From patchwork Fri Sep 11 22:14:55 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 98074 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id BC838C88E5C for ; Fri, 11 Sep 2026 22:15:49 +0000 (UTC) Received: from mail-wm2-f12.google.com (mail-wm2-f12.google.com [74.125.225.140]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.50887.1789164946992321927 for ; Fri, 11 Sep 2026 15:15:47 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=BG/sBy9O; spf=pass (domain: smile.fr, ip: 74.125.225.140, mailfrom: yoann.congal@smile.fr) Received: by mail-wm2-f12.google.com with SMTP id 5b1f17b1804b1-49b912e2406so1710445e9.1 for ; Fri, 11 Sep 2026 15:15:46 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1789164945; x=1789769745; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=IoqidnrdKQBRUlvFZnNfc8+4ASy/jL8Bpa5K2Cn3C5U=; b=BG/sBy9OfthefWgkh9e2zAOs1hrWq70lJ/ueVGStsnbFxV3Pdc/kihm6nqFGY4hbAG Qs01bF7p2HIqUHAHky3XGaUwBKu4oheRUNk+K4G6YKORSrOZe5UX1PXbpZwDS32e07mE XgUERnhIaU5Ro1FR/4oLJCdOVE6bYMN3c/07Q= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1789164945; x=1789769745; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=IoqidnrdKQBRUlvFZnNfc8+4ASy/jL8Bpa5K2Cn3C5U=; b=FREi6jTobTauLr6qr1iXhQ33HIhzgnzIvIjMybIyYdjS/cxHK6H+OOElgZGgZ4Ag2n CjGWmzCFPY4UvPstertzXWLEG9JbeK8gwIc5QJFQB7XtO7kOpTFF8tZLMvN/m7k79cw4 N3w5QmKfmmpO2O2J2PFMluiyC0+XYFHzDvUlWVP89+j8j+fwBGWI4yp45IEqTWAlbfaQ xLMtnYthN6BS8x09EilGLETz9CAyrWibDmj7KsoRWI0d9Q1DoxO3iYC/UBnp+ns1eFHV ks/gNQ3m6jKJ81XeA/UjToMt3S03Sz+pb7YyncDFmtejCWFor2lHfAyGJ0f1NURzWRgD YeKw== X-Gm-Message-State: AFuF++kz86c4fx2ESwqYZOUzDYSMbX02C9+PLlr5t+uQiZvpEPRr+XvS +b40uxQX8U0bHTm0hWZatOt2FjIN1ENjRxkR8JFuBEaOkXzXRcnFev2ItMbGSroH6uR49FTVFw2 XfQrMSg8= X-Gm-Gg: AYBFou0+yloXbrJy0ahlS27QQ8w/WM4KBTa4jwIHIIxM2/6LMzCfNsGSHDw23lu3+hx uRJMgXMTjieK3DmEk7MK7Td2ClcpBRV7c5lMQ05EjWx05BahARJPSXu6c6x8Ox2jpxBQobjAX4I FQoTHzKednW09kPil/nAizgMd2QoxV+ZdqzLcEnpoP/YSNsktSWeCGn2dGmVJh05A6NIrWKlK9/ rJfQ699hkp2oJ9Y9wmcyishbr6yW7+eJEuCjoDHSyrW7pQtunmwa0FC3p7FFl/rTZ8oKZZkkmjX Nx0Wn5uV4u0OUJdJr8LISKeMCDOIUyUXASftvjTMZ3/+GfQFP51xYkEGztTKoAzTsJ5gd0GYue/ j42wFhpcMVgS178t9mhQbWBcDuiCka1fA3kN6OzaOm5Xf8AFzmLK9S7IfwPe809QFu0N/Y6JHPW 6PE4Tq/qn9zsU0DjG9kxMXgPL73dm4stKHmfjTF3DfIwJY4YWxpvWnndlTUSer/AjbBOd2S712j ej7SVIZ1b7t7XCr61Dh5Og3THnQjc65w3VlE/E8KCNqUj8UltvRJpvQyBgy3EezIb9pShgJ0us= X-Received: by 2002:a05:600c:19cb:b0:49e:6581:7baf with SMTP id 5b1f17b1804b1-49e658188e3mr55283595e9.2.1789164943998; Fri, 11 Sep 2026 15:15:43 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-49e6c566bdbsm8434045e9.11.2026.09.11.15.15.43 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Fri, 11 Sep 2026 15:15:43 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][scarthgap 01/13] linux-yocto/6.6: update CVE exclusions (6.6.151) Date: Sat, 12 Sep 2026 00:14:55 +0200 Message-ID: <0298f0068f71ba4991ce1dca1c4e0a3e4bbe8be1.1789163914.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Fri, 11 Sep 2026 22:15:49 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/245674 From: Yoann Congal $ ./meta/recipes-kernel/linux/generate-cve-exclusions.py .../cvelistV5/ 6.6.151 > meta/recipes-kernel/linux/cve-exclusion_6.6.inc Generated at 2026-09-10 12:23:31.488006+00:00 for kernel version 6.6.151 From cvelistV5 cve_2026-09-10_1100Z-4-g5fc16492753 Signed-off-by: Yoann Congal --- .../linux/cve-exclusion_6.6.inc | 4540 ++++++++++++++++- 1 file changed, 4465 insertions(+), 75 deletions(-) diff --git a/meta/recipes-kernel/linux/cve-exclusion_6.6.inc b/meta/recipes-kernel/linux/cve-exclusion_6.6.inc index fd17e611a4b..d2704e76449 100644 --- a/meta/recipes-kernel/linux/cve-exclusion_6.6.inc +++ b/meta/recipes-kernel/linux/cve-exclusion_6.6.inc @@ -1,11 +1,11 @@ # Auto-generated CVE metadata, DO NOT EDIT BY HAND. -# Generated at 2026-07-23 08:09:32.765073+00:00 for kernel version 6.6.144 -# From cvelistV5 cve_2026-07-23_0700Z +# Generated at 2026-09-10 12:23:31.488006+00:00 for kernel version 6.6.151 +# From cvelistV5 cve_2026-09-10_1100Z-4-g5fc16492753 python check_kernel_cve_status_version() { - this_version = "6.6.144" + this_version = "6.6.151" kernel_version = d.getVar("LINUX_VERSION") if kernel_version != this_version: bb.warn("Kernel CVE status needs updating: generated for %s but kernel is %s" % (this_version, kernel_version)) @@ -1226,8 +1226,6 @@ CVE_STATUS[CVE-2021-47502] = "fixed-version: Fixed from version 5.16" CVE_STATUS[CVE-2021-47503] = "fixed-version: Fixed from version 5.16" -CVE_STATUS[CVE-2021-47504] = "fixed-version: Fixed from version 5.16" - CVE_STATUS[CVE-2021-47505] = "fixed-version: Fixed from version 5.16" CVE_STATUS[CVE-2021-47506] = "fixed-version: Fixed from version 5.16" @@ -1480,7 +1478,7 @@ CVE_STATUS[CVE-2021-47643] = "fixed-version: Fixed from version 5.18" CVE_STATUS[CVE-2021-47644] = "fixed-version: Fixed from version 5.18" -CVE_STATUS[CVE-2021-47645] = "fixed-version: Fixed from version 5.18" +# CVE-2021-47645 has no known resolution CVE_STATUS[CVE-2021-47646] = "fixed-version: Fixed from version 5.18" @@ -2028,8 +2026,6 @@ CVE_STATUS[CVE-2022-48875] = "fixed-version: Fixed from version 6.2" CVE_STATUS[CVE-2022-48876] = "fixed-version: Fixed from version 6.2" -CVE_STATUS[CVE-2022-48877] = "fixed-version: Fixed from version 6.2" - CVE_STATUS[CVE-2022-48878] = "fixed-version: Fixed from version 6.2" CVE_STATUS[CVE-2022-48879] = "fixed-version: Fixed from version 6.2" @@ -4198,6 +4194,8 @@ CVE_STATUS[CVE-2022-49998] = "fixed-version: Fixed from version 6.0" CVE_STATUS[CVE-2022-49999] = "fixed-version: Fixed from version 6.0" +CVE_STATUS[CVE-2022-4994] = "fixed-version: Fixed from version 6.0" + CVE_STATUS[CVE-2022-50000] = "fixed-version: Fixed from version 6.0" CVE_STATUS[CVE-2022-50001] = "fixed-version: Fixed from version 6.0" @@ -5916,7 +5914,7 @@ CVE_STATUS[CVE-2023-52483] = "fixed-version: Fixed from version 6.6" CVE_STATUS[CVE-2023-52484] = "fixed-version: Fixed from version 6.6" -# CVE-2023-52485 needs backporting (fixed from 6.8) +CVE_STATUS[CVE-2023-52485] = "fixed-version: only affects 6.7 onwards" CVE_STATUS[CVE-2023-52486] = "cpe-stable-backport: Backported in 6.6.15" @@ -6054,7 +6052,7 @@ CVE_STATUS[CVE-2023-52583] = "cpe-stable-backport: Backported in 6.6.16" CVE_STATUS[CVE-2023-52584] = "cpe-stable-backport: Backported in 6.6.16" -CVE_STATUS[CVE-2023-52585] = "cpe-stable-backport: Backported in 6.6.32" +CVE_STATUS[CVE-2023-52585] = "fixed-version: only affects 6.7 onwards" # CVE-2023-52586 needs backporting (fixed from 6.8) @@ -9034,6 +9032,8 @@ CVE_STATUS[CVE-2023-7324] = "fixed-version: Fixed from version 6.3" CVE_STATUS[CVE-2024-14027] = "cpe-stable-backport: Backported in 6.6.133" +# CVE-2024-14040 needs backporting (fixed from 6.12) + CVE_STATUS[CVE-2024-26581] = "cpe-stable-backport: Backported in 6.6.17" CVE_STATUS[CVE-2024-26582] = "cpe-stable-backport: Backported in 6.6.18" @@ -9852,7 +9852,7 @@ CVE_STATUS[CVE-2024-27008] = "cpe-stable-backport: Backported in 6.6.29" CVE_STATUS[CVE-2024-27009] = "cpe-stable-backport: Backported in 6.6.29" -# CVE-2024-27010 needs backporting (fixed from 6.9) +# CVE-2024-27010 may need backporting (fixed from 6.6.156) CVE_STATUS[CVE-2024-27011] = "cpe-stable-backport: Backported in 6.6.55" @@ -11068,7 +11068,7 @@ CVE_STATUS[CVE-2024-39476] = "cpe-stable-backport: Backported in 6.6.34" CVE_STATUS[CVE-2024-39477] = "fixed-version: only affects 6.9 onwards" -# CVE-2024-39478 needs backporting (fixed from 6.10) +# CVE-2024-39478 may need backporting (fixed from 6.6.156) CVE_STATUS[CVE-2024-39479] = "cpe-stable-backport: Backported in 6.6.34" @@ -12472,7 +12472,7 @@ CVE_STATUS[CVE-2024-46752] = "cpe-stable-backport: Backported in 6.6.51" CVE_STATUS[CVE-2024-46753] = "cpe-stable-backport: Backported in 6.6.87" -# CVE-2024-46754 needs backporting (fixed from 6.11) +# CVE-2024-46754 may need backporting (fixed from 6.6.156) CVE_STATUS[CVE-2024-46755] = "cpe-stable-backport: Backported in 6.6.51" @@ -15134,9 +15134,9 @@ CVE_STATUS[CVE-2024-58092] = "fixed-version: only affects 6.8 onwards" CVE_STATUS[CVE-2024-58093] = "cpe-stable-backport: Backported in 6.6.87" -# CVE-2024-58094 needs backporting (fixed from 6.15) +# CVE-2024-58094 may need backporting (fixed from 6.6.156) -# CVE-2024-58095 needs backporting (fixed from 6.15) +# CVE-2024-58095 may need backporting (fixed from 6.6.156) CVE_STATUS[CVE-2024-58096] = "cpe-stable-backport: Backported in 6.6.123" @@ -16088,7 +16088,7 @@ CVE_STATUS[CVE-2025-22102] = "cpe-stable-backport: Backported in 6.6.92" CVE_STATUS[CVE-2025-22103] = "cpe-stable-backport: Backported in 6.6.117" -# CVE-2025-22104 needs backporting (fixed from 6.15) +# CVE-2025-22104 may need backporting (fixed from 6.6.156) CVE_STATUS[CVE-2025-22105] = "cpe-stable-backport: Backported in 6.6.119" @@ -17108,13 +17108,13 @@ CVE_STATUS[CVE-2025-38201] = "cpe-stable-backport: Backported in 6.6.124" CVE_STATUS[CVE-2025-38202] = "cpe-stable-backport: Backported in 6.6.95" -# CVE-2025-38203 needs backporting (fixed from 6.16) +# CVE-2025-38203 may need backporting (fixed from 6.6.156) # CVE-2025-38204 needs backporting (fixed from 6.16) CVE_STATUS[CVE-2025-38205] = "fixed-version: only affects 6.7 onwards" -# CVE-2025-38206 needs backporting (fixed from 6.16) +# CVE-2025-38206 may need backporting (fixed from 6.6.156) # CVE-2025-38207 needs backporting (fixed from 6.16) @@ -17174,7 +17174,7 @@ CVE_STATUS[CVE-2025-38235] = "fixed-version: only affects 6.15 onwards" CVE_STATUS[CVE-2025-38236] = "cpe-stable-backport: Backported in 6.6.96" -# CVE-2025-38237 needs backporting (fixed from 6.16) +# CVE-2025-38237 may need backporting (fixed from 6.6.156) CVE_STATUS[CVE-2025-38238] = "fixed-version: only affects 6.14 onwards" @@ -17748,7 +17748,7 @@ CVE_STATUS[CVE-2025-38523] = "fixed-version: only affects 6.12 onwards" CVE_STATUS[CVE-2025-38524] = "cpe-stable-backport: Backported in 6.6.100" -CVE_STATUS[CVE-2025-38525] = "fixed-version: only affects 6.14 onwards" +CVE_STATUS[CVE-2025-38525] = "cpe-stable-backport: Backported in 6.6.151" CVE_STATUS[CVE-2025-38526] = "cpe-stable-backport: Backported in 6.6.100" @@ -18484,7 +18484,7 @@ CVE_STATUS[CVE-2025-39831] = "fixed-version: only affects 6.11 onwards" CVE_STATUS[CVE-2025-39832] = "cpe-stable-backport: Backported in 6.6.104" -# CVE-2025-39833 needs backporting (fixed from 6.17) +# CVE-2025-39833 may need backporting (fixed from 6.6.156) CVE_STATUS[CVE-2025-39834] = "fixed-version: only affects 6.12 onwards" @@ -18616,7 +18616,7 @@ CVE_STATUS[CVE-2025-39899] = "fixed-version: only affects 6.8 onwards" CVE_STATUS[CVE-2025-39900] = "fixed-version: only affects 6.12 onwards" -# CVE-2025-39901 needs backporting (fixed from 6.17) +CVE_STATUS[CVE-2025-39901] = "cpe-stable-backport: Backported in 6.6.148" CVE_STATUS[CVE-2025-39902] = "cpe-stable-backport: Backported in 6.6.105" @@ -18664,7 +18664,7 @@ CVE_STATUS[CVE-2025-39923] = "cpe-stable-backport: Backported in 6.6.107" CVE_STATUS[CVE-2025-39924] = "fixed-version: only affects 6.15 onwards" -# CVE-2025-39925 needs backporting (fixed from 6.17) +# CVE-2025-39925 may need backporting (fixed from 6.6.156) CVE_STATUS[CVE-2025-39926] = "fixed-version: only affects 6.9 onwards" @@ -18922,7 +18922,7 @@ CVE_STATUS[CVE-2025-40052] = "cpe-stable-backport: Backported in 6.6.112" CVE_STATUS[CVE-2025-40053] = "cpe-stable-backport: Backported in 6.6.112" -# CVE-2025-40054 needs backporting (fixed from 6.18) +# CVE-2025-40054 may need backporting (fixed from 6.6.153) CVE_STATUS[CVE-2025-40055] = "cpe-stable-backport: Backported in 6.6.112" @@ -18942,7 +18942,7 @@ CVE_STATUS[CVE-2025-40062] = "cpe-stable-backport: Backported in 6.6.112" CVE_STATUS[CVE-2025-40063] = "fixed-version: only affects 6.16 onwards" -# CVE-2025-40064 needs backporting (fixed from 6.18) +# CVE-2025-40064 may need backporting (fixed from 6.6.156) # CVE-2025-40065 needs backporting (fixed from 6.18) @@ -19018,7 +19018,7 @@ CVE_STATUS[CVE-2025-40100] = "cpe-stable-backport: Backported in 6.6.114" CVE_STATUS[CVE-2025-40101] = "fixed-version: only affects 6.7.11 onwards" -# CVE-2025-40102 needs backporting (fixed from 6.18) +# CVE-2025-40102 may need backporting (fixed from 6.6.156) CVE_STATUS[CVE-2025-40103] = "cpe-stable-backport: Backported in 6.6.114" @@ -19090,7 +19090,7 @@ CVE_STATUS[CVE-2025-40137] = "cpe-stable-backport: Backported in 6.6.112" CVE_STATUS[CVE-2025-40138] = "fixed-version: only affects 6.17 onwards" -# CVE-2025-40139 needs backporting (fixed from 6.18) +# CVE-2025-40139 may need backporting (fixed from 6.6.156) CVE_STATUS[CVE-2025-40140] = "cpe-stable-backport: Backported in 6.6.112" @@ -19146,7 +19146,7 @@ CVE_STATUS[CVE-2025-40166] = "fixed-version: only affects 6.8 onwards" CVE_STATUS[CVE-2025-40167] = "cpe-stable-backport: Backported in 6.6.114" -# CVE-2025-40168 needs backporting (fixed from 6.18) +# CVE-2025-40168 may need backporting (fixed from 6.6.156) CVE_STATUS[CVE-2025-40169] = "cpe-stable-backport: Backported in 6.6.112" @@ -19424,7 +19424,7 @@ CVE_STATUS[CVE-2025-40305] = "fixed-version: only affects 6.14 onwards" CVE_STATUS[CVE-2025-40306] = "cpe-stable-backport: Backported in 6.6.117" -# CVE-2025-40307 needs backporting (fixed from 6.18) +CVE_STATUS[CVE-2025-40307] = "cpe-stable-backport: Backported in 6.6.148" CVE_STATUS[CVE-2025-40308] = "cpe-stable-backport: Backported in 6.6.117" @@ -19798,7 +19798,7 @@ CVE_STATUS[CVE-2025-68310] = "cpe-stable-backport: Backported in 6.6.117" CVE_STATUS[CVE-2025-68312] = "cpe-stable-backport: Backported in 6.6.117" -CVE_STATUS[CVE-2025-68313] = "fixed-version: only affects 6.8 onwards" +CVE_STATUS[CVE-2025-68313] = "fixed-version: only affects 6.6.156 onwards" CVE_STATUS[CVE-2025-68314] = "fixed-version: only affects 6.17 onwards" @@ -20048,7 +20048,7 @@ CVE_STATUS[CVE-2025-68779] = "fixed-version: only affects 6.18 onwards" CVE_STATUS[CVE-2025-68780] = "cpe-stable-backport: Backported in 6.6.120" -CVE_STATUS[CVE-2025-68781] = "cpe-stable-backport: Backported in 6.6.120" +# CVE-2025-68781 needs backporting (fixed from 6.19) CVE_STATUS[CVE-2025-68782] = "cpe-stable-backport: Backported in 6.6.120" @@ -20442,7 +20442,7 @@ CVE_STATUS[CVE-2025-71287] = "cpe-stable-backport: Backported in 6.6.130" CVE_STATUS[CVE-2025-71288] = "cpe-stable-backport: Backported in 6.6.130" -# CVE-2025-71289 needs backporting (fixed from 7.0) +CVE_STATUS[CVE-2025-71289] = "cpe-stable-backport: Backported in 6.6.145" CVE_STATUS[CVE-2025-71290] = "fixed-version: only affects 6.16 onwards" @@ -20494,6 +20494,8 @@ CVE_STATUS[CVE-2025-71314] = "fixed-version: only affects 6.10 onwards" # CVE-2025-71315 needs backporting (fixed from 6.19) +CVE_STATUS[CVE-2026-17523] = "fixed-version: Fixed from version 5.4" + CVE_STATUS[CVE-2026-22976] = "cpe-stable-backport: Backported in 6.6.121" CVE_STATUS[CVE-2026-22977] = "cpe-stable-backport: Backported in 6.6.121" @@ -21308,7 +21310,7 @@ CVE_STATUS[CVE-2026-23382] = "cpe-stable-backport: Backported in 6.6.130" CVE_STATUS[CVE-2026-23384] = "fixed-version: only affects 6.18 onwards" -CVE_STATUS[CVE-2026-23385] = "fixed-version: only affects 6.10 onwards" +CVE_STATUS[CVE-2026-23385] = "cpe-stable-backport: Backported in 6.6.151" CVE_STATUS[CVE-2026-23386] = "cpe-stable-backport: Backported in 6.6.130" @@ -21456,7 +21458,7 @@ CVE_STATUS[CVE-2026-23457] = "cpe-stable-backport: Backported in 6.6.130" CVE_STATUS[CVE-2026-23458] = "cpe-stable-backport: Backported in 6.6.130" -CVE_STATUS[CVE-2026-23459] = "fixed-version: only affects 6.14 onwards" +CVE_STATUS[CVE-2026-23459] = "fixed-version: only affects 6.6.153 onwards" CVE_STATUS[CVE-2026-23460] = "cpe-stable-backport: Backported in 6.6.130" @@ -21516,8 +21518,6 @@ CVE_STATUS[CVE-2026-31402] = "cpe-stable-backport: Backported in 6.6.130" CVE_STATUS[CVE-2026-31403] = "cpe-stable-backport: Backported in 6.6.130" -CVE_STATUS[CVE-2026-31404] = "fixed-version: only affects 6.14 onwards" - CVE_STATUS[CVE-2026-31405] = "cpe-stable-backport: Backported in 6.6.130" CVE_STATUS[CVE-2026-31406] = "fixed-version: only affects 6.11 onwards" @@ -21712,7 +21712,7 @@ CVE_STATUS[CVE-2026-31500] = "cpe-stable-backport: Backported in 6.6.131" CVE_STATUS[CVE-2026-31501] = "fixed-version: only affects 6.15 onwards" -# CVE-2026-31502 needs backporting (fixed from 7.0) +CVE_STATUS[CVE-2026-31502] = "cpe-stable-backport: Backported in 6.6.145" CVE_STATUS[CVE-2026-31503] = "cpe-stable-backport: Backported in 6.6.131" @@ -22512,7 +22512,7 @@ CVE_STATUS[CVE-2026-43117] = "cpe-stable-backport: Backported in 6.6.136" # CVE-2026-43118 needs backporting (fixed from 7.0) -# CVE-2026-43119 needs backporting (fixed from 7.0) +CVE_STATUS[CVE-2026-43119] = "cpe-stable-backport: Backported in 6.6.145" CVE_STATUS[CVE-2026-43120] = "cpe-stable-backport: Backported in 6.6.136" @@ -22704,7 +22704,7 @@ CVE_STATUS[CVE-2026-43214] = "cpe-stable-backport: Backported in 6.6.128" CVE_STATUS[CVE-2026-43215] = "cpe-stable-backport: Backported in 6.6.128" -# CVE-2026-43216 needs backporting (fixed from 7.0) +CVE_STATUS[CVE-2026-43216] = "cpe-stable-backport: Backported in 6.6.145" CVE_STATUS[CVE-2026-43217] = "fixed-version: only affects 6.15 onwards" @@ -23180,7 +23180,7 @@ CVE_STATUS[CVE-2026-43454] = "fixed-version: only affects 6.16 onwards" CVE_STATUS[CVE-2026-43455] = "cpe-stable-backport: Backported in 6.6.130" -# CVE-2026-43456 needs backporting (fixed from 7.0) +CVE_STATUS[CVE-2026-43456] = "cpe-stable-backport: Backported in 6.6.145" CVE_STATUS[CVE-2026-43457] = "cpe-stable-backport: Backported in 6.6.130" @@ -23534,7 +23534,7 @@ CVE_STATUS[CVE-2026-45960] = "cpe-stable-backport: Backported in 6.6.128" CVE_STATUS[CVE-2026-45962] = "cpe-stable-backport: Backported in 6.6.128" -# CVE-2026-45963 needs backporting (fixed from 7.0) +# CVE-2026-45963 may need backporting (fixed from 6.6.156) CVE_STATUS[CVE-2026-45964] = "cpe-stable-backport: Backported in 6.6.128" @@ -23994,8 +23994,6 @@ CVE_STATUS[CVE-2026-46192] = "fixed-version: only affects 6.17 onwards" CVE_STATUS[CVE-2026-46193] = "cpe-stable-backport: Backported in 6.6.140" -CVE_STATUS[CVE-2026-46194] = "cpe-stable-backport: Backported in 6.6.140" - CVE_STATUS[CVE-2026-46195] = "cpe-stable-backport: Backported in 6.6.140" CVE_STATUS[CVE-2026-46196] = "cpe-stable-backport: Backported in 6.6.140" @@ -24516,7 +24514,7 @@ CVE_STATUS[CVE-2026-53023] = "cpe-stable-backport: Backported in 6.6.141" CVE_STATUS[CVE-2026-53026] = "fixed-version: only affects 6.18.4 onwards" -# CVE-2026-53027 needs backporting (fixed from 7.1) +CVE_STATUS[CVE-2026-53027] = "cpe-stable-backport: Backported in 6.6.145" CVE_STATUS[CVE-2026-53028] = "fixed-version: only affects 6.18 onwards" @@ -24640,9 +24638,9 @@ CVE_STATUS[CVE-2026-53087] = "fixed-version: only affects 6.15 onwards" CVE_STATUS[CVE-2026-53088] = "cpe-stable-backport: Backported in 6.6.141" -# CVE-2026-53089 needs backporting (fixed from 7.1) +# CVE-2026-53089 may need backporting (fixed from 6.6.156) -# CVE-2026-53090 needs backporting (fixed from 7.1) +CVE_STATUS[CVE-2026-53090] = "cpe-stable-backport: Backported in 6.6.148" # CVE-2026-53091 needs backporting (fixed from 7.1) @@ -25124,7 +25122,7 @@ CVE_STATUS[CVE-2026-53329] = "cpe-stable-backport: Backported in 6.6.143" CVE_STATUS[CVE-2026-53331] = "cpe-stable-backport: Backported in 6.6.143" -# CVE-2026-53332 needs backporting (fixed from 7.1) +CVE_STATUS[CVE-2026-53332] = "cpe-stable-backport: Backported in 6.6.145" CVE_STATUS[CVE-2026-53333] = "fixed-version: only affects 6.18 onwards" @@ -25244,9 +25242,9 @@ CVE_STATUS[CVE-2026-53390] = "cpe-stable-backport: Backported in 6.6.144" CVE_STATUS[CVE-2026-53391] = "cpe-stable-backport: Backported in 6.6.144" -# CVE-2026-53392 needs backporting (fixed from 7.2rc1) +CVE_STATUS[CVE-2026-53392] = "cpe-stable-backport: Backported in 6.6.145" -# CVE-2026-53393 needs backporting (fixed from 7.2rc1) +CVE_STATUS[CVE-2026-53393] = "cpe-stable-backport: Backported in 6.6.145" CVE_STATUS[CVE-2026-53394] = "fixed-version: only affects 6.10 onwards" @@ -25258,13 +25256,13 @@ CVE_STATUS[CVE-2026-53397] = "cpe-stable-backport: Backported in 6.6.144" CVE_STATUS[CVE-2026-53398] = "cpe-stable-backport: Backported in 6.6.144" -# CVE-2026-53399 needs backporting (fixed from 7.2rc1) +CVE_STATUS[CVE-2026-53399] = "cpe-stable-backport: Backported in 6.6.145" -# CVE-2026-53400 needs backporting (fixed from 7.2rc1) +CVE_STATUS[CVE-2026-53400] = "cpe-stable-backport: Backported in 6.6.145" -# CVE-2026-53401 needs backporting (fixed from 7.2rc1) +# CVE-2026-53401 needs backporting (fixed from 7.2) -# CVE-2026-53402 needs backporting (fixed from 7.2rc1) +CVE_STATUS[CVE-2026-53402] = "cpe-stable-backport: Backported in 6.6.145" CVE_STATUS[CVE-2026-53403] = "cpe-stable-backport: Backported in 6.6.144" @@ -25292,9 +25290,9 @@ CVE_STATUS[CVE-2026-63803] = "cpe-stable-backport: Backported in 6.6.144" CVE_STATUS[CVE-2026-63804] = "cpe-stable-backport: Backported in 6.6.144" -# CVE-2026-63805 needs backporting (fixed from 7.2rc1) +# CVE-2026-63805 needs backporting (fixed from 7.2) -# CVE-2026-63806 needs backporting (fixed from 7.2rc1) +CVE_STATUS[CVE-2026-63806] = "cpe-stable-backport: Backported in 6.6.145" CVE_STATUS[CVE-2026-63807] = "cpe-stable-backport: Backported in 6.6.144" @@ -25302,9 +25300,9 @@ CVE_STATUS[CVE-2026-63808] = "cpe-stable-backport: Backported in 6.6.144" CVE_STATUS[CVE-2026-63809] = "cpe-stable-backport: Backported in 6.6.144" -# CVE-2026-63810 needs backporting (fixed from 7.2rc1) +CVE_STATUS[CVE-2026-63810] = "cpe-stable-backport: Backported in 6.6.145" -# CVE-2026-63811 needs backporting (fixed from 7.2rc1) +# CVE-2026-63811 needs backporting (fixed from 7.2) CVE_STATUS[CVE-2026-63812] = "cpe-stable-backport: Backported in 6.6.144" @@ -25312,15 +25310,15 @@ CVE_STATUS[CVE-2026-63813] = "fixed-version: only affects 7.0 onwards" CVE_STATUS[CVE-2026-63814] = "cpe-stable-backport: Backported in 6.6.144" -# CVE-2026-63815 needs backporting (fixed from 7.2rc1) +CVE_STATUS[CVE-2026-63815] = "cpe-stable-backport: Backported in 6.6.145" -# CVE-2026-63816 needs backporting (fixed from 7.2rc1) +CVE_STATUS[CVE-2026-63816] = "cpe-stable-backport: Backported in 6.6.145" CVE_STATUS[CVE-2026-63817] = "cpe-stable-backport: Backported in 6.6.144" -# CVE-2026-63818 needs backporting (fixed from 7.2rc1) +CVE_STATUS[CVE-2026-63818] = "cpe-stable-backport: Backported in 6.6.145" -# CVE-2026-63819 needs backporting (fixed from 7.2rc1) +# CVE-2026-63819 needs backporting (fixed from 7.2) CVE_STATUS[CVE-2026-63820] = "fixed-version: only affects 7.0 onwards" @@ -25332,7 +25330,7 @@ CVE_STATUS[CVE-2026-63823] = "cpe-stable-backport: Backported in 6.6.144" CVE_STATUS[CVE-2026-63824] = "cpe-stable-backport: Backported in 6.6.144" -# CVE-2026-63825 needs backporting (fixed from 7.2rc1) +# CVE-2026-63825 needs backporting (fixed from 7.2) CVE_STATUS[CVE-2026-63826] = "cpe-stable-backport: Backported in 6.6.144" @@ -25340,7 +25338,7 @@ CVE_STATUS[CVE-2026-63827] = "cpe-stable-backport: Backported in 6.6.144" CVE_STATUS[CVE-2026-63828] = "cpe-stable-backport: Backported in 6.6.144" -# CVE-2026-63829 needs backporting (fixed from 7.2rc1) +CVE_STATUS[CVE-2026-63829] = "cpe-stable-backport: Backported in 6.6.145" CVE_STATUS[CVE-2026-63830] = "cpe-stable-backport: Backported in 6.6.144" @@ -25426,8 +25424,6 @@ CVE_STATUS[CVE-2026-63870] = "cpe-stable-backport: Backported in 6.6.143" # CVE-2026-63871 needs backporting (fixed from 7.1) -# CVE-2026-63872 needs backporting (fixed from 7.1) - CVE_STATUS[CVE-2026-63873] = "fixed-version: only affects 6.16 onwards" CVE_STATUS[CVE-2026-63874] = "fixed-version: only affects 6.15 onwards" @@ -25822,7 +25818,7 @@ CVE_STATUS[CVE-2026-64068] = "fixed-version: only affects 6.10 onwards" CVE_STATUS[CVE-2026-64069] = "fixed-version: only affects 6.14 onwards" -# CVE-2026-64070 needs backporting (fixed from 7.1) +# CVE-2026-64070 may need backporting (fixed from 6.6.156) CVE_STATUS[CVE-2026-64071] = "fixed-version: only affects 6.13 onwards" @@ -25846,7 +25842,7 @@ CVE_STATUS[CVE-2026-64080] = "fixed-version: only affects 6.15 onwards" CVE_STATUS[CVE-2026-64081] = "fixed-version: only affects 6.15 onwards" -# CVE-2026-64082 needs backporting (fixed from 7.1) +# CVE-2026-64082 may need backporting (fixed from 6.6.156) CVE_STATUS[CVE-2026-64083] = "cpe-stable-backport: Backported in 6.6.142" @@ -25998,8 +25994,6 @@ CVE_STATUS[CVE-2026-64156] = "fixed-version: only affects 6.14 onwards" CVE_STATUS[CVE-2026-64157] = "fixed-version: only affects 6.10.8 onwards" -CVE_STATUS[CVE-2026-64158] = "fixed-version: only affects 6.8 onwards" - CVE_STATUS[CVE-2026-64159] = "fixed-version: only affects 6.10.8 onwards" # CVE-2026-64160 needs backporting (fixed from 7.1) @@ -26056,23 +26050,4419 @@ CVE_STATUS[CVE-2026-64185] = "cpe-stable-backport: Backported in 6.6.142" CVE_STATUS[CVE-2026-64186] = "fixed-version: only affects 6.17 onwards" -# CVE-2026-64187 needs backporting (fixed from 7.2rc4) +CVE_STATUS[CVE-2026-64187] = "cpe-stable-backport: Backported in 6.6.145" CVE_STATUS[CVE-2026-64188] = "cpe-stable-backport: Backported in 6.6.144" -# CVE-2026-64189 needs backporting (fixed from 7.2rc2) +CVE_STATUS[CVE-2026-64189] = "cpe-stable-backport: Backported in 6.6.145" # CVE-2026-64190 needs backporting (fixed from 7.1) CVE_STATUS[CVE-2026-64191] = "cpe-stable-backport: Backported in 6.6.144" -# CVE-2026-64192 needs backporting (fixed from 7.2rc2) +CVE_STATUS[CVE-2026-64192] = "cpe-stable-backport: Backported in 6.6.148" -# CVE-2026-64205 needs backporting (fixed from 7.2rc1) +CVE_STATUS[CVE-2026-64205] = "cpe-stable-backport: Backported in 6.6.148" -# CVE-2026-64206 needs backporting (fixed from 7.2rc3) +CVE_STATUS[CVE-2026-64206] = "cpe-stable-backport: Backported in 6.6.145" CVE_STATUS[CVE-2026-64207] = "fixed-version: only affects 6.17 onwards" -# CVE-2026-64600 needs backporting (fixed from 7.2rc4) +CVE_STATUS[CVE-2026-64208] = "fixed-version: only affects 6.16 onwards" + +CVE_STATUS[CVE-2026-64209] = "fixed-version: only affects 7.0 onwards" + +# CVE-2026-64210 needs backporting (fixed from 7.1) + +CVE_STATUS[CVE-2026-64211] = "fixed-version: only affects 7.0 onwards" + +# CVE-2026-64212 needs backporting (fixed from 7.1) + +# CVE-2026-64213 needs backporting (fixed from 7.1) + +CVE_STATUS[CVE-2026-64214] = "cpe-stable-backport: Backported in 6.6.142" + +CVE_STATUS[CVE-2026-64215] = "fixed-version: only affects 6.19 onwards" + +CVE_STATUS[CVE-2026-64216] = "fixed-version: only affects 6.12 onwards" + +CVE_STATUS[CVE-2026-64217] = "cpe-stable-backport: Backported in 6.6.142" + +CVE_STATUS[CVE-2026-64218] = "cpe-stable-backport: Backported in 6.6.142" + +CVE_STATUS[CVE-2026-64219] = "cpe-stable-backport: Backported in 6.6.142" + +CVE_STATUS[CVE-2026-64220] = "cpe-stable-backport: Backported in 6.6.142" + +CVE_STATUS[CVE-2026-64221] = "cpe-stable-backport: Backported in 6.6.142" + +CVE_STATUS[CVE-2026-64222] = "cpe-stable-backport: Backported in 6.6.143" + +CVE_STATUS[CVE-2026-64223] = "fixed-version: only affects 6.9 onwards" + +CVE_STATUS[CVE-2026-64224] = "fixed-version: only affects 6.13 onwards" + +CVE_STATUS[CVE-2026-64225] = "cpe-stable-backport: Backported in 6.6.143" + +CVE_STATUS[CVE-2026-64226] = "fixed-version: only affects 6.12 onwards" + +CVE_STATUS[CVE-2026-64227] = "fixed-version: only affects 6.7 onwards" + +CVE_STATUS[CVE-2026-64228] = "fixed-version: only affects 6.16 onwards" + +CVE_STATUS[CVE-2026-64229] = "fixed-version: only affects 6.15 onwards" + +CVE_STATUS[CVE-2026-64230] = "fixed-version: only affects 6.14 onwards" + +CVE_STATUS[CVE-2026-64231] = "cpe-stable-backport: Backported in 6.6.142" + +CVE_STATUS[CVE-2026-64232] = "fixed-version: only affects 6.12 onwards" + +CVE_STATUS[CVE-2026-64233] = "cpe-stable-backport: Backported in 6.6.143" + +CVE_STATUS[CVE-2026-64234] = "cpe-stable-backport: Backported in 6.6.143" + +CVE_STATUS[CVE-2026-64235] = "fixed-version: only affects 6.9 onwards" + +CVE_STATUS[CVE-2026-64236] = "fixed-version: only affects 6.14 onwards" + +CVE_STATUS[CVE-2026-64237] = "cpe-stable-backport: Backported in 6.6.143" + +CVE_STATUS[CVE-2026-64238] = "fixed-version: only affects 6.19.12 onwards" + +CVE_STATUS[CVE-2026-64239] = "cpe-stable-backport: Backported in 6.6.143" + +CVE_STATUS[CVE-2026-64240] = "cpe-stable-backport: Backported in 6.6.143" + +# CVE-2026-64241 needs backporting (fixed from 7.1) + +CVE_STATUS[CVE-2026-64242] = "cpe-stable-backport: Backported in 6.6.143" + +CVE_STATUS[CVE-2026-64243] = "cpe-stable-backport: Backported in 6.6.143" + +CVE_STATUS[CVE-2026-64244] = "cpe-stable-backport: Backported in 6.6.144" + +CVE_STATUS[CVE-2026-64245] = "cpe-stable-backport: Backported in 6.6.144" + +CVE_STATUS[CVE-2026-64246] = "cpe-stable-backport: Backported in 6.6.144" + +CVE_STATUS[CVE-2026-64247] = "cpe-stable-backport: Backported in 6.6.144" + +CVE_STATUS[CVE-2026-64248] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-64249] = "cpe-stable-backport: Backported in 6.6.144" + +CVE_STATUS[CVE-2026-64250] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-64251] = "fixed-version: only affects 6.11 onwards" + +CVE_STATUS[CVE-2026-64252] = "cpe-stable-backport: Backported in 6.6.144" + +CVE_STATUS[CVE-2026-64253] = "fixed-version: only affects 6.9 onwards" + +CVE_STATUS[CVE-2026-64254] = "cpe-stable-backport: Backported in 6.6.144" + +# CVE-2026-64255 needs backporting (fixed from 7.2) + +CVE_STATUS[CVE-2026-64256] = "fixed-version: only affects 6.8 onwards" + +CVE_STATUS[CVE-2026-64257] = "fixed-version: Fixed from version 5.16" + +CVE_STATUS[CVE-2026-64258] = "fixed-version: only affects 6.16 onwards" + +CVE_STATUS[CVE-2026-64259] = "fixed-version: only affects 6.14 onwards" + +CVE_STATUS[CVE-2026-64260] = "fixed-version: only affects 6.14 onwards" + +CVE_STATUS[CVE-2026-64261] = "fixed-version: only affects 6.14 onwards" + +CVE_STATUS[CVE-2026-64262] = "fixed-version: only affects 6.14 onwards" + +CVE_STATUS[CVE-2026-64263] = "fixed-version: only affects 6.16 onwards" + +CVE_STATUS[CVE-2026-64264] = "fixed-version: only affects 6.14 onwards" + +CVE_STATUS[CVE-2026-64265] = "fixed-version: only affects 6.9 onwards" + +CVE_STATUS[CVE-2026-64266] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-64267] = "fixed-version: only affects 6.18 onwards" + +CVE_STATUS[CVE-2026-64268] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-64269] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-64270] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-64271] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-64272] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-64273] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-64274] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-64275] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-64276] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-64277] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-64278] = "fixed-version: only affects 6.14 onwards" + +CVE_STATUS[CVE-2026-64279] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-64280] = "cpe-stable-backport: Backported in 6.6.148" + +CVE_STATUS[CVE-2026-64281] = "fixed-version: only affects 7.1 onwards" + +CVE_STATUS[CVE-2026-64282] = "fixed-version: only affects 6.16 onwards" + +CVE_STATUS[CVE-2026-64283] = "fixed-version: only affects 6.8 onwards" + +CVE_STATUS[CVE-2026-64284] = "fixed-version: only affects 6.12 onwards" + +CVE_STATUS[CVE-2026-64285] = "fixed-version: only affects 7.0 onwards" + +CVE_STATUS[CVE-2026-64286] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-64287] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-64288] = "fixed-version: only affects 6.16 onwards" + +CVE_STATUS[CVE-2026-64289] = "fixed-version: only affects 6.8 onwards" + +CVE_STATUS[CVE-2026-64290] = "fixed-version: only affects 6.11 onwards" + +CVE_STATUS[CVE-2026-64291] = "fixed-version: only affects 6.15 onwards" + +CVE_STATUS[CVE-2026-64292] = "fixed-version: only affects 6.15 onwards" + +CVE_STATUS[CVE-2026-64293] = "fixed-version: only affects 6.15 onwards" + +CVE_STATUS[CVE-2026-64294] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-64295] = "fixed-version: only affects 6.15 onwards" + +CVE_STATUS[CVE-2026-64296] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-64297] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-64298] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-64299] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-64300] = "fixed-version: only affects 6.14 onwards" + +CVE_STATUS[CVE-2026-64301] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-64302] = "fixed-version: only affects 6.18.7 onwards" + +CVE_STATUS[CVE-2026-64303] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-64304] = "cpe-stable-backport: Backported in 6.6.145" + +# CVE-2026-64305 needs backporting (fixed from 7.2) + +CVE_STATUS[CVE-2026-64306] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-64307] = "fixed-version: only affects 6.12.75 onwards" + +CVE_STATUS[CVE-2026-64308] = "fixed-version: only affects 6.12.75 onwards" + +CVE_STATUS[CVE-2026-64309] = "fixed-version: only affects 6.12.75 onwards" + +CVE_STATUS[CVE-2026-64310] = "fixed-version: only affects 6.12.75 onwards" + +CVE_STATUS[CVE-2026-64311] = "fixed-version: only affects 6.18 onwards" + +CVE_STATUS[CVE-2026-64312] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-64313] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-64314] = "fixed-version: only affects 6.16 onwards" + +CVE_STATUS[CVE-2026-64315] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-64316] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-64317] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-64318] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-64319] = "cpe-stable-backport: Backported in 6.6.145" + +# CVE-2026-64320 needs backporting (fixed from 7.2) + +CVE_STATUS[CVE-2026-64321] = "fixed-version: only affects 6.8 onwards" + +CVE_STATUS[CVE-2026-64322] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-64323] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-64324] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-64325] = "fixed-version: only affects 6.14 onwards" + +CVE_STATUS[CVE-2026-64326] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-64327] = "fixed-version: only affects 6.9 onwards" + +CVE_STATUS[CVE-2026-64328] = "fixed-version: only affects 6.9 onwards" + +CVE_STATUS[CVE-2026-64329] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-64330] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-64331] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-64332] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-64333] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-64334] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-64335] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-64336] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-64337] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-64338] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-64339] = "fixed-version: only affects 6.18 onwards" + +CVE_STATUS[CVE-2026-64340] = "cpe-stable-backport: Backported in 6.6.145" + +# CVE-2026-64341 needs backporting (fixed from 7.2) + +CVE_STATUS[CVE-2026-64342] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-64343] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-64344] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-64345] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-64346] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-64347] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-64348] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-64349] = "fixed-version: only affects 6.18.32 onwards" + +CVE_STATUS[CVE-2026-64350] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-64351] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-64352] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-64353] = "fixed-version: only affects 6.14 onwards" + +CVE_STATUS[CVE-2026-64354] = "fixed-version: only affects 6.11.6 onwards" + +CVE_STATUS[CVE-2026-64355] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-64356] = "fixed-version: only affects 6.13 onwards" + +CVE_STATUS[CVE-2026-64357] = "fixed-version: only affects 6.10 onwards" + +CVE_STATUS[CVE-2026-64358] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-64359] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-64360] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-64361] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-64362] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-64363] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-64364] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-64365] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-64366] = "fixed-version: only affects 6.15 onwards" + +CVE_STATUS[CVE-2026-64367] = "fixed-version: only affects 6.12 onwards" + +CVE_STATUS[CVE-2026-64368] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-64369] = "fixed-version: only affects 6.7 onwards" + +CVE_STATUS[CVE-2026-64370] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-64371] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-64372] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-64373] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-64374] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-64375] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-64376] = "cpe-stable-backport: Backported in 6.6.145" + +# CVE-2026-64377 needs backporting (fixed from 7.2) + +CVE_STATUS[CVE-2026-64378] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-64379] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-64380] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-64381] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-64382] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-64383] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-64384] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-64385] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-64386] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-64387] = "cpe-stable-backport: Backported in 6.6.145" + +# CVE-2026-64388 needs backporting (fixed from 7.2) + +# CVE-2026-64389 needs backporting (fixed from 7.2) + +CVE_STATUS[CVE-2026-64390] = "cpe-stable-backport: Backported in 6.6.145" + +# CVE-2026-64391 needs backporting (fixed from 7.2) + +CVE_STATUS[CVE-2026-64392] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-64393] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-64394] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-64395] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-64396] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-64397] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-64398] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-64399] = "cpe-stable-backport: Backported in 6.6.145" + +# CVE-2026-64400 needs backporting (fixed from 7.2) + +CVE_STATUS[CVE-2026-64401] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-64402] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-64403] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-64404] = "fixed-version: only affects 6.12.6 onwards" + +CVE_STATUS[CVE-2026-64405] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-64406] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-64407] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-64408] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-64409] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-64410] = "fixed-version: only affects 6.19 onwards" + +CVE_STATUS[CVE-2026-64411] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-64412] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-64413] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-64414] = "fixed-version: only affects 6.12 onwards" + +CVE_STATUS[CVE-2026-64415] = "fixed-version: only affects 6.12 onwards" + +CVE_STATUS[CVE-2026-64416] = "fixed-version: only affects 6.12 onwards" + +CVE_STATUS[CVE-2026-64417] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-64418] = "fixed-version: only affects 6.7 onwards" + +CVE_STATUS[CVE-2026-64419] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-64420] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-64421] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-64422] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-64423] = "cpe-stable-backport: Backported in 6.6.145" + +# CVE-2026-64424 needs backporting (fixed from 7.2) + +CVE_STATUS[CVE-2026-64425] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-64426] = "fixed-version: only affects 6.13 onwards" + +CVE_STATUS[CVE-2026-64427] = "fixed-version: only affects 7.1 onwards" + +CVE_STATUS[CVE-2026-64428] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-64429] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-64430] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-64431] = "fixed-version: only affects 7.1 onwards" + +CVE_STATUS[CVE-2026-64432] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-64433] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-64434] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-64435] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-64436] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-64437] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-64438] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-64439] = "fixed-version: only affects 6.15 onwards" + +CVE_STATUS[CVE-2026-64440] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-64441] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-64442] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-64443] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-64444] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-64445] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-64446] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-64447] = "fixed-version: only affects 6.17 onwards" + +CVE_STATUS[CVE-2026-64448] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-64449] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-64450] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-64451] = "fixed-version: only affects 6.19 onwards" + +CVE_STATUS[CVE-2026-64452] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-64453] = "fixed-version: only affects 6.18 onwards" + +CVE_STATUS[CVE-2026-64454] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-64455] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-64456] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-64457] = "fixed-version: only affects 6.11 onwards" + +CVE_STATUS[CVE-2026-64458] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-64459] = "fixed-version: only affects 6.18 onwards" + +CVE_STATUS[CVE-2026-64460] = "fixed-version: only affects 6.17 onwards" + +CVE_STATUS[CVE-2026-64461] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-64462] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-64463] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-64464] = "fixed-version: only affects 6.16 onwards" + +CVE_STATUS[CVE-2026-64465] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-64466] = "fixed-version: only affects 6.18 onwards" + +CVE_STATUS[CVE-2026-64467] = "fixed-version: only affects 6.18 onwards" + +CVE_STATUS[CVE-2026-64468] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-64469] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-64470] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-64471] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-64472] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-64473] = "fixed-version: only affects 6.8 onwards" + +CVE_STATUS[CVE-2026-64474] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-64475] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-64476] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-64477] = "fixed-version: only affects 6.11 onwards" + +CVE_STATUS[CVE-2026-64478] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-64479] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-64480] = "cpe-stable-backport: Backported in 6.6.145" + +# CVE-2026-64481 needs backporting (fixed from 7.2) + +CVE_STATUS[CVE-2026-64482] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-64483] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-64484] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-64485] = "fixed-version: only affects 6.13 onwards" + +CVE_STATUS[CVE-2026-64486] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-64487] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-64488] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-64489] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-64490] = "fixed-version: only affects 6.9 onwards" + +CVE_STATUS[CVE-2026-64491] = "fixed-version: only affects 6.18 onwards" + +CVE_STATUS[CVE-2026-64492] = "fixed-version: only affects 6.13 onwards" + +CVE_STATUS[CVE-2026-64493] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-64494] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-64495] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-64496] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-64497] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-64498] = "fixed-version: only affects 7.1 onwards" + +CVE_STATUS[CVE-2026-64499] = "fixed-version: only affects 6.11 onwards" + +CVE_STATUS[CVE-2026-64500] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-64501] = "fixed-version: only affects 6.14 onwards" + +CVE_STATUS[CVE-2026-64502] = "fixed-version: only affects 6.14 onwards" + +CVE_STATUS[CVE-2026-64503] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-64504] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-64505] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-64506] = "fixed-version: only affects 7.1 onwards" + +CVE_STATUS[CVE-2026-64507] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-64508] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-64509] = "fixed-version: only affects 6.11 onwards" + +CVE_STATUS[CVE-2026-64510] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-64511] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-64512] = "cpe-stable-backport: Backported in 6.6.145" + +# CVE-2026-64513 needs backporting (fixed from 7.2) + +CVE_STATUS[CVE-2026-64514] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-64515] = "fixed-version: only affects 6.9 onwards" + +CVE_STATUS[CVE-2026-64516] = "fixed-version: only affects 6.19 onwards" + +CVE_STATUS[CVE-2026-64517] = "fixed-version: only affects 6.12 onwards" + +CVE_STATUS[CVE-2026-64518] = "fixed-version: only affects 6.12.5 onwards" + +CVE_STATUS[CVE-2026-64519] = "fixed-version: only affects 6.9 onwards" + +CVE_STATUS[CVE-2026-64520] = "fixed-version: only affects 6.12 onwards" + +CVE_STATUS[CVE-2026-64521] = "fixed-version: only affects 6.15 onwards" + +CVE_STATUS[CVE-2026-64522] = "fixed-version: only affects 6.17.4 onwards" + +# CVE-2026-64523 needs backporting (fixed from 7.1) + +CVE_STATUS[CVE-2026-64524] = "cpe-stable-backport: Backported in 6.6.143" + +CVE_STATUS[CVE-2026-64525] = "fixed-version: only affects 6.12.83 onwards" + +CVE_STATUS[CVE-2026-64526] = "fixed-version: only affects 6.14 onwards" + +CVE_STATUS[CVE-2026-64527] = "cpe-stable-backport: Backported in 6.6.143" + +CVE_STATUS[CVE-2026-64528] = "cpe-stable-backport: Backported in 6.6.143" + +CVE_STATUS[CVE-2026-64529] = "cpe-stable-backport: Backported in 6.6.144" + +CVE_STATUS[CVE-2026-64530] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-64531] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-64532] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-64533] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-64534] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-64535] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-64536] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-64537] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-64538] = "cpe-stable-backport: Backported in 6.6.145" + +# CVE-2026-64539 needs backporting (fixed from 7.2) + +CVE_STATUS[CVE-2026-64540] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-64541] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-64542] = "cpe-stable-backport: Backported in 6.6.148" + +CVE_STATUS[CVE-2026-64543] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-64544] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-64545] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-64546] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-64547] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-64548] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-64549] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-64550] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-64551] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-64552] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-64553] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-64554] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-64555] = "fixed-version: only affects 6.7 onwards" + +CVE_STATUS[CVE-2026-64556] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-64557] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-64558] = "fixed-version: only affects 6.12 onwards" + +CVE_STATUS[CVE-2026-64559] = "fixed-version: only affects 6.12 onwards" + +CVE_STATUS[CVE-2026-64560] = "cpe-stable-backport: Backported in 6.6.147" + +CVE_STATUS[CVE-2026-64561] = "cpe-stable-backport: Backported in 6.6.148" + +CVE_STATUS[CVE-2026-64562] = "cpe-stable-backport: Backported in 6.6.148" + +CVE_STATUS[CVE-2026-64563] = "cpe-stable-backport: Backported in 6.6.151" + +CVE_STATUS[CVE-2026-64564] = "cpe-stable-backport: Backported in 6.6.148" + +CVE_STATUS[CVE-2026-64565] = "cpe-stable-backport: Backported in 6.6.148" + +CVE_STATUS[CVE-2026-64566] = "fixed-version: only affects 6.14 onwards" + +CVE_STATUS[CVE-2026-64567] = "cpe-stable-backport: Backported in 6.6.148" + +CVE_STATUS[CVE-2026-64568] = "fixed-version: only affects 6.7 onwards" + +CVE_STATUS[CVE-2026-64569] = "cpe-stable-backport: Backported in 6.6.148" + +CVE_STATUS[CVE-2026-64570] = "fixed-version: only affects 6.7 onwards" + +CVE_STATUS[CVE-2026-64571] = "cpe-stable-backport: Backported in 6.6.148" + +CVE_STATUS[CVE-2026-64572] = "cpe-stable-backport: Backported in 6.6.148" + +CVE_STATUS[CVE-2026-64573] = "cpe-stable-backport: Backported in 6.6.148" + +CVE_STATUS[CVE-2026-64574] = "cpe-stable-backport: Backported in 6.6.148" + +CVE_STATUS[CVE-2026-64575] = "fixed-version: only affects 6.17 onwards" + +CVE_STATUS[CVE-2026-64576] = "cpe-stable-backport: Backported in 6.6.148" + +CVE_STATUS[CVE-2026-64577] = "cpe-stable-backport: Backported in 6.6.148" + +CVE_STATUS[CVE-2026-64578] = "cpe-stable-backport: Backported in 6.6.148" + +CVE_STATUS[CVE-2026-64579] = "cpe-stable-backport: Backported in 6.6.148" + +CVE_STATUS[CVE-2026-64580] = "cpe-stable-backport: Backported in 6.6.148" + +# CVE-2026-64581 may need backporting (fixed from 6.6.154) + +CVE_STATUS[CVE-2026-64582] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-64583] = "cpe-stable-backport: Backported in 6.6.148" + +CVE_STATUS[CVE-2026-64584] = "cpe-stable-backport: Backported in 6.6.148" + +CVE_STATUS[CVE-2026-64585] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-64586] = "cpe-stable-backport: Backported in 6.6.151" + +CVE_STATUS[CVE-2026-64587] = "cpe-stable-backport: Backported in 6.6.130" + +CVE_STATUS[CVE-2026-64588] = "fixed-version: only affects 6.14 onwards" + +CVE_STATUS[CVE-2026-64589] = "fixed-version: only affects 6.12.11 onwards" + +CVE_STATUS[CVE-2026-64590] = "cpe-stable-backport: Backported in 6.6.148" + +CVE_STATUS[CVE-2026-64591] = "fixed-version: only affects 6.18.20 onwards" + +CVE_STATUS[CVE-2026-64592] = "fixed-version: only affects 6.12 onwards" + +CVE_STATUS[CVE-2026-64593] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-64594] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-64595] = "fixed-version: only affects 7.1 onwards" + +CVE_STATUS[CVE-2026-64596] = "fixed-version: only affects 6.15.6 onwards" + +CVE_STATUS[CVE-2026-64597] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-64598] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-64599] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-64600] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-64601] = "fixed-version: only affects 6.18 onwards" + +CVE_STATUS[CVE-2026-64602] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-64603] = "fixed-version: only affects 6.8 onwards" + +CVE_STATUS[CVE-2026-64604] = "cpe-stable-backport: Backported in 6.6.145" + +# CVE-2026-68081 needs backporting (fixed from 7.2) + +# CVE-2026-68082 may need backporting (fixed from 6.6.153) + +# CVE-2026-68083 needs backporting (fixed from 7.2) + +CVE_STATUS[CVE-2026-68084] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-68085] = "fixed-version: only affects 6.12.92 onwards" + +# CVE-2026-68086 has no known resolution + +CVE_STATUS[CVE-2026-68087] = "fixed-version: only affects 6.15 onwards" + +CVE_STATUS[CVE-2026-68088] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-68089] = "fixed-version: only affects 6.15 onwards" + +CVE_STATUS[CVE-2026-68090] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-68091] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-68092] = "fixed-version: only affects 6.12.5 onwards" + +CVE_STATUS[CVE-2026-68093] = "cpe-stable-backport: Backported in 6.6.148" + +CVE_STATUS[CVE-2026-68094] = "fixed-version: only affects 7.1 onwards" + +CVE_STATUS[CVE-2026-68095] = "fixed-version: only affects 6.14 onwards" + +CVE_STATUS[CVE-2026-68096] = "cpe-stable-backport: Backported in 6.6.148" + +CVE_STATUS[CVE-2026-68097] = "cpe-stable-backport: Backported in 6.6.148" + +CVE_STATUS[CVE-2026-68098] = "cpe-stable-backport: Backported in 6.6.148" + +CVE_STATUS[CVE-2026-68099] = "cpe-stable-backport: Backported in 6.6.148" + +CVE_STATUS[CVE-2026-68100] = "cpe-stable-backport: Backported in 6.6.148" + +CVE_STATUS[CVE-2026-68102] = "cpe-stable-backport: Backported in 6.6.148" + +CVE_STATUS[CVE-2026-68103] = "fixed-version: only affects 6.16 onwards" + +CVE_STATUS[CVE-2026-68104] = "cpe-stable-backport: Backported in 6.6.148" + +CVE_STATUS[CVE-2026-68105] = "fixed-version: only affects 6.11 onwards" + +CVE_STATUS[CVE-2026-68106] = "cpe-stable-backport: Backported in 6.6.148" + +CVE_STATUS[CVE-2026-68107] = "cpe-stable-backport: Backported in 6.6.148" + +CVE_STATUS[CVE-2026-68108] = "cpe-stable-backport: Backported in 6.6.148" + +CVE_STATUS[CVE-2026-68109] = "fixed-version: only affects 7.0 onwards" + +CVE_STATUS[CVE-2026-68110] = "cpe-stable-backport: Backported in 6.6.148" + +CVE_STATUS[CVE-2026-68111] = "cpe-stable-backport: Backported in 6.6.148" + +CVE_STATUS[CVE-2026-68112] = "cpe-stable-backport: Backported in 6.6.148" + +CVE_STATUS[CVE-2026-68113] = "fixed-version: only affects 6.11 onwards" + +CVE_STATUS[CVE-2026-68114] = "fixed-version: only affects 7.0 onwards" + +CVE_STATUS[CVE-2026-68115] = "cpe-stable-backport: Backported in 6.6.148" + +CVE_STATUS[CVE-2026-68116] = "cpe-stable-backport: Backported in 6.6.148" + +CVE_STATUS[CVE-2026-68117] = "cpe-stable-backport: Backported in 6.6.148" + +# CVE-2026-68118 may need backporting (fixed from 6.6.153) + +CVE_STATUS[CVE-2026-68119] = "fixed-version: only affects 6.7 onwards" + +CVE_STATUS[CVE-2026-68120] = "fixed-version: only affects 6.12 onwards" + +CVE_STATUS[CVE-2026-68121] = "cpe-stable-backport: Backported in 6.6.148" + +CVE_STATUS[CVE-2026-68122] = "fixed-version: only affects 6.16 onwards" + +CVE_STATUS[CVE-2026-68123] = "cpe-stable-backport: Backported in 6.6.148" + +CVE_STATUS[CVE-2026-68124] = "cpe-stable-backport: Backported in 6.6.148" + +CVE_STATUS[CVE-2026-68125] = "cpe-stable-backport: Backported in 6.6.148" + +CVE_STATUS[CVE-2026-68126] = "cpe-stable-backport: Backported in 6.6.148" + +CVE_STATUS[CVE-2026-68127] = "cpe-stable-backport: Backported in 6.6.148" + +CVE_STATUS[CVE-2026-68128] = "fixed-version: only affects 6.12 onwards" + +CVE_STATUS[CVE-2026-68129] = "cpe-stable-backport: Backported in 6.6.151" + +CVE_STATUS[CVE-2026-68130] = "cpe-stable-backport: Backported in 6.6.148" + +CVE_STATUS[CVE-2026-68131] = "cpe-stable-backport: Backported in 6.6.148" + +# CVE-2026-68132 may need backporting (fixed from 6.6.153) + +CVE_STATUS[CVE-2026-68133] = "fixed-version: only affects 6.9 onwards" + +CVE_STATUS[CVE-2026-68134] = "fixed-version: only affects 6.13 onwards" + +CVE_STATUS[CVE-2026-68135] = "cpe-stable-backport: Backported in 6.6.148" + +# CVE-2026-68136 may need backporting (fixed from 6.6.153) + +CVE_STATUS[CVE-2026-68137] = "cpe-stable-backport: Backported in 6.6.148" + +# CVE-2026-68138 may need backporting (fixed from 6.6.153) + +CVE_STATUS[CVE-2026-68139] = "fixed-version: only affects 6.7 onwards" + +CVE_STATUS[CVE-2026-68140] = "cpe-stable-backport: Backported in 6.6.148" + +CVE_STATUS[CVE-2026-68141] = "cpe-stable-backport: Backported in 6.6.148" + +CVE_STATUS[CVE-2026-68142] = "cpe-stable-backport: Backported in 6.6.148" + +CVE_STATUS[CVE-2026-68143] = "cpe-stable-backport: Backported in 6.6.148" + +CVE_STATUS[CVE-2026-68144] = "cpe-stable-backport: Backported in 6.6.148" + +# CVE-2026-68145 may need backporting (fixed from 6.6.153) + +CVE_STATUS[CVE-2026-68146] = "cpe-stable-backport: Backported in 6.6.148" + +CVE_STATUS[CVE-2026-68147] = "cpe-stable-backport: Backported in 6.6.148" + +CVE_STATUS[CVE-2026-68148] = "cpe-stable-backport: Backported in 6.6.148" + +CVE_STATUS[CVE-2026-68149] = "cpe-stable-backport: Backported in 6.6.148" + +CVE_STATUS[CVE-2026-68150] = "fixed-version: only affects 6.16 onwards" + +CVE_STATUS[CVE-2026-68151] = "cpe-stable-backport: Backported in 6.6.148" + +# CVE-2026-68152 needs backporting (fixed from 7.2) + +CVE_STATUS[CVE-2026-68153] = "cpe-stable-backport: Backported in 6.6.148" + +CVE_STATUS[CVE-2026-68154] = "cpe-stable-backport: Backported in 6.6.148" + +CVE_STATUS[CVE-2026-68155] = "cpe-stable-backport: Backported in 6.6.148" + +CVE_STATUS[CVE-2026-68156] = "cpe-stable-backport: Backported in 6.6.148" + +CVE_STATUS[CVE-2026-68157] = "cpe-stable-backport: Backported in 6.6.148" + +CVE_STATUS[CVE-2026-68158] = "cpe-stable-backport: Backported in 6.6.148" + +# CVE-2026-68159 may need backporting (fixed from 6.6.153) + +CVE_STATUS[CVE-2026-68160] = "cpe-stable-backport: Backported in 6.6.148" + +CVE_STATUS[CVE-2026-68161] = "cpe-stable-backport: Backported in 6.6.151" + +CVE_STATUS[CVE-2026-68162] = "cpe-stable-backport: Backported in 6.6.151" + +CVE_STATUS[CVE-2026-68163] = "fixed-version: only affects 6.19 onwards" + +CVE_STATUS[CVE-2026-68164] = "cpe-stable-backport: Backported in 6.6.148" + +CVE_STATUS[CVE-2026-68165] = "cpe-stable-backport: Backported in 6.6.148" + +# CVE-2026-68166 may need backporting (fixed from 6.6.153) + +CVE_STATUS[CVE-2026-68167] = "fixed-version: only affects 7.1 onwards" + +CVE_STATUS[CVE-2026-68168] = "fixed-version: only affects 6.14 onwards" + +CVE_STATUS[CVE-2026-68169] = "cpe-stable-backport: Backported in 6.6.151" + +CVE_STATUS[CVE-2026-68170] = "fixed-version: only affects 6.19 onwards" + +CVE_STATUS[CVE-2026-68172] = "fixed-version: only affects 6.16 onwards" + +CVE_STATUS[CVE-2026-68173] = "fixed-version: only affects 6.14.6 onwards" + +CVE_STATUS[CVE-2026-68174] = "fixed-version: only affects 6.14 onwards" + +CVE_STATUS[CVE-2026-68175] = "cpe-stable-backport: Backported in 6.6.148" + +CVE_STATUS[CVE-2026-68176] = "cpe-stable-backport: Backported in 6.6.148" + +CVE_STATUS[CVE-2026-68177] = "fixed-version: only affects 6.19 onwards" + +CVE_STATUS[CVE-2026-68178] = "fixed-version: only affects 6.8 onwards" + +CVE_STATUS[CVE-2026-68179] = "fixed-version: only affects 6.8 onwards" + +CVE_STATUS[CVE-2026-68180] = "cpe-stable-backport: Backported in 6.6.148" + +CVE_STATUS[CVE-2026-68181] = "cpe-stable-backport: Backported in 6.6.148" + +CVE_STATUS[CVE-2026-68182] = "cpe-stable-backport: Backported in 6.6.148" + +CVE_STATUS[CVE-2026-68183] = "cpe-stable-backport: Backported in 6.6.151" + +CVE_STATUS[CVE-2026-68184] = "cpe-stable-backport: Backported in 6.6.148" + +# CVE-2026-68185 needs backporting (fixed from 7.2) + +CVE_STATUS[CVE-2026-68186] = "cpe-stable-backport: Backported in 6.6.148" + +CVE_STATUS[CVE-2026-68187] = "cpe-stable-backport: Backported in 6.6.148" + +CVE_STATUS[CVE-2026-68188] = "cpe-stable-backport: Backported in 6.6.148" + +CVE_STATUS[CVE-2026-68189] = "cpe-stable-backport: Backported in 6.6.148" + +CVE_STATUS[CVE-2026-68190] = "cpe-stable-backport: Backported in 6.6.148" + +CVE_STATUS[CVE-2026-68191] = "fixed-version: only affects 7.0 onwards" + +CVE_STATUS[CVE-2026-68192] = "cpe-stable-backport: Backported in 6.6.148" + +CVE_STATUS[CVE-2026-68193] = "fixed-version: only affects 6.7 onwards" + +CVE_STATUS[CVE-2026-68194] = "cpe-stable-backport: Backported in 6.6.148" + +CVE_STATUS[CVE-2026-68195] = "cpe-stable-backport: Backported in 6.6.148" + +CVE_STATUS[CVE-2026-68196] = "cpe-stable-backport: Backported in 6.6.148" + +CVE_STATUS[CVE-2026-68197] = "cpe-stable-backport: Backported in 6.6.148" + +CVE_STATUS[CVE-2026-68198] = "cpe-stable-backport: Backported in 6.6.151" + +CVE_STATUS[CVE-2026-68199] = "cpe-stable-backport: Backported in 6.6.148" + +CVE_STATUS[CVE-2026-68200] = "fixed-version: only affects 6.12 onwards" + +CVE_STATUS[CVE-2026-68201] = "fixed-version: only affects 6.12 onwards" + +CVE_STATUS[CVE-2026-68202] = "cpe-stable-backport: Backported in 6.6.148" + +# CVE-2026-68203 needs backporting (fixed from 7.2) + +CVE_STATUS[CVE-2026-68204] = "cpe-stable-backport: Backported in 6.6.148" + +CVE_STATUS[CVE-2026-68205] = "cpe-stable-backport: Backported in 6.6.151" + +CVE_STATUS[CVE-2026-68206] = "cpe-stable-backport: Backported in 6.6.148" + +CVE_STATUS[CVE-2026-68207] = "cpe-stable-backport: Backported in 6.6.148" + +CVE_STATUS[CVE-2026-68208] = "fixed-version: only affects 7.0 onwards" + +CVE_STATUS[CVE-2026-68209] = "cpe-stable-backport: Backported in 6.6.148" + +CVE_STATUS[CVE-2026-68210] = "cpe-stable-backport: Backported in 6.6.148" + +CVE_STATUS[CVE-2026-68211] = "fixed-version: only affects 6.8 onwards" + +CVE_STATUS[CVE-2026-68212] = "cpe-stable-backport: Backported in 6.6.148" + +CVE_STATUS[CVE-2026-68213] = "cpe-stable-backport: Backported in 6.6.148" + +CVE_STATUS[CVE-2026-68214] = "cpe-stable-backport: Backported in 6.6.148" + +CVE_STATUS[CVE-2026-68215] = "cpe-stable-backport: Backported in 6.6.148" + +CVE_STATUS[CVE-2026-68216] = "cpe-stable-backport: Backported in 6.6.148" + +CVE_STATUS[CVE-2026-68217] = "cpe-stable-backport: Backported in 6.6.148" + +CVE_STATUS[CVE-2026-68218] = "cpe-stable-backport: Backported in 6.6.148" + +CVE_STATUS[CVE-2026-68219] = "cpe-stable-backport: Backported in 6.6.148" + +CVE_STATUS[CVE-2026-68220] = "cpe-stable-backport: Backported in 6.6.148" + +CVE_STATUS[CVE-2026-68221] = "fixed-version: only affects 6.7 onwards" + +CVE_STATUS[CVE-2026-68222] = "cpe-stable-backport: Backported in 6.6.148" + +CVE_STATUS[CVE-2026-68223] = "cpe-stable-backport: Backported in 6.6.148" + +CVE_STATUS[CVE-2026-68224] = "fixed-version: only affects 6.19 onwards" + +CVE_STATUS[CVE-2026-68225] = "fixed-version: only affects 6.8 onwards" + +CVE_STATUS[CVE-2026-68226] = "cpe-stable-backport: Backported in 6.6.148" + +CVE_STATUS[CVE-2026-68227] = "cpe-stable-backport: Backported in 6.6.148" + +CVE_STATUS[CVE-2026-68228] = "fixed-version: only affects 6.8 onwards" + +CVE_STATUS[CVE-2026-68229] = "cpe-stable-backport: Backported in 6.6.148" + +CVE_STATUS[CVE-2026-68230] = "fixed-version: only affects 6.16 onwards" + +CVE_STATUS[CVE-2026-68231] = "cpe-stable-backport: Backported in 6.6.148" + +CVE_STATUS[CVE-2026-68232] = "fixed-version: only affects 6.15 onwards" + +# CVE-2026-68233 needs backporting (fixed from 7.2) + +CVE_STATUS[CVE-2026-68234] = "cpe-stable-backport: Backported in 6.6.148" + +CVE_STATUS[CVE-2026-68235] = "fixed-version: only affects 6.19 onwards" + +CVE_STATUS[CVE-2026-68236] = "cpe-stable-backport: Backported in 6.6.148" + +CVE_STATUS[CVE-2026-68237] = "fixed-version: only affects 6.19 onwards" + +# CVE-2026-68238 needs backporting (fixed from 7.2) + +CVE_STATUS[CVE-2026-68239] = "fixed-version: only affects 6.15 onwards" + +CVE_STATUS[CVE-2026-68240] = "fixed-version: only affects 6.18 onwards" + +# CVE-2026-68241 needs backporting (fixed from 7.2) + +# CVE-2026-68242 needs backporting (fixed from 7.2) + +CVE_STATUS[CVE-2026-68243] = "cpe-stable-backport: Backported in 6.6.148" + +CVE_STATUS[CVE-2026-68244] = "cpe-stable-backport: Backported in 6.6.148" + +CVE_STATUS[CVE-2026-68245] = "fixed-version: only affects 6.9 onwards" + +CVE_STATUS[CVE-2026-68246] = "cpe-stable-backport: Backported in 6.6.148" + +# CVE-2026-68247 needs backporting (fixed from 7.2) + +CVE_STATUS[CVE-2026-68248] = "cpe-stable-backport: Backported in 6.6.148" + +CVE_STATUS[CVE-2026-68249] = "cpe-stable-backport: Backported in 6.6.148" + +CVE_STATUS[CVE-2026-68250] = "cpe-stable-backport: Backported in 6.6.148" + +CVE_STATUS[CVE-2026-68251] = "cpe-stable-backport: Backported in 6.6.148" + +CVE_STATUS[CVE-2026-68252] = "fixed-version: only affects 6.11 onwards" + +CVE_STATUS[CVE-2026-68253] = "cpe-stable-backport: Backported in 6.6.151" + +CVE_STATUS[CVE-2026-68254] = "cpe-stable-backport: Backported in 6.6.151" + +CVE_STATUS[CVE-2026-68255] = "cpe-stable-backport: Backported in 6.6.148" + +CVE_STATUS[CVE-2026-68256] = "cpe-stable-backport: Backported in 6.6.148" + +CVE_STATUS[CVE-2026-68257] = "fixed-version: only affects 6.12.59 onwards" + +# CVE-2026-68258 needs backporting (fixed from 7.2) + +CVE_STATUS[CVE-2026-68259] = "cpe-stable-backport: Backported in 6.6.148" + +CVE_STATUS[CVE-2026-68260] = "fixed-version: only affects 6.8 onwards" + +CVE_STATUS[CVE-2026-68261] = "fixed-version: only affects 6.8 onwards" + +CVE_STATUS[CVE-2026-68262] = "fixed-version: only affects 6.8 onwards" + +CVE_STATUS[CVE-2026-68263] = "fixed-version: only affects 6.8 onwards" + +CVE_STATUS[CVE-2026-68264] = "fixed-version: only affects 6.12 onwards" + +CVE_STATUS[CVE-2026-68265] = "fixed-version: only affects 6.18 onwards" + +CVE_STATUS[CVE-2026-68266] = "fixed-version: only affects 6.8 onwards" + +CVE_STATUS[CVE-2026-68267] = "fixed-version: only affects 6.11 onwards" + +CVE_STATUS[CVE-2026-68268] = "fixed-version: only affects 6.18 onwards" + +CVE_STATUS[CVE-2026-68269] = "cpe-stable-backport: Backported in 6.6.148" + +CVE_STATUS[CVE-2026-68270] = "fixed-version: only affects 6.16 onwards" + +CVE_STATUS[CVE-2026-68271] = "cpe-stable-backport: Backported in 6.6.148" + +CVE_STATUS[CVE-2026-68272] = "cpe-stable-backport: Backported in 6.6.148" + +# CVE-2026-68273 needs backporting (fixed from 7.2) + +CVE_STATUS[CVE-2026-68274] = "fixed-version: only affects 6.13 onwards" + +CVE_STATUS[CVE-2026-68275] = "fixed-version: only affects 6.18 onwards" + +CVE_STATUS[CVE-2026-68276] = "fixed-version: only affects 6.12 onwards" + +CVE_STATUS[CVE-2026-68277] = "cpe-stable-backport: Backported in 6.6.148" + +CVE_STATUS[CVE-2026-68278] = "cpe-stable-backport: Backported in 6.6.148" + +CVE_STATUS[CVE-2026-68279] = "cpe-stable-backport: Backported in 6.6.148" + +CVE_STATUS[CVE-2026-68280] = "cpe-stable-backport: Backported in 6.6.148" + +CVE_STATUS[CVE-2026-68281] = "fixed-version: only affects 6.8 onwards" + +CVE_STATUS[CVE-2026-68282] = "fixed-version: only affects 6.15 onwards" + +CVE_STATUS[CVE-2026-68283] = "fixed-version: only affects 6.19 onwards" + +CVE_STATUS[CVE-2026-68284] = "cpe-stable-backport: Backported in 6.6.148" + +CVE_STATUS[CVE-2026-68285] = "fixed-version: only affects 7.0 onwards" + +# CVE-2026-68286 needs backporting (fixed from 7.2) + +# CVE-2026-68287 needs backporting (fixed from 7.2) + +# CVE-2026-68288 needs backporting (fixed from 7.2) + +# CVE-2026-68289 needs backporting (fixed from 7.2) + +CVE_STATUS[CVE-2026-68290] = "fixed-version: only affects 6.12.10 onwards" + +CVE_STATUS[CVE-2026-68291] = "fixed-version: only affects 6.7 onwards" + +CVE_STATUS[CVE-2026-68292] = "fixed-version: only affects 6.18 onwards" + +# CVE-2026-68293 needs backporting (fixed from 7.2) + +CVE_STATUS[CVE-2026-68294] = "cpe-stable-backport: Backported in 6.6.148" + +CVE_STATUS[CVE-2026-68295] = "fixed-version: only affects 6.7 onwards" + +CVE_STATUS[CVE-2026-68296] = "fixed-version: only affects 6.12 onwards" + +CVE_STATUS[CVE-2026-68297] = "cpe-stable-backport: Backported in 6.6.148" + +CVE_STATUS[CVE-2026-68298] = "fixed-version: only affects 6.18 onwards" + +CVE_STATUS[CVE-2026-68299] = "cpe-stable-backport: Backported in 6.6.148" + +CVE_STATUS[CVE-2026-68300] = "cpe-stable-backport: Backported in 6.6.148" + +CVE_STATUS[CVE-2026-68301] = "cpe-stable-backport: Backported in 6.6.148" + +CVE_STATUS[CVE-2026-68302] = "cpe-stable-backport: Backported in 6.6.148" + +# CVE-2026-68303 needs backporting (fixed from 7.2) + +CVE_STATUS[CVE-2026-68304] = "cpe-stable-backport: Backported in 6.6.148" + +CVE_STATUS[CVE-2026-68305] = "fixed-version: only affects 6.18 onwards" + +CVE_STATUS[CVE-2026-68306] = "cpe-stable-backport: Backported in 6.6.148" + +CVE_STATUS[CVE-2026-68307] = "fixed-version: only affects 6.11 onwards" + +CVE_STATUS[CVE-2026-68308] = "cpe-stable-backport: Backported in 6.6.148" + +CVE_STATUS[CVE-2026-68309] = "cpe-stable-backport: Backported in 6.6.148" + +CVE_STATUS[CVE-2026-68310] = "cpe-stable-backport: Backported in 6.6.148" + +CVE_STATUS[CVE-2026-68311] = "fixed-version: only affects 6.11 onwards" + +# CVE-2026-68312 needs backporting (fixed from 7.2) + +CVE_STATUS[CVE-2026-68313] = "cpe-stable-backport: Backported in 6.6.148" + +CVE_STATUS[CVE-2026-68314] = "fixed-version: only affects 6.7 onwards" + +CVE_STATUS[CVE-2026-68315] = "cpe-stable-backport: Backported in 6.6.148" + +CVE_STATUS[CVE-2026-68316] = "fixed-version: only affects 6.19 onwards" + +CVE_STATUS[CVE-2026-68317] = "cpe-stable-backport: Backported in 6.6.148" + +# CVE-2026-68318 needs backporting (fixed from 7.2) + +CVE_STATUS[CVE-2026-68319] = "fixed-version: only affects 6.8.7 onwards" + +CVE_STATUS[CVE-2026-68320] = "cpe-stable-backport: Backported in 6.6.148" + +CVE_STATUS[CVE-2026-68321] = "fixed-version: only affects 6.11 onwards" + +CVE_STATUS[CVE-2026-68322] = "cpe-stable-backport: Backported in 6.6.151" + +# CVE-2026-68323 needs backporting (fixed from 7.2) + +CVE_STATUS[CVE-2026-68324] = "cpe-stable-backport: Backported in 6.6.148" + +CVE_STATUS[CVE-2026-68325] = "cpe-stable-backport: Backported in 6.6.148" + +CVE_STATUS[CVE-2026-68326] = "cpe-stable-backport: Backported in 6.6.148" + +CVE_STATUS[CVE-2026-68327] = "cpe-stable-backport: Backported in 6.6.148" + +CVE_STATUS[CVE-2026-68328] = "cpe-stable-backport: Backported in 6.6.148" + +CVE_STATUS[CVE-2026-68329] = "cpe-stable-backport: Backported in 6.6.148" + +CVE_STATUS[CVE-2026-68330] = "fixed-version: only affects 6.16 onwards" + +CVE_STATUS[CVE-2026-68331] = "cpe-stable-backport: Backported in 6.6.148" + +CVE_STATUS[CVE-2026-68332] = "fixed-version: only affects 6.18.6 onwards" + +CVE_STATUS[CVE-2026-68333] = "cpe-stable-backport: Backported in 6.6.148" + +CVE_STATUS[CVE-2026-68334] = "fixed-version: only affects 6.16 onwards" + +CVE_STATUS[CVE-2026-68335] = "cpe-stable-backport: Backported in 6.6.148" + +CVE_STATUS[CVE-2026-68336] = "cpe-stable-backport: Backported in 6.6.148" + +# CVE-2026-68337 needs backporting (fixed from 7.2) + +CVE_STATUS[CVE-2026-68338] = "cpe-stable-backport: Backported in 6.6.148" + +CVE_STATUS[CVE-2026-68339] = "cpe-stable-backport: Backported in 6.6.148" + +CVE_STATUS[CVE-2026-68340] = "cpe-stable-backport: Backported in 6.6.148" + +CVE_STATUS[CVE-2026-68341] = "fixed-version: only affects 6.16 onwards" + +CVE_STATUS[CVE-2026-68342] = "fixed-version: only affects 6.16 onwards" + +CVE_STATUS[CVE-2026-68343] = "cpe-stable-backport: Backported in 6.6.148" + +CVE_STATUS[CVE-2026-68344] = "cpe-stable-backport: Backported in 6.6.148" + +CVE_STATUS[CVE-2026-68345] = "fixed-version: only affects 6.19 onwards" + +CVE_STATUS[CVE-2026-68346] = "fixed-version: only affects 6.7 onwards" + +CVE_STATUS[CVE-2026-68347] = "fixed-version: only affects 7.0 onwards" + +CVE_STATUS[CVE-2026-68348] = "cpe-stable-backport: Backported in 6.6.148" + +CVE_STATUS[CVE-2026-68349] = "cpe-stable-backport: Backported in 6.6.148" + +CVE_STATUS[CVE-2026-68350] = "cpe-stable-backport: Backported in 6.6.148" + +CVE_STATUS[CVE-2026-68351] = "cpe-stable-backport: Backported in 6.6.148" + +CVE_STATUS[CVE-2026-68352] = "cpe-stable-backport: Backported in 6.6.148" + +CVE_STATUS[CVE-2026-68353] = "cpe-stable-backport: Backported in 6.6.148" + +CVE_STATUS[CVE-2026-68354] = "cpe-stable-backport: Backported in 6.6.148" + +CVE_STATUS[CVE-2026-68355] = "cpe-stable-backport: Backported in 6.6.148" + +CVE_STATUS[CVE-2026-68356] = "fixed-version: only affects 6.13 onwards" + +CVE_STATUS[CVE-2026-68357] = "cpe-stable-backport: Backported in 6.6.148" + +CVE_STATUS[CVE-2026-68358] = "fixed-version: only affects 6.9 onwards" + +CVE_STATUS[CVE-2026-68359] = "cpe-stable-backport: Backported in 6.6.148" + +CVE_STATUS[CVE-2026-68360] = "cpe-stable-backport: Backported in 6.6.148" + +CVE_STATUS[CVE-2026-68361] = "cpe-stable-backport: Backported in 6.6.148" + +CVE_STATUS[CVE-2026-68362] = "cpe-stable-backport: Backported in 6.6.148" + +CVE_STATUS[CVE-2026-68363] = "cpe-stable-backport: Backported in 6.6.148" + +CVE_STATUS[CVE-2026-68364] = "fixed-version: only affects 7.1 onwards" + +CVE_STATUS[CVE-2026-68365] = "cpe-stable-backport: Backported in 6.6.148" + +CVE_STATUS[CVE-2026-68366] = "cpe-stable-backport: Backported in 6.6.148" + +CVE_STATUS[CVE-2026-68367] = "cpe-stable-backport: Backported in 6.6.151" + +CVE_STATUS[CVE-2026-68368] = "cpe-stable-backport: Backported in 6.6.148" + +CVE_STATUS[CVE-2026-68369] = "cpe-stable-backport: Backported in 6.6.148" + +CVE_STATUS[CVE-2026-68370] = "cpe-stable-backport: Backported in 6.6.148" + +CVE_STATUS[CVE-2026-68371] = "cpe-stable-backport: Backported in 6.6.151" + +CVE_STATUS[CVE-2026-68372] = "fixed-version: only affects 6.7 onwards" + +CVE_STATUS[CVE-2026-68373] = "cpe-stable-backport: Backported in 6.6.148" + +CVE_STATUS[CVE-2026-68374] = "fixed-version: only affects 6.9 onwards" + +CVE_STATUS[CVE-2026-68375] = "fixed-version: only affects 6.10 onwards" + +CVE_STATUS[CVE-2026-68376] = "cpe-stable-backport: Backported in 6.6.148" + +CVE_STATUS[CVE-2026-68377] = "cpe-stable-backport: Backported in 6.6.148" + +CVE_STATUS[CVE-2026-68378] = "fixed-version: only affects 6.17 onwards" + +CVE_STATUS[CVE-2026-68379] = "fixed-version: only affects 6.18 onwards" + +CVE_STATUS[CVE-2026-68380] = "fixed-version: only affects 6.14 onwards" + +CVE_STATUS[CVE-2026-68381] = "cpe-stable-backport: Backported in 6.6.148" + +CVE_STATUS[CVE-2026-68382] = "fixed-version: only affects 6.10.14 onwards" + +CVE_STATUS[CVE-2026-68383] = "fixed-version: only affects 6.12.43 onwards" + +CVE_STATUS[CVE-2026-68384] = "fixed-version: only affects 6.18 onwards" + +CVE_STATUS[CVE-2026-68385] = "fixed-version: only affects 6.9 onwards" + +CVE_STATUS[CVE-2026-68386] = "cpe-stable-backport: Backported in 6.6.148" + +CVE_STATUS[CVE-2026-68387] = "fixed-version: only affects 6.18 onwards" + +CVE_STATUS[CVE-2026-68388] = "cpe-stable-backport: Backported in 6.6.148" + +CVE_STATUS[CVE-2026-68389] = "cpe-stable-backport: Backported in 6.6.148" + +CVE_STATUS[CVE-2026-68390] = "fixed-version: only affects 6.19 onwards" + +CVE_STATUS[CVE-2026-68391] = "cpe-stable-backport: Backported in 6.6.148" + +CVE_STATUS[CVE-2026-68392] = "cpe-stable-backport: Backported in 6.6.148" + +CVE_STATUS[CVE-2026-68393] = "fixed-version: only affects 6.12.28 onwards" + +CVE_STATUS[CVE-2026-68394] = "fixed-version: only affects 6.11 onwards" + +CVE_STATUS[CVE-2026-68395] = "cpe-stable-backport: Backported in 6.6.148" + +# CVE-2026-68396 needs backporting (fixed from 7.2) + +CVE_STATUS[CVE-2026-68397] = "cpe-stable-backport: Backported in 6.6.148" + +CVE_STATUS[CVE-2026-68398] = "cpe-stable-backport: Backported in 6.6.148" + +# CVE-2026-68399 needs backporting (fixed from 7.2) + +CVE_STATUS[CVE-2026-68400] = "fixed-version: only affects 6.7 onwards" + +# CVE-2026-68401 needs backporting (fixed from 7.2) + +CVE_STATUS[CVE-2026-68402] = "cpe-stable-backport: Backported in 6.6.148" + +CVE_STATUS[CVE-2026-68403] = "cpe-stable-backport: Backported in 6.6.148" + +# CVE-2026-68404 needs backporting (fixed from 7.2) + +CVE_STATUS[CVE-2026-68405] = "cpe-stable-backport: Backported in 6.6.148" + +CVE_STATUS[CVE-2026-68406] = "cpe-stable-backport: Backported in 6.6.148" + +CVE_STATUS[CVE-2026-68407] = "cpe-stable-backport: Backported in 6.6.148" + +CVE_STATUS[CVE-2026-68408] = "fixed-version: only affects 6.12.78 onwards" + +# CVE-2026-68409 needs backporting (fixed from 7.2) + +CVE_STATUS[CVE-2026-68410] = "cpe-stable-backport: Backported in 6.6.148" + +CVE_STATUS[CVE-2026-68411] = "cpe-stable-backport: Backported in 6.6.148" + +# CVE-2026-68412 needs backporting (fixed from 7.2) + +CVE_STATUS[CVE-2026-68413] = "cpe-stable-backport: Backported in 6.6.148" + +CVE_STATUS[CVE-2026-68414] = "cpe-stable-backport: Backported in 6.6.148" + +CVE_STATUS[CVE-2026-68415] = "fixed-version: only affects 6.14 onwards" + +CVE_STATUS[CVE-2026-68416] = "cpe-stable-backport: Backported in 6.6.148" + +CVE_STATUS[CVE-2026-68417] = "cpe-stable-backport: Backported in 6.6.148" + +# CVE-2026-68418 needs backporting (fixed from 7.2) + +CVE_STATUS[CVE-2026-68419] = "cpe-stable-backport: Backported in 6.6.148" + +CVE_STATUS[CVE-2026-68420] = "fixed-version: only affects 6.14 onwards" + +CVE_STATUS[CVE-2026-68421] = "fixed-version: only affects 6.12 onwards" + +CVE_STATUS[CVE-2026-68422] = "cpe-stable-backport: Backported in 6.6.148" + +CVE_STATUS[CVE-2026-68423] = "fixed-version: only affects 7.1 onwards" + +CVE_STATUS[CVE-2026-68424] = "fixed-version: only affects 7.1 onwards" + +CVE_STATUS[CVE-2026-68425] = "cpe-stable-backport: Backported in 6.6.148" + +# CVE-2026-68426 needs backporting (fixed from 7.2) + +CVE_STATUS[CVE-2026-68427] = "cpe-stable-backport: Backported in 6.6.148" + +CVE_STATUS[CVE-2026-68428] = "cpe-stable-backport: Backported in 6.6.148" + +CVE_STATUS[CVE-2026-68429] = "cpe-stable-backport: Backported in 6.6.148" + +CVE_STATUS[CVE-2026-68430] = "cpe-stable-backport: Backported in 6.6.148" + +# CVE-2026-68431 may need backporting (fixed from 6.6.153) + +CVE_STATUS[CVE-2026-68432] = "cpe-stable-backport: Backported in 6.6.148" + +CVE_STATUS[CVE-2026-68433] = "cpe-stable-backport: Backported in 6.6.148" + +CVE_STATUS[CVE-2026-68434] = "cpe-stable-backport: Backported in 6.6.148" + +# CVE-2026-68435 needs backporting (fixed from 7.2) + +CVE_STATUS[CVE-2026-68436] = "fixed-version: only affects 6.10 onwards" + +CVE_STATUS[CVE-2026-68437] = "fixed-version: only affects 6.8 onwards" + +CVE_STATUS[CVE-2026-68438] = "fixed-version: only affects 7.1 onwards" + +CVE_STATUS[CVE-2026-68439] = "fixed-version: only affects 6.7 onwards" + +CVE_STATUS[CVE-2026-68440] = "fixed-version: only affects 6.19 onwards" + +# CVE-2026-68441 needs backporting (fixed from 7.2) + +CVE_STATUS[CVE-2026-68442] = "fixed-version: only affects 6.8 onwards" + +CVE_STATUS[CVE-2026-68443] = "fixed-version: only affects 6.8 onwards" + +CVE_STATUS[CVE-2026-68444] = "cpe-stable-backport: Backported in 6.6.148" + +CVE_STATUS[CVE-2026-68445] = "cpe-stable-backport: Backported in 6.6.148" + +CVE_STATUS[CVE-2026-68446] = "cpe-stable-backport: Backported in 6.6.148" + +# CVE-2026-68447 needs backporting (fixed from 7.2) + +# CVE-2026-68448 needs backporting (fixed from 7.2) + +CVE_STATUS[CVE-2026-68449] = "cpe-stable-backport: Backported in 6.6.148" + +CVE_STATUS[CVE-2026-68450] = "cpe-stable-backport: Backported in 6.6.148" + +CVE_STATUS[CVE-2026-68451] = "cpe-stable-backport: Backported in 6.6.151" + +CVE_STATUS[CVE-2026-68452] = "cpe-stable-backport: Backported in 6.6.151" + +# CVE-2026-68453 needs backporting (fixed from 7.2) + +CVE_STATUS[CVE-2026-68454] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-68455] = "fixed-version: only affects 6.19 onwards" + +CVE_STATUS[CVE-2026-68456] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-68457] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-68458] = "fixed-version: only affects 6.14 onwards" + +CVE_STATUS[CVE-2026-68459] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-68460] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-68461] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-68462] = "fixed-version: only affects 7.1 onwards" + +CVE_STATUS[CVE-2026-68463] = "fixed-version: only affects 6.16 onwards" + +CVE_STATUS[CVE-2026-68464] = "fixed-version: only affects 6.16 onwards" + +CVE_STATUS[CVE-2026-68465] = "fixed-version: only affects 6.16 onwards" + +CVE_STATUS[CVE-2026-68466] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-68467] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-68468] = "fixed-version: only affects 7.1 onwards" + +CVE_STATUS[CVE-2026-68469] = "cpe-stable-backport: Backported in 6.6.145" + +# CVE-2026-68470 needs backporting (fixed from 7.2) + +# CVE-2026-68471 needs backporting (fixed from 7.2) + +CVE_STATUS[CVE-2026-68472] = "fixed-version: only affects 6.14 onwards" + +CVE_STATUS[CVE-2026-68473] = "fixed-version: only affects 7.0 onwards" + +CVE_STATUS[CVE-2026-68474] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-68475] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-68476] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-68477] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-68478] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-68479] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-68480] = "cpe-stable-backport: Backported in 6.6.150" + +CVE_STATUS[CVE-2026-72003] = "fixed-version: only affects 6.16 onwards" + +CVE_STATUS[CVE-2026-72004] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-72005] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-72006] = "fixed-version: only affects 6.17 onwards" + +CVE_STATUS[CVE-2026-72007] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-72008] = "fixed-version: only affects 6.19 onwards" + +# CVE-2026-72009 needs backporting (fixed from 7.2) + +CVE_STATUS[CVE-2026-72010] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-72011] = "fixed-version: only affects 6.14 onwards" + +CVE_STATUS[CVE-2026-72012] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-72013] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-72014] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-72015] = "cpe-stable-backport: Backported in 6.6.148" + +CVE_STATUS[CVE-2026-72016] = "fixed-version: only affects 6.15 onwards" + +CVE_STATUS[CVE-2026-72017] = "cpe-stable-backport: Backported in 6.6.148" + +CVE_STATUS[CVE-2026-72018] = "fixed-version: only affects 6.10 onwards" + +CVE_STATUS[CVE-2026-72019] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-72020] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-72021] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-72022] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-72023] = "cpe-stable-backport: Backported in 6.6.148" + +CVE_STATUS[CVE-2026-72024] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-72025] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-72026] = "fixed-version: only affects 6.12 onwards" + +CVE_STATUS[CVE-2026-72027] = "fixed-version: only affects 6.9 onwards" + +CVE_STATUS[CVE-2026-72028] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-72029] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-72030] = "cpe-stable-backport: Backported in 6.6.148" + +CVE_STATUS[CVE-2026-72031] = "fixed-version: only affects 6.9 onwards" + +CVE_STATUS[CVE-2026-72032] = "fixed-version: only affects 6.12 onwards" + +CVE_STATUS[CVE-2026-72033] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-72034] = "fixed-version: only affects 6.11 onwards" + +CVE_STATUS[CVE-2026-72035] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-72036] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-72037] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-72038] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-72039] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-72040] = "cpe-stable-backport: Backported in 6.6.148" + +CVE_STATUS[CVE-2026-72041] = "cpe-stable-backport: Backported in 6.6.145" + +# CVE-2026-72042 may need backporting (fixed from 6.7) + +CVE_STATUS[CVE-2026-72043] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-72045] = "cpe-stable-backport: Backported in 6.6.148" + +CVE_STATUS[CVE-2026-72046] = "fixed-version: only affects 6.9 onwards" + +CVE_STATUS[CVE-2026-72047] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-72048] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-72049] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-72050] = "fixed-version: only affects 6.9 onwards" + +CVE_STATUS[CVE-2026-72051] = "cpe-stable-backport: Backported in 6.6.148" + +CVE_STATUS[CVE-2026-72052] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-72053] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-72054] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-72055] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-72056] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-72057] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-72058] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-72059] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-72060] = "fixed-version: only affects 6.16 onwards" + +CVE_STATUS[CVE-2026-72061] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-72062] = "cpe-stable-backport: Backported in 6.6.148" + +CVE_STATUS[CVE-2026-72063] = "cpe-stable-backport: Backported in 6.6.148" + +CVE_STATUS[CVE-2026-72064] = "fixed-version: only affects 6.18 onwards" + +CVE_STATUS[CVE-2026-72065] = "cpe-stable-backport: Backported in 6.6.148" + +CVE_STATUS[CVE-2026-72066] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-72067] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-72068] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-72069] = "cpe-stable-backport: Backported in 6.6.148" + +CVE_STATUS[CVE-2026-72070] = "cpe-stable-backport: Backported in 6.6.148" + +CVE_STATUS[CVE-2026-72071] = "cpe-stable-backport: Backported in 6.6.148" + +CVE_STATUS[CVE-2026-72072] = "cpe-stable-backport: Backported in 6.6.145" + +# CVE-2026-72073 needs backporting (fixed from 7.2) + +CVE_STATUS[CVE-2026-72074] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-72075] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-72076] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-72077] = "cpe-stable-backport: Backported in 6.6.148" + +CVE_STATUS[CVE-2026-72078] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-72079] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-72080] = "fixed-version: only affects 6.16 onwards" + +CVE_STATUS[CVE-2026-72081] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-72082] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-72083] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-72084] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-72085] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-72086] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-72087] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-72088] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-72089] = "cpe-stable-backport: Backported in 6.6.148" + +CVE_STATUS[CVE-2026-72090] = "fixed-version: only affects 6.19 onwards" + +CVE_STATUS[CVE-2026-72091] = "fixed-version: only affects 6.14 onwards" + +CVE_STATUS[CVE-2026-72092] = "fixed-version: only affects 6.14 onwards" + +CVE_STATUS[CVE-2026-72093] = "fixed-version: only affects 6.16 onwards" + +CVE_STATUS[CVE-2026-72094] = "fixed-version: only affects 7.1 onwards" + +CVE_STATUS[CVE-2026-72095] = "fixed-version: only affects 6.16 onwards" + +CVE_STATUS[CVE-2026-72096] = "cpe-stable-backport: Backported in 6.6.148" + +CVE_STATUS[CVE-2026-72097] = "cpe-stable-backport: Backported in 6.6.145" + +# CVE-2026-72098 needs backporting (fixed from 7.2) + +CVE_STATUS[CVE-2026-72099] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-72100] = "fixed-version: only affects 6.11 onwards" + +CVE_STATUS[CVE-2026-72101] = "fixed-version: only affects 6.11 onwards" + +CVE_STATUS[CVE-2026-72102] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-72103] = "fixed-version: only affects 6.9 onwards" + +CVE_STATUS[CVE-2026-72104] = "fixed-version: only affects 6.18 onwards" + +CVE_STATUS[CVE-2026-72105] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-72106] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-72107] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-72108] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-72109] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-72110] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-72111] = "fixed-version: only affects 6.10.13 onwards" + +CVE_STATUS[CVE-2026-72112] = "fixed-version: only affects 7.1 onwards" + +CVE_STATUS[CVE-2026-72113] = "cpe-stable-backport: Backported in 6.6.148" + +CVE_STATUS[CVE-2026-72114] = "cpe-stable-backport: Backported in 6.6.148" + +CVE_STATUS[CVE-2026-72115] = "cpe-stable-backport: Backported in 6.6.148" + +CVE_STATUS[CVE-2026-72116] = "cpe-stable-backport: Backported in 6.6.148" + +CVE_STATUS[CVE-2026-72117] = "cpe-stable-backport: Backported in 6.6.148" + +CVE_STATUS[CVE-2026-72118] = "cpe-stable-backport: Backported in 6.6.148" + +CVE_STATUS[CVE-2026-72119] = "cpe-stable-backport: Backported in 6.6.148" + +CVE_STATUS[CVE-2026-72120] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-72121] = "cpe-stable-backport: Backported in 6.6.148" + +CVE_STATUS[CVE-2026-72122] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-72123] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-72124] = "cpe-stable-backport: Backported in 6.6.148" + +CVE_STATUS[CVE-2026-72125] = "cpe-stable-backport: Backported in 6.6.148" + +CVE_STATUS[CVE-2026-72126] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-72127] = "fixed-version: only affects 6.8 onwards" + +CVE_STATUS[CVE-2026-72128] = "fixed-version: only affects 6.14 onwards" + +CVE_STATUS[CVE-2026-72129] = "cpe-stable-backport: Backported in 6.6.145" + +# CVE-2026-72130 needs backporting (fixed from 7.2) + +CVE_STATUS[CVE-2026-72131] = "fixed-version: only affects 6.18 onwards" + +CVE_STATUS[CVE-2026-72132] = "cpe-stable-backport: Backported in 6.6.148" + +CVE_STATUS[CVE-2026-72133] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-72134] = "fixed-version: only affects 7.0 onwards" + +CVE_STATUS[CVE-2026-72135] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-72136] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-72137] = "fixed-version: only affects 6.11 onwards" + +CVE_STATUS[CVE-2026-72138] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-72139] = "fixed-version: only affects 6.18 onwards" + +CVE_STATUS[CVE-2026-72140] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-72141] = "fixed-version: only affects 6.13 onwards" + +CVE_STATUS[CVE-2026-72142] = "cpe-stable-backport: Backported in 6.6.148" + +CVE_STATUS[CVE-2026-72143] = "fixed-version: only affects 6.18.16 onwards" + +CVE_STATUS[CVE-2026-72144] = "cpe-stable-backport: Backported in 6.6.148" + +CVE_STATUS[CVE-2026-72145] = "fixed-version: only affects 7.1 onwards" + +CVE_STATUS[CVE-2026-72146] = "cpe-stable-backport: Backported in 6.6.148" + +CVE_STATUS[CVE-2026-72147] = "cpe-stable-backport: Backported in 6.6.148" + +CVE_STATUS[CVE-2026-72148] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-72149] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-72150] = "fixed-version: only affects 6.15 onwards" + +CVE_STATUS[CVE-2026-72151] = "fixed-version: only affects 6.10 onwards" + +CVE_STATUS[CVE-2026-72152] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-72153] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-72154] = "fixed-version: only affects 6.18 onwards" + +CVE_STATUS[CVE-2026-72155] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-72156] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-72157] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-72158] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-72159] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-72160] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-72161] = "cpe-stable-backport: Backported in 6.6.145" + +# CVE-2026-72162 needs backporting (fixed from 7.2) + +CVE_STATUS[CVE-2026-72163] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-72164] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-72165] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-72166] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-72167] = "cpe-stable-backport: Backported in 6.6.145" + +# CVE-2026-72168 needs backporting (fixed from 7.2) + +CVE_STATUS[CVE-2026-72169] = "fixed-version: only affects 6.16 onwards" + +CVE_STATUS[CVE-2026-72170] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-72171] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-72172] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-72173] = "fixed-version: only affects 6.19 onwards" + +CVE_STATUS[CVE-2026-72174] = "fixed-version: only affects 6.7 onwards" + +CVE_STATUS[CVE-2026-72175] = "fixed-version: only affects 6.7 onwards" + +CVE_STATUS[CVE-2026-72176] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-72177] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-72178] = "fixed-version: only affects 6.11 onwards" + +CVE_STATUS[CVE-2026-72179] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-72180] = "fixed-version: only affects 6.19 onwards" + +CVE_STATUS[CVE-2026-72181] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-72182] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-72183] = "fixed-version: only affects 6.12.24 onwards" + +CVE_STATUS[CVE-2026-72184] = "fixed-version: only affects 7.1 onwards" + +CVE_STATUS[CVE-2026-72185] = "fixed-version: only affects 7.1 onwards" + +CVE_STATUS[CVE-2026-72186] = "fixed-version: only affects 7.1 onwards" + +CVE_STATUS[CVE-2026-72187] = "fixed-version: only affects 7.1 onwards" + +CVE_STATUS[CVE-2026-72188] = "fixed-version: only affects 7.1 onwards" + +CVE_STATUS[CVE-2026-72189] = "fixed-version: only affects 7.1 onwards" + +CVE_STATUS[CVE-2026-72190] = "fixed-version: only affects 7.1 onwards" + +CVE_STATUS[CVE-2026-72191] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-72192] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-72193] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-72194] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-72195] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-72196] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-72197] = "cpe-stable-backport: Backported in 6.6.145" + +# CVE-2026-72198 needs backporting (fixed from 7.2) + +CVE_STATUS[CVE-2026-72199] = "fixed-version: only affects 7.1 onwards" + +# CVE-2026-72200 needs backporting (fixed from 7.2) + +CVE_STATUS[CVE-2026-72201] = "fixed-version: only affects 7.1 onwards" + +CVE_STATUS[CVE-2026-72202] = "fixed-version: only affects 7.1 onwards" + +# CVE-2026-72203 needs backporting (fixed from 7.2) + +CVE_STATUS[CVE-2026-72204] = "fixed-version: only affects 7.1 onwards" + +CVE_STATUS[CVE-2026-72205] = "fixed-version: only affects 7.1 onwards" + +CVE_STATUS[CVE-2026-72206] = "fixed-version: only affects 7.1 onwards" + +CVE_STATUS[CVE-2026-72207] = "fixed-version: only affects 7.1 onwards" + +CVE_STATUS[CVE-2026-72208] = "fixed-version: only affects 7.1 onwards" + +CVE_STATUS[CVE-2026-72209] = "fixed-version: only affects 7.1 onwards" + +CVE_STATUS[CVE-2026-72210] = "fixed-version: only affects 7.1 onwards" + +CVE_STATUS[CVE-2026-72211] = "fixed-version: only affects 7.1 onwards" + +CVE_STATUS[CVE-2026-72212] = "fixed-version: only affects 6.8 onwards" + +# CVE-2026-72213 needs backporting (fixed from 7.2) + +CVE_STATUS[CVE-2026-72214] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-72215] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-72216] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-72217] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-72218] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-72219] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-72220] = "fixed-version: only affects 6.18 onwards" + +CVE_STATUS[CVE-2026-72221] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-72222] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-72223] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-72224] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-72225] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-72226] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-72227] = "fixed-version: only affects 6.8 onwards" + +CVE_STATUS[CVE-2026-72228] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-72229] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-72230] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-72231] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-72232] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-72233] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-72234] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-72235] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-72236] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-72237] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-72238] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-72239] = "fixed-version: only affects 7.1 onwards" + +CVE_STATUS[CVE-2026-72240] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-72241] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-72242] = "cpe-stable-backport: Backported in 6.6.148" + +CVE_STATUS[CVE-2026-72243] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-72244] = "fixed-version: only affects 6.7 onwards" + +CVE_STATUS[CVE-2026-72245] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-72247] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-72248] = "fixed-version: only affects 6.19 onwards" + +CVE_STATUS[CVE-2026-72249] = "fixed-version: only affects 6.19 onwards" + +CVE_STATUS[CVE-2026-72250] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-72251] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-72252] = "cpe-stable-backport: Backported in 6.6.148" + +CVE_STATUS[CVE-2026-72253] = "cpe-stable-backport: Backported in 6.6.148" + +CVE_STATUS[CVE-2026-72254] = "cpe-stable-backport: Backported in 6.6.148" + +CVE_STATUS[CVE-2026-72255] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-72256] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-72257] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-72258] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-72259] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-72260] = "cpe-stable-backport: Backported in 6.6.148" + +CVE_STATUS[CVE-2026-72261] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-72262] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-72263] = "fixed-version: only affects 6.19 onwards" + +CVE_STATUS[CVE-2026-72264] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-72265] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-72266] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-72267] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-72268] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-72269] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-72270] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-72271] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-72272] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-72273] = "cpe-stable-backport: Backported in 6.6.148" + +CVE_STATUS[CVE-2026-72274] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-72275] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-72276] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-72277] = "fixed-version: only affects 6.16 onwards" + +CVE_STATUS[CVE-2026-72278] = "fixed-version: only affects 6.16 onwards" + +CVE_STATUS[CVE-2026-72279] = "fixed-version: only affects 6.16 onwards" + +CVE_STATUS[CVE-2026-72280] = "fixed-version: only affects 6.11 onwards" + +CVE_STATUS[CVE-2026-72281] = "fixed-version: only affects 7.1 onwards" + +CVE_STATUS[CVE-2026-72282] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-72283] = "fixed-version: only affects 6.17 onwards" + +CVE_STATUS[CVE-2026-72284] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-72285] = "fixed-version: only affects 6.19 onwards" + +CVE_STATUS[CVE-2026-72286] = "fixed-version: only affects 6.11 onwards" + +CVE_STATUS[CVE-2026-72287] = "fixed-version: only affects 6.19 onwards" + +# CVE-2026-72288 needs backporting (fixed from 7.2) + +CVE_STATUS[CVE-2026-72289] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-72290] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-72291] = "fixed-version: only affects 7.1 onwards" + +CVE_STATUS[CVE-2026-72292] = "fixed-version: only affects 7.0 onwards" + +CVE_STATUS[CVE-2026-72293] = "fixed-version: only affects 7.0 onwards" + +CVE_STATUS[CVE-2026-72294] = "fixed-version: only affects 6.7 onwards" + +CVE_STATUS[CVE-2026-72295] = "fixed-version: only affects 6.13 onwards" + +CVE_STATUS[CVE-2026-72296] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-72297] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-72298] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-72299] = "cpe-stable-backport: Backported in 6.6.148" + +CVE_STATUS[CVE-2026-72300] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-72301] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-72302] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-72303] = "fixed-version: only affects 7.0 onwards" + +CVE_STATUS[CVE-2026-72304] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-72305] = "cpe-stable-backport: Backported in 6.6.148" + +CVE_STATUS[CVE-2026-72306] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-72307] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-72308] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-72309] = "fixed-version: only affects 7.1 onwards" + +CVE_STATUS[CVE-2026-72310] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-72311] = "fixed-version: only affects 7.1 onwards" + +CVE_STATUS[CVE-2026-72312] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-72313] = "fixed-version: only affects 6.19 onwards" + +CVE_STATUS[CVE-2026-72314] = "cpe-stable-backport: Backported in 6.6.145" + +# CVE-2026-72315 may need backporting (fixed from 6.7) + +CVE_STATUS[CVE-2026-72316] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-72317] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-72318] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-72319] = "cpe-stable-backport: Backported in 6.6.145" + +# CVE-2026-72320 needs backporting (fixed from 7.2) + +# CVE-2026-72321 needs backporting (fixed from 7.2) + +CVE_STATUS[CVE-2026-72322] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-72323] = "cpe-stable-backport: Backported in 6.6.145" + +# CVE-2026-72324 needs backporting (fixed from 7.2) + +# CVE-2026-72325 needs backporting (fixed from 7.2) + +CVE_STATUS[CVE-2026-72326] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-72327] = "fixed-version: only affects 6.8 onwards" + +CVE_STATUS[CVE-2026-72328] = "fixed-version: only affects 6.16 onwards" + +# CVE-2026-72329 needs backporting (fixed from 7.2) + +CVE_STATUS[CVE-2026-72330] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-72331] = "fixed-version: only affects 6.16 onwards" + +CVE_STATUS[CVE-2026-72332] = "fixed-version: only affects 6.19 onwards" + +CVE_STATUS[CVE-2026-72333] = "fixed-version: only affects 6.18.21 onwards" + +# CVE-2026-72334 needs backporting (fixed from 7.2) + +CVE_STATUS[CVE-2026-72335] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-72336] = "cpe-stable-backport: Backported in 6.6.145" + +# CVE-2026-72337 needs backporting (fixed from 7.2) + +CVE_STATUS[CVE-2026-72338] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-72339] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-72340] = "cpe-stable-backport: Backported in 6.6.145" + +# CVE-2026-72341 needs backporting (fixed from 7.2) + +CVE_STATUS[CVE-2026-72342] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-72343] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-72344] = "fixed-version: only affects 7.1 onwards" + +CVE_STATUS[CVE-2026-72345] = "fixed-version: only affects 6.14 onwards" + +CVE_STATUS[CVE-2026-72346] = "fixed-version: only affects 7.1 onwards" + +CVE_STATUS[CVE-2026-72347] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-72348] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-72349] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-72350] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-72351] = "cpe-stable-backport: Backported in 6.6.145" + +# CVE-2026-72352 needs backporting (fixed from 7.2) + +CVE_STATUS[CVE-2026-72353] = "fixed-version: only affects 7.1 onwards" + +CVE_STATUS[CVE-2026-72354] = "fixed-version: only affects 7.1 onwards" + +CVE_STATUS[CVE-2026-72355] = "fixed-version: only affects 6.10 onwards" + +CVE_STATUS[CVE-2026-72356] = "fixed-version: only affects 6.10 onwards" + +CVE_STATUS[CVE-2026-72357] = "fixed-version: only affects 6.18 onwards" + +CVE_STATUS[CVE-2026-72358] = "fixed-version: only affects 7.1 onwards" + +CVE_STATUS[CVE-2026-72359] = "fixed-version: only affects 7.1 onwards" + +CVE_STATUS[CVE-2026-72360] = "fixed-version: only affects 6.11 onwards" + +CVE_STATUS[CVE-2026-72361] = "fixed-version: only affects 6.8 onwards" + +CVE_STATUS[CVE-2026-72362] = "fixed-version: only affects 6.8 onwards" + +CVE_STATUS[CVE-2026-72363] = "fixed-version: only affects 6.14 onwards" + +CVE_STATUS[CVE-2026-72364] = "fixed-version: only affects 6.10 onwards" + +CVE_STATUS[CVE-2026-72365] = "fixed-version: only affects 6.10 onwards" + +CVE_STATUS[CVE-2026-72366] = "fixed-version: only affects 6.11 onwards" + +CVE_STATUS[CVE-2026-72367] = "fixed-version: only affects 6.12.10 onwards" + +CVE_STATUS[CVE-2026-72368] = "fixed-version: only affects 6.19 onwards" + +CVE_STATUS[CVE-2026-72369] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-72370] = "fixed-version: only affects 6.13 onwards" + +CVE_STATUS[CVE-2026-72371] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-72372] = "fixed-version: only affects 6.12.97 onwards" + +# CVE-2026-72373 needs backporting (fixed from 7.2) + +CVE_STATUS[CVE-2026-72374] = "cpe-stable-backport: Backported in 6.6.145" + +# CVE-2026-72375 needs backporting (fixed from 7.2) + +# CVE-2026-72376 needs backporting (fixed from 7.2) + +CVE_STATUS[CVE-2026-72377] = "fixed-version: only affects 6.14 onwards" + +CVE_STATUS[CVE-2026-72378] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-72379] = "cpe-stable-backport: Backported in 6.6.145" + +# CVE-2026-72380 needs backporting (fixed from 7.2) + +CVE_STATUS[CVE-2026-72381] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-72382] = "cpe-stable-backport: Backported in 6.6.145" + +# CVE-2026-72383 needs backporting (fixed from 7.2) + +CVE_STATUS[CVE-2026-72384] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-72385] = "fixed-version: only affects 6.14 onwards" + +CVE_STATUS[CVE-2026-72386] = "fixed-version: only affects 6.10 onwards" + +CVE_STATUS[CVE-2026-72387] = "fixed-version: only affects 6.10 onwards" + +CVE_STATUS[CVE-2026-72388] = "fixed-version: only affects 6.10 onwards" + +CVE_STATUS[CVE-2026-72389] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-72390] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-72391] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-72392] = "cpe-stable-backport: Backported in 6.6.151" + +CVE_STATUS[CVE-2026-72393] = "fixed-version: only affects 6.15 onwards" + +CVE_STATUS[CVE-2026-72394] = "fixed-version: only affects 6.9 onwards" + +CVE_STATUS[CVE-2026-72395] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-72396] = "cpe-stable-backport: Backported in 6.6.145" + +# CVE-2026-72397 needs backporting (fixed from 7.2) + +# CVE-2026-72398 needs backporting (fixed from 7.2) + +CVE_STATUS[CVE-2026-72399] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-72400] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-72401] = "fixed-version: only affects 6.19 onwards" + +# CVE-2026-72402 needs backporting (fixed from 7.2) + +CVE_STATUS[CVE-2026-72403] = "fixed-version: only affects 6.14 onwards" + +# CVE-2026-72404 needs backporting (fixed from 7.2) + +# CVE-2026-72405 needs backporting (fixed from 7.2) + +CVE_STATUS[CVE-2026-72406] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-72407] = "fixed-version: only affects 7.0 onwards" + +CVE_STATUS[CVE-2026-72408] = "fixed-version: only affects 7.0 onwards" + +CVE_STATUS[CVE-2026-72409] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-72410] = "fixed-version: only affects 6.8 onwards" + +CVE_STATUS[CVE-2026-72411] = "fixed-version: only affects 7.1 onwards" + +CVE_STATUS[CVE-2026-72412] = "fixed-version: only affects 7.0 onwards" + +# CVE-2026-72413 needs backporting (fixed from 7.2) + +CVE_STATUS[CVE-2026-72414] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-72415] = "fixed-version: only affects 7.0 onwards" + +CVE_STATUS[CVE-2026-72416] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-72417] = "fixed-version: only affects 6.19 onwards" + +CVE_STATUS[CVE-2026-72418] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-72419] = "cpe-stable-backport: Backported in 6.6.145" + +# CVE-2026-72420 needs backporting (fixed from 7.2) + +CVE_STATUS[CVE-2026-72421] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-72422] = "cpe-stable-backport: Backported in 6.6.145" + +# CVE-2026-72423 needs backporting (fixed from 7.2) + +CVE_STATUS[CVE-2026-72424] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-72425] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-72426] = "fixed-version: only affects 7.1 onwards" + +CVE_STATUS[CVE-2026-72427] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-72428] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-72429] = "fixed-version: only affects 6.16 onwards" + +CVE_STATUS[CVE-2026-72430] = "fixed-version: only affects 6.7 onwards" + +CVE_STATUS[CVE-2026-72431] = "fixed-version: only affects 6.17 onwards" + +CVE_STATUS[CVE-2026-72432] = "fixed-version: only affects 7.1 onwards" + +CVE_STATUS[CVE-2026-72433] = "cpe-stable-backport: Backported in 6.6.145" + +# CVE-2026-72434 needs backporting (fixed from 7.2) + +CVE_STATUS[CVE-2026-72435] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-72436] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-72437] = "cpe-stable-backport: Backported in 6.6.145" + +# CVE-2026-72438 needs backporting (fixed from 7.2) + +# CVE-2026-72439 needs backporting (fixed from 7.2) + +# CVE-2026-72440 needs backporting (fixed from 7.2) + +CVE_STATUS[CVE-2026-72441] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-72442] = "fixed-version: only affects 7.0 onwards" + +CVE_STATUS[CVE-2026-72443] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-72444] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-72445] = "fixed-version: only affects 6.16 onwards" + +CVE_STATUS[CVE-2026-72446] = "fixed-version: only affects 6.16 onwards" + +CVE_STATUS[CVE-2026-72447] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-72448] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-72449] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-72450] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-72451] = "fixed-version: only affects 6.12.13 onwards" + +CVE_STATUS[CVE-2026-72452] = "fixed-version: only affects 6.12.80 onwards" + +CVE_STATUS[CVE-2026-72453] = "fixed-version: only affects 6.19 onwards" + +# CVE-2026-72454 needs backporting (fixed from 7.2) + +CVE_STATUS[CVE-2026-72455] = "fixed-version: only affects 6.18.14 onwards" + +CVE_STATUS[CVE-2026-72456] = "fixed-version: only affects 7.0 onwards" + +CVE_STATUS[CVE-2026-72457] = "fixed-version: only affects 6.17 onwards" + +CVE_STATUS[CVE-2026-72458] = "fixed-version: only affects 6.17 onwards" + +CVE_STATUS[CVE-2026-72459] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-72460] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-72461] = "fixed-version: only affects 6.17 onwards" + +CVE_STATUS[CVE-2026-72462] = "fixed-version: only affects 6.17 onwards" + +CVE_STATUS[CVE-2026-72463] = "fixed-version: only affects 6.12.94 onwards" + +CVE_STATUS[CVE-2026-72464] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-72465] = "fixed-version: only affects 7.1 onwards" + +CVE_STATUS[CVE-2026-72466] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-72467] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-72468] = "fixed-version: only affects 6.11 onwards" + +# CVE-2026-72469 needs backporting (fixed from 7.2) + +CVE_STATUS[CVE-2026-72470] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-72471] = "fixed-version: only affects 7.0 onwards" + +# CVE-2026-72472 needs backporting (fixed from 7.2) + +CVE_STATUS[CVE-2026-72473] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-72474] = "fixed-version: only affects 6.8 onwards" + +CVE_STATUS[CVE-2026-72475] = "fixed-version: only affects 6.11 onwards" + +CVE_STATUS[CVE-2026-72476] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-72477] = "fixed-version: only affects 6.17 onwards" + +CVE_STATUS[CVE-2026-72478] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-72479] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-72480] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-72481] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-72482] = "fixed-version: only affects 6.18.22 onwards" + +CVE_STATUS[CVE-2026-72483] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-72484] = "cpe-stable-backport: Backported in 6.6.145" + +# CVE-2026-72485 needs backporting (fixed from 7.2) + +CVE_STATUS[CVE-2026-72486] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-72487] = "cpe-stable-backport: Backported in 6.6.145" + +# CVE-2026-72488 needs backporting (fixed from 7.2) + +CVE_STATUS[CVE-2026-72489] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-72490] = "fixed-version: only affects 7.1 onwards" + +CVE_STATUS[CVE-2026-72491] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-72492] = "cpe-stable-backport: Backported in 6.6.145" + +# CVE-2026-72493 needs backporting (fixed from 7.2) + +# CVE-2026-72494 needs backporting (fixed from 7.2) + +# CVE-2026-72495 needs backporting (fixed from 7.2) + +# CVE-2026-72496 needs backporting (fixed from 7.2) + +CVE_STATUS[CVE-2026-72497] = "fixed-version: only affects 6.12 onwards" + +CVE_STATUS[CVE-2026-72498] = "fixed-version: only affects 6.13 onwards" + +CVE_STATUS[CVE-2026-72499] = "fixed-version: only affects 6.8 onwards" + +CVE_STATUS[CVE-2026-72500] = "fixed-version: only affects 6.12 onwards" + +# CVE-2026-72501 needs backporting (fixed from 7.2) + +CVE_STATUS[CVE-2026-72502] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-74255] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-74256] = "cpe-stable-backport: Backported in 6.6.145" + +# CVE-2026-74257 needs backporting (fixed from 7.2) + +# CVE-2026-74258 needs backporting (fixed from 7.2) + +CVE_STATUS[CVE-2026-74259] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-74260] = "fixed-version: only affects 6.16 onwards" + +# CVE-2026-74261 needs backporting (fixed from 7.2) + +CVE_STATUS[CVE-2026-74262] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-74263] = "cpe-stable-backport: Backported in 6.6.145" + +# CVE-2026-74264 needs backporting (fixed from 7.2) + +CVE_STATUS[CVE-2026-74265] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-74266] = "fixed-version: only affects 6.17 onwards" + +CVE_STATUS[CVE-2026-74267] = "cpe-stable-backport: Backported in 6.6.145" + +# CVE-2026-74268 needs backporting (fixed from 7.2) + +# CVE-2026-74269 needs backporting (fixed from 7.2) + +CVE_STATUS[CVE-2026-74270] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-74271] = "cpe-stable-backport: Backported in 6.6.145" + +# CVE-2026-74272 needs backporting (fixed from 7.2) + +# CVE-2026-74273 needs backporting (fixed from 7.2) + +CVE_STATUS[CVE-2026-74274] = "fixed-version: only affects 6.19 onwards" + +CVE_STATUS[CVE-2026-74275] = "fixed-version: only affects 7.1 onwards" + +CVE_STATUS[CVE-2026-74276] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-74277] = "fixed-version: only affects 6.16 onwards" + +# CVE-2026-74278 needs backporting (fixed from 7.2) + +CVE_STATUS[CVE-2026-74279] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-74280] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-74281] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-74282] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-74283] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-74284] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-74285] = "fixed-version: only affects 7.1 onwards" + +CVE_STATUS[CVE-2026-74286] = "fixed-version: only affects 6.10 onwards" + +CVE_STATUS[CVE-2026-74287] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-74288] = "cpe-stable-backport: Backported in 6.6.145" + +# CVE-2026-74289 needs backporting (fixed from 7.2) + +CVE_STATUS[CVE-2026-74290] = "cpe-stable-backport: Backported in 6.6.145" + +# CVE-2026-74291 needs backporting (fixed from 7.2) + +CVE_STATUS[CVE-2026-74292] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-74293] = "cpe-stable-backport: Backported in 6.6.145" + +# CVE-2026-74294 needs backporting (fixed from 7.2) + +CVE_STATUS[CVE-2026-74295] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-74296] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-74297] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-74298] = "fixed-version: only affects 7.1 onwards" + +CVE_STATUS[CVE-2026-74299] = "fixed-version: only affects 7.1 onwards" + +CVE_STATUS[CVE-2026-74300] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-74301] = "fixed-version: only affects 6.11 onwards" + +# CVE-2026-74302 may need backporting (fixed from 6.7) + +CVE_STATUS[CVE-2026-74303] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-74304] = "fixed-version: only affects 7.0 onwards" + +CVE_STATUS[CVE-2026-74305] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-74306] = "fixed-version: only affects 6.10 onwards" + +# CVE-2026-74307 needs backporting (fixed from 7.2) + +CVE_STATUS[CVE-2026-74308] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-74309] = "fixed-version: only affects 6.14 onwards" + +CVE_STATUS[CVE-2026-74310] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-74311] = "fixed-version: only affects 6.16 onwards" + +CVE_STATUS[CVE-2026-74312] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-74313] = "cpe-stable-backport: Backported in 6.6.145" + +# CVE-2026-74314 needs backporting (fixed from 7.2) + +CVE_STATUS[CVE-2026-74315] = "fixed-version: only affects 7.1 onwards" + +CVE_STATUS[CVE-2026-74316] = "fixed-version: only affects 6.9 onwards" + +# CVE-2026-74317 needs backporting (fixed from 7.2) + +# CVE-2026-74318 needs backporting (fixed from 7.2) + +CVE_STATUS[CVE-2026-74319] = "fixed-version: only affects 7.1 onwards" + +CVE_STATUS[CVE-2026-74320] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-74321] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-74322] = "fixed-version: only affects 6.15 onwards" + +CVE_STATUS[CVE-2026-74323] = "fixed-version: only affects 6.18 onwards" + +CVE_STATUS[CVE-2026-74324] = "fixed-version: only affects 6.7 onwards" + +CVE_STATUS[CVE-2026-74325] = "fixed-version: only affects 6.14 onwards" + +CVE_STATUS[CVE-2026-74326] = "fixed-version: only affects 7.1 onwards" + +CVE_STATUS[CVE-2026-74327] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-74328] = "fixed-version: only affects 6.19 onwards" + +CVE_STATUS[CVE-2026-74329] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-74330] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-74331] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-74332] = "fixed-version: only affects 6.12 onwards" + +CVE_STATUS[CVE-2026-74333] = "fixed-version: only affects 6.13 onwards" + +# CVE-2026-74334 needs backporting (fixed from 7.2) + +CVE_STATUS[CVE-2026-74335] = "fixed-version: only affects 6.13 onwards" + +CVE_STATUS[CVE-2026-74336] = "fixed-version: only affects 6.18 onwards" + +# CVE-2026-74337 needs backporting (fixed from 7.2) + +# CVE-2026-74338 needs backporting (fixed from 7.2) + +CVE_STATUS[CVE-2026-74339] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-74340] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-74341] = "cpe-stable-backport: Backported in 6.6.145" + +# CVE-2026-74342 needs backporting (fixed from 7.2) + +CVE_STATUS[CVE-2026-74343] = "fixed-version: only affects 7.1 onwards" + +# CVE-2026-74344 needs backporting (fixed from 7.2) + +# CVE-2026-74345 needs backporting (fixed from 7.2) + +CVE_STATUS[CVE-2026-74346] = "cpe-stable-backport: Backported in 6.6.145" + +# CVE-2026-74347 needs backporting (fixed from 7.2) + +CVE_STATUS[CVE-2026-74348] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-74349] = "cpe-stable-backport: Backported in 6.6.145" + +# CVE-2026-74350 needs backporting (fixed from 7.2) + +CVE_STATUS[CVE-2026-74351] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-74352] = "fixed-version: only affects 6.13 onwards" + +CVE_STATUS[CVE-2026-74353] = "fixed-version: only affects 6.12 onwards" + +CVE_STATUS[CVE-2026-74354] = "fixed-version: only affects 6.9 onwards" + +CVE_STATUS[CVE-2026-74355] = "fixed-version: only affects 6.15 onwards" + +# CVE-2026-74356 needs backporting (fixed from 7.2) + +CVE_STATUS[CVE-2026-74357] = "fixed-version: only affects 7.1 onwards" + +CVE_STATUS[CVE-2026-74358] = "fixed-version: only affects 6.16 onwards" + +CVE_STATUS[CVE-2026-74359] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-74360] = "fixed-version: only affects 6.18 onwards" + +CVE_STATUS[CVE-2026-74361] = "fixed-version: only affects 6.16 onwards" + +CVE_STATUS[CVE-2026-74362] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-74363] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-74364] = "fixed-version: only affects 6.18 onwards" + +CVE_STATUS[CVE-2026-74365] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-74366] = "fixed-version: only affects 6.14 onwards" + +CVE_STATUS[CVE-2026-74367] = "fixed-version: only affects 6.13 onwards" + +# CVE-2026-74368 may need backporting (fixed from 6.7) + +CVE_STATUS[CVE-2026-74369] = "fixed-version: only affects 7.1 onwards" + +CVE_STATUS[CVE-2026-74370] = "fixed-version: only affects 6.19 onwards" + +CVE_STATUS[CVE-2026-74371] = "fixed-version: only affects 6.17 onwards" + +CVE_STATUS[CVE-2026-74372] = "fixed-version: only affects 6.13 onwards" + +# CVE-2026-74373 needs backporting (fixed from 7.2) + +# CVE-2026-74374 needs backporting (fixed from 7.2) + +# CVE-2026-74375 needs backporting (fixed from 7.2) + +CVE_STATUS[CVE-2026-74376] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-74377] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-74378] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-74379] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-74380] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-74381] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-74382] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-74383] = "fixed-version: only affects 6.16 onwards" + +CVE_STATUS[CVE-2026-74384] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-74385] = "fixed-version: only affects 6.7 onwards" + +# CVE-2026-74386 needs backporting (fixed from 7.2) + +CVE_STATUS[CVE-2026-74387] = "cpe-stable-backport: Backported in 6.6.145" + +# CVE-2026-74388 needs backporting (fixed from 7.2) + +# CVE-2026-74389 needs backporting (fixed from 7.2) + +CVE_STATUS[CVE-2026-74390] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-74391] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-74392] = "fixed-version: only affects 6.19 onwards" + +CVE_STATUS[CVE-2026-74393] = "fixed-version: only affects 6.9 onwards" + +CVE_STATUS[CVE-2026-74394] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-74395] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-74396] = "fixed-version: only affects 6.16 onwards" + +CVE_STATUS[CVE-2026-74397] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-74398] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-74399] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-74400] = "fixed-version: only affects 6.15 onwards" + +CVE_STATUS[CVE-2026-74401] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-74402] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-74403] = "fixed-version: only affects 6.19 onwards" + +CVE_STATUS[CVE-2026-74404] = "fixed-version: only affects 6.9 onwards" + +# CVE-2026-74405 needs backporting (fixed from 7.2) + +CVE_STATUS[CVE-2026-74406] = "cpe-stable-backport: Backported in 6.6.145" + +# CVE-2026-74407 needs backporting (fixed from 7.2) + +CVE_STATUS[CVE-2026-74408] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-74409] = "fixed-version: only affects 6.14 onwards" + +CVE_STATUS[CVE-2026-74410] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-74411] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-74412] = "fixed-version: only affects 6.17 onwards" + +CVE_STATUS[CVE-2026-74413] = "fixed-version: only affects 6.17 onwards" + +CVE_STATUS[CVE-2026-74414] = "fixed-version: only affects 7.1 onwards" + +CVE_STATUS[CVE-2026-74415] = "fixed-version: only affects 7.0 onwards" + +CVE_STATUS[CVE-2026-74416] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-74417] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-74418] = "fixed-version: only affects 7.1 onwards" + +CVE_STATUS[CVE-2026-74419] = "fixed-version: only affects 6.14 onwards" + +CVE_STATUS[CVE-2026-74420] = "fixed-version: only affects 6.15 onwards" + +CVE_STATUS[CVE-2026-74421] = "fixed-version: only affects 6.18 onwards" + +CVE_STATUS[CVE-2026-74422] = "fixed-version: only affects 7.0 onwards" + +CVE_STATUS[CVE-2026-74423] = "fixed-version: only affects 6.18 onwards" + +CVE_STATUS[CVE-2026-74424] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-74425] = "fixed-version: only affects 6.15 onwards" + +CVE_STATUS[CVE-2026-74426] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-74427] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-74428] = "fixed-version: only affects 6.16 onwards" + +CVE_STATUS[CVE-2026-74429] = "fixed-version: only affects 6.14 onwards" + +CVE_STATUS[CVE-2026-74430] = "fixed-version: only affects 6.14 onwards" + +CVE_STATUS[CVE-2026-74431] = "fixed-version: only affects 6.16 onwards" + +CVE_STATUS[CVE-2026-74432] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-74433] = "fixed-version: only affects 6.16 onwards" + +CVE_STATUS[CVE-2026-74434] = "fixed-version: only affects 6.16 onwards" + +CVE_STATUS[CVE-2026-74435] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-74436] = "cpe-stable-backport: Backported in 6.6.148" + +CVE_STATUS[CVE-2026-74437] = "fixed-version: only affects 6.16 onwards" + +CVE_STATUS[CVE-2026-74438] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-74439] = "fixed-version: only affects 6.8.2 onwards" + +CVE_STATUS[CVE-2026-74440] = "fixed-version: only affects 6.8 onwards" + +CVE_STATUS[CVE-2026-74441] = "cpe-stable-backport: Backported in 6.6.151" + +CVE_STATUS[CVE-2026-74442] = "fixed-version: only affects 6.10 onwards" + +CVE_STATUS[CVE-2026-74443] = "cpe-stable-backport: Backported in 6.6.151" + +CVE_STATUS[CVE-2026-74444] = "cpe-stable-backport: Backported in 6.6.151" + +CVE_STATUS[CVE-2026-74445] = "cpe-stable-backport: Backported in 6.6.151" + +CVE_STATUS[CVE-2026-74446] = "cpe-stable-backport: Backported in 6.6.151" + +CVE_STATUS[CVE-2026-74447] = "fixed-version: only affects 6.12.75 onwards" + +CVE_STATUS[CVE-2026-74448] = "cpe-stable-backport: Backported in 6.6.151" + +CVE_STATUS[CVE-2026-74449] = "fixed-version: only affects 6.11 onwards" + +# CVE-2026-74450 may need backporting (fixed from 6.6.153) + +CVE_STATUS[CVE-2026-74451] = "fixed-version: only affects 6.10 onwards" + +CVE_STATUS[CVE-2026-74452] = "fixed-version: only affects 6.10 onwards" + +CVE_STATUS[CVE-2026-74453] = "cpe-stable-backport: Backported in 6.6.151" + +CVE_STATUS[CVE-2026-74454] = "cpe-stable-backport: Backported in 6.6.151" + +CVE_STATUS[CVE-2026-74455] = "cpe-stable-backport: Backported in 6.6.151" + +CVE_STATUS[CVE-2026-74456] = "cpe-stable-backport: Backported in 6.6.151" + +CVE_STATUS[CVE-2026-74457] = "cpe-stable-backport: Backported in 6.6.151" + +CVE_STATUS[CVE-2026-74458] = "cpe-stable-backport: Backported in 6.6.151" + +CVE_STATUS[CVE-2026-74459] = "cpe-stable-backport: Backported in 6.6.151" + +CVE_STATUS[CVE-2026-74460] = "cpe-stable-backport: Backported in 6.6.151" + +CVE_STATUS[CVE-2026-74461] = "cpe-stable-backport: Backported in 6.6.151" + +CVE_STATUS[CVE-2026-74462] = "fixed-version: only affects 6.14 onwards" + +CVE_STATUS[CVE-2026-74463] = "cpe-stable-backport: Backported in 6.6.151" + +CVE_STATUS[CVE-2026-74464] = "cpe-stable-backport: Backported in 6.6.151" + +CVE_STATUS[CVE-2026-74465] = "cpe-stable-backport: Backported in 6.6.151" + +# CVE-2026-74466 needs backporting (fixed from 7.2) + +CVE_STATUS[CVE-2026-74467] = "cpe-stable-backport: Backported in 6.6.151" + +CVE_STATUS[CVE-2026-74468] = "cpe-stable-backport: Backported in 6.6.151" + +CVE_STATUS[CVE-2026-74469] = "cpe-stable-backport: Backported in 6.6.151" + +CVE_STATUS[CVE-2026-74470] = "cpe-stable-backport: Backported in 6.6.151" + +CVE_STATUS[CVE-2026-74471] = "cpe-stable-backport: Backported in 6.6.151" + +CVE_STATUS[CVE-2026-74472] = "cpe-stable-backport: Backported in 6.6.151" + +CVE_STATUS[CVE-2026-74473] = "cpe-stable-backport: Backported in 6.6.151" + +# CVE-2026-74474 may need backporting (fixed from 6.6.153) + +CVE_STATUS[CVE-2026-74475] = "cpe-stable-backport: Backported in 6.6.151" + +# CVE-2026-74476 may need backporting (fixed from 6.6.153) + +CVE_STATUS[CVE-2026-74477] = "fixed-version: only affects 6.13 onwards" + +CVE_STATUS[CVE-2026-74478] = "cpe-stable-backport: Backported in 6.6.151" + +# CVE-2026-74479 may need backporting (fixed from 6.6.153) + +CVE_STATUS[CVE-2026-74480] = "cpe-stable-backport: Backported in 6.6.151" + +CVE_STATUS[CVE-2026-74481] = "cpe-stable-backport: Backported in 6.6.151" + +CVE_STATUS[CVE-2026-74482] = "cpe-stable-backport: Backported in 6.6.151" + +CVE_STATUS[CVE-2026-74483] = "fixed-version: only affects 6.7 onwards" + +CVE_STATUS[CVE-2026-74484] = "fixed-version: only affects 6.7 onwards" + +CVE_STATUS[CVE-2026-74485] = "cpe-stable-backport: Backported in 6.6.151" + +CVE_STATUS[CVE-2026-74486] = "fixed-version: only affects 6.14 onwards" + +# CVE-2026-74487 may need backporting (fixed from 6.6.153) + +CVE_STATUS[CVE-2026-74488] = "cpe-stable-backport: Backported in 6.6.151" + +CVE_STATUS[CVE-2026-74489] = "fixed-version: only affects 7.1 onwards" + +CVE_STATUS[CVE-2026-74490] = "cpe-stable-backport: Backported in 6.6.151" + +CVE_STATUS[CVE-2026-74491] = "fixed-version: only affects 6.13 onwards" + +CVE_STATUS[CVE-2026-74492] = "cpe-stable-backport: Backported in 6.6.151" + +CVE_STATUS[CVE-2026-74493] = "cpe-stable-backport: Backported in 6.6.151" + +# CVE-2026-74494 may need backporting (fixed from 6.6.153) + +CVE_STATUS[CVE-2026-74495] = "cpe-stable-backport: Backported in 6.6.151" + +# CVE-2026-74496 needs backporting (fixed from 7.2) + +CVE_STATUS[CVE-2026-74497] = "cpe-stable-backport: Backported in 6.6.151" + +CVE_STATUS[CVE-2026-74498] = "cpe-stable-backport: Backported in 6.6.151" + +CVE_STATUS[CVE-2026-74499] = "cpe-stable-backport: Backported in 6.6.151" + +CVE_STATUS[CVE-2026-74500] = "fixed-version: only affects 6.10.14 onwards" + +CVE_STATUS[CVE-2026-74501] = "cpe-stable-backport: Backported in 6.6.151" + +CVE_STATUS[CVE-2026-74502] = "cpe-stable-backport: Backported in 6.6.151" + +CVE_STATUS[CVE-2026-74503] = "fixed-version: only affects 6.12.94 onwards" + +CVE_STATUS[CVE-2026-74504] = "fixed-version: only affects 6.12 onwards" + +CVE_STATUS[CVE-2026-74505] = "cpe-stable-backport: Backported in 6.6.151" + +# CVE-2026-74506 needs backporting (fixed from 7.2) + +CVE_STATUS[CVE-2026-74507] = "cpe-stable-backport: Backported in 6.6.151" + +CVE_STATUS[CVE-2026-74508] = "cpe-stable-backport: Backported in 6.6.151" + +# CVE-2026-74509 may need backporting (fixed from 6.6.154) + +CVE_STATUS[CVE-2026-74510] = "cpe-stable-backport: Backported in 6.6.151" + +CVE_STATUS[CVE-2026-74512] = "cpe-stable-backport: Backported in 6.6.151" + +CVE_STATUS[CVE-2026-74513] = "fixed-version: only affects 6.10 onwards" + +# CVE-2026-74514 may need backporting (fixed from 6.6.152) + +CVE_STATUS[CVE-2026-74515] = "cpe-stable-backport: Backported in 6.6.151" + +CVE_STATUS[CVE-2026-74516] = "cpe-stable-backport: Backported in 6.6.151" + +CVE_STATUS[CVE-2026-74517] = "fixed-version: only affects 6.12.41 onwards" + +CVE_STATUS[CVE-2026-74518] = "cpe-stable-backport: Backported in 6.6.151" + +CVE_STATUS[CVE-2026-74519] = "cpe-stable-backport: Backported in 6.6.151" + +CVE_STATUS[CVE-2026-74520] = "fixed-version: only affects 6.11 onwards" + +# CVE-2026-74521 needs backporting (fixed from 7.2) + +CVE_STATUS[CVE-2026-74522] = "cpe-stable-backport: Backported in 6.6.151" + +CVE_STATUS[CVE-2026-74523] = "cpe-stable-backport: Backported in 6.6.151" + +CVE_STATUS[CVE-2026-74524] = "fixed-version: only affects 6.11 onwards" + +CVE_STATUS[CVE-2026-74525] = "cpe-stable-backport: Backported in 6.6.151" + +CVE_STATUS[CVE-2026-74526] = "fixed-version: only affects 7.0 onwards" + +# CVE-2026-74527 needs backporting (fixed from 7.2) + +CVE_STATUS[CVE-2026-74528] = "fixed-version: only affects 6.19 onwards" + +CVE_STATUS[CVE-2026-74529] = "fixed-version: only affects 6.12.28 onwards" + +CVE_STATUS[CVE-2026-74530] = "fixed-version: only affects 6.12.28 onwards" + +CVE_STATUS[CVE-2026-74531] = "cpe-stable-backport: Backported in 6.6.151" + +CVE_STATUS[CVE-2026-74532] = "cpe-stable-backport: Backported in 6.6.151" + +CVE_STATUS[CVE-2026-74533] = "fixed-version: only affects 6.11.11 onwards" + +CVE_STATUS[CVE-2026-74534] = "fixed-version: only affects 6.11.11 onwards" + +CVE_STATUS[CVE-2026-74535] = "fixed-version: only affects 6.12.2 onwards" + +# CVE-2026-74536 needs backporting (fixed from 7.2) + +# CVE-2026-74537 needs backporting (fixed from 7.2) + +CVE_STATUS[CVE-2026-74538] = "fixed-version: only affects 6.8.9 onwards" + +CVE_STATUS[CVE-2026-74539] = "fixed-version: only affects 6.16 onwards" + +CVE_STATUS[CVE-2026-74540] = "cpe-stable-backport: Backported in 6.6.151" + +CVE_STATUS[CVE-2026-74541] = "cpe-stable-backport: Backported in 6.6.151" + +CVE_STATUS[CVE-2026-74542] = "fixed-version: only affects 6.12 onwards" + +# CVE-2026-74543 needs backporting (fixed from 7.2) + +# CVE-2026-74544 needs backporting (fixed from 7.2) + +CVE_STATUS[CVE-2026-74545] = "fixed-version: only affects 6.12 onwards" + +CVE_STATUS[CVE-2026-74546] = "cpe-stable-backport: Backported in 6.6.151" + +CVE_STATUS[CVE-2026-74547] = "cpe-stable-backport: Backported in 6.6.151" + +CVE_STATUS[CVE-2026-74548] = "cpe-stable-backport: Backported in 6.6.151" + +CVE_STATUS[CVE-2026-74549] = "cpe-stable-backport: Backported in 6.6.151" + +CVE_STATUS[CVE-2026-74550] = "cpe-stable-backport: Backported in 6.6.151" + +CVE_STATUS[CVE-2026-74551] = "cpe-stable-backport: Backported in 6.6.151" + +CVE_STATUS[CVE-2026-74552] = "cpe-stable-backport: Backported in 6.6.151" + +CVE_STATUS[CVE-2026-74553] = "cpe-stable-backport: Backported in 6.6.151" + +CVE_STATUS[CVE-2026-74554] = "fixed-version: only affects 7.0 onwards" + +CVE_STATUS[CVE-2026-74555] = "cpe-stable-backport: Backported in 6.6.151" + +CVE_STATUS[CVE-2026-74556] = "cpe-stable-backport: Backported in 6.6.151" + +CVE_STATUS[CVE-2026-74557] = "cpe-stable-backport: Backported in 6.6.151" + +# CVE-2026-74558 needs backporting (fixed from 7.2) + +# CVE-2026-74559 needs backporting (fixed from 7.2) + +# CVE-2026-74560 needs backporting (fixed from 7.2) + +CVE_STATUS[CVE-2026-74561] = "fixed-version: only affects 6.16 onwards" + +CVE_STATUS[CVE-2026-74562] = "fixed-version: only affects 6.16 onwards" + +CVE_STATUS[CVE-2026-74563] = "cpe-stable-backport: Backported in 6.6.151" + +CVE_STATUS[CVE-2026-74564] = "cpe-stable-backport: Backported in 6.6.151" + +# CVE-2026-74565 needs backporting (fixed from 7.2) + +CVE_STATUS[CVE-2026-74566] = "cpe-stable-backport: Backported in 6.6.151" + +CVE_STATUS[CVE-2026-74567] = "cpe-stable-backport: Backported in 6.6.151" + +CVE_STATUS[CVE-2026-74568] = "fixed-version: only affects 6.17 onwards" + +CVE_STATUS[CVE-2026-74569] = "cpe-stable-backport: Backported in 6.6.151" + +CVE_STATUS[CVE-2026-74570] = "fixed-version: only affects 7.1 onwards" + +# CVE-2026-74571 needs backporting (fixed from 7.2) + +CVE_STATUS[CVE-2026-74572] = "cpe-stable-backport: Backported in 6.6.151" + +CVE_STATUS[CVE-2026-74573] = "fixed-version: only affects 6.13 onwards" + +CVE_STATUS[CVE-2026-74574] = "cpe-stable-backport: Backported in 6.6.151" + +CVE_STATUS[CVE-2026-74575] = "cpe-stable-backport: Backported in 6.6.151" + +CVE_STATUS[CVE-2026-74576] = "fixed-version: only affects 6.10 onwards" + +CVE_STATUS[CVE-2026-74577] = "cpe-stable-backport: Backported in 6.6.151" + +CVE_STATUS[CVE-2026-74578] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-74579] = "cpe-stable-backport: Backported in 6.6.151" + +# CVE-2026-74580 may need backporting (fixed from 6.6.152) + +CVE_STATUS[CVE-2026-74581] = "cpe-stable-backport: Backported in 6.6.151" + +# CVE-2026-74582 may need backporting (fixed from 6.6.152) + +# CVE-2026-74583 may need backporting (fixed from 6.6.152) + +CVE_STATUS[CVE-2026-74584] = "cpe-stable-backport: Backported in 6.6.144" + +# CVE-2026-74585 may need backporting (fixed from 6.6.152) + +# CVE-2026-74586 may need backporting (fixed from 6.6.152) + +# CVE-2026-74587 may need backporting (fixed from 6.6.152) + +# CVE-2026-74588 may need backporting (fixed from 6.6.152) + +# CVE-2026-74589 may need backporting (fixed from 6.6.152) + +CVE_STATUS[CVE-2026-74590] = "fixed-version: only affects 6.8 onwards" + +CVE_STATUS[CVE-2026-74591] = "fixed-version: only affects 6.15 onwards" + +# CVE-2026-74592 needs backporting (fixed from 7.2) + +CVE_STATUS[CVE-2026-74593] = "fixed-version: only affects 6.18 onwards" + +# CVE-2026-74594 may need backporting (fixed from 6.6.152) + +# CVE-2026-74595 may need backporting (fixed from 6.6.152) + +CVE_STATUS[CVE-2026-74596] = "fixed-version: only affects 7.0 onwards" + +# CVE-2026-74597 may need backporting (fixed from 6.6.152) + +# CVE-2026-74598 may need backporting (fixed from 6.6.152) + +# CVE-2026-74599 may need backporting (fixed from 6.6.153) + +# CVE-2026-74600 needs backporting (fixed from 7.2) + +# CVE-2026-74601 may need backporting (fixed from 6.6.153) + +CVE_STATUS[CVE-2026-74602] = "fixed-version: only affects 6.8 onwards" + +# CVE-2026-74603 may need backporting (fixed from 6.6.152) + +# CVE-2026-74604 may need backporting (fixed from 6.6.152) + +# CVE-2026-74605 may need backporting (fixed from 6.7) + +# CVE-2026-74606 may need backporting (fixed from 6.6.152) + +# CVE-2026-74607 may need backporting (fixed from 6.6.153) + +# CVE-2026-74608 may need backporting (fixed from 6.6.152) + +# CVE-2026-74609 may need backporting (fixed from 6.6.152) + +# CVE-2026-74610 may need backporting (fixed from 6.6.152) + +# CVE-2026-74611 needs backporting (fixed from 7.2) + +# CVE-2026-74612 may need backporting (fixed from 6.6.152) + +# CVE-2026-74613 may need backporting (fixed from 6.6.152) + +# CVE-2026-74614 may need backporting (fixed from 6.6.152) + +# CVE-2026-74615 may need backporting (fixed from 6.6.152) + +# CVE-2026-74616 may need backporting (fixed from 6.6.152) + +CVE_STATUS[CVE-2026-74617] = "fixed-version: only affects 6.18 onwards" + +CVE_STATUS[CVE-2026-74618] = "fixed-version: only affects 6.7 onwards" + +# CVE-2026-74619 may need backporting (fixed from 6.6.152) + +# CVE-2026-74620 may need backporting (fixed from 6.6.152) + +# CVE-2026-74621 may need backporting (fixed from 6.6.152) + +# CVE-2026-74622 may need backporting (fixed from 6.6.152) + +# CVE-2026-74623 may need backporting (fixed from 6.6.152) + +# CVE-2026-74624 may need backporting (fixed from 6.6.152) + +# CVE-2026-74625 may need backporting (fixed from 6.6.152) + +# CVE-2026-74626 may need backporting (fixed from 6.6.154) + +CVE_STATUS[CVE-2026-74627] = "fixed-version: only affects 6.16 onwards" + +# CVE-2026-74628 may need backporting (fixed from 6.6.153) + +CVE_STATUS[CVE-2026-74629] = "fixed-version: only affects 6.18 onwards" + +# CVE-2026-74630 may need backporting (fixed from 6.6.152) + +# CVE-2026-74631 may need backporting (fixed from 6.6.152) + +# CVE-2026-74632 may need backporting (fixed from 6.6.153) + +CVE_STATUS[CVE-2026-74633] = "fixed-version: only affects 6.14 onwards" + +CVE_STATUS[CVE-2026-74634] = "fixed-version: only affects 6.8 onwards" + +# CVE-2026-74635 may need backporting (fixed from 6.6.152) + +# CVE-2026-74636 may need backporting (fixed from 6.6.152) + +# CVE-2026-74637 may need backporting (fixed from 6.6.154) + +# CVE-2026-74638 may need backporting (fixed from 6.7) + +CVE_STATUS[CVE-2026-74639] = "fixed-version: only affects 6.18.39 onwards" + +CVE_STATUS[CVE-2026-74640] = "fixed-version: only affects 6.14 onwards" + +# CVE-2026-74641 may need backporting (fixed from 6.6.152) + +# CVE-2026-74642 may need backporting (fixed from 6.6.152) + +CVE_STATUS[CVE-2026-74643] = "fixed-version: only affects 6.17 onwards" + +CVE_STATUS[CVE-2026-74644] = "fixed-version: only affects 6.12.44 onwards" + +CVE_STATUS[CVE-2026-74645] = "fixed-version: only affects 7.0 onwards" + +# CVE-2026-74646 may need backporting (fixed from 6.6.152) + +# CVE-2026-74647 may need backporting (fixed from 6.6.152) + +# CVE-2026-74648 may need backporting (fixed from 6.6.152) + +# CVE-2026-74649 may need backporting (fixed from 6.6.152) + +# CVE-2026-74650 may need backporting (fixed from 6.6.152) + +# CVE-2026-74651 may need backporting (fixed from 6.6.152) + +CVE_STATUS[CVE-2026-74652] = "fixed-version: only affects 6.14 onwards" + +# CVE-2026-74653 needs backporting (fixed from 7.2) + +# CVE-2026-74654 may need backporting (fixed from 6.6.152) + +# CVE-2026-74655 may need backporting (fixed from 6.6.154) + +# CVE-2026-74656 may need backporting (fixed from 6.6.152) + +# CVE-2026-74657 may need backporting (fixed from 6.6.152) + +# CVE-2026-74658 may need backporting (fixed from 6.6.152) + +# CVE-2026-74659 may need backporting (fixed from 6.6.152) + +# CVE-2026-74660 may need backporting (fixed from 6.6.152) + +# CVE-2026-74661 may need backporting (fixed from 6.6.152) + +# CVE-2026-74662 may need backporting (fixed from 6.6.154) + +# CVE-2026-74663 may need backporting (fixed from 6.6.152) + +# CVE-2026-74664 may need backporting (fixed from 6.6.152) + +CVE_STATUS[CVE-2026-74665] = "fixed-version: only affects 6.9 onwards" + +# CVE-2026-74666 may need backporting (fixed from 6.6.152) + +# CVE-2026-74667 may need backporting (fixed from 6.6.152) + +# CVE-2026-74668 may need backporting (fixed from 6.6.152) + +# CVE-2026-74669 may need backporting (fixed from 6.6.152) + +# CVE-2026-74670 may need backporting (fixed from 6.6.152) + +# CVE-2026-74671 may need backporting (fixed from 6.6.152) + +# CVE-2026-74672 may need backporting (fixed from 6.6.153) + +# CVE-2026-74673 may need backporting (fixed from 6.6.152) + +CVE_STATUS[CVE-2026-74674] = "fixed-version: only affects 7.0 onwards" + +# CVE-2026-74675 may need backporting (fixed from 6.6.152) + +# CVE-2026-74676 may need backporting (fixed from 6.6.152) + +# CVE-2026-74677 needs backporting (fixed from 7.2) + +# CVE-2026-74678 may need backporting (fixed from 6.6.152) + +# CVE-2026-74679 may need backporting (fixed from 6.6.152) + +# CVE-2026-74680 may need backporting (fixed from 6.6.152) + +CVE_STATUS[CVE-2026-74681] = "fixed-version: only affects 6.18 onwards" + +# CVE-2026-74682 may need backporting (fixed from 6.6.152) + +# CVE-2026-74683 may need backporting (fixed from 6.6.152) + +# CVE-2026-74684 needs backporting (fixed from 7.2) + +CVE_STATUS[CVE-2026-74685] = "fixed-version: only affects 6.9 onwards" + +CVE_STATUS[CVE-2026-74686] = "fixed-version: only affects 6.19 onwards" + +# CVE-2026-74687 needs backporting (fixed from 7.2) + +# CVE-2026-74688 may need backporting (fixed from 6.6.152) + +# CVE-2026-74689 may need backporting (fixed from 6.6.152) + +# CVE-2026-74690 needs backporting (fixed from 7.2) + +# CVE-2026-74691 may need backporting (fixed from 6.6.152) + +# CVE-2026-74692 may need backporting (fixed from 6.6.152) + +# CVE-2026-74693 may need backporting (fixed from 6.6.152) + +# CVE-2026-74694 may need backporting (fixed from 6.6.152) + +# CVE-2026-74695 needs backporting (fixed from 7.2) + +# CVE-2026-74696 may need backporting (fixed from 6.6.152) + +# CVE-2026-74697 may need backporting (fixed from 6.6.152) + +CVE_STATUS[CVE-2026-74698] = "fixed-version: only affects 6.17 onwards" + +CVE_STATUS[CVE-2026-74699] = "fixed-version: only affects 7.0 onwards" + +# CVE-2026-74700 may need backporting (fixed from 6.6.152) + +# CVE-2026-74701 may need backporting (fixed from 6.6.152) + +CVE_STATUS[CVE-2026-74702] = "fixed-version: only affects 6.15 onwards" + +CVE_STATUS[CVE-2026-74703] = "fixed-version: only affects 6.15 onwards" + +# CVE-2026-74704 may need backporting (fixed from 6.6.152) + +# CVE-2026-74705 may need backporting (fixed from 6.6.152) + +CVE_STATUS[CVE-2026-74706] = "fixed-version: only affects 6.19 onwards" + +CVE_STATUS[CVE-2026-74707] = "fixed-version: only affects 6.14.2 onwards" + +CVE_STATUS[CVE-2026-74708] = "fixed-version: only affects 6.14.2 onwards" + +CVE_STATUS[CVE-2026-74709] = "fixed-version: only affects 6.14.2 onwards" + +CVE_STATUS[CVE-2026-74710] = "fixed-version: only affects 6.8 onwards" + +# CVE-2026-74711 needs backporting (fixed from 7.2) + +CVE_STATUS[CVE-2026-74712] = "fixed-version: only affects 6.12 onwards" + +# CVE-2026-74713 needs backporting (fixed from 7.2) + +# CVE-2026-74714 may need backporting (fixed from 6.6.152) + +# CVE-2026-74715 needs backporting (fixed from 7.2) + +CVE_STATUS[CVE-2026-74716] = "fixed-version: only affects 6.16 onwards" + +# CVE-2026-74717 may need backporting (fixed from 6.6.152) + +# CVE-2026-74718 may need backporting (fixed from 6.6.152) + +# CVE-2026-74719 may need backporting (fixed from 6.6.152) + +# CVE-2026-74720 may need backporting (fixed from 6.6.152) + +CVE_STATUS[CVE-2026-74721] = "fixed-version: only affects 6.16 onwards" + +# CVE-2026-74722 may need backporting (fixed from 6.6.152) + +# CVE-2026-74723 needs backporting (fixed from 7.2) + +# CVE-2026-74724 may need backporting (fixed from 6.6.152) + +# CVE-2026-74725 needs backporting (fixed from 7.2) + +# CVE-2026-74726 may need backporting (fixed from 6.6.152) + +CVE_STATUS[CVE-2026-74727] = "fixed-version: only affects 6.16 onwards" + +CVE_STATUS[CVE-2026-74728] = "fixed-version: only affects 6.9 onwards" + +# CVE-2026-74729 needs backporting (fixed from 7.2) + +# CVE-2026-74730 may need backporting (fixed from 6.6.152) + +CVE_STATUS[CVE-2026-74731] = "fixed-version: only affects 7.1 onwards" + +# CVE-2026-74732 needs backporting (fixed from 7.2) + +# CVE-2026-74733 may need backporting (fixed from 6.7) + +# CVE-2026-74734 needs backporting (fixed from 7.2) + +# CVE-2026-74735 needs backporting (fixed from 7.2) + +# CVE-2026-74736 may need backporting (fixed from 6.6.153) + +# CVE-2026-74737 may need backporting (fixed from 6.6.153) + +CVE_STATUS[CVE-2026-74738] = "fixed-version: only affects 6.14 onwards" + +# CVE-2026-74739 may need backporting (fixed from 6.6.153) + +# CVE-2026-74740 may need backporting (fixed from 6.6.153) + +CVE_STATUS[CVE-2026-74741] = "fixed-version: only affects 6.16 onwards" + +CVE_STATUS[CVE-2026-74742] = "fixed-version: only affects 6.12.61 onwards" + +# CVE-2026-74743 may need backporting (fixed from 6.6.153) + +# CVE-2026-74744 may need backporting (fixed from 6.6.153) + +CVE_STATUS[CVE-2026-74745] = "fixed-version: only affects 6.15 onwards" + +# CVE-2026-74746 may need backporting (fixed from 6.6.153) + +# CVE-2026-74747 needs backporting (fixed from 7.2) + +# CVE-2026-74748 may need backporting (fixed from 6.6.153) + +CVE_STATUS[CVE-2026-74749] = "fixed-version: only affects 7.1 onwards" + +CVE_STATUS[CVE-2026-74750] = "fixed-version: only affects 6.16 onwards" + +CVE_STATUS[CVE-2026-74751] = "fixed-version: only affects 7.1 onwards" + +# CVE-2026-74752 needs backporting (fixed from 7.2) + +# CVE-2026-74753 may need backporting (fixed from 6.6.156) + +# CVE-2026-74754 needs backporting (fixed from 7.2) + +CVE_STATUS[CVE-2026-80519] = "fixed-version: only affects 6.16 onwards" + +CVE_STATUS[CVE-2026-80520] = "fixed-version: only affects 6.16 onwards" + +# CVE-2026-80521 may need backporting (fixed from 6.7) + +CVE_STATUS[CVE-2026-80522] = "fixed-version: only affects 6.10 onwards" + +CVE_STATUS[CVE-2026-80523] = "fixed-version: only affects 7.0 onwards" + +CVE_STATUS[CVE-2026-80524] = "fixed-version: only affects 6.18 onwards" + +CVE_STATUS[CVE-2026-80525] = "fixed-version: only affects 6.10 onwards" + +# CVE-2026-80526 may need backporting (fixed from 6.6.153) + +# CVE-2026-80527 may need backporting (fixed from 6.6.153) + +# CVE-2026-80528 may need backporting (fixed from 6.6.153) + +# CVE-2026-80529 may need backporting (fixed from 6.6.153) + +CVE_STATUS[CVE-2026-80530] = "fixed-version: only affects 6.10 onwards" + +CVE_STATUS[CVE-2026-80531] = "fixed-version: only affects 6.10 onwards" + +CVE_STATUS[CVE-2026-80532] = "fixed-version: only affects 6.10 onwards" + +CVE_STATUS[CVE-2026-80533] = "fixed-version: only affects 6.10 onwards" + +# CVE-2026-80534 may need backporting (fixed from 6.6.153) + +CVE_STATUS[CVE-2026-80535] = "fixed-version: only affects 6.10 onwards" + +# CVE-2026-80536 may need backporting (fixed from 6.6.154) + +CVE_STATUS[CVE-2026-80537] = "fixed-version: only affects 6.14 onwards" + +CVE_STATUS[CVE-2026-80538] = "fixed-version: only affects 6.13 onwards" + +# CVE-2026-80539 may need backporting (fixed from 6.6.153) + +# CVE-2026-80540 may need backporting (fixed from 6.6.153) + +# CVE-2026-80541 may need backporting (fixed from 6.6.153) + +CVE_STATUS[CVE-2026-80542] = "fixed-version: only affects 6.18 onwards" + +CVE_STATUS[CVE-2026-80543] = "fixed-version: only affects 7.1 onwards" + +CVE_STATUS[CVE-2026-80544] = "fixed-version: only affects 7.1 onwards" + +CVE_STATUS[CVE-2026-80545] = "fixed-version: only affects 7.1 onwards" + +CVE_STATUS[CVE-2026-80546] = "fixed-version: only affects 7.1 onwards" + +# CVE-2026-80547 may need backporting (fixed from 6.6.154) + +# CVE-2026-80548 may need backporting (fixed from 6.6.153) + +# CVE-2026-80549 may need backporting (fixed from 6.6.153) + +# CVE-2026-80550 may need backporting (fixed from 6.6.153) + +# CVE-2026-80551 may need backporting (fixed from 6.6.154) + +# CVE-2026-80552 may need backporting (fixed from 6.6.153) + +# CVE-2026-80553 may need backporting (fixed from 6.6.153) + +# CVE-2026-80554 may need backporting (fixed from 6.6.153) + +# CVE-2026-80555 may need backporting (fixed from 6.6.154) + +# CVE-2026-80556 needs backporting (fixed from 7.2) + +# CVE-2026-80557 may need backporting (fixed from 6.6.154) + +# CVE-2026-80558 may need backporting (fixed from 6.6.153) + +# CVE-2026-80559 may need backporting (fixed from 6.6.153) + +# CVE-2026-80560 may need backporting (fixed from 6.6.153) + +# CVE-2026-80561 may need backporting (fixed from 6.6.153) + +# CVE-2026-80562 may need backporting (fixed from 6.6.154) + +CVE_STATUS[CVE-2026-80563] = "fixed-version: only affects 6.11 onwards" + +CVE_STATUS[CVE-2026-80564] = "fixed-version: only affects 6.17 onwards" + +# CVE-2026-80565 may need backporting (fixed from 6.6.153) + +# CVE-2026-80566 may need backporting (fixed from 6.6.153) + +# CVE-2026-80567 may need backporting (fixed from 6.6.153) + +# CVE-2026-80568 may need backporting (fixed from 6.6.153) + +# CVE-2026-80569 may need backporting (fixed from 6.6.153) + +# CVE-2026-80570 may need backporting (fixed from 6.6.153) + +CVE_STATUS[CVE-2026-80571] = "fixed-version: only affects 6.16 onwards" + +# CVE-2026-80572 may need backporting (fixed from 6.6.154) + +# CVE-2026-80573 may need backporting (fixed from 6.6.153) + +# CVE-2026-80574 may need backporting (fixed from 6.6.153) + +CVE_STATUS[CVE-2026-80575] = "fixed-version: only affects 6.11 onwards" + +# CVE-2026-80576 needs backporting (fixed from 7.2) + +CVE_STATUS[CVE-2026-80577] = "fixed-version: only affects 6.10 onwards" + +# CVE-2026-80578 may need backporting (fixed from 6.6.153) + +# CVE-2026-80579 needs backporting (fixed from 7.2) + +# CVE-2026-80580 needs backporting (fixed from 7.2) + +# CVE-2026-80581 may need backporting (fixed from 6.6.154) + +CVE_STATUS[CVE-2026-80582] = "fixed-version: only affects 7.0 onwards" + +# CVE-2026-80583 may need backporting (fixed from 6.6.154) + +# CVE-2026-80584 may need backporting (fixed from 6.6.153) + +# CVE-2026-80585 may need backporting (fixed from 6.6.153) + +# CVE-2026-80586 may need backporting (fixed from 6.6.153) + +# CVE-2026-80587 may need backporting (fixed from 6.6.153) + +CVE_STATUS[CVE-2026-80588] = "fixed-version: only affects 6.18.35 onwards" + +# CVE-2026-80589 may need backporting (fixed from 6.6.153) + +# CVE-2026-80590 may need backporting (fixed from 6.6.155) + +CVE_STATUS[CVE-2026-80591] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-80592] = "fixed-version: only affects 6.16 onwards" + +CVE_STATUS[CVE-2026-80593] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-80594] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-80595] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-80596] = "fixed-version: only affects 6.11 onwards" + +CVE_STATUS[CVE-2026-80597] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-80598] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-80599] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-80600] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-80601] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-80602] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-80603] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-80604] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-80605] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-80606] = "fixed-version: only affects 6.18 onwards" + +# CVE-2026-80607 needs backporting (fixed from 7.2) + +CVE_STATUS[CVE-2026-80608] = "fixed-version: only affects 7.1 onwards" + +CVE_STATUS[CVE-2026-80609] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-80610] = "fixed-version: only affects 6.19 onwards" + +# CVE-2026-80611 needs backporting (fixed from 7.2) + +CVE_STATUS[CVE-2026-80612] = "fixed-version: only affects 6.19 onwards" + +CVE_STATUS[CVE-2026-80613] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-80614] = "fixed-version: only affects 6.12 onwards" + +CVE_STATUS[CVE-2026-80615] = "fixed-version: only affects 7.0 onwards" + +# CVE-2026-80616 needs backporting (fixed from 7.2) + +CVE_STATUS[CVE-2026-80617] = "fixed-version: only affects 6.18.33 onwards" + +CVE_STATUS[CVE-2026-80618] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-80619] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-80620] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-80621] = "fixed-version: only affects 6.15 onwards" + +CVE_STATUS[CVE-2026-80622] = "cpe-stable-backport: Backported in 6.6.145" + +# CVE-2026-80623 needs backporting (fixed from 7.2) + +CVE_STATUS[CVE-2026-80624] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-80625] = "fixed-version: only affects 6.19 onwards" + +CVE_STATUS[CVE-2026-80626] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-80627] = "cpe-stable-backport: Backported in 6.6.145" + +# CVE-2026-80628 needs backporting (fixed from 7.2) + +# CVE-2026-80629 needs backporting (fixed from 7.2) + +CVE_STATUS[CVE-2026-80630] = "cpe-stable-backport: Backported in 6.6.145" + +# CVE-2026-80631 needs backporting (fixed from 7.2) + +CVE_STATUS[CVE-2026-80632] = "fixed-version: only affects 7.1 onwards" + +CVE_STATUS[CVE-2026-80633] = "fixed-version: only affects 7.1 onwards" + +# CVE-2026-80634 needs backporting (fixed from 7.2) + +CVE_STATUS[CVE-2026-80635] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-80636] = "cpe-stable-backport: Backported in 6.6.145" + +# CVE-2026-80637 needs backporting (fixed from 7.2) + +CVE_STATUS[CVE-2026-80638] = "fixed-version: only affects 6.19 onwards" + +CVE_STATUS[CVE-2026-80639] = "fixed-version: only affects 6.19 onwards" + +CVE_STATUS[CVE-2026-80640] = "fixed-version: only affects 6.15 onwards" + +CVE_STATUS[CVE-2026-80641] = "fixed-version: only affects 7.0 onwards" + +CVE_STATUS[CVE-2026-80642] = "fixed-version: only affects 7.0 onwards" + +# CVE-2026-80643 needs backporting (fixed from 7.2) + +CVE_STATUS[CVE-2026-80644] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-80645] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-80646] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-80647] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-80648] = "fixed-version: only affects 6.13 onwards" + +CVE_STATUS[CVE-2026-80649] = "cpe-stable-backport: Backported in 6.6.145" + +# CVE-2026-80650 needs backporting (fixed from 7.2) + +CVE_STATUS[CVE-2026-80651] = "fixed-version: only affects 6.19 onwards" + +CVE_STATUS[CVE-2026-80652] = "cpe-stable-backport: Backported in 6.6.145" + +# CVE-2026-80653 needs backporting (fixed from 7.2) + +# CVE-2026-80654 needs backporting (fixed from 7.2) + +CVE_STATUS[CVE-2026-80655] = "fixed-version: only affects 6.11 onwards" + +CVE_STATUS[CVE-2026-80656] = "fixed-version: only affects 7.1 onwards" + +CVE_STATUS[CVE-2026-80657] = "fixed-version: only affects 6.14 onwards" + +CVE_STATUS[CVE-2026-80658] = "fixed-version: only affects 6.18 onwards" + +CVE_STATUS[CVE-2026-80659] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-80660] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-80661] = "fixed-version: only affects 6.15 onwards" + +# CVE-2026-80662 needs backporting (fixed from 7.2) + +CVE_STATUS[CVE-2026-80663] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-80664] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-80665] = "fixed-version: only affects 6.16 onwards" + +CVE_STATUS[CVE-2026-80666] = "fixed-version: only affects 6.13 onwards" + +CVE_STATUS[CVE-2026-80667] = "fixed-version: only affects 6.7 onwards" + +# CVE-2026-80668 may need backporting (fixed from 6.7) + +CVE_STATUS[CVE-2026-80669] = "cpe-stable-backport: Backported in 6.6.145" + +# CVE-2026-80670 needs backporting (fixed from 7.2) + +# CVE-2026-80671 needs backporting (fixed from 7.2) + +CVE_STATUS[CVE-2026-80672] = "fixed-version: only affects 7.1 onwards" + +CVE_STATUS[CVE-2026-80673] = "fixed-version: only affects 7.1 onwards" + +CVE_STATUS[CVE-2026-80674] = "fixed-version: only affects 7.1 onwards" + +CVE_STATUS[CVE-2026-80675] = "fixed-version: only affects 6.18 onwards" + +# CVE-2026-80676 needs backporting (fixed from 7.2) + +CVE_STATUS[CVE-2026-80677] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-80678] = "cpe-stable-backport: Backported in 6.6.151" + +CVE_STATUS[CVE-2026-80679] = "cpe-stable-backport: Backported in 6.6.151" + +CVE_STATUS[CVE-2026-80680] = "cpe-stable-backport: Backported in 6.6.151" + +CVE_STATUS[CVE-2026-80681] = "cpe-stable-backport: Backported in 6.6.151" + +CVE_STATUS[CVE-2026-80682] = "fixed-version: only affects 7.1 onwards" + +CVE_STATUS[CVE-2026-80683] = "fixed-version: only affects 6.13 onwards" + +CVE_STATUS[CVE-2026-80684] = "cpe-stable-backport: Backported in 6.6.151" + +CVE_STATUS[CVE-2026-80685] = "fixed-version: only affects 6.15 onwards" + +# CVE-2026-80686 may need backporting (fixed from 6.6.153) + +CVE_STATUS[CVE-2026-80687] = "fixed-version: only affects 6.17 onwards" + +CVE_STATUS[CVE-2026-80688] = "fixed-version: only affects 6.13.11 onwards" + +# CVE-2026-80689 needs backporting (fixed from 7.2) + +CVE_STATUS[CVE-2026-80690] = "fixed-version: only affects 6.19 onwards" + +CVE_STATUS[CVE-2026-80691] = "cpe-stable-backport: Backported in 6.6.151" + +# CVE-2026-80692 may need backporting (fixed from 6.7) + +CVE_STATUS[CVE-2026-80693] = "fixed-version: only affects 6.7 onwards" + +# CVE-2026-80694 needs backporting (fixed from 7.2) + +# CVE-2026-80695 needs backporting (fixed from 7.2) + +CVE_STATUS[CVE-2026-80696] = "fixed-version: only affects 6.9 onwards" + +CVE_STATUS[CVE-2026-80697] = "fixed-version: only affects 7.0 onwards" + +# CVE-2026-80698 needs backporting (fixed from 7.2) + +CVE_STATUS[CVE-2026-80699] = "fixed-version: only affects 6.19 onwards" + +CVE_STATUS[CVE-2026-80700] = "cpe-stable-backport: Backported in 6.6.151" + +CVE_STATUS[CVE-2026-80701] = "fixed-version: only affects 6.16 onwards" + +CVE_STATUS[CVE-2026-80702] = "cpe-stable-backport: Backported in 6.6.151" + +CVE_STATUS[CVE-2026-80703] = "cpe-stable-backport: Backported in 6.6.151" + +# CVE-2026-80704 needs backporting (fixed from 7.2) + +CVE_STATUS[CVE-2026-80705] = "fixed-version: only affects 6.11 onwards" + +CVE_STATUS[CVE-2026-80706] = "cpe-stable-backport: Backported in 6.6.151" + +CVE_STATUS[CVE-2026-80707] = "cpe-stable-backport: Backported in 6.6.151" + +# CVE-2026-80708 may need backporting (fixed from 6.6.152) + +CVE_STATUS[CVE-2026-80709] = "cpe-stable-backport: Backported in 6.6.151" + +CVE_STATUS[CVE-2026-80710] = "cpe-stable-backport: Backported in 6.6.151" + +CVE_STATUS[CVE-2026-80711] = "fixed-version: only affects 6.7 onwards" + +CVE_STATUS[CVE-2026-80712] = "fixed-version: only affects 6.15 onwards" + +CVE_STATUS[CVE-2026-80713] = "fixed-version: only affects 7.0 onwards" + +CVE_STATUS[CVE-2026-80714] = "cpe-stable-backport: Backported in 6.6.151" + +# CVE-2026-80715 may need backporting (fixed from 6.6.153) + +CVE_STATUS[CVE-2026-80716] = "cpe-stable-backport: Backported in 6.6.151" + +CVE_STATUS[CVE-2026-80717] = "cpe-stable-backport: Backported in 6.6.151" + +CVE_STATUS[CVE-2026-80718] = "cpe-stable-backport: Backported in 6.6.151" + +CVE_STATUS[CVE-2026-80719] = "fixed-version: only affects 7.1 onwards" + +CVE_STATUS[CVE-2026-80720] = "fixed-version: only affects 6.15 onwards" + +CVE_STATUS[CVE-2026-80721] = "fixed-version: only affects 6.11.11 onwards" + +CVE_STATUS[CVE-2026-80722] = "cpe-stable-backport: Backported in 6.6.151" + +CVE_STATUS[CVE-2026-80723] = "fixed-version: only affects 6.12.13 onwards" + +CVE_STATUS[CVE-2026-80724] = "fixed-version: only affects 6.13 onwards" + +# CVE-2026-80725 may need backporting (fixed from 6.6.154) + +# CVE-2026-80726 may need backporting (fixed from 6.6.152) + +CVE_STATUS[CVE-2026-80727] = "fixed-version: only affects 6.8 onwards" + +# CVE-2026-80728 may need backporting (fixed from 6.6.152) + +CVE_STATUS[CVE-2026-80729] = "fixed-version: only affects 6.15 onwards" + +# CVE-2026-80730 may need backporting (fixed from 6.6.152) + +# CVE-2026-80731 may need backporting (fixed from 6.6.152) + +# CVE-2026-80732 may need backporting (fixed from 6.6.152) + +# CVE-2026-80733 may need backporting (fixed from 6.6.152) + +CVE_STATUS[CVE-2026-80734] = "fixed-version: only affects 6.14.6 onwards" + +CVE_STATUS[CVE-2026-80735] = "fixed-version: only affects 6.16 onwards" + +CVE_STATUS[CVE-2026-80736] = "fixed-version: only affects 6.9 onwards" + +# CVE-2026-80737 may need backporting (fixed from 6.6.154) + +# CVE-2026-80738 needs backporting (fixed from 7.2) + +# CVE-2026-80739 may need backporting (fixed from 6.6.152) + +CVE_STATUS[CVE-2026-80740] = "fixed-version: only affects 6.14 onwards" + +CVE_STATUS[CVE-2026-80741] = "fixed-version: only affects 6.14 onwards" + +# CVE-2026-80742 may need backporting (fixed from 6.6.153) + +# CVE-2026-80743 may need backporting (fixed from 6.6.153) + +# CVE-2026-80744 may need backporting (fixed from 6.6.153) + +CVE_STATUS[CVE-2026-80745] = "fixed-version: only affects 6.19 onwards" + +CVE_STATUS[CVE-2026-80746] = "fixed-version: only affects 7.1 onwards" + +# CVE-2026-80747 needs backporting (fixed from 7.2) + +CVE_STATUS[CVE-2026-80748] = "fixed-version: only affects 6.17 onwards" + +CVE_STATUS[CVE-2026-80749] = "fixed-version: only affects 6.11 onwards" + +CVE_STATUS[CVE-2026-80750] = "fixed-version: only affects 6.18 onwards" + +CVE_STATUS[CVE-2026-80751] = "fixed-version: only affects 6.19 onwards" + +# CVE-2026-80752 may need backporting (fixed from 6.6.153) + +CVE_STATUS[CVE-2026-80753] = "fixed-version: only affects 6.16 onwards" + +# CVE-2026-80754 may need backporting (fixed from 6.6.153) + +# CVE-2026-80755 needs backporting (fixed from 7.2) + +# CVE-2026-80756 may need backporting (fixed from 6.6.153) + +# CVE-2026-80757 may need backporting (fixed from 6.6.153) + +CVE_STATUS[CVE-2026-80758] = "fixed-version: only affects 6.16 onwards" + +CVE_STATUS[CVE-2026-80759] = "fixed-version: only affects 6.12 onwards" + +CVE_STATUS[CVE-2026-80760] = "fixed-version: only affects 6.13 onwards" + +# CVE-2026-80761 needs backporting (fixed from 7.3rc1) + +# CVE-2026-80762 may need backporting (fixed from 6.6.156) + +# CVE-2026-80763 may need backporting (fixed from 6.6.154) + +# CVE-2026-80764 may need backporting (fixed from 6.6.154) + +# CVE-2026-80765 may need backporting (fixed from 6.6.154) + +# CVE-2026-80766 may need backporting (fixed from 6.6.156) + +# CVE-2026-80767 may need backporting (fixed from 6.6.154) + +# CVE-2026-80768 may need backporting (fixed from 6.6.156) + +CVE_STATUS[CVE-2026-80769] = "fixed-version: only affects 7.0 onwards" + +# CVE-2026-80770 may need backporting (fixed from 6.6.156) + +# CVE-2026-80771 needs backporting (fixed from 7.3rc1) + +# CVE-2026-80772 may need backporting (fixed from 6.6.154) + +CVE_STATUS[CVE-2026-80773] = "fixed-version: only affects 7.1 onwards" + +CVE_STATUS[CVE-2026-80774] = "fixed-version: only affects 6.12.35 onwards" + +CVE_STATUS[CVE-2026-80775] = "fixed-version: only affects 6.17 onwards" + +CVE_STATUS[CVE-2026-80776] = "fixed-version: only affects 6.16 onwards" + +CVE_STATUS[CVE-2026-80777] = "fixed-version: only affects 6.16 onwards" + +CVE_STATUS[CVE-2026-80778] = "fixed-version: only affects 6.16 onwards" + +CVE_STATUS[CVE-2026-80779] = "fixed-version: only affects 6.9 onwards" + +# CVE-2026-80780 may need backporting (fixed from 6.6.156) + +# CVE-2026-80781 may need backporting (fixed from 6.6.154) + +# CVE-2026-80782 may need backporting (fixed from 6.6.154) + +# CVE-2026-80783 may need backporting (fixed from 6.6.156) + +# CVE-2026-80784 may need backporting (fixed from 6.6.154) + +# CVE-2026-80785 needs backporting (fixed from 7.2) + +# CVE-2026-80786 needs backporting (fixed from 7.2) + +CVE_STATUS[CVE-2026-80787] = "fixed-version: only affects 6.14 onwards" + +# CVE-2026-80788 may need backporting (fixed from 6.6.154) + +# CVE-2026-80789 may need backporting (fixed from 6.6.156) + +# CVE-2026-80790 may need backporting (fixed from 6.6.154) + +# CVE-2026-80791 may need backporting (fixed from 6.6.154) + +# CVE-2026-80792 may need backporting (fixed from 6.6.154) + +# CVE-2026-80793 may need backporting (fixed from 6.6.154) + +# CVE-2026-80794 may need backporting (fixed from 6.6.154) + +# CVE-2026-80795 may need backporting (fixed from 6.6.154) + +# CVE-2026-80796 may need backporting (fixed from 6.6.156) + +# CVE-2026-80797 may need backporting (fixed from 6.6.154) + +# CVE-2026-80798 may need backporting (fixed from 6.6.154) + +# CVE-2026-80799 may need backporting (fixed from 6.6.154) + +# CVE-2026-80800 may need backporting (fixed from 6.6.154) + +# CVE-2026-80801 may need backporting (fixed from 6.6.154) + +# CVE-2026-80802 may need backporting (fixed from 6.6.154) + +# CVE-2026-80803 may need backporting (fixed from 6.6.154) + +CVE_STATUS[CVE-2026-80804] = "fixed-version: only affects 7.0 onwards" + +# CVE-2026-80805 may need backporting (fixed from 6.6.154) + +# CVE-2026-80806 may need backporting (fixed from 6.6.156) + +# CVE-2026-80807 may need backporting (fixed from 6.6.156) + +# CVE-2026-80808 may need backporting (fixed from 6.6.154) + +# CVE-2026-80809 may need backporting (fixed from 6.6.154) + +CVE_STATUS[CVE-2026-80810] = "fixed-version: only affects 6.15 onwards" + +CVE_STATUS[CVE-2026-80811] = "fixed-version: only affects 6.15 onwards" + +# CVE-2026-80812 may need backporting (fixed from 6.6.154) + +CVE_STATUS[CVE-2026-80813] = "fixed-version: only affects 6.13 onwards" + +# CVE-2026-80814 may need backporting (fixed from 6.6.154) + +CVE_STATUS[CVE-2026-80815] = "fixed-version: only affects 6.10 onwards" + +CVE_STATUS[CVE-2026-80816] = "fixed-version: only affects 6.14 onwards" + +CVE_STATUS[CVE-2026-80817] = "fixed-version: only affects 6.13 onwards" + +CVE_STATUS[CVE-2026-80818] = "fixed-version: only affects 6.17 onwards" + +# CVE-2026-80819 may need backporting (fixed from 6.6.154) + +# CVE-2026-80820 needs backporting (fixed from 7.2) + +CVE_STATUS[CVE-2026-80821] = "fixed-version: only affects 6.14 onwards" + +CVE_STATUS[CVE-2026-80822] = "fixed-version: only affects 6.14 onwards" + +# CVE-2026-80823 may need backporting (fixed from 6.6.154) + +# CVE-2026-80824 may need backporting (fixed from 6.6.156) + +CVE_STATUS[CVE-2026-80825] = "fixed-version: only affects 6.7 onwards" + +# CVE-2026-80826 may need backporting (fixed from 6.6.156) + +# CVE-2026-80827 may need backporting (fixed from 6.6.156) + +# CVE-2026-80828 may need backporting (fixed from 6.6.156) + +# CVE-2026-80829 may need backporting (fixed from 6.6.156) + +# CVE-2026-80830 may need backporting (fixed from 6.6.156) + +# CVE-2026-80831 may need backporting (fixed from 6.6.156) + +# CVE-2026-80832 may need backporting (fixed from 6.6.156) + +# CVE-2026-80833 needs backporting (fixed from 7.3rc1) + +# CVE-2026-80834 needs backporting (fixed from 7.3rc1) + +CVE_STATUS[CVE-2026-80835] = "fixed-version: only affects 6.7 onwards" + +# CVE-2026-80836 needs backporting (fixed from 7.3rc1) + +# CVE-2026-80837 needs backporting (fixed from 7.3rc1) + +CVE_STATUS[CVE-2026-80838] = "fixed-version: only affects 6.7 onwards" + +CVE_STATUS[CVE-2026-80839] = "fixed-version: only affects 6.8 onwards" + +# CVE-2026-80840 may need backporting (fixed from 6.6.156) + +# CVE-2026-80841 needs backporting (fixed from 7.3rc1) + +# CVE-2026-80842 may need backporting (fixed from 6.6.156) + +# CVE-2026-80843 may need backporting (fixed from 6.6.156) + +# CVE-2026-80844 may need backporting (fixed from 6.6.156) + +CVE_STATUS[CVE-2026-80845] = "fixed-version: only affects 6.11 onwards" + +# CVE-2026-80846 may need backporting (fixed from 6.6.156) + +# CVE-2026-80847 needs backporting (fixed from 7.3rc1) + +# CVE-2026-80848 may need backporting (fixed from 6.6.156) + +CVE_STATUS[CVE-2026-80849] = "fixed-version: only affects 6.7 onwards" + +CVE_STATUS[CVE-2026-80850] = "fixed-version: only affects 6.7 onwards" + +# CVE-2026-80851 needs backporting (fixed from 7.3rc1) + +# CVE-2026-80852 may need backporting (fixed from 6.6.156) + +CVE_STATUS[CVE-2026-80853] = "fixed-version: only affects 7.2 onwards" + +# CVE-2026-80854 may need backporting (fixed from 6.6.156) + +# CVE-2026-80855 may need backporting (fixed from 6.6.156) + +# CVE-2026-80856 may need backporting (fixed from 6.6.156) + +CVE_STATUS[CVE-2026-80857] = "fixed-version: only affects 6.18.25 onwards" + +CVE_STATUS[CVE-2026-80858] = "fixed-version: only affects 6.14 onwards" + +CVE_STATUS[CVE-2026-80859] = "fixed-version: only affects 6.14 onwards" + +CVE_STATUS[CVE-2026-80860] = "fixed-version: only affects 6.12.96 onwards" + +# CVE-2026-80861 needs backporting (fixed from 7.3rc1) + +CVE_STATUS[CVE-2026-80862] = "fixed-version: only affects 6.12 onwards" + +# CVE-2026-80863 may need backporting (fixed from 6.6.156) + +# CVE-2026-80864 needs backporting (fixed from 7.3rc1) + +CVE_STATUS[CVE-2026-80865] = "cpe-stable-backport: Backported in 6.6.145" + +# CVE-2026-80866 needs backporting (fixed from 7.2) + +CVE_STATUS[CVE-2026-80867] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-80868] = "fixed-version: only affects 7.0 onwards" + +CVE_STATUS[CVE-2026-80869] = "fixed-version: only affects 7.1 onwards" + +CVE_STATUS[CVE-2026-80870] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-80871] = "fixed-version: only affects 6.18 onwards" + +# CVE-2026-80872 needs backporting (fixed from 7.2) + +CVE_STATUS[CVE-2026-80873] = "fixed-version: only affects 6.17 onwards" + +CVE_STATUS[CVE-2026-80874] = "fixed-version: only affects 6.19 onwards" + +CVE_STATUS[CVE-2026-80875] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-80876] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-80877] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-80878] = "fixed-version: only affects 6.8 onwards" + +CVE_STATUS[CVE-2026-80879] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-80880] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-80881] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-80882] = "fixed-version: only affects 6.12.91 onwards" + +CVE_STATUS[CVE-2026-80883] = "cpe-stable-backport: Backported in 6.6.145" + +# CVE-2026-80884 needs backporting (fixed from 7.2) + +CVE_STATUS[CVE-2026-80885] = "fixed-version: only affects 6.16 onwards" + +CVE_STATUS[CVE-2026-80886] = "cpe-stable-backport: Backported in 6.6.145" + +CVE_STATUS[CVE-2026-80887] = "cpe-stable-backport: Backported in 6.6.151" + +CVE_STATUS[CVE-2026-80888] = "cpe-stable-backport: Backported in 6.6.151" + +CVE_STATUS[CVE-2026-80889] = "cpe-stable-backport: Backported in 6.6.151" + +CVE_STATUS[CVE-2026-80890] = "cpe-stable-backport: Backported in 6.6.151" + +CVE_STATUS[CVE-2026-80891] = "cpe-stable-backport: Backported in 6.6.151" + +CVE_STATUS[CVE-2026-80892] = "cpe-stable-backport: Backported in 6.6.151" + +CVE_STATUS[CVE-2026-80893] = "cpe-stable-backport: Backported in 6.6.151" + +CVE_STATUS[CVE-2026-80894] = "fixed-version: only affects 6.12.24 onwards" + +CVE_STATUS[CVE-2026-80895] = "fixed-version: only affects 6.15 onwards" + +CVE_STATUS[CVE-2026-80896] = "fixed-version: only affects 6.15 onwards" + +CVE_STATUS[CVE-2026-80897] = "fixed-version: only affects 6.14 onwards" + +CVE_STATUS[CVE-2026-80898] = "fixed-version: only affects 6.14 onwards" + +CVE_STATUS[CVE-2026-80899] = "fixed-version: only affects 6.9 onwards" + +CVE_STATUS[CVE-2026-80900] = "fixed-version: only affects 6.19 onwards" + +CVE_STATUS[CVE-2026-80901] = "cpe-stable-backport: Backported in 6.6.151" + +CVE_STATUS[CVE-2026-80902] = "cpe-stable-backport: Backported in 6.6.151" + +CVE_STATUS[CVE-2026-80903] = "fixed-version: only affects 6.12.18 onwards" + +# CVE-2026-80904 may need backporting (fixed from 6.6.153) + +# CVE-2026-80905 needs backporting (fixed from 7.2) + +# CVE-2026-80906 may need backporting (fixed from 6.6.153) + +# CVE-2026-80907 may need backporting (fixed from 6.6.153) + +# CVE-2026-80908 may need backporting (fixed from 6.6.153) + +# CVE-2026-80909 may need backporting (fixed from 6.6.153) + +# CVE-2026-80910 may need backporting (fixed from 6.6.153) + +# CVE-2026-80911 may need backporting (fixed from 6.6.153) + +# CVE-2026-80912 may need backporting (fixed from 6.6.153) + +# CVE-2026-80913 may need backporting (fixed from 6.6.153) + +# CVE-2026-80914 needs backporting (fixed from 7.3rc1) + +CVE_STATUS[CVE-2026-80915] = "fixed-version: only affects 6.11.3 onwards" + +# CVE-2026-80916 may need backporting (fixed from 6.6.154) + +# CVE-2026-80917 may need backporting (fixed from 6.6.154) + +# CVE-2026-80918 may need backporting (fixed from 6.6.154) + +CVE_STATUS[CVE-2026-80919] = "fixed-version: only affects 7.1 onwards" + +# CVE-2026-80920 needs backporting (fixed from 7.3rc1) + +# CVE-2026-80921 may need backporting (fixed from 6.6.156) + +CVE_STATUS[CVE-2026-80922] = "fixed-version: only affects 6.7 onwards" + +# CVE-2026-80923 may need backporting (fixed from 6.6.156) + +CVE_STATUS[CVE-2026-80924] = "fixed-version: only affects 6.15 onwards" + +# CVE-2026-80925 needs backporting (fixed from 7.3rc1) From patchwork Fri Sep 11 22:14:56 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 98066 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 6FC15C88E4D for ; Fri, 11 Sep 2026 22:15:48 +0000 (UTC) Received: from mail-wm2-f12.google.com (mail-wm2-f12.google.com [74.125.225.140]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.50971.1789164946266791435 for ; Fri, 11 Sep 2026 15:15:46 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=y+BtR1bx; spf=pass (domain: smile.fr, ip: 74.125.225.140, mailfrom: yoann.congal@smile.fr) Received: by mail-wm2-f12.google.com with SMTP id 5b1f17b1804b1-49d097b4939so1471735e9.0 for ; Fri, 11 Sep 2026 15:15:46 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1789164944; x=1789769744; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=yaopoIeE/hIwqJaTaQEE0BPVMa5mcd1EYCSb+HLhDNQ=; b=y+BtR1bxcdNIjcO2r67p9hx7MKe8Csf2WNCPfahQNtGfwBLX5W7QeRuyQbHZIJcmzo F0kTMjv9OCAociOwOAaCdbZOGmBoDGgHXk9kvTAPP7+h/cySHUekjMG+zxR8ihksrqb7 XLyW33C0FNJhC177UDz92meceJoqidBuf2rp8= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1789164944; x=1789769744; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=yaopoIeE/hIwqJaTaQEE0BPVMa5mcd1EYCSb+HLhDNQ=; b=Nce9hATXVjX99t1mXlEG26Yuh9GkMgvMYPZ632nsrxkEvuSDHSr9AfGwRR9Sp6MfxO +qDnUCKHbkKOO4XjkpK5qUBSDXyDB3TswbcG9CDv6twac/g+CP3/t50zYC8XaVmjdEv1 QmYz7RqkW8ph+veYFKxIcgcB4QSzo8wz3C7CG9TpO4eLmwtvpTNvzJUDMkbJamnpvQbY Wsyfgk3E5TEoaag/uFthOcAov7K+sloiVXhI+I54pFcUWzrFbpB2xT+h/LdkyLlcZGG8 IhI7cazlKx2tqZjukJRSyKPHGMns9VI99KminvjrZLyXQHXeVcSZ2VpGyPrJmTECwCU6 yelg== X-Gm-Message-State: AFuF++mYfdCws1H4tYCa7tkWiRl+Z321fFlrI2Mktl9aUBAlzUSf+EK/ 8CbNaRQg2yilfY9EG78GkJYZBxYivXz+iHVAPCjzVVG10sWkfMivTd967DRN5OXlSY6B40JjrPY m9RX6OAg= X-Gm-Gg: AYBFou2OfBZJFLU8GHemFrii1CKFX9jHEzpiw7QQaMkydmGL4Dra9y8EA8nwfJ+Rvih 0ovye9tPF3Ogkt7vpm4vDKXhWLQsu1lL+7gG1fr1Lv4KsJ3BQqGGmgg++U9o2MZzbZlTdVWzNmb CE49nUpx9enMEEFLR3FE5t1RVSz1HrFSCYNO6TMLG2dB+pzyAYJ16QzHlhzc4+S7VDO2apXliV+ A6DJS8Rp5T5NflCEfOU/2fEdYqWO4qqhJCc7yRhS2J5l2eFvTKCBIRYiU/vrzdRu4cp4FXaQD8u geePLzydMKmqB1KOH5+7Z8VLCsaGIigBC0peTGtqbOl2lH0K0zd89TvS4RU2AVXPhUH0aBYyhEK nwLDwI1uwyVDqgrHVtWBJ5yBStFKa6+lYvtoXUbGf/M2eoee+UbSWnHPG9Cvl5y9OOomNMIF1Vc yu+nK3TYSHfheCvMebeu11jub7A9qFfJvVqOJNLcFfB3Fpe3KSSE05si8rCJClZwP0dUp9W2BPE EVPZe5Rx4Fn72zzRSjGkqjG9iocSG3GN5zl0RAA3lzm7oRhRXhx0y4VJfXdAMT1U0mzBsmCB6IX 471j7xlDyA== X-Received: by 2002:a05:600d:8646:20b0:49d:1fd8:b874 with SMTP id 5b1f17b1804b1-49e619c079cmr51882855e9.19.1789164944545; Fri, 11 Sep 2026 15:15:44 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-49e6c566bdbsm8434045e9.11.2026.09.11.15.15.44 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Fri, 11 Sep 2026 15:15:44 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][scarthgap 02/13] p11-kit: Fix CVE-2026-18938 Date: Sat, 12 Sep 2026 00:14:56 +0200 Message-ID: <65db9618c3e80ca3fb6d87bea1153de554144165.1789163914.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Fri, 11 Sep 2026 22:15:48 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/245671 From: Vijay Anusuri Pick patch according to [2] [1] https://nvd.nist.gov/vuln/detail/cve-2026-18938 [2] https://ubuntu.com/security/CVE-2026-18938 Signed-off-by: Vijay Anusuri Signed-off-by: Yoann Congal --- .../p11-kit/files/CVE-2026-18938.patch | 52 +++++++++++++++++++ .../recipes-support/p11-kit/p11-kit_0.25.3.bb | 1 + 2 files changed, 53 insertions(+) create mode 100644 meta/recipes-support/p11-kit/files/CVE-2026-18938.patch diff --git a/meta/recipes-support/p11-kit/files/CVE-2026-18938.patch b/meta/recipes-support/p11-kit/files/CVE-2026-18938.patch new file mode 100644 index 00000000000..9439a4da318 --- /dev/null +++ b/meta/recipes-support/p11-kit/files/CVE-2026-18938.patch @@ -0,0 +1,52 @@ +From 3e64244e538550c6a7fcf826fa8c50a4604416dc Mon Sep 17 00:00:00 2001 +From: Zoltan Fridrich +Date: Thu, 6 Aug 2026 11:39:22 +0200 +Subject: [PATCH] rpc: guard against overflow when decoding nested attributes + (CVE-2026-18938) + +A local attacker, or one with equivalent access to a reachable RPC channel, +could exploit an integer overflow vulnerability. By sending specially crafted +messages, the attacker can cause the system to miscalculate memory allocation +for nested attributes. This leads to a memory corruption issue, specifically +a heap out-of-bounds write, which can crash the p11-kit RPC parsing process, +resulting in a Denial of Service (DoS). This vulnerability is only exploitable +on 32 bit systems. + +Signed-off-by: Zoltan Fridrich + +Upstream-Status: Backport [https://github.com/p11-glue/p11-kit/commit/3e64244e538550c6a7fcf826fa8c50a4604416dc] +CVE: CVE-2026-18938 +Signed-off-by: Vijay Anusuri +--- + p11-kit/rpc-message.c | 8 ++++++++ + 1 file changed, 8 insertions(+) + +diff --git a/p11-kit/rpc-message.c b/p11-kit/rpc-message.c +index d6f0aad..105a4f1 100644 +--- a/p11-kit/rpc-message.c ++++ b/p11-kit/rpc-message.c +@@ -1160,6 +1160,10 @@ p11_rpc_buffer_get_attribute_array_value (p11_buffer *buffer, + if (!p11_rpc_buffer_get_uint32 (buffer, offset, &count)) + return false; + ++ /* Guard against overflow */ ++ if (count != 0 && (SIZE_MAX / count) < sizeof (CK_ATTRIBUTE)) ++ return false; ++ + if (!value) { + memset (&temp, 0, sizeof (CK_ATTRIBUTE)); + attr = &temp; +@@ -1191,6 +1195,10 @@ p11_rpc_buffer_get_mechanism_type_array_value (p11_buffer *buffer, + if (!p11_rpc_buffer_get_uint32 (buffer, offset, &count)) + return false; + ++ /* Guard against overflow */ ++ if (count != 0 && (SIZE_MAX / count) < sizeof (CK_MECHANISM_TYPE)) ++ return false; ++ + if (!value) { + memset (&temp, 0, sizeof (CK_MECHANISM_TYPE)); + mech = &temp; +-- +2.43.0 + diff --git a/meta/recipes-support/p11-kit/p11-kit_0.25.3.bb b/meta/recipes-support/p11-kit/p11-kit_0.25.3.bb index 6c5b82e6bc9..ca10bbc6acf 100644 --- a/meta/recipes-support/p11-kit/p11-kit_0.25.3.bb +++ b/meta/recipes-support/p11-kit/p11-kit_0.25.3.bb @@ -13,6 +13,7 @@ DEPENDS:append = "${@' glib-2.0' if d.getVar('GTKDOC_ENABLED') == 'True' else '' SRC_URI = "gitsm://github.com/p11-glue/p11-kit;branch=master;protocol=https \ file://fix-parallel-build-failures.patch \ file://CVE-2026-13757.patch \ + file://CVE-2026-18938.patch \ " SRCREV = "917e02a3211dabbdea4b079cb598581dce84fda1" S = "${WORKDIR}/git" From patchwork Fri Sep 11 22:14:57 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 98067 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 463CBC88E53 for ; Fri, 11 Sep 2026 22:15:49 +0000 (UTC) Received: from mail-wm1-f42.google.com (mail-wm1-f42.google.com [209.85.128.42]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.50972.1789164946730923285 for ; Fri, 11 Sep 2026 15:15:47 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=b/pwxh8V; spf=pass (domain: smile.fr, ip: 209.85.128.42, mailfrom: yoann.congal@smile.fr) Received: by mail-wm1-f42.google.com with SMTP id 5b1f17b1804b1-49b0d8bc2aaso16454615e9.0 for ; Fri, 11 Sep 2026 15:15:46 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1789164945; x=1789769745; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=QlRudoMFiU+Tx+y0IeKlPFN9bAsxkJ8nDiqEALC/1wE=; b=b/pwxh8V8B5/MXY8EyM95FFbaio3cMgmOn7+hbEZRIt9aN8S/1Gv4qyxwKAzsg6nDD URqPFc/FAp0B4odXdFT+BgolbkTc20aibVmsocXgx60YV3y7I8PmnEYLt6dp9IKOa6EZ zJs6sWYunA7CKSc+L5SE7PmERvoe0oiqd1xJQ= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1789164945; x=1789769745; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=QlRudoMFiU+Tx+y0IeKlPFN9bAsxkJ8nDiqEALC/1wE=; b=gEDluhBGQ7h55w+VJZhQZpul5DRG7wxmuIGC8/rdhXz814Sr0B8zet4HNdvYqp+Tlu lxNrFT35ljc3h427mwyJs2swXPn2Z5I2H1BKPBjUAZxJXlVklFaqoV7B+WL4yzAp9JkI DSApcGZK/ETMdMK9dJo7o4EASdCx9TkZE0DbfEXid4kIGzE7//+ZN2YVne2RliP6IQpw O2jjAAy5yXwmWn20scL97YGGt4hbgpeocn+axZloSgly0CqSbhKNT5aDxO+y4pwVv//B pxWAAo9Jbxj34nShbsQ077gtf5bKmPt/7rLyo8W32K6aKdCMfYo5lOGyQQC4H+L7S42K zdtw== X-Gm-Message-State: AFuF++nUi8pj2PGX00EUCKIgd6+8XdAfPlNMtqJEdxg5hrRU7btuyxmo L1GtbY4OVV6EUzh7/xqYieQcYQ06pbySAhTF09t4lbLg6AmFUymXxusKu6T/ZwEYFQGMWeLADFg 0FG7TMnc= X-Gm-Gg: AYBFou1lZH0bEyx5gKtLzAZaDaq9pvlznQ5N/zfWH2GR/eUxHVZmuNIIrdoDQhHteOJ GoFBtYWp8wpgNXbXqw4g5p9NQ8mvdvvfgWM7TkZKFtjVRK27htqhsDkFlSihdysaZ3cbZJ3rxYT wjnyttNxlaIRUP0tUlU8NEUDOF80nl+Ti0dPr1pptsO0U1wICdmmrapDIGEwpLWDEfl416XE1Uw X449Xqp6BLWt0skQqIcp9itJKDmFeh93aSbFFrXGDkCI88mjXOMaOFTTbqj9tV9u3VTnGVodnrf Ohf/SjlHAZCqw6eyl2A4GMdgEAufOdBhBPWv13kGtpZuphEnHkpmgkYWN7/8SpA/vxg6+M4g/46 u9mhANCe+um1DThDqiXG1B1pwtiO7gAxBYo/PyZdV0XXrczG6GnU49ZRw5durRgX6+ZxkC7QJB+ fDd45XsylaZjLFYBPPZdGDEmWoYltsdnTxYOJxQtz4Hy0r4YQu+K5IYNpaQP6pbSlFEKSSkp6Dc eVFd5z5ZI7OP9fsyuAk8Crqij1PA0uRlScYWejh6QufMh6TNJWNk3bnvo17Zw+RhnrVMrtLrfU= X-Received: by 2002:a05:600c:3513:b0:49e:6b62:edbd with SMTP id 5b1f17b1804b1-49e6b62ee31mr11959235e9.1.1789164944953; Fri, 11 Sep 2026 15:15:44 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-49e6c566bdbsm8434045e9.11.2026.09.11.15.15.44 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Fri, 11 Sep 2026 15:15:44 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][scarthgap 03/13] openssl: upgrade 3.5.7 -> 3.5.8 Date: Sat, 12 Sep 2026 00:14:57 +0200 Message-ID: X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Fri, 11 Sep 2026 22:15:49 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/245672 From: Peter Marko Release information [1]: OpenSSL 3.5.8 is a security patch release. The most severe CVE fixed in this release is Moderate. This release incorporates the following bug fixes and mitigations: * Fixed QUIC server being able to trigger double free when processing INITIAL packet. (CVE-2026-18798) * Fixed heap buffer overflow in CMS key unwrapping. (CVE-2026-63072) * Fixed invalid pointer dereference in CMP server via crafted protectionAlg. (CVE-2026-63076) * Fixed unbounded memory growth in QUIC server incoming channel queue. (CVE-2026-14456) * Fixed RPK server signature algorithm selection being able to dereference a missing certificate. (CVE-2026-14457) * Fixed excessive memory use buffering DTLS records for a future epoch. (CVE-2026-54874) * Fixed untrusted Sender DN being used as a format string in CMP response validation. (CVE-2026-63073) * Fixed CMP indefinite cache growth of extraCerts. (CVE-2026-63074) * Fixed QUIC ACK-only packet retention being able to cause memory exhaustion. (CVE-2026-63075) * Fixed possibility of AEAD forgeries with empty ciphertext when using EVP_Cipher(). (CVE-2026-75803) * Fixed checking of authentication tags for empty ciphertexts for AEAD ciphers in CCM cipher mode. [1] https://github.com/openssl/openssl/blob/openssl-3.5/NEWS.md#major-changes-between-openssl-357-and-openssl-358-25-aug-2026 Signed-off-by: Peter Marko Signed-off-by: Mathieu Dubois-Briand Signed-off-by: Richard Purdie (cherry picked from commit db81c1a42a0f552d9a8ec124f004ae2063d58c33) Signed-off-by: Yoann Congal --- .../openssl/{openssl_3.5.7.bb => openssl_3.5.8.bb} | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) rename meta/recipes-connectivity/openssl/{openssl_3.5.7.bb => openssl_3.5.8.bb} (99%) diff --git a/meta/recipes-connectivity/openssl/openssl_3.5.7.bb b/meta/recipes-connectivity/openssl/openssl_3.5.8.bb similarity index 99% rename from meta/recipes-connectivity/openssl/openssl_3.5.7.bb rename to meta/recipes-connectivity/openssl/openssl_3.5.8.bb index 0b8e8afec81..be52e228f10 100644 --- a/meta/recipes-connectivity/openssl/openssl_3.5.7.bb +++ b/meta/recipes-connectivity/openssl/openssl_3.5.8.bb @@ -19,7 +19,7 @@ SRC_URI:append:class-nativesdk = " \ file://environment.d-openssl.sh \ " -SRC_URI[sha256sum] = "a8c0d28a529ca480f9f36cf5792e2cd21984552a3c8e4aa11a24aa31aeac98e8" +SRC_URI[sha256sum] = "a8f84a39918ec6415ce765d9b429d313ba97b8143169c172e734b9514464f5b2" inherit lib_package multilib_header multilib_script ptest perlnative manpages MULTILIB_SCRIPTS = "${PN}-bin:${bindir}/c_rehash" From patchwork Fri Sep 11 22:14:58 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 98070 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 96C13C88E5A for ; Fri, 11 Sep 2026 22:15:49 +0000 (UTC) Received: from mail-wm2-f13.google.com (mail-wm2-f13.google.com [74.125.225.141]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.50973.1789164947289885629 for ; Fri, 11 Sep 2026 15:15:47 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=xnaN/F3p; spf=pass (domain: smile.fr, ip: 74.125.225.141, mailfrom: yoann.congal@smile.fr) Received: by mail-wm2-f13.google.com with SMTP id 5b1f17b1804b1-49d1fb0cf5eso2896455e9.3 for ; Fri, 11 Sep 2026 15:15:47 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1789164945; x=1789769745; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=gsFYN+pcI7hDCK/JVE0Viq/lnthADiPRHWoQhvTPfIQ=; b=xnaN/F3pQdtbMBwymMbPmKaPM4YAQmBgIjSUuJoYePGbZjWNlRehqD4+e/nNMr9d3J 3L3M/nS2zCskxqjGQ/v2VO1MibRRvmwOCYHPr2AqeONsUuYjRpRVzKITppmh8s4Y0EJ0 W65a1EsxWjWlCiLSSkAofX19Xr3a7h83rpe8c= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1789164945; x=1789769745; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=gsFYN+pcI7hDCK/JVE0Viq/lnthADiPRHWoQhvTPfIQ=; b=gKtXTWzLnSbJ+XEkm99TScyTlZOyFXMJYilC7g5J+CpZhIs4dQkus69uBOoAD66/jh ZLGzU0KRGnWrSYPlv4Usx6iGoNBEZfIZq8Hm1BTUlWoLqo6lNFAXJv9SsBHYQxwCM3Lp YxZBc2Y+FP1p9TQRY+5wQ9uf531w/qkQUeZMd6xIt7GYImdpSVFBaroH2sUch46xGLpe 6oU/bEVSeudxUMZPjtKaqkmnkNfMvOwjoEDnk9szTiTatKwzYUGNwZVREB3Xaf609z2x 4mBECra3GlEpaic9nesKW0rxAAO1Ck+bdup6iAHcIGEGdURnkZkT84dN0P/faeZPGCo3 2v5Q== X-Gm-Message-State: AFuF++nW89l/OMjDgbWRSNikuWWdrFk3Dtk0+Y0T6qvisbXFMl9PPPXR dvDpuTvyFcH1nOXV+jqHK05AED2UdeiLr+8QfT2Awq0d/kkwR8yNqjZa6rl4HnIPaz73NGqAy0N 6qOMgLTo= X-Gm-Gg: AYBFou2g7Uptxb/6UwAWrz1oY33xFx3FCOZVhrQWwxWPPmc6lkKiE5FbrwF9OgkPMUr GqcTdhwmGD27YoD095y+GQJW+NLn6cBS2LFObTOAHaIt/k1T/Mj3aOYYuLc55fRgfrLqwQXTdqg 9MDeWL553/2jM+o2sgByUZ2je1dSy6fr92pE602nzwYH1mqfh6/NNH2KdJmZUsra5bowAYy6lP+ bvvEr+YkB99StVNK/Aqz3INBLy+5l6LXHFawbmGnDdNQkqF7XvOifk85y9l89Z6Oj3zJ1b1pyOQ elRyZBHwDg7h4VSAiXmVL5p04mAjF9/ESbNrN8RlSX9gx19a1lJYOK/vKXJ+z+59XWLfPR8MEa3 UqiTAaNuAivvyOcxAlDygcsn53kTYlfGSyZPoqlQm59eWEs+3Ws6ZPRz5Iq5htgiDivKoLb4BHf nNbgqfcnBzZ/YlAOP0WitizZFYcUzXbkoeTesZI3nlC7eIxXFYl58WJpT0iSTUkfgvhaucCN53s G7zNC6sUP2lG14KociE22IQI+FBFZLF8B/Thg9dD6zv31RDqYoh97cjX54SaPyADcGMilCNm2M= X-Received: by 2002:a05:600c:1d08:b0:49d:2450:68ac with SMTP id 5b1f17b1804b1-49e619b57admr155574515e9.5.1789164945439; Fri, 11 Sep 2026 15:15:45 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-49e6c566bdbsm8434045e9.11.2026.09.11.15.15.45 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Fri, 11 Sep 2026 15:15:45 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][scarthgap 04/13] python3-pip: Fix CVE-2026-8643 Date: Sat, 12 Sep 2026 00:14:58 +0200 Message-ID: <2c276677d619bc6205872eb2b5a9948a4605d8ea.1789163914.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Fri, 11 Sep 2026 22:15:49 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/245673 From: Hetvi Thakar Apply the primary upstream fix referenced in [4] with commit [1]. Then apply the two follow-up regression-fix commits [2] and [3]. The primary fix rejects entry-point names that escape the configured scripts directory. The follow-up fixes handle doubled-slash roots and reuse the existing directory-containment helper. [1] https://github.com/pypa/pip/commit/8eb178480bd1a2b223f509fc430796b265158dfb [2] https://github.com/pypa/pip/commit/7ff8bdd81ec5edca2bebf78ad8506dda710d6af5 [3] https://github.com/pypa/pip/commit/fa7854f6b37113a2c4698cdde902e1fcc9bebdd5 [4] https://github.com/advisories/GHSA-wf93-45jw-7689 Signed-off-by: Hetvi Thakar Signed-off-by: Yoann Congal --- .../CVE-2026-8643-regression_p1.patch | 34 ++++++++ .../CVE-2026-8643-regression_p2.patch | 69 ++++++++++++++++ .../python/python3-pip/CVE-2026-8643.patch | 79 +++++++++++++++++++ .../python/python3-pip_24.0.bb | 3 + 4 files changed, 185 insertions(+) create mode 100644 meta/recipes-devtools/python/python3-pip/CVE-2026-8643-regression_p1.patch create mode 100644 meta/recipes-devtools/python/python3-pip/CVE-2026-8643-regression_p2.patch create mode 100644 meta/recipes-devtools/python/python3-pip/CVE-2026-8643.patch diff --git a/meta/recipes-devtools/python/python3-pip/CVE-2026-8643-regression_p1.patch b/meta/recipes-devtools/python/python3-pip/CVE-2026-8643-regression_p1.patch new file mode 100644 index 00000000000..966a98f9d27 --- /dev/null +++ b/meta/recipes-devtools/python/python3-pip/CVE-2026-8643-regression_p1.patch @@ -0,0 +1,34 @@ +From 7cac095948e86d8a0e0e17de6b763727e9b051ac Mon Sep 17 00:00:00 2001 +From: Damian Shaw +Date: Mon, 18 May 2026 23:22:51 -0400 +Subject: [PATCH] Fix is_within_directory for doubled-slash roots + +CVE: CVE-2026-8643 +Upstream-Status: Backport [https://github.com/pypa/pip/commit/7ff8bdd81ec5edca2bebf78ad8506dda710d6af5] + +Backport Changes: +- Omit tests/unit/test_utils_unpacking.py because the pip 24.0 PyPI sdist used + by this recipe does not ship the upstream tests directory. + +(cherry picked from commit 7ff8bdd81ec5edca2bebf78ad8506dda710d6af5) +Signed-off-by: Hetvi Thakar +--- + src/pip/_internal/utils/unpacking.py | 3 +-- + 1 file changed, 1 insertion(+), 2 deletions(-) + +diff --git a/src/pip/_internal/utils/unpacking.py b/src/pip/_internal/utils/unpacking.py +index 0b26525fb..188f27e67 100644 +--- a/src/pip/_internal/utils/unpacking.py ++++ b/src/pip/_internal/utils/unpacking.py +@@ -81,8 +81,7 @@ def is_within_directory(directory: str, target: str) -> bool: + abs_directory = os.path.abspath(directory) + abs_target = os.path.abspath(target) + +- prefix = os.path.commonpath([abs_directory, abs_target]) +- return prefix == abs_directory ++ return abs_target == abs_directory or abs_target.startswith(abs_directory + os.sep) + + + def set_extracted_file_to_default_mode_plus_executable(path: str) -> None: +-- +2.35.6 diff --git a/meta/recipes-devtools/python/python3-pip/CVE-2026-8643-regression_p2.patch b/meta/recipes-devtools/python/python3-pip/CVE-2026-8643-regression_p2.patch new file mode 100644 index 00000000000..025b4fe929d --- /dev/null +++ b/meta/recipes-devtools/python/python3-pip/CVE-2026-8643-regression_p2.patch @@ -0,0 +1,69 @@ +From b77d10eee5805aea3055e434e08ad1f105bd330c Mon Sep 17 00:00:00 2001 +From: Damian +Date: Sun, 24 May 2026 14:54:47 -0400 +Subject: [PATCH] Use is_within_directory for entry point check + +CVE: CVE-2026-8643 +Upstream-Status: Backport [https://github.com/pypa/pip/commit/fa7854f6b37113a2c4698cdde902e1fcc9bebdd5] + +Backport Changes: +- Omit tests/unit/test_wheel.py because the pip 24.0 PyPI sdist used by this + recipe does not ship the upstream tests directory. + +(cherry picked from commit fa7854f6b37113a2c4698cdde902e1fcc9bebdd5) +Signed-off-by: Hetvi Thakar +--- + src/pip/_internal/operations/install/wheel.py | 18 ++---- + src/pip/_internal/utils/unpacking.py | 1 + + 2 files changed, 7 insertions(+), 12 deletions(-) + +diff --git a/src/pip/_internal/operations/install/wheel.py b/src/pip/_internal/operations/install/wheel.py +index 8a36a66ae..ce3e8efe6 100644 +--- a/src/pip/_internal/operations/install/wheel.py ++++ b/src/pip/_internal/operations/install/wheel.py +@@ -409,17 +409,6 @@ class MissingCallableSuffix(InstallationError): + ) + + +-def _script_within_dir(name: str, scripts_dir: str) -> bool: +- """Return whether script ``name`` resolves to a path inside the ``scripts_dir``. +- +- distlib joins the entry point name onto the scripts directory, so a name +- with path separators or ``..`` components can resolve elsewhere. +- """ +- root = os.path.normpath(scripts_dir) +- dest = os.path.normpath(os.path.join(scripts_dir, name)) +- return dest.startswith(root + os.sep) +- +- + def _raise_for_invalid_entrypoint(specification: str, scripts_dir: str) -> None: + entry = get_export_entry(specification) + if entry is None: +@@ -428,7 +417,12 @@ def _raise_for_invalid_entrypoint(specification: str, scripts_dir: str) -> None: + if entry.suffix is None: + raise MissingCallableSuffix(str(entry)) + +- if not _script_within_dir(entry.name, scripts_dir): ++ # distlib joins the entry point name onto the scripts directory, so a name ++ # with path separators or ``..`` components can resolve elsewhere. The script ++ # must resolve to a path strictly inside the scripts directory. ++ dest = os.path.join(scripts_dir, entry.name) ++ resolves_to_scripts_dir = os.path.abspath(dest) == os.path.abspath(scripts_dir) ++ if resolves_to_scripts_dir or not is_within_directory(scripts_dir, dest): + raise InstallationError( + f"Invalid script entry point name {entry.name!r}: the script " + f"would be installed outside the scripts directory ({scripts_dir})." +diff --git a/src/pip/_internal/utils/unpacking.py b/src/pip/_internal/utils/unpacking.py +index 188f27e67..14b7e846a 100644 +--- a/src/pip/_internal/utils/unpacking.py ++++ b/src/pip/_internal/utils/unpacking.py +@@ -77,6 +77,7 @@ def has_leading_dir(paths: Iterable[str]) -> bool: + def is_within_directory(directory: str, target: str) -> bool: + """ + Return true if the absolute path of target is within the directory ++ (including when target is equal to the directory). + """ + abs_directory = os.path.abspath(directory) + abs_target = os.path.abspath(target) +-- +2.35.6 diff --git a/meta/recipes-devtools/python/python3-pip/CVE-2026-8643.patch b/meta/recipes-devtools/python/python3-pip/CVE-2026-8643.patch new file mode 100644 index 00000000000..ad1124a4419 --- /dev/null +++ b/meta/recipes-devtools/python/python3-pip/CVE-2026-8643.patch @@ -0,0 +1,79 @@ +From fc0f7c683c372d66f2e2d6edc00909cc5f225f67 Mon Sep 17 00:00:00 2001 +From: Damian Shaw +Date: Wed, 20 May 2026 15:20:25 -0400 +Subject: [PATCH] Reject entry point names that escape scripts dir (#14000) + +* Reject entry point names that escape scripts dir + +* NEWS ENTRY + +CVE: CVE-2026-8643 +Upstream-Status: Backport [https://github.com/pypa/pip/commit/8eb178480bd1a2b223f509fc430796b265158dfb] + +Backport Changes: +- Omit tests/unit/test_wheel.py because the pip 24.0 PyPI sdist used by this + recipe does not ship the upstream tests directory. + +(cherry picked from commit 8eb178480bd1a2b223f509fc430796b265158dfb) +Signed-off-by: Hetvi Thakar +--- + news/14000.bugfix.rst | 2 + + src/pip/_internal/operations/install/wheel.py | 26 +++++++- + 2 files changed, 25 insertions(+), 3 deletions(-) + create mode 100644 news/14000.bugfix.rst + +diff --git a/news/14000.bugfix.rst b/news/14000.bugfix.rst +new file mode 100644 +index 000000000..3b86f1b3b +--- /dev/null ++++ b/news/14000.bugfix.rst +@@ -0,0 +1,2 @@ ++Reject ``console_scripts`` and ``gui_scripts`` entry points whose name would ++install a script outside the scripts directory. +diff --git a/src/pip/_internal/operations/install/wheel.py b/src/pip/_internal/operations/install/wheel.py +index f67180c9e..8a36a66ae 100644 +--- a/src/pip/_internal/operations/install/wheel.py ++++ b/src/pip/_internal/operations/install/wheel.py +@@ -409,17 +409,37 @@ class MissingCallableSuffix(InstallationError): + ) + + +-def _raise_for_invalid_entrypoint(specification: str) -> None: ++def _script_within_dir(name: str, scripts_dir: str) -> bool: ++ """Return whether script ``name`` resolves to a path inside the ``scripts_dir``. ++ ++ distlib joins the entry point name onto the scripts directory, so a name ++ with path separators or ``..`` components can resolve elsewhere. ++ """ ++ root = os.path.normpath(scripts_dir) ++ dest = os.path.normpath(os.path.join(scripts_dir, name)) ++ return dest.startswith(root + os.sep) ++ ++ ++def _raise_for_invalid_entrypoint(specification: str, scripts_dir: str) -> None: + entry = get_export_entry(specification) +- if entry is not None and entry.suffix is None: ++ if entry is None: ++ return ++ ++ if entry.suffix is None: + raise MissingCallableSuffix(str(entry)) + ++ if not _script_within_dir(entry.name, scripts_dir): ++ raise InstallationError( ++ f"Invalid script entry point name {entry.name!r}: the script " ++ f"would be installed outside the scripts directory ({scripts_dir})." ++ ) ++ + + class PipScriptMaker(ScriptMaker): + def make( + self, specification: str, options: Optional[Dict[str, Any]] = None + ) -> List[str]: +- _raise_for_invalid_entrypoint(specification) ++ _raise_for_invalid_entrypoint(specification, self.target_dir) + return super().make(specification, options) + + +-- +2.35.6 diff --git a/meta/recipes-devtools/python/python3-pip_24.0.bb b/meta/recipes-devtools/python/python3-pip_24.0.bb index 51fff41e257..d535e1f53d7 100644 --- a/meta/recipes-devtools/python/python3-pip_24.0.bb +++ b/meta/recipes-devtools/python/python3-pip_24.0.bb @@ -33,6 +33,9 @@ inherit pypi python_setuptools_build_meta SRC_URI += "file://no_shebang_mangling.patch \ file://CVE-2026-1703.patch \ + file://CVE-2026-8643.patch \ + file://CVE-2026-8643-regression_p1.patch \ + file://CVE-2026-8643-regression_p2.patch \ " SRC_URI[sha256sum] = "ea9bd1a847e8c5774a5777bb398c19e80bcd4e2aa16a4b301b718fe6f593aba2" From patchwork Fri Sep 11 22:14:59 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 98069 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 220D8C88E5E for ; Fri, 11 Sep 2026 22:15:50 +0000 (UTC) Received: from mail-wm2-f13.google.com (mail-wm2-f13.google.com [74.125.225.141]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.50888.1789164947700555776 for ; Fri, 11 Sep 2026 15:15:48 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=ltSQ6/Rw; spf=pass (domain: smile.fr, ip: 74.125.225.141, mailfrom: yoann.congal@smile.fr) Received: by mail-wm2-f13.google.com with SMTP id 5b1f17b1804b1-49e6b885ef8so1073525e9.1 for ; Fri, 11 Sep 2026 15:15:47 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1789164946; x=1789769746; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=7ElfScPHC87//Dcs0OkdqU7g4oK52PnO5brnPF7HoZ8=; b=ltSQ6/RwZlN3WEPDh6+Py2t8fy4wOMGmpJWluBfRi/MSKfG2fbzACZYQ6OLp69Mlvj kRvVFF/foFhWaxNyoFkphwvd44GHRx4Ixy8gNq/m1TR4GyqOJDdgfmCYVKGGLqXlCwgA 7sbEEmUio2ZWoFW0HkvolOIt6+wIUitwfR9WI= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1789164946; x=1789769746; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=7ElfScPHC87//Dcs0OkdqU7g4oK52PnO5brnPF7HoZ8=; b=gWOiXxRrJSLCU3Sxi86mT4fjOwWRG1z53MrAGouNtvbsCluopWqyAIVdZHFiMhwK85 PbldEoEIk/F1Aeb6i7AW0ZKLX6H4+UhMn5yFCvyj6aG5esTNhUypKWHjBWohtE23a5pa L7JpWA6ERAsTe5CgPl30dhQYARf+x6L097OGWltDHGCZwt7O65YX1P+me978FHa25GiI 2kakLOZWzQ7UtCot+QCDucke2h8Q4pGYKXduHo7ZBbmk9nxz1ZNLfdKOCHCLpqeR8yon f03uvAsoAINnqNP+dQjrwZ787SWbC2SQLe1mNGS+M9SHsyrUHF6Kkws+XtDz6WUuPcsq xPtw== X-Gm-Message-State: AFuF++n8Q6HlrgVDzZs9ln2pnNJLhexcJp6avftr37s03TBtc0jZ8nwU V7koo6L4JZlOiMW5Oenth+vnTqXhHe4rawM2MJU4hcBfD78oe++GVR/6NpcoEfgpKIL/AwlYp2J foAxypMo= X-Gm-Gg: AYBFou2m7W2CusCJe9RZognCy2ZvjqTUO0PWPNMhzaOQHI5PpUp8RlB335s2Lh+5DZ/ DLdXE6pVb45xyoWO8qBABlSuZoWDEBaSNb8DvbXIjv1rPpBXafiaW15RVUNySo6WmNTKgeaoD1U yY3fpWjjQP+0eVbvKQzV5xf8XLHzCgCx+ZfZGfaICsQJXiKeAP2OWsgRkpiSOQQmJAlH4suAqJt THXKd75hZs6TfQiaC8YPXUXNtRA4GPKgYnysPv0S115TJ6S//BzLJ45fcg+aHkr5A5Js48+oVR4 oBJqZJRHYQVidIx5mSChzBwJv/GcwaScpXD2zIjRiiidXE1fCiS5UWqL9TlV7rtktQ3MpofgPSy ku+T4KWudNZU5h7oTO8cHTo/PN32JsvCOLwsdJqsCLzEF1Xu3MWYGabbMovqytgeo9oZaxTSIKr YIHrKi5ZKsQio8F6hDa1mCkDpUqqnAm8T9Hd6TQaOCat72yLCOYiw52v/NJ5JH02ecNpGrCsP6M +R5jkpMeh+ADZ0rmcCcL2q2ylpov4FA8seZafI4w/4Arn33l7lyoufkXvHOxQ1MIHQ5BiWCejQ= X-Received: by 2002:a05:600c:4f47:b0:49c:fa21:e748 with SMTP id 5b1f17b1804b1-49e619dbd2bmr83452125e9.30.1789164945887; Fri, 11 Sep 2026 15:15:45 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-49e6c566bdbsm8434045e9.11.2026.09.11.15.15.45 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Fri, 11 Sep 2026 15:15:45 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][scarthgap 05/13] go: Fix CVE-2026-33814 Date: Sat, 12 Sep 2026 00:14:59 +0200 Message-ID: <4fe1f459482cfc54333b4cb90bb822a901822e28.1789163914.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Fri, 11 Sep 2026 22:15:50 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/245675 From: Hetvi Thakar This patch applies the upstream fix as referenced in [2], using the commit shown in [1]. [1] https://github.com/golang/go/commit/9024c3f6b150fb1349d8a5dc5e9aa31d7896f67f [2] https://pkg.go.dev/vuln/GO-2026-4918 Signed-off-by: Hetvi Thakar Signed-off-by: Yoann Congal --- meta/recipes-devtools/go/go-1.22.12.inc | 1 + .../go/go/CVE-2026-33814.patch | 44 +++++++++++++++++++ 2 files changed, 45 insertions(+) create mode 100644 meta/recipes-devtools/go/go/CVE-2026-33814.patch diff --git a/meta/recipes-devtools/go/go-1.22.12.inc b/meta/recipes-devtools/go/go-1.22.12.inc index 99c5f8b63b6..ee2f5ca2777 100644 --- a/meta/recipes-devtools/go/go-1.22.12.inc +++ b/meta/recipes-devtools/go/go-1.22.12.inc @@ -62,6 +62,7 @@ SRC_URI += "\ file://CVE-2026-25679.patch \ file://CVE-2026-32288.patch \ file://CVE-2026-27145.patch \ + file://CVE-2026-33814.patch \ " SRC_URI[main.sha256sum] = "012a7e1f37f362c0918c1dfa3334458ac2da1628c4b9cf4d9ca02db986e17d71" diff --git a/meta/recipes-devtools/go/go/CVE-2026-33814.patch b/meta/recipes-devtools/go/go/CVE-2026-33814.patch new file mode 100644 index 00000000000..8265bf205f6 --- /dev/null +++ b/meta/recipes-devtools/go/go/CVE-2026-33814.patch @@ -0,0 +1,44 @@ +From 825d42a14d8ffbdbdda87a39e78795eb17e4f0f2 Mon Sep 17 00:00:00 2001 +From: Mark Freeman +Date: Fri, 17 Apr 2026 16:28:03 -0400 +Subject: [PATCH] [release-branch.go1.25] all: update x/net to a9171bc8 + +Fixes #78477 + +Change-Id: I0a4c8e25f569fc1bfb8ac39ff728bfe7300b751f +Reviewed-on: https://go-review.googlesource.com/c/go/+/768323 +Reviewed-by: Dmitri Shuralyov +TryBot-Bypass: Dmitri Shuralyov + +CVE: CVE-2026-33814 +Upstream-Status: Backport [https://github.com/golang/go/commit/9024c3f6b150fb1349d8a5dc5e9aa31d7896f67f] + +Backport Changes: +- Omitted src/go.mod, src/go.sum, and src/vendor/modules.txt because + their x/net version updates are not required for this focused backport. +- Omitted removal of the SETTINGS_ENABLE_CONNECT_PROTOCOL-specific + s.Valid call because Go 1.22 does not contain that setting case; validation + is added at the start of the settings callback instead. + +(cherry picked from commit 9024c3f6b150fb1349d8a5dc5e9aa31d7896f67f) +Signed-off-by: Hetvi Thakar +--- + src/net/http/h2_bundle.go | 3 +++ + 1 file changed, 3 insertions(+) + +diff --git a/src/net/http/h2_bundle.go b/src/net/http/h2_bundle.go +index c1a2e76ea4d..2f5a6d3d5a2 100644 +--- a/src/net/http/h2_bundle.go ++++ b/src/net/http/h2_bundle.go +@@ -9910,6 +9910,9 @@ func (rl *http2clientConnReadLoop) processSettingsNoWrite(f *http2SettingsFrame) + + var seenMaxConcurrentStreams bool + err := f.ForeachSetting(func(s http2Setting) error { ++ if err := s.Valid(); err != nil { ++ return err ++ } + switch s.ID { + case http2SettingMaxFrameSize: + cc.maxFrameSize = s.Val +-- +2.35.6 From patchwork Fri Sep 11 22:15:00 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 8bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 98068 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 9566AC88E5D for ; Fri, 11 Sep 2026 22:15:50 +0000 (UTC) Received: from mail-wm2-f12.google.com (mail-wm2-f12.google.com [74.125.225.140]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.50889.1789164948276316481 for ; Fri, 11 Sep 2026 15:15:48 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=r50Rj4hu; spf=pass (domain: smile.fr, ip: 74.125.225.140, mailfrom: yoann.congal@smile.fr) Received: by mail-wm2-f12.google.com with SMTP id 5b1f17b1804b1-49cd38e0f79so1967755e9.3 for ; Fri, 11 Sep 2026 15:15:48 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1789164946; x=1789769746; darn=lists.openembedded.org; h=content-transfer-encoding:content-type:mime-version:references :in-reply-to:message-id:date:subject:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=eFLECs/3moIUfc9zTK2fFrm2FaORc9hKoi+l4Vblqto=; b=r50Rj4huBLyTe/0pELdN3+0hNPzFSOmIYqc2EtMp8tH96RAcQ04dLn09QNquv5TH18 p3DRoGuTX4q5JlOftKqM1kJQyPmuk/tTAUheSEAJUmzf1CM3F4NMppdqt+4xTxZUCo0a hj7bxOHoQ/t1t9nLU4GbKwjIi8fYRUCRsAh60= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1789164946; x=1789769746; h=content-transfer-encoding:content-type:mime-version:references :in-reply-to:message-id:date:subject:to:from:x-gm-gg :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to :content-type; bh=eFLECs/3moIUfc9zTK2fFrm2FaORc9hKoi+l4Vblqto=; b=bf+QSAnjo5EfbGuJKultxj0Ah3L/cLVFb0eWM0FNCoAWSES2DF4UE4gWH14gyLEtdB P6Alb8yc15LbU/95okhm9WbvyZ2fvTgSkeXaKCC/5mmqr+GwerN1OxpBeiuF6MhrXVil uHpJVTFDShsDJFMz+H5Y9kZ4EK7nEL0VdFjauH2Vmk5mX0n1jLd7wG1FbaBYoImBAJ9s /OnCB6ir3C2Jxj7wLEbyC+TTGKRgdtlCaG+RwEKqJ9bOlH5WQOg69CnKtUExWRvgVaHz pUBcPttv6iZUfr8K/2W+eRpNpDLTKPJrcATvTgswT6ggQm8Q4tZzmptYglAWiaOVwgsr h99A== X-Gm-Message-State: AFuF++nFCTiK/3AuozS492QEkjeYk25HxQZ4npBkMubDmpkvkxl566CS N2Hvx4JZgFYtZ5EsvsKS5LLk/cWwECWvfblO2cbEvW+tS7bXG8CkoJYaxFJbJe933b4EkBpBGkE tWVx01l4= X-Gm-Gg: AYBFou2w01dZ/aZzERltKNX2DaR/MyP51JgAI7p5rSF24cxRsDjy5UnOlM5XUgkj3FD Zza1sUV3z+qydyXE4CtG52/E+w5tdcFKJeJzrZlYIFnvc7L9xXUQFGpojo4Gevnv3jvWOtf0IBG a9r5OhSY9Epr0NG2QfwsA7j9ut6Za498sPHFYAajwgiGeqFPpFzN0Uhu8VhccMnB6GaHzCMkdxg 11E0K2wVDpmg4vBn6ZNKsQw77gLZOh37ojcRMxqdBJmZrQnTi6r/4MPvr099etO4oHbOuabA/Ik GeDpYQOUj5mBk7o603tKsL/TYqZVlTclI4S+zF+4cAue8EusIo10NMdLCoGTQYdVNnph6cJC4xt PQhY9ARpgIBryD863cw5gQI6CmAvbz00KkM6zex5I85/KoMbG2cZTBjpHTM/cjw3AcNn7xKyvcQ pJsql1/8NxtaHPJzpoCV9y4/rHexkcjC5vd3JnFucIvBNEVRpewHULTYfM/yuDrwtk7Yj7KdBUk LWOorM5+9nfTkd+1UU4PX7Qr6Gu85zIm5/pQj5Lky0LMA+8hx7FLZK+/Hn8f+wEKEYoU5W4Fmo= X-Received: by 2002:a05:600c:540e:b0:49e:6692:27fd with SMTP id 5b1f17b1804b1-49e66922810mr91999455e9.2.1789164946419; Fri, 11 Sep 2026 15:15:46 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-49e6c566bdbsm8434045e9.11.2026.09.11.15.15.46 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Fri, 11 Sep 2026 15:15:46 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][scarthgap 06/13] go: Fix CVE-2026-39823 Date: Sat, 12 Sep 2026 00:15:00 +0200 Message-ID: <007e664db5bb393393415accf802b3cb57298dcb.1789163914.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Fri, 11 Sep 2026 22:15:50 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/245676 From: Hetvi Thakar This patch applies the upstream fix as referenced in [2], using the commit shown in [1]. [1] https://github.com/golang/go/commit/f0384f7c664892ed3ee8c0fec68638d9b3b01811 [2] https://pkg.go.dev/vuln/GO-2026-4982 Signed-off-by: Hetvi Thakar Signed-off-by: Yoann Congal --- meta/recipes-devtools/go/go-1.22.12.inc | 1 + .../go/go/CVE-2026-39823.patch | 100 ++++++++++++++++++ 2 files changed, 101 insertions(+) create mode 100644 meta/recipes-devtools/go/go/CVE-2026-39823.patch diff --git a/meta/recipes-devtools/go/go-1.22.12.inc b/meta/recipes-devtools/go/go-1.22.12.inc index ee2f5ca2777..a2c0efa3781 100644 --- a/meta/recipes-devtools/go/go-1.22.12.inc +++ b/meta/recipes-devtools/go/go-1.22.12.inc @@ -63,6 +63,7 @@ SRC_URI += "\ file://CVE-2026-32288.patch \ file://CVE-2026-27145.patch \ file://CVE-2026-33814.patch \ + file://CVE-2026-39823.patch \ " SRC_URI[main.sha256sum] = "012a7e1f37f362c0918c1dfa3334458ac2da1628c4b9cf4d9ca02db986e17d71" diff --git a/meta/recipes-devtools/go/go/CVE-2026-39823.patch b/meta/recipes-devtools/go/go/CVE-2026-39823.patch new file mode 100644 index 00000000000..00e25bb35c6 --- /dev/null +++ b/meta/recipes-devtools/go/go/CVE-2026-39823.patch @@ -0,0 +1,100 @@ +From 4915efb53a017a136a233a7676e80858d5b6e560 Mon Sep 17 00:00:00 2001 +From: Neal Patel +Date: Wed, 22 Apr 2026 18:41:25 -0400 +Subject: [PATCH] [release-branch.go1.25] html/template: fix escaping of URLs + in meta content attributes +MIME-Version: 1.0 +Content-Type: text/plain; charset=UTF-8 +Content-Transfer-Encoding: 8bit + +The WHATWG "shared declarative refresh steps" algorithm (§4.2.5.3) +skips ASCII whitespace between "url" and "=" when parsing the URL +portion of a meta content attribute. + +Thank you to Samy Ghannad for reporting this issue. + +Updates #78913 +Fixes #79031 +Fixes CVE-2026-39823 + +Change-Id: I7fc3bb9394b95e07b9b10fbc95725a3de6791774 +Reviewed-on: https://go-review.googlesource.com/c/go/+/769920 +Reviewed-by: Roland Shoemaker +TryBot-Bypass: Roland Shoemaker +(cherry picked from commit f2ec1254ff32fa39f3ce4faf72bbe44eeeeebad9) +Reviewed-on: https://go-review.googlesource.com/c/go/+/772101 +LUCI-TryBot-Result: golang-scoped@luci-project-accounts.iam.gserviceaccount.com + +CVE: CVE-2026-39823 +Upstream-Status: Backport [https://github.com/golang/go/commit/f0384f7c664892ed3ee8c0fec68638d9b3b01811] + +(cherry picked from commit f0384f7c664892ed3ee8c0fec68638d9b3b01811) +Signed-off-by: Hetvi Thakar +--- + src/html/template/escape_test.go | 20 ++++++++++++++++++++ + src/html/template/transition.go | 12 +++++++----- + 2 files changed, 27 insertions(+), 5 deletions(-) + +diff --git a/src/html/template/escape_test.go b/src/html/template/escape_test.go +index ce064407384..c9e566a9076 100644 +--- a/src/html/template/escape_test.go ++++ b/src/html/template/escape_test.go +@@ -759,6 +759,26 @@ func TestEscape(t *testing.T) { + ``, + ``, + }, ++ { ++ "meta content url with whitespace before equals", ++ ``, ++ ``, ++ }, ++ { ++ "meta content url with tab before equals", ++ "", ++ "", ++ }, ++ { ++ "meta content url with space after equals", ++ ``, ++ ``, ++ }, ++ { ++ "meta content url with whitespace both sides of equals", ++ "", ++ "", ++ }, + } + + for _, test := range tests { +diff --git a/src/html/template/transition.go b/src/html/template/transition.go +index 5aa3c35440b..ac05d56b418 100644 +--- a/src/html/template/transition.go ++++ b/src/html/template/transition.go +@@ -626,10 +626,12 @@ func tError(c context, s []byte) (context, int) { + + // tMetaContent is the context transition function for the meta content attribute state. + func tMetaContent(c context, s []byte) (context, int) { +- for i := 0; i < len(s); i++ { +- if i+3 <= len(s)-1 && bytes.Equal(bytes.ToLower(s[i:i+4]), []byte("url=")) { +- c.state = stateMetaContentURL +- return c, i + 4 ++ for i := range len(s) { ++ if i+3 <= len(s)-1 && bytes.EqualFold(s[i:i+3], []byte("url")) { ++ if j := eatWhiteSpace(s, i+3); j < len(s) && s[j] == '=' { ++ c.state = stateMetaContentURL ++ return c, j + 1 ++ } + } + } + return c, len(s) +@@ -637,7 +639,7 @@ func tMetaContent(c context, s []byte) (context, int) { + + // tMetaContentURL is the context transition function for the "url=" part of a meta content attribute state. + func tMetaContentURL(c context, s []byte) (context, int) { +- for i := 0; i < len(s); i++ { ++ for i := range len(s) { + if s[i] == ';' { + c.state = stateMetaContent + return c, i + 1 +-- +2.35.6 From patchwork Fri Sep 11 22:15:01 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 98071 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id E97D0C88E4D for ; Fri, 11 Sep 2026 22:15:50 +0000 (UTC) Received: from mail-wm1-f49.google.com (mail-wm1-f49.google.com [209.85.128.49]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.50890.1789164948911248161 for ; Fri, 11 Sep 2026 15:15:49 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=ZvNlCQgB; spf=pass (domain: smile.fr, ip: 209.85.128.49, mailfrom: yoann.congal@smile.fr) Received: by mail-wm1-f49.google.com with SMTP id 5b1f17b1804b1-49b0d8bc2aaso16454795e9.0 for ; Fri, 11 Sep 2026 15:15:48 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1789164947; x=1789769747; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=aAN30IEOMwnmAP8OM+2Pr/cy83LElup7yjPQU4Zs0GM=; b=ZvNlCQgBQkOjEUt/Mpx+6eEnI+XsxrwilVj6PLNZcah1fOlU3hyDmcRBxYovAWC4Da JJPGLmPqRi133q812i5aB0PX5/LyCgfKlqyl9O8wYXNvE7icHO1qK8RQvsNaPJukqZhm Abh7Ztsbx59DujgFjp+LgrZGRDmA2/BVpIPLI= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1789164947; x=1789769747; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=aAN30IEOMwnmAP8OM+2Pr/cy83LElup7yjPQU4Zs0GM=; b=Bkp3YBrR5dFwiHRghfUGvJSTVGyNWg3LviTP6eG4oXguM0RR/rAg+eRlJggM7QxlsI IBZy8GvkxdWW4NAgGgJqe96BTzOE9uFNN/ymQ1G4VQMxkMI5tpEx+YNSQxobgyJhBPxJ j70+LMWIBk+qIAED+CJa0IcfBOg/7Ly+g+FQDiZJVJEAAZ4OaiXtI9WtbAbsP792WbGl q0pSokDAxz9gfkF32YevqjueSG3sZvoiyk/QEvU2YqmzwqfbkuzXrU7N1OO3hN+9B3rJ /z8B8VEOritIWW9bLc/Y0KKqGTeRAyH3/3X9h1a+r0KxTPY44dnw58tmCCPmzRlbCi6E 8WUg== X-Gm-Message-State: AFuF++msfIiUl49TlJ6+vShU6KB0Cn2/T/MF7hGEX4K/S2Sokoahuviv OuJoRdWx1WeHjiAw+8XD29dz/zQ+YIQSgLXviJnrIAYXlLTjCit1PI25alQd5hbXe3OkaVctpXR /Pb+a9WU= X-Gm-Gg: AYBFou39dW4HE8eH9W5tFH8jBbLg+lMaSMs+oexFtwIjQIRo/xPht/5KGWZEI6QQa5y At+yYJKCUhxyITHiubUgkQWaG5HNTWHXEzPPr/0pAt7DyG0sHwJ8DclzPIwIxaPIrsLh6O81iok jH2XWYA1q8Hhx3hW3kTFVbmcGlJyRITe9OCTCqfUnbycLvV81qc08TcC2kYHWRF0Xwk2r4t8JHx L6t8ABvwxSKbLqxPdaKXst2SyyHHm16fCwy6LH1scTISV3KtbwdAgnNzoAucyYBzyRmA+sEG1cX 4+Bh/UeJdE297hXDx8quK5dwO9izJlEqPXAfdoKVny9BjwHLSJ1OjFesSdReZulFpDPnRRse/Q6 iOl7v9ZLR8/nM3nZkNIs3f/SiX1EwETGnAd6sMCcUEtpPHVVtkS9W/wimBbYPNlPXmZQZoYbL5W o/OgKlrepbm3kboPU2Jv5+tMPGiDFq0+igAWdG9/PMa7qG0yg8JhKXNrlRFsvjeWVfXKS7U4YPi XDaiLnN8HvcWXBpX826fPpA1ultEk+O+lKNDi8HraBPETF8d/brwtKzDmyaxPaa1YfYNuIRwPOy qZCU9gSeoJI= X-Received: by 2002:a05:600d:6414:10b0:49c:fc6c:be16 with SMTP id 5b1f17b1804b1-49e619c64cfmr51966335e9.28.1789164947161; Fri, 11 Sep 2026 15:15:47 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-49e6c566bdbsm8434045e9.11.2026.09.11.15.15.46 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Fri, 11 Sep 2026 15:15:46 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][scarthgap 07/13] binutils: fix CVE-2026-3441 and CVE-2026-3442 Date: Sat, 12 Sep 2026 00:15:01 +0200 Message-ID: <4f81bf96e18efd7951c2171581afd2ea80e09bc2.1789163914.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Fri, 11 Sep 2026 22:15:50 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/245677 From: Deepak Rathore This patch applies the upstream fix [1], which addresses two out-of-bounds read issues in bfd/xcofflink.c within xcoff_link_add_symbols(). The changes shown in [2] are referenced by [3] and [4]. [1] https://sourceware.org/git/?p=binutils-gdb.git;a=commit;h=c2bf7de1eb77a91d7a3c86d56408bf57de540faf [2] https://sourceware.org/git/?p=binutils-gdb.git;a=blobdiff;f=bfd/xcofflink.c;h=1781182fa6a3f92e5e91996f8b0dcf3ab192679b;hp=fde21c9f9583baff05e72e390e6bb896d02f9d43;hb=c2bf7de1eb77a91d7a3c86d56408bf57de540faf;hpb=d7f532cb3a46527 [3] https://bugzilla.suse.com/show_bug.cgi?id=CVE-2026-3441 [4] https://bugzilla.suse.com/show_bug.cgi?id=CVE-2026-3442 Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-3441 https://nvd.nist.gov/vuln/detail/CVE-2026-3442 https://www.suse.com/security/cve/CVE-2026-3441.html https://www.suse.com/security/cve/CVE-2026-3442.html Signed-off-by: Deepak Rathore Signed-off-by: Yoann Congal --- .../binutils/binutils-2.42.inc | 1 + .../CVE-2026-3441_CVE-2026-3442.patch | 51 +++++++++++++++++++ 2 files changed, 52 insertions(+) create mode 100644 meta/recipes-devtools/binutils/binutils/CVE-2026-3441_CVE-2026-3442.patch diff --git a/meta/recipes-devtools/binutils/binutils-2.42.inc b/meta/recipes-devtools/binutils/binutils-2.42.inc index d395ae1b1e0..8665a2549aa 100644 --- a/meta/recipes-devtools/binutils/binutils-2.42.inc +++ b/meta/recipes-devtools/binutils/binutils-2.42.inc @@ -82,5 +82,6 @@ SRC_URI = "\ file://CVE-2025-8224.patch \ file://CVE-2026-15003.patch \ file://CVE-2026-18220.patch \ + file://CVE-2026-3441_CVE-2026-3442.patch \ " S = "${WORKDIR}/git" diff --git a/meta/recipes-devtools/binutils/binutils/CVE-2026-3441_CVE-2026-3442.patch b/meta/recipes-devtools/binutils/binutils/CVE-2026-3441_CVE-2026-3442.patch new file mode 100644 index 00000000000..61b1c7dc198 --- /dev/null +++ b/meta/recipes-devtools/binutils/binutils/CVE-2026-3441_CVE-2026-3442.patch @@ -0,0 +1,51 @@ +From 0f650fc3fc147b05f819ef96af02238cee02c68e Mon Sep 17 00:00:00 2001 +From: Alan Modra +Date: Sat, 28 Feb 2026 13:16:40 +1030 +Subject: [PATCH 1/2] xcofflink buffer overflows + +This fixes two fuzzed object file out-of-bounds accesses. + + * xcofflink.c (xcoff_link_add_symbols): Properly bounds check + XTY_LD x_scnlen index. Sanity check r_symndx before using it + to index sym hashes. + +CVE: CVE-2026-3441 CVE-2026-3442 +Upstream-Status: Backport [https://sourceware.org/git/?p=binutils-gdb.git;a=commit;h=c2bf7de1eb77a91d7a3c86d56408bf57de540faf] + +(cherry picked from commit c2bf7de1eb77a91d7a3c86d56408bf57de540faf) +Signed-off-by: Deepak Rathore +--- + bfd/xcofflink.c | 10 ++++------ + 1 file changed, 4 insertions(+), 6 deletions(-) + +diff --git a/bfd/xcofflink.c b/bfd/xcofflink.c +index a48cc94fed0..dbfa17c6d58 100644 +--- a/bfd/xcofflink.c ++++ b/bfd/xcofflink.c +@@ -1888,12 +1888,9 @@ xcoff_link_add_symbols (bfd *abfd, struct bfd_link_info *info) + follow its appropriate XTY_SD symbol. The .set pseudo op can + cause the XTY_LD to not follow the XTY_SD symbol. */ + { +- bool bad; +- +- bad = false; +- if (aux.x_csect.x_scnlen.u64 +- >= (size_t) (esym - (bfd_byte *) obj_coff_external_syms (abfd))) +- bad = true; ++ bool bad = (aux.x_csect.x_scnlen.u64 ++ >= ((esym - (bfd_byte *) obj_coff_external_syms (abfd)) ++ / symesz)); + if (! bad) + { + section = xcoff_data (abfd)->csects[aux.x_csect.x_scnlen.u64]; +@@ -2259,6 +2256,7 @@ xcoff_link_add_symbols (bfd *abfd, struct bfd_link_info *info) + functions imported from dynamic objects. */ + if (info->output_bfd->xvec == abfd->xvec + && *rel_csect != bfd_und_section_ptr ++ && (unsigned long) rel->r_symndx < obj_raw_syment_count (abfd) + && obj_xcoff_sym_hashes (abfd)[rel->r_symndx] != NULL) + { + struct xcoff_link_hash_entry *h; +-- +2.44.4 + From patchwork Fri Sep 11 22:15:02 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 98073 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 09468C88E5F for ; Fri, 11 Sep 2026 22:15:51 +0000 (UTC) Received: from mail-wm2-f12.google.com (mail-wm2-f12.google.com [74.125.225.140]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.50891.1789164949544431440 for ; Fri, 11 Sep 2026 15:15:49 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=0a7X+cSv; spf=pass (domain: smile.fr, ip: 74.125.225.140, mailfrom: yoann.congal@smile.fr) Received: by mail-wm2-f12.google.com with SMTP id 5b1f17b1804b1-49ce364488dso1041835e9.0 for ; Fri, 11 Sep 2026 15:15:49 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1789164948; x=1789769748; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=Gh2cukWabGiynrkBCDNmHgCmoZrmZhSm83ModsV6vRQ=; b=0a7X+cSvMltYLClpgs9CMESwCMbh0qM98ETq9OQh/Talch8UTGTUmYDtHf5yJR/qhP j8Qu8+gG2niWkWe8L+NiyDUd8mhzX/eVGlykKETAET8jr2Lc9o1h8J6wKta5OIRn+De6 M+m9+Z1X/ExJIWlfDkVv4TuUZzmvBBbjMhBWU= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1789164948; x=1789769748; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=Gh2cukWabGiynrkBCDNmHgCmoZrmZhSm83ModsV6vRQ=; b=aQSnV3Gwwd8jiYwTXlKh/vfL6f8c7djjPTJWneaTdiDYSiImw+r4+/llkO88cVC3Ib 9N2h9HCstDG1rC+DcC5Yi7cWR3r9n+TBtpEOS/vKE+TBaqT+0+JpXY3CGSoNU7IO1mtp ucraZITiwE7AoeuFiHMHAA17CewzYk+tHWZli4xhRFMiG9ePdB/t1vDSmDmT118LrPCF oJlHf4R7fLuq9FGHGW9zuO51NLcpjwbAyFZdIhdisoI5tgPsl1p6y2eB8gtn0zhBU/X5 QIAiqkV8kso2tmR4eI2dM8JMUa922AfNMQIb70oZv1B1JZE+VkC8Nrqk65NGnTRWQFqL HHzw== X-Gm-Message-State: AFuF++mPZMKBDt09FMr+WqTYT2KAXVoK4Wd7b9rMqfsovmn6iCwzvziR qJjoiXd1Kl9qrMrlRK3cXGw8rZ3XIRb8qoo+DPQ5kWTyTfzRJrx2Ky170w/firqBAdvRMvUhM9m RFKSo4Rg= X-Gm-Gg: AYBFou3BmNxtd+o3LUfGwoE4P8GrKuY6MzchWycfGUpWrwvUA5RxCoVb+hF0x7ckLlX Y98aZ6hCj5CKJQ3DG5bZy+JBDXYVLrKLuXP+8iWfa6hDdWarnNEvafnEdA2RAK9mlBLssQcVO1b YGGfi6fbMFsFuBlsALbSMCMQzhpNcVHVkSWbeTaG5oPJgFoZrrTYXxty4UpQ4Hcm+QWx391VMci OtrMYprFpeaqrzQ9YYFtvKaHFaQ9Rd/9m+gn/TdwzNuWYdMB6LkRq64ovBfJohiW9pIzmuUXkke JLfnNRMnOgxtKbut7nhPbZcgYzcduHdKnTFx1t6xMhFT4wsSCpibGwOKIkb+2Uqgd1FYpAf9nRu 7giDtz/vkKM/G1IDXuBQnQZJ9ObislfhQs5Q1W/qV6Tg9Y86HaBL2TW4bS1oyw7+QazypvNMmSA D6NFANU1g+CkLACTaYF5vYFF2q1aXn27LXaxkyEJ8nFcdu0jmhDG6LC7SLRqKbdGqZuD95lpYoY SdO5k0mRbLazxXG+SU7Pyi2dV02+8hY2Aje+WQEpTgwGrgH2nmCaft+FDoWDMZwNueuDutd7Q0u X-Received: by 2002:a05:600c:1d01:b0:49e:6ad7:95b5 with SMTP id 5b1f17b1804b1-49e6ad79624mr21860495e9.7.1789164947712; Fri, 11 Sep 2026 15:15:47 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-49e6c566bdbsm8434045e9.11.2026.09.11.15.15.47 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Fri, 11 Sep 2026 15:15:47 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][scarthgap 08/13] binutils: fix CVE-2026-4647 Date: Sat, 12 Sep 2026 00:15:02 +0200 Message-ID: X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Fri, 11 Sep 2026 22:15:51 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/245678 From: Deepak Rathore This patch applies the upstream fix [1], which addresses an out-of-bounds read issue in XCOFF relocation processing, as described in [2]. [1] https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=9e99dbc1f19ffaf18d0250788951706066ebe7f2 [2] https://sourceware.org/bugzilla/show_bug.cgi?id=33919 Reference: https://bugzilla.suse.com/show_bug.cgi?id=1260338 https://www.suse.com/security/cve/CVE-2026-4647.html https://nvd.nist.gov/vuln/detail/CVE-2026-4647 Signed-off-by: Deepak Rathore Signed-off-by: Yoann Congal --- .../binutils/binutils-2.42.inc | 1 + .../binutils/binutils/CVE-2026-4647.patch | 228 ++++++++++++++++++ 2 files changed, 229 insertions(+) create mode 100644 meta/recipes-devtools/binutils/binutils/CVE-2026-4647.patch diff --git a/meta/recipes-devtools/binutils/binutils-2.42.inc b/meta/recipes-devtools/binutils/binutils-2.42.inc index 8665a2549aa..37dce2cb3e5 100644 --- a/meta/recipes-devtools/binutils/binutils-2.42.inc +++ b/meta/recipes-devtools/binutils/binutils-2.42.inc @@ -83,5 +83,6 @@ SRC_URI = "\ file://CVE-2026-15003.patch \ file://CVE-2026-18220.patch \ file://CVE-2026-3441_CVE-2026-3442.patch \ + file://CVE-2026-4647.patch \ " S = "${WORKDIR}/git" diff --git a/meta/recipes-devtools/binutils/binutils/CVE-2026-4647.patch b/meta/recipes-devtools/binutils/binutils/CVE-2026-4647.patch new file mode 100644 index 00000000000..2152903d341 --- /dev/null +++ b/meta/recipes-devtools/binutils/binutils/CVE-2026-4647.patch @@ -0,0 +1,228 @@ +From 3f02998235538f179d7884a76bd4d91e86a533b0 Mon Sep 17 00:00:00 2001 +From: Alan Modra +Date: Fri, 13 Mar 2026 17:28:28 +1030 +Subject: [PATCH 2/2] PR33919 Out-of-bounds read in XCOFF relocation processing + + PR 33919 + * coff-rs6000.c (xcoff_calculate_relocation): Don't use explicit + array size. + (xcoff_complain_overflow): Likewise. + (xcoff_rtype2howto): Return a NULL howto rather than aborting. + (_bfd_xcoff_reloc_name_lookup): Use ARRAY_SIZE. + (xcoff_ppc_relocate_section): Sanity check reloc r_type before + accessing xcoff_howto_table. Print r_type using %#x. Remove + now redundant later reloc r_type sanity check. + * coff64-rs6000.c: Similarly. + * libxcoff.h (XCOFF_MAX_CALCULATE_RELOCATION): Don't define. + (XCOFF_MAX_COMPLAIN_OVERFLOW): Don't define. + +CVE: CVE-2026-4647 +Upstream-Status: Backport [https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=9e99dbc1f19ffaf18d0250788951706066ebe7f2] + +(cherry picked from commit 9e99dbc1f19ffaf18d0250788951706066ebe7f2) +Signed-off-by: Deepak Rathore +--- + bfd/coff-rs6000.c | 36 +++++++++++++++++++++--------------- + bfd/coff64-rs6000.c | 33 ++++++++++++++++++++------------- + bfd/libxcoff.h | 3 --- + 3 files changed, 41 insertions(+), 31 deletions(-) + +diff --git a/bfd/coff-rs6000.c b/bfd/coff-rs6000.c +index 87feb672bf1..0f2cc496b63 100644 +--- a/bfd/coff-rs6000.c ++++ b/bfd/coff-rs6000.c +@@ -155,8 +155,7 @@ static xcoff_complain_function xcoff_complain_overflow_bitfield_func; + static xcoff_complain_function xcoff_complain_overflow_signed_func; + static xcoff_complain_function xcoff_complain_overflow_unsigned_func; + +-xcoff_reloc_function *const +-xcoff_calculate_relocation[XCOFF_MAX_CALCULATE_RELOCATION] = ++xcoff_reloc_function *const xcoff_calculate_relocation[] = + { + xcoff_reloc_type_pos, /* R_POS (0x00) */ + xcoff_reloc_type_neg, /* R_NEG (0x01) */ +@@ -210,8 +209,7 @@ xcoff_calculate_relocation[XCOFF_MAX_CALCULATE_RELOCATION] = + xcoff_reloc_type_toc, /* R_TOCL (0x31) */ + }; + +-xcoff_complain_function *const +-xcoff_complain_overflow[XCOFF_MAX_COMPLAIN_OVERFLOW] = ++xcoff_complain_function *const xcoff_complain_overflow[] = + { + xcoff_complain_overflow_dont_func, + xcoff_complain_overflow_bitfield_func, +@@ -1158,8 +1156,11 @@ reloc_howto_type xcoff_howto_table[] = + void + xcoff_rtype2howto (arelent *relent, struct internal_reloc *internal) + { +- if (internal->r_type > R_TOCL) +- abort (); ++ if (internal->r_type >= ARRAY_SIZE (xcoff_howto_table)) ++ { ++ relent->howto = NULL; ++ return; ++ } + + /* Default howto layout works most of the time */ + relent->howto = &xcoff_howto_table[internal->r_type]; +@@ -1183,7 +1184,7 @@ xcoff_rtype2howto (arelent *relent, struct internal_reloc *internal) + if (relent->howto->dst_mask != 0 + && (relent->howto->bitsize + != ((unsigned int) internal->r_size & 0x1f) + 1)) +- abort (); ++ relent->howto = NULL; + } + + reloc_howto_type * +@@ -1236,9 +1237,7 @@ _bfd_xcoff_reloc_name_lookup (bfd *abfd ATTRIBUTE_UNUSED, + { + unsigned int i; + +- for (i = 0; +- i < sizeof (xcoff_howto_table) / sizeof (xcoff_howto_table[0]); +- i++) ++ for (i = 0; i < ARRAY_SIZE (xcoff_howto_table); i++) + if (xcoff_howto_table[i].name != NULL + && strcasecmp (xcoff_howto_table[i].name, r_name) == 0) + return &xcoff_howto_table[i]; +@@ -3776,6 +3775,14 @@ xcoff_ppc_relocate_section (bfd *output_bfd, + the csect including the symbol which it references. */ + if (rel->r_type == R_REF) + continue; ++ if (rel->r_type >= ARRAY_SIZE (xcoff_howto_table)) ++ { ++ /* xgettext:c-format */ ++ _bfd_error_handler (_("%pB: unsupported relocation type %#x"), ++ input_bfd, rel->r_type); ++ bfd_set_error (bfd_error_bad_value); ++ return false; ++ } + + /* Retrieve default value in HOWTO table and fix up according + to r_size field, if it can be different. +@@ -3795,7 +3802,7 @@ xcoff_ppc_relocate_section (bfd *output_bfd, + + default: + _bfd_error_handler +- (_("%pB: relocation (%d) at 0x%" PRIx64 " has wrong r_rsize (0x%x)\n"), ++ (_("%pB: relocation (%#x) at 0x%" PRIx64 " has wrong r_rsize (0x%x)\n"), + input_bfd, rel->r_type, (uint64_t) rel->r_vaddr, rel->r_size); + return false; + } +@@ -3871,10 +3878,9 @@ xcoff_ppc_relocate_section (bfd *output_bfd, + } + } + +- if (rel->r_type >= XCOFF_MAX_CALCULATE_RELOCATION +- || !((*xcoff_calculate_relocation[rel->r_type]) +- (input_bfd, input_section, output_bfd, rel, sym, &howto, val, +- addend, &relocation, contents, info))) ++ if (!((*xcoff_calculate_relocation[rel->r_type]) ++ (input_bfd, input_section, output_bfd, rel, sym, &howto, val, ++ addend, &relocation, contents, info))) + return false; + + /* address */ +diff --git a/bfd/coff64-rs6000.c b/bfd/coff64-rs6000.c +index 0f8d9e08783..c74698070d5 100644 +--- a/bfd/coff64-rs6000.c ++++ b/bfd/coff64-rs6000.c +@@ -177,8 +177,7 @@ static bool xcoff64_bad_format_hook + /* Relocation functions */ + static xcoff_reloc_function xcoff64_reloc_type_br; + +-xcoff_reloc_function *const +-xcoff64_calculate_relocation[XCOFF_MAX_CALCULATE_RELOCATION] = ++xcoff_reloc_function *const xcoff64_calculate_relocation[] = + { + xcoff_reloc_type_pos, /* R_POS (0x00) */ + xcoff_reloc_type_neg, /* R_NEG (0x01) */ +@@ -1439,8 +1438,11 @@ reloc_howto_type xcoff64_howto_table[] = + void + xcoff64_rtype2howto (arelent *relent, struct internal_reloc *internal) + { +- if (internal->r_type > R_TOCL) +- abort (); ++ if (internal->r_type >= ARRAY_SIZE (xcoff64_howto_table)) ++ { ++ relent->howto = NULL; ++ return; ++ } + + /* Default howto layout works most of the time */ + relent->howto = &xcoff64_howto_table[internal->r_type]; +@@ -1473,7 +1475,7 @@ xcoff64_rtype2howto (arelent *relent, struct internal_reloc *internal) + if (relent->howto->dst_mask != 0 + && (relent->howto->bitsize + != ((unsigned int) internal->r_size & 0x3f) + 1)) +- abort (); ++ relent->howto = NULL; + } + + reloc_howto_type * +@@ -1528,9 +1530,7 @@ xcoff64_reloc_name_lookup (bfd *abfd ATTRIBUTE_UNUSED, + { + unsigned int i; + +- for (i = 0; +- i < sizeof (xcoff64_howto_table) / sizeof (xcoff64_howto_table[0]); +- i++) ++ for (i = 0; i < ARRAY_SIZE (xcoff64_howto_table); i++) + if (xcoff64_howto_table[i].name != NULL + && strcasecmp (xcoff64_howto_table[i].name, r_name) == 0) + return &xcoff64_howto_table[i]; +@@ -1574,6 +1574,14 @@ xcoff64_ppc_relocate_section (bfd *output_bfd, + the csect including the symbol which it references. */ + if (rel->r_type == R_REF) + continue; ++ if (rel->r_type >= ARRAY_SIZE (xcoff64_howto_table)) ++ { ++ /* xgettext:c-format */ ++ _bfd_error_handler (_("%pB: unsupported relocation type %#x"), ++ input_bfd, rel->r_type); ++ bfd_set_error (bfd_error_bad_value); ++ return false; ++ } + + /* Retrieve default value in HOWTO table and fix up according + to r_size field, if it can be different. +@@ -1595,7 +1603,7 @@ xcoff64_ppc_relocate_section (bfd *output_bfd, + + default: + _bfd_error_handler +- (_("%pB: relocation (%d) at (0x%" PRIx64 ") has wrong" ++ (_("%pB: relocation (%#x) at (0x%" PRIx64 ") has wrong" + " r_rsize (0x%x)\n"), + input_bfd, rel->r_type, rel->r_vaddr, rel->r_size); + return false; +@@ -1668,10 +1676,9 @@ xcoff64_ppc_relocate_section (bfd *output_bfd, + } + } + +- if (rel->r_type >= XCOFF_MAX_CALCULATE_RELOCATION +- || !((*xcoff64_calculate_relocation[rel->r_type]) +- (input_bfd, input_section, output_bfd, rel, sym, &howto, val, +- addend, &relocation, contents, info))) ++ if (!((*xcoff64_calculate_relocation[rel->r_type]) ++ (input_bfd, input_section, output_bfd, rel, sym, &howto, val, ++ addend, &relocation, contents, info))) + return false; + + /* address */ +diff --git a/bfd/libxcoff.h b/bfd/libxcoff.h +index 81c4e205e06..ca716a9ef3a 100644 +--- a/bfd/libxcoff.h ++++ b/bfd/libxcoff.h +@@ -215,9 +215,6 @@ struct xcoff_backend_data_rec + #define bfd_xcoff_text_align_power(a) ((xcoff_data (a)->text_align_power)) + #define bfd_xcoff_data_align_power(a) ((xcoff_data (a)->data_align_power)) + +-/* xcoff*_ppc_relocate_section macros */ +-#define XCOFF_MAX_CALCULATE_RELOCATION (0x32) +-#define XCOFF_MAX_COMPLAIN_OVERFLOW (4) + /* N_ONES produces N one bits, without overflowing machine arithmetic. */ + #ifdef N_ONES + #undef N_ONES +-- +2.44.4 + From patchwork Fri Sep 11 22:15:03 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 98072 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 6B5CAC88E50 for ; Fri, 11 Sep 2026 22:15:51 +0000 (UTC) Received: from mail-wm1-f41.google.com (mail-wm1-f41.google.com [209.85.128.41]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.50974.1789164950483845212 for ; Fri, 11 Sep 2026 15:15:50 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=bV0qIpyN; spf=pass (domain: smile.fr, ip: 209.85.128.41, mailfrom: yoann.congal@smile.fr) Received: by mail-wm1-f41.google.com with SMTP id 5b1f17b1804b1-49b0d8bc2aaso16454895e9.0 for ; Fri, 11 Sep 2026 15:15:50 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1789164949; x=1789769749; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=w6jJG89Op7C0IhvlVv5QAiYHvmD5fqO0HNbVU5kRxX8=; b=bV0qIpyNniAe+3oDfViPmUlQLOsCycgqLWf+/zWsW5kxNWGRZQrqgU0dx+Xdl2Mb7/ jWcJgaa5N8Dx+QdTEjj/Ubfy9aBGnkAIBPCH3z4oSXNZj9cA1/D4rtFNiK2XfY1xMvKh Bj78Y5lQkUXeN2TlNjCO/V1JrhRsrv/v+LL0k= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1789164949; x=1789769749; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=w6jJG89Op7C0IhvlVv5QAiYHvmD5fqO0HNbVU5kRxX8=; b=IIEMg7NrrycENTQQcynSKysNJDBnmt1QqTtRJHsZ03vzo8nK01wUZYTFiUj6dL9bcq 3fL71nFWK3E9RIMTaXjJW8/3IenC4tyovot1qAZEfZZq+BcXpMTvgXhPLUYiAqCcRKXs 6RyjoSrCKzuFCvEv/wbm4AYnDpixM44ffmbyZSoyOXVcvE9sQxpKS246JFQBXBpNrqCY CbG3t6GddE29809X3LH+Z7atYoZXB2CnDflv2CLl/DjDJqQL1jqNBqe4Qe7EVp1cxaKe SORH0CXroevBVD/nBCw2xb8AXY3yeH1vxC8/2dtZOjfyJOnOQEC/YvAvds8X4lVttcaG 3v3g== X-Gm-Message-State: AFuF++kFT89msPHOfB22qEVLilRGyH6nj9a6cpoWPdkncoK4D4FxXkQI otHD6Vodm+KFR5lUR2KXtTqRnn49VMeXXfNTpak6B5EheiZVnrAAh+IXPJIrbRKaxfD4ffAYvcU u0aavtxE= X-Gm-Gg: AYBFou1V7LdLvp7OWLRJXkODeiNkg8WcVj4zDlj4uqNSkImCFMstGgEpidcyGwBAXrV 3XMb6G94TpGUjPSmYILUH0PWHT1FSQdx4z2/kHhoK6KxHVcqHwUlFZYXA/xvwhQUyXyOvrIzRl3 cVqujo4bnyU1v2Ov7ynBt98KGJ/C3qnA5bIoYbkLt47cQzB2/FdFA4liTYZ+y3FTO5c92ACOOCK RzXbCO65uPXmjxkynVY2j1arxvk/t/jC30VY66rzWWEp0eO3hkAMSKr1gT/Jvv4CX4T48zSQ8zJ 81Xw+RDAwrRH4hP29tNN5qrzaWRHOPJpSNOn/1Lu9uBd0GxO8xAbxyr/52t+ZMzRRd1ScNu+Uq6 MupZ0or1/rRGVw33LF+SnAwdyUG3dxfxC9gONGCJbHsUl9yEkfyZ+qjMds5BUh+xwaYMFIGUeaM YnTeYqpBYf14tFEEF3LKEHOz55uhUX8q5rTpepgDglW4CjDsk9dksm4c+p8EJ5u8hvGVeJZuy32 FthJ+ZacV+NWQod0xYZIEhdWDGIpb8sV+klIysT+cuYxBf+wKzhMZX9smcYXtwVim/+HLHd0dY= X-Received: by 2002:a05:600c:a03:b0:49c:dada:f57f with SMTP id 5b1f17b1804b1-49e6197f78dmr75131155e9.7.1789164948767; Fri, 11 Sep 2026 15:15:48 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-49e6c566bdbsm8434045e9.11.2026.09.11.15.15.47 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Fri, 11 Sep 2026 15:15:47 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][scarthgap 09/13] python3-py: set CVE_PRODUCT Date: Sat, 12 Sep 2026 00:15:03 +0200 Message-ID: <54c6a775ab49f88f04305fd18fe19fe4fedeb161.1789163914.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Fri, 11 Sep 2026 22:15:51 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/245679 From: Gyorgy Sarvari The related CVEs are tracked using pytest:py CPE, so set the CVE_PRODUCT accordingly instead of the default python:py. See CVE db query: sqlite> select * from products where product like 'py'; CVE-2020-29651|pytest|py|||1.9.0|<= CVE-2022-42969|pytest|py|||1.11.0|<= Signed-off-by: Gyorgy Sarvari Signed-off-by: Khem Raj (cherry picked from commit 1fac509459c4e2d970121b66ae33cd53ef1eb8a6) Signed-off-by: Darsh Kelaiya Signed-off-by: Yoann Congal [YC: This is a cherry-pick from meta-openembedded] --- meta/recipes-devtools/python/python3-py_1.11.0.bb | 2 ++ 1 file changed, 2 insertions(+) diff --git a/meta/recipes-devtools/python/python3-py_1.11.0.bb b/meta/recipes-devtools/python/python3-py_1.11.0.bb index 31d5a377a7e..a75b9c2b142 100644 --- a/meta/recipes-devtools/python/python3-py_1.11.0.bb +++ b/meta/recipes-devtools/python/python3-py_1.11.0.bb @@ -5,6 +5,8 @@ LIC_FILES_CHKSUM = "file://LICENSE;md5=a6bb0320b04a0a503f12f69fea479de9" SRC_URI[sha256sum] = "51c75c4126074b472f746a24399ad32f6053d1b34b68d2fa41e558e6f4a98719" +CVE_PRODUCT = "py" + DEPENDS += "python3-setuptools-scm-native" inherit pypi python_setuptools_build_meta From patchwork Fri Sep 11 22:15:04 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 98078 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 2414CC88E53 for ; Fri, 11 Sep 2026 22:16:01 +0000 (UTC) Received: from mail-wm1-f48.google.com (mail-wm1-f48.google.com [209.85.128.48]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.50975.1789164951348883214 for ; Fri, 11 Sep 2026 15:15:51 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=VAWDV2yO; spf=pass (domain: smile.fr, ip: 209.85.128.48, mailfrom: yoann.congal@smile.fr) Received: by mail-wm1-f48.google.com with SMTP id 5b1f17b1804b1-49cd77e0f95so11142515e9.3 for ; Fri, 11 Sep 2026 15:15:51 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1789164949; x=1789769749; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=ZZ+YAE/hs0KF7SZXSQyxjN8a0Sr3LiITFFM1iNHgM1g=; b=VAWDV2yOKOlsi/7yoBa7etzckwQZL9PIS8itbdJJx3bzj/3URFg7JJ+EQTlJkQp/1a rbFF6YoWcSiHwZUwu6WDzD87CrRTzSldVjpAZMG71rPhlkothMofoEEOzfT+cyEkBClf aEOBsLXtd23Rw5djetEbHaMPPUNHGzxL6+LgQ= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1789164949; x=1789769749; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=ZZ+YAE/hs0KF7SZXSQyxjN8a0Sr3LiITFFM1iNHgM1g=; b=tTUvCpL4yYVqFfOHHH8M4LMBp06ehYNlLYLamQKmU10qqULC94PopS6WBeV8XZyrY+ 0YvC3y9zvsr6Oh3/007JQ7dqy/t3LQhRLcpgPlO8pUwBEyIcO+nrBEKksgx362V7VBkL FMqdsAa4y3wRRwprkS992tX5GJ8YRL0BspJObncGCB8D87CkF+VZZeyO6OI7in57xUsM I8zyOeWi/RpxepV8WrDTehFaVX35XT/hThIEY1Q/2FO7vlXv0+5l2t7HRhRntha430KU alUZTlWcVv/nCkAF5xEs6YPsNjoS1e7JludtH2zn7AeFeqbY/KBwMRW+dSxNvxqbDe68 hpzw== X-Gm-Message-State: AFuF++nVocaBJVarvSVAoOMua9t+Vf105fk0jw4HO4b/edAgeT38BJvo drusluQfGHGmCZg8K1cUNzVCZY3zSmfvRHT13F8piAWyOZWM5splPAt/0q2suk31/LZnkZh7TxC o3Ylp51c= X-Gm-Gg: AYBFou0QpBN6ebpqK2tnKK4xBJC53xu75LS6req0cvZu+qVsSGZ2Aj2FzPYVo0DqzW0 /g7883+mmnvBDZdN22QjUniRNnU8De3Xj9fZegwz2rPMAlMIfeM9JPHCPO55FKC7LCZIebQxKJ3 xH7FziC9gTk1sfXBp27S4lCVNCO6J9ewOitfWe+w8p6uXSJgQGz5j6p/qQ5YMcGSLLlub6my+/H rt+Cz+Eg/otk1Am/8iF3eO2NAdQ97WNEILjg7L5z6cMoVM9HD4+7ccrd7vVWuJ6luG55T0TtYle X7+avTvMAdwvUYLBDdZ2S9iGX+4s1akHSzgRvja5XSbPZZahJeabDEroBx37jmqCekbqg9538ZG zwTWYrWcQAmrfa9atl5z/91unCsxDuH657G9rCCT4OxD1xxhPoGgsUBaUrgd87oX5gC+8BYaoBm ZenpUso7cB98S0ZI7+es11waPGshXC0HUnUr0FusZ6jqnOe4ruWTJeE5BOxzPg1jgE9CwIfiofK MbivNPWa0RSwC/LTS/7Cj0iTuBVKhhVhcthP2YOThWUHIzDYxuCPyRZOrCFM3LHGdtuoi0maj7Z CdYc9pjSqA== X-Received: by 2002:a05:600c:3b27:b0:49c:fc6e:a3d8 with SMTP id 5b1f17b1804b1-49e619cc2aemr76560605e9.23.1789164949418; Fri, 11 Sep 2026 15:15:49 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-49e6c566bdbsm8434045e9.11.2026.09.11.15.15.48 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Fri, 11 Sep 2026 15:15:49 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][scarthgap 10/13] python3-lxml: fix CVE-2026-41066 Date: Sat, 12 Sep 2026 00:15:04 +0200 Message-ID: <1f18d27577b802e65c9d44bb497cbc27eb7f1f1e.1789163914.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Fri, 11 Sep 2026 22:16:01 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/245680 From: Darsh Kelaiya This patch applies the upstream fix as referenced in [2], using the commit shown in [1]. Regenerate etree.c with the matching Cython 3.0.9 release. Keep the iterparse source layout line-stable so that the generated diff contains only the functional and documentation changes instead of unrelated source-location updates. [1] https://github.com/lxml/lxml/commit/ab431ea0b9a7357d968f1d1c5c614649e9aaf358 [2] https://github.com/lxml/lxml/security/advisories/GHSA-vfmq-68hx-4jfw Signed-off-by: Darsh Kelaiya Signed-off-by: Yoann Congal --- .../python/python3-lxml/CVE-2026-41066.patch | 262 ++++++++++++++++++ .../python/python3-lxml_5.0.2.bb | 4 +- 2 files changed, 265 insertions(+), 1 deletion(-) create mode 100644 meta/recipes-devtools/python/python3-lxml/CVE-2026-41066.patch diff --git a/meta/recipes-devtools/python/python3-lxml/CVE-2026-41066.patch b/meta/recipes-devtools/python/python3-lxml/CVE-2026-41066.patch new file mode 100644 index 00000000000..a58a0734723 --- /dev/null +++ b/meta/recipes-devtools/python/python3-lxml/CVE-2026-41066.patch @@ -0,0 +1,262 @@ +From 4fe0735416504223919151aa43c8ccba4626597f Mon Sep 17 00:00:00 2001 +From: Stefan Behnel +Date: Fri, 10 Apr 2026 10:13:03 +0200 +Subject: [PATCH] LP#2146291: Set "resolve_entities='internal'" as default for + all parser subclasses. + +CVE: CVE-2026-41066 +Upstream-Status: Backport [https://github.com/lxml/lxml/commit/ab431ea0b9a7357d968f1d1c5c614649e9aaf358] + +Backport Changes: +- Keep the lxml 5.0.2 XMLParser signature without decompress. +- Keep the iterparse documentation and signature changes on existing + source lines, avoiding unrelated Cython source-location changes in + etree.c. +- Regenerate src/lxml/etree.c with Cython 3.0.9 using Python 3.12: + python3.12 setup.py build_ext -i --with-cython --warnings -j1. + The command was run from an otherwise clean lxml 5.0.2 source tree + after applying the .pxi changes; the generated C file is retained + because the Scarthgap recipe does not depend on Cython at build time. + +(cherry picked from commit ab431ea0b9a7357d968f1d1c5c614649e9aaf358) +Signed-off-by: Darsh Kelaiya +--- + src/lxml/etree.c | 40 ++++++++++++++++++++-------------------- + src/lxml/iterparse.pxi | 6 +++--- + src/lxml/parser.pxi | 6 +++--- + 3 files changed, 26 insertions(+), 26 deletions(-) + +diff --git a/src/lxml/etree.c b/src/lxml/etree.c +index 6012a1b..41b3c45 100644 +--- a/src/lxml/etree.c ++++ b/src/lxml/etree.c +@@ -3146,7 +3146,7 @@ struct __pyx_obj_4lxml_5etree__FeedParser { + * ) + * + * cdef class XMLParser(_FeedParser): # <<<<<<<<<<<<<< +- * u"""XMLParser(self, encoding=None, attribute_defaults=False, dtd_validation=False, load_dtd=False, no_network=True, ns_clean=False, recover=False, schema: XMLSchema =None, huge_tree=False, remove_blank_text=False, resolve_entities=True, remove_comments=False, remove_pis=False, strip_cdata=True, collect_ids=True, target=None, compact=True) ++ * u"""XMLParser(self, encoding=None, attribute_defaults=False, dtd_validation=False, load_dtd=False, no_network=True, ns_clean=False, recover=False, schema: XMLSchema =None, huge_tree=False, remove_blank_text=False, resolve_entities='internal', remove_comments=False, remove_pis=False, strip_cdata=True, collect_ids=True, target=None, compact=True) + * + */ + struct __pyx_obj_4lxml_5etree_XMLParser { +@@ -5424,7 +5424,7 @@ static struct __pyx_vtabstruct_4lxml_5etree__FeedParser *__pyx_vtabptr_4lxml_5et + * ) + * + * cdef class XMLParser(_FeedParser): # <<<<<<<<<<<<<< +- * u"""XMLParser(self, encoding=None, attribute_defaults=False, dtd_validation=False, load_dtd=False, no_network=True, ns_clean=False, recover=False, schema: XMLSchema =None, huge_tree=False, remove_blank_text=False, resolve_entities=True, remove_comments=False, remove_pis=False, strip_cdata=True, collect_ids=True, target=None, compact=True) ++ * u"""XMLParser(self, encoding=None, attribute_defaults=False, dtd_validation=False, load_dtd=False, no_network=True, ns_clean=False, recover=False, schema: XMLSchema =None, huge_tree=False, remove_blank_text=False, resolve_entities='internal', remove_comments=False, remove_pis=False, strip_cdata=True, collect_ids=True, target=None, compact=True) + * + */ + +@@ -142620,7 +142620,7 @@ static int __pyx_pw_4lxml_5etree_17ETCompatXMLParser_1__init__(PyObject *__pyx_v + * def __init__(self, *, encoding=None, attribute_defaults=False, + * dtd_validation=False, load_dtd=False, no_network=True, # <<<<<<<<<<<<<< + * ns_clean=False, recover=False, schema=None, +- * huge_tree=False, remove_blank_text=False, resolve_entities=True, ++ * huge_tree=False, remove_blank_text=False, resolve_entities='internal', + */ + values[2] = __Pyx_Arg_NewRef_VARARGS(((PyObject *)Py_False)); + values[3] = __Pyx_Arg_NewRef_VARARGS(((PyObject *)Py_False)); +@@ -142630,7 +142630,7 @@ static int __pyx_pw_4lxml_5etree_17ETCompatXMLParser_1__init__(PyObject *__pyx_v + * def __init__(self, *, encoding=None, attribute_defaults=False, + * dtd_validation=False, load_dtd=False, no_network=True, + * ns_clean=False, recover=False, schema=None, # <<<<<<<<<<<<<< +- * huge_tree=False, remove_blank_text=False, resolve_entities=True, ++ * huge_tree=False, remove_blank_text=False, resolve_entities='internal', + * remove_comments=True, remove_pis=True, strip_cdata=True, + */ + values[5] = __Pyx_Arg_NewRef_VARARGS(((PyObject *)Py_False)); +@@ -142640,17 +142640,17 @@ static int __pyx_pw_4lxml_5etree_17ETCompatXMLParser_1__init__(PyObject *__pyx_v + /* "src/lxml/parser.pxi":1703 + * dtd_validation=False, load_dtd=False, no_network=True, + * ns_clean=False, recover=False, schema=None, +- * huge_tree=False, remove_blank_text=False, resolve_entities=True, # <<<<<<<<<<<<<< ++ * huge_tree=False, remove_blank_text=False, resolve_entities='internal', # <<<<<<<<<<<<<< + * remove_comments=True, remove_pis=True, strip_cdata=True, + * target=None, compact=True): + */ + values[8] = __Pyx_Arg_NewRef_VARARGS(((PyObject *)Py_False)); + values[9] = __Pyx_Arg_NewRef_VARARGS(((PyObject *)Py_False)); +- values[10] = __Pyx_Arg_NewRef_VARARGS(((PyObject *)Py_True)); ++ values[10] = __Pyx_Arg_NewRef_VARARGS(((PyObject *)__pyx_n_s_internal)); + + /* "src/lxml/parser.pxi":1704 + * ns_clean=False, recover=False, schema=None, +- * huge_tree=False, remove_blank_text=False, resolve_entities=True, ++ * huge_tree=False, remove_blank_text=False, resolve_entities='internal', + * remove_comments=True, remove_pis=True, strip_cdata=True, # <<<<<<<<<<<<<< + * target=None, compact=True): + * XMLParser.__init__(self, +@@ -142660,7 +142660,7 @@ static int __pyx_pw_4lxml_5etree_17ETCompatXMLParser_1__init__(PyObject *__pyx_v + values[13] = __Pyx_Arg_NewRef_VARARGS(((PyObject *)Py_True)); + + /* "src/lxml/parser.pxi":1705 +- * huge_tree=False, remove_blank_text=False, resolve_entities=True, ++ * huge_tree=False, remove_blank_text=False, resolve_entities='internal', + * remove_comments=True, remove_pis=True, strip_cdata=True, + * target=None, compact=True): # <<<<<<<<<<<<<< + * XMLParser.__init__(self, +@@ -191418,7 +191418,7 @@ static int __pyx_pw_4lxml_5etree_9iterparse_1__init__(PyObject *__pyx_v_self, Py + * def __init__(self, source, events=(u"end",), *, tag=None, + * attribute_defaults=False, dtd_validation=False, # <<<<<<<<<<<<<< + * load_dtd=False, no_network=True, remove_blank_text=False, +- * compact=True, resolve_entities=True, remove_comments=False, ++ * compact=True, resolve_entities='internal', remove_comments=False, + */ + values[3] = __Pyx_Arg_NewRef_VARARGS(((PyObject *)Py_False)); + values[4] = __Pyx_Arg_NewRef_VARARGS(((PyObject *)Py_False)); +@@ -191427,7 +191427,7 @@ static int __pyx_pw_4lxml_5etree_9iterparse_1__init__(PyObject *__pyx_v_self, Py + * def __init__(self, source, events=(u"end",), *, tag=None, + * attribute_defaults=False, dtd_validation=False, + * load_dtd=False, no_network=True, remove_blank_text=False, # <<<<<<<<<<<<<< +- * compact=True, resolve_entities=True, remove_comments=False, ++ * compact=True, resolve_entities='internal', remove_comments=False, + * remove_pis=False, strip_cdata=True, encoding=None, + */ + values[5] = __Pyx_Arg_NewRef_VARARGS(((PyObject *)Py_False)); +@@ -191437,17 +191437,17 @@ static int __pyx_pw_4lxml_5etree_9iterparse_1__init__(PyObject *__pyx_v_self, Py + /* "src/lxml/iterparse.pxi":70 + * attribute_defaults=False, dtd_validation=False, + * load_dtd=False, no_network=True, remove_blank_text=False, +- * compact=True, resolve_entities=True, remove_comments=False, # <<<<<<<<<<<<<< ++ * compact=True, resolve_entities='internal', remove_comments=False, # <<<<<<<<<<<<<< + * remove_pis=False, strip_cdata=True, encoding=None, + * html=False, recover=None, huge_tree=False, collect_ids=True, + */ + values[8] = __Pyx_Arg_NewRef_VARARGS(((PyObject *)Py_True)); +- values[9] = __Pyx_Arg_NewRef_VARARGS(((PyObject *)Py_True)); ++ values[9] = __Pyx_Arg_NewRef_VARARGS(((PyObject *)__pyx_n_s_internal)); + values[10] = __Pyx_Arg_NewRef_VARARGS(((PyObject *)Py_False)); + + /* "src/lxml/iterparse.pxi":71 + * load_dtd=False, no_network=True, remove_blank_text=False, +- * compact=True, resolve_entities=True, remove_comments=False, ++ * compact=True, resolve_entities='internal', remove_comments=False, + * remove_pis=False, strip_cdata=True, encoding=None, # <<<<<<<<<<<<<< + * html=False, recover=None, huge_tree=False, collect_ids=True, + * XMLSchema schema=None): +@@ -191457,7 +191457,7 @@ static int __pyx_pw_4lxml_5etree_9iterparse_1__init__(PyObject *__pyx_v_self, Py + values[13] = __Pyx_Arg_NewRef_VARARGS(((PyObject *)Py_None)); + + /* "src/lxml/iterparse.pxi":72 +- * compact=True, resolve_entities=True, remove_comments=False, ++ * compact=True, resolve_entities='internal', remove_comments=False, + * remove_pis=False, strip_cdata=True, encoding=None, + * html=False, recover=None, huge_tree=False, collect_ids=True, # <<<<<<<<<<<<<< + * XMLSchema schema=None): +@@ -263534,7 +263534,7 @@ static PyMethodDef __pyx_methods_4lxml_5etree_XMLParser[] = { + }; + #if CYTHON_USE_TYPE_SPECS + static PyType_Slot __pyx_type_4lxml_5etree_XMLParser_slots[] = { +- {Py_tp_doc, (void *)PyDoc_STR("XMLParser(self, encoding=None, attribute_defaults=False, dtd_validation=False, load_dtd=False, no_network=True, ns_clean=False, recover=False, schema: XMLSchema =None, huge_tree=False, remove_blank_text=False, resolve_entities=True, remove_comments=False, remove_pis=False, strip_cdata=True, collect_ids=True, target=None, compact=True)\n\n The XML parser.\n\n Parsers can be supplied as additional argument to various parse\n functions of the lxml API. A default parser is always available\n and can be replaced by a call to the global function\n 'set_default_parser'. New parsers can be created at any time\n without a major run-time overhead.\n\n The keyword arguments in the constructor are mainly based on the\n libxml2 parser configuration. A DTD will also be loaded if DTD\n validation or attribute default values are requested (unless you\n additionally provide an XMLSchema from which the default\n attributes can be read).\n\n Available boolean keyword arguments:\n\n - attribute_defaults - inject default attributes from DTD or XMLSchema\n - dtd_validation - validate against a DTD referenced by the document\n - load_dtd - use DTD for parsing\n - no_network - prevent network access for related files (default: True)\n - ns_clean - clean up redundant namespace declarations\n - recover - try hard to parse through broken XML\n - remove_blank_text - discard blank text nodes that appear ignorable\n - remove_comments - discard comments\n - remove_pis - discard processing instructions\n - strip_cdata - replace CDATA sections by normal text content (default: True)\n - compact - save memory for short text content (default: True)\n - collect_ids - use a hash table of XML IDs for fast access (default: True, always True with DTD validation)\n - huge_tree - disable security restrictions and support very deep trees\n "" and very long text content (only affects libxml2 2.7+)\n\n Other keyword arguments:\n\n - resolve_entities - replace entities by their text value: False for keeping the\n entity references, True for resolving them, and 'internal' for resolving\n internal definitions only (no external file/URL access).\n The default used to be True and was changed to 'internal' in lxml 5.0.\n - encoding - override the document encoding (note: libiconv encoding name)\n - target - a parser target object that will receive the parse events\n - schema - an XMLSchema to validate against\n\n Note that you should avoid sharing parsers between threads. While this is\n not harmful, it is more efficient to use separate parsers. This does not\n apply to the default parser.\n ")}, ++ {Py_tp_doc, (void *)PyDoc_STR("XMLParser(self, encoding=None, attribute_defaults=False, dtd_validation=False, load_dtd=False, no_network=True, ns_clean=False, recover=False, schema: XMLSchema =None, huge_tree=False, remove_blank_text=False, resolve_entities='internal', remove_comments=False, remove_pis=False, strip_cdata=True, collect_ids=True, target=None, compact=True)\n\n The XML parser.\n\n Parsers can be supplied as additional argument to various parse\n functions of the lxml API. A default parser is always available\n and can be replaced by a call to the global function\n 'set_default_parser'. New parsers can be created at any time\n without a major run-time overhead.\n\n The keyword arguments in the constructor are mainly based on the\n libxml2 parser configuration. A DTD will also be loaded if DTD\n validation or attribute default values are requested (unless you\n additionally provide an XMLSchema from which the default\n attributes can be read).\n\n Available boolean keyword arguments:\n\n - attribute_defaults - inject default attributes from DTD or XMLSchema\n - dtd_validation - validate against a DTD referenced by the document\n - load_dtd - use DTD for parsing\n - no_network - prevent network access for related files (default: True)\n - ns_clean - clean up redundant namespace declarations\n - recover - try hard to parse through broken XML\n - remove_blank_text - discard blank text nodes that appear ignorable\n - remove_comments - discard comments\n - remove_pis - discard processing instructions\n - strip_cdata - replace CDATA sections by normal text content (default: True)\n - compact - save memory for short text content (default: True)\n - collect_ids - use a hash table of XML IDs for fast access (default: True, always True with DTD validation)\n - huge_tree - disable security restrictions and support very deep trees""\n and very long text content (only affects libxml2 2.7+)\n\n Other keyword arguments:\n\n - resolve_entities - replace entities by their text value: False for keeping the\n entity references, True for resolving them, and 'internal' for resolving\n internal definitions only (no external file/URL access).\n The default used to be True and was changed to 'internal' in lxml 5.0.\n - encoding - override the document encoding (note: libiconv encoding name)\n - target - a parser target object that will receive the parse events\n - schema - an XMLSchema to validate against\n\n Note that you should avoid sharing parsers between threads. While this is\n not harmful, it is more efficient to use separate parsers. This does not\n apply to the default parser.\n ")}, + {Py_tp_traverse, (void *)__pyx_tp_traverse_4lxml_5etree__BaseParser}, + {Py_tp_clear, (void *)__pyx_tp_clear_4lxml_5etree__BaseParser}, + {Py_tp_methods, (void *)__pyx_methods_4lxml_5etree_XMLParser}, +@@ -263582,7 +263582,7 @@ static PyTypeObject __pyx_type_4lxml_5etree_XMLParser = { + 0, /*tp_setattro*/ + 0, /*tp_as_buffer*/ + Py_TPFLAGS_DEFAULT|Py_TPFLAGS_HAVE_VERSION_TAG|Py_TPFLAGS_CHECKTYPES|Py_TPFLAGS_HAVE_NEWBUFFER|Py_TPFLAGS_BASETYPE|Py_TPFLAGS_HAVE_GC, /*tp_flags*/ +- PyDoc_STR("XMLParser(self, encoding=None, attribute_defaults=False, dtd_validation=False, load_dtd=False, no_network=True, ns_clean=False, recover=False, schema: XMLSchema =None, huge_tree=False, remove_blank_text=False, resolve_entities=True, remove_comments=False, remove_pis=False, strip_cdata=True, collect_ids=True, target=None, compact=True)\n\n The XML parser.\n\n Parsers can be supplied as additional argument to various parse\n functions of the lxml API. A default parser is always available\n and can be replaced by a call to the global function\n 'set_default_parser'. New parsers can be created at any time\n without a major run-time overhead.\n\n The keyword arguments in the constructor are mainly based on the\n libxml2 parser configuration. A DTD will also be loaded if DTD\n validation or attribute default values are requested (unless you\n additionally provide an XMLSchema from which the default\n attributes can be read).\n\n Available boolean keyword arguments:\n\n - attribute_defaults - inject default attributes from DTD or XMLSchema\n - dtd_validation - validate against a DTD referenced by the document\n - load_dtd - use DTD for parsing\n - no_network - prevent network access for related files (default: True)\n - ns_clean - clean up redundant namespace declarations\n - recover - try hard to parse through broken XML\n - remove_blank_text - discard blank text nodes that appear ignorable\n - remove_comments - discard comments\n - remove_pis - discard processing instructions\n - strip_cdata - replace CDATA sections by normal text content (default: True)\n - compact - save memory for short text content (default: True)\n - collect_ids - use a hash table of XML IDs for fast access (default: True, always True with DTD validation)\n - huge_tree - disable security restrictions and support very deep trees\n "" and very long text content (only affects libxml2 2.7+)\n\n Other keyword arguments:\n\n - resolve_entities - replace entities by their text value: False for keeping the\n entity references, True for resolving them, and 'internal' for resolving\n internal definitions only (no external file/URL access).\n The default used to be True and was changed to 'internal' in lxml 5.0.\n - encoding - override the document encoding (note: libiconv encoding name)\n - target - a parser target object that will receive the parse events\n - schema - an XMLSchema to validate against\n\n Note that you should avoid sharing parsers between threads. While this is\n not harmful, it is more efficient to use separate parsers. This does not\n apply to the default parser.\n "), /*tp_doc*/ ++ PyDoc_STR("XMLParser(self, encoding=None, attribute_defaults=False, dtd_validation=False, load_dtd=False, no_network=True, ns_clean=False, recover=False, schema: XMLSchema =None, huge_tree=False, remove_blank_text=False, resolve_entities='internal', remove_comments=False, remove_pis=False, strip_cdata=True, collect_ids=True, target=None, compact=True)\n\n The XML parser.\n\n Parsers can be supplied as additional argument to various parse\n functions of the lxml API. A default parser is always available\n and can be replaced by a call to the global function\n 'set_default_parser'. New parsers can be created at any time\n without a major run-time overhead.\n\n The keyword arguments in the constructor are mainly based on the\n libxml2 parser configuration. A DTD will also be loaded if DTD\n validation or attribute default values are requested (unless you\n additionally provide an XMLSchema from which the default\n attributes can be read).\n\n Available boolean keyword arguments:\n\n - attribute_defaults - inject default attributes from DTD or XMLSchema\n - dtd_validation - validate against a DTD referenced by the document\n - load_dtd - use DTD for parsing\n - no_network - prevent network access for related files (default: True)\n - ns_clean - clean up redundant namespace declarations\n - recover - try hard to parse through broken XML\n - remove_blank_text - discard blank text nodes that appear ignorable\n - remove_comments - discard comments\n - remove_pis - discard processing instructions\n - strip_cdata - replace CDATA sections by normal text content (default: True)\n - compact - save memory for short text content (default: True)\n - collect_ids - use a hash table of XML IDs for fast access (default: True, always True with DTD validation)\n - huge_tree - disable security restrictions and support very deep trees""\n and very long text content (only affects libxml2 2.7+)\n\n Other keyword arguments:\n\n - resolve_entities - replace entities by their text value: False for keeping the\n entity references, True for resolving them, and 'internal' for resolving\n internal definitions only (no external file/URL access).\n The default used to be True and was changed to 'internal' in lxml 5.0.\n - encoding - override the document encoding (note: libiconv encoding name)\n - target - a parser target object that will receive the parse events\n - schema - an XMLSchema to validate against\n\n Note that you should avoid sharing parsers between threads. While this is\n not harmful, it is more efficient to use separate parsers. This does not\n apply to the default parser.\n "), /*tp_doc*/ + __pyx_tp_traverse_4lxml_5etree__BaseParser, /*tp_traverse*/ + __pyx_tp_clear_4lxml_5etree__BaseParser, /*tp_clear*/ + 0, /*tp_richcompare*/ +@@ -263763,7 +263763,7 @@ static PyMethodDef __pyx_methods_4lxml_5etree_ETCompatXMLParser[] = { + }; + #if CYTHON_USE_TYPE_SPECS + static PyType_Slot __pyx_type_4lxml_5etree_ETCompatXMLParser_slots[] = { +- {Py_tp_doc, (void *)PyDoc_STR("ETCompatXMLParser(self, encoding=None, attribute_defaults=False, dtd_validation=False, load_dtd=False, no_network=True, ns_clean=False, recover=False, schema=None, huge_tree=False, remove_blank_text=False, resolve_entities=True, remove_comments=True, remove_pis=True, strip_cdata=True, target=None, compact=True)\n\n An XML parser with an ElementTree compatible default setup.\n\n See the XMLParser class for details.\n\n This parser has ``remove_comments`` and ``remove_pis`` enabled by default\n and thus ignores comments and processing instructions.\n ")}, ++ {Py_tp_doc, (void *)PyDoc_STR("ETCompatXMLParser(self, encoding=None, attribute_defaults=False, dtd_validation=False, load_dtd=False, no_network=True, ns_clean=False, recover=False, schema=None, huge_tree=False, remove_blank_text=False, resolve_entities='internal', remove_comments=True, remove_pis=True, strip_cdata=True, target=None, compact=True)\n\n An XML parser with an ElementTree compatible default setup.\n\n See the XMLParser class for details.\n\n This parser has ``remove_comments`` and ``remove_pis`` enabled by default\n and thus ignores comments and processing instructions.\n ")}, + {Py_tp_traverse, (void *)__pyx_tp_traverse_4lxml_5etree__BaseParser}, + {Py_tp_clear, (void *)__pyx_tp_clear_4lxml_5etree__BaseParser}, + {Py_tp_methods, (void *)__pyx_methods_4lxml_5etree_ETCompatXMLParser}, +@@ -263811,7 +263811,7 @@ static PyTypeObject __pyx_type_4lxml_5etree_ETCompatXMLParser = { + 0, /*tp_setattro*/ + 0, /*tp_as_buffer*/ + Py_TPFLAGS_DEFAULT|Py_TPFLAGS_HAVE_VERSION_TAG|Py_TPFLAGS_CHECKTYPES|Py_TPFLAGS_HAVE_NEWBUFFER|Py_TPFLAGS_BASETYPE|Py_TPFLAGS_HAVE_GC, /*tp_flags*/ +- PyDoc_STR("ETCompatXMLParser(self, encoding=None, attribute_defaults=False, dtd_validation=False, load_dtd=False, no_network=True, ns_clean=False, recover=False, schema=None, huge_tree=False, remove_blank_text=False, resolve_entities=True, remove_comments=True, remove_pis=True, strip_cdata=True, target=None, compact=True)\n\n An XML parser with an ElementTree compatible default setup.\n\n See the XMLParser class for details.\n\n This parser has ``remove_comments`` and ``remove_pis`` enabled by default\n and thus ignores comments and processing instructions.\n "), /*tp_doc*/ ++ PyDoc_STR("ETCompatXMLParser(self, encoding=None, attribute_defaults=False, dtd_validation=False, load_dtd=False, no_network=True, ns_clean=False, recover=False, schema=None, huge_tree=False, remove_blank_text=False, resolve_entities='internal', remove_comments=True, remove_pis=True, strip_cdata=True, target=None, compact=True)\n\n An XML parser with an ElementTree compatible default setup.\n\n See the XMLParser class for details.\n\n This parser has ``remove_comments`` and ``remove_pis`` enabled by default\n and thus ignores comments and processing instructions.\n "), /*tp_doc*/ + __pyx_tp_traverse_4lxml_5etree__BaseParser, /*tp_traverse*/ + __pyx_tp_clear_4lxml_5etree__BaseParser, /*tp_clear*/ + 0, /*tp_richcompare*/ +@@ -267005,7 +267005,7 @@ static struct PyGetSetDef __pyx_getsets_4lxml_5etree_iterparse[] = { + #if CYTHON_USE_TYPE_SPECS + static PyType_Slot __pyx_type_4lxml_5etree_iterparse_slots[] = { + {Py_tp_dealloc, (void *)__pyx_tp_dealloc_4lxml_5etree_iterparse}, +- {Py_tp_doc, (void *)PyDoc_STR("iterparse(self, source, events=(\"end\",), tag=None, attribute_defaults=False, dtd_validation=False, load_dtd=False, no_network=True, remove_blank_text=False, remove_comments=False, remove_pis=False, encoding=None, html=False, recover=None, huge_tree=False, schema=None)\n\n Incremental parser.\n\n Parses XML into a tree and generates tuples (event, element) in a\n SAX-like fashion. ``event`` is any of 'start', 'end', 'start-ns',\n 'end-ns'.\n\n For 'start' and 'end', ``element`` is the Element that the parser just\n found opening or closing. For 'start-ns', it is a tuple (prefix, URI) of\n a new namespace declaration. For 'end-ns', it is simply None. Note that\n all start and end events are guaranteed to be properly nested.\n\n The keyword argument ``events`` specifies a sequence of event type names\n that should be generated. By default, only 'end' events will be\n generated.\n\n The additional ``tag`` argument restricts the 'start' and 'end' events to\n those elements that match the given tag. The ``tag`` argument can also be\n a sequence of tags to allow matching more than one tag. By default,\n events are generated for all elements. Note that the 'start-ns' and\n 'end-ns' events are not impacted by this restriction.\n\n The other keyword arguments in the constructor are mainly based on the\n libxml2 parser configuration. A DTD will also be loaded if validation or\n attribute default values are requested.\n\n Available boolean keyword arguments:\n - attribute_defaults: read default attributes from DTD\n - dtd_validation: validate (if DTD is available)\n - load_dtd: use DTD for parsing\n - no_network: prevent network access for related files\n - remove_blank_text: discard blank text nodes\n - remove_comments: discard comments\n - remove_pis: discard processing instructions\n - strip_cdata: repla""ce CDATA sections by normal text content (default: True)\n - compact: safe memory for short text content (default: True)\n - resolve_entities: replace entities by their text value (default: True)\n - huge_tree: disable security restrictions and support very deep trees\n and very long text content (only affects libxml2 2.7+)\n - html: parse input as HTML (default: XML)\n - recover: try hard to parse through broken input (default: True for HTML,\n False otherwise)\n\n Other keyword arguments:\n - encoding: override the document encoding\n - schema: an XMLSchema to validate against\n ")}, ++ {Py_tp_doc, (void *)PyDoc_STR("iterparse(self, source, events=(\"end\",), tag=None, attribute_defaults=False, dtd_validation=False, load_dtd=False, no_network=True, remove_blank_text=False, compact=True, resolve_entities='internal', remove_comments=False, remove_pis=False, strip_cdata=True, encoding=None, html=False, recover=None, huge_tree=False, schema=None)\n\n Incremental parser.\n\n Parses XML into a tree and generates tuples (event, element) in a\n SAX-like fashion. ``event`` is any of 'start', 'end', 'start-ns',\n 'end-ns'.\n\n For 'start' and 'end', ``element`` is the Element that the parser just\n found opening or closing. For 'start-ns', it is a tuple (prefix, URI) of\n a new namespace declaration. For 'end-ns', it is simply None. Note that\n all start and end events are guaranteed to be properly nested.\n\n The keyword argument ``events`` specifies a sequence of event type names\n that should be generated. By default, only 'end' events will be\n generated.\n\n The additional ``tag`` argument restricts the 'start' and 'end' events to\n those elements that match the given tag. The ``tag`` argument can also be\n a sequence of tags to allow matching more than one tag. By default,\n events are generated for all elements. Note that the 'start-ns' and\n 'end-ns' events are not impacted by this restriction.\n\n The other keyword arguments in the constructor are mainly based on the\n libxml2 parser configuration. A DTD will also be loaded if validation or\n attribute default values are requested.\n\n Available boolean keyword arguments:\n - attribute_defaults: read default attributes from DTD\n - dtd_validation: validate (if DTD is available)\n - load_dtd: use DTD for parsing\n - no_network: prevent network access for related files\n - remove_blank_text: discard blank text nodes\n - remove_comments: discard comments\n - remove_pi""s: discard processing instructions\n - strip_cdata: replace CDATA sections by normal text content (default: True)\n - compact: safe memory for short text content (default: True)\n - resolve_entities: replace entities by their text value (default: 'internal' only)\n - huge_tree: disable security restrictions and support very deep trees\n and very long text content (only affects libxml2 2.7+)\n - html: parse input as HTML (default: XML)\n - recover: try hard to parse through broken input (default: True for HTML,\n False otherwise)\n\n Other keyword arguments:\n - encoding: override the document encoding\n - schema: an XMLSchema to validate against\n ")}, + {Py_tp_traverse, (void *)__pyx_tp_traverse_4lxml_5etree_iterparse}, + {Py_tp_clear, (void *)__pyx_tp_clear_4lxml_5etree_iterparse}, + {Py_tp_iter, (void *)__pyx_pw_4lxml_5etree_9iterparse_7__iter__}, +@@ -267056,7 +267056,7 @@ static PyTypeObject __pyx_type_4lxml_5etree_iterparse = { + 0, /*tp_setattro*/ + 0, /*tp_as_buffer*/ + Py_TPFLAGS_DEFAULT|Py_TPFLAGS_HAVE_VERSION_TAG|Py_TPFLAGS_CHECKTYPES|Py_TPFLAGS_HAVE_NEWBUFFER|Py_TPFLAGS_BASETYPE|Py_TPFLAGS_HAVE_GC, /*tp_flags*/ +- PyDoc_STR("iterparse(self, source, events=(\"end\",), tag=None, attribute_defaults=False, dtd_validation=False, load_dtd=False, no_network=True, remove_blank_text=False, remove_comments=False, remove_pis=False, encoding=None, html=False, recover=None, huge_tree=False, schema=None)\n\n Incremental parser.\n\n Parses XML into a tree and generates tuples (event, element) in a\n SAX-like fashion. ``event`` is any of 'start', 'end', 'start-ns',\n 'end-ns'.\n\n For 'start' and 'end', ``element`` is the Element that the parser just\n found opening or closing. For 'start-ns', it is a tuple (prefix, URI) of\n a new namespace declaration. For 'end-ns', it is simply None. Note that\n all start and end events are guaranteed to be properly nested.\n\n The keyword argument ``events`` specifies a sequence of event type names\n that should be generated. By default, only 'end' events will be\n generated.\n\n The additional ``tag`` argument restricts the 'start' and 'end' events to\n those elements that match the given tag. The ``tag`` argument can also be\n a sequence of tags to allow matching more than one tag. By default,\n events are generated for all elements. Note that the 'start-ns' and\n 'end-ns' events are not impacted by this restriction.\n\n The other keyword arguments in the constructor are mainly based on the\n libxml2 parser configuration. A DTD will also be loaded if validation or\n attribute default values are requested.\n\n Available boolean keyword arguments:\n - attribute_defaults: read default attributes from DTD\n - dtd_validation: validate (if DTD is available)\n - load_dtd: use DTD for parsing\n - no_network: prevent network access for related files\n - remove_blank_text: discard blank text nodes\n - remove_comments: discard comments\n - remove_pis: discard processing instructions\n - strip_cdata: repla""ce CDATA sections by normal text content (default: True)\n - compact: safe memory for short text content (default: True)\n - resolve_entities: replace entities by their text value (default: True)\n - huge_tree: disable security restrictions and support very deep trees\n and very long text content (only affects libxml2 2.7+)\n - html: parse input as HTML (default: XML)\n - recover: try hard to parse through broken input (default: True for HTML,\n False otherwise)\n\n Other keyword arguments:\n - encoding: override the document encoding\n - schema: an XMLSchema to validate against\n "), /*tp_doc*/ ++ PyDoc_STR("iterparse(self, source, events=(\"end\",), tag=None, attribute_defaults=False, dtd_validation=False, load_dtd=False, no_network=True, remove_blank_text=False, compact=True, resolve_entities='internal', remove_comments=False, remove_pis=False, strip_cdata=True, encoding=None, html=False, recover=None, huge_tree=False, schema=None)\n\n Incremental parser.\n\n Parses XML into a tree and generates tuples (event, element) in a\n SAX-like fashion. ``event`` is any of 'start', 'end', 'start-ns',\n 'end-ns'.\n\n For 'start' and 'end', ``element`` is the Element that the parser just\n found opening or closing. For 'start-ns', it is a tuple (prefix, URI) of\n a new namespace declaration. For 'end-ns', it is simply None. Note that\n all start and end events are guaranteed to be properly nested.\n\n The keyword argument ``events`` specifies a sequence of event type names\n that should be generated. By default, only 'end' events will be\n generated.\n\n The additional ``tag`` argument restricts the 'start' and 'end' events to\n those elements that match the given tag. The ``tag`` argument can also be\n a sequence of tags to allow matching more than one tag. By default,\n events are generated for all elements. Note that the 'start-ns' and\n 'end-ns' events are not impacted by this restriction.\n\n The other keyword arguments in the constructor are mainly based on the\n libxml2 parser configuration. A DTD will also be loaded if validation or\n attribute default values are requested.\n\n Available boolean keyword arguments:\n - attribute_defaults: read default attributes from DTD\n - dtd_validation: validate (if DTD is available)\n - load_dtd: use DTD for parsing\n - no_network: prevent network access for related files\n - remove_blank_text: discard blank text nodes\n - remove_comments: discard comments\n - remove_pi""s: discard processing instructions\n - strip_cdata: replace CDATA sections by normal text content (default: True)\n - compact: safe memory for short text content (default: True)\n - resolve_entities: replace entities by their text value (default: 'internal' only)\n - huge_tree: disable security restrictions and support very deep trees\n and very long text content (only affects libxml2 2.7+)\n - html: parse input as HTML (default: XML)\n - recover: try hard to parse through broken input (default: True for HTML,\n False otherwise)\n\n Other keyword arguments:\n - encoding: override the document encoding\n - schema: an XMLSchema to validate against\n "), /*tp_doc*/ + __pyx_tp_traverse_4lxml_5etree_iterparse, /*tp_traverse*/ + __pyx_tp_clear_4lxml_5etree_iterparse, /*tp_clear*/ + 0, /*tp_richcompare*/ +diff --git a/src/lxml/iterparse.pxi b/src/lxml/iterparse.pxi +index 2758b14..d8fc02f 100644 +--- a/src/lxml/iterparse.pxi ++++ b/src/lxml/iterparse.pxi +@@ -6,7 +6,7 @@ cdef class iterparse: + u"""iterparse(self, source, events=("end",), tag=None, \ + attribute_defaults=False, dtd_validation=False, \ + load_dtd=False, no_network=True, remove_blank_text=False, \ +- remove_comments=False, remove_pis=False, encoding=None, \ ++ compact=True, resolve_entities='internal', remove_comments=False, remove_pis=False, strip_cdata=True, encoding=None, \ + html=False, recover=None, huge_tree=False, schema=None) + + Incremental parser. +@@ -44,7 +44,7 @@ cdef class iterparse: + - remove_pis: discard processing instructions + - strip_cdata: replace CDATA sections by normal text content (default: True) + - compact: safe memory for short text content (default: True) +- - resolve_entities: replace entities by their text value (default: True) ++ - resolve_entities: replace entities by their text value (default: 'internal' only) + - huge_tree: disable security restrictions and support very deep trees + and very long text content (only affects libxml2 2.7+) + - html: parse input as HTML (default: XML) +@@ -67,7 +67,7 @@ cdef class iterparse: + def __init__(self, source, events=(u"end",), *, tag=None, + attribute_defaults=False, dtd_validation=False, + load_dtd=False, no_network=True, remove_blank_text=False, +- compact=True, resolve_entities=True, remove_comments=False, ++ compact=True, resolve_entities='internal', remove_comments=False, + remove_pis=False, strip_cdata=True, encoding=None, + html=False, recover=None, huge_tree=False, collect_ids=True, + XMLSchema schema=None): +diff --git a/src/lxml/parser.pxi b/src/lxml/parser.pxi +index e9f4bec..bded239 100644 +--- a/src/lxml/parser.pxi ++++ b/src/lxml/parser.pxi +@@ -1564,7 +1564,7 @@ _XML_DEFAULT_PARSE_OPTIONS = ( + ) + + cdef class XMLParser(_FeedParser): +- u"""XMLParser(self, encoding=None, attribute_defaults=False, dtd_validation=False, load_dtd=False, no_network=True, ns_clean=False, recover=False, schema: XMLSchema =None, huge_tree=False, remove_blank_text=False, resolve_entities=True, remove_comments=False, remove_pis=False, strip_cdata=True, collect_ids=True, target=None, compact=True) ++ u"""XMLParser(self, encoding=None, attribute_defaults=False, dtd_validation=False, load_dtd=False, no_network=True, ns_clean=False, recover=False, schema: XMLSchema =None, huge_tree=False, remove_blank_text=False, resolve_entities='internal', remove_comments=False, remove_pis=False, strip_cdata=True, collect_ids=True, target=None, compact=True) + + The XML parser. + +@@ -1686,7 +1686,7 @@ cdef class ETCompatXMLParser(XMLParser): + u"""ETCompatXMLParser(self, encoding=None, attribute_defaults=False, \ + dtd_validation=False, load_dtd=False, no_network=True, \ + ns_clean=False, recover=False, schema=None, \ +- huge_tree=False, remove_blank_text=False, resolve_entities=True, \ ++ huge_tree=False, remove_blank_text=False, resolve_entities='internal', \ + remove_comments=True, remove_pis=True, strip_cdata=True, \ + target=None, compact=True) + +@@ -1700,7 +1700,7 @@ cdef class ETCompatXMLParser(XMLParser): + def __init__(self, *, encoding=None, attribute_defaults=False, + dtd_validation=False, load_dtd=False, no_network=True, + ns_clean=False, recover=False, schema=None, +- huge_tree=False, remove_blank_text=False, resolve_entities=True, ++ huge_tree=False, remove_blank_text=False, resolve_entities='internal', + remove_comments=True, remove_pis=True, strip_cdata=True, + target=None, compact=True): + XMLParser.__init__(self, diff --git a/meta/recipes-devtools/python/python3-lxml_5.0.2.bb b/meta/recipes-devtools/python/python3-lxml_5.0.2.bb index c0b385c7ea8..2d2d55202c0 100644 --- a/meta/recipes-devtools/python/python3-lxml_5.0.2.bb +++ b/meta/recipes-devtools/python/python3-lxml_5.0.2.bb @@ -20,7 +20,9 @@ DEPENDS += "libxml2 libxslt" SRC_URI[sha256sum] = "6399703c40ba53e2c3b72fdb56cb908d2b83c08082ecf17de839b27e68d1e598" -SRC_URI += "${PYPI_SRC_URI}" +SRC_URI += "${PYPI_SRC_URI} \ + file://CVE-2026-41066.patch \ + " inherit pkgconfig pypi setuptools3 # {standard input}: Assembler messages: From patchwork Fri Sep 11 22:15:05 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 98076 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 3DECEC88E50 for ; Fri, 11 Sep 2026 22:16:01 +0000 (UTC) Received: from mail-wm2-f12.google.com (mail-wm2-f12.google.com [74.125.225.140]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.50892.1789164951634588858 for ; Fri, 11 Sep 2026 15:15:51 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=ugQfoIVd; spf=pass (domain: smile.fr, ip: 74.125.225.140, mailfrom: yoann.congal@smile.fr) Received: by mail-wm2-f12.google.com with SMTP id 5b1f17b1804b1-49b912d822dso470445e9.2 for ; Fri, 11 Sep 2026 15:15:51 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1789164950; x=1789769750; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=067A+DjUQf7dXPbO1H2XVLZbPTNE+AIDysJ6ehso6kM=; b=ugQfoIVdfZ0YDaiHwCFNOLr9kBUwEEc+n9IrjnHJFIYWPtwHx+CUYZQzP4auQXvAXV yH3uyiIpUSps7UdQMsG9kQqvCXB7lt46XE2X7xmQ6OuxP+Ht7PiWQTqow7ZTHrU+ThRi gZ+sex3zxMoG72P+C4Lgz12F6X+/JxAz/pBsw= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1789164950; x=1789769750; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=067A+DjUQf7dXPbO1H2XVLZbPTNE+AIDysJ6ehso6kM=; b=ZO2kacjA1Esk4S0WUptIUEygcrjrBcnFdK359DIbqVscnk+FStfzJt4+mWSe73gva/ y1DEr0IMTYAMmN6R8w2haSk1KgpIjLiZOvY9y0SLWJM+JVjNV5tVGrDsLfLe6OD/ob1G nTr0yJRdW9+wWQ4VQ2yb6ZnQ1OZgksRbXU9xQu7AqMc4KSqITRASgLOOibCFIUSwTHCG opXxCmyl/qqUtjQNdPAdvgmriuEnsO5KvwdKm+GC26EPgCi29vn0hZrBGcrPS7OSGsuA COEs7rVlM+2uU7Fy9TlfGJ+nJgKPu6eohYegcvV4bROTYb14X0xHbeWBNX0LXlLW4k5u a51w== X-Gm-Message-State: AFuF++kbs6sz9XU0DrO7cyt2314PSgza7GlIfrKBnfZgzkuGtDPbcZTR 7pmR8/iS2r7xZU6xPRfk7IHJg/ny6pfGiWBCgv3suk6c78Bxg1FqJUyZfMW10xU9DQI9pBrG1hG q2lA5KB8= X-Gm-Gg: AYBFou3b/W2MILzWDoAXoE/6Ab429l77re+xRlrMyGMVadleVSN1tlNbK3VtooUoGdB QDwF31AvbNLC8N+y2ipGNUsAcJPwc/w8aiI6T89vYeuj/Mx0yIgaIuP/nk31rEhC/pic2ZWavtc 1RvTxN8oT9/twAwQnE6c/ZIFMQBEGadu5C+FdwzYWt3+lVBEQeei+TSpbdBq8bGwdQrdoXY+Y4l eJKrQQsoW6UetzLW5jJlw6UoniQj/tJeBYOttcLhN7iqwj9pfn8K4CVzgUqQze2J0Du3aDuVtuR 2hj7ViO53ytGjAkphduPUW9qD7mvaGkZVw7RKFnJPoaOOv9ulDW6j3fLN8YjUO/tFt/MP4i+CPZ 2KrQlEhYy6crvuG61+0BjVDjteuayezkzfWfx/say4hCHbfA/ndLulkqv+bQ4CC0JDZgsdUgyuV agzWnyFS2rmSv+TgQgAjzoMciWZpjtQRIOO4jJYu9goRlpDcwuDqcmcCqRNdbn1mrTbNhpGxxfO rrOfIZiao4IpuH9hQWDyByygP5GawRKgETgC3GYPVxo+9pC6MfxrPBexmEaMwmNyl9gDmrrUhuF X-Received: by 2002:a05:600c:548f:b0:496:c1f3:e8f8 with SMTP id 5b1f17b1804b1-49e6caa69e8mr1359155e9.7.1789164949853; Fri, 11 Sep 2026 15:15:49 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-49e6c566bdbsm8434045e9.11.2026.09.11.15.15.49 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Fri, 11 Sep 2026 15:15:49 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][scarthgap 11/13] libarchive: mark CVE-2026-14164 as fixed-version Date: Sat, 12 Sep 2026 00:15:05 +0200 Message-ID: X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Fri, 11 Sep 2026 22:16:01 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/245681 From: Daniel Turull The RAR5 double-free in init_unpack() is a regression introduced upstream by commit 620bdafa on 2026-05-16 and existed only on the git master branch until it was fixed by PR #3071 (commit 1c914cdf) on 2026-05-24. It was never part of an upstream release. The upstream release tarballs (3.6.x/3.7.x/3.8.6) use the older init_unpack() with unchecked calloc and no early-return path, so the freed window_buf/filtered_buf pointers are never left dangling and the double-free cannot occur. References: https://nvd.nist.gov/vuln/detail/CVE-2026-14164 https://lore.kernel.org/openembedded-core/0447ebc9d29b0736de8ba0c75f155ed4f880d072.camel@pbarker.dev/ Signed-off-by: Daniel Turull Signed-off-by: Yoann Congal --- meta/recipes-extended/libarchive/libarchive_3.7.9.bb | 5 +++++ 1 file changed, 5 insertions(+) diff --git a/meta/recipes-extended/libarchive/libarchive_3.7.9.bb b/meta/recipes-extended/libarchive/libarchive_3.7.9.bb index b36632cc1fe..2eb22e2d61a 100644 --- a/meta/recipes-extended/libarchive/libarchive_3.7.9.bb +++ b/meta/recipes-extended/libarchive/libarchive_3.7.9.bb @@ -84,3 +84,8 @@ ALTERNATIVE_LINK_NAME[cpio] = "${base_bindir}/cpio" ALTERNATIVE_TARGET[cpio] = "${bindir}/bsdcpio" BBCLASSEXTEND = "native nativesdk" + +CVE_STATUS[CVE-2026-14164] = "fixed-version: Double-free regression in the RAR5\ + reader's init_unpack() was introduced upstream by commit 620bdafa (2026-05-16) and existed\ + only on the git master branch until the fix in PR #3071 (commit 1c914cdf, 2026-05-24). It was\ + never part of an upstream release tarball." From patchwork Fri Sep 11 22:15:06 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 98077 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 20733C88E5D for ; Fri, 11 Sep 2026 22:16:02 +0000 (UTC) Received: from mail-wm2-f13.google.com (mail-wm2-f13.google.com [74.125.225.141]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.50893.1789164952255613770 for ; Fri, 11 Sep 2026 15:15:52 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=biMdg2VD; spf=pass (domain: smile.fr, ip: 74.125.225.141, mailfrom: yoann.congal@smile.fr) Received: by mail-wm2-f13.google.com with SMTP id 5b1f17b1804b1-49cd38e0f79so1967905e9.3 for ; Fri, 11 Sep 2026 15:15:52 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1789164950; x=1789769750; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=nAYu83NUihV8yhAk+YaLXMx6JOScET0E9BQeu4jPkGc=; b=biMdg2VDiPx9BjL4Dqtb2ycrZLjn7NI0dX8N6rCGPuQE1EQ6F/MJldfgqMRJ2fEFcx GgRqlW1jBm91VXiUJlzuUUND6RpqL+J4QjYp211RJ+k5vvCldd48NvCns52VfhJFnGWF yW0I12JzGcPVBUO06FveKNSCIUHvaoyMbOt1U= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1789164950; x=1789769750; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=nAYu83NUihV8yhAk+YaLXMx6JOScET0E9BQeu4jPkGc=; b=Qw5vYg4OYBuFlUrNnTnHbCdr0o/W2UMtWxF3OZ86ipw3C4aMpQY0VvR92ghvBUzUpI 8oQokvJ8Fa704tHrvqSS6fNX00hY6QHsp8LqCMPSAhqEPTWs87eUuoBWJzKS0kX1Lah6 yucbiAWZGQEnIGZdieDxUPFlPZ71PLjOXUGdBcXUSdRJOK5SEAnJXoMDqVYBmeYdCAf8 rkTQWpW3TZhngIF8IHE5aXdPSqzHSbLGKtTsTWH3z7Ryg4Cdg7JTlCH0b1sW9cZMNdCM qiENWTe60Dix5warbAGVieYc/6A4OAKuYYpZ2yMaAdrv2a83t7q6Hwvu3ZiwMiksBiEZ fMag== X-Gm-Message-State: AFuF++ny8/Ciaydi+ZXtDPAHcfUU3P3kylXEg/XR3tLeZamN29Xzucd6 kHKHxDRWDqJXGOEgn45W1eY6JCjevw1wj4YB/rjw0C9WNHkLlGuD0T4eJThKeqdbu8jxoNTdhTO yvMzzB+c= X-Gm-Gg: AYBFou2R9oHpt/P/E9bF6/IOeIh6wnrlhlZiUtUP+v/r/jaO3ZqO7EPE2Tp3M2TcY5/ 0JUw/ULDpI7/uLLE5F4KnOzrkl7tbh/b0OjNTxHLSL6aXYjTIQ5Yo/9hV4hZTMKVv7MDj6123Un gEWRNyKSGMabKS96bzh8MxOpbeCm+YEEr2c2DexBx1JoxGNjkFiiZsV97VulA6Wx4AjbzFeAgsa jBEJk0SK9PAmnTFOQd1CRniFy+Mfb/Rp2q7a7YE2m3OZO1v6MqGcpON99KsQt/3mW0aWPVf9/M2 alb1wazslrceFdtcTKXjM4Qh1B3d4P9jsOxvCjJVGF+1R7ikfhch1XWfpWGVADhKF48bouDHmTo xvhSXyoooxv08ikl0YRtOoyLevaNG24XXRW0MIAyp6JIrMqJ5JlUa6RYYrdsqX49QrVlNs4icYP Aw1J1YMAaXkuYNFJ9/hwSgx/GHoGh2lCNiVvIfTjd0vHLfHRVCwBiQOLH7kV5p98tNYwPV83q0u kpU4hQNKHiwc1UQq/O9zdC7hQft2rw6VGMLzQwKuIvgsRnzEC3m3R83P81pxFv+nAtr2a3tDsA= X-Received: by 2002:a05:600c:a40e:b0:49e:65ac:eb5f with SMTP id 5b1f17b1804b1-49e65aced4bmr95420965e9.10.1789164950388; Fri, 11 Sep 2026 15:15:50 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-49e6c566bdbsm8434045e9.11.2026.09.11.15.15.50 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Fri, 11 Sep 2026 15:15:50 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][scarthgap 12/13] u-boot: share CVE_PRODUCT with u-boot-tools Date: Sat, 12 Sep 2026 00:15:06 +0200 Message-ID: <3efc243b9260e393d88ece4dc445551726f688c7.1789163914.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Fri, 11 Sep 2026 22:16:02 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/245682 From: Devansh Patel u-boot-tools builds host utilities from the same source as u-boot, but it does not inherit the existing CVE_PRODUCT assignment and falls back to its unrecognized recipe-name identity. Move the mapping to u-boot-common.inc so both recipes inherit it. Use "u-boot:u-boot" for the CNA/CVE List V5 affected-data identity and "denx:u-boot" for the NVD dictionary CPE and configuration identity. The CNA records are also covered by NVD today, but retaining both authoritative identities permits direct matching independently of NVD enrichment. (cherry picked from commit bc30a343627e2d207c38d2262a7b07f506259051) Signed-off-by: Devansh Patel Signed-off-by: Mathieu Dubois-Briand Signed-off-by: Richard Purdie Signed-off-by: Hiago De Franco Signed-off-by: Yoann Congal --- meta/recipes-bsp/u-boot/u-boot-common.inc | 2 ++ meta/recipes-bsp/u-boot/u-boot.inc | 2 -- 2 files changed, 2 insertions(+), 2 deletions(-) diff --git a/meta/recipes-bsp/u-boot/u-boot-common.inc b/meta/recipes-bsp/u-boot/u-boot-common.inc index 5f6bd44ab77..27e6ac9db5b 100644 --- a/meta/recipes-bsp/u-boot/u-boot-common.inc +++ b/meta/recipes-bsp/u-boot/u-boot-common.inc @@ -10,6 +10,8 @@ LICENSE = "GPL-2.0-or-later" LIC_FILES_CHKSUM = "file://Licenses/README;md5=2ca5f2c35c8cc335f0a19756634782f1" PE = "1" +CVE_PRODUCT = "u-boot:u-boot denx:u-boot" + # We use the revision in order to avoid having to fetch it from the # repo during parse SRCREV = "866ca972d6c3cabeaf6dbac431e8e08bb30b3c8e" diff --git a/meta/recipes-bsp/u-boot/u-boot.inc b/meta/recipes-bsp/u-boot/u-boot.inc index 00dda93b4ac..7935f2b4aa4 100644 --- a/meta/recipes-bsp/u-boot/u-boot.inc +++ b/meta/recipes-bsp/u-boot/u-boot.inc @@ -19,8 +19,6 @@ PACKAGECONFIG ??= "openssl" # a host build dependency. PACKAGECONFIG[openssl] = ",,openssl-native" -CVE_PRODUCT = "denx:u-boot" - # Allow setting an additional version string that will be picked up by the # u-boot build system and appended to the u-boot version. If the .scmversion # file already exists it will not be overwritten. From patchwork Fri Sep 11 22:15:07 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 98075 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 2410BC88E4D for ; Fri, 11 Sep 2026 22:16:01 +0000 (UTC) Received: from mail-wm2-f13.google.com (mail-wm2-f13.google.com [74.125.225.141]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.50894.1789164952981931698 for ; Fri, 11 Sep 2026 15:15:53 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=GRs6IO2t; spf=pass (domain: smile.fr, ip: 74.125.225.141, mailfrom: yoann.congal@smile.fr) Received: by mail-wm2-f13.google.com with SMTP id 5b1f17b1804b1-49ccf3ca94bso299405e9.3 for ; Fri, 11 Sep 2026 15:15:52 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1789164951; x=1789769751; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=ZHjWo0WaDDAl05bPFxgISGavG/4SMIm6ccr4cZ5Xhtk=; b=GRs6IO2tqFwOf7dwu7Dxeui5q8XC67MEmvmIGFxyagGCpCDx6UldmKT5vk+L0ZIQGA R03s3d9M5uXaQWQNTR+ZeSYpVde5xl5nNRnandPWtG51Q828WYXEtOLGT+Ro1USfPLbK ZzUVylF/378Fj5xvWqYtUOJZ1mCkAHctMhwBU= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1789164951; x=1789769751; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=ZHjWo0WaDDAl05bPFxgISGavG/4SMIm6ccr4cZ5Xhtk=; b=e8XQ++mXomN1wevkqP8HXRzE6zC2tpxDoBgWrqoMJUbhd2IZXeFnmpWNHXi85R2uRx 1RF+s0l6uf8P0xIe28LMtK5giQBrWmPatqiPN9mI3LzS3t70HR4H+bC57Adv6RQhM++p mcsFReGd1V7AHfs9jb08abEX5O2pW9KrAektchJfjwlB+k8cHt1rK2boo9lizIKn1bPT igeUwh6sjd2SL7IzJ8aX3qOxK3ZJ/1NS5E1c+vk5VvA9u5MXYwsIwvJyCnvk15WNnYQO SUZk8FifuS42xoLFgQzQGTtrQi51voTF+lkM6nFqM8bDcN90B5cT09KNbj25wLfZm79V 8HBg== X-Gm-Message-State: AFuF++kjmnCQeJGlu0/bDPSM7UNlekeMxy2L3I29qO6sXtLXm01Ixwru 1RUU9SkzARMmQ86zUt4GGS/YI3io2vwPXUIq8uM/pwzvXjMp4wYRPCvjlHTlDsoEM0z01zcfcSY R4k+v7HQ= X-Gm-Gg: AYBFou24NNvxwbFKkwzhG9w+wuYeGk+/7eeIAztfbTC8CEcajl2nQATDGvaD7kizzTD kbrb6xiULkbLPKW/oXvmGwyxNLa3zSjg+Iye0nn5BgFbaS+QYWFIfK6BiCMU7eoPFRRlD4HVjWN PmwGhPbnbjXCUvKpfBIabGqnkloq9R5ar1/m2Pu0R0tZ2OvBBqGf+FiMfeTosbrVsX5h8T4NDCG TQJ9Xq/nBWZnqjp3GLw2fttM2gjAOCAFHweoJqpwmk9s+gbKA0hZiSeKZg28gGMKO20k9JaawuH PUEbyRR6Pe413hH1w/24n4qQnfbIqZKDcwhi55msYMDoLZW6AFe49dyazYsvEXs1bPoDXx9F8DO bXVJ+AwtcDYG0fCbRsq1W/0ThWrvcOoJ6x61tZ0Qu12bNrjB65wEySkDyoLnpKmBeT5eE5+fZVN SSvLcuJsvdgBI27ssrVHIIH6Tg4xHHN7NM4JvYRMRHjSEJUXZV55ublrTBGzg17Smi682BzJJZL sWsAcmvV0Z7TJU2zD9gvgfo/jZKD2yICngK1yyh3W4u8ZqTZLTzPh3c+lsAOCCzxI9Hxvky4l0= X-Received: by 2002:a05:600c:4709:b0:49c:fc6c:be00 with SMTP id 5b1f17b1804b1-49e6cbf7526mr1214995e9.23.1789164950995; Fri, 11 Sep 2026 15:15:50 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-49e6c566bdbsm8434045e9.11.2026.09.11.15.15.50 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Fri, 11 Sep 2026 15:15:50 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][scarthgap 13/13] u-boot, u-boot-tools: Fix CVE-2026-46728 Date: Sat, 12 Sep 2026 00:15:07 +0200 Message-ID: X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Fri, 11 Sep 2026 22:16:01 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/245683 From: Hetvi Thakar This patch applies the upstream U-Boot fix referenced by the advisory in [2], using the commit shown in [1]. The fix rebuilds the FIT signed-node list from the selected configuration instead of trusting the attacker-controlled hashed-nodes property. [1] https://github.com/u-boot/u-boot/commit/2092322b31cc [2] https://nvd.nist.gov/vuln/detail/CVE-2026-46728 Signed-off-by: Hetvi Thakar Signed-off-by: Yoann Congal --- .../u-boot/files/CVE-2026-46728.patch | 379 ++++++++++++++++++ .../u-boot/u-boot-tools_2024.01.bb | 2 + meta/recipes-bsp/u-boot/u-boot_2024.01.bb | 1 + 3 files changed, 382 insertions(+) create mode 100644 meta/recipes-bsp/u-boot/files/CVE-2026-46728.patch diff --git a/meta/recipes-bsp/u-boot/files/CVE-2026-46728.patch b/meta/recipes-bsp/u-boot/files/CVE-2026-46728.patch new file mode 100644 index 00000000000..e6737f38a6d --- /dev/null +++ b/meta/recipes-bsp/u-boot/files/CVE-2026-46728.patch @@ -0,0 +1,379 @@ +From 2092322b31cc8b1f8c9e2e238d1043ae0637b241 Mon Sep 17 00:00:00 2001 +From: Simon Glass +Date: Thu, 5 Mar 2026 18:20:09 -0700 +Subject: [PATCH] boot: Add fit_config_get_hash_list() to build signed node + list + +The hashed-nodes property in a FIT signature node lists which FDT paths +are included in the signature hash. It is intended as a hint so should +not be used for verification. + +Add a function to build the node list from scratch by iterating the +configuration's image references. Skip properties known not to be image +references. For each image, collect the path plus all hash and cipher +subnodes. + +Use the new function in fit_config_check_sig() instead of reading +'hashed-nodes'. + +Update the test_vboot kernel@ test case: fit_check_sign now catches the +attack at signature-verification time (the @-suffixed node is hashed +instead of the real one, causing a mismatch) rather than at +fit_check_format() time. + +Update the docs to cover this. The FIT spec can be updated separately. + +Signed-off-by: Simon Glass +Closes: https://lore.kernel.org/u-boot/20260302220937.3682128-1-trini@konsulko.com/ +Reported-by: Apple Security Engineering and Architecture (SEAR) +Tested-by: Tom Rini + +CVE: CVE-2026-46728 +Upstream-Status: Backport [https://github.com/u-boot/u-boot/commit/2092322b31cc8b1f8c9e2e238d1043ae0637b241] + +Backport Changes: +- Use the v2024.01 FIT_COMP_PROP name for the compatible property. +- Adapt test_vboot.py context to the v2024.01 test layout. + +(cherry picked from commit 2092322b31cc8b1f8c9e2e238d1043ae0637b241) +Signed-off-by: Hetvi Thakar +--- + boot/image-fit-sig.c | 227 +++++++++++++++++++++++++++++------- + doc/usage/fit/signature.rst | 19 ++- + test/py/tests/test_vboot.py | 8 +- + 3 files changed, 201 insertions(+), 53 deletions(-) + +diff --git a/boot/image-fit-sig.c b/boot/image-fit-sig.c +index 12369896..79e7ff93 100644 +--- a/boot/image-fit-sig.c ++++ b/boot/image-fit-sig.c +@@ -19,6 +19,7 @@ DECLARE_GLOBAL_DATA_PTR; + #include + + #define IMAGE_MAX_HASHED_NODES 100 ++#define FIT_MAX_HASH_PATH_BUF 4096 + + /** + * fit_region_make_list() - Make a list of image regions +@@ -225,6 +226,179 @@ int fit_image_verify_required_sigs(const void *fit, int image_noffset, + return 0; + } + ++/** ++ * fit_config_add_hash() - Add hash nodes for one image to the node list ++ * ++ * Adds the image path, all its hash-* subnode paths, and its cipher ++ * subnode path (if present) to the packed buffer. ++ * ++ * @fit: FIT blob ++ * @image_noffset: Image node offset (e.g. /images/kernel-1) ++ * @node_inc: Array of path pointers to fill ++ * @count: Pointer to current count (updated on return) ++ * @max_nodes: Maximum entries in @node_inc ++ * @buf: Buffer for packed path strings ++ * @buf_used: Pointer to bytes used in @buf (updated on return) ++ * @buf_len: Total size of @buf ++ * Return: 0 on success, -ve on error ++ */ ++static int fit_config_add_hash(const void *fit, int image_noffset, ++ char **node_inc, int *count, int max_nodes, ++ char *buf, int *buf_used, int buf_len) ++{ ++ int noffset, hash_count, ret, len; ++ ++ if (*count >= max_nodes) ++ return -ENOSPC; ++ ++ ret = fdt_get_path(fit, image_noffset, buf + *buf_used, ++ buf_len - *buf_used); ++ if (ret < 0) ++ return -ENOENT; ++ len = strlen(buf + *buf_used) + 1; ++ node_inc[(*count)++] = buf + *buf_used; ++ *buf_used += len; ++ ++ /* Add all this image's hash subnodes */ ++ hash_count = 0; ++ for (noffset = fdt_first_subnode(fit, image_noffset); ++ noffset >= 0; ++ noffset = fdt_next_subnode(fit, noffset)) { ++ const char *name = fit_get_name(fit, noffset, NULL); ++ ++ if (strncmp(name, FIT_HASH_NODENAME, ++ strlen(FIT_HASH_NODENAME))) ++ continue; ++ if (*count >= max_nodes) ++ return -ENOSPC; ++ ret = fdt_get_path(fit, noffset, buf + *buf_used, ++ buf_len - *buf_used); ++ if (ret < 0) ++ return -ENOENT; ++ len = strlen(buf + *buf_used) + 1; ++ node_inc[(*count)++] = buf + *buf_used; ++ *buf_used += len; ++ hash_count++; ++ } ++ ++ if (!hash_count) { ++ printf("No hash nodes in image '%s'\n", ++ fdt_get_name(fit, image_noffset, NULL)); ++ return -ENOMSG; ++ } ++ ++ /* Add this image's cipher node if present */ ++ noffset = fdt_subnode_offset(fit, image_noffset, FIT_CIPHER_NODENAME); ++ if (noffset != -FDT_ERR_NOTFOUND) { ++ if (noffset < 0) ++ return -EIO; ++ if (*count >= max_nodes) ++ return -ENOSPC; ++ ret = fdt_get_path(fit, noffset, buf + *buf_used, ++ buf_len - *buf_used); ++ if (ret < 0) ++ return -ENOENT; ++ len = strlen(buf + *buf_used) + 1; ++ node_inc[(*count)++] = buf + *buf_used; ++ *buf_used += len; ++ } ++ ++ return 0; ++} ++ ++/** ++ * fit_config_get_hash_list() - Build the list of nodes to hash ++ * ++ * Works through every image referenced by the configuration and collects the ++ * node paths: root + config + all referenced images with their hash and ++ * cipher subnodes. ++ * ++ * Properties known not to be image references (description, compatible, ++ * default, load-only) are skipped, so any new image type is covered by default. ++ * ++ * @fit: FIT blob ++ * @conf_noffset: Configuration node offset ++ * @node_inc: Array to fill with path string pointers ++ * @max_nodes: Size of @node_inc array ++ * @buf: Buffer for packed null-terminated path strings ++ * @buf_len: Size of @buf ++ * Return: number of entries in @node_inc, or -ve on error ++ */ ++static int fit_config_get_hash_list(const void *fit, int conf_noffset, ++ char **node_inc, int max_nodes, ++ char *buf, int buf_len) ++{ ++ const char *conf_name; ++ int image_count; ++ int prop_offset; ++ int used = 0; ++ int count = 0; ++ int ret, len; ++ ++ conf_name = fit_get_name(fit, conf_noffset, NULL); ++ ++ /* Always include the root node and the configuration node */ ++ if (max_nodes < 2) ++ return -ENOSPC; ++ ++ len = 2; /* "/" + nul */ ++ if (len > buf_len) ++ return -ENOSPC; ++ strcpy(buf, "/"); ++ node_inc[count++] = buf; ++ used += len; ++ ++ len = snprintf(buf + used, buf_len - used, "%s/%s", FIT_CONFS_PATH, ++ conf_name) + 1; ++ if (used + len > buf_len) ++ return -ENOSPC; ++ node_inc[count++] = buf + used; ++ used += len; ++ ++ /* Process each image referenced by the config */ ++ image_count = 0; ++ fdt_for_each_property_offset(prop_offset, fit, conf_noffset) { ++ const char *prop_name; ++ int img_count, i; ++ ++ fdt_getprop_by_offset(fit, prop_offset, &prop_name, NULL); ++ if (!prop_name) ++ continue; ++ ++ /* Skip properties that are not image references */ ++ if (!strcmp(prop_name, FIT_DESC_PROP) || ++ !strcmp(prop_name, FIT_COMP_PROP) || ++ !strcmp(prop_name, FIT_DEFAULT_PROP)) ++ continue; ++ ++ img_count = fdt_stringlist_count(fit, conf_noffset, prop_name); ++ for (i = 0; i < img_count; i++) { ++ int noffset; ++ ++ noffset = fit_conf_get_prop_node_index(fit, ++ conf_noffset, ++ prop_name, i); ++ if (noffset < 0) ++ continue; ++ ++ ret = fit_config_add_hash(fit, noffset, node_inc, ++ &count, max_nodes, buf, &used, ++ buf_len); ++ if (ret < 0) ++ return ret; ++ ++ image_count++; ++ } ++ } ++ ++ if (!image_count) { ++ printf("No images in config '%s'\n", conf_name); ++ return -ENOMSG; ++ } ++ ++ return count; ++} ++ + /** + * fit_config_check_sig() - Check the signature of a config + * +@@ -265,20 +439,16 @@ static int fit_config_check_sig(const void *fit, int noffset, int conf_noffset, + FIT_DATA_POSITION_PROP, + FIT_DATA_OFFSET_PROP, + }; +- +- const char *prop, *end, *name; ++ char *node_inc[IMAGE_MAX_HASHED_NODES]; ++ char hash_buf[FIT_MAX_HASH_PATH_BUF]; + struct image_sign_info info; + const uint32_t *strings; +- const char *config_name; + uint8_t *fit_value; + int fit_value_len; +- bool found_config; + int max_regions; +- int i, prop_len; + char path[200]; + int count; + +- config_name = fit_get_name(fit, conf_noffset, NULL); + debug("%s: fdt=%p, conf='%s', sig='%s'\n", __func__, key_blob, + fit_get_name(fit, noffset, NULL), + fit_get_name(key_blob, required_keynode, NULL)); +@@ -293,45 +463,12 @@ static int fit_config_check_sig(const void *fit, int noffset, int conf_noffset, + return -1; + } + +- /* Count the number of strings in the property */ +- prop = fdt_getprop(fit, noffset, "hashed-nodes", &prop_len); +- end = prop ? prop + prop_len : prop; +- for (name = prop, count = 0; name < end; name++) +- if (!*name) +- count++; +- if (!count) { +- *err_msgp = "Can't get hashed-nodes property"; +- return -1; +- } +- +- if (prop && prop_len > 0 && prop[prop_len - 1] != '\0') { +- *err_msgp = "hashed-nodes property must be null-terminated"; +- return -1; +- } +- +- /* Add a sanity check here since we are using the stack */ +- if (count > IMAGE_MAX_HASHED_NODES) { +- *err_msgp = "Number of hashed nodes exceeds maximum"; +- return -1; +- } +- +- /* Create a list of node names from those strings */ +- char *node_inc[count]; +- +- debug("Hash nodes (%d):\n", count); +- found_config = false; +- for (name = prop, i = 0; name < end; name += strlen(name) + 1, i++) { +- debug(" '%s'\n", name); +- node_inc[i] = (char *)name; +- if (!strncmp(FIT_CONFS_PATH, name, strlen(FIT_CONFS_PATH)) && +- name[sizeof(FIT_CONFS_PATH) - 1] == '/' && +- !strcmp(name + sizeof(FIT_CONFS_PATH), config_name)) { +- debug(" (found config node %s)", config_name); +- found_config = true; +- } +- } +- if (!found_config) { +- *err_msgp = "Selected config not in hashed nodes"; ++ /* Build the node list from the config, ignoring hashed-nodes */ ++ count = fit_config_get_hash_list(fit, conf_noffset, ++ node_inc, IMAGE_MAX_HASHED_NODES, ++ hash_buf, sizeof(hash_buf)); ++ if (count < 0) { ++ *err_msgp = "Failed to build hash node list"; + return -1; + } + +diff --git a/doc/usage/fit/signature.rst b/doc/usage/fit/signature.rst +index 0804bffd..80373234 100644 +--- a/doc/usage/fit/signature.rst ++++ b/doc/usage/fit/signature.rst +@@ -353,20 +353,27 @@ meantime. + Details + ------- + The signature node contains a property ('hashed-nodes') which lists all the +-nodes that the signature was made over. The image is walked in order and each +-tag processed as follows: ++nodes that the signature was made over. The signer (mkimage) writes this ++property as a record of what was included in the hash. During verification, ++however, U-Boot does not read 'hashed-nodes'. Instead it rebuilds the node ++list from the configuration's own image references (kernel, fdt, ramdisk, ++etc.), since 'hashed-nodes' is not itself covered by the signature. The ++rebuilt list always includes the root node, the configuration node, each ++referenced image node and its hash/cipher subnodes. ++ ++The image is walked in order and each tag processed as follows: + + DTB_BEGIN_NODE + The tag and the following name are included in the signature +- if the node or its parent are present in 'hashed-nodes' ++ if the node or its parent are present in the node list + + DTB_END_NODE + The tag is included in the signature if the node or its parent +- are present in 'hashed-nodes' ++ are present in the node list + + DTB_PROPERTY + The tag, the length word, the offset in the string table, and +- the data are all included if the current node is present in 'hashed-nodes' ++ the data are all included if the current node is present in the node list + and the property name is not 'data'. + + DTB_END +@@ -374,7 +381,7 @@ DTB_END + + DTB_NOP + The tag is included in the signature if the current node is present +- in 'hashed-nodes' ++ in the node list + + In addition, the signature contains a property 'hashed-strings' which contains + the offset and length in the string table of the strings that are to be +diff --git a/test/py/tests/test_vboot.py b/test/py/tests/test_vboot.py +index 04fa59f9..817eb980 100644 +--- a/test/py/tests/test_vboot.py ++++ b/test/py/tests/test_vboot.py +@@ -362,10 +362,14 @@ def test_vboot(u_boot_console, name, sha_algo, padding, sign_options, required, + shutil.copyfile(fit, efit) + vboot_evil.add_evil_node(fit, efit, evil_kernel, 'kernel@') + +- msg = 'Signature checking prevents use of unit addresses (@) in nodes' ++ # fit_check_sign catches this via signature mismatch (the @ ++ # node is hashed instead of the real one) + util.run_and_log_expect_exception( + cons, [fit_check_sign, '-f', efit, '-k', dtb], +- 1, msg) ++ 1, 'Failed to verify required signature') ++ ++ # bootm catches it earlier, at fit_check_format() time ++ msg = 'Signature checking prevents use of unit addresses (@) in nodes' + run_bootm(sha_algo, 'evil kernel@', msg, False, efit) + + # Create a new properly signed fit and replace header bytes diff --git a/meta/recipes-bsp/u-boot/u-boot-tools_2024.01.bb b/meta/recipes-bsp/u-boot/u-boot-tools_2024.01.bb index 7eaf721ca83..4b6d89ed4e1 100644 --- a/meta/recipes-bsp/u-boot/u-boot-tools_2024.01.bb +++ b/meta/recipes-bsp/u-boot/u-boot-tools_2024.01.bb @@ -1,2 +1,4 @@ require u-boot-common.inc require u-boot-tools.inc + +SRC_URI += "file://CVE-2026-46728.patch" diff --git a/meta/recipes-bsp/u-boot/u-boot_2024.01.bb b/meta/recipes-bsp/u-boot/u-boot_2024.01.bb index e412f503f10..7eaeed1004b 100644 --- a/meta/recipes-bsp/u-boot/u-boot_2024.01.bb +++ b/meta/recipes-bsp/u-boot/u-boot_2024.01.bb @@ -12,4 +12,5 @@ SRC_URI += "file://CVE-2024-57254.patch \ file://CVE-2024-57258-3.patch \ file://CVE-2024-57259.patch \ file://CVE-2024-42040.patch \ + file://CVE-2026-46728.patch \ "