654 i2c: spacemit: request IRQ after controller initialization 6a5cc2b4e6faf ice: fix memory leak in ice_lbtest_prepare_rings() 326c89ea2685a ice: fix VF interrupts cleanup 7e8789f5b5d8a ice: wait for reset completion in ice_resume() e0ba8eaef2a0d net: openvswitch: fix skb leak on flow key update failure during ct 9c7246cc509fd net: openvswitch: fix skb leak on flow key update failure during recirculation 90623c9499627 net: openvswitch: fix potential UAF on meter attach failure 74b30e7ef4618 phy: zynqmp: keep SERDES scrambler and 8b/10b enabled for USB 79a312664118f phy: zynqmp: use read-modify-write for SERDES scrambler bypass 4211450f0fecb phy: zynqmp: fix L0_TM_DISABLE_SCRAMBLE_ENCODER mask 013a4484f061a s390/zcrypt: Validate length for CCA ECC private key requests ad93a1f1a4565 s390/zcrypt: Validate length for CCA AES cipher key requests fbb0410986e8a s390/zcrypt: Fix missing mem scrub at clear key import in cca_clr2cipherkey() a57fd7fcdb63e s390/zcrypt: Fix buffer over-read in cca_cipher2protkey 672b12940e3f1 s390/zcrypt: Fix wrong domain value verification with EP11 CPRBs e16e0fc54120c s390/dasd: Fix undersized format-check buffer 86cdfd061509b s390/dasd: Fix potential NULL pointer dereference bd63c7879eaa8 s390/qeth: Check CAP_NET_ADMIN for private ioctls ef1aa7cfb8c63 s390/pci: Fix s390_pci_mmio_write syscall error return without MIO b039f13e095d2 power: supply: max17040: handle missing status supplier 6d89f33a64675 power: supply: bq25890: fix the -10 C NTC lookup entry 63d6c855b27df cpufreq: schedutil: Publish util hooks only after all sg_cpu are initialized 437b38a08c0a8 cpufreq: powernow-k8: Fix possible memory leak in powernowk8_cpu_init() efbcecdecefc2 cifs: add fscache_resize_cookie() to cifs_setsize() 466ab0c41d5f5 gpio: pch: use raw_spinlock_t for the register lock 2e4bc8422cdee gpio: pca953x: fix cache_only and IRQ state on restore_context() failure 1883a09a37fed i2c: amd-mp2: Unregister callback on adapter add failure 7a91d07939e07 hwmon: (pmbus/core) notify on the hwmon device, not the i2c client 30ae663746378 hwmon: (npcm750-pwm-fan): stop fan timer on device detach 4ba5bf7ed50f2 sctp: prevent peer transport count overflow a0d1693923f41 sctp: reject stale cookies with mismatched verification tags 2047ed09bf134 scsi: scsi_debug: Fix REPORT ZONES alloc_len underflow OOB write 5b4d4d5a29f92 selftests/clone3: fix wild pointer access of getline due to missing init a0bc578641d74 selftests/mm: fix potential wild pointer access of getline due to missing init 2e047b4171de4 spi: qcom-qspi: Correct max DMA length to avoid 64K boundary failure 581e5166f0780 spi: spi-qpic-snand: write the feature value before executing SET_FEATURE c26a6477e149c tracing/filters: Fix false positive match in regex_match_full() cbb5ed3be9cae tracing: Check return value of __register_event() in trace_module_add_events() 205feb72e5beb ublk: reset kernel-owned dev_info fields in ublk_ctrl_add_dev() ee799977d7941 vxlan: use pskb_network_may_pull() in route_shortcircuit() 94dee751aad62 vxlan: use pskb_network_may_pull() for transmit path header pulls ff89415d34c3a vxlan: use neigh_ha_snapshot() in route_shortcircuit() adeed09eeb3b6 vxlan: unclone skb head before modifying eth header in route_shortcircuit() 1235e017aa11c vxlan: re-fetch eth header after route_shortcircuit() b24ba0bbffe3e veth: convert frag_list skbs before running XDP 3bd35a5e272a1 uprobes: Fix NULL pointer dereference in hprobe_expire() 180ff4c81faf0 um: vector: fix use-after-free in vector_mmsg_rx() e4b98f9778dfc powerpc/ps3: Fix map failure path in dma_ioc0_map_pages() 4ef801b838d85 net: pktgen: fix proc entry use-after-free dc3ab04220667 net: ipv6: clear suppressed fib6 rule result 0309ebbc57000 net: bridge: stop fast-leave after deleting a port group 332a546b4ee56 mm: memcg: initialize *locked in memcg1_oom_prepare() stub b11907c905fa0 mm/page_reporting: use system_freezable_wq to fix UAF during suspend 63b361f228866 io_uring/net: initialize mshot_len for send 4dad8ca637d44 binfmt_misc: don't let an 'F' entry pin its own instance 840bb9c49c3e7 binfmt_misc: reject a flag character as the field delimiter 255a758697da8 binfmt_misc: use exe_file_deny_write_access() for the interpreter clone fdc1d702bf300 binfmt_misc: restore write access when removing an entry c9dcfe6b8b713 wifi: mwifiex: use the subframe length when parsing A-MSDU TDLS frames bed792737b5f1 tipc: avoid use-after-free in poll trace queue dumps 88752b811f72a of/address: Fix NULL bus dereference in of_pci_range_parser_one() 4ae701848e4ba netfilter: ipset: do not update comments from kernel-side hash adds f807a63d0d956 net/smc: fix socket use-after-free during link group termination 2060764e0f46c mshv: fix hv_input_get_system_property struct a60b5da05e318 ksmbd: reject repeated SMB2 NEGOTIATE requests b5ee5b266f833 ipvs: do not propagate one-packet flag to synced conns 3b5aee6fcbf6b igc: remove napi_synchronize() in igc_down() 845a9cdd9b03b igbvf: Fix leak in TX DMA error cleanup b10bb77e91e97 e1000: fix memory leak in e1000_probe() b0bdca3a49cf3 dmaengine: qcom: bam_dma: Fix command element mask field for BAM v1.6.0+ 2db4535d6af79 ALSA: usb-audio: Clamp frame size in implicit-feedback mode 04595233e5606 ALSA: usb-audio: Fix DMA buffer out-of-bounds write when fill_max is set b5305a0d0bb8e ALSA: usb-audio: fix OOB write in snd_usbmidi_akai_output() 7ba01e0d3539d ALSA: usb-audio: fix stack info leak in RME Digiface status cc014ebf80317 ALSA: usb-audio: fix use-after-free in ump_to_endpoint() 79f8720029f26 ata: libata-sata: fix ata_scsi_lpm_supported() iteration 9562ddbc6ed8f ata: libata-eh: Increase STANDBY IMMEDIATE timeout 0a02b0c878071 ASoC: tas2562: fix broken entries in the volume lookup table 35d5f1852e390 ASoC: tas2562: fix DVC coefficient write order cac7d2066b2f0 ASoC: fsl_easrc: fix m2m_init error path to use goto instead of bare return 6df5b32881602 ASoC: fsl_asrc: fix m2m_init error path to use goto instead of bare return 032746c2dd9a4 ALSA: ump: fix double free of out_cvts on rawmidi error a26a2e52736f9 ALSA: timer: Clear SNDRV_TIMER_IFLG_DEAD once the close completes 5260e195c53e8 ALSA: seq: Fix division by zero in initialize_timer() 2940cc3cf43c7 ALSA: pcm: wake linked drain waiters on unlink 4969533a1b950 ALSA: lx6464es: fix period byte count for 16-bit streams 7484669d1fbab ALSA: hda/realtek: Add quirk for TongFang X6SP45xU 11e2953d9f4c7 ALSA: 6fire: Fix UAF at error handling during probe c0d3b81f703b2 afs: Fix UAF when sending a message d703f022a28a2 afs: Fix afs_fs_fetch_data() to subtract transferred from len b53face003b4d afs: Fix afs_fs_fetch_data() to set call->async 5c7fdcbecbab2 bpf: lwt: Fix dst reference leak on reroute failure 27cc0e603355c Bluetooth: HIDP: validate numbered report payloads 2ebf63aa557a6 Bluetooth: HIDP: reject frames without a transaction header eb1d8318764de Bluetooth: hci_sync: Fix advertising data UAFs c569def320aa8 Bluetooth: mgmt: fix UAF in pair command cancellation a33bc07b4730b Bluetooth: SCO: give the socket its own sco_conn reference 814f82f432dc6 Bluetooth: mgmt: fix pending command UAF in EIR updates 6936b367ee6d4 Bluetooth: btmtk: Fix short read errors in btmtk_usb_uhw_reg_read() f14d41dbc2fdf Bluetooth: btusb: Fix short read errors in btusb_qca_send_vendor_req() cae0dfed5d307 audit: fix potential use-after-free in audit_del_rule() 185c784c98094 audit: fix potential integer overflow in audit_log_n_string() 17b412468c7a4 sctp: validate Adaptation Indication parameter length c0837aeace961 dibs: fix use-after-free of dmb_node in loopback attach/detach/unregister b878ba7e28144 KVM: s390: pci: Validate AIBV and AISB before pinning guest pages e137d082325bb KVM: s390: pci: Fix NULL dereference on AIBV allocation failure 1abf9ce39a862 KVM: s390: pci: Fix missing error codes and memory unaccounting 70871b121f81d KVM: s390: pci: Fix memory accounting for pinned/unpinned pages 6837f0ae85fd5 KVM: s390: pci: Reject adapter interrupt forwarding if already enabled 7668c58dcf465 KVM: SVM: Update x2APIC MSR intercepts if AVIC is inhibited while L2 is active 5acc92947baa2 KVM: VMX: add memory clobber to asm for VMX instructions e768ea3a422d1 tracing/fprobe: Roll back on enable_trace_fprobe() failure 3b2e08e0ede72 tracing/probes: Reject $arg0 in meta argument expansion e0fa737783b5b mm/vmstat: fold stranded per-cpu node stats when a node comes online 126a70bf1a08d mm/hugetlb: fix list corruption in allocate_file_region_entries() 32134cf9211b8 mm/percpu-km: fix bitmap overflow and accounting in pcpu_create_chunk() 7d3e1d3a0dce9 fs/proc/task_mmu: fix PAGEMAP_SCAN written state for PMD holes c091462e46f75 selftest: fix headers in fclog.c 9668ffe0e2a5e mm/util: don't read __page_2 for order-1 folios in snapshot_page() 2be94d6b20789 mm: migrate_device: fix pte_pfn/pte_dirty called on non-present PTE 2205263b1e013 fortify: Disable -Wstringop-overread in tests 96b0aa79b0e1e pinctrl: bm1880: add missing select GENERIC_PINCONF 5aaa06dfc10f8 erofs: cap LZMA stream pool size ad0ad3c228b6f pinctrl: devicetree: don't free uninitialized dev_name on error path 93d934668047f pinctrl: microchip-sgpio: add missing select REGMAP_MMIO 6da8f37419dd4 iommu/iommufd: Fix IOPF group ownership UAF 564ac339c0f8b iommufd: Fix wrong hwpt passed to iommufd_auto_response_faults on replace ee2212b482320 iommufd/viommu: Publish a vDEVICE only after vdevice_init() succeeds 294b464b2be7e iommufd/viommu: Release the igroup lock on the vdevice_size error path 062aa5dcc49a9 mshv: Order pt_vp_array publish against irqfd assertion path f50f5d3972da0 mshv: Fix level-triggered check on uninitialized data fc362bfcb060e mshv: adjust interrupt control structure for ARM64 72a90ce4918b5 mshv: Fix race in mshv_irqfd_deassign cfc686a1174aa iomap: add a separate bio_set for iomap_split_ioend 9be4a66f019ea ksmbd: fix use-after-free in __close_file_table_ids() 213b4568f6e5d ksmbd: return success for deferred final close cebba11df714b drm/i915/hdmi: Poll for 200 msec for TMDS_Scrambler_Status e51becb8f3377 qede: sync udp_tunnel ports outside qede_lock in the recovery path 51c52e493346f spi: spi-nxp-fspi: add per-SoC SDR/DTR clock rate limits for all supported SoCs caeaaf23f7c36 sched/deadline: Use revised wakeup rule only for running dl_server 5a73e8c632c31 octeontx2-pf: Set correct sequence for carrier off and tx queue stop b90916156b472 net: libwx: fix FDIR ATR queue mismatch for software VLAN packets 6bf322ab07418 ptp: netc: fix potential interrupt storm caused by incorrect unbind order 1e0dfb7e7a5d9 net: dsa: mt7530: error out on failed reads in MT7531 PHY polling fd9586881d478 net: dsa: mt7530: check bus->read() errors in the MDIO regmap backend 54e07a158f7ae riscv: mm: Fix out-of-bounds page-table walk during memory hot-remove b297559dc2f29 accel/qaic: use sizeof(*trans_hdr) for transaction length check 01bd01b61ad9e riscv: drop __init from vec_check_unaligned_access_speed_all_cpus a20a0010eb648 tracing/mmiotrace: Add NULL check for mmio_trace_array in logging functions 9b604041f1009 tracing/mmiotrace: Reset dropped_count in mmio_reset_data() fc97dcb42fb46 fprobe: Fix module reference count leak on error in register_fprobe() 84b5aa55de7c8 drm/i915/dp: Ignore the sink's DSC max FRL rate without a PCON DSC encoder 50edffd0854fe can: isotp: check register_netdevice_notifier() error in module init b4f8c33593f25 net: sxgbe: check descriptor ring allocation failures 42b87cfd9666e net: sxgbe: free TX rings on RX allocation failure 69a258a5a322e scsi: target: Clear cmd_cnt when initial counter enrollment fails 54c6fb24c6021 scsi: zfcp: Fix memory leak during adapter release by destroying gid_pn_req ff333def31476 scsi: ufs: core: Revert "Delegate the interrupt service routine to a threaded IRQ handler" c249cfe1d8df2 scsi: ufs: core: Avoid IRQ thread wakeup during active UIC command e504204489993 scsi: ufs: core: Cancel RTC work in active-active suspend bdd8a1297ef10 scsi: target: iblock: Fix wrong PR ops NULL check for PREEMPT/RELEASE 613aaeeaf8cb1 net: phylink: put link_gpio if phylink_create fails 5ea70ad040c1b x86/boot: Add volatile, clobbers and zero-length test in memcmp() 5576afebf726c Bluetooth: hci_sync: fix hci_conn_del() use in hci_le_create_conn_sync e8f9fef362bab Bluetooth: hci_conn: hold conn reference in abort_conn_sync() de17305393ec8 Bluetooth: hci_sync: make hci_cmd_sync_run_once return -EEXIST if exists c618a9a5b08ea Bluetooth: btintel: Validate length before parsing diagnostics TLV 3b921533e8aa9 Bluetooth: ISO: fix refcounting of iso_conn e941799c31f68 Bluetooth: ISO: ensure no dangling hcon references in iso_conn 82e982f54f962 Bluetooth: ISO: avoid deadlocks in iso_sock_timeout e76a0ae6542ae Bluetooth: ISO: fix leaking sk after socket release 4e9b5e8669b36 Bluetooth: ISO: hold sk properly in iso_conn_ready 09a69828ae594 Bluetooth: ISO: fix CONNECTED -> CLOSED transition on shutdown/release cde36776cfe64 Bluetooth: ISO: Fix not updating BIS sender source address dfce8d30fc5be Bluetooth: ISO: validate sockaddr_iso first in iso_sock_rebind_bis() 1fc2132950c23 Bluetooth: ISO: fix timeout vs sync_timeout typo in check_bcast_qos e8e9cff6d80ee Bluetooth: ISO: lock sk in iso_connect_ind 3120664aa3330 Bluetooth: ISO: Fix data-race on iso_pi(sk) in socket and HCI event paths f1f167991a68f Bluetooth: HCI: Add initial support for PAST 72d5bb1d77d7c Bluetooth: ISO: lock sk in iso_sock_getname 58e3c5289ad23 Bluetooth: L2CAP: fix UAF in l2cap_le_connect_rsp 63c0f396a18b7 Bluetooth: ISO: clear iso_data always when detaching conn from hcon 4e1f45de5b313 ice: suppress DPLL errors during reset recovery 6ebbf198e76ca idpf: Fix mailbox IRQ name leak on request failure d44081c61dc92 idpf: adjust TxQ ring count minimum ae7120102e1bb hwmon: (pmbus) Fix return value from pmbus_update_byte_data() 276f1f180f55d net: ethernet: mtk_eth_soc: pass eth to mtk_handle_irq_rx in poll_controller 2c148a31ca01f netfs: release readahead folios on iterator preparation failure 291ebecdf315d netfs: handle single writeback rolling buffer allocation failure 627826ef42080 netfs: clear PG_private_2 on copy-to-cache append failure b558e07708d88 wifi: mac80211: validate individual TWT params before driver setup f82a2ded3d7a9 net: udp_tunnel: fix memory leak in udp_tunnel_nic_unregister() acbf711a20669 powerpc/boot: Fix treeboot-akebono CPU node lookup check b407b98cf665d powerpc/boot: Fix treeboot-currituck CPU node lookup check 3d24f2e5641b2 powerpc/boot: Fix simpleboot CPU node lookup check db986098f3088 rtase: fix double free of multi-frag skb on DMA map failure 5a6b0ccb8b018 hwmon: (adt7470) Fix PWM auto temp state array and bounds check 96ad57d317635 hwmon: (adt7470) Fix divide-by-zero TOCTOU crash in fan speed read ddd689bd72264 hwmon: (adt7470) Use cached PWM frequency value 1d6b54dbe8850 hwmon: (adt7470) Fix swapped PWM3 and PWM4 auto mode masks d5d4034bb6f6e hwmon: (adt7470) Fix temperature alarm logic in hwmon_temp_read() 82d65f7ef11ed hwmon: (adt7470) Fix busy-loop and I2C flooding in update thread 3e06ff0c79ea3 hwmon: (adt7470) Fix cache updated before hardware write on I2C error 28548ecc2b458 hwmon: (adt7470) Fix fans stuck in manual mode on I2C errors ae20a8a4de06a forcedeth: fix UAF of txrx_stats in nv_remove 2e0c6761c0553 net: bridge: mrp: fix Option TLV length in MRP_Test frames 1b722740ac5c2 hwmon: (nct6775-core) Prevent access to unsupported weight registers 5ec5f00fc606a net: do not send ICMP/NDISC Redirects when peer allocation fails 2332d35aaf206 hwmon: (nzxt-smart2) DMA-align output buffer 075fce376cf85 hwmon: (lm90) Only report alarms if driver is ready c498adfd4c3e8 hwmon: (sht3x) Fix unaligned accesses 08aee6d45eefc hwmon: (ltc4282) Fix reading the minimum alarm voltage b60e8486c04de hwmon: (ina2xx) Fix various overflow issues e627f4ad9eea2 hwmon: (ina2xx) Shift INA234 shunt and current registers fdfde077e025c hwmon: (ina2xx) Add support for INA234 8da94361f9ae1 hwmon: (ina2xx) Make it easier to add more devices a42d727dae570 hwmon: (nct6775-core) Fix number of temperature registers for NCT6116 e28d478c003d7 spi: spi-cadence: Move TX FIFO full busy-wait into FIFO d3337eefab626 spi: spi-cadence: supports transmission with bits_per_word of 16 and 32 fcc3d77fef02c ASoC: tas2781: Use correct calibration data for SINEGAIN2 register b2851429afc5b smb: client: fix buffer leaks in SMB1 read and write 9e24b47ef81d4 scsi: libsas: Fix HA resume deadlock and hisi_sas disk-wake race 72815741715bd scsi: libiscsi_tcp: Bound SCSI Response data segment to the connection buffer 3ef209ca0b4b6 scsi: libiscsi: Fix stale-data leak into the SCSI sense buffer 8e0996418590b pinctrl-amd: Don't clear S4 wake bits at probe ceb00cb87a22c xsk: drain continuation descs after overflow in xsk_build_skb() 411554cb868b8 xsk: use a smaller new lock for shared pool case 05e283466b86e xsk: fix buffer leak in xsk_drop_skb() for AF_XDP multi-buffer Tx 814c5b1590037 selftests/net/af_unix: test listen() rejects wrong socket states 643ec3e24a490 selftest: af_unix: Create its own .gitignore. 0372a52191127 selftests: af_unix: Add tests for ECONNRESET and EOF semantics 5c170577049f9 af_unix: fix listen() succeeding on sockets in the wrong state b1d480fce05f8 rds: tcp: hold the RCU lock across ipv6_chk_addr() in rds_tcp_laddr_check() f6787fdffcae5 rds: Fix inet6_addr_lst NULL dereference when IPv6 is disabled 4147866087fbe ASoC: SDCA: Ensure that Control Range is large enough for header 16b553c46e347 netfilter: nft_payload: fix mask build for partial field offload e6f4b4b40db87 ipvs: do not mangle ICMP replies for non-first fragments ce96c40a049be ipvs: fix places with wrong packet offsets 00eb23829fd08 ipvs: fix the checksum validations d186f77d18bdf netfilter: xt_hashlimit: validate hashtable supports XT_HASHLIMIT_RATE_MATCH 63ba12b664a2c netfilter: nf_tables: make nft_object rhltable per table adf1a3ba27ad1 assoc_array: trim the final shortcut word using the current chunk end 3d9f16c0b643c keys: make keyring key-chunk byte order agree with keyring_diff_objects() e9417d21a22ad keys: fix out-of-bounds read in keyring_get_key_chunk() 6469ad3005087 KEYS: trusted: dcp: fix key_len validation and calc_blob_len() return type 31d491f9da948 KVM: arm64: Reject guest_memfd memslots when the VM has MTE db1c4a8e9080f mshv: Fix sleeping under spinlock in mshv_portid_alloc a920ead0bc2f1 mshv: Fix duplicate GSI detection for GSI 0 b215cb70e14c7 Drivers: hv: vmbus: Replace lockdep_hardirq_threaded() with lockdep annotation d397787dbc4bf Drivers: hv: Allocate the paravisor SynIC pages when required 74d20e3cf88e4 Drivers: hv: Rename fields for SynIC message and event pages 82cdbb6155a2c arch/x86: mshyperv: Discover Confidential VMBus availability 6e70eba930a24 drm/mediatek: Check CRTC state before freeing f74554e67ccf0 netfilter: nf_conntrack_sip: widen NAT rewrite delta to s32 in sip_help_tcp() ec81ecd2ac093 phy: zynqmp: fix runtime PM leak on probe allocation failure 86fb88ac8c915 phy: zynqmp: fix clock error handling in xpsgtr_phy_init() dff474e723ede btrfs: raid56: fix an incorrect csum skip during scrub 4d4ef6627304a btrfs: zoned: reset meta_write_pointer on zone reset deddd28fd83c2 btrfs: zoned: fix deadlock between metadata writeback and transaction commit 762561c438599 btrfs: fix leaking BTRFS_FS_STATE_REMOUNTING flag cfa7e27348773 of: reserved_mem: prevent OOB when too many dynamic regions are defined f5edba9bc69d0 ASoC: max98090: fix missing IS_ERR() before PTR_ERR() on mclk lookup 3cbfb9b886dc1 ASoC: max98095: fix missing IS_ERR() before PTR_ERR() on mclk lookup 3fd94b9ffe997 phy: qcom: m31-eusb2: Fix return value of init call 9355f526c821f ata: ahci_ceva: fix error paths in ceva_ahci_platform_enable_resources() a0f288ebe6d8a ata: sata_mv: accept 1 or 2 resources in platform probe 8229a53888540 selftests/seccomp: Fix pointer type mismatch build error 99dc2c143dfc0 selftests/lkdtm: rename STACKLEAK_ERASING to KSTACK_ERASE 094145989b31f gpio: sloppy-logic-analyzer: Fix memory leak in gpio_la_poll_probe() 3808bab5d95ae iommu/arm-smmu-v3-iommufd: Require exactly one Stream ID for a vDEVICE 0679c0c189d25 dmaengine: idxd: fix fdev setup failure cleanup in idxd_cdev_open() 9086b488f2737 dmaengine: sun6i-dma: Fix reclaim descriptors while terminating DMA 2ef9bb422dd6d pinctrl: qcom: sc8280xp: Add missing wakeup entries for GPIO143/151 3e55d28095476 pinctrl: qcom: Unconditionally mark gpio as wakeup enable 54a62153c765c thunderbolt: Prevent XDomain delayed work use-after-free on disconnect d01e88d421a6d mm/slab: prevent unbounded recursion in free path with new kmalloc type 3e957c9b160cf lib/alloc_tag: introduce mem_alloc_profiling_permanently_disabled() 98f57011e6cd1 HID: logitech-dj: fix wrong detection of bad DJ_SHORT output report bc3bba4656ad2 HID: logitech-dj: Prevent REPORT_ID_DJ_SHORT related user initiated OOB write df0f33293c0a3 HID: logitech-dj: Standardise hid_report_enum variable nomenclature 302eb87651326 ALSA: hda/realtek: add quirk for HP Dragonfly Folio G3 2-in-1 e8362523fd1b6 drm/gpusvm: publish dpagemap early to avoid device mapping leak on error a5cdd2407dd89 net: mpls: initialize rtm_tos in mpls_getroute() 85b94a74a0b83 netfilter: br_netfilter: Reallocate headroom if necessary in neigh_hh_bridge() 9bb3714e09986 kunit: tool: Terminate kernel under test on SIGINT d36086cd1826e kunit: tool: skip stty when stdin is not a tty 285641eb82f0e netfilter: nf_conntrack_expect: restore helper propagation via expectation Signed-off-by: Bruce Ashfield Signed-off-by: Richard Purdie (cherry picked from commit 5ad5ad94f023ec2149585f0e0bae9847fc5bb06d) Signed-off-by: Yoann Congal --- .../linux/linux-yocto-rt_6.18.bb | 6 ++--- .../linux/linux-yocto-tiny_6.18.bb | 6 ++--- meta/recipes-kernel/linux/linux-yocto_6.18.bb | 24 +++++++++---------- 3 files changed, 18 insertions(+), 18 deletions(-) diff --git a/meta/recipes-kernel/linux/linux-yocto-rt_6.18.bb b/meta/recipes-kernel/linux/linux-yocto-rt_6.18.bb index edb3696b25e..a7051c6e47c 100644 --- a/meta/recipes-kernel/linux/linux-yocto-rt_6.18.bb +++ b/meta/recipes-kernel/linux/linux-yocto-rt_6.18.bb @@ -15,13 +15,13 @@ python () { raise bb.parse.SkipRecipe("Set PREFERRED_PROVIDER_virtual/kernel to linux-yocto-rt to enable it") } -SRCREV_machine ?= "f3301719a9aa0f6e52a9ef3f54f7339a4241f7b9" -SRCREV_meta ?= "7f630b9b05e171d09925e2f0edd84697ff826f93" +SRCREV_machine ?= "f987d803014658f4fbccff70cfb9c42cc381f710" +SRCREV_meta ?= "7b09e5efab49e4bae0c69f7f2c65b4df00e9c565" SRC_URI = "git://git.yoctoproject.org/linux-yocto.git;branch=${KBRANCH};name=machine;protocol=https \ git://git.yoctoproject.org/yocto-kernel-cache;type=kmeta;name=meta;branch=yocto-6.18;destsuffix=${KMETA};protocol=https" -LINUX_VERSION ?= "6.18.43" +LINUX_VERSION ?= "6.18.44" LIC_FILES_CHKSUM = "file://COPYING;md5=6bc538ed5bd9a7fc9398086aedcd7e46" diff --git a/meta/recipes-kernel/linux/linux-yocto-tiny_6.18.bb b/meta/recipes-kernel/linux/linux-yocto-tiny_6.18.bb index 894267acdf1..6f3c9b63e5a 100644 --- a/meta/recipes-kernel/linux/linux-yocto-tiny_6.18.bb +++ b/meta/recipes-kernel/linux/linux-yocto-tiny_6.18.bb @@ -9,7 +9,7 @@ require recipes-kernel/linux/linux-yocto.inc include recipes-kernel/linux/cve-exclusion.inc include recipes-kernel/linux/cve-exclusion_6.18.inc -LINUX_VERSION ?= "6.18.43" +LINUX_VERSION ?= "6.18.44" LIC_FILES_CHKSUM = "file://COPYING;md5=6bc538ed5bd9a7fc9398086aedcd7e46" DEPENDS += "${@bb.utils.contains('ARCH', 'x86', 'elfutils-native', '', d)}" @@ -18,8 +18,8 @@ DEPENDS += "openssl-native util-linux-native" KMETA = "kernel-meta" KCONF_BSP_AUDIT_LEVEL = "2" -SRCREV_machine ?= "73fd4709c133ba2ee6012cfb6a63eb908d1a5cc6" -SRCREV_meta ?= "7f630b9b05e171d09925e2f0edd84697ff826f93" +SRCREV_machine ?= "1b6ed62ce69bdf976f1b580c20f5271ed105958e" +SRCREV_meta ?= "7b09e5efab49e4bae0c69f7f2c65b4df00e9c565" PV = "${LINUX_VERSION}+git" diff --git a/meta/recipes-kernel/linux/linux-yocto_6.18.bb b/meta/recipes-kernel/linux/linux-yocto_6.18.bb index e510ff01aaf..2a515e6bfe9 100644 --- a/meta/recipes-kernel/linux/linux-yocto_6.18.bb +++ b/meta/recipes-kernel/linux/linux-yocto_6.18.bb @@ -17,25 +17,25 @@ KBRANCH:qemux86-64 ?= "v6.18/standard/base" KBRANCH:qemuloongarch64 ?= "v6.18/standard/base" KBRANCH:qemumips64 ?= "v6.18/standard/mti-malta" -SRCREV_machine:qemuarm ?= "6e4861d133214a07c0b2f3e6d8de190fa2734697" -SRCREV_machine:qemuarm64 ?= "73fd4709c133ba2ee6012cfb6a63eb908d1a5cc6" -SRCREV_machine:qemuloongarch64 ?= "73fd4709c133ba2ee6012cfb6a63eb908d1a5cc6" +SRCREV_machine:qemuarm ?= "ca14f75460e4cdd77e7f4b18e356d772236fc4bf" +SRCREV_machine:qemuarm64 ?= "1b6ed62ce69bdf976f1b580c20f5271ed105958e" +SRCREV_machine:qemuloongarch64 ?= "1b6ed62ce69bdf976f1b580c20f5271ed105958e" SRCREV_machine:qemumips ?= "62ea92a539f58803a222be98b81118403074206e" -SRCREV_machine:qemuppc ?= "73fd4709c133ba2ee6012cfb6a63eb908d1a5cc6" -SRCREV_machine:qemuriscv64 ?= "73fd4709c133ba2ee6012cfb6a63eb908d1a5cc6" -SRCREV_machine:qemuriscv32 ?= "73fd4709c133ba2ee6012cfb6a63eb908d1a5cc6" -SRCREV_machine:qemux86 ?= "73fd4709c133ba2ee6012cfb6a63eb908d1a5cc6" -SRCREV_machine:qemux86-64 ?= "73fd4709c133ba2ee6012cfb6a63eb908d1a5cc6" +SRCREV_machine:qemuppc ?= "1b6ed62ce69bdf976f1b580c20f5271ed105958e" +SRCREV_machine:qemuriscv64 ?= "1b6ed62ce69bdf976f1b580c20f5271ed105958e" +SRCREV_machine:qemuriscv32 ?= "1b6ed62ce69bdf976f1b580c20f5271ed105958e" +SRCREV_machine:qemux86 ?= "1b6ed62ce69bdf976f1b580c20f5271ed105958e" +SRCREV_machine:qemux86-64 ?= "1b6ed62ce69bdf976f1b580c20f5271ed105958e" SRCREV_machine:qemumips64 ?= "9fb4ff0187c85426f21fd40d4c61b742800f65c4" -SRCREV_machine ?= "73fd4709c133ba2ee6012cfb6a63eb908d1a5cc6" -SRCREV_meta ?= "7f630b9b05e171d09925e2f0edd84697ff826f93" +SRCREV_machine ?= "1b6ed62ce69bdf976f1b580c20f5271ed105958e" +SRCREV_meta ?= "7b09e5efab49e4bae0c69f7f2c65b4df00e9c565" # set your preferred provider of linux-yocto to 'linux-yocto-upstream', and you'll # get the /base branch, which is pure upstream -stable, and the same # meta SRCREV as the linux-yocto-standard builds. Select your version using the # normal PREFERRED_VERSION settings. BBCLASSEXTEND = "devupstream:target" -SRCREV_machine:class-devupstream ?= "7b923c78b50d2ec52690c4353e5aad8302e80599" +SRCREV_machine:class-devupstream ?= "1efe5d048a391de3ead2804b2e7f86376c356cc5" PN:class-devupstream = "linux-yocto-upstream" KBRANCH:class-devupstream = "v6.18/base" @@ -43,7 +43,7 @@ SRC_URI = "git://git.yoctoproject.org/linux-yocto.git;name=machine;branch=${KBRA git://git.yoctoproject.org/yocto-kernel-cache;type=kmeta;name=meta;branch=yocto-6.18;destsuffix=${KMETA};protocol=https" LIC_FILES_CHKSUM = "file://COPYING;md5=6bc538ed5bd9a7fc9398086aedcd7e46" -LINUX_VERSION ?= "6.18.43" +LINUX_VERSION ?= "6.18.44" PV = "${LINUX_VERSION}+git" From patchwork Wed Sep 9 07:29:03 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 97664 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 9ED3EC79FB9 for ; Wed, 9 Sep 2026 07:29:59 +0000 (UTC) Received: from mail-wr1-f54.google.com (mail-wr1-f54.google.com [209.85.221.54]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.6430.1788938997300836205 for ; Wed, 09 Sep 2026 00:29:57 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=Bzkhdr7I; spf=pass (domain: smile.fr, ip: 209.85.221.54, mailfrom: yoann.congal@smile.fr) Received: by mail-wr1-f54.google.com with SMTP id ffacd0b85a97d-47f96c5b722so3889765f8f.0 for ; Wed, 09 Sep 2026 00:29:57 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1788938995; x=1789543795; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=Io6KDWFWJjeBfov3c6B+ah48x7CTVaKauI3BrgXzycM=; b=Bzkhdr7IuicGRYQJBr5dHtL8oUJmsd19J8MCcqD7JN4wXDs2RA7XiKpzWiWYN1FFGr PuT6auWZpnCPGzX/PK6QxkMVz3xQrbxL5Gvd5U7bYNgSGyih5LT+rOke2UoH7KxkxAV3 IViqP0jObvmzQ3EyDeojqvbCMkqCqbi67WP7o= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1788938995; x=1789543795; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=Io6KDWFWJjeBfov3c6B+ah48x7CTVaKauI3BrgXzycM=; b=Tt9xjf92G5ybzBAjw3WbHVeZLAfsaYM5IqGOVKeKSi3pYvNZfZX0O238XJ65IV21u7 EETE/Wx8ODE3/R5s84MhOOhLlO7niL07FXrnbaSFPp6sRxf4lv8WrfKD/teKiNMQfH15 iVhSpW4kyYQ3CUjZhMjKvva1qXPqPjflaoK36YScEE7bzbTvJ92vI/A6yRsGkLtIn//G L53HzWFqNaY67tHyvAPp/MxYJTg3LR1p1LEBgK3yC5V1D/f7+YZe38RxfCZFzBPb2UdL JdbqtbWni0b3wG4yy4R4zSxQ6XZ3rHnPFUXJ/lDfVbdd9eyMI9ifFSeqqCzGS2oWW6MW Hl7w== X-Gm-Message-State: AFuF++kFAwmRBqlVmIgtS0XNZcyUTg8nu4bAjFvLfyofwynEarj5g3x3 zfg8W1sowxg1GaBHvp2bVS4d8zhktdK+Ot1PCkKmnSkSo+DeXRisfqbmcrqjOtHSL/DQnZ6ZNsH U6QTZUck= X-Gm-Gg: AYBFou0ODF4ypH4gEFEODtHpk0boW6kaRKbFawd+pjzSpPjBUUcywYUuGn8czEgnVhn a5Sa6MQM7sqEtXl/vCxLg68A9PykmF3YmLfb63k3nCSgD4shm1H7bDYNgI56dhL9VLaI31Qyfgz zwmFK7FQ8IOjj3VgZEYV+Zt7QbNLjbFoXFCrgK3WjAU1uq59XNqAN3gIrTwxp3571H8OW/SUAbt ka019qbBf1AvIftErwgj4xglEc6WOX3VYDJVPUne9ULv0U+FvgGZkK/DST7FefZ7qxNV3M4jUFp VAuB/++7glP45/TEbpAQ9gOo5HzgaXc4p53dAZjvSFEUsnc45Rdbu0oqnCd13+ruE2fK0oMZw4Y 6RAxyzFuPqwYywHwJRQEey/8JpDHal21QmNubTmBgdbpHUTPKbUXU6Hz6zCfAvWyqGc8fZJM7eD rQ9rubUtt3mJ9lMoOTvILSyrRoWZ5cvXi6kjevUrwKOC2q2WHt6joz0AVbAcYgvOmDFf3JpVkUA pjV8rzn7rKkr5wFvuS98r9VItS5rEmj4BQA63Br0FtTA6LWmFlr79eVVvOSlc3XmXTzEhPcZNQ= X-Received: by 2002:a05:6000:4a0a:b0:484:3310:f39b with SMTP id ffacd0b85a97d-485872e05f9mr36397343f8f.28.1788938994868; Wed, 09 Sep 2026 00:29:54 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-4858ac2b4cdsm40624310f8f.16.2026.09.09.00.29.54 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 09 Sep 2026 00:29:54 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][wrynose 04/38] linux-yocto/6.18: update to v6.18.48 Date: Wed, 9 Sep 2026 09:29:03 +0200 Message-ID: <6e1e2cea84e83705a95e341d7eccf7e1b804b9fb.1788938909.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Wed, 09 Sep 2026 07:29:59 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/245414 From: Bruce Ashfield Updating linux-yocto/6.18 to the latest korg -stable release that comprises the following commits: 5bbb9c9f8f808 Linux 6.18.48 c49f04e8d2b94 inet: frags: strip GSO state from fragments before reassembly 7519e95095c9b Linux 6.18.47 3ce832e2bd431 net: gro: properly validate BIG TCP aggregation criteria 5b4f2bec7bea6 ptp: vmclock: prevent read-only mappings from becoming writable dba60d26e9dda futex: Avoid private hash use-after-free on final put e1534d49a7b8b Bluetooth: hci_aml: validate firmware segment lengths b7d9edcf9fe6e Bluetooth: MGMT: reject HCI_CMD_SYNC params_len above 255 1f6d1f2611af0 Bluetooth: ISO: zero the sockaddr before returning it in getname 753af97d8d423 Bluetooth: ISO: do not force BT_LISTEN after a failed BIG sync fe93a697a7a92 Bluetooth: hci_sync: Fix accept list UAF during suspend e3f82e8f2a591 Bluetooth: hci_event: validate LE Set CIG Parameters response 39a3afb91be3c Bluetooth: hci_event: fix LE list UAF on reset 608f8fd8c0f7b HID: hyperv: validate initial device info bounds 849e537160bbb HID: uclogic: fix use-after-free of inrange_timer on remove 8406d4b69d48b HID: sensor: custom: Fix use-after-free in enable_sensor 1fa1591efd417 HID: core: fix number/pointer type confusion on long items 5efcd7bbfaaec HID: nintendo: stop device IO before hid_hw_stop on probe failure 268679f501386 HID: nintendo: register input device after capabilities are set 51cfd1adbe7a4 HID: nintendo: fix out-of-bounds read in joycon_ctlr_read_handler() 942b89f7824f8 futex: Fix might_sleep() warning in futex_pivot_pending() 86d12b34bafc9 futex: Fix race on the initial mm->futex.phash.ref allocation fdf538b2e6965 futex/pi: Plug private futex exec() race 4da67def9efe6 futex: Sanitize and document task_struct::futex::state transitions 2b92e5562653b futex/pi: Reject cross-mm private futex owners f303f6a4c9099 Input: atkbd - skip deactivate for HONOR ZQC-P 936ea65543da0 Input: atkbd - skip deactivate for HONOR FMB-P's internal keyboard 0ea8f06454012 xfrm: fix sk_dst_cache double-free in xfrm_user_policy() 39fc615e355b6 net/ionic: avoid OOB TX partner lookup for hwstamp RXQ 4529c03c3da8f HID: pidff: fix OOB write when hid->inputs is empty 9a1d7c5f0d82e HID: core: fix OOB read of field->usage in hid_set_field() ace7fc4d38799 HID: magicmouse: Prevent out-of-bounds (OOB) read during DOUBLE_REPORT_ID 15b60ade825c8 HID: magicmouse: do not keep a stale msc->input if no input is claimed 62ec3c591ee81 HID: magicmouse: re-enable multitouch after reset-resume 02a88f8308ae7 HID: magicmouse: fix battery reporting for Bluetooth Magic Trackpad USB-C b6baab796d11f ASoC: codecs: lpass-tx-macro: Fix enum kcontrol accesses 9fe5eebb664ec mptcp: pm: fix memory leak from alloc-during-teardown race 6fa2064761ec0 mptcp: pm: uniform announced addresses helpers 714c6d11aceaa mptcp: pm: rename add_entry structure to add_addr defc59e74c1b4 mptcp: pm: use for_each_subflow helper f31650243c1ab nvmet: pci-epf: put CQ ref on create_cq mapping failure 20be486d1c225 nvmet: pci-epf: fix use-after-free in nvmet_pci_epf_exec_iod_work() 9c95f7e66c62e nvmet-tcp: Do not WARN on remotely-controlled oversized SGL allocations 6d27199ebe8cb nvmet-tcp: bound SGL data length before allocating command buffers 8bce9cd08aae4 nvmet-fc: fix invalid free in LS IOD error path b26189d284421 nvmet-auth: zero the AUTH_RECEIVE response buffer 23a475ff24d29 dmaengine: fsl-edma: Add error handling for devm_kasprintf 364edaedf4125 mailbox: mchp-ipc-sbi: Add null check for devm_kasprintf() 3dc98e5fe82d0 ipv6: fix use-after-free in ip6_finish_output2() d9d1a676b033a ipv4: reject undersized MTUs in ip_do_fragment() f034150305791 drm/xe: Fix DPT allocation paths. 20892d2923e48 nfc: nci: free destination parameters when closing a connection 0d4b5cfab6891 nfc: nci: fix uninit-value in the RF discover/activated NTF handlers 2f08dbce3b376 nfc: nci: fix out-of-bounds write in nci_target_auto_activated() 9620a91f8d643 nfc: nci: add data_len bound checks to activation parameter extractors bfcca5f42c9aa nfc: st21nfca: validate ATR_REQ length against the received frame 2f5d093194ec2 nfc: pn533: purge fragmented skbs during cleanup e969e98410051 nfc: llcp: reject PDUs shorter than the LLCP header 2d239590d1845 nfc: llcp: fix OOB read and u8 offset wrap in TLV parsers e87527b506c40 nfc: llcp: bound the connect_sn TLV walk to the skb d0902a7c45432 nfc: microread: validate target discovery payload lengths db7e464b35096 nfc: fdp: bound the device-reported read length and fix an skb leak a56773e649ea9 nfc: digital: clamp SENSF_RES length to the destination buffer cb8246e5846db libceph: fix OOB read in decode_watchers() via missing bounds check 184c1a80421a5 xfs: validate attr entry pointer before field access e0e7f464d6ce8 ext4: fix incorrect function call when initializing s_resgid 458776af0061a ext4: don't enable DAX on new encrypted files f3d2fa3a99336 ext4: propagate errors from fast commit range replay 5f46f084f74b5 ext4: avoid tail write_begin walk for uptodate folios fb5980fbe44fc ext4: clear error before retrying inode xattr space fallback e447f7edb99bd nilfs2: reject invalid block index in GC ioctl 4902a5cba21ae ext4: stop retrying saturated xattr cache entries e11f5b48c8270 kcov: fix data corruption and race conditions on PREEMPT_RT 164ca33cf5366 null_blk: fix UBSAN shift-out-of-bounds when zone_size is 0 or overflows 6176313622e34 ocfs2: fix missing metadata reservation for large xattrs 15ccf53709859 io_uring/uring_cmd: don't skip completion for a synchronous multishot cmd 45c945107e007 io_uring/rsrc: fix folio size overflow in io_vec_fill_bvec() 4074ae2f1da9e io_uring/io-wq: fix worker accounting when canceling creation callbacks b6a768aa975b9 io_uring/cmd: fix iovec leak when the async cmd is not recycled f20c2c32ec1c5 ALSA: dummy: Check card index validity at probe 3da64f2ed902b io_uring/futex: don't mark futex wake requests as inflight 61dc1a37e04d4 nvmet: fix NULL pointer dereference in nvmet_execute_identify_nslist() e971d956353d3 rndis_host: add overflow check in rndis_rx_fixup() 4305e4b52acc0 ALSA: scarlett2: Use a private URB for the notification endpoint 65aceb45ca91d ALSA: FCP: Use a private URB for the notification endpoint 7596354148c5a iommu/iommufd: Fix NULL pointer deref in iommufd_ioas_change_process when racing with iopt_map_file_pages d2ab08437e913 iommu/tegra241-cmdqv: Fix CMD_SYNC use-after-free on teardown d4b1a13b1eff2 Bluetooth: RFCOMM: take rfcomm_mutex for the deferred setup accept 0c55707bd5d0d PCI: host-generic: Fix NULL pointer dereference on 32-bit CAM systems 159d162fe80bd xfs: don't livelock in scrub on a circular unlinked list a05a1b663464b xfs: hoist per-bucket unlinked list check to helper 8d678be8e58e9 xfs: rtsummary scrub should treat rtbitmap corruption errors as an xref error 00e2baf0b5ea9 xfs: add a xchk_ip_set_corrupt helper 755d0b7ee3563 serial: sc16is7xx: enable THRI before filling TX FIFO c5a12344a043e serial: sc16is7xx: use guards for simple mutex locks 450fe8f6f1f8c serial: sc16is7xx: rename EFR mutex with generic name 1f99e9ab748fc Linux 6.18.46 b7ce4b3bc1068 ALSA: hda/realtek: Enable headset mic on F+ FLAPTOP r 192f44513a03b firewire: ohci: initialize page array to use alloc_pages_bulk() correctly e5e6ce7009a6c drm/vmwgfx: Set surface-framebuffer GEM objects 7e351209dc2f4 erofs: fix EROFS_FS_ZIP_LZMA_DEFAULT_MAX_STREAMS on some UP platforms 67ac7e01c26be spi: virtio: mark device ready before registering the controller a7d172b27aa3e drm/log: Fix infinite loop when scale is too large for display a6325e2807dc2 drm/client: Remove drm_client_framebuffer_delete() 329731b3119f0 drm/client: Deprecate struct drm_client_buffer.gem 0763282e689e2 drm/client: Inline drm_client_buffer_addfb() and _rmfb() 60f1a2ecdf8b9 drm/client: Move dumb-buffer handling to drm_client_framebuffer_create() 841bc853a2b11 drm/client: Remove pitch from struct drm_client_buffer 16a2716910ecf drm/log: Fix out-of-bounds read on empty message length 948f346fe36e1 drm/xe/oa: Fix sync entry leak on OA config emit failure ed5470771c7ed firewire: ohci: fix NULL pointer dereference in ar_context_release 384d9f04b38f4 firewire: ohci: split page allocation from dma mapping adb3e7c26a51a net/sched: cls_bpf: reject dev-bound programs bound to a different device 1f493c44a2f04 accel/amdxdna: Skip unmapped range in aie2_populate_range() 72e4e3d7efc3b net: ethernet: ti: am65-cpsw-nuss: Fix port_id extraction from SRC TAG 6cf600b276a55 regmap: sdw-mbq: don't call an unset readable_reg callback c27eed546ae20 m68k: Define NR_CPUS to 1 31f26a95eeee9 net/sched: cls_u32: skip hash tables in u32_bind_class() abceabc4408fc net/sched: act_api: fix TOCTOU NULL deref on a->goto_chain 98c5914d6b7bd af_packet: Don't send zero-byte data in tpacket_snd(). 37c5ccaaacd48 regmap: sdw-mbq: Fix swap of timeout and retry times f51a540b14eec ASoC: xilinx: formatter_pcm: pass aud_drv_data to irq handlers 82d9269f01ebf net/tls: Fail tls_sw_splice_read() after a failed async decrypt cef4c5b9aca24 net: ngbe: fix NULL pointer dereference in non-MSI-X interrupt enabling 5ffaa5d7f56ab net: tap: fix wrong transport_header when sending VLAN-tagged frame f9297abbcaba7 net: packet: fix wrong transport_header when sending VLAN-tagged frame 0af3afd054e7b net: phy: realtek: fix EEE advertisement write on the internal PHY MMD path 17e3181d740d1 tcp: fix icsk_ack.ato bitfield overflow 73f8dd22b1e53 veth: fix queue index used to wake the peer txq in veth_poll 96fa90b74385b macvlan: inherit needed_headroom and needed_tailroom from lowerdev 5f33188457bbc ipvlan: inherit needed_headroom and needed_tailroom from phy_dev 1072f0f442820 eth: bnxt: keep the aRFS rmap updated when TPH is enabled 394f1b16c5d1b eth: bnxt: cancel IRQ notifier before freeing affinity mask a26a1be1b6541 netfilter: ipset: let destroy callbacks adjust ext mem size 29c011b3537d7 netfilter: ipset: fix list type element drift bug d9d3050a70efe netfilter: flowtable: publish GC-visible tuple last 4a923fe60939a netfilter: nf_tables_offload: suppress WARN_ON_ONCE for ENOMEM in abort path cb20da33839f2 netfilter: ipset: fix refcount race between list:set GC and swap 9e75e7da43740 ASoC: tas2781: fix clang build error for goto bypassing cleanup variable 24d0f33f5415f gpio: ml-ioh: share the register lock across channels 7a03413f31c19 perf: Reject exited events as group leaders 6c85d169eeecc riscv: ftrace: Fix ftrace_modify_call failure on kprobed functions a3a676495c641 ovpn: finish crypto callback cleanup before peer release a47a080d06ee9 ovpn: fix NULL dereference when killing missing key 99a18e1d979e0 crypto: tegra - fix rctx->cryptlen calculation in tegra_gcm_do_one_req() 3e4bf50c94511 crypto: ccm - Set rfc4309 maxauthsize from child d9ecc9787e118 arm64: tegra: Add EL2 virtual timer interrupt for Tegra194 a4e340971fe8c NTB: ntb_netdev: Preserve RX queue depth on allocation failure 08437c5156b0a net: ntb_netdev: Introduce per-queue context 2a7d8fc0fd50e ASoC: SOF: ipc4-topology: Refresh copier IPC payload before widget setup 8c685df5c3b26 drm/amd/pm: fix pptable use-after-free 2895aeb4327c9 drm/amd/pm: adjust the visibility of pp_table sysfs node 7755be923e325 mm/page_table_check: skip special zero mappings 4ae625d16eefb ring-buffer: Prevent resizing of persistent ring buffer 54fc67500ad1b ring-buffer: Store bpage pointers into subbuf_ids 27d7fcaf237df ring-buffer: Add helper functions for allocations 2ca6b43edf83f sched_ext: Take cgroup_lock() first in scx_cgroup_lock() f786e6652b931 sched_ext: Reorganize enable/disable path for multi-scheduler support 0907f81536f7d sched_ext: Update p->scx.disallow warning in scx_init_task() 4a7e941ca29a6 futex: Fix race in futex_pivot_pending() during private hash resize 870f8392b284e can: rcar_canfd: change the initializing flow for clocks and resets 45bf067681ad5 can: rcar_canfd: Extract rcar_canfd_global_{,de}init() e7a4ca927857a can: rcar_canfd: Use devm_clk_get_optional() for RAM clk f8c8c81707d17 can: rcar_canfd: Invert global vs. channel teardown 562d4befa9357 can: rcar_canfd: Invert reset assert order 867aed6a48487 binfmt_misc: don't leak the user namespace when the mount fails 4c8d7595a10a6 ata: libata-scsi: terminate deferred commands on time out db488d653d896 ASoC: tas2562: Validate values for volume writes 5f0a99ea72120 KVM: x86: Cancel delayed I/O APIC EOI handling before destroying vCPUs ef60eca789ee6 userfaultfd: wait on source PMD during UFFDIO_MOVE ea563ed2b10ae mm: replace pmd_to_swp_entry() with softleaf_from_pmd() 54a09573eb440 fs/proc/task_mmu: refactor pagemap_pmd_range() 549148d5aa4e3 btrfs: zoned: fix missing chunk metadata reservation 58ae8b7e8dc88 btrfs: remove fs_info argument from btrfs_zoned_activate_one_bg() d9e9753dfd43b ksmbd: validate minimum PDU size for transform requests 15a2fedb5dff3 smb/server: fix minimum SMB2 PDU size 23d34ce118857 smb/server: fix minimum SMB1 PDU size 5649004f71613 ksmbd: rename smb2_get_msg to smb_get_msg 29dbb4e29e1f1 ksmbd: Fix to handle removal of rfc1002 header from smb_hdr df3cf61adbe68 smb/server: rename include guard in smb_common.h 9d154c3c0f5d9 smb: move get_rfc1002_len() to common/smbglob.h 8ddc2eb0d2da9 net/sched: serialize qdisc_rtab_list against concurrent get/put 89df5d71f83f8 libceph: fix two unsafe bare decodes in decode_lockers() 590b07ceea138 libceph: bound pg_{temp,upmap,upmap_items} length to CEPH_PG_MAX_SIZE 89a50fb32d69a libceph: Amend checking to fix `make W=1` build breakage a3bc6b3e9ef3f ceph: fix hanging __ceph_get_caps() with stale mds_wanted 79d95b43ca090 ceph: avoid fs reclaim while using current->journal_info bb13785d54999 xfs: check v5 superblock features early 04228b8ba196f xfs: check xfarray iteration errors when committing unlinked inode lists 33b56c6c465aa xfs: don't ignore runtime errors in xrep_iunlink_reload_next 38a4dbe588bd0 xfs: don't swallow dquot recovery verification errors 0f27b22343b63 xfs: fix exchange-range reflink flag clearing issue with INO1_WRITTEN cd1f876d1bc2e xfs: avoid UAF on sc->tempip in xrep_tempfile_create e75150d494dcd xfs: don't return EFSCORRUPTED when scrubbing corrupt parent pointers b6baf0db357fb xfs: fix another iunlink infinite loop bug in online fsck fc7d8a5c5fcc7 xfs: fix allocated inodes that show up in the unlinked list c36d7f68f1c2e xfs: don't walk off the end of a null sc->sa.agi_bp in AGI repair 73ffd2620df3a xfs: don't zap the attr fork on repair when there are queued pptr updates 514a5d42d4188 xfs: fix ilock leak on error in xfs_dq_get_next_id 9680b1929d897 xfs: load next_agino from the correct xfarray in xrep_iunlink_relink_prev 8b52fa8fb3abb xfs: nlink scrub must take IOLOCK before determining ILOCK state 7d1d82c463e22 xfs: pass runtime errors from xrep_iunlink_mark_ondisk_rec up to callers ab4e133370763 xfs: set the prev pointer when reinserting an inode on the unlinked list ce2a7006ec5ed xfs: don't double-lock when deleting a self-referential directory 983588e756a30 xfs: only check mergeability of bnobt records 62c0b1435dfe2 xfs: zero i_nlink before repair puts inode on unlinked list a9114c6d4ec2f xfs: fix transaction block reservation in xrep_rtbitmap 90a49b8fcf821 xfs: check cowextsize in xrep_inode_cowextsize 069c0eadc8df0 xfs: clear zapped attr fork state when bmap repair finds no attr fork aeadf3fd2dc3c xfs: mark nonzero sb_gquotino as corrupt on metadir filesystems f8288214459ea xfs: bounds-check buffer log item's dirty bitmap 8a0ecae2ecda9 xfs: fix off-by-one in rtrefcount btree root level validation ec19cea4ef1ce xfs: propagate errors from xfs_rtginode_load 71aa45f7bfe46 drm/amdgpu: disallow multiple FENCE chunks in one submit 25ee120f3803a drm/amdgpu: Fix UVD decode image min size calculation 38914cb2c6afb drm/amdgpu: Fix UVD dpb min size calculation for H264 c76e5cca0675b drm/amdgpu: Fix UVD min buffer sizes 86a5cb0203221 drm/amdgpu: Implement insert_end for VCE 3 339deb76ee485 drm/amdgpu: Reject UVD message with dimensions above 4096 220aa2589d732 drm/amdgpu: validate GEM_CREATE domain combinations a082bd76c5f25 drm/amdgpu: check ASPM on the dGPU host link 916e8a1550be1 drm/amdgpu: fix nbif 6.3.1 l1 low power not functional e304c3e0d9ce2 drm/amdgpu: Reject UVD message with invalid number of h265 refs e3e6a631dcb1c drm/amd/display: fix BT.2020 YCbCr output CSC matrices for DCE cd99fa1cbaf5a drm/amd/display: fix BT.2020 YCbCr limited output CSC matrix 5045fb4c70bfd drm/amd/display: Fix NULL pointer dereference in amdgpu_dm_crtc_set_vblank() 95c1de6923b06 s390/zcrypt: Fix CPRB memory allocation in zcrypt misc code 7902be374cbfc s390/vfio_ccw: Implement a crw lock 3b224d3c50a38 s390/vfio_ccw: Calculate idal length based on idaw type b6aecea4b2b24 s390/vfio_ccw: Selectively expand io_mutex af1759d8e6e6d s390/vfio_ccw: Move cp cleanup out of not operational 4c2e1d359d7a2 s390/vfio_ccw: Fix out of bounds check on CCW array 08ef2a8211569 s390/vfio_ccw: Ensure first IDAW remains constant 649badf3a2fd8 s390/vfio_ccw: Ensure index for read/write regions are within range b7ae0f7993867 s390/vfio_ccw: Cancel existing workqueues 06f4d6e5a8af6 s390/vfio_ccw: Limit the number of channel program segments 32e3d364a7b82 s390/vfio_ccw: Free all memory if cp_init() fails 45aa38567c798 eth: bnxt: make sure we populate the qcfg defaults on old FW/HW 0382ed41c6645 eth: bnxt: always set the queue mgmt ops 31ef57083e785 drm/radeon: fix autosuspend cleanup during teardown 361114857813d drm/xe: Fix xe_device_probe() failure 7b90db6f024b8 drm/xe: Order ring writes before ring tail updates 198b4a89b9033 pmdomain: mediatek: Fix mt8183 hang on boot 8f7f7a6d5aed8 mmc: loongson2: Fix sg iteration in data reorder functions e5b527804a1ea drm/connector/hdmi: Fix out of bounds memory read b5060ff2f5460 mmc: atmel-mci: Fix use-after-free in atmci_remove due to race condition 78e59ab343372 pmdomains: mediatek: Avoid setting RTFF's CLK_DIS before NRESTORE 7c0d1767ce464 mmc: sdhci: make tuning_err a signed int 970b9c83a07c4 pmdomain: mediatek: fix remaining %pOF after of_node_put() 36d1b69c5c698 mmc: sdhci: unmap the bounce buffer before device release 0418b7ed2c1c6 mmc: omap_hsmmc: fix busy_timeout overflow in ns conversion on 32-bit b37e84280045b libceph: tolerate addrvecs with multiple entries of the same type 4490fad7992a7 ceph: fix MDS random selection readiness predicate 4f392fec07556 libceph: Avoid using invalid osd indices from primary_temp f3854719fba9f Input: sur40 - fix V4L error path cleanup 5c1c5227c93f1 Input: sur40 - fix input device registration ordering a88d688be8d7f openrisc: signal: do not restore privileged SR bits on sigreturn f634598e8fb7b ftrace: Fix off-by-one fentry site disable in ftrace_free_mem() f8fe843a96344 ftrace: Protect direct_functions in ftrace_find_rec_direct d1bba38574d09 libceph: fix multiple unsafe decodes in decode_locker() ebdecef6fd842 pmdomain: arm: Fix -EINVAL from scmi_pd_set_perf_state() on state 0 bc7934d0acd4f gpio: ml-ioh: use raw_spinlock_t for the register lock 9e678cffc11c2 gve: fix zero-length skb frag with header-split bd4e5a97edf8c selftests/ftrace: Convert ELF entry point to file offset in uprobe test 23e9f32c0c7d2 gpio: sloppy-logic-analyzer: fix use-after-free via debugfs trigger on unbind e9482feeed66d gve: fix NULL dereference due to missing ptp adjfine a134e4b8102c0 crypto: qce - fix error path in devm_qce_register_algs ef92c0ad0268e crypto: starfive - use scatterlist length before DMA mapping 38e7d5c1ade04 Input: hynitron_cstxxx - validate touch count and finger IDs 70f9aad394355 Input: synaptics-rmi4 - propagate F54 worker errors to V4L2 queue ff0849705d292 Input: synaptics-rmi4 - block s_input when F54 queue is busy 6b06aab79ff16 Input: synaptics-rmi4 - bound the F54 report size to the allocated buffer b28593a05afdd Input: synaptics-rmi4 - zero report size on F54 work error 828a8d1a9107a powerpc/pseries: papr-phy-attest - validate cmd.length, plug mem leak 2bdec532202b3 powerpc/pseries: lparcfg - fix kbuf[] underflow 8dbfd8e32a13e Input: byd - synchronize timer deletion before freeing private data a64a8b6b31cd6 Input: iforce - validate input packet lengths e7b8a107ecad5 Input: atkbd - skip deactivate for Xiaomi Book Pro 14's internal keyboard 8d622c58205ad Input: psxpad-spi - set driver data before use 83c265bfc084d Input: focaltech - fix array out-of-bounds in focaltech_process_rel_packet 9b184c8337c6e Input: synaptics-rmi4 - fix F55 transmitter electrode count typo 652e952850d9a powerpc/pseries: pci - logic bug 52a818c586ae2 Input: cs40l50-vibra - validate custom data from user space 455dbb5bdd814 Input: xpad - add support for ZENAIM LEVERLESS 6635d544bd6bc ASoC: SOF: topology: Use acpi mach from the machine driver bcc66461f574a drm/amdgpu: fix aperture iounmap skipped on device removal dffacbe8118fc drm/amdgpu: fix JPEG v4.0.5 queue reset failure in DPG mode e45356f6adae4 drm/amdgpu: fix JPEG v5.0.0 queue reset failure in DPG mode 4550b90bd2e6c drm/amdgpu: read TRUNCATE_COORD_MODE on gfx12 1474f3970d1af drm/amdgpu: reject oversized IBs with per-ring packet limits 25556a46ae6ec drm/panthor: skip zero-sized firmware sections 7ff87a01ae3a8 fbdev: core: Fix pointer desynchronization in fb_io_read() 2fe7a89b2b5b7 ASoC: codecs: lpass-wsa-macro: Fix enum kcontrol accesses cc61f0fa2c714 ASoC: cs35l41: sort the register default table 3298f13d1f126 ASoC: cs35l45: sort the register default table d7bd683b0d90c ASoC: cs4265: sort the register default table f2435a46dfa1a ASoC: SOF: ipc4-pcm: Continue the pipeline trigger in case of IPC timeout 8cba53b862e14 ASoC: SOF: sof-audio: Fix error path in sof_widget_setup_unlocked() a308364774794 s390/qeth: validate user buffer length in SNMP and ARP query ioctls 75e564b2ced1c mptcp: fastopen: only mark MPTFO subflows with SYN data 3f8e5eb0c4999 mptcp: pm: fix data race in add_addr timer callback 1fade1b2ac5b1 mptcp: options: reset DSS fields in case of unexpected size a04dcc784959e mptcp: avoid combining some incoming suboptions 0cb3846c26c11 selftests: mptcp: join: mark tests with data corruption as failed 473f1a5ab2abc mptcp: reclaim forward-allocated memory on RX path errors 9b46fba7528f5 selinux: reject a permission value exceeding the class permission count 841aea4d5a25e selinux: reject an unclaimed class value in security_get_classes() 1b4ff94ae7c58 selinux: do not cancel a policy conversion that never started acd5b09be98fd selinux: reject a class permission count below its inherited common 42a7107f99d86 selinux: require every boolean value to be defined 1a4c3ffe2a48b ipvs: separate destination availability state 9ff46bf75bfad ubi: fastmap: fix ubi->fm memory leak 075036cea14ae mtd: ubi: skip programming unused bits in ubi headers bb03b56d1d754 block: stop the timeout timer when releasing a never added disk e2c3337c2238e ALSA: hda/realtek: Add quirk for HP Dragonfly Folio G3 2-in-1 (103c:8a05) bf3be28f6721e Linux 6.18.45 1eb0dc458b6e8 netfilter: flowtable: ensure sufficient headroom in xmit path 99ec511f258e0 netfilter: always set route tuple out ifindex 9977321835c7a thunderbolt: Fix bandwidth group reservation indexing 40d2ffb74094c thunderbolt: Bound the DROM dual link port number before indexing sw->ports ca33df36aa014 sctp: clear new_transport when removing a peer 07daf4f975010 sctp: fix use-after-free of cached ASCONF chunk 2b3b5eec8b2c3 sctp: keep chunk->transport in step with the list it is queued on 3bd46d33e3fd5 scsi: scsi_debug: Negate wrapped memcmp() result a14e4ef1d90c3 bpf, sockmap: Fix sk_redir use-after-free in send verdict 3c6d4ffa0c6db fsverity: Fix silent truncation in bpf_get_fsverity_digest() 2a5cfcad1d56e fsverity: Fix bpf_get_fsverity_digest() dynptr assumptions 4917e3ebcab50 mm/filemap: __filemap_add_folio() restore index before retrying dd21c96a71e87 ima: Instantiate file_truncate and path_truncate hooks 102fb2dacf450 sched/psi: Create the psimon kthread outside of cgroup_mutex 8037c5b2b2a44 sched/psi: Shut down rtpoll_timer in psi_cgroup_free() 653e888a24c87 fscrypt: use the mount idmap for the owner check in fscrypt_ioctl_set_policy() 4eb15c465337b ip6_tunnel: clear skb2->cb[] in ip6ip6_err() 3b2231e358d26 ipv6: fix Route Information option length validation 7f740664aec1f mm/ptdump: always stabilise against page table freeing using init_mm 5b926fb04cb9e ring-buffer: Use current_context for safe per-CPU buffer swap 2e37f2bf11142 ring-buffer: Initialise reader page order in rb_allocate_cpu_buffer() 5fd91dd4a1434 ptp: ocp: Fix board ID over-read 8d34019d14136 Revert "thermal/drivers/hwmon: Cleanup coding style a bit" 5635211b44969 eventfs: Fix use-after-free in eventfs_remove_rec() 66bc868a33cf1 KVM: x86/mmu: WARN and clear role.invalid when creating a child shadow page 47976eaaf0a4e KVM: SVM: Serialize accesses to the owner and mirror list with separate lock 1ffacbadc1453 smb: client: Fix use-after-free in cifs_try_adding_channels() c3f2347a47754 tipc: read le->link under the node lock in tipc_node_link_down() 3fc5044796dd8 tls: don't leave a full plaintext sk_msg ring unpushed 68787940274ec tls: rx: restore msg_iter before TLS 1.3 optimistic retry f1e21108e3ddf vhost: reset the vring metadata cache on vring reconfiguration cdf745b7a777f veth: fix skb length accounting after XDP frag adjustment 38c7763fdc533 vsock/virtio: avoid refilling the RX queue after teardown bd43a7ec668be vsock/virtio: read virtqueues under worker locks 46bb297ad7768 vxlan: do not arm the ageing timer on a device that is down fab820f1691a9 xdp: reject clones that overrun skb_shared_info tailroom e708fc1566ebd x86/mce: Set up the polling timer before CMCI discovery 846b92e26c8ab x86/CPU: Add a tlbi= cmdline switch 69298af46f397 arm64: remove redundant concurrent ptdump UAF mitigation fe79571f40434 dibs: initialise dibs->lock in dibs_dev_alloc() a2e326c52c4bc Revert "drm/amdgpu: fix aperture mapping leak" 24e95a24f151c binfmt_misc: don't warn when the mount is completed from another user namespace be161fa31e3e9 ovl: don't warn when the mount is completed from another user namespace 92f00f1d4d204 net/sched: act_gact, act_police: range check the fallback control action b47bb899e04b5 net/sched: act_ct: fix sk_buff leak when the header checks reject a packet 782cc40b7ade4 net: atlantic: free RX pages of consumed but not refilled buffers b13202d401e1a net: atlantic: free stranded TX buffers on ring deinit 0424186d570aa netfilter: nf_conntrack: defer invalid log until after unlock c58d34fe8b7e4 netfilter: bridge: release template ct on non-IP path e9bfe12b1d04c net: devmem: prevent net-iov / page mixing 4bc522b33438f net/x25: fix use-after-free of the socket by its timers ece6426b61241 net/dibs: Correct freeing of dmb_clientid_arr 680fbd7942185 ipv6: prevent in6_dev_get() from resurrecting inet6_dev 0b7d54cedea5c net: smc: fix splice entry lifetime imbalance in smc_rx_splice b65c11bc62216 net: phy: mediatek: fix TX blink masks using the RX bits 105d04edbec83 mm/huge_memory: fix huge_zero_pfn race 152a00440dc6e tracing: Fix NULL pointer dereference in module event cache removal 62978cf634797 ring-buffer: Prevent subbuf order change when resizing is disabled bc9db0d879c65 fbdev: bitblit: bound-check glyph index in bit_cursor() ed49684e69f84 tracing: Fix race between update_event_fields and, event_define_fields a979a642402d0 perf/core: Fix group leader use-after-free after sibling detach 5884851a096d8 drm/v3d: Serialize the scheduler timeout handlers 7779249561d14 ALSA: us144mkii: re-anchor capture URBs on resubmission a6b79dff1cc1c ALSA: hda/tas2781: fix ACPI reference handling bb30e35c36ed0 ALSA: FCP: fix OOB write in fcp_meter_ctl_get() f75d6f61f0d9c ALSA: usx2y: bound the hwdep mmap fault offset d217d723c5e43 ALSA: usb: Fix UAF at delayed release of MIDI2 EPs 976da5475472e mm/damon: adjust isolated pages stat for DAMOS_MIGRATE_{HOT,COLD} e16b8d640ec99 samples/damon/mtier: error out for zero quota goal target values 460181e4bb47a mm/damon/ops-common: putback folios on invalid migrate nid 6dd7a06894d6d ring-buffer: Fix crash passing ERR_PTR to kthread_stop() 688c71bed6852 misc: fastrpc: fix memory leak in fastrpc_channel_ctx_free af6345159abcb misc: fastrpc: take fl->lock when moving mmaps on interrupted invoke 9bf22a7d950ce misc: fastrpc: Remove buffer from list prior to unmap operation c5a03c2cadd2f misc: fastrpc: fix channel ctx ref leak when session alloc fails cd02b93863159 misc: fastrpc: Fix initial memory allocation for Audio PD memory pool 8b3e4ed9c35d3 staging: rtl8723bs: validate monitor transmit frame lengths a28a4b0592e4a staging: rtl8723bs: fix missing shared-key auth challenge length check e5b7610008f4e staging: rtl8723bs: fix OOB read in WMM_param_handler() e167a38a8a8f5 staging: rtl8723bs: fix OOB read in rtw_get_wpa_ie() 5974cb66681ea serial: amba-pl011: synchronize DMA teardown 759ead98a39fb serial: amba-pl011: cancel RS485 hrtimers after freeing IRQ 2a0ee25f75cdb serial: amba-pl011: fix indefinite RS485 post-send delay 3ce24bc4d1153 serial: 8250_of: clear stuck empty-FIFO RX-timeout on LPC32xx ae05d9e50b6b9 serial: 8250_dma: Clear stale RX state on shutdown 1c31e2377f4c1 serial: qcom-geni: fix TX DMA buffer flush dd6946a70ddbd rust_binder: do not query current thread for all ioctls 9dbe1d0111893 nvmem: layouts: Add fixed-layout driver da59844f561d1 nvmem: apple-spmi-nvmem: wrap regmap calls to satisfy CFI 104c2e8b8e38b mei: pull kvfree out of spinlock 63996ffc594d1 ipv4: fix use-after-free in fib_nhc_update_mtu() a59edda6eda12 ipv4: Fix fib_nlmsg_size() for RTA_VIA nexthops 94166072975aa selftests/bpf: Adapt sockmap update error handling edee58a9c460a selftests/bpf: Ensure UDP sockets are bound dc0c462fa838c Bluetooth: btusb: Add TP-Link UB600 for Realtek 8761BUV 373d425f7638a Bluetooth: btrtl: fix RTL8761B/BU broken LE extended scan 8545f4ef9eae6 netfilter: nf_tables: avoid softlockup warnings in nft_chain_validate 7b8c53263f887 futex: Prevent robust futex exit race some more cf8a9672fc25c iommu/vt-d: Gather the unmapped range before freeing its page tables 643b410bdfa48 dt-bindings: crypto: qcom,ice: Fix missing power-domain and iface clk 8d817ef1aa4e9 KVM: s390: pci: Fix aisb calculation cf895cd72e404 blk-mq: reinsert cached request to the list 97e2d08de282e blk-mq: pop cached request if it is usable 59b07ccca4c05 Revert "drm/amd/display: Fix backlight max_brightness to match exported range" 5912cf1822fbe net: bridge: mrp: fix uninitialised bytes on the wire 47a119ec8a7e2 netfilter: ebt_nflog: pin the NFLOG backend a0e76de6a2f28 igc: fix netdev not re-attached after resume if interface is down e6cd416a899ed mac802154: fix netdev use-after-free in beacon worker 9f904dd3e4557 inet: frags: publish queues before arming timer dbb30dc943a93 net: remove CAP_SYS_RAWIO zero-padding in dev_validate_header 99ae2239069ed net: octeontx2-pf: Fix UB in shift operation a4b14a4df29d3 net/sched: reject overly deep qdisc hierarchies 23716dd9d8d46 net: openvswitch: reallocate update replies for mismatched IDs 5f30f9c302cea net: fix skb length accounting after generic XDP frag adjustment 2c7b5eb87b2b2 packet: synchronize pressure clearing with ring reconfiguration 971aa7d99242b net/packet: reset the MAC header on the packet-socket transmit path 27e068d1b35db packet: use consistent hard_header_len in TX_RING send path 5bb10753d428a packet: use consistent hard_header_len in non-ring send paths 75eec935444db ipvs: clear IPv4 options after rebasing tunnel ICMP errors 0f88fe0552bee ipvs: properly update the overload flag on dest edit 59b90c17bec5b ipvs: add totalconns for dest e7f34f29b3302 ipvs: stop estimator after disabled calc phase 27f3924061592 ima: fix out-of-bounds read in xattr_verify() c5bf8cd148cfe mm/vmalloc: acquire init_mm lock on huge vmap to avoid ptdump UAF bd3c4108a56de Input: evdev - fix information leak in evdev_pass_values() b664592e9ba8c vt: stabilize tty reference in kbd_keycode with tty_port_tty_get a1c31e026c93e vt: add permission check for KDSKBMETA ioctl 2c7496124e94c net: usb: ipheth: fix carrier_work UAF on disconnect 58733b1dd46bb net: usb: ax88179_178a: fix skb leak in ax88179_tx_fixup() d328fdc607fa1 usb: gadget: f_ncm: Use unsigned int for ndp_index 2dfefdd498ab4 usb: cdnsp: fix incorrect endian conversions for APB timeout register 6e4c09bea8e9c thunderbolt: icm: Preserve USB4 proxy data-valid bit 2f73a065791d2 usb: atm: cxacru: properly kill rcv_urb on error in cxacru_cm() ebfd1e82ab0a6 usb: misc: usbio: check ibuf_len against rxbuf_len in bulk msg 04b71290fb419 usb: quirks: Add ShanWan gamepad to quirk list 1740fd2aaa8fd usb: core: Add quirk for 255-bytes initial config read 0a235379825e1 ALSA: usb-audio: fix OOB write on Type II inbound URBs 4034ef247a9dd Input: evdev - sanitize event type index when fetching event masks 8b444b126cd8e net: tap: set skb->dev before parsing virtio net header in tap_get_user_xdp() fad7cecb5c2c0 net: fec: do not release NULL pages when RX buffer allocation fails c768fb2e43c8a hwmon: (ltc4282) Fix parsing adi,current-limit-sense-microvolt de58b90a4d141 hwmon: (ltc4282) Clamp negative current limits 124bd4b006199 hwmon: (ltc4282) Avoid overflow in maximum power calculation 678a76c8fd33d hwmon: (ads7828) Fix external VREF regulator handling 5ee1f603a64bd hwmon: (corsair-psu) fix possible out-of-bounds access on missing string termination 29fe74c9aa69d watchdog: at91sam9_wdt: prevent timer rearm during teardown 6d1d3ca6c8f4a tls: don't abort the connection on signal-interrupted sends 18d704bdd8093 sctp: clear control chunk transport if it is being removed 9f77c1ab38218 net/atm: fix slab-out-of-bounds read in vcc_setsockopt() fc3021284050e s390/ism: Fix UAF of sba and ieq during ism_dev_exit() 8fa684db8709b bnge: Fix resource leak in bnge_init_nic() error path a837deeaa37cc ata: pata_sl82c105: fix bridge revision use-after-free 4dd71cb0d23d4 net: thunderbolt: Tear down DMA paths before stopping the rings 78e5ebcd1c10e net/smc: fix TOCTOU race between smc_listen_out() and listener close c8f256dc84920 net: remove WARN_ON_ONCE() from sk_mc_loop() 363e048a9d0a6 net: prestera: validate firmware header length 02226af693627 net/ncsi: fix heap OOB read in NCSI_CMD_SEND_CMD payload length 12afa450a6a6c netfilter: nf_flow_table: drop existing skb dst before skb_dst_set_noref() 25d40cf9dab15 netfilter: flowtable: consolidate xmit path a66e869cf0c90 tcp: fix TFO max_qlen accounting across reuseport migration 6c24ec01fb768 sctp: fix addip_serial increment on ASCONF_ACK allocation failure 1e8f24b1e3fee bnxt_en: Fix PTP PPS setting bug aab3b5f4d8ec8 bnxt_en: Disable EOP for TPA on all chips to prevent data corruption 6a2e50924e57e bnxt_en: Refresh VNIC default ring on queue restart if needed f1a4e95e296b2 bnxt_en: Determine and store default RX ring in vnic structure 965c45be24e15 bnxt_en: Move RSS table fill outside __bnxt_hwrm_vnic_set_rss() 88664c48d7d1e net/mlx5e: fix BQL reset on SQ re-activation beb47092fe8fc bnge: use int for bnge_fix_rings_count() return value 4901b23b5ca7b net: stmmac: resume PHY before hardware setup when opening the interface 99b7bcee01589 selftests/ftrace: refactor eprobes test to fix argument checks a7a00ecf54243 hwmon: (pmbus/lm25066) Fix PMBus coefficient calculations 2e5ea8272ceae hwmon: (nzxt-smart2) Check return value of init_device() in probe 9fccf43f05317 drm/xe/uc: Apply RCS/CCS yield policy to SR-IOV VFs d6222af7274f0 net/sched: cls_api: Always acquire rtnl_lock when destroying locked classifiers a8139285c8925 net/openvswitch: check Ethernet header length in key_extract() a06e4611d4551 vhost-scsi: reject feature changes after endpoint 2417a498cf3fe vhost-scsi: Validate T10 PI scatterlist counts cd2f1d9fe8a50 net/sched: sch_cake: drop WARN_ON(1) for malformed packets in ACK filter 64d322c288577 udp: fix potential use-after-free in tunnel segmentation 5fd121971912d xsk: validate metadata when processing requests 1a1534cc3b419 xsk: move xsk_tx_metadata_request() to xdp_sock_drv.h af511afa1d297 xsk: validate launch-time metadata size 0ba2e1eb07a82 xsk: clear metadata pointer when no timestamp is requested 5ec4f525373bc xsk: pass TX metadata pointer by reference 642c6e73fce17 xsk: require at least 16 bytes of TX metadata b0b7202f751bb bnxt: fix memory leak in bnxt_queue_mem_alloc error cases ad9ffc61fafeb eth: bnxt: support qcfg provided rx page size cd5485a702efd eth: bnxt: store rx buffer size per queue 9c1406e2ecd2e net: pass queue rx page size from memory provider b3fecb888e94b net: add bare bone queue configs 96197286b0ac8 net: reduce indent of struct netdev_queue_mgmt_ops members 34debe05685d1 bnxt_en: Do not set EOP on RX AGG BDs on 5760X chips 5ba1a458c5e26 tcp: do not change rcv_ssthresh in tcp_measure_rcv_mss() 821f6416e6978 hwmon: (pmbus) Fix type confusion in notification logic 11720d869be1a hwmon: (pmbus_core) Use guard() for mutex protection cde8931a25392 vdpa/mlx5: Fix buffer length in create_direct_keys() a1c236b385d85 vhost/vdpa: reject overflowing PA map page counts on 32-bit cefcbbe20846a bpf: tcp: Fix use-after-free in bpf_iter_tcp_established_batch() 846ce792b6dd2 counter: microchip-tcb-capture: Fix DT channel validation 80094352bd40b net/mlx5: fw_tracer, return NULL on create error 7b02c6d2a3cd2 devlink: fix net namespace reference leak in reload 1efcc71140094 net: hisilicon: hix5hd2_gmac: remove redundant NAPI delete 0e7a8cf8895b0 net/sched: cls_route: fix fastmap use-after-free on filter 10cb31b2b74cb net/smc: fix qentry overwrite for CONFIRM_LINK and ADD_LINK_CONT in smc_llc_event_handler() d8a6f79935205 bpf: Propagate untrusted pointer state in commuted arithmetic c2da73a1f715f bpf: split check_reg_sane_offset() in two parts db6382ed3361b bpf: Preserve pointer state for commuted arithmetic 24a8f2c29aebb btrfs: fix memory leak in btrfs_do_encoded_write() 26e968526eb53 watchdog: bd96801_wdt: Fix timeout for enabled WDG b3ff48c4ea8b2 ipvs: return the csum validation for forward hook a69a4b3fff581 ipvs: avoid out-of-bounds write in ip_vs_nat_icmp 1e8a5467a7a7b netfilter: ipset: switch ext_size to atomic64_t 970e9494f44af pds_core: cancel pending PCI reset work on AER recovery ef8e37ac448d4 pds_core: keep the health thread stopped during reset ff9e7d5e3500b net/mlx5e: TC, Check if flow is PEER before acquiring devcom lock e506e704b7474 enic: fix tx_hang_reset use-after-free on device removal 2faf75a8a0650 bonding: alb: re-check primary_is_promisc under RTNL in bond_alb_monitor 35ddcc856b5b3 Revert "net: thunderbolt: Enable end-to-end flow control also in transmit" d512823059af8 net: hns3: fix speed configuration residue after driver reload 8701a643db231 drm/bridge: ps8640: propagate AUX transfer register errors d47212d866906 ovpn: fix incorrect use of rcu_access_pointer() 54dd83f24b913 ovpn: ensure TCP vars are initialized first f34949d63cbbe ovpn: disable IPv4 redirects on MP interfaces e774f7d8fc733 ovpn: hash floated peer by transport identity only 9a776388ef8d5 ovpn: zero-initialize sockaddr before learning a floated endpoint 61fb3cca40ff9 ovpn: ensure socket is owned by ovpn before deref sk_user_data 157164812a0c5 ovpn: rehash peer in by_transp_addr table on CMD_PEER_SET d20c181088984 ovpn: skip rehash for peers already removed from by_id 9e5e88fbfc87d ARM: dts: BCM5301X: fix PCIe controller 2 second interrupt 92b9d92a35a0f ovpn: add missing rtnl_link_ops->get_size callback d740dea9e2557 pinctrl: qcom: ipq806x: mark pci reset as a GPIO pin function 23c94a468efe3 pinctrl: qcom: ipq806x: mark gpio as a GPIO pin function 913d2295b772e selftests/sched_ext: Handle sleeping task affinity changes in numa test ce0212d230bd6 ARM: npcm: Fix OF node refcount leaks in SMP setup ccf6738adcafa xfs: handle NULL b_addr in xfs_buf_free d90599a42f6c5 arm64: dts: broadcom: bcm2712: Remove non-functional EL2 virtual timer d71dfffa512e7 NFS: Pin the 'struct nfs_server' during a FREE_STATEID call bd45b89d7346f arm64: dts: qcom: sdm850-lenovo-yoga-c630: lower PSCI cluster idle df9d22383d7c0 arm64: dts: qcom: purwa: Fix GPU IOMMU property 7a6e90afb696c arm64: dts: qcom: rename x1p42100 to purwa 1e2b408c1a769 arm64: dts: qcom: Rework X1-based Asus Zenbook A14's displays 387edbe4706b6 arm64: dts: qcom: rename x1e80100 to hamoa d089f32d34f82 drm/amd/display: Check for tg ops in dce110_set_avmute 8aba384bfc8aa drm/amd/display: Add AV mute wait frames to dce110_set_avmute 50359c42e0eba selftests/bpf: Fail unbound UDP on sockmap update 62fefb817bb3b sched/fair: Revert 6d71a9c61604 ("sched/fair: Fix EEVDF entity placement bug causing scheduling lag") 4043e196dc882 sched/fair: Separate se->vlag from se->vprot 9a3eef676cd8b mount: honour SB_NOUSER in the new mount API 79a45d44323b3 KVM: s390: pci: Fix resource leak on IRQ registration failure Signed-off-by: Bruce Ashfield Signed-off-by: Richard Purdie (cherry picked from commit 714654a1625f4f39a5c44c5ded9602d75b6cb6c8) Signed-off-by: Yoann Congal --- .../linux/linux-yocto-rt_6.18.bb | 6 ++--- .../linux/linux-yocto-tiny_6.18.bb | 6 ++--- meta/recipes-kernel/linux/linux-yocto_6.18.bb | 24 +++++++++---------- 3 files changed, 18 insertions(+), 18 deletions(-) diff --git a/meta/recipes-kernel/linux/linux-yocto-rt_6.18.bb b/meta/recipes-kernel/linux/linux-yocto-rt_6.18.bb index a7051c6e47c..a0c2abf1c5f 100644 --- a/meta/recipes-kernel/linux/linux-yocto-rt_6.18.bb +++ b/meta/recipes-kernel/linux/linux-yocto-rt_6.18.bb @@ -15,13 +15,13 @@ python () { raise bb.parse.SkipRecipe("Set PREFERRED_PROVIDER_virtual/kernel to linux-yocto-rt to enable it") } -SRCREV_machine ?= "f987d803014658f4fbccff70cfb9c42cc381f710" -SRCREV_meta ?= "7b09e5efab49e4bae0c69f7f2c65b4df00e9c565" +SRCREV_machine ?= "40cf3a2e9ae15c3d4b3a528d4de015263639cac3" +SRCREV_meta ?= "185549fc38a492dc3e431b32ac6774620ae6b468" SRC_URI = "git://git.yoctoproject.org/linux-yocto.git;branch=${KBRANCH};name=machine;protocol=https \ git://git.yoctoproject.org/yocto-kernel-cache;type=kmeta;name=meta;branch=yocto-6.18;destsuffix=${KMETA};protocol=https" -LINUX_VERSION ?= "6.18.44" +LINUX_VERSION ?= "6.18.48" LIC_FILES_CHKSUM = "file://COPYING;md5=6bc538ed5bd9a7fc9398086aedcd7e46" diff --git a/meta/recipes-kernel/linux/linux-yocto-tiny_6.18.bb b/meta/recipes-kernel/linux/linux-yocto-tiny_6.18.bb index 6f3c9b63e5a..0d4c98f2840 100644 --- a/meta/recipes-kernel/linux/linux-yocto-tiny_6.18.bb +++ b/meta/recipes-kernel/linux/linux-yocto-tiny_6.18.bb @@ -9,7 +9,7 @@ require recipes-kernel/linux/linux-yocto.inc include recipes-kernel/linux/cve-exclusion.inc include recipes-kernel/linux/cve-exclusion_6.18.inc -LINUX_VERSION ?= "6.18.44" +LINUX_VERSION ?= "6.18.48" LIC_FILES_CHKSUM = "file://COPYING;md5=6bc538ed5bd9a7fc9398086aedcd7e46" DEPENDS += "${@bb.utils.contains('ARCH', 'x86', 'elfutils-native', '', d)}" @@ -18,8 +18,8 @@ DEPENDS += "openssl-native util-linux-native" KMETA = "kernel-meta" KCONF_BSP_AUDIT_LEVEL = "2" -SRCREV_machine ?= "1b6ed62ce69bdf976f1b580c20f5271ed105958e" -SRCREV_meta ?= "7b09e5efab49e4bae0c69f7f2c65b4df00e9c565" +SRCREV_machine ?= "5b95344d2d0cfbe5889e3eb5a2ea3939dc3412f0" +SRCREV_meta ?= "185549fc38a492dc3e431b32ac6774620ae6b468" PV = "${LINUX_VERSION}+git" diff --git a/meta/recipes-kernel/linux/linux-yocto_6.18.bb b/meta/recipes-kernel/linux/linux-yocto_6.18.bb index 2a515e6bfe9..1a7a8659bf8 100644 --- a/meta/recipes-kernel/linux/linux-yocto_6.18.bb +++ b/meta/recipes-kernel/linux/linux-yocto_6.18.bb @@ -17,25 +17,25 @@ KBRANCH:qemux86-64 ?= "v6.18/standard/base" KBRANCH:qemuloongarch64 ?= "v6.18/standard/base" KBRANCH:qemumips64 ?= "v6.18/standard/mti-malta" -SRCREV_machine:qemuarm ?= "ca14f75460e4cdd77e7f4b18e356d772236fc4bf" -SRCREV_machine:qemuarm64 ?= "1b6ed62ce69bdf976f1b580c20f5271ed105958e" -SRCREV_machine:qemuloongarch64 ?= "1b6ed62ce69bdf976f1b580c20f5271ed105958e" +SRCREV_machine:qemuarm ?= "1cd95e881ac1b4f07906bd0e9482891e12f84a83" +SRCREV_machine:qemuarm64 ?= "5b95344d2d0cfbe5889e3eb5a2ea3939dc3412f0" +SRCREV_machine:qemuloongarch64 ?= "5b95344d2d0cfbe5889e3eb5a2ea3939dc3412f0" SRCREV_machine:qemumips ?= "62ea92a539f58803a222be98b81118403074206e" -SRCREV_machine:qemuppc ?= "1b6ed62ce69bdf976f1b580c20f5271ed105958e" -SRCREV_machine:qemuriscv64 ?= "1b6ed62ce69bdf976f1b580c20f5271ed105958e" -SRCREV_machine:qemuriscv32 ?= "1b6ed62ce69bdf976f1b580c20f5271ed105958e" -SRCREV_machine:qemux86 ?= "1b6ed62ce69bdf976f1b580c20f5271ed105958e" -SRCREV_machine:qemux86-64 ?= "1b6ed62ce69bdf976f1b580c20f5271ed105958e" +SRCREV_machine:qemuppc ?= "5b95344d2d0cfbe5889e3eb5a2ea3939dc3412f0" +SRCREV_machine:qemuriscv64 ?= "5b95344d2d0cfbe5889e3eb5a2ea3939dc3412f0" +SRCREV_machine:qemuriscv32 ?= "5b95344d2d0cfbe5889e3eb5a2ea3939dc3412f0" +SRCREV_machine:qemux86 ?= "5b95344d2d0cfbe5889e3eb5a2ea3939dc3412f0" +SRCREV_machine:qemux86-64 ?= "5b95344d2d0cfbe5889e3eb5a2ea3939dc3412f0" SRCREV_machine:qemumips64 ?= "9fb4ff0187c85426f21fd40d4c61b742800f65c4" -SRCREV_machine ?= "1b6ed62ce69bdf976f1b580c20f5271ed105958e" -SRCREV_meta ?= "7b09e5efab49e4bae0c69f7f2c65b4df00e9c565" +SRCREV_machine ?= "5b95344d2d0cfbe5889e3eb5a2ea3939dc3412f0" +SRCREV_meta ?= "185549fc38a492dc3e431b32ac6774620ae6b468" # set your preferred provider of linux-yocto to 'linux-yocto-upstream', and you'll # get the /base branch, which is pure upstream -stable, and the same # meta SRCREV as the linux-yocto-standard builds. Select your version using the # normal PREFERRED_VERSION settings. BBCLASSEXTEND = "devupstream:target" -SRCREV_machine:class-devupstream ?= "1efe5d048a391de3ead2804b2e7f86376c356cc5" +SRCREV_machine:class-devupstream ?= "5bbb9c9f8f808710e2123f2b30f0d61d7d698f52" PN:class-devupstream = "linux-yocto-upstream" KBRANCH:class-devupstream = "v6.18/base" @@ -43,7 +43,7 @@ SRC_URI = "git://git.yoctoproject.org/linux-yocto.git;name=machine;branch=${KBRA git://git.yoctoproject.org/yocto-kernel-cache;type=kmeta;name=meta;branch=yocto-6.18;destsuffix=${KMETA};protocol=https" LIC_FILES_CHKSUM = "file://COPYING;md5=6bc538ed5bd9a7fc9398086aedcd7e46" -LINUX_VERSION ?= "6.18.44" +LINUX_VERSION ?= "6.18.48" PV = "${LINUX_VERSION}+git" From patchwork Wed Sep 9 07:29:04 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 97660 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 409D8C79FAA for ; Wed, 9 Sep 2026 07:30:01 +0000 (UTC) Received: from mail-wm1-f46.google.com (mail-wm1-f46.google.com [209.85.128.46]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.6431.1788938997446498474 for ; Wed, 09 Sep 2026 00:29:57 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=R0OsdtKQ; spf=pass (domain: smile.fr, ip: 209.85.128.46, mailfrom: yoann.congal@smile.fr) Received: by mail-wm1-f46.google.com with SMTP id 5b1f17b1804b1-49556f97a9dso46080655e9.1 for ; Wed, 09 Sep 2026 00:29:57 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1788938996; x=1789543796; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=KxYbtkq4AnTA3YBcl5OKTYJ83o4iiNy9+ZHhyTPPmZ4=; b=R0OsdtKQE4o0zW1GDTvTs/34TjtAAcHb4dTk9QmD6bejVbmawd1k70fb3yElsTjQPT /jEgbl6Mk01VbHT+FfFqhF4RQlRJTqCS09CqpMfSpMJT78GdnK4SfmB7Ehl7niTz3yjE KTnCKRNh5aep0xApgZt/h70kI/lxnX1t/7vhc= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1788938996; x=1789543796; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=KxYbtkq4AnTA3YBcl5OKTYJ83o4iiNy9+ZHhyTPPmZ4=; b=oDovkTNSlb3IN0OnCK98X6izHAwHJa/6ChTnS+8z2mKtmIOp+mYH8ReYyu7AJwhtB1 g0oLK27ar3Pvc6XoBFc53sIiPQAWR3Sz+RAv5GdQB54XZzt1kEd17hqZG1tEN/xZkjC6 NnH+72mSCsdzDwVpFXxtmpS7oLdjkFGR+X4QfErI/Enj1yTe8eBbuzRgRR3XX9C1clQp gCKbdY/Mkg1vRS+GilUTryyus2zu+G5GIQXWGab4cDcpP1MvlHJ/hgJz0uHzp1bd134b KFyHWLRWzEf2CRAHkH3c1iRAP8TS6BjdyXFGtySTcZjxJ1XdPYmSodjonfBSb/Zc/f26 mExg== X-Gm-Message-State: AFuF++lWIDzxs5UPfKe41JTXk+momqEqQVmEUQqjA1UYsIfwORmSEwBY Nkk1meqK/etu1qQikgjVzVrDQycGuwV9/OvPgDFmDYwkcKj40MOAkRVCcfaYZOhxcnJNU4L2a5J uS3jMR0s= X-Gm-Gg: AYBFou2KFoX2QZWzKFLXUQ0hUg0JPuTu9Qo1vRORvmAUanjK9c1erS1mdx5XuSHmNJ9 5neg034fIByRDLLPuTWCudzdLPAEDcgNPptqpIJM7ITXONWuZse9LkylydxsgAjuqUIB9/TLkz4 FIYOm5d7E1Alah1Qflp8A3Ln0zunjl9yGxXAUiPkNleFA/DjX5Z/jmdGrK6nFeAlCtbFMgHqkrp RcggNDQujNGJitwxHFoWFhy/3SR9hM6x/g0y0659+TxQXmP6KdZaL5L+TDW1XLHRv9JeEgt3xPq m3aGn1Uu73Hh50Umg04bXvH4Iu9RxWE/D2o48ME7V/KXXMOv9Hg1HZW7OVh1BpMsg+PQNAeEFAt s7gph8H1HaJrCTqWzr4JlvD1tiFasDziIy6ppbLlf25eI7ohYR8adkNqubiUhs5f7XZTanzivQh QcBTwif1nFGBurMZ4Y9kbpFwj45t4Izk9oIeJFkwuSsd9s3ngjVBTseePlQ7FKd9zB7bLsw/YhF ZPD3hD8mHMJoN7FU1pqspp5KfbyVBaL7atyEjjDMD2RlaT4nj6nrADvXTTXfp7zXMbDMg5tAice TJ3wJwzQbw== X-Received: by 2002:a05:600c:138d:b0:49d:243a:e4f9 with SMTP id 5b1f17b1804b1-49d243ae71fmr8930405e9.10.1788938995504; Wed, 09 Sep 2026 00:29:55 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-4858ac2b4cdsm40624310f8f.16.2026.09.09.00.29.55 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 09 Sep 2026 00:29:55 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][wrynose 05/38] testimage: handle bootlog variants on failed qemu tests Date: Wed, 9 Sep 2026 09:29:04 +0200 Message-ID: X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Wed, 09 Sep 2026 07:30:01 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/245413 From: Peter Tatrai The failure summary path assumed the unsuffixed bootlog file always exists and unconditionally opened it. This is not guaranteed when SERIAL_CONSOLES has fewer than two entries (including empty), where qemurunner can produce only bootlog suffix variants (for example .2 or .stdout). On test failures, collect snippets from all existing files matching bootlog and bootlog.* and prefix each snippet with its filename. Also skip creating a symlink for a missing bootlog path. This prevents FileNotFoundError from masking the original test failure and improves diagnostics across qemu serial configurations. (From OE-Core rev: 7a6596925cb0eb8dd48a0362a51875cdd60152bc) Signed-off-by: Peter Tatrai Signed-off-by: Richard Purdie Signed-off-by: Yoann Congal --- meta/classes-recipe/testimage.bbclass | 27 +++++++++++++++++++++++---- 1 file changed, 23 insertions(+), 4 deletions(-) diff --git a/meta/classes-recipe/testimage.bbclass b/meta/classes-recipe/testimage.bbclass index 9902b8a5682..0f34d551e99 100644 --- a/meta/classes-recipe/testimage.bbclass +++ b/meta/classes-recipe/testimage.bbclass @@ -186,6 +186,7 @@ def get_testimage_boot_patterns(d): def testimage_main(d): import os + import glob import json import signal import logging @@ -409,15 +410,33 @@ def testimage_main(d): # Copy additional logs to tmp/log/oeqa so it's easier to find them targetdir = os.path.join(get_json_result_dir(d), d.getVar("PN")) os.makedirs(targetdir, exist_ok=True) - os.symlink(bootlog, os.path.join(targetdir, os.path.basename(bootlog))) + if os.path.exists(bootlog): + os.symlink(bootlog, os.path.join(targetdir, os.path.basename(bootlog))) + else: + bb.note("testimage: boot log not found at %s" % bootlog) + os.symlink(d.getVar("BB_LOGFILE"), os.path.join(targetdir, os.path.basename(d.getVar("BB_LOGFILE") + "." + d.getVar('DATETIME')))) if not results or not complete: bb.error('%s - FAILED - tests were interrupted during execution, check the logs in %s' % (pn, d.getVar("LOG_DIR")), forcelog=True) if results and not results.wasSuccessful(): - with open(bootlog, 'r') as bootlogfile: - bootlines = "".join(bootlogfile.readlines()[-20:]) - bb.plain('%s - FAILED - Last lines of QEMU boot log:\n%s' % (pn, bootlines)) + bootlog_files = [] + for candidate in [bootlog] + sorted(glob.glob(bootlog + ".*")): + if os.path.exists(candidate) and candidate not in bootlog_files: + bootlog_files.append(candidate) + + if bootlog_files: + snippets = [] + for bootlog_file in bootlog_files: + try: + with open(bootlog_file, 'r') as bootlogfile: + bootlines = "".join(bootlogfile.readlines()[-20:]) + except OSError as err: + bootlines = "\n" % (bootlog_file, err) + snippets.append("--- %s ---\n%s" % (os.path.basename(bootlog_file), bootlines)) + bb.plain('%s - FAILED - Last lines of QEMU boot logs:\n%s' % (pn, "\n".join(snippets))) + else: + bb.plain('%s - FAILED - QEMU boot logs not available at %s or %s.*' % (pn, bootlog, bootlog)) bb.error('%s - FAILED - also check the logs in %s' % (pn, d.getVar("LOG_DIR")), forcelog=True) def get_runtime_paths(d): From patchwork Wed Sep 9 07:29:05 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 97658 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 777FDC79FB5 for ; Wed, 9 Sep 2026 07:29:59 +0000 (UTC) Received: from mail-wr1-f42.google.com (mail-wr1-f42.google.com [209.85.221.42]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.6310.1788938997869206717 for ; Wed, 09 Sep 2026 00:29:58 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=I0T7rgbU; spf=pass (domain: smile.fr, ip: 209.85.221.42, mailfrom: yoann.congal@smile.fr) Received: by mail-wr1-f42.google.com with SMTP id ffacd0b85a97d-482ea739de2so3777704f8f.0 for ; Wed, 09 Sep 2026 00:29:57 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1788938996; x=1789543796; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=D5nVIsp0yZDdbNKYrsbtkKMh0YPln7Jf4OMKnxCwP9A=; b=I0T7rgbUbDq5ZUq6t/rGXg9Ij7Su8oHCFIiZ47XBQthxG8v7IPHyJxQR5owiuL5zyb HU/g54KP38xxCMazZgF8f4pBUJME6HpBV+VuwAQ/aCkmt4OmOPtXhEUPAGznrtAKSH0V rHkcvlGggnhgIPrcyx04n+PJTtkfb5OjunB18= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1788938996; x=1789543796; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=D5nVIsp0yZDdbNKYrsbtkKMh0YPln7Jf4OMKnxCwP9A=; b=JiPnjXUF/gtJz9/1zIA/xAqoJtCDU30Br8MhLS4dUpyfp0XAtB/ljiDfmXLE1xKJrT xXeiLYeK091kfR/jTIt8Dss7+4vxTToZ1RdXZ2rExB76s3NlSKFLwL7k6lDKDxAH2G8+ PQ1tV/JO6FSE7Y1FAV1bAytjPXEoBkb3NmNr0MJqXZNWs7nrgxs5oERBD8YTprzgQNam P4CQNCkKvCHUP4YkA45+76FWl2OQe2j+r6Juo4PV8kE1IeooFoSswzysQJ6EHXuES2gg EjMoL9BHjJlb/YqH5sWwnzWMsmiX2KIl3TYuD8ZFPHwEkzyEnE4bvHRgXdMge55ZeGJd RDJw== X-Gm-Message-State: AFuF++kGgH4BiUVq7zt8odGXQh9kwKHyurBO2w011Su3Dl2Qork8DL8g L/VJzlW6KitjHjo83WIibHmFmTAkdPrrHjs+C9Vogv1idfjrDMF9LndB/AFV+dtCAiX5qpb4B8X HkuOeLDY= X-Gm-Gg: AYBFou1TBgM4Uhuxff6IhOr1bv1BjaoHMVZkVi/JQb88OnS4q+oHu0IpN9sq3eR5REQ FTLoTt9SNS5NjGwFOqtPRGJdP+uk8BcfQNnCkjI+7HNcO03gZ/YNLuwj+AkJqtR9CQVb4k5Nvgk osqhrpy3930U+ScxuH1QvHz7idz+kibts1lriqkD4UVWuOxexA3fiT/golpeolvg3cR7zne9CE7 yrD7c3sHXzKmphHHokm/AaFxSfpd4Kn97ntJeeUJPrahTcVrNk4cejssSdwKlJNMuOhLTpc+18f yyHBI4I/gAD6vuT3yPTHu/eirfyNHFnzYmTncFpmnuU8skN8pynMEd2T62OWXc4tTxomYIGxpHL ecpi5kn0gXRhvsf7Pxu1G0qn0fZ4bUNrs+9sgC3xir13L3ushIZQea9gSAV50+CZeTBY0gDWEUU BeWmISNM3Hb8h9+4M2UIhkEStenjvtYYmbrraHhLQXXtOV57ad5RLuaUg/+1OtjuBCLfqI3Hwje 1k+aL8TBLocx0AIgmt1S4w9mdjuw2Iy1B8Mr5GTWpd+rnc8hSiTyQdpKw1JD1jpbeDXxeK0OTAs ZL20fgpLMQ== X-Received: by 2002:a05:6000:2c11:b0:485:8c16:a349 with SMTP id ffacd0b85a97d-4858c16a7e9mr33190548f8f.33.1788938996019; Wed, 09 Sep 2026 00:29:56 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-4858ac2b4cdsm40624310f8f.16.2026.09.09.00.29.55 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 09 Sep 2026 00:29:55 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][wrynose 06/38] openssl: upgrade 3.5.7 -> 3.5.8 Date: Wed, 9 Sep 2026 09:29:05 +0200 Message-ID: <097d3e6f4c5835e8baaf6daf125b3ea212d5acce.1788938909.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Wed, 09 Sep 2026 07:29:59 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/245415 From: Peter Marko Release information [1]: OpenSSL 3.5.8 is a security patch release. The most severe CVE fixed in this release is Moderate. This release incorporates the following bug fixes and mitigations: * Fixed QUIC server being able to trigger double free when processing INITIAL packet. (CVE-2026-18798) * Fixed heap buffer overflow in CMS key unwrapping. (CVE-2026-63072) * Fixed invalid pointer dereference in CMP server via crafted protectionAlg. (CVE-2026-63076) * Fixed unbounded memory growth in QUIC server incoming channel queue. (CVE-2026-14456) * Fixed RPK server signature algorithm selection being able to dereference a missing certificate. (CVE-2026-14457) * Fixed excessive memory use buffering DTLS records for a future epoch. (CVE-2026-54874) * Fixed untrusted Sender DN being used as a format string in CMP response validation. (CVE-2026-63073) * Fixed CMP indefinite cache growth of extraCerts. (CVE-2026-63074) * Fixed QUIC ACK-only packet retention being able to cause memory exhaustion. (CVE-2026-63075) * Fixed possibility of AEAD forgeries with empty ciphertext when using EVP_Cipher(). (CVE-2026-75803) * Fixed checking of authentication tags for empty ciphertexts for AEAD ciphers in CCM cipher mode. [1] https://github.com/openssl/openssl/blob/openssl-3.5/NEWS.md#major-changes-between-openssl-357-and-openssl-358-25-aug-2026 Signed-off-by: Peter Marko Signed-off-by: Mathieu Dubois-Briand Signed-off-by: Richard Purdie (cherry picked from commit db81c1a42a0f552d9a8ec124f004ae2063d58c33) Signed-off-by: Yoann Congal --- .../openssl/{openssl_3.5.7.bb => openssl_3.5.8.bb} | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) rename meta/recipes-connectivity/openssl/{openssl_3.5.7.bb => openssl_3.5.8.bb} (99%) diff --git a/meta/recipes-connectivity/openssl/openssl_3.5.7.bb b/meta/recipes-connectivity/openssl/openssl_3.5.8.bb similarity index 99% rename from meta/recipes-connectivity/openssl/openssl_3.5.7.bb rename to meta/recipes-connectivity/openssl/openssl_3.5.8.bb index 212879dfa35..cc148f07c7d 100644 --- a/meta/recipes-connectivity/openssl/openssl_3.5.7.bb +++ b/meta/recipes-connectivity/openssl/openssl_3.5.8.bb @@ -19,7 +19,7 @@ SRC_URI:append:class-nativesdk = " \ file://environment.d-openssl.sh \ " -SRC_URI[sha256sum] = "a8c0d28a529ca480f9f36cf5792e2cd21984552a3c8e4aa11a24aa31aeac98e8" +SRC_URI[sha256sum] = "a8f84a39918ec6415ce765d9b429d313ba97b8143169c172e734b9514464f5b2" inherit lib_package multilib_header multilib_script ptest perlnative manpages MULTILIB_SCRIPTS = "${PN}-bin:${bindir}/c_rehash" From patchwork Wed Sep 9 07:29:06 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 8bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 97666 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id BC764C79FB5 for ; Wed, 9 Sep 2026 07:30:01 +0000 (UTC) Received: from mail-wr1-f46.google.com (mail-wr1-f46.google.com [209.85.221.46]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.6314.1788938998867069874 for ; Wed, 09 Sep 2026 00:29:59 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=qZCVMFxC; spf=pass (domain: smile.fr, ip: 209.85.221.46, mailfrom: yoann.congal@smile.fr) Received: by mail-wr1-f46.google.com with SMTP id ffacd0b85a97d-4859245e493so2969471f8f.1 for ; Wed, 09 Sep 2026 00:29:58 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1788938997; x=1789543797; darn=lists.openembedded.org; h=content-transfer-encoding:content-type:mime-version:references :in-reply-to:message-id:date:subject:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=vLm0orLkmNPhqEXzNv0DIpYCo7/Uo7ZArtKONlPXf9Q=; b=qZCVMFxCIlIOluKfFeeuTZWTqTgChbr/rFGhgvgslxMhclIFxu+268GEACeS3SIDue zqmFYLSSu87zPRuuM14CEiWzoO0HQdxytjAWq0fg2Y8CivWbJNji5iQUwbzF4rt7vT13 iyaW0HGkLwu4gcZHuOjmJEGtovPZIlmkxVe1o= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1788938997; x=1789543797; h=content-transfer-encoding:content-type:mime-version:references :in-reply-to:message-id:date:subject:to:from:x-gm-gg :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to :content-type; bh=vLm0orLkmNPhqEXzNv0DIpYCo7/Uo7ZArtKONlPXf9Q=; b=AJhTkkRw2z5bu8NcpwF3twZh8cr2IfZexmRFezF44gg2zL2acLeVJHkrOXH1soL6LQ zymV5C/7KzmWKrFm12mFDiS3oRxEP9OczOnV1aL+Vic5sghu3wMveeBU1+qFbIDrXDYc 4asVK4uNH2eLR4vi7F+i50ILNATgRnS0niXujZ2h3bDLhTR22QyGa6K4wBEh3VsO8xXz Y9Yu8dKYrjLV1ueshpGUzXckNcfBqj3PZFLZdZBPFA+poUSTJKF2DCAzRlgSxl7pDwkI WgXsARXvyvpH+UY3B7F0DHLGxE/Qutgh5uFvjnbQJFHkHdVDXqycJcxnmfWfK1p1E8Pv cXdA== X-Gm-Message-State: AFuF++m8e1clISjmowzs+OUGW4wfN/2cKFEp3XVs1JLe6hCiRgKA4em1 w4tDF3Qp7NOeLIrsTW5StsWXBVHcZOWXbMDp0XwYwZ4Z0wNRIEVfK4NHmD90O8kTSPx1QiWAApZ hbS0Gmls= X-Gm-Gg: AYBFou3f2lbt3F1MprQzRzdysriyt0RFjtfzwJtVRdpqaTKbw7n5ycNrx7890K57hm7 SByO7I/J2EG0Ig4e0Ux1obo+MBnaOoHrAkvfw4N3Af4b3Q3OsLUK3a/jflBiC/1fgj9sOCka7/F Qr6OlOdqN+b043h5rATZ/0z80TQ5nrHwH6U3M8UJDuBKO8kahuGsjkz7K15qiHV9znmIV0EVLPy ZkxcKf9VGdk/UOtB116W+twBKUhp/c794QVxClv41Wl3avfRnWJ+glF5BckDaC3ll1kr+3DsRc4 n3BpVTz6ytUys0FLDR3PyKe+tceFz6XJ+2b+mQXxD56OqPdVTwmw/ofbcz90trNRpk1pLlIhRFd ksdcY7MXs2+RtL6HL/fUaHopunR4r7tpJxJrTLoJZuKLH1jftDHl2F2fceDlC4Oqe0SWI5KuRyE hNec6sReQ6EF08lDuApfUCIJ+tZUGAVUsigqUbOgZwvtazW0hBgggE12i3bUu2RyM1sxGbU4Dz0 gTEH1RKAfUT0jt6C0gmDnUjTfLg+nsgWTNXgMpNaMpZvwBV2gl/jcpkO2yi4SF/KqvKLz5bus0= X-Received: by 2002:a5d:5f09:0:b0:485:8a47:5b81 with SMTP id ffacd0b85a97d-4858a475c55mr28865116f8f.30.1788938996550; Wed, 09 Sep 2026 00:29:56 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-4858ac2b4cdsm40624310f8f.16.2026.09.09.00.29.56 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 09 Sep 2026 00:29:56 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][wrynose 07/38] apr-util: upgrade 1.6.3 -> 1.6.5 Date: Wed, 9 Sep 2026 09:29:06 +0200 Message-ID: <112245f1bbf764ef856bcdf7420e4d72ab95ba1c.1788938909.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Wed, 09 Sep 2026 07:30:01 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/245416 From: Peter Marko Removed included patches and refresh remaining one. Release Notes: [1] Changes with APR-util 1.6.5 *) Fix oracle DBD compilation errors introduced in 1.6.4. PR 70170. Changes with APR-util 1.6.4 *) SECURITY: CVE-2026-34502: Heap buffer overflow in APR memcached client (cve.mitre.org) Heap-based Buffer Overflow vulnerability in Apache Portable Runtime Utility memcached client This issue affects Apache Portable Runtime Utility: from 1.3.0 through 1.6.3. Credits: Elhanan Haenel *) SECURITY: CVE-2026-34501: Apache Portable Runtime Utility: Heap buffer overflow in APR redis client (cve.mitre.org) Heap-based Buffer Overflow vulnerability in Apache Portable Runtime Utility redis client. This issue affects Apache Portable Runtime Utility: from 1.6.0 through 1.6.3. Users are recommended to upgrade to version 1.6.4, which fixes the issue. Credits: Elhanan Haenel *) SECURITY: CVE-2026-34191: Apache Portable Runtime Utility: SQL Injection in apr_dbd_oracle (cve.mitre.org) Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Portable Runtime Utility via apr_dbd_oracle provider. This issue affects Apache Portable Runtime Utility: from 1.6.0 through 1.6.3. Users are recommended to upgrade to version 1.6.4, which fixes the issue. Credits: Elhanan Haenel *) SECURITY: CVE-2026-32327: Apache Portable Runtime Utility: apr-util XML stack recursion crash (cve.mitre.org) A bug in APR-util version 1.6.3 (and earlier) allows a stack recursion attack against any library consumer which parses XML from untrusted sources and uses the apr_xml_quote_elem() function. Users are recommended to upgrade to version 1.6.4, which fixes this issue. Credits: Younghyo Cho @ CISLab, SeoulTech *) SECURITY: CVE-2025-49506: apr_password_validate() vulnerable to timing attack (cve.mitre.org) APR-util versions 1.6.3 (and earlier) function apr_password_validate() was not constant-time with regards to hashes or passwords comparisons, potentially leaking their content via a side channel timing attack particularly on platforms without crypt() such as  Windows, BeOS, NetWare, or Android. Users are recommended to upgrade to version 1.6.4, which fixes this issue. Credits: Michael Rowley *) apr_brigade: Don't split the final LF in apr_brigade_split_line() to avoid producing an empty bucket. PR 64273 [Barnim Dzwillo , Joe Orton] *) apr_brigade: Metadata buckets are now ignored in apr_brigade_split_line, apr_brigade_flatten and apr_brigade_to_iovec, fixing possible undefined behaviour. PR 68278 [Ben Kallus , Joe Orton] *) apr_crypto_openssl: Compatibility with OpenSSL 3. [Yann Ylavic] *) apr_crypto_openssl: use OPENSSL_init_crypto() to initialise OpenSSL on versions 1.1+. [Graham Leggett] *) apr_memcache: Fix name lookup to allow IPv6 as well as IPv4. [Lubos Uhliarik ] *) configure: Fix Berkeley DB detection with compilers enforcing strict C99 compliance. PR 66396. [Florian Weimer ] [1] https://github.com/apache/apr-util/blob/1.6.5/CHANGES Signed-off-by: Peter Marko Signed-off-by: Richard Purdie (cherry picked from commit bb8e0e12c54c452ffb17ce600972edfa9455f459) Signed-off-by: Hetvi Thakar Signed-off-by: Yoann Congal --- ...le-function-prototype-warning-with-c.patch | 130 ------------------ ...ion-Check-if-transform-is-supported-.patch | 37 ----- .../apr/apr-util/configfix.patch | 4 +- .../{apr-util_1.6.3.bb => apr-util_1.6.5.bb} | 4 +- 4 files changed, 3 insertions(+), 172 deletions(-) delete mode 100644 meta/recipes-support/apr/apr-util/0001-sdbm-Fix-old-style-function-prototype-warning-with-c.patch delete mode 100644 meta/recipes-support/apr/apr-util/0001-test_transformation-Check-if-transform-is-supported-.patch rename meta/recipes-support/apr/{apr-util_1.6.3.bb => apr-util_1.6.5.bb} (93%) diff --git a/meta/recipes-support/apr/apr-util/0001-sdbm-Fix-old-style-function-prototype-warning-with-c.patch b/meta/recipes-support/apr/apr-util/0001-sdbm-Fix-old-style-function-prototype-warning-with-c.patch deleted file mode 100644 index e523859927a..00000000000 --- a/meta/recipes-support/apr/apr-util/0001-sdbm-Fix-old-style-function-prototype-warning-with-c.patch +++ /dev/null @@ -1,130 +0,0 @@ -From 05afaf207eaff4c175198abd129ed1acde220df3 Mon Sep 17 00:00:00 2001 -From: Yann Ylavic -Date: Thu, 14 Mar 2024 15:52:25 +0000 -Subject: [PATCH] sdbm: Fix old style function prototype warning with clang - -This fixes the following warning with clang - -../dbm/sdbm/sdbm_pair.c:63:1: warning: a function definition without a prototype is -deprecated in all versions of C and is not supported in C2x [-Wdeprecated-non-prototype] - 63 | fitpair(pag, need) - | ^ - -Upstream-Status: Backport [https://github.com/apache/apr-util/commit/073368a46fbe92995927258ae2fc97d3920872f2] -Signed-off-by: Biswapriyo Nath -Submitted by: Biswapriyo Nath -Github: closes #47 - -Merges r1912679 from ^/apr/apr/trunk - -git-svn-id: https://svn.apache.org/repos/asf/apr/apr-util/branches/1.7.x@1916307 13f79535-47bb-0310-9956-ffa450edef68 -Signed-off-by: Khem Raj ---- - dbm/sdbm/sdbm_pair.c | 39 +++++++++------------------------------ - 1 file changed, 9 insertions(+), 30 deletions(-) - -diff --git a/dbm/sdbm/sdbm_pair.c b/dbm/sdbm/sdbm_pair.c -index 50d7965..6ecaff6 100644 ---- a/dbm/sdbm/sdbm_pair.c -+++ b/dbm/sdbm/sdbm_pair.c -@@ -60,9 +60,7 @@ static int seepair(char *, int, char *, int); - */ - - int --fitpair(pag, need) --char *pag; --int need; -+fitpair(char *pag, int need) - { - register int n; - register int off; -@@ -79,10 +77,7 @@ int need; - } - - void --putpair(pag, key, val) --char *pag; --apr_sdbm_datum_t key; --apr_sdbm_datum_t val; -+putpair(char *pag, apr_sdbm_datum_t key, apr_sdbm_datum_t val) - { - register int n; - register int off; -@@ -108,9 +103,7 @@ apr_sdbm_datum_t val; - } - - apr_sdbm_datum_t --getpair(pag, key) --char *pag; --apr_sdbm_datum_t key; -+getpair(char *pag, apr_sdbm_datum_t key) - { - register int i; - register int n; -@@ -129,18 +122,14 @@ apr_sdbm_datum_t key; - } - - int --duppair(pag, key) --char *pag; --apr_sdbm_datum_t key; -+duppair(char *pag, apr_sdbm_datum_t key) - { - register short *ino = (short *) pag; - return ino[0] > 0 && seepair(pag, ino[0], key.dptr, key.dsize) > 0; - } - - apr_sdbm_datum_t --getnkey(pag, num) --char *pag; --int num; -+getnkey(char *pag, int num) - { - apr_sdbm_datum_t key; - register int off; -@@ -159,9 +148,7 @@ int num; - } - - int --delpair(pag, key) --char *pag; --apr_sdbm_datum_t key; -+delpair(char *pag, apr_sdbm_datum_t key) - { - register int n; - register int i; -@@ -231,11 +218,7 @@ apr_sdbm_datum_t key; - * return 0 if not found. - */ - static int --seepair(pag, n, key, siz) --char *pag; --register int n; --register char *key; --register int siz; -+seepair(char *pag, register int n, register char *key, register int siz) - { - register int i; - register int off = PBLKSIZ; -@@ -251,10 +234,7 @@ register int siz; - } - - void --splpage(pag, new, sbit) --char *pag; --char *new; --long sbit; -+splpage(char *pag, char *new, long sbit) - { - apr_sdbm_datum_t key; - apr_sdbm_datum_t val; -@@ -295,8 +275,7 @@ long sbit; - * this could be made more rigorous. - */ - int --chkpage(pag) --char *pag; -+chkpage(char *pag) - { - register int n; - register int off; diff --git a/meta/recipes-support/apr/apr-util/0001-test_transformation-Check-if-transform-is-supported-.patch b/meta/recipes-support/apr/apr-util/0001-test_transformation-Check-if-transform-is-supported-.patch deleted file mode 100644 index 261b78736f6..00000000000 --- a/meta/recipes-support/apr/apr-util/0001-test_transformation-Check-if-transform-is-supported-.patch +++ /dev/null @@ -1,37 +0,0 @@ -From 3a97f58cfb40fc1911bbfd067e8457a472613d75 Mon Sep 17 00:00:00 2001 -From: Khem Raj -Date: Tue, 18 Apr 2023 22:58:00 -0700 -Subject: [PATCH] test_transformation: Check if transform is supported before - using it - -This helps in excluding these tests on systems where these are not -available e.g. musl - -Upstream-Status: Submitted [https://bz.apache.org/bugzilla/show_bug.cgi?id=66570] -Signed-off-by: Khem Raj ---- - test/testxlate.c | 8 ++++++-- - 1 file changed, 6 insertions(+), 2 deletions(-) - -diff --git a/test/testxlate.c b/test/testxlate.c -index 6981eff..de00fa4 100644 ---- a/test/testxlate.c -+++ b/test/testxlate.c -@@ -116,8 +116,12 @@ static void test_transformation(abts_case *tc, void *data) - } - - /* 4. Transformation using charset aliases */ -- one_test(tc, "UTF-8", "UTF-7", test_utf8, test_utf7, p); -- one_test(tc, "UTF-7", "UTF-8", test_utf7, test_utf8, p); -+ if (is_transform_supported(tc, "UTF-8", "UTF-7", p)) { -+ one_test(tc, "UTF-8", "UTF-7", test_utf8, test_utf7, p); -+ } -+ if (is_transform_supported(tc, "UTF-7", "UTF-8", p)) { -+ one_test(tc, "UTF-7", "UTF-8", test_utf7, test_utf8, p); -+ } - } - - #endif /* APR_HAS_XLATE */ --- -2.40.0 - diff --git a/meta/recipes-support/apr/apr-util/configfix.patch b/meta/recipes-support/apr/apr-util/configfix.patch index dbb1148809b..4cc0ad79ae0 100644 --- a/meta/recipes-support/apr/apr-util/configfix.patch +++ b/meta/recipes-support/apr/apr-util/configfix.patch @@ -4,7 +4,7 @@ Index: apr-util-1.3.4/apu-config.in =================================================================== --- apr-util-1.3.4.orig/apu-config.in 2009-01-12 17:08:06.000000000 +0000 +++ apr-util-1.3.4/apu-config.in 2009-01-12 17:09:00.000000000 +0000 -@@ -134,14 +134,7 @@ +@@ -139,14 +139,7 @@ while test $# -gt 0; do exit 0 ;; --includes) @@ -19,7 +19,7 @@ Index: apr-util-1.3.4/apu-config.in ;; --ldflags) flags="$flags $LDFLAGS" -@@ -155,28 +148,10 @@ +@@ -160,28 +153,10 @@ while test $# -gt 0; do exit 0 ;; --link-ld) diff --git a/meta/recipes-support/apr/apr-util_1.6.3.bb b/meta/recipes-support/apr/apr-util_1.6.5.bb similarity index 93% rename from meta/recipes-support/apr/apr-util_1.6.3.bb rename to meta/recipes-support/apr/apr-util_1.6.5.bb index cb5465f8729..ba1e3359ff5 100644 --- a/meta/recipes-support/apr/apr-util_1.6.3.bb +++ b/meta/recipes-support/apr/apr-util_1.6.5.bb @@ -11,12 +11,10 @@ LIC_FILES_CHKSUM = "file://LICENSE;md5=158aa0b1efe0c12f23d4b007ddb9a5db \ SRC_URI = "${APACHE_MIRROR}/apr/${BPN}-${PV}.tar.gz \ file://configfix.patch \ - file://0001-test_transformation-Check-if-transform-is-supported-.patch \ - file://0001-sdbm-Fix-old-style-function-prototype-warning-with-c.patch \ file://run-ptest \ " -SRC_URI[sha256sum] = "2b74d8932703826862ca305b094eef2983c27b39d5c9414442e9976a9acf1983" +SRC_URI[sha256sum] = "f43a1c8c79eef497a022ec6c99dddbdf57e42001da6ccbfae259631ed5aa2805" EXTRA_OECONF = "--with-apr=${STAGING_BINDIR_CROSS}/apr-1-config \ --without-odbc \ From patchwork Wed Sep 9 07:29:07 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 97661 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 76500C79FBE for ; Wed, 9 Sep 2026 07:30:01 +0000 (UTC) Received: from mail-wr1-f52.google.com (mail-wr1-f52.google.com [209.85.221.52]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.6315.1788938999893499777 for ; Wed, 09 Sep 2026 00:30:00 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=DaaYjqpS; spf=pass (domain: smile.fr, ip: 209.85.221.52, mailfrom: yoann.congal@smile.fr) Received: by mail-wr1-f52.google.com with SMTP id ffacd0b85a97d-48584dc164fso5085963f8f.0 for ; Wed, 09 Sep 2026 00:29:59 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1788938998; x=1789543798; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=GoGZBqu34QZxmscKGKbv+GipK0zXLJF18QR+yq5xYiM=; b=DaaYjqpStgNo4Pa1GlZ8FAZOj8zVkeB4ILuAcjYBdWOTuwwPg5Xz/n27vmVz1qWooJ mM97cVbTlci4LcTU+sVoAqyvY6XNvyJFMWqEfhhpw6MQhZIK/IqiL/DRrLhs/RO1OUxm DqHjD6u7oF+JQ0qxat1WkIaf+VgikvdzVw5E8= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1788938998; x=1789543798; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=GoGZBqu34QZxmscKGKbv+GipK0zXLJF18QR+yq5xYiM=; b=KqeYWg89mDQR/BQwSwKQfaAupgCVzFFwq6IJ8wxPM9Mst/o7SkVS79fOJUNkfLFW8I b1i+MvZazNLAoH9ObOo1D+fGxha/grK6emVMxITeB0Xz99JiXz+iyO583HlpWuKpeQ3x WBmxDz8ECXXxB3mqi0xvnGQfQSMkJMBy6ojObnxg7nFg6CYLUEV15rDhOaXTeTzLooHm giPuZAQ1OBZxg0teqwsY2v3NyVUOM4ysdp4f6Jrt25dwpsSZuwBZ85Gnand/e9j5agvj fCH19N9Gm+Aex7qhUXc+Lot6uCLyF0pchXKEqOZkPNCclVTgAnstL11l7/T+Grz3H+MV Dk+g== X-Gm-Message-State: AFuF++kBSnmieka0CTqtew7hMqJ5+ZjFJljG1KHNKiniEXhHnbhabszW e83dzi5C8aYdra+/x8sEEXcwaiKyfFh4m+Vz3bhmfodqODCKKejY3HvDvQ7DYeN2mb79vFVELYW mpNRxu6U= X-Gm-Gg: AYBFou05+bwflKkYkLYn+jAnGTzKx/NlEECzrszkoR0cVTzswMfIMaNvhMXwc3kT0NS 84IBioyEFcLqN7qSjIYxhGl76wBb42X/ewKdYQfgyipjOvFULD6ZVGrFm5iXEBZYbFY6xw0+pbU v1QCp7rrs37NvPW5u6Aitj3FMJSxYvMCIba0Of/xWeoXz05DWYX99TxofoYy/3nsipaLSEfUOpD S80VFfcAMI3F4XUrRVTlRjKMz7qmESGGaLTBOxdJBaGMynQTZ/YAcMjoB78s9uPnh9SgmqE1Sol BJnH3kFRIWRmRg6zCDKpo0aDzs4VzPnds0eUqFjuysYkyABbSUnV+TTH0JQKO+NnE4CLnfL2Pnl nTUtUdjSkh/KB/nJo6RPMEHicO88uXagEcmSd/dcsf7suGwVo+SE64Mo+ysWbrsNCxtVCDr0omb 1aPKtfz2tLITLLSaPRJMr0xHOTgp1Si/rAVP99PQkg9WxxcIEWUgEazogpnvGhIpGGR19Z0cyqL 2gNXin5GOam1Q+iFqmJolXQaxJnQdyEiZnlYL4BkNI1N65BWKyFZB1jGhM7yd01rI4skuFUz5U= X-Received: by 2002:a05:6000:2287:b0:485:8a46:704f with SMTP id ffacd0b85a97d-4858a46725cmr30208037f8f.33.1788938997919; Wed, 09 Sep 2026 00:29:57 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-4858ac2b4cdsm40624310f8f.16.2026.09.09.00.29.56 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 09 Sep 2026 00:29:56 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][wrynose 08/38] python3-pip: Fix CVE-2026-13346 Date: Wed, 9 Sep 2026 09:29:07 +0200 Message-ID: <7862170e00e79f196db15f9b5efd97470ee8fd56.1788938909.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Wed, 09 Sep 2026 07:30:01 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/245417 From: Hetvi Thakar This patch applies the upstream fix as referenced in [2], using the commit shown in [1]. [1] https://github.com/pypa/pip/commit/10dfb6b9005484578b386f64b9f36982e3dc6679 [2] https://nvd.nist.gov/vuln/detail/CVE-2026-13346 Signed-off-by: Hetvi Thakar Signed-off-by: Yoann Congal [YC: fixed patch format] --- .../python/python3-pip/CVE-2026-13346.patch | 206 ++++++++++++++++++ .../python/python3-pip_26.0.1.bb | 4 +- 2 files changed, 209 insertions(+), 1 deletion(-) create mode 100644 meta/recipes-devtools/python/python3-pip/CVE-2026-13346.patch diff --git a/meta/recipes-devtools/python/python3-pip/CVE-2026-13346.patch b/meta/recipes-devtools/python/python3-pip/CVE-2026-13346.patch new file mode 100644 index 00000000000..e800f29e304 --- /dev/null +++ b/meta/recipes-devtools/python/python3-pip/CVE-2026-13346.patch @@ -0,0 +1,206 @@ +From 10dfb6b9005484578b386f64b9f36982e3dc6679 Mon Sep 17 00:00:00 2001 +From: Damian Shaw +Date: Tue, 30 Jun 2026 21:52:39 -0400 +Subject: [PATCH] Fix Link.filename decoding URL path twice (#14110) + +Link already percent-decodes the URL path into `self._path`, but +`Link.filename` decoded the basename again, so a doubly-encoded +separator was decoded twice: `%252F` became `%2F` in `__init__`, then +`/` in `filename`, turning the single component `a%2Fb.whl` into +`a/b.whl`. + +Drop the second decode, and add a `join_within_directory` helper so the +download-path joins treat the name as a single path component. + +CVE: CVE-2026-13346 +Upstream-Status: Backport [https://github.com/pypa/pip/commit/10dfb6b9005484578b386f64b9f36982e3dc6679] + +Backport Changes: +- Omit news/14110.bugfix.rst and tests/unit/test_link.py because these + paths are absent from the pip 26.0.1 PyPI sdist used by this recipe. + All runtime-source changes are unchanged from upstream. + +(cherry picked from commit 10dfb6b9005484578b386f64b9f36982e3dc6679) +Signed-off-by: Hetvi Thakar +--- + src/pip/_internal/models/link.py | 63 ++++++++++++++++++++----- + src/pip/_internal/network/download.py | 20 ++++++-- + src/pip/_internal/operations/prepare.py | 6 +-- + 3 files changed, 69 insertions(+), 20 deletions(-) + +diff --git a/src/pip/_internal/models/link.py b/src/pip/_internal/models/link.py +index 200ec34c5..1a6439873 100644 +--- a/src/pip/_internal/models/link.py ++++ b/src/pip/_internal/models/link.py +@@ -14,6 +14,7 @@ from dataclasses import dataclass + from typing import ( + Any, + NamedTuple, ++ NewType, + ) + + from pip._internal.exceptions import InvalidEggFragment +@@ -31,6 +32,49 @@ from pip._internal.utils.urls import path_to_url, url_to_path + logger = logging.getLogger(__name__) + + ++# A single path component: percent-decoded once and reduced to a basename, so it ++# contains no path separator and is not a ``.`` or ``..`` reference. The empty ++# string means "no component". ++PathComponent = NewType("PathComponent", str) ++ ++ ++def _to_path_component(name: str) -> PathComponent: ++ """Reduce ``name`` to a single path component, or ``""`` if it has none. ++ ++ ``os.path.basename`` drops any directory part, drive letter, or separator; ++ a ``.``, ``..``, or empty result is not a component and becomes ``""``. ++ """ ++ name = os.path.basename(name) ++ if name in ("", os.curdir, os.pardir): ++ return PathComponent("") ++ ++ return PathComponent(name) ++ ++ ++def as_path_component(name: str) -> PathComponent: ++ """Like ``_to_path_component`` but reject the empty result. ++ ++ Use where a file is about to be written, so a missing name is an error ++ rather than a silent fallback to the directory itself. ++ """ ++ component = _to_path_component(name) ++ if not component: ++ raise ValueError(f"Unexpected file name derived from URL: {name!r}") ++ ++ return component ++ ++ ++def join_within_directory(directory: str, component: PathComponent) -> str: ++ """Join a single path ``component`` onto ``directory``. ++ ++ ``component`` is a :data:`PathComponent`, so by type it has no separator and ++ is not a ``.`` or ``..`` reference; the result can never escape ``directory``. ++ Requiring ``PathComponent`` rather than ``str`` lets the type checker enforce ++ at the call site that the name was reduced to a safe component beforehand. ++ """ ++ return os.path.join(directory, component) ++ ++ + # Order matters, earlier hashes have a precedence over later hashes for what + # we will pick to use. + _SUPPORTED_HASHES = ("sha512", "sha384", "sha256", "sha224", "sha1", "md5") +@@ -423,18 +467,13 @@ class Link: + return redact_auth_from_url(self.url) + + @property +- def filename(self) -> str: +- path = self.path.rstrip("/") +- name = posixpath.basename(path) +- if not name: +- # Make sure we don't leak auth information if the netloc +- # includes a username and password. +- netloc, user_pass = split_auth_from_netloc(self.netloc) +- return netloc +- +- name = urllib.parse.unquote(name) +- assert name, f"URL {self._url!r} produced no filename" +- return name ++ def filename(self) -> PathComponent: ++ name = _to_path_component(posixpath.basename(self.path.rstrip("/"))) ++ if name: ++ return name ++ ++ # No component in the path; fall back to the netloc, dropping any auth. ++ return _to_path_component(split_auth_from_netloc(self.netloc)[0]) + + @property + def file_path(self) -> str: +diff --git a/src/pip/_internal/network/download.py b/src/pip/_internal/network/download.py +index 26966423f..fa71c75a3 100644 +--- a/src/pip/_internal/network/download.py ++++ b/src/pip/_internal/network/download.py +@@ -20,7 +20,12 @@ from pip._vendor.urllib3.exceptions import ReadTimeoutError + from pip._internal.cli.progress_bars import BarType, get_download_progress_renderer + from pip._internal.exceptions import IncompleteDownloadError, NetworkConnectionError + from pip._internal.models.index import PyPI +-from pip._internal.models.link import Link ++from pip._internal.models.link import ( ++ Link, ++ PathComponent, ++ as_path_component, ++ join_within_directory, ++) + from pip._internal.network.cache import SafeFileCache, is_from_cache + from pip._internal.network.session import CacheControlAdapter, PipSession + from pip._internal.network.utils import HEADERS, raise_for_status, response_chunks +@@ -117,11 +122,14 @@ def parse_content_disposition(content_disposition: str, default_filename: str) - + return filename or default_filename + + +-def _get_http_response_filename(resp: Response, link: Link) -> str: ++def _get_http_response_filename(resp: Response, link: Link) -> PathComponent: + """Get an ideal filename from the given HTTP response, falling back to + the link filename if not provided. ++ ++ The result is validated as a single path component, so it can be joined onto ++ a download directory without escaping it. + """ +- filename = link.filename # fallback ++ filename: str = link.filename # fallback + # Have a look at the Content-Disposition header for a better guess + content_disposition = resp.headers.get("content-disposition") + if content_disposition: +@@ -135,7 +143,7 @@ def _get_http_response_filename(resp: Response, link: Link) -> str: + ext = os.path.splitext(resp.url)[1] + if ext: + filename += ext +- return filename ++ return as_path_component(filename) + + + @dataclass +@@ -188,7 +196,9 @@ class Downloader: + resp = self._http_get(link) + download_size = _get_http_response_size(resp) + +- filepath = os.path.join(location, _get_http_response_filename(resp, link)) ++ filepath = join_within_directory( ++ location, _get_http_response_filename(resp, link) ++ ) + with open(filepath, "wb") as content_file: + download = _FileDownload(link, content_file, download_size) + self._process_response(download, resp) +diff --git a/src/pip/_internal/operations/prepare.py b/src/pip/_internal/operations/prepare.py +index 67f9ee950..d260d15a2 100644 +--- a/src/pip/_internal/operations/prepare.py ++++ b/src/pip/_internal/operations/prepare.py +@@ -29,7 +29,7 @@ from pip._internal.exceptions import ( + from pip._internal.index.package_finder import PackageFinder + from pip._internal.metadata import BaseDistribution, get_metadata_distribution + from pip._internal.models.direct_url import ArchiveInfo +-from pip._internal.models.link import Link ++from pip._internal.models.link import Link, join_within_directory + from pip._internal.models.wheel import Wheel + from pip._internal.network.download import Downloader + from pip._internal.network.lazy_wheel import ( +@@ -201,7 +201,7 @@ def _check_download_dir( + """Check download_dir for previously downloaded file with correct hash + If a correct file is found return its path else None + """ +- download_path = os.path.join(download_dir, link.filename) ++ download_path = join_within_directory(download_dir, link.filename) + + if not os.path.exists(download_path): + return None +@@ -683,7 +683,7 @@ class RequirementPreparer: + # No distribution was downloaded for this requirement. + return + +- download_location = os.path.join(self.download_dir, link.filename) ++ download_location = join_within_directory(self.download_dir, link.filename) + if not os.path.exists(download_location): + shutil.copy(req.local_file_path, download_location) + download_path = display_path(download_location) +-- +2.35.6 diff --git a/meta/recipes-devtools/python/python3-pip_26.0.1.bb b/meta/recipes-devtools/python/python3-pip_26.0.1.bb index 9640bc926aa..3ff6cd39cd2 100644 --- a/meta/recipes-devtools/python/python3-pip_26.0.1.bb +++ b/meta/recipes-devtools/python/python3-pip_26.0.1.bb @@ -24,7 +24,9 @@ LIC_FILES_CHKSUM = "file://LICENSE.txt;md5=63ec52baf95163b597008bb46db68030 \ inherit pypi python_setuptools_build_meta -SRC_URI += "file://no_shebang_mangling.patch" +SRC_URI += "file://no_shebang_mangling.patch \ + file://CVE-2026-13346.patch \ + " SRC_URI[sha256sum] = "c4037d8a277c89b320abe636d59f91e6d0922d08a05b60e85e53b296613346d8" From patchwork Wed Sep 9 07:29:08 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 97663 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 98480C79FBF for ; Wed, 9 Sep 2026 07:30:01 +0000 (UTC) Received: from mail-wr1-f45.google.com (mail-wr1-f45.google.com [209.85.221.45]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.6317.1788939000659409920 for ; Wed, 09 Sep 2026 00:30:00 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=IZRNi8yS; spf=pass (domain: smile.fr, ip: 209.85.221.45, mailfrom: yoann.congal@smile.fr) Received: by mail-wr1-f45.google.com with SMTP id ffacd0b85a97d-48441fa5c37so4023534f8f.3 for ; Wed, 09 Sep 2026 00:30:00 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1788938999; x=1789543799; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=e/FCc0zq7r4B2sljo1mwdNuTiVb4up034azd4meUN8U=; b=IZRNi8ySYs0ZEfR8P1tdu+X1ubGbr8KpiEi0HAk1TLVNKGLxyEEX+jfaWUaon4OHJe 7qbLxul+OTUah/ZUSvZwAjVpdxWQpPbP4R1zJkg1oloJQTdTQCsrjvaOuhN8hXMMk4n4 nOST+OzdFjnifBQD7vIS/IDh8s752itvpdERo= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1788938999; x=1789543799; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=e/FCc0zq7r4B2sljo1mwdNuTiVb4up034azd4meUN8U=; b=XwjZW+uU/iAc+QwF2S9R341pRqDF906fpuwZpMs87ARftebj8MtaK3Pmjo9AqEvh8L szlTV9wcD61sXQazapsovEK16CyIgAvlj8M1DTHyAjSao7kx8OAKCJa+Q3oSKFKmh0j/ zQwKGxay4fhwaqQzcPbQFIjg9WIdeUF0lQWLcGT1KeL9BDAkdUqgKI9S9fVRUmnBuS/3 bkhD17EVcUF/1Qkl/ctoEZrxXbNGsCpsdGDapHpx1GUxG08bF6bkbZkTwFEGjaPnMqmE 2fCQ8TjVz04unj7y7mw3W98E+rvTIPVCqdNqVYm6pCpsugTcAPsDXmPM32UNcNyT/FbU 7row== X-Gm-Message-State: AFuF++nfh1qwGO0kpkS1zlfcXpdNO5ZzFlE3jmj5AFlL2BfoU/aqPtwF EuHHvczGm1j/GQUKj84ifrJjZTK3jiu/nghVUTtqbzdgcjzxIh6u+uo8C2ETR2pZEpbGexOqD7i Ntsf8RPI= X-Gm-Gg: AYBFou08wFxDiYizXf+QRPyzN1Ak7EpP546wfAFGN6JglN4uCV5ZVeYK65K+fCq22W7 tIBdrErGJLOHH/J/Rmcygr2kzRzR7zPSIX15OqHhJ1TR6t9yherFy6eEedbdfuGEU31Rv1GpOpq XvSOiILG8/zEuYmx2k1CZ9BE3WdjyfzZkLRQx+mZ5PSQVxZFl2NbDejgWsPFG4BZM0ghiOH6q3b H4uyp5Njy+g0WL87EZB3DRWotJaMzz3GU+wdU6Z3pT4HH464kwqRH2rWNznWx09g73QBl42Ga6R C4fcbCyPMSvuEADa0URA/8n7+C2LDW9k+ZYs4w5TjCNMaq/vJ9B4qOdwrnSBHtoTQruN5wpgfca tXcsKyAwljf0v+rkQwKsN72rhDevSbKhcnMw/moe744hHch0kMgOc8HSQVB1Ub3TUCt0K+w9jhM pYM76CRjlY5HqdL0EdXqkHlfCs1ZxTjhZSx7KMkcG4X4WaOpbH0p2ZP8Prl2yMrzUYGEXr9FBpC bqk3ykGi67LQfLVjytJKO66aOpLiNew1nyQ9J+yiOZvE2pxp3KF58jJDhXrKx08NKwRmFKg0Tk= X-Received: by 2002:a05:6000:2084:b0:485:8a46:b3d0 with SMTP id ffacd0b85a97d-4858a46b5a1mr33586620f8f.56.1788938998848; Wed, 09 Sep 2026 00:29:58 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-4858ac2b4cdsm40624310f8f.16.2026.09.09.00.29.58 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 09 Sep 2026 00:29:58 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][wrynose 09/38] time64: enable 64-bit time/file-offset flags for 32-bit nativesdk Date: Wed, 9 Sep 2026 09:29:08 +0200 Message-ID: <2bbf244ddb677ab6799cfdc9686f5e516412692d.1788938909.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Wed, 09 Sep 2026 07:30:01 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/245418 From: Peter Tatrai When SDKMACHINE is set to i686 or i586, nativesdk binaries are compiled as 32-bit. Without -D_TIME_BITS=64 and -D_FILE_OFFSET_BITS=64, stat() and time-related syscalls use 32-bit types, causing EOVERFLOW on filesystems with large inode numbers (e.g. container overlay filesystems) and Y2038 issues. Add SDK_CC_ARCH appends for class-nativesdk:i686 and class-nativesdk:i586 using GLIBC_64BIT_TIME_FLAGS, mirroring how target architectures are handled. Signed-off-by: Peter Tatrai " Signed-off-by: Richard Purdie (cherry picked from commit d9f62a45555673842021d5746437e66c40d3f3cc) Signed-off-by: Peter Tatrai Signed-off-by: Yoann Congal --- meta/conf/distro/include/time64.inc | 10 ++++++++++ 1 file changed, 10 insertions(+) diff --git a/meta/conf/distro/include/time64.inc b/meta/conf/distro/include/time64.inc index 19177b1f3cc..a2fe03354d5 100644 --- a/meta/conf/distro/include/time64.inc +++ b/meta/conf/distro/include/time64.inc @@ -38,6 +38,16 @@ TARGET_CC_ARCH:append:x86 = "${@bb.utils.contains('TUNE_FEATURES', 'm32', '${GLI GLIBC_64BIT_TIME_FLAGS:pn-glibc = "" GLIBC_64BIT_TIME_FLAGS:pn-glibc-testsuite = "" +# Apply the same flags to nativesdk packages when building for a 32-bit SDK +# host (i686, i586). +SDK_CC_ARCH:append:class-nativesdk:i686 = "${GLIBC_64BIT_TIME_FLAGS}" +SDK_CC_ARCH:append:class-nativesdk:i586 = "${GLIBC_64BIT_TIME_FLAGS}" + +# nativesdk-pseudo wraps both 32-bit and 64-bit libc calls; enabling LFS flags +# causes duplicate symbol errors (e.g. creat64, fopen64) on i686 because glibc +# aliases the non-LFS names to their 64-bit counterparts via macros. +GLIBC_64BIT_TIME_FLAGS:pn-nativesdk-pseudo = "" + # Caused by the flags exceptions above INSANE_SKIP:append:pn-glibc = " 32bit-time" From patchwork Wed Sep 9 07:29:09 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 97676 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id D2229C88E41 for ; Wed, 9 Sep 2026 07:30:12 +0000 (UTC) Received: from mail-wr1-f50.google.com (mail-wr1-f50.google.com [209.85.221.50]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.6318.1788939001494845588 for ; Wed, 09 Sep 2026 00:30:01 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=1aIxBFcs; spf=pass (domain: smile.fr, ip: 209.85.221.50, mailfrom: yoann.congal@smile.fr) Received: by mail-wr1-f50.google.com with SMTP id ffacd0b85a97d-48441a2ba14so4610069f8f.1 for ; Wed, 09 Sep 2026 00:30:01 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1788939000; x=1789543800; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=GXUOn9P6PqAKl9PWdLtqI6TyHef18vdWeAX4h9P7/4s=; b=1aIxBFcsMh5olL9lgOHGwqRM+8h3UdnHkoJOkuagY0AG6XhLQ9cvqZdSMXh0lzoK4k 4fXEkOYpbfipim7nBKMMJQchMUsm667WpykPdipSjLUJTjaecCTd3Ei1YgNMvnF3+9LI w9MjHpVlt0GQdfLR8ssoBZCujpxr0/ZERD8hQ= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1788939000; x=1789543800; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=GXUOn9P6PqAKl9PWdLtqI6TyHef18vdWeAX4h9P7/4s=; b=Ognn0C5BjohjWmbAY/s66z+dHGqY1elRq3ymOGCXk4lZ90KuC+N6FnisM9BTA/y9ew ///w+wi0BGjn1gixuzBBXLiBkhvYbAZjfVAVCdE77OHF/ewUqxdiUm8QCfW1fqbcA2h4 B6RAJr9WfFos+LZPdOoeWAuOvlW5cq5agGnHCQW9cKS67LBQlbsE/KXOyVmwe9XhFO0+ 4Ew+JqU3ZSgsR613qCFiGR+0lGy3efMU3p6n64NjHr7D0EropM5nyvpkuOejlbfNb7O8 /UYqMQxAxq7TVP7NFh0+2n3FHumbc4pIwWhs48vkavSonVvXm0J8/PfsVesUUPBJgc7c kYlA== X-Gm-Message-State: AFuF++nLNHoyWd3EJIdbAFijStX6DdNUKNapx/pXrc5sle8SvKxlJnN3 +Okk6RdRssR/KLHDgfEDiRy275qmpXFTm5HT1840MV9ytqPpMbOxr5xbDGnPiaD/Xp80+UC7sqd 3lY2Pcc0= X-Gm-Gg: AYBFou2JjiIsQqj7ea0ujOPxCOmMgmrx3s3nz1GNm9PE2ZiWp++tY30a0coCCCPNGAN iD0tnr7GQOZAO2XU1l5QKJ0rlVYD9csWKiwbbmVKmOrysGoft6EruHBZoi99vxwHdRuF56hF/K8 45Cm/QMGT2e9X5rE+0edGawotrhylXy2vHmpwckYxiqGT5Zkq+C1+zaiSJjyR/tc4gWQ5hiwOkg 2gkCcnGprXOjFQHf1pxXqI8ELwjhAdZqZ8+BnnkGpirxLSXwPdhAPBhGipEvnP35bXrl0nNlOU7 /MDtRn3oACYSGwYOKRf7iE2MyfcP06+RopYYvBx/1lDYrZ4xzJc2P/1pAUoMc8RQRUyFAa4VW3s 5Xtb+njCPktUEKASGuMnBPUQezvdzT6PXRRGwr0Vgh3u1fmpPjW4FYRJEolTo94PWS0VuMZP+7r Kef4tAwUvKTZSkkTMcclQbMtdewK6G3Da8RARFYUTp0oobtaCvu7WBGdrQ+X68TXcE6QOUnE+V+ KWcWFOcBm6R1EcAmEvbDVwFrVw+26wiECpJMIdK3ml+zOhCCX5mRfTC5gvCFql32xu6q/6xfI4= X-Received: by 2002:a5d:64c6:0:b0:485:9373:d416 with SMTP id ffacd0b85a97d-4859373d58fmr26444100f8f.11.1788938999544; Wed, 09 Sep 2026 00:29:59 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-4858ac2b4cdsm40624310f8f.16.2026.09.09.00.29.58 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 09 Sep 2026 00:29:59 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][wrynose 10/38] grub: disable grub-protect for native builds Date: Wed, 9 Sep 2026 09:29:09 +0200 Message-ID: X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Wed, 09 Sep 2026 07:30:12 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/245419 From: Himanshu Jadon grub-native fails on hosts where libtasn1 headers are not available when configure tries to build grub-protect: util/grub-protect.c:25:10: fatal error: libtasn1.h: No such file or directory grub-protect is an optional utility for sealing disk-encryption keys using the TPM2 key protector. It is not used by the GRUB native tools staged for Yocto recipe execution. Disable grub-protect for class-native so grub-native does not depend on libtasn1. This keeps the native build focused on the tools needed by Yocto and avoids adding another native library dependency only for an unused utility. Target and nativesdk builds keep the upstream default, so image and SDK behaviour is unchanged. Signed-off-by: Himanshu Jadon Signed-off-by: Richard Purdie (cherry picked from commit 9290ca0517e5a8888ee8a695a87c0d7e7b5ea377) Signed-off-by: Deepak Rathore Signed-off-by: Yoann Congal --- meta/recipes-bsp/grub/grub2.inc | 2 ++ 1 file changed, 2 insertions(+) diff --git a/meta/recipes-bsp/grub/grub2.inc b/meta/recipes-bsp/grub/grub2.inc index 0656489ead3..466c772e5bf 100644 --- a/meta/recipes-bsp/grub/grub2.inc +++ b/meta/recipes-bsp/grub/grub2.inc @@ -73,6 +73,8 @@ EXTRA_OECONF = "--with-platform=${GRUBPLATFORM} \ --disable-werror \ " +EXTRA_OECONF:append:class-native = " --disable-grub-protect" + PACKAGECONFIG ??= "" PACKAGECONFIG[grub-mount] = "--enable-grub-mount,--disable-grub-mount,fuse" PACKAGECONFIG[device-mapper] = "--enable-device-mapper,--disable-device-mapper,libdevmapper" From patchwork Wed Sep 9 07:29:10 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 97675 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 56BD5C79FBC for ; Wed, 9 Sep 2026 07:30:12 +0000 (UTC) Received: from mail-wr1-f46.google.com (mail-wr1-f46.google.com [209.85.221.46]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.6436.1788939001834303306 for ; Wed, 09 Sep 2026 00:30:02 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=LvkAkACA; spf=pass (domain: smile.fr, ip: 209.85.221.46, mailfrom: yoann.congal@smile.fr) Received: by mail-wr1-f46.google.com with SMTP id ffacd0b85a97d-485850cbac3so3560155f8f.3 for ; Wed, 09 Sep 2026 00:30:01 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1788939000; x=1789543800; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=0FsyASjafASGAIbLR9KVAyKbSTCZuoKNupEmTrZyO0U=; b=LvkAkACASccGzTBks5tz3o94gEHFiPItH6INcneU3DofaC2oMoMy6VHnh3+JNtyQh1 RtolIrxarS+fBN3JrKt/r/NOx+AWZOom2uQTTZ7tiz8faJUz8uIgMIW954ppjGJVkU0t /I6PULGvlIxV2gG5E0fu5bjDq1NWm4fFCHPoc= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1788939000; x=1789543800; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=0FsyASjafASGAIbLR9KVAyKbSTCZuoKNupEmTrZyO0U=; b=qzadvVjVvtVq/o1fw5+4/JoyshrMe72BrJRHWDnDfOXswn1bG+q5bVzmOJGPyfkiWN UFogpY2aF67B07zcMYmBmtTabJXlA+YqJ2ZITWY1FJJbnv7CDqcr+BD42B5kvNTVa7Bs z1PlYNEEn+gNpIl/45huCuTpiczk5LNoNXp5NmUe3bHCO1j3U7RJDevHi70nhS2ePhox rmwtw0rt/oM7n8GPKKg9X5YrIOCJZY0RPuO6AADRHovHDNQ9ABVOt5t3JcVYustmgulr c12p+DGqBuBxEygyr7Njfit3FsL6QTqdNfOXHCZVWQHlkwtInx2dJyUcL2vYoRudignL rbdw== X-Gm-Message-State: AFuF++lJhddYGfsDvSLo/59453OIZIRN88eA/k2Rf0I5X4tvyf0MboeI FOxlW3xvoxCZoB6MaFtkVvlzWlg4wQSIgyjzjVwVo+jtb6uGFgFWL43rdhKMFmj9UhBclhikxi8 CXqPLYaU= X-Gm-Gg: AYBFou3z5+wVGrPNJVkkBxY09cTXrEsp/iv7b9XGLt7hJM8fn8zalbnFHPy4USV+eqf q47FUhCW3tbvEI20joakZ7SGtfcYxr6ylWtqwVZfC2HIj+jPETB9LlsDk8NxHgTpmt4L9HebVaV Uk5+oGmm4QmwQuhB5/kFxXscAQD7+6HTpckxwmy92SWbQu3GRLQGfAXFJPYezDq/3wA7PeNkg3h KS747gVBTWRnAs8O+N96ywgdw/uJ0iT3DQvfJIWE3rAka+k3P4ep4XnbbBWiAqqNWCDIfW2Np8E bKqD6MsnTEIOCF1aLt8GaBzvJQj+j5St1fnvr5du16paTsNaO7todp9u3v6AFG3VucMfzRT52q9 3RNg2i9JRT1CXDYL+4UNmNfhhhAmfqtoMCBREzpTR7ihzEON035DQ8KIo03/VjZ7/u7HF46KA7L bkU0Eqw10YyNfh8U0PVK5UnMjjerKO9igQc1RSDZF3PnfFo+KtcWm/akUZDtu5ZWBym411iCsep 8BxdlsEIpK5yQ3jaIqgt+X6tT9HRXWSzTCbIlyrkqsE0bRp8znvu2sODTncMEq7+Zzdnm9vyIpr 0YP91AxErg== X-Received: by 2002:a05:600c:81c8:b0:49d:1f10:8b9f with SMTP id 5b1f17b1804b1-49d1f109802mr35900775e9.7.1788939000007; Wed, 09 Sep 2026 00:30:00 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-4858ac2b4cdsm40624310f8f.16.2026.09.09.00.29.59 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 09 Sep 2026 00:29:59 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][wrynose 11/38] procps: ptest: skip flaky pgrep full process name match test Date: Wed, 9 Sep 2026 09:29:10 +0200 Message-ID: <0cb7cb20339762dae8c1ce6b1ed41dd8714635b8.1788938909.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Wed, 09 Sep 2026 07:30:12 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/245420 From: Pratik Farkase The 'pgrep match against full process name' test uses pgrep -f with a regex pattern close to ARG_MAX in size (~100KB). This intermittently fails on qemuriscv64 where the process cmdline may not be fully visible in /proc//cmdline at the time pgrep reads it, or the large regex match times out under TCG emulation. Skip this single test case while keeping all other 30+ pgrep tests which are reliable. [YOCTO #16290] Signed-off-by: Pratik Farkase Signed-off-by: Mathieu Dubois-Briand Signed-off-by: Richard Purdie (cherry picked from commit b9166b8fda40bece8c2007ac1f06d51693ac617a) Signed-off-by: Yoann Congal --- ...p-pgrep-full-process-name-match-test.patch | 39 +++++++++++++++++++ meta/recipes-extended/procps/procps_4.0.6.bb | 1 + 2 files changed, 40 insertions(+) create mode 100644 meta/recipes-extended/procps/procps/0001-testsuite-skip-pgrep-full-process-name-match-test.patch diff --git a/meta/recipes-extended/procps/procps/0001-testsuite-skip-pgrep-full-process-name-match-test.patch b/meta/recipes-extended/procps/procps/0001-testsuite-skip-pgrep-full-process-name-match-test.patch new file mode 100644 index 00000000000..43c930ce086 --- /dev/null +++ b/meta/recipes-extended/procps/procps/0001-testsuite-skip-pgrep-full-process-name-match-test.patch @@ -0,0 +1,39 @@ +From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001 +From: Pratik Farkase +Date: Mon, 17 Aug 2026 10:00:00 +0000 +Subject: [PATCH] testsuite: skip pgrep full process name match test + +The "pgrep match against full process name" test uses pgrep -f with a +regex pattern close to ARG_MAX in size (~100KB). This intermittently +fails on qemuriscv64 where the process cmdline may not be fully visible +in /proc//cmdline at the time pgrep reads it, or the large regex +match times out under TCG emulation. + +Skip this single test case while keeping all other pgrep tests which +are reliable. + +https://bugzilla.yoctoproject.org/show_bug.cgi?id=16290 + +Upstream-Status: Inappropriate [OE-ptest specific: fails only under QEMU TCG emulation] +Signed-off-by: Pratik Farkase +--- + testsuite/pgrep.test/pgrep.exp | 6 +++--- + 1 file changed, 3 insertions(+), 3 deletions(-) + +diff --git a/testsuite/pgrep.test/pgrep.exp b/testsuite/pgrep.test/pgrep.exp +index 54e75df..66edbaa 100644 +--- a/testsuite/pgrep.test/pgrep.exp ++++ b/testsuite/pgrep.test/pgrep.exp +@@ -35,9 +35,9 @@ set test "pgrep with : delimiter" + spawn $pgrep -d : $testproc_comm + expect_pass "$test" "^${testproc1_pid}:${testproc2_pid}\\s*$" + +-set test "pgrep match against full process name" +-spawn $pgrep -f "$testproc_path\\s+$testproc_arg_str" +-expect_pass "$test" "^$testproc1_pid\\s*$" ++# Skip: intermittent failure on riscv64 - pgrep -f with large ARG_MAX ++# patterns can fail under QEMU emulation (timing/cmdline visibility race) ++untested "pgrep match against full process name" + + set test "pgrep with matching gid" + spawn $pgrep -G $gid $testproc_comm diff --git a/meta/recipes-extended/procps/procps_4.0.6.bb b/meta/recipes-extended/procps/procps_4.0.6.bb index a9ec3f39d6c..541a8cd99cd 100644 --- a/meta/recipes-extended/procps/procps_4.0.6.bb +++ b/meta/recipes-extended/procps/procps_4.0.6.bb @@ -15,6 +15,7 @@ inherit autotools gettext pkgconfig update-alternatives ptest SRC_URI = "git://gitlab.com/procps-ng/procps.git;protocol=https;branch=master;tag=v${PV} \ file://sysctl.conf \ file://0001-tests-Disable-twice-total-pmap-X-tests.patch \ + file://0001-testsuite-skip-pgrep-full-process-name-match-test.patch \ file://run-ptest \ " SRCREV = "4dafddf4c3f4646caa517f039a2307e92657ec93" From patchwork Wed Sep 9 07:29:11 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 97673 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 70DB9C79FBD for ; Wed, 9 Sep 2026 07:30:12 +0000 (UTC) Received: from mail-wr1-f44.google.com (mail-wr1-f44.google.com [209.85.221.44]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.6437.1788939002361638108 for ; Wed, 09 Sep 2026 00:30:02 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=f8cnjrd2; spf=pass (domain: smile.fr, ip: 209.85.221.44, mailfrom: yoann.congal@smile.fr) Received: by mail-wr1-f44.google.com with SMTP id ffacd0b85a97d-482ea739de2so3777769f8f.0 for ; Wed, 09 Sep 2026 00:30:02 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1788939000; x=1789543800; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=JI94KdcV7NQIIpDcpfAEw6laepzw6QJZn+3FcUREBoo=; b=f8cnjrd2Uole8/7KI8gDykTbnizEuSsfCJYz7sGgWMTnTrRsAxX/nUi0pt3d3mU54a rCZOUdHXQOk+y8lSd9SeX+2Dm3s08eiNqx2ZI2DJafLwIoHMdVl5UK1ZYSOnPnCxOFMV nW1Io1FkZa83kYxy4F10T9CyQzADm5Uxus/jc= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1788939001; x=1789543801; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=JI94KdcV7NQIIpDcpfAEw6laepzw6QJZn+3FcUREBoo=; b=T+7lQ0pXo4+9iLVSB+WVaeHI6LYyjk80UCgJJg5VJKaUmONA6b2FYy42bQlvcdCQLN MZkNH8CQ3qEdphS/97yuXA/jxXEZMxB5ZfOpc2/AgKrwGnmMt3wZ9zwpYOO4EvXKCXsd 64B3j1/dIn34IQ+jS9TJDscxKsRxOy/UY8+wumO852SydFxj0FhJ5IKp8AFOYZWL3zra 1Y2hbeWC2LGWnlNzdmcUPGJbVrunCQWiBnbY1IJuJq2iPDb+GlkpFhct0w2bwn+D/FID SH7CQeuCaXUNlMIHp88QJ7rPN+srbYxBiUalqSrliV/rZ+dPyEIpGr2IEImEidzLVQES I9PQ== X-Gm-Message-State: AFuF++mx+5jrFCmznP5k/d1qYyOUXYA1HP7GnUZXmZo4sHPqI7/gf/Zk G3UPQZejtmg8I2hNO8P9AFnOMuJasXziPhKEX8O584pWg8Ijvblf8VACIM0qd5MtMOcM+eMAtK0 V33NsisU= X-Gm-Gg: AYBFou37WlHGbe0l3dABtVEpQBRFmkPEvPWZgcVuavLeLNuSh28Z762bUVV4n/eQ9yK loc2ogG1EsAgp937QaKE839YIIanonu0RKDTZgJj7+NfYO40IWQYHUMCnbBXyFVBK92pVTMJPxQ lzlFNCvdx+NsyZAymSTCyEh84zy9zuRM9UnIR/FvoOkzgDUmP8rjKt2ikzuxFeQeDhJ/jMRX5kN khC/ydbkWPdpFSrXRArxXEep8INqAe1VouI1Lo9awLg0VIoJRaBp2HWwbeSVqlz3Seh24FYkXny qcfa5LUXSpJEnQrF/I1DQcGVvkgdBV/JfGmZlmLGv2lh0mfqiGody9iq0g+vucss6pc0lkovqgK 3QrAJ0V8NU8FKM+ORmjvnLNVy0dG7LLHyaMXX2J5l49p1wzDbAmljjTiYpALk6k25X6h7/9ZD0l oZH4iVPaVRnByD0IY6t34gNFjzzjzNapzCibT34QTGtkfD33fVvKYHKb3hlhg19/aWz8W4vPiRC 4X+QZw7CsbQuAu4x4KpEi8HKe2RyHUK2NHkVJZ9DVeNydX4cAYsP87m81RJ4E9iz8H2jBJcpz1V zRrW4RWaNw== X-Received: by 2002:a5d:5e8a:0:b0:485:af9d:cd1f with SMTP id ffacd0b85a97d-485af9dcf4dmr1682828f8f.51.1788939000510; Wed, 09 Sep 2026 00:30:00 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-4858ac2b4cdsm40624310f8f.16.2026.09.09.00.30.00 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 09 Sep 2026 00:30:00 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][wrynose 12/38] vim: Fix for CVE-2026-73072 Date: Wed, 9 Sep 2026 09:29:11 +0200 Message-ID: X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Wed, 09 Sep 2026 07:30:12 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/245421 From: Hitendra Prajapati Pick the patch from [1], also referenced in the NVD report [2]. [1] https://github.com/vim/vim/commit/05c41c922309c7a11b6ec2f124be66551c90d66a [2] https://nvd.nist.gov/vuln/detail/CVE-2026-73072 Signed-off-by: Hitendra Prajapati Signed-off-by: Yoann Congal --- .../vim/files/CVE-2026-73072.patch | 64 +++++++++++++++++++ meta/recipes-support/vim/vim.inc | 1 + 2 files changed, 65 insertions(+) create mode 100644 meta/recipes-support/vim/files/CVE-2026-73072.patch diff --git a/meta/recipes-support/vim/files/CVE-2026-73072.patch b/meta/recipes-support/vim/files/CVE-2026-73072.patch new file mode 100644 index 00000000000..0ae3b2b49e6 --- /dev/null +++ b/meta/recipes-support/vim/files/CVE-2026-73072.patch @@ -0,0 +1,64 @@ +From 05c41c922309c7a11b6ec2f124be66551c90d66a Mon Sep 17 00:00:00 2001 +From: Yasuhiro Matsumoto +Date: Fri, 24 Jul 2026 00:58:37 +0900 +Subject: [PATCH] patch 9.2.0846: [security]: heap buffer overflow in + set_sofo() + +Problem: [security]: heap buffer overflow in set_sofo() + (Yazan Balawneh) +Solution: Reset sl_sal_first (Yasuhiro Matsumoto). + +A crafted spell file with an empty SN_SAL section before an SN_SOFO +section reaches set_sofo() with sl_sal_first[] already set to -1 by +set_sal_first(). The counting loop then under-counts colliding +multi-byte "from" characters, allocates an undersized list and writes +past its end. + +Github Security Advisory: +https://github.com/vim/vim/security/advisories/GHSA-9jqx-hgpr-6v64 + +Signed-off-by: Yasuhiro Matsumoto +Signed-off-by: Christian Brabandt + +CVE: CVE-2026-73072 +Upstream-Status: Backport [https://github.com/vim/vim/commit/05c41c922309c7a11b6ec2f124be66551c90d66a] +Signed-off-by: Hitendra Prajapati +--- + src/spellfile.c | 4 +++- + src/testdir/test_spellfile.vim | 5 +++++ + 2 files changed, 8 insertions(+), 1 deletion(-) + +diff --git a/src/spellfile.c b/src/spellfile.c +index b3ee9c0d63..a9f7e83752 100644 +--- a/src/spellfile.c ++++ b/src/spellfile.c +@@ -1433,7 +1433,9 @@ set_sofo(slang_T *lp, char_u *from, char_u *to) + gap->ga_len = 256; + + // First count the number of items for each list. Temporarily use +- // sl_sal_first[] for this. ++ // sl_sal_first[] for this. Reset it first: a preceding SN_SAL section ++ // may have set the entries to -1 via set_sal_first(). ++ vim_memset(lp->sl_sal_first, 0, sizeof(salfirst_T) * 256); + for (p = from, s = to; *p != NUL && *s != NUL; ) + { + c = mb_cptr2char_adv(&p); +diff --git a/src/testdir/test_spellfile.vim b/src/testdir/test_spellfile.vim +index 3a93883b4d..0b0cf42066 100644 +--- a/src/testdir/test_spellfile.vim ++++ b/src/testdir/test_spellfile.vim +@@ -319,6 +319,11 @@ func Test_spellfile_format_error() + " SN_SOFO: multi-byte characters in sofofrom and sofoto + call Spellfile_Test(0z0600000000080002CF810002CF82FF000000000000000000000000, '') + ++ " SN_SAL (empty) followed by SN_SOFO with two multi-byte 'from' characters ++ " sharing the same low byte. A preceding SN_SAL poisons sl_sal_first[], so ++ " without a reset set_sofo() under-counts and writes out of bounds. ++ call Spellfile_Test(0z05000000000300000006000000000A0004CAABCEAB00024142FF000000000000000000000000, '') ++ + " SN_COMPOUND: compmax is less than 2 + call Spellfile_Test(0z08000000000101, 'E759:') + +-- +2.34.1 + diff --git a/meta/recipes-support/vim/vim.inc b/meta/recipes-support/vim/vim.inc index 1da47d92430..34d45079061 100644 --- a/meta/recipes-support/vim/vim.inc +++ b/meta/recipes-support/vim/vim.inc @@ -39,6 +39,7 @@ SRC_URI = "git://github.com/vim/vim.git;branch=master;protocol=https;tag=v${PV} file://CVE-2026-59856.patch \ file://CVE-2026-59857.patch \ file://CVE-2026-59858.patch \ + file://CVE-2026-73072.patch \ " PV .= ".0340" From patchwork Wed Sep 9 07:29:12 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 97678 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id D227BC88E44 for ; Wed, 9 Sep 2026 07:30:12 +0000 (UTC) Received: from mail-wr1-f42.google.com (mail-wr1-f42.google.com [209.85.221.42]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.6438.1788939002853215088 for ; Wed, 09 Sep 2026 00:30:03 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=KYAoea7A; spf=pass (domain: smile.fr, ip: 209.85.221.42, mailfrom: yoann.congal@smile.fr) Received: by mail-wr1-f42.google.com with SMTP id ffacd0b85a97d-4843f205a5bso3495820f8f.1 for ; Wed, 09 Sep 2026 00:30:02 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1788939001; x=1789543801; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=dyvG4cg3331EXUzv1T/fgXjmpd9UVWJ/1V6v+KRRmkw=; b=KYAoea7A6SNj2YPlaGN4UpXdBeH0b2dRzkqdzH1NR83KUlDVjJUyz1oqCW2/nZ8Cdt 4oC47YcpxFY4ZuQtTcX3O9djhLz/PvNqb4lygGxpEJ12FPn2wIPTzQxZuY/G+XhHVXws 6okln2+auxde2hTRutvEkP/1oiJBA+UgAnqC8= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1788939001; x=1789543801; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=dyvG4cg3331EXUzv1T/fgXjmpd9UVWJ/1V6v+KRRmkw=; b=oQoiEAfAxX92jvSSo+8lgQGyW8tZa1Pjabk6+Ux/sgNVZ6xJujq41/YyohBZAop4p0 Sikx4S//XreSVbrNoQp4sD5CavondFyPjd2njGPJTw7P8jKsknt5QB6/3jzLALHdOnEL NS8y68yHPXH++8q213UOHZN737t8TqZ43uVyz5OR+fKvEO/fVc/P6m4DW7TvpXLCSAjZ 4qgDnNAHIu4pjkNPmRKGf35eombfWPDKpXxajZca5VFJCcNZd3/p0IBvVpYMGjxjVHyV NqvzSmyjqoTnuNRwEhP//cLQ0fMsfpIU2jckgLB7DXpew1xT0uN9eYu5cSxQefO+Ouq6 ud0A== X-Gm-Message-State: AFuF++nyGdXuTDHZkXhG+PUltdLjL4nPk0B+QsgGNFGjOp+QGhy9kdM2 QRrfj1F86zf27hKPuYbJgGAvhC5jbjAJmGEQQZS06PwiW5MUD7FUNaSFAo5NME6aiLb3I+6WWky h/wMcP7o= X-Gm-Gg: AYBFou2LEsIMuNhHrbgWI4+quo1vz/basal8+/Hh3AssBKGqLSgPP7ybhK/taEnUgjo MBYJZqnqtOwI/Tztpwg6BNNd2fcdiiKu3q2GVt9xReLmPp+NwFv85GR+CJdgoSYrxRO8gn3CT8Y RHFU9Kp97ZBB2cHxfNo7GQHcYyNfc/U35F3zktuP1lFIFNvVyM3xw0S6+Mzslzs4ZwRDyinCTY1 apIenxcycW7R7YXYKmwpVLPPwTWGjzMZvWenaHlsb0HotuU6V6OCECRiHnu64moBd1loOoFUNzC okndWw01eIoVx+61Fq/h5OdMNS6MF1xDE8xLZPrvaLyrzOEgdRFL3qk2VE/YsnTL5qagRL66LbL v7IJUBvUs5A+loHQEeQox/gdzd0Xyuteq4koR9gujTRdAmkhlayupPqWWQ+7pr5StcbUX6eO2te a0vD+lRtqNYjlTqnBogx6A6Awd0suYmB+PyjEwKeVDqChPuKom5Svmo9v7TWfFizx5FslomWO+a PfPuw+Ftw5vbgybEhZD7dq5tS7C8vIyNFCrYLH6ol1/akYfk+xPEzQYxQbdT2xf3A1XoJQN53E= X-Received: by 2002:a05:6000:4816:b0:485:9bbc:ac72 with SMTP id ffacd0b85a97d-4859bbcb102mr18005110f8f.42.1788939001018; Wed, 09 Sep 2026 00:30:01 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-4858ac2b4cdsm40624310f8f.16.2026.09.09.00.30.00 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 09 Sep 2026 00:30:00 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][wrynose 13/38] vim: Fix for CVE-2026-73073 Date: Wed, 9 Sep 2026 09:29:12 +0200 Message-ID: <25fb2be661d8b6e26f6ef3b146ac9b7607be6114.1788938909.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Wed, 09 Sep 2026 07:30:12 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/245422 From: Hitendra Prajapati Pick the patch from [1], also referenced in the NVD report [2]. [1] https://github.com/vim/vim/commit/2f628d8104958fa7421664f792ca6d4f7a39a10f [2] https://nvd.nist.gov/vuln/detail/CVE-2026-73073 Signed-off-by: Hitendra Prajapati Signed-off-by: Yoann Congal --- .../vim/files/CVE-2026-73073.patch | 105 ++++++++++++++++++ meta/recipes-support/vim/vim.inc | 1 + 2 files changed, 106 insertions(+) create mode 100644 meta/recipes-support/vim/files/CVE-2026-73073.patch diff --git a/meta/recipes-support/vim/files/CVE-2026-73073.patch b/meta/recipes-support/vim/files/CVE-2026-73073.patch new file mode 100644 index 00000000000..5defa7339e6 --- /dev/null +++ b/meta/recipes-support/vim/files/CVE-2026-73073.patch @@ -0,0 +1,105 @@ +From 2f628d8104958fa7421664f792ca6d4f7a39a10f Mon Sep 17 00:00:00 2001 +From: Yasuhiro Matsumoto +Date: Fri, 17 Jul 2026 09:11:42 +0900 +Subject: [PATCH] patch 9.2.0845: [security]: arbitrary Ex command execution + during C omni-completion + +Problem: [security]: arbitrary Ex command execution during C + omni-completion (Threonine) +Solution: Match tags typeref literally to block Ex command injection + (Yasuhiro Matsumoto). + +Escaping only "/" and "\" left the typeref able to break out of the +:vimgrep pattern without a "/": an unclosed "[" makes vimgrep's pattern +skipping fail, and the parser then treats a following "|" as a command +separator, so the tag value runs as Ex commands during C omni-completion. +Match the field literally with \V so no regex metacharacter can affect +pattern parsing. + +Github Security Advisory: +https://github.com/vim/vim/security/advisories/GHSA-cx73-phcg-3j5g + +Signed-off-by: Yasuhiro Matsumoto +Signed-off-by: Christian Brabandt + +CVE: CVE-2026-73073 +Upstream-Status: Backport [https://github.com/vim/vim/commit/2f628d8104958fa7421664f792ca6d4f7a39a10f] +Signed-off-by: Hitendra Prajapati +--- + runtime/autoload/ccomplete.vim | 5 ++++- + src/testdir/test_plugin_ccomplete.vim | 26 ++++++++++++++++++++++++++ + src/version.c | 4 ++++ + 3 files changed, 34 insertions(+), 1 deletion(-) + +diff --git a/runtime/autoload/ccomplete.vim b/runtime/autoload/ccomplete.vim +index dc3388b524..593789a84f 100644 +--- a/runtime/autoload/ccomplete.vim ++++ b/runtime/autoload/ccomplete.vim +@@ -599,8 +599,11 @@ def StructMembers( # {{{1 + if complete_check() + return [] + endif ++ # Match "typename" literally (\V): escaping alone is not enough, as e.g. ++ # an unclosed "[" makes vimgrep's pattern skipping fail and the rest of ++ # the tag value is then parsed as Ex commands. + execute 'silent! keepjumps noautocmd ' +- .. n .. 'vimgrep ' .. '/\t' .. escape(typename, '/\') .. '\(\t\|$\)/j ' ++ .. n .. 'vimgrep ' .. '/\t\V' .. escape(typename, '/\') .. '\m\(\t\|$\)/j ' + .. fnames + + qflist = getqflist() +diff --git a/src/testdir/test_plugin_ccomplete.vim b/src/testdir/test_plugin_ccomplete.vim +index a635bd50bd..c1754d17c1 100644 +--- a/src/testdir/test_plugin_ccomplete.vim ++++ b/src/testdir/test_plugin_ccomplete.vim +@@ -31,6 +31,32 @@ func Test_ccomplete_no_exec_via_typeref() + unlet! g:ccomplete_injected + endfunc + ++" Escaping "/" and "\" is not enough: with no "/" in the payload, an unclosed ++" "[" makes vimgrep's pattern skipping fail, and the command parser then treats ++" the first "|" as a command separator. The typeref must be matched literally. ++func Test_ccomplete_no_exec_via_typeref_bracket() ++ CheckUnix ++ let sentinel = tempname() ++ call delete(sentinel) ++ let tagsfile = s:WriteTags([ ++ \ "myvar\tmain.c\t/^x$/;\"\tv\ttyperef:struct:[|call system('touch " .. sentinel .. "')|####", ++ \ ]) ++ ++ let save_tags = &tags ++ let &tags = tagsfile ++ ++ new ++ call ccomplete#Complete(1, '') ++ call ccomplete#Complete(0, 'myvar.x') ++ ++ call assert_false(filereadable(sentinel), ++ \ 'typeref field was executed as an Ex command during omni-completion') ++ ++ bwipe! ++ let &tags = save_tags ++ call delete(sentinel) ++endfunc ++ + " A legitimate typeref must still drive struct-member completion: escaping the + " field value must not break the normal path. + func Test_ccomplete_typeref_completion_still_works() +diff --git a/src/version.c b/src/version.c +index 92cd53129e..26e4e026c3 100644 +--- a/src/version.c ++++ b/src/version.c +@@ -734,6 +734,10 @@ static char *(features[]) = + + static int included_patches[] = + { /* Add new patch number below this line */ ++/**/ ++ 845, ++/**/ ++ 846, + /**/ + 736, + /**/ +-- +2.34.1 + diff --git a/meta/recipes-support/vim/vim.inc b/meta/recipes-support/vim/vim.inc index 34d45079061..7ab7a405ffc 100644 --- a/meta/recipes-support/vim/vim.inc +++ b/meta/recipes-support/vim/vim.inc @@ -40,6 +40,7 @@ SRC_URI = "git://github.com/vim/vim.git;branch=master;protocol=https;tag=v${PV} file://CVE-2026-59857.patch \ file://CVE-2026-59858.patch \ file://CVE-2026-73072.patch \ + file://CVE-2026-73073.patch \ " PV .= ".0340" From patchwork Wed Sep 9 07:29:13 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 97677 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 99847C88E40 for ; Wed, 9 Sep 2026 07:30:12 +0000 (UTC) Received: from mail-wm2-f12.google.com (mail-wm2-f12.google.com [74.125.225.140]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.6320.1788939003577747152 for ; Wed, 09 Sep 2026 00:30:03 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=xYz54KsS; spf=pass (domain: smile.fr, ip: 74.125.225.140, mailfrom: yoann.congal@smile.fr) Received: by mail-wm2-f12.google.com with SMTP id 5b1f17b1804b1-49cd38e0f79so3534715e9.3 for ; Wed, 09 Sep 2026 00:30:03 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1788939002; x=1789543802; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=n5hxVys31tLDYEmxaUOto3Rn05vlvRdVhLfAZRhySzo=; b=xYz54KsS83d+vXvhliY/kJeGz4UDyF2DemVKjolj3PGHTfpym/CbL+rNZPPeAW3YQP fXbanAApyht1IzkM67gsnNVXVPo33dcqUa5RHqSNSnz5kn4uUkTLh+UGlQJ8egFnUliZ Os9mNw7I+my0YsLUBqr+pQiRr5EPuzPd5qq8c= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1788939002; x=1789543802; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=n5hxVys31tLDYEmxaUOto3Rn05vlvRdVhLfAZRhySzo=; b=azyW8Ms+coXGjgr6uf40rX2cYLpKG958cq/ng3d/QK+Zu3OD7Rhyk8+I+FNr62fZIJ TruHVB5dztcj0XyTo7H1hJFv28bGo4j9ORr7cGH6/ufPPROrHKUixMu039c6l3+46rAG lmCT9paUGjfUFvC9KAhGuKtztLEFxaAS/OgFIx6yudgKqPIBRbhzwjfT/KZ7m2OxAWAw YTzfOBufDyQTNK62hTn/u0Nou6XOewWMTDBvh2Kl75FvlN+flqMasLR4PO9IzjjzllRn R2u/zTl1qH9rSqDz6GPcMU/yJ8vYqWBxWPblGl0M6W/Gd0kAt4cqSFgv4KoFxnjhpX22 95bg== X-Gm-Message-State: AFuF++mM6KYvzJJyka4SUMBRlaK/Yz9KM6Y6mJZKq24Hz5ng/FCVWaIR 1dXvR9kMlPpcYXydZzPEUf5ZbhK3j5b2F1MPKC0iOv6U8nCSYtXAmkgCBxLnW9VyKaqtRq/HXwN DPd3ApXU= X-Gm-Gg: AYBFou2P5kK232gvxkS2o40QY2L/X3Y7kPu8b8ncJWs9taAUEehTwN/mHhbPg1auqXq NYl/d6SYixpZU1u51Np19iNTNrHqDbUXr/OhwrXQVynn/C05VGnOTrjAHI0C6x1C5pVvBn8Qhn3 D8W7gWaKGa55DZ4e7Ivyju4u6270iUCNcwuGB2sSMk50EKnYFG9OnZD0HcJzkTMKrn90Vlvim9c CEA3JJpZ8E2AZfR8GSJjMAs1Yd1pB3q5br6xtAoSCuMV6TkCfuGngLBi/c08DMXwPLHl0t5PLiI JW0WfKzYttdMcdK2Qs7vXGGq0aHxoWe+R0/g45+asbbyTRcPhwR4802apPpCb0JO6+9I8c2M9yZ WkBoatyRKiwsj2lDX2t95pPe9Lu0TNC6qfyizUlKTNpvfehvBqWM8dctsBIU7IO5WUc4uMPN41/ g0MzlOKLDHGAsTXl+3Aw3jZNOUmw0eYtKyBSraV2/mKjsXLNDnpQ45YfJTbuq1J7AyeSPkb4OIE PlHCMAIgyaYNpuUk+EYpmooPL1CaqeCOLP3dPR0+qe3ejwkVcGuh5S5QwZEWvUyVM+/Xn8OAxM= X-Received: by 2002:a05:600c:c178:b0:49d:870:7a69 with SMTP id 5b1f17b1804b1-49d1f362a92mr52773295e9.12.1788939001613; Wed, 09 Sep 2026 00:30:01 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-4858ac2b4cdsm40624310f8f.16.2026.09.09.00.30.01 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 09 Sep 2026 00:30:01 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][wrynose 14/38] vim: Fix for CVE-2026-73074 Date: Wed, 9 Sep 2026 09:29:13 +0200 Message-ID: <76bfbf7742275f21acd82535584615ca5ebd2902.1788938909.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Wed, 09 Sep 2026 07:30:12 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/245423 From: Hitendra Prajapati Pick the patch from [1], also referenced in the NVD report [2]. [1] https://github.com/vim/vim/commit/a9336b476fd1a182e3f79b5f83c0ffb04f8a922b [2] https://nvd.nist.gov/vuln/detail/CVE-2026-73074 Signed-off-by: Hitendra Prajapati Signed-off-by: Yoann Congal --- .../vim/files/CVE-2026-73074.patch | 115 ++++++++++++++++++ meta/recipes-support/vim/vim.inc | 1 + 2 files changed, 116 insertions(+) create mode 100644 meta/recipes-support/vim/files/CVE-2026-73074.patch diff --git a/meta/recipes-support/vim/files/CVE-2026-73074.patch b/meta/recipes-support/vim/files/CVE-2026-73074.patch new file mode 100644 index 00000000000..896298b7032 --- /dev/null +++ b/meta/recipes-support/vim/files/CVE-2026-73074.patch @@ -0,0 +1,115 @@ +From a9336b476fd1a182e3f79b5f83c0ffb04f8a922b Mon Sep 17 00:00:00 2001 +From: Yasuhiro Matsumoto +Date: Thu, 23 Jul 2026 20:14:13 +0000 +Subject: [PATCH] patch 9.2.0841: [security]: heap overflow when adding > 65535 + text properties + +Problem: [security]: heap overflow when adding > 65535 text properties + (Wang1rrr). +Solution: Verify that the number of text properties falls within the + limit (Yasuhiro Matsumoto). + +Github Security Advisory: +https://github.com/vim/vim/security/advisories/GHSA-hm4g-pjfx-m27j + +Signed-off-by: Yasuhiro Matsumoto +Signed-off-by: Christian Brabandt + +CVE: CVE-2026-73074 +Upstream-Status: Backport [https://github.com/vim/vim/commit/a9336b476fd1a182e3f79b5f83c0ffb04f8a922b] +Signed-off-by: Hitendra Prajapati +--- + src/errors.h | 4 ++++ + src/po/vim.pot | 3 +++ + src/testdir/test_textprop.vim | 18 ++++++++++++++++++ + src/textprop.c | 7 +++++++ + src/version.c | 2 ++ + 5 files changed, 34 insertions(+) + +diff --git a/src/errors.h b/src/errors.h +index 53e5b1dda6..1682c8587c 100644 +--- a/src/errors.h ++++ b/src/errors.h +@@ -3812,3 +3812,7 @@ EXTERN char e_gethostbyname_in_channel_listen[] + EXTERN char e_cannot_create_pipes[] + INIT(= N_("E1575: Cannot create pipes")); + #endif ++#ifdef FEAT_PROP_POPUP ++EXTERN char e_too_many_text_properties_on_a_single_line[] ++ INIT(= N_("E1580: Too many text properties on a single line")); ++#endif +diff --git a/src/po/vim.pot b/src/po/vim.pot +index b2e3b0f647..aed7d833cf 100644 +--- a/src/po/vim.pot ++++ b/src/po/vim.pot +@@ -8859,6 +8859,9 @@ msgstr "" + msgid "E1575: Cannot create pipes" + msgstr "" + ++msgid "E1580: Too many text properties on a single line" ++msgstr "" ++ + #. type of cmdline window or 0 + #. result of cmdline window or 0 + #. buffer of cmdline window or NULL +diff --git a/src/testdir/test_textprop.vim b/src/testdir/test_textprop.vim +index f94acfc97c..a293363a8a 100644 +--- a/src/testdir/test_textprop.vim ++++ b/src/testdir/test_textprop.vim +@@ -4907,4 +4907,22 @@ func Test_textprop_materialize_list() + call assert_equal([], prop_list(1, #{ids: 3->range()})) + endfunc + ++" Adding more than 65535 text properties to one line must be rejected instead ++" of wrapping the uint16_t property count and overflowing the allocation. ++func Test_prop_add_over_uint16_max() ++ CheckNotAsan ++ CheckNotValgrind ++ new ++ call setline(1, 'x') ++ call prop_type_add('overflow', {}) ++ for _ in range(0xffff) ++ call prop_add(1, 1, {'type': 'overflow', 'length': 0}) ++ endfor ++ call assert_equal(0xffff, prop_list(1)->len()) ++ call assert_fails("call prop_add(1, 1, {'type': 'overflow', 'length': 0})", 'E1580:') ++ call assert_equal(0xffff, prop_list(1)->len()) ++ call prop_type_delete('overflow') ++ bwipe! ++endfunc ++ + " vim: shiftwidth=2 sts=2 expandtab +diff --git a/src/textprop.c b/src/textprop.c +index 5959ecc45f..fe453244c1 100644 +--- a/src/textprop.c ++++ b/src/textprop.c +@@ -758,6 +758,13 @@ prop_add_one( + proplen = get_text_props(buf, lnum, &props, TRUE); + textlen = ml_get_buf_len(buf, lnum) + 1; + ++ // prop_count is a uint16_t; stop before proplen + 1 wraps to zero. ++ if (proplen >= 0xffff) ++ { ++ emsg(_(e_too_many_text_properties_on_a_single_line)); ++ goto theend; ++ } ++ + if (lnum == start_lnum) + col = start_col; + else +diff --git a/src/version.c b/src/version.c +index 26e4e026c3..2a056f9da5 100644 +--- a/src/version.c ++++ b/src/version.c +@@ -734,6 +734,8 @@ static char *(features[]) = + + static int included_patches[] = + { /* Add new patch number below this line */ ++/**/ ++ 841, + /**/ + 845, + /**/ +-- +2.34.1 + diff --git a/meta/recipes-support/vim/vim.inc b/meta/recipes-support/vim/vim.inc index 7ab7a405ffc..9dda2c0be55 100644 --- a/meta/recipes-support/vim/vim.inc +++ b/meta/recipes-support/vim/vim.inc @@ -41,6 +41,7 @@ SRC_URI = "git://github.com/vim/vim.git;branch=master;protocol=https;tag=v${PV} file://CVE-2026-59858.patch \ file://CVE-2026-73072.patch \ file://CVE-2026-73073.patch \ + file://CVE-2026-73074.patch \ " PV .= ".0340" From patchwork Wed Sep 9 07:29:14 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 97679 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id F2AA6C88E43 for ; Wed, 9 Sep 2026 07:30:12 +0000 (UTC) Received: from mail-wr1-f43.google.com (mail-wr1-f43.google.com [209.85.221.43]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.6321.1788939004278536346 for ; Wed, 09 Sep 2026 00:30:04 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=l6D2kLXp; spf=pass (domain: smile.fr, ip: 209.85.221.43, mailfrom: yoann.congal@smile.fr) Received: by mail-wr1-f43.google.com with SMTP id ffacd0b85a97d-48441a2ba14so4610104f8f.1 for ; Wed, 09 Sep 2026 00:30:04 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1788939002; x=1789543802; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=4FJqMTXToMhskUMnsWj4T0NzNhRv0TdrEX7bqpUkrO0=; b=l6D2kLXpMC8lrvk717KSTqis5PX+LRlyGE3K2Wc7E0ysM3azYnFNybUJYYfnvColgC glEqCQwfYlhOdwNbDc//o/tzvytAIvAknI0W+I3XsT0Wll+E7ubjDyMZ2xDgdOXB+vnZ iPH+ZhVgIIPKSzKbHiBqVSHEG95DaNihS57SE= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1788939002; x=1789543802; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=4FJqMTXToMhskUMnsWj4T0NzNhRv0TdrEX7bqpUkrO0=; b=gInkPwOsp8M1gmdHTP8vf9kwWSGkdk1XNWrYEu3ueqdxwJps/QOZY5jYCqWTkKt95M nCK/COAvPZQFj4HLrmWFN17fMOABnb5ILf0o05Q90k+uPEwIQRioc2eXejBb0UjQOyaD O35Ym3mKGGl0JRs/lCDiP0ye7iUAohaxJeeVykdJ/gRzJMSTnHgfHr3z2vu15aBZcPyj XUAbD95BrTNXtDo+ou2ggVAVsolx0Q9jJauwztCRwVDtSvx/nPhuRJkuESvnpjUDG5u4 E8fPwZQjeXWsyFcYhsanbg4Y5r1yaLcuLHoiLxH3NiNWW2KTQOk8fzKyZOlbVCiZM8o6 QMxg== X-Gm-Message-State: AFuF++kL5rgxjGq5KmDEEncrkK8BoC4Uuk0ND4vTxUZcRZ09ukOyVrjb w0yNUsh5r8U3RD3AtVF6tD+7Jt616n87hbg2ged2G3F/wil2TRdTkBYULEgflKsX13GEdT5jNcm agblPVt0= X-Gm-Gg: AYBFou1cfh5IVcJFQ2dpnO+IHXfhOAw2wwX5OTC/LTQCUI6mqW6NNth3dVvJrJKtmMK LuvAPzm3Ig4mQkm0dND0mIbvJlTt4cQuFYuAvvefNXnYBXdP9pbReTC8FNWAdj6/io5s61uUIIE /fD/OfGPpSxlZPjGZC9wjJrt1yeSLnUZvr6MQ174WHUIxKPyM2tSr2eUDgoNtyx0UC098NvQEtj XM5ShmXEAh9PX7+bLARwtWncuYA0qsC4AQ4i5p2QLZsBPetY1MUXKj8kqmktcqRAAjA0V9ltY3H dokmgQP3RvuiWQcyw4poF7JgafFJtkWRsky0VysgoconLC4UVpg6YyZnEGNmLchGD7M5BURaI1v KgQNGIkru1nsJK0T9AsR8Ait7MFtoOh9ukzUk/7DMdVK5yooPZHT7YYQ6nCDuZEa3jtf1T7PMPM C08swFo5oL+fIY48k1WOPftTe6xx3DhZrDvDcaX81J8iWLWJjKbJB+aWS/laTNq7iYPo1RxZGGZ t6IW6OjhSuTmHRLim4UTZDj5Lih4qkoSAGtHIGbKq76E3gEfpgSsbEOohdQCdldtD/BOPAxqS3j yPCjnjlssA== X-Received: by 2002:adf:e199:0:b0:485:8a46:7052 with SMTP id ffacd0b85a97d-4858a4671ffmr33046018f8f.36.1788939002323; Wed, 09 Sep 2026 00:30:02 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-4858ac2b4cdsm40624310f8f.16.2026.09.09.00.30.01 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 09 Sep 2026 00:30:01 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][wrynose 15/38] vim: Fix for CVE-2026-73076 Date: Wed, 9 Sep 2026 09:29:14 +0200 Message-ID: <0de4221b4a87e66966e0bcc98d4f42a1d6704a74.1788938909.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Wed, 09 Sep 2026 07:30:12 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/245424 From: Hitendra Prajapati Pick the patch from [1], also referenced in the NVD report [2]. [1] https://github.com/vim/vim/commit/581a2f3ac9c6f96a26324f6b2c8c11415fd0d452 [2] https://nvd.nist.gov/vuln/detail/CVE-2026-73076 Signed-off-by: Hitendra Prajapati Signed-off-by: Yoann Congal --- .../vim/files/CVE-2026-73076.patch | 167 ++++++++++++++++++ meta/recipes-support/vim/vim.inc | 1 + 2 files changed, 168 insertions(+) create mode 100644 meta/recipes-support/vim/files/CVE-2026-73076.patch diff --git a/meta/recipes-support/vim/files/CVE-2026-73076.patch b/meta/recipes-support/vim/files/CVE-2026-73076.patch new file mode 100644 index 00000000000..5f5c92b1681 --- /dev/null +++ b/meta/recipes-support/vim/files/CVE-2026-73076.patch @@ -0,0 +1,167 @@ +From 581a2f3ac9c6f96a26324f6b2c8c11415fd0d452 Mon Sep 17 00:00:00 2001 +From: Christian Brabandt +Date: Fri, 24 Jul 2026 17:43:51 +0200 +Subject: [PATCH] patch 9.2.0847: [security]: vimball: code execution via + .VimballRecord file + +Problem: [security]: vimball: code execution via .VimballRecord file + (tdjackey) +Solution: Forbid arbitrary commands, fix broken directory deletion code, + refactor code + +Github Security Advisory: +https://github.com/vim/vim/security/advisories/GHSA-r22p-fhw4-84p2 + +Signed-off-by: Christian Brabandt + +CVE: CVE-2026-73076 +Upstream-Status: Backport [https://github.com/vim/vim/commit/581a2f3ac9c6f96a26324f6b2c8c11415fd0d452] +Signed-off-by: Hitendra Prajapati +--- + runtime/autoload/vimball.vim | 50 ++++++++++++++++++++--------- + src/testdir/test_plugin_vimball.vim | 16 ++++++++- + 2 files changed, 50 insertions(+), 16 deletions(-) + +diff --git a/runtime/autoload/vimball.vim b/runtime/autoload/vimball.vim +index d661ded631..20ce55cd69 100644 +--- a/runtime/autoload/vimball.vim ++++ b/runtime/autoload/vimball.vim +@@ -20,9 +20,9 @@ if &cp || exists("g:loaded_vimball") + finish + endif + let g:loaded_vimball = "v37" +-if v:version < 704 ++if v:version < 900 + echohl WarningMsg +- echo "***warning*** this version of vimball needs vim 7.4" ++ echo "***warning*** this version of vimball needs vim 9.0" + echohl Normal + finish + endif +@@ -237,6 +237,12 @@ fun! vimball#Vimball(really,...) + bw! Vimball + call s:ChgDir(curdir) + return ++ elseif fname =~? '\%(^\|/\)\.VimballRecord$' ++ echomsg "(Vimball) Forbidding .VimballRecord filename, aborting..." ++ exe "tabn ".curtabnr ++ bw! Vimball ++ call s:ChgDir(curdir) ++ return + endif + + if a:really +@@ -264,7 +270,7 @@ fun! vimball#Vimball(really,...) + let fnamebuf = substitute(fnamebuf,'^.\{-}/\(.*\)$','\1','') + if !isdirectory(dirname) + call mkdir(dirname) +- call s:RecordInVar(home,"rmdir('".dirname."')") ++ call s:RecordDirInVar(dirname) + endif + endwhile + endif +@@ -295,7 +301,7 @@ fun! vimball#Vimball(really,...) + exe "silent w! ".fnameescape(fnamepath) + endif + echo "wrote ".fnameescape(fnamepath) +- call s:RecordInVar(home,"call delete('".fnamepath."')") ++ call s:RecordInVar(fnamepath) + endif + + " return to tab with vimball +@@ -394,10 +400,17 @@ fun! vimball#RmVimball(...) + endif + let s:VBRstring= substitute(exestring,'call delete(','','g') + let s:VBRstring= substitute(s:VBRstring,"[')]",'','g') +- sil! keepalt keepjumps exe exestring ++ let nr_files= 0 ++ for line in split(exestring, '|') ++ if line !~ '^call delete(''[^'']\{-}''\(,"d"\)\?)$' ++ echomsg "ignoring .VimballRecord entry: " line ++ else ++ sil! keepalt keepjumps exe line ++ let nr_files+= 1 ++ endif ++ endfor + sil! keepalt keepjumps d +- let exestring= strlen(substitute(exestring,'call delete(.\{-})|\=',"D","g")) +- echomsg "removed ".exestring." files" ++ echomsg "removed ".nr_files." files" + else + let s:VBRstring= '' + let curfile = substitute(curfile,'\.vmb','','') +@@ -539,13 +552,20 @@ fun! s:ChgDir(newdir) + endfun + + " --------------------------------------------------------------------- +-" s:RecordInVar: record a un-vimball command in the .VimballRecord file {{{2 +-fun! s:RecordInVar(home,cmd) ++" s:RecordInVar: record a un-vimball file deletion in the .VimballRecord file {{{2 ++fun! s:RecordInVar(file) + if !exists("s:recordfile") +- let s:recordfile= a:cmd +- else +- let s:recordfile= s:recordfile."|".a:cmd ++ let s:recordfile=[] ++ endif ++ call add(s:recordfile, $'call delete({string(a:file)})') ++endfun ++ ++" s:RecordDirInVar: record a un-vimball dir deletion in the .VimballRecord file {{{2 ++fun! s:RecordDirInVar(dir) ++ if !exists("s:recorddir") ++ let s:recorddir = [] + endif ++ call add(s:recorddir, $'call delete({string(a:dir)},"d")') + endfun + + " --------------------------------------------------------------------- +@@ -566,11 +586,11 @@ fun! s:RecordInFile(home) + setlocal ma + $ + if exists("s:recordfile") && exists("s:recorddir") +- let cmd= cmd.s:recordfile."|".s:recorddir ++ let cmd= cmd.join(s:recordfile, '|')."|".join(s:recorddir, '|') + elseif exists("s:recorddir") +- let cmd= cmd.s:recorddir ++ let cmd= cmd.join(s:recorddir, '|') + elseif exists("s:recordfile") +- let cmd= cmd.s:recordfile ++ let cmd= cmd.join(s:recordfile, '|') + else + return + endif +diff --git a/src/testdir/test_plugin_vimball.vim b/src/testdir/test_plugin_vimball.vim +index 2d5b4ba768..8025846694 100644 +--- a/src/testdir/test_plugin_vimball.vim ++++ b/src/testdir/test_plugin_vimball.vim +@@ -65,7 +65,7 @@ func Test_vimball_basic() + call assert_true(filereadable('.VimballRecord')) + let record = readfile('.VimballRecord') + call assert_equal(1, record->len()) +- call assert_match('^Xtest.vmb: rmdir.*call delete(', record[0]) ++ call assert_match('^Xtest.vmb: call delete(''.\{-}'')|call delete(''.\{-}'',"d")$', record[0]) + call s:teardown() + endfunc + +@@ -83,3 +83,17 @@ func Test_vimball_path_traversal() + call assert_false(filereadable('../XVimball/Xtest.txt')) + call s:teardown() + endfunc ++ ++func Test_vimball_VimballRecord_filenames() ++ call s:Mkvimball() ++ call delete('XVimball', 'rf') ++ sp Xtest.vmb ++ 4s#.*\ze\t#.VimballRecord# ++ so % ++ call feedkeys("\", "it") ++ ++ let mess = execute(':mess')->split('\n')[-1] ++ call assert_match('(Vimball) Forbidding .VimballRecord filename.* aborting\.\.\.', mess) ++ call assert_false(filereadable('.VimballRecord')) ++ call s:teardown() ++endfunc +-- +2.34.1 + diff --git a/meta/recipes-support/vim/vim.inc b/meta/recipes-support/vim/vim.inc index 9dda2c0be55..f0524ba7300 100644 --- a/meta/recipes-support/vim/vim.inc +++ b/meta/recipes-support/vim/vim.inc @@ -42,6 +42,7 @@ SRC_URI = "git://github.com/vim/vim.git;branch=master;protocol=https;tag=v${PV} file://CVE-2026-73072.patch \ file://CVE-2026-73073.patch \ file://CVE-2026-73074.patch \ + file://CVE-2026-73076.patch \ " PV .= ".0340" From patchwork Wed Sep 9 07:29:15 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 97670 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 1C054C79FB9 for ; Wed, 9 Sep 2026 07:30:12 +0000 (UTC) Received: from mail-wr2-f12.google.com (mail-wr2-f12.google.com [74.125.225.76]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.6440.1788939005096253676 for ; Wed, 09 Sep 2026 00:30:05 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=j0dIuz8Y; spf=pass (domain: smile.fr, ip: 74.125.225.76, mailfrom: yoann.congal@smile.fr) Received: by mail-wr2-f12.google.com with SMTP id ffacd0b85a97d-48449f62b93so702797f8f.0 for ; Wed, 09 Sep 2026 00:30:04 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1788939003; x=1789543803; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=Gq9CURPHggWNKvBI4dopVrOSTa1T6q7CvaufP0ISClA=; b=j0dIuz8YcndZ/hUV8sXxN4I0oCShLM6CTpQsuNsiOEG8TCYuiAsJ8Hzzjqe+GsM3G2 /VJmRpDCctgFZBWDJw3DUIsBM84t/lJgHi87dFAvtfO8YucmJxK87TtOFtewXUbSwpAc uqdsldDXLTPUOPOwFOuAk8Lqpcrx93xvrmfpQ= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1788939003; x=1789543803; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=Gq9CURPHggWNKvBI4dopVrOSTa1T6q7CvaufP0ISClA=; b=E5iG5lv3JDY5eyEa43bU/k4iwLWnDoizF0mPiHpJXQHj18Q/GmFrE8UO4EXnBiU8ku syot+8fZ6+Eofbbe+wkojy3HGYQydAs5iD58eLrERbkLBLuDPJULM6whZxzKkCh4ZcQz tZzJ7ljtWc0ymi7KR2kQBSxOy8rYVC3sthdwY8T5sDtJ7oQj/+mTyCwDEE0hwaEeHZ/i b6BVy+sPc+K8qHxaLjWO2huXT0dP78Tlrc7QsDils4mxkHASS6Dmd48aIo+BWRBz1YqA EkQnuUP3CrHZdLHL06+iJL7yYea1mtF4yKnv679vxi3RB+nwe3t9BWDJxT2P7XklyIKD kblA== X-Gm-Message-State: AFuF++l3qMGBhOOnGkmGsiVjFogYlbL4PkKcWT3P/unYXAGOGccgwr67 VvWGlfWaJGJbEB/e4TzYtiE7IjdyPgj9k+guO3zDkfn9iCWizJlAoHsNbk/pbsaSbKPITKuyCqT wGGqj6go= X-Gm-Gg: AYBFou3ChQlsAgxcasCEaWHIi9T4Q2yV4Vm+y39qFXin5VpNRbDANp72Iuv65BR/WZN 94SyDDZCSvSv9XuXYTHr7NrXqMLi+w1QX1TZmigTZa0azgFkCC/GJBiVhMlXiD9Lq6xrFiGdnbz LAvvLkJu//uZQoszqpfzNDBT7SEqxmGFQ54C7UsG3FYuwjD4BCyQj2Psfnpok7T0gbSTtytzosH 0fVxZyV7ZZrBm77N7hjdrEkTHHXu55WnMlSJL6kFaXeJ0RXmGSk3BslipzLlVcjDyjLUQ4b5HH1 v+WcdYO49ZXN7ZXPhh7nURMfZ2wdmmzatdwQTzEKsRXsqVma6HRiUILVztfkpEu84ZmHaGEYfZc tn0xKnPesSv2BAiPdC7THdjeojHAW9L2bl5lC78ROj/Wnk/ZmMa6NlHDV/L32IdBp/k0BF4K7zf DVb6JMIpghO4eul4fiUxq50iF+gZ47AiJ4Ebm6ks1YuKxzDrQtKEDtq20KKHc/XCpxe90PKr00R HV2pwLPoHrLRWlKkhDJX+RX8r7yfZNGSb9cOzbgXczs8tpntlETI1YGkMUhZNfgrXEgYyQGpQk= X-Received: by 2002:a5d:4b41:0:b0:485:8224:1a46 with SMTP id ffacd0b85a97d-485a2450ab4mr10229675f8f.23.1788939003247; Wed, 09 Sep 2026 00:30:03 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-4858ac2b4cdsm40624310f8f.16.2026.09.09.00.30.02 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 09 Sep 2026 00:30:02 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][wrynose 16/38] vim: Fix for CVE-2026-73077 Date: Wed, 9 Sep 2026 09:29:15 +0200 Message-ID: X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Wed, 09 Sep 2026 07:30:12 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/245425 From: Hitendra Prajapati Pick the patch from [1], also referenced in the NVD report [2]. [1] https://github.com/vim/vim/commit/c5a82fe013e73c98004ad7cd4f906b1ad1ed610e [2] https://nvd.nist.gov/vuln/detail/CVE-2026-73077 Signed-off-by: Hitendra Prajapati Signed-off-by: Yoann Congal --- .../vim/files/CVE-2026-73077.patch | 105 ++++++++++++++++++ meta/recipes-support/vim/vim.inc | 1 + 2 files changed, 106 insertions(+) create mode 100644 meta/recipes-support/vim/files/CVE-2026-73077.patch diff --git a/meta/recipes-support/vim/files/CVE-2026-73077.patch b/meta/recipes-support/vim/files/CVE-2026-73077.patch new file mode 100644 index 00000000000..41a9fdb1586 --- /dev/null +++ b/meta/recipes-support/vim/files/CVE-2026-73077.patch @@ -0,0 +1,105 @@ +From c5a82fe013e73c98004ad7cd4f906b1ad1ed610e Mon Sep 17 00:00:00 2001 +From: Yasuhiro Matsumoto +Date: Thu, 23 Jul 2026 19:13:15 +0000 +Subject: [PATCH] patch 9.2.0839: [security]: arbitrary code execution via + keyword lookup + +Problem: [security]: arbitrary code execution via keyword lookup in + sh.vim, zsh.vim and ps1.vim filetype plugin + (manus-use) +Solution: For powershell, quote the commands using single quotes, for + sh/zsh pass the argument as a separate list item to term_start()/system() + (Yasuhiro Matsumoto). + +Github Security Advisory: +https://github.com/vim/vim/security/advisories/GHSA-r5v6-q6j8-8qw2 + +Signed-off-by: Yasuhiro Matsumoto +Signed-off-by: Christian Brabandt + +CVE: CVE-2026-73077 +Upstream-Status: Backport [https://github.com/vim/vim/commit/c5a82fe013e73c98004ad7cd4f906b1ad1ed610e] +Signed-off-by: Hitendra Prajapati +--- + runtime/ftplugin/ps1.vim | 5 +++-- + runtime/ftplugin/sh.vim | 5 +++-- + runtime/ftplugin/zsh.vim | 8 ++++---- + 3 files changed, 10 insertions(+), 8 deletions(-) + +diff --git a/runtime/ftplugin/ps1.vim b/runtime/ftplugin/ps1.vim +index f1fe78df4c..9ff764a282 100644 +--- a/runtime/ftplugin/ps1.vim ++++ b/runtime/ftplugin/ps1.vim +@@ -6,6 +6,7 @@ + " 2024 May 23 by Riley Bruins ('commentstring') + " 2024 Sep 19 by Konfekt (simplify keywordprg #15696) + " 2025 Jul 22 by phanium (use :hor term #17822) ++" 2026 Jul 10 by Vim Project (quote K argument, prevent command injection) + + " Only do this when not done yet for this buffer + if exists("b:did_ftplugin") | finish | endif +@@ -52,9 +53,9 @@ endif + + if exists('s:pwsh_cmd') + if exists(':terminal') == 2 +- command! -buffer -nargs=1 GetHelp silent exe 'hor term ' . s:pwsh_cmd . ' -NoLogo -NoProfile -NonInteractive -ExecutionPolicy RemoteSigned -Command Get-Help -Full ""' . (executable('less') ? ' | less' : '') ++ command! -buffer -nargs=1 GetHelp call term_start([s:pwsh_cmd, '-NoLogo', '-NoProfile', '-NonInteractive', '-ExecutionPolicy', 'RemoteSigned', '-Command', "Get-Help -Full '" . substitute(, "'", "''", 'g') . "'" . (executable('less') ? ' | less' : '')]) + else +- command! -buffer -nargs=1 GetHelp echo system(s:pwsh_cmd . ' -NoLogo -NoProfile -NonInteractive -ExecutionPolicy RemoteSigned -Command Get-Help -Full ') ++ command! -buffer -nargs=1 GetHelp echo system([s:pwsh_cmd, '-NoLogo', '-NoProfile', '-NonInteractive', '-ExecutionPolicy', 'RemoteSigned', '-Command', "Get-Help -Full '" . substitute(, "'", "''", 'g') . "'"]) + endif + setlocal keywordprg=:GetHelp + let b:undo_ftplugin ..= " | setl kp< | sil! delc -buffer GetHelp" +diff --git a/runtime/ftplugin/sh.vim b/runtime/ftplugin/sh.vim +index 18cd219cdc..45e6f44fcf 100644 +--- a/runtime/ftplugin/sh.vim ++++ b/runtime/ftplugin/sh.vim +@@ -8,6 +8,7 @@ + " 2024 Dec 29 by Vim Project (improve setting shellcheck compiler) + " 2025 Mar 09 by Vim Project (set b:match_skip) + " 2025 Jul 22 by phanium (use :hor term #17822) ++" 2026 Jul 10 by Vim Project (pass K argument as a list, prevent shell injection) + + if exists("b:did_ftplugin") + finish +@@ -54,9 +55,9 @@ let s:is_kornshell = get(b:, "is_kornshell", get(g:, "is_kornshell", 0)) + + if s:is_bash + if exists(':terminal') == 2 +- command! -buffer -nargs=1 ShKeywordPrg silent exe ':hor term bash -c "help "" 2>/dev/null || man """' ++ command! -buffer -nargs=1 ShKeywordPrg call term_start(['bash', '-c', 'help "$1" 2>/dev/null || man "$1"', '--', ]) + else +- command! -buffer -nargs=1 ShKeywordPrg echo system('bash -c "help " 2>/dev/null || MANPAGER= man ""') ++ command! -buffer -nargs=1 ShKeywordPrg echo system(['bash', '-c', 'help "$1" 2>/dev/null || MANPAGER= man "$1"', '--', ]) + endif + setlocal keywordprg=:ShKeywordPrg + let b:undo_ftplugin ..= " | setl kp< | sil! delc -buffer ShKeywordPrg" +diff --git a/runtime/ftplugin/zsh.vim b/runtime/ftplugin/zsh.vim +index 850bef055c..8163585939 100644 +--- a/runtime/ftplugin/zsh.vim ++++ b/runtime/ftplugin/zsh.vim +@@ -2,7 +2,7 @@ + " Language: Zsh shell script + " Maintainer: Christian Brabandt + " Previous Maintainer: Nikolai Weibull +-" Latest Revision: 2025 Jul 23 ++" Latest Revision: 2026 Jul 23 + " License: Vim (see :h license) + " Repository: https://github.com/chrisbra/vim-zsh + +@@ -25,9 +25,9 @@ endif + + if executable('zsh') && &shell !~# '/\%(nologin\|false\)$' + if exists(':terminal') == 2 +- command! -buffer -nargs=1 ZshKeywordPrg silent exe ':hor :term zsh -c "autoload -Uz run-help; run-help "' +- else +- command! -buffer -nargs=1 ZshKeywordPrg echo system('MANPAGER= zsh -c "autoload -Uz run-help; run-help 2>/dev/null"') ++ command! -buffer -nargs=1 ZshKeywordPrg call term_start(['zsh', '-c', 'autoload -Uz run-help; run-help "$1"', '--', ]) ++ elseif has("patch-9.2.0250") ++ command! -buffer -nargs=1 ZshKeywordPrg echo system(['zsh', '-c', 'autoload -Uz run-help; MANPAGER= run-help "$1" 2>/dev/null', '--', ]) + endif + setlocal keywordprg=:ZshKeywordPrg + let b:undo_ftplugin .= '| setl keywordprg< | sil! delc -buffer ZshKeywordPrg' +-- +2.34.1 + diff --git a/meta/recipes-support/vim/vim.inc b/meta/recipes-support/vim/vim.inc index f0524ba7300..c132444040a 100644 --- a/meta/recipes-support/vim/vim.inc +++ b/meta/recipes-support/vim/vim.inc @@ -43,6 +43,7 @@ SRC_URI = "git://github.com/vim/vim.git;branch=master;protocol=https;tag=v${PV} file://CVE-2026-73073.patch \ file://CVE-2026-73074.patch \ file://CVE-2026-73076.patch \ + file://CVE-2026-73077.patch \ " PV .= ".0340" From patchwork Wed Sep 9 07:29:16 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 8bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 97671 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 6193EC79FBE for ; Wed, 9 Sep 2026 07:30:12 +0000 (UTC) Received: from mail-wr1-f41.google.com (mail-wr1-f41.google.com [209.85.221.41]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.6323.1788939005934420540 for ; Wed, 09 Sep 2026 00:30:06 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=BysmqlFP; spf=pass (domain: smile.fr, ip: 209.85.221.41, mailfrom: yoann.congal@smile.fr) Received: by mail-wr1-f41.google.com with SMTP id ffacd0b85a97d-485850cf499so3709356f8f.3 for ; Wed, 09 Sep 2026 00:30:05 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1788939004; x=1789543804; darn=lists.openembedded.org; h=content-transfer-encoding:content-type:mime-version:references :in-reply-to:message-id:date:subject:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=e4SqjNdYNF3UgyV0BvL531GgOYR48jRkirnJcvwQQYc=; b=BysmqlFPoEmLflib4ZZodtCI4A2tDSeSUkh9MQd6UdVKAQUt+PW0RCblzMbhShR5gT yqMLjQnGfuN2uCyG6tZ6A8lQ5fe/SeQtxSrTGtJVyfhwu4ijSja54otSKGb2yz6Knoyo CuyQWPr2hielqG8beqpB1B3qytAADON5km1D0= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1788939004; x=1789543804; h=content-transfer-encoding:content-type:mime-version:references :in-reply-to:message-id:date:subject:to:from:x-gm-gg :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to :content-type; bh=e4SqjNdYNF3UgyV0BvL531GgOYR48jRkirnJcvwQQYc=; b=bCIoeTFt4ChKqrMglpJhjLlvRPr/QmaIGvKqCsnod7IT+EqYJI93lsx4Z/KtVZlG2p RO4iByrCk8tb88OLN50436s2OFk3XkiuRnqwyz52lTLESszs6svaMnkvF2rU28YpZ1x6 HJ4TwvzHLv7aSd1ymexQBI265BKPFOzYP857e8EJw885GfrMnJ9hrurswNJEux9zRGkj cD6bFdWZSQglTL0RnjhIhQ6mHG5E0Hl7QjNCbvG9ciXE+O0WtVMx8VPBsMj7hXz3fT1x zwX9Eq5otf4kVSsk/D+XkjJkN9K8ajYo2XF8Y56WNd8AGX123WuA56OTl9X9ze8jPzqb 9sfg== X-Gm-Message-State: AFuF++ksTpBlTYVkKK2V1K+YQ3XracDJETjboR2mPu/zRWk33bAvLXOJ 81SFCwNwO0+GKlRmOQlO6rPpyQEUwZxxBdoDRtGTuvX9yr0RLVA8MGJcZadPsHdDXY2eAXzmgzA fy5Za1a0= X-Gm-Gg: AYBFou2Ag09gH7f3MyKuzzPj7tioIP6GiCyS1BNbYGQl8gdtYzoKtW4xflfmjdzVr4x ZTkPUsqMZ2fltNT5GMp+WjaRpuE7sBtJjuO9LEKFpoLzMhRg5KRkIy1hLLTE2pVqldeqEG9RXes GfftIM1w1YvnHN4UibgJUMzfliOqVPtfkEQpTW0QvJg2X5BmwmSzjfHxrc0omQZyUplO0x7wh3X KxupxW92vahsqXhnsmoiLwT7J2mEc8vJu+oPNGMBvg9gkacfsbVTqrRU1HvwfNlGoo7Pf5XQiCa /JVOlUhHNLKzRH55xJ4oigaWH7IzZhRZ6eAVA/iPtDGL9Ou/6KjwdFI/Udy5Rf/y/d3y1tH+JB2 pBqrIvYTSxE4aeuWTbknsja+1OxoPjL+t1ALxAflGD3gTCHkRVpUvgoDRiNhhlqUbbfExV99rfa 0Z3cB/pELz7fCuwQZN1dO+4PBF/eEXNSimW0I1dZrpteG7ka5nT8rdPvKD3jzGZGKlWSYWZulGq IWyRx6rUNNmZFIdWjyRtxwb649A5HJ6E5I7/UchChquLgTMeWIikhLUuA3uusttMG6VZhQdyp4= X-Received: by 2002:adf:fa81:0:b0:484:3317:a19 with SMTP id ffacd0b85a97d-485872b896dmr29799512f8f.26.1788939004070; Wed, 09 Sep 2026 00:30:04 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-4858ac2b4cdsm40624310f8f.16.2026.09.09.00.30.03 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 09 Sep 2026 00:30:03 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][wrynose 17/38] vim: Fix for CVE-2026-73078 Date: Wed, 9 Sep 2026 09:29:16 +0200 Message-ID: X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Wed, 09 Sep 2026 07:30:12 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/245426 From: Hitendra Prajapati Pick the patch from [1], also referenced in the NVD report [2]. [1] https://github.com/vim/vim/commit/29c6fd090d4520592f8be7d9ec81190edf25ef69 [2] https://nvd.nist.gov/vuln/detail/CVE-2026-73078 Signed-off-by: Hitendra Prajapati Signed-off-by: Yoann Congal --- .../vim/files/CVE-2026-73078.patch | 94 +++++++++++++++++++ meta/recipes-support/vim/vim.inc | 1 + 2 files changed, 95 insertions(+) create mode 100644 meta/recipes-support/vim/files/CVE-2026-73078.patch diff --git a/meta/recipes-support/vim/files/CVE-2026-73078.patch b/meta/recipes-support/vim/files/CVE-2026-73078.patch new file mode 100644 index 00000000000..62d156f5680 --- /dev/null +++ b/meta/recipes-support/vim/files/CVE-2026-73078.patch @@ -0,0 +1,94 @@ +From 29c6fd090d4520592f8be7d9ec81190edf25ef69 Mon Sep 17 00:00:00 2001 +From: Yasuhiro Matsumoto +Date: Mon, 6 Jul 2026 13:54:03 +0900 +Subject: [PATCH] patch 9.2.0840: [security]: code injection in netrw via + bookmarks + +Problem: [security]: code injection in netrw via bookmarks and history + (David Carliez) +Solution: Escape the '|' explicitly (Yasuhiro Matsumoto) + +The bookmark and history menu builders interpolate paths into :execute'd +:menu commands using g:netrw_menu_escape, which did not escape the Ex +command separator '|'. A crafted path could break out of the :menu command +and run arbitrary Ex/shell commands when the menu was built or triggered. + +Add '|' to g:netrw_menu_escape for the menu names, escape the :e right-hand +side with fnameescape(), and quote the netrw#MakeTgt() argument with +string() instead of raw single-quote interpolation. + +Github Security Advisory: +https://github.com/vim/vim/security/advisories/GHSA-rcr7-f3wr-22r2 + +Signed-off-by: Yasuhiro Matsumoto +Signed-off-by: Christian Brabandt + +CVE: CVE-2026-73078 +Upstream-Status: Backport [https://github.com/vim/vim/commit/29c6fd090d4520592f8be7d9ec81190edf25ef69] +Signed-off-by: Hitendra Prajapati +--- + runtime/pack/dist/opt/netrw/autoload/netrw.vim | 16 +++++++++------- + 1 file changed, 9 insertions(+), 7 deletions(-) + +diff --git a/runtime/pack/dist/opt/netrw/autoload/netrw.vim b/runtime/pack/dist/opt/netrw/autoload/netrw.vim +index d7eca30e45..c240bbd13f 100644 +--- a/runtime/pack/dist/opt/netrw/autoload/netrw.vim ++++ b/runtime/pack/dist/opt/netrw/autoload/netrw.vim +@@ -398,7 +398,7 @@ if has("win32") + else + call s:NetrwInit("g:netrw_glob_escape",'*[]?`{~$\') + endif +-call s:NetrwInit("g:netrw_menu_escape",'.&? \') ++call s:NetrwInit("g:netrw_menu_escape",'.&? \|') + call s:NetrwInit("s:netrw_map_escape","<|\n\r\\\\"") + if has("gui_running") && (&enc == 'utf-8' || &enc == 'utf-16' || &enc == 'ucs-4') + let s:treedepthstring= "│ " +@@ -3752,13 +3752,14 @@ function s:NetrwBookmarkMenu() + if exists("g:netrw_bookmarklist") && g:netrw_bookmarklist != [] && g:netrw_dirhistmax > 0 + let cnt= 1 + for bmd in g:netrw_bookmarklist +- let bmd= escape(bmd,g:netrw_menu_escape) ++ let ebmd= escape(bmd,g:netrw_menu_escape) ++ let fbmd= escape(fnameescape(bmd),'|') + + " show bookmarks for goto menu +- exe 'sil! menu '.g:NetrwMenuPriority.".2.".cnt." ".g:NetrwTopLvlMenu.'Bookmarks.'.bmd.' :e '.bmd."\" ++ exe 'sil! menu '.g:NetrwMenuPriority.".2.".cnt." ".g:NetrwTopLvlMenu.'Bookmarks.'.ebmd.' :e '.fbmd."\" + + " show bookmarks for deletion menu +- exe 'sil! menu '.g:NetrwMenuPriority.".8.2.".cnt." ".g:NetrwTopLvlMenu.'Bookmarks\ and\ History.Bookmark\ Delete.'.bmd.' '.cnt."mB" ++ exe 'sil! menu '.g:NetrwMenuPriority.".8.2.".cnt." ".g:NetrwTopLvlMenu.'Bookmarks\ and\ History.Bookmark\ Delete.'.ebmd.' '.cnt."mB" + let cnt= cnt + 1 + endfor + +@@ -3774,7 +3775,8 @@ function s:NetrwBookmarkMenu() + let priority = g:netrw_dirhistcnt + histcnt + if exists("g:netrw_dirhist_{cnt}") + let histdir= escape(g:netrw_dirhist_{cnt},g:netrw_menu_escape) +- exe 'sil! menu '.g:NetrwMenuPriority.".3.".priority." ".g:NetrwTopLvlMenu.'History.'.histdir.' :e '.histdir."\" ++ let ehistdir= escape(fnameescape(g:netrw_dirhist_{cnt}),'|') ++ exe 'sil! menu '.g:NetrwMenuPriority.".3.".priority." ".g:NetrwTopLvlMenu.'History.'.histdir.' :e '.ehistdir."\" + endif + let first = 0 + let cnt = ( cnt - 1 ) % g:netrw_dirhistmax +@@ -7119,7 +7121,7 @@ function s:NetrwTgtMenu() + let tgtdict[bmd]= cnt + let ebmd= escape(bmd,g:netrw_menu_escape) + " show bookmarks for goto menu +- exe 'sil! menu '.g:NetrwMenuPriority.".19.1.".cnt." ".g:NetrwTopLvlMenu.'Targets.'.ebmd." :call netrw#MakeTgt('".bmd."')\" ++ exe 'sil! menu '.g:NetrwMenuPriority.".19.1.".cnt." ".g:NetrwTopLvlMenu.'Targets.'.ebmd." :call netrw#MakeTgt(".escape(string(bmd),'|').")\" + let cnt= cnt + 1 + endfor + endif +@@ -7137,7 +7139,7 @@ function s:NetrwTgtMenu() + endif + let tgtdict[histentry] = histcnt + let ehistentry = escape(histentry,g:netrw_menu_escape) +- exe 'sil! menu '.g:NetrwMenuPriority.".19.2.".priority." ".g:NetrwTopLvlMenu.'Targets.'.ehistentry." :call netrw#MakeTgt('".histentry."')\" ++ exe 'sil! menu '.g:NetrwMenuPriority.".19.2.".priority." ".g:NetrwTopLvlMenu.'Targets.'.ehistentry." :call netrw#MakeTgt(".escape(string(histentry),'|').")\" + endif + let histcnt = histcnt + 1 + endwhile +-- +2.34.1 + diff --git a/meta/recipes-support/vim/vim.inc b/meta/recipes-support/vim/vim.inc index c132444040a..77f681410a9 100644 --- a/meta/recipes-support/vim/vim.inc +++ b/meta/recipes-support/vim/vim.inc @@ -44,6 +44,7 @@ SRC_URI = "git://github.com/vim/vim.git;branch=master;protocol=https;tag=v${PV} file://CVE-2026-73074.patch \ file://CVE-2026-73076.patch \ file://CVE-2026-73077.patch \ + file://CVE-2026-73078.patch \ " PV .= ".0340" From patchwork Wed Sep 9 07:29:17 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 97672 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 31B9BC79F8C for ; Wed, 9 Sep 2026 07:30:12 +0000 (UTC) Received: from mail-wr2-f12.google.com (mail-wr2-f12.google.com [74.125.225.76]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.6324.1788939006705575568 for ; Wed, 09 Sep 2026 00:30:07 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=ndRyPrlE; spf=pass (domain: smile.fr, ip: 74.125.225.76, mailfrom: yoann.congal@smile.fr) Received: by mail-wr2-f12.google.com with SMTP id ffacd0b85a97d-482f62ccdb1so659103f8f.1 for ; Wed, 09 Sep 2026 00:30:06 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1788939005; x=1789543805; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=bbArBX4HetqxVJjoJY154xuSgKYocpRWjv4fOr1V2M4=; b=ndRyPrlEQbCIOwsHIs/OJMjqqO3VKWtOvkLIrXI6hfs9M3RBrE2kGA8KtN1b0VGE0o S92/xEtcVyyB8Ia42+ll6M8Fh2T0vOsVaa5Vxepopli55wjlNAUbg0Ffm3EkjFS5Bf13 wXF2N/XTrk6J3jvfnmqVO3dPekKTA2HHBez8w= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1788939005; x=1789543805; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=bbArBX4HetqxVJjoJY154xuSgKYocpRWjv4fOr1V2M4=; b=ZAXTXn6qefFMwFJUF5eN1tMKuvtMPh+H2xrIPMj4vC//s+gu1cJXOuilGTKlbT3GLC S8cYKqv4oRJSCuDOop7aUOBHLvAbDhDwu50i7Y03m2G6CgZ4ueTKEjn2UQCyOSzIRxVV RD0BbHqVEaJ0Q9CoWaFMaMAlb3cEY8xV+rDQXKAs9zmE0zzyvdSZ4lfUkMm/ny+nA7Ti 7VbRlq1vHV9W9hV68JW6wFbth/LmMjQDZG1TjylcHiPZ/Ta4uGEznav5wkAhIbvtJOV4 W1x9onVxv5Xtme55kVdcWTPTuXSjtHM5ZxlxtoTlHkbEV8zrEFibAuC66vHVZH+WKbHU BXwg== X-Gm-Message-State: AFuF++kx4UlPHMu8LnuMeCufPEx9yg7bHDXziMNvjoxJN8amvobyflPn AAlpNqtJbozzleGuwkCQPh6+eqXQ0V38vVk4JfTP6cP/VlVhrvTznc5gupjHVNLgLrBfUmp9Vu8 PxvvUb8M= X-Gm-Gg: AYBFou3l6dNZ45iUamUaIcHBO+tv3hzjTBUN0HMoxhXj/Sxcd8dNuJk4szTVmn+4HLO IkVJdogFlJe6y7E1SAw52dzJkrU2FGtsB3YLBp/VmkAa760xwSaWBo/Lv2vML7ratVrJyLQJUo9 ehB9hJKzDHG6OKuItbJJFaxTy25EnjDL0/fEF3ou+UF9Bx0nz41YImNJ96w3K1le/HWJT0A8o6X knIfscwVnTU4ma2z+2irodzXkR4hP97sjhw42/XADrcntzY6ipjU7Qu/EXG1SIgN6XkYMdBZoOC VyCYlnTI/UC4vJlPI+jjTSkJEHawtuUtBkdm3cI3SPC6SsfTWQcfIedI6J3Di4et2F35crlCfKn Sl/c+5ya1as8/3bsxyKoPjgOTiuSzZlhaCxDd7SB5AS5KcHs0vJ/oh5J+J6a6YQW3e5kjukpfrC nImcpI7POCJLuoa6hAjspw9GWiHDfcCsbo+UFbtm9fK08si3RJhd3xY4iPMm1Dbn5FkC96WP5qF rZ3yPIjoosWQFl0WOFbFGqy9WY7icRcHGBGbthge4tLp9KCkr75i1nJNwNwXAn3JQ54hCB7+qk= X-Received: by 2002:adf:e007:0:10b0:484:42d7:50fe with SMTP id ffacd0b85a97d-485a23c686amr10005417f8f.4.1788939004863; Wed, 09 Sep 2026 00:30:04 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-4858ac2b4cdsm40624310f8f.16.2026.09.09.00.30.04 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 09 Sep 2026 00:30:04 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][wrynose 18/38] improve_kernel_cve_report: fix backported-patch check Date: Wed, 9 Sep 2026 09:29:17 +0200 Message-ID: X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Wed, 09 Sep 2026 07:30:12 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/245427 From: Hiago De Franco The guard added in 80ff4903ea tests "detail" in cve_data, but cve_data is keyed by CVE id, so it asks whether a CVE literally named "detail" was scanned. That is never true, the condition short-circuits, and the guard never runs: a CVE_STATUS[CVE-...] = "backported-patch" set for a vendor cherry-picked patch is silently overwritten to Unpatched by the CNA. Use .get() on the entry instead. Guard the fallthrough warning the same way, it makes the same assumption. Tested against a qemuarm64 linux-yocto report (6.6.142+git, 16221 entries, 4313 of them with no detail). Current master and this version produce identical output, 18773 entries with no difference. Adding CVE_STATUS[CVE-2024-42067] = "backported-patch" to that report then makes the only difference between them: master overwrites it to Unpatched, this version keeps it Patched. The pre-80ff4903ea code aborts on the same report with "KeyError: 'detail'". (cherry picked from commit f5da16b0d3c8f889dab061ba1d8808aba95d4c67) AI-Generated: Uses Claude (claude-opus-5) Fixes: 80ff4903ea1b ("improve_kernel_cve_report: validate that cve details field exists") Signed-off-by: Hiago De Franco Signed-off-by: Richard Purdie Signed-off-by: Yoann Congal --- scripts/contrib/improve_kernel_cve_report.py | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/scripts/contrib/improve_kernel_cve_report.py b/scripts/contrib/improve_kernel_cve_report.py index b386c9383a7..f0e471be459 100755 --- a/scripts/contrib/improve_kernel_cve_report.py +++ b/scripts/contrib/improve_kernel_cve_report.py @@ -363,7 +363,7 @@ def cve_update(cve_data, cve, entry): if entry['status'] == "Unpatched" and cve_data[cve]['status'] == "Patched": # Backported-patch (e.g. vendor kernel repo with cherry-picked CVE patch) # has priority over unpatch from CNA - if "detail" in cve_data and cve_data[cve]['detail'] == "backported-patch": + if cve_data[cve].get('detail') == "backported-patch": return logging.warning("CVE entry %s update from Patched to Unpatched from the scan result", cve) cve_data[cve] = copy_data(cve_data[cve], entry) @@ -382,7 +382,7 @@ def cve_update(cve_data, cve, entry): logging.debug("CVE entry %s updated from Unpatched to Ignored", cve) return logging.warning("Unhandled CVE entry update for %s %s from %s %s to %s", - cve, cve_data[cve]['status'], cve_data[cve]['detail'], entry['status'], entry['detail']) + cve, cve_data[cve]['status'], cve_data[cve].get('detail'), entry['status'], entry['detail']) def main(): parser = argparse.ArgumentParser( From patchwork Wed Sep 9 07:29:18 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 97674 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 8BEA5C79FBF for ; Wed, 9 Sep 2026 07:30:12 +0000 (UTC) Received: from mail-wr1-f51.google.com (mail-wr1-f51.google.com [209.85.221.51]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.6325.1788939007983452348 for ; Wed, 09 Sep 2026 00:30:08 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=T1xM7B6K; spf=pass (domain: smile.fr, ip: 209.85.221.51, mailfrom: yoann.congal@smile.fr) Received: by mail-wr1-f51.google.com with SMTP id ffacd0b85a97d-4858303de5dso6695489f8f.2 for ; Wed, 09 Sep 2026 00:30:07 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1788939006; x=1789543806; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=XJ24NKopBZqiOLYLpAUAjxnFL30tptHcStQ4QE3Y5go=; b=T1xM7B6KQZQwAqVn9TcmsXOSNV3Hrnp5iOCN4tTEwFG/bvnJw7wSU10uoG0pkQzDz/ 9xDA2h3keGNMmeDmRguq8u+x4lB4yLV0jP6VmLTpLnNywRPUvGojz47+OreiDxMNAgco bJ7O+iG6Yy0X0XWIaYMxfu1LTNnU/yzqeZu5o= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1788939006; x=1789543806; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=XJ24NKopBZqiOLYLpAUAjxnFL30tptHcStQ4QE3Y5go=; b=Gun7QrU2y614Hj/7Zdbz8OmQreMTNUEiOpCUI2G0EnjX5IzM66BKGbomzEsxKvtpNH XsLkoDeU4u+PXbNyW94pudvWSZSv/8FUrRIaqk+75gjsEUe9paN3DUQG3KRyXCS0rSHe +2+fIOrmxOjjTZno8CinphccBeGxNK8/ta5JbnD6aCs/GPx2cWPKHIP9k9xrqm8MD6nK 7PF28lDrZKvcQvNyA1GPKAQXOZBQUg+ZCJB0n3uMdLiLUS01zUEpP77YL8Mskhkp51fz blt8P06eXNqpn/OAvr+OAc59JgMrfPPFoK6yDA0HEf665F3hR0K0O+q6vOc500lwOeqs 6vBA== X-Gm-Message-State: AFuF++lR5Vy6qjI1MYGLtLvWtdl8YnWGyzHUrLuzF5DbOOMzE5X+TSwT ws5IgOwzvMUxT5QkS6ln5foY271M5PXZ48xR0wJutmcvXBH8mFZrL328M/SG7dtOblvG8uDx8tP WnHXkNzI= X-Gm-Gg: AYBFou2o00TqvJRab26Amiwc0NFBDYQ4XUp5dxotTLBhsVAVPDnydvSgIBWDcXIp3Ws pKnd9zZ/INwVVrzfolKdg80IGQAMA6Xan8hDAjXb3VZI5Pv1sFHcPBsfPxfpTwdjM/jYjyBQYOG 32RkbYEJvLo/1dMKvuhxrj+i/uO0bGx6qAzCOy00O7yd0deN+T9rJu0y1m9LXZSTNFtdk6SPQgK rxyX2ndjT7g4TYwslW5G1k39QgwXB7ZTPaSvO1R1+TmjCKP9ojm2ac8ytHXWlYyaXhAsLYjS7eK nH+f33ZwI5fL9VY+/yjDXba91A7d0xGpxzMHuQaRezd8wuluM0jD+jF4PmPEzhG84wqBvyIZoEC xb5rZ9gk/VQEYSbk3B4U5fEA1uoqoZb9+1/fCYJ6saVKC4jmhK2mn6lCkuL2bV4ts+zZOxgZGRx Kdif3Ly8WtFZV2DlUIownLWQVjlFf5ySAP0STzhGxpmHzhNzf41lJ8YotXlnVb7VZsIvry2+II5 nfjcNzG3ecWnIxy8rKNxFB+c6yVCMfeqkxBELV9KmYx+TVUNlx5Xt2Ycg/SEaIiJccLVM3n5ns= X-Received: by 2002:a05:6000:1a8d:b0:485:8c16:a32f with SMTP id ffacd0b85a97d-4858c16a6cemr31128044f8f.36.1788939006123; Wed, 09 Sep 2026 00:30:06 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-4858ac2b4cdsm40624310f8f.16.2026.09.09.00.30.05 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 09 Sep 2026 00:30:05 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][wrynose 19/38] p11-kit: upgrade 0.26.4 -> 0.26.5 Date: Wed, 9 Sep 2026 09:29:18 +0200 Message-ID: X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Wed, 09 Sep 2026 07:30:12 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/245428 From: Jaipaul Cheernam ChangeLog: https://github.com/p11-glue/p11-kit/releases/tag/0.26.5 0.26.5 (stable) * rpc: guard against overflow when decoding nested attributes (CVE-2026-18938) [PR#777] Signed-off-by: Jaipaul Cheernam Signed-off-by: Richard Purdie (cherry picked from commit 21a2c91ccca5257ede8994d30460b0dcda617c3a) Signed-off-by: Vijay Anusuri Signed-off-by: Yoann Congal --- .../p11-kit/{p11-kit_0.26.4.bb => p11-kit_0.26.5.bb} | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) rename meta/recipes-support/p11-kit/{p11-kit_0.26.4.bb => p11-kit_0.26.5.bb} (97%) diff --git a/meta/recipes-support/p11-kit/p11-kit_0.26.4.bb b/meta/recipes-support/p11-kit/p11-kit_0.26.5.bb similarity index 97% rename from meta/recipes-support/p11-kit/p11-kit_0.26.4.bb rename to meta/recipes-support/p11-kit/p11-kit_0.26.5.bb index fde122d3ca5..423c751307b 100644 --- a/meta/recipes-support/p11-kit/p11-kit_0.26.4.bb +++ b/meta/recipes-support/p11-kit/p11-kit_0.26.5.bb @@ -12,7 +12,7 @@ DEPENDS:append = "${@' glib-2.0' if d.getVar('GTKDOC_ENABLED') == 'True' else '' SRC_URI = "gitsm://github.com/p11-glue/p11-kit;branch=master;protocol=https;tag=${PV} \ " -SRCREV = "a14788849d1ef44422d679534a13821eab5bb5f4" +SRCREV = "120050e353e8f43d7c40bbcc047f667f903f4de5" PACKAGECONFIG ??= "" PACKAGECONFIG[manpages] = "-Dman=true,-Dman=false,libxslt-native" From patchwork Wed Sep 9 07:29:19 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 97682 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 1C005C79FB8 for ; Wed, 9 Sep 2026 07:30:12 +0000 (UTC) Received: from mail-wr1-f42.google.com (mail-wr1-f42.google.com [209.85.221.42]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.6443.1788939009290411048 for ; Wed, 09 Sep 2026 00:30:09 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=IJsVaSyf; spf=pass (domain: smile.fr, ip: 209.85.221.42, mailfrom: yoann.congal@smile.fr) Received: by mail-wr1-f42.google.com with SMTP id ffacd0b85a97d-4843f205a5bso3495957f8f.1 for ; Wed, 09 Sep 2026 00:30:09 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1788939007; x=1789543807; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=5m1oOCMLtzGGcNBbLHEBjCo/d3vcbBuAdYu5HYumcDI=; b=IJsVaSyf9Y45v9TUd2QvzkNoKEm0HHWf6I+d+Eizx8hOH4ERB4J3gvSAz2nK7xX+rw ojfV+2dEbEbbNGSIBBmU+Qe/5bH8DaTlvoz6UJX277nT30wGHUZ1ZvpcUQrvRcwl48zf 00R7Wbq+3vrEPZqKUcxl8pVPlal+Hh3p7rFAY= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1788939007; x=1789543807; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=5m1oOCMLtzGGcNBbLHEBjCo/d3vcbBuAdYu5HYumcDI=; b=QbKbn2O1037/6qCqzN99lUh/ZMkJMvWb+REKs3IF5EBV41yEKdqYv6/wDreI9w/3Hp O7wKlleCOsED5I8L2uZpcHPA8COxB6bNV78zTjG7m6APQnlP2MkUZdzA6M6Xrb813DUJ 145NlTp2M5WLtnCAU9I5f6ZlhyKun9dy9tyochmv0EEQ8kIerKmhZoEMa/zJt+tdnBmD Zl6uonfAJ5mCEtL8NWhSvkKYT3cq1aCb8PUGwy6jAOzyX1/DQg1rkv3fMi14wSzs6kK+ 2aBAdMhbFeBgfcGthv5olnLe0eyespaHqgl8FFTjdUMUgleRdQslS4Zw9QI2ZV7sNnmv cdlA== X-Gm-Message-State: AFuF++l1q/+4EcWk+xvd/dRcPr/554zhDjesIl16zNTWzDcd5dP9nYUB GqU0qnJxm+MYcs1xO+yeb1vrVzGHYGRH8w/htqLwrERRS7tcS1gzrcOhojWBXrxR3Bf9cZjQGy9 xv3GqL8k= X-Gm-Gg: AYBFou2E3b9V/ooVSR+brlUuiNABMlKz7VSdh1dWnkOUVrcbMZO6NOLAGoAPQnvLLF/ /QeW8oRyeXA6xnfC+LJWcXtPpwVKe8zZAUXugDNtOuAJxewd7C2zvx3CEtsazM8qKjQQS9sFBRk cUW0CmrDJSKXwk9aHebUYv/CWLg72sgS0wspROqyyZ2JsBgTOk8bTYlWlKo2+Nbgf1fvTdXqQ7u 38OTMUqq9xw9fxeFbXqDQIg8GwACVgH5zncn4XLU2ikZa4YpGjJZYBkPNYE+Ccyy1bSM9Tb4BuX 0dkdI4QS9CuOdATUqvvJTqN8MPvmaTo78+Qu2n4lENPmEPm6VmIm6jgbdg4ecxqBn0m8UzMtyr9 6E3GnyPQenHcYXLUf1dC0g/8r53fEi6gZwEG+Ue/dU1jOmG0buWc1HiDKO5Hc0JuHHJwf3DwVpL MZ4FkXFIKtCyBs9PL4M9iutoCnepcmslSlLuJGQruhIJ4ZzlQ2v77D6ODwXVtZQObgSN+2zYEuC x53aAiGEZzuvfeTMUiS5JfW0M61Bbs+kUc6uGJRisiftVHByotpXnsBlIEAJ1tIlt666tDfJzA= X-Received: by 2002:a05:6000:490e:b0:485:8a46:b3bc with SMTP id ffacd0b85a97d-4858a46b4b8mr33437005f8f.36.1788939007021; Wed, 09 Sep 2026 00:30:07 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-4858ac2b4cdsm40624310f8f.16.2026.09.09.00.30.06 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 09 Sep 2026 00:30:06 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][wrynose 20/38] python3-lxml: fix CVE-2026-41066 Date: Wed, 9 Sep 2026 09:29:19 +0200 Message-ID: X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Wed, 09 Sep 2026 07:30:12 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/245429 From: Darsh Kelaiya This patch applies the upstream fix as referenced in [2], using the commit shown in [1]. [1] https://github.com/lxml/lxml/commit/ab431ea0b9a7357d968f1d1c5c614649e9aaf358 [2] https://github.com/lxml/lxml/security/advisories/GHSA-vfmq-68hx-4jfw Signed-off-by: Darsh Kelaiya Signed-off-by: Yoann Congal --- .../python/python3-lxml/CVE-2026-41066.patch | 349 ++++++++++++++++++ .../python/python3-lxml_6.0.2.bb | 4 +- 2 files changed, 352 insertions(+), 1 deletion(-) create mode 100644 meta/recipes-devtools/python/python3-lxml/CVE-2026-41066.patch diff --git a/meta/recipes-devtools/python/python3-lxml/CVE-2026-41066.patch b/meta/recipes-devtools/python/python3-lxml/CVE-2026-41066.patch new file mode 100644 index 00000000000..b1a6f6629d3 --- /dev/null +++ b/meta/recipes-devtools/python/python3-lxml/CVE-2026-41066.patch @@ -0,0 +1,349 @@ +From 3a79355229f58e0fe51371385102dd7577bbfb26 Mon Sep 17 00:00:00 2001 +From: Stefan Behnel +Date: Fri, 10 Apr 2026 10:13:03 +0200 +Subject: [PATCH] LP#2146291: Set "resolve_entities='internal'" as default for + all parser subclasses. + +CVE: CVE-2026-41066 +Upstream-Status: Backport [https://github.com/lxml/lxml/commit/ab431ea0b9a7357d968f1d1c5c614649e9aaf358] + +Backport Changes: +- Reformat the iterparse signature and resolve_entities documentation + without semantic changes, preserving line numbers to avoid generated + source-location churn. +- Regenerate src/lxml/etree.c with Cython 3.1.4, matching the version + recorded in the shipped file, using + "python setup.py build_ext -i --with-cython". +- Restore the shipped Cython metadata field order and omit + the environment-only "-w" compiler flag to avoid unrelated + generated changes. + +(cherry picked from commit ab431ea0b9a7357d968f1d1c5c614649e9aaf358) +Signed-off-by: Darsh Kelaiya +--- + src/lxml/etree.c | 60 +++++++++++++++++++++--------------------- + src/lxml/iterparse.pxi | 10 +++---- + src/lxml/parser.pxi | 6 ++--- + 3 files changed, 38 insertions(+), 38 deletions(-) + +diff --git a/src/lxml/etree.c b/src/lxml/etree.c +index 29553531..f2208e43 100644 +--- a/src/lxml/etree.c ++++ b/src/lxml/etree.c +@@ -147986,7 +147986,7 @@ static int __pyx_pw_4lxml_5etree_17ETCompatXMLParser_1__init__(PyObject *__pyx_v + * def __init__(self, *, encoding=None, attribute_defaults=False, + * dtd_validation=False, load_dtd=False, no_network=True, decompress=False, # <<<<<<<<<<<<<< + * ns_clean=False, recover=False, schema=None, +- * huge_tree=False, remove_blank_text=False, resolve_entities=True, ++ * huge_tree=False, remove_blank_text=False, resolve_entities='internal', + */ + if (!values[2]) values[2] = __Pyx_NewRef(((PyObject *)Py_False)); + if (!values[3]) values[3] = __Pyx_NewRef(((PyObject *)Py_False)); +@@ -147997,7 +147997,7 @@ static int __pyx_pw_4lxml_5etree_17ETCompatXMLParser_1__init__(PyObject *__pyx_v + * def __init__(self, *, encoding=None, attribute_defaults=False, + * dtd_validation=False, load_dtd=False, no_network=True, decompress=False, + * ns_clean=False, recover=False, schema=None, # <<<<<<<<<<<<<< +- * huge_tree=False, remove_blank_text=False, resolve_entities=True, ++ * huge_tree=False, remove_blank_text=False, resolve_entities='internal', + * remove_comments=True, remove_pis=True, strip_cdata=True, + */ + if (!values[6]) values[6] = __Pyx_NewRef(((PyObject *)Py_False)); +@@ -148007,17 +148007,17 @@ static int __pyx_pw_4lxml_5etree_17ETCompatXMLParser_1__init__(PyObject *__pyx_v + /* "src/lxml/parser.pxi":1734 + * dtd_validation=False, load_dtd=False, no_network=True, decompress=False, + * ns_clean=False, recover=False, schema=None, +- * huge_tree=False, remove_blank_text=False, resolve_entities=True, # <<<<<<<<<<<<<< ++ * huge_tree=False, remove_blank_text=False, resolve_entities='internal', # <<<<<<<<<<<<<< + * remove_comments=True, remove_pis=True, strip_cdata=True, + * target=None, compact=True): + */ + if (!values[9]) values[9] = __Pyx_NewRef(((PyObject *)Py_False)); + if (!values[10]) values[10] = __Pyx_NewRef(((PyObject *)Py_False)); +- if (!values[11]) values[11] = __Pyx_NewRef(((PyObject *)Py_True)); ++ if (!values[11]) values[11] = __Pyx_NewRef(((PyObject *)__pyx_mstate_global->__pyx_n_u_internal)); + + /* "src/lxml/parser.pxi":1735 + * ns_clean=False, recover=False, schema=None, +- * huge_tree=False, remove_blank_text=False, resolve_entities=True, ++ * huge_tree=False, remove_blank_text=False, resolve_entities='internal', + * remove_comments=True, remove_pis=True, strip_cdata=True, # <<<<<<<<<<<<<< + * target=None, compact=True): + * XMLParser.__init__(self, +@@ -148027,7 +148027,7 @@ static int __pyx_pw_4lxml_5etree_17ETCompatXMLParser_1__init__(PyObject *__pyx_v + if (!values[14]) values[14] = __Pyx_NewRef(((PyObject *)Py_True)); + + /* "src/lxml/parser.pxi":1736 +- * huge_tree=False, remove_blank_text=False, resolve_entities=True, ++ * huge_tree=False, remove_blank_text=False, resolve_entities='internal', + * remove_comments=True, remove_pis=True, strip_cdata=True, + * target=None, compact=True): # <<<<<<<<<<<<<< + * XMLParser.__init__(self, +@@ -148054,7 +148054,7 @@ static int __pyx_pw_4lxml_5etree_17ETCompatXMLParser_1__init__(PyObject *__pyx_v + * def __init__(self, *, encoding=None, attribute_defaults=False, + * dtd_validation=False, load_dtd=False, no_network=True, decompress=False, # <<<<<<<<<<<<<< + * ns_clean=False, recover=False, schema=None, +- * huge_tree=False, remove_blank_text=False, resolve_entities=True, ++ * huge_tree=False, remove_blank_text=False, resolve_entities='internal', + */ + if (!values[2]) values[2] = __Pyx_NewRef(((PyObject *)Py_False)); + if (!values[3]) values[3] = __Pyx_NewRef(((PyObject *)Py_False)); +@@ -148065,7 +148065,7 @@ static int __pyx_pw_4lxml_5etree_17ETCompatXMLParser_1__init__(PyObject *__pyx_v + * def __init__(self, *, encoding=None, attribute_defaults=False, + * dtd_validation=False, load_dtd=False, no_network=True, decompress=False, + * ns_clean=False, recover=False, schema=None, # <<<<<<<<<<<<<< +- * huge_tree=False, remove_blank_text=False, resolve_entities=True, ++ * huge_tree=False, remove_blank_text=False, resolve_entities='internal', + * remove_comments=True, remove_pis=True, strip_cdata=True, + */ + if (!values[6]) values[6] = __Pyx_NewRef(((PyObject *)Py_False)); +@@ -148075,17 +148075,17 @@ static int __pyx_pw_4lxml_5etree_17ETCompatXMLParser_1__init__(PyObject *__pyx_v + /* "src/lxml/parser.pxi":1734 + * dtd_validation=False, load_dtd=False, no_network=True, decompress=False, + * ns_clean=False, recover=False, schema=None, +- * huge_tree=False, remove_blank_text=False, resolve_entities=True, # <<<<<<<<<<<<<< ++ * huge_tree=False, remove_blank_text=False, resolve_entities='internal', # <<<<<<<<<<<<<< + * remove_comments=True, remove_pis=True, strip_cdata=True, + * target=None, compact=True): + */ + if (!values[9]) values[9] = __Pyx_NewRef(((PyObject *)Py_False)); + if (!values[10]) values[10] = __Pyx_NewRef(((PyObject *)Py_False)); +- if (!values[11]) values[11] = __Pyx_NewRef(((PyObject *)Py_True)); ++ if (!values[11]) values[11] = __Pyx_NewRef(((PyObject *)__pyx_mstate_global->__pyx_n_u_internal)); + + /* "src/lxml/parser.pxi":1735 + * ns_clean=False, recover=False, schema=None, +- * huge_tree=False, remove_blank_text=False, resolve_entities=True, ++ * huge_tree=False, remove_blank_text=False, resolve_entities='internal', + * remove_comments=True, remove_pis=True, strip_cdata=True, # <<<<<<<<<<<<<< + * target=None, compact=True): + * XMLParser.__init__(self, +@@ -148095,7 +148095,7 @@ static int __pyx_pw_4lxml_5etree_17ETCompatXMLParser_1__init__(PyObject *__pyx_v + if (!values[14]) values[14] = __Pyx_NewRef(((PyObject *)Py_True)); + + /* "src/lxml/parser.pxi":1736 +- * huge_tree=False, remove_blank_text=False, resolve_entities=True, ++ * huge_tree=False, remove_blank_text=False, resolve_entities='internal', + * remove_comments=True, remove_pis=True, strip_cdata=True, + * target=None, compact=True): # <<<<<<<<<<<<<< + * XMLParser.__init__(self, +@@ -195499,7 +195499,7 @@ static int __pyx_pw_4lxml_5etree_9iterparse_1__init__(PyObject *__pyx_v_self, Py + * def __init__(self, source, events=("end",), *, tag=None, + * attribute_defaults=False, dtd_validation=False, # <<<<<<<<<<<<<< + * load_dtd=False, no_network=True, remove_blank_text=False, +- * compact=True, resolve_entities=True, remove_comments=False, ++ * compact=True, resolve_entities='internal', remove_comments=False, + */ + if (!values[3]) values[3] = __Pyx_NewRef(((PyObject *)Py_False)); + if (!values[4]) values[4] = __Pyx_NewRef(((PyObject *)Py_False)); +@@ -195508,7 +195508,7 @@ static int __pyx_pw_4lxml_5etree_9iterparse_1__init__(PyObject *__pyx_v_self, Py + * def __init__(self, source, events=("end",), *, tag=None, + * attribute_defaults=False, dtd_validation=False, + * load_dtd=False, no_network=True, remove_blank_text=False, # <<<<<<<<<<<<<< +- * compact=True, resolve_entities=True, remove_comments=False, ++ * compact=True, resolve_entities='internal', remove_comments=False, + * remove_pis=False, strip_cdata=True, encoding=None, + */ + if (!values[5]) values[5] = __Pyx_NewRef(((PyObject *)Py_False)); +@@ -195518,17 +195518,17 @@ static int __pyx_pw_4lxml_5etree_9iterparse_1__init__(PyObject *__pyx_v_self, Py + /* "src/lxml/iterparse.pxi":71 + * attribute_defaults=False, dtd_validation=False, + * load_dtd=False, no_network=True, remove_blank_text=False, +- * compact=True, resolve_entities=True, remove_comments=False, # <<<<<<<<<<<<<< ++ * compact=True, resolve_entities='internal', remove_comments=False, # <<<<<<<<<<<<<< + * remove_pis=False, strip_cdata=True, encoding=None, + * html=False, recover=None, huge_tree=False, collect_ids=True, + */ + if (!values[8]) values[8] = __Pyx_NewRef(((PyObject *)Py_True)); +- if (!values[9]) values[9] = __Pyx_NewRef(((PyObject *)Py_True)); ++ if (!values[9]) values[9] = __Pyx_NewRef(((PyObject *)__pyx_mstate_global->__pyx_n_u_internal)); + if (!values[10]) values[10] = __Pyx_NewRef(((PyObject *)Py_False)); + + /* "src/lxml/iterparse.pxi":72 + * load_dtd=False, no_network=True, remove_blank_text=False, +- * compact=True, resolve_entities=True, remove_comments=False, ++ * compact=True, resolve_entities='internal', remove_comments=False, + * remove_pis=False, strip_cdata=True, encoding=None, # <<<<<<<<<<<<<< + * html=False, recover=None, huge_tree=False, collect_ids=True, + * XMLSchema schema=None): +@@ -195538,7 +195538,7 @@ static int __pyx_pw_4lxml_5etree_9iterparse_1__init__(PyObject *__pyx_v_self, Py + if (!values[13]) values[13] = __Pyx_NewRef(((PyObject *)Py_None)); + + /* "src/lxml/iterparse.pxi":73 +- * compact=True, resolve_entities=True, remove_comments=False, ++ * compact=True, resolve_entities='internal', remove_comments=False, + * remove_pis=False, strip_cdata=True, encoding=None, + * html=False, recover=None, huge_tree=False, collect_ids=True, # <<<<<<<<<<<<<< + * XMLSchema schema=None): +@@ -195588,7 +195588,7 @@ static int __pyx_pw_4lxml_5etree_9iterparse_1__init__(PyObject *__pyx_v_self, Py + * def __init__(self, source, events=("end",), *, tag=None, + * attribute_defaults=False, dtd_validation=False, # <<<<<<<<<<<<<< + * load_dtd=False, no_network=True, remove_blank_text=False, +- * compact=True, resolve_entities=True, remove_comments=False, ++ * compact=True, resolve_entities='internal', remove_comments=False, + */ + if (!values[3]) values[3] = __Pyx_NewRef(((PyObject *)Py_False)); + if (!values[4]) values[4] = __Pyx_NewRef(((PyObject *)Py_False)); +@@ -195597,7 +195597,7 @@ static int __pyx_pw_4lxml_5etree_9iterparse_1__init__(PyObject *__pyx_v_self, Py + * def __init__(self, source, events=("end",), *, tag=None, + * attribute_defaults=False, dtd_validation=False, + * load_dtd=False, no_network=True, remove_blank_text=False, # <<<<<<<<<<<<<< +- * compact=True, resolve_entities=True, remove_comments=False, ++ * compact=True, resolve_entities='internal', remove_comments=False, + * remove_pis=False, strip_cdata=True, encoding=None, + */ + if (!values[5]) values[5] = __Pyx_NewRef(((PyObject *)Py_False)); +@@ -195607,17 +195607,17 @@ static int __pyx_pw_4lxml_5etree_9iterparse_1__init__(PyObject *__pyx_v_self, Py + /* "src/lxml/iterparse.pxi":71 + * attribute_defaults=False, dtd_validation=False, + * load_dtd=False, no_network=True, remove_blank_text=False, +- * compact=True, resolve_entities=True, remove_comments=False, # <<<<<<<<<<<<<< ++ * compact=True, resolve_entities='internal', remove_comments=False, # <<<<<<<<<<<<<< + * remove_pis=False, strip_cdata=True, encoding=None, + * html=False, recover=None, huge_tree=False, collect_ids=True, + */ + if (!values[8]) values[8] = __Pyx_NewRef(((PyObject *)Py_True)); +- if (!values[9]) values[9] = __Pyx_NewRef(((PyObject *)Py_True)); ++ if (!values[9]) values[9] = __Pyx_NewRef(((PyObject *)__pyx_mstate_global->__pyx_n_u_internal)); + if (!values[10]) values[10] = __Pyx_NewRef(((PyObject *)Py_False)); + + /* "src/lxml/iterparse.pxi":72 + * load_dtd=False, no_network=True, remove_blank_text=False, +- * compact=True, resolve_entities=True, remove_comments=False, ++ * compact=True, resolve_entities='internal', remove_comments=False, + * remove_pis=False, strip_cdata=True, encoding=None, # <<<<<<<<<<<<<< + * html=False, recover=None, huge_tree=False, collect_ids=True, + * XMLSchema schema=None): +@@ -195627,7 +195627,7 @@ static int __pyx_pw_4lxml_5etree_9iterparse_1__init__(PyObject *__pyx_v_self, Py + if (!values[13]) values[13] = __Pyx_NewRef(((PyObject *)Py_None)); + + /* "src/lxml/iterparse.pxi":73 +- * compact=True, resolve_entities=True, remove_comments=False, ++ * compact=True, resolve_entities='internal', remove_comments=False, + * remove_pis=False, strip_cdata=True, encoding=None, + * html=False, recover=None, huge_tree=False, collect_ids=True, # <<<<<<<<<<<<<< + * XMLSchema schema=None): +@@ -263283,7 +263283,7 @@ static PyMethodDef __pyx_methods_4lxml_5etree_XMLParser[] = { + #if CYTHON_USE_TYPE_SPECS + static PyType_Slot __pyx_type_4lxml_5etree_XMLParser_slots[] = { + {Py_tp_dealloc, (void *)__pyx_tp_dealloc_4lxml_5etree__BaseParser}, +- {Py_tp_doc, (void *)PyDoc_STR("XMLParser(self, encoding=None, attribute_defaults=False, dtd_validation=False, load_dtd=False, no_network=True, decompress=False, ns_clean=False, recover=False, schema: XMLSchema =None, huge_tree=False, remove_blank_text=False, resolve_entities=True, remove_comments=False, remove_pis=False, strip_cdata=True, collect_ids=True, target=None, compact=True)\n\n The XML parser.\n\n Parsers can be supplied as additional argument to various parse\n functions of the lxml API. A default parser is always available\n and can be replaced by a call to the global function\n 'set_default_parser'. New parsers can be created at any time\n without a major run-time overhead.\n\n The keyword arguments in the constructor are mainly based on the\n libxml2 parser configuration. A DTD will also be loaded if DTD\n validation or attribute default values are requested (unless you\n additionally provide an XMLSchema from which the default\n attributes can be read).\n\n Available boolean keyword arguments:\n\n - attribute_defaults - inject default attributes from DTD or XMLSchema\n - dtd_validation - validate against a DTD referenced by the document\n - load_dtd - use DTD for parsing\n - no_network - prevent network access for related files (default: True)\n - decompress - automatically decompress gzip input\n (default: False, changed in lxml 6.0, disabling only affects libxml2 2.15+)\n - ns_clean - clean up redundant namespace declarations\n - recover - try hard to parse through broken XML\n - remove_blank_text - discard blank text nodes that appear ignorable\n - remove_comments - discard comments\n - remove_pis - discard processing instructions\n - strip_cdata - replace CDATA sections by normal text content (default: True)\n - compact "" - save memory for short text content (default: True)\n - collect_ids - use a hash table of XML IDs for fast access\n (default: True, always True with DTD validation)\n - huge_tree - disable security restrictions and support very deep trees\n and very long text content\n\n Other keyword arguments:\n\n - resolve_entities - replace entities by their text value: False for keeping the\n entity references, True for resolving them, and 'internal' for resolving\n internal definitions only (no external file/URL access).\n The default used to be True and was changed to 'internal' in lxml 5.0.\n - encoding - override the document encoding (note: libiconv encoding name)\n - target - a parser target object that will receive the parse events\n - schema - an XMLSchema to validate against\n\n Note that you should avoid sharing parsers between threads. While this is\n not harmful, it is more efficient to use separate parsers. This does not\n apply to the default parser.\n ")}, ++ {Py_tp_doc, (void *)PyDoc_STR("XMLParser(self, encoding=None, attribute_defaults=False, dtd_validation=False, load_dtd=False, no_network=True, decompress=False, ns_clean=False, recover=False, schema: XMLSchema =None, huge_tree=False, remove_blank_text=False, resolve_entities='internal', remove_comments=False, remove_pis=False, strip_cdata=True, collect_ids=True, target=None, compact=True)\n\n The XML parser.\n\n Parsers can be supplied as additional argument to various parse\n functions of the lxml API. A default parser is always available\n and can be replaced by a call to the global function\n 'set_default_parser'. New parsers can be created at any time\n without a major run-time overhead.\n\n The keyword arguments in the constructor are mainly based on the\n libxml2 parser configuration. A DTD will also be loaded if DTD\n validation or attribute default values are requested (unless you\n additionally provide an XMLSchema from which the default\n attributes can be read).\n\n Available boolean keyword arguments:\n\n - attribute_defaults - inject default attributes from DTD or XMLSchema\n - dtd_validation - validate against a DTD referenced by the document\n - load_dtd - use DTD for parsing\n - no_network - prevent network access for related files (default: True)\n - decompress - automatically decompress gzip input\n (default: False, changed in lxml 6.0, disabling only affects libxml2 2.15+)\n - ns_clean - clean up redundant namespace declarations\n - recover - try hard to parse through broken XML\n - remove_blank_text - discard blank text nodes that appear ignorable\n - remove_comments - discard comments\n - remove_pis - discard processing instructions\n - strip_cdata - replace CDATA sections by normal text content (default: True)\n - compact "" - save memory for short text content (default: True)\n - collect_ids - use a hash table of XML IDs for fast access\n (default: True, always True with DTD validation)\n - huge_tree - disable security restrictions and support very deep trees\n and very long text content\n\n Other keyword arguments:\n\n - resolve_entities - replace entities by their text value: False for keeping the\n entity references, True for resolving them, and 'internal' for resolving\n internal definitions only (no external file/URL access).\n The default used to be True and was changed to 'internal' in lxml 5.0.\n - encoding - override the document encoding (note: libiconv encoding name)\n - target - a parser target object that will receive the parse events\n - schema - an XMLSchema to validate against\n\n Note that you should avoid sharing parsers between threads. While this is\n not harmful, it is more efficient to use separate parsers. This does not\n apply to the default parser.\n ")}, + {Py_tp_traverse, (void *)__pyx_tp_traverse_4lxml_5etree__BaseParser}, + {Py_tp_clear, (void *)__pyx_tp_clear_4lxml_5etree__BaseParser}, + {Py_tp_methods, (void *)__pyx_methods_4lxml_5etree_XMLParser}, +@@ -263326,7 +263326,7 @@ static PyTypeObject __pyx_type_4lxml_5etree_XMLParser = { + 0, /*tp_setattro*/ + 0, /*tp_as_buffer*/ + Py_TPFLAGS_DEFAULT|Py_TPFLAGS_HAVE_VERSION_TAG|Py_TPFLAGS_CHECKTYPES|Py_TPFLAGS_HAVE_NEWBUFFER|Py_TPFLAGS_BASETYPE|Py_TPFLAGS_HAVE_GC, /*tp_flags*/ +- PyDoc_STR("XMLParser(self, encoding=None, attribute_defaults=False, dtd_validation=False, load_dtd=False, no_network=True, decompress=False, ns_clean=False, recover=False, schema: XMLSchema =None, huge_tree=False, remove_blank_text=False, resolve_entities=True, remove_comments=False, remove_pis=False, strip_cdata=True, collect_ids=True, target=None, compact=True)\n\n The XML parser.\n\n Parsers can be supplied as additional argument to various parse\n functions of the lxml API. A default parser is always available\n and can be replaced by a call to the global function\n 'set_default_parser'. New parsers can be created at any time\n without a major run-time overhead.\n\n The keyword arguments in the constructor are mainly based on the\n libxml2 parser configuration. A DTD will also be loaded if DTD\n validation or attribute default values are requested (unless you\n additionally provide an XMLSchema from which the default\n attributes can be read).\n\n Available boolean keyword arguments:\n\n - attribute_defaults - inject default attributes from DTD or XMLSchema\n - dtd_validation - validate against a DTD referenced by the document\n - load_dtd - use DTD for parsing\n - no_network - prevent network access for related files (default: True)\n - decompress - automatically decompress gzip input\n (default: False, changed in lxml 6.0, disabling only affects libxml2 2.15+)\n - ns_clean - clean up redundant namespace declarations\n - recover - try hard to parse through broken XML\n - remove_blank_text - discard blank text nodes that appear ignorable\n - remove_comments - discard comments\n - remove_pis - discard processing instructions\n - strip_cdata - replace CDATA sections by normal text content (default: True)\n - compact "" - save memory for short text content (default: True)\n - collect_ids - use a hash table of XML IDs for fast access\n (default: True, always True with DTD validation)\n - huge_tree - disable security restrictions and support very deep trees\n and very long text content\n\n Other keyword arguments:\n\n - resolve_entities - replace entities by their text value: False for keeping the\n entity references, True for resolving them, and 'internal' for resolving\n internal definitions only (no external file/URL access).\n The default used to be True and was changed to 'internal' in lxml 5.0.\n - encoding - override the document encoding (note: libiconv encoding name)\n - target - a parser target object that will receive the parse events\n - schema - an XMLSchema to validate against\n\n Note that you should avoid sharing parsers between threads. While this is\n not harmful, it is more efficient to use separate parsers. This does not\n apply to the default parser.\n "), /*tp_doc*/ ++ PyDoc_STR("XMLParser(self, encoding=None, attribute_defaults=False, dtd_validation=False, load_dtd=False, no_network=True, decompress=False, ns_clean=False, recover=False, schema: XMLSchema =None, huge_tree=False, remove_blank_text=False, resolve_entities='internal', remove_comments=False, remove_pis=False, strip_cdata=True, collect_ids=True, target=None, compact=True)\n\n The XML parser.\n\n Parsers can be supplied as additional argument to various parse\n functions of the lxml API. A default parser is always available\n and can be replaced by a call to the global function\n 'set_default_parser'. New parsers can be created at any time\n without a major run-time overhead.\n\n The keyword arguments in the constructor are mainly based on the\n libxml2 parser configuration. A DTD will also be loaded if DTD\n validation or attribute default values are requested (unless you\n additionally provide an XMLSchema from which the default\n attributes can be read).\n\n Available boolean keyword arguments:\n\n - attribute_defaults - inject default attributes from DTD or XMLSchema\n - dtd_validation - validate against a DTD referenced by the document\n - load_dtd - use DTD for parsing\n - no_network - prevent network access for related files (default: True)\n - decompress - automatically decompress gzip input\n (default: False, changed in lxml 6.0, disabling only affects libxml2 2.15+)\n - ns_clean - clean up redundant namespace declarations\n - recover - try hard to parse through broken XML\n - remove_blank_text - discard blank text nodes that appear ignorable\n - remove_comments - discard comments\n - remove_pis - discard processing instructions\n - strip_cdata - replace CDATA sections by normal text content (default: True)\n - compact "" - save memory for short text content (default: True)\n - collect_ids - use a hash table of XML IDs for fast access\n (default: True, always True with DTD validation)\n - huge_tree - disable security restrictions and support very deep trees\n and very long text content\n\n Other keyword arguments:\n\n - resolve_entities - replace entities by their text value: False for keeping the\n entity references, True for resolving them, and 'internal' for resolving\n internal definitions only (no external file/URL access).\n The default used to be True and was changed to 'internal' in lxml 5.0.\n - encoding - override the document encoding (note: libiconv encoding name)\n - target - a parser target object that will receive the parse events\n - schema - an XMLSchema to validate against\n\n Note that you should avoid sharing parsers between threads. While this is\n not harmful, it is more efficient to use separate parsers. This does not\n apply to the default parser.\n "), /*tp_doc*/ + __pyx_tp_traverse_4lxml_5etree__BaseParser, /*tp_traverse*/ + __pyx_tp_clear_4lxml_5etree__BaseParser, /*tp_clear*/ + 0, /*tp_richcompare*/ +@@ -263506,7 +263506,7 @@ static PyMethodDef __pyx_methods_4lxml_5etree_ETCompatXMLParser[] = { + #if CYTHON_USE_TYPE_SPECS + static PyType_Slot __pyx_type_4lxml_5etree_ETCompatXMLParser_slots[] = { + {Py_tp_dealloc, (void *)__pyx_tp_dealloc_4lxml_5etree__BaseParser}, +- {Py_tp_doc, (void *)PyDoc_STR("ETCompatXMLParser(self, encoding=None, attribute_defaults=False, dtd_validation=False, load_dtd=False, no_network=True, decompress=False, ns_clean=False, recover=False, schema=None, huge_tree=False, remove_blank_text=False, resolve_entities=True, remove_comments=True, remove_pis=True, strip_cdata=True, target=None, compact=True)\n\n An XML parser with an ElementTree compatible default setup.\n\n See the XMLParser class for details.\n\n This parser has ``remove_comments`` and ``remove_pis`` enabled by default\n and thus ignores comments and processing instructions.\n ")}, ++ {Py_tp_doc, (void *)PyDoc_STR("ETCompatXMLParser(self, encoding=None, attribute_defaults=False, dtd_validation=False, load_dtd=False, no_network=True, decompress=False, ns_clean=False, recover=False, schema=None, huge_tree=False, remove_blank_text=False, resolve_entities='internal', remove_comments=True, remove_pis=True, strip_cdata=True, target=None, compact=True)\n\n An XML parser with an ElementTree compatible default setup.\n\n See the XMLParser class for details.\n\n This parser has ``remove_comments`` and ``remove_pis`` enabled by default\n and thus ignores comments and processing instructions.\n ")}, + {Py_tp_traverse, (void *)__pyx_tp_traverse_4lxml_5etree__BaseParser}, + {Py_tp_clear, (void *)__pyx_tp_clear_4lxml_5etree__BaseParser}, + {Py_tp_methods, (void *)__pyx_methods_4lxml_5etree_ETCompatXMLParser}, +@@ -263549,7 +263549,7 @@ static PyTypeObject __pyx_type_4lxml_5etree_ETCompatXMLParser = { + 0, /*tp_setattro*/ + 0, /*tp_as_buffer*/ + Py_TPFLAGS_DEFAULT|Py_TPFLAGS_HAVE_VERSION_TAG|Py_TPFLAGS_CHECKTYPES|Py_TPFLAGS_HAVE_NEWBUFFER|Py_TPFLAGS_BASETYPE|Py_TPFLAGS_HAVE_GC, /*tp_flags*/ +- PyDoc_STR("ETCompatXMLParser(self, encoding=None, attribute_defaults=False, dtd_validation=False, load_dtd=False, no_network=True, decompress=False, ns_clean=False, recover=False, schema=None, huge_tree=False, remove_blank_text=False, resolve_entities=True, remove_comments=True, remove_pis=True, strip_cdata=True, target=None, compact=True)\n\n An XML parser with an ElementTree compatible default setup.\n\n See the XMLParser class for details.\n\n This parser has ``remove_comments`` and ``remove_pis`` enabled by default\n and thus ignores comments and processing instructions.\n "), /*tp_doc*/ ++ PyDoc_STR("ETCompatXMLParser(self, encoding=None, attribute_defaults=False, dtd_validation=False, load_dtd=False, no_network=True, decompress=False, ns_clean=False, recover=False, schema=None, huge_tree=False, remove_blank_text=False, resolve_entities='internal', remove_comments=True, remove_pis=True, strip_cdata=True, target=None, compact=True)\n\n An XML parser with an ElementTree compatible default setup.\n\n See the XMLParser class for details.\n\n This parser has ``remove_comments`` and ``remove_pis`` enabled by default\n and thus ignores comments and processing instructions.\n "), /*tp_doc*/ + __pyx_tp_traverse_4lxml_5etree__BaseParser, /*tp_traverse*/ + __pyx_tp_clear_4lxml_5etree__BaseParser, /*tp_clear*/ + 0, /*tp_richcompare*/ +@@ -266739,7 +266739,7 @@ static struct PyGetSetDef __pyx_getsets_4lxml_5etree_iterparse[] = { + #if CYTHON_USE_TYPE_SPECS + static PyType_Slot __pyx_type_4lxml_5etree_iterparse_slots[] = { + {Py_tp_dealloc, (void *)__pyx_tp_dealloc_4lxml_5etree_iterparse}, +- {Py_tp_doc, (void *)PyDoc_STR("iterparse(self, source, events=(\"end\",), tag=None, attribute_defaults=False, dtd_validation=False, load_dtd=False, no_network=True, remove_blank_text=False, remove_comments=False, remove_pis=False, encoding=None, html=False, recover=None, huge_tree=False, schema=None)\n\n Incremental parser.\n\n Parses XML into a tree and generates tuples (event, element) in a\n SAX-like fashion. ``event`` is any of 'start', 'end', 'start-ns',\n 'end-ns'.\n\n For 'start' and 'end', ``element`` is the Element that the parser just\n found opening or closing. For 'start-ns', it is a tuple (prefix, URI) of\n a new namespace declaration. For 'end-ns', it is simply None. Note that\n all start and end events are guaranteed to be properly nested.\n\n The keyword argument ``events`` specifies a sequence of event type names\n that should be generated. By default, only 'end' events will be\n generated.\n\n The additional ``tag`` argument restricts the 'start' and 'end' events to\n those elements that match the given tag. The ``tag`` argument can also be\n a sequence of tags to allow matching more than one tag. By default,\n events are generated for all elements. Note that the 'start-ns' and\n 'end-ns' events are not impacted by this restriction.\n\n The other keyword arguments in the constructor are mainly based on the\n libxml2 parser configuration. A DTD will also be loaded if validation or\n attribute default values are requested.\n\n Available boolean keyword arguments:\n - attribute_defaults: read default attributes from DTD\n - dtd_validation: validate (if DTD is available)\n - load_dtd: use DTD for parsing\n - no_network: prevent network access for related files\n - remove_blank_text: discard blank text nodes\n - remove_comments: discard comments\n - remove_pis: discard processing instructions\n - strip_cdata: repla""ce CDATA sections by normal text content (default: \n True for XML, ignored otherwise)\n - compact: safe memory for short text content (default: True)\n - resolve_entities: replace entities by their text value (default: True)\n - huge_tree: disable security restrictions and support very deep trees\n and very long text content (only affects libxml2 2.7+)\n - html: parse input as HTML (default: XML)\n - recover: try hard to parse through broken input (default: True for HTML,\n False otherwise)\n\n Other keyword arguments:\n - encoding: override the document encoding\n - schema: an XMLSchema to validate against\n ")}, ++ {Py_tp_doc, (void *)PyDoc_STR("iterparse(self, source, events=(\"end\",), tag=None, attribute_defaults=False, dtd_validation=False, load_dtd=False, no_network=True, remove_blank_text=False, compact=True, resolve_entities='internal', remove_comments=False, remove_pis=False, strip_cdata=True, encoding=None, html=False, recover=None, huge_tree=False, schema=None)\n\n Incremental parser.\n\n Parses XML into a tree and generates tuples (event, element) in a\n SAX-like fashion. ``event`` is any of 'start', 'end', 'start-ns',\n 'end-ns'.\n\n For 'start' and 'end', ``element`` is the Element that the parser just\n found opening or closing. For 'start-ns', it is a tuple (prefix, URI) of\n a new namespace declaration. For 'end-ns', it is simply None. Note that\n all start and end events are guaranteed to be properly nested.\n\n The keyword argument ``events`` specifies a sequence of event type names\n that should be generated. By default, only 'end' events will be\n generated.\n\n The additional ``tag`` argument restricts the 'start' and 'end' events to\n those elements that match the given tag. The ``tag`` argument can also be\n a sequence of tags to allow matching more than one tag. By default,\n events are generated for all elements. Note that the 'start-ns' and\n 'end-ns' events are not impacted by this restriction.\n\n The other keyword arguments in the constructor are mainly based on the\n libxml2 parser configuration. A DTD will also be loaded if validation or\n attribute default values are requested.\n\n Available boolean keyword arguments:\n - attribute_defaults: read default attributes from DTD\n - dtd_validation: validate (if DTD is available)\n - load_dtd: use DTD for parsing\n - no_network: prevent network access for related files\n - remove_blank_text: discard blank text nodes\n - remove_comments: discard comments\n - remove_pi""s: discard processing instructions\n - strip_cdata: replace CDATA sections by normal text content (default:\n True for XML, ignored otherwise)\n - compact: safe memory for short text content (default: True)\n - resolve_entities: replace entities by their text value (default: 'internal' only)\n - huge_tree: disable security restrictions and support very deep trees\n and very long text content (only affects libxml2 2.7+)\n - html: parse input as HTML (default: XML)\n - recover: try hard to parse through broken input (default: True for HTML,\n False otherwise)\n\n Other keyword arguments:\n - encoding: override the document encoding\n - schema: an XMLSchema to validate against\n ")}, + {Py_tp_traverse, (void *)__pyx_tp_traverse_4lxml_5etree_iterparse}, + {Py_tp_clear, (void *)__pyx_tp_clear_4lxml_5etree_iterparse}, + {Py_tp_iter, (void *)__pyx_pw_4lxml_5etree_9iterparse_7__iter__}, +@@ -266785,7 +266785,7 @@ static PyTypeObject __pyx_type_4lxml_5etree_iterparse = { + 0, /*tp_setattro*/ + 0, /*tp_as_buffer*/ + Py_TPFLAGS_DEFAULT|Py_TPFLAGS_HAVE_VERSION_TAG|Py_TPFLAGS_CHECKTYPES|Py_TPFLAGS_HAVE_NEWBUFFER|Py_TPFLAGS_BASETYPE|Py_TPFLAGS_HAVE_GC, /*tp_flags*/ +- PyDoc_STR("iterparse(self, source, events=(\"end\",), tag=None, attribute_defaults=False, dtd_validation=False, load_dtd=False, no_network=True, remove_blank_text=False, remove_comments=False, remove_pis=False, encoding=None, html=False, recover=None, huge_tree=False, schema=None)\n\n Incremental parser.\n\n Parses XML into a tree and generates tuples (event, element) in a\n SAX-like fashion. ``event`` is any of 'start', 'end', 'start-ns',\n 'end-ns'.\n\n For 'start' and 'end', ``element`` is the Element that the parser just\n found opening or closing. For 'start-ns', it is a tuple (prefix, URI) of\n a new namespace declaration. For 'end-ns', it is simply None. Note that\n all start and end events are guaranteed to be properly nested.\n\n The keyword argument ``events`` specifies a sequence of event type names\n that should be generated. By default, only 'end' events will be\n generated.\n\n The additional ``tag`` argument restricts the 'start' and 'end' events to\n those elements that match the given tag. The ``tag`` argument can also be\n a sequence of tags to allow matching more than one tag. By default,\n events are generated for all elements. Note that the 'start-ns' and\n 'end-ns' events are not impacted by this restriction.\n\n The other keyword arguments in the constructor are mainly based on the\n libxml2 parser configuration. A DTD will also be loaded if validation or\n attribute default values are requested.\n\n Available boolean keyword arguments:\n - attribute_defaults: read default attributes from DTD\n - dtd_validation: validate (if DTD is available)\n - load_dtd: use DTD for parsing\n - no_network: prevent network access for related files\n - remove_blank_text: discard blank text nodes\n - remove_comments: discard comments\n - remove_pis: discard processing instructions\n - strip_cdata: repla""ce CDATA sections by normal text content (default: \n True for XML, ignored otherwise)\n - compact: safe memory for short text content (default: True)\n - resolve_entities: replace entities by their text value (default: True)\n - huge_tree: disable security restrictions and support very deep trees\n and very long text content (only affects libxml2 2.7+)\n - html: parse input as HTML (default: XML)\n - recover: try hard to parse through broken input (default: True for HTML,\n False otherwise)\n\n Other keyword arguments:\n - encoding: override the document encoding\n - schema: an XMLSchema to validate against\n "), /*tp_doc*/ ++ PyDoc_STR("iterparse(self, source, events=(\"end\",), tag=None, attribute_defaults=False, dtd_validation=False, load_dtd=False, no_network=True, remove_blank_text=False, compact=True, resolve_entities='internal', remove_comments=False, remove_pis=False, strip_cdata=True, encoding=None, html=False, recover=None, huge_tree=False, schema=None)\n\n Incremental parser.\n\n Parses XML into a tree and generates tuples (event, element) in a\n SAX-like fashion. ``event`` is any of 'start', 'end', 'start-ns',\n 'end-ns'.\n\n For 'start' and 'end', ``element`` is the Element that the parser just\n found opening or closing. For 'start-ns', it is a tuple (prefix, URI) of\n a new namespace declaration. For 'end-ns', it is simply None. Note that\n all start and end events are guaranteed to be properly nested.\n\n The keyword argument ``events`` specifies a sequence of event type names\n that should be generated. By default, only 'end' events will be\n generated.\n\n The additional ``tag`` argument restricts the 'start' and 'end' events to\n those elements that match the given tag. The ``tag`` argument can also be\n a sequence of tags to allow matching more than one tag. By default,\n events are generated for all elements. Note that the 'start-ns' and\n 'end-ns' events are not impacted by this restriction.\n\n The other keyword arguments in the constructor are mainly based on the\n libxml2 parser configuration. A DTD will also be loaded if validation or\n attribute default values are requested.\n\n Available boolean keyword arguments:\n - attribute_defaults: read default attributes from DTD\n - dtd_validation: validate (if DTD is available)\n - load_dtd: use DTD for parsing\n - no_network: prevent network access for related files\n - remove_blank_text: discard blank text nodes\n - remove_comments: discard comments\n - remove_pi""s: discard processing instructions\n - strip_cdata: replace CDATA sections by normal text content (default:\n True for XML, ignored otherwise)\n - compact: safe memory for short text content (default: True)\n - resolve_entities: replace entities by their text value (default: 'internal' only)\n - huge_tree: disable security restrictions and support very deep trees\n and very long text content (only affects libxml2 2.7+)\n - html: parse input as HTML (default: XML)\n - recover: try hard to parse through broken input (default: True for HTML,\n False otherwise)\n\n Other keyword arguments:\n - encoding: override the document encoding\n - schema: an XMLSchema to validate against\n "), /*tp_doc*/ + __pyx_tp_traverse_4lxml_5etree_iterparse, /*tp_traverse*/ + __pyx_tp_clear_4lxml_5etree_iterparse, /*tp_clear*/ + 0, /*tp_richcompare*/ +diff --git a/src/lxml/iterparse.pxi b/src/lxml/iterparse.pxi +index 42b75249..9319f646 100644 +--- a/src/lxml/iterparse.pxi ++++ b/src/lxml/iterparse.pxi +@@ -6,8 +6,8 @@ cdef class iterparse: + """iterparse(self, source, events=("end",), tag=None, \ + attribute_defaults=False, dtd_validation=False, \ + load_dtd=False, no_network=True, remove_blank_text=False, \ +- remove_comments=False, remove_pis=False, encoding=None, \ +- html=False, recover=None, huge_tree=False, schema=None) ++ compact=True, resolve_entities='internal', remove_comments=False, \ ++ remove_pis=False, strip_cdata=True, encoding=None, html=False, recover=None, huge_tree=False, schema=None) + + Incremental parser. + +@@ -42,10 +42,10 @@ cdef class iterparse: + - remove_blank_text: discard blank text nodes + - remove_comments: discard comments + - remove_pis: discard processing instructions +- - strip_cdata: replace CDATA sections by normal text content (default: ++ - strip_cdata: replace CDATA sections by normal text content (default: + True for XML, ignored otherwise) + - compact: safe memory for short text content (default: True) +- - resolve_entities: replace entities by their text value (default: True) ++ - resolve_entities: replace entities by their text value (default: 'internal' only) + - huge_tree: disable security restrictions and support very deep trees + and very long text content (only affects libxml2 2.7+) + - html: parse input as HTML (default: XML) +@@ -68,7 +68,7 @@ cdef class iterparse: + def __init__(self, source, events=("end",), *, tag=None, + attribute_defaults=False, dtd_validation=False, + load_dtd=False, no_network=True, remove_blank_text=False, +- compact=True, resolve_entities=True, remove_comments=False, ++ compact=True, resolve_entities='internal', remove_comments=False, + remove_pis=False, strip_cdata=True, encoding=None, + html=False, recover=None, huge_tree=False, collect_ids=True, + XMLSchema schema=None): +diff --git a/src/lxml/parser.pxi b/src/lxml/parser.pxi +index 3106e610..ba9875c0 100644 +--- a/src/lxml/parser.pxi ++++ b/src/lxml/parser.pxi +@@ -1584,7 +1584,7 @@ cdef class XMLParser(_FeedParser): + """XMLParser(self, encoding=None, attribute_defaults=False, dtd_validation=False, \ + load_dtd=False, no_network=True, decompress=False, ns_clean=False, \ + recover=False, schema: XMLSchema =None, huge_tree=False, \ +- remove_blank_text=False, resolve_entities=True, \ ++ remove_blank_text=False, resolve_entities='internal', \ + remove_comments=False, remove_pis=False, strip_cdata=True, \ + collect_ids=True, target=None, compact=True) + +@@ -1717,7 +1717,7 @@ cdef class ETCompatXMLParser(XMLParser): + """ETCompatXMLParser(self, encoding=None, attribute_defaults=False, \ + dtd_validation=False, load_dtd=False, no_network=True, decompress=False, \ + ns_clean=False, recover=False, schema=None, \ +- huge_tree=False, remove_blank_text=False, resolve_entities=True, \ ++ huge_tree=False, remove_blank_text=False, resolve_entities='internal', \ + remove_comments=True, remove_pis=True, strip_cdata=True, \ + target=None, compact=True) + +@@ -1731,7 +1731,7 @@ cdef class ETCompatXMLParser(XMLParser): + def __init__(self, *, encoding=None, attribute_defaults=False, + dtd_validation=False, load_dtd=False, no_network=True, decompress=False, + ns_clean=False, recover=False, schema=None, +- huge_tree=False, remove_blank_text=False, resolve_entities=True, ++ huge_tree=False, remove_blank_text=False, resolve_entities='internal', + remove_comments=True, remove_pis=True, strip_cdata=True, + target=None, compact=True): + XMLParser.__init__(self, +-- +2.35.6 + diff --git a/meta/recipes-devtools/python/python3-lxml_6.0.2.bb b/meta/recipes-devtools/python/python3-lxml_6.0.2.bb index 876fda93b63..75894460ec5 100644 --- a/meta/recipes-devtools/python/python3-lxml_6.0.2.bb +++ b/meta/recipes-devtools/python/python3-lxml_6.0.2.bb @@ -20,7 +20,9 @@ DEPENDS += "libxml2 libxslt" SRC_URI[sha256sum] = "cd79f3367bd74b317dda655dc8fcfa304d9eb6e4fb06b7168c5cf27f96e0cd62" -SRC_URI += "${PYPI_SRC_URI}" +SRC_URI += "${PYPI_SRC_URI} \ + file://CVE-2026-41066.patch" + inherit pkgconfig pypi setuptools3 # {standard input}: Assembler messages: From patchwork Wed Sep 9 07:29:20 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 97680 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id A7EF1C88E42 for ; Wed, 9 Sep 2026 07:30:12 +0000 (UTC) Received: from mail-wm1-f52.google.com (mail-wm1-f52.google.com [209.85.128.52]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.6326.1788939010332403075 for ; Wed, 09 Sep 2026 00:30:10 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=FWgriBjC; spf=pass (domain: smile.fr, ip: 209.85.128.52, mailfrom: yoann.congal@smile.fr) Received: by mail-wm1-f52.google.com with SMTP id 5b1f17b1804b1-49d0da752ffso34584945e9.3 for ; Wed, 09 Sep 2026 00:30:10 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1788939008; x=1789543808; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=TNvhUlOorZ08iyUXpiv1XvjTbMXxVanPtdMnuhMpkE0=; b=FWgriBjCztCIUHefYIH3c/2IS+kkQp/EcqlZBHzl/LmvypWTicSf5auBj8uP65XZND wvihbxfpw1rSwOcQv8aAgUG1eiKqjbqBz27OqaYEhl4p3A6fJRVDwspkLH94Ljmq8R/4 zlschzIHC72oJAqM0ovac5MS2W9JJGfwYdG0g= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1788939008; x=1789543808; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=TNvhUlOorZ08iyUXpiv1XvjTbMXxVanPtdMnuhMpkE0=; b=OVuiZ5dGaKFHyyqXMNKVDXLM9cM6ZBbAlXpyWpKzNPuqOg+xf/vm5D+91O2LmrbSVM neUMZ3e+nu0D9ppgPVVMqC6m9B8CJE+tqx3DgY8f3yxEE81HZbQfSoAM2ZeoLwIfsMhf k7BHb1d52UdzckgRbWtMcVhV5/V71+FgnVJrfIkllJsY7+6e9CBOJOMHdpgIGw4r+DRa eZ6J6MBaIC7XVLTFvcbHVMzvbrgaFQciXJwsB8K9e/S71ReQG0Ly/dV3wSy7QwkIzFo2 JsHLJov3mSQE5EBF2BO9r450rL4ptKeKEkNAzwUz34GSHWX+QIMH+Ab/aklb9DFjO/F7 u+tQ== X-Gm-Message-State: AFuF++naE4K1TFLFH+qjQ406w00mCLHohWh8jWm3gJ2+bu3ppsM3BML7 zLdwqLPFcS/Bg7QbxVbFHktqIrwxVy52A1xJCQPxyikteXrPTzZML7AzMcW9441NPb5R1YruJP5 +We3uCqE= X-Gm-Gg: AYBFou19B2kxKunCZrtZsOh9sTlifhw/7m550wsKq61wlSU5mk7RAPppz0I1aJ6XdPv ApY24G2P5ynXE08oMcjeaDjvMyBLed0wEtdM/1Pwav/AWnJV3qz3RbScAxarYVIlukJDV01pHpN tD6gcNvBkaiF8inSftBQpzR2SFJ5jLHOdFGIKse/ojxDzpV9SuicV7akWnzusILNoQQEKbGpSzN NaV3UQBC7nD9p1PWiAdrJ0nNnG+u4tdClZrWH6wC2Le0E3XdKRm4pqCwv40b6O7A2FPPVPbcIax mnNGbiNP0WkVCacGI2VmDS2d95Tb1BFLLmfXDbeeuY72zH4iy9xGDIag6m11B21h5MXVtUvEi7K X0VoWqvlAdRx92BjO8nlf24p0c67JlpuM1++XaHUaDjrQjUFu1QHhWqOosD+t+4e1Bp0eQIl5lW 0dos29ZWIZ09xo/dixilg2CSCuHZRGBPVEF1ceQ+XaNyMBUaB/7jkTWCIsr8B+UpTLRoRJQTcdN UM8jG/KIo+sVmUjHOETq9nmwHeObvGJ8732exAAPdzdZMqULlcvnVUMyjfbIh9F90vKKBTmU74= X-Received: by 2002:a05:600c:4714:b0:49d:462:6eda with SMTP id 5b1f17b1804b1-49d04627387mr242148775e9.28.1788939008005; Wed, 09 Sep 2026 00:30:08 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-4858ac2b4cdsm40624310f8f.16.2026.09.09.00.30.07 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 09 Sep 2026 00:30:07 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][wrynose 21/38] glibc: fix CVE-2026-19542 Date: Wed, 9 Sep 2026 09:29:20 +0200 Message-ID: <11fef7c21845e03c044305ba57e289831e7518c9.1788938909.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Wed, 09 Sep 2026 07:30:12 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/245430 From: Harish Sadineni Allocate the maximum array sizes directly, instead of resizing the arrays as needed. This eliminates alloca usage from the function, and fixes the out-of-bounds accesses. The asserts guard against the bug coming back if the balancing of the tree turns out not to work correctly. Upstream-Status: Backport [https://sourceware.org/git/?p=glibc.git;a=patch;h=e2789c46e3bfdcd67a82bea9946b315c179e83d3] CVE: CVE-2026-19542 Reference: [1]https://security-tracker.debian.org/tracker/CVE-2026-19542 [2]https://sourceware.org/bugzilla/show_bug.cgi?id=34506 [3]https://sourceware.org/git/?p=glibc.git;a=commit;h=e2789c46e3bfdcd67a82bea9946b315c179e83d3 Signed-off-by: Harish Sadineni Signed-off-by: Yoann Congal [YC: fixed CVE: tag in patch] --- .../glibc/glibc/0023-CVE-2026-19542.patch | 98 +++++++++++++++++++ meta/recipes-core/glibc/glibc_2.43.bb | 1 + 2 files changed, 99 insertions(+) create mode 100644 meta/recipes-core/glibc/glibc/0023-CVE-2026-19542.patch diff --git a/meta/recipes-core/glibc/glibc/0023-CVE-2026-19542.patch b/meta/recipes-core/glibc/glibc/0023-CVE-2026-19542.patch new file mode 100644 index 00000000000..094a50919dc --- /dev/null +++ b/meta/recipes-core/glibc/glibc/0023-CVE-2026-19542.patch @@ -0,0 +1,98 @@ +From e2789c46e3bfdcd67a82bea9946b315c179e83d3 Mon Sep 17 00:00:00 2001 +From: Florian Weimer +Date: Fri, 14 Aug 2026 13:41:16 +0200 +Subject: [PATCH] misc: Fix out-of-bounds array write in tdelete (bug 34506) + +Allocate the maximum array sizes directly, instead of resizing +the arrays as needed. This eliminates alloca usage from the +function, and fixes the out-of-bounds accesses. The asserts +guard against the bug coming back if the balancing of the tree +turns out not to work correctly. + +CVE: CVE-2026-19542 +Upstream-Status: Backport [https://sourceware.org/git/?p=glibc.git;a=patch;h=e2789c46e3bfdcd67a82bea9946b315c179e83d3] + +Reviewed-by: Adhemerval Zanella +Signed-off-by: Harish Sadineni +--- + misc/tsearch.c | 31 +++++++++++-------------------- + 1 file changed, 11 insertions(+), 20 deletions(-) + +diff --git a/misc/tsearch.c b/misc/tsearch.c +index 9b2eb34b25..e517dfa712 100644 +--- a/misc/tsearch.c ++++ b/misc/tsearch.c +@@ -85,6 +85,7 @@ + #include + #include + #include ++#include + #include + #include + #include +@@ -406,12 +407,13 @@ __tdelete (const void *key, void **vrootp, __compar_fn_t compar) + int cmp; + node *rootp = (node *) vrootp; + node root, unchained; +- /* Stack of nodes so we remember the parents without recursion. It's +- _very_ unlikely that there are paths longer than 40 nodes. The tree +- would need to have around 250.000 nodes. */ +- int stacksize = 40; ++ /* Stack of nodes so we remember the parents without recursion. The ++ stack size is a conservative approximation of the maximum height ++ of a red-black tree, based on size of the address space. ++ Actual numbers are closer to 57 (32 bit) and 117 (63 bit). */ ++ enum { stacksize = 2 * UINTPTR_WIDTH }; + int sp = 0; +- node **nodestack = alloca (sizeof (node *) * stacksize); ++ node *nodestack[stacksize]; + + if (rootp == NULL) + return NULL; +@@ -424,14 +426,7 @@ __tdelete (const void *key, void **vrootp, __compar_fn_t compar) + root = DEREFNODEPTR(rootp); + while ((cmp = (*compar) (key, root->key)) != 0) + { +- if (sp == stacksize) +- { +- node **newstack; +- stacksize += 20; +- newstack = alloca (sizeof (node *) * stacksize); +- nodestack = memcpy (newstack, nodestack, sp * sizeof (node *)); +- } +- ++ assert (sp < stacksize); + nodestack[sp++] = rootp; + p = DEREFNODEPTR(rootp); + if (cmp < 0) +@@ -470,13 +465,7 @@ __tdelete (const void *key, void **vrootp, __compar_fn_t compar) + node upn; + for (;;) + { +- if (sp == stacksize) +- { +- node **newstack; +- stacksize += 20; +- newstack = alloca (sizeof (node *) * stacksize); +- nodestack = memcpy (newstack, nodestack, sp * sizeof (node *)); +- } ++ assert (sp < stacksize); + nodestack[sp++] = parentp; + parentp = up; + upn = DEREFNODEPTR(up); +@@ -541,6 +530,7 @@ __tdelete (const void *key, void **vrootp, __compar_fn_t compar) + SETNODEPTR(pp,q); + /* Make sure pp is right if the case below tries to use + it. */ ++ assert (sp < stacksize); + nodestack[sp++] = pp = LEFTPTR(q); + q = RIGHT(p); + } +@@ -625,6 +615,7 @@ __tdelete (const void *key, void **vrootp, __compar_fn_t compar) + SETLEFT(p,RIGHT(q)); + SETRIGHT(q,p); + SETNODEPTR(pp,q); ++ assert (sp < stacksize); + nodestack[sp++] = pp = RIGHTPTR(q); + q = LEFT(p); + } diff --git a/meta/recipes-core/glibc/glibc_2.43.bb b/meta/recipes-core/glibc/glibc_2.43.bb index 9f3a3814d0a..3ef2301191d 100644 --- a/meta/recipes-core/glibc/glibc_2.43.bb +++ b/meta/recipes-core/glibc/glibc_2.43.bb @@ -55,6 +55,7 @@ SRC_URI = "${GLIBC_GIT_URI};branch=${SRCBRANCH};name=glibc \ file://0020-fix-create-thread-failed-in-unprivileged-process-BZ-.patch \ file://0021-tests-Skip-2-qemu-tests-that-can-hang-in-oe-selftest.patch \ file://0022-Propagate-ffile-prefix-map-from-CFLAGS-to-ASFLAGS.patch \ + file://0023-CVE-2026-19542.patch \ " B = "${WORKDIR}/build-${TARGET_SYS}" From patchwork Wed Sep 9 07:29:21 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 97668 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id B96FBC79FB5 for ; Wed, 9 Sep 2026 07:30:11 +0000 (UTC) Received: from mail-wr1-f42.google.com (mail-wr1-f42.google.com [209.85.221.42]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.6444.1788939010515681758 for ; Wed, 09 Sep 2026 00:30:10 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=PDBJdrqG; spf=pass (domain: smile.fr, ip: 209.85.221.42, mailfrom: yoann.congal@smile.fr) Received: by mail-wr1-f42.google.com with SMTP id ffacd0b85a97d-47de0093c42so5140822f8f.3 for ; Wed, 09 Sep 2026 00:30:10 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1788939009; x=1789543809; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=OrveqAv+QxJC3F62zjmWv3J1LTKtOYoS9O016HZicqI=; b=PDBJdrqG6HpLQYDtcZdQcE9/rgyK47jAqSGC82tJ3lH3m7QeY4CiB4sUSqorPFu6XF A59Bz1maThQc5ciDl79aN80xMdfoSvVFR0XqWSjwf8DFFxm3edqyBamgu6xbFmm5HZeN LLKPbP8om29/2U9IkVz/n3KD3WaaysqBxihWA= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1788939009; x=1789543809; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=OrveqAv+QxJC3F62zjmWv3J1LTKtOYoS9O016HZicqI=; b=g+AR/1pw4qPvsBNy6apdgd59lCqVftkRVnDLHcsma2Z4naNbzXtjr7xPdOFaAkqiR7 g5ASgixDoyB7ewaNSqXS2jIon2vbpAL87i6uu8XMZYGv1qI5L2UOHBpEAfxgnzX+b3ZE cOIJfNte8gpBNYGby0wpWvoMmFsJTYKz5oXBECTp2wxMND7FOQFbll4Te7guINpYgjDA qF+jNm1rwLHxlohHGxGJA4uoUumzQrsQntUTCNpfDo55lxgBpv5G0DtRXl4zJi5c4BMt IQXgRCiDV5r8lCJKZvAF/5R/o3OrxsMMZada5WtAjqS+QGIXW+vhN+JJvgUrKm0dDYEO EIqg== X-Gm-Message-State: AFuF++mb8bXmjLegVTBQsbOMzxHTrlxaaYriG8YZi+k32atQrznSyhiT JTQqQqPx0aMwYMu2XhqwfMcI+OtC0BEeCEeEABp/LFmFzIiPFTqcHfvFpf+fitENO8+E5zsK2Aw Bn2ouUVA= X-Gm-Gg: AYBFou2YdFl4qr6Fb/nWe13vtlj7ffaIaVxOjGoq4OMWMsaq4OZco9nlPqmzknKlu55 dgxhq9/9E9hsRVmxpR1iqBhFThTxKEH1JIj8xY0V0Q5czXYsECxjs+8Swys+RvUWBldlqLRFTmD N/mol50PFlRB6q2xI5WBcGXtzHXyYOvvwbGhAfmpEaX9x1ZeS/Wqp5BQWOfdBGk5vGpLHrwHtDU sdlff5TMPXLUZ7f/bBt1pAhYDzcUbR0EuR+NyZVhEkj4J3T/xzVmAEg+VFi8YRiIKEKraHAYMPS llZEf4RdlV41rl8DpzdkKbH/YGLzpYMrSGOIr526eui5YaE97jg841r1LyJf8WCE+O7+BaYcoVP 2YpZpRvHIppn04TUaYb+0rrD0DzSO4wlFLW+MXop0uARY8CNUzAwcO4zvvyglgoNtiRGxQUJ3pQ P0HJRCP+x7KQzf9QEV05qv2Cf1B9FuSTtGmLRwbacbThRQpdmiuaCE2scmMn/dHzJ76coqmHoNV a+jp21PAmsOR6RhZkkMt7dhCY+IzDQehlv18FL6mFFsrEqKAm60NFqi8+8RNAkfU3c+cDNtDQE= X-Received: by 2002:a05:6000:704:b0:485:8c16:5eea with SMTP id ffacd0b85a97d-4858c166202mr35355938f8f.36.1788939008573; Wed, 09 Sep 2026 00:30:08 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-4858ac2b4cdsm40624310f8f.16.2026.09.09.00.30.08 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 09 Sep 2026 00:30:08 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][wrynose 22/38] libxfont: Fix CVE-2026-56001 Date: Wed, 9 Sep 2026 09:29:21 +0200 Message-ID: X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Wed, 09 Sep 2026 07:30:11 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/245431 From: Vijay Anusuri Pick patch according to [2] [1] https://nvd.nist.gov/vuln/detail/CVE-2026-56001 [2] https://security-tracker.debian.org/tracker/CVE-2026-56001 Signed-off-by: Vijay Anusuri Signed-off-by: Yoann Congal --- .../xorg-lib/libxfont/CVE-2026-56001.patch | 87 +++++++++++++++++++ .../xorg-lib/libxfont_1.5.4.bb | 3 + 2 files changed, 90 insertions(+) create mode 100644 meta/recipes-graphics/xorg-lib/libxfont/CVE-2026-56001.patch diff --git a/meta/recipes-graphics/xorg-lib/libxfont/CVE-2026-56001.patch b/meta/recipes-graphics/xorg-lib/libxfont/CVE-2026-56001.patch new file mode 100644 index 00000000000..1de7f3e0372 --- /dev/null +++ b/meta/recipes-graphics/xorg-lib/libxfont/CVE-2026-56001.patch @@ -0,0 +1,87 @@ +From be0b08e2d354138d3222b4490e2a77c6ee42f778 Mon Sep 17 00:00:00 2001 +From: Peter Hutterer +Date: Mon, 1 Jun 2026 16:46:10 +1000 +Subject: [PATCH] bitscale: fix integer overflow in BitmapScaleBitmaps + bytestoalloc + +bytestoalloc is declared as unsigned int (32-bit). When the sum of +per-glyph byte counts exceeds 2^32, the value wraps around and calloc() +allocates a buffer that is too small. The subsequent ScaleBitmap loop +then writes past the end of the allocated buffer. + +Change bytestoalloc from unsigned int to size_t to match the actual +allocation size type, and add an explicit overflow check in the +accumulation loop to bail out if the total would exceed SIZE_MAX. + +This vulnerability was discovered by: +Anonymous working with TrendAI Zero Day Initiative + +CVE-2026-56001/ZDI-CAN-30558 + +Assisted-by: Claude:claude-opus-4-6 +Signed-off-by: Peter Hutterer +Part-of: + +Note: 'SIZE_MAX' is defined in header ''. Add '#include +' to fix build failure. + +Upstream-Status: Backport [import from debian libxfont1 1.5.2-4+deb9u1 +Upstream commit https://gitlab.freedesktop.org/xorg/lib/libxfont/-/commit/be0b08e2d354138d3222b4490e2a77c6ee42f778] +CVE: CVE-2026-56001 +Signed-off-by: Vijay Anusuri +--- + src/bitmap/bitscale.c | 24 +++++++++++++++++++++--- + 1 file changed, 21 insertions(+), 3 deletions(-) + +diff --git a/src/bitmap/bitscale.c b/src/bitmap/bitscale.c +index 13ed924..32144d6 100644 +--- a/src/bitmap/bitscale.c ++++ b/src/bitmap/bitscale.c +@@ -38,6 +38,7 @@ from The Open Group. + #include + #include + #include ++#include + + #ifndef MAX + #define MAX(a,b) (((a)>(b)) ? a : b) +@@ -1459,7 +1460,7 @@ BitmapScaleBitmaps(FontPtr pf, /* scaled font */ + opci; + FontInfoPtr pfi; + int glyph; +- unsigned bytestoalloc = 0; ++ size_t bytestoalloc = 0; + int firstCol, lastCol, firstRow, lastRow; + + double xform[4], inv_xform[4]; +@@ -1486,8 +1487,25 @@ BitmapScaleBitmaps(FontPtr pf, /* scaled font */ + glyph = pf->glyph; + for (i = 0; i < nchars; i++) + { +- if ((pci = ACCESSENCODING(bitmapFont->encoding, i))) +- bytestoalloc += BYTES_FOR_GLYPH(pci, glyph); ++ if ((pci = ACCESSENCODING(bitmapFont->encoding, i))) { ++ size_t glyphsize = BYTES_FOR_GLYPH(pci, glyph); ++ if (bytestoalloc > SIZE_MAX - glyphsize) { ++ fprintf(stderr, ++ "Error: bitmap allocation overflow for scaled font\n"); ++ goto bail; ++ } ++ bytestoalloc += glyphsize; ++ } ++ } ++ ++ /* Reject unreasonably large bitmap allocations that could result ++ * from malicious fonts with extreme scale factors. 256 MiB is ++ * far beyond any legitimate scaled bitmap font. */ ++#define BITMAP_SCALE_MAX_ALLOC (256 * 1024 * 1024) ++ if (bytestoalloc > BITMAP_SCALE_MAX_ALLOC) { ++ fprintf(stderr, ++ "Error: scaled bitmap size %zu exceeds limit\n", bytestoalloc); ++ goto bail; + } + + /* Do we add the font malloc stuff for VALUE ADDED ? */ +-- +2.43.0 + diff --git a/meta/recipes-graphics/xorg-lib/libxfont_1.5.4.bb b/meta/recipes-graphics/xorg-lib/libxfont_1.5.4.bb index 9ec7cc30f58..59c489b785d 100644 --- a/meta/recipes-graphics/xorg-lib/libxfont_1.5.4.bb +++ b/meta/recipes-graphics/xorg-lib/libxfont_1.5.4.bb @@ -19,6 +19,9 @@ XORG_EXT = "tar.bz2" BBCLASSEXTEND = "native" +SRC_URI += "file://CVE-2026-56001.patch \ + " + SRC_URI[sha256sum] = "1a7f7490774c87f2052d146d1e0e64518d32e6848184a18654e8d0bb57883242" PACKAGECONFIG ??= "${@bb.utils.filter('DISTRO_FEATURES', 'ipv6', d)}" From patchwork Wed Sep 9 07:29:22 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 97669 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 95437C79FAA for ; Wed, 9 Sep 2026 07:30:11 +0000 (UTC) Received: from mail-wr2-f12.google.com (mail-wr2-f12.google.com [74.125.225.76]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.6327.1788939011177684321 for ; Wed, 09 Sep 2026 00:30:11 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=YYiuMPPc; spf=pass (domain: smile.fr, ip: 74.125.225.76, mailfrom: yoann.congal@smile.fr) Received: by mail-wr2-f12.google.com with SMTP id ffacd0b85a97d-4843c2790ccso429393f8f.1 for ; Wed, 09 Sep 2026 00:30:10 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1788939009; x=1789543809; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=nP0u2NdMIYyX7OsSRPzzPwjXmLukXHr2loTU+Je+i4o=; b=YYiuMPPc+XS4opY1Dm0cmEP8vN505pFHTED92D2etfY3VmJMe0PtQ7d4XsdBqc8/oM x3AvDZ8Jk5eiR722UhMy56bcBhWF+GhyYYSaZcx4trSJ3vEOIsS9wqrAXOi4LWhzaxAH 6bUzt3fv1GcwAX1SmGkgTjdFgIg7qVBjlxkWo= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1788939009; x=1789543809; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=nP0u2NdMIYyX7OsSRPzzPwjXmLukXHr2loTU+Je+i4o=; b=sePB4BuHfeh71CYrV/8he7cPVMlJOMgBHw3P6LTTxotkNQbWnd1Rf8EanpIufNPAlk oZ4d26PZ/LtB+0wSr4LrnJrzUVFeiPemQBbNIcwuzGKs0DbRtS/ZYLXa+q5R6CfX8kN4 S9YF2vxSf2biH5ojDGzFZc12xK940MQpPr9Mi8uV7Y/8Oth3WRs7R+DNbXvm6QxERmMr yM77KJXwy6r4C7zeaHkgmllfQzOieq+OY0r+XG+QRdg/CTTNwpmyjyoWmUpVidwyzGQd 8OuBihMlweDu5YUKshmSTd1+JyFB90pHynT3LVo2w3YsVf90Y3A3QzbLDsI1HXALkZC7 Hp9Q== X-Gm-Message-State: AFuF++nSJfzIas47eKMlr3yi2XD8RZPtuqxY7j8goABZlGo2PFsYCaN+ ArbYmFNI5UL3mf7Z+xc79bCxe/DhAeQH1J81LDnEiuzJt912gSiRFgB9pkOpxWvZ8XKqEcmqLyy 6kqY+D98= X-Gm-Gg: AYBFou0v7Io6iu7LDCr3KuRrL29653xswHFDRq9+M/RzjJ4tAvUwvyaymEL9Hn7z/ju IYECGNyhggMXmg0A4p9MBxkd5VOsBYU17ytT9yd4TpVOGtxkqVb86KmRHwTLniT9wV+r0OSwg6+ /OezoRljmSj994PSBVZnrywmjOm+18F/07CCkLeJjt9sByphgmEOxU6rNSeHkqAGhaHQ2tuLXXw GbTqoCUzWbVCJJbokj20fdCX9e+JnlArOaGsOCj3Dqm7wEIpL6jypwgq07ELTZ+W8thaEKaRyds +xnSMFCji4Uc5aiVQH6kRfWaypcsAx7XuVbxDMxlMmq/8yI+ELezTT5vmkGoH1DI2JtgBGfbaMK lgLQTpYNe0oesQ7Y1GzOejlfMzBhrhUFADK2bkMXC16mslx8qiVCtzPz8THo6G4lt0jn9MpEWuE pGKAy82HCnCsc/auTujWDAQRvb82j/dERY4MkWVrNYqFAn3c7vv8eIhGzRaC+AhL4o155nzACrM 178EpD+xtIecS6mqUwMofYrw8GBt502XZQhMvER5i1uv6JAymaL/py+YBHU0RONrFtkKELoeVI= X-Received: by 2002:a05:6000:1883:b0:482:ea08:8c97 with SMTP id ffacd0b85a97d-485aad9458dmr7923016f8f.2.1788939009290; Wed, 09 Sep 2026 00:30:09 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-4858ac2b4cdsm40624310f8f.16.2026.09.09.00.30.08 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 09 Sep 2026 00:30:08 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][wrynose 23/38] libxfont: Fix CVE-2026-56002 Date: Wed, 9 Sep 2026 09:29:22 +0200 Message-ID: X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Wed, 09 Sep 2026 07:30:11 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/245432 From: Vijay Anusuri Pick patch according to [2] [1] https://nvd.nist.gov/vuln/detail/CVE-2026-56002 [2] https://security-tracker.debian.org/tracker/CVE-2026-56002 Signed-off-by: Vijay Anusuri Signed-off-by: Yoann Congal --- .../xorg-lib/libxfont/CVE-2026-56002.patch | 150 ++++++++++++++++++ .../xorg-lib/libxfont_1.5.4.bb | 1 + 2 files changed, 151 insertions(+) create mode 100644 meta/recipes-graphics/xorg-lib/libxfont/CVE-2026-56002.patch diff --git a/meta/recipes-graphics/xorg-lib/libxfont/CVE-2026-56002.patch b/meta/recipes-graphics/xorg-lib/libxfont/CVE-2026-56002.patch new file mode 100644 index 00000000000..cef8a06a686 --- /dev/null +++ b/meta/recipes-graphics/xorg-lib/libxfont/CVE-2026-56002.patch @@ -0,0 +1,150 @@ +From b4389e0b1d84a690b819bb27b1439968811a3674 Mon Sep 17 00:00:00 2001 +From: Peter Hutterer +Date: Mon, 1 Jun 2026 16:48:40 +1000 +Subject: [PATCH] pcfread: validate bitmap sizes and offsets against per-glyph + metrics + +pcfReadFont() uses bitmapSizes[] read directly from the PCF file to +allocate the repadded bitmap buffer. However, per-glyph metrics (also +from the file) control how much data RepadBitmap() writes. A malicious +PCF font can declare a small bitmapSizes[] value while having per-glyph +metrics that require more space, causing a heap buffer overflow. + +A similar issue happens with the encoding offsets: pcfReadFont reads +encoding offsets from the PCF file and uses them to index into the +metrics array without bounds checking. A crafted font can set an +encoding offset larger than nmetrics, causing an out-of-bounds pointer +that is later dereferenced when glyphs are accessed through the encoding +table. + +And the no-repad bitmap path (when PCF_GLYPH_PAD matches the requested +glyph pad) only validated that each glyph's offset was within the bitmap +buffer, but did not check that the full glyph extent (offset + +BYTES_PER_ROW * height) fits within the buffer. A crafted font with a +glyph offset near the end of a small bitmap buffer but large glyph +metrics causes a heap buffer over-read when the glyph is later rendered. + +This vulnerability was discovered by: + Anonymous working with TrendAI Zero Day Initiative + +CVE-2026-56002/ZDI-CAN-30559 + +Assisted-by: Claude:claude-opus-4-6 +Signed-off-by: Peter Hutterer +Part-of: + +Note: 'INT_MAX' is defined in header ''. Add '#include +' to fix build failure. + +Upstream-Status: Backport [import from debian libxfont1 1.5.2-4+deb9u1 +Upstream commit https://gitlab.freedesktop.org/xorg/lib/libxfont/-/commit/b4389e0b1d84a690b819bb27b1439968811a3674] +CVE: CVE-2026-56002 +Signed-off-by: Vijay Anusuri +--- + src/bitmap/pcfread.c | 60 +++++++++++++++++++++++++++++++++++++++++--- + 1 file changed, 57 insertions(+), 3 deletions(-) + +diff --git a/src/bitmap/pcfread.c b/src/bitmap/pcfread.c +index 4a372c5..0cc9777 100644 +--- a/src/bitmap/pcfread.c ++++ b/src/bitmap/pcfread.c +@@ -45,6 +45,7 @@ from The Open Group. + #include + #include + #include ++#include + + void + pcfError(const char* message, ...) +@@ -529,25 +530,74 @@ pcfReadFont(FontPtr pFont, FontFilePtr file, + int old, + new; + xCharInfo *metric; ++ int srcPad = PCF_GLYPH_PAD(format); + +- sizepadbitmaps = bitmapSizes[PCF_SIZE_TO_INDEX(glyph)]; +- padbitmaps = malloc(sizepadbitmaps); ++ /* Compute the actual required size from per-glyph metrics instead ++ * of trusting the file's bitmapSizes[] value, which may be smaller ++ * than the actual data written by RepadBitmap. */ ++ sizepadbitmaps = 0; ++ for (i = 0; i < nbitmaps; i++) { ++ int w, h, glyphBytes; ++ metric = &metrics[i].metrics; ++ w = metric->rightSideBearing - metric->leftSideBearing; ++ h = metric->ascent + metric->descent; ++ glyphBytes = BYTES_PER_ROW(w, glyph) * h; ++ if (glyphBytes < 0 || (glyphBytes > 0 && sizepadbitmaps > INT_MAX - glyphBytes)) { ++ pcfError("pcfReadFont(): bitmap size overflow\n"); ++ goto Bail; ++ } ++ sizepadbitmaps += glyphBytes; ++ } ++ padbitmaps = malloc(sizepadbitmaps ? sizepadbitmaps : 1); + if (!padbitmaps) { + pcfError("pcfReadFont(): Couldn't allocate padbitmaps (%d)\n", sizepadbitmaps); + goto Bail; + } + new = 0; + for (i = 0; i < nbitmaps; i++) { ++ int srcGlyphBytes; ++ + old = offsets[i]; + metric = &metrics[i].metrics; ++ ++ /* Validate source offset and source glyph size against the ++ * source bitmap buffer to prevent out-of-bounds reads. */ ++ srcGlyphBytes = BYTES_PER_ROW( ++ metric->rightSideBearing - metric->leftSideBearing, ++ srcPad) * (metric->ascent + metric->descent); ++ if (old < 0 || old > sizebitmaps || ++ srcGlyphBytes < 0 || srcGlyphBytes > sizebitmaps - old) { ++ pcfError("pcfReadFont(): bitmap offset/size out of bounds\n"); ++ free(padbitmaps); ++ goto Bail; ++ } ++ + offsets[i] = new; + new += RepadBitmap(bitmaps + old, padbitmaps + new, +- PCF_GLYPH_PAD(format), glyph, ++ srcPad, glyph, + metric->rightSideBearing - metric->leftSideBearing, + metric->ascent + metric->descent); + } + free(bitmaps); + bitmaps = padbitmaps; ++ } else { ++ /* Validate offsets and full glyph extents against bitmap buffer */ ++ for (i = 0; i < nbitmaps; i++) { ++ int glyphBytes; ++ xCharInfo *metric = &metrics[i].metrics; ++ ++ glyphBytes = BYTES_PER_ROW( ++ metric->rightSideBearing - metric->leftSideBearing, ++ glyph) * (metric->ascent + metric->descent); ++ if (offsets[i] >= (CARD32)sizebitmaps || ++ glyphBytes < 0 || ++ glyphBytes > sizebitmaps - (int)offsets[i]) { ++ pcfError("pcfReadFont(): bitmap offset/size out of bounds " ++ "(offset %u, size %d, total %d)\n", ++ offsets[i], glyphBytes, sizebitmaps); ++ goto Bail; ++ } ++ } + } + for (i = 0; i < nbitmaps; i++) + metrics[i].bits = bitmaps + offsets[i]; +@@ -622,6 +672,10 @@ pcfReadFont(FontPtr pFont, FontFilePtr file, + if (IS_EOF(file)) goto Bail; + if (encodingOffset == 0xFFFF) { + pFont->info.allExist = FALSE; ++ } else if (encodingOffset >= nmetrics) { ++ pcfError("pcfReadFont(): encoding offset %d out of range (nmetrics=%d)\n", ++ encodingOffset, nmetrics); ++ goto Bail; + } else { + if(!encoding[SEGMENT_MAJOR(i)]) { + encoding[SEGMENT_MAJOR(i)]= +-- +2.43.0 + diff --git a/meta/recipes-graphics/xorg-lib/libxfont_1.5.4.bb b/meta/recipes-graphics/xorg-lib/libxfont_1.5.4.bb index 59c489b785d..08c96fdac87 100644 --- a/meta/recipes-graphics/xorg-lib/libxfont_1.5.4.bb +++ b/meta/recipes-graphics/xorg-lib/libxfont_1.5.4.bb @@ -20,6 +20,7 @@ XORG_EXT = "tar.bz2" BBCLASSEXTEND = "native" SRC_URI += "file://CVE-2026-56001.patch \ + file://CVE-2026-56002.patch \ " SRC_URI[sha256sum] = "1a7f7490774c87f2052d146d1e0e64518d32e6848184a18654e8d0bb57883242" From patchwork Wed Sep 9 07:29:23 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 97681 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 1A0D5C88E45 for ; Wed, 9 Sep 2026 07:30:13 +0000 (UTC) Received: from mail-wr1-f43.google.com (mail-wr1-f43.google.com [209.85.221.43]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.6445.1788939011736981609 for ; Wed, 09 Sep 2026 00:30:12 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=FdkGLVOa; spf=pass (domain: smile.fr, ip: 209.85.221.43, mailfrom: yoann.congal@smile.fr) Received: by mail-wr1-f43.google.com with SMTP id ffacd0b85a97d-4843efcbdb2so3316301f8f.2 for ; Wed, 09 Sep 2026 00:30:11 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1788939010; x=1789543810; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=lOn8cCIJ9Xz5xKUhydfcUQ/TFOOMJ/2bMNujRV1NfTM=; b=FdkGLVOaa1+A4iDvjQ+WU/44bkzYYYOanF/v1eqFzdhvE2JkOZ83K0D46x3UiX05iG Bvnv1mRmYR+GuqoZYgMH1tao8SJTp1cUO8Z3lXQD+xB/zjt44fIzn5p104Sudp1uMtgL mTeODrjwcSfZAbJ9LAdzPPo7/nuNAuNRAcykY= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1788939010; x=1789543810; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=lOn8cCIJ9Xz5xKUhydfcUQ/TFOOMJ/2bMNujRV1NfTM=; b=LuxVd27NYjt+Vhz9Bg2zYEaYd5N8dRvTWhz0u9NdvR1bfd709zlqpmzxsHMWJRa5hP 3B0gxU/J6YNGt0HCWxsrjMLb4Zz0ETh3d5fh/eMZeXxaVJuEXqKtxSgGOA/qItx6wCKP ya6T2Oy/K801k6hxeminY+0JJvPdlZP6EYOg98TNqIGGX3zYpi1sX7Oty3cEVIA8ObOF qyxqFf0ulZ9uokmczm7S/spJPeh5KW4n0CSOqMJCTHftdq0d6Hur7cPcyrD6cAYvcUc7 5W179boikvy7BT9nw4G2e/YQug01EQIHJeSoDkFfKlnGD5X0sbxr9lbQ73Ib5PN9gtwj OkJQ== X-Gm-Message-State: AFuF++nciVB131lUv1GHUvpzUeImAT31LNVxZYF4rqomk7qqyXptDkBr rNGUX/XOZdRQ1ZK0P9bGHYiZWoVedonAwVBhwxGdqSalwprukuu+FEVoG14gz2U28QZ3S8DEJSx 6fCigVHw= X-Gm-Gg: AYBFou33+2hFnoSLTeCPfq+HWMUtFl1rFvHLCW9vL7VObCrK1oI8fe5vZGbpyhKBVN/ QGISWNtsL72oRiUJAe2ieJVSECx/lq1zDtpP5CLBGYhpVe+ZGyYwJsCLcLx2EpORMQGzN36atHF fIZZQ/W/qpuQA5XjgQh2NRa+liLPufsES81rof1RUY4FbAyfrKOlsiuUhzS7atQBn5kjE58gDCp PH4h+eaaU8TWSmBaHkfMTNwDz0aaQRlPOH6fWmGqP154r6ktRs2//dtbg0ZJZnPpW08S2LiNH6V dqWrrUn5VDS5vC+Ae9UJGonCFepCS1I/Z2cP192aVyJL/KKGlMdqeU5+XlcJs1qoiIBqLwv75WO O6NY1GCTl7tN5InA/Yu4fCNykWLiaoCFt9JUbBXl5rbaWuZG2IjzBpjw5e0MxzHaj0NIdz99Y1A 2OHEdaM+TvgLh02rdUY/3VQ7Obbfm6OKsfxlnJbQsib+RIkjtYv2RLMq9l8ZugKphMjtZyw/Jqi IuPNiWg1VUmWPw09TZA/Q6OmOCMp+Gbav5w7QRuS9taawVKVwF1F7/pc2eIooHeoBIS6hziHgo= X-Received: by 2002:adf:e007:0:10b0:485:ac0e:6fa6 with SMTP id ffacd0b85a97d-485ac0e7071mr2184212f8f.14.1788939009897; Wed, 09 Sep 2026 00:30:09 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-4858ac2b4cdsm40624310f8f.16.2026.09.09.00.30.09 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 09 Sep 2026 00:30:09 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][wrynose 24/38] libxfont: Fix CVE-2026-56003 Date: Wed, 9 Sep 2026 09:29:23 +0200 Message-ID: <287aff0bef289587df0c4ebcf9ca155efb652c80.1788938909.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Wed, 09 Sep 2026 07:30:13 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/245433 From: Vijay Anusuri Pick patch according to [2] [1] https://nvd.nist.gov/vuln/detail/CVE-2026-56003 [2] https://security-tracker.debian.org/tracker/CVE-2026-56003 Signed-off-by: Vijay Anusuri Signed-off-by: Yoann Congal --- .../xorg-lib/libxfont/CVE-2026-56003.patch | 114 ++++++++++++++++++ .../xorg-lib/libxfont_1.5.4.bb | 1 + 2 files changed, 115 insertions(+) create mode 100644 meta/recipes-graphics/xorg-lib/libxfont/CVE-2026-56003.patch diff --git a/meta/recipes-graphics/xorg-lib/libxfont/CVE-2026-56003.patch b/meta/recipes-graphics/xorg-lib/libxfont/CVE-2026-56003.patch new file mode 100644 index 00000000000..0092c712d44 --- /dev/null +++ b/meta/recipes-graphics/xorg-lib/libxfont/CVE-2026-56003.patch @@ -0,0 +1,114 @@ +From dff957a5158da038a282a59a31fe736702732939 Mon Sep 17 00:00:00 2001 +From: Peter Hutterer +Date: Mon, 1 Jun 2026 16:49:55 +1000 +Subject: [PATCH] bitscale: add bounds check to computeProps for property + buffer + +ComputeScaledProperties allocates a fixed-size property buffer of 70 +slots. computeProps iterates the source font's properties and writes 1 +slot for unscaled properties or 2 slots for scaledX/scaledY properties, +with no bounds check. A malicious font with many duplicate properties +matching fontPropTable entries can overflow the allocated buffer. + +Fix this by passing the remaining buffer capacity to computeProps and +checking it before each write. Properties that would exceed the buffer +are silently skipped. + +The function is also restructured to handle the buffer writes for +scaledX/scaledY inside the switch cases directly, rather than in a +separate block after the switch. This makes the control flow clearer and +ensures the bounds check covers all writes. + +This vulnerability was discovered by: +Anonymous working with TrendAI Zero Day Initiative + +CVE-2026-56003/ZDI-CAN-30560 + +Assisted-by: Claude:claude-opus-4-6 +Signed-off-by: Peter Hutterer +Part-of: + +Upstream-Status: Backport [https://gitlab.freedesktop.org/xorg/lib/libxfont/-/commit/dff957a5158da038a282a59a31fe736702732939] +CVE: CVE-2026-56003 +Signed-off-by: Vijay Anusuri +--- + src/bitmap/bitscale.c | 39 ++++++++++++++++++++------------------- + 1 file changed, 20 insertions(+), 19 deletions(-) + +diff --git a/src/bitmap/bitscale.c b/src/bitmap/bitscale.c +index 32144d6..2affc11 100644 +--- a/src/bitmap/bitscale.c ++++ b/src/bitmap/bitscale.c +@@ -513,7 +513,8 @@ static int + computeProps(FontPropPtr pf, char *wasStringProp, + FontPropPtr npf, char *isStringProp, + unsigned int nprops, double xfactor, double yfactor, +- double sXfactor, double sYfactor) ++ double sXfactor, double sYfactor, ++ int maxprops) + { + int n; + int count; +@@ -528,14 +529,26 @@ computeProps(FontPropPtr pf, char *wasStringProp, + + switch (t->type) { + case scaledX: +- npf->value = doround(xfactor * (double)pf->value); +- rawfactor = sXfactor; +- break; + case scaledY: +- npf->value = doround(yfactor * (double)pf->value); +- rawfactor = sYfactor; ++ if (count + 2 > maxprops) ++ continue; ++ npf->value = (t->type == scaledX) ++ ? doround(xfactor * (double)pf->value) ++ : doround(yfactor * (double)pf->value); ++ rawfactor = (t->type == scaledX) ? sXfactor : sYfactor; ++ npf->name = pf->name; ++ npf++; ++ count++; ++ npf->value = doround(rawfactor * (double)pf->value); ++ npf->name = rawFontPropTable[t - fontPropTable].atom; ++ npf++; ++ count++; ++ *isStringProp++ = *wasStringProp; ++ *isStringProp++ = *wasStringProp; + break; + case unscaled: ++ if (count + 1 > maxprops) ++ continue; + npf->value = pf->value; + npf->name = pf->name; + npf++; +@@ -545,18 +558,6 @@ computeProps(FontPropPtr pf, char *wasStringProp, + default: + break; + } +- if (t->type != unscaled) +- { +- npf->name = pf->name; +- npf++; +- count++; +- npf->value = doround(rawfactor * (double)pf->value); +- npf->name = rawFontPropTable[t - fontPropTable].atom; +- npf++; +- count++; +- *isStringProp++ = *wasStringProp; +- *isStringProp++ = *wasStringProp; +- } + } + return count; + } +@@ -671,7 +672,7 @@ ComputeScaledProperties(FontInfoPtr sourceFontInfo, /* the font to be scaled */ + n = NPROPS; + n += computeProps(sourceFontInfo->props, sourceFontInfo->isStringProp, + fp, isStringProp, sourceFontInfo->nprops, dx, dy, +- sdx, sdy); ++ sdx, sdy, nProps - NPROPS); + return n; + } + +-- +2.43.0 + diff --git a/meta/recipes-graphics/xorg-lib/libxfont_1.5.4.bb b/meta/recipes-graphics/xorg-lib/libxfont_1.5.4.bb index 08c96fdac87..e254516fcf9 100644 --- a/meta/recipes-graphics/xorg-lib/libxfont_1.5.4.bb +++ b/meta/recipes-graphics/xorg-lib/libxfont_1.5.4.bb @@ -21,6 +21,7 @@ BBCLASSEXTEND = "native" SRC_URI += "file://CVE-2026-56001.patch \ file://CVE-2026-56002.patch \ + file://CVE-2026-56003.patch \ " SRC_URI[sha256sum] = "1a7f7490774c87f2052d146d1e0e64518d32e6848184a18654e8d0bb57883242" From patchwork Wed Sep 9 07:29:24 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 8bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 97693 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id E927AC79FBF for ; Wed, 9 Sep 2026 07:30:23 +0000 (UTC) Received: from mail-wr1-f50.google.com (mail-wr1-f50.google.com [209.85.221.50]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.6328.1788939013462494502 for ; Wed, 09 Sep 2026 00:30:13 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=HYToUbRG; spf=pass (domain: smile.fr, ip: 209.85.221.50, mailfrom: yoann.congal@smile.fr) Received: by mail-wr1-f50.google.com with SMTP id ffacd0b85a97d-4843efcbdb2so3316326f8f.2 for ; Wed, 09 Sep 2026 00:30:13 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1788939012; x=1789543812; darn=lists.openembedded.org; h=content-transfer-encoding:content-type:mime-version:references :in-reply-to:message-id:date:subject:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=6frAlEchsV8FNh7hyjSCuiiUPhVzWBPzEgYDNuQ/H7g=; b=HYToUbRGWb0keOD54oulDSR6pBa7nosjXLk4IpLvnxFE7lQdbrL+CFbQUa/JznEAXd 6ofoKy2wyzzeaKE1Q/ybeNgCq4/Q2CleItciRXXMXakUZWfScC4cZ7OsV0SWPdiEwEq8 M6ClJXxA0tiz/p3MbL5k85ufaX/Boq+beGur0= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1788939012; x=1789543812; h=content-transfer-encoding:content-type:mime-version:references :in-reply-to:message-id:date:subject:to:from:x-gm-gg :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to :content-type; bh=6frAlEchsV8FNh7hyjSCuiiUPhVzWBPzEgYDNuQ/H7g=; b=d0zmLJJ5h9TRWGIEOcL0EP6e68/49+N9KjjpdZOSmMHEDv/vyVTs99j3iakuSY6aa2 WzXjSz3A073vxKJKXgMW6MppxefFEbJJ5WhYfyih9tzGJ1sa/Ca/1FcLkngRmJF+D5UM onBB5127562dClngSHIldNDeHPQm+3XrssRFuAGbjJbYDtAk7HUNk0p8fHeCmN/HeLcT IJcA/c/BYJXgjEZqdADfneCc5mxm7IWhZHBSVb1KhoPcTD6Xdc8GPzO1wCyQ6V3qPoRY 0PFrmzDCmgVjFApAdJ8s3UEIdZ1vYA7ET9BGFKj+Hxzuw2AhBANmiH+X8TJnvjlNb2DA x/aw== X-Gm-Message-State: AFuF++lUhr3LL2DrO8LWh8D3krKriRoIqqdPIc67iElXwLiSGA8AD/nE oe307LBBBC/NC9mM13mtY3Wo0DcfNs6iMPH73N7ic9e9SW4Bao9Ol6pqyRwtuTrBgHlvZgscX/v pInvBJ4U= X-Gm-Gg: AYBFou1Kl017vLViwLF9RzAJz63Og02cQlaBkz4qV6zl1okL2I8g8SChR3fvFv3bnrC JXdZaC6zDFj7xHf1sdaHCY2kbxNiGj1ZmGYeHpNGGM0guYAzqaYwHE/JqWWjJupQkP9qkugBWFg pfUoOxgSg98GSiQsGzmgDSyZ0HYRlBQwRwZ+OlnAt1AMPUbHKFRTUT4kp453e+kLXLqR3LtNIxX 4hW56A9oBhIUGuVEFqShv22xGwTAJckATwDTl8GuETs/gnui8j3ycfUmhC480PJ5w69HwZw80zN 4lsRJybtqaOLn16b50zE9RvLC5aMYMIeQjpEWdDa0r/nEVP5OGckkF7miRqsy1NkedmsleY8tb0 XOUzuhsi+diydgjO8H133nOJCpcvLn9TlKpHRGbXHYbvP2/5I+jlNJ4uXnpxEHOHgnXq2YxAM7O uFUQR4uiLzlZM3H8UmGYe4dVr+Q5XWYW5aW5xf4zlroN3EJug5mhoQ7GVp+ER/x/HN4NHrfY+x/ IgWN64/5TrmFACq/thTGikgwoiaO2YBuWptdAA3tYeyxEnBaFQ02lbkCNry0sA22u7tUJ51gj4= X-Received: by 2002:a05:6000:2dc4:b0:485:8a47:5b8d with SMTP id ffacd0b85a97d-4858ddea668mr29865996f8f.42.1788939010692; Wed, 09 Sep 2026 00:30:10 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-4858ac2b4cdsm40624310f8f.16.2026.09.09.00.30.09 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 09 Sep 2026 00:30:10 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][wrynose 25/38] wget: fix CVE-2026-16599 Date: Wed, 9 Sep 2026 09:29:24 +0200 Message-ID: <0c600b59a2f1625c5eeffc76ef0e048aa7534788.1788938909.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Wed, 09 Sep 2026 07:30:23 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/245434 From: Ghanshyam Banait GNU wget is vulnerable to denial of service in its FTP OPIE/S-KEY authentication functionality. The server-supplied sequence number from the FTP challenge line is used as an iteration count for an MD5 key-derivation loop without any upper bound validation. A malicious FTP server or a network attacker positioned to intercept FTP traffic can send a crafted OPIE challenge with a sequence number near INT_MAX, causing wget to perform up to approximately 2.1 billion MD5 computations and suspend for some time. The --timeout option does not mitigate this because it applies only to network I/O, not CPU computation. This issue was fixed in commit e9697d98e7249b0f68a6be040a4f3dcc5bc101fa Reference: https://nvd.nist.gov/vuln/detail/cve-2026-16599 Backport the patch to fix CVE-2026-16599. https://gitlab.com/gnuwget/wget/-/commit/e9697d98e7249b0f68a6be040a4f3dcc5bc101fa Signed-off-by: Ghanshyam Banait Signed-off-by: Yoann Congal [YC: rewrapped commit message] --- .../wget/wget/CVE-2026-16599.patch | 68 +++++++++++++++++++ meta/recipes-extended/wget/wget_1.25.0.bb | 1 + 2 files changed, 69 insertions(+) create mode 100644 meta/recipes-extended/wget/wget/CVE-2026-16599.patch diff --git a/meta/recipes-extended/wget/wget/CVE-2026-16599.patch b/meta/recipes-extended/wget/wget/CVE-2026-16599.patch new file mode 100644 index 00000000000..fbe8c0566cd --- /dev/null +++ b/meta/recipes-extended/wget/wget/CVE-2026-16599.patch @@ -0,0 +1,68 @@ +From e9697d98e7249b0f68a6be040a4f3dcc5bc101fa Mon Sep 17 00:00:00 2001 +From: =?UTF-8?q?Tim=20R=C3=BChsen?= +Date: Sat, 20 Jun 2026 14:39:54 +0200 +Subject: [PATCH] Fix server-controlled unbounded MD5 loop in FTP OPIE +MIME-Version: 1.0 +Content-Type: text/plain; charset=UTF-8 +Content-Transfer-Encoding: 8bit + +* src/ftp-basic.c (ftp_login): Limit the skey sequence to 9999. + +Report: +wget accepts an unbounded server-controlled integer as the iteration +count for its OPIE/S-KEY MD5 key-derivation loop. No upper bound is +enforced on the sequence number supplied by the server in the FTP +challenge line. The value is passed directly to skey_response() as a +loop counter, causing wget to perform up to ~2.1 billion full MD5 +computations before responding to the authentication challenge. + +Reported-by: Michał Majchrowicz and Marcin Wyczechowski + +CVE: CVE-2026-16599 + +Upstream-Status: Backport [https://gitlab.com/gnuwget/wget/-/commit/e9697d98e7249b0f68a6be040a4f3dcc5bc101fa] + +Signed-off-by: Ghanshyam Banait +--- + src/ftp-basic.c | 15 +++++++++++---- + 1 file changed, 11 insertions(+), 4 deletions(-) + +diff --git a/src/ftp-basic.c b/src/ftp-basic.c +index 0f4bb821..af38a69a 100644 +--- a/src/ftp-basic.c ++++ b/src/ftp-basic.c +@@ -204,12 +204,11 @@ ftp_login (int csock, const char *acc, const char *pass) + "331 s/key ", + "331 opiekey " + }; +- size_t i; + const char *seed = NULL; + +- for (i = 0; i < countof (skey_head); i++) ++ for (size_t i = 0; i < countof (skey_head); i++) + { +- int l = strlen (skey_head[i]); ++ size_t l = strlen (skey_head[i]); + if (0 == c_strncasecmp (skey_head[i], respline, l)) + { + seed = respline + l; +@@ -222,7 +221,15 @@ ftp_login (int csock, const char *acc, const char *pass) + + /* Extract the sequence from SEED. */ + for (; c_isdigit (*seed); seed++) +- skey_sequence = 10 * skey_sequence + *seed - '0'; ++ { ++ skey_sequence = 10 * skey_sequence + *seed - '0'; ++ if (skey_sequence > 9999) ++ { ++ xfree (respline); ++ return FTPLOGREFUSED; ++ } ++ } ++ + if (*seed == ' ') + ++seed; + else +-- +GitLab + diff --git a/meta/recipes-extended/wget/wget_1.25.0.bb b/meta/recipes-extended/wget/wget_1.25.0.bb index dc4903429be..95845d695a9 100644 --- a/meta/recipes-extended/wget/wget_1.25.0.bb +++ b/meta/recipes-extended/wget/wget_1.25.0.bb @@ -21,6 +21,7 @@ SRC_URI = "${GNU_MIRROR}/wget/wget-${PV}.tar.gz \ file://CVE-2026-58471.patch \ file://CVE-2026-58472.patch \ file://CVE-2026-58472-regression.patch \ + file://CVE-2026-16599.patch \ " SRC_URI[sha256sum] = "766e48423e79359ea31e41db9e5c289675947a7fcf2efdcedb726ac9d0da3784" From patchwork Wed Sep 9 07:29:25 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 97685 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 8F154C79FB9 for ; Wed, 9 Sep 2026 07:30:23 +0000 (UTC) Received: from mail-wr1-f47.google.com (mail-wr1-f47.google.com [209.85.221.47]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.6329.1788939013568482827 for ; Wed, 09 Sep 2026 00:30:13 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=zfyj8Lrm; spf=pass (domain: smile.fr, ip: 209.85.221.47, mailfrom: yoann.congal@smile.fr) Received: by mail-wr1-f47.google.com with SMTP id ffacd0b85a97d-482e067e908so4375269f8f.2 for ; Wed, 09 Sep 2026 00:30:13 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1788939012; x=1789543812; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=rlix+JwxD7UI1BfGKYXrDSbKOeIItmD9P/hXYa4zxZ0=; b=zfyj8LrmkuMZlIaxuyaXulER3Hn0QzqNx0PPx85EeScftyzhI5tz01Mj+5KKqFmLW3 nk2SemFWem0TtYkkFk+CiQDNB0oosOMt2KZZLmv6U5w58SsyK613jbobwvnnJYlDo9gy 4TzwOQN0maQxx13TwvU4XbEvLLV5Y2RCMaIQE= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1788939012; x=1789543812; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=rlix+JwxD7UI1BfGKYXrDSbKOeIItmD9P/hXYa4zxZ0=; b=GpjkvHgDeYhX06T7qD36NuyY7h+3OmiFjnsqtFOaAVqC54SJS+YakjdwhoRbsKePwt w6ofCIcR2Xbykv3ZUWC+t1ggrSyGCsj3fZVNbXAdboeWeKyS0kqy+X6/kTqGJzhT3e/a N1Yj2cH2PTAV7oa/PmXec1vAm2HaTCKMFM58Kt/AovHEmcEqMVYVwBifWUVoBKVWBAuP 8yDVioNRqhllfHSfMmwZaKcvvE2TTrpHTzoj9Tt0pOG2IMyKe9twGDdqGCRbjMXWoYOk NcpGkYWMFxhI7/DNojrF6VGVcj4AQtvyY8FT9mEYKAEPYE4shDzoDhL3E1halG6h/Izs AkoA== X-Gm-Message-State: AFuF++nk9buV8KTEdyXNh9jf4AYZyyjEfNpJCcHUtFYO3jXpwh5d0Qfz EN8HkvLuxCvNrHgokmkWZEiVVEyVEglBjPv0tq0Y2g1fewcQVrNSknrbEJXoqJ+7YJp9ao5iimS +wd8Njyg= X-Gm-Gg: AYBFou344OuO4UmKsWb07b31lHIBd4pFsmAHaeyH/fgQeRkgKXTCGVqc5ymVN0Jzo1R nmr71ysq1KW5P3i5fdVbfTXtYdMcVstKfnjmqHtxet4hmqwNEzC8Mz7oDqjm7W991i+3ZjSxBs4 dJQRoXhbYk2Sxdlu2eWQJhi6f2ShcUPvN3G2D1VoWEoLbpVmBwjBwzczFBBZ5Y7YT7VFh2sdd1i L5Mmvl3FXiBy0EkwXEB7GjtWaKxppamWGORcQ7DikO+WsjDCvvqNrAmjmpybqJLUsdicHkViVU9 t9R3girZtsY+TL36YUD8UQmAlE7Thv5D4okf3JHaDBm88E09dIktpdgAhBU1f8wwwBKZpoaPY4s /TkM6UwSEXaZYGrlcXhDSix6jlT+c8XZJyxIZtxT3pYMrHK6y3souv/6ehrTVUe5cn6phJCMFgY 6D/sUBlvCQ3CqlxfSFHyN1SF2dTFG/sduYeXtwg86iSQHXSsBqIXZ1dlBIPkENvZE3FI3rhVzwA oPXxksr2iQbO0t5jBreANz2VjoaAW99R0aftmTmZfgo/7CXJyXRu8DJJKsem6RT5K9D/ZXIAz0= X-Received: by 2002:a05:6000:4a1e:b0:482:f0dc:b4f7 with SMTP id ffacd0b85a97d-48587091b97mr37547334f8f.4.1788939011638; Wed, 09 Sep 2026 00:30:11 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-4858ac2b4cdsm40624310f8f.16.2026.09.09.00.30.10 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 09 Sep 2026 00:30:10 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][wrynose 26/38] libarchive: mark CVE-2026-14164 as fixed-version Date: Wed, 9 Sep 2026 09:29:25 +0200 Message-ID: X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Wed, 09 Sep 2026 07:30:23 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/245435 From: Daniel Turull - The RAR5 double-free in init_unpack() is a regression introduced upstream by commit 620bdafa on 2026-05-16 and existed only on the git master branch until it was fixed by PR #3071 (commit 1c914cdf) on 2026-05-24. It was never part of an upstream release. - The upstream release tarballs (3.6.x/3.7.x/3.8.6) use the older init_unpack() with unchecked calloc and no early-return path, so the freed window_buf/filtered_buf pointers are never left dangling and the double-free cannot occur. References: https://nvd.nist.gov/vuln/detail/cve-2026-14164 https://lore.kernel.org/openembedded-core/0447ebc9d29b0736de8ba0c75f155ed4f880d072.camel@pbarker.dev/ Signed-off-by: Daniel Turull Signed-off-by: Yoann Congal --- meta/recipes-extended/libarchive/libarchive_3.8.7.bb | 4 ++++ 1 file changed, 4 insertions(+) diff --git a/meta/recipes-extended/libarchive/libarchive_3.8.7.bb b/meta/recipes-extended/libarchive/libarchive_3.8.7.bb index e8c3a3bfe3d..afc06f85d4c 100644 --- a/meta/recipes-extended/libarchive/libarchive_3.8.7.bb +++ b/meta/recipes-extended/libarchive/libarchive_3.8.7.bb @@ -92,3 +92,7 @@ RDEPENDS:${PN}-ptest += "bsdtar bsdcpio" CVE_STATUS[CVE-2026-4426] = "fixed-version: fixed since 3.8.7" CVE_STATUS[CVE-2026-5121] = "fixed-version: fixed since 3.8.7" CVE_STATUS[CVE-2026-5745] = "fixed-version: fixed since 3.8.6" +CVE_STATUS[CVE-2026-14164] = "fixed-version: Double-free regression in the RAR5\ + reader's init_unpack() was introduced upstream by commit 620bdafa (2026-05-16) and existed\ + only on the git master branch until the fix in PR #3071 (commit 1c914cdf, 2026-05-24). It was\ + never part of an upstream release tarball." From patchwork Wed Sep 9 07:29:26 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 97689 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id B89BEC79FBB for ; Wed, 9 Sep 2026 07:30:23 +0000 (UTC) Received: from mail-wr2-f12.google.com (mail-wr2-f12.google.com [74.125.225.76]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.6446.1788939014176373321 for ; Wed, 09 Sep 2026 00:30:14 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=kdGo/UcZ; spf=pass (domain: smile.fr, ip: 74.125.225.76, mailfrom: yoann.congal@smile.fr) Received: by mail-wr2-f12.google.com with SMTP id ffacd0b85a97d-484366874b0so355965f8f.2 for ; Wed, 09 Sep 2026 00:30:13 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1788939012; x=1789543812; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=/xz70x1STo52SYgPosnRhG/RARHHskdXc5ZJKEox3dU=; b=kdGo/UcZUKmRdxduM+QZXP/FPu3Z4iUi9ULHkF9/EO//huuRcoLiochH2HqkSbUAdr j5kWQOZs6us+YiQx1kUtXVDFkcKSZSRklxm0Xw0uwKG+Ftex1NIwnqupPt+6VQ2LTu4y ApVjPqKOeIIWSdsF1OWMXTKlFc0Q55yCCftzo= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1788939012; x=1789543812; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=/xz70x1STo52SYgPosnRhG/RARHHskdXc5ZJKEox3dU=; b=U42KJ5F2qz65vjIsnoF90P+60bv3XfXly2cWYq3cBbJF7f2I3Uf7mKiS60xodt8SKo /ICOogWRy5La0V2VTt6+8XE2OE7XJRnmtv6Ew/5rpwRnxaZsMPvQYxu0neNpC2dVR/Jx moDHuqbTdhYmUmjTzPva6SSc/I8toNBGgQBhKFaRhHoQ3lDaxcrh5S0WGIZKW66f20k6 7cpTOIfCIvlEmzHhVYDy+5oX3zYPg12Qr0vyaDgPoaynTjPwVE6ujeRsFEhARxPhS3QX kuT1qOAI/whiNAaL2S6sQYZn9+1tuWTxS9EhQXCkROoRQsaj5/3Uaj3WI85LCC9/L+/7 CeoA== X-Gm-Message-State: AFuF++nNYCSGJtSFETAOlbBGjebtl10bJ5mG/oSLXZofTnhpeB7U/s1/ 4adLbJ2y5gf+HPmq0WwpH1c8PiABo+FBinAunXu1TLmPiEvugPrDxRaHekkaSL6NzkcyHqezILZ tSqoXUmU= X-Gm-Gg: AYBFou2xjy/2Zrw7/1na6f6VZnBSlbuyJm85aS1/caXareGiNfADJKBXZksv0Xm0mIQ p9kej+cW5drqxIP8TciQoI4KCJos/LHorPA4HSwM7kYHecECZNOzF3o+6senAVqiiYQ5yUsFeuI F2YqYyEPtVsfTuNKF6TBwQFW7BwDxk6Q44PVjg8RvCvcbCTZ+yQ2RcVXx7nQatvo/oz6tT+IovN VIlsHAtjoDHni8KR8YWklYzlw0U1Zc55aTR3qLzZ8O2gpZWpGJP27utL90V3TmKXgx+Fq2SdY8o FqXBIJBk1GqURqy/Ao+D7H2nmJ5MOGbdOIUrfBXofXBf42s7x+GTNbygg6R7FOLlUQ46sV/FWer xMBK+Gx3YOCKy/T5PMipKXxMyYPcfItu4GVcRyJhggMg7hOAsVZW31dO7FUXk401SLjYYjuZxyH zuAf/pbbZKcu14suisPNhXzRiCNcixmdjkw4Dw3eDn731pYhC53vXPBJnlf3QYhEYcWX8lyp/kP hkoTQbjVK67xAEkobaXB1r9aKUC5ssL5PmBz7DLAhk9+oA70OzBzCZkFbD/Grg0QfDn90Cs6fjt sMSmFSZT/Q== X-Received: by 2002:a05:6000:41c8:b0:485:8d27:dbe7 with SMTP id ffacd0b85a97d-485aad9ec9amr8991233f8f.10.1788939012315; Wed, 09 Sep 2026 00:30:12 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-4858ac2b4cdsm40624310f8f.16.2026.09.09.00.30.11 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 09 Sep 2026 00:30:11 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][wrynose 27/38] u-boot-tools: Ignore CVE-2026-29007 Date: Wed, 9 Sep 2026 09:29:26 +0200 Message-ID: <3d02f9f0f0ac74275633f2f9eff9c568e351457d.1788938909.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Wed, 09 Sep 2026 07:30:23 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/245436 From: Hetvi Thakar Analysis: - NVD identifies the vulnerable code as net/tcp.c when CONFIG_PROT_TCP is enabled [1]. - tools-only_defconfig disables networking, so this code is not built into u-boot-tools [2]. - Hence ignoring the CVE for this recipe. Reference: [1] https://nvd.nist.gov/vuln/detail/CVE-2026-29007 [2] https://github.com/u-boot/u-boot/blob/v2026.01/configs/tools-only_defconfig Signed-off-by: Hetvi Thakar Signed-off-by: Yoann Congal --- meta/recipes-bsp/u-boot/u-boot-tools_2026.01.bb | 2 ++ 1 file changed, 2 insertions(+) diff --git a/meta/recipes-bsp/u-boot/u-boot-tools_2026.01.bb b/meta/recipes-bsp/u-boot/u-boot-tools_2026.01.bb index 7eaf721ca83..0e57bb88849 100644 --- a/meta/recipes-bsp/u-boot/u-boot-tools_2026.01.bb +++ b/meta/recipes-bsp/u-boot/u-boot-tools_2026.01.bb @@ -1,2 +1,4 @@ require u-boot-common.inc require u-boot-tools.inc + +CVE_STATUS[CVE-2026-29007] = "not-applicable-config: tools-only_defconfig disables networking; net/tcp.c is not compiled into u-boot-tools." From patchwork Wed Sep 9 07:29:27 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 97691 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 00D14C88E40 for ; Wed, 9 Sep 2026 07:30:24 +0000 (UTC) Received: from mail-wm1-f50.google.com (mail-wm1-f50.google.com [209.85.128.50]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.6330.1788939015027318241 for ; Wed, 09 Sep 2026 00:30:15 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=UtctylrJ; spf=pass (domain: smile.fr, ip: 209.85.128.50, mailfrom: yoann.congal@smile.fr) Received: by mail-wm1-f50.google.com with SMTP id 5b1f17b1804b1-49b9320423cso62402995e9.0 for ; Wed, 09 Sep 2026 00:30:14 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1788939013; x=1789543813; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=3TsAXj5s84GpEqC5k8/riVCCceTI60eu6933Jo9uEdA=; b=UtctylrJITpeZiKkACsRJvVdYMSfYXzXTiA06rXCdeX9UxXB+osSWTPmwv+8AC/xCF cuiWMbd3rkJEoej4fD3iMYYiL4uW2R4JqdeeqjQZ7t92k7l58s4kFj41gFQ8qIey1+0s Te7OTTZsV8huW+/cQuCnyB8iit/Yy9rqLPHG8= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1788939013; x=1789543813; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=3TsAXj5s84GpEqC5k8/riVCCceTI60eu6933Jo9uEdA=; b=FbJ2/vNZRyR3iaNc2S5gT1CnK+Nk1xvN6VayuxQsbT1lYSL3+tfA9Dy7S0yp0/n3vU 0W+nIoMByDnTM0tF0yQchjwdetIilr8+M6eeVXLf8vN0cu08ImrlKftLdi7uXexlKuEL YoTJg8Pks2XHnW0zepmsDdi0lYTJVEqxKvk5F+SfFEbhxBuaEuZhM2Mp36Ao1gvZJq6N xnuXKN569uYopVbiOph5HujiHuD3aHLDXKaoss/KQ8HSCKYRYLKThzkmS55mzyEUnPYR RhWPYJSE3HeppKNq9YG3iMKqNXknzVJ9YWFMFWs7qU2gwQTer/9s5MJVNpLzd4GhDAYJ DPKQ== X-Gm-Message-State: AFuF++nW13eR13y+TP9Tw7kwpLha2KQmF1j5UTfeBwIc+xUMYKtjjjAB /UtZcUSWV+TG6yzA+J4CsD3BN26aPtK7vRDqVuuk+SAdpoNryvKu38V4c8Y3darPN+vzW/AHCti KcRDZAoY= X-Gm-Gg: AYBFou39Xus/qwTLAgrlE4DDS84sONDTpnfF/0nqHpumy5He/6/tHiggtwb6g0n7R7D xyvA2eTvZ3CYcFeoABz1wqRq9VL3/h+ZDp3AFvUymszwGzAAcWlyVfxAPLiDvsL1EarAQEfhC8Z +Kw1SjY+wlWJP8iMlWG4iwuFj2BMBGHJWU/WBBpA/dx1zlLhmFbx+iduGn+chBHSMCN9zVKwta5 8e3oeBzRviUGD9PdkzFlyUPurqiPRHxIcLUyik0u5ni6E99BXbbL7tfpqK8jlMoG+NOWPOcalHz ioxiRx7Zj/2FPR69DVLfZdLGXFNPKF1GjShjBahjd1cdF8Hq9XUCZMcDqNRgJN9PASFVKODk8+7 6tT9BssS93DDkw78IrXCLDNvtyt9HaxL9iN9RDql2AF00Hwui4O/GDSVW/CYHCIm460u7iA6816 1yGXsZfCd8uFhGH2ZM/VZ18H02IEJz0W/lJHrIRlkz/b+YUegkQKRt1swe1HzyGL4ZPG/skORIl WKwky5iiUfIkDaOC3D3NNWjKpvPNxrH0DqGrwQfgSNIeNF1Emx2vSlTFse/jMicWnXKvXQBXXn+ GRdmBSP6QQ== X-Received: by 2002:a05:600c:1990:b0:49c:f512:2361 with SMTP id 5b1f17b1804b1-49cf82524a2mr517934265e9.14.1788939012996; Wed, 09 Sep 2026 00:30:12 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-4858ac2b4cdsm40624310f8f.16.2026.09.09.00.30.12 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 09 Sep 2026 00:30:12 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][wrynose 28/38] u-boot-tools: Ignore CVE-2026-29008 Date: Wed, 9 Sep 2026 09:29:27 +0200 Message-ID: X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Wed, 09 Sep 2026 07:30:24 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/245437 From: Hetvi Thakar Analysis: - NVD identifies the vulnerable code as net/tcp.c when CONFIG_PROT_TCP is enabled [1]. - tools-only_defconfig disables networking, so this code is not built into u-boot-tools [2]. - Hence ignoring the CVE for this recipe. Reference: [1] https://nvd.nist.gov/vuln/detail/CVE-2026-29008 [2] https://github.com/u-boot/u-boot/blob/v2026.01/configs/tools-only_defconfig Signed-off-by: Hetvi Thakar Signed-off-by: Yoann Congal --- meta/recipes-bsp/u-boot/u-boot-tools_2026.01.bb | 1 + 1 file changed, 1 insertion(+) diff --git a/meta/recipes-bsp/u-boot/u-boot-tools_2026.01.bb b/meta/recipes-bsp/u-boot/u-boot-tools_2026.01.bb index 0e57bb88849..6b28718c54a 100644 --- a/meta/recipes-bsp/u-boot/u-boot-tools_2026.01.bb +++ b/meta/recipes-bsp/u-boot/u-boot-tools_2026.01.bb @@ -2,3 +2,4 @@ require u-boot-common.inc require u-boot-tools.inc CVE_STATUS[CVE-2026-29007] = "not-applicable-config: tools-only_defconfig disables networking; net/tcp.c is not compiled into u-boot-tools." +CVE_STATUS[CVE-2026-29008] = "not-applicable-config: tools-only_defconfig disables networking; net/tcp.c is not compiled into u-boot-tools." From patchwork Wed Sep 9 07:29:28 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 97687 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id C5416C79FBC for ; Wed, 9 Sep 2026 07:30:23 +0000 (UTC) Received: from mail-wm1-f47.google.com (mail-wm1-f47.google.com [209.85.128.47]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.6331.1788939015749062391 for ; Wed, 09 Sep 2026 00:30:16 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=mPhuKP6u; spf=pass (domain: smile.fr, ip: 209.85.128.47, mailfrom: yoann.congal@smile.fr) Received: by mail-wm1-f47.google.com with SMTP id 5b1f17b1804b1-49d0d2d37ceso19280755e9.0 for ; Wed, 09 Sep 2026 00:30:15 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1788939014; x=1789543814; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=Kfp8lqJ3JstFipffuTIP1j8eENGdtTGif0xjP5C84bk=; b=mPhuKP6un7F0tN4omJ35+UG24jppzlTT1xcKB/gw0bj9xYGsjRZRf+2v+tRPP9TzBi 3LfnRmJZshR+gLq+ldxW6sObv8OY8Ois5EBRPjYj20cZ0jk20qMly4S/zbaVzquNjcqM gguwbz1Rb02/EC8QYb5pKDBG/XsmkXs2dL6G0= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1788939014; x=1789543814; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=Kfp8lqJ3JstFipffuTIP1j8eENGdtTGif0xjP5C84bk=; b=tOaYRZKlXjuRg2YUVBOMGkLGT1Ru/dDJ5tMbVdlMTcx/XRWmLZRdBmNnvpJ4wyGVMU UNiN7j32jsa2wpzYGVEddjBTX0doCgWp91LpZZsgCHuX6Ifawhf6Pf79naZQmuxaxxU9 RqheVK910X0C9yX8IjueEMLcHXKkmXaWK/DUebS/bJuJHkf8VBtIUCN9Oc8eI7QWtupP MEXkgSUop6f1Ux+yVO3DNIsfeNpnbcdnGI+etYauacmALYWSzG4vTArs6m/xLZ2QMNF9 sOttHXMrlO6rPIfkh1mem8CHSQiG+KnNTKJnW5W4JLarcjJmb2Pi0w1BYgGM0LnmBXWc /CGQ== X-Gm-Message-State: AFuF++l1gTozQL1hHqYCyojYeeEeTr5SBdy6yramQqeE6V0k/K/oIuMF p+FNkvgfMyC3bt0PgmzIuy6Kxg8XF90Mr8eMaXcno7e0aCw2/pph8b3+SaFyd68iFF32f7w9CCT Ejk9/PiE= X-Gm-Gg: AYBFou16lmJ7QKXURPzzHOV9iNumoowsVdzOMFYcSD26pOJRnVn50swFqkI1/fFpkfq /Ye7T4xAQngj3sjpphB2arXXvjhfjYnJoI30e6eIZ7pt6+cW3n79l1MH8ktmRlAV3lYp2/2xxrb fqkAB52yBNN5dwXGK086ohEXpBXydH9xVWeFQJYXKwGXBK2MJ6RypsqECJkqLLk0ZWNtek1EGZB fZ5UMy6PYSnJKZhninalipUc5ifb2j/3Ir1N5rZWByfYPmXstDzDemuz2amNtBAjp6SVaQNfLGg ymCNv6xOBA4eIJQ0LROYgKRsZvhvEzfMaW+JDYwfYT8kNzOrZir6Z09RZ4KPK1KYZHPoMCoYBmN yzMdubVZ3+lq0fS9dCU17LQRbpAcd+IppaMiuAflRQM6kJgi2+vDZRTBHD6Pz8JKisCaonUlpGf RQ/MmjGC420yorHVfiocsPttgwQom8bp9+7HhPKQdjCsOfFpQFvXddBLiSAWJ3s47zMUZUZGhI1 5TiL7cnQTKPbVQcqA3oEvuX9J+tO0JkugQQetE+1COkU3QrS7a0qzRG5EHMGb46Q1psIaxWr0GQ X-Received: by 2002:a05:600c:3b1f:b0:49c:ee06:9c58 with SMTP id 5b1f17b1804b1-49cf821eff7mr336208455e9.4.1788939013912; Wed, 09 Sep 2026 00:30:13 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-4858ac2b4cdsm40624310f8f.16.2026.09.09.00.30.13 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 09 Sep 2026 00:30:13 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][wrynose 29/38] u-boot-tools: Ignore CVE-2026-29009 Date: Wed, 9 Sep 2026 09:29:28 +0200 Message-ID: X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Wed, 09 Sep 2026 07:30:23 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/245438 From: Hetvi Thakar Analysis: - NVD identifies the vulnerable code as the NFS client implementation enabled by CONFIG_CMD_NFS [1]. - tools-only_defconfig disables networking, so net/nfs.c is not built into u-boot-tools [2]. - Hence ignoring the CVE for this recipe. Reference: [1] https://nvd.nist.gov/vuln/detail/CVE-2026-29009 [2] https://github.com/u-boot/u-boot/blob/v2026.01/configs/tools-only_defconfig Signed-off-by: Hetvi Thakar Signed-off-by: Yoann Congal --- meta/recipes-bsp/u-boot/u-boot-tools_2026.01.bb | 1 + 1 file changed, 1 insertion(+) diff --git a/meta/recipes-bsp/u-boot/u-boot-tools_2026.01.bb b/meta/recipes-bsp/u-boot/u-boot-tools_2026.01.bb index 6b28718c54a..5e2ed063868 100644 --- a/meta/recipes-bsp/u-boot/u-boot-tools_2026.01.bb +++ b/meta/recipes-bsp/u-boot/u-boot-tools_2026.01.bb @@ -3,3 +3,4 @@ require u-boot-tools.inc CVE_STATUS[CVE-2026-29007] = "not-applicable-config: tools-only_defconfig disables networking; net/tcp.c is not compiled into u-boot-tools." CVE_STATUS[CVE-2026-29008] = "not-applicable-config: tools-only_defconfig disables networking; net/tcp.c is not compiled into u-boot-tools." +CVE_STATUS[CVE-2026-29009] = "not-applicable-config: tools-only_defconfig disables networking; net/nfs.c is not compiled into u-boot-tools." From patchwork Wed Sep 9 07:29:29 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 97695 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 27A2BC88E42 for ; Wed, 9 Sep 2026 07:30:24 +0000 (UTC) Received: from mail-wm1-f52.google.com (mail-wm1-f52.google.com [209.85.128.52]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.6447.1788939017290049919 for ; Wed, 09 Sep 2026 00:30:17 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=XxwTcPpe; spf=pass (domain: smile.fr, ip: 209.85.128.52, mailfrom: yoann.congal@smile.fr) Received: by mail-wm1-f52.google.com with SMTP id 5b1f17b1804b1-49d05d51553so31953995e9.2 for ; Wed, 09 Sep 2026 00:30:17 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1788939015; x=1789543815; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=35pAHGcfz7UHc1nksZQJw1xk7rZPR/HiqIJGUry6dxw=; b=XxwTcPpeo0g1O6vSL5Tun/3ymQVNcMryhD34hAI5h1NGGfFYHEBT79zZS3V/RHbvAo wK/sAOeg+IbCPsrDJ4dJIQkIyXtEPhE2cA6mkZyvmG9eGEcZrEjPMfuBl7pqtbIViiyh 7am9NQ1yXOIdRwa+Z4UqtRmmUm7rNC06dtUtQ= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1788939015; x=1789543815; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=35pAHGcfz7UHc1nksZQJw1xk7rZPR/HiqIJGUry6dxw=; b=BOrWWsr4C30C03kmYMdK1PD5xVs7hoS7H+GaEPR8jA6HhMykRa+qqKFweBfXxEK0tS VSR8cWgVbqiXZMlqePol3Te3VIbrGG5zCFxuFAqx702eDu39iZZ1Q0zuRAqjPMTrdye1 2G/hdbhNkC/Os+1QGebmxJ/aa0CKBhbckM9qcgO1DSCaQp4f7LSU3jY2oKjhY+eAVYyP 6OyEuL67T3YZOK8PMEdDA8ZMW7DQoNWdfo0b9nDVoUxuOtgDKH67kHBnl9+hWwmePwoG Zg9pZ0uT5Ey0KW2DnFwf/9LyTyUSNd9/4+/4eNZlo2epRB3wxCmXiaH+6a+0xeTUIFd8 Q5tw== X-Gm-Message-State: AFuF++kPWMETu1IEx+RwV6KAF7jBufXqJEQ2r2TkCIpODiNWEABi5WdY hmFKeXZmJ4jUWqL17kwtbHJzsvgtXhG06j8Roqukb/w4hQ6QZOJAPW9Q552ii1yToS3NOt5yu+s DFx/liKA= X-Gm-Gg: AYBFou2kFndkRUuYb1Az5W0B5Mg3ia1GTkdifXTiqITJ5gcE4bqULMZ/Pt8x+z+sNUd drw+eGdIf5T5hN29uNeCCf2pePgvAPmhuESKWKqAZMMlhW3IrjKV9DO6Hn5K0dZHfL99WKZXZ5m tv9Hlzv8ritwoBysY8Ev+jBDw2gt86vyKHrn2k1OK0lUp32nDu8Xhh3wXjvvfKrFxvauLqWuA0U pEPNOL721iMmRlI8G84pjneWYAOv3lWBuVvn4A4evU3HZd9elRjtWhQhqkH35DFQqW7e0hhN2fC 4pfHkY9zmtAKrNWKs1TWRSRxXkjYyCvHw8KVS6r/YmiDC4Nyv5HABxVbZygW/6fBeVOmFBsS/BL /ihNoct1yhUXXZnJUzm1QPHAgAu9APJdGpDM4Uu57o6Ev422HgGcQ9vOnq9ioYcR3ejwigJp6n4 63QHCaOJnNTX6Wqof0d5L0N9txLk6BsmcMQWxNYBiQx8+tM3psZMCY7rUL5NZ5toA4S4X6YTEPF j/UU/kOH6l1niZDcfuRI5hLLrp+p6RJ00fWqTR0j8o/xD/90/IFdFU4+ctbBM0XoxrCgauWr9Ub X-Received: by 2002:a05:600c:1d0d:b0:49d:99c:3bd9 with SMTP id 5b1f17b1804b1-49d099c3fc9mr194483095e9.33.1788939015360; Wed, 09 Sep 2026 00:30:15 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-4858ac2b4cdsm40624310f8f.16.2026.09.09.00.30.13 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 09 Sep 2026 00:30:14 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][wrynose 30/38] u-boot, u-boot-tools: Correct CVE-2026-46728 attribution for FIT fix Date: Wed, 9 Sep 2026 09:29:29 +0200 Message-ID: X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Wed, 09 Sep 2026 07:30:24 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/245439 From: Hetvi Thakar CVE-2026-33243 is assigned to barebox, but NVD currently also maps it to denx:u-boot. That U-Boot mapping is incorrect because the U-Boot-side FIT hashed-nodes verification issue is tracked separately as CVE-2026-46728. A correction request has been sent to NVD to remove the incorrect denx:u-boot mapping. The existing patch backports U-Boot commit 2092322b31cc8b1f8c9e2e238d1043ae0637b241 [3], which is the U-Boot fix referenced by CVE-2026-46728 [2]. Rename the patch and update its CVE tag so the filename and metadata identify the affected U-Boot vendor correctly. Apply the same patch to u-boot-tools because that recipe builds fit_check_sign, which uses the affected FIT signature-verification path. The bootloader recipe already carried the backport, but u-boot-tools did not. [1] https://github.com/barebox/barebox/security/advisories/GHSA-3fvj-q26p-j6h4 [2] https://nvd.nist.gov/vuln/detail/CVE-2026-46728 [3] https://github.com/u-boot/u-boot/commit/2092322b31cc8b1f8c9e2e238d1043ae0637b241 Signed-off-by: Hetvi Thakar Signed-off-by: Yoann Congal --- .../{CVE-2026-33243.patch => CVE-2026-46728.patch} | 11 ++++++++--- meta/recipes-bsp/u-boot/u-boot-tools_2026.01.bb | 4 ++++ meta/recipes-bsp/u-boot/u-boot_2026.01.bb | 4 +++- 3 files changed, 15 insertions(+), 4 deletions(-) rename meta/recipes-bsp/u-boot/files/{CVE-2026-33243.patch => CVE-2026-46728.patch} (98%) diff --git a/meta/recipes-bsp/u-boot/files/CVE-2026-33243.patch b/meta/recipes-bsp/u-boot/files/CVE-2026-46728.patch similarity index 98% rename from meta/recipes-bsp/u-boot/files/CVE-2026-33243.patch rename to meta/recipes-bsp/u-boot/files/CVE-2026-46728.patch index c7086e183fb..4e582d529ea 100644 --- a/meta/recipes-bsp/u-boot/files/CVE-2026-33243.patch +++ b/meta/recipes-bsp/u-boot/files/CVE-2026-46728.patch @@ -28,11 +28,16 @@ Closes: https://lore.kernel.org/u-boot/20260302220937.3682128-1-trini@konsulko.c Reported-by: Apple Security Engineering and Architecture (SEAR) Tested-by: Tom Rini -[YB: Removed a skippable condition in fit_config_get_hash_list. - This flag is not available in this version] -CVE: CVE-2026-33243 +CVE: CVE-2026-46728 Upstream-Status: Backport [https://github.com/u-boot/u-boot/commit/2092322b31cc8b1f8c9e2e238d1043ae0637b241] + +Backport Changes: +Dropped the FIT_COMPAT_PROP condition because this macro is not +available in U-Boot v2026.01. + +(cherry picked from commit 2092322b31cc8b1f8c9e2e238d1043ae0637b241) Signed-off-by: Yanis Binard +Signed-off-by: Hetvi Thakar --- boot/image-fit-sig.c | 226 +++++++++++++++++++++++++++++------- doc/usage/fit/signature.rst | 19 ++- diff --git a/meta/recipes-bsp/u-boot/u-boot-tools_2026.01.bb b/meta/recipes-bsp/u-boot/u-boot-tools_2026.01.bb index 5e2ed063868..77e086815c1 100644 --- a/meta/recipes-bsp/u-boot/u-boot-tools_2026.01.bb +++ b/meta/recipes-bsp/u-boot/u-boot-tools_2026.01.bb @@ -1,6 +1,10 @@ require u-boot-common.inc require u-boot-tools.inc +SRC_URI += "file://CVE-2026-46728.patch" + +CVE_STATUS[CVE-2026-33243] = "cpe-incorrect: NVD currently maps this CVE to denx:u-boot, but that mapping is incorrect for U-Boot; the U-Boot-side FIT issue is tracked separately as CVE-2026-46728 and is fixed by the included U-Boot backport." + CVE_STATUS[CVE-2026-29007] = "not-applicable-config: tools-only_defconfig disables networking; net/tcp.c is not compiled into u-boot-tools." CVE_STATUS[CVE-2026-29008] = "not-applicable-config: tools-only_defconfig disables networking; net/tcp.c is not compiled into u-boot-tools." CVE_STATUS[CVE-2026-29009] = "not-applicable-config: tools-only_defconfig disables networking; net/nfs.c is not compiled into u-boot-tools." diff --git a/meta/recipes-bsp/u-boot/u-boot_2026.01.bb b/meta/recipes-bsp/u-boot/u-boot_2026.01.bb index 6d9bc126a16..9610d9e8fe0 100644 --- a/meta/recipes-bsp/u-boot/u-boot_2026.01.bb +++ b/meta/recipes-bsp/u-boot/u-boot_2026.01.bb @@ -3,7 +3,9 @@ require u-boot.inc DEPENDS += "bc-native dtc-native gnutls-native python3-pyelftools-native" -SRC_URI += "file://CVE-2026-33243.patch" +SRC_URI += "file://CVE-2026-46728.patch" + +CVE_STATUS[CVE-2026-33243] = "cpe-incorrect: NVD currently maps this CVE to denx:u-boot, but that mapping is incorrect for U-Boot; the U-Boot-side FIT issue is tracked separately as CVE-2026-46728 and is fixed by the included U-Boot backport." # workarounds for aarch64 kvm qemu boot regressions SRC_URI:append:qemuarm64 = " file://disable-CONFIG_BLOBLIST.cfg" From patchwork Wed Sep 9 07:29:30 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 97684 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 6620BC79F8C for ; Wed, 9 Sep 2026 07:30:23 +0000 (UTC) Received: from mail-wr1-f54.google.com (mail-wr1-f54.google.com [209.85.221.54]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.6333.1788939018648968584 for ; Wed, 09 Sep 2026 00:30:18 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=eJr4+0Q6; spf=pass (domain: smile.fr, ip: 209.85.221.54, mailfrom: yoann.congal@smile.fr) Received: by mail-wr1-f54.google.com with SMTP id ffacd0b85a97d-485850cf499so3709578f8f.3 for ; Wed, 09 Sep 2026 00:30:18 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1788939017; x=1789543817; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=nILTlRiDZSO/29qteBww/HqazTdJX9MdU9pEP4KAU6c=; b=eJr4+0Q6lgnmQCwWk/wYZWj6S6gFtEzcr2MmnQph/HYDviYH9CdlZIq2qfjdSegRte rGHySAof0HLRVAEFagQvM7UIhTl5IcwQ3Tx0+HwWjdAYzJPcSlsUn0U10b2gadaGL9yh eWbngUOnr4IYDibhFfiLLESxfOmaGiEsPHhNg= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1788939017; x=1789543817; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=nILTlRiDZSO/29qteBww/HqazTdJX9MdU9pEP4KAU6c=; b=GE8rWBug8oNhWlLAd4vnRXzvdaLGNEhUvoSx42m8Gsutl9rUh8usTo4Hanw7snyXrK +s/k9cF/7E/OSqvtA8VadJ2jvOxxxT2lJOiwH2EAgdYf8YmQIOKP5w7ujLcIRfzs629V aZOsnSTKKdELT8n2RsnOn+mNzcoj0yXjz0tZ/dAOsqH/Y7n7SdIYfFrfEigLrcN5B/R1 Jr8miZahZ/ono+7AsNqqHQsreHUOCrkD3GxyX/ybhGwad/3ccnkUawuFituyZcNP5pjC dDGlp/BWz8Kiy32kUB3uUTBq+IyQCXghhkHex/wM6oXJrU+pywcUvG6WHWVI1xIc3aXb Hzvw== X-Gm-Message-State: AFuF++mh60d/VL+H8N9kg+3XuLmggjqPxYFHw/bQjMZ5dROFOr4krcAO aM7HV0RmtXdmbhmffKhLR88kYEy3WBgOPLpCgbeSQKFmotdL0/lA4at5Ou7Y2pyey5ND1NDrAxB Tf2XZK40= X-Gm-Gg: AYBFou1lsEg/CxyI8b2Z59z9ZVLTqKUX8c9Y08d/CF67IiUuMfiPsv/In+usF8ZnWh7 DKNepkqLZvIzec0JVw90cXC07Z1IaZsfsGF1uZkwaAIfho7jv/S/GBPRhNAoz3586U0KzW+UivD GErzg/W2p4BvXC7dLGLD4FAQYEfebnsNOxJx1FTOnYjHBpvwxuze+6vfJdgT6Etv08hNdB9AknR KsQKkdr0hpsIyDCfhYNiDvUauuLls0BzYVaz+lQ3RntOEwDVy0keWHV0nsvdoYPgQhaZ2sYFtk0 m/KvQyPHFb3vKc1MrJwWvrQOKaFyGf7o1+MKmzAlQ83IYAimfnEo/k+FNWeeWdGz1odfqn6bZKZ AYLikNyxtNr0aYY2XsC9Rm/nbgIjh4nrHIJN6TkVCXKOlpMKJO0tXBVM3/MyKSLVLjkDEb2BxSy V05A32QTyxsT3k1r+xgGawS2Q7se9x/AAPzSy3sA8af3idONtufrE0yxf11D1Zbqjo9YTlwgFCn dywAwnhcDFt/LI2mlQocV3k04aXw6zCwqgtOYPvXq3mYROxd+VyuiuTx/9Q4AK70YE7cAiihms= X-Received: by 2002:a05:6000:4a1a:b0:485:8c17:976c with SMTP id ffacd0b85a97d-4858c17994cmr29970440f8f.46.1788939016274; Wed, 09 Sep 2026 00:30:16 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-4858ac2b4cdsm40624310f8f.16.2026.09.09.00.30.15 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 09 Sep 2026 00:30:15 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][wrynose 31/38] wpa-supplicant: patch CVE-2026-58374 Date: Wed, 9 Sep 2026 09:29:30 +0200 Message-ID: X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Wed, 09 Sep 2026 07:30:23 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/245440 From: Ankur Tyagi Apply patches recommended by upstream[1] as mentioned in the NVD[2] [1] https://w1.fi/security/2026-1/ [2] https://nvd.nist.gov/vuln/detail/cve-2026-58374 Signed-off-by: Ankur Tyagi Signed-off-by: Yoann Congal --- .../wpa-supplicant/CVE-2026-58374-1.patch | 52 ++++++++++++++++++ .../wpa-supplicant/CVE-2026-58374-2.patch | 47 ++++++++++++++++ .../wpa-supplicant/CVE-2026-58374-3.patch | 55 +++++++++++++++++++ .../wpa-supplicant/CVE-2026-58374-4.patch | 46 ++++++++++++++++ .../wpa-supplicant/CVE-2026-58374-5.patch | 47 ++++++++++++++++ .../wpa-supplicant/wpa-supplicant_2.11.bb | 5 ++ 6 files changed, 252 insertions(+) create mode 100644 meta/recipes-connectivity/wpa-supplicant/wpa-supplicant/CVE-2026-58374-1.patch create mode 100644 meta/recipes-connectivity/wpa-supplicant/wpa-supplicant/CVE-2026-58374-2.patch create mode 100644 meta/recipes-connectivity/wpa-supplicant/wpa-supplicant/CVE-2026-58374-3.patch create mode 100644 meta/recipes-connectivity/wpa-supplicant/wpa-supplicant/CVE-2026-58374-4.patch create mode 100644 meta/recipes-connectivity/wpa-supplicant/wpa-supplicant/CVE-2026-58374-5.patch diff --git a/meta/recipes-connectivity/wpa-supplicant/wpa-supplicant/CVE-2026-58374-1.patch b/meta/recipes-connectivity/wpa-supplicant/wpa-supplicant/CVE-2026-58374-1.patch new file mode 100644 index 00000000000..625371c2b55 --- /dev/null +++ b/meta/recipes-connectivity/wpa-supplicant/wpa-supplicant/CVE-2026-58374-1.patch @@ -0,0 +1,52 @@ +From 708a4247581c98c0cc46504e4abb874b4c835ffe Mon Sep 17 00:00:00 2001 +From: Jouni Malinen +Date: Tue, 31 Mar 2026 23:24:04 +0300 +Subject: [PATCH 1/5] AP MLD: Fix link ID validation in Basic MLE parsing + +Link ID 15 can be indicated in the field, but that is not a valid value +and must be rejected to avoid issues pointing beyond the array of links +for a non-AP MLD. Without this, an invalid MLE could result in writing +beyond the end of the buffer and causing process termination or +unexpected behavior. + +Fixes: 5f5db9366cde ("AP: MLO: Process Multi-Link element from (Re)Association Request frame") +Signed-off-by: Jouni Malinen + +CVE: CVE-2026-58374 +Upstream-Status: Backport [https://git.w1.fi/cgit/hostap/commit/?id=46dd5a4ffc9bcf44cf8fc45120b3e1e5ec922187] +Signed-off-by: Ankur Tyagi +--- + src/ap/ieee802_11_eht.c | 10 ++++++++-- + 1 file changed, 8 insertions(+), 2 deletions(-) + +diff --git a/src/ap/ieee802_11_eht.c b/src/ap/ieee802_11_eht.c +index b935ee889a89..804808c0dbfd 100644 +--- a/src/ap/ieee802_11_eht.c ++++ b/src/ap/ieee802_11_eht.c +@@ -1262,6 +1262,7 @@ u16 hostapd_process_ml_assoc_req(struct hostapd_data *hapd, + size_t sub_elem_len = *(pos + 1); + size_t sta_info_len; + u16 control; ++ u8 link_id; + + wpa_printf(MSG_DEBUG, "MLD: sub element len=%zu", + sub_elem_len); +@@ -1302,8 +1303,13 @@ u16 hostapd_process_ml_assoc_req(struct hostapd_data *hapd, + goto out; + } + control = WPA_GET_LE16(pos); +- link_info = &info->links[control & +- EHT_PER_STA_CTRL_LINK_ID_MSK]; ++ link_id = control & BASIC_MLE_STA_CTRL_LINK_ID_MASK; ++ if (link_id >= MAX_NUM_MLD_LINKS) { ++ wpa_printf(MSG_DEBUG, ++ "MLD: Invalid Link ID in Per-STA Profile subelement"); ++ goto out; ++ } ++ link_info = &info->links[link_id]; + pos += 2; + ml_len -= 2; + sub_elem_len -= 2; +-- +2.43.0 + diff --git a/meta/recipes-connectivity/wpa-supplicant/wpa-supplicant/CVE-2026-58374-2.patch b/meta/recipes-connectivity/wpa-supplicant/wpa-supplicant/CVE-2026-58374-2.patch new file mode 100644 index 00000000000..07dd9d3a65f --- /dev/null +++ b/meta/recipes-connectivity/wpa-supplicant/wpa-supplicant/CVE-2026-58374-2.patch @@ -0,0 +1,47 @@ +From 00e74b2f6e21e4d01aa58433a441ca4c81fb10ab Mon Sep 17 00:00:00 2001 +From: Amarnath Hullur Subramanyam +Date: Thu, 30 Apr 2026 18:24:35 -0700 +Subject: [PATCH 2/5] BSS: Add bounds check for link_id in Basic MLE parsing + +In wpa_bss_parse_basic_ml_element() in bss.c, an extracted link_id is +used without validation against the maximum allowed links +(MAX_NUM_MLD_LINKS). Processing a malformed Basic Multi-Link element +(MLE) with an out-of-bounds link_id could lead to memory corruption. +However, the modified location is within the body of the received frame +and as such, this does not result in additional issues since that area +is controlled by the transmitter of the frame. In any case, it is better +to be explicit with validating the Link ID value. + +This commit introduces a strict bounds check immediately after link_id +extraction. If link_id exceeds or equals MAX_NUM_MLD_LINKS, parsing is +gracefully aborted with a debug log entry. + +Fixes: de5e01010cb2 ("wpa_supplicant: Support ML probe request") +Signed-off-by: Amarnath Hullur Subramanyam + +CVE: CVE-2026-58374 +Upstream-Status: Backport [https://git.w1.fi/cgit/hostap/commit/?id=aa9d345887389a251c63a3781d2ad2940d079193] +Signed-off-by: Ankur Tyagi +--- + wpa_supplicant/bss.c | 5 +++++ + 1 file changed, 5 insertions(+) + +diff --git a/wpa_supplicant/bss.c b/wpa_supplicant/bss.c +index e8aaf6fe1848..11950064a1b6 100644 +--- a/wpa_supplicant/bss.c ++++ b/wpa_supplicant/bss.c +@@ -1710,6 +1710,11 @@ int wpa_bss_parse_basic_ml_element(struct wpa_supplicant *wpa_s, + ETH_ALEN); + + link_id = ml_basic_common_info->variable[0] & EHT_ML_LINK_ID_MSK; ++ if (link_id >= MAX_NUM_MLD_LINKS) { ++ wpa_printf(MSG_DEBUG, "MLD: Invalid link ID %u in Basic MLE", ++ link_id); ++ goto out; ++ } + + bss->mld_link_id = link_id; + seen = bss->valid_links = BIT(link_id); +-- +2.43.0 + diff --git a/meta/recipes-connectivity/wpa-supplicant/wpa-supplicant/CVE-2026-58374-3.patch b/meta/recipes-connectivity/wpa-supplicant/wpa-supplicant/CVE-2026-58374-3.patch new file mode 100644 index 00000000000..9e28d0a95a3 --- /dev/null +++ b/meta/recipes-connectivity/wpa-supplicant/wpa-supplicant/CVE-2026-58374-3.patch @@ -0,0 +1,55 @@ +From ae24a10634f6e19d75888f5d786f380bb7af5b86 Mon Sep 17 00:00:00 2001 +From: Jouni Malinen +Date: Tue, 31 Mar 2026 23:16:08 +0300 +Subject: [PATCH 3/5] MLD: Validate MLE Link ID fields in association rejection + case + +The Link ID Info field in the Common Info field needs to ignore the +reserved bits to be more extensible for future. Both that link ID for +the association link and the link IDs for other links need to be +verified to be within the valid range (0-14), so check that here. The +parsed link ID was not used for anything yet, but it is better to make +sure this in theory common parser is not exposing invalid data to the +caller should it be used for additional purposes in the future. + +Signed-off-by: Jouni Malinen + +CVE: CVE-2026-58374 +Upstream-Status: Backport [https://git.w1.fi/cgit/hostap/commit/?id=a8531e3d871e6fa72f2f85d91e9f787326b2af8b] +Signed-off-by: Ankur Tyagi +--- + wpa_supplicant/events.c | 11 ++++++++++- + 1 file changed, 10 insertions(+), 1 deletion(-) + +diff --git a/wpa_supplicant/events.c b/wpa_supplicant/events.c +index 49917f7aaf72..600718d8efc4 100644 +--- a/wpa_supplicant/events.c ++++ b/wpa_supplicant/events.c +@@ -3864,7 +3864,12 @@ static unsigned int wpas_ml_parse_assoc(struct wpa_supplicant *wpa_s, + pos = common_info->variable; + + /* Store the information for the association link */ +- ml_info[i].link_id = *pos; ++ ml_info[i].link_id = *pos & EHT_ML_LINK_ID_MSK; ++ if (ml_info[i].link_id >= MAX_NUM_MLD_LINKS) { ++ wpa_printf(MSG_DEBUG, ++ "MLD: Invalid Link ID value for assoc link"); ++ goto out; ++ } + pos++; + + /* Skip the BSS Parameters Change Count */ +@@ -3999,6 +4004,10 @@ static unsigned int wpas_ml_parse_assoc(struct wpa_supplicant *wpa_s, + MAC2STR(pos + 1), nstr_bitmap_len); + + ml_info[i].link_id = ctrl & EHT_PER_STA_CTRL_LINK_ID_MSK; ++ if (ml_info[i].link_id >= MAX_NUM_MLD_LINKS) { ++ wpa_printf(MSG_DEBUG, "MLD: Invalid Link ID value"); ++ goto out; ++ } + os_memcpy(ml_info[i].bssid, pos + 1, ETH_ALEN); + + pos += sta_info_len; +-- +2.43.0 + diff --git a/meta/recipes-connectivity/wpa-supplicant/wpa-supplicant/CVE-2026-58374-4.patch b/meta/recipes-connectivity/wpa-supplicant/wpa-supplicant/CVE-2026-58374-4.patch new file mode 100644 index 00000000000..1f42a4017f1 --- /dev/null +++ b/meta/recipes-connectivity/wpa-supplicant/wpa-supplicant/CVE-2026-58374-4.patch @@ -0,0 +1,46 @@ +From c4fc1bf2fd7fe6bebf72d32385bc2bd20d144093 Mon Sep 17 00:00:00 2001 +From: Jouni Malinen +Date: Mon, 18 May 2026 15:45:15 +0300 +Subject: [PATCH 4/5] AP MLD: Verify AP MLD link ID validity before updating + bitmap of links + +Link ID is 0..14, so ignore value 15 if an invalid frame is processed. +It does not look like the invalid value was actually used to reference +any local array, but in any case, it is better to not mark an invalid +link as being specified. + +Signed-off-by: Jouni Malinen + +CVE: CVE-2026-58374 +Upstream-Status: Backport [https://git.w1.fi/cgit/hostap/commit/?id=ce1a8612e309fe86133ecf05ffb452b0bdf3b035] +Signed-off-by: Ankur Tyagi +--- + src/ap/beacon.c | 5 ++++- + 1 file changed, 4 insertions(+), 1 deletion(-) + +diff --git a/src/ap/beacon.c b/src/ap/beacon.c +index cec0c9829fd9..cc295c18f61b 100644 +--- a/src/ap/beacon.c ++++ b/src/ap/beacon.c +@@ -1305,6 +1305,7 @@ static bool parse_ml_probe_req(const struct ieee80211_eht_ml *ml, size_t ml_len, + for_each_element_id(sub, 0, pos, len) { + const struct ieee80211_eht_per_sta_profile *sta; + u16 sta_control; ++ u8 link_id; + + if (*links == 0xffff) + *links = 0; +@@ -1324,7 +1325,9 @@ static bool parse_ml_probe_req(const struct ieee80211_eht_ml *ml, size_t ml_len, + * partial profile was requested. + */ + sta_control = le_to_host16(sta->sta_control); +- *links |= BIT(sta_control & EHT_PER_STA_CTRL_LINK_ID_MSK); ++ link_id = sta_control & BASIC_MLE_STA_CTRL_LINK_ID_MASK; ++ if (link_id < MAX_NUM_MLD_LINKS) ++ *links |= BIT(link_id); + } + + if (!for_each_element_completed(sub, pos, len)) { +-- +2.43.0 + diff --git a/meta/recipes-connectivity/wpa-supplicant/wpa-supplicant/CVE-2026-58374-5.patch b/meta/recipes-connectivity/wpa-supplicant/wpa-supplicant/CVE-2026-58374-5.patch new file mode 100644 index 00000000000..34a0c0af3ba --- /dev/null +++ b/meta/recipes-connectivity/wpa-supplicant/wpa-supplicant/CVE-2026-58374-5.patch @@ -0,0 +1,47 @@ +From dad0d98570e3615b441d1c1e72e2945483a6fe77 Mon Sep 17 00:00:00 2001 +From: Jouni Malinen +Date: Tue, 31 Mar 2026 17:47:03 +0300 +Subject: [PATCH 5/5] MLD: Fix length check in common info for association + failure cases + +It is not sufficient to check that the indicated common info length is +sufficiently large to contain the information; there needs to be a check +for the indicated value to not be too large to go beyond the end of the +MLE as well. Without this, invalid MLE might result in ml_len wrapping +around to a huge value and reading beyond the end of the buffer for the +received frame. This could result in process termination. + +Add the missed check for the Common Info field not being truncated in +the MLE in association failure cases. + +Fixes: a58a0c592e20 ("MLD: Fix Multi-Link element parsing for association failures") +Signed-off-by: Jouni Malinen + +CVE: CVE-2026-58374 +Upstream-Status: Backport [https://git.w1.fi/cgit/hostap/commit/?id=41c86a2ebed50567c73de23c102c2bf83eb883f2] +Signed-off-by: Ankur Tyagi +--- + wpa_supplicant/events.c | 7 +++++++ + 1 file changed, 7 insertions(+) + +diff --git a/wpa_supplicant/events.c b/wpa_supplicant/events.c +index 600718d8efc4..d81578438588 100644 +--- a/wpa_supplicant/events.c ++++ b/wpa_supplicant/events.c +@@ -3852,6 +3852,13 @@ static unsigned int wpas_ml_parse_assoc(struct wpa_supplicant *wpa_s, + goto out; + } + ++ if (sizeof(*ml) + common_info->len > ml_len) { ++ wpa_printf(MSG_DEBUG, ++ "MLD: Truncated common info (common_info->len=%u ml_len=%zu)", ++ common_info->len, ml_len); ++ goto out; ++ } ++ + wpa_printf(MSG_DEBUG, "MLD: address: " MACSTR, + MAC2STR(common_info->mld_addr)); + +-- +2.43.0 + diff --git a/meta/recipes-connectivity/wpa-supplicant/wpa-supplicant_2.11.bb b/meta/recipes-connectivity/wpa-supplicant/wpa-supplicant_2.11.bb index 7c7a8bd9c13..7d1f9ffc6d6 100644 --- a/meta/recipes-connectivity/wpa-supplicant/wpa-supplicant_2.11.bb +++ b/meta/recipes-connectivity/wpa-supplicant/wpa-supplicant_2.11.bb @@ -21,6 +21,11 @@ SRC_URI = "http://w1.fi/releases/wpa_supplicant-${PV}.tar.gz \ file://0004-defconfig-Uncomment-CONFIG_IEEE80211BE-y.patch \ file://CVE-2025-24912-01.patch \ file://CVE-2025-24912-02.patch \ + file://CVE-2026-58374-1.patch \ + file://CVE-2026-58374-2.patch \ + file://CVE-2026-58374-3.patch \ + file://CVE-2026-58374-4.patch \ + file://CVE-2026-58374-5.patch \ " SRC_URI[sha256sum] = "912ea06f74e30a8e36fbb68064d6cdff218d8d591db0fc5d75dee6c81ac7fc0a" From patchwork Wed Sep 9 07:29:31 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 97686 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 9B09CC79FB8 for ; Wed, 9 Sep 2026 07:30:23 +0000 (UTC) Received: from mail-wm1-f50.google.com (mail-wm1-f50.google.com [209.85.128.50]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.6334.1788939018885887130 for ; Wed, 09 Sep 2026 00:30:19 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=JuPKRRpR; spf=pass (domain: smile.fr, ip: 209.85.128.50, mailfrom: yoann.congal@smile.fr) Received: by mail-wm1-f50.google.com with SMTP id 5b1f17b1804b1-49b8687630fso46277455e9.3 for ; Wed, 09 Sep 2026 00:30:18 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1788939017; x=1789543817; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=SQVFAkc0LRgEfAgQZdw9j4YKAWZ4rNq+VtJOKM8D8PU=; b=JuPKRRpR6R3y7Pn3Ib9YKdnrTJVtAL90IWNUZWYKdnT5hJKL2i4hmBWiiHy1kEifvt P206dZU5v3TFIzzfwC0VQ0ueL8NB9+sDZfyrRKIfGqK4bYrodDaZ74fWPwqLEjcvml+i Ni7j/C/AjLm9cx0McyBcBIqjNrak7RXfkELl0= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1788939017; x=1789543817; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=SQVFAkc0LRgEfAgQZdw9j4YKAWZ4rNq+VtJOKM8D8PU=; b=btEqUy5djWwVp7BDZgunN+60UW+48wSpXftNRe4Ps7j1cof3rTPTM9h8H1MgYNclqu Gty72eIy5dK4pbq5vMX5HJ/MlJSc2zN6ZxMUJnN8kyyukfLBROcXgE8rHYEHVyQzUWEy baqjDcM7KFsx2JrhOxM5UDNJCFCrQ3+7ymqBRGFBBNcRGqflzJnG6XIEjtpbxRZKDK9K BUqAWhT2aKTMxPg0Q23uHAD1WBGP/VeC/Nu80uEFUnjjweCV1vwgXSy2urbgwMaodUNo bYgOT1vUoDnGp84vp4o8z+q5oSmiIcuE+V1yDF3gtLnkSb9puxYMNmFXXoIRIqVYPeK+ 1l0Q== X-Gm-Message-State: AFuF++mdkedfMqRUf88nQWpkyoYD1aE0T857KU0NHPPIWNPUJ/avMI7t IBfoHE26NqRGmvfR9pqwuwImef7Y1OA4eWjEDWA2qVBVMq1M8cLVgu3RCRFrGqhTvulsTsYVZsE DDW7BOrw= X-Gm-Gg: AYBFou1qpA5B9AgekK442QIM+18nRV9AzOeniKcUlya1R0pFSx25zjDcTp3puJ5hQ2q bq81z/eTodiKKgfmtaN2SOuLYtwG4cJCpLJkexd+oTbGptPm+kNS0C9U8ecdWmNwZTi4KAynYbh Q6JpYos2qv95ZGgHD9YEmjjzPKsFrmh48vcUmFfwxrOhKxDKnz5MEo24FPFgnaxBzNV9v9Th1Wk dds73R8Fanrn4MECtj+FMtnhWcTpNZgPhbeKhmeQmHbWjPJVywTcUHDZ7ed6AAlTHpLD4EIxwRI XwZf9NfD8qRPtD4lAzZkI37CUt0WauErIpOwF7SUpiWXhp3pqEPNQC5R3c2tCiRBdHDrMyhOvZu GpKYxMTIvgzQwKyqn86Mk5glpnexcjVPpcCezae1AZocM/fnfDG64qBzSzy3K+7cDU1TmZeTYdz NHHA8Yx4gPTfxwy+UA6AnoYDxg9MjOPyn7+5Ef5p8vuQ4Zn+HlgutwxcvDHlAZ4czVUYw3FWdXx dYXAkLmhcei88SMWVyZU3QIsZmY/9mQG8t1YoBlOUn7YjbUvv1FgXKqiwtWzRAaPrpOwQWe1Qm7 vFOfFeRqUQ== X-Received: by 2002:a05:600c:350f:b0:499:b65d:124f with SMTP id 5b1f17b1804b1-49cf825d1dcmr336340165e9.11.1788939016984; Wed, 09 Sep 2026 00:30:16 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-4858ac2b4cdsm40624310f8f.16.2026.09.09.00.30.16 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 09 Sep 2026 00:30:16 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][wrynose 32/38] curl: patch CVE-2026-11352 Date: Wed, 9 Sep 2026 09:29:31 +0200 Message-ID: <360087f55af6acb6c2325421208f9befc7d88589.1788938909.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Wed, 09 Sep 2026 07:30:23 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/245441 From: Peter Marko Pick patch per [1]. [1] https://curl.se/docs/CVE-2026-11352.html Signed-off-by: Peter Marko Signed-off-by: Yoann Congal --- .../curl/curl/CVE-2026-11352.patch | 48 +++++++++++++++++++ meta/recipes-support/curl/curl_8.19.0.bb | 1 + 2 files changed, 49 insertions(+) create mode 100644 meta/recipes-support/curl/curl/CVE-2026-11352.patch diff --git a/meta/recipes-support/curl/curl/CVE-2026-11352.patch b/meta/recipes-support/curl/curl/CVE-2026-11352.patch new file mode 100644 index 00000000000..df414b9112b --- /dev/null +++ b/meta/recipes-support/curl/curl/CVE-2026-11352.patch @@ -0,0 +1,48 @@ +From 56eca2afb4806f1032872fa97d1834b3c1385276 Mon Sep 17 00:00:00 2001 +From: Stefan Eissing +Date: Fri, 5 Jun 2026 08:34:46 +0200 +Subject: [PATCH] quic: count zero length packets against max + +With a flood of zero lenght UDP packets to curl, the receive loop might +run longer than intended to. Count such packets against the max to +terminate the loop as intended. + +URL: https://hackerone.com/reports/3783438 +Reported-by: vectorqueue on hackerone +Closes #21869 + +CVE: CVE-2026-11352 +Upstream-Status: Backport [https://github.com/curl/curl/commit/56eca2afb4806f1032872fa97d1834b3c1385276] +Signed-off-by: Peter Marko +--- + lib/vquic/vquic.c | 8 ++++++-- + 1 file changed, 6 insertions(+), 2 deletions(-) + +diff --git a/lib/vquic/vquic.c b/lib/vquic/vquic.c +index 2f0e072951..475f18e04a 100644 +--- a/lib/vquic/vquic.c ++++ b/lib/vquic/vquic.c +@@ -454,8 +454,10 @@ static CURLcode recvmmsg_packets(struct Curl_cfilter *cf, + VERBOSE(++calls); + for(i = 0; i < mcount; ++i) { + /* A zero-length UDP packet is no QUIC packet. Ignore. */ +- if(!mmsg[i].msg_len) ++ if(!mmsg[i].msg_len) { ++ ++pkts; + continue; ++ } + total_nread += mmsg[i].msg_len; + + gso_size = vquic_msghdr_get_udp_gro(&mmsg[i].msg_hdr); +@@ -538,8 +540,10 @@ static CURLcode recvmsg_packets(struct Curl_cfilter *cf, + ++calls; + + /* A 0-length UDP packet is no QUIC packet */ +- if(!nread) ++ if(!nread) { ++ ++pkts; + continue; ++ } + + gso_size = vquic_msghdr_get_udp_gro(&msg); + if(gso_size == 0) diff --git a/meta/recipes-support/curl/curl_8.19.0.bb b/meta/recipes-support/curl/curl_8.19.0.bb index 7497337cb95..6c9801f8792 100644 --- a/meta/recipes-support/curl/curl_8.19.0.bb +++ b/meta/recipes-support/curl/curl_8.19.0.bb @@ -27,6 +27,7 @@ SRC_URI = " \ file://CVE-2026-8927.patch \ file://CVE-2026-8932-dependent.patch \ file://CVE-2026-8932.patch \ + file://CVE-2026-11352.patch \ " SRC_URI:append:class-nativesdk = " \ From patchwork Wed Sep 9 07:29:32 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 97688 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 72983C79FB5 for ; Wed, 9 Sep 2026 07:30:23 +0000 (UTC) Received: from mail-wr1-f41.google.com (mail-wr1-f41.google.com [209.85.221.41]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.6335.1788939019751421307 for ; Wed, 09 Sep 2026 00:30:20 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=l71huKZ9; spf=pass (domain: smile.fr, ip: 209.85.221.41, mailfrom: yoann.congal@smile.fr) Received: by mail-wr1-f41.google.com with SMTP id ffacd0b85a97d-4859b45abadso397069f8f.2 for ; Wed, 09 Sep 2026 00:30:19 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1788939018; x=1789543818; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=XCO7U/bbyHVrGlMGY7Q9Qly6xKr6w0CXDwz9U66ZLUA=; b=l71huKZ9MyIp/Z/nDflHo5N6sFJ59JnaL+S1XczDe6BkJsrMZ0jscOr+ukBZUChBMx IvYCLDApDWMzNUS6mFP7k7pakIGiZynxm48XK62MiS1ETE/qMBNZpu7zh9UCYbMqyNkW 5nK0kI4msAXaYBy7cuCTGAJoH/1qt9F0WAvrg= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1788939018; x=1789543818; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=XCO7U/bbyHVrGlMGY7Q9Qly6xKr6w0CXDwz9U66ZLUA=; b=oY4Da68wA3oC9w4IG9ZiSXXo8Bx8mAZ6iWnkgR1nqFn4gnekRmYFlqup31vkjFNhee RHPV8JsC0Pj5DZ2SrtdE8d08NM1VTqxrJqnLFcYsWxVt16kD27JGfPhh/y0qUNyYJpex QfZAaf3X7ARbrmTqv/VwgpPrdehW0RK10txZHjZAkikf1o065HN6UAd/1rGW6iw6YWkN 2EVcu0rTVeRJYfZk6bIGjDOjLCtDjnmuvZiIs+U3YNPGsiCjcIJzI5bBsYlCZIZmzJYs sPpAL+DAiiswzzud7SEB/fHFx6chGhtJ2/dso8icotG7ulKP6iFh2rWCEd1EfB4FRz77 2wIg== X-Gm-Message-State: AFuF++lb+4M10dpGR4uFFW4E0NrCQ20gKMggEER3hRC45n++NaEwYXFl f831t8kYmJ893nYGZ/8tfzEPJwTdaLlN+BEQqqmc3KhimodjoTXKfYPJlcs9ACUPBBW/d7wAc3c vipRh85M= X-Gm-Gg: AYBFou36qSjRMqquFtHSXUxpd9zpmQW2dZ+K+2yv5nVpburxrYOPp2lkXMo3q0WU4f+ 5qLSQbjjDrjQ7lGs5fOcTR5cTis4cprNdFfhek5PXuGnSCnmBg9eDSPdnn3V0dLjEki1oLYEvjO uCY9MSstXaHIw29rMv0i+EPZhnH5CKEn12LrW3N+DpM3CMSIP8LPXsp7SXqQo6KBgl0hedAGmko Zshkd8xusugMFY7DqGdd3GMZqsjLnsU281DJoJWEtRi7c88sPXE1b5wEzVgLiwD9Ntg+P9s4kbL 1F/qFZhB9iuiNzeGy0YJKQYALSjc9BkCV85H886Fh82yvZiNP5L1o0JM4aQU3obvqzvPZuOmtGT iHgp+o3oR1gG2zqbJTOFnvl9dIB1CTwHSmt/y6KdYCXejckM9eADlLi6kldncjrk/v7XJ4NS59a ZJcTk1lmFAbdPv4BhkGrUv9lv6IotJkMPI5hOqnJJo5bkBFAAUDcFS75lDgl2D4riIhBAkO+xL3 QCrSXtrQBRzr1T6dwGu4tt9FRV5L2BLKPenfiTO71iFd7EaRwXcU3iyDVLAZbKLmGk1SGWZuWU= X-Received: by 2002:a05:6000:4b11:b0:485:8a46:b3bd with SMTP id ffacd0b85a97d-4858a46b4c8mr30478282f8f.37.1788939017753; Wed, 09 Sep 2026 00:30:17 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-4858ac2b4cdsm40624310f8f.16.2026.09.09.00.30.17 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 09 Sep 2026 00:30:17 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][wrynose 33/38] curl: patch CVE-2026-11586 Date: Wed, 9 Sep 2026 09:29:32 +0200 Message-ID: <6b4a3a3e44c51896d81d4db83b606447d214c3f0.1788938909.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Wed, 09 Sep 2026 07:30:23 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/245442 From: Peter Marko Pick patch per [1]. Resolve fuzz caused by having additional tests in new version. [1] https://curl.se/docs/CVE-2026-11586.html Signed-off-by: Peter Marko Signed-off-by: Yoann Congal --- .../curl/curl/CVE-2026-11586.patch | 203 ++++++++++++++++++ meta/recipes-support/curl/curl_8.19.0.bb | 1 + 2 files changed, 204 insertions(+) create mode 100644 meta/recipes-support/curl/curl/CVE-2026-11586.patch diff --git a/meta/recipes-support/curl/curl/CVE-2026-11586.patch b/meta/recipes-support/curl/curl/CVE-2026-11586.patch new file mode 100644 index 00000000000..3444166b326 --- /dev/null +++ b/meta/recipes-support/curl/curl/CVE-2026-11586.patch @@ -0,0 +1,203 @@ +From 849317ff5c5a5e13f50ec3d001e46ddffa77d8a4 Mon Sep 17 00:00:00 2001 +From: Stefan Eissing +Date: Mon, 8 Jun 2026 16:57:01 +0200 +Subject: [PATCH] ws: make pong sending lazy + +Do not send PONG frames unless there is sufficient space left in the +websocket send buffer. A server might be lazy in reading our data and +intermediary PONG frames can be skipped by a client (RFC 6455, ch. +5.5.3). + +Add test case measuring no real RSS increase on a server blasting with +PING frames. + +Closes #21911 + +CVE: CVE-2026-11586 +Upstream-Status: Backport [https://github.com/curl/curl/commit/849317ff5c5a5e13f50ec3d001e46ddffa77d8a4] +Signed-off-by: Peter Marko +--- + lib/ws.c | 33 +++++++++----- + tests/http/test_20_websockets.py | 78 ++++++++++++++++++++++++++++++++ + 2 files changed, 99 insertions(+), 12 deletions(-) + +diff --git a/lib/ws.c b/lib/ws.c +index d7840f1ffb..d00891b83f 100644 +--- a/lib/ws.c ++++ b/lib/ws.c +@@ -632,6 +632,7 @@ static CURLcode ws_enc_add_cntrl(struct Curl_easy *data, + size_t plen, + unsigned int frame_type) + { ++ (void)data; + DEBUGASSERT(plen <= WS_MAX_CNTRL_LEN); + if(plen > WS_MAX_CNTRL_LEN) + return CURLE_BAD_FUNCTION_ARGUMENT; +@@ -641,13 +642,6 @@ static CURLcode ws_enc_add_cntrl(struct Curl_easy *data, + ws->pending.type = frame_type; + ws->pending.payload_len = plen; + memcpy(ws->pending.payload, payload, plen); +- +- if(!ws->enc.payload_remain) { /* not in the middle of another frame */ +- CURLcode result = ws_enc_add_pending(data, ws); +- if(!result) +- (void)ws_flush(data, ws, Curl_is_in_callback(data)); +- return result; +- } + return CURLE_OK; + } + +@@ -716,7 +710,7 @@ static CURLcode ws_cw_write(struct Curl_easy *data, + { + struct ws_cw_ctx *ctx = writer->ctx; + struct websocket *ws; +- CURLcode result; ++ CURLcode result = CURLE_OK; + + CURL_TRC_WRITE(data, "ws_cw_write(len=%zu, type=%d)", nbytes, type); + if(!(type & CLIENTWRITE_BODY) || data->set.ws_raw_mode) +@@ -749,7 +743,8 @@ static CURLcode ws_cw_write(struct Curl_easy *data, + if(result == CURLE_AGAIN) { + /* insufficient amount of data, keep it for later. + * we pretend to have written all since we have a copy */ +- return CURLE_OK; ++ result = CURLE_OK; ++ goto out; + } + else if(result) { + failf(data, "[WS] decode payload error %d", (int)result); +@@ -760,10 +755,16 @@ static CURLcode ws_cw_write(struct Curl_easy *data, + if((type & CLIENTWRITE_EOS) && !Curl_bufq_is_empty(&ctx->buf)) { + failf(data, "[WS] decode ending with %zd frame bytes remaining", + Curl_bufq_len(&ctx->buf)); +- return CURLE_RECV_ERROR; ++ result = CURLE_RECV_ERROR; + } + +- return CURLE_OK; ++out: ++ if(!result) { ++ result = ws_flush(data, ws, Curl_is_in_callback(data)); ++ if(result == CURLE_AGAIN) ++ result = CURLE_OK; ++ } ++ return result; + } + + /* WebSocket payload decoding client writer. */ +@@ -1627,8 +1628,16 @@ CURLcode curl_ws_recv(CURL *d, void *buffer, + static CURLcode ws_flush(struct Curl_easy *data, struct websocket *ws, + bool blocking) + { ++ CURLcode result; ++ ++ /* If there is space, add any pending control frame */ ++ if(Curl_bufq_len(&ws->sendbuf) < ws->sendbuf.chunk_size) { ++ result = ws_enc_add_pending(data, ws); ++ if(result && (result != CURLE_AGAIN)) ++ return result; ++ } ++ + if(!Curl_bufq_is_empty(&ws->sendbuf)) { +- CURLcode result; + const uint8_t *out; + size_t outlen, n; + #ifdef DEBUGBUILD +diff --git a/tests/http/test_20_websockets.py b/tests/http/test_20_websockets.py +index 3a55d41b2b..00fc394a3b 100644 +--- a/tests/http/test_20_websockets.py ++++ b/tests/http/test_20_websockets.py +@@ -24,11 +24,15 @@ + # + ########################################################################### + # ++import base64 ++import hashlib + import logging + import os ++import re + import shutil + import socket + import subprocess ++import threading + import time + from datetime import datetime, timedelta + from typing import Dict +@@ -207,3 +211,77 @@ class TestWebsockets: + large = 0 + r = client.run(args=[f'-{model}', '-c', str(count), '-m', str(large), url]) + r.check_exit_code(0) ++ ++ def test_20_11_crazy_pings(self, env: Env): ++ st = {} ++ send_rounds = 1 ++ ++ def srv(): ++ try: ++ with socket.socket() as s: ++ s.setsockopt(socket.SOL_SOCKET, socket.SO_REUSEADDR, 1) ++ s.bind(("127.0.0.1", 0)) ++ s.listen(1) ++ st["p"] = s.getsockname()[1] ++ ++ c, _ = s.accept() ++ c.setsockopt(socket.SOL_SOCKET, socket.SO_RCVBUF, 4096) ++ c.settimeout(Env.SERVER_TIMEOUT) ++ req = b"" ++ while b"\r\n\r\n" not in req: ++ req += c.recv(4096) ++ ++ k = re.search(rb"(?im)^Sec-WebSocket-Key:\s*(\S+)", req).group(1) ++ a = base64.b64encode( ++ hashlib.sha1(k + b"258EAFA5-E914-47DA-95CA-C5AB0DC85B11").digest() ++ ).decode() ++ c.sendall( ++ ( ++ "HTTP/1.1 101 Switching Protocols\r\n" ++ "Upgrade: websocket\r\n" ++ "Connection: Upgrade\r\n" ++ f"Sec-WebSocket-Accept: {a}\r\n\r\n" ++ ).encode() ++ ) ++ ++ f = b"\x89\x00" * 65536 # PING frames, many ++ try: ++ for _ in range(send_rounds): ++ c.sendall(f) ++ f = b"\x88\x00" # CLOSE frame ++ c.sendall(f) ++ except OSError: ++ pass ++ time.sleep(1) ++ c.close() ++ except OSError as e: ++ st["err"] = e ++ ++ curl = CurlClient(env=env) ++ send_rounds = 2 ++ threading.Thread(target=srv, daemon=True).start() ++ while "p" not in st and "err" not in st: ++ time.sleep(0.01) ++ assert "err" not in st, f'ws-ping server failed to start: {st["err"]}' ++ ++ url = f'ws://127.0.0.1:{st["p"]}/' ++ r = curl.http_download(urls=[url], alpn_proto='http/1.1', with_stats=True, ++ with_profile=True) ++ assert r.exit_code in [55, 56], f'{r.dump_logs()}' # SEND/RECV_ERROR ++ assert r.profile, f'{r}' ++ rss1 = r.profile.stats['rss'] / (1024 * 1024) ++ ++ st.clear() ++ send_rounds = 10 ++ threading.Thread(target=srv, daemon=True).start() ++ while "p" not in st and "err" not in st: ++ time.sleep(0.01) ++ assert "err" not in st, f'ws-ping server failed to start: {st["err"]}' ++ ++ url = f'ws://127.0.0.1:{st["p"]}/' ++ r = curl.http_download(urls=[url], alpn_proto='http/1.1', with_stats=True, ++ with_profile=True) ++ assert r.exit_code in [55, 56], f'{r.dump_logs()}' # SEND/RECV_ERROR ++ assert r.profile, f'{r}' ++ rss2 = r.profile.stats['rss'] / (1024 * 1024) ++ assert (rss1 * 1.1) >= rss2, 'bad memory increase' diff --git a/meta/recipes-support/curl/curl_8.19.0.bb b/meta/recipes-support/curl/curl_8.19.0.bb index 6c9801f8792..a964868d872 100644 --- a/meta/recipes-support/curl/curl_8.19.0.bb +++ b/meta/recipes-support/curl/curl_8.19.0.bb @@ -28,6 +28,7 @@ SRC_URI = " \ file://CVE-2026-8932-dependent.patch \ file://CVE-2026-8932.patch \ file://CVE-2026-11352.patch \ + file://CVE-2026-11586.patch \ " SRC_URI:append:class-nativesdk = " \ From patchwork Wed Sep 9 07:29:33 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 97692 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id D0F54C79FBE for ; Wed, 9 Sep 2026 07:30:23 +0000 (UTC) Received: from mail-wr1-f45.google.com (mail-wr1-f45.google.com [209.85.221.45]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.6336.1788939021550095561 for ; Wed, 09 Sep 2026 00:30:21 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=2kBjFOdM; spf=pass (domain: smile.fr, ip: 209.85.221.45, mailfrom: yoann.congal@smile.fr) Received: by mail-wr1-f45.google.com with SMTP id ffacd0b85a97d-485abf3b93aso226844f8f.2 for ; Wed, 09 Sep 2026 00:30:21 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1788939020; x=1789543820; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=peT+PEiFJL3SuN0Kc8nvFNtZJVxDdFKZkEt4sod1GeE=; b=2kBjFOdMdGGjwfiGCiAOHSVeaDsuBRO6BfsdlTlLPkGu/tWBMHlvPMear1MSsSEhjW CH9doy5+HET/wMEglVj00X+cExTl4UID7cmoRt1skQi94zY5bUO9OEHk//b+AImSXkwp mgRFxnjGA2O4mFjwct1IrBMKFeiI07xTiWHRw= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1788939020; x=1789543820; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=peT+PEiFJL3SuN0Kc8nvFNtZJVxDdFKZkEt4sod1GeE=; b=ZUhLLvQ0NBRHRrSy/7EcUr7Na81wCPxHMngFtMRdXoX5J7tjEx+gYb+t44WRoBh/IQ KVmxNZ6yHxnicJyq8S8krRLeixyrGazzkrqTD5XVRp/sc3cwQklzdF5JXOSWpxdOUkp4 3vLocQyrpt3wWBVuudKjq1NQvDO8c+FS4nl5Gt4ZCsv0IG8it5+sV8YCKJjmaLl3IMvX xwnfxuHkP0w9fZfJjF8h9kLPdlp0pUNLRzrlAe6TptZfP+tZb7EH8GAxm+s843sJUfFQ ax/0J35WFxnWmYS3lP18o69TWiWCi6mIxruLU8WRyzM4mpYhkG50Hosk6hMJANdm4pzJ ATCg== X-Gm-Message-State: AFuF++n7GFYEhOU3iTsEvjPNk2Gvnp6X0VOXHYDLxK1MCWu9JLG8aVQZ 8L0hbskPa0au1ndD4NKWNYZOirpJr8EEn/tfGofVQmbN2DVGatOEO4tfljFz14dkTeiNnp85SV9 oy5wuWBg= X-Gm-Gg: AYBFou2vav+4aw4XsY0KZEgR3ChmbL6T5iXpdCCbTwt4u0SnHLJzHF1Lb6SjUWVKHnk kt55DQFPp63OVHvCcB+Q6O8hb0nXO41cgR7KvRr5vyXvVHSgjQb1YrZbDjyUAa8fCHslB7YnMN6 7IIyGmFUctvI7EdfGneCq3BY1JaJ+BI39ytomT7dP6Lkfhh+IYhubfTiW0SMuJELyOMLjOe+hRQ jJBd63MYd0cVc/Ch8n7UIBTqQUQg1nqjqvIp8Exgov4HUteC3cLhT/FRE+93+0PykbnoSYEnAO6 DsuHvWuv+R9XizBI5lZxSlrwmg716NHGuHdIaGRXiKMvr5KlUd8z9W9UJv2uUR729boq13oSDVs /TMRiroSxzPJWvNy8rjkripVXIHHnpkFxVpG1QPCTDGHPDqkLuzqtiDcpMDAlGyc7hM2z3LAWyB 61wNDclLI9YPr7MuPTRw3Dy9NPA8izEibayM4OL+nnHJNCCpUj8Bng/ibQ46dvmTlC2+kt4OVsU JwNuMMg/uuttTqD/bJX1V9WBt1umNDBefRCJDjfSgxT5+0W1lHSvAyeo7YOEQcOca4haI0fv4xh X-Received: by 2002:a05:6000:2506:b0:485:9227:6bc8 with SMTP id ffacd0b85a97d-48592276c5dmr26329192f8f.24.1788939018418; Wed, 09 Sep 2026 00:30:18 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-4858ac2b4cdsm40624310f8f.16.2026.09.09.00.30.17 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 09 Sep 2026 00:30:18 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][wrynose 34/38] gnutls: fix CVE-2026-33845 Date: Wed, 9 Sep 2026 09:29:33 +0200 Message-ID: <5d6ef998e1c61e5bf8a438b8856d0772d841b6a3.1788938909.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Wed, 09 Sep 2026 07:30:23 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/245443 From: Adarsh Jagadish Kamini Backport patch to fix CVE-2026-33845. References: https://nvd.nist.gov/vuln/detail/CVE-2026-33845 Upstream fix: https://gitlab.com/gnutls/gnutls/-/commit/e5b72c53c7d789d19d1d1cd10b275e87d0415413 Signed-off-by: Adarsh Jagadish Kamini Signed-off-by: Yoann Congal --- .../gnutls/gnutls/CVE-2026-33845.patch | 166 ++++++++++++++++++ meta/recipes-support/gnutls/gnutls_3.8.12.bb | 1 + 2 files changed, 167 insertions(+) create mode 100644 meta/recipes-support/gnutls/gnutls/CVE-2026-33845.patch diff --git a/meta/recipes-support/gnutls/gnutls/CVE-2026-33845.patch b/meta/recipes-support/gnutls/gnutls/CVE-2026-33845.patch new file mode 100644 index 00000000000..004d3082c5a --- /dev/null +++ b/meta/recipes-support/gnutls/gnutls/CVE-2026-33845.patch @@ -0,0 +1,166 @@ +From 490bfb28002fc0253010243ac387c756014c06e5 Mon Sep 17 00:00:00 2001 +From: Alexander Sosedkin +Date: Mon, 23 Mar 2026 15:09:43 +0100 +Subject: [PATCH] buffers: switch from end_offset over to frag_length + +Instead of maintaining an inclusive [start_offset, end_offset] range +when reassembling DTLS handshake, +track start_offset and a relative frag_length instead. + +You'd think it'd be a no-op, but it fixes: + +* 0-length fragments triggering completion if message was 1 byte long +* a remotely triggerable underflow and an ensuing heap overrun + +Reported-by: Joshua Rogers of AISLE Research Team +Fixes: #1811 +Fixes: CVE-2026-33845 +Fixes: GNUTLS-SA-2026-04-29-3 +CVSS: 7.5 High CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H +Signed-off-by: Alexander Sosedkin + +CVE: CVE-2026-33845 +Upstream-Status: Backport [https://gitlab.com/gnutls/gnutls/-/commit/e5b72c53c7d789d19d1d1cd10b275e87d0415413] +Signed-off-by: Adarsh Jagadish Kamini +--- + lib/buffers.c | 50 +++++++++++++++++++++++++----------------------- + lib/gnutls_int.h | 4 ++-- + 2 files changed, 28 insertions(+), 26 deletions(-) + +diff --git a/lib/buffers.c b/lib/buffers.c +index 09779a8f3..02cc222c4 100644 +--- a/lib/buffers.c ++++ b/lib/buffers.c +@@ -919,10 +919,7 @@ static int parse_handshake_header(gnutls_session_t session, mbuffer_st *bufel, + } + data_size = _mbuffer_get_udata_size(bufel) - handshake_header_size; + +- if (frag_size > 0) +- hsk->end_offset = hsk->start_offset + frag_size - 1; +- else +- hsk->end_offset = 0; ++ hsk->frag_length = frag_size; + + _gnutls_handshake_log( + "HSK[%p]: %s (%u) was received. Length %d[%d], frag offset %d, frag length: %d, sequence: %d\n", +@@ -936,9 +933,10 @@ static int parse_handshake_header(gnutls_session_t session, mbuffer_st *bufel, + + if (hsk->length > 0 && + (frag_size > data_size || +- (frag_size > 0 && hsk->end_offset >= hsk->length))) { ++ (frag_size > 0 && hsk->start_offset + frag_size > hsk->length))) { + return gnutls_assert_val(GNUTLS_E_UNEXPECTED_PACKET_LENGTH); +- } else if (hsk->length == 0 && hsk->end_offset != 0 && ++ } else if (hsk->length == 0 && ++ hsk->start_offset + frag_size != hsk->start_offset && + hsk->start_offset != 0) + return gnutls_assert_val(GNUTLS_E_UNEXPECTED_PACKET_LENGTH); + +@@ -1002,11 +1000,10 @@ static int merge_handshake_packet(gnutls_session_t session, + hsk->data.length = hsk->length; + } + +- if (hsk->length > 0 && hsk->end_offset > 0 && +- hsk->end_offset - hsk->start_offset + 1 != hsk->length) { ++ if (hsk->length > 0 && hsk->frag_length > 0 && ++ hsk->frag_length != hsk->length) { + memmove(&hsk->data.data[hsk->start_offset], +- hsk->data.data, +- hsk->end_offset - hsk->start_offset + 1); ++ hsk->data.data, hsk->frag_length); + } + + session->internals.handshake_recv_buffer_size++; +@@ -1040,20 +1037,27 @@ static int merge_handshake_packet(gnutls_session_t session, + } + + if (hsk->start_offset < recv_buf[pos].start_offset && +- hsk->end_offset + 1 >= recv_buf[pos].start_offset) { ++ hsk->start_offset + hsk->frag_length >= ++ recv_buf[pos].start_offset) { + memcpy(&recv_buf[pos].data.data[hsk->start_offset], + hsk->data.data, hsk->data.length); + recv_buf[pos].start_offset = hsk->start_offset; +- recv_buf[pos].end_offset = +- MIN(hsk->end_offset, recv_buf[pos].end_offset); +- } else if (hsk->end_offset > recv_buf[pos].end_offset && +- hsk->start_offset <= recv_buf[pos].end_offset + 1) { ++ recv_buf[pos].frag_length = MIN( ++ hsk->frag_length, recv_buf[pos].frag_length); ++ } else if (hsk->start_offset + hsk->frag_length > ++ recv_buf[pos].start_offset + ++ recv_buf[pos].frag_length && ++ hsk->start_offset <= ++ recv_buf[pos].start_offset + ++ recv_buf[pos].frag_length) { + memcpy(&recv_buf[pos].data.data[hsk->start_offset], + hsk->data.data, hsk->data.length); + +- recv_buf[pos].end_offset = hsk->end_offset; + recv_buf[pos].start_offset = MIN( + hsk->start_offset, recv_buf[pos].start_offset); ++ recv_buf[pos].frag_length = hsk->start_offset + ++ hsk->frag_length - ++ recv_buf[pos].start_offset; + } + _gnutls_handshake_buffer_clear(hsk); + } +@@ -1113,8 +1117,8 @@ static int get_last_packet(gnutls_session_t session, + } + + else if ((recv_buf[LAST_ELEMENT].start_offset == 0 && +- recv_buf[LAST_ELEMENT].end_offset == +- recv_buf[LAST_ELEMENT].length - 1) || ++ recv_buf[LAST_ELEMENT].frag_length == ++ recv_buf[LAST_ELEMENT].length) || + recv_buf[LAST_ELEMENT].length == 0) { + session->internals.dtls.hsk_read_seq++; + _gnutls_handshake_buffer_move(hsk, +@@ -1125,8 +1129,9 @@ static int get_last_packet(gnutls_session_t session, + /* if we don't have a complete handshake message, but we + * have queued data waiting, try again to reconstruct the + * handshake packet, using the queued */ +- if (recv_buf[LAST_ELEMENT].end_offset != +- recv_buf[LAST_ELEMENT].length - 1 && ++ if ((recv_buf[LAST_ELEMENT].start_offset + ++ recv_buf[LAST_ELEMENT].frag_length) != ++ recv_buf[LAST_ELEMENT].length && + record_check_unprocessed(session) > 0) + return gnutls_assert_val( + GNUTLS_E_INT_CHECK_AGAIN); +@@ -1313,9 +1318,7 @@ int _gnutls_parse_record_buffered_msgs(gnutls_session_t session) + &session->internals.record_buffer, + bufel, ret); + +- data_size = MIN(tmp.length, +- tmp.end_offset - +- tmp.start_offset + 1); ++ data_size = MIN(tmp.length, tmp.frag_length); + + ret = _gnutls_buffer_append_data( + &tmp.data, +@@ -1331,7 +1334,6 @@ int _gnutls_parse_record_buffered_msgs(gnutls_session_t session) + ret = merge_handshake_packet(session, &tmp); + if (ret < 0) + return gnutls_assert_val(ret); +- + } while (_mbuffer_get_udata_size(bufel) > 0); + + prev = bufel; +diff --git a/lib/gnutls_int.h b/lib/gnutls_int.h +index 54d3c9f67..283f25c07 100644 +--- a/lib/gnutls_int.h ++++ b/lib/gnutls_int.h +@@ -479,10 +479,10 @@ typedef struct { + uint16_t sequence; + + /* indicate whether that message is complete. +- * complete means start_offset == 0 and end_offset == length ++ * complete means start_offset == 0 and frag_length == length + */ + uint32_t start_offset; +- uint32_t end_offset; ++ uint32_t frag_length; /* used exclusively in DTLS reassembly */ + + uint8_t header[MAX_HANDSHAKE_HEADER_SIZE]; + int header_size; diff --git a/meta/recipes-support/gnutls/gnutls_3.8.12.bb b/meta/recipes-support/gnutls/gnutls_3.8.12.bb index 51ef394dfcf..d513752072c 100644 --- a/meta/recipes-support/gnutls/gnutls_3.8.12.bb +++ b/meta/recipes-support/gnutls/gnutls_3.8.12.bb @@ -40,6 +40,7 @@ SRC_URI = "https://www.gnupg.org/ftp/gcrypt/gnutls/v${SHRT_VER}/gnutls-${PV}.tar file://CVE-2026-42011_p1.patch \ file://CVE-2026-42011_p2.patch \ file://CVE-2026-42010.patch \ + file://CVE-2026-33845.patch \ " SRC_URI[sha256sum] = "a7b341421bfd459acf7a374ca4af3b9e06608dcd7bd792b2bf470bea012b8e51" From patchwork Wed Sep 9 07:29:34 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 97683 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 27CF9C79FAA for ; Wed, 9 Sep 2026 07:30:23 +0000 (UTC) Received: from mail-wr1-f47.google.com (mail-wr1-f47.google.com [209.85.221.47]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.6448.1788939021734033426 for ; Wed, 09 Sep 2026 00:30:22 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=Gxblkov1; spf=pass (domain: smile.fr, ip: 209.85.221.47, mailfrom: yoann.congal@smile.fr) Received: by mail-wr1-f47.google.com with SMTP id ffacd0b85a97d-485888b3c3dso5564582f8f.2 for ; Wed, 09 Sep 2026 00:30:21 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1788939020; x=1789543820; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=Lg3SnixQAarj1OIG49PMqRrYi7MHm9cccJBPqqj+bo0=; b=Gxblkov1993XIvb509IpztkydYq9dKSVxSnOUOT8nbRaGCim8ddiFZE0NYcWYKhWQM c8XTpMZND7S6n7JtWIwfFRHdtaGq2uOoFRuDm5NSZhP0FZ5c57mzPRm5nBPiB0nqdjYV fV0zUCUSX4TOTv6w3f8AUCpJTq66YndSmqNn4= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1788939020; x=1789543820; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=Lg3SnixQAarj1OIG49PMqRrYi7MHm9cccJBPqqj+bo0=; b=erXV6HBQOooFJPxnMEbSZNOHaBeh34uQ0nQ9zYkrqISPdgmnVq64i6An8Q2BtsKUoV WP1daH3SlsxA8DhglTZxQqo/fw083Qx4jU6Z9N62ZZ/IU41BnyXWToZ081ovHVSbHYrM XO170ptOksrMjrVaHF3mWJ2bv5rcIGVW30Se9PHO6zc7/NWxtFQI6C+OdVi5XIuex+++ gZIPjs6/N1sQPgOjZnwfSuPYBGc2EldgikUCMxwwacYCA4F/y2YOTnibHkCuacZ4aZtL iusVoLHQvOqNOvN7NUIrY7quA4UoXQpY2n5d8Tx/fR4xVpRZKcbPFrsDiBnEsjdFAauT 6AMQ== X-Gm-Message-State: AFuF++mKS1BWAvR/5MMjbl5o3coU977xwv8E4PUhmbtTgiQlgINqdsQt MoFnvTwvTLNTR89ZlH6QFUYU+QMp8PvRjVev0ZVofBWjYFOlhjKS19Fl/fAe1cW6FWPJfTmO1GT Ju2Aarxo= X-Gm-Gg: AYBFou27pd6gwDcwwx179ahHevjyKbMIlDOW1usAjU15YE4BIKmZX8GjLB3z72jVHae zJslgtSriVrVE9gIhZSVZP1a1bNjMapX7k6wgiM2WsKpG3fxMefT6pXYEnXuzcaba7JjWMI6hSy Tz1g21VcCJhZtHPP49g6hTRVSJ4XUePganW5+lMe3+wBtZUR9RMjNhskJz8mD0qIYO4jFcMHRNy G/1/1TLnblOi0uDbdRRhNsQlZ5VSE7sMZ9oufFJoPkXDPNCI2pjXU1MUwlOs9KzImQluP+YcB97 +2EiTP5Cq6E6N/JyI8Ozm/RVZVxy0+8OLjR107zE/pijI6qXwuFIBOSfhIjmZzyGeyUGAPjKi2T yY0CxWHuu5obCA7XQx0/HeKLeHrz50MdERu30+ULSO0WENNngeGbBbN6yZK4XlvRfJa+noehLSL mQx8wHIHZdQea9RcaMB3bEGhiQaDrqap/OgALDuQmiDXw8xGaA0RAvJfQqSfSaqf48MvbpKumPS KIbNzH4ZRDBRn5c4b7zQQaxiyOBtf2dLMk3aZfE2rcw52OmZcdIhvgu1OchR2t6QW1rBY+uYpo= X-Received: by 2002:a05:6000:430b:b0:485:adb5:2075 with SMTP id ffacd0b85a97d-485adb52e38mr1837628f8f.51.1788939018908; Wed, 09 Sep 2026 00:30:18 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-4858ac2b4cdsm40624310f8f.16.2026.09.09.00.30.18 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 09 Sep 2026 00:30:18 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][wrynose 35/38] perl: Fix CVE-2026-57433 Date: Wed, 9 Sep 2026 09:29:34 +0200 Message-ID: <959d2d8c1d8e36c7d9e202d6f4cf33d08f844c89.1788938909.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Wed, 09 Sep 2026 07:30:23 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/245444 From: Vijay Anusuri Pick patch according to [2] [1] https://nvd.nist.gov/vuln/detail/cve-2026-57433 [2] https://security-tracker.debian.org/tracker/CVE-2026-57433 Signed-off-by: Vijay Anusuri Signed-off-by: Yoann Congal --- .../perl/files/CVE-2026-57433.patch | 32 +++++++++++++++++++ meta/recipes-devtools/perl/perl_5.42.0.bb | 1 + 2 files changed, 33 insertions(+) create mode 100644 meta/recipes-devtools/perl/files/CVE-2026-57433.patch diff --git a/meta/recipes-devtools/perl/files/CVE-2026-57433.patch b/meta/recipes-devtools/perl/files/CVE-2026-57433.patch new file mode 100644 index 00000000000..f0ea08b1fe0 --- /dev/null +++ b/meta/recipes-devtools/perl/files/CVE-2026-57433.patch @@ -0,0 +1,32 @@ +From e4f681784bcdeaa91ff02a2fa4cdcae5c46779d7 Mon Sep 17 00:00:00 2001 +From: "Paul \"LeoNerd\" Evans" +Date: Sat, 9 May 2026 16:47:14 +0100 +Subject: [PATCH] Storable.xs: Avoid signed int overflow when unpacking a list + of hook data items + +Upstream-Status: Backport [https://github.com/Perl/perl5/commit/e4f681784bcdeaa91ff02a2fa4cdcae5c46779d7] +CVE: CVE-2026-57433 +Signed-off-by: Vijay Anusuri +--- + dist/Storable/Storable.xs | 5 ++++- + 1 file changed, 4 insertions(+), 1 deletion(-) + +diff --git a/dist/Storable/Storable.xs b/dist/Storable/Storable.xs +index 3930db6..62a1a6d 100644 +--- a/dist/Storable/Storable.xs ++++ b/dist/Storable/Storable.xs +@@ -5035,7 +5035,10 @@ static SV *retrieve_hook_common(pTHX_ stcxt_t *cxt, const char *cname, int large + } + else + GETMARK(len3); +- if (len3) { ++ if (len3 == I32_MAX) ++ /* If len3 is exactly I32_MAX it will upset av_extend below */ ++ CROAK(("Invalid count of hook data items")); ++ else if (len3) { + av = newAV(); + av_extend(av, len3 + 1); /* Leave room for [0] */ + AvFILLp(av) = len3; /* About to be filled anyway */ +-- +2.43.0 + diff --git a/meta/recipes-devtools/perl/perl_5.42.0.bb b/meta/recipes-devtools/perl/perl_5.42.0.bb index 3469258f727..6f0092c1cc7 100644 --- a/meta/recipes-devtools/perl/perl_5.42.0.bb +++ b/meta/recipes-devtools/perl/perl_5.42.0.bb @@ -22,6 +22,7 @@ SRC_URI = "https://www.cpan.org/src/5.0/perl-${PV}.tar.gz;name=perl \ file://CVE-2026-57432-01.patch \ file://CVE-2026-57432-02.patch \ file://CVE-2026-42496.patch \ + file://CVE-2026-57433.patch \ " SRC_URI:append:class-native = " \ file://perl-configpm-switch.patch \ From patchwork Wed Sep 9 07:29:35 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 97690 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id DCBF3C79FBD for ; Wed, 9 Sep 2026 07:30:23 +0000 (UTC) Received: from mail-wr1-f44.google.com (mail-wr1-f44.google.com [209.85.221.44]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.6449.1788939021763239327 for ; Wed, 09 Sep 2026 00:30:22 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=ZQxI1wdB; spf=pass (domain: smile.fr, ip: 209.85.221.44, mailfrom: yoann.congal@smile.fr) Received: by mail-wr1-f44.google.com with SMTP id ffacd0b85a97d-484362f5c4aso6642261f8f.3 for ; Wed, 09 Sep 2026 00:30:21 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1788939020; x=1789543820; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=OIrW2dBnPtmt/VxBTERJa09xdj8lkDL1J2BAWWkvQbg=; b=ZQxI1wdBwh8howlDtO09VaOtbr4EVYjvdePeh5r52DvdbF6qBAqdkgp/28+N/kFr+t PUmjWVBxYD9xUseuSVm2r2Vtf68mwCJfiiXlJmesOjRnzmTMBQ6ctWBV4bOmbSFZLr6Q 9MZCBdXBhvUM2kre5LB9vcnaFE9H8hKK3xA3I= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1788939020; x=1789543820; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=OIrW2dBnPtmt/VxBTERJa09xdj8lkDL1J2BAWWkvQbg=; b=mErpm0VCugteD9BWY66fFo2AoCHIrw5Swl67ISFAMV2Tp9t1qSy0DmQFB26gfMBqqX O/hLnFkBRbIz1apu+Fh5ZQbXLBuqpsc6THNWTOfd07uG8con6hi/ClmIqTtUb1PbBX2N SDLMCJ6Q7jDmAlOg5AGdphwOz4IDQQT4H6NqjrSTHsxY6UZMEHdw4SYFFiOTtufMeJey D/U+R85rgH45Hn/II4Kjw9PvZihpHm56dtF2h6fMuWd180DzBcgcr8mNy24Pzx2oeUwo RfwrnxIzxvj+IDpclTfaaZlk73g+VjS+FvRwjW6PiVR+I6iO+IReXMPDxitXRdFG46Wt lNcQ== X-Gm-Message-State: AFuF++l7urhd80X2ZXk2EoqjTFKDNyaK7ULOxe/Oh5xgILuhf+pI4cDu DB64EKzhv9emBT703MqGxnZs07SqK5kRwDFDN5nZ7BY/gIr6/85tvyMIlMcWnSJ1WvBQlYgCgLf tLktHs60= X-Gm-Gg: AYBFou28LMaLoXu5DFw7vyadgby0Ch9hK8izKw8EwPw3F7wTBCAN496WnhZV3u1dpVW V/GdeZn8ovE1tT6zjYiye3xiezH5Vxa/R5pjEkA4L/utODFzDZSA1ctu1gLNZyNsnC4jsiWvle9 d7uhVsM6v3mDIb9n/boNSg57r+f8NB8hn41J7GmBF17ouaWWSKkvGnYvbmozxq9yj4eNocwNXJC t9OX7D7KNM9C/uem2Lie5h5lp1vC2FpneJXE+tu7uzKOx0YuQOaJ7ooJ8ibMNYqzRS/dw4Ea/Ek EqVYLre5b5fJo0FMS+2pYssj2EA4MWPxMj9CcLIJrNUCIYnK6CiawFyDwZ59WtHGbw862zA9lIm H1DmiwccC5qNSV1Acq+iedTuQjNz76qljSg4FIc+7AEgUujEwFDgyVAaCOqCd83MglZyBjUgpKc 2hyQooHqDjBlMAIlxQtp1KuOcTVeHS8Rm/FeqDmYa7sHfXEVlvgpHTHFoPOxfi+k9l4zjsT+b95 VggZJ6uWHikPNGETVdnLxj6AfAkmAYqT/aHCz/PLqJk4xMacqWm1ANCkPU7OnnpzjwyPLXzodI= X-Received: by 2002:a05:6000:4a0f:b0:485:ac48:f873 with SMTP id ffacd0b85a97d-485ac48fe3cmr6366129f8f.11.1788939019862; Wed, 09 Sep 2026 00:30:19 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-4858ac2b4cdsm40624310f8f.16.2026.09.09.00.30.18 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 09 Sep 2026 00:30:19 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][wrynose 36/38] wget: Fix CVE-2026-58470 Date: Wed, 9 Sep 2026 09:29:35 +0200 Message-ID: <491affe9154d35254e2111d220482ffa47864ad9.1788938909.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Wed, 09 Sep 2026 07:30:23 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/245445 From: Hetvi Thakar This patch applies the upstream fix as referenced in [2], using the commit shown in [1]. It also includes the upstream follow-up in [3], which preserves 64-bit wgint parsing on 32-bit targets. [1] https://gitlab.com/gnuwget/wget/-/commit/43d3ba9336bc94937e6fae2365c6ffd30c34ffcf [2] https://nvd.nist.gov/vuln/detail/CVE-2026-58470 [3] https://gitlab.com/gnuwget/wget/-/commit/01ff771caac1958662ca8665eed2021ec386a7af Signed-off-by: Hetvi Thakar Signed-off-by: Mathieu Dubois-Briand Signed-off-by: Richard Purdie (cherry picked from commit 9b2b418a1546ae4bd6d044474765fa817e9a95f8) Signed-off-by: Hetvi Thakar Signed-off-by: Yoann Congal --- .../wget/wget/CVE-2026-58470-regression.patch | 48 +++++++++++ .../wget/wget/CVE-2026-58470.patch | 79 +++++++++++++++++++ meta/recipes-extended/wget/wget_1.25.0.bb | 2 + 3 files changed, 129 insertions(+) create mode 100644 meta/recipes-extended/wget/wget/CVE-2026-58470-regression.patch create mode 100644 meta/recipes-extended/wget/wget/CVE-2026-58470.patch diff --git a/meta/recipes-extended/wget/wget/CVE-2026-58470-regression.patch b/meta/recipes-extended/wget/wget/CVE-2026-58470-regression.patch new file mode 100644 index 00000000000..c452261a9ac --- /dev/null +++ b/meta/recipes-extended/wget/wget/CVE-2026-58470-regression.patch @@ -0,0 +1,48 @@ +From 01ff771caac1958662ca8665eed2021ec386a7af Mon Sep 17 00:00:00 2001 +From: =?UTF-8?q?Tim=20R=C3=BChsen?= +Date: Wed, 12 Aug 2026 19:45:21 +0200 +Subject: [PATCH] * src/http.c (parse_content_range): Use strtoll instead of + strtol. + +CVE: CVE-2026-58470 +Upstream-Status: Backport [https://gitlab.com/gnuwget/wget/-/commit/01ff771caac1958662ca8665eed2021ec386a7af] + +(cherry picked from commit 01ff771caac1958662ca8665eed2021ec386a7af) +Signed-off-by: Hetvi Thakar +--- + src/http.c | 6 +++--- + 1 file changed, 3 insertions(+), 3 deletions(-) + +diff --git a/src/http.c b/src/http.c +index e5e75ee695..8170a43c27 100644 +--- a/src/http.c ++++ b/src/http.c +@@ -949,7 +949,7 @@ parse_content_range (const char *hdr, wgint *first_byte_ptr, + return false; + + errno = 0; +- num = strtol(hdr, &end, 10); ++ num = strtoll(hdr, &end, 10); + if (errno == ERANGE) + return false; + hdr = end; +@@ -959,7 +959,7 @@ parse_content_range (const char *hdr, wgint *first_byte_ptr, + *first_byte_ptr = num; + + errno = 0; +- num = strtol(hdr, &end, 10); ++ num = strtoll(hdr, &end, 10); + if (errno == ERANGE) + return false; + hdr = end; +@@ -976,7 +976,7 @@ parse_content_range (const char *hdr, wgint *first_byte_ptr, + else + { + errno = 0; +- num = strtol(hdr, NULL, 10); ++ num = strtoll(hdr, NULL, 10); + if (errno == ERANGE) + return false; + } +-- +2.35.6 diff --git a/meta/recipes-extended/wget/wget/CVE-2026-58470.patch b/meta/recipes-extended/wget/wget/CVE-2026-58470.patch new file mode 100644 index 00000000000..5d864c5fda6 --- /dev/null +++ b/meta/recipes-extended/wget/wget/CVE-2026-58470.patch @@ -0,0 +1,79 @@ +From 8740efcdd0d9e7eb04122f63bdb151f1f4d94af8 Mon Sep 17 00:00:00 2001 +From: =?UTF-8?q?Tim=20R=C3=BChsen?= +Date: Mon, 29 Jun 2026 18:57:54 +0200 +Subject: [PATCH] * src/http.c (parse_content_range): Fix integer overflow + +Reported-by: TristanInSec@gmail.com + +CVE: CVE-2026-58470 +Upstream-Status: Backport [https://gitlab.com/gnuwget/wget/-/commit/43d3ba9336bc94937e6fae2365c6ffd30c34ffcf] + +(cherry picked from commit 43d3ba9336bc94937e6fae2365c6ffd30c34ffcf) +Signed-off-by: Hetvi Thakar +--- + src/http.c | 35 ++++++++++++++++++++++++----------- + 1 file changed, 24 insertions(+), 11 deletions(-) + +diff --git a/src/http.c b/src/http.c +index 07af1867..ea2e591b 100644 +--- a/src/http.c ++++ b/src/http.c +@@ -914,6 +914,7 @@ parse_content_range (const char *hdr, wgint *first_byte_ptr, + wgint *last_byte_ptr, wgint *entity_length_ptr) + { + wgint num; ++ char *end; + + /* Ancient versions of Netscape proxy server, presumably predating + rfc2068, sent out `Content-Range' without the "bytes" +@@ -932,27 +933,39 @@ parse_content_range (const char *hdr, wgint *first_byte_ptr, + } + if (!c_isdigit (*hdr)) + return false; +- for (num = 0; c_isdigit (*hdr); hdr++) +- num = 10 * num + (*hdr - '0'); +- if (*hdr != '-' || !c_isdigit (*(hdr + 1))) ++ ++ errno = 0; ++ num = strtol(hdr, &end, 10); ++ if (errno == ERANGE) ++ return false; ++ hdr = end; ++ ++ if (*hdr++ != '-' || !c_isdigit (*hdr)) + return false; + *first_byte_ptr = num; +- ++hdr; +- for (num = 0; c_isdigit (*hdr); hdr++) +- num = 10 * num + (*hdr - '0'); +- if (*hdr != '/') ++ ++ errno = 0; ++ num = strtol(hdr, &end, 10); ++ if (errno == ERANGE) ++ return false; ++ hdr = end; ++ ++ if (*hdr++ != '/') + return false; + *last_byte_ptr = num; +- if (!(c_isdigit (*(hdr + 1)) || *(hdr + 1) == '*')) ++ if (!(c_isdigit (*hdr) || *hdr == '*')) + return false; + if (*last_byte_ptr < *first_byte_ptr) + return false; +- ++hdr; + if (*hdr == '*') + num = -1; + else +- for (num = 0; c_isdigit (*hdr); hdr++) +- num = 10 * num + (*hdr - '0'); ++ { ++ errno = 0; ++ num = strtol(hdr, NULL, 10); ++ if (errno == ERANGE) ++ return false; ++ } + *entity_length_ptr = num; + if ((*entity_length_ptr <= *last_byte_ptr) && *entity_length_ptr != -1) + return false; diff --git a/meta/recipes-extended/wget/wget_1.25.0.bb b/meta/recipes-extended/wget/wget_1.25.0.bb index 95845d695a9..26f5c84e5a7 100644 --- a/meta/recipes-extended/wget/wget_1.25.0.bb +++ b/meta/recipes-extended/wget/wget_1.25.0.bb @@ -22,6 +22,8 @@ SRC_URI = "${GNU_MIRROR}/wget/wget-${PV}.tar.gz \ file://CVE-2026-58472.patch \ file://CVE-2026-58472-regression.patch \ file://CVE-2026-16599.patch \ + file://CVE-2026-58470.patch \ + file://CVE-2026-58470-regression.patch \ " SRC_URI[sha256sum] = "766e48423e79359ea31e41db9e5c289675947a7fcf2efdcedb726ac9d0da3784" From patchwork Wed Sep 9 07:29:36 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 97696 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 6656EC88E43 for ; Wed, 9 Sep 2026 07:30:24 +0000 (UTC) Received: from mail-wm1-f51.google.com (mail-wm1-f51.google.com [209.85.128.51]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.6337.1788939022612846120 for ; Wed, 09 Sep 2026 00:30:22 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=nT1EppLI; spf=pass (domain: smile.fr, ip: 209.85.128.51, mailfrom: yoann.congal@smile.fr) Received: by mail-wm1-f51.google.com with SMTP id 5b1f17b1804b1-49d036e0e99so22456895e9.1 for ; Wed, 09 Sep 2026 00:30:22 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1788939021; x=1789543821; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=YGbHeGOv5MwL6AF0IYMcFn6VFNnHBIFIZhiGy6XnRR0=; b=nT1EppLIZCw0+kR1dp0nvzQTkBVuHhaueSUMG338EAsszHVmJTQVQH5tgN6iw+VStR BBLvWOQ6it7vYSZsNu7NZBLZaxx1dk0odyNj7gdaMc2VVyB2kTH5BIaN/7bVvovNnIH4 /VZIx+y6DcgM3uqh7c3nc0Vkc9l5r0I30jL4I= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1788939021; x=1789543821; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=YGbHeGOv5MwL6AF0IYMcFn6VFNnHBIFIZhiGy6XnRR0=; b=GszxR7/L2cL56QI8lh0aG5SHdyvIt945Wsgz0Q0Yxj93O5h1T8Xp+RGMsQYHAVoI7x Xq3mDbUxaEtOxNJZoWTTWc+Y3IOpcGOtvlPqK+A7s6m6NfPg9PEut9IH9tSO+qVx+mPg CP9COau5mT48DN2iJqdsd/k9GDO0fW2MP++UPDBif9f0SHEX6dfLgax5fT+azLIGMsY0 TIgHmv2iexerhihSvYg5U7fr86BCGcwPz6eM//q9KOcvfHySzcJTn59+oZnyIoOUpZRX QpszfcWD2D32VvYSCS3jHDxE2Lypyk0UC3ZDZZvamaCQctCLEy4m4XAYFlj9guoL0BKg HDXQ== X-Gm-Message-State: AFuF++nSjl2XHr5NNPNSOjPATPTK9bqrKpdEsAROnkLcpvkBx2jItut/ qJrhL/JKhqP47jSdjD5Mow4cnJR9dqeFvjovZj11k1eyoKUvZkjKiEz6RRfSK2ze/EjF++PAQYH doV6Ze/o= X-Gm-Gg: AYBFou21oo2KDuphMSYFUfQ16NH7LTaV9HoIDbmEpLnFMXkPy4uLYYk3HpiiYjWO74N v2Ooz0SdPwwC6Om/Q+l+jkOMSSCotKGy+QSf56uR4h5HxQ1SZeiQg2gRTpPgy3/oct7tSTCXElO k/+Yn0qN+c/25KoYMm/wbqTdJSm2WjjoTVTbbx11Bf/NGTxqQBbbuzW4j6Thj+eUhUJoYg6WMFN 8+6LrhZTkF2s9UZvnznL0aBHSmdmiJholqsI0L5Sw253y1beWGOHckv52DphUx1Dn8C8D/rb0ds v5QFz7Qbg+2UissoQYcp3VIzRw1YFVvQKPFl6M0UIenuN8VERpPqsVoSHwwlPuO+VQZo/X3Y5dC q9A4kAY19csAvdOe3qXY7KbCw28Hi06OWm4G8KhP8vIi03pnvAUaE9hYSeT5fWdUwrb220t49un YV1ypYVIlMn6av/a1JCsRqwcES41TMhPUNSemL0CUh6x9ow2cYTtHBsyeGW36C1Gz+VjJAjtWDo Ss3dCVUpt40/gQ0DyxXUeyBab95H2pcNlrkZNyXRUuy2SC/tux/+yiTrSo4r/d/zCOlswokp0Q= X-Received: by 2002:a05:600c:4505:b0:49c:dca2:ac47 with SMTP id 5b1f17b1804b1-49cf7fe607cmr312961375e9.2.1788939020535; Wed, 09 Sep 2026 00:30:20 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-4858ac2b4cdsm40624310f8f.16.2026.09.09.00.30.19 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 09 Sep 2026 00:30:20 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][wrynose 37/38] python3-pip: Fix CVE-2026-8643 Date: Wed, 9 Sep 2026 09:29:36 +0200 Message-ID: X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Wed, 09 Sep 2026 07:30:24 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/245446 From: Hetvi Thakar This patch backports the upstream fix for CVE-2026-8643 and the two follow-up regression fixes. The primary commit is included in pip 26.1.2 and referenced in [1]. The public CVE advisory is referenced in [2]. The first follow-up fixes doubled-slash directory handling and the second reuses pip's shared directory-containment helper. The upstream regression commits are referenced in [3] and [4]. [1] https://github.com/pypa/pip/commit/8eb178480bd1a2b223f509fc430796b265158dfb [2] https://github.com/advisories/GHSA-wf93-45jw-7689 [3] https://github.com/pypa/pip/commit/7ff8bdd81ec5edca2bebf78ad8506dda710d6af5 [4] https://github.com/pypa/pip/commit/fa7854f6b37113a2c4698cdde902e1fcc9bebdd5 Signed-off-by: Hetvi Thakar Signed-off-by: Yoann Congal --- .../CVE-2026-8643-regression_p1.patch | 35 ++++++++ .../CVE-2026-8643-regression_p2.patch | 69 ++++++++++++++++ .../python/python3-pip/CVE-2026-8643.patch | 80 +++++++++++++++++++ .../python/python3-pip_26.0.1.bb | 3 + 4 files changed, 187 insertions(+) create mode 100644 meta/recipes-devtools/python/python3-pip/CVE-2026-8643-regression_p1.patch create mode 100644 meta/recipes-devtools/python/python3-pip/CVE-2026-8643-regression_p2.patch create mode 100644 meta/recipes-devtools/python/python3-pip/CVE-2026-8643.patch diff --git a/meta/recipes-devtools/python/python3-pip/CVE-2026-8643-regression_p1.patch b/meta/recipes-devtools/python/python3-pip/CVE-2026-8643-regression_p1.patch new file mode 100644 index 00000000000..e269dca667b --- /dev/null +++ b/meta/recipes-devtools/python/python3-pip/CVE-2026-8643-regression_p1.patch @@ -0,0 +1,35 @@ +From 7ff8bdd81ec5edca2bebf78ad8506dda710d6af5 Mon Sep 17 00:00:00 2001 +From: Damian Shaw +Date: Mon, 18 May 2026 23:22:51 -0400 +Subject: [PATCH] Fix is_within_directory for doubled-slash roots + +CVE: CVE-2026-8643 +Upstream-Status: Backport [https://github.com/pypa/pip/commit/7ff8bdd81ec5edca2bebf78ad8506dda710d6af5] + +Backport Changes: +- Omitted tests/unit/test_utils_unpacking.py because the pip 26.0.1 + PyPI sdist used by this recipe does not ship the upstream tests + directory. + +(cherry picked from commit 7ff8bdd81ec5edca2bebf78ad8506dda710d6af5) +Signed-off-by: Hetvi Thakar +--- + src/pip/_internal/utils/unpacking.py | 3 +-- + 1 file changed, 1 insertion(+), 2 deletions(-) + +diff --git a/src/pip/_internal/utils/unpacking.py b/src/pip/_internal/utils/unpacking.py +index 879b40c37e..ba7cb52579 100644 +--- a/src/pip/_internal/utils/unpacking.py ++++ b/src/pip/_internal/utils/unpacking.py +@@ -83,8 +83,7 @@ def is_within_directory(directory: str, target: str) -> bool: + abs_directory = os.path.abspath(directory) + abs_target = os.path.abspath(target) + +- prefix = os.path.commonpath([abs_directory, abs_target]) +- return prefix == abs_directory ++ return abs_target == abs_directory or abs_target.startswith(abs_directory + os.sep) + + + def _get_default_mode_plus_executable() -> int: +-- +2.35.6 diff --git a/meta/recipes-devtools/python/python3-pip/CVE-2026-8643-regression_p2.patch b/meta/recipes-devtools/python/python3-pip/CVE-2026-8643-regression_p2.patch new file mode 100644 index 00000000000..bd40e3b9e8f --- /dev/null +++ b/meta/recipes-devtools/python/python3-pip/CVE-2026-8643-regression_p2.patch @@ -0,0 +1,69 @@ +From fa7854f6b37113a2c4698cdde902e1fcc9bebdd5 Mon Sep 17 00:00:00 2001 +From: Damian +Date: Sun, 24 May 2026 14:54:47 -0400 +Subject: [PATCH] Use is_within_directory for entry point check + +CVE: CVE-2026-8643 +Upstream-Status: Backport [https://github.com/pypa/pip/commit/fa7854f6b37113a2c4698cdde902e1fcc9bebdd5] + +Backport Changes: +- Omitted tests/unit/test_wheel.py because the pip 26.0.1 PyPI sdist + used by this recipe does not ship the upstream tests directory. + +(cherry picked from commit fa7854f6b37113a2c4698cdde902e1fcc9bebdd5) +Signed-off-by: Hetvi Thakar +--- + src/pip/_internal/operations/install/wheel.py | 18 ++++++------------ + src/pip/_internal/utils/unpacking.py | 1 + + 2 files changed, 7 insertions(+), 12 deletions(-) + +diff --git a/src/pip/_internal/operations/install/wheel.py b/src/pip/_internal/operations/install/wheel.py +index 231e400658..6f9a983364 100644 +--- a/src/pip/_internal/operations/install/wheel.py ++++ b/src/pip/_internal/operations/install/wheel.py +@@ -397,17 +397,6 @@ class MissingCallableSuffix(InstallationError): + ) + + +-def _script_within_dir(name: str, scripts_dir: str) -> bool: +- """Return whether script ``name`` resolves to a path inside the ``scripts_dir``. +- +- distlib joins the entry point name onto the scripts directory, so a name +- with path separators or ``..`` components can resolve elsewhere. +- """ +- root = os.path.normpath(scripts_dir) +- dest = os.path.normpath(os.path.join(scripts_dir, name)) +- return dest.startswith(root + os.sep) +- +- + def _raise_for_invalid_entrypoint(specification: str, scripts_dir: str) -> None: + entry = get_export_entry(specification) + if entry is None: +@@ -416,7 +405,12 @@ def _raise_for_invalid_entrypoint(specification: str, scripts_dir: str) -> None: + if entry.suffix is None: + raise MissingCallableSuffix(str(entry)) + +- if not _script_within_dir(entry.name, scripts_dir): ++ # distlib joins the entry point name onto the scripts directory, so a name ++ # with path separators or ``..`` components can resolve elsewhere. The script ++ # must resolve to a path strictly inside the scripts directory. ++ dest = os.path.join(scripts_dir, entry.name) ++ resolves_to_scripts_dir = os.path.abspath(dest) == os.path.abspath(scripts_dir) ++ if resolves_to_scripts_dir or not is_within_directory(scripts_dir, dest): + raise InstallationError( + f"Invalid script entry point name {entry.name!r}: the script " + f"would be installed outside the scripts directory ({scripts_dir})." +diff --git a/src/pip/_internal/utils/unpacking.py b/src/pip/_internal/utils/unpacking.py +index ba7cb52579..8a9b2059ca 100644 +--- a/src/pip/_internal/utils/unpacking.py ++++ b/src/pip/_internal/utils/unpacking.py +@@ -79,6 +79,7 @@ def has_leading_dir(paths: Iterable[str]) -> bool: + def is_within_directory(directory: str, target: str) -> bool: + """ + Return true if the absolute path of target is within the directory ++ (including when target is equal to the directory). + """ + abs_directory = os.path.abspath(directory) + abs_target = os.path.abspath(target) +-- +2.35.6 diff --git a/meta/recipes-devtools/python/python3-pip/CVE-2026-8643.patch b/meta/recipes-devtools/python/python3-pip/CVE-2026-8643.patch new file mode 100644 index 00000000000..2f38ad0207c --- /dev/null +++ b/meta/recipes-devtools/python/python3-pip/CVE-2026-8643.patch @@ -0,0 +1,80 @@ +From 483d83c13c9d69c1916c06cab29991f6c2725cee Mon Sep 17 00:00:00 2001 +From: Damian Shaw +Date: Wed, 20 May 2026 15:20:25 -0400 +Subject: [PATCH] Reject entry point names that escape scripts dir (#14000) + +* Reject entry point names that escape scripts dir + +* NEWS ENTRY + +CVE: CVE-2026-8643 +Upstream-Status: Backport [https://github.com/pypa/pip/commit/8eb178480bd1a2b223f509fc430796b265158dfb] + +Backport Changes: +- Omitted tests/unit/test_wheel.py because the pip 26.0.1 PyPI sdist + does not ship the upstream test suite and the OE recipe does not + enable ptest. + +(cherry picked from commit 8eb178480bd1a2b223f509fc430796b265158dfb) +Signed-off-by: Hetvi Thakar +--- + news/14000.bugfix.rst | 2 ++ + src/pip/_internal/operations/install/wheel.py | 26 ++++++++++++++++--- + 2 files changed, 25 insertions(+), 3 deletions(-) + create mode 100644 news/14000.bugfix.rst + +diff --git a/news/14000.bugfix.rst b/news/14000.bugfix.rst +new file mode 100644 +index 000000000..3b86f1b3b +--- /dev/null ++++ b/news/14000.bugfix.rst +@@ -0,0 +1,2 @@ ++Reject ``console_scripts`` and ``gui_scripts`` entry points whose name would ++install a script outside the scripts directory. +diff --git a/src/pip/_internal/operations/install/wheel.py b/src/pip/_internal/operations/install/wheel.py +index 40097d6a7..231e40065 100644 +--- a/src/pip/_internal/operations/install/wheel.py ++++ b/src/pip/_internal/operations/install/wheel.py +@@ -397,11 +397,31 @@ class MissingCallableSuffix(InstallationError): + ) + + +-def _raise_for_invalid_entrypoint(specification: str) -> None: ++def _script_within_dir(name: str, scripts_dir: str) -> bool: ++ """Return whether script ``name`` resolves to a path inside the ``scripts_dir``. ++ ++ distlib joins the entry point name onto the scripts directory, so a name ++ with path separators or ``..`` components can resolve elsewhere. ++ """ ++ root = os.path.normpath(scripts_dir) ++ dest = os.path.normpath(os.path.join(scripts_dir, name)) ++ return dest.startswith(root + os.sep) ++ ++ ++def _raise_for_invalid_entrypoint(specification: str, scripts_dir: str) -> None: + entry = get_export_entry(specification) +- if entry is not None and entry.suffix is None: ++ if entry is None: ++ return ++ ++ if entry.suffix is None: + raise MissingCallableSuffix(str(entry)) + ++ if not _script_within_dir(entry.name, scripts_dir): ++ raise InstallationError( ++ f"Invalid script entry point name {entry.name!r}: the script " ++ f"would be installed outside the scripts directory ({scripts_dir})." ++ ) ++ + + class PipScriptMaker(ScriptMaker): + # Override distlib's default script template with one that +@@ -419,7 +439,7 @@ class PipScriptMaker(ScriptMaker): + def make( + self, specification: str, options: dict[str, Any] | None = None + ) -> list[str]: +- _raise_for_invalid_entrypoint(specification) ++ _raise_for_invalid_entrypoint(specification, self.target_dir) + return super().make(specification, options) + + diff --git a/meta/recipes-devtools/python/python3-pip_26.0.1.bb b/meta/recipes-devtools/python/python3-pip_26.0.1.bb index 3ff6cd39cd2..b6581575580 100644 --- a/meta/recipes-devtools/python/python3-pip_26.0.1.bb +++ b/meta/recipes-devtools/python/python3-pip_26.0.1.bb @@ -26,6 +26,9 @@ inherit pypi python_setuptools_build_meta SRC_URI += "file://no_shebang_mangling.patch \ file://CVE-2026-13346.patch \ + file://CVE-2026-8643.patch \ + file://CVE-2026-8643-regression_p1.patch \ + file://CVE-2026-8643-regression_p2.patch \ " SRC_URI[sha256sum] = "c4037d8a277c89b320abe636d59f91e6d0922d08a05b60e85e53b296613346d8" From patchwork Wed Sep 9 07:29:37 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 97694 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 59AF8C88E41 for ; Wed, 9 Sep 2026 07:30:24 +0000 (UTC) Received: from mail-wr1-f52.google.com (mail-wr1-f52.google.com [209.85.221.52]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.6450.1788939023119422494 for ; Wed, 09 Sep 2026 00:30:23 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=cVAO9bSO; spf=pass (domain: smile.fr, ip: 209.85.221.52, mailfrom: yoann.congal@smile.fr) Received: by mail-wr1-f52.google.com with SMTP id ffacd0b85a97d-48436251906so6135869f8f.0 for ; Wed, 09 Sep 2026 00:30:22 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1788939021; x=1789543821; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=6Xmc90mmiqmDMSEaarGy6Bwv+gkxAvH8v8Z+5Gxr1HM=; b=cVAO9bSOJzWLzf/96rR6IaA9q9aCe8AMT3VgnRspJXy9uiEY3Y83rOsCQ/ekuiXZrf uLhi+b4UdwtRePYXXfGz/thAwtU87Hbk271eRUy+XzT7vuoWGHbX+DXVJmmu5ITnk/eE uTrFJTiUttsr3G4oDofoJbCea5vWMG194sI6k= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1788939021; x=1789543821; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=6Xmc90mmiqmDMSEaarGy6Bwv+gkxAvH8v8Z+5Gxr1HM=; b=pGLoCmRkJOfQhkru4AeF3bof+5yZh88xeWJSLwWVgSaVMaH5lhk+ZTiCGGPaPcpZR8 YIZdkSQqapd+9b6e4KR2SDJZ8yhShGid3MBdRomXlCUVbX9Bc4VoNN6aodWq40ysD7fg jVIyY5U8CovzwzqhvUlfsPnXWPk2JNEyO/v9S3VEgBXk7PJ/B1DkW7hPsIcV2f5KWs36 H6355hBpDZBseRfi6yYi7uJ7jC+ucTQLXnhTp5J7RFBh+wx6l7HXhOHdWzorxarznRp4 Kx25sfenyvvuVic91G7DXuyN2flV1pDCvOnufZCaSv2qPG2afy5P61cDnn8hFWLrvsap VvuA== X-Gm-Message-State: AFuF++kLhsauZbBYeuNaNsDmA2gv0Ny6zN8Qdc0prhnqmpv7Ux+3jLRf RLmVm+Rb55UNOAA2PSvdAfgUkuYCXg/h3puXaXkQg0/OxD73Gfp7u3EOHRp3qob07DwSTMY+cQe 5isHGgKE= X-Gm-Gg: AYBFou0o0DqaHIWCWGz/Zz7KKI+Hk1n0CR4Kqvsb2bknlPOS0ruYGHNA3tIFBfl9Dj+ GWMNAtT9ZbGISC1R6+GACbzeSs3pmR3OrVMryKFRa3wPGh/I6JfPDB5Y61k5vbeLS99Yuh9LKKN 7rssBq+oGVmj3tPHJ5pZ6UKDoCiB3z545WKFqBvf78Et0GGoXeDfoRD4o4QUWDTVkooWUpOKoog XISknZNsL0wgGRfsUF5OTLHs04d6pAV/WRR1Gt1wt0LwK7Q26z6Rdq3y8B/ar5TYyIUF1anFWQk uZSXMB76YDkgKNdAGPpFWbfWfNuL1EDadswR8jkqLaJamEz5X42ChpfsPA6bdoaGOWvZB0CsvU3 5lDRqSM6LOgIbCWXVt1KcVyNo8o5jqQrMwMnYMtRk/oQ53D5dk+GmMv4jcn1lz6Mjg8N0sclp0h 9tqVRbJyaw6x6dzE2obPuIW1vJZ+N3CYgiD711tEm8ErXUs6+DAtO7XFP8tC14lHI4fjbWHjPEg PjZ4xhJJaKdqXtypujw94L8mWMsVsyYkiHtIP27pZEKZvVNWFIplL1S9kIL X-Received: by 2002:a05:6000:41cb:b0:482:f61c:7cdd with SMTP id ffacd0b85a97d-48586e4a6bbmr73222619f8f.4.1788939021249; Wed, 09 Sep 2026 00:30:21 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-4858ac2b4cdsm40624310f8f.16.2026.09.09.00.30.20 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 09 Sep 2026 00:30:20 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][wrynose 38/38] gawk: skip randtest in ptest suite Date: Wed, 9 Sep 2026 09:29:37 +0200 Message-ID: <4ce10a99a44924dd629fbd79268207b145ccfc62.1788938909.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Wed, 09 Sep 2026 07:30:24 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/245447 From: Himani Ramesh Barde randtest performs autocorrelation analysis on random number sequences and fails intermittently on overloaded CI/autobuilder systems where CPU scheduling and floating point conditions vary between runs. An upstream fix was previously merged (ccabae3036a7) to improve sigma threshold handling, but the test failed again on qemux86-64-musl-ptest on 2026-07-21 with 'Tau= 162, Autocorr= 5.15181 sigma'. The test is inherently unsuitable for shared overloaded build infrastructure. Skip it, consistent with how 'time' and 'timeout' are already handled. [YOCTO #16254] Signed-off-by: Himani Barde Signed-off-by: Richard Purdie (cherry picked from commit 5266eed8f8c2096462da720093aa1556df726098) Signed-off-by: Yoann Congal --- meta/recipes-extended/gawk/gawk_5.4.0.bb | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/meta/recipes-extended/gawk/gawk_5.4.0.bb b/meta/recipes-extended/gawk/gawk_5.4.0.bb index f44d82b37c5..5be7efad452 100644 --- a/meta/recipes-extended/gawk/gawk_5.4.0.bb +++ b/meta/recipes-extended/gawk/gawk_5.4.0.bb @@ -85,7 +85,10 @@ do_install_ptest() { # https://bugzilla.yoctoproject.org/show_bug.cgi?id=14371 rm -f ${D}${PTEST_PATH}/test/time.* rm -f ${D}${PTEST_PATH}/test/timeout.* - for t in time timeout; do + # randtest is a statistical test that intermittently fails on overloaded systems + # https://bugzilla.yoctoproject.org/show_bug.cgi?id=16254 + rm -f ${D}${PTEST_PATH}/test/randtest.* + for t in time timeout randtest; do echo $t >> ${D}${PTEST_PATH}/test/skipped.txt done }