From patchwork Thu Sep 17 22:05:46 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 98568 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id D41CDC982D9 for ; Thu, 17 Sep 2026 22:07:53 +0000 (UTC) Received: from mail-wm2-f12.google.com (mail-wm2-f12.google.com [74.125.225.140]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.1553.1789682871810049853 for ; Thu, 17 Sep 2026 15:07:52 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=In94UOjd; spf=pass (domain: smile.fr, ip: 74.125.225.140, mailfrom: yoann.congal@smile.fr) Received: by mail-wm2-f12.google.com with SMTP id 5b1f17b1804b1-49b912d37b5so686325e9.2 for ; Thu, 17 Sep 2026 15:07:51 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1789682870; x=1790287670; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=jeDsP/cNzkyjIl54CbRsreT5mJwaLKHx9NeKVRraxWc=; b=In94UOjdFITE+3XPmkKL190TJpRUJwx8HDu1lOlID+9pzpjmRDbo6cNoA9GJ8ZRx4g Rw9ejytAt+J+yP4fJT18CCP4HWTZshm0DOrq5qs0RAB4lsVdr3fuTxtelFdB8LrP4AUJ gcpVKpkLAO22HBs2z2w5De2C1WV6aJk2H9phU= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1789682870; x=1790287670; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=jeDsP/cNzkyjIl54CbRsreT5mJwaLKHx9NeKVRraxWc=; b=d4tBuaTyNw5fHmtEWy2+UqLLlBjIyWSww5+mOqE2KM+klkOOjpwnRY5Uk4smh8uucT Ml2Uv81wgDPuM+agkkbQKgIKJGioG0F+BPhzC7apWBDba/evTY+WrE3JL7xnMqouQZ3Q VVfetYwGg8dXISYipOXDfYJ2cOwV+44r1aF4Z7GisrO60nWr7eBVCBfdvn3/31UDA469 AHnjA3xEVBBhtUOx0eWJDW0OU+2uOspLxfDIQLJfzptDrvYMaq08YRO9VkBZzxZiNC0X fznrhq42Nq4oD0iI7kyVsQ1jgKie3QOCAT7cDQ6Zcczmc6mCijAcKF7VstjSQ/55nxny HXgg== X-Gm-Message-State: AFuF++m0tJnr1kNqc1bdiFeJJLfOl9aoGgmgxIk9/ocD7QFeTf61KtWX 1UE8mcqZKypcEkHH1MVbtRHN+uSb4Sa4rDrvoezzIwMlnYwBA1A+C2NcUV+h8YWppTq5nmY3Aeg 9ys7CYkg= X-Gm-Gg: AYBFou0vOAiMIeITJseqYRgEMtLmTfkIO4nM8mTgETxNOfrFo4PvzxLWnYr1BpH2Ibd RauM9HmOs1tgCc/KLmaAVuyUYXcakc4jKQmyN0H7tScl8kFiCCpB9tJC+BRrMBz7CFrfE8VHUDr FrKN01hQsCGzvYNdUs0STar/KI8oFkjyNHxr35rJ4ZJTiDgMKK4Vaugy9lOejHlFVpW2Y/nRzmd uxGwu7aB1XwuStc6OB+BQy2AiGxNRIYmDhpZmHbCsmgLAd3uFTt8cpmQqBX0tuXSPHwodu9Sqpf oo2CJE2F/MKsPDbFL8tBZbP3QtHejfPEQYZH/h+NQXYwDiN5q6tow6pZt3HPA8Xt4qCcrhR2PKv d0qinA8/02VlullQpX6fJ5q8Wq2FyQAZTW13ilpKtUd6rxP54cEQwoD7qrAQs89zqRy0jWhfNec BSxVoeuIB4BQ/jxCMjuViOQhvWBEhhH9a+NmLdHbvzMb+fa0kY4PX1XaD2opEzKhLnJQYy5j8E+ NgAK8El/13LNOikbl3XAhEzd0Kv0isuODiv+StANYzspyk79Jq2AFbfeMfdsnQqCHDxN7kTOCY= X-Received: by 2002:a05:600c:46c5:b0:49e:6050:9fbe with SMTP id 5b1f17b1804b1-49fc573e80fmr5494615e9.15.1789682870158; Thu, 17 Sep 2026 15:07:50 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-49fc471b9a2sm8984075e9.0.2026.09.17.15.07.49 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Thu, 17 Sep 2026 15:07:49 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][wrynose 01/79] rootfs.py: fix run-postinsts removal on multilib images Date: Fri, 18 Sep 2026 00:05:46 +0200 Message-ID: X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Thu, 17 Sep 2026 22:07:53 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/246095 From: Kyungjik Min ROOTFS_BOOTSTRAP_INSTALL in image.bbclass unconditionally stages run-postinsts into every image. When no delayed postinsts remain, _uninstall_unneeded() is supposed to remove it again, but the removal call used the bare "run-postinsts" package name without applying MLPREFIX. On a multilib image (e.g. lib32-core-image-minimal), the package that is actually installed is lib32-run-postinsts, so the unprefixed removal silently matches nothing and run-postinsts leaks into the final image manifest, along with its now-pointless init script / systemd unit. Expand MLPREFIX before removing the package, matching the pattern already used elsewhere in oe-core (e.g. oe/package.py) for package-name lookups that need to work across multilib variants. Signed-off-by: Kyungjik Min Signed-off-by: Mathieu Dubois-Briand Signed-off-by: Richard Purdie (cherry picked from commit dfa5673907bdc5211671ecdfce8ab1fb332eae48) Signed-off-by: Yoann Congal --- meta/lib/oe/rootfs.py | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/meta/lib/oe/rootfs.py b/meta/lib/oe/rootfs.py index 7ef7e71f9e1..3504762b7ea 100644 --- a/meta/lib/oe/rootfs.py +++ b/meta/lib/oe/rootfs.py @@ -267,7 +267,8 @@ class Rootfs(object, metaclass=ABCMeta): delayed_postinsts = self._get_delayed_postinsts() if delayed_postinsts is None: if os.path.exists(self.d.expand("${IMAGE_ROOTFS}${sysconfdir}/init.d/run-postinsts")) or os.path.exists(self.d.expand("${IMAGE_ROOTFS}${systemd_system_unitdir}/run-postinsts.service")): - self.pm.remove(["run-postinsts"]) + mlprefix = self.d.getVar('MLPREFIX') or "" + self.pm.remove([mlprefix + "run-postinsts"]) image_rorfs = bb.utils.contains("IMAGE_FEATURES", "read-only-rootfs", True, False, self.d) and \ From patchwork Thu Sep 17 22:05:47 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 98567 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id D3389C982D0 for ; Thu, 17 Sep 2026 22:07:53 +0000 (UTC) Received: from mail-wm2-f12.google.com (mail-wm2-f12.google.com [74.125.225.140]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.1554.1789682872505545381 for ; Thu, 17 Sep 2026 15:07:52 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=vDZ1wM3S; spf=pass (domain: smile.fr, ip: 74.125.225.140, mailfrom: yoann.congal@smile.fr) Received: by mail-wm2-f12.google.com with SMTP id 5b1f17b1804b1-49cd38e0e5dso1333485e9.2 for ; Thu, 17 Sep 2026 15:07:52 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1789682870; x=1790287670; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=p1k89c+HjF1r8L1YEfsDallpilPWI6ndc4Xy6xccvEc=; b=vDZ1wM3SzsCVU4Ulua9xC/gY6mSUmWqRTSMa0ijVChHuRy6T2WuMvxhFZNl4K4x4wV ajGYukann7SGpV+FQ2Z3ndgeRhpVaBD18aXeM3hRHJ1y8Nr0nKo8bY1bsImH57oPXBuE tazNCuaakdWhl+Rt9mg39e8MPKoyBYU5DNqPU= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1789682870; x=1790287670; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=p1k89c+HjF1r8L1YEfsDallpilPWI6ndc4Xy6xccvEc=; b=nWUDy3PxZ0o9qbVQZNEaj9LLYFwuR17Z0g5vek3MDzdMQjKG0K2wLBxsQEAqn0L56v 4U/buK8jWO6hSxRPKbW+rBL103azrhO1Dte5v+ASMZaQr1EDSZ9MiBEwouz6srjOJecs hrWrJVBrlSae16rD6fAYyHAhRCs2RTtZajGArxxAaB/rEYmsGUcsy8ahh7Q5xwQBLXUu GYVRdEf9D/MOO2j7DJnrGOmR3Osg9U2HBjytX8Qxn81TgZXr4Rp1i4L4RhIS8fSWLIiC Lj87X0/BoItq+3E3gmiYQK7Ysg59napaEu0viCTQYMWgyQxDtNUMHkUdYvvT9xz0OsbE ynAQ== X-Gm-Message-State: AFuF++n3eloM4NoDGt1IfjZ1riIMoMt9dFvXekEkV/k+LRt/haZ24h1S Xb0e4qiAvITnjzyH6DQavWpnQVqzxhzBgTeEfy5XydTBM5cH8Mp2THriPud4LK4TGqo5ruYF781 joizFF+E= X-Gm-Gg: AYBFou0Y7DJKbEPIMLy0kpznNYMsR/BU38WOt6DMM8UbN2nE9Or8Gnlgf52V3OyJ8U3 5EWV6tCCh7chC4OHhujZnoiVLDtdn+UZov5XwxNbG5IBPQRZUltoaObFzY4KaG8U8R4O3rkrth9 pFXOH03C9u0ZT7caGZfIxLTboxe3yM6YjG8SeyrX2NLXeTHwncBH2tBbf1xC9OdkuvYMlwpWlsz ycv6JvnfbGSbsCjucVoeq5j7/2GsChGMVEftzWP2qgnO8gGRfNRfpUIo9EQIlsIpJPGS7H7oUp2 qM8TZAwMGT/r1tTs7tyqzSUxEU5VyMKf0KwWM2KVyZNNBHBqIwvFxOZfMPLucvrsEXCW7pi9wzl hYTJxelzacG+3C02NgfVZawNlGpXQAfj1SOfHv+e15Tp7YsmGQJGA15eZq26audRI2ySa+8G/kP W/FEhedTro5Bi42nDa77u7MsNgNaBfsyYvjcT/YyQXz6pgIIKm01UtwtJ7XofSKZfILIA4B4y+G ytp/YVsJWrtKVy/nS6Ueh5xfhC6IIMsW4Kz7WqSKSWbZlaMJ9HbiFFiPCmSWvIpEFzg8gGYC7A= X-Received: by 2002:a05:600c:a14:b0:49d:1e09:694a with SMTP id 5b1f17b1804b1-49fc568f869mr3137165e9.11.1789682870568; Thu, 17 Sep 2026 15:07:50 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-49fc471b9a2sm8984075e9.0.2026.09.17.15.07.50 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Thu, 17 Sep 2026 15:07:50 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][wrynose 02/79] wireless-regdb: upgrade 2026.05.30 -> 2026.09.03 Date: Fri, 18 Sep 2026 00:05:47 +0200 Message-ID: <09f0ff20c780957661214759771b0345eeda66c1.1789681419.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Thu, 17 Sep 2026 22:07:53 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/246097 From: Richard Purdie Signed-off-by: Richard Purdie (cherry picked from commit 7e92e1fe36a5767a7b31d96b9897357e0aa28cec) Signed-off-by: Ankur Tyagi Signed-off-by: Yoann Congal --- ...ireless-regdb_2026.05.30.bb => wireless-regdb_2026.09.03.bb} | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) rename meta/recipes-kernel/wireless-regdb/{wireless-regdb_2026.05.30.bb => wireless-regdb_2026.09.03.bb} (94%) diff --git a/meta/recipes-kernel/wireless-regdb/wireless-regdb_2026.05.30.bb b/meta/recipes-kernel/wireless-regdb/wireless-regdb_2026.09.03.bb similarity index 94% rename from meta/recipes-kernel/wireless-regdb/wireless-regdb_2026.05.30.bb rename to meta/recipes-kernel/wireless-regdb/wireless-regdb_2026.09.03.bb index e544b729656..ad84208f6e9 100644 --- a/meta/recipes-kernel/wireless-regdb/wireless-regdb_2026.05.30.bb +++ b/meta/recipes-kernel/wireless-regdb/wireless-regdb_2026.09.03.bb @@ -5,7 +5,7 @@ LICENSE = "ISC" LIC_FILES_CHKSUM = "file://LICENSE;md5=07c4f6dea3845b02a18dc00c8c87699c" SRC_URI = "https://www.kernel.org/pub/software/network/${BPN}/${BP}.tar.xz" -SRC_URI[sha256sum] = "8a27bfc081bafed8c24dd70fab0d96f098e5a0bfcd08d3da672595f225ab8993" +SRC_URI[sha256sum] = "b22e0901227b820cd1c280abe681a15b773a5103a5e10dc442e94ebb34cbf58d" inherit bin_package allarch From patchwork Thu Sep 17 22:05:48 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 98572 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 21664C982DC for ; Thu, 17 Sep 2026 22:07:54 +0000 (UTC) Received: from mail-wm2-f13.google.com (mail-wm2-f13.google.com [74.125.225.141]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.1667.1789682872776456416 for ; Thu, 17 Sep 2026 15:07:53 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=2U4oJJIQ; spf=pass (domain: smile.fr, ip: 74.125.225.141, mailfrom: yoann.congal@smile.fr) Received: by mail-wm2-f13.google.com with SMTP id 5b1f17b1804b1-49e7d2bb404so315665e9.1 for ; Thu, 17 Sep 2026 15:07:52 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1789682871; x=1790287671; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=ESC2QBsbUE5N5PD+6ShhZ82iIHEXAgPIIkbO9VXSidI=; b=2U4oJJIQX5KuiLNz4PrOnHoMw8D/Ok4nwarQX0pz6M/5GRH/OCNbVCqyIBRGf6//Ot T7lPAu2vCzpRA4kjquJ7rhCquZi5Qxkn+CMwUPAdMG1QR+s9qYo6Y/XJqEysHHhthNHQ IMghjw+rLaPFzUkOLTLd6dqn+SWHiveADt7Eg= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1789682871; x=1790287671; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=ESC2QBsbUE5N5PD+6ShhZ82iIHEXAgPIIkbO9VXSidI=; b=ll2C1F5w9mZzdujQb0C1/Ve7az60Ilquihn/fPmCyBAeY+Fjlksago5B2rZSGD28Mz S8Kvw76MQCWex6UbrvUFMvhBhmIBSa/vU3uuKliIkuhz9uty8FMdoWOMC0gThWaH9POO bvyg7TDS1Nkmkrz/uKCYalt8366x7PjywXVhAQTZeGNkzoWOuo+FPv1nUQQDG3eBahuW 5jZPNZe/3Xsyuao2l6+n4pNGWsgVamQmVDXIAYYUKTWV/kadPuit933iZ7j+jnM6xkRz FTeERKcAcVdriNXxvp/kS2m2UmxA8N0CGNQpe04Eo4CuIWPAlsko1N3LHKi+BKLI5IHi OXAw== X-Gm-Message-State: AFuF++kvsdYna7ci1eU0/LkKRFDjtqsYVnKJpAxMIlCiPsFBu93p6V03 xIJ4do156JSSCASzwUP+hh/P2eejIwLIXO0ZYJOkGTBjVZj9z5Mm2vsW7R4ZTmnZSpISwvD25JF IoY63ETo= X-Gm-Gg: AYBFou05YrBDWeTgvN/MZRc648T7wvygc79Q/oV9Xnt4v+yMx+g8hnK58AU24wTfFJq uFpiiWERfZrRcsydfO2LkteEKsfo7qsqZFN6g6GKIU3itvP7mjS4r7g5XD/4PCxE87cn0aW3M8t nRjOFehL9us9EA4nlyPqqz30SbyljxP2wAEAwzW9YdF2Abht4NXMvmmuVktSQoBZshlbes9pUFP L+sZ9TASumbITqgM54+gVQR4O2g8/ZNpRDQu8xn31B3f3ZMapA7bu8h0skKydBqnat68WcFGUgO JlyHj3vPwrmMfgiHNXoGDWIFrAtEpqk6amWP7ONK/Wx68mHZt8BjIPWtGBloGqLtEdh+dES65L4 8ii3nbrBJEnPxStn/qgDbBH7TJGa7BzB6WrFHm0jH/A7zps2xlrH+tlMX7jXmKKFCEKwqoJ36ae vKcHBA1TUCvLv+jE3MRVER+qJkJoU93EH1WbmPNIS09BaFSbyox6w/jtT+51Sr0hMIPX+d0FOH3 NByWHkJLUatyx3U/FunWGkt7jCCU0HIppujTrWN5zgdVrxqgJlDFr/yfHyO9UN+HVbckxkDSh8= X-Received: by 2002:a05:600c:4e42:b0:49e:63cc:6324 with SMTP id 5b1f17b1804b1-49fc4f85e54mr6913325e9.6.1789682871008; Thu, 17 Sep 2026 15:07:51 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-49fc471b9a2sm8984075e9.0.2026.09.17.15.07.50 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Thu, 17 Sep 2026 15:07:50 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][wrynose 03/79] ca-certificates: upgrade 20260601 -> 20260816 Date: Fri, 18 Sep 2026 00:05:48 +0200 Message-ID: <62e75e4ad0cdbbe692d196bc68dae81d3a75196a.1789681419.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Thu, 17 Sep 2026 22:07:54 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/246099 From: Jaipaul Cheernam Source: debian/changelog ca-certificates (20260816) unstable; urgency=medium * Update Mozilla certificate authority bundle to version 2.90 The following certificate authorities were added (+): + "SECOM TLS ECC Root CA 2024" + "SECOM TLS RSA Root CA 2024" + "Telia EC TLS Root CA v3" + "Telia RSA TLS Root CA v3" The following certificate authorities were removed (-): - "Atos TrustedRoot 2011" - "Entrust Root Certification Authority" - "SecureSign Root CA12" - "ePKI Root Certification Authority" -- Julien Cristau Sun, 16 Aug 2026 23:04:36 +0200 Signed-off-by: Jaipaul Cheernam Signed-off-by: Mathieu Dubois-Briand Signed-off-by: Richard Purdie (cherry picked from commit e639396818e7152896e75364cff5fb97ae19cb32) Signed-off-by: Ankur Tyagi Signed-off-by: Yoann Congal --- ...vert-mozilla-certdata2pem.py-print-a-warning-for-e.patch | 6 +++--- ...date-ca-certificates-don-t-use-Debianisms-in-run-p.patch | 2 +- ...date-ca-certificates-use-relative-symlinks-from-ET.patch | 2 +- ...certificates_20260601.bb => ca-certificates_20260816.bb} | 2 +- 4 files changed, 6 insertions(+), 6 deletions(-) rename meta/recipes-support/ca-certificates/{ca-certificates_20260601.bb => ca-certificates_20260816.bb} (97%) diff --git a/meta/recipes-support/ca-certificates/ca-certificates/0001-Revert-mozilla-certdata2pem.py-print-a-warning-for-e.patch b/meta/recipes-support/ca-certificates/ca-certificates/0001-Revert-mozilla-certdata2pem.py-print-a-warning-for-e.patch index 1226508c983..001b4686246 100644 --- a/meta/recipes-support/ca-certificates/ca-certificates/0001-Revert-mozilla-certdata2pem.py-print-a-warning-for-e.patch +++ b/meta/recipes-support/ca-certificates/ca-certificates/0001-Revert-mozilla-certdata2pem.py-print-a-warning-for-e.patch @@ -1,4 +1,4 @@ -From 743774cd53ed1c45bb660eddacf6dadb5ee3e145 Mon Sep 17 00:00:00 2001 +From 8ea56b7d5eadb04309dc3cf1e6b0d94d1d053d80 Mon Sep 17 00:00:00 2001 From: Alexander Kanavin Date: Mon, 18 Oct 2021 12:05:49 +0200 Subject: [PATCH] Revert "mozilla/certdata2pem.py: print a warning for expired @@ -16,10 +16,10 @@ Signed-off-by: Alexander Kanavin 3 files changed, 1 insertion(+), 13 deletions(-) diff --git a/debian/changelog b/debian/changelog -index dbe3e9c..496e05d 100644 +index 7ad495f..058ef5e 100644 --- a/debian/changelog +++ b/debian/changelog -@@ -156,7 +156,6 @@ ca-certificates (20211004) unstable; urgency=low +@@ -234,7 +234,6 @@ ca-certificates (20211004) unstable; urgency=low - "Trustis FPS Root CA" - "Staat der Nederlanden Root CA - G3" * Blacklist expired root certificate "DST Root CA X3" (closes: #995432) diff --git a/meta/recipes-support/ca-certificates/ca-certificates/0001-update-ca-certificates-don-t-use-Debianisms-in-run-p.patch b/meta/recipes-support/ca-certificates/ca-certificates/0001-update-ca-certificates-don-t-use-Debianisms-in-run-p.patch index 1a29da756fc..dcfa3554117 100644 --- a/meta/recipes-support/ca-certificates/ca-certificates/0001-update-ca-certificates-don-t-use-Debianisms-in-run-p.patch +++ b/meta/recipes-support/ca-certificates/ca-certificates/0001-update-ca-certificates-don-t-use-Debianisms-in-run-p.patch @@ -1,4 +1,4 @@ -From 63086d41f76b1c3357e23c6509df72d3f75af20c Mon Sep 17 00:00:00 2001 +From bab2e13b69af12c1864cccf371ebc4ef57a6fec2 Mon Sep 17 00:00:00 2001 From: Ross Burton Date: Mon, 6 Jul 2015 15:19:41 +0100 Subject: [PATCH] ca-certificates: remove Debianism in run-parts invocation diff --git a/meta/recipes-support/ca-certificates/ca-certificates/0003-update-ca-certificates-use-relative-symlinks-from-ET.patch b/meta/recipes-support/ca-certificates/ca-certificates/0003-update-ca-certificates-use-relative-symlinks-from-ET.patch index 929945b56f9..4d97c81b0d7 100644 --- a/meta/recipes-support/ca-certificates/ca-certificates/0003-update-ca-certificates-use-relative-symlinks-from-ET.patch +++ b/meta/recipes-support/ca-certificates/ca-certificates/0003-update-ca-certificates-use-relative-symlinks-from-ET.patch @@ -1,4 +1,4 @@ -From a69933f96a8675369de702bdb55e57dc21f65e7f Mon Sep 17 00:00:00 2001 +From 8a5b4e2dd1479de0338db7a7234d037ef0f71c2f Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Andr=C3=A9=20Draszik?= Date: Wed, 28 Mar 2018 16:45:05 +0100 Subject: [PATCH] update-ca-certificates: use relative symlinks from diff --git a/meta/recipes-support/ca-certificates/ca-certificates_20260601.bb b/meta/recipes-support/ca-certificates/ca-certificates_20260816.bb similarity index 97% rename from meta/recipes-support/ca-certificates/ca-certificates_20260601.bb rename to meta/recipes-support/ca-certificates/ca-certificates_20260816.bb index 1bc64fe34a4..9dd3a05948c 100644 --- a/meta/recipes-support/ca-certificates/ca-certificates_20260601.bb +++ b/meta/recipes-support/ca-certificates/ca-certificates_20260816.bb @@ -14,7 +14,7 @@ DEPENDS:class-nativesdk = "openssl-native" # Need rehash from openssl and run-parts from debianutils PACKAGE_WRITE_DEPS += "openssl-native debianutils-native" -SRC_URI[sha256sum] = "7ab6301f7f34eef90a4d278647c260bc0762e0e14561f4649854cf4b0d4bea21" +SRC_URI[sha256sum] = "d939bcdd0cb058712cf4175bac76997676eb8b68fe9473765e1b40fb3d5b186a" SRC_URI = "${DEBIAN_MIRROR}/main/c/ca-certificates/${BPN}_${PV}.tar.xz \ file://0001-update-ca-certificates-don-t-use-Debianisms-in-run-p.patch \ file://0003-update-ca-certificates-use-relative-symlinks-from-ET.patch \ From patchwork Thu Sep 17 22:05:49 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 98569 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 15FF0C982DA for ; Thu, 17 Sep 2026 22:07:54 +0000 (UTC) Received: from mail-wm2-f12.google.com (mail-wm2-f12.google.com [74.125.225.140]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.1555.1789682873200990348 for ; Thu, 17 Sep 2026 15:07:53 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=Q9DtB+T5; spf=pass (domain: smile.fr, ip: 74.125.225.140, mailfrom: yoann.congal@smile.fr) Received: by mail-wm2-f12.google.com with SMTP id 5b1f17b1804b1-49d1fb0cf5eso866645e9.3 for ; Thu, 17 Sep 2026 15:07:52 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1789682871; x=1790287671; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=w8mCTDQIkb5Tu25Elw1GbAxfMnSsKJTMce7Unioq8uo=; b=Q9DtB+T5OJ5Nnt80i2V+4Rgiv7Pxsk1s5fQYluNyP9aCsrJAgBJkzddlbaPmm27SLD EnqXggsNUiTX2yA/UxgXg04tIigk6DNG35CJRCV+MvyVsL3uIH0ZE9meGfd22NAwd44w QV6XbhIlqrsykXDCP2iYAHcBChk1a7Dwk1L2M= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1789682871; x=1790287671; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=w8mCTDQIkb5Tu25Elw1GbAxfMnSsKJTMce7Unioq8uo=; b=hzNghjOsvtsCQ2Vgm1c+YXuqkE2OCrO1ddx6WIkspy++9Lx0OCer4310+MafcOzoZZ 5ctjclwUPcd2e/eHjYhKrM2o5buoKXYma4obHrOxT77RgmNJeWvjcxJWI7FCyZPBQHa2 pU2OfhpvBVGit1uE04a0paSs/M8t6AS3rMvTDDVMyIo2/DS5xLq9CYtVmxMQzc2DDe4K n03hK5RZ2Dlpq4pxRGlT2JlvJlNY/1P2dwalC+UcopdD5lfIVxrlKfABDgN0kZLro4GA VH8y2JINlj1kqC6b5Q8Qy4kkjjVZq+plUsAEwZbeIehpTqb3YrG/fv0nj6cLhJHzi/KV u/+g== X-Gm-Message-State: AFuF++nRNydA5a1/HAy8580hWgJyKJQ92OEg7eAo5otnDxc4fVgMeiyr YcOqMXCttXIAXDqe8JrmgG42X2T3DCLRlgO1gW/dfzC7PwrjV9xuHQ76qquzu9SqNnlDJ1MCNHR S4OZouek= X-Gm-Gg: AYBFou3bIb+uO8mI+CkMWSqB6lB9KPWoF4GKSbzciJPxkYHhfT7XPnp2NORUT78QV7L 3+/SAmoSrpSxL4dEqvVE2MzNwPsXnCd55RVxPwGMbywsMr29Ll1LhqqrZI92ynWCy7wO1H8+O2k S7RUmYsK6TFjnjhc38Tl9ZqITbj0grPD5K8kw6noapYCNMxMJV9cVxzhzRs8TIutOLYY1jS5Nql TaSPQtg1Dcs8X80ClVAOIUVsI7TolKL3VdAHMqjWkfENC3fBRJXrKIcHpw3n4IRr9gDcsyjCQ4d J0GsFStCfZ49iov8RGGn1xm3R3Gv55hhtDz7RTgzMrIXj2pLlN7OzfPIp8niCE04500uyQ3/8TM eDc+4n1LccTcnNDdunr+Jt4sM1B3ebig6Iwn3vmLpgQ3+rOJxgmjUbSurhJEHaeHQZ8P//l3X+R 41phUI05lMpX+I8qMgEzVwdz/GD8EbhAW1BNW0MUPLsPOj0idXI7bBLj6TYVQofpAfH60xAqa/Z WsDNMOu+VyZAFav9rp3TQZT3uAGpopQwlhYvQkRZawD81x2tFgW8XiAA6qVJamTSWTIIAs0qr8= X-Received: by 2002:a05:600c:8b03:b0:499:a277:e8b5 with SMTP id 5b1f17b1804b1-49fc566e609mr3143925e9.3.1789682871415; Thu, 17 Sep 2026 15:07:51 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-49fc471b9a2sm8984075e9.0.2026.09.17.15.07.51 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Thu, 17 Sep 2026 15:07:51 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][wrynose 04/79] cmake-native: use bundled nghttp2 with bundled curl Date: Fri, 18 Sep 2026 00:05:49 +0200 Message-ID: <8553003ffbed5f3f16d10373dae9672db9bfa417.1789681419.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Thu, 17 Sep 2026 22:07:54 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/246098 From: Himanshu Jadon cmake.inc enables system library lookup through CMAKE_USE_SYSTEM_LIBRARIES=1. cmake-native already keeps curl bundled, but it did not also disable system nghttp2 lookup. With CMake 4.3.1, the bundled cmcurl configure can enable nghttp2 when headers are found on the host. The later compile uses only the OE native sysroot, so the build can fail with: fatal error: nghttp2/nghttp2.h: No such file or directory Disable system nghttp2 lookup for cmake-native also. This keeps it consistent with the existing bundled curl setting instead of adding a new native dependency because the host happened to expose nghttp2 during configure. Add the bundled cmnghttp2 license checksum because the native build now uses that copy explicitly. Signed-off-by: Himanshu Jadon Signed-off-by: Richard Purdie (cherry picked from commit 0b20ba549d6f17af40b9877eb9ab0c52ca62a18c) Backport note: CMake 4.3.1 used by Wrynose has the same behavior: with CMAKE_USE_SYSTEM_LIBRARIES=1 and system curl disabled, CMAKE_USE_SYSTEM_NGHTTP2 defaults to ON. If the host provides nghttp2, configure records the host include and library paths, while do_compile uses only the OE native sysroot. Therefore this setting is needed for Wrynose as well. Signed-off-by: Deepak Rathore Signed-off-by: Yoann Congal --- meta/recipes-devtools/cmake/cmake-native_4.3.1.bb | 2 ++ 1 file changed, 2 insertions(+) diff --git a/meta/recipes-devtools/cmake/cmake-native_4.3.1.bb b/meta/recipes-devtools/cmake/cmake-native_4.3.1.bb index a859cef1517..911155773cc 100644 --- a/meta/recipes-devtools/cmake/cmake-native_4.3.1.bb +++ b/meta/recipes-devtools/cmake/cmake-native_4.3.1.bb @@ -15,6 +15,7 @@ LIC_FILES_CHKSUM:append = " \ file://Utilities/cmlibrhash/COPYING;md5=a8c2a557a5c53b1c12cddbee98c099af \ file://Utilities/cmlibuv/LICENSE;md5=ad93ca1fffe931537fcf64f6fcce084d \ file://Utilities/cmcurl/COPYING;md5=72f4e9890e99e68d77b7e40703d789b8 \ + file://Utilities/cmnghttp2/COPYING;md5=764abdf30b2eadd37ce47dcbce0ea1ec \ file://Utilities/cmcppdap/LICENSE;md5=3b83ef96387f14655fc854ddc3c6bd57 \ " @@ -34,6 +35,7 @@ EXTRA_OECMAKE += "\ -DCMAKE_DISABLE_FIND_PACKAGE_Libidn2=ON \ -DENABLE_ACL=0 -DHAVE_ACL_LIBACL_H=0 \ -DHAVE_SYS_ACL_H=0 \ + -DCMAKE_USE_SYSTEM_LIBRARY_NGHTTP2=0 \ " # Ensure e2fsprogs isn't found on the host to remove a build dependency and reproducible builds. From patchwork Thu Sep 17 22:05:50 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 98570 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 7F42DC982DB for ; Thu, 17 Sep 2026 22:07:54 +0000 (UTC) Received: from mail-wm2-f13.google.com (mail-wm2-f13.google.com [74.125.225.141]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.1557.1789682873691947474 for ; Thu, 17 Sep 2026 15:07:54 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=EgfpE7WP; spf=pass (domain: smile.fr, ip: 74.125.225.141, mailfrom: yoann.congal@smile.fr) Received: by mail-wm2-f13.google.com with SMTP id 5b1f17b1804b1-49ccfd61ecaso1011145e9.3 for ; Thu, 17 Sep 2026 15:07:53 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1789682872; x=1790287672; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=8NpdUPWZVOVoZohSSzSKanPFI/K8WGLTavl6xcsnf2Q=; b=EgfpE7WPcyf5FB537h5sG2FprDQtmFNFx1U1Lnk4tWB2rjKrCpKCBCjHTPeSX1Bw2j pVpv33PfiuXYDu9BnFcKv1wjDGx0Scrl5SngSwmu3mNIj2WEKBuFl5lkhyVOZ0jnNYCh SHIrweqrFFWjZFwjCeQR70IIT2tWl7908s9/I= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1789682872; x=1790287672; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=8NpdUPWZVOVoZohSSzSKanPFI/K8WGLTavl6xcsnf2Q=; b=nWGl7DAcxATXIeUERM1NksHYnH4RqHgdwlTBkmUQl4Xszx3ndffe8desU4Yz02FIhA T+uyRZa2VmuXSxNcOP8Nyh5nTm/lijs/VwTM9UYcypsQnFXRxYpTUpsas9RheCIIL5EN fIA2/0MbhrBng/1ikwI14O9BuovLFMP1Cm1oNv72fYOxT3l98wdSxsay2cckhxNgomQY +HMimorIc1BMMOpG8/yvuBa0uWcqfmyhhffc9lU0CIYNSrK5sg1x5jMTJ3lx/u9b12Z+ TmJ7TeF2m0PPByNtOivE+Lm2mQdammbYCrlV+uGE/l14DbJ+l7LaLsY/OrHNm9DG4w36 2vtA== X-Gm-Message-State: AFuF++kn6y3X+xskiWtmJZKzJ8XqTA4PQASiIEo5la/ocjAIXdEFUZpA CP1m0ncffGPjjHsZ0zFWirKT25f9XrnUOuiNBAiSgWGShSHBfAM6tAEtsv9d9Z5iWwoFCl3i3pH 8OZIgbKA= X-Gm-Gg: AYBFou0xqhmLARTzLjoBwrGX3Wt3nGox8A36dFCuZdLiKw3VwfhZvuqqwca++X3dh5b 3iiRhqqFHkAqxdVJGRS/dtvei5onckA1V5jSkyYaawM3zkojQvrdd024xEE/t5Ry0phbP828hRt 7P4HSSofFYhRyb5+Xd+QZgcAoUKeWBZT5Xsi+k9S09ETobXaonr8cXeE4wovfkpuxp3MBKltuNz pVE8bbgimv8ADu1UiCn/a18v4W410G9U8ilzL2Ud+y5KgWkodl+AJ9adz27g0HkKmmwbaU+Tvwg ugE1L58qgiz+cCUe0SWWix8LvVNIsC8ElcS51dtRY/rUpGEWhTb2HLCyarPzOv6T0Cfux3NqNHk ZAAaFgWqc6XDmzHvZrN/SYW2Eq9T53jryYsaVWq0DXZYxSdLL8Fqpq0+IZY2uhUUwnc0XT0U8m9 Sd8Tc5qdk1/054lc5tOLmUSY5G1hAesz4as115aCM4SZKTddrs/QrioTzPx10mVcGW5cYQpSTnD KMJHcx7qWuzPBRHyI5s1HwQAY8fmYbudHulkbLRicGY0/OZKXhWQgeAJ6yKtSlKs7ksLWP4JAQ= X-Received: by 2002:a05:600c:1391:b0:49d:1fd8:b874 with SMTP id 5b1f17b1804b1-49fc574114fmr2979915e9.19.1789682871851; Thu, 17 Sep 2026 15:07:51 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-49fc471b9a2sm8984075e9.0.2026.09.17.15.07.51 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Thu, 17 Sep 2026 15:07:51 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][wrynose 05/79] vim: Fix CVE-2026-52858 regression Date: Fri, 18 Sep 2026 00:05:50 +0200 Message-ID: <7a78c67a15aecd7c455196419103a83b9ce12c4e.1789681419.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Thu, 17 Sep 2026 22:07:54 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/246100 From: Devansh Patel This patch fixes a regression introduced by the CVE-2026-52858 fix already carried by OE-Core in commit [1]. The original security fix added the g:pythoncomplete_allow_import opt-in, but the documented behavior was broken because vim was not imported in the completion class scope. This patch applies upstream Vim patch 9.2.0568 to restore that behavior. [1] https://github.com/openembedded/openembedded-core/commit/24ef5a9dfffe7b3d96fb62c0d3248348696c9115 [2] https://github.com/vim/vim/commit/4b850457e12e1a678dd209f2868154f7553cbf8d [3] https://github.com/vim/vim/commit/868ad62cb8bf8038322eab2badd31bd98b02b9df [4] https://github.com/vim/vim/security/advisories/GHSA-52mc-rq6p-rc7c Signed-off-by: Devansh Patel Signed-off-by: Yoann Congal --- .../vim/files/CVE-2026-52858-regression.patch | 93 +++++++++++++++++++ meta/recipes-support/vim/vim.inc | 1 + 2 files changed, 94 insertions(+) create mode 100644 meta/recipes-support/vim/files/CVE-2026-52858-regression.patch diff --git a/meta/recipes-support/vim/files/CVE-2026-52858-regression.patch b/meta/recipes-support/vim/files/CVE-2026-52858-regression.patch new file mode 100644 index 00000000000..50392fb76f1 --- /dev/null +++ b/meta/recipes-support/vim/files/CVE-2026-52858-regression.patch @@ -0,0 +1,93 @@ +From 8075209bb1e721ca89c2e7fd5d216d7fe2bd3ea6 Mon Sep 17 00:00:00 2001 +From: thinca +Date: Sun, 31 May 2026 12:33:07 +0000 +Subject: [PATCH] patch 9.2.0568: pythoncomplete: g:pythoncomplete_allow_import + had no effect + +Problem: The security patch 9.2.0561 added a vim.eval() call inside + Completer.evalsource() to honor g:pythoncomplete_allow_import. + But the 'vim' module is only imported inside the outer + vimcomplete() / vimpy3complete() function, not at the script's + top level, so referring to it from a Completer method raises + NameError. The surrounding bare 'except' silently swallows + the error and leaves allow_imports at 0, meaning the opt-in + never takes effect -- 'import os' (and any other + buffer-level import) is always skipped, no candidates are + produced for 'os.<...>' and + Test_popup_and_preview_autocommand() fails on the Windows + CI matrix (Linux skips the test because Python 2 is absent). +Solution: Re-import 'vim' at the top of evalsource() in both + pythoncomplete.vim and python3complete.vim so the eval reads + the global, and set g:pythoncomplete_allow_import = 1 in the + test (it is the opt-in intended for callers that trust the + buffer contents) (thinca). + +closes: #20386 + +CVE: CVE-2026-52858 +Upstream-Status: Backport [https://github.com/vim/vim/commit/868ad62cb8bf8038322eab2badd31bd98b02b9df] + +Backport Changes: +- Omitted src/version.c because the Wrynose recipe remains at Vim 9.2.0340; + the upstream version-table hunk is not needed for this backport. + +Signed-off-by: thinca +Signed-off-by: Christian Brabandt +(cherry picked from commit 868ad62cb8bf8038322eab2badd31bd98b02b9df) +Signed-off-by: Devansh Patel +--- + runtime/autoload/python3complete.vim | 3 +++ + runtime/autoload/pythoncomplete.vim | 3 +++ + src/testdir/test_popup.vim | 4 ++++ + 3 files changed, 10 insertions(+) + +diff --git a/runtime/autoload/python3complete.vim b/runtime/autoload/python3complete.vim +index a0314242b..bdabf62c8 100644 +--- a/runtime/autoload/python3complete.vim ++++ b/runtime/autoload/python3complete.vim +@@ -158,6 +158,9 @@ class Completer(object): + self.parser = PyParser() + + def evalsource(self,text,line=0): ++ # vim is imported locally in vimpy3complete(); re-import here so the ++ # vim.eval() below works (otherwise NameError, silently caught). ++ import vim + sc = self.parser.parse(text,line) + try: allow_imports = int( + vim.eval("get(g:, 'pythoncomplete_allow_import', 0)")) +diff --git a/runtime/autoload/pythoncomplete.vim b/runtime/autoload/pythoncomplete.vim +index 39b1efd29..761488244 100644 +--- a/runtime/autoload/pythoncomplete.vim ++++ b/runtime/autoload/pythoncomplete.vim +@@ -172,6 +172,9 @@ class Completer(object): + self.parser = PyParser() + + def evalsource(self,text,line=0): ++ # vim is imported locally in vimcomplete(); re-import here so the ++ # vim.eval() below works (otherwise NameError, silently caught). ++ import vim + sc = self.parser.parse(text,line) + try: allow_imports = int( + vim.eval("get(g:, 'pythoncomplete_allow_import', 0)")) +diff --git a/src/testdir/test_popup.vim b/src/testdir/test_popup.vim +index fac2a7592..55c2f232d 100644 +--- a/src/testdir/test_popup.vim ++++ b/src/testdir/test_popup.vim +@@ -723,6 +723,9 @@ func Test_popup_and_preview_autocommand() + au! + au BufAdd * nested tab sball + augroup END ++ " Let pythoncomplete follow the buffer's 'import os' (off by default ++ " since v9.2.0561) so 'os.' can be completed. ++ let g:pythoncomplete_allow_import = 1 + set omnifunc=pythoncomplete#Complete + call setline(1, 'import os') + " make the line long +@@ -745,6 +748,7 @@ func Test_popup_and_preview_autocommand() + augroup END + augroup! MyBufAdd + bw! ++ unlet g:pythoncomplete_allow_import + endfunc + + func s:run_popup_and_previewwindow_dump(lines, dumpfile) diff --git a/meta/recipes-support/vim/vim.inc b/meta/recipes-support/vim/vim.inc index 77f681410a9..b3732cb780e 100644 --- a/meta/recipes-support/vim/vim.inc +++ b/meta/recipes-support/vim/vim.inc @@ -21,6 +21,7 @@ SRC_URI = "git://github.com/vim/vim.git;branch=master;protocol=https;tag=v${PV} file://CVE-2026-45130.patch \ file://CVE-2026-46483.patch \ file://CVE-2026-52858.patch \ + file://CVE-2026-52858-regression.patch \ file://CVE-2026-52859.patch \ file://CVE-2026-52860.patch \ file://CVE-2026-42307.patch \ From patchwork Thu Sep 17 22:05:51 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 98573 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 54218C982D0 for ; Thu, 17 Sep 2026 22:08:04 +0000 (UTC) Received: from mail-wm2-f13.google.com (mail-wm2-f13.google.com [74.125.225.141]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.1558.1789682873972723271 for ; Thu, 17 Sep 2026 15:07:54 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=AW+sY6ls; spf=pass (domain: smile.fr, ip: 74.125.225.141, mailfrom: yoann.congal@smile.fr) Received: by mail-wm2-f13.google.com with SMTP id 5b1f17b1804b1-49cd38e0e5dso1333695e9.2 for ; Thu, 17 Sep 2026 15:07:53 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1789682872; x=1790287672; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=nNFCD13pJmmp7e6u36VRMOS6G1vTlHQsNkX7Jck2Vwg=; b=AW+sY6lsKFoAG5eRqpJuAgmQK8UHo1f8RtMIwhbZD5hywM+1uRWZ9zYeGNTVTC2aeS 69XuXVVwAYuQu0rIdsCcAGSWPuN8rFVSaPuxTjbK8hfgqOeONnDIJ1Fac2i5EXBPtkO+ q7eRoK4UoBFJGVhtxhSt5sazy2XSA14Dh430o= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1789682872; x=1790287672; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=nNFCD13pJmmp7e6u36VRMOS6G1vTlHQsNkX7Jck2Vwg=; b=twx6Fv4ka6gz2pir40D6R5SQypXw8XCYjlyN4OKWsxbpFFUNBM/vkAvjn1IG720abe ycVcYe3/jPBKpeTiUMUvVSH0q4ktWHW0UeD5SvM1VB3fBZvoY5dw/fjpGF8/QeCn3LQV cjQRPzjX8gPX9v9ZwQDluPFQ0w4yEW/Z8LwghHzdo6Fdjd3XYSplCwSy/RcV2ZgjpbfX UzK/Q8wTwB9oXbegfUN/i1j8ausPt/+nlycnh8tJvw8/mcuZDa1EUy3lX1XkEB69cI1r 52UoheTSvDf5c4xuB0Od4BsL2dtGV8UylqBZBZ/sWXE6BkpgXPvrnwhsb0HkSW+uDfBu Tkgg== X-Gm-Message-State: AFuF++mAw+XNiifK58NS1bqtDmYw0Q+8V2AqSsNVhytKV3mmUd8f5PPc yYyz1bD0gjr3PRTQp35tXddTyP7EJDzGB3V+OSyclyZHCbu24XSxA47HxEq/nWO/4MFH4wPuQ8k DWCbauJw= X-Gm-Gg: AYBFou1+B3Dn23rMdfBgFOhnJmc7T0ph+XEBH2Ji8O70lxypUIADaflSZlhY1rDQhGs 2U53Vca2z41A4W5raViRRnnQoGkbDmJBBntk8kkHhS6CbI8xNqyowUAO3ggY9MHaQZdyHTIOqCm Jn1EoBcbC+ying0+tQ2ZCus3nN0aErlaV4iP7qROuylzW7V7OjMCVSj7N+r0Wq3N8ugjL2m0Ngr sspUnlB92pqC2PdK05k5Yj0dRgicpAXjz6vUUlJKSy9EB4PdWjdVe7LIgxzydMX0FPVrSFnHSBX +UwscII4+aWiAsDL4ixcm6QoASzfjk27xOK51usTFhN7eSua9nFnq7R7z8kWQEtyf7VrhjXZN50 bWz0RjuYNRmqrL2HMP5m88gm8JuhBurxY/1VwLZetX908SlIXEsf5faIFc4nRAv1gv+UfIMJtk7 wpMHmEYP222iLaYUGUa100xXzvsRczLehbiEWF8jD8uQkIXO7AXzKux/tkE9qGBpQnSFRKhOCXa LDyiX3Di+DTL3y+uyXONfjE/ydta39X1q88Nc/lD/Lz3k712fVw+IrFSUHc4hXqHDlUSDgDpI0= X-Received: by 2002:a05:600c:3492:b0:49c:cee0:e7c1 with SMTP id 5b1f17b1804b1-49fc572f645mr2826115e9.16.1789682872297; Thu, 17 Sep 2026 15:07:52 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-49fc471b9a2sm8984075e9.0.2026.09.17.15.07.51 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Thu, 17 Sep 2026 15:07:52 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][wrynose 06/79] kernel-yocto-rust: Add clang toolchain check for riscv64 Date: Fri, 18 Sep 2026 00:05:51 +0200 Message-ID: <8256d2c19680fb8111471cdefc99fb89839d23ab.1789681419.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Thu, 17 Sep 2026 22:08:04 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/246101 From: Harish Sadineni Kernel Rust support on riscv64 requires Clang. Wrynose doesn't provide a Clang toolchain for kernel builds, but downstream layers may add this support via a linux-yocto_%.bbappend. Rather than unconditionally skipping riscv64, check whether a Clang toolchain is available and only error out with a clear message when it isn't, so that users with Clang-enabled downstream configurations aren't broken. Signed-off-by: Harish Sadineni Signed-off-by: Yoann Congal [YC: fixed a typo in message. This matches master commit 2b228490b7ef] --- meta/classes-recipe/kernel-yocto-rust.bbclass | 10 ++++++++++ 1 file changed, 10 insertions(+) diff --git a/meta/classes-recipe/kernel-yocto-rust.bbclass b/meta/classes-recipe/kernel-yocto-rust.bbclass index 49f2bfc1ae8..4c0b7231e6a 100644 --- a/meta/classes-recipe/kernel-yocto-rust.bbclass +++ b/meta/classes-recipe/kernel-yocto-rust.bbclass @@ -25,3 +25,13 @@ do_kernel_configme:append () { # More details in: https://lists.openembedded.org/g/openembedded-core/message/229336 # Disable ccache for kernel build if kernel rust support is enabled to workaround this. CCACHE_DISABLE ?= "1" + +python () { + if d.getVar('TARGET_ARCH') == 'riscv64' and d.getVar('TOOLCHAIN') != 'clang': + raise bb.parse.SkipRecipe( + "Rust support in the kernel on riscv64 requires kernel to be build with clang " + "toolchain, but the kernel is built with toolchain '%s'. See " + "https://docs.kernel.org/rust/arch-support.html for details." + % d.getVar('TOOLCHAIN') + ) +} From patchwork Thu Sep 17 22:05:52 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 98589 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 646AAC982E3 for ; Thu, 17 Sep 2026 22:08:05 +0000 (UTC) Received: from mail-wm2-f13.google.com (mail-wm2-f13.google.com [74.125.225.141]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.1559.1789682874907745001 for ; Thu, 17 Sep 2026 15:07:55 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=LDWvDycQ; spf=pass (domain: smile.fr, ip: 74.125.225.141, mailfrom: yoann.congal@smile.fr) Received: by mail-wm2-f13.google.com with SMTP id 5b1f17b1804b1-49e79a408deso498765e9.2 for ; Thu, 17 Sep 2026 15:07:54 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1789682873; x=1790287673; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=+kBi3rtEz3r0Av8Z6ksqcXspFxshq9l5DCr2d0dD/WU=; b=LDWvDycQ+ryVNeV9XGXQ1f2+2TlKdYp08yujaHRF6mHBbXoWySOSF1zVVs2vPwi6qR Y5O3pa7Zrps2l65XbgPTS+ahZeZt7ztMNA71obk7lqqyAOzk0aAAgruEEu9ZGT9Zw+Gi 37c/k2VVzQt3062CiBYmMnaNFZBVvTmNihg2E= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1789682873; x=1790287673; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=+kBi3rtEz3r0Av8Z6ksqcXspFxshq9l5DCr2d0dD/WU=; b=xMg2PK1eEuz5XPJql8OOzv3PC6oLPjmdSJ+M5T+mwJanrRFo+/NxtAu2mvjjO4sAQg MBvMTi1jLUlDQUaTc4kA30aZ8XM5hek6eW0fDt6wVHCHY+Fzx4HtRzuBLtbYK2kuCZeI vrwe1rKVHxN4CINKu2IxO55goNgFqsHnaswQu4sPcbV/s0XfyANRSAakPl3ey0QMGn0a zL5PtVDc17POATSCiPz5mxQF2mWg5r/NRBwety8IinGZvK65sovnoUXGH1CheAy7G1LL WBa+NI6uKRkT5ZQgdXcX1eJpcxPKE0+bb/yeMWstQSMT+UJOV4vFHV4sTOcEUMfGcnwY 6y1A== X-Gm-Message-State: AFuF++kvRND0AMjp96FrAJsYa+ai3vVUACwaRrXxb4yNamyyb/5W6wSS 7yEWJzJqZadfcA01CuYXzbdieOn95R0+hGh9eC78Unx7gU6auoBRcIwmorERy///swajgO9uUUz Gt+2iRTM= X-Gm-Gg: AYBFou2GyJ7mMNZRx0HnsWPHf1tI3jc9v1cJq0Cun6Wl0NzgVHm0tVeRu2miIIGOuva PRar0eJjt+K0VDNbYLwqyiyhbJaB4TvuFYt0bZ5vi02pzmJPj0FsiReL5VBDhf8Ym+aGKqWrfuY WfD/RQ0I+hErFCxjgkCaPlgMcR81KurI2w0kB00yZCjX5hqm8Mt9kRTm2cCUEo29wjqT5ZPY7sf KQ/jpqEdswb9Abf0AaX5DkDJ/mkB+7dZe46dysdS9j4JaU4B0pDLqay+ENFAqsmXi2Ue1EQIOXz gdCqFJgaLS1PDHiMFToXDSgHwvwtQOHO22aI3gXdpApykX28TOgpNHqPVWJex8mERpUsQFwA4Kr 1ILi9KVP9Hlub0nsltbhlStUnX2qDVdx1PBvJhqkbxVlra5lmMmYJv6Mp8Gnu/YgN6L7s9zv3f8 HOJ75ZmncEKE0Qcvpkw8TO9lPq9yHKBgpgTJoleaqpotx/5d+0Ry0lWT+p8/C0YaG9N/RFQN76D sXKIDOhaRAZv5DOXGDGQpN/4bjxk/p8M92PfFd4U/uvgPBTWKaaca7LHC/fsq6yLbbfPoWT06U= X-Received: by 2002:a05:600c:4e46:b0:49e:642a:4f6f with SMTP id 5b1f17b1804b1-49fc585e9edmr2640565e9.33.1789682872969; Thu, 17 Sep 2026 15:07:52 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-49fc471b9a2sm8984075e9.0.2026.09.17.15.07.52 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Thu, 17 Sep 2026 15:07:52 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][wrynose 07/79] python3-cryptography: Fix CVE-2026-69248 Date: Fri, 18 Sep 2026 00:05:52 +0200 Message-ID: <7ea4f707d08c0286dbf748d2b1be78c5f9ada92b.1789681419.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Thu, 17 Sep 2026 22:08:05 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/246102 From: Vijay Anusuri Pick patch according to [2] [1] https://nvd.nist.gov/vuln/detail/cve-2026-69248 [2] https://security-tracker.debian.org/tracker/CVE-2026-69248 Signed-off-by: Vijay Anusuri Signed-off-by: Yoann Congal --- .../python/python3-cryptography.bb | 1 + .../python3-cryptography/CVE-2026-69248.patch | 302 ++++++++++++++++++ 2 files changed, 303 insertions(+) create mode 100644 meta/recipes-devtools/python/python3-cryptography/CVE-2026-69248.patch diff --git a/meta/recipes-devtools/python/python3-cryptography.bb b/meta/recipes-devtools/python/python3-cryptography.bb index c6561deb3c4..5c1de9192b1 100644 --- a/meta/recipes-devtools/python/python3-cryptography.bb +++ b/meta/recipes-devtools/python/python3-cryptography.bb @@ -15,6 +15,7 @@ SRC_URI[sha256sum] = "e4cfd68c5f3e0bfdad0d38e023239b96a2fe84146481852dffbcca442c SRC_URI += "file://0001-pyproject.toml-remove-benchmark-disable-option.patch \ file://0002-Fix-installing-stray-files-into-site-packages.patch \ + file://CVE-2026-69248.patch \ file://check-memfree.py \ file://run-ptest \ " diff --git a/meta/recipes-devtools/python/python3-cryptography/CVE-2026-69248.patch b/meta/recipes-devtools/python/python3-cryptography/CVE-2026-69248.patch new file mode 100644 index 00000000000..66cfa12a6c1 --- /dev/null +++ b/meta/recipes-devtools/python/python3-cryptography/CVE-2026-69248.patch @@ -0,0 +1,302 @@ +From 4d035a4225965edeffd312079a510ef25fcfdcb2 Mon Sep 17 00:00:00 2001 +From: William Woodruff +Date: Thu, 21 May 2026 20:44:05 -0400 +Subject: [PATCH] x509: distinguish NC kinds when evaluating wildcard DNS SANs + (#14888) + +* x509: distinguish NC kinds when evaluating wildcard DNS SANs + +* Bump x509-limbo + +Upstream-Status: Backport [https://github.com/pyca/cryptography/commit/4d035a4225965edeffd312079a510ef25fcfdcb2] +CVE: CVE-2026-69248 +Signed-off-by: Vijay Anusuri +--- + .../cryptography-x509-verification/src/lib.rs | 43 ++++- + .../src/types.rs | 165 ++++++++++++------ + 2 files changed, 145 insertions(+), 63 deletions(-) + +diff --git a/src/rust/cryptography-x509-verification/src/lib.rs b/src/rust/cryptography-x509-verification/src/lib.rs +index c59f84f..60c89d4 100644 +--- a/src/rust/cryptography-x509-verification/src/lib.rs ++++ b/src/rust/cryptography-x509-verification/src/lib.rs +@@ -147,6 +147,7 @@ impl<'a, 'chain> NameChain<'a, 'chain> { + + fn evaluate_single_constraint( + &self, ++ kind: SubtreeKind, + constraint: &GeneralName<'chain>, + san: &GeneralName<'chain>, + budget: &mut Budget, +@@ -155,14 +156,18 @@ impl<'a, 'chain> NameChain<'a, 'chain> { + + match (constraint, san) { + (GeneralName::DNSName(constraint), GeneralName::DNSName(name)) => { +- // NOTE: A DNS SAN can be a wildcard pattern instead of a normal DNS name. +- // These are handled by matching unconditionally on the inner name, +- // since a NC of `foo.com` will match both `foo.com` and any arbitrarily deep +- // subdomain of `foo.com`, where a wildcard SAN like `*.foo.com` will only +- // match exactly one subdomain of `foo.com`. Therefore, the NC's matching +- // set is a strict superset of any possible wildcard SAN pattern. ++ // NOTE: A DNS SAN can be a wildcard pattern (e.g. `*.foo.com`) ++ // rather than an ordinary DNS name. A wildcard represents a ++ // *set* of names, so the check depends on which subtree we're ++ // evaluating: a `permittedSubtrees` constraint must contain ++ // *every* name the wildcard can expand to, whereas an ++ // `excludedSubtrees` constraint matches if it overlaps the ++ // wildcard at all. We dispatch on `kind` accordingly. + match (DNSConstraint::new(constraint.0), DNSPattern::new(name.0)) { +- (Some(constraint), Some(name)) => Ok(Applied(constraint.matches(&name))), ++ (Some(constraint), Some(name)) => Ok(Applied(match kind { ++ SubtreeKind::Permitted => constraint.permits(&name), ++ SubtreeKind::Excluded => constraint.excludes(&name), ++ })), + (_, None) => Err(ValidationError::new(ValidationErrorKind::Other(format!( + "unsatisfiable DNS name constraint: malformed SAN {}", + name.0 +@@ -232,7 +237,12 @@ impl<'a, 'chain> NameChain<'a, 'chain> { + let mut permit = true; + if let Some(permitted_subtrees) = &constraints.permitted_subtrees { + for p in permitted_subtrees.clone() { +- let status = self.evaluate_single_constraint(&p.base, &san, budget)?; ++ let status = self.evaluate_single_constraint( ++ SubtreeKind::Permitted, ++ &p.base, ++ &san, ++ budget, ++ )?; + if status.is_applied() { + permit = status.is_match(); + if permit { +@@ -250,7 +260,12 @@ impl<'a, 'chain> NameChain<'a, 'chain> { + + if let Some(excluded_subtrees) = &constraints.excluded_subtrees { + for e in excluded_subtrees.clone() { +- let status = self.evaluate_single_constraint(&e.base, &san, budget)?; ++ let status = self.evaluate_single_constraint( ++ SubtreeKind::Excluded, ++ &e.base, ++ &san, ++ budget, ++ )?; + if status.is_match() { + return Err(ValidationError::new(ValidationErrorKind::Other( + "excluded name constraint matched SAN".into(), +@@ -284,6 +299,16 @@ struct ChainBuilder<'a, 'chain, B: CryptoOps> { + store: &'a Store<'chain, B>, + } + ++/// Identifies which kind of name constraint subtree a SAN is being evaluated ++/// against. The two subtree kinds use different matching semantics for ++/// wildcard DNS SANs (containment vs. overlap); see [`DNSConstraint::permits`] ++/// and [`DNSConstraint::excludes`]. ++#[derive(Clone, Copy)] ++enum SubtreeKind { ++ Permitted, ++ Excluded, ++} ++ + // When applying a name constraint, we need to distinguish between a few different scenarios: + // * `Applied(true)`: The name constraint is the same type as the SAN and matches. + // * `Applied(false)`: The name constraint is the same type as the SAN and does not match. +diff --git a/src/rust/cryptography-x509-verification/src/types.rs b/src/rust/cryptography-x509-verification/src/types.rs +index 86316f4..0ec0be2 100644 +--- a/src/rust/cryptography-x509-verification/src/types.rs ++++ b/src/rust/cryptography-x509-verification/src/types.rs +@@ -150,44 +150,69 @@ impl<'a> DNSConstraint<'a> { + DNSName::new(pattern).map(Self) + } + +- /// Returns true if this `DNSConstraint` matches the given `DNSPattern`. ++ /// Returns true if the given exact `DNSName` falls within this ++ /// constraint's subtree. + /// +- /// Constraint matching is defined by RFC 5280: any DNS name that can +- /// be constructed by simply adding zero or more labels to the left-hand +- /// side of the name satisfies the name constraint. ++ /// Per RFC 5280, a name satisfies the constraint if it can be constructed ++ /// by adding zero or more labels to the left-hand side of the constraint's ++ /// name (i.e. it is the constraint's name, or a subdomain of it). ++ fn contains(&self, name: &DNSName<'_>) -> bool { ++ // NOTE: This may seem like an obtuse way to perform label matching, ++ // but it saves us a few allocations: doing a substring check instead ++ // would require us to clone each string and do case normalization. ++ // Note also that we check the length in advance: Rust's zip ++ // implementation terminates with the shorter iterator, so we need ++ // to first check that the candidate name is at least as long as ++ // the constraint it's matching against. ++ name.as_str().len() >= self.0.as_str().len() ++ && self ++ .0 ++ .rlabels() ++ .zip(name.rlabels()) ++ .all(|(a, o)| a.eq_ignore_ascii_case(o)) ++ } ++ ++ /// Returns true if the given `DNSPattern` is permitted by this constraint, ++ /// for use with a `permittedSubtrees` name constraint. + /// +- /// On top of what RFC 5280 specifies, we define behavior for wildcard +- /// patterns (which are not covered by RFC 5280): a wildcard pattern +- /// matches a constraint if the pattern matches the constraint's inner name, +- /// _or_ if the pattern's inner name matches the constraint. +- /// This allows us to reject DNS names like `*.example.com` when +- /// the constraint is `example.com` or `bar.example.com`. +- pub fn matches(&self, name: &DNSPattern<'_>) -> bool { +- match name { +- DNSPattern::Exact(name) => { +- // NOTE: This may seem like an obtuse way to perform label matching, +- // but it saves us a few allocations: doing a substring check instead +- // would require us to clone each string and do case normalization. +- // Note also that we check the length in advance: Rust's zip +- // implementation terminates with the shorter iterator, so we need +- // to first check that the candidate name is at least as long as +- // the constraint it's matching against. +- name.as_str().len() >= self.0.as_str().len() +- && self +- .0 +- .rlabels() +- .zip(name.rlabels()) +- .all(|(a, o)| a.eq_ignore_ascii_case(o)) +- } +- DNSPattern::Wildcard(inner) => { +- // NOTE: This check is not as simple as a single pattern match, +- // since we need two subtly distinct cases here: +- // 1. Constraint `bar.example.com` on `*.example.com` +- // 2. Constraint `example.com` on `*.example.com` +- // The first cases is handled by `DNSPattern::matches`, and the second is handled +- // by `DNSConstraint::matches`. +- name.matches(&self.0) || self.matches(&DNSPattern::Exact(inner.clone())) +- } ++ /// A pattern is permitted only if *every* name it can represent falls ++ /// within the constraint's subtree. An exact name is permitted by ordinary ++ /// subtree containment (per RFC 5280). ++ /// ++ /// Wildcard patterns are not covered by RFC 5280; we define their behavior ++ /// here. A wildcard pattern `*.X` is permitted only if its base name `X` ++ /// itself falls within the constraint's subtree. This is stricter than ++ /// mere overlap: `*.example.com` is *not* permitted by `foo.example.com`, ++ /// since it can also expand to a sibling such as `bar.example.com` that ++ /// lies outside the permitted subtree. ++ pub fn permits(&self, pattern: &DNSPattern<'_>) -> bool { ++ match pattern { ++ DNSPattern::Exact(name) => self.contains(name), ++ DNSPattern::Wildcard(base) => self.contains(base), ++ } ++ } ++ ++ /// Returns true if the given `DNSPattern` is excluded by this constraint, ++ /// for use with an `excludedSubtrees` name constraint. ++ /// ++ /// A pattern is excluded if *any* name it can represent falls within the ++ /// constraint's subtree. An exact name is excluded by ordinary subtree ++ /// containment (per RFC 5280). ++ /// ++ /// Wildcard patterns are not covered by RFC 5280; we define their behavior ++ /// here. A wildcard pattern `*.X` is excluded if it overlaps the subtree ++ /// at all, which happens in two subtly distinct cases: ++ /// ++ /// 1. The constraint is more specific than the wildcard, e.g. constraint ++ /// `bar.example.com` and pattern `*.example.com` (which can expand to ++ /// `bar.example.com`). This is handled by `DNSPattern::matches`. ++ /// 2. The wildcard's base name falls within the subtree, e.g. constraint ++ /// `example.com` and pattern `*.example.com`. This is handled by ++ /// `DNSConstraint::contains`. ++ pub fn excludes(&self, pattern: &DNSPattern<'_>) -> bool { ++ match pattern { ++ DNSPattern::Exact(name) => self.contains(name), ++ DNSPattern::Wildcard(base) => pattern.matches(&self.0) || self.contains(base), + } + } + } +@@ -590,37 +615,69 @@ mod tests { + } + + #[test] +- fn test_dnsconstraint_matches() { ++ fn test_dnsconstraint_exact() { + let example_com = DNSConstraint::new("example.com").unwrap(); + +- // Exact domain and arbitrary subdomains match. +- assert!(example_com.matches(&DNSPattern::new("example.com").unwrap())); +- assert!(example_com.matches(&DNSPattern::new("foo.example.com").unwrap())); +- assert!(example_com.matches(&DNSPattern::new("foo.bar.baz.quux.example.com").unwrap())); ++ // For exact patterns, `permits` and `excludes` behave identically: ++ // the pattern must fall within the constraint's subtree. ++ for permitted in [ ++ "example.com", ++ "foo.example.com", ++ "foo.bar.baz.quux.example.com", ++ ] { ++ let pattern = DNSPattern::new(permitted).unwrap(); ++ assert!(example_com.permits(&pattern)); ++ assert!(example_com.excludes(&pattern)); ++ } + + // Parent domains, distinct domains, and substring domains do not match. +- assert!(!example_com.matches(&DNSPattern::new("com").unwrap())); +- assert!(!example_com.matches(&DNSPattern::new("badexample.com").unwrap())); +- assert!(!example_com.matches(&DNSPattern::new("wrong.com").unwrap())); ++ for rejected in ["com", "badexample.com", "wrong.com"] { ++ let pattern = DNSPattern::new(rejected).unwrap(); ++ assert!(!example_com.permits(&pattern)); ++ assert!(!example_com.excludes(&pattern)); ++ } + } + + #[test] +- fn test_dnsconstraint_matches_wildcard() { ++ fn test_dnsconstraint_permits_wildcard() { ++ let com = DNSConstraint::new("com").unwrap(); ++ let example_com = DNSConstraint::new("example.com").unwrap(); ++ let foo_example_com = DNSConstraint::new("foo.example.com").unwrap(); ++ let any_example_com = DNSPattern::new("*.example.com").unwrap(); ++ ++ // A wildcard `*.example.com` is permitted only by constraints whose ++ // subtree contains *every* name the wildcard can expand to, i.e. those ++ // that contain `example.com` itself. ++ assert!(com.permits(&any_example_com)); ++ assert!(example_com.permits(&any_example_com)); ++ ++ // A constraint more specific than the wildcard's base does *not* ++ // permit it: the wildcard can expand to siblings outside the subtree ++ // (e.g. `*.example.com` can be `bar.example.com`, which lies outside ++ // `foo.example.com`). ++ assert!(!foo_example_com.permits(&any_example_com)); ++ } ++ ++ #[test] ++ fn test_dnsconstraint_excludes_wildcard() { + let com = DNSConstraint::new("com").unwrap(); + let example_com = DNSConstraint::new("example.com").unwrap(); + let bar_example_com = DNSConstraint::new("bar.example.com").unwrap(); + let baz_bar_example_com = DNSConstraint::new("baz.bar.example.com").unwrap(); + let any_example_com = DNSPattern::new("*.example.com").unwrap(); + +- assert!(com.matches(&any_example_com)); +- assert!(example_com.matches(&any_example_com)); +- assert!(bar_example_com.matches(&any_example_com)); +- +- // A constraint on `baz.bar.example.com` doesn't match `*.example.com`, +- // since `baz.bar.example.com` matches zero or more sublabels of +- // `baz.bar.example.com` while `*.example.com` matches exactly one +- // sublabel of `example.com`. +- assert!(!baz_bar_example_com.matches(&any_example_com)); ++ // A wildcard `*.example.com` is excluded by any constraint whose ++ // subtree it overlaps, including constraints more specific than the ++ // wildcard's base. ++ assert!(com.excludes(&any_example_com)); ++ assert!(example_com.excludes(&any_example_com)); ++ assert!(bar_example_com.excludes(&any_example_com)); ++ ++ // A constraint on `baz.bar.example.com` doesn't overlap ++ // `*.example.com`, since `baz.bar.example.com` matches zero or more ++ // sublabels of `baz.bar.example.com` while `*.example.com` matches ++ // exactly one sublabel of `example.com`. ++ assert!(!baz_bar_example_com.excludes(&any_example_com)); + } + + #[test] +-- +2.43.0 + From patchwork Thu Sep 17 22:05:53 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 98591 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id CAD7DC982E9 for ; Thu, 17 Sep 2026 22:08:05 +0000 (UTC) Received: from mail-wm2-f12.google.com (mail-wm2-f12.google.com [74.125.225.140]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.1560.1789682875284044630 for ; Thu, 17 Sep 2026 15:07:55 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=XEh24+B9; spf=pass (domain: smile.fr, ip: 74.125.225.140, mailfrom: yoann.congal@smile.fr) Received: by mail-wm2-f12.google.com with SMTP id 5b1f17b1804b1-49e620fa473so732495e9.1 for ; Thu, 17 Sep 2026 15:07:55 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1789682873; x=1790287673; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=tIs5yHPwh/xOP2k16tnjAlBBarB1L5b5Gx/8UvI38ZE=; b=XEh24+B9aEwxYXPRkV0tqsZb3nqgEZiUg4SRfADXmt9i3hXyAB20YWSFNF+n9yNFJV Vykr5o6MYuJG0xELf5LCIfwbqcSaOAMom5gA+a9kAhlLrcV+awowE0MwiKgNNAtst4Ki NrDdYguLmDmoDD+HhU8TIRL9UNjYEF1YxfKAQ= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1789682873; x=1790287673; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=tIs5yHPwh/xOP2k16tnjAlBBarB1L5b5Gx/8UvI38ZE=; b=X+M6qvYdXiGhTLktc4k00sfJu05UYMI5sx4XCkyjBVyA4Gemfj+1+twHmr7VPjKjj3 A39Vt2CXt7eKXRMnvXl/m3dPveJZlePKYF20y70VkomvLnXVPgSJLzgyZTM3VR0gk7Ur 1K0yreftVWdQpU9UUdapc9B2OvKUEWTOgHefwizwJ1cs8Tr7StMdPEgWplR2Bz1DdIIq RQ2mZ2fOX7i5WzV4L2A92nCMQvuOKVpIOLk7jrXjF0b+uu8fPhhRMWrPzX17SBkVteQq Kq+mK/37MI6PUR45c6tVmFLHYP2L9Mv5AdZ/dyCY0ZvSzgUwmxHpLetaHi2Ijn2aGBZc nxhQ== X-Gm-Message-State: AFuF++nmSkF1YtrUm9JsXvqUGni8uBB59lYZhTn5NVUw90X6XOcQtm+t AW4i8EoEhL42ewtwAUZ4Ab7SHvPi/4FGWvnGWSxnXeJ/zoKi/Blbt82eP1VAGDGg1tK40BLaAaq /YK/ka5I= X-Gm-Gg: AYBFou1CICSm4Y/uaOjrTEx1LL1JOTeoWP1YTMhH1xi0yI0LgnE0Yzyh94GRvPzrEhk qLzenM4xp/ExGkE7IkM2CDEFujNYxY1YLuzCPiwvj5N5XSOed5MM5SUQMDNkydd7IYum4A2Z6xz 4mg5QonsYd14aIg/hETE7pKs7H4ukvGdZMJhdcmErf7gC6viRsHIORAtZAl1zURsR6C3/asO0LE 1JINo617+x6zqlOkcQguGjEFVbr7fU+vW3B9f3MAIpo6WkAVZ4CkqPEF50l1mvz9XNIL/96YTkJ 9M+abKZLrbdi3Xveakiu+O2gRKeUDIuWgVuCLbzZB2lNxDkDqq2Gl5HrEo5bQDb6Ix+rFnUIaxv Uu6Venfs7vOBYa5HFcs254TXVFRoYNbKdGbAk11tKWjEMHcYfpu5JFgyyYoSHLvhkWoRSWDVSoG tBO8rac6y42z+M1yhGp3aU+H4An72sNjO6aAs+hQzM4p1nXy6SEi1DkbhPfpRDAiI9GrEO2TqLo FzWaGpsTXQR/51KMFjKyGvyYg/YyWIR8iAdS4Yff54i3FNEtsSL0Z6wnwEnywl+DHuw4dOrN98= X-Received: by 2002:a05:600c:4505:b0:49e:69e3:884d with SMTP id 5b1f17b1804b1-49fc56dba00mr2984415e9.4.1789682873472; Thu, 17 Sep 2026 15:07:53 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-49fc471b9a2sm8984075e9.0.2026.09.17.15.07.53 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Thu, 17 Sep 2026 15:07:53 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][wrynose 08/79] python3-cryptography: Fix CVE-2026-69249 Date: Fri, 18 Sep 2026 00:05:53 +0200 Message-ID: X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Thu, 17 Sep 2026 22:08:05 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/246103 From: Vijay Anusuri Pick patch according to [2] [1] https://nvd.nist.gov/vuln/detail/cve-2026-69249 [2] https://security-tracker.debian.org/tracker/CVE-2026-69249 Signed-off-by: Vijay Anusuri Signed-off-by: Yoann Congal --- .../python/python3-cryptography.bb | 1 + .../python3-cryptography/CVE-2026-69249.patch | 338 ++++++++++++++++++ 2 files changed, 339 insertions(+) create mode 100644 meta/recipes-devtools/python/python3-cryptography/CVE-2026-69249.patch diff --git a/meta/recipes-devtools/python/python3-cryptography.bb b/meta/recipes-devtools/python/python3-cryptography.bb index 5c1de9192b1..f3cb755ed5b 100644 --- a/meta/recipes-devtools/python/python3-cryptography.bb +++ b/meta/recipes-devtools/python/python3-cryptography.bb @@ -16,6 +16,7 @@ SRC_URI[sha256sum] = "e4cfd68c5f3e0bfdad0d38e023239b96a2fe84146481852dffbcca442c SRC_URI += "file://0001-pyproject.toml-remove-benchmark-disable-option.patch \ file://0002-Fix-installing-stray-files-into-site-packages.patch \ file://CVE-2026-69248.patch \ + file://CVE-2026-69249.patch \ file://check-memfree.py \ file://run-ptest \ " diff --git a/meta/recipes-devtools/python/python3-cryptography/CVE-2026-69249.patch b/meta/recipes-devtools/python/python3-cryptography/CVE-2026-69249.patch new file mode 100644 index 00000000000..f700d3f1eee --- /dev/null +++ b/meta/recipes-devtools/python/python3-cryptography/CVE-2026-69249.patch @@ -0,0 +1,338 @@ +From 4a12cf49675a184e47f912b00b04f3a629283582 Mon Sep 17 00:00:00 2001 +From: William Woodruff +Date: Sat, 6 Jun 2026 23:30:03 -0400 +Subject: [PATCH] Add a signature validation budget during path construction + (#14960) + +* Add a signature validation budget during path construction + +This extends our existing NC budget check to include a budget +for signature validations. If a path construction exceeds the +budget by performing more than the allowed number of signature +validation steps, the entire construction fails. + +For now, our budget is 128 signature validations. This is +consistent with (higher than) Go and rustls-webpki, which +both set a limit of 100. Like Go, we attempt to make the "best" +use of our signature budget by ordering by likelihood, using +AKI/SKI match as the strongest signal of fitness. + +* Bump limbo + +* Temporary commit + +* Revert "Temporary commit" + +This reverts commit bcdb6808562a8b8f484f85d21cb201cfdb2bbbd7. + +* Fudge a coverage test into place + +* Coverage for the coverage god + +Upstream-Status: Backport [https://github.com/pyca/cryptography/commit/4a12cf49675a184e47f912b00b04f3a629283582] +CVE: CVE-2026-69249 +Signed-off-by: Vijay Anusuri +--- + .../cryptography-x509-verification/src/lib.rs | 183 +++++++++++++++++- + .../src/policy/mod.rs | 9 +- + 2 files changed, 182 insertions(+), 10 deletions(-) + +diff --git a/src/rust/cryptography-x509-verification/src/lib.rs b/src/rust/cryptography-x509-verification/src/lib.rs +index 60c89d4..7ee3bb0 100644 +--- a/src/rust/cryptography-x509-verification/src/lib.rs ++++ b/src/rust/cryptography-x509-verification/src/lib.rs +@@ -18,10 +18,14 @@ use std::vec; + use asn1::ObjectIdentifier; + use cryptography_x509::common::Asn1Read; + use cryptography_x509::extensions::{ +- DuplicateExtensionsError, Extensions, NameConstraints, SubjectAlternativeName, ++ AuthorityKeyIdentifier, DuplicateExtensionsError, Extensions, NameConstraints, ++ SubjectAlternativeName, + }; + use cryptography_x509::name::GeneralName; +-use cryptography_x509::oid::{NAME_CONSTRAINTS_OID, SUBJECT_ALTERNATIVE_NAME_OID}; ++use cryptography_x509::oid::{ ++ AUTHORITY_KEY_IDENTIFIER_OID, NAME_CONSTRAINTS_OID, SUBJECT_ALTERNATIVE_NAME_OID, ++ SUBJECT_KEY_IDENTIFIER_OID, ++}; + + use crate::certificate::cert_is_self_issued; + use crate::ops::{CryptoOps, VerificationCertificate}; +@@ -98,15 +102,23 @@ impl Display for ValidationError<'_, B> { + + struct Budget { + name_constraint_checks: usize, ++ signature_checks: usize, + } + + impl Budget { +- // Same limit as other validators ++ // The maximum number of name constraint checks performed when attempting ++ // path construction. This is the same limit as other validators. + const DEFAULT_NAME_CONSTRAINT_CHECK_LIMIT: usize = 1 << 20; + ++ // The maximum number of signature verifications performed when attempting ++ // path construction. The is similar to other validators: ++ // both Go and rustls-webpki pick 100. ++ const DEFAULT_SIGNATURE_CHECK_LIMIT: usize = 1 << 7; ++ + fn new() -> Budget { + Budget { + name_constraint_checks: Self::DEFAULT_NAME_CONSTRAINT_CHECK_LIMIT, ++ signature_checks: Self::DEFAULT_SIGNATURE_CHECK_LIMIT, + } + } + +@@ -119,6 +131,15 @@ impl Budget { + })?; + Ok(()) + } ++ ++ fn signature_check<'chain, B: CryptoOps>(&mut self) -> ValidationResult<'chain, (), B> { ++ self.signature_checks = self.signature_checks.checked_sub(1).ok_or_else(|| { ++ ValidationError::new(ValidationErrorKind::FatalError( ++ "Exceeded maximum signature check limit", ++ )) ++ })?; ++ Ok(()) ++ } + } + + struct NameChain<'a, 'chain> { +@@ -341,18 +362,57 @@ impl<'a, 'chain, B: CryptoOps> ChainBuilder<'a, 'chain, B> { + } + } + ++ /// Identify and return potential issuers for `cert`, considering ++ /// candidates from both the trusted store and untrusted intermediate set. ++ /// Trusted candidates are returned before untrusted intermediate ++ /// candidates, and both groups are opportunisitically ordered by ++ /// "likeliness" in terms of AKI/SKI match. + fn potential_issuers( + &self, + cert: &'a VerificationCertificate<'chain, B>, +- ) -> impl Iterator> + '_ { +- // TODO: Optimizations: +- // * Search by AKI and other identifiers? +- self.store ++ cert_extensions: &Extensions<'chain>, ++ ) -> Vec<&'a VerificationCertificate<'chain, B>> { ++ let mut candidates: Vec<&'a VerificationCertificate<'chain, B>> = self ++ .store + .get_by_subject(&cert.certificate().tbs_cert.issuer) + .iter() + .chain(self.intermediates.iter().filter(|&candidate| { + candidate.certificate().subject() == cert.certificate().issuer() + })) ++ .collect(); ++ ++ let want_kid: Option<&[u8]> = cert_extensions ++ .get_extension(&AUTHORITY_KEY_IDENTIFIER_OID) ++ .and_then(|ext| ext.value::>().ok()) ++ .and_then(|aki| aki.key_identifier); ++ ++ // This mirrors Go's `findPotentialParents`: we have a global ++ // signature budget, so we want to bucket candidates by likeliness ++ // to avoid wasting budget on (potentially adversarial) name collisions. ++ // ++ // Observe that we use a stable sort to preserve trusted candidates ++ // before untrusted candidates in each likeliness bucket. In other ++ // words, we always try a likely trusted candidate over an equally ++ // likely untrusted one. ++ // ++ // See: ++ candidates.sort_by_key(|candidate| { ++ let have_kid: Option<&[u8]> = ++ candidate.certificate().extensions().ok().and_then(|exts| { ++ exts.get_extension(&SUBJECT_KEY_IDENTIFIER_OID) ++ .and_then(|ext| ext.value::<&[u8]>().ok()) ++ }); ++ ++ match (want_kid, have_kid) { ++ // cert AKID matches candidate SKID, highest likelihood. ++ (Some(want), Some(have)) if want == have => 0, ++ // cert AKID and candidate SKID don't match, lowest likelihood. ++ (Some(_), Some(_)) => 2, ++ // cert AKID and/or candidate SKID is not present, medium likelihood. ++ _ => 1u8, ++ } ++ }); ++ candidates + } + + fn build_chain_inner( +@@ -385,7 +445,8 @@ impl<'a, 'chain, B: CryptoOps> ChainBuilder<'a, 'chain, B> { + // Otherwise, we collect a list of potential issuers for this cert, + // and continue with the first that verifies. + let mut last_err: Option> = None; +- for issuing_cert_candidate in self.potential_issuers(working_cert) { ++ for issuing_cert_candidate in self.potential_issuers(working_cert, working_cert_extensions) ++ { + // A candidate issuer is said to verify if it both + // signs for the working certificate and conforms to the + // policy. +@@ -395,6 +456,7 @@ impl<'a, 'chain, B: CryptoOps> ChainBuilder<'a, 'chain, B> { + working_cert, + current_depth, + &issuer_extensions, ++ budget, + ) { + Ok(_) => { + match self.build_chain_inner( +@@ -503,10 +565,15 @@ impl<'a, 'chain, B: CryptoOps> ChainBuilder<'a, 'chain, B> { + #[cfg(test)] + mod tests { + use asn1::ParseError; ++ use cryptography_x509::certificate::Certificate; + use cryptography_x509::oid::SUBJECT_ALTERNATIVE_NAME_OID; + + use crate::certificate::tests::PublicKeyErrorOps; +- use crate::{ValidationError, ValidationErrorKind}; ++ use crate::ops::{CryptoOps, VerificationCertificate}; ++ use crate::policy::{Policy, PolicyDefinition, Subject}; ++ use crate::trust_store::Store; ++ use crate::types::DNSName; ++ use crate::{Budget, ChainBuilder, NameChain, ValidationError, ValidationErrorKind}; + + #[test] + fn test_validationerror_display() { +@@ -528,4 +595,102 @@ mod tests { + ValidationError::::new(ValidationErrorKind::FatalError("oops")); + assert_eq!(err.to_string(), "fatal error: oops"); + } ++ ++ /// A `CryptoOps` whose public key extraction and signature verification ++ /// always succeed, so that `valid_issuer` can be driven to completion ++ /// without real cryptographic material. ++ struct NullOps; ++ ++ impl CryptoOps for NullOps { ++ type Key = (); ++ type Err = (); ++ type CertificateExtra = (); ++ type PolicyExtra = (); ++ ++ fn public_key(&self, _cert: &Certificate<'_>) -> Result { ++ Ok(()) ++ } ++ ++ fn verify_signed_by( ++ &self, ++ _cert: &Certificate<'_>, ++ _key: &Self::Key, ++ ) -> Result<(), Self::Err> { ++ Ok(()) ++ } ++ ++ fn clone_public_key(_key: &Self::Key) -> Self::Key {} ++ ++ fn clone_extra(_extra: &Self::CertificateExtra) -> Self::CertificateExtra {} ++ } ++ ++ #[test] ++ fn test_clone() { ++ assert_eq!(NullOps::clone_public_key(&()), ()); ++ assert_eq!(NullOps::clone_extra(&()), ()); ++ } ++ ++ // A self-issued ("looping") CA certificate that is its own issuer. ++ fn looping_ca_pem() -> pem::Pem { ++ pem::parse( ++ "-----BEGIN CERTIFICATE----- ++MIIBcjCCARmgAwIBAgIBATAKBggqhkjOPQQDAjAhMR8wHQYDVQQDDBZsb29waW5n ++IHNlbGYtc2lnbmVkIENBMB4XDTIzMTIzMTAwMDAwMFoXDTI0MDEzMTAwMDAwMFow ++ITEfMB0GA1UEAwwWbG9vcGluZyBzZWxmLXNpZ25lZCBDQTBZMBMGByqGSM49AgEG ++CCqGSM49AwEHA0IABKAoXUGnHdfXJbSXjRjeW+PCVHmlo4KEki69N5pJUA0QyQMR ++v9ySOMnWf3Ea7TR4g3zdguwTP7LdpSku3uR1QkmjQjBAMA8GA1UdEwEB/wQFMAMB ++Af8wDgYDVR0PAQH/BAQDAgGGMB0GA1UdDgQWBBR23MGdG1Ma9iR+3CxKTafD/OE0 ++dTAKBggqhkjOPQQDAgNHADBEAiA4RCr07KfZdM16VfGNZAQFjvC60SWIU3RRVY/L ++qolIOwIgCaIgj9ipK0Q0p+45UJiq+L/ncrxsweJkFq/UYubzhX0= ++-----END CERTIFICATE-----", ++ ) ++ .unwrap() ++ } ++ ++ /// Exercises our pathlen overflow error scenario. ++ /// ++ /// This condition is logically unreachable from Python, since ++ /// we unconditionally limit signature checks to a number smaller ++ /// than `u8::MAX`, meaning that we always exhaust the signature budget ++ /// before potentially exhausting the pathlen budget. ++ /// ++ /// To test that directly, we manually lift the signature budget ++ /// and start our pathlen state right at `u8::MAX`, guaranteeing ++ /// an overflow on the immediate chain building step. ++ #[test] ++ fn test_build_chain_inner_depth_overflow() { ++ let pem = looping_ca_pem(); ++ let ca = asn1::parse_single::>(pem.contents()).unwrap(); ++ let ca_exts = ca.extensions().ok().unwrap(); ++ ++ // The same self-issued CA is both the working certificate and its own ++ // (only) candidate issuer, so the search recurses on itself. ++ let working = VerificationCertificate::::new(&ca, ()); ++ let intermediates = [VerificationCertificate::::new(&ca, ())]; ++ let store: Store<'_, NullOps> = Store::new([]); ++ ++ let subject = Subject::DNS(DNSName::new("example.com").unwrap()); ++ let time = asn1::DateTime::new(2024, 1, 1, 0, 0, 0).unwrap(); ++ let policy_def = ++ PolicyDefinition::server(NullOps, subject, time, Some(u8::MAX), None, None).unwrap(); ++ let policy = Policy::new(&policy_def, ()); ++ ++ let builder = ChainBuilder::new(&intermediates, &policy, &store); ++ let mut budget = Budget { ++ name_constraint_checks: usize::MAX, ++ signature_checks: usize::MAX, ++ }; ++ ++ let name_chain = NameChain::new::(None, &ca_exts, false) ++ .ok() ++ .unwrap(); ++ let err = builder ++ .build_chain_inner(&working, u8::MAX, &ca_exts, name_chain, &mut budget) ++ .unwrap_err(); ++ ++ assert!(matches!( ++ err.kind, ++ ValidationErrorKind::Other(msg) if msg.contains("current depth calculation overflowed") ++ )); ++ } + } +diff --git a/src/rust/cryptography-x509-verification/src/policy/mod.rs b/src/rust/cryptography-x509-verification/src/policy/mod.rs +index 1d82e4b..b3a1f08 100644 +--- a/src/rust/cryptography-x509-verification/src/policy/mod.rs ++++ b/src/rust/cryptography-x509-verification/src/policy/mod.rs +@@ -30,7 +30,9 @@ pub use crate::policy::extension::{ + PresentExtensionValidatorCallback, + }; + use crate::types::{DNSName, DNSPattern, IPAddress}; +-use crate::{ValidationError, ValidationErrorKind, ValidationResult, VerificationCertificate}; ++use crate::{ ++ Budget, ValidationError, ValidationErrorKind, ValidationResult, VerificationCertificate, ++}; + + // RSA key constraints, as defined in CA/B 6.1.5. + const WEBPKI_MINIMUM_RSA_MODULUS: usize = 2048; +@@ -503,6 +505,7 @@ impl<'a, B: CryptoOps> Policy<'a, B> { + child: &VerificationCertificate<'chain, B>, + current_depth: u8, + issuer_extensions: &Extensions<'_>, ++ budget: &mut Budget, + ) -> ValidationResult<'chain, (), B> { + // The issuer needs to be a valid CA at the current depth. + self.permits_ca(issuer, current_depth, issuer_extensions) +@@ -563,6 +566,10 @@ impl<'a, B: CryptoOps> Policy<'a, B> { + } + } + ++ // Charge the (potentially expensive) signature verification against the ++ // budget before performing it, bounding the total work an attacker can ++ // force during chain building. ++ budget.signature_check()?; + if self.ops.verify_signed_by(child.certificate(), pk).is_err() { + return Err(ValidationError::new(ValidationErrorKind::Other( + "signature does not match".to_string(), +-- +2.43.0 + From patchwork Thu Sep 17 22:05:54 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 98593 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id DBA2DC982EC for ; Thu, 17 Sep 2026 22:08:05 +0000 (UTC) Received: from mail-wm2-f13.google.com (mail-wm2-f13.google.com [74.125.225.141]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.1561.1789682876149632576 for ; Thu, 17 Sep 2026 15:07:56 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=PWFAgEl6; spf=pass (domain: smile.fr, ip: 74.125.225.141, mailfrom: yoann.congal@smile.fr) Received: by mail-wm2-f13.google.com with SMTP id 5b1f17b1804b1-49e6c0fce17so584555e9.1 for ; Thu, 17 Sep 2026 15:07:55 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1789682874; x=1790287674; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=ehbNKlJOrfIxbV6oqRGBieBG41HEmrB5j3jYDVKKVtM=; b=PWFAgEl6ikHRUGsErCMdhSbdhqcSOP8Ie0uju2C4xUPcUJDGjKOpffrfEGzqAOLFP3 m8nM6UpKfH0yrX36EBVbf1mLGk21BNQEOjaTZcs3j4zlw6x4aGE9AMQzpWmt3j6s3x1o Wyvfw872BWksTesHHjVm7k/+0nhG5jhI/UOZ8= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1789682874; x=1790287674; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=ehbNKlJOrfIxbV6oqRGBieBG41HEmrB5j3jYDVKKVtM=; b=GUbDmdkjZUMmX+tY3AjdWbbZrj/EciV41H/y+sxJlKojF9X9JI7M0lr5eijxKj6xfP yTYMmH/+zGvqIg5gUpk9+aJtQBFTEV6OHfai7uWdv32IW1xNNFgM0rSyGDc7X3ItB3Y7 LsYyByxzn0NTaOW3uy3I61HOK1hYJUpcJYy6Dh4wetK7Ad33Fi/+6dHiGMpS0sVA0kQM TS6FnMQR5d22vmUcyaLC8Ed5/cYw183xhBgEJ1KcT79EYrfkSnmguIwX2NdvHAMSZTeN /V+u2z2b1n1jfWYKLGcYUXZVwFIT9IAb8G/z8STdHcrIJ/jiZTExvaz/BUwhnjMptFBs qYsQ== X-Gm-Message-State: AFuF++k/MH5ZBX9efug/ZK7Y0INr+r7uE4s/A7yRvpk+/Y67ScKDtsQu spP7qLdqorlTJgRs05SjelmdAzJVsCNKGdwCzq62ALtcNadX+h65YF4elT+hKEE0/dWHK6XyW6U wRKdP38k= X-Gm-Gg: AYBFou0zAnN0TMxqqed3M9NV2p0+9WkeFmlPJeOJpAG9OUG+PS+mHzLHtczyaKsio7C nZZJcDfC9lQHJ11spmowW4/ZYYWYBqh5b28Cj9YM4WqtqbNrIA2tcI0LiX79qAvoLmjrE5Rti6P PxEAIxm+EIDIhrMvOGWjttjyjJCnbThaipQvLbAL8ix3UqNY9FFyTV2J7724ANIXst/yXb7SLDD Y1XHi/UjKsedet4SOfX+GHsNnTJHyxw7LmAXDzI+x55RBmVU9C7DFXtIwruoQ4tB01p1phpfX25 jZsAEIAL/Wny7IaBYpsrJM0cGh/Bz5Qhak5vfiS2PGGNBU/LaOFFY6OH0lzGYUVp3bzqbuChzJV vB/bh/4eO7mSwBFBdHKj1xBRgKMal/JGHucXJ7JD6NRqI7/ml/8wsvSwsckP67MlJMkTj4xYPHx gah/9khQ5MZgbrnvkKca323HG5otqWns2LtHkdEsMgyrhRND6HxSMC/2HWr3llLRJRSWDsguiJD wEzIUBBaHptl9aLEEM4Xf0nIjK8nrdruiL5a26pGIex0xbXIbbT6qJ/43g0sb9/L+nkcBayBgaK X-Received: by 2002:a05:600c:34d4:b0:49c:fc6e:a3d5 with SMTP id 5b1f17b1804b1-49fc574f51cmr3038885e9.20.1789682874294; Thu, 17 Sep 2026 15:07:54 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-49fc471b9a2sm8984075e9.0.2026.09.17.15.07.53 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Thu, 17 Sep 2026 15:07:53 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][wrynose 09/79] libxml2: upgrade 2.15.3 -> 2.15.4 Date: Fri, 18 Sep 2026 00:05:54 +0200 Message-ID: <22cf12907dfe4ba8ac6aa0aa62f9f954dacfa591.1789681419.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Thu, 17 Sep 2026 22:08:05 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/246104 From: Siddharth Doshi v2.15.4: Sep 01 2026 - xmlregexp: Prevent out-of-bounds read in NXT macro - fix: add missing overflow checks in dict.c, uri.c, and valid.c - xmlregexp: Calc string length after null checking - xpointer: Check overflow in xmlXPtrEvalXPtrPart - xmlIO: Check for int overflow before calling writecallback - fix(xinclude): propagate parseFlags in xmlXIncludeProcess and xmlXIncludeProcessTree - Improve bound checks for xmlcatalog and xmllint arguments (out-of-bound) - Fix memory leak in static Windows library (memory-leak) - xmlreader: Copy DTD in xmlTextReaderDumpCopy - parser: Fix double free in xmlIOParseDTD (double-free) - parser: fix division-by-zero when maxAmpl is set to 0 - parser: Fix memory leak in xmlCtxtSetSaxHandler (memory-leak) - catalog: Make sure to reset catalog resolve cache - xmlAddChild: unlink node before free for text nodes (memory-leak) - Normalize entity values in attr in xmlNodeGetContent - Handle whitespace for date/time/duration types - catalog: Fix NULL deref for nextCatalog without 'catalog' attribute (null-deref) For detailed information, see the link below: [1] https://gitlab.gnome.org/GNOME/libxml2/-/commit/96498992efa48d52b0e8b83058bd88dbdaf153c1 Note: Removed CVE-2026-11979 as it is already fixed. CVE's Fixed: CVE-2026-11979 (CVSSv3: 7.8): https://nvd.nist.gov/vuln/detail/CVE-2026-11979 CVE-2026-86137 (CVSSv3: 2.9): https://nvd.nist.gov/vuln/detail/CVE-2026-86137 CVE-2026-86138 (CVSSv3: 6.9): https://nvd.nist.gov/vuln/detail/CVE-2026-86138 CVE-2026-86139 (CVSSv3: 6.9): https://nvd.nist.gov/vuln/detail/CVE-2026-86139 CVE-2026-86140 (CVSSv3: 8.0): https://nvd.nist.gov/vuln/detail/CVE-2026-86140 CVE-2026-86141 (CVSSv3: 2.9): https://nvd.nist.gov/vuln/detail/CVE-2026-86141 CVE-2026-86142 (CVSSv3: 6.9): https://nvd.nist.gov/vuln/detail/CVE-2026-86142 CVE-2026-86143 (CVSSv3: 6.9): https://nvd.nist.gov/vuln/detail/CVE-2026-86143 CVE-2026-86144 (CVSSv3: 5.6): https://nvd.nist.gov/vuln/detail/CVE-2026-86144 Signed-off-by: Richard Purdie (cherry picked from commit 8875c7e8dbecc0700aa6db49b66b8d77a21938b1) Signed-off-by: Siddharth Doshi Signed-off-by: Yoann Congal [YC: I merged commit message from master/RP and Siddharth] --- .../libxml/libxml2/CVE-2026-11979.patch | 81 ------------------- .../{libxml2_2.15.3.bb => libxml2_2.15.4.bb} | 3 +- 2 files changed, 1 insertion(+), 83 deletions(-) delete mode 100644 meta/recipes-core/libxml/libxml2/CVE-2026-11979.patch rename meta/recipes-core/libxml/{libxml2_2.15.3.bb => libxml2_2.15.4.bb} (96%) diff --git a/meta/recipes-core/libxml/libxml2/CVE-2026-11979.patch b/meta/recipes-core/libxml/libxml2/CVE-2026-11979.patch deleted file mode 100644 index a14e566681e..00000000000 --- a/meta/recipes-core/libxml/libxml2/CVE-2026-11979.patch +++ /dev/null @@ -1,81 +0,0 @@ -From dfad0660f7dab3b5f8317b703b16ad0b0d12697d Mon Sep 17 00:00:00 2001 -From: Daniel Garcia Moreno -Date: Fri, 22 May 2026 12:21:20 +0200 -Subject: [PATCH] xmlcatalog: overflow check for large --shell commands - -Fix https://gitlab.gnome.org/GNOME/libxml2/-/work_items/1124 - -CVE: CVE-2026-11979 -Signed-off-by: Anton Skorup -Upstream-Status: Backport [https://gitlab.gnome.org/GNOME/libxml2/-/commit/c2e233fc1b341685fc99621b2768b503f777a72e] ---- - test/catalogs/test.sh | 11 +++++++++++ - xmlcatalog.c | 16 ++++++++++++++++ - 2 files changed, 27 insertions(+) - -diff --git a/test/catalogs/test.sh b/test/catalogs/test.sh -index 7e5eaa76..84e8b90a 100755 ---- a/test/catalogs/test.sh -+++ b/test/catalogs/test.sh -@@ -10,6 +10,17 @@ fi - - exitcode=0 - -+# Test xmlcatalog --shell command line -+# Case 1: Really long argument (470 chars) -+input=""; for i in {1..470}; do input="${input}A"; done -+echo $input | $xmlcatalog --shell test/catalogs/dockbook.xml || exit 1 -+# Case 2: public + long argument -+input="public "; for i in {1..470}; do input="${input}A"; done -+echo $input | $xmlcatalog --shell test/catalogs/dockbook.xml || exit 1 -+# Case 3: public + lots of args -+input="public "; for i in {1..80}; do input="${input} x"; done -+echo $input | $xmlcatalog --shell test/catalogs/dockbook.xml || exit 1 -+ - for i in test/catalogs/*.script ; do - name=$(basename $i .script) - xml="./test/catalogs/$name.xml" -diff --git a/xmlcatalog.c b/xmlcatalog.c -index b400c7cb..5113e930 100644 ---- a/xmlcatalog.c -+++ b/xmlcatalog.c -@@ -135,6 +135,12 @@ static void usershell(void) { - (*cur != '\n') && (*cur != '\r')) { - if (*cur == 0) - break; -+ /* Do not read beyond the command array capacity */ -+ if (i >= (int)sizeof(command) - 2) { -+ printf("Invalid command %s\n", cur); -+ i = 0; -+ break; -+ } - command[i++] = *cur++; - } - command[i] = 0; -@@ -152,6 +158,11 @@ static void usershell(void) { - while ((*cur != '\n') && (*cur != '\r') && (*cur != 0)) { - if (*cur == 0) - break; -+ if (i >= (int)sizeof(arg) - 2) { -+ printf("Invalid arg %s\n", arg); -+ i = 0; -+ break; -+ } - arg[i++] = *cur++; - } - arg[i] = 0; -@@ -164,6 +175,11 @@ static void usershell(void) { - cur = arg; - memset(argv, 0, sizeof(argv)); - while (*cur != 0) { -+ if (i >= (int)sizeof(argv) / (int)sizeof(char*)) { -+ printf("Too much arguments\n"); -+ break; -+ } -+ - while ((*cur == ' ') || (*cur == '\t')) cur++; - if (*cur == '\'') { - cur++; --- -2.43.0 - diff --git a/meta/recipes-core/libxml/libxml2_2.15.3.bb b/meta/recipes-core/libxml/libxml2_2.15.4.bb similarity index 96% rename from meta/recipes-core/libxml/libxml2_2.15.3.bb rename to meta/recipes-core/libxml/libxml2_2.15.4.bb index abf9889b3f3..fc367892bfe 100644 --- a/meta/recipes-core/libxml/libxml2_2.15.3.bb +++ b/meta/recipes-core/libxml/libxml2_2.15.4.bb @@ -18,11 +18,10 @@ SRC_URI += "http://www.w3.org/XML/Test/xmlts20130923.tar;subdir=${BP};name=testt file://run-ptest \ file://install-tests.patch \ file://0001-Revert-cmake-Fix-installation-directories-in-libxml2.patch \ - file://CVE-2026-11979.patch \ " -SRC_URI[archive.sha256sum] = "78262a6e7ac170d6528ebfe2efccdf220191a5af6a6cd61ea4a9a9a5042c7a07" SRC_URI[testtar.sha256sum] = "c6b2d42ee50b8b236e711a97d68e6c4b5c8d83e69a2be4722379f08702ea7273" +SRC_URI[archive.sha256sum] = "98087fd181d9070724f3fbc65c7377db03038eb92bd882374daff44940138821" CVE_STATUS[CVE-2025-6170] = "fixed-version: fixed in version 2.14.5" CVE_STATUS[CVE-2026-6732] = "fixed-version: fixed in version 2.15.3" From patchwork Thu Sep 17 22:05:55 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 98577 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 60D44C982D9 for ; Thu, 17 Sep 2026 22:08:04 +0000 (UTC) Received: from mail-wm2-f13.google.com (mail-wm2-f13.google.com [74.125.225.141]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.1563.1789682876719439887 for ; Thu, 17 Sep 2026 15:07:57 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=Uz5d967Z; spf=pass (domain: smile.fr, ip: 74.125.225.141, mailfrom: yoann.congal@smile.fr) Received: by mail-wm2-f13.google.com with SMTP id 5b1f17b1804b1-49ccf3ca626so602475e9.0 for ; Thu, 17 Sep 2026 15:07:56 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1789682875; x=1790287675; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=cDylMoEclDi8x5kxfF+n8L7uo5yiDeLtBinoj2RO3HQ=; b=Uz5d967Zrv4HPyDPoFp7LEnwobGgbskHGRaH1L0otinKhweurCLnRUlRlHazm8HnxE IFk6dVmVpIPuC1hZoM8h8WWtKuXkrFMxYUH7OaoJyb9EmQntLwRZtuBxC9u1KEYrP4PP I6H0GWvpflimb7oY9atmPUyWLYOXbmx21qPJU= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1789682875; x=1790287675; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=cDylMoEclDi8x5kxfF+n8L7uo5yiDeLtBinoj2RO3HQ=; b=m29scAEijCd36OuYfcflQ52S6mabZ76nrvh11V/8G/3Lha9K2AKAV4kX14Xs+dm4In NijWFusBjimqq504XjFm2b+wtf9vicLJjC6rUr6dqUZPDyX/o0TYqvwMOQLrZ2XFNlyZ S9kXy4JYuFfRHxeygMRhu7n2yq0/m/BRpp2txI6eS7QK7U3QVX4oLxr2LT//ca6qmYoH FOAwvN9QnvGxo9E1DbAZ61Ae8wrVpgzF122+fDohEzhOTLqCNoJQ4ZXQvgdDHSHwSfXm vPLXVAv9KD8Q3ThabW19la0J9rq5e6gtuW2ItfoFdeH/iI8sEUADunkzjo2I+51BTLt1 P0aA== X-Gm-Message-State: AFuF++k2pTBCUvmYOf9b/HrlBUjb2FgKegKESzoynDLL/l8OzRoMkImh 64azrDW7UWoxuPdxPa3mGgJAnZfUIk00UoTPXxlXsqzv1CLCcq0t9VSR8EzXkiZt8+azrCNtkRA fykWDUps= X-Gm-Gg: AYBFou3YAL3nm8RxZxzTuOUPo0q0AHprlu5rzthiZ7acvoWHHejMpiLTeGSzDD/8GYJ rNQBQMmb1/nVNKQZZ8UQ9x+rKeMZsOzHjOx7SNaT4JhNmxK4K4pUXNxRpW2e/hIn1u6HLad1YXD YLYkTrCQvg9JNgCk3RntQuMk/54GiIOjg+yC4V1LRlko9EQlQJ/VfOqsTIe8aSFbq7nKMk4ZHhl T+v+E17iibwV4b7P0jR+vhrOhYOFWkVcjMowiNepqzTHMN3TDa++Ym/YQ8fWSNsly0D9P3RbTMT e6DjPCHuGgNWoKf3XLxqs9ajfkQs+UfaNCp0oDrdCK84iNxXy0PCtNS2nt9RsHYeouu4yofnS0c 4dbNt9fhT8bV8qX3tHBNDjMyB/OGhmwStvJeADLC1KfAnJQ8Kc31OEBv+li5Pc3gqEtEqP/9PBc 3ZqRTyu4qPLVi6pC6z6m3VYuCt0QzxzzVuPlwMiIyuDOUapRZRr87AVgARFMkiIBxIU7EnhvoXq hh+zyEN+pB3lECud1kKFyJw4R9JDPHqRdSnzhiir8rbiWnozkub/AzWG9K8/d+AerSaEBmqihgf EUhKbO5SVA== X-Received: by 2002:a05:600c:4ed4:b0:49c:cee2:a508 with SMTP id 5b1f17b1804b1-49fc5728f9amr2850985e9.16.1789682874887; Thu, 17 Sep 2026 15:07:54 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-49fc471b9a2sm8984075e9.0.2026.09.17.15.07.54 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Thu, 17 Sep 2026 15:07:54 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][wrynose 10/79] kbd: Fix CVE-2026-72693 Date: Fri, 18 Sep 2026 00:05:55 +0200 Message-ID: <51db5b506929def353ffcf851a9c9d315d7ebf92.1789681419.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Thu, 17 Sep 2026 22:08:04 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/246105 From: Vijay Anusuri Pick patch according to [1] [1] https://security-tracker.debian.org/tracker/CVE-2026-72693 [2] https://nvd.nist.gov/vuln/detail/CVE-2026-72693 [3] https://access.redhat.com/security/cve/cve-2026-72693 Signed-off-by: Vijay Anusuri Signed-off-by: Yoann Congal --- .../recipes-core/kbd/kbd/CVE-2026-72693.patch | 155 ++++++++++++++++++ meta/recipes-core/kbd/kbd_2.9.0.bb | 1 + 2 files changed, 156 insertions(+) create mode 100644 meta/recipes-core/kbd/kbd/CVE-2026-72693.patch diff --git a/meta/recipes-core/kbd/kbd/CVE-2026-72693.patch b/meta/recipes-core/kbd/kbd/CVE-2026-72693.patch new file mode 100644 index 00000000000..06b8c195a5a --- /dev/null +++ b/meta/recipes-core/kbd/kbd/CVE-2026-72693.patch @@ -0,0 +1,155 @@ +From 78d5ae119742e87baa7dbe0f5c4107e7533fd698 Mon Sep 17 00:00:00 2001 +From: Alexey Gladkov +Date: Tue, 12 May 2026 10:20:50 +0200 +Subject: [PATCH] openvt: make -u process matching more conservative + +The -u mode relies on the current VT owner to decide which user should +be used for the new login session. Make that check stricter by requiring +a matching process owner and controlling terminal instead of relying on +the ownership of an inherited file descriptor. + +Also reject root as a pre-authenticated target and document the tighter +behavior in the man page. + +Signed-off-by: Alexey Gladkov + +Upstream-Status: Backport [https://github.com/legionus/kbd/commit/78d5ae119742e87baa7dbe0f5c4107e7533fd698] +CVE: CVE-2026-72693 +Signed-off-by: Vijay Anusuri +--- + docs/man/man1/openvt.1 | 10 +++++++ + src/openvt.c | 64 +++++++++++++++++++++++++++++++++++++----- + 2 files changed, 67 insertions(+), 7 deletions(-) + +diff --git a/docs/man/man1/openvt.1 b/docs/man/man1/openvt.1 +index 8f1244f..404e4a0 100644 +--- a/docs/man/man1/openvt.1 ++++ b/docs/man/man1/openvt.1 +@@ -36,6 +36,8 @@ will be made the new current VT. + \fB\-u\fR, \fB\-\-user\fR + Figure out the owner of the current VT, and run login as that user. + Suitable to be called by init. Shouldn't be used with \fI\-c\fR or \fI\-l\fR. ++This option refuses to pre-authenticate root and requires a process owned by ++the VT owner whose controlling terminal is the current VT. + .TP + \fB\-l\fR, \fB\-\-login\fR + Make the command a login shell. A \- is prepended to the name of the command +@@ -64,6 +66,14 @@ If + is compiled with a getopt_long() and you wish to set + options to the command to be run, then you must supply + the end of options \-\- flag before the command. ++.PP ++The ++.B \-u ++option uses ++.BR "login -f" ++and therefore bypasses normal password authentication for the detected user. ++It is intended only for controlled init or keyboard-request configurations. ++Use a normal authenticated login command when authentication is required. + .SH EXAMPLES + .B openvt + can be used to start a shell on the next free VT, by using the command: +diff --git a/src/openvt.c b/src/openvt.c +index a94392b..ddd9239 100644 +--- a/src/openvt.c ++++ b/src/openvt.c +@@ -57,6 +57,51 @@ usage(int rc, const struct kbd_help *options) + exit(rc); + } + ++static int ++proc_pid_stat(const char *pid, uid_t *uid, dev_t *tty) ++{ ++ char filename[NAME_MAX + 12]; ++ char line[BUFSIZ]; ++ char *lp, *rp; ++ FILE *fp; ++ struct stat st; ++ long tty_nr; ++ ++ snprintf(filename, sizeof(filename), "/proc/%s/stat", pid); ++ fp = fopen(filename, "r"); ++ if (!fp) ++ return -1; ++ ++ if (fstat(fileno(fp), &st)) { ++ fclose(fp); ++ return -1; ++ } ++ ++ if (!fgets(line, sizeof(line), fp)) { ++ fclose(fp); ++ return -1; ++ } ++ fclose(fp); ++ ++ rp = strrchr(line, ')'); ++ if (!rp) ++ return -1; ++ ++ /* ++ * /proc//stat fields after comm are: ++ * state ppid pgrp session tty_nr ... ++ */ ++ if (!rp || sscanf(rp + 1, " %*c %*d %*d %*d %ld", &tty_nr) != 1) ++ return -1; ++ ++ if (tty_nr <= 0) ++ return -1; ++ ++ *uid = st.st_uid; ++ *tty = (dev_t) tty_nr; ++ return 0; ++} ++ + /* + * Support for Spawn_Console: openvt running from init + * added by Joshua Spoerri, Thu Jul 18 21:13:16 EDT 1996 +@@ -88,8 +133,7 @@ authenticate_user(int curvt) + DIR *dp; + struct dirent *dentp; + struct stat buf; +- dev_t console_dev; +- ino_t console_ino; ++ dev_t console_rdev; + uid_t console_uid; + char filename[NAME_MAX + 12]; + struct passwd *pwnam; +@@ -109,10 +153,12 @@ authenticate_user(int curvt) + kbd_error(EXIT_FAILURE, errsv, "%s", filename); + } + } +- console_dev = buf.st_dev; +- console_ino = buf.st_ino; ++ console_rdev = buf.st_rdev; + console_uid = buf.st_uid; + ++ if (console_uid == 0) ++ kbd_error(EXIT_FAILURE, 0, _("Refusing to pre-authenticate root on current tty.")); ++ + /* get the owner of current tty */ + if (!(pwnam = getpwuid(console_uid))) + kbd_error(EXIT_FAILURE, errno, "getpwuid"); +@@ -120,12 +166,16 @@ authenticate_user(int curvt) + /* check to make sure that user has a process on that tty */ + /* this will fail for example when X is running on the tty */ + while ((dentp = readdir(dp))) { +- sprintf(filename, "/proc/%s/fd/0", dentp->d_name); ++ uid_t proc_uid; ++ dev_t proc_tty; ++ ++ if (dentp->d_name[0] < '0' || dentp->d_name[0] > '9') ++ continue; + +- if (stat(filename, &buf)) ++ if (proc_pid_stat(dentp->d_name, &proc_uid, &proc_tty) < 0) + continue; + +- if (buf.st_dev == console_dev && buf.st_ino == console_ino && buf.st_uid == console_uid) ++ if (proc_uid == console_uid && proc_tty == console_rdev) + goto got_a_process; + } + +-- +2.43.0 + diff --git a/meta/recipes-core/kbd/kbd_2.9.0.bb b/meta/recipes-core/kbd/kbd_2.9.0.bb index 79b011e529d..06341ba8c04 100644 --- a/meta/recipes-core/kbd/kbd_2.9.0.bb +++ b/meta/recipes-core/kbd/kbd_2.9.0.bb @@ -26,6 +26,7 @@ RCONFLICTS:${PN} = "console-tools" SRC_URI = "${KERNELORG_MIRROR}/linux/utils/${BPN}/${BP}.tar.xz \ file://0001-Preserve-only-necessary-metadata-during-install.patch \ file://0001-libkbdfile-Fix-problem-with-undeclared-sym_gzopen.patch \ + file://CVE-2026-72693.patch \ " SRC_URI[sha256sum] = "fb3197f17a99eb44d22a3a1a71f755f9622dd963e66acfdea1a45120951b02ed" From patchwork Thu Sep 17 22:05:56 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 98581 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id CB2B0C982DD for ; Thu, 17 Sep 2026 22:08:04 +0000 (UTC) Received: from mail-wm2-f12.google.com (mail-wm2-f12.google.com [74.125.225.140]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.1564.1789682877024684893 for ; Thu, 17 Sep 2026 15:07:57 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=NCetk4aH; spf=pass (domain: smile.fr, ip: 74.125.225.140, mailfrom: yoann.congal@smile.fr) Received: by mail-wm2-f12.google.com with SMTP id 5b1f17b1804b1-49ccead2aecso577575e9.0 for ; Thu, 17 Sep 2026 15:07:56 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1789682875; x=1790287675; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=4yDq2yG86NEYD1rLTU8XWE8gZLbm7TeN8CXaOjdMOa0=; b=NCetk4aH7feMB8gmQ+JTgCFD3Co99D0qLWr5fMZkLur7zN501N/HXVD012+eXjLsS/ 3/9N0NOEWAq7S6ipFdBb+6nxX+LJyOjh829FAJMIY11zXENNhjdBrCxUXwxQ1GPr5cdl oUOCV+3dOqg3sP6eSRvYocu0nlNoHAqkh1Yvo= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1789682875; x=1790287675; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=4yDq2yG86NEYD1rLTU8XWE8gZLbm7TeN8CXaOjdMOa0=; b=BybMkSkHRx/dyLIREOzVQlO01n2MMbN8m3kn1w8t9bkl4532L2yjigMUpKoMVSYZGI qPLs3s32jXmcYLohE8CczzTY5nehzbQ6527gr5WKvmuzLCPDB91lCrH1GVeP0c9EDvfx RL8vkbuHxyfgZckxTbldWh1WcGg42oD8QYbpm0X3IBZ83vIrfSdIwdz3yEDqs1PzKPB8 fDS1ns5+KQS6J6LHMTfZFMSghPNoN9blm/VaWHI7f+tV9nsyJrV5iKf1+G95gQpD9jQa prJ5hxd8ECrlHOR8t36De3dZwGAW951AvwDh2pnsYF2LvtoaCTmkW10bzdtjIPrm5i8U t2yA== X-Gm-Message-State: AFuF++nldTsu7LNZBpkeEqZB6Pl1ilbn5ybckyEBUTYxQh2mVWWQGDxn OJ69ZmBRihVG+gfHBagWWpHVpN5k0kbvslJVsiKdAZd7PsOiolHnD9UjjBP0tYrruG92xudZ5Ca pb9peZ8w= X-Gm-Gg: AYBFou0qYASPt5OErw+ZaJ2cpUeG+pPlklhOTiPwqxc9W8RlIttZdoFdmOch6uRRuw3 AArM22TNMKQdYtb/ujUFEIA7oCYlP4BCimbWOKgiQtCAVVavakshLschQUc+dvHCDodXxHThRDS xAkqvtoz7dFJz10HcpNF0GePi4oP/hwMc4b6CGQySlo1C6nzSk7Q1rr8sY6hgjz8Hib4obaAdRp gYINzkFC4KIvr+PkYAiab1PyFuQdwSii8A7khKvWsz8Bx0P+bao8zpofTSUwwGMDFG845qaPjtC RL4dLOo0UqO3i8/8bR4/r+gOaZJkvKEV6d7NPFMlyF8hP+mx/VpR3wMtPVryxUA6jYFgXNSEMGo f8GYndUk/KLZkYWfEKhmaZTkYPsRIoY/YxsbqGDHy3Zs//ZGcJ+rB23DCDW8sKITqAxhS86VIlA JBG/RdAC5+tWIqZK9RVM50XefmLi2PXHjcjE9ED2JYYEh6/OG9ytv0IMm9DTifATsvXG/JDUfBG c+SMBLREhURoil0sOYCkUEiTp6N6XWnhGdW0jRiw2hYtpDLxSsm+OliltZ8ACV/lnA2x8dDJxtU iXFPmtbG8Q== X-Received: by 2002:a05:600c:3ba7:b0:49c:fc6c:be00 with SMTP id 5b1f17b1804b1-49fc57509f8mr3808235e9.23.1789682875362; Thu, 17 Sep 2026 15:07:55 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-49fc471b9a2sm8984075e9.0.2026.09.17.15.07.55 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Thu, 17 Sep 2026 15:07:55 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][wrynose 11/79] golang: fix homepage Date: Fri, 18 Sep 2026 00:05:56 +0200 Message-ID: <8ec3d1b577b22e04b42b40775c2e7efca0e11945.1789681419.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Thu, 17 Sep 2026 22:08:04 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/246106 From: Peter Marko Leading space leads to SPDX document validation errors in some tools. Example: SchemaError: \" http://golang.org/\" is not valid under any of the schemas listed in the 'anyOf' keyword (components -> ... -> externalReferences -> 0 -> url) Signed-off-by: Peter Marko Signed-off-by: Richard Purdie (From OE-Core rev: cbf36f436b477d81b58ff605846a2482308aefa4) Signed-off-by: Peter Marko Signed-off-by: Yoann Congal --- meta/recipes-devtools/go/go-binary-native_1.26.7.bb | 2 +- meta/recipes-devtools/go/go-common.inc | 2 +- 2 files changed, 2 insertions(+), 2 deletions(-) diff --git a/meta/recipes-devtools/go/go-binary-native_1.26.7.bb b/meta/recipes-devtools/go/go-binary-native_1.26.7.bb index 753f1b13bb5..034c051cee7 100644 --- a/meta/recipes-devtools/go/go-binary-native_1.26.7.bb +++ b/meta/recipes-devtools/go/go-binary-native_1.26.7.bb @@ -1,7 +1,7 @@ # This recipe is for bootstrapping our go-cross from a prebuilt binary of Go from golang.org. SUMMARY = "Go programming language compiler (upstream binary for bootstrap)" -HOMEPAGE = " http://golang.org/" +HOMEPAGE = "http://golang.org/" LICENSE = "BSD-3-Clause" LIC_FILES_CHKSUM = "file://LICENSE;md5=7998cb338f82d15c0eff93b7004d272a" diff --git a/meta/recipes-devtools/go/go-common.inc b/meta/recipes-devtools/go/go-common.inc index 5d0177bdb68..a96e67617b4 100644 --- a/meta/recipes-devtools/go/go-common.inc +++ b/meta/recipes-devtools/go/go-common.inc @@ -9,7 +9,7 @@ DESCRIPTION = " The Go programming language is an open source project to make \ fast, statically typed, compiled language that feels like a\ dynamically typed, interpreted language." -HOMEPAGE = " http://golang.org/" +HOMEPAGE = "http://golang.org/" LICENSE = "BSD-3-Clause" inherit goarch From patchwork Thu Sep 17 22:05:57 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 98585 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 0F364C982E2 for ; Thu, 17 Sep 2026 22:08:05 +0000 (UTC) Received: from mail-wm2-f12.google.com (mail-wm2-f12.google.com [74.125.225.140]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.1566.1789682877584025511 for ; Thu, 17 Sep 2026 15:07:57 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=Y2tlkAsV; spf=pass (domain: smile.fr, ip: 74.125.225.140, mailfrom: yoann.congal@smile.fr) Received: by mail-wm2-f12.google.com with SMTP id 5b1f17b1804b1-49e69b9e16aso1211625e9.1 for ; Thu, 17 Sep 2026 15:07:57 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1789682876; x=1790287676; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=bTO2/rq1NEhkpRBDYxxW1LxS2GV319zCXXzq65qQ5mM=; b=Y2tlkAsVwydDA8qcOACvR+iFyv+Y6jJn2/jG8UF7wCtwSa8+V5MDSqzsnGXICOj19r KD+qzbuqzxJb3Y6u1hckYc6efO3koskM9cqhEt652TND5Q7TYNhs95n4U3WBWffzuUFJ aQENlY1B3tGReL6zNBiW+nxrX0FkmWXPeSL3Y= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1789682876; x=1790287676; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=bTO2/rq1NEhkpRBDYxxW1LxS2GV319zCXXzq65qQ5mM=; b=HFoIE0j6RK0CEav8g/leiTTDb+ZFViTR4xm6IWq6hvN1Q5ivZiTRkT9LLfe/p/493f pIH2ZWqisTiOeA5VHvMM2u4MeAIfD8YZdRXmcwWJH8lhFKcn4gvihsky3Rg0jKZL4ypG VOHYkZzs/B3/2UKWgXbzs3Lq76OijGSYRyxmSbRDc1pOZUyrTMnKLMPH84vk1XyKrVxi k5M2wRryM5Lbxrl0vRdHVmgDyZH3hbZt453NUTRRIy3CBxy4GuvMAuUxuLdvHSfj97/7 gnSAI3kvIgC3lu9dKDD/ynUI5UB3vdvNGETQKCL8TyBFNGLnSBsVKUi2BhwPwzwozw0I NQag== X-Gm-Message-State: AFuF++mF04c0M8a95UIOExFMz5rleaI+sQsElGzsqqW9ArxZwOaUI5LA o/TV/fxOiOLdQcNW9OwFhkm+Z2k4bApxttb5tDer+VAIdepff27QfCMalYs2k01iypDm0ABvnUb e4ZWJmKQ= X-Gm-Gg: AYBFou0TjEgPE8G/pyhUQ186tAS/9XtUf4e41TSiDay5F0BuP4uJBJH533GH5/yi+h8 trBUKg0jZjzcyIbLrnFe8KfspjXWMh4NPNom/VO/NOY8d7D4dNw8asWUHBOTNhKcTxTrzOd+i+O 7/ozJTOfOA6jm28TsQxpUMu1ZH4FdYe7ecNyLWfQMDOlZ2ejb0VndgNaOC3Fhl2rN+FIDANYwck OrOgpTxbX9rwIAim7TpgWqYyPxGebFXZXYUaTHkU8rNd37kMr8eqwCBNpPQcO5NsxHfAfsoAgG7 Y29kB/n8mxw95yTQevy5bR4W4U8Yk0icAwFapws8RnVO7DCBZq3yklqk5T28u4FFKyqDNPxkN+4 WxAswM4A2W3Vrx5b3IzqWeXqLRyEH8sAhabGDLQrM9GI5geD1hqE8/MMvhXscbVmc9gX/KJjwQa Sw9zZD4fUlDcp+njaaVPK/REeGizaof4jpMeYiwlZrqtSprMeKHD0LYT8japnsFG9XCggYdB26S sVuEHc/ZRC16OWLqbVMPDen+RwzABhZ6AIuSCdn1nY6uALi+GCFnsDdIJgwdCeaXN7E0Cttx0A= X-Received: by 2002:a05:600c:3585:b0:49c:cee0:f383 with SMTP id 5b1f17b1804b1-49fc5734ef6mr4319615e9.16.1789682875807; Thu, 17 Sep 2026 15:07:55 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-49fc471b9a2sm8984075e9.0.2026.09.17.15.07.55 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Thu, 17 Sep 2026 15:07:55 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][wrynose 12/79] python3-certifi: fix homepage Date: Fri, 18 Sep 2026 00:05:57 +0200 Message-ID: X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Thu, 17 Sep 2026 22:08:05 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/246107 From: Peter Marko Leading space leads to SPDX document validation errors in some tools. Example: SchemaError: \" http://certifi.io/\" is not valid under any of the schemas listed in the 'anyOf' keyword (components -> ... -> externalReferences -> 0 -> url) Signed-off-by: Peter Marko Signed-off-by: Richard Purdie (From OE-Core rev: ee556d1e1cc16327e0a11207e90ac61d9f1577f3) Signed-off-by: Peter Marko Signed-off-by: Yoann Congal --- meta/recipes-devtools/python/python3-certifi_2026.2.25.bb | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/meta/recipes-devtools/python/python3-certifi_2026.2.25.bb b/meta/recipes-devtools/python/python3-certifi_2026.2.25.bb index 0425f3544fa..fb08bff815f 100644 --- a/meta/recipes-devtools/python/python3-certifi_2026.2.25.bb +++ b/meta/recipes-devtools/python/python3-certifi_2026.2.25.bb @@ -2,7 +2,7 @@ SUMMARY = "Python package for providing Mozilla's CA Bundle." DESCRIPTION = "This installable Python package contains a CA Bundle that you can reference in your \ Python code. This is useful for verifying HTTP requests, for example. This is the same CA Bundle \ which ships with the Requests codebase, and is derived from Mozilla Firefox's canonical set." -HOMEPAGE = " http://certifi.io/" +HOMEPAGE = "http://certifi.io/" LICENSE = "ISC" LIC_FILES_CHKSUM = "file://LICENSE;md5=11618cb6a975948679286b1211bd573c" From patchwork Thu Sep 17 22:05:58 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 98587 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 48908C982E4 for ; Thu, 17 Sep 2026 22:08:05 +0000 (UTC) Received: from mail-wm2-f13.google.com (mail-wm2-f13.google.com [74.125.225.141]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.1568.1789682878085068626 for ; Thu, 17 Sep 2026 15:07:58 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=ia8bL24z; spf=pass (domain: smile.fr, ip: 74.125.225.141, mailfrom: yoann.congal@smile.fr) Received: by mail-wm2-f13.google.com with SMTP id 5b1f17b1804b1-49e8185e037so650845e9.3 for ; Thu, 17 Sep 2026 15:07:57 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1789682876; x=1790287676; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=dpp3t7n7ijUwiNXRGahxvwJ9QCSQogxtbKES7nGqS+s=; b=ia8bL24zqM40/SwcthS3KnL/LtrMQljL1assqoR+/agFpDPGCWNoKdDaIWc1vTV3VO pp3Tlmaa/9tagbrDhdtJJ3pA3Tcfl+TZkfGbGk6iJQkZ/FjCxzRsY2ajeIh6IAWaicjf VyoYiAVdqWe0qCTfRhz8iF/hMvx/2ppIqRSBU= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1789682876; x=1790287676; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=dpp3t7n7ijUwiNXRGahxvwJ9QCSQogxtbKES7nGqS+s=; b=VmSPk+1WwZ63egCJ+5gSvOBReU/wmSz5Fl2Mx+EJOIK1zdD1hA2PCZzoSfxKO0Tzx7 AXzmkUXFkbvpxr5lGjtvlC3QTUKzkdHEhuT0V3I+GDF0y+KAlmcZXj6mi7J3GvXcZJSt B3qDezwmXNbTT7ittwwSeAJh6w3/K+ItB9B9cvj/9E/u/aghcwbNhatoesZ1Jn1B5xtt RLj9QO5WPxcF5jkQko/YlQylhOfno3tGlODW3av60Txu4WFfl7xL9WH5mV1AVQv5u/Pw L+ykZ3gNREZvQ8NYbFz6MrZjn6/E48PLxy97inMWE5FvcB5zZ/KlBb7DOBeso6YYuJiW e73Q== X-Gm-Message-State: AFuF++mRQ9zIcsjJMZ//Hn4U0dIBT6b6G7iLpdF6xQtXacvyQ0rNPXeL LaGC3mr+EoUbUqWQK4KiRC/5sBqJ5wF07k9e/VK9SZZuGppJztLHYZLT9m6ApafX3auyduJ74j5 zT2Xj7go= X-Gm-Gg: AYBFou2baBpbnIp8wh4M2z2+N4/lE7+1ec/Dx/PWTM7q+NUAQlT57rouK1XXEe/ASI3 yyRmseqbzBpy0WqaIbvIVcOcFCluXVgL+Xi9QNCUSHu9oNTd+D1vvk5BOEnirYv9mOQR1kSlGgS Mu64ET2rJU1pscFgTiyd38XK0pD0Vlw8MBsyNdiHPlYdupUdpt+orR+CekX6NJOCNnjfJxiFsAA CXP+TZzox6id//Hx+9Kkh2FitUjYgFKlNLvArRT2MLouZLFYuw6B/nqTNTUkgqm8+XdpyHNAQ7I 7ExSCQdvhWO4miRgs5K8ng4pUh9UqDQ/Wle1JhbTMI4LOEzKp7BHHVHLcbQ/nbTCSYsno7WCokH tP/xTIYM9/evdKEOw70tQgZWeEuYJ+xTgbS1UqYwz0Sp+4tJDCsn7Cz35QcOtuistotk8jSHcw4 S8OPK6XBu/btVDU0ci+RXlfybbRi8AvNwOnJoUgEFF8AvD6ssVkVMdt3fsk8mxpibUtlWrH7j9X k5wS+tK70WluBaHqrHGjhpxnpUm7jyOqFgWPybGm8mOrRRany5L/PJEkYlR78BsXez0fJDBrZ0= X-Received: by 2002:a05:600c:81c8:b0:49c:fc6c:be08 with SMTP id 5b1f17b1804b1-49fc58581bfmr2403965e9.31.1789682876344; Thu, 17 Sep 2026 15:07:56 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-49fc471b9a2sm8984075e9.0.2026.09.17.15.07.55 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Thu, 17 Sep 2026 15:07:56 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][wrynose 13/79] gnutls: fix CVE-2026-5419 Date: Fri, 18 Sep 2026 00:05:58 +0200 Message-ID: <3fd9a75370faf690d9936e13cb541be2b78a4d0b.1789681419.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Thu, 17 Sep 2026 22:08:05 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/246108 From: Jakub Szczudlo (Nokia) Backport patch to fix CVE-2026-5419. References: https://nvd.nist.gov/vuln/detail/CVE-2026-5419 Upstream fix: https://gitlab.com/gnutls/gnutls/-/commit/1e627aa5ad95c6dc0518d94e9a009997b081a1ab Tested with ptes Signed-off-by: Jakub Szczudlo Signed-off-by: Yoann Congal [YC: fixed patch unneeded changes] --- .../gnutls/gnutls/CVE-2026-5419.patch | 248 ++++++++++++++++++ meta/recipes-support/gnutls/gnutls_3.8.12.bb | 1 + 2 files changed, 249 insertions(+) create mode 100644 meta/recipes-support/gnutls/gnutls/CVE-2026-5419.patch diff --git a/meta/recipes-support/gnutls/gnutls/CVE-2026-5419.patch b/meta/recipes-support/gnutls/gnutls/CVE-2026-5419.patch new file mode 100644 index 00000000000..714814eee2c --- /dev/null +++ b/meta/recipes-support/gnutls/gnutls/CVE-2026-5419.patch @@ -0,0 +1,248 @@ +From 2f3732538d7d8e1ae255ca68c20efc61a1d5b3e2 Mon Sep 17 00:00:00 2001 +From: Daiki Ueno +Date: Fri, 4 Sep 2026 09:17:32 +0000 +Subject: [PATCH] gnutls_cipher_decrypt3: make PKCS#7 unpadding branch free + +This tries to make the logic of PKCS#7 padding removal constant-time, +by removing potential branching operations. + +CVE: CVE-2026-5419 +Upstream-Status: Backport [https://gitlab.com/gnutls/gnutls/-/commit/1e627aa5ad95c6dc0518d94e9a009997b081a1ab] + +Backport Changes: +- Adjusted the upstream hunk to match the GnuTLS 3.8.12 code layout. +- Drop .gitignore from the backport. + +Reported-by: Doria Tang of Stony Brook University +Fixes: #1815 +Fixes: CVE-2026-5419 +Fixes: GNUTLS-SA-2026-04-29-13 +CVSS: 3.7 Low CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N +Signed-off-by: Daiki Ueno +Signed-off-by: Jakub Szczudlo + +--- + lib/crypto-api.c | 54 +++++++++++++++++------ + lib/libgnutls.map | 2 + + tests/Makefile.am | 2 +- + tests/pkcs7-pad.c | 109 ++++++++++++++++++++++++++++++++++++++++++++++ + 4 files changed, 153 insertions(+), 14 deletions(-) + create mode 100644 tests/pkcs7-pad.c + +diff --git a/lib/crypto-api.c b/lib/crypto-api.c +index 01539d5b52..32143e9de0 100644 +--- a/lib/crypto-api.c ++++ b/lib/crypto-api.c +@@ -498,6 +498,39 @@ error: + return ret; + } + ++/* If succeeds, returns the number of padding bytes to be removed; ++ * zero otherwise. ++ */ ++unsigned int _gnutls_pkcs7_unpad(const uint8_t *block, unsigned int block_size) ++{ ++ uint8_t padding = block[block_size - 1]; ++ volatile unsigned int mask = ~0; ++ volatile unsigned int count = 0; ++ ++ /* Count consecutive PADDING bytes from the end, in a ++ * constant-time manner. ++ */ ++ for (size_t i = block_size; i > 0; i--) { ++ volatile unsigned int mask2; ++ ++ mask2 = -(unsigned int)(block[i - 1] == padding); ++ mask2 &= -(unsigned int)(count < padding); ++ ++ /* MASK is initially ~0 and will be flipped to 0 upon first ++ * non-padding bytes. ++ */ ++ mask &= mask2; ++ count += 1 & mask; ++ } ++ ++ /* PADDING == 0 is effectively excluded here, given COUNT ++ * will never be 0. ++ */ ++ mask = -(unsigned int)(count <= block_size); ++ mask &= -(unsigned int)(count == padding); ++ return count & mask; ++} ++ + /** + * gnutls_cipher_decrypt3: + * @handle: is a #gnutls_cipher_hd_t type +@@ -532,22 +565,17 @@ int gnutls_cipher_decrypt3(gnutls_cipher_hd_t handle, const void *ctext, + if (_gnutls_cipher_type(h->ctx_enc.e) == CIPHER_BLOCK && + (flags & GNUTLS_CIPHER_PADDING_PKCS7)) { + uint8_t *p = ptext; +- uint8_t padding = p[*ptext_len - 1]; +- if (!padding || +- padding > _gnutls_cipher_get_block_size(h->ctx_enc.e)) { +- return gnutls_assert_val(GNUTLS_E_DECRYPTION_FAILED); +- } +- /* Check that the prior bytes are all PADDING */ +- for (size_t i = *ptext_len - padding; i < *ptext_len; i++) { +- if (padding != p[*ptext_len - 1]) { +- return gnutls_assert_val( +- GNUTLS_E_DECRYPTION_FAILED); +- } +- } ++ size_t block_size = _gnutls_cipher_get_block_size(h->ctx_enc.e); ++ uint8_t *block = &p[*ptext_len - block_size]; ++ unsigned int padding = _gnutls_pkcs7_unpad(block, block_size); ++ volatile unsigned int mask; ++ ++ mask = -(unsigned int)(padding == 0); ++ ret = GNUTLS_E_DECRYPTION_FAILED & mask; + *ptext_len -= padding; + } + +- return 0; ++ return ret; + } + + /** +diff --git a/lib/libgnutls.map b/lib/libgnutls.map +index 955704e..5cc12c8 100644 +--- a/lib/libgnutls.map ++++ b/lib/libgnutls.map +@@ -1574,4 +1574,6 @@ GNUTLS_PRIVATE_3_4 { + _gnutls_pathbuf_append; + _gnutls_pathbuf_truncate; + _gnutls_pathbuf_deinit; ++ # needed by tests/pkcs7-pad ++ _gnutls_pkcs7_unpad; + } GNUTLS_3_4; +diff --git a/tests/Makefile.am b/tests/Makefile.am +index ab2685c..1304d2f 100644 +--- a/tests/Makefile.am ++++ b/tests/Makefile.am +@@ -241,7 +241,7 @@ ctests += mini-record-2 simple gnutls_hmac_fast set_pkcs12_cred cert certuniquei + x509cert-dntypes id-on-xmppAddr tls13-compat-mode ciphersuite-name \ + x509-upnconstraint xts-key-check cipher-padding pkcs7-verify-double-free \ + fips-rsa-sizes tls12-rehandshake-ticket pathbuf tls-force-ems \ +- psk-importer privkey-derive dh-compute2 ecdh-compute2 \ ++ psk-importer privkey-derive dh-compute2 ecdh-compute2 pkcs7-pad \ + mini-dtls-fragments + + ctests += tls-channel-binding +diff --git a/tests/pkcs7-pad.c b/tests/pkcs7-pad.c +new file mode 100644 +index 0000000..d4c3798 +--- /dev/null ++++ b/tests/pkcs7-pad.c +@@ -0,0 +1,109 @@ ++/* ++ * Copyright (C) 2026 Red Hat, Inc. ++ * ++ * This file is part of GnuTLS. ++ * ++ * GnuTLS is free software; you can redistribute it and/or modify it ++ * under the terms of the GNU General Public License as published by ++ * the Free Software Foundation; either version 3 of the License, or ++ * (at your option) any later version. ++ * ++ * GnuTLS is distributed in the hope that it will be useful, but ++ * WITHOUT ANY WARRANTY; without even the implied warranty of ++ * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU ++ * General Public License for more details. ++ * ++ * You should have received a copy of the GNU General Public License ++ * along with GnuTLS. If not, see . ++ */ ++ ++/* Test that _gnutls_pkcs7_unpad is branch-free, using valgrind */ ++ ++#ifdef HAVE_CONFIG_H ++#include "config.h" ++#endif ++ ++#include ++#include ++ ++#ifdef HAVE_VALGRIND_MEMCHECK_H ++#include ++#endif ++ ++#include "utils.h" ++ ++static inline void _gnutls_memory_mark_undefined(void *addr, size_t size) ++{ ++#ifdef HAVE_VALGRIND_MEMCHECK_H ++ if (RUNNING_ON_VALGRIND) ++ VALGRIND_MAKE_MEM_UNDEFINED(addr, size); ++#endif ++} ++ ++static inline void _gnutls_memory_mark_defined(void *addr, size_t size) ++{ ++#ifdef HAVE_VALGRIND_MEMCHECK_H ++ if (RUNNING_ON_VALGRIND) ++ VALGRIND_MAKE_MEM_DEFINED(addr, size); ++#endif ++} ++ ++extern unsigned int _gnutls_pkcs7_unpad(const uint8_t *block, ++ unsigned int block_size); ++ ++static unsigned int wrap_pkcs7_unpad(uint8_t *block, unsigned int block_size) ++{ ++ unsigned int padding; ++ ++ _gnutls_memory_mark_undefined(block, block_size); ++ ++ padding = _gnutls_pkcs7_unpad(block, block_size); ++ ++ _gnutls_memory_mark_defined(block, block_size); ++ _gnutls_memory_mark_defined(&padding, sizeof(padding)); ++ ++ return padding; ++} ++ ++#define PAD 5 ++ ++void doit(void) ++{ ++ uint8_t block[16]; ++ unsigned int padding; ++ ++ memset(block, 0xFF, sizeof(block)); ++ memset(&block[sizeof(block) - PAD], PAD, PAD); ++ ++ padding = wrap_pkcs7_unpad(block, sizeof(block)); ++ if (padding != PAD) ++ fail("padding should be %d\n", PAD); ++ ++ /* The last padding byte exceeds the block size */ ++ block[sizeof(block) - 1] = sizeof(block) + 1; ++ padding = wrap_pkcs7_unpad(block, sizeof(block)); ++ if (padding != 0) ++ fail("padding should be 0\n"); ++ block[sizeof(block) - 1] = PAD; ++ ++ /* The last padding byte is zero */ ++ block[sizeof(block) - 1] = 0; ++ padding = wrap_pkcs7_unpad(block, sizeof(block)); ++ if (padding != 0) ++ fail("padding should be 0\n"); ++ block[sizeof(block) - 1] = PAD; ++ ++ /* The first padding byte is invalid */ ++ block[sizeof(block) - PAD] = PAD + 1; ++ padding = wrap_pkcs7_unpad(block, sizeof(block)); ++ if (padding != 0) ++ fail("padding should be 0\n"); ++ block[sizeof(block) - PAD] = PAD; ++ ++ /* The byte before the first padding equals to PAD */ ++ block[sizeof(block) - PAD - 1] = PAD; ++ padding = wrap_pkcs7_unpad(block, sizeof(block)); ++ if (padding != PAD) ++ fail("padding should be %d\n", PAD); ++ block[sizeof(block) - PAD - 1] = 0xFF; ++} +-- +2.43.0 + diff --git a/meta/recipes-support/gnutls/gnutls_3.8.12.bb b/meta/recipes-support/gnutls/gnutls_3.8.12.bb index d513752072c..538fd9c9e0d 100644 --- a/meta/recipes-support/gnutls/gnutls_3.8.12.bb +++ b/meta/recipes-support/gnutls/gnutls_3.8.12.bb @@ -41,6 +41,7 @@ SRC_URI = "https://www.gnupg.org/ftp/gcrypt/gnutls/v${SHRT_VER}/gnutls-${PV}.tar file://CVE-2026-42011_p2.patch \ file://CVE-2026-42010.patch \ file://CVE-2026-33845.patch \ + file://CVE-2026-5419.patch \ " SRC_URI[sha256sum] = "a7b341421bfd459acf7a374ca4af3b9e06608dcd7bd792b2bf470bea012b8e51" From patchwork Thu Sep 17 22:05:59 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 98586 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 58411C982E5 for ; Thu, 17 Sep 2026 22:08:05 +0000 (UTC) Received: from mail-wm2-f12.google.com (mail-wm2-f12.google.com [74.125.225.140]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.1670.1789682878525537903 for ; Thu, 17 Sep 2026 15:07:58 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=zjQs7+pt; spf=pass (domain: smile.fr, ip: 74.125.225.140, mailfrom: yoann.congal@smile.fr) Received: by mail-wm2-f12.google.com with SMTP id 5b1f17b1804b1-49e66390995so564305e9.2 for ; Thu, 17 Sep 2026 15:07:58 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1789682877; x=1790287677; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=UTV7Xk50d7T34ketiW0egi0tizvCaz9I5qWsL1ZJSu8=; b=zjQs7+pt6VgoOZsFBi0PFAC75otTCzAwSB3eh2YAFUgYUNAIV3z/GjWoDYSt8+Gxdm xk6MA1gmRdYsQAG7gNBzGBnny79slWAZx+whyefKSy6BwvknDczPSLgrm19Aa1kK33tC eKR5ueiP0gPwKNqFqaokwtNwr9MliqfYThUOQ= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1789682877; x=1790287677; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=UTV7Xk50d7T34ketiW0egi0tizvCaz9I5qWsL1ZJSu8=; b=jwn2g0vNJBAEymYm5PSjEPvkO9gjY3WKAhQ5g+gbFKxLBYQDW6Qozi7uA4I46Lf2R2 sRWJOiwQzkfJqng3dhvkmKYlgvgUOToWPC/dS9VK+7SH68FgIQQn20xeRf+EOhQo08Fy nfpNu7v0nYkpr4Ap4Hgs2H2/ypDaXir27L7yq6A37SHdENNYCFrClW8ooxwOQn77iVTK EAXOc23CZXp4zH6ELX3VqFiVQkUhOdrEg1Vxs/tSDyBKXERoSyszvCs5JZhxzg5t4U9C ErOGw51Vxpdf1djZiNdK8TWd+mPsRDEcGw5LO3EulIUodpzvYcOhVkmzZGBp36e85ahs A6Pg== X-Gm-Message-State: AFuF++m516DJo5M2FoQpLWnc2tmqT1g3Pu/xbX0gmMYbLubsm68FmFOY wgxVoJNYOg4uOdBNENpK0nvrOzqnfhvh1TrFZFo0UuK9g0Yd7RUDDuOHLft2UVp4G5uO4TFgSbF scqGfqac= X-Gm-Gg: AYBFou0E6m7Pner4yrQiv/Eo0b5t8bggBMrUDSpgVwLufa731GMxP0kcADixHQfw9FV //Ow6yWW9zrc1x6hQkGjPDqNSjA7G5+82dMcrkuCIAvamlYsC4SeqlARjzaj7vwP0/WyMlF6UmH oqMdbWxdPI1vr0kXyO6Dfl28o4xkvETRT9X5I4cewV8xpmOO9NqSeu3X/Fnlgvaq9kqfqbWgFGB zX83ALTICHoq4zNiUIhsnN9vn9Va24gR51W8D7SYeaA7igwBYi8Hqep3yAcsFqeutjhGwm2Mnko OzD6WWYE0taald6LVoFxcX3dENDfPQ5GTqzjiuQCGhgeJWje4SHA/ZRWDllkY2hxLOLgyN9ezu6 kN/C0/4hCGBbWVKjV3uiJ4WlUi2bXxhB+XsZ8SZcORAUZq7k6iSUgFEZPF35t/hvhJaVTtECf4q eNRYjaGBS2hf89eqyZc9Czj3BE/9C19HiFqqomMH+QTCdF9Kpnw0ljBrGShn+Ndkp3zardIqgxR dEZp/jFHcxhEa/6adHqBYbvOeRszuhq9lbYr34KQUQkBtAZci0RJnPCbGV7CpJ+R7injsefxVY= X-Received: by 2002:a05:600c:3550:b0:49e:7d74:7b7a with SMTP id 5b1f17b1804b1-49fc56db8f3mr3330225e9.6.1789682876752; Thu, 17 Sep 2026 15:07:56 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-49fc471b9a2sm8984075e9.0.2026.09.17.15.07.56 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Thu, 17 Sep 2026 15:07:56 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][wrynose 14/79] sbom-cve-check-update-nvd-native: upgrade 2026.05.07-000006 -> 2026.06.09-000006 Date: Fri, 18 Sep 2026 00:05:59 +0200 Message-ID: <1a593c7063ed86519d5b8a3a0bbcde98834569cd.1789681419.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Thu, 17 Sep 2026 22:08:05 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/246109 From: Wang Mingyu Signed-off-by: Wang Mingyu Signed-off-by: Mathieu Dubois-Briand Signed-off-by: Richard Purdie (From OE-Core rev: d33c73535229b5066901faedaaaca0aa6bbd99bf) Signed-off-by: Peter Marko Signed-off-by: Yoann Congal --- ...bb => sbom-cve-check-update-nvd-native_2026.06.09-000006.bb} | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) rename meta/recipes-devtools/sbom-cve-check/{sbom-cve-check-update-nvd-native_2026.05.07-000006.bb => sbom-cve-check-update-nvd-native_2026.06.09-000006.bb} (89%) diff --git a/meta/recipes-devtools/sbom-cve-check/sbom-cve-check-update-nvd-native_2026.05.07-000006.bb b/meta/recipes-devtools/sbom-cve-check/sbom-cve-check-update-nvd-native_2026.06.09-000006.bb similarity index 89% rename from meta/recipes-devtools/sbom-cve-check/sbom-cve-check-update-nvd-native_2026.05.07-000006.bb rename to meta/recipes-devtools/sbom-cve-check/sbom-cve-check-update-nvd-native_2026.06.09-000006.bb index 02446e30cee..2917c89e628 100644 --- a/meta/recipes-devtools/sbom-cve-check/sbom-cve-check-update-nvd-native_2026.05.07-000006.bb +++ b/meta/recipes-devtools/sbom-cve-check/sbom-cve-check-update-nvd-native_2026.06.09-000006.bb @@ -6,7 +6,7 @@ HOMEPAGE = "https://github.com/fkie-cad/nvd-json-data-feeds" SRC_URI = "git://github.com/fkie-cad/nvd-json-data-feeds.git;branch=main;protocol=https;destsuffix=" SBOM_CVE_CHECK_DB_NAME = "nvd-fkie" -SRCREV = "72d8841c8ad9083ebf6723063f275444ea0d76f9" +SRCREV = "7ff4a0622bfdf5313c79635951112d2a45bbe9fd" UPSTREAM_CHECK_GITTAGREGEX = "v(?P.+)" require sbom-cve-check-update-db.inc From patchwork Thu Sep 17 22:06:00 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 98584 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 131B7C982E0 for ; Thu, 17 Sep 2026 22:08:05 +0000 (UTC) Received: from mail-wm2-f12.google.com (mail-wm2-f12.google.com [74.125.225.140]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.1671.1789682878919900343 for ; Thu, 17 Sep 2026 15:07:59 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=qcqp4+Ip; spf=pass (domain: smile.fr, ip: 74.125.225.140, mailfrom: yoann.congal@smile.fr) Received: by mail-wm2-f12.google.com with SMTP id 5b1f17b1804b1-49b912df756so780435e9.3 for ; Thu, 17 Sep 2026 15:07:58 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1789682877; x=1790287677; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=dycyFwYReeEDhYJ3eXAHkuG0cvtzLZO58ttFIR3tqRE=; b=qcqp4+IprRGzklI9jGBUGU5i0VZ/z1knr/7XjqBMxrmDwYNOBnEpCoEgtyNrbnKUW1 XV5CLfZH41hJM0A1NZ3oqkOFnNahBnXZ3uMZdJ1QLdKpCm83hxbO3V07IT3CpIzS8FM0 Po8rKcXUu9eLJlTwkTul9l/5TgRe5jF+8pgWQ= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1789682877; x=1790287677; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=dycyFwYReeEDhYJ3eXAHkuG0cvtzLZO58ttFIR3tqRE=; b=ET2wQy6t2qs1up9yvE8wuC+7hIBDTIwAV07WDxC1F2o/Cm7rWbNwcdcZ0zmmUVDpQG s3pU5wdRtWOe0vaRks/dMO2ChhveUXLhptaOLLyes61pUx6Uoyqak0PHFtvnDJ0JSHXK 1YL41DCSunV9Iigfa0dD1uASkmiITcaZU+/klB90OmXOKNCMxxxdBA686o5w3M9FnHc2 YbeL1034qklGDnJvx96BeNrrXYcg1HYWpVOzd0Rich+hmUEATUfP6WRhmpxSFBHs4jNZ 8OX3ckXIDLiOXBJwDyj3LOEa0DM8v0DHRMC0Fuy4uWxZgI/Jgx77czSvBDpNKMgAdeJ5 MBBA== X-Gm-Message-State: AFuF++lfedu+Yfvbqg3S0y4ZWBhvHRmsW+9f0V0a7wdnvBdstEvKQYI7 JtbKn+LwucismNG6Dz+RXCDCTBGAX9KG2Pk8klQRd4ZalOD7FBtSROytt1eokFuDTkt5pzhBv8+ SdOrK6V0= X-Gm-Gg: AYBFou3vCRxJ+U9tUz8+Hw1QhSKU9Ag7yykMzQcc67uCnQpb4sJa3nBhyD4+xbWM2hl 7OVwmrbJlb9VRwLQ+/fdEC98n6hmkrwthOsbbRfQWjYOlhzpR1sF9y/e63GS+L61uCp99qHD4ve lFTUywtztEsCLi7Mlp+NNhqA0go4wB0tWbWMRsoinw0aq0LTl22WiDw56S+GuByg27naktOzImg E4ZfFwsqQcDkqeeRpXybiL+ui5ea1NDs7QihU9AXIc0PZfGgr2gi6axI1JM6BxNXpV3QvOlYPR1 2hAaF/5neuhqVvD9SNRthIfgW056nDapVti/Z4a1sXEtDIZd1+GM7sLGSDeaaUOmgEPIqa4uPBI bkVExrWvF5Ts3mdRTTZTVnfg+OVXgbT9M9FNvNI5A60fwpfsI1+DmTEPmB+fSXo0hTGrvqqGfmk Vx7rqx13Z8V2bDUMbVO0r6Qw5TyPPQKldsg6QPxPGiUD8Bz0c5IqC0IstPyKuHn76u6w3w3DJN4 ITl0Bkux4kd36KC+LreBdfQuKFO0zI8QR7EKnsR8IrMsBAAqproepd4jnc80nHe4GEfaQwh4C8= X-Received: by 2002:a05:600c:3148:b0:49c:fc6e:8caf with SMTP id 5b1f17b1804b1-49fc5737ac5mr3376625e9.19.1789682877148; Thu, 17 Sep 2026 15:07:57 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-49fc471b9a2sm8984075e9.0.2026.09.17.15.07.56 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Thu, 17 Sep 2026 15:07:56 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][wrynose 15/79] python3-shacl2code: upgrade 1.0.1 -> 1.1.0 Date: Fri, 18 Sep 2026 00:06:00 +0200 Message-ID: <3aa18c06496d004752acd87951fb19b449ebc2f3.1789681419.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Thu, 17 Sep 2026 22:08:05 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/246110 From: Alexander Kanavin Add a patch to python3-spdx-python-model to support this release. Signed-off-by: Alexander Kanavin Signed-off-by: Richard Purdie (From OE-Core rev: f6557000abc90b0c3b7ca5b4560849e64425c853) Signed-off-by: Peter Marko Signed-off-by: Yoann Congal [YC: Changelog: https://github.com/JPEWdev/shacl2code/releases/tag/v1.1.0] --- ...e_1.0.1.bb => python3-shacl2code_1.1.0.bb} | 2 +- ...pdate-shacl2code-to-1.1.0-and-add-ke.patch | 41 +++++++++++++++++++ .../python/python3-spdx-python-model_0.0.5.bb | 10 ++--- 3 files changed, 47 insertions(+), 6 deletions(-) rename meta/recipes-devtools/python/{python3-shacl2code_1.0.1.bb => python3-shacl2code_1.1.0.bb} (81%) create mode 100644 meta/recipes-devtools/python/python3-spdx-python-model/0001-pyproject.toml-Update-shacl2code-to-1.1.0-and-add-ke.patch diff --git a/meta/recipes-devtools/python/python3-shacl2code_1.0.1.bb b/meta/recipes-devtools/python/python3-shacl2code_1.1.0.bb similarity index 81% rename from meta/recipes-devtools/python/python3-shacl2code_1.0.1.bb rename to meta/recipes-devtools/python/python3-shacl2code_1.1.0.bb index 904940926fe..a9c8bec84fc 100644 --- a/meta/recipes-devtools/python/python3-shacl2code_1.0.1.bb +++ b/meta/recipes-devtools/python/python3-shacl2code_1.1.0.bb @@ -5,7 +5,7 @@ LICENSE = "MIT" LIC_FILES_CHKSUM = "file://LICENSE;md5=0582f358628f299f29c23bf5fb2f73c9" PYPI_PACKAGE = "shacl2code" -SRC_URI[sha256sum] = "c856822b40c330452b8b31e94a658ad4595a5ef03cdb75ea432ea9c73d0cf7d9" +SRC_URI[sha256sum] = "0f3a243c6482a0f95c5a793288d304908506b51b82dc6133de22be477cd75c24" inherit pypi python_hatchling diff --git a/meta/recipes-devtools/python/python3-spdx-python-model/0001-pyproject.toml-Update-shacl2code-to-1.1.0-and-add-ke.patch b/meta/recipes-devtools/python/python3-spdx-python-model/0001-pyproject.toml-Update-shacl2code-to-1.1.0-and-add-ke.patch new file mode 100644 index 00000000000..d9dc0a03c8d --- /dev/null +++ b/meta/recipes-devtools/python/python3-spdx-python-model/0001-pyproject.toml-Update-shacl2code-to-1.1.0-and-add-ke.patch @@ -0,0 +1,41 @@ +From b623473f634aebeb30028cc746fb7a3da4fb2ce3 Mon Sep 17 00:00:00 2001 +From: Arthit Suriyawongkul +Date: Sat, 6 Jun 2026 02:44:48 +0100 +Subject: [PATCH] pyproject.toml: Update shacl2code to 1.1.0 and add keywords + (#35) + +Signed-off-by: Arthit Suriyawongkul +Upstream-Status: Backport [https://github.com/spdx/spdx-python-model/commit/2d7b71a7c8e6270a1c8795cdeb4f3dcd9393b3a9] +Signed-off-by: Alexander Kanavin +--- + pyproject.toml | 10 +++++++++- + 1 file changed, 9 insertions(+), 1 deletion(-) + +diff --git a/pyproject.toml b/pyproject.toml +index c8b3e56..df011e8 100644 +--- a/pyproject.toml ++++ b/pyproject.toml +@@ -8,6 +8,14 @@ authors = [ + {name = "Joshua Watt", email = "JPEWhacker@gmail.com"}, + ] + readme = "README.md" ++keywords = [ ++ "spdx", ++ "sbom", ++ "spdx3", ++ "software-bill-of-materials", ++ "shacl2code", ++ "bindings", ++] + classifiers = [ + "Development Status :: 4 - Beta", + "Intended Audience :: Developers", +@@ -36,7 +44,7 @@ Issues = "https://github.com/spdx/spdx-python-model/issues" + requires = [ + "hatchling >= 1.27.0", + "hatch-build-scripts >= 0.0.4", +- "shacl2code == 1.0.1", ++ "shacl2code == 1.1.0", + ] + build-backend = "hatchling.build" + diff --git a/meta/recipes-devtools/python/python3-spdx-python-model_0.0.5.bb b/meta/recipes-devtools/python/python3-spdx-python-model_0.0.5.bb index c77bdffada9..19d9bb815ba 100644 --- a/meta/recipes-devtools/python/python3-spdx-python-model_0.0.5.bb +++ b/meta/recipes-devtools/python/python3-spdx-python-model_0.0.5.bb @@ -7,11 +7,11 @@ LIC_FILES_CHKSUM = "file://LICENSE;md5=86d3f3a95c324c9479bd8986968f4327" PYPI_PACKAGE = "spdx_python_model" SRC_URI[sha256sum] = "4bcf7c6e5e2e8f0b787ed4eb8fb519e2ed776e820cb6d9eb93e44e98eb92ca2d" -SRC_URI += " \ - https://spdx.org/rdf/3.0.1/spdx-context.jsonld;name=spdx1 \ - https://spdx.org/rdf/3.0.1/spdx-json-serialize-annotations.ttl;name=spdx2 \ - https://spdx.org/rdf/3.0.1/spdx-model.ttl;name=spdx3 \ -" +SRC_URI += "https://spdx.org/rdf/3.0.1/spdx-context.jsonld;name=spdx1 \ + https://spdx.org/rdf/3.0.1/spdx-json-serialize-annotations.ttl;name=spdx2 \ + https://spdx.org/rdf/3.0.1/spdx-model.ttl;name=spdx3 \ + file://0001-pyproject.toml-Update-shacl2code-to-1.1.0-and-add-ke.patch \ + " SRC_URI[spdx1.sha256sum] = "c72b0928f094c83e5c127784edb1ebca2af74a104fcacc007c332b23cbc788bd" SRC_URI[spdx2.sha256sum] = "c6a54b51230eb2bf3b31302546af201f303e0b7931c1db404d7f5b72b6f863e6" From patchwork Thu Sep 17 22:06:01 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 98590 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id BB856C982E7 for ; Thu, 17 Sep 2026 22:08:05 +0000 (UTC) Received: from mail-wm2-f12.google.com (mail-wm2-f12.google.com [74.125.225.140]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.1672.1789682879446091641 for ; Thu, 17 Sep 2026 15:07:59 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=n4V4xq0q; spf=pass (domain: smile.fr, ip: 74.125.225.140, mailfrom: yoann.congal@smile.fr) Received: by mail-wm2-f12.google.com with SMTP id 5b1f17b1804b1-49e620fa473so732715e9.1 for ; Thu, 17 Sep 2026 15:07:59 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1789682878; x=1790287678; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=luF8XoDCDhg5jTpiKUdXEMXwvUCSqvPma1BoMoL+d0Y=; b=n4V4xq0qBcBwR4NpBfP/yJabiey93eUnMWL0bn3CM69tFL/yCBFRV3pKFVPeR08r8M F88ysPgg5IwoZRsgtUqXOrlUozQV4mKNtU4u42qmKDHW8riH2bq9kwOpc0g+12jR62E2 1Po+Ad0ZH/fzNv5njz/3FZ+hl45Jr7b3e3KMo= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1789682878; x=1790287678; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=luF8XoDCDhg5jTpiKUdXEMXwvUCSqvPma1BoMoL+d0Y=; b=GaO62E+/m7E6rwjDtrQaSVTeSYUum+41kushURjy6UOVK01X2bA7+CSqGX01aSMpzj 8UJwx3ke5JLkwVL2r3jgzsul2foj+a68CyLp5NCmKl464kk4UUbq1ZG6F9bP5ddZC3xQ QpNl3a86zYUp15kVZcRa+tCcQ76NOYTZeFgWAsGn49q5sO9Un/thkvWtslCpc6snEWZq Gh0ZwRHlNsTxdaOahingJ6X5jrMUF9vP84NSpmNr44WXSOa821ONTYQI848G+HR7BFyg qqnwUX9R/tt6lzX9dskkxHEVG7VFCl3VRCqpf7eMUaa06eFbZy29CjxW4O83rKCgfea+ elew== X-Gm-Message-State: AFuF++m5FkS5jj+bU75/Sqz8wkXnjFbQHofXE0IdW92a0QN17qln5P0r RYQbATuW00ZBnxY5JquohOjMwL5jg7o7hAXW5IYXoeqb2q0F858p4Tk5tlqViPjwLYyAnbZTFkR 9SUBfeIs= X-Gm-Gg: AYBFou2X4FD9FLHPyuyY9uXDt9t96lu+ZnCHWpbShgL/Xj+xmRpTOaLLzegsdYSNZoC vvVF1tYIsd2u9Cx5TncU4Hu9zrvU3KOmF8VRX4W1RfLUT4Vk7mHzzXYU9H22M8+n1Y10N4y7jUs WYhqzYRatNsPoKgYxF3NEB6QT5M9RqFAIX035xK3LbAroX2r7gw7p7hq3RaQtvSGqUWEGhue35J t/GExzVIDGVClA3PEqA1yfQa8+Hj75nq2UKjkzQfB6ABAhdlvlfU0/44SmJbjPGYQg379Ptgl8Q DKHGRgcASPNhohzzUMGU3mRjcskNtf83X6XsVQXGOUyv5pHcdXJ5XieVugeuMDKJAlOm5cd1tMe Z1wodkbfV3t2BduOofj9mm/Wf0dQB7Q2NzrOhlSt8Vajpf7K/YDvCXzkqXr3mtVqJpDSRsJMGBR TyoVH2e4s/SdpolXvVX5ZsufwOWHFH6JUgKf/FLm8nGclYWkKq/EwZFIqO95EPsyt/ebmmW7OSs xsJc4gLC2fkzlzs7pUb9RdYvvacYZ3rqAPc32eJF05sr0wX6geVSdGDRqLecwjsG0+ckvBVBx0= X-Received: by 2002:a05:600c:468d:b0:49d:93c:d903 with SMTP id 5b1f17b1804b1-49fc5746554mr3343195e9.20.1789682877640; Thu, 17 Sep 2026 15:07:57 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-49fc471b9a2sm8984075e9.0.2026.09.17.15.07.57 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Thu, 17 Sep 2026 15:07:57 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][wrynose 16/79] python3-spdx-python-model: update from version 0.0.5 to 0.0.6 Date: Fri, 18 Sep 2026 00:06:01 +0200 Message-ID: <93065713246d5b0a4d0393d9f4357674e7013f1c.1789681419.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Thu, 17 Sep 2026 22:08:05 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/246111 From: Benjamin Robin (Schneider Electric) Drop the patch which should no longer be necessary. This is a partial revert of f6557000abc90b0c3b7ca5b4560849e64425c853 Signed-off-by: Benjamin Robin (Schneider Electric) Signed-off-by: Mathieu Dubois-Briand Signed-off-by: Richard Purdie (From OE-Core rev: 9b5c92cd6b8ef8a56ebc3815120fd4af5872173c) Signed-off-by: Peter Marko Signed-off-by: Yoann Congal [YC: Changelog: https://github.com/spdx/spdx-python-model/releases/tag/v0.0.6] --- ...pdate-shacl2code-to-1.1.0-and-add-ke.patch | 41 ------------------- ....bb => python3-spdx-python-model_0.0.6.bb} | 12 +++--- 2 files changed, 6 insertions(+), 47 deletions(-) delete mode 100644 meta/recipes-devtools/python/python3-spdx-python-model/0001-pyproject.toml-Update-shacl2code-to-1.1.0-and-add-ke.patch rename meta/recipes-devtools/python/{python3-spdx-python-model_0.0.5.bb => python3-spdx-python-model_0.0.6.bb} (72%) diff --git a/meta/recipes-devtools/python/python3-spdx-python-model/0001-pyproject.toml-Update-shacl2code-to-1.1.0-and-add-ke.patch b/meta/recipes-devtools/python/python3-spdx-python-model/0001-pyproject.toml-Update-shacl2code-to-1.1.0-and-add-ke.patch deleted file mode 100644 index d9dc0a03c8d..00000000000 --- a/meta/recipes-devtools/python/python3-spdx-python-model/0001-pyproject.toml-Update-shacl2code-to-1.1.0-and-add-ke.patch +++ /dev/null @@ -1,41 +0,0 @@ -From b623473f634aebeb30028cc746fb7a3da4fb2ce3 Mon Sep 17 00:00:00 2001 -From: Arthit Suriyawongkul -Date: Sat, 6 Jun 2026 02:44:48 +0100 -Subject: [PATCH] pyproject.toml: Update shacl2code to 1.1.0 and add keywords - (#35) - -Signed-off-by: Arthit Suriyawongkul -Upstream-Status: Backport [https://github.com/spdx/spdx-python-model/commit/2d7b71a7c8e6270a1c8795cdeb4f3dcd9393b3a9] -Signed-off-by: Alexander Kanavin ---- - pyproject.toml | 10 +++++++++- - 1 file changed, 9 insertions(+), 1 deletion(-) - -diff --git a/pyproject.toml b/pyproject.toml -index c8b3e56..df011e8 100644 ---- a/pyproject.toml -+++ b/pyproject.toml -@@ -8,6 +8,14 @@ authors = [ - {name = "Joshua Watt", email = "JPEWhacker@gmail.com"}, - ] - readme = "README.md" -+keywords = [ -+ "spdx", -+ "sbom", -+ "spdx3", -+ "software-bill-of-materials", -+ "shacl2code", -+ "bindings", -+] - classifiers = [ - "Development Status :: 4 - Beta", - "Intended Audience :: Developers", -@@ -36,7 +44,7 @@ Issues = "https://github.com/spdx/spdx-python-model/issues" - requires = [ - "hatchling >= 1.27.0", - "hatch-build-scripts >= 0.0.4", -- "shacl2code == 1.0.1", -+ "shacl2code == 1.1.0", - ] - build-backend = "hatchling.build" - diff --git a/meta/recipes-devtools/python/python3-spdx-python-model_0.0.5.bb b/meta/recipes-devtools/python/python3-spdx-python-model_0.0.6.bb similarity index 72% rename from meta/recipes-devtools/python/python3-spdx-python-model_0.0.5.bb rename to meta/recipes-devtools/python/python3-spdx-python-model_0.0.6.bb index 19d9bb815ba..def12b20492 100644 --- a/meta/recipes-devtools/python/python3-spdx-python-model_0.0.5.bb +++ b/meta/recipes-devtools/python/python3-spdx-python-model_0.0.6.bb @@ -5,13 +5,13 @@ LICENSE = "Apache-2.0" LIC_FILES_CHKSUM = "file://LICENSE;md5=86d3f3a95c324c9479bd8986968f4327" PYPI_PACKAGE = "spdx_python_model" -SRC_URI[sha256sum] = "4bcf7c6e5e2e8f0b787ed4eb8fb519e2ed776e820cb6d9eb93e44e98eb92ca2d" +SRC_URI[sha256sum] = "f1938eb08d08218278122849bba123b8993a0171e9b4f5ea6af7aeb71f3204d7" -SRC_URI += "https://spdx.org/rdf/3.0.1/spdx-context.jsonld;name=spdx1 \ - https://spdx.org/rdf/3.0.1/spdx-json-serialize-annotations.ttl;name=spdx2 \ - https://spdx.org/rdf/3.0.1/spdx-model.ttl;name=spdx3 \ - file://0001-pyproject.toml-Update-shacl2code-to-1.1.0-and-add-ke.patch \ - " +SRC_URI += " \ + https://spdx.org/rdf/3.0.1/spdx-context.jsonld;name=spdx1 \ + https://spdx.org/rdf/3.0.1/spdx-json-serialize-annotations.ttl;name=spdx2 \ + https://spdx.org/rdf/3.0.1/spdx-model.ttl;name=spdx3 \ +" SRC_URI[spdx1.sha256sum] = "c72b0928f094c83e5c127784edb1ebca2af74a104fcacc007c332b23cbc788bd" SRC_URI[spdx2.sha256sum] = "c6a54b51230eb2bf3b31302546af201f303e0b7931c1db404d7f5b72b6f863e6" From patchwork Thu Sep 17 22:06:02 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 98583 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id E36F1C982DF for ; Thu, 17 Sep 2026 22:08:04 +0000 (UTC) Received: from mail-wm2-f12.google.com (mail-wm2-f12.google.com [74.125.225.140]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.1569.1789682879838982372 for ; Thu, 17 Sep 2026 15:08:00 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=oHz4PL9a; spf=pass (domain: smile.fr, ip: 74.125.225.140, mailfrom: yoann.congal@smile.fr) Received: by mail-wm2-f12.google.com with SMTP id 5b1f17b1804b1-49e69b9e16aso1211785e9.1 for ; Thu, 17 Sep 2026 15:07:59 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1789682878; x=1790287678; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=jhBwWjuPbSjfgIx76vb3JkbFKFcGtHy7eYN8LtXDVrI=; b=oHz4PL9a4dGRLf1vGs2m2PYLL9puU4cLAQ6z2qewNghSatC5jTsPNFX+pPJeD+28Po 9VnINsvWlI24wquh2NgtduYI7nVzkMuxZS8Gdai1sHHuWVZGPGpxS2VaR8UhXOln+B+8 fk7JbNM4qu+GWZWbDvZFAXhIULGTSV5FpJbyI= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1789682878; x=1790287678; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=jhBwWjuPbSjfgIx76vb3JkbFKFcGtHy7eYN8LtXDVrI=; b=urqhfbJ+Jrt5AQs2dDta6BZOD1Fr1+ZDqtHNM5l8gcpKlx5e5PZKlzldRFpJ64M3W+ /DeqAK/jWD4h1dP6wXe2MVDasq5Yj+000qIK+KhNl029pU8Z6KmS4Dr/98ubJLkxXJv+ MFcJk5C9Q8qsvr+vRyx8yQ2aHUqAUgpCvZDLduKatETouXFQLtnuIgMfJsBBJ8CGYTTQ /iLd6bUwPshegAVYJaGTbnCjKLUgBpoDJN+kaj1PHtiYBmnAFOF5MeuLFAo6w9x5fJMP xu665c10lpBikJp9BB73sJjfHwmdDVXgwD48EwHErbbYawxGGcnGU7IPhNV48HUm4L1M wTzg== X-Gm-Message-State: AFuF++keAofFZe9L6LHM3PBBBflsRP7MBDSkJU1bb0T7vKGxin/vzW3e 2OdXGPEE65loZEJz0pI7r5C0oJmCa6rRmTRbYQI2haZiiZ/BF0nUXE8vl/hnzW9msR3uIliW8Ay pcVjab3Y= X-Gm-Gg: AYBFou0zTdEcgzO0K0jlwS5uEPkDFAh6zhfaLFnlkW0AbNvuaaoefvGMgIiDnNPlx9z Tgo4l5wFaqyO1zdze2A5wDs4LWikWfpXqewN30iAugromst+e2TKrLaEGpdefEZT1uVX+zKj4Jc KKKrWuI+lHb31huA3CLqbHkzIa4R0OVG5PlJIVZL+TLY8SW+Mb+Xijlkjf4G+9jL+eLgFnfjh9c dEHG8abhBwQoh75cfLG23BbEfrG/Rdlr41vXF8HSTZS2B0x6PYpC+EegPrYUI9ixTXbEw4Rat/f 830lPeK7w5Kc88wwjLQ8tzyvC7eUKKgwdOqddaKpINx0ZHWbyRg/BFOSYPg25Kt8dH2ZbkhbrP5 lVh3g6XFFZMVj8cz7hzZv/Q3Tnzibmk4iZVu9XBO4dDtdDP06lDxDWOUuHFvZLivuPv4w7uNf8t M3ILQQXRU9mbxgxAeB4mrFyQkoj0z0oNVAnzpfE2Fz58xrTb2pXerSnR3EkO5TALtI9LuYfP3K/ 5/B4BLOS56bCq3kau1g64uwunqtviQWB97gUSK2CaayZCfRZhe4NH5iB3DiI8rt/uYGRpMJ4n8= X-Received: by 2002:a05:600c:1f87:b0:49d:99:1d98 with SMTP id 5b1f17b1804b1-49fc56ae924mr3932485e9.9.1789682878136; Thu, 17 Sep 2026 15:07:58 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-49fc471b9a2sm8984075e9.0.2026.09.17.15.07.57 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Thu, 17 Sep 2026 15:07:57 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][wrynose 17/79] python3-sbom-cve-check: update to version 1.3.2 Date: Fri, 18 Sep 2026 00:06:02 +0200 Message-ID: <16ac8d4ccc2cf6b6a476b657fc90b1ed4a9ab48d.1789681419.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Thu, 17 Sep 2026 22:08:04 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/246112 From: Benjamin Robin (Schneider Electric) For details on this new release, see: https://github.com/bootlin/sbom-cve-check/releases/tag/v1.3.2 Signed-off-by: Benjamin Robin (Schneider Electric) Signed-off-by: Mathieu Dubois-Briand Signed-off-by: Richard Purdie (From OE-Core rev: cd6313d94ac221dc37c30ffec8c83b6c8d1deeff) Signed-off-by: Peter Marko Signed-off-by: Yoann Congal --- ...-sbom-cve-check_1.3.1.bb => python3-sbom-cve-check_1.3.2.bb} | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) rename meta/recipes-devtools/sbom-cve-check/{python3-sbom-cve-check_1.3.1.bb => python3-sbom-cve-check_1.3.2.bb} (82%) diff --git a/meta/recipes-devtools/sbom-cve-check/python3-sbom-cve-check_1.3.1.bb b/meta/recipes-devtools/sbom-cve-check/python3-sbom-cve-check_1.3.2.bb similarity index 82% rename from meta/recipes-devtools/sbom-cve-check/python3-sbom-cve-check_1.3.1.bb rename to meta/recipes-devtools/sbom-cve-check/python3-sbom-cve-check_1.3.2.bb index 8120848a667..f14901e3008 100644 --- a/meta/recipes-devtools/sbom-cve-check/python3-sbom-cve-check_1.3.1.bb +++ b/meta/recipes-devtools/sbom-cve-check/python3-sbom-cve-check_1.3.2.bb @@ -5,7 +5,7 @@ LICENSE = "GPL-2.0-or-later" LIC_FILES_CHKSUM = "file://LICENSE;md5=570a9b3749dd0463a1778803b12a6dce" PYPI_PACKAGE = "sbom_cve_check" -SRC_URI[sha256sum] = "675828b2f02f11620b7a229853a24d09264bf41161be5fbb80a92456f46a14e0" +SRC_URI[sha256sum] = "0a7f07a0c6ce45d40adc6d311ddc25c4466f59bafcbce149b6fb3663791a5d89" inherit pypi python_hatchling From patchwork Thu Sep 17 22:06:03 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 98588 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 90F8AC982E6 for ; Thu, 17 Sep 2026 22:08:05 +0000 (UTC) Received: from mail-wr2-f12.google.com (mail-wr2-f12.google.com [74.125.225.76]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.1571.1789682880549927441 for ; Thu, 17 Sep 2026 15:08:00 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=TdFQZ5/p; spf=pass (domain: smile.fr, ip: 74.125.225.76, mailfrom: yoann.congal@smile.fr) Received: by mail-wr2-f12.google.com with SMTP id ffacd0b85a97d-485b1d2874fso16860f8f.0 for ; Thu, 17 Sep 2026 15:08:00 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1789682878; x=1790287678; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=sfoQtQCjVkWGhL55r2DcK4y5Ckr4qrwPeBiSwgGtVH4=; b=TdFQZ5/pbgskR3UeSvsoklrtGEnaXvviAFMSSimFIIHZ3J9Vfkjui3KqjMGJk1i/h/ rFZtcRBeSjBq84YvT/6LaRaK9Hjh685j3wmBILrCOrnNIQ4zIsd6T1RgmQXoENAdsexw BA3Ngz/BD3UljqqBjyzAj31QZIx2+3QmcxPOI= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1789682878; x=1790287678; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=sfoQtQCjVkWGhL55r2DcK4y5Ckr4qrwPeBiSwgGtVH4=; b=zHx9u5EKb03Wy3NA5rQWdcHOKxP59GCoA+0CPCLNYsOt+hpgPSlXrnU+04HnZ0nwTe sJRrYvhQt186VcMqgBEdei7uR3GAa8AJ6+h0SmJ8h5ywAWbUlYb1IdTOeeWTi93a8NBV YI7ReUs7Wq6SyM3/mCtlu3UGwb4UopasUr3LZVBWEraAf2O6FeHAjiytDUxomd0O8Gbm RxwkQUXcYdGzJs0DmAHrR2iWFRMvPpzI/LDP23aSUKbji7u92eWie0Aa/MwoJFE5Dqwd gP5sYx42/A9D5W/UpQ2h6t8L1gXmSAL384jx8KCjtNssyjoQC+GMNxkPaXiD32Rh+O/t Zm0w== X-Gm-Message-State: AFuF++ksMsjoXzI9PMSAFvlMSgnoV+OtGuQtDC0p4ClAHy8O5NJaqQ6t L0lhNTNNuZwfkgJvn/cd6zE+Efz8auQ0rBEaK+Q9yCaNPlrFkjlUt+zalM9hiXHcH3k4mTmyB0U cSpW1Xg0= X-Gm-Gg: AYBFou1Hq2gdElJXGKMBxJFVPkx9HA9Y0+aiW01nwFkdYCnCDFVDoJrDtU1epIzpB8K X6W3V5sIH07OFw6l4oPozb1jRtG1GGhqRD7k8/UMCS9slUKX5t5LlSruN/cci56it/z9emJr7aX wSao8lN45JkmE2+HowI83MWAUBywMKsPcM+i2ERQnLdvzKuboQ2iWcwMRhnR6BTNQPPM3QDgQTP 2Y5HHqXNmeL+O7zgcFbEJJb55HmBHSmVKfS0EinakuFLc+NhPCTQFOyiU65ck3fhG/bYT7s6T9V j0qg+8DO5L7ZlGic2/hCdATwKmfeGbfav5abkXezsNGGjU7iIU7jV1R068thl2PhVbPCzaxMCM5 5uSw8N3shc5MYsLVHNzuzRyu1I2yZbk1/y7sr+zBVCatu/N8ggLWorKbI3We2Yj8LT45bbc+3pX EjnJ52N+ieR05J2fqewWorh+tT+QG8vkPuBrphdj2EA02lUdmKfPkwd7yL8BLNVRquGPfFsVfle usvFPcaILaYBEZOEC97wX52hpBWMvEO6zEZTEXdjSfFoM+MD8ZBJfSbuAkYgKXDGcmOdBoeqgk= X-Received: by 2002:a05:600c:3f06:b0:49d:257c:a735 with SMTP id 5b1f17b1804b1-49fc4ff42b4mr5977135e9.11.1789682878580; Thu, 17 Sep 2026 15:07:58 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-49fc471b9a2sm8984075e9.0.2026.09.17.15.07.58 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Thu, 17 Sep 2026 15:07:58 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][wrynose 18/79] sbom-cve-check-update-cvelist-native: update to version 2026-06-24 Date: Fri, 18 Sep 2026 00:06:03 +0200 Message-ID: <4f248ad8c60ee85d3a5a99195e6b11dea79765e2.1789681419.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Thu, 17 Sep 2026 22:08:05 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/246113 From: Benjamin Robin (Schneider Electric) Update cvelistV5 to the CVE database from 2026-06-24. Signed-off-by: Benjamin Robin (Schneider Electric) Signed-off-by: Mathieu Dubois-Briand Signed-off-by: Richard Purdie (From OE-Core rev: f7a706321eb783ad43d8d9666ea3536024cb5be8) Signed-off-by: Peter Marko Signed-off-by: Yoann Congal --- ...07.bb => sbom-cve-check-update-cvelist-native_2026-06-24.bb} | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) rename meta/recipes-devtools/sbom-cve-check/{sbom-cve-check-update-cvelist-native_2026-05-07.bb => sbom-cve-check-update-cvelist-native_2026-06-24.bb} (89%) diff --git a/meta/recipes-devtools/sbom-cve-check/sbom-cve-check-update-cvelist-native_2026-05-07.bb b/meta/recipes-devtools/sbom-cve-check/sbom-cve-check-update-cvelist-native_2026-06-24.bb similarity index 89% rename from meta/recipes-devtools/sbom-cve-check/sbom-cve-check-update-cvelist-native_2026-05-07.bb rename to meta/recipes-devtools/sbom-cve-check/sbom-cve-check-update-cvelist-native_2026-06-24.bb index 7670172c40b..ca192bc9cf3 100644 --- a/meta/recipes-devtools/sbom-cve-check/sbom-cve-check-update-cvelist-native_2026-05-07.bb +++ b/meta/recipes-devtools/sbom-cve-check/sbom-cve-check-update-cvelist-native_2026-06-24.bb @@ -6,7 +6,7 @@ HOMEPAGE = "https://github.com/CVEProject/cvelistV5" SRC_URI = "git://github.com/CVEProject/cvelistV5.git;branch=main;protocol=https;destsuffix=" SBOM_CVE_CHECK_DB_NAME = "cvelist" -SRCREV = "dd0e93c75034d0167498174c886a56729edc44de" +SRCREV = "966bddf787997b471325e065cae82702a60c64ff" UPSTREAM_CHECK_GITTAGREGEX = "(?P.+)_baseline" require sbom-cve-check-update-db.inc From patchwork Thu Sep 17 22:06:04 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 98578 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id BDE88C982DC for ; Thu, 17 Sep 2026 22:08:04 +0000 (UTC) Received: from mail-wm2-f12.google.com (mail-wm2-f12.google.com [74.125.225.140]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.1572.1789682880735308009 for ; Thu, 17 Sep 2026 15:08:01 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=kNvGpFFL; spf=pass (domain: smile.fr, ip: 74.125.225.140, mailfrom: yoann.congal@smile.fr) Received: by mail-wm2-f12.google.com with SMTP id 5b1f17b1804b1-49cd38e0e5dso1334545e9.2 for ; Thu, 17 Sep 2026 15:08:00 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1789682879; x=1790287679; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=OuE0GuFaxyRmWAd/w1KjivG8psg3cFaLbBKFexj0xos=; b=kNvGpFFLG/KA6+2u4hjXZ8mFPfGeqMudukJA9146uYFiTJzaEMpqyKXzQlbhpz5oD6 1rZrD00D27iJkJTw2n9n6eocKcQK5djbRVHpYa0cfF/scIwVQeXQb6T456ZraK+TaxE8 sofctY+E5PrWr/tYQUO+SLY+dXiH8vXoleuFY= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1789682879; x=1790287679; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=OuE0GuFaxyRmWAd/w1KjivG8psg3cFaLbBKFexj0xos=; b=Rd3Q3CKdk1nMy+c4dSe+tRvrzRcxHlKNZO4mhORbpcJjkeustZGCIFJ+z36gpXwaTk Z7AW52RQ3iUR10ZPMvl2pvWobZeN1b2DYZknC8lvN3A/3VLYKf45t6cQD4g7OqbZH49M MSf5EWAB6MTaIeHNQ0vJMsO17gb/teaMw/MLkYi+F/eFx8Re3egC92+oW69hl0Cxgl0i 9AfvsCk4YqBfWh2DZIESOnGbpcppFZ9ex6NbsbZ5/dMM1B3CGYcYi++uNvbBCyD2haPV wI5u6uLGXprUWFl8GC/Koko1/mPmntCpQcihKxbzSD/wTKgljCeZOLLoXyEeCVC7323m ngpA== X-Gm-Message-State: AFuF++nM3v+aETb3TdxPI6sv6liYvEA+pevPWY8favW4xuTexEPhVel2 PqWTX0prXKv6RMUBQnM7YCtWlTmVRvtkJHaw861DI+q82HmsOk2BFYdjemsUGYC3gG7DpawNuJp CHdDJ2WA= X-Gm-Gg: AYBFou3pZeXRnlrbZDPPM5u8DgoicJjSVcc+5+rcx6Gi+5YOg2fXGVPFerb5IYwiYIW V6pClE7ll3bphGlw+10/Vp1Ltl7MIqMqasxWG/SCqRdY5+b5fftC1mLHcIpTjIhZplkWY+npl2t kn4vDCkU3i9VZx3RIUdMRUVk12Sc4iwQgkg+wXnGz967Zyfngd2b+J3iuej78YMBb+hMkUGSrQC hfD6wUcjHQfdkaescgM/Q/cp6HKVeYoe0ZGv5pkbJp2JdW2A4i2KBU6uHDdA6ItY2jwiF6BhxY3 GSH9erYGA2nS21C5rcd/UUJifP4Q2U88v5aRA99vmJSehkBs/3C4fLEMr9w4QhAKsYQWlbmvXgP NXjOC/gL3fgIcBdj5L+l1S/du7aiCZ4dWI3MlKFZ6wkV4M2uo6fGXUfZ2HPRpyYD9y4kfMliyS3 3AiWwwJXWi/gaunWZRQKgVYPRRIIARI/qnCRLQXZjP63AfT9GZvdxAH6qehFCRu8hsXYTVvKG0C lgfQo18knehaWtMyZMkQAoF9FFVVx4S/EdVXVyojZyKoZA2iIAI6NJO0kim7uaj07gFefsxmBg= X-Received: by 2002:a05:600c:a14:b0:499:b65e:49c9 with SMTP id 5b1f17b1804b1-49fc568f7a7mr3180995e9.10.1789682879026; Thu, 17 Sep 2026 15:07:59 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-49fc471b9a2sm8984075e9.0.2026.09.17.15.07.58 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Thu, 17 Sep 2026 15:07:58 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][wrynose 19/79] sbom-cve-check-update-nvd-native: update to version 2026.06.24-000003 Date: Fri, 18 Sep 2026 00:06:04 +0200 Message-ID: <52b64f4bbd50bbf37db3e0524406276592dddcf6.1789681419.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Thu, 17 Sep 2026 22:08:04 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/246114 From: Benjamin Robin (Schneider Electric) Update fkie-cad/nvd-json-data-feeds to the CVE database from 2026-06-24. Signed-off-by: Benjamin Robin (Schneider Electric) Signed-off-by: Mathieu Dubois-Briand Signed-off-by: Richard Purdie (From OE-Core rev: fba290297e9bbc8c6c4086e7784ece5d06dbd26d) Signed-off-by: Peter Marko Signed-off-by: Yoann Congal --- ...bb => sbom-cve-check-update-nvd-native_2026.06.24-000003.bb} | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) rename meta/recipes-devtools/sbom-cve-check/{sbom-cve-check-update-nvd-native_2026.06.09-000006.bb => sbom-cve-check-update-nvd-native_2026.06.24-000003.bb} (89%) diff --git a/meta/recipes-devtools/sbom-cve-check/sbom-cve-check-update-nvd-native_2026.06.09-000006.bb b/meta/recipes-devtools/sbom-cve-check/sbom-cve-check-update-nvd-native_2026.06.24-000003.bb similarity index 89% rename from meta/recipes-devtools/sbom-cve-check/sbom-cve-check-update-nvd-native_2026.06.09-000006.bb rename to meta/recipes-devtools/sbom-cve-check/sbom-cve-check-update-nvd-native_2026.06.24-000003.bb index 2917c89e628..73d9e776929 100644 --- a/meta/recipes-devtools/sbom-cve-check/sbom-cve-check-update-nvd-native_2026.06.09-000006.bb +++ b/meta/recipes-devtools/sbom-cve-check/sbom-cve-check-update-nvd-native_2026.06.24-000003.bb @@ -6,7 +6,7 @@ HOMEPAGE = "https://github.com/fkie-cad/nvd-json-data-feeds" SRC_URI = "git://github.com/fkie-cad/nvd-json-data-feeds.git;branch=main;protocol=https;destsuffix=" SBOM_CVE_CHECK_DB_NAME = "nvd-fkie" -SRCREV = "7ff4a0622bfdf5313c79635951112d2a45bbe9fd" +SRCREV = "11e62eba27133a54836b7a081d05ff96f72d879b" UPSTREAM_CHECK_GITTAGREGEX = "v(?P.+)" require sbom-cve-check-update-db.inc From patchwork Thu Sep 17 22:06:05 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 98579 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id B22D9C982DB for ; Thu, 17 Sep 2026 22:08:04 +0000 (UTC) Received: from mail-wm2-f12.google.com (mail-wm2-f12.google.com [74.125.225.140]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.1573.1789682881073228268 for ; Thu, 17 Sep 2026 15:08:01 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=jvaVZTf9; spf=pass (domain: smile.fr, ip: 74.125.225.140, mailfrom: yoann.congal@smile.fr) Received: by mail-wm2-f12.google.com with SMTP id 5b1f17b1804b1-49b912d391aso786145e9.2 for ; Thu, 17 Sep 2026 15:08:00 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1789682879; x=1790287679; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=xxP52CXndjVafiChfoJzg1ggw4TunHghYuZx0pFmcZU=; b=jvaVZTf9slFdO3JU74vlQXSrFqnlhLipLPlqhO7JXo2mwY1PUqD/bDrLe8gXDM1M/d pUYAZWjeRu4mav2YZsx0Lb/jVMRCTCdAcg5fHAmjyYj62hCm0Et7rfLEKbzAnOAirbST 3z7J/QPloav2APtl24Ig7c6qY93zwNIgA6KRE= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1789682879; x=1790287679; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=xxP52CXndjVafiChfoJzg1ggw4TunHghYuZx0pFmcZU=; b=I77niHhG9LL9OuaFHTTetf6LFuc550nPx/aYV0/nP5vJ4qnIvh1EB05K4RSVqbp82f XDRMVSXbRM2ufA6pkIED2St5ONriSdFEazFXM0l9fGwpdBfX7mhislqry3JR6QBHLYbg OEoarPnY/rkkwKMMrU6rL+7RXDgOOXuwjDknRDDVMBXorHJajUXkMlsboExSAan8FWEb Dtvs0PYv9uVEzK8JTXynS81QCOCSycAzYHpiWTy9zOWma7m2KfhcV+REiZv/LBjLBCRr oZbkkULd+rnQe3KJgDJz/Rj9DHiyYwjX8+QujGpAgkMFgYSB95P83dmIMmZtqq/p1wLV ULCQ== X-Gm-Message-State: AFuF++nvRrhME0siiuuOSoDJQaMZ3YfXI/qofFysJXs4G+0bZb5MCN/F 5Xrj/LeXB240uyGvY41aTi3p0MI3FDP9eoQJZJ9PXBsqq/0DEyt4+w3UN7h/TMJncnrR3u/jEqn F9FQKDyA= X-Gm-Gg: AYBFou2KK7gZ5OU+IkTtQm5cIDlnQkNpysHknpOTdKQixkJ/wSG7z+UL+NnDSEannzL mwz3R+HgmbnKCQrr9YNVCb4DKYONWnMhTshS2CdrJhXOzZvpO3SLOtn6Y4IX0LQCWay4zKidrAd uR8Qg0X6j+e6X/y62C0Q7uOE2lczglFQqw+zpRjyZlvoBsowWop9m3iFtry1rLt/WXFRRkEEmgu OafvEQCXHOaT0jCK6kxxHIpprVgLXWMTttg3NxwSkysyapbCKl8rjt+sQ4pI3KXbvCvu6DhTaWq u1eV5bKOoImzydfhReWkXiJuTZrbdg9uSflJup9bmBT9z0CVo+vpd1Fj83P+Pl/0BUa2GYJDVGq XD7BaSLmhfMiEplyk7FW9mpvOLhax+w7cE0wbKywkSzL1mpFVHX8msaAD88FXQUKXRFj9gJBdkK aU0jsulSy6Cy7ccmw4M4ltomNwxgHqtLouBLdg9XFyt6T8v0RXiFO33DgHkIcowXq//fExSJbAg WJWkOQgHS4CjOS9yCxJZkQugQTjblINzpV7Mf4kw0h1hc8tRIzrI0bdn/hcZ42hh/W0ZrJsPzEx /7Ph9vBH9w== X-Received: by 2002:a05:600c:4e8f:b0:49c:fc6c:be19 with SMTP id 5b1f17b1804b1-49fc574c2b9mr3201995e9.31.1789682879445; Thu, 17 Sep 2026 15:07:59 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-49fc471b9a2sm8984075e9.0.2026.09.17.15.07.59 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Thu, 17 Sep 2026 15:07:59 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][wrynose 20/79] sbom-cve-check-update-cvelist-native: -> 2026-07-23 Date: Fri, 18 Sep 2026 00:06:05 +0200 Message-ID: X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Thu, 17 Sep 2026 22:08:04 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/246115 From: Tim Orling The diff is quite large, but a partial comparison can be seen: https://github.com/CVEProject/cvelistV5/compare/2026-06-24_baseline..2026-07-23_baseline Signed-off-by: Tim Orling Signed-off-by: Richard Purdie (From OE-Core rev: 1323691ceab2a338c4d5b9c15624b8d22c472e7f) Signed-off-by: Peter Marko Signed-off-by: Yoann Congal --- ...24.bb => sbom-cve-check-update-cvelist-native_2026-07-23.bb} | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) rename meta/recipes-devtools/sbom-cve-check/{sbom-cve-check-update-cvelist-native_2026-06-24.bb => sbom-cve-check-update-cvelist-native_2026-07-23.bb} (89%) diff --git a/meta/recipes-devtools/sbom-cve-check/sbom-cve-check-update-cvelist-native_2026-06-24.bb b/meta/recipes-devtools/sbom-cve-check/sbom-cve-check-update-cvelist-native_2026-07-23.bb similarity index 89% rename from meta/recipes-devtools/sbom-cve-check/sbom-cve-check-update-cvelist-native_2026-06-24.bb rename to meta/recipes-devtools/sbom-cve-check/sbom-cve-check-update-cvelist-native_2026-07-23.bb index ca192bc9cf3..0e664d89e07 100644 --- a/meta/recipes-devtools/sbom-cve-check/sbom-cve-check-update-cvelist-native_2026-06-24.bb +++ b/meta/recipes-devtools/sbom-cve-check/sbom-cve-check-update-cvelist-native_2026-07-23.bb @@ -6,7 +6,7 @@ HOMEPAGE = "https://github.com/CVEProject/cvelistV5" SRC_URI = "git://github.com/CVEProject/cvelistV5.git;branch=main;protocol=https;destsuffix=" SBOM_CVE_CHECK_DB_NAME = "cvelist" -SRCREV = "966bddf787997b471325e065cae82702a60c64ff" +SRCREV = "7a274ec07043f54c07d0a3b5c7fc89ba5793f023" UPSTREAM_CHECK_GITTAGREGEX = "(?P.+)_baseline" require sbom-cve-check-update-db.inc From patchwork Thu Sep 17 22:06:06 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 98575 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 8C496C982DA for ; Thu, 17 Sep 2026 22:08:04 +0000 (UTC) Received: from mail-wm2-f12.google.com (mail-wm2-f12.google.com [74.125.225.140]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.1673.1789682881649114162 for ; Thu, 17 Sep 2026 15:08:01 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=WpKh/3kM; spf=pass (domain: smile.fr, ip: 74.125.225.140, mailfrom: yoann.congal@smile.fr) Received: by mail-wm2-f12.google.com with SMTP id 5b1f17b1804b1-49b912e2406so557315e9.1 for ; Thu, 17 Sep 2026 15:08:01 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1789682880; x=1790287680; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=8p+v+n/3TOQIwIybuDH5sS6ombHaDjY49hD+Y99mwKs=; b=WpKh/3kM3La1MT0KtmG8GWLET3Lg3Jdf7MrGtEfocb0MEvP3w5ovbtFxvDnPPheq+v zbL2if0f248V5tGx/kBrGY/6/maIhUOhivTSd+9H0Q0UsRdounomOI1gCyst8e/GRyqX shOBPujgiy4IbJQ+7Qp1YpSatNvtd+fIXpdaA= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1789682880; x=1790287680; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=8p+v+n/3TOQIwIybuDH5sS6ombHaDjY49hD+Y99mwKs=; b=k8yt1y3Z18LQtJcBFmovvGi0BwjpqJxqx8qjj9v/S+/f+QI5j/jbCqpK9TQE3627Hi BlaU5VRZMmog630O+VsC2YJRmzsDoHrVA9HDY4b8FsIIPIXvrRUjV+kqPjDztzn2hXy0 1HxHdmPFR/CEBhGWipF8nCfEAJM1H8GFKPN3Kac7TYEuZx9cpXpjNHKxLx6cAfP0+30B EgDXdz5/1JgxUqyiLIYEbEwe3ORdz06q3pPij9uYXb/GNmw82G8JoLxb0lHE6v/Fw1n7 gCHtSgRqzYjulFm+4eLWxz1k2SfcFgj7VEidt9XgGky0XUmUh+wS4z+7YUXcV/+5QnPy 6IWw== X-Gm-Message-State: AFuF++lMSJxPbVQVKEUNPWx+hxbz9x5/hFwYGcZYHIQQzs3CmTSgZRv4 S2Kfpb2MiRFIPDSC/Fb+6QvOfM/+ZtGVrArlkFmJT8eVew2santE6TTlEyQgcLiHunr1PTlq55s iXHEWUEY= X-Gm-Gg: AYBFou09ktK9DeG0FZHd4Np5VjOQ6sZnGXc6OzP7MMf9AWvVSIgBXT/WZiiQTIzibqp Fef+VTEHcVtobad1AHKv+6xUj8m+Q38B1KWspemSGh/+UOs5PmQ9SvYO4+OmcORfRWoJu76zh7f sTWdj1z+FxBSWLG/DNEeXRQyiicjthwgUYfyelC1EHR+Yd3zI1NAKCo0/MOREq54KUUbL91akg2 OCFfgSgMzfWm2ttaTO8LmpblU5R1N6KOqdG55LwGLJxmONT+k3I3SM4Bp4nexvyB+1AoLjVT/6E 4rh3nicRB36o5pol8bCsdnuKjXlCHzIahGMNgr6oynYMgnbep+O3JU5eNd7w6W6w7yLHt3W0w5G /w4tg03fri/AKu/Vqh1uLPfEwZd9bNYbuj0k2oD05xwfiIHvwKX8Fnk6CUWW6rqADilERpzpqin ZEYHTDKHMYysKdtmpVP6O1Ii5aPdXWAFUJxXz2IenlA6o+zsuzlFkTWsOy14Y8ERsu+opqXxKdz wwPI0cyRoVziSaoiB/Zjr1Wt6ukRmx52uzB8icuA1rujAZYWJDL/7zv8u343lTdqL+aIdfIbQs= X-Received: by 2002:a05:600c:4e89:b0:49e:6ca6:d40f with SMTP id 5b1f17b1804b1-49fc4ff40a9mr6622575e9.9.1789682879932; Thu, 17 Sep 2026 15:07:59 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-49fc471b9a2sm8984075e9.0.2026.09.17.15.07.59 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Thu, 17 Sep 2026 15:07:59 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][wrynose 21/79] sbom-cve-check-update-nvd-native: -> 2026.07.23-000007 Date: Fri, 18 Sep 2026 00:06:06 +0200 Message-ID: <19a4405ba0a94e83d93535426bba85a9b4ce5870.1789681419.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Thu, 17 Sep 2026 22:08:04 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/246116 From: Tim Orling The diff is quite large, but a partial comparison can be seen: https://github.com/fkie-cad/nvd-json-data-feeds/compare/v2026.06.24-000003..v2026.07.23-000007 Signed-off-by: Tim Orling Signed-off-by: Richard Purdie (From OE-Core rev: 9d89b3b802bab144afa30e03b0411ae58232ef11) Signed-off-by: Peter Marko Signed-off-by: Yoann Congal --- ...bb => sbom-cve-check-update-nvd-native_2026.07.23-000007.bb} | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) rename meta/recipes-devtools/sbom-cve-check/{sbom-cve-check-update-nvd-native_2026.06.24-000003.bb => sbom-cve-check-update-nvd-native_2026.07.23-000007.bb} (89%) diff --git a/meta/recipes-devtools/sbom-cve-check/sbom-cve-check-update-nvd-native_2026.06.24-000003.bb b/meta/recipes-devtools/sbom-cve-check/sbom-cve-check-update-nvd-native_2026.07.23-000007.bb similarity index 89% rename from meta/recipes-devtools/sbom-cve-check/sbom-cve-check-update-nvd-native_2026.06.24-000003.bb rename to meta/recipes-devtools/sbom-cve-check/sbom-cve-check-update-nvd-native_2026.07.23-000007.bb index 73d9e776929..cf35b169235 100644 --- a/meta/recipes-devtools/sbom-cve-check/sbom-cve-check-update-nvd-native_2026.06.24-000003.bb +++ b/meta/recipes-devtools/sbom-cve-check/sbom-cve-check-update-nvd-native_2026.07.23-000007.bb @@ -6,7 +6,7 @@ HOMEPAGE = "https://github.com/fkie-cad/nvd-json-data-feeds" SRC_URI = "git://github.com/fkie-cad/nvd-json-data-feeds.git;branch=main;protocol=https;destsuffix=" SBOM_CVE_CHECK_DB_NAME = "nvd-fkie" -SRCREV = "11e62eba27133a54836b7a081d05ff96f72d879b" +SRCREV = "64a0cea215628d780438fba8bfe0f3300db1b702" UPSTREAM_CHECK_GITTAGREGEX = "v(?P.+)" require sbom-cve-check-update-db.inc From patchwork Thu Sep 17 22:06:07 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 98580 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id BE020C982DE for ; Thu, 17 Sep 2026 22:08:04 +0000 (UTC) Received: from mail-wm2-f13.google.com (mail-wm2-f13.google.com [74.125.225.141]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.1574.1789682882166777159 for ; Thu, 17 Sep 2026 15:08:02 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=Ewu76ApX; spf=pass (domain: smile.fr, ip: 74.125.225.141, mailfrom: yoann.congal@smile.fr) Received: by mail-wm2-f13.google.com with SMTP id 5b1f17b1804b1-49b91369d18so1103675e9.0 for ; Thu, 17 Sep 2026 15:08:01 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1789682880; x=1790287680; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=VfCP4w+pPYfqf2V11PT5XWippQGNLlPd4lJzZkQUVLo=; b=Ewu76ApX7Ee68Ks7GDx2emCz7JH3i/fvc9pBO0gk9YXHKkHljlR0t+Jko5y0/RB6uh 971K2mEVTi0DwVeVCSUm38SSsapdCC8zhmWWd/53UB/WGjJ+fwjRHXpN4DyAdhLb9jDT 8mGIQrQb73X2X9qVrkuAXG/BL02CwxSXIJYdQ= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1789682880; x=1790287680; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=VfCP4w+pPYfqf2V11PT5XWippQGNLlPd4lJzZkQUVLo=; b=MMEseDISM6Dgdg3MidGphzFaz4+Q881CALzYay0FU3Ob9DMWT6W1JZeZ8FvQHkytH3 8A88RMTaXCBs9OIvIrXqAbWbnxZzuX2tv9feCKD9kR0HFjMVpP6ToiWtxcBkn9Ag4145 IlHMpieFKrAE2X44vjiYYfxvnx/oz8zcCxCjuuIk7UYQPJdcsMI/dNBtNKPc/W7NEAKq h2u2/Xbjyq2UnvT4X9xFYOFAZnY+DLi6myR7nw8I00g8WdwukiRyYxTFywvLG5oeOWYg CieJNSNyX1BP1F2LaTsOmULFH3QC0PtOzlB5sE6aECTWm/AOS4/YWBp5cUhOVJuZK4sM FR5A== X-Gm-Message-State: AFuF++mZGBT7OeeAqmgzFKorkYSKafG4rAKwUbRzm3+ATlBIbhiUsPSm U/8IYCQrDsMxI8FeykeUFlbjwNIRk6pZLTJmx8o6VD0db7nybz+RKkBYjw/gWTHq9Gu7ToAkb7D KEnj0XKg= X-Gm-Gg: AYBFou0RFSxauAS7hJqIq/m5M1Ope5dvO1SmndtPvNlJ/M+46a6+ZNwwcV2uksXa6rL k3AmzPwEeZ9rpYo1XOncSe8CTnpbL+HouMbGaNA6NSkAtfcJFYUmVsUr3OKJcKRpAmRAwAGFbW0 ixrkzTTCINuXHobbGQt02aUcl3G/H1isAcBX0rQuACGnfcURYYKN/pYALRGl21UgTVffSvCQTh4 h1gUjTzq17a7ehRMAmByd+VSFY8K3tbxw6WXJS0sn8LXd/JGkbiqDImO1Iv0jWWucEHgQCfe8l2 1bQn+w3CjjDDUHPCuL3hqURGcOlY7P03ACQwW9LXe/daciqTM/NLVilTg/S8uLXn+AdOczTN7Y3 JgxpfLJ8dyUiDvk3rrx8+VcBlkrp8zbzZ9mb97jQtyBQ7tw9IOLVMy28IuT8/lHLFxubelFEtjW l4oWZz42sOVMHD40IchyHtgs5Ldt4YQUFO31XXI6rK1dLQ9DG8TXPZFNiCGb7AyDIhzgdnrU66x hasFahEYvEUVM5FdY8gChMQTPwLq+f5wz5KmLYVpO26WyJBaf2lPu3XtmNGD8Q4u3mabmZFpYhP zEouH9RNXA== X-Received: by 2002:a05:600c:19d1:b0:49c:fc6e:a3d6 with SMTP id 5b1f17b1804b1-49fc574ef3cmr2901705e9.21.1789682880375; Thu, 17 Sep 2026 15:08:00 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-49fc471b9a2sm8984075e9.0.2026.09.17.15.08.00 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Thu, 17 Sep 2026 15:08:00 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][wrynose 22/79] python3-sbom-cve-check: update to version 1.3.3 Date: Fri, 18 Sep 2026 00:06:07 +0200 Message-ID: <4705eefd8ee8ff414207ea6ab0f037d267af8f90.1789681419.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Thu, 17 Sep 2026 22:08:04 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/246117 From: Benjamin Robin For details on this new release, see: https://github.com/bootlin/sbom-cve-check/releases/tag/v1.3.3 Signed-off-by: Benjamin Robin (Schneider Electric) Signed-off-by: Richard Purdie (From OE-Core rev: 7feb4e30ba17a4b0eb37a1c6dde671d4491bd35d) Signed-off-by: Peter Marko Signed-off-by: Yoann Congal [YC: Noticeable change: Generate a "not affected" assessment if the vulnerability is disputed ] --- ...-sbom-cve-check_1.3.2.bb => python3-sbom-cve-check_1.3.3.bb} | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) rename meta/recipes-devtools/sbom-cve-check/{python3-sbom-cve-check_1.3.2.bb => python3-sbom-cve-check_1.3.3.bb} (82%) diff --git a/meta/recipes-devtools/sbom-cve-check/python3-sbom-cve-check_1.3.2.bb b/meta/recipes-devtools/sbom-cve-check/python3-sbom-cve-check_1.3.3.bb similarity index 82% rename from meta/recipes-devtools/sbom-cve-check/python3-sbom-cve-check_1.3.2.bb rename to meta/recipes-devtools/sbom-cve-check/python3-sbom-cve-check_1.3.3.bb index f14901e3008..2aca1005694 100644 --- a/meta/recipes-devtools/sbom-cve-check/python3-sbom-cve-check_1.3.2.bb +++ b/meta/recipes-devtools/sbom-cve-check/python3-sbom-cve-check_1.3.3.bb @@ -5,7 +5,7 @@ LICENSE = "GPL-2.0-or-later" LIC_FILES_CHKSUM = "file://LICENSE;md5=570a9b3749dd0463a1778803b12a6dce" PYPI_PACKAGE = "sbom_cve_check" -SRC_URI[sha256sum] = "0a7f07a0c6ce45d40adc6d311ddc25c4466f59bafcbce149b6fb3663791a5d89" +SRC_URI[sha256sum] = "8b766be1ae92b4eceaa2f694dd4724e310886c6436f44267a6bbc6a7b81ab8b9" inherit pypi python_hatchling From patchwork Thu Sep 17 22:06:08 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 98576 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 710A2C982D8 for ; Thu, 17 Sep 2026 22:08:04 +0000 (UTC) Received: from mail-wm2-f13.google.com (mail-wm2-f13.google.com [74.125.225.141]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.1674.1789682882558563661 for ; Thu, 17 Sep 2026 15:08:02 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=qZ6A9NYn; spf=pass (domain: smile.fr, ip: 74.125.225.141, mailfrom: yoann.congal@smile.fr) Received: by mail-wm2-f13.google.com with SMTP id 5b1f17b1804b1-49e71cdb22bso873775e9.2 for ; Thu, 17 Sep 2026 15:08:02 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1789682881; x=1790287681; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=aUbTIDP8lBEomyLSty1uw/lmOFt9uMJIXpUqVu5GPNU=; b=qZ6A9NYnhKuVFNA7pyYG97y3ApaeLr6NyhxJ4rOJrjZQnh6BhxTFNRgGdDjEHU6PDs 0HcT7z7OeaZhbPGvzWMFymoGBj/1SCwL/yzQEcbHDdr4+FXkZy5WS7ZyDKLzZyqAnS96 /YVLtlgZtvVwbL2no344bmXjLhOhhu/JxpWjo= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1789682881; x=1790287681; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=aUbTIDP8lBEomyLSty1uw/lmOFt9uMJIXpUqVu5GPNU=; b=cOldyvv0ZnWoN45wBinnh8E5d/pz32Cld/rgfgwD0fb1N2/cSxvYFV/ZeiIGS/Ggt4 xaylAtiPGw/p/mhlOCsCXrJO2y45wVHYEBB73SkL8Vs6b8Di6BQjRaPXJy7FkzKontu+ AAsw77TrL+ZdBf/BCQc+QyAuY3hF4uIs0/beiXAiee9R8y6G4kLsRSlF0oSTU/a2A8B+ gQYS6mCMW8La9erznIef6+uZmepa6FpPYCvFNclFmuy57FKBukFChw8Fvtf8TeU7UMln ggTQNnJhzFNdrb9v1SUZpO5vqF855ITGw0esiatpnqrXzkl48i2eAHFennxNIn/1YZ+a D7gg== X-Gm-Message-State: AFuF++mSEsaoexBlM7Pn6ne7AgZSLcFMok1EUt7+PBufc4qrwq1w5xUX FKMacaFwzzWju3AdvIPVidngozFDTn2kv/Qs0nqZRqUz0BnCmFFK+n3WfCpHTz+rdxVJOtZHOE/ zgUEnJow= X-Gm-Gg: AYBFou3mn9T1Mx+OAPEIABCjYYoYV0kvFmQNf6u2Z8p39kOk05iALlm/HL5kgFeI95P qeD1D/4btFQA/kFOrTUUBFmjWZ9bjSYX1KQob8yn8nADkaO4GtF5sjxy0AmUsJFNaaBye28wfJx /fFfaOzGTmnzCX5lGO1nknbzJVy+4gdHvLlXAxstbRLxvZyEYvzoyTZi5oL9LYQVGWzx+/PClKR 2ZGe5Z6Ms8cXqd1Oe40wVKOu5/UuJs8TeA2Tbs91IGumojByqLIhEgufcoFegNgKQTFFELD+ayV EocOvUFHIAOLXyIIzdOQzaksuoQccBZA4C0m9KMDpZlyykiygtL0B4G8yBnHsadhvX/NEQxHYn7 1SuNtyYxp4XUSNCisTCq7LsnQ+UbdUuNgaKKNC5wop1RsZtmvdX0X4SFNDD4zW4fQMlco6zfmqO Q84hhTirE2X4QZ+qop+YngR//7ILSbasS7q/mNSxNDLJOApsgpAI2WomavsVQopriixZCao9oQV rvC21cGzJaAQylsZQFx782O9aOGM31SukVKH//rrn+Pd8GQ1kkq+usnDxNpPneMRVoCV2Od5j3E ms41mFZZtw== X-Received: by 2002:a05:600c:6211:b0:49c:fa20:cbfb with SMTP id 5b1f17b1804b1-49fc5728f84mr2888465e9.18.1789682880850; Thu, 17 Sep 2026 15:08:00 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-49fc471b9a2sm8984075e9.0.2026.09.17.15.08.00 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Thu, 17 Sep 2026 15:08:00 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][wrynose 23/79] sbom-cve-check-update-cvelist-native: update to version 2026-08-03 Date: Fri, 18 Sep 2026 00:06:08 +0200 Message-ID: X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Thu, 17 Sep 2026 22:08:04 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/246118 From: Benjamin Robin Update cvelistV5 to the CVE database from 2026-08-03. Signed-off-by: Benjamin Robin (Schneider Electric) Signed-off-by: Richard Purdie (From OE-Core rev: 25e68deb8178f7021605a39fa85acea04a375372) Signed-off-by: Peter Marko Signed-off-by: Yoann Congal --- ...23.bb => sbom-cve-check-update-cvelist-native_2026-08-03.bb} | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) rename meta/recipes-devtools/sbom-cve-check/{sbom-cve-check-update-cvelist-native_2026-07-23.bb => sbom-cve-check-update-cvelist-native_2026-08-03.bb} (89%) diff --git a/meta/recipes-devtools/sbom-cve-check/sbom-cve-check-update-cvelist-native_2026-07-23.bb b/meta/recipes-devtools/sbom-cve-check/sbom-cve-check-update-cvelist-native_2026-08-03.bb similarity index 89% rename from meta/recipes-devtools/sbom-cve-check/sbom-cve-check-update-cvelist-native_2026-07-23.bb rename to meta/recipes-devtools/sbom-cve-check/sbom-cve-check-update-cvelist-native_2026-08-03.bb index 0e664d89e07..aa21b06953e 100644 --- a/meta/recipes-devtools/sbom-cve-check/sbom-cve-check-update-cvelist-native_2026-07-23.bb +++ b/meta/recipes-devtools/sbom-cve-check/sbom-cve-check-update-cvelist-native_2026-08-03.bb @@ -6,7 +6,7 @@ HOMEPAGE = "https://github.com/CVEProject/cvelistV5" SRC_URI = "git://github.com/CVEProject/cvelistV5.git;branch=main;protocol=https;destsuffix=" SBOM_CVE_CHECK_DB_NAME = "cvelist" -SRCREV = "7a274ec07043f54c07d0a3b5c7fc89ba5793f023" +SRCREV = "b160e6f2915ac726b29ee0689fc920f5016abef5" UPSTREAM_CHECK_GITTAGREGEX = "(?P.+)_baseline" require sbom-cve-check-update-db.inc From patchwork Thu Sep 17 22:06:09 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 98582 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 0D549C982E1 for ; Thu, 17 Sep 2026 22:08:05 +0000 (UTC) Received: from mail-wm2-f12.google.com (mail-wm2-f12.google.com [74.125.225.140]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.1575.1789682883361266857 for ; Thu, 17 Sep 2026 15:08:03 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=ceVUdxHt; spf=pass (domain: smile.fr, ip: 74.125.225.140, mailfrom: yoann.congal@smile.fr) Received: by mail-wm2-f12.google.com with SMTP id 5b1f17b1804b1-49b912e2406so557385e9.1 for ; Thu, 17 Sep 2026 15:08:03 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1789682882; x=1790287682; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=B2TpUqkD2mDSrK/nsQLWiVHbmbWQyLRorNHmLTBNucQ=; b=ceVUdxHtGe0CVguu6lPuz+E0oNfW/P3jXeM+BWSluqvauXZTBHf2nMiEcgkk16XT3D yUJnFKIjl0BwHDP4Fou0XFQM3TXQl+1tafw+GKdWhFO526hUV/3/m+a0WTbPtbtPiydD max0iPP6kI2nLIBYA94xWOVMdR7GDcx4P7PAw= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1789682882; x=1790287682; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=B2TpUqkD2mDSrK/nsQLWiVHbmbWQyLRorNHmLTBNucQ=; b=TPsB9LH/sxMWavmbMYBgR+m3Kg9JgeeA7wUNsjMWL2QPB3buAemYva1gNxwIpluCm2 NiYZO9oe/+cQluUWeIqmtDQJS4UpRGppN6Z7lJuSMrHyZgohYaf/sYF7WLRxnVc/CClv L5lGNBnc5eujwViVcYf57RQXkMcKq9QiXGbS1ET6Sh4kglGLxz40PGevfIB01cB02ZCb cSxPv/xKQOYT9vqf4vU475DotFJFdr3czNLqf7n/8AeiCtDeMp9KOl93IdsgfAPhCfw+ 3zFogJl+i0OByldV/lHCgQlUJAwliOrNsbyg6OZgY3Gchh2EXG6q/M4imrFflvWT7Pfw NN6g== X-Gm-Message-State: AFuF++kEjKF1hm89vzd29QsAikOXrq6/vP8KACoH2wjXPVLpVB7xQQHb scyXWagfPUCH1Fw0E0g4n1v/vvbN1m/agURgtSRzt2VxpqgCK9r1Z/ld5Q+yEc5XNFRdyq1FX0+ aE4Mu3AE= X-Gm-Gg: AYBFou3NQSzb6nlKaK+f8b1HEftNZDcxVdxavOb/V6PQtZC0c8SN47fhKlTHWDnYxsg wKj9qi/GCWwj6Vd+ZGqgS5YUQ/N34ic3o/I1JMcEIVPUOkX8JTOrFSQD6rIa5WVUKVmphurVrGS vGCNVHYTfz2/fYedYPbLu78DWmgbiOdlRHvtS2/5yL6bcUu/bG0JdlzPgfdlEQ27Te72Tmw/W6i m3Pv9wPuyxPvU6dpgT6peC1R8fnj0YCW+k3q/rF0sGX4jlb8cMrN0v+NEGWx28x0cf9DN1zmgHJ 1gfjZop5aAf9PTWR3G2IDNJlbRzzAObg0MVBrxRB2WR8iYrxfawqvtDC3piRggujzGNaUVHaHbH X7GxI0XG00YKKWgukQq8Gi9n28gKXBggY3pEEGVm+aKjQNGVqiyg4El3GSeOfY95nI3uVWoJnnh c8xfyEFxk8rc81TlI7nBFNLZ+vymX6rsBxraqgXLML37gILWbkLMwPz6fv0hY+UZT9BETthT8Bn n1WE11M1OIHjEh6aDkOHeHBD/14UGKcBOZi2fs6gyFhTdl+sufu8YUTmFTRzSpUK1GZoAgWBMe2 X-Received: by 2002:a05:600c:3510:b0:49e:6836:5386 with SMTP id 5b1f17b1804b1-49fc4eef2dfmr5700375e9.0.1789682881610; Thu, 17 Sep 2026 15:08:01 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-49fc471b9a2sm8984075e9.0.2026.09.17.15.08.00 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Thu, 17 Sep 2026 15:08:01 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][wrynose 24/79] sbom-cve-check-update-nvd-native: update to version 2026.08.03-000011 Date: Fri, 18 Sep 2026 00:06:09 +0200 Message-ID: X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Thu, 17 Sep 2026 22:08:05 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/246119 From: Benjamin Robin Update fkie-cad/nvd-json-data-feeds to the CVE database from 2026.08.03. Signed-off-by: Benjamin Robin (Schneider Electric) Signed-off-by: Richard Purdie (From OE-Core rev: 5928cf1985d65b5dc7a909df596d7ff91533fccd) Signed-off-by: Peter Marko Signed-off-by: Yoann Congal --- ...bb => sbom-cve-check-update-nvd-native_2026.08.03-000011.bb} | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) rename meta/recipes-devtools/sbom-cve-check/{sbom-cve-check-update-nvd-native_2026.07.23-000007.bb => sbom-cve-check-update-nvd-native_2026.08.03-000011.bb} (89%) diff --git a/meta/recipes-devtools/sbom-cve-check/sbom-cve-check-update-nvd-native_2026.07.23-000007.bb b/meta/recipes-devtools/sbom-cve-check/sbom-cve-check-update-nvd-native_2026.08.03-000011.bb similarity index 89% rename from meta/recipes-devtools/sbom-cve-check/sbom-cve-check-update-nvd-native_2026.07.23-000007.bb rename to meta/recipes-devtools/sbom-cve-check/sbom-cve-check-update-nvd-native_2026.08.03-000011.bb index cf35b169235..720b5ded0ac 100644 --- a/meta/recipes-devtools/sbom-cve-check/sbom-cve-check-update-nvd-native_2026.07.23-000007.bb +++ b/meta/recipes-devtools/sbom-cve-check/sbom-cve-check-update-nvd-native_2026.08.03-000011.bb @@ -6,7 +6,7 @@ HOMEPAGE = "https://github.com/fkie-cad/nvd-json-data-feeds" SRC_URI = "git://github.com/fkie-cad/nvd-json-data-feeds.git;branch=main;protocol=https;destsuffix=" SBOM_CVE_CHECK_DB_NAME = "nvd-fkie" -SRCREV = "64a0cea215628d780438fba8bfe0f3300db1b702" +SRCREV = "b9f52bb052695dac5cabbd58e049eaac73697161" UPSTREAM_CHECK_GITTAGREGEX = "v(?P.+)" require sbom-cve-check-update-db.inc From patchwork Thu Sep 17 22:06:10 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 98574 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 473A4C982D2 for ; Thu, 17 Sep 2026 22:08:04 +0000 (UTC) Received: from mail-wm2-f13.google.com (mail-wm2-f13.google.com [74.125.225.141]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.1576.1789682883881137942 for ; Thu, 17 Sep 2026 15:08:04 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=fcXmtem7; spf=pass (domain: smile.fr, ip: 74.125.225.141, mailfrom: yoann.congal@smile.fr) Received: by mail-wm2-f13.google.com with SMTP id 5b1f17b1804b1-49e6c0fce17so584995e9.1 for ; Thu, 17 Sep 2026 15:08:03 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1789682882; x=1790287682; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=IUtyKV6f29lo29VlsDpRewdngBnzoZNi97G/PcnO8bg=; b=fcXmtem7IR/hJ/hjHBh3QJir9OqmPvGRr/LK4bP/47gXp7B8mIPcSdOZuwvKjf9V50 EuCbWd+SzV7CMKrsS4H2QXV2jculTaTXeaOztF2oBSKgp3hxD9lksy0PfR+eKlnPFRVO 3+wTKk6ncSKklEkaxlaleV8Qu0m4BE4rVQr5g= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1789682882; x=1790287682; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=IUtyKV6f29lo29VlsDpRewdngBnzoZNi97G/PcnO8bg=; b=u2i0cAS9+n8xUSYTqi1I5ZqZnvIr2T5JZyULgf4/05CV3siPV8iqJSq9Pj8mNUOdjz 3LJ4TNlr+dAQkwEWP3zjCz3CG4Yt0L+LWxkX2SBQCxzOygtxdUtsL2OBm3a7YSlxmZq6 rerVP4HCFwJbqReITSKDDA0/kqWD4d6D1qiWVO1TnSk1kZHoTed3LU3audMO5rzyFbOc relgto3PPJ+SeiElyb/AyCoz0rhk/iz4NH0ojlkrEPmnRU63OI9YH4ykpl/1kU7e64HC 135AtiVUjjDLcJIfbznIaY5Nbt0f100cHh2kjtYNkTdE1FyZtw0jFeG3K3V3G0mZ/bQ7 UUVg== X-Gm-Message-State: AFuF++mbb/kHwMJ65hkioldJbD97B0Hb5Ls+aypUjy1V8nACGjwvwObg dKXkoKF07XCtUFvQ6f/6p8ukgn7Ol+xEkI6yLyOUxTbllx2q+YMGDg7mH7C9jfG1p6H9TPYzLlg WpBQhF5c= X-Gm-Gg: AYBFou0Bz0o6r4S7dRqi5F12fhqB3YXOQY9B9KNESr58Ya0QAiJavzaGl8nkVotNMzI l/7IKHrnGBuetPub01yOd5pwdUrMyYnxTFofH/OPgIxFRpRAcWF99pTSpgFujBbR9Qh4XIVxsLw ysyc9uqxqbSjhMD1w76nrcFdP02E6VUTWjr8nOpf2q+D1XcXf30ubYuPaYGxZ9iPxzexYpf3hHv 2oMrtL+hIKajacsW0zYZrvteKsE7/gYopznG8QAKNTCbSBlRNVZLh8fAsgqO8rl052KQaN/G/AL HZRBJ+Mq0eES9q25IjGtP0I5354rynPbugFXFO7XO5eZQuFZVSr7LnP1zuGY2IMGcMU/57BeykJ HNCkLMHaEZlBlhTN3Ci5sAPWilzMeMH38ZMI6jtzkTre3AqZsCrZzCgkE+r0CqQvsdmmIaa+Ufo 9bDqK5Na8JA0iha4J744lt8Z1SRFzSWd1bmQhbheVKC6idG5UgnrMqixUEBu5Z9Rqwf3lptuNet sD2CTN63pymCGLWT06t4ij88AneczrbrKw6dwKJGlcPcwPilGD2FbBSy9KMVBdshfdC1AkDs7DK pnTrCQ82xQ== X-Received: by 2002:a05:600c:4e48:b0:49e:6bce:b0f9 with SMTP id 5b1f17b1804b1-49fc574f4d7mr3110725e9.16.1789682882173; Thu, 17 Sep 2026 15:08:02 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-49fc471b9a2sm8984075e9.0.2026.09.17.15.08.01 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Thu, 17 Sep 2026 15:08:01 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][wrynose 25/79] python3-mako: correct CVE_PRODUCT mapping Date: Fri, 18 Sep 2026 00:06:10 +0200 Message-ID: X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Thu, 17 Sep 2026 22:08:04 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/246120 From: Devansh Patel The inherited "python:mako" mapping is not used for the packaged Mako source and causes its vulnerability records to be missed. Use "makotemplates:mako" for its historical NVD configuration identity and "sqlalchemy:mako" for the current NVD dictionary CPE, NVD configuration, and CNA affected-data identity. Backport note: this applies the metadata to Wrynose Mako 1.3.10 rather than master 1.4.1; the older release exposes applicable unpatched records. Signed-off-by: Devansh Patel Signed-off-by: Richard Purdie (cherry picked from commit 76fc2046d3f251af34dd04f8fdcfc0c1d6016380) Signed-off-by: Devansh Patel Signed-off-by: Yoann Congal --- meta/recipes-devtools/python/python3-mako_1.3.12.bb | 2 ++ 1 file changed, 2 insertions(+) diff --git a/meta/recipes-devtools/python/python3-mako_1.3.12.bb b/meta/recipes-devtools/python/python3-mako_1.3.12.bb index b2c1a8dad8d..48f660870e7 100644 --- a/meta/recipes-devtools/python/python3-mako_1.3.12.bb +++ b/meta/recipes-devtools/python/python3-mako_1.3.12.bb @@ -10,6 +10,8 @@ inherit pypi python_setuptools_build_meta ptest-python-pytest SRC_URI[sha256sum] = "9f778e93289bd410bb35daadeb4fc66d95a746f0b75777b942088b7fd7af550a" +CVE_PRODUCT = "makotemplates:mako sqlalchemy:mako" + RDEPENDS:${PN} = "python3-html \ python3-markupsafe \ python3-misc \ From patchwork Thu Sep 17 22:06:11 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 98592 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 00803C982ED for ; Thu, 17 Sep 2026 22:08:06 +0000 (UTC) Received: from mail-wm2-f13.google.com (mail-wm2-f13.google.com [74.125.225.141]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.1676.1789682884514637638 for ; Thu, 17 Sep 2026 15:08:04 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=hltglKY6; spf=pass (domain: smile.fr, ip: 74.125.225.141, mailfrom: yoann.congal@smile.fr) Received: by mail-wm2-f13.google.com with SMTP id 5b1f17b1804b1-49e66390995so564525e9.2 for ; Thu, 17 Sep 2026 15:08:04 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1789682883; x=1790287683; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=rKFwj9kFzbVkF5uCqrnDDK4YU9WmY6KLEpz71ZeMACo=; b=hltglKY6mImcN7XEGwbpZwddc00GYHHrQPBum4RHRej3HVDqoPKMvqw+bKkary+rHd QR2D6J0B6mbbBFjcQCq1h8BtQVH9bYInwC5S8umXDRpKgfqyEufAl/aM3nIscit72Aaa iVadzxmECbySQJ3GCZHiDsVekjOAYN8LTHeFY= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1789682883; x=1790287683; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=rKFwj9kFzbVkF5uCqrnDDK4YU9WmY6KLEpz71ZeMACo=; b=VZO8jdYnEjzznupI+khfXSC57CboQ2V+i1OHqMgRbz5Ipue1hH6WiIzwuitVd4/ubN 9MK7G5/ZTt/QBBSN5iBtS6RIh9A37VRw6FBtAs7uDwDMfaiOMXGVw9W3wBrgvSkN2Qkd 4DYXnQzA8PL5mQ10S/lcF/ZuJ+mPe3B224cF5Dk8WMufA71yizAjjlpxv4Xd7eLQNBiq bFYqvCXm9QwSAdgrmXXyiJYmt3xmG5EnSP+EQkaesEi2326SLQ3/05eWbc+7lmLy8LKU Ydf1BO5bmm2bnUBubqLdXNdrTfmYm/mCgRZkaVJh/Q8f4/8+YPXwxviOGpNH3ZpIPyGh 9FLg== X-Gm-Message-State: AFuF++npyEjgZAJzMhTTjYOV7eBfVr0DnOYrzwCpSrSArPrr8pyXzC6E vaE5utbuO1zmTlzhzWZ2+2KPFtJHwOtsyA3KJDoKVynENYX1/8bL+7y80o58Z7M67J1N/bsLeEC WZxXEcF0= X-Gm-Gg: AYBFou2iMnI+r6t2/1PQKZ2ynPv1zkbJgEBe7C0jmRUMk1HW6lclzsneiC8pG71utfq /sEcgkDqGujdilvdBzAJSTtaeLrXm+d6z0bh9XLWCxX1CkC9VMcW0Vr3lRZ54P7Fe/gwvn/6qCw rzDb1ZSsWLfigb8hg1prhHDwh12Ia8Uti2pgj98rOgUMtoxqTKLNRHGX6TJ9oov+WRNpNNdSH/4 oTSngfT0shzC0k2HA6Wig2ILzx7DjKUWWk2FddSzNWB/fJpfMV201nlQLPYjMg0A8cgSa1FZmjb ynR/wpuU6bsJJuRktemiXVRnyxYsIyvU9TdVfFTTXwV9pq1QOgydxliLC9LylU3pjgKAZvoXS7u fq4ku5Tb5mUSJWZM7oZ5Y7sivWjZyCa+hE7WtiJVDSiDSBpJ3m6KRjATvd0sgxOiIedxL98lvav sJeGdMLm4u0+NkoG1yJ6KEcH3ZxUvFgyTEXsIfbVf6dQ0Yogz4OGZHMxDbeUKJH/NmLMa9gGkRK v524O9s8eYTkfoVHscdA0ZDxGMhQAFCCnLwZtl7rDkr0WdTbp5Qh8e9IohcHPw9VvWSiYxcaeY= X-Received: by 2002:a05:600c:1989:b0:49c:e42b:a4ac with SMTP id 5b1f17b1804b1-49fc5714d14mr3188365e9.11.1789682882744; Thu, 17 Sep 2026 15:08:02 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-49fc471b9a2sm8984075e9.0.2026.09.17.15.08.02 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Thu, 17 Sep 2026 15:08:02 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][wrynose 26/79] recipeutils: add optional stable_upgrade parameter to get_recipe_upgrade_status Date: Fri, 18 Sep 2026 00:06:11 +0200 Message-ID: <62a6faf3006d874cd3ad941c83dd8b0c9af0e018.1789681419.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Thu, 17 Sep 2026 22:08:05 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/246121 From: Chen Qi We want the ability to do stable version upgrades for recipes. To this end, add an optional stable_upgrade parameter to the get_recipe_upgrade_status function, which defaults to False and when enabled will try to get the latest stable version of the recipe. The UPSTREAM_STABLE_RELEASE_REGEX is respected. If a recipe sets it, it will be used as the filter_regex. If it's not set explicitly, it means that there's no stable updates or the recipe hasn't been checked yet. Signed-off-by: Chen Qi Signed-off-by: Antonin Godard Signed-off-by: Richard Purdie (cherry picked from commit 1ed8fdda035dcc21f3df71c0c996973224f4f683) Signed-off-by: Daniel Turull Signed-off-by: Yoann Congal --- meta/lib/oe/recipeutils.py | 23 +++++++++++++++++------ 1 file changed, 17 insertions(+), 6 deletions(-) diff --git a/meta/lib/oe/recipeutils.py b/meta/lib/oe/recipeutils.py index c6604f536db..7c1df518a8d 100644 --- a/meta/lib/oe/recipeutils.py +++ b/meta/lib/oe/recipeutils.py @@ -1009,7 +1009,7 @@ def get_recipe_pv_with_pfx_sfx(pv, uri_type): return (pv, pfx, sfx) -def get_recipe_upstream_version(rd): +def get_recipe_upstream_version(rd, stable_upgrade): """ Get upstream version of recipe using bb.fetch2 methods with support for http, https, ftp and git. @@ -1080,7 +1080,15 @@ def get_recipe_upstream_version(rd): except bb.fetch2.FetchError as e: bb.warn("Unable to obtain latest revision: {}".format(e)) else: - pupver = ud.method.latest_versionstring(ud, rd) + if stable_upgrade: + stable_release_regex = rd.getVar("UPSTREAM_STABLE_RELEASE_REGEX") + if stable_release_regex: + pupver = ud.method.latest_versionstring(ud, rd, filter_regex=stable_release_regex) + else: + # Not explicitly setting "UPSTREAM_STABLE_RELEASE_REGEX" means there's no stable upgrade + pupver = (ru['current_version'], None) + else: + pupver = ud.method.latest_versionstring(ud, rd) (upversion, revision) = pupver if upversion: @@ -1094,8 +1102,8 @@ def get_recipe_upstream_version(rd): return ru -def _get_recipe_upgrade_status(data): - uv = get_recipe_upstream_version(data) +def _get_recipe_upgrade_status(data, stable_upgrade): + uv = get_recipe_upstream_version(data, stable_upgrade) pn = data.getVar('PN') cur_ver = uv['current_version'] @@ -1119,9 +1127,10 @@ def _get_recipe_upgrade_status(data): return {'pn':pn, 'status':status, 'cur_ver':cur_ver, 'next_ver':next_ver, 'maintainer':maintainer, 'revision':revision, 'no_upgrade_reason':no_upgrade_reason} -def get_recipe_upgrade_status(recipes=None): +def get_recipe_upgrade_status(recipes=None, stable_upgrade=False): pkgs_list = [] data_copy_list = [] + stable_copy_list = [] copy_vars = ('SRC_URI', 'PV', 'DL_DIR', @@ -1134,6 +1143,7 @@ def get_recipe_upgrade_status(recipes=None): 'UPSTREAM_CHECK_REGEX', 'UPSTREAM_CHECK_URI', 'UPSTREAM_VERSION_UNKNOWN', + 'UPSTREAM_STABLE_RELEASE_REGEX', 'RECIPE_MAINTAINER', 'RECIPE_NO_UPDATE_REASON', 'RECIPE_UPSTREAM_VERSION', @@ -1180,12 +1190,13 @@ def get_recipe_upgrade_status(recipes=None): data_copy.setVar(k, data.getVar(k)) data_copy_list.append(data_copy) + stable_copy_list.append(stable_upgrade) recipeincludes[data.getVar('FILE')] = {'bbincluded':data.getVar('BBINCLUDED').split(),'pn':data.getVar('PN')} from concurrent.futures import ProcessPoolExecutor with ProcessPoolExecutor(max_workers=utils.cpu_count()) as executor: - pkgs_list = executor.map(_get_recipe_upgrade_status, data_copy_list) + pkgs_list = executor.map(_get_recipe_upgrade_status, data_copy_list, stable_copy_list) return _group_recipes(pkgs_list, _get_common_include_recipes(recipeincludes)) From patchwork Thu Sep 17 22:06:12 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 98594 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 181CBC982EA for ; Thu, 17 Sep 2026 22:08:06 +0000 (UTC) Received: from mail-wm2-f13.google.com (mail-wm2-f13.google.com [74.125.225.141]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.1577.1789682885150250086 for ; Thu, 17 Sep 2026 15:08:05 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=2pEpQztX; spf=pass (domain: smile.fr, ip: 74.125.225.141, mailfrom: yoann.congal@smile.fr) Received: by mail-wm2-f13.google.com with SMTP id 5b1f17b1804b1-49e79a408deso498985e9.2 for ; Thu, 17 Sep 2026 15:08:04 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1789682883; x=1790287683; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=v/I7oQDm02BS8pLXC2HfBgObX93p9V5NFryJGngLDso=; b=2pEpQztX9fpHyZ2SzQmfltdCWZRAgMjgCRsHSyX9Xw+U/8uv3VNrJEo60tVo1lozaY Xk7jOI29pcwlkKN1qoUkrvD3KYkj7bOkI73WFmkvCuuo1OndcsHZxB77HzHJdtlam1tU NaNACnFLd18dDxXjOp2Cbsw6OD1U9JBHHN+no= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1789682883; x=1790287683; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=v/I7oQDm02BS8pLXC2HfBgObX93p9V5NFryJGngLDso=; b=a1pMyVlV69CdeiZ1KFu57fStguWqGPMH4Mx2T0De/otmQgGm/gqDsRv5HCylwPsUDx 8X86Vt2un2X0PaiDjdZnHD4FvnSJ1N0a5qqRUYdx3iobWTz2uVBqyE6EjpuO4ufzKOGY ZpXBjsbT63JZ5Z6XmWh8eNHGMzARnQDPc7o3eRor+7pYVEfJ6aPW/3i4FNh28XXCBK0C 8V+njyTcHmjygBKMD3cNH8ZA/veurc5alkB4GmhW0dC+Cj0BehVd3arJd7C7/Bs1p6Cx 1Hja6/ebh+Es0KSbO/mYA21xN3ZxnTbS0l3+ozfPGiqBiKv+SbmJZ7ZHfkwTX/P3vn9v EMPg== X-Gm-Message-State: AFuF++l2kXcph3xZg8wUvpnPcGK/3TPJrvZQbbbyyuOXelCcXHF7cklj omqrDSdaybg28zDcEEPhUg+oyiC9aTSXgzEtWbCUWDx3I8h/yGm7Y8NZ5Eop65OFlrMm+9Z7z1L QR5IFSXU= X-Gm-Gg: AYBFou2FJOhMkGPYZmXe7m7ey1oreXwQQPFiYpYDGqQNipKI+1VzYVkiTNtJ20fpVrS 95QsabbW4HlZY8EPWkWQs73nX5TMv/nPH6hB+RuAaVHT7DX2ws6wudjPCyPzBwEn3tJoUsc/MO/ 2I9aEBShPHTqm4A2+C6DpQACOYfhCR/MZ0Hikmx+YOBAHHRFGXibBFqW1tUv3L3H9BS+R5xhPNi ue5l3w94FHp55JDLRz6oV+wGz3qKEqvZ5DEzjHsbN3vXd7ntLWYwo64KP0eTNuVLZe52MIZQAHi ElymvdzJymJ0Tqexs9Smz+sqW8TnZJEBINxT/uV62jD33ZigN6t2oM2GR7xPxm3vsIc3kSw5lpH /ZN0fxCOhQlU0ftbcD7cGMURtRw7hdYoMEJkjq9ZCxDvlq7hkh5ml/FytcR3FOmLz3IrKrlUecL slyyupR6cLqUZm6k1AAJTKGxSUMt0+rIrtmoSv5kY6Acr9LAf+DeKIGF/kQF/dUK4J1AHeN+zMe su+uzwJ2plcLBp33DuaTloalMZ/i3to+txISejSkIy8JRTIiJi4wdC+seP9YD3yj1d0AZtDaFc= X-Received: by 2002:a05:600c:8b61:b0:49d:e0c:e55e with SMTP id 5b1f17b1804b1-49fc574a635mr3448235e9.23.1789682883447; Thu, 17 Sep 2026 15:08:03 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-49fc471b9a2sm8984075e9.0.2026.09.17.15.08.02 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Thu, 17 Sep 2026 15:08:03 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][wrynose 27/79] lib/oe/recipeutils: make stable_upgrade argument optional in get_recipe_upstream_version() Date: Fri, 18 Sep 2026 00:06:12 +0200 Message-ID: X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Thu, 17 Sep 2026 22:08:06 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/246122 From: Ross Burton The change[1] that added the stable_upgrade argument made it optional for the high-level get_recipe_upgrade_status() function, but not get_recipe_upstream_version(). This function is exposed API so be kind to users and also make it an optional argument there. [1] oe-core 1ed8fdda035 ("recipeutils: add optional stable_upgrade parameter to get_recipe_upgrade_status") Signed-off-by: Ross Burton Signed-off-by: Mathieu Dubois-Briand Signed-off-by: Richard Purdie (cherry picked from commit 6f8ae1ecf38d85fe4464bef2954a86b6dc4f059c) Signed-off-by: Yoann Congal --- meta/lib/oe/recipeutils.py | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/meta/lib/oe/recipeutils.py b/meta/lib/oe/recipeutils.py index 7c1df518a8d..64bf2f950f8 100644 --- a/meta/lib/oe/recipeutils.py +++ b/meta/lib/oe/recipeutils.py @@ -1009,7 +1009,7 @@ def get_recipe_pv_with_pfx_sfx(pv, uri_type): return (pv, pfx, sfx) -def get_recipe_upstream_version(rd, stable_upgrade): +def get_recipe_upstream_version(rd, stable_upgrade=False): """ Get upstream version of recipe using bb.fetch2 methods with support for http, https, ftp and git. From patchwork Thu Sep 17 22:06:13 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 98595 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 1302DC982D2 for ; Thu, 17 Sep 2026 22:08:16 +0000 (UTC) Received: from mail-wm2-f12.google.com (mail-wm2-f12.google.com [74.125.225.140]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.1680.1789682886138291106 for ; Thu, 17 Sep 2026 15:08:06 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=iRfcJvhk; spf=pass (domain: smile.fr, ip: 74.125.225.140, mailfrom: yoann.congal@smile.fr) Received: by mail-wm2-f12.google.com with SMTP id 5b1f17b1804b1-49cd38e0e5dso1335365e9.2 for ; Thu, 17 Sep 2026 15:08:05 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1789682884; x=1790287684; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=ciD5AUiLNycPEI7ZpDiXJigUru3nXJ3Bi3lJmE3hwgY=; b=iRfcJvhkxJKcze1dwjNi9uo9zFQcQkWYYEnZGTaTCT2fNe65UhFYZm4S7v9FCEbXXq pMm/HCLhHCjdfHXo7XriOIsFiN8QxAq5/9DlstXxbQEpZJg7/Yvn/XNqy3ikGIe6Fdl/ 52xTvlCtP7Rem3BA4EgIFi/Hhl/WgAaMfgw2U= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1789682884; x=1790287684; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=ciD5AUiLNycPEI7ZpDiXJigUru3nXJ3Bi3lJmE3hwgY=; b=ih4Le6NG2ralfOsYw2AYSuZPlkrgPkSb9iZ2pl44Xhg55jALx5UgdXbajyc+vMw5wE nArOFHLWUGAZu8nzSh9+3omNulDmX8IIhkkKb6XBURPooqf3+xaQW15axfvA3dpmPfGH /1f/d492lImvxkh0rCdeC2JsZtpp1NdMSpb/9OBAMiRwWd3pPto+0P6Qk3/oib3gz9Ea o/4UJ+2V/UD1g+rcyS3JfM7czQiB9BtvVgJzZpcg5LiiaqzsYnc/JZbr7RL8eOh/2tHO kuwSNugPmnYhAp2cWYFGBnTddOv3vX0YOojX/4NrSEv4IDg6WziV7AH1JR8EV5uqZCOJ T/Sw== X-Gm-Message-State: AFuF++ngBXfB5B/qGgrGHLzDK/E+OHLTdN/ZRGjb6G53nQCUgtHMt3kp ELZxwG1PKmJ7jHcZH67j4YTU1SQAb1OlZUcrfiwksukCMmf6CVFoAd4rq2AJiHCEGCVox8qhU33 t+DU7nU0= X-Gm-Gg: AYBFou3ohNY7xyqzjswkcqMUKEjFMOucw5ghfMaZFYT3Fy3AC9UlIuE+yxpLAmJqvpz PqpV279nQ/dZu2COgJ+dQ245mslBWSyqsPTby6Tw0Iq+aDedvuvbF/OAXBNkLcMyqQQMT0MF90G AQu0DTrR7yw9mb+gpLRJk+IOqbWvUg3DzJ7po6Qzj50n0+zATO37zyb39PEbAptUXSehMdI34mE O2+a7TJmQvu1a76aXnolrb/CkyX9apeMLZPlnYD5Ieb2sqcT+dReQRJBdKP38c0okOxY8Jnn5hY lPvBQUarkB3uUACPPgwzUPsmXamdu/lPhHJ3Q6GU+FVz/Ak8UT5hurX2Mn16e4Up1qd0gWnoyX0 gfZBcaQc8rqm4O7f3fDqQw/zjUT8SN3VV7csGXcpvW0iOY3sIvsIj7j6sb8qAkWxjYTX8dLU1R0 QjhwlBp6Wm2cKwTH8nLzgAhWcySOm0a3QeBWlfDRjiva0xsIsw0/TarOf65ET+WfwocsRTQNKJW vF4MgE+wlliYdfTfQwnyye9vdeAauiy6fuvHJzzzCfbkEIzy1hJBq1F4uFWSwWKizjQiQeMnoc= X-Received: by 2002:a05:600c:4f86:b0:49f:bd3c:bc25 with SMTP id 5b1f17b1804b1-49fc574e7d3mr3345185e9.32.1789682884397; Thu, 17 Sep 2026 15:08:04 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-49fc471b9a2sm8984075e9.0.2026.09.17.15.08.03 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Thu, 17 Sep 2026 15:08:03 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][wrynose 28/79] upstream-stable-release-point.bbclass: add bbclass for stable point upgrade Date: Fri, 18 Sep 2026 00:06:13 +0200 Message-ID: <976e9d7fe13f8e8534de26a47a75c3d355437e84.1789681419.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Thu, 17 Sep 2026 22:08:16 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/246123 From: Chen Qi If a recipe can do stable version upgrade and the stable parts of the version is seperated by '.', then it can inherit this bbclass. By default, the stable parts number is 2, which means the following upgrades are stable version upgrades: x.y.z -> x.y.z+1 x.y.z+1 -> x.y.z+1.zz x.y.z+1.zz -> x.y.z+2 Recipes that have different stable version parts can also inherit this bbclass and set STABLE_VERSION_PARTS. For example, systemd sets this variable to "1". For recipes whose stable version part is not separated by '.', they should not inherit this bbclass and intead set UPSTREAM_STABLE_RELEASE_REGEX themselves. For example, openssh's stable part is separted by 'p' and should not inherit this bbclass. Signed-off-by: Chen Qi Signed-off-by: Antonin Godard Signed-off-by: Richard Purdie (cherry picked from commit a1e069d04cb13e990b362804bd56a4935338ef96) Signed-off-by: Daniel Turull Signed-off-by: Yoann Congal --- .../upstream-stable-release-point.bbclass | 21 +++++++++++++++++++ 1 file changed, 21 insertions(+) create mode 100644 meta/classes-recipe/upstream-stable-release-point.bbclass diff --git a/meta/classes-recipe/upstream-stable-release-point.bbclass b/meta/classes-recipe/upstream-stable-release-point.bbclass new file mode 100644 index 00000000000..98fdb5b808e --- /dev/null +++ b/meta/classes-recipe/upstream-stable-release-point.bbclass @@ -0,0 +1,21 @@ +# +# Copyright OpenEmbedded Contributors +# +# SPDX-License-Identifier: MIT +# + +# +# This bbclass is expected to be inherited by recipes explicitly. +# If a recipe's version is separated by point and we know for sure +# which parts of the version represent the stable part, then the +# recipe could inherit this bbclass. +# + +STABLE_VERSION_PARTS ?= "2" +def get_majmin_version_regex(d): + pv = d.getVar('PV') + stable_parts = pv.split('.')[:int(d.getVar('STABLE_VERSION_PARTS'))] + return r'\.'.join(stable_parts) + +STABLE_VERSION_REGEX = "${@get_majmin_version_regex(d)}" +UPSTREAM_STABLE_RELEASE_REGEX ?= "^${STABLE_VERSION_REGEX}(\.\d+)*$" From patchwork Thu Sep 17 22:06:14 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 98607 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 24C11C982E5 for ; Thu, 17 Sep 2026 22:08:17 +0000 (UTC) Received: from mail-wm2-f12.google.com (mail-wm2-f12.google.com [74.125.225.140]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.1681.1789682886586314741 for ; Thu, 17 Sep 2026 15:08:06 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=shMB/Gg3; spf=pass (domain: smile.fr, ip: 74.125.225.140, mailfrom: yoann.congal@smile.fr) Received: by mail-wm2-f12.google.com with SMTP id 5b1f17b1804b1-49b965f447cso893675e9.3 for ; Thu, 17 Sep 2026 15:08:06 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1789682885; x=1790287685; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=6znJAI08k6oTDYdM4U6eg9/6PHmDGP3afM3OydqPPwE=; b=shMB/Gg3fPaRdypwsiCcqdfPXNAnrw0Un+xzVvBqNYmGaSrUtelxUY++4+BEnAS+sn Klr9prNMruz0vWrev5WVV8OvXudXpeArzq9wRcJnnpIANjtajRln23WYqqTF6vCXGvIz XZvDGnR9xGgk2BlTROJOWfuPLUInBctR3wi8s= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1789682885; x=1790287685; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=6znJAI08k6oTDYdM4U6eg9/6PHmDGP3afM3OydqPPwE=; b=VAlHQLHYhj9bJVcngeLt8jC1NRyO+U/TAfUzjcwEcETj4daMZov3I++nzY52A3qOre 1uBU+oE1MKJ2w6Cq2q6m1MPC3LaYTGbKhZ+OhhOJV97oLp1B0XP5MiVr0zu/5MEGHf/H uHPpi8S6kc2X1+hsHToR75NONpqVp5haVo0MKh/J7OGpZqk2LYWpUumJ26dc0CeeT0bM +NpRNr6mQB64CcVWqyv4sgkqFGddLxAmBtg7PzmpCU0xrcyB6fjcj27IZVMtNBBpJx5W jb8OYUaMfmvRnemN+xiTXHwj1r8nTsDbVMUaf2QMKv97H/b8xdApZgJHk6vTo1J8UR6F cLeQ== X-Gm-Message-State: AFuF++kftXaRH7dxWdn2iqxrrALa+80n2OgQAaaswA1MT4r0PnbB6v3d 8nOSJhk3uIh9kgVV9o41bijybYRO0QbL8Kut4pfW4/u5NXSukLpstTaSqLgIAzttuek3GkxZ6v+ ZyRceEL8= X-Gm-Gg: AYBFou2p+P9THM3rmUkpb2ubCFArWWuXLoKyKaCqMfrRIG5u2RMEAruVfZKiPGgvjSS peTtMMFSXe58XgoXuqzQOG5sKnhthPd5lLml9RT7vneYVnk+hLsVK8nN4k5Gi6LHVD5GLkqMLqn I9N+PfweTZ9AjWY2HHtYAJjtFoImX7Kbr8hKmkQ3pE+SWHhB1VNeBrR8bOPhAAL3qMJJO/nhl7t t8uu4Tjk3f7wHLHpn1iC8dzAtyz8rlJ5Um3gmbc6Jz9gMVUDItS1SSl1WTQCp7DQnWDtJ1/hF5m 6PYRDZ3RxzfsAb06984HCvZjXFAGQFwbdPf+6h0Ncb2x5zZLYh2+gBelmdgNzASJHQoSrKI+8Vk AO8tDWEsb8OCOylSp91DsRWee/PH8WHIA5u1sUFJ0/QbmP7Vli15Ze0Hfy11cdK7HLScP01mdky iTEDMRXhSqMVMJz1EMSiTxMhz0XCPMtBdjmxzRfJFlh+GnYrisAg8jjYqmef6yv5cnTig3Zd6Ir kQBW2TSBodV1TE66Cnbwz9LQwSb/3TDjygH6nuUIIW+vcUeRfASUxI4up+X//BT5HXI2K4gSaA= X-Received: by 2002:a05:600c:1c20:b0:49c:fa20:cc07 with SMTP id 5b1f17b1804b1-49fc5741914mr3262675e9.30.1789682884883; Thu, 17 Sep 2026 15:08:04 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-49fc471b9a2sm8984075e9.0.2026.09.17.15.08.04 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Thu, 17 Sep 2026 15:08:04 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][wrynose 29/79] devtool/upgrade.py: add --stable option Date: Fri, 18 Sep 2026 00:06:14 +0200 Message-ID: X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Thu, 17 Sep 2026 22:08:17 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/246124 From: Chen Qi Add '--stable' option to the three subcommands: - latest-version - check-upgrade-status - upgrade The effect of this option is to make the subcommand only consider stable releases. Signed-off-by: Chen Qi Signed-off-by: Mathieu Dubois-Briand (cherry picked from commit 1e86aa039108621b2af734ef358a1e9d3c4d88d8) Signed-off-by: Daniel Turull Signed-off-by: Yoann Congal --- scripts/lib/devtool/upgrade.py | 9 ++++++--- 1 file changed, 6 insertions(+), 3 deletions(-) diff --git a/scripts/lib/devtool/upgrade.py b/scripts/lib/devtool/upgrade.py index 8930fde5d66..91cb85403c4 100644 --- a/scripts/lib/devtool/upgrade.py +++ b/scripts/lib/devtool/upgrade.py @@ -560,7 +560,7 @@ def upgrade(args, config, basepath, workspace): # try to automatically discover latest version and revision if not provided on command line if not args.version and not args.srcrev: - version_info = oe.recipeutils.get_recipe_upstream_version(rd) + version_info = oe.recipeutils.get_recipe_upstream_version(rd, args.stable) if version_info['version'] and not version_info['version'].endswith("new-commits-available"): args.version = version_info['version'] if version_info['revision']: @@ -626,7 +626,7 @@ def latest_version(args, config, basepath, workspace): rd = parse_recipe(config, tinfoil, args.recipename, True) if not rd: return 1 - version_info = oe.recipeutils.get_recipe_upstream_version(rd) + version_info = oe.recipeutils.get_recipe_upstream_version(rd, args.stable) # "new-commits-available" is an indication that upstream never issues version tags if not version_info['version'].endswith("new-commits-available"): logger.info("Current version: {}".format(version_info['current_version'])) @@ -649,7 +649,7 @@ def check_upgrade_status(args, config, basepath, workspace): "cannot be updated due to: %s" %(recipe['no_upgrade_reason']) if recipe['no_upgrade_reason'] else "")) if not args.recipe: logger.info("Checking the upstream status for all recipes may take a few minutes") - results = oe.recipeutils.get_recipe_upgrade_status(args.recipe) + results = oe.recipeutils.get_recipe_upgrade_status(args.recipe, args.stable) for recipegroup in results: upgrades = [r for r in recipegroup if r['status'] != 'MATCH'] currents = [r for r in recipegroup if r['status'] == 'MATCH'] @@ -673,6 +673,7 @@ def register_commands(subparsers, context): group='starting') parser_upgrade.add_argument('recipename', help='Name of recipe to upgrade (just name - no version, path or extension)') parser_upgrade.add_argument('srctree', nargs='?', help='Path to where to extract the source tree. If not specified, a subdirectory of %s will be used.' % defsrctree) + parser_upgrade.add_argument('--stable', action="store_true", help='Only consider stable upstream releases') parser_upgrade.add_argument('--version', '-V', help='Version to upgrade to (PV). If omitted, latest upstream version will be determined and used, if possible.') parser_upgrade.add_argument('--srcrev', '-S', help='Source revision to upgrade to (useful when fetching from an SCM such as git)') parser_upgrade.add_argument('--srcbranch', '-B', help='Branch in source repository containing the revision to use (if fetching from an SCM such as git)') @@ -690,11 +691,13 @@ def register_commands(subparsers, context): description='Queries the upstream server for what the latest upstream release is (for git, tags are checked, for tarballs, a list of them is obtained, and one with the highest version number is reported)', group='info') parser_latest_version.add_argument('recipename', help='Name of recipe to query (just name - no version, path or extension)') + parser_latest_version.add_argument('--stable', action="store_true", help='Only consider stable upstream releases') parser_latest_version.set_defaults(func=latest_version) parser_check_upgrade_status = subparsers.add_parser('check-upgrade-status', help="Report upgradability for multiple (or all) recipes", description="Prints a table of recipes together with versions currently provided by recipes, and latest upstream versions, when there is a later version available", group='info') parser_check_upgrade_status.add_argument('recipe', help='Name of the recipe to report (omit to report upgrade info for all recipes)', nargs='*') + parser_check_upgrade_status.add_argument('--stable', action="store_true", help='Only consider stable upstream releases') parser_check_upgrade_status.add_argument('--all', '-a', help='Show all recipes, not just recipes needing upgrade', action="store_true") parser_check_upgrade_status.set_defaults(func=check_upgrade_status) From patchwork Thu Sep 17 22:06:15 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 98612 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 7E3A4C982E4 for ; Thu, 17 Sep 2026 22:08:17 +0000 (UTC) Received: from mail-wm2-f12.google.com (mail-wm2-f12.google.com [74.125.225.140]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.1682.1789682887083967564 for ; Thu, 17 Sep 2026 15:08:07 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=g/A8dOFS; spf=pass (domain: smile.fr, ip: 74.125.225.140, mailfrom: yoann.congal@smile.fr) Received: by mail-wm2-f12.google.com with SMTP id 5b1f17b1804b1-49e620fa473so733185e9.1 for ; Thu, 17 Sep 2026 15:08:06 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1789682885; x=1790287685; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=oKB21cRxL2ZAytd07ALg9b7O8F/e/35Tw0ZST+sWzmQ=; b=g/A8dOFSPupKLgTxDSXmjsbc+fUE48iiQMWQk+u+Mn22jk+sRwnD9M0j/42nbwC+o7 Wkhdz+ZeFw46/wbR2WY5yRdfLilUW7fUFU591ZTTYfzGqgehPOxQqdnFNgnP7XEDnKyL 6E4JcAJThFLSbTyptE0wRwBBqG75By1N61bpo= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1789682885; x=1790287685; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=oKB21cRxL2ZAytd07ALg9b7O8F/e/35Tw0ZST+sWzmQ=; b=W0cQ3dY8UDQb6nl+nyCSQLDaxLI0ZxodRYP5Jl3s+fsANIHiuyTprJL+wlSqRguRVw 4JYF8Qa3gZgm2FZdyu38Go8tPIfeWVF3mRnPcxmfPQ3TxcYPHS9+Z5yBvmSUuJClY6wY CSWYJUwUIBA5PulbauwnzaA42Ik0nEMP+IwvCsEqklg+TrsPZTmbj9wcO+SSq1+75GBh k3rBwpZTVVM8tmQeJTMhnOAFozi0+Vj6kBGzz6yAAlT3mHFfq+uYUTZWVNELtAVgKGEa VIR34JdpbpEPMmvAS1jjVlrh0ac2DsXwOhxTLPw9d7/IfNUHL2GQxyNoDUQ+QrW16W0+ NUwg== X-Gm-Message-State: AFuF++m+RfBaEZpcAowos2z9mFk/R9cYUzvIb+JDq3/pziAHMoJNLbIc 9HyKYtiT4VkFdROnggpZM8R2BwcpVBvaKNfjPc33HxUhKggcZowcchRFyNxSw2ews6N9FNF6TYe PoqhDqAY= X-Gm-Gg: AYBFou3X4FobuvBIiT3EI57AzqOpb0IvrbQh44mxICG9UU708RL/pZc9PoAYc7wCFQk Ftxd1It7ZRUXIIRU8AfdF0uIIan29u9FQfPmiTIh9vIDtvaVBZb1NNfaHIeZUpIXo2lfYvIk4hp gnUxTKGIhTAt7+fZz73V9p0w3xIvMVh/3ATpmER6XS/g3Cdyz90+uVfST3xW+in9/uUORSkmdks zBfCps7BOfkmRISRl97W6oJdfbfR+deJPeI56VQcWxQML3IoSe0skbnwNs+MbdVW8U1hmaat1N+ WKUovjLNoaJPKTRAR5/zELY418Ka0ppnkeFdiMHtRX766hM0xLljhG2q837rBc0GWNIpVYUnr7e w4/bA/xqKhwEhiyayIqCAQeU8zQ9hRQmx3iebZZCB58CCHSyvvyhox67Jo9J532EOIVoC3f3ott 8F5Wv5feDyfix++3ZODHvoRyMix85uztiHTdImXxd0b+G8c9h8bRziPCydVLd3mLp10F6ioQ3aA e7Gesd4aQXRJj5oyaKdAUL7PMeUjmEWFBAKgbxpSYIy1OvA2KEywtRx0Gbb5Ueg928HETsp+vXE tCCW01xCrw== X-Received: by 2002:a05:600c:1993:b0:49c:ffe3:2b3f with SMTP id 5b1f17b1804b1-49fc56dbc54mr3299435e9.3.1789682885373; Thu, 17 Sep 2026 15:08:05 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-49fc471b9a2sm8984075e9.0.2026.09.17.15.08.04 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Thu, 17 Sep 2026 15:08:05 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][wrynose 30/79] systemd: inherit upstream-stable-release-point Date: Fri, 18 Sep 2026 00:06:15 +0200 Message-ID: X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Thu, 17 Sep 2026 22:08:17 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/246125 From: Daniel Turull systemd's README ("STABLE BRANCHES AND BACKPORTS") documents per-release stable branches carrying backported patches. The current one, v261-stable, is branched in the main repository; the README still points at the systemd-stable repository, which holds the branches up to v255. The major is a single version part (261 -> 261.1), so upgrades within a major are stable point upgrades per the OE-Core stable release policy (ref-manual, "Stable Point Release Upgrades"). STABLE_VERSION_PARTS is set to 1 accordingly. https://docs.yoctoproject.org/dev/ref-manual/release-process.html#stable-point-release-upgrades https://github.com/systemd/systemd/blob/v261.1/README#L460 https://github.com/systemd/systemd/tree/v261-stable Checked the last point release for feature creep: 261.2 (Jul 23 2026), against 261.1 (Jun 26 2026): 277 commits, mostly fixes. NEWS files both releases under "CHANGES WITH 261" and gives neither its own entry. Four items are feature-shaped: refcounting, argument handling and JSON output additions, plus one new internal string-util flag. Those are small internal additions on a real, diverged stable branch rather than mainline drift, and none introduce a new subsystem: closer in scope to a security-hardening batch than a feature release, though broader than a pure bugfix release. These bumps are not free: the scarthgap 255.4 -> 255.13 bump was held for a v2 because TCLIBC=musl broke, and was merged once fixed. A point release being fixes-only upstream does not remove the need to build and test it. Already tracked this way on the OE stable branches, counting only bumps made since each branch forked from master: kirkstone 250.4 -> 250.14 and scarthgap 255.4 -> 255.21. wrynose has had no point-release bump yet. AI-Generated: Kiro with Claude Opus 5 Signed-off-by: Daniel Turull Signed-off-by: Richard Purdie (cherry picked from commit c19dd5b2afa61ca78dad0b65556ba66e83db57c5) Signed-off-by: Yoann Congal --- meta/recipes-core/systemd/systemd.inc | 5 +++++ 1 file changed, 5 insertions(+) diff --git a/meta/recipes-core/systemd/systemd.inc b/meta/recipes-core/systemd/systemd.inc index f107c4c5da5..bbcacf9deb5 100644 --- a/meta/recipes-core/systemd/systemd.inc +++ b/meta/recipes-core/systemd/systemd.inc @@ -21,6 +21,11 @@ SRC_URI = "git://github.com/systemd/systemd.git;protocol=https;branch=${SRCBRANC CVE_PRODUCT = "systemd" +# systemd publishes bugfix/security-only releases on its stable/v-stable +# branches (e.g. 261 -> 261.1). The major is a single version part. +STABLE_VERSION_PARTS = "1" +inherit upstream-stable-release-point + CVE_STATUS[CVE-2019-3815] = "not-applicable-platform: only applied to RHEL" CVE_STATUS[CVE-2026-40223] = "fixed-version: fixed in 259.2" CVE_STATUS[CVE-2026-40224] = "fixed-version: fixed in 259.3" From patchwork Thu Sep 17 22:06:16 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 98613 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 935CCC982E7 for ; Thu, 17 Sep 2026 22:08:17 +0000 (UTC) Received: from mail-wm2-f12.google.com (mail-wm2-f12.google.com [74.125.225.140]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.1683.1789682887636218133 for ; Thu, 17 Sep 2026 15:08:07 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=pKjwHN3B; spf=pass (domain: smile.fr, ip: 74.125.225.140, mailfrom: yoann.congal@smile.fr) Received: by mail-wm2-f12.google.com with SMTP id 5b1f17b1804b1-49cd4ba9f68so1479735e9.1 for ; Thu, 17 Sep 2026 15:08:07 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1789682886; x=1790287686; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=6H+DbirnZH19EmX/bueBv+FeZKJhwCKJfWGXnoK85gg=; b=pKjwHN3BxRc7InOru3De159DFivjul8Lx5yiOETHRz3sSXqmCLRaARe7I0PuwDtM+Z e5fRevDLhee/4Cme3h2OZy25nwKo26kBc2ZaXMPf9kc5NIRfCXuP28p9Yw6ktpXfeOrO TxG7qfjg0z2PK3goUwZejso3Vg3oEw0t2zjLc= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1789682886; x=1790287686; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=6H+DbirnZH19EmX/bueBv+FeZKJhwCKJfWGXnoK85gg=; b=1/klkdDpfT8gcoK/qgcTqnrtKvU8WAkKHJxAsYcoYFRTZLGUBLQwKbTb++p/bSM5/k ccLmFaurZGou8qN5EE595H/NbGJrIIlBDNufnN+BRFBfGfyJvU6G4Uh3/gtjuxyt1qbv MvUGskcu3epIrQTUHN0rpTRAsZHT6t0AgP/9tkDY8cSd02sA1IUz/6rzD+thURfdjW6s XVrf6V6dfzPxdTIfCW07NHhJnu9pZfLOHEOz4F5RGV1kVbphN/MgeFpm2bVimup6XqzH L//jovYUHFrwr9cUyXXqFczWiND44+9Ooz7Cwdhv32rdm3VwEgHQOB3U4529Abw1+/uB KyWg== X-Gm-Message-State: AFuF++nsDDhNRRGsOITVWT/6fZ4GX0dYH3Kf/lOejbbnlAmUvtAxd9Ye S/j4EHb46o572IijVHtlzfNQiPC7Aaok5y78KPnZsXjQGhBug0aZQjePdkkCBb12knmEZYwgQp6 MXwovsuQ= X-Gm-Gg: AYBFou1FUR6YaxRAM17UPLNHsi1WWwaxZkZm/yWZAQf3RoOGfJKA2fuRdr+YV8cJEUM 0Rw5JQrwR+PkTuC1zLbQFfxGCV1fNQSTh9ra/EDhRCkglrSiWeFzWVnkFDaTb1c6ydQlJkiWCmC tO+S42drIwyfd9/erKJpfizYUwG4YeDoZrZDmoZNc5cVJlruc8KoqtpRPDtNgCbUIwfKW5LFOqD SwdpONOXCKRS22NMN3pcqTHVjZO9+6VN7GwkTIQVkMWRp5g2Inun/lI0fAgAu0LugT+JHrNEK+4 LLkxAs69U9a0Ec9Df7xY7vzDeuBnOW0mqLh3s3nF8oBtTcRvci5ub5izqc8Ljs9sfSQf1XdTRbK bzb7wG3E/j8Y5BM8WaVKDyslwy83BtH/HDKKKg9gT9q1zM46RYQKUoXjooJh2ZjRSpbmLFaIUh1 zlkcr8L1k5GSzq46Nm6nYp5zOucUX938G6dwfZiYHnyWnTY9S/6t02WhVZRgWHbL9biIRXNOSJJ E66sa12zQcqlb31GCKi5z1WXI4xgFX0UBVXahxLVfG6JfedTl/gE6QhkKXu7rMPgqHGXANmwuUo zIgaiCgWLg== X-Received: by 2002:a05:600c:19d1:b0:49c:fed6:cd3f with SMTP id 5b1f17b1804b1-49fc5743bc4mr3224415e9.23.1789682885917; Thu, 17 Sep 2026 15:08:05 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-49fc471b9a2sm8984075e9.0.2026.09.17.15.08.05 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Thu, 17 Sep 2026 15:08:05 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][wrynose 31/79] glib-2.0: inherit upstream-stable-release-point Date: Fri, 18 Sep 2026 00:06:16 +0200 Message-ID: X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Thu, 17 Sep 2026 22:08:17 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/246126 From: Daniel Turull GLib's docs/backports.md states that only bug and documentation fixes are backported to the current stable branch, that new features and API/ABI changes must not be, and that micro stable releases are intended as drop-in replacements. So upgrades within a major.minor are stable point upgrades per the OE-Core stable release policy (ref-manual, "Stable Point Release Upgrades"). https://docs.yoctoproject.org/dev/ref-manual/release-process.html#stable-point-release-upgrades https://gitlab.gnome.org/GNOME/glib/-/blob/2.88.2/docs/backports.md#L18 Checked the last two point releases for feature creep: 2.88.2 (Jun 25 2026): entirely "Bugs fixed" backports plus translation updates. 2.88.1 (May 02 2026): seven fixes -- a GCC 16 miscompilation, a GRegex out-of-bounds read with security impact, and five further out-of-bounds reads. No API or behaviour changes. The series opened with 2.88.0 (Mar 16 2026), which must stay outside the regex as the feature-level release. Already tracked this way on the OE stable branches, counting only bumps made since each branch forked from master: kirkstone 2.72.0 -> 2.72.3, scarthgap 2.78.4 -> 2.78.6, and wrynose 2.88.0 -> 2.88.2. AI-Generated: Kiro with Claude Opus 5 Signed-off-by: Daniel Turull Signed-off-by: Richard Purdie (cherry picked from commit 8de7017a3161ffb04f36e9c6ba2f7ead402dc4a5) Signed-off-by: Yoann Congal --- meta/recipes-core/glib-2.0/glib.inc | 4 +++- 1 file changed, 3 insertions(+), 1 deletion(-) diff --git a/meta/recipes-core/glib-2.0/glib.inc b/meta/recipes-core/glib-2.0/glib.inc index d49ae131685..cad74f53f71 100644 --- a/meta/recipes-core/glib-2.0/glib.inc +++ b/meta/recipes-core/glib-2.0/glib.inc @@ -30,7 +30,9 @@ LEAD_SONAME = "libglib-2.0.*" GNOMEBN = "glib" -inherit gettext gi-docgen gnomebase ptest-gnome upstream-version-is-even bash-completion gio-module-cache manpages gobject-introspection-data +# GLib publishes bugfix/security-only micro releases on its stable +# (even-minor) series. +inherit gettext gi-docgen gnomebase ptest-gnome upstream-version-is-even bash-completion gio-module-cache manpages gobject-introspection-data upstream-stable-release-point S = "${UNPACKDIR}/${GNOMEBN}-${PV}" From patchwork Thu Sep 17 22:06:17 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 98596 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 24A3EC982D0 for ; Thu, 17 Sep 2026 22:08:16 +0000 (UTC) Received: from mail-wr2-f12.google.com (mail-wr2-f12.google.com [74.125.225.76]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.1684.1789682888147890687 for ; Thu, 17 Sep 2026 15:08:08 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=1lQKyLzy; spf=pass (domain: smile.fr, ip: 74.125.225.76, mailfrom: yoann.congal@smile.fr) Received: by mail-wr2-f12.google.com with SMTP id ffacd0b85a97d-482f6356256so13540f8f.1 for ; Thu, 17 Sep 2026 15:08:07 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1789682886; x=1790287686; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=sx5VEyQ8rwdvYdJ0qPc7noa8vHmysM5ALhBMD2Ld7aU=; b=1lQKyLzy8OvlEzdl1eLota7Y6XES+JB7a1rZ3IMLoDdhVcW0icu7tHnB0dNaBtwwpD HSSQzioz7B4rlD/ua6V+NBXneVRuzVSLe61y6uVohRanahBESYbKqZ1OBLa/HNv/aL2h K5y9uyjskal3pD3KDk5RqBO07LxmjkP2vcmjw= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1789682886; x=1790287686; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=sx5VEyQ8rwdvYdJ0qPc7noa8vHmysM5ALhBMD2Ld7aU=; b=yqiSJhmsNsaGK9kjDtZdlL9NHoIIDsmN0NbuR+/cI4QJpGrQxJUJyoJpcPMAWrAwFB /d/6FgwCRCzIMolOwLYarOIYuMDIoAJGL35+VGtoI8gyZeGEUFSPa5n7KQaceZ+ap07O WqQ0mzDbxy4EMDShORlcQt4ZdtNaD4H5ICaEWy6SM9I6x80g5jrVbuYApyHc63m+zTFy QOvcMQKoqbe7ulinym+aoanOyG0R6rBCnpn8l49o5THB8CRJHI86+Uekz3d0nhbA3ems wpnrPgK1s8+BgtbbtVeZsIm0k1pxu8i8OKn2cRBApmqLwP6YtIPw/xo3flseokAaVc2s eXCQ== X-Gm-Message-State: AFuF++nNsfaDkJhTRGmhsRG6WyhvEcysXWuoQSOauI1xeZ3j1wFozGXH 84pqcrY0hajU9zgRebmirx3T3Iyc8P8Pnc/O9/C2CI+kw4ngvxbZ2ouQ1TfDOccbLC4YIKyMZun sFnkK5Fg= X-Gm-Gg: AYBFou3UMwLcXagZ3BJ6u+sdOxUk3QHBEbtScaRrQcmL1BvzTuxP5X8zMP60lBAtGht cH91E8MOOhC++YPy8cJoIt6qSHTOfwiCCBaetbhEe8PcsSki8SFwF0Nm8QbD5aR1jIOcd+MmvR3 eNLF9IVoH8PQe2awnlMW0PmRKJj/Qn1vv3ZPaale/tNbdlcnyUtrQSjGZwCFyy9L9iSyUoccUTj 4UOs13/TMVmp2t/fDHcYRCCOfIOwtTtuDR4GNg8YZjnzuJBiN+qX5Ps3zjmCpA5oc+8dP9OKco3 1mNSyEDdksQrCTn1JVjnN2LAJIN4Dwnk6OeN0H3/haKWFz39eS8YV8SpxdaWQPrHxIw238zOeza rBphV8rbi8wl5EpPPvfYfH7CDLzQuMqsMCld83jbj7SI9qmnogcfZ9LX4CZlaU0uvSAXLc0/Na4 xxrD90U/kD4E9vN8mm/ez3Rj9JL/GowY+6s0RWAfT9lDkRznsmAYB0ifRzHFaNJ4HsYWL3X97By RInsRiBglI+OQm8ic38bhLrr1uvdbThIHvdYKZCCNs65HSF6rYI+gd2bRwP5oNNDn26J6NR/s2E I6DAcYW5PA== X-Received: by 2002:a05:600c:a49:b0:49e:6865:904e with SMTP id 5b1f17b1804b1-49fc500055cmr6239265e9.12.1789682886332; Thu, 17 Sep 2026 15:08:06 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-49fc471b9a2sm8984075e9.0.2026.09.17.15.08.06 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Thu, 17 Sep 2026 15:08:06 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][wrynose 32/79] dbus: inherit upstream-stable-release-point Date: Fri, 18 Sep 2026 00:06:17 +0200 Message-ID: <64c67ca44405f9757ec94c79477dd21a16e17227.1789681419.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Thu, 17 Sep 2026 22:08:16 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/246127 From: Daniel Turull D-Bus's CONTRIBUTING.md documents even-minor stable branches, currently dbus-1.16.x, that receive only cherry-picked bug fixes, so upgrades within a major.minor are stable point upgrades per the OE-Core stable release policy (ref-manual, "Stable Point Release Upgrades"). It also states that odd-minor development branches such as 1.17.x are not supported at all and receive no bug fixes, not even for security vulnerabilities, so only the even-minor stable series should be tracked. https://docs.yoctoproject.org/dev/ref-manual/release-process.html#stable-point-release-upgrades https://gitlab.freedesktop.org/dbus/dbus/-/blob/dbus-1.16.2/CONTRIBUTING.md#L65 Checked the only point release in the series so far for feature creep, the 1.16.x series having just one non-.0 release to date: 1.16.2 (Feb 27 2025): two items -- one build-regression fix for verbose-mode builds against libselinux >= 3.8, and a documentation update. No API or behaviour changes. Already tracked this way on the OE stable branches, counting only bumps made since each branch forked from master: kirkstone 1.14.0 -> 1.14.8. scarthgap has had zero point-release bumps since its fork and remains at 1.14.10; wrynose ships 1.16.2 as its initial version with no bump yet. AI-Generated: Kiro with Claude Opus 5 Signed-off-by: Daniel Turull Signed-off-by: Richard Purdie (cherry picked from commit 63948049e50abeda630fb716ea0ba97e71b4f7cd) Signed-off-by: Yoann Congal --- meta/recipes-core/dbus/dbus_1.16.2.bb | 6 ++++++ 1 file changed, 6 insertions(+) diff --git a/meta/recipes-core/dbus/dbus_1.16.2.bb b/meta/recipes-core/dbus/dbus_1.16.2.bb index 7425bd23642..1102a8660ee 100644 --- a/meta/recipes-core/dbus/dbus_1.16.2.bb +++ b/meta/recipes-core/dbus/dbus_1.16.2.bb @@ -5,6 +5,12 @@ SECTION = "base" inherit meson pkgconfig gettext upstream-version-is-even ptest-gnome +# D-Bus publishes bugfix/security-only micro releases on its stable +# (even-minor) branches. Odd-minor development branches (e.g. 1.17.x) are +# not supported at all and receive no bug fixes, not even for security +# vulnerabilities, so only the even-minor stable series is tracked here. +inherit upstream-stable-release-point + LICENSE = "AFL-2.1 | GPL-2.0-or-later" LIC_FILES_CHKSUM = "file://COPYING;md5=eb0ffc69a965797a3d6686baa153ef05 \ file://dbus/dbus.h;beginline=6;endline=22;md5=df4251a6c6e15e6a9e3c77b2ac30065d \ From patchwork Thu Sep 17 22:06:18 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 98606 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 90CE6C982DE for ; Thu, 17 Sep 2026 22:08:16 +0000 (UTC) Received: from mail-wm2-f13.google.com (mail-wm2-f13.google.com [74.125.225.141]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.1685.1789682888792726439 for ; Thu, 17 Sep 2026 15:08:09 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=AjH3qx98; spf=pass (domain: smile.fr, ip: 74.125.225.141, mailfrom: yoann.congal@smile.fr) Received: by mail-wm2-f13.google.com with SMTP id 5b1f17b1804b1-49e66390995so564715e9.2 for ; Thu, 17 Sep 2026 15:08:08 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1789682887; x=1790287687; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=rbpNkHUboRJzziIW1x2bVsRE7y3dZxseWouQ7boSMjM=; b=AjH3qx98NGtNbSranB/PGG7KCbX5tzoP/I8Ae6ox08dE4/5m4YXcTlFZplNrVCfTLt khWFgRl9lLFNi55L5J6hrzc6N1GWeBBuyPnV8tqSFjOdQw98DLVIORenR8pKQdrJLDf1 bMHReHqap1+J9JFgGSm6hpXmtKfDIsGQOzG7k= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1789682887; x=1790287687; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=rbpNkHUboRJzziIW1x2bVsRE7y3dZxseWouQ7boSMjM=; b=rRX9Tq5FFqgdLuxmBNmdBioXyLKhptaajAO/PnHjAnbaNsqGeAIR+RIm4+dpeA88uC hrm6d6uwom3xVTCjMJRaQBYt0eruEHGqlswQud19/5xde//lQuWX1mjhYLBQNPCjYyu0 kfSKn799U5xTbGgThXwvbW6MZgp+ht8yh6qPOvTFNv3g2PoqKv4+t2oiJAg8ZC7ZjgHf WF9Eq2p6lwKxgkkz1aH6xRJDSN7UyrNgxItN2XRyzJ4gfKlABXDp0v3dWzTDMCTTNdXz lP7FsBtl5R9maNjqB/Ku9S1aGaN4uBbxTJNJnRob2xwYny09mUXwAL1abJtTNezEXhWs hLFQ== X-Gm-Message-State: AFuF++lvHSH6tZXLX3aHPbBlaP9kLhN6GFxpnr89lbVEo9Siq/yElt2S n3oHGWVYZsZQHE5gD7xU0qIM3zh/bp5q4aZ88MwJy1S/XGF9LSsJm3dELjwby5WkSPr6jb3IbaZ FahkbnBQ= X-Gm-Gg: AYBFou3+SHlRn1//pGn767kPkQ9CHpbtZEnRai34sLiHyelYM5XwhVlqpKibjy+ABoe LQQzNKpi4Do8aoQ+PYfc/m4scA1iQaen/LeRXyr5y7ERAY3zeWhId1oboPOFjc4KrBltn/SfJjy S8Gy65DUY+cFxyNqqIQSmsAeZtea1tgABnHC23NWNIjG+vv3IT3radQt6PciPTVeyXmbr4u4zeq g/LtK0onQvBgMhLhWD5FK5zRSjWZrbsi5eHPH8DrFKMYGB6urPAqdHK0a4REE3zBP9lcHYkGVPR Mgdy5yJDZYDQwLC1tnfeqrzsLVo+P/Tbbb70w16oJR481ykxaQIjca6IhggXWSjkrhiEo5/Jqc3 3ETRSu0vs2msmIjm+y0hPuiu5ivrUWEQ2IkUPfhfaLfcZ+NjsyFA+Y7KCbiqyo39f5jhtXdojYg cS+HPuhaYYzq1q73/qcZ21J3unPyrmfxOgBUdTDiW+O3/ImDlZ39Fqa1cyIKmx+rSqV4Ojt33rr i1GCYKQaEBeR9nvuABH2/usWKSXw3fT9dvDdKArctm6PRLigTeLn+ksrUha/RYtYVaMivK5ZSwf 6Xf35PxeJw== X-Received: by 2002:a05:600c:3f0b:b0:49d:1df6:2592 with SMTP id 5b1f17b1804b1-49fc5750c61mr2695345e9.21.1789682886978; Thu, 17 Sep 2026 15:08:06 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-49fc471b9a2sm8984075e9.0.2026.09.17.15.08.06 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Thu, 17 Sep 2026 15:08:06 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][wrynose 33/79] xz: inherit upstream-stable-release-point Date: Fri, 18 Sep 2026 00:06:18 +0200 Message-ID: <280f13ad6578a8696750d5b8b573e8cb9a009d54.1789681419.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Thu, 17 Sep 2026 22:08:16 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/246128 From: Daniel Turull XZ Utils's README documents that an even minor (Y) is a stable series where the revision (Z) "is incremented when bugs get fixed without adding any new features". So upgrades within a major.minor are stable point upgrades per the OE-Core stable release policy (ref-manual, "Stable Point Release Upgrades"). https://docs.yoctoproject.org/dev/ref-manual/release-process.html#stable-point-release-upgrades https://github.com/tukaani-project/xz/blob/v5.8.3/README#L138 Checked the last two point releases for feature creep: 5.8.3 (Mar 31 2026): one CVE (CVE-2026-34743, a buffer overflow in lzma_index_append), one invalid-memory-access fix, build portability fixes for Windows ARM64EC and Hurd, and man page translations. No new options or API. 5.8.2 (Dec 17 2025): build portability fixes for four toolchains, a RHEL 9 kernel-bug workaround, and a resource-aware memory-limit default tweak that is a bugfix rather than a new feature. No new options or API. Already tracked this way on the OE stable branches, counting only bumps made since each branch forked from master: kirkstone picked up 5.2.6 and scarthgap 5.4.7, one bump each. AI-Generated: Kiro with Claude Opus 5 Signed-off-by: Daniel Turull Signed-off-by: Richard Purdie Adapted for wrynose: applied to xz_5.8.2.bb (upstream: xz_5.8.3.bb). (cherry picked from commit e336ba1ed32bc924dab329afe1d687e0382f1c87) Signed-off-by: Yoann Congal --- meta/recipes-extended/xz/xz_5.8.2.bb | 4 ++++ 1 file changed, 4 insertions(+) diff --git a/meta/recipes-extended/xz/xz_5.8.2.bb b/meta/recipes-extended/xz/xz_5.8.2.bb index 15eaa7a52f8..5e7ad1fc704 100644 --- a/meta/recipes-extended/xz/xz_5.8.2.bb +++ b/meta/recipes-extended/xz/xz_5.8.2.bb @@ -33,6 +33,10 @@ SRC_URI[sha256sum] = "ce09c50a5962786b83e5da389c90dd2c15ecd0980a258dd01f70f9e7ce UPSTREAM_CHECK_REGEX = "releases/tag/v(?P\d+(\.\d+)+)" UPSTREAM_CHECK_URI = "https://github.com/tukaani-project/xz/releases/" +# XZ Utils publishes bugfix/security-only micro releases on its stable +# (even-minor) branches. +inherit upstream-stable-release-point + CACHED_CONFIGUREVARS += "gl_cv_posix_shell=/bin/sh" inherit autotools gettext ptest From patchwork Thu Sep 17 22:06:19 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 98603 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id E191EC982E0 for ; Thu, 17 Sep 2026 22:08:16 +0000 (UTC) Received: from mail-wm2-f13.google.com (mail-wm2-f13.google.com [74.125.225.141]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.1580.1789682889293638223 for ; Thu, 17 Sep 2026 15:08:09 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=bl6j2FWW; spf=pass (domain: smile.fr, ip: 74.125.225.141, mailfrom: yoann.congal@smile.fr) Received: by mail-wm2-f13.google.com with SMTP id 5b1f17b1804b1-49d1fb0cf5eso867695e9.3 for ; Thu, 17 Sep 2026 15:08:09 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1789682887; x=1790287687; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=00cvucd+fmh7LczMzMFmlZdQ6IZRiaikukidt+xCfGQ=; b=bl6j2FWWztCGk2mI10ZM0mryEjneLy6aUBZIuoWVdU2pyUO6Ott/ECvpJE+qGpiMVE amPJ+THE5dIoaHTC8zRbCJr97Kk6YwruxqnsPgE+EMKKkUhbj7PTr6tWsUxu56HcFhN8 a+xIaXAu+uw6AuaQEGAcBbkFFDNu+7/iflKog= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1789682887; x=1790287687; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=00cvucd+fmh7LczMzMFmlZdQ6IZRiaikukidt+xCfGQ=; b=LsKeTxYCFcOiNqgZEXPMVpnGAVKUQIBRwfFr1fCl0djWE34NWj1E5IIXSBPQ0Dywwg 8eMK9Qc2tz5q1Td63lUwjbmdupAj/1OvpnbYaON481ggVDG8OMv5HGzq7fBJAFNuz+Q3 Sj6pyWXlzymkB7XpkllMt9nqrr/tDMzTiferDbzCM5/SoKBWP+ViaXKcc+YFpvnM+q8g NFo66PSQPoO6kaTCQwfiHnPEOgtBx+WGko2niUv7TP+6ZJ4L1EhuurebkAy6c1691BoW lFNr5P5uWcMn/Svd4qbKaiuJGK+JTtMw0shHQ0Sj8bDb7o61b6+uPE+Hc8NeJVnpAIpW kL5g== X-Gm-Message-State: AFuF++mEaaz/gw1CT9ozSNO6nvQBvGBWvDtiR+INtF5znMKTqgaaDJE9 ltk8sqPHc+FKJuPwKoh+HehbIwly8WXgu8EqveJqcHyuogXcat3t0S/kOYW7B+BFd3b84lLWfly NJvBARBs= X-Gm-Gg: AYBFou0Ap5x8tBw4uuG+O4XhhTc+DFRgnb/3wPssw8pwKI7QMFOlK2BIpMMV/Pd/t5B nVcJS/R/zzCs4yMUOUStPpLyTblkE/P49yNilEwmTzLh/HYUX2aNjCEwdpiq53PNKIvuxsNYWHk LeurGU3rT2NKHNdQhBCv2ZZaFlrhFoUhz21hYcAYDWyYSHw4qkAJz1djaufJSBpQhUdWG6mcCre pNPe2tsZacw34b6W9iSK68zFKkLKQ8RLAMFioCYS67s1Xo4/hLdk/Dlwxu3iie9XUD/gm5p7GTn 0BO9KI0ffVdhpyKD1Wn5MYx3fZEtR/xtZ122e6qIhVujW4evYKV5eEaZApynKHXwN+bV4a2GmlT KccND3Zin/n6XLLiY+vdE8qLVNVJsNQk8Lhm1HOTFDUwjWqIHBrH+glKUiA5KnpGQop29XmTddk Mf+zfDTgJbgDne4kZ+aAVXD+xGpoDN0IeyyjFllbIjaW3Vvp/7NWv03tTI1sDMB7DV7axfV+pLf DgXC5NIF5r5Dkr4ino8nRWeKggaA2NcC/k2okIO/eH3i9Oqud54eq2nigrx+YQ3nq0mccFHRf0Z yYTjOdK9zw== X-Received: by 2002:a05:600c:6095:b0:49d:17d4:aff2 with SMTP id 5b1f17b1804b1-49fc566e558mr3439985e9.1.1789682887516; Thu, 17 Sep 2026 15:08:07 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-49fc471b9a2sm8984075e9.0.2026.09.17.15.08.07 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Thu, 17 Sep 2026 15:08:07 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][wrynose 34/79] git: inherit upstream-stable-release-point Date: Fri, 18 Sep 2026 00:06:19 +0200 Message-ID: <9c0f52e6bff26c8115a428aedb4d4ad34c449987.1789681419.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Thu, 17 Sep 2026 22:08:16 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/246129 From: Daniel Turull Git's maintainer documentation defines the version scheme explicitly: vX.Y.0 are feature releases carrying bugfixes and enhancements in any area, while vX.Y.Z (Z>0) maintenance releases "contain only bugfixes for the corresponding vX.Y.0 feature release and earlier maintenance releases". So upgrades within a major.minor are stable point upgrades per the OE-Core stable release policy (ref-manual, "Stable Point Release Upgrades"). https://docs.yoctoproject.org/dev/ref-manual/release-process.html#stable-point-release-upgrades https://github.com/git/git/blob/v2.55.0/Documentation/howto/maintain-git.adoc#L47 Checked recent maintenance releases for feature creep: 2.44.4 (May 28 2025): CVE fixes only, seven of them, merged up from the fixes that appeared in v2.43.7. The release notes contain nothing else. 2.35.7 (Feb 06 2023): four fixes -- two libcurl portability fixes, and two symlink-escape fixes in apply and clone back-merged from older maintenance lines. No 2.55.x point release exists yet, 2.55.0 being the current tip, so this relies on the documented policy plus the historical pattern above rather than a same-series point release. The ref-manual admits that basis: a recipe may qualify on clear historical evidence that a class of bump is bugfix-only (ref-manual, "Criteria for Qualifying Upstreams"). Already tracked this way on the OE stable branches, counting only bumps made since each branch forked from master: kirkstone 2.35.2 -> 2.35.7, five point bumps, and scarthgap 2.44.0 -> 2.44.4, three point bumps. wrynose ships 2.53.0 as its initial version with no bump yet. AI-Generated: Kiro with Claude Opus 5 Signed-off-by: Daniel Turull Signed-off-by: Richard Purdie Adapted for wrynose: applied to git_2.53.0.bb (upstream: git_2.55.0.bb) (cherry picked from commit 4300d9a707ee6ae2012ee03b4f4efae38521863c) Signed-off-by: Yoann Congal --- meta/recipes-devtools/git/git_2.53.0.bb | 4 ++++ 1 file changed, 4 insertions(+) diff --git a/meta/recipes-devtools/git/git_2.53.0.bb b/meta/recipes-devtools/git/git_2.53.0.bb index 8d71905f419..5244891113c 100644 --- a/meta/recipes-devtools/git/git_2.53.0.bb +++ b/meta/recipes-devtools/git/git_2.53.0.bb @@ -48,6 +48,10 @@ EXTRA_OECONF:append:class-native = " --with-gitconfig=/etc/gitconfig " # Needs brokensep as this doesn't use automake inherit autotools-brokensep perlnative bash-completion manpages +# Git's maintainer docs define vX.Y.Z (Z>0) maintenance releases as +# bugfix-only, scoped to the corresponding vX.Y.0 feature release. +inherit upstream-stable-release-point + EXTRA_OEMAKE = "NO_PYTHON=1 CFLAGS='${CFLAGS}' LDFLAGS='${LDFLAGS}'" EXTRA_OEMAKE += "'PERL_PATH=/usr/bin/env perl'" EXTRA_OEMAKE += "COMPUTE_HEADER_DEPENDENCIES=no" From patchwork Thu Sep 17 22:06:20 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 98608 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 0D29DC982E2 for ; Thu, 17 Sep 2026 22:08:17 +0000 (UTC) Received: from mail-wm2-f12.google.com (mail-wm2-f12.google.com [74.125.225.140]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.1581.1789682889817872030 for ; Thu, 17 Sep 2026 15:08:10 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=0qeLZN41; spf=pass (domain: smile.fr, ip: 74.125.225.140, mailfrom: yoann.congal@smile.fr) Received: by mail-wm2-f12.google.com with SMTP id 5b1f17b1804b1-49cd38e0e5dso1335935e9.2 for ; Thu, 17 Sep 2026 15:08:09 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1789682888; x=1790287688; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=lO55akwutrxdqbJc8o8lw2d+NH2bNscmWPUSVMCkDkc=; b=0qeLZN418zL4Dvr9FVvPb8RkV3dHCIWK+GtbTsgsnAfGSYQywkL5v40f7EYt6L/8sl 1tBbfizSfmWUqBp6h6GmO+InC2wxwOgfqenTn3RtQCaBQliqfOMsPh2hpa32gxZ0grve wgu8lFa9RtZnP8B0vaQEOsK/ZRdK0BPMlOYjQ= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1789682888; x=1790287688; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=lO55akwutrxdqbJc8o8lw2d+NH2bNscmWPUSVMCkDkc=; b=TP2Cl7Pf3SQbLIbZ+TRAODyPrCxOdQpaOhHP2BYpr1pAZdLld5GLCBPK6wNMYOonop VCK7NyBhBUeEmD+4sdyhyVwnLDs+GWl+gz1FN1t2SLF4ty+SEYWtGIJR554nIkZXZDgc /9YBbzI/ns3r9589W+KU8Nkxg4yK/x5EfuzZ0Zg5ylFiRXC+dKkmgDN9WRB7UNHcoWzM z53u4+G2tEPtYgEOg1ewx+ORsoMJn8I+1NqS1dIlxxgV/mYO2a00DlAEZZ+BykOgi5Jo l+59lxgzg6DLuTRFPV3TDSZcgGFdOYF05E8OmnRbkXjanJZnRfaLElqrAjIhIOVwiFwX kltg== X-Gm-Message-State: AFuF++lSkzNnla2GnnKAajUPQZCekMaJMaGdQ/rHq3FfqOIl1FaFej2q VzYcGIBQ6Ehnu0EeTqzJOr/bqQx9jpXBSD30Jx9JKoiee1o5EKtiyW6hfAp4i0DhfQ3rvw7noUO GJLe5B/g= X-Gm-Gg: AYBFou0YkcG8x0B6jyVFymc+xCqmy/7PDwPWBHO9bIUXvoFu23UuXaC/4GUZLhR83M5 VhHJP4hKs/ja+o/QKT27OhGbsGGmBAxdcKa9RQ3xv71FZYy8Ihivb30Wz4rsZxnG2yZS/4fNzLf oCJPzOjl+sWtA1buyXlsXUzoXSxUpeDkhY/dZHDF4mx8jIxVysSqy07jvEAZC86nduR9MZiLHIW DZCLzQDdNLR5G2IJAJKMjyWIToAJrmiVnJlv1K36ZKAx8kRXDv38DsN99PnfT/VxY70KOJZEq6l h9pN61HGVolxx0DCmwPJ643HHjl7xGfcMu8y88ln8/wn3vIovz2RaXaMavg6g014IdxYFqI+VrT aWUwo2aJhXgqP40MPJ+WpQKEb5tZOXvtPTO8KwDeYuP6wf5igGbyg6VihczDv7XO2AjbvfnAbKA pR/jM7d1DkO3LA6qhPJ1vBGe6F8cTBnVUQHqRG9OzGp1A0fPn8S7Fk5HvfjOF6OSx7cKVOPX1s5 50XiJFgb6IcSspipytsccm+euNQ5qBNUM4gtvSCVDZz9DZubUyd8t1Qf/iUb8+ZvVBKTsR3ePY= X-Received: by 2002:a05:600c:4691:b0:49f:bd3c:bc1b with SMTP id 5b1f17b1804b1-49fc572f297mr3092015e9.22.1789682888070; Thu, 17 Sep 2026 15:08:08 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-49fc471b9a2sm8984075e9.0.2026.09.17.15.08.07 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Thu, 17 Sep 2026 15:08:07 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][wrynose 35/79] perl: inherit upstream-stable-release-point Date: Fri, 18 Sep 2026 00:06:20 +0200 Message-ID: X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Thu, 17 Sep 2026 22:08:17 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/246130 From: Daniel Turull perlpolicy documents a strict maintenance-branch policy: new releases of a maint branch may only contain security/CVE fixes, crashing bugs, regressions, build and install blockers, portability fixes and factual documentation corrections, and must not contain patches that "add or remove features", "break binary compatibility", or "add new warnings or errors or deprecate features". New dual-life module versions are explicitly deferred to the next stable series. So upgrades within a major.minor are stable point upgrades per the OE-Core stable release policy (ref-manual, "Stable Point Release Upgrades"). Long-lived per-even-minor maint branches back this up, maint-5.6 through maint-5.42, with a documented back-porting vote process. https://docs.yoctoproject.org/dev/ref-manual/release-process.html#stable-point-release-upgrades https://github.com/Perl/perl5/blob/v5.42.2/pod/perlpolicy.pod#L259 Checked the last two point releases for feature creep. perldelta makes this easy to see, as maint releases carry no "Core Enhancements" section at all: 5.42.2 (Mar 29 2026): one CVE in a vendored dependency, CVE-2026-4176 in Compress::Raw::Zlib, plus module version bumps. States "There are no changes intentionally incompatible with 5.42.1". 5.42.1 (Mar 08 2026): four fixes -- a Configure fix so POSIX locale values can be passed in for cross-compilation, an AIX thread-safe locale workaround, a Win32 build fix, and module version bumps. States "There are no changes intentionally incompatible with Perl 5.42.0". 5.42.0 (Jul 02 2025) is the series-opening release, not a point release: it adds seven language-level features, confirming X.Y.0 bumps are feature bumps that must stay outside the regex. Cross-checked the previous series the same way: 5.40.1, 5.40.2 and 5.40.3 all show the same profile, with security, module, documentation, test and bug-fix sections only and no Core Enhancements. The policy forbidding binary-compatibility breaks in maint releases also covers the ABI concern directly. Already tracked this way on the OE stable branches, counting only bumps made since each branch forked from master: kirkstone 5.34.1 -> 5.34.3 and scarthgap 5.38.2 -> 5.38.4 are both in-series point bumps. wrynose is still at 5.42.0 while master is at 5.42.2, so it is missing the CVE-2026-4176 fix -- exactly the tracking gap --stable is meant to close. AI-Generated: Kiro with Claude Opus 5 Signed-off-by: Daniel Turull Signed-off-by: Richard Purdie Adapted for wrynose: applied to perl_5.42.0.bb (upstream: perl_5.44.0.bb). (cherry picked from commit 73ae055e5a05078225226355f1545fc9e464e78d) Signed-off-by: Yoann Congal --- meta/recipes-devtools/perl/perl_5.42.0.bb | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/meta/recipes-devtools/perl/perl_5.42.0.bb b/meta/recipes-devtools/perl/perl_5.42.0.bb index 6f0092c1cc7..886eaaaa379 100644 --- a/meta/recipes-devtools/perl/perl_5.42.0.bb +++ b/meta/recipes-devtools/perl/perl_5.42.0.bb @@ -35,7 +35,7 @@ SRC_URI[perl.sha256sum] = "e093ef184d7f9a1b9797e2465296f55510adb6dab8842b0c3ed53 B = "${WORKDIR}/perl-${PV}-build" -inherit upstream-version-is-even update-alternatives +inherit upstream-version-is-even update-alternatives upstream-stable-release-point DEPENDS += "perlcross-native bzip2 zlib virtual/crypt" DEPENDS:append:class-native = " bzip2-replacement-native" From patchwork Thu Sep 17 22:06:21 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 98599 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 1FEFEC982E3 for ; Thu, 17 Sep 2026 22:08:17 +0000 (UTC) Received: from mail-wm2-f13.google.com (mail-wm2-f13.google.com [74.125.225.141]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.1582.1789682890395987619 for ; Thu, 17 Sep 2026 15:08:10 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=yU7YfmWx; spf=pass (domain: smile.fr, ip: 74.125.225.141, mailfrom: yoann.congal@smile.fr) Received: by mail-wm2-f13.google.com with SMTP id 5b1f17b1804b1-49b912df756so781335e9.3 for ; Thu, 17 Sep 2026 15:08:10 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1789682889; x=1790287689; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=QHhbQhUNFOO1C9WP2xLF7BGBdHH+UiyNe9NemMYy1aI=; b=yU7YfmWx9mzvNVbL8zMmJBFrT/j/KCLFH5jTnm3iuaWKWavMdcibtp13eOfWGJhE4Y 3J5QVdmbHFvWcgV34orqK8C1WgI7jJ77oN6dWjd4gbhnHj7qXjh5K4efp2fDSKUufe/Z n6OUDee3uul3jtgHVQztI2s/zxTBZwNbafuXs= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1789682889; x=1790287689; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=QHhbQhUNFOO1C9WP2xLF7BGBdHH+UiyNe9NemMYy1aI=; b=VgJqHXdTYasvIraKre6x/DDENuKm6hYOeBZB6fJ2HHdSUMaag0yvjOD/UiO2lbFlOm FoLh9wY5HnR8xDxc2eFeXKNcxlTx4J+jKD5kOB+erNrS3Rnnu4SByJ2o6VH/NVnCVKUm AV9vk1nsVItti0a4Ybj+XdUam0Czvvs/TfxXH+YzNQO11ZCwHklKVzRJ3tdtrIFpQbrR C/EuDitPl1KZuX7Fa2H87Ar4+vP8jPEBgETyfcSnTT9TKOk+jeQnOW6Jfr8IFNw152Yr 58rksMHwGr3CV4ZT1RjYZfQK0qXpJYZokEpu6iXZ5C4YHFJy9W3OpLkfNcCabCSPGp7x Ey6A== X-Gm-Message-State: AFuF++nx0yqIYYVbrpuYfZcs/D3WiQ+wwoXbCWBZiQP+H/FVi3hgWzR8 oEoUd7JGDjyU9cRsdDvxIt9KWRC2UmXIysIVarzWjYB0YOh+lygGGeJe16YB01A0v2W3Ke4PSDs x3CWUEsk= X-Gm-Gg: AYBFou2CF0+rNhR9r3YKsa/9lt6fRlF9+uyWUMAupDyWmHdmWrR4lXw2jTMptxr/M7C iY8nw0iu7sPfwwobtVvdEGfXS6HPR46aB0qmV0EG7cs4cb+T7MSqF/LnCIi1YRYQBj8tp0J6n4w z4FLx0c6lLhi6a5NSrjuKZhzetTMBvKbqAYSjA2R3+hpnhc5s0vO7OwOO9D040zjfSNEVw22oKZ XKSkpkhz+jeQZjP8mJ46EmeJxfw85Ia4ZoEFT/JCI61wVjAQORCvK8oGV3b5cBByAWQWdPc7LIb vxIgGoXacqG8kjFCtx0paoUUwJWXVf5Et1OYZKKXMmjIMtwhR8ZqUgs5LU9rZZMR78ZNagZXZ91 1CduodYrNtB7/wjeYpzu4Ibc9zyg6QhEAB1tOc3YiuM7O0k5R6ybbOnra3uAV86G5YHAXiAhUKw 3gSBJ3286b6RSRrdPFh1hRZFJv5LqkDC3JWEqwmGrGyqnDQz/EwHITN2Q0jDk2kSI/PblpIfn/M KZfJuwZVjF0fQOQ04TM3+VobKGfavlwE4EoABHCbftTP43tjeEGWz1ijWSRGNbINxunoi/G0FcD YCFDF+/ZPss= X-Received: by 2002:a05:600c:3e05:b0:49c:fc6e:8cb1 with SMTP id 5b1f17b1804b1-49fc5737ad0mr3260175e9.21.1789682888581; Thu, 17 Sep 2026 15:08:08 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-49fc471b9a2sm8984075e9.0.2026.09.17.15.08.08 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Thu, 17 Sep 2026 15:08:08 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][wrynose 36/79] libxml2: inherit upstream-stable-release-point Date: Fri, 18 Sep 2026 00:06:21 +0200 Message-ID: X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Thu, 17 Sep 2026 22:08:17 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/246131 From: Daniel Turull libxml2 maintains per-minor stable branches (2.9 through 2.15) that take only bug-fix micro releases, and releases from several of them in parallel: 2.13.9 and 2.14.6 went out the same day, after 2.14.5 was already out. So upgrades within a major.minor are stable point upgrades per the OE-Core stable release policy (ref-manual, "Stable Point Release Upgrades"). https://docs.yoctoproject.org/dev/ref-manual/release-process.html#stable-point-release-upgrades https://gitlab.gnome.org/GNOME/libxml2/-/tree/2.15 Checked the last three point releases. 2.15.3 (Apr 15 2026) is five security fixes plus an "Improvements" section that is also entirely fixes, and 2.15.1 (Oct 16 2025) is security, regression and build fixes. 2.15.2 (Mar 03 2026) is five CVE fixes plus one addition, a --xpath0 option confined to the xmllint command-line tool. A public-header diff across the three shows zero added, removed or changed libxml2.so declarations, so the library API and ABI are unaffected by that addition. Already tracked this way on the OE stable branches, counting only bumps since each branch forked: kirkstone picked up 2.9.14, scarthgap 2.12.5 -> 2.12.10. AI-Generated: Kiro with Claude Opus 5 Signed-off-by: Daniel Turull Signed-off-by: Mathieu Dubois-Briand Adapted for wrynose: applied to libxml2_2.15.2.bb (upstream: libxml2_2.15.3.bb). (cherry picked from commit a9fd7975e991124b8f54c4c763917e705fb4213c) Signed-off-by: Yoann Congal --- meta/recipes-core/libxml/libxml2_2.15.4.bb | 4 ++++ 1 file changed, 4 insertions(+) diff --git a/meta/recipes-core/libxml/libxml2_2.15.4.bb b/meta/recipes-core/libxml/libxml2_2.15.4.bb index fc367892bfe..896b33f2677 100644 --- a/meta/recipes-core/libxml/libxml2_2.15.4.bb +++ b/meta/recipes-core/libxml/libxml2_2.15.4.bb @@ -30,6 +30,10 @@ BINCONFIG = "${bindir}/xml2-config" inherit autotools pkgconfig binconfig-disabled ptest +# libxml2 publishes bugfix/security-only micro releases on its per-minor +# release branches. +inherit upstream-stable-release-point + LDFLAGS:append:riscv64 = "${@bb.utils.contains('DISTRO_FEATURES', 'ld-is-lld ptest', ' -fuse-ld=bfd', '', d)}" RDEPENDS:${PN}-ptest += "locale-base-en-us" From patchwork Thu Sep 17 22:06:22 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 98600 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id CB9FFC982E1 for ; Thu, 17 Sep 2026 22:08:16 +0000 (UTC) Received: from mail-wm2-f12.google.com (mail-wm2-f12.google.com [74.125.225.140]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.1583.1789682890887549551 for ; Thu, 17 Sep 2026 15:08:11 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=SjpsjS1u; spf=pass (domain: smile.fr, ip: 74.125.225.140, mailfrom: yoann.congal@smile.fr) Received: by mail-wm2-f12.google.com with SMTP id 5b1f17b1804b1-49d1ca5b0d6so930685e9.0 for ; Thu, 17 Sep 2026 15:08:10 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1789682889; x=1790287689; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=jetXS0VQ38xoVvVx165OIv3MztjEOThJrvyUD7qtNq0=; b=SjpsjS1uS3SX28GkmVItXSv+95Vp3OZGV8Ei8Y+vrp+i3GICZDlLO7wZ0KUTe6TOp8 05SsSGpok+2EPAbInoFK2AfdxGTnElGCBfOE3z3Mh60DxiqgG2qw3g2nOWxKR7ZQ4YcG JUBaZSZBhMvifKfpr95kHAP6neo2ZAlvm53Bc= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1789682889; x=1790287689; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=jetXS0VQ38xoVvVx165OIv3MztjEOThJrvyUD7qtNq0=; b=iKRq+g48oW5J/XpehU0e5aX00HlIdoxIlUvi2YixBHSLNS7KKNY94TckV5N1v8FVqM Y1pw5I6ofxMW4FBQ0M017Qdc88QT35soo2eB8HjbImDFh0/G6+v2N3gbAs2Ax0iPYMqJ WoOYBj9F+Te8tLHGyqVYDH6vEMa1EjXaW4ruKURedPKhOyjlr/GU7cTjHYbvnv8JrWt2 vv1KzIRdIxzuo4nQAZtWCsl+b2C+WVmprRwQ7oQA9BY/HTf8WAEOfq4SdBNz+0Eejv9p PX6MZAyFQtLKWkdA7a2EpBxczb0US/qyR0U7Sc2p9iQNGzgmw0BGQGJ4Fd16N4U9CEqO uZgg== X-Gm-Message-State: AFuF++mJsWqM6dVnVejL5TvBh47oYhfoCODbWMWX5Lc/ctBWgrnQnGyv O7ceWalFrp7bY2l7KwMfT+XFE7aKLiNQtN0CMDLIV0pPKlW7JTdqRxYaGvc912HJ7qtMK+s8Yxk FWmQiouA= X-Gm-Gg: AYBFou0dFhCjhWpBRpFVDtVuUEqT3iPFPJr1+DR+3YTrk4Rp+d0hyWZSsN/GaGt4I7R dnVMsAuNWLQTt5heS7naRMN7CYz8DL/6wGy1oxzJ6Y6/1uIIwd+FWqDA8ngE1ZqTai+ouetNOmv qURhZyZYEkkTBj/w4yYc0/QuupGzxNWZCufwYPTuZmK76ZGXTrzkfGIXnOajmW/+wReYVvNKvmh ctN/35XCoTmdem5/JUoU8iJm2xpGtF/H37h0k5Bxfz44L6Y5dibGuNT9GHVX1KeVWMngz1+ptnp FnJaMpirvz2Q1Qrl+O3oHCDp8VKJgToaoo4GLc5Jeq5zHpkws9YWik4mAkhCEfhC+wQ1/0qv24k ZsYoMsSHmDYOlAYR0ReRhtVK6q9CJdrmRRiXeVBm2TMWe2DV07hs4Xtr6ACnNsqu6NaHBY9mj8v Drkpurbti2Axw2SMEvaqXgmLu/i9/GWjSfL9zpBItkcIqMoOkhjDZ6bKW3B/MelJ+RIfdO/P0Cq md8/vLTcwySdlLpK5eKD0NwXMykcwWL7jnyZvJ4zmXiduvDEM17rM8WyZwcKWp4Totqugm9b7E= X-Received: by 2002:a05:600c:6296:b0:49e:6fd2:a45 with SMTP id 5b1f17b1804b1-49fc5737c43mr2857915e9.16.1789682889123; Thu, 17 Sep 2026 15:08:09 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-49fc471b9a2sm8984075e9.0.2026.09.17.15.08.08 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Thu, 17 Sep 2026 15:08:08 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][wrynose 37/79] python3: inherit upstream-stable-release-point Date: Fri, 18 Sep 2026 00:06:22 +0200 Message-ID: <73694e077d37633c5b44a2d450ac2413df39e52e.1789681419.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Thu, 17 Sep 2026 22:08:16 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/246132 From: Daniel Turull Python maintains each release series on a per-minor maintenance branch that, once released, takes bug and security fixes only, and it releases from several at once: 3.10.20, 3.11.15 and 3.12.13 all went out on 2026-03-03, after 3.14.3. So upgrades within a major.minor are stable point upgrades per the OE-Core stable release policy (ref-manual, "Stable Point Release Upgrades"). https://docs.yoctoproject.org/dev/ref-manual/release-process.html#stable-point-release-upgrades https://devguide.python.org/versions/ Checked the last three point releases by category, since these are substantial bug-fix releases rather than security-only. 3.14.6 (Jun 10 2026) has 8 Security, 32 Library and 17 Core entries; 3.14.4 (Apr 07 2026) has 5, 59 and 46. Every C API entry in both is a fix, so neither adds C API. 3.14.5 (May 10 2026) is mostly fixes but does add RFC 9309 support to urllib.robotparser -- one extra capability in one module, touching neither the language, the C API nor the stable ABI. Already tracked this way on the OE stable branches, counting only bumps since each branch forked: kirkstone 3.10.4 -> 3.10.20, scarthgap 3.12.3 -> 3.12.13, wrynose 3.14.4 -> 3.14.6. AI-Generated: Kiro with Claude Opus 5 Signed-off-by: Daniel Turull Signed-off-by: Mathieu Dubois-Briand (cherry picked from commit e49e237208a9a5074d7bbc65b748962f3ea0eb49) Signed-off-by: Yoann Congal --- meta/recipes-devtools/python/python3_3.14.7.bb | 4 ++++ 1 file changed, 4 insertions(+) diff --git a/meta/recipes-devtools/python/python3_3.14.7.bb b/meta/recipes-devtools/python/python3_3.14.7.bb index b798f1c3697..e73dc8d7728 100644 --- a/meta/recipes-devtools/python/python3_3.14.7.bb +++ b/meta/recipes-devtools/python/python3_3.14.7.bb @@ -45,6 +45,10 @@ SRC_URI[sha256sum] = "3b48dac8fb59f62eaa67ac83c1eb12bda1b7a08406dd286e252c11a66b # exclude pre-releases for both python 2.x and 3.x UPSTREAM_CHECK_REGEX = "[Pp]ython-(?P\d+(\.\d+)+).tar" +# Python publishes bugfix/security-only releases on its per-minor +# maintenance branches. +inherit upstream-stable-release-point + CVE_PRODUCT = "python:python python_software_foundation:python cpython" PYTHON_MAJMIN = "3.14" From patchwork Thu Sep 17 22:06:23 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 98609 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 83807C982E9 for ; Thu, 17 Sep 2026 22:08:17 +0000 (UTC) Received: from mail-wm2-f12.google.com (mail-wm2-f12.google.com [74.125.225.140]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.1584.1789682891419286015 for ; Thu, 17 Sep 2026 15:08:11 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=ojMDLe8x; spf=pass (domain: smile.fr, ip: 74.125.225.140, mailfrom: yoann.congal@smile.fr) Received: by mail-wm2-f12.google.com with SMTP id 5b1f17b1804b1-49e66390995so564875e9.2 for ; Thu, 17 Sep 2026 15:08:11 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1789682890; x=1790287690; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=ZlZ5QLf5AdD9LiGYnvaLvy8/7L8w0l0RsDOcX6JBxkU=; b=ojMDLe8xJifjWHu7pe1ntZVduyj4uXc3zfNqmKkjXnoXxvMSEaHW9CRs2E4NpCoDjC DoAU4sEA0u5aWMo7+l/+v33a4Udm94lqhdZ7oTSXMaNsMcgS+ljuTT6xCcprGOHkmzCN 3s9ingnIAAHFK0MimaD2BGH1jUnPFTxgZk/3o= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1789682890; x=1790287690; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=ZlZ5QLf5AdD9LiGYnvaLvy8/7L8w0l0RsDOcX6JBxkU=; b=i5yYlb+qqzA+t5q8obcIA6gQXVoHkyaZJHrRImnIdP9E6oLU6zAhxSxz2y+dTzW+YC wweGse9ILqfN83fdW+GOe4xISydPteX3KOG4SOAFsX2ph88OzMmGCNu+ZoxekegvNMVH Q6MBKSNBLeBY28yIg7xAVerLezIKIJtfxMQIS/p+SFkq780lCUX8vBU3BbSEeDCcjeNc 8t2MltbrQntn6WAF2TychCErTWSBEE59g1tMSUxtyoX56yiTGERxHM6ClTYiQF+/WVVh o29Mr2DMXBpSVWjhI5s7/GRdaArYGKdjh50o1hBcRaHHm0WwtgHwz9u1CRe8B+7x3buU 7O1Q== X-Gm-Message-State: AFuF++ndGTur7MHSk6AnamSiiwGhtNM3eWkXeTM5uXc9VbjWBtURE+m3 AfhbSePbrmGMcsEviuofssTONduZYLoDWh5PWj0ircRtPl6MiY2T/9a+6d8kimveB2goyWec0FE mFEPNXGY= X-Gm-Gg: AYBFou3MXhcQlmBj6FAgykVhE2CFPFLtWFdrgNoVoPfd0VRPVPnAxXTTUfHgSJxTvWg RdXcFryW7C3sl/k9k5mD2WDtK1Ohf4rCLR1HYVUBMBNjiliWUBm3k9fUVWZI0RY5pjQxDYxWWsU 763j5Xwdj2he9xtmegn1qJg31TPzgBTwNRmAhk+un8XjjT5VEpD5XzbCOD2vTx4xZek15Pv5BOn 7ArFvuEwdi08YXnbJE4F3zjhHkh4SCg3kblhCQAlbS8ec4Jv23aUMPlah2xLhh9LUO6pCjJC8Op AGs82OKj15QcPA5/q1JPv5Ej17BV4bT5Y4xboZk5McCL0/0oUN6Bl/8zosKkQWKnkFx12ZgP8V1 4I7f9fq9uaAjvM453qKdtC3IakY/eSChhqDEopoOwURVan2PcxnRS/zYvBrJEDOYGDTz9F9C2o8 nwcyrqzzsAIoLx0Xq+tzfybI/QM2mEHc3FIB/a/xTiqchOOdSo8KeJXspyL+TiyW+EfZogUSaPa nye+Mi55ZFWD17EQtVXShxIGGdNNHX0CBSyrmt+Dd0Jp9mU4AqkoFi+fONaQka5/1LqmnrbICY= X-Received: by 2002:a05:600c:6296:b0:49e:63cd:31fb with SMTP id 5b1f17b1804b1-49fc5714bdamr2943675e9.9.1789682889656; Thu, 17 Sep 2026 15:08:09 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-49fc471b9a2sm8984075e9.0.2026.09.17.15.08.09 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Thu, 17 Sep 2026 15:08:09 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][wrynose 38/79] openssl: inherit upstream-stable-release-point Date: Fri, 18 Sep 2026 00:06:23 +0200 Message-ID: X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Thu, 17 Sep 2026 22:08:17 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/246133 From: Daniel Turull OpenSSL's release strategy states that patch releases contain only bug and security fixes, with no new features and no API or ABI breaking changes. It maintains several series at once: 3.0.21, 3.4.6, 3.5.7 and 3.6.3 were all released on 2026-06-09, with 4.0.0 already out. So upgrades within a major.minor are stable point upgrades per the OE-Core stable release policy (ref-manual, "Stable Point Release Upgrades"). https://docs.yoctoproject.org/dev/ref-manual/release-process.html#stable-point-release-upgrades https://openssl-library.org/policies/releasestrat/ Checked the last three point releases. Each is labelled "a security patch release" in its own NEWS.md header, and every entry is a CVE fix, the item count matching the unique CVE count exactly: 15 CVEs in 3.5.7 (Jun 09 2026), 7 in 3.5.6 (Apr 07 2026), 12 in 3.5.5 (Jan 27 2026). When a series reaches EOL the regex must be moved to the next maintained series by hand, as that is a feature-level change. One limit is worth stating, from this recipe's own history: 3.2.4 -> 3.2.5 was refused on scarthgap in July 2025 for intermittent ptest failures in a dependent recipe, bisected to an upstream commit and reported upstream, and the branch went to 3.2.6 instead. A fixes-only release can still fail to integrate, so proposing an upgrade is not the same as it passing. Already tracked this way on the OE stable branches, counting only bumps since each branch forked: kirkstone 3.0.2 -> 3.0.19 on the 3.0 LTS series; scarthgap 3.2.1 -> 3.2.6 then, at EOL, 3.5.5 -> 3.5.7; wrynose picked up 3.5.7. AI-Generated: Kiro with Claude Opus 5 Signed-off-by: Daniel Turull Signed-off-by: Mathieu Dubois-Briand (cherry picked from commit 75f78c58cf9e4b385ddf4f09668b7f1a49117d97) Signed-off-by: Yoann Congal --- meta/recipes-connectivity/openssl/openssl_3.5.8.bb | 5 +++++ 1 file changed, 5 insertions(+) diff --git a/meta/recipes-connectivity/openssl/openssl_3.5.8.bb b/meta/recipes-connectivity/openssl/openssl_3.5.8.bb index cc148f07c7d..d8cae41291a 100644 --- a/meta/recipes-connectivity/openssl/openssl_3.5.8.bb +++ b/meta/recipes-connectivity/openssl/openssl_3.5.8.bb @@ -24,6 +24,11 @@ SRC_URI[sha256sum] = "a8f84a39918ec6415ce765d9b429d313ba97b8143169c172e734b95144 inherit lib_package multilib_header multilib_script ptest perlnative manpages MULTILIB_SCRIPTS = "${PN}-bin:${bindir}/c_rehash" +# OpenSSL publishes bugfix/security-only releases on its per-minor branches. +# When the tracked series reaches EOL, bump the regex manually to the next +# maintained series. +inherit upstream-stable-release-point + PACKAGECONFIG ?= "" PACKAGECONFIG:class-native = "" PACKAGECONFIG:class-nativesdk = "" From patchwork Thu Sep 17 22:06:24 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 98605 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id ADE3AC982DF for ; Thu, 17 Sep 2026 22:08:16 +0000 (UTC) Received: from mail-wm2-f13.google.com (mail-wm2-f13.google.com [74.125.225.141]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.1689.1789682891896821593 for ; Thu, 17 Sep 2026 15:08:12 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=wpIAtODL; spf=pass (domain: smile.fr, ip: 74.125.225.141, mailfrom: yoann.congal@smile.fr) Received: by mail-wm2-f13.google.com with SMTP id 5b1f17b1804b1-49b965f447cso894015e9.3 for ; Thu, 17 Sep 2026 15:08:11 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1789682890; x=1790287690; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=QuOMrV6qV0AU1BjFW6uJsF3h+4UCZ1gxFxCs6bMggMw=; b=wpIAtODL9TIv3mXF77MgxDWFRPZeRs65aG3rnOmHMeYfFqQHjV3I1BD70ghvsfLT3Z KuoLYRG6QjsVWP8t1cRp1eGPKM4ZV6Tyq8yqjiVEhL5ffJIWgqWdckgirYYU7JkfUjYQ Vyad155DA1hCvN45DdpA8OxUug9c7BC5JisDE= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1789682890; x=1790287690; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=QuOMrV6qV0AU1BjFW6uJsF3h+4UCZ1gxFxCs6bMggMw=; b=1Gv81LxTktX9THwH/eb1hJV31H097MryLtFtYIWkEOoJbTmb8xpMFMIoe7Ek7CoIEU BZ5pqGLLxLBy3C7aQmX9cFOq1IMP3WXUXgaUb3vs1cxrjYZAULYfM5G6rduaiHTGMjrC mgBB7pFp2AuZF+FKfKgAl3Do+mf1HzBAImAclJ5PQVGB91hMWaMCKrY4H0SmjR4JYbZN BSw8kupDtXq+bzyGmg0oSFpImaaPYBOKhTYRNj9lU43WvvZHinXENqj1H3nlxTVM0GN8 I7xniw6VNtTARLP+KWLIRPbROGhKsFqGWjq4V9CFz/Ix3h9kd4wjshwK1ETwamn8VDfw Irnw== X-Gm-Message-State: AFuF++nfFduajN+tQS5lz6tejoxwxp1TbP2udYy8ZTnPk9J6ZaPEqlyE 90J6xUoel/UJRDGBqc2pi2xT98JX8tq1xgW8u+mP/2262s+iU44aRfmtDoCrT6BElTTv94jDUeQ xhSGGR3s= X-Gm-Gg: AYBFou2U7x8+zFEBoi9rs0Fc0Be4K+4y+MKsbyI3ISQ/Xvhtd1ToBLnUkK0qnVvj5o5 s9CYGB5dmUaTP0PecHYaP7laM+xPpc/n3kx0hYAYKpVRvWKA+jmhQ6eE+xcwERbTU3IsmU2GId3 HPIda8PyeIw7EMSjts3AEWPipjmq4aZjQeqUhwNulx8Z7OdzZutIzhKSnc1s10IpHKFq6XGRiql A3PExjgQtnvYLWwbTr18TOzPUVvuDEwLkEfBlhZ3MNJJEAyvZKWAhClqzrcqbyfuFe/p6cuTeC4 /iu6Tw4t4L9ANnEPfLpGPwZYifmKg4mouzAcC2L6FXMRJCDriyLnWABiavU+TMyV8hJfknVT2Zj 6TBASRewIO3ECVuiXekHVv8mkWNPc0SEe/eQjmlF81eZynHY2g4stmfu/U6hWVh/bhvfPzHQOEl Kq/nA8G81HMPw0tRalr3I0rGlW/2L+sc5dLbo8ZxYrcCY5UJrurkrp63KwA5kH/AV4yT8v305ti tCe63Ez7Sjzd/MOWP0Lf8cIWDfqMEQrTMzTysB3gy/MBtPAejdn6UdMFzwe29fMT7Mkilhwryw= X-Received: by 2002:a05:600c:3ba9:b0:49c:f504:2af5 with SMTP id 5b1f17b1804b1-49fc566939emr3570535e9.1.1789682890171; Thu, 17 Sep 2026 15:08:10 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-49fc471b9a2sm8984075e9.0.2026.09.17.15.08.09 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Thu, 17 Sep 2026 15:08:09 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][wrynose 39/79] binutils: inherit upstream-stable-release-point Date: Fri, 18 Sep 2026 00:06:24 +0200 Message-ID: <14700798446c6f9809d33ffc4e1c4b3ef22e00c5.1789681419.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Thu, 17 Sep 2026 22:08:16 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/246134 From: Daniel Turull binutils cuts a per-X.Y stable branch, binutils-2_46-branch for the current series, that takes only bugfixes and backported CVE fixes, and tags X.Y.Z (Z>0) releases from it. Superseded branches stay alive: one x86 MODRM fix landed on the 2.40, 2.42 and 2.43 branches on the same day in May 2025. So upgrades within a major.minor are stable point upgrades per the OE-Core stable release policy (ref-manual, "Stable Point Release Upgrades"). This is not spelled out in a policy document, so qualification rests on the branch structure and the release contents below. https://docs.yoctoproject.org/dev/ref-manual/release-process.html#stable-point-release-upgrades https://sourceware.org/git/?p=binutils-gdb.git;a=shortlog;h=refs/heads/binutils-2_46-branch Checked the last two point releases. 2.46.1 (Jun 08 2026) is 137 commits, mostly automatic version-string date bumps, with six substantive changes, all fixes: gprof testsuite, build warnings, an sframe encoder/decoder call-site fix, a DOS-filesystem fix and two linker fixes. 2.45.1 (Nov 10 2025) is aarch64/gas fixes to incorrectly restricted instruction encodings, linker metadata fixes adding GLIBC_ABI_*_TLS version dependencies to match glibc's own ABI tags, and libctf, strip and warning fixes. Neither adds options or instruction support. Already tracked this way on the OE stable branches, counting only bumps since each branch forked: kirkstone has five or more "binutils: stable 2.38 branch update(s)" commits staying within 2.38.x, scarthgap the same for 2.42.x, and wrynose has already taken 2.46.1. AI-Generated: Kiro with Claude Opus 5 Signed-off-by: Daniel Turull Signed-off-by: Mathieu Dubois-Briand (cherry picked from commit e61767b8d9486c1a13f505563919654af5955a23) Signed-off-by: Yoann Congal --- meta/recipes-devtools/binutils/binutils.inc | 5 +++++ 1 file changed, 5 insertions(+) diff --git a/meta/recipes-devtools/binutils/binutils.inc b/meta/recipes-devtools/binutils/binutils.inc index b3d0728e4b2..29c05b1a279 100644 --- a/meta/recipes-devtools/binutils/binutils.inc +++ b/meta/recipes-devtools/binutils/binutils.inc @@ -15,6 +15,11 @@ DEPENDS = "flex-native bison-native zlib-native gnu-config-native autoconf-nativ inherit autotools gettext multilib_header pkgconfig texinfo +# binutils maintains a stable branch per X.Y release (e.g. binutils-2_46-branch) +# that only takes bugfixes and backported CVE fixes; X.Y.Z (Z>0) releases are +# cut from that branch. +inherit upstream-stable-release-point + FILES:${PN} = " \ ${bindir}/${TARGET_PREFIX}* \ ${libdir}/lib*.so.* \ From patchwork Thu Sep 17 22:06:25 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 98598 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 56A1FC982E6 for ; Thu, 17 Sep 2026 22:08:17 +0000 (UTC) Received: from mail-wm2-f13.google.com (mail-wm2-f13.google.com [74.125.225.141]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.1585.1789682892409158591 for ; Thu, 17 Sep 2026 15:08:12 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=WaSLOXln; spf=pass (domain: smile.fr, ip: 74.125.225.141, mailfrom: yoann.congal@smile.fr) Received: by mail-wm2-f13.google.com with SMTP id 5b1f17b1804b1-49b912d3920so876105e9.1 for ; Thu, 17 Sep 2026 15:08:12 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1789682891; x=1790287691; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=CH84+mS+ZEteQFJctfhr9XygkFnuDlQGvzI1Qlxdia0=; b=WaSLOXlnVVVDiU29CMk7gFbXC4sMCyPTc/Jt7xUTadlI3i+aRYpLdnt4SCOuEBHtEv khJoMXDIxpmKz04KnSJrM0eTYRYHG5P5ouYf43guYMfgIh1hly5QcZcKpxFxRb44TJdW M5rti6if/DcbKauCH+wmBr9A0YcOMk8Uo+F0Q= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1789682891; x=1790287691; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=CH84+mS+ZEteQFJctfhr9XygkFnuDlQGvzI1Qlxdia0=; b=gqtKYX3fcatX7oMW78tvU6DV3dQeq8V3ywgmmiSc8n79ivEo+U4wYnwTgh9zBrRLxa 5j1VZtibe5wgLaSWWaw8z8nMCrBFBmcvlrTFeW5+nuKv+upo5Ci6Wf5qf2/vURc1sQaR zodugHReTmXVUriNI9Xoy0PLfIC2UT3J2p0MRegVetzxt1ZT+8ZLwBldYutBOQ5xR+zL CRKnu2nrACTlU5rQK/0paLI6x0l1wE02Nu2Nuu5fOR6Vp2EnY+hz5aY0XVWwvtZfjq+g 5srLZVuZDFC1djfLTxTbp8fGPBh8r1l+FVZZFOQeEgEElF7KGK98jBNGiqf0JH6lAHgM FcYQ== X-Gm-Message-State: AFuF++kKVKZAplvAZuupgd1Jn2A5MoERzA4HlG3fdsZGD6ab+tZHyFYm lXT9fPcbj9VIp1UW3pPKlM4+SuKxja8jvfJ3Qtjgw1ETWSGFpV1lEZ0aY5ZQhVQQisMGa/hdPpj 3xANbX50= X-Gm-Gg: AYBFou0AJnuBznC1Atc3OmDUzOiOpzSCuvxMQPHJ0XOB8wj90g1IEDW/O3JOAinMTnk Yeu6dH7C/QZFRk3v8NSiy7mUVqlsM2dXd89oB1uvbOVz1p0gNTHsqi5+kbEFK6KzTidqtDQq70n 3WoTNXt2SRB2AW3MC1ygbVkOakocILBpYI2NsTg0iA3IDlivNL6bvgk4BcE5VhZCO6JajcQ+D3M ubUkqIFUB08u1UVCpO6BQoU6GaQEjHgohGiHtYI9xvH/vJ4ama4yoqsB11Aky8dnWmpPwfQld/h pdBrw14CcjpfOgQPjPLdC4TeoPLXZKI5gUUSeuSTq5CeVwrPzIaXXj4EdgLvSSICsffGxwl2Rxu kbCp8onKkiBXuGB3CcPFzfkB6qEpt1LtvAg/cPxYnMKEp/jOvvmN7rwIU7PQMxYTyNMyFmnEAEs ueG9n19sJu0eLn895Cd0l6trer+Qq3ZXVXpxDcmdNcv6af6iiGD7qFQTr9YM1vYZg3shR94d1ld dvXTKfyrBbx0seWD79HVJOOHVEjFPoqSANFju/frDfup3F+t+BqkFUfvEs3ozwbO1j606UVOs8= X-Received: by 2002:a05:600c:34c1:b0:49e:799a:8951 with SMTP id 5b1f17b1804b1-49fc56aba0dmr3628615e9.11.1789682890660; Thu, 17 Sep 2026 15:08:10 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-49fc471b9a2sm8984075e9.0.2026.09.17.15.08.10 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Thu, 17 Sep 2026 15:08:10 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][wrynose 40/79] libgcrypt: inherit upstream-stable-release-point Date: Fri, 18 Sep 2026 00:06:25 +0200 Message-ID: <761295ea203dca54399137c9458b19b4590e4699.1789681419.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Thu, 17 Sep 2026 22:08:17 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/246135 From: Daniel Turull libgcrypt keeps a long-lived maintenance branch per minor version, LIBGCRYPT-1.12-BRANCH matching the current PV with equivalents back to 1.2, and releases from several in parallel: in one week of April 2026 it released into four of them, 1.12.2 and 1.8.13 on the 15th, 1.11.3 and 1.10.4 on the 21st. So upgrades within a major.minor are stable point upgrades per the OE-Core stable release policy (ref-manual, "Stable Point Release Upgrades"). https://docs.yoctoproject.org/dev/ref-manual/release-process.html#stable-point-release-upgrades https://github.com/gpg/libgcrypt/tree/LIBGCRYPT-1.12-BRANCH NEWS separates "Bug fixes" from "New and extended interfaces", and neither point release in the current series has the latter section at all: 1.12.2 (Apr 15 2026) is four fixes, including an ECDH buffer overwrite and a missing Dilithium bounds check, and 1.12.1 (Feb 20 2026) four build or arithmetic regressions. 1.12.0 (Jan 29 2026) opens the series and does add features, confirming X.Y.0 bumps must stay outside the regex. The libtool version-info in each NEWS heading is upstream's own ABI record, and across the current series only the revision moves. One deviation is worth disclosing from the previous series: 1.11.2 adds a single enum constant, GCRY_KEM_RAW_P256R1, with current and age incremented together so it stays backward compatible. Point releases here are fixes-focused rather than absolutely fixes-only, with the deviation bounded to additive constants. Already tracked this way on the OE stable branches, counting only bumps since each branch forked: scarthgap took 1.10.3 -> 1.10.4, which needed a build fix backported alongside it because 1.10.4 broke building with -O2 in the sysroot path. kirkstone has taken no in-series bump and stays at 1.9.4. AI-Generated: Kiro with Claude Opus 5 Signed-off-by: Daniel Turull Signed-off-by: Mathieu Dubois-Briand Adapted for wrynose: applied to libgcrypt_1.12.1.bb (upstream: libgcrypt_1.12.2.bb). (cherry picked from commit 97caf8a110281becde5d888338712d71627cbf98) Signed-off-by: Yoann Congal --- meta/recipes-support/libgcrypt/libgcrypt_1.12.1.bb | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/meta/recipes-support/libgcrypt/libgcrypt_1.12.1.bb b/meta/recipes-support/libgcrypt/libgcrypt_1.12.1.bb index d7f8563ae6e..d7b3e182cd2 100644 --- a/meta/recipes-support/libgcrypt/libgcrypt_1.12.1.bb +++ b/meta/recipes-support/libgcrypt/libgcrypt_1.12.1.bb @@ -32,7 +32,7 @@ SRC_URI[sha256sum] = "7df5c08d952ba33f9b6bdabdb06a61a78b2cf62d2122c2d1d03a91a798 BINCONFIG = "${bindir}/libgcrypt-config" -inherit autotools texinfo binconfig-disabled pkgconfig ptest +inherit autotools texinfo binconfig-disabled pkgconfig ptest upstream-stable-release-point require recipes-support/gnupg/drop-unknown-suffix.inc From patchwork Thu Sep 17 22:06:26 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 98601 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 7BAACC982DA for ; Thu, 17 Sep 2026 22:08:16 +0000 (UTC) Received: from mail-wm2-f12.google.com (mail-wm2-f12.google.com [74.125.225.140]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.1586.1789682892967150483 for ; Thu, 17 Sep 2026 15:08:13 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=s6Sj6A3G; spf=pass (domain: smile.fr, ip: 74.125.225.140, mailfrom: yoann.congal@smile.fr) Received: by mail-wm2-f12.google.com with SMTP id 5b1f17b1804b1-49cd4ba9f68so1480605e9.1 for ; Thu, 17 Sep 2026 15:08:12 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1789682891; x=1790287691; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=EYQDqsu+jbSIPDGCZoA4pVb/dZiHbd3UiiXezFeghKA=; b=s6Sj6A3GgqXaZRgu5KBpVGAqOd5vjmrAsd/EXnWkewbbLSZb8eUKSVMXuFxLnt+XCx p0CDKsyua1PYyTTSbSDc5yyYvJY8VGFf1gJAQdV+uqg7tTQrpkTVJYYFwwg/YDOyckcX gwNzO71VD7MG9XTdfUtNspCj7yaEeQP2RNd2w= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1789682891; x=1790287691; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=EYQDqsu+jbSIPDGCZoA4pVb/dZiHbd3UiiXezFeghKA=; b=IUOVyC7756muHZvkwDygoOxfKIB5Ndelj7eZ+lqSwbWnf+TU8BZVHHklKOhUFOFjfG AlNO5ZXx6nNjOCWDznzM+G/68daneMRv0i9dL53bvNHiQqHvVNzTMAh3IyF0eRQx4EDc IcOqsLEhm1p7UDnJedyR+I7Ax4cBMc7PnVT4KDysHm/D+VuwhFVrLOylxPOigo/5Id3q Cwb4knGkjt8NaeMQwS/21Yt2b4+LPCxQTidD8TfNodk6H8Q2X5t+NpeUuhha8NS91ho0 OBUWqZfaEpx7gMbL48gV59avQ/yOssbjXP00+8dtYA4RQox83QSLdC2nAAVLwEIIJjzd RblQ== X-Gm-Message-State: AFuF++kE2+Nj+N+vlWbEYrGdPP/aeBogVc6Lfqiu4tPQxpHxLDJCrvhG sXySoq7viGzYp/fMyl+yyfQZDpm39apDE/4/9qwRdaN6IC/ZyIbWxyKkM+re7luCVemHaT78KXr zFAdR9fU= X-Gm-Gg: AYBFou31J+dVk9cnPZ6CCQ+ETtCtqD9RElz4YdolmQ8+cA4P0xHWvwZH5vxrHYgJhgM xFPd8bPkHdqZIXYeH8I5DxvSMXe2WCfdurMihSdxEjNCuz7bjPMtjidA2JV6HvT+sh/UAW4INkC 5RV5JNXqj7BvD0QmRhfXz6fGdCEEbbuYBO9VHngjhjxv2zY1UoHt4srL8UZlG9QfKJfQXX3j5SJ ld2rQZCoL7TvB0cY0x51Jd2jvYOj9Ryi+cIB5bJU3z5A7yNwf+8LeyxZY8T358yf/9VCQbhitVa tTIqDdizC5Hf2jDfOa6hL0U0ryAuApiTGdpwTeYhaAfBMzwlcRfn5HI0wUBhCRTb1sf40y3UMMM 1+4RgWmdvq/sMzaiSCzfeF+hmXTQDkorkqM5hTDzdGNuyAkIYuqwrjz6/NbYQDHKNB8+Xr7aWmi 5TdA0nqhCYYOoKFQeXvMN1Eo2tz38cnm8yc+CNw7PgllVhqMx06N3nk34Jv0SH5sLip7Q0GVitL aXfMoCpm3kXQwUlbJFwp2OVg9gAEDTN2s98CflNbJ1fzvHhJ4mrp1CD5VRWRYNWBb7bNrhz+qA= X-Received: by 2002:a05:600c:698c:b0:49d:462:6eda with SMTP id 5b1f17b1804b1-49fc5743c19mr2684505e9.28.1789682891203; Thu, 17 Sep 2026 15:08:11 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-49fc471b9a2sm8984075e9.0.2026.09.17.15.08.10 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Thu, 17 Sep 2026 15:08:10 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][wrynose 41/79] sqlite3: inherit upstream-stable-release-point Date: Fri, 18 Sep 2026 00:06:26 +0200 Message-ID: X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Thu, 17 Sep 2026 22:08:16 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/246136 From: Daniel Turull SQLite cuts a per-minor maintenance branch for each release series, branch-3.53 matching the current PV alongside branch-3.52, -3.51 and -3.50, and tags patch releases off it. Superseded branches keep receiving them: 3.44.5 and 3.42.1 were released in mid-2025, long after 3.50 was current. So upgrades within a major.minor are stable point upgrades per the OE-Core stable release policy (ref-manual, "Stable Point Release Upgrades"). https://docs.yoctoproject.org/dev/ref-manual/release-process.html#stable-point-release-upgrades https://github.com/sqlite/sqlite/tree/branch-3.53 Checked the whole current series. 3.53.1 (May 05 2026) through 3.53.4 (Jul 24 2026) are almost entirely memory-safety and corruption-handling fixes: five out-of-bounds reads, two buffer overreads or overwrites, two integer overflows, hot-journal rollback with a zeroed super-journal record, safer double-to-int64 conversion, and mutex acquisition added to a batch of sqlite3_* entry points. 3.53.0 (Apr 09 2026) opens the series and does add API surface, confirming X.Y.0 bumps must stay outside the regex. Two additive exceptions in 3.53.4, neither touching the core library ABI: the SQLITE_SHELL_EDITION compile-time option for the CLI, and sqlite3_intck_register() in the incremental integrity-check extension. Already tracked this way on the OE stable branches, counting only bumps since each branch forked: kirkstone 3.38.2 -> 3.38.3 -> 3.38.5 and scarthgap 3.45.1 -> 3.45.3. wrynose is at 3.51.3 with no in-series bump yet. AI-Generated: Kiro with Claude Opus 5 Signed-off-by: Daniel Turull Signed-off-by: Mathieu Dubois-Briand (cherry picked from commit 22cd1dfc82049e47be5e73057c2f12cda036f352) Signed-off-by: Yoann Congal --- meta/recipes-support/sqlite/sqlite3.inc | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/meta/recipes-support/sqlite/sqlite3.inc b/meta/recipes-support/sqlite/sqlite3.inc index 94dbc38ec5e..8791749dc85 100644 --- a/meta/recipes-support/sqlite/sqlite3.inc +++ b/meta/recipes-support/sqlite/sqlite3.inc @@ -21,7 +21,7 @@ UPSTREAM_CHECK_REGEX = "releaselog/(?P(\d+[\.\-_]*)+)\.html" CVE_PRODUCT = "sqlite" -inherit pkgconfig siteinfo +inherit pkgconfig siteinfo upstream-stable-release-point # enable those which are enabled by default in configure PACKAGECONFIG ?= "fts4 fts5 rtree dyn_ext" From patchwork Thu Sep 17 22:06:27 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 98610 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 69612C982DB for ; Thu, 17 Sep 2026 22:08:16 +0000 (UTC) Received: from mail-wm2-f13.google.com (mail-wm2-f13.google.com [74.125.225.141]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.1587.1789682893472513827 for ; Thu, 17 Sep 2026 15:08:13 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=rjoeG9fw; spf=pass (domain: smile.fr, ip: 74.125.225.141, mailfrom: yoann.congal@smile.fr) Received: by mail-wm2-f13.google.com with SMTP id 5b1f17b1804b1-49b912e64ccso1006375e9.0 for ; Thu, 17 Sep 2026 15:08:13 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1789682892; x=1790287692; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=pj5yV0qoBpDeqOnXVp8Hw/rP6cqliaUFCFAlIJ4F67s=; b=rjoeG9fw5Zaq9SYjRlpYqx758zPF6G9kDvm9fAC9SOq/P8EC1nVn3V4xKYpFqUYRp1 SqOAzwspOIS/lf+U/Fal6ANs42zPj6eDv2sc2y9odvZq/x5DeP1TSZxvtWj0MxUVoUBI IDzwb8XYa5g1/TWg22fcJunxklVcEZo8FwB8E= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1789682892; x=1790287692; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=pj5yV0qoBpDeqOnXVp8Hw/rP6cqliaUFCFAlIJ4F67s=; b=ajd+vcEKoqBIDXVLWMclh0JYgYmDx8ldDDlBLLmR/e0+Kf8dsVoL8GCQUVHS+6tNDy V6CELSkGC//Vw85hsawUEno37EfFij8/uK0oXH+2xDtUETiCxL7IDi/X4uR0h7d1AYML Ld/Or1njOYLq0aUn3UVl3ksBCD4Xy9bzeVzzHBZUQ+HTR3ovI7VD6m5LQVKPRoD8m5Z6 +awoBAnXCUd2V2WggvQBwlW1FMn1FSsCmHx55KaDZ4av6fCaR8DaR7mmKlwJ0J25UOY5 QFqV3Vz613LIS+q+q7C9e4xsYymmbSbrAzccTkOUloYjHdKIF21puuGvLsFDCBLhFIGQ IbWg== X-Gm-Message-State: AFuF++nX+V0SQUS6CrfyKVve8czmuB3oeWwjcNLO2CR6+XOOl4qwUafA AaZsBr3WWDlKEryubsY13wFJ+z2BQH8Mq8i09lzX2ZNJWuL1s8n/S/6P7YzKhPSWC3u+KZpnAiu Cc1vGPs4= X-Gm-Gg: AYBFou1KVnuGSUhtvw6kIrW3KiExXhICEXYCSlD/OOfmpimqd7nXNugNyfMMAU1uOS4 uOQyPHFFo+f93cpVNhbB31DdGdD7StvxUTgMQLnrAI8wl3YYGelUmm8fUZIrvIJpEKHHfCMCLBi jre2mhi3uAkv0kLVbUVUYtDha87aKrEtughasLPG240gnZC4Be9wvB9FE1KUkml9wjguHxQN8W9 bvMKu7IEGICLhmDuDGfm/+j3L60FUUQHVOxi2DSv5POaCZnqLV09AN31iMDtjdcNzHN8ZIYylLm tgpB9AVFdz3fR1UQgani3tJSHlQKxeMLS5iAumITjsJyilQCvpYz1L3t12dKxM11P3BMmZhQ+KE 6Hzxy21I2S5D+QPX8FeLazIyJrY0uTOA+oEX+uRpO1Ax3eP1LIQsKcrhB3gqH/ofwGY6mUekeGJ WrqcgjJ94ltTLgYKH8ZqXquK4Dva6ZicMJGhJJRNMgfQH0zVXj4df+x/OSiarWyycmpPHT14ecd 0QvvKLALzpws5DkHqzfFVBvI++Dzg3eDvjORn3lo7usraUfB9Ufw3jkXpyXs0X3+5fRW9wZtdsm PXd8BJ0pUQ== X-Received: by 2002:a05:600c:190d:b0:49f:bd3c:bc26 with SMTP id 5b1f17b1804b1-49fc574f069mr2982545e9.33.1789682891706; Thu, 17 Sep 2026 15:08:11 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-49fc471b9a2sm8984075e9.0.2026.09.17.15.08.11 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Thu, 17 Sep 2026 15:08:11 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][wrynose 42/79] lttng-tools: inherit upstream-stable-release-point Date: Fri, 18 Sep 2026 00:06:27 +0200 Message-ID: X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Thu, 17 Sep 2026 22:08:16 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/246137 From: Daniel Turull lttng-tools maintains a branch per minor series (stable-2.11 through stable-2.16) and tags point releases from it, releasing from more than one at a time: 2.14.2 and 2.15.1 went out the same day. So upgrades within a major.minor are stable point upgrades per the OE-Core stable release policy (ref-manual, "Stable Point Release Upgrades"). There is no written policy document, so qualification rests on the branch structure and the release contents below. https://docs.yoctoproject.org/dev/ref-manual/release-process.html#stable-point-release-upgrades https://github.com/lttng/lttng-tools/blob/v2.15.1/ChangeLog https://github.com/lttng/lttng-tools/tree/stable-2.15 Upstream keeps a ChangeLog with a per-release entry list, and all 48 entries for 2.15.1 (Jun 05 2026, against 2.15.0 in February) are fixes, tests, documentation or refactors. Seven address machine interface output alone; the rest cover a consumerd lockfile fd leak across fork+exec, a missing default kernel probe entry, an uninitialised read in uri_compare, a musl compatibility fix, popt error handling, test fixes, and one refactor preparing the CPU-mask escaping fix. Already tracked this way on the OE stable branches, counting only bumps since each branch forked: kirkstone took 2.13.4 -> 2.13.8 and 2.13.8 -> 2.13.9, scarthgap 2.13.11 -> 2.13.13. wrynose has taken none and sits at 2.14.1. AI-Generated: Kiro with Claude Opus 5 Signed-off-by: Daniel Turull Signed-off-by: Mathieu Dubois-Briand Adapted for wrynose: applied to lttng-tools_2.14.1.bb (upstream: lttng-tools_2.15.1.bb). (cherry picked from commit 40f22582ff6989f9275808bfda229a8ec78504e4) Signed-off-by: Yoann Congal [YC: lttng-tools has a written stable policy: https://github.com/lttng/lttng-tools/tree/stable-2.15#supported-versions |The LTTng project supports the last two released stable versions |(e.g. stable-2.13 and stable-2.12). | |Fixes are backported from the master branch to the last stable version unless |those fixes would break the ABI or API. Those fixes may be backported to the |second-last stable version, depending on complexity and ABI/API compatibility. | |Security fixes are backported from the master branch to both of the last stable |version and the second-last stable version. | |New features are integrated into the master branch and not backported to the |last stable branch. ] --- meta/recipes-kernel/lttng/lttng-tools_2.14.1.bb | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/meta/recipes-kernel/lttng/lttng-tools_2.14.1.bb b/meta/recipes-kernel/lttng/lttng-tools_2.14.1.bb index 3a3f2cff2c6..3df9ed1c00c 100644 --- a/meta/recipes-kernel/lttng/lttng-tools_2.14.1.bb +++ b/meta/recipes-kernel/lttng/lttng-tools_2.14.1.bb @@ -54,7 +54,7 @@ SRC_URI = "https://lttng.org/files/lttng-tools/lttng-tools-${PV}.tar.bz2 \ SRC_URI[sha256sum] = "0e68eb27923621c4bc127cfce40422d28cf7e473fedf6229ae6c32ba5c5b7c6d" -inherit autotools ptest pkgconfig useradd python3-dir manpages systemd +inherit autotools ptest pkgconfig useradd python3-dir manpages systemd upstream-stable-release-point CACHED_CONFIGUREVARS = "PGREP=/usr/bin/pgrep" From patchwork Thu Sep 17 22:06:28 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 8bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 98611 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 4D6E3C982D9 for ; Thu, 17 Sep 2026 22:08:16 +0000 (UTC) Received: from mail-wm2-f12.google.com (mail-wm2-f12.google.com [74.125.225.140]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.1588.1789682893976335834 for ; Thu, 17 Sep 2026 15:08:14 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=Cw5N5F2f; spf=pass (domain: smile.fr, ip: 74.125.225.140, mailfrom: yoann.congal@smile.fr) Received: by mail-wm2-f12.google.com with SMTP id 5b1f17b1804b1-49d1ca5b0d6so931045e9.0 for ; Thu, 17 Sep 2026 15:08:13 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1789682892; x=1790287692; darn=lists.openembedded.org; h=content-transfer-encoding:content-type:mime-version:references :in-reply-to:message-id:date:subject:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=lkWGrJH51sgMunY4tBW9cage/X0mtJi3Ixg97vlX/v8=; b=Cw5N5F2fmPzUCQji1NCmiFUACboPQXYtv88og+1jbnPsNHNaFVH/xS4Z4oa9UpyKOW Le6CThmCCnrw4y8bUt2POylnCQ5tt1QqecBpz3QlljYqm292I7pFzr+sjXCKekxFoqda RBRi/t/at9g6w40rBJCx85KfKEQ+jY3gDaO/I= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1789682892; x=1790287692; h=content-transfer-encoding:content-type:mime-version:references :in-reply-to:message-id:date:subject:to:from:x-gm-gg :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to :content-type; bh=lkWGrJH51sgMunY4tBW9cage/X0mtJi3Ixg97vlX/v8=; b=DAmUXWBvC4jKsRmLMmFPShHQA6IYHqoZKXkGRszJdUJsQe+U/TEs29xDMxSmFOkWi+ WxOkK33ugjDk0k138pj2eq7DMUfPRpldpD4qj0CxS31B9MzRwkkhb0vJDjC1By3C0qfB xDXGtU4arVSidy4ZLpf/pwIiGEY3zigQWnmLdcIqP/1x5yOCkKS3F9XBgjqkSxh1ENLl AaOhOXkDxmCXTZoQTqtcI/kjHK6ooh/FSHtyYcunQrwxYvQmz6b8NmNz4ZUhqIPzhopD MNA9Be40XOYu9T5tYhAp64tgsC2/NwahY32Ie8BzhkCsLWzfS/0KyxupEuiOTCnWgW0y BFvw== X-Gm-Message-State: AFuF++mpHgnu9DO1POE/UIBb5tmG1tK5H21Fyi1YlwKtxILTiH1GPmG2 By0TdSl5u259Ccn8QmSmxXVYQMPRVarCF32ADLEZ2qhxucuvxLBPgYc1C+6g+/QZAYt6D88ra0c ceEAFnvo= X-Gm-Gg: AYBFou3RYstM77ERGa/AChlOFFK9oUVNhg8ioMSgN0Z1Eapc8ysl+8a/EdeOkVU6hHT ZKvipP7aSXdaZBRWce+DQVCdUVJTtaKLSqFhQYh3KaexuCJ+IjN0N7vdO0QyV8N4WmPwrqIngAS z2e4oMyxQ7eTBMd5t8Xx/Lyj223ovswbHuBaV6pvov34EVFvKC7xNHD0fS+iD4zEPh/QARzXT38 8y1KCwTeGbFsMeYvsRgLrSGcmAI8qWXzLTDDH+gXK47Ouauo982/ImY58N9YKtSCYF4Hms0Zcfz TUvyLOrnwib7OvAW9CoBzPbJ4Bkv78Hm2OMMizMRkMHPKZKYSq2HPNQXd6eZRdCFOW+X9/3deB6 csmjmv/O5J/6WP7tiPyVKVBjV6rlKHRhHDA284WWUpwhYb7sAyaNeBcwPraTERqwiGJW6ikTeQq dBqRIOU557agoET/WC+/SWMKQRCGNh6CsVwjHjsrZUdgc3f0hiYs+Jb4im5FVsrj9SybJyENYTj iCFvReKmrMWXo26g08A70zp1r7zX/V0UJo2oWecbJtNvWl7DtV15QRZfjThBrc/XStvhIM+tg4= X-Received: by 2002:a05:600c:3b17:b0:49c:fc6e:8cae with SMTP id 5b1f17b1804b1-49fc5737b80mr2821275e9.18.1789682892211; Thu, 17 Sep 2026 15:08:12 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-49fc471b9a2sm8984075e9.0.2026.09.17.15.08.11 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Thu, 17 Sep 2026 15:08:11 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][wrynose 43/79] util-linux: inherit upstream-stable-release-point Date: Fri, 18 Sep 2026 00:06:28 +0200 Message-ID: <9cf210b327f0e645757f7187efa6c74360218c21.1789681419.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Thu, 17 Sep 2026 22:08:16 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/246138 From: Daniel Turull util-linux's README ("Stable Branches") documents stable/v. branches whose maintenance releases are bug fixes only, so upgrades within a major.minor are stable point upgrades per the OE-Core stable release policy (ref-manual, "Stable Point Release Upgrades"). https://docs.yoctoproject.org/dev/ref-manual/release-process.html#stable-point-release-upgrades https://github.com/util-linux/util-linux/blob/v2.42.2/README#L95 Checked the last point release for feature creep: 2.42.2 (Jun 16 2026), against 2.42.1 (May 18 2026): 32 commits, all fixes or hardening -- memory safety (a libblkid use-after-free, two buffer overflows, a libfdisk GPT fix), privilege tightening (X-mount.subdir restricted for non-root), diagnostics (fanotify queue overflow detection) and documentation. No new options or behaviour. These releases are not picked up on the OE stable branches: util-linux has had zero point-release bumps on kirkstone, scarthgap or wrynose since each branch forked from master, leaving them at 2.37.4, 2.39.3 and 2.41.3 respectively. This addresses that gap going forward. Scarthgap already has v2.39.3, and the 2.39.x stable branch history (mount API regression fix in 2.39.1, new CPU model support, and libblkid’s bcachefs handling) demonstrates that util-linux exercises good judgement in managing stable branches, so we can safely track their stable series there as well. For the avoidance of doubt it is not a development-series effect either: util-linux has no development/stable version split, and pre-release work goes to -rc tags. AI-Generated: Kiro with Claude Opus 5 Signed-off-by: Daniel Turull Signed-off-by: Richard Purdie (cherry picked from commit d51c6e87a10c7c75a692ca86b71af9a818026ecb) Signed-off-by: Yoann Congal --- meta/recipes-core/util-linux/util-linux.inc | 4 ++++ 1 file changed, 4 insertions(+) diff --git a/meta/recipes-core/util-linux/util-linux.inc b/meta/recipes-core/util-linux/util-linux.inc index 09916594b0a..be49160eac9 100644 --- a/meta/recipes-core/util-linux/util-linux.inc +++ b/meta/recipes-core/util-linux/util-linux.inc @@ -28,3 +28,7 @@ SRC_URI[sha256sum] = "f586e35d320ff537aab3ffeca37e9ecd482ccbe013590db4429a414d8a CVE_PRODUCT = "util-linux" CVE_STATUS[CVE-2026-13595] = "cpe-stable-backport: Fixed from version >=2.41.5" + +# util-linux publishes bugfix/security-only point releases on its +# stable/v branches. +inherit upstream-stable-release-point From patchwork Thu Sep 17 22:06:29 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 98604 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 8E358C982DC for ; Thu, 17 Sep 2026 22:08:16 +0000 (UTC) Received: from mail-wm2-f13.google.com (mail-wm2-f13.google.com [74.125.225.141]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.1589.1789682894470389806 for ; Thu, 17 Sep 2026 15:08:14 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=XEnpcUdH; spf=pass (domain: smile.fr, ip: 74.125.225.141, mailfrom: yoann.congal@smile.fr) Received: by mail-wm2-f13.google.com with SMTP id 5b1f17b1804b1-49e6c0fce17so585435e9.1 for ; Thu, 17 Sep 2026 15:08:14 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1789682893; x=1790287693; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=y2yxohL04FaC66ic1nHPsxZggE9jbCHoXmyxbJ+7ZOg=; b=XEnpcUdHuyv/E9oSBnkVffjZUz5+M0cO3oFO0LuwweRNsZN0Fb1tqpjYaRqnJB9D+P Og3DU3DUk5NADnCrDJkC/yR6pDJ5znTjggZJF7xvjJcPihuBgsRbzcp7/ySJrHROzkII kilhmO9/vaQ2D/arDsxsnI9Cijm7JwtRgrSkg= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1789682893; x=1790287693; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=y2yxohL04FaC66ic1nHPsxZggE9jbCHoXmyxbJ+7ZOg=; b=kh37/7LZIG7FHLEiQeuCvWb+rzzjmvfE112Z1AZftjEa+DcF2BI+CWAG9uoMisOI24 c103WuPetfXacUKdktwISXfSEk3FYeD2LzZWyrsPFigUn+wogPrPoaqpHLzuF7quoBF6 pvuDSKr6nxmkEK6uYmEKwt5UuXU6qzyMfM/WheqUW/DGYINyGuYkXoGOXcAoXUFMdGjA c0YreS5XUgJw1RcFa82wBGHqFV78fMQWjV+Kf7+z4LzDfEPObRQdpzAHwl/wZ+ur0fkv yJKbBZU8JMIv1qK5IuxjDkxnvH8cecMNKUM7xbLrDUwUOdLEbb0AVViGsORRPvROYoSL zhkA== X-Gm-Message-State: AFuF++lDyy6/z/0adXgyGPe08A+b68XgJAa/6obS5SZ1tOmxc0Yjq3uE 4iBDaTJnzEtw0tPhxukzghdEvQIIHL8tVCICzgeG6VB6pf7OSn5/6q0T8KkbNTmQKPZ+YCy+qT5 WEZ/5kdw= X-Gm-Gg: AYBFou3bGVHYwf768uEJ5Jy47xZY52p48+DbYtDHql1eocU/NKTN7K09CYewohjZAgI AcdiCo7ryxIIVksu5zgeDswlNFkoeBevu9LHOsmp9Eb8BZ+4m8h3QXKVVp9uYyjaJmctDCB8SIv 4yYnqdQVpehni/s1mhctx/HgIng1dap0xjGwQaaTLyTAtAgI2XUZeaKufnPD3RvK7HN6VjSVYrW j2f2EB6Hh9eiL2yDxPyAU/c9gkDPFs6GHhbdtrH9JD1u6nEycWxUtvX6XGhxSdyaqwuxu7N22BH 7kg25Kczg9mWixLsJQi6iDBpgP0M2lVFFWdUZYi1N9xik5v25v2U3AaQIPglMajbQlIqmoLXL1v rDgiYv8275s8mGZdyQPE7BPtLyU8O42eOSnwYnVffi2wognUGng0b/VhrkEm4m5fbS6pUyHvmYw n2FnNMe/Vyuwrxng2wKhW2o5LKxAdcvNSFL2DIs6AW7dcSGd9hSYPW12L4Q9jYBFBEtSFgnhm7w t3fSUTm+8xcGMIGdZ5ZaeoAWe4qoArf7hcx+ygtr43nXfTIPqFQOaUqDCgs4qsFbmqP3VG3yTc= X-Received: by 2002:a05:600c:8b21:b0:49d:1df8:156d with SMTP id 5b1f17b1804b1-49fc574f001mr2975365e9.18.1789682892745; Thu, 17 Sep 2026 15:08:12 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-49fc471b9a2sm8984075e9.0.2026.09.17.15.08.12 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Thu, 17 Sep 2026 15:08:12 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][wrynose 44/79] lttng-ust: inherit upstream-stable-release-point Date: Fri, 18 Sep 2026 00:06:29 +0200 Message-ID: <767c3921cdd88f0709731a9c46b59ed5b8479044.1789681419.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Thu, 17 Sep 2026 22:08:16 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/246139 From: Daniel Turull lttng-ust maintains a branch per minor series (stable-2.13 through stable-2.16) and releases from several at once: 2.14.2 and 2.15.1 went out the same day in May 2026, and three series together in February, 2.13.10, 2.14.1 and 2.15.0. So upgrades within a major.minor are stable point upgrades per the OE-Core stable release policy (ref-manual, "Stable Point Release Upgrades"). There is no written policy document, so qualification rests on that branch structure and the release contents below. https://docs.yoctoproject.org/dev/ref-manual/release-process.html#stable-point-release-upgrades https://github.com/lttng/lttng-ust/tree/stable-2.15 Upstream keeps a ChangeLog with a per-release entry list, and every entry for the one point release in the current series is labelled a fix. 2.15.1 (May 22 2026) covers a negative error code on incorrect message size, a shmp() return value checked before dereference, an underflow warning in zero_file, uninitialised LTTNG_UST_LFILE and sigevent structs, close_range inefficiency and excessive fd-tracker memory use, and a NULL check in ustctl. The one non-fix entry changes a likely to unlikely branch hint. Only one point release exists in the 2.15 series so far, so this also rests on the 2.13 series' record, which ran to ten. Already tracked this way on the OE stable branches, counting only bumps since each branch forked: kirkstone took 2.13.5 -> 2.13.6 and scarthgap 2.13.7 -> 2.13.8 -> 2.13.10. wrynose has taken none and sits at 2.14.0. AI-Generated: Kiro with Claude Opus 5 Signed-off-by: Daniel Turull Signed-off-by: Mathieu Dubois-Briand Signed-off-by: Richard Purdie Adapted for wrynose: applied to lttng-ust_2.14.0.bb (upstream: lttng-ust_2.15.1.bb). (cherry picked from commit a5dcaef20fc91539efa08b47607c4c91f4f49849) Signed-off-by: Yoann Congal [YC: lttng-ust stable policy: https://github.com/lttng/lttng-tools/blob/stable-2.15/README.adoc#supported-versions: |Supported versions |------------------ | |The LTTng project supports the last two released stable versions |(e.g. stable-2.13 and stable-2.12). | |Fixes are backported from the master branch to the last stable version |unless those fixes would break the ABI or API. Those fixes may be backported |to the second-last stable version, depending on complexity and ABI/API |compatibility. | |Security fixes are backported from the master branch to both of the last stable |version and the the second-last stable version. | |New features are integrated into the master branch and not backported to the |last stable branch. ] --- meta/recipes-kernel/lttng/lttng-ust_2.14.0.bb | 4 +++- 1 file changed, 3 insertions(+), 1 deletion(-) diff --git a/meta/recipes-kernel/lttng/lttng-ust_2.14.0.bb b/meta/recipes-kernel/lttng/lttng-ust_2.14.0.bb index 1a15c5b4201..4285a445d67 100644 --- a/meta/recipes-kernel/lttng/lttng-ust_2.14.0.bb +++ b/meta/recipes-kernel/lttng/lttng-ust_2.14.0.bb @@ -11,7 +11,9 @@ PYTHON_OPTION = "am_cv_python_pyexecdir='${PYTHON_SITEPACKAGES_DIR}' \ PYTHON_INCLUDE='-I${STAGING_INCDIR}/python${PYTHON_BASEVERSION}${PYTHON_ABI}' \ " -inherit autotools lib_package manpages python3native pkgconfig +# lttng-ust publishes bugfix/security-only releases on its per-minor +# stable-X.Y branches, the same upstream and release model as lttng-tools. +inherit autotools lib_package manpages python3native pkgconfig upstream-stable-release-point include lttng-platforms.inc From patchwork Thu Sep 17 22:06:30 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 98597 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 3A803C982D8 for ; Thu, 17 Sep 2026 22:08:16 +0000 (UTC) Received: from mail-wm2-f13.google.com (mail-wm2-f13.google.com [74.125.225.141]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.1690.1789682894928114525 for ; Thu, 17 Sep 2026 15:08:15 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=osjxu1Ut; spf=pass (domain: smile.fr, ip: 74.125.225.141, mailfrom: yoann.congal@smile.fr) Received: by mail-wm2-f13.google.com with SMTP id 5b1f17b1804b1-49b912e64ccso1006445e9.0 for ; Thu, 17 Sep 2026 15:08:14 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1789682893; x=1790287693; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=/mynyi+jqbESn6LtPwFNdECTVYiQOm98OP4ssLDlvyw=; b=osjxu1UttzbIxLsME0BFStUL+R2vx94Og1/gcPxrRy51/01pHJsI5LKxN/zQU1oZ3e aAp6ukLcdB/fNpy4pmHheA3+47zSnJX3f1cKunsQ4ThdOC5po4M19tXBJFxESIjz/ecF liX/Z/ipERa+ik/yJi9x9I9ta5wCzFeTF+6+c= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1789682893; x=1790287693; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=/mynyi+jqbESn6LtPwFNdECTVYiQOm98OP4ssLDlvyw=; b=ne9SjhqXmN0D4I6SV0QNW+MGtyG0eJIr2p8CbAAtGHXUXBhXMBvQPBxnfuBBTM+xIu jv7c922DYbeWQkMzNOkhVxTnPMTL05T/fGuLvnb8q9dscBBhcC6mAMkbfgXS3CKjGy/x A+c9+5Dx9xL2V0Ssa5YOPbYrd5NsVNPh7ElMP1A7qzHRcYyhG7tdeHuiQKTTxTeSBlAI Ws+N+JVHOaCafdKS05w/poviFpLh56y2zQEtB30gR7tuJXB4F2d+X317MN+wmkASnbzU 6SWvcI3jhwveP10JtOv75+iGPKlvrmODtIb3//fYbEc5/9q67M4PK19zdS7nJNkJP1Vj 0Ytg== X-Gm-Message-State: AFuF++l1QMMbsE/tkHAZdWeYz2z+WtL/WrwYehlIkGvH3lbggpYPTS6c jHSFCJ7jpRcZ448tg7HtbYDZ0ZC7Cr52XYA6aTqHlbb79PgEiNvbszKPVR6aIQc08PiXDZm0Hnl mT4RYDI0= X-Gm-Gg: AYBFou20mQs0HOQGsBfTd/Uo6M4aohbYUlQtFey/57NExR39bTyBXRi317F8b7Eajt/ GQLcY8mAVFAyGw2YwvN+cZWtsHAsWVmKeCdxKFzKywTCtug9X3ISdV3OOVeUGT4pWEC9wmKPwrQ bkBltSSnn7fvWJyBhX9reUN9wfWvX4YgDHncmnpss5RWi+1iQrI8tfwFZkEliTN7Bxe9r2NVush iST6uWYVKOoWTE+abmgy3KCSVi4ZnxqK6WRxteBzJxW6ZFezGxJpESj+q2Rvp/vaaD0pdvHDnkI u0JNupUqLAR1BTSC8Slltf0xyGQoOHakrNo4hVVi6chBZaUzBpt16moLwm2YJbP2ZFEi3XvNmRG G/TaVBOj/DyXbIVXmz9Zgor+hkLLmO1s4t4oA347EqUlETFLewNctz6qUacIahtByMJOU0QA9bd 85WfjZSvHIZoPccMWtf2GKuOPUENUMgbo5rDwaF+mgk0kmQUAGFThRz+56swPt8rqEwXNLrZF0j dRObQWf0v+jm2trScCYxpNno9TTLaTGpS1YiR78GcNrqrZR98+M3O2j3m2D0oVjoDYBBWXX0mgo X-Received: by 2002:a05:600c:4e86:b0:49c:d52e:d0ea with SMTP id 5b1f17b1804b1-49fc566e6efmr3231465e9.4.1789682893209; Thu, 17 Sep 2026 15:08:13 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-49fc471b9a2sm8984075e9.0.2026.09.17.15.08.12 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Thu, 17 Sep 2026 15:08:12 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][wrynose 45/79] babeltrace2: inherit upstream-stable-release-point Date: Fri, 18 Sep 2026 00:06:30 +0200 Message-ID: X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Thu, 17 Sep 2026 22:08:16 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/246140 From: Daniel Turull babeltrace2 maintains a branch per minor series (stable-2.0, stable-2.1) and keeps the older one alive: 2.0.7 and 2.1.2 were released the same day in July 2025, with 2.1.1 already out since April. So upgrades within a major.minor are stable point upgrades per the OE-Core stable release policy (ref-manual, "Stable Point Release Upgrades"). There is no written policy document, so qualification rests on that branch structure and the release contents below. https://docs.yoctoproject.org/dev/ref-manual/release-process.html#stable-point-release-upgrades https://github.com/efficios/babeltrace/tree/stable-2.1 Upstream keeps a ChangeLog with a per-release entry list. Both point releases in the current series are fixes, tests and documentation: 2.1.2 (Jul 22 2025) is 13 commits, and 2.1.1 (Apr 14 2025) 10. Already tracked this way on the OE stable branches, counting only bumps since each branch forked: kirkstone took 2.0.4 -> 2.0.5 and scarthgap 2.0.5 -> 2.0.6. wrynose has taken none and sits at 2.1.2. AI-Generated: Kiro with Claude Opus 5 Signed-off-by: Daniel Turull Signed-off-by: Mathieu Dubois-Briand Signed-off-by: Richard Purdie (cherry picked from commit 3d742fa47d795b6b013d5ca3d78f0dd601432832) Signed-off-by: Yoann Congal --- meta/recipes-kernel/lttng/babeltrace2_2.1.2.bb | 4 +++- 1 file changed, 3 insertions(+), 1 deletion(-) diff --git a/meta/recipes-kernel/lttng/babeltrace2_2.1.2.bb b/meta/recipes-kernel/lttng/babeltrace2_2.1.2.bb index b0cd6efde18..5b9c02b0c21 100644 --- a/meta/recipes-kernel/lttng/babeltrace2_2.1.2.bb +++ b/meta/recipes-kernel/lttng/babeltrace2_2.1.2.bb @@ -19,7 +19,9 @@ SRC_URI = "git://git.efficios.com/babeltrace.git;branch=stable-2.1;protocol=http SRCREV = "d0e946a71faf5f0c2d7f1fb5b92a369983e9cf10" UPSTREAM_CHECK_GITTAGREGEX = "v(?P2(\.\d+)+)$" -inherit autotools pkgconfig ptest setuptools3-base +# babeltrace2 publishes bugfix/security-only releases on its per-minor +# stable-X.Y branches. +inherit autotools pkgconfig ptest setuptools3-base upstream-stable-release-point EXTRA_OECONF = "--disable-debug-info --disable-Werror --enable-python-plugins --enable-python-bindings" From patchwork Thu Sep 17 22:06:31 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 98602 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id C42A9C982DD for ; Thu, 17 Sep 2026 22:08:16 +0000 (UTC) Received: from mail-wm2-f13.google.com (mail-wm2-f13.google.com [74.125.225.141]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.1590.1789682895613281577 for ; Thu, 17 Sep 2026 15:08:15 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=sKKH4Hr/; spf=pass (domain: smile.fr, ip: 74.125.225.141, mailfrom: yoann.congal@smile.fr) Received: by mail-wm2-f13.google.com with SMTP id 5b1f17b1804b1-49e721b5503so1217415e9.0 for ; Thu, 17 Sep 2026 15:08:15 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1789682894; x=1790287694; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=iSXlHMYpiXCM7Hl89IMes8px9euHPY2Z0uJPd2LUpJU=; b=sKKH4Hr/E/uqwHL5EHRqa8oqeDgzD2oIJMU6hoBodpLW9HrABjGgshkPYoOhyqYdB8 XxoH65HNU2tBhu2H6clwxT02qihRx0aYSsujfVyRm8BHolMgbrm8ljWXIJwUTuw7f3Qq V8TjNpoCJsZe9paCbHUh8NVA3MAi2bUkkJzBE= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1789682894; x=1790287694; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=iSXlHMYpiXCM7Hl89IMes8px9euHPY2Z0uJPd2LUpJU=; b=AeqEuryaeyGuZIlsFjbgWw6cgpqYfEQEGdeJDr68nsjtKev6NgKvFOWdPnSqrZHyGp +Ze6fbR5dq5wWK0YfuHlXIKnWngzkHcwBzCaj9wdDGmlk0SE8QTRpQ7VOgz5DlerDHg0 VElHuYVhQs+PLzP3gO01L2Pg2RQ0brWXUpOGWGXDpSK7DbRR5xVJss+TmohwU5xXx441 927HETmHyaGBxofbjv9Q5lmiCVp5LER29kcF1/ZtM7J5of5XuiOXFlRh4isPNs9eiiTe sWw0JN2mXj+4Y6660cuX+LgRKKS5XlE+hE7H4yYyagsV/5RVqNATGLPn4qiIbUL7YpVz v0Yw== X-Gm-Message-State: AFuF++nVQwQPkqPC46cJbBXRj14zSGEDq7RPqwnDMH0Akpk2yuT+zYD8 v4BtrruvzRx92oZ2K8VqyC7kxi0pU5u1I8AM0cd5srCBNGGwaWDqLAwD6UpDdMUTGpOQo2IKvGC VXGDSeNs= X-Gm-Gg: AYBFou0vVkZQTlCAh3rjh87lPouq/9mxwKHpvWcGKedPsCWe1UMriZ4ZrFj5/B4gkbq 92m/OfYve17wiuY3f9NBDXCdjYuJoMJmMCTIkooOWp0IH02VZpzAyPhn+6Sfv1l5gGBT2G/pMHT u6UhTOtXKaKWmI+RD1imTe94bIEcB7Ov3KadD9OCnwc7p7igF70e2y0JAX44/mQDTaxMYlVVQ1Q gzxlWvMrgOEDeWWlfqN55vPsDGKQCvyoUGDhARK9il0+ydfD5GUq9cGU04QGONGe3HLDvQlu6WJ gFhFVfUj3Skh7Eza+n8+Wl12pV0LHLhzBTdDnyFLtNe/6Kpsvu7KbYi2eiD/lAJ2fQO8Zezll35 UZzOh3mldwMRDxqhP64yzI4kaTy9TKL3W7HZDD4Q3aAn0VZuppB+sW6WaQXiJ+gaF+jp11GjSw1 obdG1/sngjw0taPDUMIvptWPC+74ORNOUn22j1LB1YXKtjXORnhpbkyeEyQE1Wncg/bek+Hjhb1 9px4f52gecPlzTL2XSn6zKKjO8CBf/Q+Oj1HsNZvQ/65rao2Q2smsY/gdXHBj4NFEjMDBqpvxM= X-Received: by 2002:a05:600c:3556:b0:49d:797:83bf with SMTP id 5b1f17b1804b1-49fc57360damr3385215e9.21.1789682893836; Thu, 17 Sep 2026 15:08:13 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-49fc471b9a2sm8984075e9.0.2026.09.17.15.08.13 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Thu, 17 Sep 2026 15:08:13 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][wrynose 46/79] lttng-modules: inherit upstream-stable-release-point Date: Fri, 18 Sep 2026 00:06:31 +0200 Message-ID: <104bd209ec7eec8b3ff046e40d363b35e9a9829b.1789681419.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Thu, 17 Sep 2026 22:08:16 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/246141 From: Daniel Turull The LTTng project documents its stable-branch policy in README.md, "Supported versions" at L171: fixes are backported to the last stable version unless they would break the ABI or API, and security fixes to the last two. So upgrades within a major.minor are stable point upgrades per the OE-Core stable release policy (ref-manual, "Stable Point Release Upgrades"). https://docs.yoctoproject.org/dev/ref-manual/release-process.html#stable-point-release-upgrades https://github.com/lttng/lttng-modules/blob/v2.15.2/README.md#supported-versions https://github.com/lttng/lttng-modules/tree/stable-2.15 This recipe's policy differs from the rest of the project in one respect worth stating. Where lttng-ust and lttng-tools do not backport new features at all, L185 says kernel-version enablement is backported to the last stable version. That is the only non-fix content a point release carries, and for a kernel tracer it keeps existing probes working against newer kernels rather than adding anything a user can call: no new options, no new API, no changed defaults. Upstream labels these entries "fix:" alongside the rest. Six branches are maintained in parallel, stable-2.11 through stable-2.16, and released from together: 2.14.6 and 2.15.2 the same day in June 2026, 2.14.5 and 2.15.1 in April, seven such days in the last two years. The ChangeLog entries for the current series are fixes throughout. 2.15.2 (Jun 19 2026) is 13 entries: a leaked file and fd on channel create error, plus twelve probe adjustments tracking kernel changes to ext4, btrfs, vfs, vmscan and hrtimer tracepoints. 2.15.1 (Apr 24 2026) is three, covering kallsyms on powerpc64 with ABI V1, a snd_soc_dapm_context move and a btrfs probe range. This recipe must share its minor version with lttng-ust and lttng-tools: lttng-tools README.adoc L123 states it supports the kernel and user space tracers "sharing the same _minor_ version", and that cross-version combinations are untested. Pinning the regex to the minor is what keeps that guarantee, permitting 2.15.x -> 2.15.y and excluding the 2.15 -> 2.16 bump that would need the three coordinated. Within a series they have never moved together on any branch: taking modules, tools and ust in turn, kirkstone ships 2.13.14, 2.13.9 and 2.13.6; scarthgap 2.13.12, 2.13.13 and 2.13.10; wrynose 2.14.4, 2.14.1 and 2.14.0. The minor agrees in every row and the patch in none, and scarthgap has lttng-tools ahead of this recipe rather than behind. There is no build dependency between them either. Already tracked this way on the OE stable branches, and more thoroughly than most: counting only bumps since each branch forked, kirkstone took 2.13.4 -> 2.13.5 -> 2.13.7 -> 2.13.8 -> 2.13.9 -> 2.13.14, scarthgap 2.13.9 -> 2.13.10 -> 2.13.11 -> 2.13.12, and wrynose 2.14.0 through 2.14.4. Each also carries local "fix build for kernel N" patches between those bumps, which is the burden that staying current within a series reduces. AI-Generated: Kiro with Claude Opus 5 Signed-off-by: Daniel Turull Signed-off-by: Mathieu Dubois-Briand Signed-off-by: Richard Purdie Adapted for wrynose: applied to lttng-modules_2.14.4.bb (upstream: lttng-modules_2.15.2.bb). (cherry picked from commit d4666244a51c7fb8fa7e66c11d91692197c89ce7) Signed-off-by: Yoann Congal --- meta/recipes-kernel/lttng/lttng-modules_2.14.4.bb | 6 ++++++ 1 file changed, 6 insertions(+) diff --git a/meta/recipes-kernel/lttng/lttng-modules_2.14.4.bb b/meta/recipes-kernel/lttng/lttng-modules_2.14.4.bb index b2c697d365d..d0983f58cbe 100644 --- a/meta/recipes-kernel/lttng/lttng-modules_2.14.4.bb +++ b/meta/recipes-kernel/lttng/lttng-modules_2.14.4.bb @@ -7,6 +7,12 @@ LIC_FILES_CHKSUM = "file://LICENSE;md5=018e002dbdda3306682e394ddd65fa32" inherit module +# lttng-modules publishes bugfix/security-only releases on its per-minor +# stable-X.Y branches. Point releases also carry kernel-version enablement, +# which keeps existing probes working against newer kernels rather than adding +# user-visible functionality. +inherit upstream-stable-release-point + include lttng-platforms.inc SRC_URI = "https://lttng.org/files/${BPN}/${BPN}-${PV}.tar.bz2 \ From patchwork Thu Sep 17 22:06:32 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 98614 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id A7297C982EC for ; Thu, 17 Sep 2026 22:08:17 +0000 (UTC) Received: from mail-wm2-f12.google.com (mail-wm2-f12.google.com [74.125.225.140]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.1692.1789682896301029686 for ; Thu, 17 Sep 2026 15:08:16 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=I/LXFC0J; spf=pass (domain: smile.fr, ip: 74.125.225.140, mailfrom: yoann.congal@smile.fr) Received: by mail-wm2-f12.google.com with SMTP id 5b1f17b1804b1-49d097b4939so701105e9.0 for ; Thu, 17 Sep 2026 15:08:16 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1789682894; x=1790287694; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=qLHBkJPeDLHxG6F2ovknGr0/CTuiEk9I6SfWOArHTfo=; b=I/LXFC0J9XXuzXmvjxlYpwkwg2xbYyro3Be2j4pOjb1oFz+l0t3a+79dewcBDFZhb/ miRte+SSO1CFSRBgF70lxtXBtPeTlcXz/YJbY3uwGTT2qvD1hufUzKsJjRRipE6wmHNt pMUNqkszjyF1gnsQOMBVkSKfPSOt9r/W0r1Is= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1789682894; x=1790287694; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=qLHBkJPeDLHxG6F2ovknGr0/CTuiEk9I6SfWOArHTfo=; b=PGUGObcXtUNx4tmH9+6tQxNY4iH7zUsokN5073eEZ/BWse3K3h5PaqMiNHDaLzowH8 W9FfQKo6nxwYRoCqKfP+thd054zMQ5pvYN4dNAi7tQ8PztObJFJdqe4MQMiZ6Xi3K5mh S992iiqba357xvMHeElteNwrUSUtnkycP/GyWWixNf2pAsJnCbfeaTLylvmQLsEx2EKu ZeuCECnClELft38zYzjKXGxTnXc7KyBD2ndJZEQixZpNeVKE/eMByatfZB+dgXIjkJpo 2o5oPFcpsxFg+o8d8PTuaDWO7pRhj8gvqLMXFCR4f4+Xw1NeRG1waIapEX09mBK7wMvs vE0A== X-Gm-Message-State: AFuF++kJ0Jf2ERNbT3yAWayzLDf4HRRB2gMPXlb4Q45LX/rcY9twTwO/ NYeRqdIKWZHqEw52kA/1UOAqASgpf9KHWqrTpK4p96Pxj3Bf0SwHDG3mxn/q+v7E86wuRDpekbG w4FV4ms8= X-Gm-Gg: AYBFou3AH3pyMRXRP3mJV+ie4+f+KoRAQYxEggSxdoiWifc+YjW6QLgf3IIqobcpjL1 XlG6iYfY31bfuJbgGEQ+5C5WShFSLdt0JBidwTBRpeYenA/GCmQ3BufAiPYIQwdW17poRzBpms9 u8G1QajaXooTDlAHQKMfsqAGnS0XfTJ46fOkACwIf+VzI3BRjQU8kudzAERCmkjAqZosBiDnrQY x/aJGfhaTfzl4/uW/yoHpGQPhtOqnZSYlvrQ8zcrz5U4QSGdgla8EjcjnnnxKXY0rPo2Zr/z4uk Q4MQhJeYQTgfL+cl6dKjnQM8nAD9+FC1AtQe8pszoNZ52nIX+sEen6ecL2xnHSnIREexkjmgfkd jY3KTb2WNT+L43Zs9TsTzJ/rbM3GtkabXwF//cgqbYNnJ7fVmCUWuDh2GwpVqlN72gDpCUCiYeW y6xWX3/isGiwduXcIdrssgF0Oxf4gIjeS7vsI8Unu8jwL9K45gFzxFjcX3DdG+GeVcVJbXMyl0C SChQLWbbbNwvT9dNhxhsZxoGnJ2ugyxWaSDGyrkVnSZ3GIEyi2AhFqSa9sXbYzz84iZ0xIzeCI= X-Received: by 2002:a05:600c:3e06:b0:49e:7a10:1b71 with SMTP id 5b1f17b1804b1-49fc56d2ea3mr3499155e9.11.1789682894624; Thu, 17 Sep 2026 15:08:14 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-49fc471b9a2sm8984075e9.0.2026.09.17.15.08.14 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Thu, 17 Sep 2026 15:08:14 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][wrynose 47/79] libslirp: fix upstream version check Date: Fri, 18 Sep 2026 00:06:32 +0200 Message-ID: X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Thu, 17 Sep 2026 22:08:17 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/246142 From: Alexander Kanavin The regex excludes bogus old yyyymmdd tags which sort higher than real versions. Signed-off-by: Alexander Kanavin Signed-off-by: Richard Purdie (From OE-Core rev: 2a60e5db4460cd8ec99b43d8f2ff733ba509c373) Signed-off-by: Peter Marko Signed-off-by: Yoann Congal --- meta/recipes-connectivity/slirp/libslirp_4.9.1.bb | 1 + 1 file changed, 1 insertion(+) diff --git a/meta/recipes-connectivity/slirp/libslirp_4.9.1.bb b/meta/recipes-connectivity/slirp/libslirp_4.9.1.bb index 9f7005d7098..50577fd4ae2 100644 --- a/meta/recipes-connectivity/slirp/libslirp_4.9.1.bb +++ b/meta/recipes-connectivity/slirp/libslirp_4.9.1.bb @@ -6,6 +6,7 @@ LIC_FILES_CHKSUM = "file://COPYRIGHT;md5=bca0186b14e6b05e338e729f106db727" SRC_URI = "git://gitlab.freedesktop.org/slirp/libslirp.git;protocol=https;branch=master" SRCREV = "9c744e1e52aa0d9646ed91d789d588696292c21e" +UPSTREAM_CHECK_GITTAGREGEX = "v(?P\d+(\.\d+)+)" DEPENDS = "glib-2.0" From patchwork Thu Sep 17 22:06:33 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 98615 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id BAC2FC982EB for ; Thu, 17 Sep 2026 22:08:17 +0000 (UTC) Received: from mail-wm2-f13.google.com (mail-wm2-f13.google.com [74.125.225.141]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.1591.1789682896783613870 for ; Thu, 17 Sep 2026 15:08:17 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=sH4YGne+; spf=pass (domain: smile.fr, ip: 74.125.225.141, mailfrom: yoann.congal@smile.fr) Received: by mail-wm2-f13.google.com with SMTP id 5b1f17b1804b1-49e6c0fce17so585555e9.1 for ; Thu, 17 Sep 2026 15:08:16 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1789682895; x=1790287695; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=H+cvQyfnd75XcDVK1mc4cC9M57/SDsrtPWc2L4OTYNQ=; b=sH4YGne+pVgHnwNQORwRNigUbP3q4njoQ7BpPPUyLrG8xSzaqY+5gkmFVk7MvZZKHr M8+npkW2soSWjlx9A5qg4fUQdBLA2V3xBzy4BOr3jKg9tDtXC6AojMD288aHGlkanQU3 /4w0iqsuIvuVv4xLZ9KZg9noEbjYuLs4TcQlk= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1789682895; x=1790287695; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=H+cvQyfnd75XcDVK1mc4cC9M57/SDsrtPWc2L4OTYNQ=; b=jKtqTBSTZ12uo7Pjr3tJqNYDVhEOG//WGCmTizkr0+m6lT6E9Uxk7IRbdhmGUPAle4 mVflilcmeXtwaqAKYmOqKzbQxnAAHd1n/+FuAEZZiuNZ3aRurEk4mMfpnfMcuoPzI3/Y eafS1YDRdCFR7EM7q+Vvy3o0z3kVzYgFsM3yn6qfyCxb9nE7GyC7+ylyb0rbxDzY13Vq 2RDv5a5ORs4cBnvvJd2PHp+iANJ/JWH0+Vo6wmeEz1I/Z2Nt8gGXImABFd1XiOqFvrRX X+R0no4NbeiDsCGJL4BNsz+2y5d+kZzcG06JJk8ZPnZWzwzu9DVYhA/HBFSBv9x8VMgp gdGg== X-Gm-Message-State: AFuF++kOD8F87vDYW7v4Im+cHH8ZUzIZt3AtVQblUz/Tt+rLYO1LMYco IbS6yvYW0NC1Mb7pne9YKS2O2l2n0axepr39HtsGH51iP2IzLBilKxE8cK03dbgA6gUkY0mVTNH P7vxRY3U= X-Gm-Gg: AYBFou3lUQYW84KVBCSm4xv/MFX8iVEyraRjC5pRBusIUQUq6WwcThb3bTET7bZWQ5v 9RGraPIdbBIX88mK5ABvp4ueEP2hu8LXrkt2Gwr3++DKUx7Kd/OY21ZJ1fTnVHmlfUroppMLUBK A8HYzyP3lzX3r3dqqMCe0+SsWoHT8EHLkGEPDS4cg2P5IGUB89F5LyeohR/3ehzemb1TZxb8p30 9bdqRu7rgB5eXPcFmUJUakDNdxzbvmvlKoZtVgLPbU9CEBFaEPlEc90wSnc7rNDG5hi5eRsiP25 177oALwtSGi9OtkCEEQzTI15IfOlQf7mvAwZW1b1n5PBR0zrf2HXjR08TPk4Lhd35PlbPD/rleQ ulGktZ9t7XQegeB2ydYkuC5cYD5oVcWrY69OvwXjKQHjiCsCR+cWdO7JPg/TZhMHuDc60wwOA7L 0Ja3nCIgl2tVCanW+dGQjbMYOYs+olAUGKaSKET8DWSMHl6yV4T9aBMBLGrZSgf95BiO68W+Gie G67uxm4t6jv9hgA1qXa3X/rbRqFZv+AFfSBlOX6IRGQ+JsS5LyeyQ/1fTq2QDCAyDVgasHILzQ= X-Received: by 2002:a05:600c:310d:b0:49d:15b9:2a2a with SMTP id 5b1f17b1804b1-49fc5721b9dmr3319005e9.10.1789682895054; Thu, 17 Sep 2026 15:08:15 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-49fc471b9a2sm8984075e9.0.2026.09.17.15.08.14 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Thu, 17 Sep 2026 15:08:14 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][wrynose 48/79] libslirp: upgrade 4.9.1 -> 4.9.3 Date: Fri, 18 Sep 2026 00:06:33 +0200 Message-ID: <3888ddc31d2e2a9ec59d08733a5ddad9a83e2f84.1789681419.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Thu, 17 Sep 2026 22:08:17 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/246143 From: Alexander Kanavin License-Update: license moved to a separate file https://gitlab.com/qemu-project/libslirp/-/commit/d6cfac6d060d57c0e38a9c61157eaf6962b6c257 Signed-off-by: Alexander Kanavin Signed-off-by: Richard Purdie (From OE-Core rev: 16f511425c537239e487b73998f9d8133a8ca2c4) Full release notes: * https://gitlab.freedesktop.org/slirp/libslirp/-/blob/v4.9.3/CHANGELOG.md?ref_type=tags It also shows one "change": * bootp: allow https for UEFI HTTP boot It however does not change ABI and can also be interpreted as security feature (allowing https), thus should be allowed for LTS backport. Signed-off-by: Peter Marko Signed-off-by: Yoann Congal --- .../slirp/{libslirp_4.9.1.bb => libslirp_4.9.3.bb} | 5 +++-- 1 file changed, 3 insertions(+), 2 deletions(-) rename meta/recipes-connectivity/slirp/{libslirp_4.9.1.bb => libslirp_4.9.3.bb} (70%) diff --git a/meta/recipes-connectivity/slirp/libslirp_4.9.1.bb b/meta/recipes-connectivity/slirp/libslirp_4.9.3.bb similarity index 70% rename from meta/recipes-connectivity/slirp/libslirp_4.9.1.bb rename to meta/recipes-connectivity/slirp/libslirp_4.9.3.bb index 50577fd4ae2..734e59a59b1 100644 --- a/meta/recipes-connectivity/slirp/libslirp_4.9.1.bb +++ b/meta/recipes-connectivity/slirp/libslirp_4.9.3.bb @@ -2,10 +2,11 @@ SUMMARY = "A general purpose TCP-IP emulator" DESCRIPTION = "A general purpose TCP-IP emulator used by virtual machine hypervisors to provide virtual networking services." HOMEPAGE = "https://gitlab.freedesktop.org/slirp/libslirp" LICENSE = "BSD-3-Clause & MIT" -LIC_FILES_CHKSUM = "file://COPYRIGHT;md5=bca0186b14e6b05e338e729f106db727" +LIC_FILES_CHKSUM = "file://COPYRIGHT;md5=f95a9bf4a7e411164fe843697ccda59e \ + file://LICENSE;md5=cfea6044642fd63b90ce9d79f5db64d9" SRC_URI = "git://gitlab.freedesktop.org/slirp/libslirp.git;protocol=https;branch=master" -SRCREV = "9c744e1e52aa0d9646ed91d789d588696292c21e" +SRCREV = "dd76415fce457e319d665eb8210d05c5731360ba" UPSTREAM_CHECK_GITTAGREGEX = "v(?P\d+(\.\d+)+)" DEPENDS = "glib-2.0" From patchwork Thu Sep 17 22:06:34 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 98616 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id AF1D7C982D8 for ; Thu, 17 Sep 2026 22:08:27 +0000 (UTC) Received: from mail-wm2-f12.google.com (mail-wm2-f12.google.com [74.125.225.140]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.1693.1789682897484171736 for ; Thu, 17 Sep 2026 15:08:17 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=FEKEhSr7; spf=pass (domain: smile.fr, ip: 74.125.225.140, mailfrom: yoann.congal@smile.fr) Received: by mail-wm2-f12.google.com with SMTP id 5b1f17b1804b1-49b912d822dso779575e9.2 for ; Thu, 17 Sep 2026 15:08:17 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1789682896; x=1790287696; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=Jx06CbSppKSUW9ph1rTd6PV3f+5T3VQKWk+Zqecs5Yw=; b=FEKEhSr7m7S5BmKjHWQE502WvgWZ0IhhSy8Dd9vJitanCDq0zVnjDaphQLKszz8Na0 G+5RvLYp+8MFeQla+S/WaE3VbT/66PbdH/ZoZkQpKkynHkX9BoYNc6+4R9V/0LofbDFs +Snm5kuTL0G3vveTrXSc/TGjIsWd+p6vciJoc= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1789682896; x=1790287696; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=Jx06CbSppKSUW9ph1rTd6PV3f+5T3VQKWk+Zqecs5Yw=; b=KJpMWUhat/NoXbJk4eTYA7qGPVORQYW2gYsY5D/QZWRL/SIqihu3d8Dr/vVH5GP9sQ 5HrRpMi2QqCe96ox1Jug/ZWdbmLoj+udGpPDoHYbPpmgQSaRxbYXlhxMRN2LR+jMhLrs lN0OvDh+s0bLDcD0Rg7NcmaB/uV0LC/zNy8BPMrjPOTrR8hThAyPA9pAhqrSLLMf+y83 BUsQeG9bT7yDJrMLh+Ys1rT6Dpzf38QpdTg40k+od4vKs53PSMX+ZUe4wujsKmNfio8h 2sar1Xq/PHW8TeIv05bWsCnzYVza7WXds/vtLooRR4zbqFVlhKdzXulb8c7UljK0l2JV ARaQ== X-Gm-Message-State: AFuF++mJvhiXvQTqQqXsdBxfyzc8erlEU5ylyEWfeLeqlBonmvvaSZ75 DSkwhsFN5DY390A8HcktkhzTsvdpQTUoV0nMFXsbwcFS2Ksj5ifeh4aOh5gIyQWkLs8gkeSsaR5 OCKAq1gs= X-Gm-Gg: AYBFou27tsQOShJyP5I3jxahiWRLvXCZgEJTb9KTBF3KEmuMT5zLJxvyhHwV0OJjUoR E7u9xj+iR3sZQeYdb3ZRJrWdBzLOavPIBuqgrRWi2sxd7Pduo8GnyYRud5zMdLqHUbKCYG+eZ0F M+3FB3hgvtbiDrW/X8fsjbSo1xSyVZQ3zKg2d1yP0dIxS5P/Hym4KkKftQHSlkca2EIJFRE0WA5 CayuFGhdQHx3waAUbYHA74EubCWq8v1+5NKNkxMNhfLoOZBixDWl1I/VpgCtuc5/n4iANdWOtyd 5bgqzVsSwJn5cnZJ2UoHTOd5v1VL5Z9HwS4G/ZkZcxrAdVDRdwZZlmCJnzWYAdU6MWorceDvtZB LEqLn/5hmPaNlSnqUA4lbrOsi2fX+Kd6oS0I0Kmii08WXxWWkUmm2CMUaAfe3dxeuVbbMjzGS4y VXrWkbjwqRYxRDHjK6Ma3Ehon0FGE1fN04PivUowfhvHYgYI2P85scfnV+xWsTRFBaWJrYcjfmv vomokxx8GxiiSGKRlQUK2GnZqFjNzGphMgz44Q4jC6M0kAIOh4jXeBANcfAoBc/SgbBxz0jTBk= X-Received: by 2002:a05:600c:19cb:b0:49d:1840:4fd2 with SMTP id 5b1f17b1804b1-49fc573d965mr3158695e9.23.1789682895785; Thu, 17 Sep 2026 15:08:15 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-49fc471b9a2sm8984075e9.0.2026.09.17.15.08.15 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Thu, 17 Sep 2026 15:08:15 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][wrynose 49/79] libslirp: add tag in SRC_URI Date: Fri, 18 Sep 2026 00:06:34 +0200 Message-ID: <842f88435f104aedd9dff2680935d42af3be79ea.1789681419.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Thu, 17 Sep 2026 22:08:27 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/246144 From: Peter Marko This is partial cherry-pick for single recipe: * 00864cf5bcb6d85ec73d338c3e17e263512409a4 It will allow future cherry-picks from mastear and also uses single filename in downloads mirror between master and wrynose (tag is added to filename). Signed-off-by: Peter Marko Signed-off-by: Yoann Congal --- meta/recipes-connectivity/slirp/libslirp_4.9.3.bb | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/meta/recipes-connectivity/slirp/libslirp_4.9.3.bb b/meta/recipes-connectivity/slirp/libslirp_4.9.3.bb index 734e59a59b1..1b45fd32479 100644 --- a/meta/recipes-connectivity/slirp/libslirp_4.9.3.bb +++ b/meta/recipes-connectivity/slirp/libslirp_4.9.3.bb @@ -5,7 +5,7 @@ LICENSE = "BSD-3-Clause & MIT" LIC_FILES_CHKSUM = "file://COPYRIGHT;md5=f95a9bf4a7e411164fe843697ccda59e \ file://LICENSE;md5=cfea6044642fd63b90ce9d79f5db64d9" -SRC_URI = "git://gitlab.freedesktop.org/slirp/libslirp.git;protocol=https;branch=master" +SRC_URI = "git://gitlab.freedesktop.org/slirp/libslirp.git;protocol=https;branch=master;tag=v${PV}" SRCREV = "dd76415fce457e319d665eb8210d05c5731360ba" UPSTREAM_CHECK_GITTAGREGEX = "v(?P\d+(\.\d+)+)" From patchwork Thu Sep 17 22:06:35 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 8bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 98635 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id CDF08C982D2 for ; Thu, 17 Sep 2026 22:08:27 +0000 (UTC) Received: from mail-wm2-f13.google.com (mail-wm2-f13.google.com [74.125.225.141]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.1696.1789682899574561638 for ; Thu, 17 Sep 2026 15:08:20 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=PbJNVM/q; spf=pass (domain: smile.fr, ip: 74.125.225.141, mailfrom: yoann.congal@smile.fr) Received: by mail-wm2-f13.google.com with SMTP id 5b1f17b1804b1-49cd38e0e5dso1337085e9.2 for ; Thu, 17 Sep 2026 15:08:19 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1789682898; x=1790287698; darn=lists.openembedded.org; h=content-transfer-encoding:content-type:mime-version:references :in-reply-to:message-id:date:subject:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=p3Vug3aByeqStDE8G3mfaKXON3fnPDqV2t/hPBa+3bM=; b=PbJNVM/qIw5MmnBn/DEHCYE9rQADYQPdsa66XHAar7K3gPNzz4Vdc2+gaFut0z27Ii o256TRb5BBPBH8XkELBJMgs6WIWF/o38hdePbDL7+7ZUX1WwrsoNZRKyIVv5V406LzyV LrqsleZjRGbtyjz3gr1SfnFN+/4oKWnjjrQW0= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1789682898; x=1790287698; h=content-transfer-encoding:content-type:mime-version:references :in-reply-to:message-id:date:subject:to:from:x-gm-gg :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to :content-type; bh=p3Vug3aByeqStDE8G3mfaKXON3fnPDqV2t/hPBa+3bM=; b=nBAMhhZFECht/r+uTrjyRO+59SLPZN+umBT5Epa+ZSMPCsd5S67SY1UxDq7z8+pfig 0d4oDF04qysrS4fsWC3M6/Ile6KW7af4pwqscN6+xKvSxOygmG2/xvH4L+YWfWQARnWK 5lLYyLH4nV6DtZSweaGjU2RR1mh4VLCbNpXegh8aQ7oGBb3RM1nCSUdySTsUExMNz628 z+Zcd9v7DeivPuJp8EOLL37Dx17UiW3UlPAlco+NWMa/FCPHcAPDR38o0ku1r1vK8yOU y2bA7DA/W2TuDKsViQ7tjNyayVq8tDYT9frmaqF/eZkIFCyB6jsVDlVl4nuxmF1a58Gh z98A== X-Gm-Message-State: AFuF++mcjufskfCTBKgPHo3WAr5Ugw+mRc2ZqgxIGq9sWghiE3PfsLZB hh6gX2caSNM0DR8H2G45MGOkgdQs9xnBDcWg+gtjwlOOI0v38HiEnf5cCvRHpbguySxj2rQptGY NShBXJss= X-Gm-Gg: AYBFou2Zd3+BcXyEzCRXEdYIwVFvCt2cRxbRwWQZiTwGbMLAUMyUGFXJfIGKqgsR0ha EAMx36dg+i6WKoLLs0qt0nc7yz5qFEpw0Y7oqH8RojbFJ5BVOrohYQeTSADACHvQ9dzcjIGuKo5 XIbGx5ZmJA70U1jgR8mNlC94+tKPTsMcMsRp6HkRuV5Gj2CofDJsVeebQykZnUDtOT67I0Qm0W2 OESbRGGCgxMLjOzenkgG8kkwiB3n14yuihuz4rdiPGKwUUA54PoRmx0NCaYwlbtj8EOCrG831c2 mloSxqm2o0JbCmIPzxWttHHcWUbtbEmI1WFEer0hDbb5vDUOBdnS1bm1ns722Ocht6RtFV93Fzw qUDX9p4Rs9kYuscuV8VP1LEyEK2A5LM3llsXC0VsO7oW6mQuAkprygtz4SwmyppeSB6OKKQLYFi ZfegTwD4JgLttX7snMNGP+mkxjuVGcJEPhEN92gUTcYvboXgzGFKQfEei8fFaoZdqVeuojxshLQ kRXUOWi1nKdxPM+WJp6Asz5Mud2L51xWQDInlcTQLYU07Ofdn7O4k8uVDSGggYDhQI5FF1pSfw= X-Received: by 2002:a05:600c:1c20:b0:49f:bd3c:bc1c with SMTP id 5b1f17b1804b1-49fc5739f3bmr3250155e9.23.1789682896577; Thu, 17 Sep 2026 15:08:16 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-49fc471b9a2sm8984075e9.0.2026.09.17.15.08.15 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Thu, 17 Sep 2026 15:08:16 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][wrynose 50/79] expat: upgrade 2.7.5 -> 2.8.3 Date: Fri, 18 Sep 2026 00:06:35 +0200 Message-ID: <4eccd2a25b65e095d167b4fd375667f9c3242f82.1789681419.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Thu, 17 Sep 2026 22:08:27 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/246148 From: Adarsh Jagadish Kamini Upgrade to 2.8.3, dropping 26 backported CVE patches (12 CVEs). This is an exception to the usual stable upgrade policy as we are carrying a large number of patches that are all included upstream in 2.8.3. ABI compatibility verified with abidiff between 2.7.5 and 2.8.3 — no ABI break and no SONAME major bump. Changelog reviewed — no feature removals or backward-incompatible changes; only opt-in additions disabled by default. bitbake world -k built with oe-core + meta-openembedded layers, no expat-related failures. All direct expat dependents built successfully: apr-util, avahi, cmake, createrepo-c, dbus, dbus-broker, dbus-glib, exiv2, fontconfig, gdb, git, graphviz, lftp, libcomps, libdbus-c++, libsolv, libwmf, libxml-parser-perl, log4c, matchbox-keyboard, matchbox-wm, mesa, neon, poco, python3, python3-dbus, sdbus-c++, sdbus-c++-tools, serf, subversion, unbound, wayland, wbxml2, wireshark Ptests passed on qemux86-64 for expat and its runtime consumers: core-image-ptest-expat: OK core-image-ptest-python3: OK core-image-ptest-libxml-parser-perl: OK Additionally includes fixes for (not previously backported): CVE-2026-50219 CVE-2026-56131 CVE-2026-56412 (2.8.2) CVE-2026-72522 (2.8.3) [1] https://github.com/libexpat/libexpat/blob/R_2_8_3/expat/Changes [2] https://sourceware.org/libabigail/manual/abidiff.html [3] https://github.com/nordix/meta-binaryaudit Signed-off-by: Adarsh Jagadish Kamini Signed-off-by: Yoann Congal --- .../expat/expat/CVE-2026-41080-1.patch | 517 ------------------ .../expat/expat/CVE-2026-41080-2.patch | 33 -- .../expat/expat/CVE-2026-45186-01.patch | 70 --- .../expat/expat/CVE-2026-45186-02.patch | 318 ----------- .../expat/expat/CVE-2026-45186-03.patch | 46 -- .../expat/expat/CVE-2026-45186-04.patch | 32 -- .../expat/expat/CVE-2026-45186-05.patch | 32 -- .../expat/expat/CVE-2026-45186-06.patch | 87 --- .../expat/expat/CVE-2026-45186-07.patch | 52 -- .../expat/expat/CVE-2026-56132_p1.patch | 90 --- .../expat/expat/CVE-2026-56132_p2.patch | 63 --- .../expat/expat/CVE-2026-56132_p3.patch | 77 --- .../expat/expat/CVE-2026-56132_p4.patch | 63 --- .../expat/expat/CVE-2026-56132_p5.patch | 58 -- .../expat/expat/CVE-2026-56403_p1.patch | 83 --- .../expat/expat/CVE-2026-56403_p2.patch | 40 -- .../expat/expat/CVE-2026-56404.patch | 47 -- .../expat/expat/CVE-2026-56405.patch | 32 -- .../expat/CVE-2026-56406-dependent.patch | 58 -- .../expat/expat/CVE-2026-56406.patch | 37 -- .../expat/expat/CVE-2026-56407.patch | 44 -- .../expat/expat/CVE-2026-56408.patch | 36 -- .../expat/expat/CVE-2026-56409.patch | 53 -- .../expat/expat/CVE-2026-56410_p1.patch | 40 -- .../expat/expat/CVE-2026-56410_p2.patch | 41 -- .../expat/expat/CVE-2026-56411.patch | 47 -- meta/recipes-core/expat/expat_2.7.5.bb | 62 --- meta/recipes-core/expat/expat_2.8.3.bb | 33 ++ 28 files changed, 33 insertions(+), 2158 deletions(-) delete mode 100644 meta/recipes-core/expat/expat/CVE-2026-41080-1.patch delete mode 100644 meta/recipes-core/expat/expat/CVE-2026-41080-2.patch delete mode 100644 meta/recipes-core/expat/expat/CVE-2026-45186-01.patch delete mode 100644 meta/recipes-core/expat/expat/CVE-2026-45186-02.patch delete mode 100644 meta/recipes-core/expat/expat/CVE-2026-45186-03.patch delete mode 100644 meta/recipes-core/expat/expat/CVE-2026-45186-04.patch delete mode 100644 meta/recipes-core/expat/expat/CVE-2026-45186-05.patch delete mode 100644 meta/recipes-core/expat/expat/CVE-2026-45186-06.patch delete mode 100644 meta/recipes-core/expat/expat/CVE-2026-45186-07.patch delete mode 100644 meta/recipes-core/expat/expat/CVE-2026-56132_p1.patch delete mode 100644 meta/recipes-core/expat/expat/CVE-2026-56132_p2.patch delete mode 100644 meta/recipes-core/expat/expat/CVE-2026-56132_p3.patch delete mode 100644 meta/recipes-core/expat/expat/CVE-2026-56132_p4.patch delete mode 100644 meta/recipes-core/expat/expat/CVE-2026-56132_p5.patch delete mode 100644 meta/recipes-core/expat/expat/CVE-2026-56403_p1.patch delete mode 100644 meta/recipes-core/expat/expat/CVE-2026-56403_p2.patch delete mode 100644 meta/recipes-core/expat/expat/CVE-2026-56404.patch delete mode 100644 meta/recipes-core/expat/expat/CVE-2026-56405.patch delete mode 100644 meta/recipes-core/expat/expat/CVE-2026-56406-dependent.patch delete mode 100644 meta/recipes-core/expat/expat/CVE-2026-56406.patch delete mode 100644 meta/recipes-core/expat/expat/CVE-2026-56407.patch delete mode 100644 meta/recipes-core/expat/expat/CVE-2026-56408.patch delete mode 100644 meta/recipes-core/expat/expat/CVE-2026-56409.patch delete mode 100644 meta/recipes-core/expat/expat/CVE-2026-56410_p1.patch delete mode 100644 meta/recipes-core/expat/expat/CVE-2026-56410_p2.patch delete mode 100644 meta/recipes-core/expat/expat/CVE-2026-56411.patch delete mode 100644 meta/recipes-core/expat/expat_2.7.5.bb create mode 100644 meta/recipes-core/expat/expat_2.8.3.bb diff --git a/meta/recipes-core/expat/expat/CVE-2026-41080-1.patch b/meta/recipes-core/expat/expat/CVE-2026-41080-1.patch deleted file mode 100644 index e93ad093f25..00000000000 --- a/meta/recipes-core/expat/expat/CVE-2026-41080-1.patch +++ /dev/null @@ -1,517 +0,0 @@ -From fa1ebd60bfcc6d32f329803e5e837251e2387ed1 Mon Sep 17 00:00:00 2001 -From: Sebastian Pipping -Date: Sun, 30 Mar 2025 19:26:55 +0200 -Subject: [PATCH v2 1/2] expat: fix CVE-2026-41080 - -The existing hash flooding protection in libexpat (based on SipHash) -only used 4 to 8 bytes of entropy for a salt, when 16 bytes are -supported by the SipHash implementation. This allows attackers to more -feasibly guess the hash salt and craft inputs that cause hash -collisions, leading to denial of service. - -Backport upstream changes that: -- Migrate hash salt storage to larger struct sipkey (128-bit) -- Drop unused parameter from generate_hash_secret_salt -- Drop unneeded void * casts in generate_hash_secret_salt -- Extract full 16 bytes of entropy for hash flooding protection -- Introduce internal flag m_hash_secret_salt_set -- Remove now-dead get_hash_secret_salt function (copy_salt_to_sipkey - accesses the struct directly) -- Add XML_SetHashSalt16Bytes API function -- Deprecate XML_SetHashSalt -- Add symbol export in libexpat.map.in (LIBEXPAT_2.7.6) -- Add backport feature macro XML_BACKPORT_SET_HASH_SALT_16_BYTES -- Add test_hash_salt_setter unit test -- Update documentation and Changes file - -Squashed backport of upstream PR #1183 commits 909201a8, bc193afc, -08697a9b, f5eacefb, fa1ebd60, f76124e7, e3349d85, c8c5caf4, -592d5fa3, 8ad3ef57, ec9fcd2e, and 8017e11e. - -CVE: CVE-2026-41080 -Upstream-Status: Backport [https://github.com/libexpat/libexpat/pull/1183] -Signed-off-by: Amaury Couderc ---- - Changes | 17 ++++++ - doc/reference.html | 55 +++++++++++++++++-- - lib/expat.h | 15 ++++++ - lib/internal.h | 2 + - lib/libexpat.map.in | 5 ++ - lib/xmlparse.c | 124 +++++++++++++++++++++++++++++++++---------- - tests/basic_tests.c | 25 +++++++++ - 7 files changed, 212 insertions(+), 31 deletions(-) - -diff --git a/Changes b/Changes -index 2b3704a6..1d8227ec 100644 ---- a/Changes -+++ b/Changes -@@ -29,6 +29,23 @@ - !! THANK YOU! Sebastian Pipping -- Berlin, 2026-03-17 !! - !!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!! - -+Patches -+ Security fixes: -+ #47 #1183 CVE-2026-41080 -- The existing hash flooding protection -+ (based on SipHash) only used 4 to 8 bytes of entropy for -+ a salt, when 16 bytes of salt are supported by the -+ implementation of SipHash used by Expat. Now full 16 bytes -+ of entropy are used to improve protection against hash -+ flooding attacks. -+ Existing API function XML_SetHashSalt is now deprecated -+ because of its limitations, and its use should be -+ considered a vulnerability. Please either use the new API -+ function XML_SetHashSalt16Bytes (with known-high-quality -+ entropy input only!) instead, or leave the derivation of -+ a 16-bytes hash salt from high quality entropy to Expat's -+ internal machinery (by *not* calling either of the two -+ XML_SetHashSalt* functions). -+ - Release 2.7.5 Tue March 17 2026 - Security fixes: - #1158 CVE-2026-32776 -- Fix NULL function pointer dereference for -diff --git a/doc/reference.html b/doc/reference.html -index 5faa8d65..64b9fd67 100644 ---- a/doc/reference.html -+++ b/doc/reference.html -@@ -404,7 +404,11 @@ - - -
  • -- XML_SetHashSalt -+ XML_SetHashSalt (deprecated) -+
  • -+ -+
  • -+ XML_SetHashSalt16Bytes -
  • - -
  • -@@ -3449,22 +3453,35 @@ XML_SetParamEntityParsing(XML_Parser p, - - -

    -- XML_SetHashSalt -+ XML_SetHashSalt (deprecated) -

    - -
    - int XMLCALL
    --XML_SetHashSalt(XML_Parser p,
    -+XML_SetHashSalt(XML_Parser parser,
    -                 unsigned long hash_salt);
    - 
    -
    - Sets the hash salt to use for internal hash calculations. Helps in preventing DoS - attacks based on predicting hash function behavior. In order to have an effect - this must be called before parsing has started. Returns 1 if successful, 0 when -- called after XML_Parse or XML_ParseBuffer. -+ called after XML_Parse or XML_ParseBuffer or when -+ parser is NULL. -+

    -+ Note: Function XML_SetHashSalt is -+ deprecated. Please use function XML_SetHashSalt16Bytes instead for better -+ security. XML_SetHashSalt only provides 4 to 8 bytes of entropy -+ (depending on the size of type unsigned long) while the SipHash -+ implementation used by Expat can leverage up to 16 bytes of entropy — at least -+ twice as much. Function XML_SetHashSalt16Bytes of Expat >=2.7.6 -+ (and where backported) matches the amount of entropy supported by SipHash. -+

    -+ -

    - Note: This call is optional, as the parser will auto-generate a new -- random salt value if no value has been set at the start of parsing. -+ random salt value internally if no value has been set by the start of parsing. -

    - -

    -@@ -3475,6 +3492,34 @@ XML_SetHashSalt(XML_Parser p, -

    -
    - -+

    -+ XML_SetHashSalt16Bytes -+

    -+ -+
    -+/* Added in Expat 2.7.6. */
    -+XML_Bool XMLCALL
    -+XML_SetHashSalt16Bytes(XML_Parser parser,
    -+                       const uint8_t entropy[16]);
    -+
    -+
    -+ Sets the hash salt to use for internal hash calculations. Helps in preventing DoS -+ attacks based on predicting hash function behavior. In order to have an effect -+ this must be called before parsing has started. Returns XML_TRUE if -+ successful, XML_FALSE when called after XML_Parse or -+ XML_ParseBuffer or when parser is NULL. -+

    -+ Note: Setting a salt that is not from a source of high quality -+ entropy (like getentropy(3)) will make the parser vulnerable to -+ hash flooding attacks. -+

    -+ -+

    -+ Note: This call is optional, as the parser will auto-generate a new -+ random salt value internally if no value has been set by the start of parsing. -+

    -+
    -+ -

    - XML_UseForeignDTD -

    -diff --git a/lib/expat.h b/lib/expat.h -index 18dbaebd..7693f62c 100644 ---- a/lib/expat.h -+++ b/lib/expat.h -@@ -45,6 +45,7 @@ - #ifndef Expat_INCLUDED - # define Expat_INCLUDED 1 - -+# include // for uint8_t - # include - # include "expat_external.h" - -@@ -917,10 +918,25 @@ XML_SetParamEntityParsing(XML_Parser parser, - function behavior. This must be called before parsing is started. - Returns 1 if successful, 0 when called after parsing has started. - Note: If parser == NULL, the function will do nothing and return 0. -+ DEPRECATED since Expat 2.7.6. - */ - XMLPARSEAPI(int) - XML_SetHashSalt(XML_Parser parser, unsigned long hash_salt); - -+/* Sets the hash salt to use for internal hash calculations. -+ Helps in preventing DoS attacks based on predicting hash function behavior. -+ This must be called before parsing is started. -+ Returns XML_TRUE if successful, XML_FALSE when called after parsing has -+ started or when parser is NULL. -+ Added in Expat 2.7.6. -+*/ -+XMLPARSEAPI(XML_Bool) -+XML_SetHashSalt16Bytes(XML_Parser parser, const uint8_t entropy[16]); -+ -+/* Backport feature macro: signals that XML_SetHashSalt16Bytes is available -+ even though XML_COMBINED_VERSION < 20800. */ -+# define XML_BACKPORT_SET_HASH_SALT_16_BYTES 1 -+ - /* If XML_Parse or XML_ParseBuffer have returned XML_STATUS_ERROR, then - XML_GetErrorCode returns information about the error. - */ -diff --git a/lib/internal.h b/lib/internal.h -index 61266ebb..1995c17b 100644 ---- a/lib/internal.h -+++ b/lib/internal.h -@@ -113,6 +113,7 @@ - #if defined(_WIN32) \ - && (! defined(__USE_MINGW_ANSI_STDIO) \ - || (1 - __USE_MINGW_ANSI_STDIO - 1 == 0)) -+# define EXPAT_FMT_LLX(midpart) "%" midpart "I64x" - # define EXPAT_FMT_ULL(midpart) "%" midpart "I64u" - # if defined(_WIN64) // Note: modifiers "td" and "zu" do not work for MinGW - # define EXPAT_FMT_PTRDIFF_T(midpart) "%" midpart "I64d" -@@ -122,6 +123,7 @@ - # define EXPAT_FMT_SIZE_T(midpart) "%" midpart "u" - # endif - #else -+# define EXPAT_FMT_LLX(midpart) "%" midpart "llx" - # define EXPAT_FMT_ULL(midpart) "%" midpart "llu" - # if ! defined(ULONG_MAX) - # error Compiler did not define ULONG_MAX for us -diff --git a/lib/libexpat.map.in b/lib/libexpat.map.in -index 52e59ed3..8527eb54 100644 ---- a/lib/libexpat.map.in -+++ b/lib/libexpat.map.in -@@ -117,3 +117,8 @@ LIBEXPAT_2.7.2 { - @_EXPAT_COMMENT_DTD_OR_GE@ XML_SetAllocTrackerActivationThreshold; - @_EXPAT_COMMENT_DTD_OR_GE@ XML_SetAllocTrackerMaximumAmplification; - } LIBEXPAT_2.6.0; -+ -+LIBEXPAT_2.7.6 { -+ global: -+ XML_SetHashSalt16Bytes; -+} LIBEXPAT_2.7.2; -diff --git a/lib/xmlparse.c b/lib/xmlparse.c -index 0248b665..75a7e5d0 100644 ---- a/lib/xmlparse.c -+++ b/lib/xmlparse.c -@@ -604,7 +604,7 @@ static ELEMENT_TYPE *getElementType(XML_Parser parser, const ENCODING *enc, - - static XML_Char *copyString(const XML_Char *s, XML_Parser parser); - --static unsigned long generate_hash_secret_salt(XML_Parser parser); -+static struct sipkey generate_hash_secret_salt(void); - static XML_Bool startParsing(XML_Parser parser); - - static XML_Parser parserCreate(const XML_Char *encodingName, -@@ -777,7 +777,8 @@ struct XML_ParserStruct { - XML_Bool m_useForeignDTD; - enum XML_ParamEntityParsing m_paramEntityParsing; - #endif -- unsigned long m_hash_secret_salt; -+ struct sipkey m_hash_secret_salt_128; -+ XML_Bool m_hash_secret_salt_set; - #if XML_GE == 1 - ACCOUNTING m_accounting; - MALLOC_TRACKER m_alloc_tracker; -@@ -1192,69 +1193,65 @@ gather_time_entropy(void) { - - #endif /* ! defined(HAVE_ARC4RANDOM_BUF) && ! defined(HAVE_ARC4RANDOM) */ - --static unsigned long --ENTROPY_DEBUG(const char *label, unsigned long entropy) { -+static struct sipkey -+ENTROPY_DEBUG(const char *label, struct sipkey entropy_128) { - if (getDebugLevel("EXPAT_ENTROPY_DEBUG", 0) >= 1u) { -- fprintf(stderr, "expat: Entropy: %s --> 0x%0*lx (%lu bytes)\n", label, -- (int)sizeof(entropy) * 2, entropy, (unsigned long)sizeof(entropy)); -+ fprintf(stderr, -+ "expat: Entropy: %s --> [0x" EXPAT_FMT_LLX( -+ "016") ", 0x" EXPAT_FMT_LLX("016") "] (16 bytes)\n", -+ label, (unsigned long long)entropy_128.k[0], -+ (unsigned long long)entropy_128.k[1]); - } -- return entropy; -+ return entropy_128; - } - --static unsigned long --generate_hash_secret_salt(XML_Parser parser) { -- unsigned long entropy; -- (void)parser; -+static struct sipkey -+generate_hash_secret_salt(void) { -+ struct sipkey entropy; - - /* "Failproof" high quality providers: */ - #if defined(HAVE_ARC4RANDOM_BUF) - arc4random_buf(&entropy, sizeof(entropy)); - return ENTROPY_DEBUG("arc4random_buf", entropy); - #elif defined(HAVE_ARC4RANDOM) -- writeRandomBytes_arc4random((void *)&entropy, sizeof(entropy)); -+ writeRandomBytes_arc4random(&entropy, sizeof(entropy)); - return ENTROPY_DEBUG("arc4random", entropy); - #else - /* Try high quality providers first .. */ - # ifdef _WIN32 -- if (writeRandomBytes_rand_s((void *)&entropy, sizeof(entropy))) { -+ if (writeRandomBytes_rand_s(&entropy, sizeof(entropy))) { - return ENTROPY_DEBUG("rand_s", entropy); - } - # elif defined(HAVE_GETRANDOM) || defined(HAVE_SYSCALL_GETRANDOM) -- if (writeRandomBytes_getrandom_nonblock((void *)&entropy, sizeof(entropy))) { -+ if (writeRandomBytes_getrandom_nonblock(&entropy, sizeof(entropy))) { - return ENTROPY_DEBUG("getrandom", entropy); - } - # endif - # if ! defined(_WIN32) && defined(XML_DEV_URANDOM) -- if (writeRandomBytes_dev_urandom((void *)&entropy, sizeof(entropy))) { -+ if (writeRandomBytes_dev_urandom(&entropy, sizeof(entropy))) { - return ENTROPY_DEBUG("/dev/urandom", entropy); - } - # endif /* ! defined(_WIN32) && defined(XML_DEV_URANDOM) */ - /* .. and self-made low quality for backup: */ - -- entropy = gather_time_entropy(); -+ entropy.k[0] = 0; -+ entropy.k[1] = gather_time_entropy(); - # if ! defined(__wasi__) - /* Process ID is 0 bits entropy if attacker has local access */ -- entropy ^= getpid(); -+ entropy.k[1] ^= getpid(); - # endif - - /* Factors are 2^31-1 and 2^61-1 (Mersenne primes M31 and M61) */ - if (sizeof(unsigned long) == 4) { -- return ENTROPY_DEBUG("fallback(4)", entropy * 2147483647); -+ entropy.k[1] *= 2147483647; -+ return ENTROPY_DEBUG("fallback(4)", entropy); - } else { -- return ENTROPY_DEBUG("fallback(8)", -- entropy * (unsigned long)2305843009213693951ULL); -+ entropy.k[1] *= 2305843009213693951ULL; -+ return ENTROPY_DEBUG("fallback(8)", entropy); - } - #endif - } - --static unsigned long --get_hash_secret_salt(XML_Parser parser) { -- const XML_Parser rootParser = getRootParserOf(parser, NULL); -- assert(! rootParser->m_parentParser); -- -- return rootParser->m_hash_secret_salt; --} -- - static enum XML_Error - callProcessor(XML_Parser parser, const char *start, const char *end, - const char **endPtr) { -@@ -1323,8 +1320,10 @@ callProcessor(XML_Parser parser, const char *start, const char *end, - static XML_Bool /* only valid for root parser */ - startParsing(XML_Parser parser) { - /* hash functions must be initialized before setContext() is called */ -- if (parser->m_hash_secret_salt == 0) -- parser->m_hash_secret_salt = generate_hash_secret_salt(parser); -+ if (parser->m_hash_secret_salt_set != XML_TRUE) { -+ parser->m_hash_secret_salt_128 = generate_hash_secret_salt(); -+ parser->m_hash_secret_salt_set = XML_TRUE; -+ } - if (parser->m_ns) { - /* implicit context only set for root parser, since child - parsers (i.e. external entity parsers) will inherit it -@@ -1612,7 +1611,9 @@ parserInit(XML_Parser parser, const XML_Char *encodingName) { - parser->m_useForeignDTD = XML_FALSE; - parser->m_paramEntityParsing = XML_PARAM_ENTITY_PARSING_NEVER; - #endif -- parser->m_hash_secret_salt = 0; -+ parser->m_hash_secret_salt_128.k[0] = 0; -+ parser->m_hash_secret_salt_128.k[1] = 0; -+ parser->m_hash_secret_salt_set = XML_FALSE; - - #if XML_GE == 1 - memset(&parser->m_accounting, 0, sizeof(ACCOUNTING)); -@@ -1779,7 +1780,8 @@ XML_ExternalEntityParserCreate(XML_Parser oldParser, const XML_Char *context, - from hash tables associated with either parser without us having - to worry which hash secrets each table has. - */ -- unsigned long oldhash_secret_salt; -+ struct sipkey oldhash_secret_salt_128; -+ XML_Bool oldhash_secret_salt_set; - XML_Bool oldReparseDeferralEnabled; - - /* Validate the oldParser parameter before we pull everything out of it */ -@@ -1825,7 +1827,8 @@ XML_ExternalEntityParserCreate(XML_Parser oldParser, const XML_Char *context, - from hash tables associated with either parser without us having - to worry which hash secrets each table has. - */ -- oldhash_secret_salt = parser->m_hash_secret_salt; -+ oldhash_secret_salt_128 = parser->m_hash_secret_salt_128; -+ oldhash_secret_salt_set = parser->m_hash_secret_salt_set; - oldReparseDeferralEnabled = parser->m_reparseDeferralEnabled; - - #ifdef XML_DTD -@@ -1880,7 +1883,8 @@ XML_ExternalEntityParserCreate(XML_Parser oldParser, const XML_Char *context, - parser->m_externalEntityRefHandlerArg = oldExternalEntityRefHandlerArg; - parser->m_defaultExpandInternalEntities = oldDefaultExpandInternalEntities; - parser->m_ns_triplets = oldns_triplets; -- parser->m_hash_secret_salt = oldhash_secret_salt; -+ parser->m_hash_secret_salt_128 = oldhash_secret_salt_128; -+ parser->m_hash_secret_salt_set = oldhash_secret_salt_set; - parser->m_reparseDeferralEnabled = oldReparseDeferralEnabled; - parser->m_parentParser = oldParser; - #ifdef XML_DTD -@@ -2327,6 +2331,7 @@ XML_SetParamEntityParsing(XML_Parser parser, - #endif - } - -+// DEPRECATED since Expat 2.7.6. - int XMLCALL - XML_SetHashSalt(XML_Parser parser, unsigned long hash_salt) { - if (parser == NULL) -@@ -2337,10 +2342,46 @@ XML_SetHashSalt(XML_Parser parser, unsigned long hash_salt) { - /* block after XML_Parse()/XML_ParseBuffer() has been called */ - if (parserBusy(rootParser)) - return 0; -- rootParser->m_hash_secret_salt = hash_salt; -+ -+ rootParser->m_hash_secret_salt_128.k[0] = 0; -+ rootParser->m_hash_secret_salt_128.k[1] = hash_salt; -+ -+ if (hash_salt != 0) { // to remain backwards compatible -+ rootParser->m_hash_secret_salt_set = XML_TRUE; -+ -+ if (sizeof(unsigned long) == 4) -+ ENTROPY_DEBUG("explicit(4)", rootParser->m_hash_secret_salt_128); -+ else -+ ENTROPY_DEBUG("explicit(8)", rootParser->m_hash_secret_salt_128); -+ } -+ - return 1; - } - -+XML_Bool XMLCALL -+XML_SetHashSalt16Bytes(XML_Parser parser, const uint8_t entropy[16]) { -+ if (parser == NULL) -+ return XML_FALSE; -+ -+ if (entropy == NULL) -+ return XML_FALSE; -+ -+ const XML_Parser rootParser = getRootParserOf(parser, NULL); -+ assert(! rootParser->m_parentParser); -+ -+ /* block after XML_Parse()/XML_ParseBuffer() has been called */ -+ if (parserBusy(rootParser)) -+ return XML_FALSE; -+ -+ sip_tokey(&(rootParser->m_hash_secret_salt_128), entropy); -+ -+ rootParser->m_hash_secret_salt_set = XML_TRUE; -+ -+ ENTROPY_DEBUG("explicit(16)", rootParser->m_hash_secret_salt_128); -+ -+ return XML_TRUE; -+} -+ - enum XML_Status XMLCALL - XML_Parse(XML_Parser parser, const char *s, int len, int isFinal) { - if ((parser == NULL) || (len < 0) || ((s == NULL) && (len != 0))) { -@@ -7842,8 +7883,10 @@ keylen(KEY s) { - - static void - copy_salt_to_sipkey(XML_Parser parser, struct sipkey *key) { -- key->k[0] = 0; -- key->k[1] = get_hash_secret_salt(parser); -+ const XML_Parser rootParser = getRootParserOf(parser, NULL); -+ assert(! rootParser->m_parentParser); -+ -+ *key = rootParser->m_hash_secret_salt_128; - } - - static unsigned long FASTCALL -diff --git a/tests/basic_tests.c b/tests/basic_tests.c -index 02d1d5fd..26662fee 100644 ---- a/tests/basic_tests.c -+++ b/tests/basic_tests.c -@@ -204,6 +204,30 @@ START_TEST(test_hash_collision) { - END_TEST - #undef COLLIDING_HASH_SALT - -+START_TEST(test_hash_salt_setter) { -+ const uint8_t entropy[16] = {'0', '1', '2', '3', '4', '5', '6', '7', -+ '8', '9', 'a', 'b', 'c', 'd', 'e', 'f'}; -+ XML_Parser parser = XML_ParserCreate(NULL); -+ -+ // NULL parser should be rejected -+ assert_true(XML_SetHashSalt16Bytes(NULL, entropy) == XML_FALSE); -+ -+ // NULL entropy should be rejected -+ assert_true(XML_SetHashSalt16Bytes(parser, NULL) == XML_FALSE); -+ -+ // Setting should be allowed more than once -+ assert_true(XML_SetHashSalt16Bytes(parser, entropy) == XML_TRUE); -+ assert_true(XML_SetHashSalt16Bytes(parser, entropy) == XML_TRUE); -+ -+ // But not after parsing has started -+ assert_true(XML_Parse(parser, "", 0, XML_FALSE /* isFinal */) -+ == XML_STATUS_OK); -+ assert_true(XML_SetHashSalt16Bytes(parser, entropy) == XML_FALSE); -+ -+ XML_ParserFree(parser); -+} -+END_TEST -+ - /* Regression test for SF bug #491986. */ - START_TEST(test_danish_latin1) { - const char *text = "\n" -@@ -6292,6 +6316,7 @@ make_basic_test_case(Suite *s) { - tcase_add_test(tc_basic, test_bom_utf16_le); - tcase_add_test(tc_basic, test_nobom_utf16_le); - tcase_add_test(tc_basic, test_hash_collision); -+ tcase_add_test(tc_basic, test_hash_salt_setter); - tcase_add_test(tc_basic, test_illegal_utf8); - tcase_add_test(tc_basic, test_utf8_auto_align); - tcase_add_test(tc_basic, test_utf16); --- -2.34.1 diff --git a/meta/recipes-core/expat/expat/CVE-2026-41080-2.patch b/meta/recipes-core/expat/expat/CVE-2026-41080-2.patch deleted file mode 100644 index 0410f8b070f..00000000000 --- a/meta/recipes-core/expat/expat/CVE-2026-41080-2.patch +++ /dev/null @@ -1,33 +0,0 @@ -From 3cdd1df2644388aff25dd0ed7128c7bb1de1a7d8 Mon Sep 17 00:00:00 2001 -From: Christoph Reiter -Date: Wed, 10 Jun 2026 21:27:51 +0200 -Subject: [PATCH 2/2] cmake|windows: add missing export for new - XML_SetHashSalt16Bytes - -A new XML_SetHashSalt16Bytes symbol was added in #1183, but it -wasn't added to the def file, so the export is missing when building -libexpat on Windows with cmake. - -Add the new symbol to the .def template. - -CVE: CVE-2026-41080 -Upstream-Status: Backport [https://github.com/libexpat/libexpat/commit/3cdd1df2644388aff25dd0ed7128c7bb1de1a7d8] - -Signed-off-by: Christoph Reiter -Signed-off-by: Amaury Couderc ---- - lib/libexpat.def.cmake | 2 ++ - 1 file changed, 2 insertions(+) - -diff --git a/lib/libexpat.def.cmake b/lib/libexpat.def.cmake -index 9b9e22cb..948135a5 100644 ---- a/lib/libexpat.def.cmake -+++ b/lib/libexpat.def.cmake -@@ -83,3 +83,5 @@ EXPORTS - ; added with version 2.7.2 - @_EXPAT_COMMENT_DTD_OR_GE@ XML_SetAllocTrackerMaximumAmplification @72 - @_EXPAT_COMMENT_DTD_OR_GE@ XML_SetAllocTrackerActivationThreshold @73 -+; added with version 2.7.6 -+ XML_SetHashSalt16Bytes @74 --- -2.34.1 diff --git a/meta/recipes-core/expat/expat/CVE-2026-45186-01.patch b/meta/recipes-core/expat/expat/CVE-2026-45186-01.patch deleted file mode 100644 index 478978f4ca2..00000000000 --- a/meta/recipes-core/expat/expat/CVE-2026-45186-01.patch +++ /dev/null @@ -1,70 +0,0 @@ -From b659bf974f29b991870ba1f66af687c73e07fbf8 Mon Sep 17 00:00:00 2001 -From: =?UTF-8?q?Berkay=20Eren=20=C3=9Cr=C3=BCn?= -Date: Fri, 13 Mar 2026 13:26:45 +0100 -Subject: [PATCH 1/7] Make "counting_start_element_handler" count default attrs - -(cherry picked from commit 0802a5892030610144b736dec6e2f63e8600fe85) - -CVE: CVE-2026-45186 -Upstream-Status: Backport [https://github.com/libexpat/libexpat/pull/1216/commits/0802a5892030610144b736dec6e2f63e8600fe85] -Signed-off-by: Theo Gaige ---- - tests/basic_tests.c | 8 ++++---- - tests/handlers.c | 2 +- - tests/handlers.h | 1 + - 3 files changed, 6 insertions(+), 5 deletions(-) - -diff --git a/tests/basic_tests.c b/tests/basic_tests.c -index 02d1d5f..8c025a2 100644 ---- a/tests/basic_tests.c -+++ b/tests/basic_tests.c -@@ -2466,9 +2466,9 @@ START_TEST(test_attributes) { - {XCS("id"), XCS("one")}, - {NULL, NULL}}; - AttrInfo tag_info[] = {{XCS("c"), XCS("3")}, {NULL, NULL}}; -- ElementInfo info[] = {{XCS("doc"), 3, XCS("id"), NULL}, -- {XCS("tag"), 1, NULL, NULL}, -- {NULL, 0, NULL, NULL}}; -+ ElementInfo info[] = {{XCS("doc"), 3, 0, XCS("id"), NULL}, -+ {XCS("tag"), 1, 0, NULL, NULL}, -+ {NULL, 0, 0, NULL, NULL}}; - info[0].attributes = doc_info; - info[1].attributes = tag_info; - -@@ -5543,7 +5543,7 @@ START_TEST(test_deep_nested_attribute_entity) { - (long unsigned)(N_LINES - 1)); - - AttrInfo doc_info[] = {{XCS("name"), XCS("deepText")}, {NULL, NULL}}; -- ElementInfo info[] = {{XCS("foo"), 1, NULL, NULL}, {NULL, 0, NULL, NULL}}; -+ ElementInfo info[] = {{XCS("foo"), 1, 0, NULL, NULL}, {NULL, 0, 0, NULL, NULL}}; - info[0].attributes = doc_info; - - XML_Parser parser = XML_ParserCreate(NULL); -diff --git a/tests/handlers.c b/tests/handlers.c -index e456df2..bd1b54e 100644 ---- a/tests/handlers.c -+++ b/tests/handlers.c -@@ -137,7 +137,7 @@ counting_start_element_handler(void *userData, const XML_Char *name, - fail("ID does not have the correct name"); - return; - } -- for (i = 0; i < info->attr_count; i++) { -+ for (i = 0; i < info->attr_count + info->default_attr_count; i++) { - attr = info->attributes; - while (attr->name != NULL) { - if (! xcstrcmp(atts[0], attr->name)) -diff --git a/tests/handlers.h b/tests/handlers.h -index fcde27a..27a53f2 100644 ---- a/tests/handlers.h -+++ b/tests/handlers.h -@@ -88,6 +88,7 @@ typedef struct attrInfo { - typedef struct elementInfo { - const XML_Char *name; - int attr_count; -+ int default_attr_count; - const XML_Char *id_name; - AttrInfo *attributes; - } ElementInfo; --- -2.43.0 - diff --git a/meta/recipes-core/expat/expat/CVE-2026-45186-02.patch b/meta/recipes-core/expat/expat/CVE-2026-45186-02.patch deleted file mode 100644 index 6c90e15b47d..00000000000 --- a/meta/recipes-core/expat/expat/CVE-2026-45186-02.patch +++ /dev/null @@ -1,318 +0,0 @@ -From 32848241057dfaa4c68fae475f51fbe1a182c004 Mon Sep 17 00:00:00 2001 -From: =?UTF-8?q?Berkay=20Eren=20=C3=9Cr=C3=BCn?= -Date: Fri, 13 Mar 2026 13:27:31 +0100 -Subject: [PATCH 2/7] test(attlist): Cover duplicate attribute names - -Co-authored-by: Sebastian Pipping -(cherry picked from commit e569f47181c43dca5d262089e541ddf9a9c09927) - -CVE: CVE-2026-45186 -Upstream-Status: Backport [https://github.com/libexpat/libexpat/pull/1216/commits/e569f47181c43dca5d262089e541ddf9a9c09927] -Signed-off-by: Theo Gaige ---- - tests/basic_tests.c | 282 ++++++++++++++++++++++++++++++++++++++++++++ - 1 file changed, 282 insertions(+) - -diff --git a/tests/basic_tests.c b/tests/basic_tests.c -index 8c025a2..83c453c 100644 ---- a/tests/basic_tests.c -+++ b/tests/basic_tests.c -@@ -2489,6 +2489,279 @@ START_TEST(test_attributes) { - } - END_TEST - -+START_TEST(test_duplicate_cdata_attribute) { -+ /* -+ https://www.w3.org/TR/xml/#attdecls -+ -+ Test the following statement from the linked specification: -+ When more than one definition is provided for the same attribute of a given -+ element type, the first declaration is binding and later declarations are -+ ignored. -+ */ -+ -+ const char *text -+ = "\n" -+ "]>\n" -+ "\n"; -+ AttrInfo doc_info[] = {{XCS("attribute"), XCS("expected")}, {NULL, NULL}}; -+ ElementInfo info[] -+ = {{XCS("doc"), 0, 1, NULL, doc_info}, {NULL, 0, 0, NULL, NULL}}; -+ -+ XML_Parser parser = XML_ParserCreate(NULL); -+ assert_true(parser != NULL); -+ -+ ParserAndElementInfo parserAndElementInfos = { -+ parser, -+ info, -+ }; -+ -+ XML_SetStartElementHandler(parser, counting_start_element_handler); -+ XML_SetUserData(parser, &parserAndElementInfos); -+ -+ if (_XML_Parse_SINGLE_BYTES(parser, text, (int)strlen(text), XML_TRUE) -+ != XML_STATUS_OK) -+ xml_failure(parser); -+ -+ XML_ParserFree(parser); -+} -+END_TEST -+ -+START_TEST(test_duplicate_id_attribute_1) { -+ /* -+ https://www.w3.org/TR/xml/#attdecls -+ -+ Test the following statement from the linked specification: -+ When more than one definition is provided for the same attribute of a given -+ element type, the first declaration is binding and later declarations are -+ ignored. -+ */ -+ -+ const char *text -+ = "\n" -+ "]>\n" -+ "\n"; -+ AttrInfo doc_info[] = {{XCS("identifier"), XCS("expected")}, {NULL, NULL}}; -+ ElementInfo info[] -+ = {{XCS("doc"), 0, 1, NULL, doc_info}, {NULL, 0, 0, NULL, NULL}}; -+ -+ XML_Parser parser = XML_ParserCreate(NULL); -+ assert_true(parser != NULL); -+ -+ ParserAndElementInfo parserAndElementInfos = { -+ parser, -+ info, -+ }; -+ -+ XML_SetStartElementHandler(parser, counting_start_element_handler); -+ XML_SetUserData(parser, &parserAndElementInfos); -+ -+ if (_XML_Parse_SINGLE_BYTES(parser, text, (int)strlen(text), XML_TRUE) -+ != XML_STATUS_OK) -+ xml_failure(parser); -+ -+ XML_ParserFree(parser); -+} -+END_TEST -+ -+START_TEST(test_duplicate_id_attribute_2) { -+ /* -+ https://www.w3.org/TR/xml/#attdecls -+ -+ Test the following statement from the linked specification: -+ When more than one definition is provided for the same attribute of a given -+ element type, the first declaration is binding and later declarations are -+ ignored. -+ */ -+ -+ const char *text -+ = "\n" -+ "]>\n" -+ "\n"; -+ AttrInfo doc_info[] = {{NULL, NULL}}; -+ -+ ElementInfo info[] -+ = {{XCS("doc"), 0, 0, NULL, doc_info}, {NULL, 0, 0, NULL, NULL}}; -+ -+ XML_Parser parser = XML_ParserCreate(NULL); -+ assert_true(parser != NULL); -+ -+ ParserAndElementInfo parserAndElementInfos = { -+ parser, -+ info, -+ }; -+ -+ XML_SetStartElementHandler(parser, counting_start_element_handler); -+ XML_SetUserData(parser, &parserAndElementInfos); -+ -+ if (_XML_Parse_SINGLE_BYTES(parser, text, (int)strlen(text), XML_TRUE) -+ != XML_STATUS_OK) -+ xml_failure(parser); -+ -+ XML_ParserFree(parser); -+} -+END_TEST -+ -+START_TEST(test_duplicate_cdata_attribute_multiple_attlistdecl) { -+ /* -+ https://www.w3.org/TR/xml/#attdecls -+ -+ Test the following statement from the linked specification: -+ When more than one AttlistDecl is provided for a given element type, -+ the contents of all those provided are merged. -+ */ -+ const char *text = "\n" -+ " \n" -+ "]>\n" -+ "\n"; -+ AttrInfo doc_info[] = {{XCS("attribute"), XCS("expected")}, {NULL, NULL}}; -+ ElementInfo info[] -+ = {{XCS("doc"), 0, 1, NULL, doc_info}, {NULL, 0, 0, NULL, NULL}}; -+ -+ XML_Parser parser = XML_ParserCreate(NULL); -+ assert_true(parser != NULL); -+ -+ ParserAndElementInfo parserAndElementInfos = { -+ parser, -+ info, -+ }; -+ -+ XML_SetStartElementHandler(parser, counting_start_element_handler); -+ XML_SetUserData(parser, &parserAndElementInfos); -+ -+ if (_XML_Parse_SINGLE_BYTES(parser, text, (int)strlen(text), XML_TRUE) -+ != XML_STATUS_OK) -+ xml_failure(parser); -+ -+ XML_ParserFree(parser); -+} -+END_TEST -+ -+START_TEST(test_duplicate_cdata_attribute_multiple_attlistdecl_2) { -+ /* -+ https://www.w3.org/TR/xml/#attdecls -+ -+ Test the following statement from the linked specification: -+ When more than one AttlistDecl is provided for a given element type, -+ the contents of all those provided are merged. -+ */ -+ const char *text = "\n" -+ " \n" -+ " \n" -+ "]>\n" -+ "\n"; -+ AttrInfo doc_info[] = {{XCS("attribute"), XCS("expected_doc")}, {NULL, NULL}}; -+ AttrInfo tag_info[] = {{XCS("attribute"), XCS("expected_tag")}, {NULL, NULL}}; -+ ElementInfo info[] = {{XCS("doc"), 0, 1, NULL, doc_info}, -+ {XCS("tag"), 0, 1, NULL, tag_info}, -+ {NULL, 0, 0, NULL, NULL}}; -+ -+ XML_Parser parser = XML_ParserCreate(NULL); -+ assert_true(parser != NULL); -+ -+ ParserAndElementInfo parserAndElementInfos = { -+ parser, -+ info, -+ }; -+ -+ XML_SetStartElementHandler(parser, counting_start_element_handler); -+ XML_SetUserData(parser, &parserAndElementInfos); -+ -+ if (_XML_Parse_SINGLE_BYTES(parser, text, (int)strlen(text), XML_TRUE) -+ != XML_STATUS_OK) -+ xml_failure(parser); -+ -+ XML_ParserFree(parser); -+} -+END_TEST -+ -+START_TEST(test_duplicate_cdata_attribute_multiple_attlistdecl_3) { -+ /* -+ https://www.w3.org/TR/xml/#attdecls -+ -+ Test the following statement from the linked specification: -+ When more than one AttlistDecl is provided for a given element type, -+ the contents of all those provided are merged. -+ */ -+ const char *text -+ = "\n" -+ " \n" -+ " \n" -+ "]>\n" -+ "\n"; -+ AttrInfo doc_info[] = {{XCS("attribute"), XCS("expected_doc")}, -+ {XCS("second_attribute"), XCS("second_expected_doc")}, -+ {NULL, NULL}}; -+ AttrInfo tag_info[] = {{XCS("attribute"), XCS("expected_tag")}, {NULL, NULL}}; -+ ElementInfo info[] = {{XCS("doc"), 0, 2, NULL, doc_info}, -+ {XCS("tag"), 0, 1, NULL, tag_info}, -+ {NULL, 0, 0, NULL, NULL}}; -+ -+ XML_Parser parser = XML_ParserCreate(NULL); -+ assert_true(parser != NULL); -+ -+ ParserAndElementInfo parserAndElementInfos = { -+ parser, -+ info, -+ }; -+ -+ XML_SetStartElementHandler(parser, counting_start_element_handler); -+ XML_SetUserData(parser, &parserAndElementInfos); -+ -+ if (_XML_Parse_SINGLE_BYTES(parser, text, (int)strlen(text), XML_TRUE) -+ != XML_STATUS_OK) -+ xml_failure(parser); -+ -+ XML_ParserFree(parser); -+} -+END_TEST -+ -+START_TEST(test_duplicate_id_attribute_multiple_attlistdecl) { -+ /* -+ https://www.w3.org/TR/xml/#attdecls -+ -+ Test the following statement from the linked specification: -+ When more than one AttlistDecl is provided for a given element type, -+ the contents of all those provided are merged. -+ */ -+ const char *text = "\n" -+ " \n" -+ " \n" -+ "]>\n" -+ "\n"; -+ AttrInfo doc_info[] -+ = {{XCS("identifier"), XCS("doc_identity")}, {NULL, NULL}}; -+ AttrInfo tag_info[] -+ = {{XCS("identifier"), XCS("identifier_tag")}, {NULL, NULL}}; -+ ElementInfo info[] = {{XCS("doc"), 1, 0, XCS("identifier"), doc_info}, -+ {XCS("tag"), 0, 1, NULL, tag_info}, -+ {NULL, 0, 0, NULL, NULL}}; -+ -+ XML_Parser parser = XML_ParserCreate(NULL); -+ assert_true(parser != NULL); -+ -+ ParserAndElementInfo parserAndElementInfos = { -+ parser, -+ info, -+ }; -+ -+ XML_SetStartElementHandler(parser, counting_start_element_handler); -+ XML_SetUserData(parser, &parserAndElementInfos); -+ -+ if (_XML_Parse_SINGLE_BYTES(parser, text, (int)strlen(text), XML_TRUE) -+ != XML_STATUS_OK) -+ xml_failure(parser); -+ -+ XML_ParserFree(parser); -+} -+END_TEST -+ - /* Test reset works correctly in the middle of processing an internal - * entity. Exercises some obscure code in XML_ParserReset(). - */ -@@ -6374,6 +6647,15 @@ make_basic_test_case(Suite *s) { - tcase_add_test__ifdef_xml_dtd(tc_basic, test_empty_foreign_dtd); - tcase_add_test(tc_basic, test_set_base); - tcase_add_test(tc_basic, test_attributes); -+ tcase_add_test(tc_basic, test_duplicate_cdata_attribute); -+ tcase_add_test(tc_basic, test_duplicate_id_attribute_1); -+ tcase_add_test(tc_basic, test_duplicate_id_attribute_2); -+ tcase_add_test(tc_basic, test_duplicate_cdata_attribute_multiple_attlistdecl); -+ tcase_add_test(tc_basic, -+ test_duplicate_cdata_attribute_multiple_attlistdecl_2); -+ tcase_add_test(tc_basic, -+ test_duplicate_cdata_attribute_multiple_attlistdecl_3); -+ tcase_add_test(tc_basic, test_duplicate_id_attribute_multiple_attlistdecl); - tcase_add_test__if_xml_ge(tc_basic, test_reset_in_entity); - tcase_add_test(tc_basic, test_resume_invalid_parse); - tcase_add_test(tc_basic, test_resume_resuspended); --- -2.43.0 - diff --git a/meta/recipes-core/expat/expat/CVE-2026-45186-03.patch b/meta/recipes-core/expat/expat/CVE-2026-45186-03.patch deleted file mode 100644 index f3b0614b8df..00000000000 --- a/meta/recipes-core/expat/expat/CVE-2026-45186-03.patch +++ /dev/null @@ -1,46 +0,0 @@ -From 468d6f44264e7ad73f3045f6487baccc846014e6 Mon Sep 17 00:00:00 2001 -From: Sebastian Pipping -Date: Mon, 20 Apr 2026 13:44:43 +0200 -Subject: [PATCH 3/7] tests: Define .attributes the first time around - -(cherry picked from commit 05307d352a5aa858cdda57ec53a53b597b3a4a82) - -CVE: CVE-2026-45186 -Upstream-Status: Backport [https://github.com/libexpat/libexpat/pull/1216/commits/05307d352a5aa858cdda57ec53a53b597b3a4a82] -Signed-off-by: Theo Gaige ---- - tests/basic_tests.c | 10 ++++------ - 1 file changed, 4 insertions(+), 6 deletions(-) - -diff --git a/tests/basic_tests.c b/tests/basic_tests.c -index 83c453c..810ff5e 100644 ---- a/tests/basic_tests.c -+++ b/tests/basic_tests.c -@@ -2466,11 +2466,9 @@ START_TEST(test_attributes) { - {XCS("id"), XCS("one")}, - {NULL, NULL}}; - AttrInfo tag_info[] = {{XCS("c"), XCS("3")}, {NULL, NULL}}; -- ElementInfo info[] = {{XCS("doc"), 3, 0, XCS("id"), NULL}, -- {XCS("tag"), 1, 0, NULL, NULL}, -+ ElementInfo info[] = {{XCS("doc"), 3, 0, XCS("id"), doc_info}, -+ {XCS("tag"), 1, 0, NULL, tag_info}, - {NULL, 0, 0, NULL, NULL}}; -- info[0].attributes = doc_info; -- info[1].attributes = tag_info; - - XML_Parser parser = XML_ParserCreate(NULL); - assert_true(parser != NULL); -@@ -5816,8 +5814,8 @@ START_TEST(test_deep_nested_attribute_entity) { - (long unsigned)(N_LINES - 1)); - - AttrInfo doc_info[] = {{XCS("name"), XCS("deepText")}, {NULL, NULL}}; -- ElementInfo info[] = {{XCS("foo"), 1, 0, NULL, NULL}, {NULL, 0, 0, NULL, NULL}}; -- info[0].attributes = doc_info; -+ ElementInfo info[] -+ = {{XCS("foo"), 1, 0, NULL, doc_info}, {NULL, 0, 0, NULL, NULL}}; - - XML_Parser parser = XML_ParserCreate(NULL); - ParserAndElementInfo parserPlusElemenInfo = {parser, info}; --- -2.43.0 - diff --git a/meta/recipes-core/expat/expat/CVE-2026-45186-04.patch b/meta/recipes-core/expat/expat/CVE-2026-45186-04.patch deleted file mode 100644 index d30ffa3f512..00000000000 --- a/meta/recipes-core/expat/expat/CVE-2026-45186-04.patch +++ /dev/null @@ -1,32 +0,0 @@ -From 0582bcabb773d4600d7c85516132b016f0163deb Mon Sep 17 00:00:00 2001 -From: Sebastian Pipping -Date: Mon, 13 Apr 2026 01:34:03 +0200 -Subject: [PATCH 4/7] tests: Make counting_start_element_handler enforce - complete attribute lists - -(cherry picked from commit 4176aff73840711060913e0ac6aa1168d8ba5c8d) - -CVE: CVE-2026-45186 -Upstream-Status: Backport [https://github.com/libexpat/libexpat/pull/1216/commits/4176aff73840711060913e0ac6aa1168d8ba5c8d] -Signed-off-by: Theo Gaige ---- - tests/handlers.c | 3 +++ - 1 file changed, 3 insertions(+) - -diff --git a/tests/handlers.c b/tests/handlers.c -index bd1b54e..8cda3a8 100644 ---- a/tests/handlers.c -+++ b/tests/handlers.c -@@ -155,6 +155,9 @@ counting_start_element_handler(void *userData, const XML_Char *name, - /* Remember, two entries in atts per attribute (see above) */ - atts += 2; - } -+ -+ // Self-test that the test case's list of expected attributes is complete -+ assert_true(atts[0] == NULL); - } - - void XMLCALL --- -2.43.0 - diff --git a/meta/recipes-core/expat/expat/CVE-2026-45186-05.patch b/meta/recipes-core/expat/expat/CVE-2026-45186-05.patch deleted file mode 100644 index 6d98a3cd091..00000000000 --- a/meta/recipes-core/expat/expat/CVE-2026-45186-05.patch +++ /dev/null @@ -1,32 +0,0 @@ -From ebe5486739006105629b0bca6022f664566e56de Mon Sep 17 00:00:00 2001 -From: Sebastian Pipping -Date: Sun, 8 Mar 2026 22:14:41 +0100 -Subject: [PATCH 5/7] lib: Extract a constant for upcoming reuse - -(cherry picked from commit fb35f2d2040d114f355bae8a7450942533237530) - -CVE: CVE-2026-45186 -Upstream-Status: Backport [https://github.com/libexpat/libexpat/pull/1216/commits/fb35f2d2040d114f355bae8a7450942533237530] -Signed-off-by: Theo Gaige ---- - lib/xmlparse.c | 3 ++- - 1 file changed, 2 insertions(+), 1 deletion(-) - -diff --git a/lib/xmlparse.c b/lib/xmlparse.c -index 0248b66..e833520 100644 ---- a/lib/xmlparse.c -+++ b/lib/xmlparse.c -@@ -7719,8 +7719,9 @@ dtdCopy(XML_Parser oldParser, DTD *newDtd, const DTD *oldDtd, - newE->prefix = (PREFIX *)lookup(oldParser, &(newDtd->prefixes), - oldE->prefix->name, 0); - for (i = 0; i < newE->nDefaultAtts; i++) { -+ const XML_Char *const attributeName = oldE->defaultAtts[i].id->name; - newE->defaultAtts[i].id = (ATTRIBUTE_ID *)lookup( -- oldParser, &(newDtd->attributeIds), oldE->defaultAtts[i].id->name, 0); -+ oldParser, &(newDtd->attributeIds), attributeName, 0); - newE->defaultAtts[i].isCdata = oldE->defaultAtts[i].isCdata; - if (oldE->defaultAtts[i].value) { - newE->defaultAtts[i].value --- -2.43.0 - diff --git a/meta/recipes-core/expat/expat/CVE-2026-45186-06.patch b/meta/recipes-core/expat/expat/CVE-2026-45186-06.patch deleted file mode 100644 index 1b47776a172..00000000000 --- a/meta/recipes-core/expat/expat/CVE-2026-45186-06.patch +++ /dev/null @@ -1,87 +0,0 @@ -From 41f9f3c8479e8f8547d5bce6355b0484c2744d1e Mon Sep 17 00:00:00 2001 -From: Sebastian Pipping -Date: Sun, 8 Mar 2026 23:05:49 +0100 -Subject: [PATCH 6/7] lib: Introduce ELEMENT_TYPE.defaultAttsNames - -(cherry picked from commit 7f0f1b9e70d937072d2e9e37ae9edf27784cc080) - -CVE: CVE-2026-45186 -Upstream-Status: Backport [https://github.com/libexpat/libexpat/pull/1216/commits/7f0f1b9e70d937072d2e9e37ae9edf27784cc080] -Signed-off-by: Theo Gaige ---- - lib/xmlparse.c | 17 +++++++++++++++++ - 1 file changed, 17 insertions(+) - -diff --git a/lib/xmlparse.c b/lib/xmlparse.c -index e833520..b7e2d72 100644 ---- a/lib/xmlparse.c -+++ b/lib/xmlparse.c -@@ -388,6 +388,7 @@ typedef struct { - int nDefaultAtts; - int allocDefaultAtts; - DEFAULT_ATTRIBUTE *defaultAtts; -+ HASH_TABLE defaultAttsNames; - } ELEMENT_TYPE; - - typedef struct { -@@ -3853,6 +3854,8 @@ storeAtts(XML_Parser parser, const ENCODING *enc, const char *attStr, - sizeof(ELEMENT_TYPE)); - if (! elementType) - return XML_ERROR_NO_MEMORY; -+ if (! elementType->defaultAttsNames.parser) -+ hashTableInit(&(elementType->defaultAttsNames), parser); - if (parser->m_ns && ! setElementTypePrefix(parser, elementType)) - return XML_ERROR_NO_MEMORY; - } -@@ -7561,6 +7564,7 @@ dtdReset(DTD *p, XML_Parser parser) { - ELEMENT_TYPE *e = (ELEMENT_TYPE *)hashTableIterNext(&iter); - if (! e) - break; -+ hashTableDestroy(&(e->defaultAttsNames)); - if (e->allocDefaultAtts != 0) - FREE(parser, e->defaultAtts); - } -@@ -7602,6 +7606,7 @@ dtdDestroy(DTD *p, XML_Bool isDocEntity, XML_Parser parser) { - ELEMENT_TYPE *e = (ELEMENT_TYPE *)hashTableIterNext(&iter); - if (! e) - break; -+ hashTableDestroy(&(e->defaultAttsNames)); - if (e->allocDefaultAtts != 0) - FREE(parser, e->defaultAtts); - } -@@ -7695,6 +7700,10 @@ dtdCopy(XML_Parser oldParser, DTD *newDtd, const DTD *oldDtd, - sizeof(ELEMENT_TYPE)); - if (! newE) - return 0; -+ -+ if (! newE->defaultAttsNames.parser) -+ hashTableInit(&(newE->defaultAttsNames), parser); -+ - if (oldE->nDefaultAtts) { - /* Detect and prevent integer overflow. - * The preprocessor guard addresses the "always false" warning -@@ -7730,6 +7739,12 @@ dtdCopy(XML_Parser oldParser, DTD *newDtd, const DTD *oldDtd, - return 0; - } else - newE->defaultAtts[i].value = NULL; -+ -+ NAMED *const nameAddedOrFound = (NAMED *)lookup( -+ parser, &(newE->defaultAttsNames), attributeName, sizeof(NAMED)); -+ if (! nameAddedOrFound) { -+ return 0; -+ } - } - } - -@@ -8474,6 +8489,8 @@ getElementType(XML_Parser parser, const ENCODING *enc, const char *ptr, - sizeof(ELEMENT_TYPE)); - if (! ret) - return NULL; -+ if (! ret->defaultAttsNames.parser) -+ hashTableInit(&(ret->defaultAttsNames), getRootParserOf(parser, NULL)); - if (ret->name != name) - poolDiscard(&dtd->pool); - else { --- -2.43.0 - diff --git a/meta/recipes-core/expat/expat/CVE-2026-45186-07.patch b/meta/recipes-core/expat/expat/CVE-2026-45186-07.patch deleted file mode 100644 index 5551d10243c..00000000000 --- a/meta/recipes-core/expat/expat/CVE-2026-45186-07.patch +++ /dev/null @@ -1,52 +0,0 @@ -From 141a3c12639f9a4066293e81dbedde4c15b0881f Mon Sep 17 00:00:00 2001 -From: Sebastian Pipping -Date: Sun, 8 Mar 2026 23:06:29 +0100 -Subject: [PATCH 7/7] lib: Leverage ELEMENT_TYPE.defaultAttsNames for attribute - collision detection - -.. to resolve quadratic runtime behavior - -(cherry picked from commit 4cd4eb0683e04cd45a2ffc81a08ca2a2663994b5) - -CVE: CVE-2026-45186 -Upstream-Status: Backport [https://github.com/libexpat/libexpat/pull/1216/commits/4cd4eb0683e04cd45a2ffc81a08ca2a2663994b5] -Signed-off-by: Theo Gaige ---- - lib/xmlparse.c | 14 ++++++++++---- - 1 file changed, 10 insertions(+), 4 deletions(-) - -diff --git a/lib/xmlparse.c b/lib/xmlparse.c -index b7e2d72..04195cb 100644 ---- a/lib/xmlparse.c -+++ b/lib/xmlparse.c -@@ -7189,10 +7189,10 @@ defineAttribute(ELEMENT_TYPE *type, ATTRIBUTE_ID *attId, XML_Bool isCdata, - if (value || isId) { - /* The handling of default attributes gets messed up if we have - a default which duplicates a non-default. */ -- int i; -- for (i = 0; i < type->nDefaultAtts; i++) -- if (attId == type->defaultAtts[i].id) -- return 1; -+ NAMED *const nameFound -+ = (NAMED *)lookup(parser, &(type->defaultAttsNames), attId->name, 0); -+ if (nameFound) -+ return 1; - if (isId && ! type->idAtt && ! attId->xmlns) - type->idAtt = attId; - } -@@ -7239,6 +7239,12 @@ defineAttribute(ELEMENT_TYPE *type, ATTRIBUTE_ID *attId, XML_Bool isCdata, - att->isCdata = isCdata; - if (! isCdata) - attId->maybeTokenized = XML_TRUE; -+ -+ NAMED *const nameAddedOrFound = (NAMED *)lookup( -+ parser, &(type->defaultAttsNames), attId->name, sizeof(NAMED)); -+ if (! nameAddedOrFound) -+ return 0; -+ - type->nDefaultAtts += 1; - return 1; - } --- -2.43.0 - diff --git a/meta/recipes-core/expat/expat/CVE-2026-56132_p1.patch b/meta/recipes-core/expat/expat/CVE-2026-56132_p1.patch deleted file mode 100644 index a413bf0acd0..00000000000 --- a/meta/recipes-core/expat/expat/CVE-2026-56132_p1.patch +++ /dev/null @@ -1,90 +0,0 @@ -From 2e5920edcbc77bf29ce8575bd38ed2886408f4af Mon Sep 17 00:00:00 2001 -From: Matthew Fernandez -Date: Thu, 4 Jun 2026 17:01:02 -0700 -Subject: [PATCH] lib: Remove reuse of `m_groupSize` to count `m_scaffIndex` - allocation - -The sizes of the two arrays `m_groupConnector` and `scaffIndex` need to -vary independently. This change is a step towards allowing this. - -Anthropic: ANT-2026-00037 -Anthropic: ANT-2026-03621 -Anthropic: ANT-2026-03867 -Co-authored-by: Alessandro Gario - -CVE: CVE-2026-56132 -Upstream-Status: Backport [https://github.com/libexpat/libexpat/commit/3a4eaf47af8fd7abda38ea2c08308c91152061f3] - -(cherry picked from commit 3a4eaf47af8fd7abda38ea2c08308c91152061f3) -Signed-off-by: Deepak Rathore ---- - expat/lib/xmlparse.c | 8 ++++++-- - 1 file changed, 6 insertions(+), 2 deletions(-) - -diff --git a/expat/lib/xmlparse.c b/expat/lib/xmlparse.c -index 8e90fea8..d4864af8 100644 ---- a/expat/lib/xmlparse.c -+++ b/expat/lib/xmlparse.c -@@ -424,6 +424,7 @@ typedef struct { - unsigned scaffCount; - int scaffLevel; - int *scaffIndex; -+ size_t scaffIndexSize; - } DTD; - - enum EntityType { -@@ -5995,7 +5996,6 @@ doProlog(XML_Parser parser, const ENCODING *enc, const char *s, const char *end, - * sizeof(unsigned int) < sizeof(size_t), e.g. on x86_64. */ - #if UINT_MAX >= SIZE_MAX - if (parser->m_groupSize > SIZE_MAX / sizeof(int)) { -- parser->m_groupSize /= 2; - return XML_ERROR_NO_MEMORY; - } - #endif -@@ -6003,10 +6003,10 @@ doProlog(XML_Parser parser, const ENCODING *enc, const char *s, const char *end, - int *const new_scaff_index = REALLOC( - parser, dtd->scaffIndex, parser->m_groupSize * sizeof(int)); - if (new_scaff_index == NULL) { -- parser->m_groupSize /= 2; - return XML_ERROR_NO_MEMORY; - } - dtd->scaffIndex = new_scaff_index; -+ dtd->scaffIndexSize = parser->m_groupSize; - } - } else { - parser->m_groupConnector = MALLOC(parser, parser->m_groupSize = 32); -@@ -7587,6 +7587,7 @@ dtdCreate(XML_Parser parser) { - - p->in_eldecl = XML_FALSE; - p->scaffIndex = NULL; -+ p->scaffIndexSize = 0; - p->scaffold = NULL; - p->scaffLevel = 0; - p->scaffSize = 0; -@@ -7627,6 +7628,7 @@ dtdReset(DTD *p, XML_Parser parser) { - - FREE(parser, p->scaffIndex); - p->scaffIndex = NULL; -+ p->scaffIndexSize = 0; - FREE(parser, p->scaffold); - p->scaffold = NULL; - -@@ -7801,6 +7803,7 @@ dtdCopy(XML_Parser oldParser, DTD *newDtd, const DTD *oldDtd, - newDtd->scaffSize = oldDtd->scaffSize; - newDtd->scaffLevel = oldDtd->scaffLevel; - newDtd->scaffIndex = oldDtd->scaffIndex; -+ newDtd->scaffIndexSize = oldDtd->scaffIndexSize; - - return 1; - } /* End dtdCopy */ -@@ -8331,6 +8334,7 @@ nextScaffoldPart(XML_Parser parser) { - dtd->scaffIndex = MALLOC(parser, parser->m_groupSize * sizeof(int)); - if (! dtd->scaffIndex) - return -1; -+ dtd->scaffIndexSize = parser->m_groupSize; - dtd->scaffIndex[0] = 0; - } - --- -2.43.7 - diff --git a/meta/recipes-core/expat/expat/CVE-2026-56132_p2.patch b/meta/recipes-core/expat/expat/CVE-2026-56132_p2.patch deleted file mode 100644 index 6fb8f6078ba..00000000000 --- a/meta/recipes-core/expat/expat/CVE-2026-56132_p2.patch +++ /dev/null @@ -1,63 +0,0 @@ -From 2b6ebe08e4b6b3dd4d0f4f197dac18eecef16e6e Mon Sep 17 00:00:00 2001 -From: Matthew Fernandez -Date: Thu, 4 Jun 2026 17:01:02 -0700 -Subject: [PATCH] lib: doProlog: Fix out-of-bound scaffolding index store -MIME-Version: 1.0 -Content-Type: text/plain; charset=UTF-8 -Content-Transfer-Encoding: 8bit - -The scaffold backing array is reallocated using the caller parser’s -per-parser `m_groupSize`, but the DTD struct (which carries -`scaffIndex`) is shared between a parent parser and any external -parameter-entity sub-parser created via -`XML_ExternalEntityParserCreate(parent, NULL, …)`. A sub-parser whose -group nesting is shallower than the parent’s can `REALLOC` the shared -`scaffIndex` down to its own size; when the parent resumes and parses a -deeper element content model, its bounds check passes (its private -`m_groupSize` is still large enough), the doubling-grow path is skipped, -and the next write lands past the shrunken buffer. - -Anthropic: ANT-2026-00037 -Anthropic: ANT-2026-03621 -Anthropic: ANT-2026-03867 -Co-authored-by: Alessandro Gario -Reported-by: Trail of Bits, in collaboration with Anthropic - -CVE: CVE-2026-56132 -Upstream-Status: Backport [https://github.com/libexpat/libexpat/commit/58400483d7c97be316d7a77739c0a6af5d55932e] - -(cherry picked from commit 58400483d7c97be316d7a77739c0a6af5d55932e) -Signed-off-by: Deepak Rathore ---- - expat/lib/xmlparse.c | 15 +++++++++++++++ - 1 file changed, 15 insertions(+) - -diff --git a/expat/lib/xmlparse.c b/expat/lib/xmlparse.c -index d4864af8..b528c9bc 100644 ---- a/expat/lib/xmlparse.c -+++ b/expat/lib/xmlparse.c -@@ -6022,6 +6022,21 @@ doProlog(XML_Parser parser, const ENCODING *enc, const char *s, const char *end, - if (myindex < 0) - return XML_ERROR_NO_MEMORY; - assert(dtd->scaffIndex != NULL); -+ if ((size_t)dtd->scaffLevel >= dtd->scaffIndexSize) { -+ /* Detect and prevent integer overflow */ -+ if (dtd->scaffIndexSize > SIZE_MAX / 2 / sizeof(int)) { -+ return XML_ERROR_NO_MEMORY; -+ } -+ assert(dtd->scaffIndexSize > 0); -+ const size_t new_size = dtd->scaffIndexSize * 2; -+ int *const new_scaff_index -+ = REALLOC(parser, dtd->scaffIndex, new_size * sizeof(int)); -+ if (new_scaff_index == NULL) { -+ return XML_ERROR_NO_MEMORY; -+ } -+ dtd->scaffIndex = new_scaff_index; -+ dtd->scaffIndexSize = new_size; -+ } - dtd->scaffIndex[dtd->scaffLevel] = myindex; - dtd->scaffLevel++; - dtd->scaffold[myindex].type = XML_CTYPE_SEQ; --- -2.43.7 - diff --git a/meta/recipes-core/expat/expat/CVE-2026-56132_p3.patch b/meta/recipes-core/expat/expat/CVE-2026-56132_p3.patch deleted file mode 100644 index 5405224ec38..00000000000 --- a/meta/recipes-core/expat/expat/CVE-2026-56132_p3.patch +++ /dev/null @@ -1,77 +0,0 @@ -From 22805ecc87ba8f66b693220442408a6f7c7e741d Mon Sep 17 00:00:00 2001 -From: Matthew Fernandez -Date: Thu, 4 Jun 2026 17:01:02 -0700 -Subject: [PATCH] tests: Add a test case for scaffolding array limits in shared - DTDs - -This test case provokes the bug fixed in the previous commit. - -Anthropic: ANT-2026-00037 -Anthropic: ANT-2026-03621 -Anthropic: ANT-2026-03867 -Co-authored-by: Alessandro Gario -Reported-by: Trail of Bits, in collaboration with Anthropic - -CVE: CVE-2026-56132 -Upstream-Status: Backport [https://github.com/libexpat/libexpat/commit/353919b3b9f2174073a557ac7d517a5f3cd0cbbf] - -(cherry picked from commit 353919b3b9f2174073a557ac7d517a5f3cd0cbbf) -Signed-off-by: Deepak Rathore ---- - expat/tests/basic_tests.c | 33 +++++++++++++++++++++++++++++++++ - 1 file changed, 33 insertions(+) - -diff --git a/expat/tests/basic_tests.c b/expat/tests/basic_tests.c -index 02d1d5fd..53b920da 100644 ---- a/expat/tests/basic_tests.c -+++ b/expat/tests/basic_tests.c -@@ -4091,6 +4091,37 @@ START_TEST(test_skipped_external_entity) { - } - END_TEST - -+START_TEST(test_scaff_index_shared_across_external_entity_parser) { -+ const char text[] -+ = "\n" -+ "\n" -+ "%e;\n" -+ "\n" -+ "]>\n" -+ ""; -+ ExtOption options[] -+ = {{XCS("ext"), -+ ""}, -+ {NULL, NULL}}; -+ -+ XML_Parser parser = XML_ParserCreate(NULL); -+ XML_SetParamEntityParsing(parser, XML_PARAM_ENTITY_PARSING_ALWAYS); -+ XML_SetUserData(parser, options); -+ XML_SetExternalEntityRefHandler(parser, external_entity_optioner); -+ XML_SetElementDeclHandler(parser, dummy_element_decl_handler); -+ -+ if (_XML_Parse_SINGLE_BYTES(parser, text, (int)strlen(text), XML_TRUE) -+ == XML_STATUS_ERROR) -+ xml_failure(parser); -+ -+ XML_ParserFree(parser); -+} -+END_TEST -+ - /* Test a different form of unknown external entity */ - START_TEST(test_skipped_null_loaded_ext_entity) { - const char *text = "\n" -@@ -6448,6 +6479,8 @@ make_basic_test_case(Suite *s) { - tcase_add_test(tc_basic, test_trailing_cr_in_att_value); - tcase_add_test(tc_basic, test_standalone_internal_entity); - tcase_add_test(tc_basic, test_skipped_external_entity); -+ tcase_add_test__ifdef_xml_dtd( -+ tc_basic, test_scaff_index_shared_across_external_entity_parser); - tcase_add_test(tc_basic, test_skipped_null_loaded_ext_entity); - tcase_add_test(tc_basic, test_skipped_unloaded_ext_entity); - tcase_add_test__ifdef_xml_dtd(tc_basic, test_param_entity_with_trailing_cr); --- -2.43.7 - diff --git a/meta/recipes-core/expat/expat/CVE-2026-56132_p4.patch b/meta/recipes-core/expat/expat/CVE-2026-56132_p4.patch deleted file mode 100644 index 0cef4df4527..00000000000 --- a/meta/recipes-core/expat/expat/CVE-2026-56132_p4.patch +++ /dev/null @@ -1,63 +0,0 @@ -From 36df125531dab7e0dc640b341d07b4b1f5ede37b Mon Sep 17 00:00:00 2001 -From: Matthew Fernandez -Date: Thu, 4 Jun 2026 17:01:02 -0700 -Subject: [PATCH] lib: Remove unnecessary `scaffIndex` expansion - -Following the previous changes, all locations that append entries to -`scaffIndex` handle expanding the array if it is not already large -enough. So this extra expansion code is no longer necessary. In some -cases such as processing siblings with alternating scaffolding counts, -this logic would actually _shrink_ the array only to then later -re-expand it. - -Anthropic: ANT-2026-00037 -Anthropic: ANT-2026-03621 -Anthropic: ANT-2026-03867 -Co-authored-by: Alessandro Gario - -CVE: CVE-2026-56132 -Upstream-Status: Backport [https://github.com/libexpat/libexpat/commit/bca93b4ba9e15fd84425568d772b69baebf790e4] - -Backport Changes: -- Remove the expanded Expat 2.7.5 scaffIndex resize block, including its - branch-specific integer overflow guard. - -(cherry picked from commit bca93b4ba9e15fd84425568d772b69baebf790e4) -Signed-off-by: Deepak Rathore ---- - expat/lib/xmlparse.c | 20 -------------------- - 1 file changed, 20 deletions(-) - -diff --git a/expat/lib/xmlparse.c b/expat/lib/xmlparse.c -index b528c9bc..e59ad556 100644 ---- a/expat/lib/xmlparse.c -+++ b/expat/lib/xmlparse.c -@@ -5988,26 +5988,6 @@ doProlog(XML_Parser parser, const ENCODING *enc, const char *s, const char *end, - } - parser->m_groupConnector = new_connector; - } -- -- if (dtd->scaffIndex) { -- /* Detect and prevent integer overflow. -- * The preprocessor guard addresses the "always false" warning -- * from -Wtype-limits on platforms where -- * sizeof(unsigned int) < sizeof(size_t), e.g. on x86_64. */ --#if UINT_MAX >= SIZE_MAX -- if (parser->m_groupSize > SIZE_MAX / sizeof(int)) { -- return XML_ERROR_NO_MEMORY; -- } --#endif -- -- int *const new_scaff_index = REALLOC( -- parser, dtd->scaffIndex, parser->m_groupSize * sizeof(int)); -- if (new_scaff_index == NULL) { -- return XML_ERROR_NO_MEMORY; -- } -- dtd->scaffIndex = new_scaff_index; -- dtd->scaffIndexSize = parser->m_groupSize; -- } - } else { - parser->m_groupConnector = MALLOC(parser, parser->m_groupSize = 32); - if (! parser->m_groupConnector) { --- -2.43.7 diff --git a/meta/recipes-core/expat/expat/CVE-2026-56132_p5.patch b/meta/recipes-core/expat/expat/CVE-2026-56132_p5.patch deleted file mode 100644 index 8655298b65f..00000000000 --- a/meta/recipes-core/expat/expat/CVE-2026-56132_p5.patch +++ /dev/null @@ -1,58 +0,0 @@ -From c6256eca63fe36d4ef26fd59cbcaab7b72e1d6f2 Mon Sep 17 00:00:00 2001 -From: Matthew Fernandez -Date: Thu, 4 Jun 2026 17:01:02 -0700 -Subject: [PATCH] lib: Remove indented scoping of `new_connector` local - -Following the previous change, the lifetime of `new_connector` as -constrained by this introduced scope was identical to the parent scope. - -CVE: CVE-2026-56132 -Upstream-Status: Backport [https://github.com/libexpat/libexpat/commit/08baa7ef9d168b99094249998fd78f8d190526e5] - -Backport Changes: -- Keep the Expat 2.7.5 unsigned-int overflow guard while removing the - redundant new_connector scope. - -(cherry picked from commit 08baa7ef9d168b99094249998fd78f8d190526e5) -Signed-off-by: Deepak Rathore ---- - expat/lib/xmlparse.c | 22 ++++++++++------------ - 1 file changed, 10 insertions(+), 12 deletions(-) - -diff --git a/expat/lib/xmlparse.c b/expat/lib/xmlparse.c -index e59ad556..e8d6fc3a 100644 ---- a/expat/lib/xmlparse.c -+++ b/expat/lib/xmlparse.c -@@ -5974,20 +5974,18 @@ doProlog(XML_Parser parser, const ENCODING *enc, const char *s, const char *end, - case XML_ROLE_GROUP_OPEN: - if (parser->m_prologState.level >= parser->m_groupSize) { - if (parser->m_groupSize) { -- { -- /* Detect and prevent integer overflow */ -- if (parser->m_groupSize > (unsigned int)(-1) / 2u) { -- return XML_ERROR_NO_MEMORY; -- } -+ /* Detect and prevent integer overflow */ -+ if (parser->m_groupSize > (unsigned int)(-1) / 2u) { -+ return XML_ERROR_NO_MEMORY; -+ } - -- char *const new_connector = REALLOC( -- parser, parser->m_groupConnector, parser->m_groupSize *= 2); -- if (new_connector == NULL) { -- parser->m_groupSize /= 2; -- return XML_ERROR_NO_MEMORY; -- } -- parser->m_groupConnector = new_connector; -+ char *const new_connector = REALLOC(parser, parser->m_groupConnector, -+ parser->m_groupSize *= 2); -+ if (new_connector == NULL) { -+ parser->m_groupSize /= 2; -+ return XML_ERROR_NO_MEMORY; - } -+ parser->m_groupConnector = new_connector; - } else { - parser->m_groupConnector = MALLOC(parser, parser->m_groupSize = 32); - if (! parser->m_groupConnector) { --- -2.43.7 diff --git a/meta/recipes-core/expat/expat/CVE-2026-56403_p1.patch b/meta/recipes-core/expat/expat/CVE-2026-56403_p1.patch deleted file mode 100644 index 4cf5c3bd54d..00000000000 --- a/meta/recipes-core/expat/expat/CVE-2026-56403_p1.patch +++ /dev/null @@ -1,83 +0,0 @@ -From 4a264be1794368a1acc08476058b6cf087686d11 Mon Sep 17 00:00:00 2001 -From: Sebastian Pipping -Date: Wed, 20 May 2026 12:12:10 +0200 -Subject: [PATCH] lib: Protect function `storeAtts` from signed integer - overflow - -CVE: CVE-2026-56403 -Upstream-Status: Backport [https://github.com/libexpat/libexpat/commit/12dc6d8d3d65f79471a94d8565f6bf1cf245f648] - -Backport Changes: -- Retain the Expat 2.7.5 binding URI reallocation and active tag pointer - updates while using the overflow-safe localPartLen calculation. - -(cherry picked from commit 12dc6d8d3d65f79471a94d8565f6bf1cf245f648) -Signed-off-by: Deepak Rathore ---- - expat/lib/xmlparse.c | 30 ++++++++++++++++++++---------- - 1 file changed, 20 insertions(+), 10 deletions(-) - -diff --git a/expat/lib/xmlparse.c b/expat/lib/xmlparse.c -index 0248b665..e441ff7f 100644 ---- a/expat/lib/xmlparse.c -+++ b/expat/lib/xmlparse.c -@@ -4235,26 +4235,32 @@ storeAtts(XML_Parser parser, const ENCODING *enc, const char *attStr, - return XML_ERROR_NONE; - prefixLen = 0; - if (parser->m_ns_triplets && binding->prefix->name) { -- while (binding->prefix->name[prefixLen++]) -- ; /* prefixLen includes null terminator */ -+ size_t candidateLen = 0; -+ while (binding->prefix->name[candidateLen++]) -+ ; /* candidateLen includes null terminator */ -+ /* Detect and prevent integer overflow */ -+ if (candidateLen > INT_MAX) -+ return XML_ERROR_NO_MEMORY; -+ prefixLen = (int)candidateLen; - } - tagNamePtr->localPart = localPart; - tagNamePtr->uriLen = binding->uriLen; - tagNamePtr->prefix = binding->prefix->name; - tagNamePtr->prefixLen = prefixLen; -- for (i = 0; localPart[i++];) -- ; /* i includes null terminator */ -+ -+ size_t localPartLen = 0; -+ for (; localPart[localPartLen++];) -+ ; /* localPartLen includes null terminator */ - - /* Detect and prevent integer overflow */ -- if (binding->uriLen > INT_MAX - prefixLen -- || i > INT_MAX - (binding->uriLen + prefixLen)) { -+ if (localPartLen > INT_MAX || binding->uriLen > INT_MAX - prefixLen -+ || localPartLen > (size_t)INT_MAX - (binding->uriLen + prefixLen)) { - return XML_ERROR_NO_MEMORY; - } - -- n = i + binding->uriLen + prefixLen; -+ n = (int)localPartLen + binding->uriLen + prefixLen; - if (n > binding->uriAlloc) { - TAG *p; -- - /* Detect and prevent integer overflow */ - if (n > INT_MAX - EXPAND_SPARE) { - return XML_ERROR_NO_MEMORY; -@@ -4282,10 +4288,14 @@ storeAtts(XML_Parser parser, const ENCODING *enc, const char *attStr, - } - /* if m_namespaceSeparator != '\0' then uri includes it already */ - uri = binding->uri + binding->uriLen; -- memcpy(uri, localPart, i * sizeof(XML_Char)); -+ /* Detect and prevent integer overflow */ -+ if (localPartLen > SIZE_MAX / sizeof(XML_Char)) { -+ return XML_ERROR_NO_MEMORY; -+ } -+ memcpy(uri, localPart, localPartLen * sizeof(XML_Char)); - /* we always have a namespace separator between localPart and prefix */ - if (prefixLen) { -- uri += i - 1; -+ uri += localPartLen - 1; - *uri = parser->m_namespaceSeparator; /* replace null terminator */ - memcpy(uri + 1, binding->prefix->name, prefixLen * sizeof(XML_Char)); - } --- -2.43.7 diff --git a/meta/recipes-core/expat/expat/CVE-2026-56403_p2.patch b/meta/recipes-core/expat/expat/CVE-2026-56403_p2.patch deleted file mode 100644 index 62fdff79e3c..00000000000 --- a/meta/recipes-core/expat/expat/CVE-2026-56403_p2.patch +++ /dev/null @@ -1,40 +0,0 @@ -From e8100827a4f68c70d8cadf446bb82bec7cbebbac Mon Sep 17 00:00:00 2001 -From: Sebastian Pipping -Date: Fri, 22 May 2026 00:43:52 +0200 -Subject: [PATCH] xmlwf: Protect function `xcsdup` from signed integer overflow - -CVE: CVE-2026-56403 -Upstream-Status: Backport [https://github.com/libexpat/libexpat/commit/147c8f36d6277d5c6011c098370a8362aed47b15] - -(cherry picked from commit 147c8f36d6277d5c6011c098370a8362aed47b15) -Signed-off-by: Deepak Rathore ---- - expat/xmlwf/xmlwf.c | 7 ++++++- - 1 file changed, 6 insertions(+), 1 deletion(-) - -diff --git a/expat/xmlwf/xmlwf.c b/expat/xmlwf/xmlwf.c -index 2d0c4f8e..934473ce 100644 ---- a/expat/xmlwf/xmlwf.c -+++ b/expat/xmlwf/xmlwf.c -@@ -305,13 +305,18 @@ processingInstruction(void *userData, const XML_Char *target, - static XML_Char * - xcsdup(const XML_Char *s) { - XML_Char *result; -- int count = 0; -+ size_t count = 0; - size_t numBytes; - - /* Get the length of the string, including terminator */ - while (s[count++] != 0) { - /* Do nothing */ - } -+ -+ // Detect and prevent integer overflow -+ if (count > SIZE_MAX / sizeof(XML_Char)) -+ return NULL; -+ - numBytes = count * sizeof(XML_Char); - result = malloc(numBytes); - if (result == NULL) --- -2.43.7 diff --git a/meta/recipes-core/expat/expat/CVE-2026-56404.patch b/meta/recipes-core/expat/expat/CVE-2026-56404.patch deleted file mode 100644 index 6bca7cf961c..00000000000 --- a/meta/recipes-core/expat/expat/CVE-2026-56404.patch +++ /dev/null @@ -1,47 +0,0 @@ -From 8cb4583ac3204175a03c8ea8e371adee583b0bec Mon Sep 17 00:00:00 2001 -From: netliomax25-code -Date: Thu, 28 May 2026 12:44:11 +0530 -Subject: [PATCH] lib: protect function addBinding from signed integer overflow - -CVE: CVE-2026-56404 -Upstream-Status: Backport [https://github.com/libexpat/libexpat/commit/babfc48090977cbf7be24b2c48f6053dca75c164] - -(cherry picked from commit babfc48090977cbf7be24b2c48f6053dca75c164) -Signed-off-by: Deepak Rathore ---- - expat/lib/xmlparse.c | 11 ++++++++++- - 1 file changed, 10 insertions(+), 1 deletion(-) - -diff --git a/expat/lib/xmlparse.c b/expat/lib/xmlparse.c -index 53f842d1..33b92c9c 100644 ---- a/expat/lib/xmlparse.c -+++ b/expat/lib/xmlparse.c -@@ -4485,6 +4485,10 @@ addBinding(XML_Parser parser, PREFIX *prefix, const ATTRIBUTE_ID *attId, - } - - for (len = 0; uri[len]; len++) { -+ /* Detect and prevent signed integer overflow */ -+ if (len == INT_MAX) { -+ return XML_ERROR_NO_MEMORY; -+ } - if (isXML && (len > xmlLen || uri[len] != xmlNamespace[len])) - isXML = XML_FALSE; - -@@ -4525,8 +4529,13 @@ addBinding(XML_Parser parser, PREFIX *prefix, const ATTRIBUTE_ID *attId, - if (isXMLNS) - return XML_ERROR_RESERVED_NAMESPACE_URI; - -- if (parser->m_namespaceSeparator) -+ if (parser->m_namespaceSeparator) { -+ /* Detect and prevent signed integer overflow */ -+ if (len == INT_MAX) { -+ return XML_ERROR_NO_MEMORY; -+ } - len++; -+ } - if (parser->m_freeBindingList) { - b = parser->m_freeBindingList; - if (len > b->uriAlloc) { --- -2.43.7 - diff --git a/meta/recipes-core/expat/expat/CVE-2026-56405.patch b/meta/recipes-core/expat/expat/CVE-2026-56405.patch deleted file mode 100644 index c850801c1ac..00000000000 --- a/meta/recipes-core/expat/expat/CVE-2026-56405.patch +++ /dev/null @@ -1,32 +0,0 @@ -From 73209f445f0265b203829fa7873caa78ca83cefe Mon Sep 17 00:00:00 2001 -From: netliomax25-code -Date: Fri, 29 May 2026 11:45:17 +0530 -Subject: [PATCH] lib: Protect function getAttributeId from signed integer - overflow - -CVE: CVE-2026-56405 -Upstream-Status: Backport [https://github.com/libexpat/libexpat/commit/2c6c42d33689f6b266a5267b639e03cde17e53c0] - -(cherry picked from commit 2c6c42d33689f6b266a5267b639e03cde17e53c0) -Signed-off-by: Deepak Rathore ---- - expat/lib/xmlparse.c | 4 ++++ - 1 file changed, 4 insertions(+) - -diff --git a/expat/lib/xmlparse.c b/expat/lib/xmlparse.c -index 1b7e289f..ec707336 100644 ---- a/expat/lib/xmlparse.c -+++ b/expat/lib/xmlparse.c -@@ -7324,6 +7324,10 @@ getAttributeId(XML_Parser parser, const ENCODING *enc, const char *start, - } else { - int i; - for (i = 0; name[i]; i++) { -+ /* Detect and prevent signed integer overflow */ -+ if (i == INT_MAX) { -+ return NULL; -+ } - /* attributes without prefix are *not* in the default namespace */ - if (name[i] == XML_T(ASCII_COLON)) { - int j; --- -2.43.7 diff --git a/meta/recipes-core/expat/expat/CVE-2026-56406-dependent.patch b/meta/recipes-core/expat/expat/CVE-2026-56406-dependent.patch deleted file mode 100644 index 6ef7c42298c..00000000000 --- a/meta/recipes-core/expat/expat/CVE-2026-56406-dependent.patch +++ /dev/null @@ -1,58 +0,0 @@ -From 4f828b7ee9d6efef618e8a99a0392acbb95e84f2 Mon Sep 17 00:00:00 2001 -From: Matthew Fernandez -Date: Wed, 27 May 2026 17:01:44 -0700 -Subject: [PATCH] lib: Make `XML_Index` overflow check more intuitive - -In fixing a bug, 7e5b71b748491b6e459e5c9a1d090820f94544d8 introduced a -magic number `2` in this code that made it difficult to understand the -rationale for this overflow check without reading the commit log. This -change introduces some more readable constants to use in these -situations. - -CVE: CVE-2026-56406 -Upstream-Status: Backport [https://github.com/libexpat/libexpat/commit/252ff1a307b1490ce0f430632791e7e52d7e43fd] - -(cherry picked from commit 252ff1a307b1490ce0f430632791e7e52d7e43fd) -Signed-off-by: Deepak Rathore ---- - expat/lib/xmlparse.c | 10 ++++++++-- - 1 file changed, 8 insertions(+), 2 deletions(-) - -diff --git a/expat/lib/xmlparse.c b/expat/lib/xmlparse.c -index 96127bf8..5ecea7a8 100644 ---- a/expat/lib/xmlparse.c -+++ b/expat/lib/xmlparse.c -@@ -101,7 +101,7 @@ - #include - #include /* memset(), memcpy() */ - #include --#include /* INT_MAX, UINT_MAX */ -+#include /* INT_MAX, LLONG_MAX, LONG_MAX, UINT_MAX */ - #include /* fprintf */ - #include /* getenv, rand_s */ - #include /* SIZE_MAX, uintptr_t */ -@@ -209,6 +209,12 @@ typedef char ICHAR; - - #endif - -+#ifdef XML_LARGE_SIZE -+# define XML_INDEX_MAX LLONG_MAX -+#else -+# define XML_INDEX_MAX LONG_MAX -+#endif -+ - /* Round up n to be a multiple of sz, where sz is a power of 2. */ - #define ROUND_UP(n, sz) (((n) + ((sz) - 1)) & ~((sz) - 1)) - -@@ -2395,7 +2401,7 @@ XML_Parse(XML_Parser parser, const char *s, int len, int isFinal) { - int nLeftOver; - enum XML_Status result; - /* Detect overflow (a+b > MAX <==> b > MAX-a) */ -- if ((XML_Size)len > ((XML_Size)-1) / 2 - parser->m_parseEndByteIndex) { -+ if (len > XML_INDEX_MAX - parser->m_parseEndByteIndex) { - parser->m_errorCode = XML_ERROR_NO_MEMORY; - parser->m_eventPtr = parser->m_eventEndPtr = NULL; - parser->m_processor = errorProcessor; --- -2.43.7 - diff --git a/meta/recipes-core/expat/expat/CVE-2026-56406.patch b/meta/recipes-core/expat/expat/CVE-2026-56406.patch deleted file mode 100644 index 4077b9946a9..00000000000 --- a/meta/recipes-core/expat/expat/CVE-2026-56406.patch +++ /dev/null @@ -1,37 +0,0 @@ -From 6e52f18aded0a76cf89f191d7810bc04287f5337 Mon Sep 17 00:00:00 2001 -From: Sebastian Pipping -Date: Sun, 31 May 2026 15:18:58 +0200 -Subject: [PATCH] lib: Copy overflow check from `XML_Parse` to - `XML_ParseBuffer` - -CVE: CVE-2026-56406 -Upstream-Status: Backport [https://github.com/libexpat/libexpat/commit/99d8454fdf900a6d00c2a52748e6c0eeb507574d] - -(cherry picked from commit 99d8454fdf900a6d00c2a52748e6c0eeb507574d) -Signed-off-by: Deepak Rathore ---- - expat/lib/xmlparse.c | 8 ++++++++ - 1 file changed, 8 insertions(+) - -diff --git a/expat/lib/xmlparse.c b/expat/lib/xmlparse.c -index 5ecea7a8..71fe2c79 100644 ---- a/expat/lib/xmlparse.c -+++ b/expat/lib/xmlparse.c -@@ -2518,6 +2518,14 @@ XML_ParseBuffer(XML_Parser parser, int len, int isFinal) { - parser->m_parsingStatus.parsing = XML_PARSING; - } - -+ // Detect and avoid integer overflow -+ if (len > XML_INDEX_MAX - parser->m_parseEndByteIndex) { -+ parser->m_errorCode = XML_ERROR_NO_MEMORY; -+ parser->m_eventPtr = parser->m_eventEndPtr = NULL; -+ parser->m_processor = errorProcessor; -+ return XML_STATUS_ERROR; -+ } -+ - start = parser->m_bufferPtr; - parser->m_positionPtr = start; - parser->m_bufferEnd += len; --- -2.43.7 - diff --git a/meta/recipes-core/expat/expat/CVE-2026-56407.patch b/meta/recipes-core/expat/expat/CVE-2026-56407.patch deleted file mode 100644 index 5a2a22e0172..00000000000 --- a/meta/recipes-core/expat/expat/CVE-2026-56407.patch +++ /dev/null @@ -1,44 +0,0 @@ -From 7216b3584bcfb2d415026d16b8902ee7eacad5ca Mon Sep 17 00:00:00 2001 -From: netliomax25-code -Date: Tue, 2 Jun 2026 11:59:01 +0530 -Subject: [PATCH] cap entity textLen against signed integer overflow - -CVE: CVE-2026-56407 -Upstream-Status: Backport [https://github.com/libexpat/libexpat/commit/30c2fc179ce5d2b1b1bae30bbe0dfddeac894e13] - -(cherry picked from commit 30c2fc179ce5d2b1b1bae30bbe0dfddeac894e13) -Signed-off-by: Deepak Rathore ---- - expat/lib/xmlparse.c | 9 +++++++++ - 1 file changed, 9 insertions(+) - -diff --git a/expat/lib/xmlparse.c b/expat/lib/xmlparse.c -index 71fe2c79..8e90fea8 100644 ---- a/expat/lib/xmlparse.c -+++ b/expat/lib/xmlparse.c -@@ -5684,6 +5684,10 @@ doProlog(XML_Parser parser, const ENCODING *enc, const char *s, const char *end, - parser, enc, s + enc->minBytesPerChar, next - enc->minBytesPerChar, - XML_ACCOUNT_NONE); - if (parser->m_declEntity) { -+ /* Detect and prevent signed integer overflow */ -+ if ((size_t)poolLength(&dtd->entityValuePool) > (size_t)INT_MAX) { -+ return XML_ERROR_NO_MEMORY; -+ } - parser->m_declEntity->textPtr = poolStart(&dtd->entityValuePool); - parser->m_declEntity->textLen - = (int)(poolLength(&dtd->entityValuePool)); -@@ -7099,6 +7103,11 @@ storeSelfEntityValue(XML_Parser parser, ENTITY *entity) { - return XML_ERROR_NO_MEMORY; - } - -+ /* Detect and prevent signed integer overflow */ -+ if ((size_t)poolLength(pool) > (size_t)INT_MAX) { -+ poolDiscard(pool); -+ return XML_ERROR_NO_MEMORY; -+ } - entity->textPtr = poolStart(pool); - entity->textLen = (int)(poolLength(pool)); - poolFinish(pool); --- -2.43.7 - diff --git a/meta/recipes-core/expat/expat/CVE-2026-56408.patch b/meta/recipes-core/expat/expat/CVE-2026-56408.patch deleted file mode 100644 index b8c43636cc0..00000000000 --- a/meta/recipes-core/expat/expat/CVE-2026-56408.patch +++ /dev/null @@ -1,36 +0,0 @@ -From b0cf9e9b0f5dfdd938148931a4605a0fd6b917a7 Mon Sep 17 00:00:00 2001 -From: Sebastian Pipping -Date: Thu, 23 Apr 2026 10:31:45 +0200 -Subject: [PATCH] lib: Waterproof `copyString` from integer overflow - -CVE: CVE-2026-56408 -Upstream-Status: Backport [https://github.com/libexpat/libexpat/commit/16e2efd867ea8567ffa012210b52ef5918e20817] - -Backport Changes: -- Adapt the fix to Expat 2.7.5, which calculates charsRequired using - an existing loop instead of xcslen. The upstream string helper - refactoring is not required for the overflow guard. - -(cherry picked from commit 16e2efd867ea8567ffa012210b52ef5918e20817) -Signed-off-by: Deepak Rathore ---- - expat/lib/xmlparse.c | 4 ++++ - 1 file changed, 4 insertions(+) - -diff --git a/expat/lib/xmlparse.c b/expat/lib/xmlparse.c -index e441ff7f..4ff5e33b 100644 ---- a/expat/lib/xmlparse.c -+++ b/expat/lib/xmlparse.c -@@ -8505,6 +8505,10 @@ copyString(const XML_Char *s, XML_Parser parser) { - /* Include the terminator */ - charsRequired++; - -+ /* Detect and prevent integer overflow */ -+ if (charsRequired > SIZE_MAX / sizeof(XML_Char)) -+ return NULL; -+ - /* Now allocate space for the copy */ - result = MALLOC(parser, charsRequired * sizeof(XML_Char)); - if (result == NULL) --- -2.43.7 diff --git a/meta/recipes-core/expat/expat/CVE-2026-56409.patch b/meta/recipes-core/expat/expat/CVE-2026-56409.patch deleted file mode 100644 index ff0e650a2ab..00000000000 --- a/meta/recipes-core/expat/expat/CVE-2026-56409.patch +++ /dev/null @@ -1,53 +0,0 @@ -From 10938bc2cef7573087566b5b1c948061baa68b98 Mon Sep 17 00:00:00 2001 -From: netliomax25-code -Date: Mon, 1 Jun 2026 11:53:19 +0530 -Subject: [PATCH] xmlwf: protect output path join from integer overflow - -CVE: CVE-2026-56409 -Upstream-Status: Backport [https://github.com/libexpat/libexpat/commit/61f7cdda22546c4bee38dd2d3fa3d6e4aa64d33e] - -Backport Changes: -- Adapt the allocation hunk to the explicit cast used by Expat 2.7.5. - -(cherry picked from commit 61f7cdda22546c4bee38dd2d3fa3d6e4aa64d33e) -Signed-off-by: Deepak Rathore ---- - expat/xmlwf/xmlwf.c | 22 ++++++++++++++++++++-- - 1 file changed, 20 insertions(+), 2 deletions(-) - -diff --git a/expat/xmlwf/xmlwf.c b/expat/xmlwf/xmlwf.c -index 06416454..6a0a707a 100644 ---- a/expat/xmlwf/xmlwf.c -+++ b/expat/xmlwf/xmlwf.c -@@ -1236,8 +1236,26 @@ tmain(int argc, XML_Char **argv) { - } - #endif - } -- outName = (XML_Char *)malloc((tcslen(outputDir) + tcslen(file) + 2) -- * sizeof(XML_Char)); -+ const size_t outputDirLen = tcslen(outputDir); -+ const size_t fileLen = tcslen(file); -+ -+ /* Detect and prevent integer overflow in the addition (without -+ risking underflow) and the multiplication, mirroring the guards -+ in xcsdup() and resolveSystemId() */ -+ if (outputDirLen > SIZE_MAX - fileLen -+ || outputDirLen > SIZE_MAX - fileLen - 2) { -+ tperror(T("Could not allocate memory")); -+ exit(XMLWF_EXIT_INTERNAL_ERROR); -+ } -+ -+ const size_t charsRequired = outputDirLen + fileLen + 2; -+ -+ if (charsRequired > SIZE_MAX / sizeof(XML_Char)) { -+ tperror(T("Could not allocate memory")); -+ exit(XMLWF_EXIT_INTERNAL_ERROR); -+ } -+ -+ outName = malloc(charsRequired * sizeof(XML_Char)); - if (! outName) { - tperror(T("Could not allocate memory")); - exit(XMLWF_EXIT_INTERNAL_ERROR); --- -2.43.7 - diff --git a/meta/recipes-core/expat/expat/CVE-2026-56410_p1.patch b/meta/recipes-core/expat/expat/CVE-2026-56410_p1.patch deleted file mode 100644 index aa4378f1b77..00000000000 --- a/meta/recipes-core/expat/expat/CVE-2026-56410_p1.patch +++ /dev/null @@ -1,40 +0,0 @@ -From 759b77a8439bcbf57c86900bc472d46d8ef70c92 Mon Sep 17 00:00:00 2001 -From: netliomax25-code -Date: Fri, 29 May 2026 17:51:25 +0530 -Subject: [PATCH] xmlwf: protect resolveSystemId from integer overflow - -CVE: CVE-2026-56410 -Upstream-Status: Backport [https://github.com/libexpat/libexpat/commit/deeb97f7c88d17a16b0ea2521a13733abc283347] - -Backport Changes: -- Adjust the removed allocation line for Wrynose's explicit malloc cast while - keeping upstream's overflow checks and final allocation logic. - -(cherry picked from commit deeb97f7c88d17a16b0ea2521a13733abc283347) -Signed-off-by: Deepak Rathore ---- - expat/xmlwf/xmlfile.c | 9 +++++++-- - 1 file changed, 7 insertions(+), 2 deletions(-) - -diff --git a/expat/xmlwf/xmlfile.c b/expat/xmlwf/xmlfile.c -index c4eb839f..31a40209 100644 ---- a/expat/xmlwf/xmlfile.c -+++ b/expat/xmlwf/xmlfile.c -@@ -138,8 +138,13 @@ resolveSystemId(const XML_Char *base, const XML_Char *systemId, - #endif - ) - return systemId; -- *toFree = (XML_Char *)malloc((tcslen(base) + tcslen(systemId) + 2) -- * sizeof(XML_Char)); -+ const size_t charsRequired = tcslen(base) + tcslen(systemId) + 2; -+ -+ /* Detect and prevent integer overflow */ -+ if (charsRequired > SIZE_MAX / sizeof(XML_Char)) -+ return systemId; -+ -+ *toFree = malloc(charsRequired * sizeof(XML_Char)); - if (! *toFree) - return systemId; - tcscpy(*toFree, base); --- -2.43.7 diff --git a/meta/recipes-core/expat/expat/CVE-2026-56410_p2.patch b/meta/recipes-core/expat/expat/CVE-2026-56410_p2.patch deleted file mode 100644 index 71f3122602a..00000000000 --- a/meta/recipes-core/expat/expat/CVE-2026-56410_p2.patch +++ /dev/null @@ -1,41 +0,0 @@ -From f16fa442eaa81bfceec5302d977219959eaac7b7 Mon Sep 17 00:00:00 2001 -From: netliomax25-code -Date: Sat, 30 May 2026 11:28:51 +0530 -Subject: [PATCH] xmlwf: guard each operator in resolveSystemId length sum - -CVE: CVE-2026-56410 -Upstream-Status: Backport [https://github.com/libexpat/libexpat/commit/cee20e91bf14dc7f6d2fc48f0d70d86b2dc3afea] - -(cherry picked from commit cee20e91bf14dc7f6d2fc48f0d70d86b2dc3afea) -Signed-off-by: Deepak Rathore ---- - expat/xmlwf/xmlfile.c | 12 ++++++++++-- - 1 file changed, 10 insertions(+), 2 deletions(-) - -diff --git a/expat/xmlwf/xmlfile.c b/expat/xmlwf/xmlfile.c -index 31a40209..15c69217 100644 ---- a/expat/xmlwf/xmlfile.c -+++ b/expat/xmlwf/xmlfile.c -@@ -139,9 +139,17 @@ resolveSystemId(const XML_Char *base, const XML_Char *systemId, - #endif - ) - return systemId; -- const size_t charsRequired = tcslen(base) + tcslen(systemId) + 2; -+ const size_t baseLen = tcslen(base); -+ const size_t systemIdLen = tcslen(systemId); - -- /* Detect and prevent integer overflow */ -+ /* Detect and prevent integer overflow in the addition (without risking -+ underflow) */ -+ if (baseLen > SIZE_MAX - systemIdLen || baseLen > SIZE_MAX - systemIdLen - 2) -+ return systemId; -+ -+ const size_t charsRequired = baseLen + systemIdLen + 2; -+ -+ /* Detect and prevent integer overflow in the multiplication */ - if (charsRequired > SIZE_MAX / sizeof(XML_Char)) - return systemId; - --- -2.43.7 - diff --git a/meta/recipes-core/expat/expat/CVE-2026-56411.patch b/meta/recipes-core/expat/expat/CVE-2026-56411.patch deleted file mode 100644 index 884837b61e1..00000000000 --- a/meta/recipes-core/expat/expat/CVE-2026-56411.patch +++ /dev/null @@ -1,47 +0,0 @@ -From e447d5d72884a1246894f111a5b72de4e479152e Mon Sep 17 00:00:00 2001 -From: netliomax25-code -Date: Tue, 2 Jun 2026 13:13:34 +0530 -Subject: [PATCH] xmlwf: protect notation list allocation from integer overflow - -CVE: CVE-2026-56411 -Upstream-Status: Backport [https://github.com/libexpat/libexpat/commit/528a4e5017e1bd3b48b689fd0c131df940ae3ea5] - -(cherry picked from commit 528a4e5017e1bd3b48b689fd0c131df940ae3ea5) -Signed-off-by: Deepak Rathore ---- - expat/xmlwf/xmlwf.c | 11 +++++++++-- - 1 file changed, 9 insertions(+), 2 deletions(-) - -diff --git a/expat/xmlwf/xmlwf.c b/expat/xmlwf/xmlwf.c -index 6a0a707a..a9640190 100644 ---- a/expat/xmlwf/xmlwf.c -+++ b/expat/xmlwf/xmlwf.c -@@ -383,9 +383,9 @@ static void XMLCALL - endDoctypeDecl(void *userData) { - XmlwfUserData *data = (XmlwfUserData *)userData; - NotationList **notations; -- int notationCount = 0; -+ size_t notationCount = 0; - NotationList *p; -- int i; -+ size_t i; - - /* How many notations do we have? */ - for (p = data->notationListHead; p != NULL; p = p->next) -@@ -395,6 +395,13 @@ endDoctypeDecl(void *userData) { - goto cleanUp; - } - -+ /* Detect and prevent integer overflow in the multiplication, mirroring -+ the guards in xcsdup() and resolveSystemId() */ -+ if (notationCount > SIZE_MAX / sizeof(NotationList *)) { -+ fprintf(stderr, "Unable to sort notations"); -+ goto cleanUp; -+ } -+ - notations = malloc(notationCount * sizeof(NotationList *)); - if (notations == NULL) { - fprintf(stderr, "Unable to sort notations"); --- -2.43.7 - diff --git a/meta/recipes-core/expat/expat_2.7.5.bb b/meta/recipes-core/expat/expat_2.7.5.bb deleted file mode 100644 index da35b8f9ff5..00000000000 --- a/meta/recipes-core/expat/expat_2.7.5.bb +++ /dev/null @@ -1,62 +0,0 @@ -SUMMARY = "A stream-oriented XML parser library" -DESCRIPTION = "Expat is an XML parser library written in C. It is a stream-oriented parser in which an application registers handlers for things the parser might find in the XML document (like start tags)" -HOMEPAGE = "https://github.com/libexpat/libexpat" -SECTION = "libs" -LICENSE = "MIT" - -LIC_FILES_CHKSUM = "file://COPYING;md5=f4fedd6116da0e171f7cb4d2923d7ac2" - -VERSION_TAG = "${@d.getVar('PV').replace('.', '_')}" - -SRC_URI = "${GITHUB_BASE_URI}/download/R_${VERSION_TAG}/expat-${PV}.tar.bz2 \ - file://run-ptest \ - file://CVE-2026-45186-01.patch \ - file://CVE-2026-45186-02.patch \ - file://CVE-2026-45186-03.patch \ - file://CVE-2026-45186-04.patch \ - file://CVE-2026-45186-05.patch \ - file://CVE-2026-45186-06.patch \ - file://CVE-2026-45186-07.patch \ - file://CVE-2026-41080-1.patch \ - file://CVE-2026-41080-2.patch \ - file://CVE-2026-56403_p1.patch;striplevel=2 \ - file://CVE-2026-56403_p2.patch;striplevel=2 \ - file://CVE-2026-56408.patch;striplevel=2 \ - file://CVE-2026-56404.patch;striplevel=2 \ - file://CVE-2026-56405.patch;striplevel=2 \ - file://CVE-2026-56410_p1.patch;striplevel=2 \ - file://CVE-2026-56410_p2.patch;striplevel=2 \ - file://CVE-2026-56406-dependent.patch;striplevel=2 \ - file://CVE-2026-56406.patch;striplevel=2 \ - file://CVE-2026-56409.patch;striplevel=2 \ - file://CVE-2026-56411.patch;striplevel=2 \ - file://CVE-2026-56407.patch;striplevel=2 \ - file://CVE-2026-56132_p1.patch;striplevel=2 \ - file://CVE-2026-56132_p2.patch;striplevel=2 \ - file://CVE-2026-56132_p3.patch;striplevel=2 \ - file://CVE-2026-56132_p4.patch;striplevel=2 \ - file://CVE-2026-56132_p5.patch;striplevel=2 \ - " - -GITHUB_BASE_URI = "https://github.com/libexpat/libexpat/releases/" -UPSTREAM_CHECK_REGEX = "releases/tag/R_(?P.+)" - -SRC_URI[sha256sum] = "386a423d40580f1e392e8b512b7635cac5083fe0631961e74e036b0a7a830d77" - -EXTRA_OECMAKE:class-native += "-DEXPAT_BUILD_DOCS=OFF" - -RDEPENDS:${PN}-ptest += "bash" - -inherit cmake lib_package ptest github-releases - -do_install_ptest:class-target() { - install -m 755 ${B}/tests/runtests* ${D}${PTEST_PATH} - install -m 755 ${B}/tests/benchmark/benchmark ${D}${PTEST_PATH} -} - -BBCLASSEXTEND += "native nativesdk" - -CVE_PRODUCT = "expat libexpat" - -CVE_STATUS[CVE-2026-72522] = "not-applicable-config: Needs Expat compiled with 16bit character support , Issue only affects firefox/Windows. \ -EXPAT_CHAR_TYPE:STRING=char is for Yocto builds" diff --git a/meta/recipes-core/expat/expat_2.8.3.bb b/meta/recipes-core/expat/expat_2.8.3.bb new file mode 100644 index 00000000000..79e8c15227a --- /dev/null +++ b/meta/recipes-core/expat/expat_2.8.3.bb @@ -0,0 +1,33 @@ +SUMMARY = "A stream-oriented XML parser library" +DESCRIPTION = "Expat is an XML parser library written in C. It is a stream-oriented parser in which an application registers handlers for things the parser might find in the XML document (like start tags)" +HOMEPAGE = "https://github.com/libexpat/libexpat" +SECTION = "libs" +LICENSE = "MIT" + +LIC_FILES_CHKSUM = "file://COPYING;md5=f4fedd6116da0e171f7cb4d2923d7ac2" + +VERSION_TAG = "${@d.getVar('PV').replace('.', '_')}" + +SRC_URI = "${GITHUB_BASE_URI}/download/R_${VERSION_TAG}/expat-${PV}.tar.bz2 \ + file://run-ptest \ + " + +GITHUB_BASE_URI = "https://github.com/libexpat/libexpat/releases/" +UPSTREAM_CHECK_REGEX = "releases/tag/R_(?P.+)" + +SRC_URI[sha256sum] = "b4cc2483927d5e90bf8c40b44a6b95b368b42a8a96e25883fce188b48a92b670" + +EXTRA_OECMAKE:class-native += "-DEXPAT_BUILD_DOCS=OFF" + +RDEPENDS:${PN}-ptest += "bash" + +inherit cmake lib_package ptest github-releases + +do_install_ptest:class-target() { + install -m 755 ${B}/tests/runtests* ${D}${PTEST_PATH} + install -m 755 ${B}/tests/benchmark/benchmark ${D}${PTEST_PATH} +} + +BBCLASSEXTEND += "native nativesdk" + +CVE_PRODUCT = "expat libexpat" From patchwork Thu Sep 17 22:06:36 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 98626 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 8E551C982E4 for ; Thu, 17 Sep 2026 22:08:28 +0000 (UTC) Received: from mail-wm2-f13.google.com (mail-wm2-f13.google.com [74.125.225.141]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.1595.1789682898930844096 for ; Thu, 17 Sep 2026 15:08:19 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=Tuydu5S4; spf=pass (domain: smile.fr, ip: 74.125.225.141, mailfrom: yoann.congal@smile.fr) Received: by mail-wm2-f13.google.com with SMTP id 5b1f17b1804b1-49e69b9e16aso1213985e9.1 for ; Thu, 17 Sep 2026 15:08:18 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1789682897; x=1790287697; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=486eR0RSbIvl43Gqk3wsnojPV7p+RPUqxOycUF8Ao6I=; b=Tuydu5S4ftmiRCKBJAtCDBIGeuTinEN2SxQoYHlqF31lJbzgyqbF0VbD95F/9bEY8j SMqTVScO2XkeOmTGWkRO/HAe6O08dncHW8Cg4uf0ZhlGPVMfEfR391l+9n72N5w9pfa1 cNg5Ra4DHwl+NtcWmo6rpVqPplilNzYpi2rnA= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1789682897; x=1790287697; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=486eR0RSbIvl43Gqk3wsnojPV7p+RPUqxOycUF8Ao6I=; b=yV7ZFrVEz3leo0CqEZYZFpaWVLEjuZlbW++GDce3uCtBjAF9NgcDgMSoM3zcoqHL5l kIfqb9QNsyK6t5PjZmeRx87JE+IcVmtHTjsWr8zH/9+uWaSmGKyEDYQourK8nGyHt7z+ +Vd5h7D2CKkUNM8WIK5f+d/J0Js23Is8I1SzDHlEJJLGGBDHDcy/etVCT/1U03HnQoaE RjFYxHQ4Gkn+0hB9+XoXAc89rfahdYi8eHJSJ/YDhE0ImFEez4M7PcngZlnyxhNQmYbb uaB0xzdPUE0QkG8OJVK3gDZi3f5s78KJfr+RqxaRNhkBfS54/IdbnY8e7UZYeuEw5TSY SmtQ== X-Gm-Message-State: AFuF++muKznreb7GFCN1F3ia3eJ2hXfGaJMD7ULuY+oOldGMAOtcCpyE c/hhWisnEa8CpneVOiOwbtbayMe9ycpBJAqhHfwVpV3JPADm+yjmNNixq3wyj6EBgtwbXMiAvYc gtUtEiqQ= X-Gm-Gg: AYBFou3CkZHqUQPmgKiy2KqUytHVXy777Lhd4lPzTOVVi7JV0lZNRAz4Knox4IUnhHF 9CgxTn7arRPKGYn5VHVTv32ZskB1M7IHc2nrlMz0yCBORqispGqpM3HZ5rwpTSg0EyrRCTFpL7V om8disAi9QaIBKmXDycC06np+NXpqsAV6rshH5CQvJUm8cN2a1ytB3lfB1Hs6NNX5A8/hDluOZn qM34Ou/gPGiQV7Gnwy75mQRBDTsZ1aUQpEoEPVOu6+jMn7wMCjJk7RbqD8ytC5995shDjCTJwbz /CAfprANgV+seoM3MAlRB5KX1peRb66e/sp8GE2h073wR1QuPbZUYOPuml71A8oJAtZ9XU8Q3Sa cbntk6fRMSd++Xsc8OvMgm4CnFjcdsp91ZdLvzbAwuJMefN+QI41oYhlPQ5n/oqCgaKxvN1xXEe pam/7G2IU9fQ7SzqPIFF2GTZbdQpa+CoojyznitY7bNtF3c4t6BdGymfj4bH6HigDEVnOHwEMjD r8UtYq0w0X/vvVBjThlrfDOQ/6Tmsda1DIlg36/Mox8DWfg2wI8jC7WuEpbn9oUl4ikKp6BRf4= X-Received: by 2002:a05:600c:8b61:b0:49e:69ff:c6b1 with SMTP id 5b1f17b1804b1-49fc5749edemr3654755e9.31.1789682897195; Thu, 17 Sep 2026 15:08:17 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-49fc471b9a2sm8984075e9.0.2026.09.17.15.08.16 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Thu, 17 Sep 2026 15:08:16 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][wrynose 51/79] curl: patch CVE-2026-7009 Date: Fri, 18 Sep 2026 00:06:36 +0200 Message-ID: X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Thu, 17 Sep 2026 22:08:28 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/246145 From: Peter Marko Pick patch per [1]. [1] https://curl.se/docs/CVE-2026-7009.html Signed-off-by: Peter Marko Signed-off-by: Yoann Congal --- .../curl/curl/CVE-2026-7009.patch | 50 +++++++++++++++++++ meta/recipes-support/curl/curl_8.19.0.bb | 1 + 2 files changed, 51 insertions(+) create mode 100644 meta/recipes-support/curl/curl/CVE-2026-7009.patch diff --git a/meta/recipes-support/curl/curl/CVE-2026-7009.patch b/meta/recipes-support/curl/curl/CVE-2026-7009.patch new file mode 100644 index 00000000000..ec124378eca --- /dev/null +++ b/meta/recipes-support/curl/curl/CVE-2026-7009.patch @@ -0,0 +1,50 @@ +From 51905671e07f087e28e5741063646c379fe17d89 Mon Sep 17 00:00:00 2001 +From: Stefan Eissing +Date: Sat, 25 Apr 2026 10:34:06 +0200 +Subject: [PATCH] sectrust: fail on missing OCSP stapling + +When using Apple SecTrust, requiring the server to send +an OCSP response and does not, fail correctly. + +Reported-by: Carlos Carrillo +Closes #21444 + +CVE: CVE-2026-7009 +Upstream-Status: Backport [https://github.com/curl/curl/commit/51905671e07f087e28e5741063646c379fe17d89] +Signed-off-by: Peter Marko +--- + lib/vtls/openssl.c | 12 +++++++++++- + 1 file changed, 11 insertions(+), 1 deletion(-) + +diff --git a/lib/vtls/openssl.c b/lib/vtls/openssl.c +index c84ef8bc65..4629ca4444 100644 +--- a/lib/vtls/openssl.c ++++ b/lib/vtls/openssl.c +@@ -4744,16 +4744,26 @@ static CURLcode ossl_apple_verify(struct Curl_cfilter *cf, + unsigned char *ocsp_data = NULL; + #endif + long ocsp_len = 0; ++ bool ocsp_missing = FALSE; + if(conn_config->verifystatus && !octx->reused_session) + ocsp_len = (long)SSL_get_tlsext_status_ocsp_resp(octx->ssl, &ocsp_data); + + /* SSL_get_tlsext_status_ocsp_resp() returns the length of the OCSP + response data or -1 if there is no OCSP response data. */ +- if(ocsp_len < 0) ++ if(ocsp_len < 0) { + ocsp_len = 0; /* no data available */ ++ ocsp_missing = TRUE; ++ } + result = Curl_vtls_apple_verify(cf, data, peer, chain.num_certs, + ossl_chain_get_der, &chain, + ocsp_data, ocsp_len); ++ if(!result && ocsp_missing && conn_config->verifystatus && ++ !octx->reused_session) { ++ /* verified, but OCSP stapling is required and server sent none */ ++ *pverified = TRUE; ++ failf(data, "No OCSP response received"); ++ return CURLE_SSL_INVALIDCERTSTATUS; ++ } + } + *pverified = !result; + return result; diff --git a/meta/recipes-support/curl/curl_8.19.0.bb b/meta/recipes-support/curl/curl_8.19.0.bb index a964868d872..2a27fd4d5bf 100644 --- a/meta/recipes-support/curl/curl_8.19.0.bb +++ b/meta/recipes-support/curl/curl_8.19.0.bb @@ -29,6 +29,7 @@ SRC_URI = " \ file://CVE-2026-8932.patch \ file://CVE-2026-11352.patch \ file://CVE-2026-11586.patch \ + file://CVE-2026-7009.patch \ " SRC_URI:append:class-nativesdk = " \ From patchwork Thu Sep 17 22:06:37 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 98631 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id EC01AC982E7 for ; Thu, 17 Sep 2026 22:08:28 +0000 (UTC) Received: from mail-wm2-f13.google.com (mail-wm2-f13.google.com [74.125.225.141]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.1695.1789682899349705927 for ; Thu, 17 Sep 2026 15:08:19 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=XSlQKLXU; spf=pass (domain: smile.fr, ip: 74.125.225.141, mailfrom: yoann.congal@smile.fr) Received: by mail-wm2-f13.google.com with SMTP id 5b1f17b1804b1-49b912d3931so840975e9.3 for ; Thu, 17 Sep 2026 15:08:19 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1789682898; x=1790287698; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=RTDYOGo1DFVuvQSs89yWnCEF2bGlL8qBuIFdAl57Now=; b=XSlQKLXU4ggvY04pvaEaK9rU+k7Hd7b+HTvJgUtj8rfJs5PzV9ZaL8NfmQFjnIOgUb PGZCRqsmTD3s3ugye5OaUkirTMp1kGIQiY070S8IPjFB4Jd7TQaIQjSVjcIjKGEfTmBg HwyA9jZqol7CqRU9DFd7Rm/xzfzKzsZj/I/aQ= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1789682898; x=1790287698; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=RTDYOGo1DFVuvQSs89yWnCEF2bGlL8qBuIFdAl57Now=; b=ZrXaru9pLlAfJD1Jv+ACp0aZvIwE0nq4CA8fEkMK6eH5yMhuVWH7JmxVqlGEgdOvHT OzTid4fqP5YLeTu3ypzUR55k5DXYB//pA2kt+t8hJ77mqKGMsRzqu1/HyYavjoGN9PoC ryrPCP7ctcQzKJhKPSUdWpwY9azXlael3yYAj5cNpcmispPLNZldApGuQ3dtVMu4PO+6 dWTVcOWKXSJmZtUvwzI9JKoQPQ+4+kZQI5VPuaGeptTUelVz6N+NXwXOaGB53vIxagNa c/lZoQa3VAqX3Lmv/ZAYp2UXP7pJewVxyQv59BSZ2J9DBNxMAIll/YoAEp2YPKP04bLi Ircw== X-Gm-Message-State: AFuF++n0S47HSWxcSO2FuCMChIJJJ1bYaafJ78BnAQXa2qm5eYjEZ60q cuXNESk5etgNkuuiNnFPQ6k6gyEmXWh/B+Hu+RMUEVzW2h31eqStOYyUNxOMra7Kg1Lf7nK18Ug 4QuJ/sIo= X-Gm-Gg: AYBFou0IK3qrPSz/f+xwU/JM+qGMmpqfynYlimqlb9sV3PfqbkEeZRj9T61VTabGWQo 3zrfq/vTh77EJwMQ7je8gAnkiCpG0T9Vi/9E94Y5yEZ2k5YX0sPkLcCzQcWz+oRw53d+usczO83 B+swGeFeh6+loMszSkmnD4vxsordPah4Nd90hGjxecTKx2CYJoYOpciiDaXAYlufeEjZXenoNYW E2ozGpZX8+rCTAHDUIJmq9GFBqlhUi84RDQBlWOka/8lr5lCvJ7rkVAOjLz16jRmoOEK5DaqZsv kkiR2hpC+Oa9zn6n9lGS6S+RBsC2yUPx6qvLkUrl1Z53AqaHCXlGDZxw5oUxlCDIm2Y6OYRPrpD Zk/vFA6B6jgg8kR8l4IObpfCT7/6cVAKH4/M3jm/2PLMnGtiwOix/BBjNAegIH5GQ3Jh8q0G+M9 D5E1aFLjEYIbOStFvpeNlxc+4oX4hdoc0Mk9RkdHK0kjLhWBTHsY+c4HzEir7zFrrFxaNqLX+d+ 0XchEGNrFhbKqFWhBn+jDyyeb89evME9IiGCnvqh62iUKzF3O8FyM18OusiK1h329JXRq/AzcM= X-Received: by 2002:a05:600c:4e4a:b0:49e:6e94:7cae with SMTP id 5b1f17b1804b1-49fc5741495mr2853085e9.28.1789682897627; Thu, 17 Sep 2026 15:08:17 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-49fc471b9a2sm8984075e9.0.2026.09.17.15.08.17 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Thu, 17 Sep 2026 15:08:17 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][wrynose 52/79] curl: patch CVE-2026-8925 Date: Fri, 18 Sep 2026 00:06:37 +0200 Message-ID: X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Thu, 17 Sep 2026 22:08:28 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/246146 From: Peter Marko Pick patch per [1]. [1] https://curl.se/docs/CVE-2026-8925.html Signed-off-by: Peter Marko Signed-off-by: Yoann Congal --- .../curl/curl/CVE-2026-8925.patch | 57 +++++++++++++++++++ meta/recipes-support/curl/curl_8.19.0.bb | 1 + 2 files changed, 58 insertions(+) create mode 100644 meta/recipes-support/curl/curl/CVE-2026-8925.patch diff --git a/meta/recipes-support/curl/curl/CVE-2026-8925.patch b/meta/recipes-support/curl/curl/CVE-2026-8925.patch new file mode 100644 index 00000000000..da486e6ac16 --- /dev/null +++ b/meta/recipes-support/curl/curl/CVE-2026-8925.patch @@ -0,0 +1,57 @@ +From 3da249e1f0716c06644ed3522a37a8bf81808012 Mon Sep 17 00:00:00 2001 +From: Viktor Szakats +Date: Thu, 14 May 2026 14:35:21 +0200 +Subject: [PATCH] gsasl: fix potential double free + +Also: +- require libgsasl 1.6.0+ (2010-12-14) for a `gsasl_finish()` that + handles a NULL argument. + Ref: https://gitlab.com/gsasl/gsasl/-/commit/b550032df8488a9ceaa3cfd4c634947d8f219717 + +Reported-by: Joshua Rogers (Aisle Research) + +Closes #21609 + +CVE: CVE-2026-8925 +Upstream-Status: Backport [https://github.com/curl/curl/commit/3da249e1f0716c06644ed3522a37a8bf81808012] +Signed-off-by: Peter Marko +--- + docs/INTERNALS.md | 1 + + lib/vauth/gsasl.c | 5 +++++ + 2 files changed, 6 insertions(+) + +diff --git a/docs/INTERNALS.md b/docs/INTERNALS.md +index c145690a2c..77f2e43735 100644 +--- a/docs/INTERNALS.md ++++ b/docs/INTERNALS.md +@@ -30,6 +30,7 @@ We aim to support these or later versions. + - c-ares 1.6.0 (2008-12-09) + - GnuTLS 3.6.5 (2018-12-01) + - libidn2 2.0.0 (2017-03-29) ++- libgsasl 1.6.0 (2010-12-14) + - LibreSSL 2.9.1 (2019-04-22) + - libssh 0.9.0 (2019-06-28) + - libssh2 1.9.0 (2019-06-20) +diff --git a/lib/vauth/gsasl.c b/lib/vauth/gsasl.c +index 3ea77eecd1..10a83fdb09 100644 +--- a/lib/vauth/gsasl.c ++++ b/lib/vauth/gsasl.c +@@ -32,6 +32,10 @@ + + #include + ++#if GSASL_VERSION_NUMBER < 0x010600 ++#error "requires libgsasl 1.6.0+" ++#endif ++ + bool Curl_auth_gsasl_is_supported(struct Curl_easy *data, + const char *mech, + struct gsasldata *gsasl) +@@ -47,6 +51,7 @@ bool Curl_auth_gsasl_is_supported(struct Curl_easy *data, + res = gsasl_client_start(gsasl->ctx, mech, &gsasl->client); + if(res != GSASL_OK) { + gsasl_done(gsasl->ctx); ++ gsasl->ctx = NULL; + return FALSE; + } + diff --git a/meta/recipes-support/curl/curl_8.19.0.bb b/meta/recipes-support/curl/curl_8.19.0.bb index 2a27fd4d5bf..bed11141ea6 100644 --- a/meta/recipes-support/curl/curl_8.19.0.bb +++ b/meta/recipes-support/curl/curl_8.19.0.bb @@ -30,6 +30,7 @@ SRC_URI = " \ file://CVE-2026-11352.patch \ file://CVE-2026-11586.patch \ file://CVE-2026-7009.patch \ + file://CVE-2026-8925.patch \ " SRC_URI:append:class-nativesdk = " \ From patchwork Thu Sep 17 22:06:38 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 98633 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 02ADFC982E6 for ; Thu, 17 Sep 2026 22:08:29 +0000 (UTC) Received: from mail-wm2-f13.google.com (mail-wm2-f13.google.com [74.125.225.141]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.1697.1789682899741120390 for ; Thu, 17 Sep 2026 15:08:20 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=O6Bf/LIK; spf=pass (domain: smile.fr, ip: 74.125.225.141, mailfrom: yoann.congal@smile.fr) Received: by mail-wm2-f13.google.com with SMTP id 5b1f17b1804b1-49d1fb0cf5eso868255e9.3 for ; Thu, 17 Sep 2026 15:08:19 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1789682898; x=1790287698; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=1Q3F9P0wcq/ozNBj/QUbwUt6lFl1fsGLoLnDNYX0zv4=; b=O6Bf/LIKhxKiBGfY5Pe7Bl0HiPGFln4zESOprfKno0z7uxbwGKwX/oFQXKMPfhZwZj 8kH8T1ra0rI650Pbfk1ClUe4x8y+LC41+hpZBNZrBqFIfV9DVFiuTBp9c6ztflZnYJVs ss8pUHfGmFSn4cfcUMVFF0rdnz4qV7VBVwTfw= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1789682898; x=1790287698; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=1Q3F9P0wcq/ozNBj/QUbwUt6lFl1fsGLoLnDNYX0zv4=; b=N5kfftll4p+E6siFyewwYP0Vl8B/JCK7lnH6X6DEDNQLH+Zhir+PhLUzvBzuE5ZnoD Cq0xqI22mkPQaevOd8pkER6asyiMeKnwi/onPvZdrUHkJxEuEsvqQUj1sFkhHX24ymvY +5joXLrQD5Wr+4peDDl0nO0HUs0Nta4ljlohggpQ92nvWKGEQGeB6kIxkwUFNrw6mxGH 6o2DT0ECkqFVWFOxkQPbbusXAZZq3vBkgFfoACpUUVgxODdHX4khT4PeDjsWEKoOp0qa 6OynIvXjuqwuJWOFDZvvCr4dCaspndFDErEnttoNAhbqMpdcb/jfhmRC8fTiLPdWCw8c Uruw== X-Gm-Message-State: AFuF++lI5+7NwpQtP/bbQYG34onVh47kfnn0XuT2t4Drm0p6W1Y0pVak vouE4i0a//VN+RuW71SmlFMwwW3A98cWHWKclliIN5YCLGCyxjOo6lIlB0fY/JE9EmGykF0PiaL OKdXPEDQ= X-Gm-Gg: AYBFou2LfaiboyrWCYjbn7vuseEvvfnaKmn8oyXMxDX/c7UWt8CQbFZYRTVI5trnWIk +LVoIUBhBP6sr58vLpzIIFNsbRUdaCSDyd+KUTLimILv0CTttJOOYzlsI8ZyV53B0w5BZl+GYsl yVFA3lg04hocXTrJMBKojm1pFQARnKluH3qTftPc43QGqA/SozpFSM+euI1gnw4ljS7teQeSkTY 6cH6nhpROQz42RJkdKD7LBEe3E0KJPyygSmUKArxk3gYpNP93ZQk6lxa4pN/GNsjleD8WQr2Vwi uP+wdwu49ZTiiREcj5B/WCB+iEqquLjrpKOknOlMyM2NXs9kR1tuXr3xzNkvXIEwELAv7Ndq/ys n40JWlZKOuKecSfry80IfBmUk55YegJAXUqCeRo9bR/nCigwU3qeBP5Znnv4KiTDgQ7VV/XyQC+ OmFOP06O3pZsrZFOT2cbHSq9KaAOyhrJeoDSQyOCTNgoS65YAy/FvmBqk7TJ0hHG/rYPEdPR5Js +FAfDAjbR+AUo7SzdXuHMNjNLk+R9h4iu2Ab7rVfwgRgxN8RWiAO+IuNfcXMiZqnVvGnz79LmI= X-Received: by 2002:a05:600c:3b8c:b0:49f:bd3c:bc16 with SMTP id 5b1f17b1804b1-49fc572f58fmr3849785e9.17.1789682898078; Thu, 17 Sep 2026 15:08:18 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-49fc471b9a2sm8984075e9.0.2026.09.17.15.08.17 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Thu, 17 Sep 2026 15:08:17 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][wrynose 53/79] curl: patch CVE-2026-9080 Date: Fri, 18 Sep 2026 00:06:38 +0200 Message-ID: <3c1af6137fa043ad97c7092926006673793a4ca5.1789681419.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Thu, 17 Sep 2026 22:08:29 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/246147 From: Peter Marko Pick patch per [1]. [1] https://curl.se/docs/CVE-2026-9080.html Signed-off-by: Peter Marko Signed-off-by: Yoann Congal --- .../curl/curl/CVE-2026-9080.patch | 95 +++++++++++++++++++ meta/recipes-support/curl/curl_8.19.0.bb | 1 + 2 files changed, 96 insertions(+) create mode 100644 meta/recipes-support/curl/curl/CVE-2026-9080.patch diff --git a/meta/recipes-support/curl/curl/CVE-2026-9080.patch b/meta/recipes-support/curl/curl/CVE-2026-9080.patch new file mode 100644 index 00000000000..b1cf613f8a5 --- /dev/null +++ b/meta/recipes-support/curl/curl/CVE-2026-9080.patch @@ -0,0 +1,95 @@ +From 5ab34cba42e4ee4282fe8bab43f311d51b9bf9bd Mon Sep 17 00:00:00 2001 +From: Daniel Stenberg +Date: Tue, 26 May 2026 09:52:19 +0200 +Subject: [PATCH] multi: handle pause in multi socket callback + +The mev_sh_entry object might be removed if curl_easy_pause() is called +from within the socket callback. + +Introduced a 'magic' struct field to to 'mev_sh_entry' to make it easier +to programmatically detect/assert if the pointer is bad - in debug +builds. + +Reported-by: Joshua Rogers +Closes #21748 + +CVE: CVE-2026-9080 +Upstream-Status: Backport [https://github.com/curl/curl/commit/5ab34cba42e4ee4282fe8bab43f311d51b9bf9bd] +Signed-off-by: Peter Marko +--- + lib/multi_ev.c | 23 ++++++++++++++++++++--- + 1 file changed, 20 insertions(+), 3 deletions(-) + +diff --git a/lib/multi_ev.c b/lib/multi_ev.c +index 478d5a48d5..7ea3b2827e 100644 +--- a/lib/multi_ev.c ++++ b/lib/multi_ev.c +@@ -40,6 +40,8 @@ static void mev_in_callback(struct Curl_multi *multi, bool value) + multi->in_callback = value; + } + ++#define SH_ENTRY_MAGIC 0x570091d ++ + /* Information about a socket for which we inform the libcurl application + * what to supervise (CURL_POLL_IN/CURL_POLL_OUT/CURL_POLL_REMOVE) + */ +@@ -51,6 +53,9 @@ struct mev_sh_entry { + * libcurl application to watch out for */ + unsigned int readers; /* this many transfers want to read */ + unsigned int writers; /* this many transfers want to write */ ++#ifdef DEBUGBUILD ++ unsigned int magic; ++#endif + BIT(announced); /* this socket has been passed to the socket + callback at least once */ + }; +@@ -75,6 +80,9 @@ static void mev_sh_entry_dtor(void *freethis) + { + struct mev_sh_entry *entry = (struct mev_sh_entry *)freethis; + Curl_uint32_spbset_destroy(&entry->xfers); ++#ifdef DEBUGBUILD ++ entry->magic = 0; ++#endif + curlx_free(entry); + } + +@@ -113,7 +121,9 @@ static struct mev_sh_entry *mev_sh_entry_add(struct Curl_hash *sh, + mev_sh_entry_dtor(check); + return NULL; /* major failure */ + } +- ++#ifdef DEBUGBUILD ++ check->magic = SH_ENTRY_MAGIC; ++#endif + return check; /* things are good in sockhash land */ + } + +@@ -223,6 +233,7 @@ static CURLMcode mev_sh_entry_update(struct Curl_multi *multi, + + /* we should only be called when the callback exists */ + DEBUGASSERT(multi->socket_cb); ++ DEBUGASSERT(entry->magic == SH_ENTRY_MAGIC); + if(!multi->socket_cb) + return CURLM_OK; + +@@ -272,12 +283,18 @@ static CURLMcode mev_sh_entry_update(struct Curl_multi *multi, + rc = multi->socket_cb(data, s, comboaction, multi->socket_userp, + entry->user_data); + mev_in_callback(multi, FALSE); +- entry->announced = TRUE; + if(rc == -1) { + multi->dead = TRUE; + return CURLM_ABORTED_BY_CALLBACK; + } +- entry->action = (unsigned int)comboaction; ++ /* curl_easy_pause() is documented as callable from any callback; it ++ * re-enters mev_assess() which may free this 'entry'. Re-fetch. */ ++ entry = mev_sh_entry_get(&multi->ev.sh_entries, s); ++ if(entry) { ++ DEBUGASSERT(entry->magic == SH_ENTRY_MAGIC); ++ entry->announced = TRUE; ++ entry->action = (unsigned int)comboaction; ++ } + return CURLM_OK; + } + diff --git a/meta/recipes-support/curl/curl_8.19.0.bb b/meta/recipes-support/curl/curl_8.19.0.bb index bed11141ea6..4f28b63a746 100644 --- a/meta/recipes-support/curl/curl_8.19.0.bb +++ b/meta/recipes-support/curl/curl_8.19.0.bb @@ -31,6 +31,7 @@ SRC_URI = " \ file://CVE-2026-11586.patch \ file://CVE-2026-7009.patch \ file://CVE-2026-8925.patch \ + file://CVE-2026-9080.patch \ " SRC_URI:append:class-nativesdk = " \ From patchwork Thu Sep 17 22:06:39 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 98624 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 3189CC982DC for ; Thu, 17 Sep 2026 22:08:28 +0000 (UTC) Received: from mail-wm2-f12.google.com (mail-wm2-f12.google.com [74.125.225.140]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.1699.1789682900335825205 for ; Thu, 17 Sep 2026 15:08:20 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=mDPAVWhp; spf=pass (domain: smile.fr, ip: 74.125.225.140, mailfrom: yoann.congal@smile.fr) Received: by mail-wm2-f12.google.com with SMTP id 5b1f17b1804b1-49b912e4b11so541985e9.3 for ; Thu, 17 Sep 2026 15:08:20 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1789682899; x=1790287699; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=7HQ3NbKdyxyer5ZP0mDlp7aQgKZf68WgcCmQEi49HhU=; b=mDPAVWhptH5vRbDd0BbwVV94nCEQEBAT5vItBVEuG37W+UrQEkeeLlP7C9bUCdw2oN Wq3ouc5CPi+3YZvLQz1EWCMjfSVxGHEOUO+QidMlzsuxhhG8vVVJRjq2/xtxs/7TCdcL xXuRScS27iB2CzmA4Ixo3bYh0Ej73uiEEW8/I= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1789682899; x=1790287699; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=7HQ3NbKdyxyer5ZP0mDlp7aQgKZf68WgcCmQEi49HhU=; b=Cc0I7dJiyg9gJ4x0dvjRk0HIdWR/0cm2V4T7icXq18GRNZSGA/CYYGcvQqgX6zgR4k jmsTEXk16eX+0HQRFU0EqLYVbrwJWwCiTV5uL46io8OaW9ECDRBCPh+JOcmA/2N/0IAk oITrkfA4bLsH+BWGSaNdPTbkmVrxt9xzQk0zYDsuQSLG+lR1vpQM89TXQF9ZhaQm+Ty+ qnBMeD5yWS/QUoY9Jro5QpAw0RHBsPyAGGboniax/BBWTd0kyVgFzYayDGBj5uw4qmA9 xmC4682/2R9MRCuF/BOsQj7kZDmlw9hG9+cSq4j/2SddpBbTY2UvqjzoC+QIBy87dYDZ AYYw== X-Gm-Message-State: AFuF++nqTNPy9SM9H8PEZRIiIXdBkXFctHvy+H4AvkFrNs4a9qYYeE4h 9LgSZhUY7lgb+Ei0jINhexZmOO5ZrJRfMXv2Dr9gCpUUVcY/Luyt7Q3bgd073YMvL7iX5bYRF4h zvQbxiHs= X-Gm-Gg: AYBFou0yX55sa52jwxxXsxBDcqzq22kuGPdUdkS/76wrZvSgX0AWBy+DWwOBHMcks+X wYMfgPJQKTThDPnvsG6mvLi8A4SNkQhCPfouv2ELTp2J/O5kheqvdal1OkCS/lXte7zFjiAwW1V Pjx3K8hxzQfwcOOti6OfqORdY/WxO7pXTzCChX1erIt7og4sjq2SQB4IUf6rq52iquwA+Riv4dI JE8uzeriGu8y/ld9RN0h3+JNsyJyG1Ylb1qaDMWKzrXujFJKOujMHSPf1wX4jLEjwNMcD+NIYmb h/pnABKZY5EN1+3AtFWx/KFVNey4vJCOI/R681qCR3SUowiswDyYwfSIFp/D9YpFeJwvsOgJPMA jSCnhPFlibufsTxb99zatIsxgmfv4ked6pm+6UC2T7AhtF9hW6TqtXbWUJW3p3tFBqLSA1pjLnp PvDbPLAZcOCJCxlG7BvpWurrbAM1BhtNlKpY/4QBBdnWw1VzsJVuZ7IUpcOG9ek3cPJ6603dAwc XOoqOHoefVPsTaHf/PereAJ5DQGaqGx5k8u/uqDsDPwfUBKz9QynxFIgwdtK9rte/eRSyENGwMV 6ec7dpQI+A== X-Received: by 2002:a05:600c:1c01:b0:49c:fc6e:a3d7 with SMTP id 5b1f17b1804b1-49fc5753eb2mr3757075e9.22.1789682898519; Thu, 17 Sep 2026 15:08:18 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-49fc471b9a2sm8984075e9.0.2026.09.17.15.08.18 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Thu, 17 Sep 2026 15:08:18 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][wrynose 54/79] curl: patch CVE-2026-9545 Date: Fri, 18 Sep 2026 00:06:39 +0200 Message-ID: <5afccc91ad2a4db1428241fa848bcbb471853b75.1789681419.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Thu, 17 Sep 2026 22:08:28 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/246149 From: Peter Marko Pick patch per [1]. Also pick additional patch for a clean cherry-pick. [1] https://curl.se/docs/CVE-2026-9545.html Signed-off-by: Peter Marko Signed-off-by: Yoann Congal --- .../curl/curl/CVE-2026-9545-01.patch | 157 ++++++++++++++++++ .../curl/curl/CVE-2026-9545-02.patch | 67 ++++++++ meta/recipes-support/curl/curl_8.19.0.bb | 2 + 3 files changed, 226 insertions(+) create mode 100644 meta/recipes-support/curl/curl/CVE-2026-9545-01.patch create mode 100644 meta/recipes-support/curl/curl/CVE-2026-9545-02.patch diff --git a/meta/recipes-support/curl/curl/CVE-2026-9545-01.patch b/meta/recipes-support/curl/curl/CVE-2026-9545-01.patch new file mode 100644 index 00000000000..5325c51e5e7 --- /dev/null +++ b/meta/recipes-support/curl/curl/CVE-2026-9545-01.patch @@ -0,0 +1,157 @@ +From 41aaac61e215a827619b896d5b8588200cfdae28 Mon Sep 17 00:00:00 2001 +From: Stefan Eissing +Date: Wed, 18 Mar 2026 11:37:18 +0100 +Subject: [PATCH] lib: always use Curl_1st_fatal instead of Curl_1st_err + +Curl_1st_err() does not return the second error if the first result is +CURLE_AGAIN. This may cause errors to not become noticeable when they +should be. + +Replace all use of Curl_1st_err() with Curl_1st_fatal(), which handles +CURLE_AGAIN as a not-a-real-error case. + +Closes #20980 + +CVE: CVE-2026-9545 +Upstream-Status: Backport [https://github.com/curl/curl/commit/41aaac61e215a827619b896d5b8588200cfdae28] +Signed-off-by: Peter Marko +--- + lib/easy.c | 6 ++++-- + lib/http.c | 2 +- + lib/multi.c | 2 +- + lib/url.c | 5 ----- + lib/url.h | 7 ------- + lib/vquic/curl_ngtcp2.c | 6 +++--- + lib/vquic/curl_quiche.c | 4 ++-- + 7 files changed, 11 insertions(+), 21 deletions(-) + +diff --git a/lib/easy.c b/lib/easy.c +index 2c653b00e9..5a5dac4f56 100644 +--- a/lib/easy.c ++++ b/lib/easy.c +@@ -1157,12 +1157,14 @@ CURLcode curl_easy_pause(CURL *d, int action) + if((send_paused != send_paused_new) || + (send_paused_new != Curl_creader_is_paused(data))) { + changed = TRUE; +- result = Curl_1st_err(result, Curl_xfer_pause_send(data, send_paused_new)); ++ result = Curl_1st_fatal( ++ result, Curl_xfer_pause_send(data, send_paused_new)); + } + + if(recv_paused != recv_paused_new) { + changed = TRUE; +- result = Curl_1st_err(result, Curl_xfer_pause_recv(data, recv_paused_new)); ++ result = Curl_1st_fatal( ++ result, Curl_xfer_pause_recv(data, recv_paused_new)); + } + + /* If not completely pausing both directions now, run again in any case. */ +diff --git a/lib/http.c b/lib/http.c +index aa34b5d14f..96e7b0de0c 100644 +--- a/lib/http.c ++++ b/lib/http.c +@@ -4135,7 +4135,7 @@ static CURLcode http_on_response(struct Curl_easy *data, + out: + if(last_hd) { + /* if not written yet, write it now */ +- result = Curl_1st_err( ++ result = Curl_1st_fatal( + result, http_write_header(data, last_hd, last_hd_len)); + } + if(conn_changed) { +diff --git a/lib/multi.c b/lib/multi.c +index 482c160fde..685bb01f0c 100644 +--- a/lib/multi.c ++++ b/lib/multi.c +@@ -718,7 +718,7 @@ static CURLcode multi_done(struct Curl_easy *data, + } + + /* Make sure that transfer client writes are really done now. */ +- result = Curl_1st_err(result, Curl_xfer_write_done(data, premature)); ++ result = Curl_1st_fatal(result, Curl_xfer_write_done(data, premature)); + + /* Inform connection filters that this transfer is done */ + Curl_conn_ev_data_done(data, premature); +diff --git a/lib/url.c b/lib/url.c +index a9ef60709a..cd06d6c626 100644 +--- a/lib/url.c ++++ b/lib/url.c +@@ -3875,11 +3875,6 @@ void *Curl_conn_meta_get(struct connectdata *conn, const char *key) + return Curl_hash_pick(&conn->meta_hash, CURL_UNCONST(key), strlen(key) + 1); + } + +-CURLcode Curl_1st_err(CURLcode r1, CURLcode r2) +-{ +- return r1 ? r1 : r2; +-} +- + CURLcode Curl_1st_fatal(CURLcode r1, CURLcode r2) + { + if(r1 && (r1 != CURLE_AGAIN)) +diff --git a/lib/url.h b/lib/url.h +index 09bc33390f..0afa7eb26e 100644 +--- a/lib/url.h ++++ b/lib/url.h +@@ -92,16 +92,9 @@ bool Curl_conn_seems_dead(struct connectdata *conn, + CURLcode Curl_conn_upkeep(struct Curl_easy *data, + struct connectdata *conn); + +-/** +- * Always eval all arguments, return the first result != CURLE_OK. +- * A non-short-circuit evaluation. +- */ +-CURLcode Curl_1st_err(CURLcode r1, CURLcode r2); +- + /** + * Always eval all arguments, return the first + * result != (CURLE_OK|CURLE_AGAIN) or `r1`. +- * A non-short-circuit evaluation. + */ + CURLcode Curl_1st_fatal(CURLcode r1, CURLcode r2); + +diff --git a/lib/vquic/curl_ngtcp2.c b/lib/vquic/curl_ngtcp2.c +index ea79eaf747..04f660ac63 100644 +--- a/lib/vquic/curl_ngtcp2.c ++++ b/lib/vquic/curl_ngtcp2.c +@@ -1461,8 +1461,8 @@ static CURLcode cf_ngtcp2_recv(struct Curl_cfilter *cf, struct Curl_easy *data, + result = CURLE_AGAIN; + + out: +- result = Curl_1st_err(result, cf_progress_egress(cf, data, &pktx)); +- result = Curl_1st_err(result, check_and_set_expiry(cf, data, &pktx)); ++ result = Curl_1st_fatal(result, cf_progress_egress(cf, data, &pktx)); ++ result = Curl_1st_fatal(result, check_and_set_expiry(cf, data, &pktx)); + denied: + CURL_TRC_CF(data, cf, "[%" PRId64 "] cf_recv(blen=%zu) -> %d, %zu", + stream ? stream->id : -1, blen, result, *pnread); +@@ -1788,7 +1788,7 @@ static CURLcode cf_ngtcp2_send(struct Curl_cfilter *cf, struct Curl_easy *data, + result = cf_progress_egress(cf, data, &pktx); + + out: +- result = Curl_1st_err(result, check_and_set_expiry(cf, data, &pktx)); ++ result = Curl_1st_fatal(result, check_and_set_expiry(cf, data, &pktx)); + denied: + CURL_TRC_CF(data, cf, "[%" PRId64 "] cf_send(len=%zu) -> %d, %zu", + stream ? stream->id : -1, len, result, *pnwritten); +diff --git a/lib/vquic/curl_quiche.c b/lib/vquic/curl_quiche.c +index a9a5ae6b99..4e8788aa1e 100644 +--- a/lib/vquic/curl_quiche.c ++++ b/lib/vquic/curl_quiche.c +@@ -918,7 +918,7 @@ static CURLcode cf_quiche_recv(struct Curl_cfilter *cf, struct Curl_easy *data, + result = CURLE_AGAIN; + + out: +- result = Curl_1st_err(result, cf_flush_egress(cf, data)); ++ result = Curl_1st_fatal(result, cf_flush_egress(cf, data)); + if(*pnread > 0) + ctx->data_recvd += *pnread; + CURL_TRC_CF(data, cf, "[%" PRIu64 "] cf_recv(len=%zu) -> %d, %zu, total=%" +@@ -1144,7 +1144,7 @@ static CURLcode cf_quiche_send(struct Curl_cfilter *cf, struct Curl_easy *data, + } + + out: +- result = Curl_1st_err(result, cf_flush_egress(cf, data)); ++ result = Curl_1st_fatal(result, cf_flush_egress(cf, data)); + + CURL_TRC_CF(data, cf, "[%" PRIu64 "] cf_send(len=%zu) -> %d, %zu", + stream ? stream->id : (uint64_t)~0, len, diff --git a/meta/recipes-support/curl/curl/CVE-2026-9545-02.patch b/meta/recipes-support/curl/curl/CVE-2026-9545-02.patch new file mode 100644 index 00000000000..4fc60eb5c9a --- /dev/null +++ b/meta/recipes-support/curl/curl/CVE-2026-9545-02.patch @@ -0,0 +1,67 @@ +From 7b9613fa9b1a5e04301a3920eef58e8138dad05e Mon Sep 17 00:00:00 2001 +From: Stefan Eissing +Date: Thu, 21 May 2026 14:21:59 +0200 +Subject: [PATCH] ngtcp2: fail handshake directly + +When certificate verification fails, error out of the handshake +callback, forcing ngtcp2 to stop processing the connection any further. + +Closes #21712 + +CVE: CVE-2026-9545 +Upstream-Status: Backport [https://github.com/curl/curl/commit/7b9613fa9b1a5e04301a3920eef58e8138dad05e] +Signed-off-by: Peter Marko +--- + lib/vquic/curl_ngtcp2.c | 11 ++++++++++- + 1 file changed, 10 insertions(+), 1 deletion(-) + +diff --git a/lib/vquic/curl_ngtcp2.c b/lib/vquic/curl_ngtcp2.c +index 4d27ebc0c1..fb7fd61889 100644 +--- a/lib/vquic/curl_ngtcp2.c ++++ b/lib/vquic/curl_ngtcp2.c +@@ -504,7 +504,7 @@ static int cf_ngtcp2_handshake_completed(ngtcp2_conn *tconn, void *user_data) + data = CF_DATA_CURRENT(cf); + DEBUGASSERT(data); + if(!ctx || !data) +- return NGHTTP3_ERR_CALLBACK_FAILURE; ++ return NGTCP2_ERR_CALLBACK_FAILURE; + + ctx->handshake_at = *Curl_pgrs_now(data); + ctx->tls_handshake_complete = TRUE; +@@ -512,6 +512,9 @@ static int cf_ngtcp2_handshake_completed(ngtcp2_conn *tconn, void *user_data) + + ctx->tls_vrfy_result = Curl_vquic_tls_verify_peer(&ctx->tls, cf, + data, &ctx->peer); ++ if(ctx->tls_vrfy_result) ++ return NGTCP2_ERR_CALLBACK_FAILURE; ++ + #ifdef CURLVERBOSE + if(Curl_trc_is_verbose(data)) { + const ngtcp2_transport_params *rp; +@@ -1463,6 +1466,8 @@ static CURLcode cf_ngtcp2_recv(struct Curl_cfilter *cf, struct Curl_easy *data, + out: + result = Curl_1st_fatal(result, cf_progress_egress(cf, data, &pktx)); + result = Curl_1st_fatal(result, check_and_set_expiry(cf, data, &pktx)); ++ if(ctx->tls_vrfy_result) ++ result = ctx->tls_vrfy_result; + denied: + CURL_TRC_CF(data, cf, "[%" PRId64 "] cf_recv(blen=%zu) -> %d, %zu", + stream ? stream->id : -1, blen, result, *pnread); +@@ -1789,6 +1794,8 @@ static CURLcode cf_ngtcp2_send(struct Curl_cfilter *cf, struct Curl_easy *data, + + out: + result = Curl_1st_fatal(result, check_and_set_expiry(cf, data, &pktx)); ++ if(ctx->tls_vrfy_result) ++ result = ctx->tls_vrfy_result; + denied: + CURL_TRC_CF(data, cf, "[%" PRId64 "] cf_send(len=%zu) -> %d, %zu", + stream ? stream->id : -1, len, result, *pnwritten); +@@ -2717,6 +2724,8 @@ static CURLcode cf_ngtcp2_connect(struct Curl_cfilter *cf, + } + + out: ++ if(ctx->tls_vrfy_result) ++ result = ctx->tls_vrfy_result; + if(ctx->qconn && + ((result == CURLE_RECV_ERROR) || (result == CURLE_SEND_ERROR)) && + ngtcp2_conn_in_draining_period(ctx->qconn)) { diff --git a/meta/recipes-support/curl/curl_8.19.0.bb b/meta/recipes-support/curl/curl_8.19.0.bb index 4f28b63a746..3695f8d083d 100644 --- a/meta/recipes-support/curl/curl_8.19.0.bb +++ b/meta/recipes-support/curl/curl_8.19.0.bb @@ -32,6 +32,8 @@ SRC_URI = " \ file://CVE-2026-7009.patch \ file://CVE-2026-8925.patch \ file://CVE-2026-9080.patch \ + file://CVE-2026-9545-01.patch \ + file://CVE-2026-9545-02.patch \ " SRC_URI:append:class-nativesdk = " \ From patchwork Thu Sep 17 22:06:40 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 98625 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 6361EC982E0 for ; Thu, 17 Sep 2026 22:08:28 +0000 (UTC) Received: from mail-wm2-f12.google.com (mail-wm2-f12.google.com [74.125.225.140]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.1700.1789682900920910886 for ; Thu, 17 Sep 2026 15:08:21 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=pOHuM5LE; spf=pass (domain: smile.fr, ip: 74.125.225.140, mailfrom: yoann.congal@smile.fr) Received: by mail-wm2-f12.google.com with SMTP id 5b1f17b1804b1-49e69b9e16aso1214195e9.1 for ; Thu, 17 Sep 2026 15:08:20 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1789682899; x=1790287699; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=IA6eCpEg/XTLjXbJSZPZ5WHJjdd31tOSTAGEPCGj8Fc=; b=pOHuM5LEDhOlreV3yB3Q2K8qoyjB0Zquh6BQ7/QZbQjPRFh4qfYmI+O5WJbMS0Plvs kBDyFgbgK08+SWyNAURIkXHVo9j0Uuij6v1HqmtS4bHw/64QEOVU1NKBOcTzd+y5/kii ohcOwNOxjnuto5azaJAdH2GJELH9Gudf1ivW8= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1789682899; x=1790287699; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=IA6eCpEg/XTLjXbJSZPZ5WHJjdd31tOSTAGEPCGj8Fc=; b=jaYfDuKXdkSt1JuidA3S73V0w3WeXk6e1ZUSwCgeUDyCsLTnn4AMGgTSQCtg4vHgMf N3PD1Op7ciExsOAOJHXn7cafMqs/A26ZA4INIgZnr5IH8TIeNjQoxF9UKuAfdcuc/vgt uIhNsqPv9I0ZfFzRuj9dbWa9LZolZ82kGtXHZKRFSsP6Qpi+MXMy2lA0dI9b0pYt49Qy FhV95Ar8ZZXLEyztgoSOdnCzoa3iIVohyc+z/fMng1hFyOR7XIMt1lcwW/955veDX75D GQ1iYDaJoNt18lEzaAXKkkg1pKYijhc/aKjbcw6RIOf3N2+T1W9U/8BQXRNHFx9+CF14 jcoQ== X-Gm-Message-State: AFuF++m1bt83buDqB+g9WN3WzekiRUztShmypyAot4UI+4T8wizgta86 8/2OyjHrnwqaw6b05BRqTFbflkQOBJy54QPvu7YVepeJ2CYRfl2MZvayfh7nIIvVYIO2kmVXIjY EAL8Uc/U= X-Gm-Gg: AYBFou2Mu/e68m4ytwal3mAhCxuSYUXCGq4ay1+czh76ag1uC988Ymfx1gf3CgebSDX w/MKbPaNTfD7BcN71xIFuZ+GUaWdpe2AW6Z+tJv2qxpMkfql0W1yXRqKrvUS49Hhl6mqbpSbCpM LJLqh08hHME8Oly7wRYhwOD+FURKLzA8t6tlYg4EIEPHFbkfsaUEW/SvyGiJHP/qemDmVUox5SU Xe7xvPM4yhPOAuYgk6hjopF3ynx3jFkIxKUxODq1IIugk0m2oV0nInkUv7BsfKfo2w8HYwbJqlv J1PjkvyVv5bSShlabs8KksZpuZu6MwayCl2CKWkWDeXik+443EC2jDfo4xBjVYM6YKz7f6JrlQ2 qsNvsJg7pIWQtZ2ULB0PZRS0+vP7mI5B5b0bfDlZ6bkI34tvEuPKbjEdsZRNtxEBvaBbtCewSGp kPI/2u2X5Mz51D4M5ckiAwa52MQlZES75YoJAN8+7z29dFOzs+xkLcMbJgAs73YWNR8CfXrNyTb lNiuPbwwQM52uIk5FBb4NPO5F3D5mPZPaXHISYkHzOlLEEBPPPIox1U4S62nHZAglRUCOJNhDo= X-Received: by 2002:a05:600d:848f:10b0:49d:827:e5b6 with SMTP id 5b1f17b1804b1-49fc5735351mr2161675e9.20.1789682898987; Thu, 17 Sep 2026 15:08:18 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-49fc471b9a2sm8984075e9.0.2026.09.17.15.08.18 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Thu, 17 Sep 2026 15:08:18 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][wrynose 55/79] curl: Fix for CVE-2026-9079 Date: Fri, 18 Sep 2026 00:06:40 +0200 Message-ID: <8837882db6db82cbfb7924973012c50cadc7daf5.1789681419.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Thu, 17 Sep 2026 22:08:28 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/246150 From: Bhavesh R Maheshwari Pick patch from [1] mentioned in [2] taken from NVD report in [3]. [1] https://github.com/curl/curl/commit/88c7e16cceec816a2df45c89 [2] https://curl.se/docs/CVE-2026-9079.html [3] https://nvd.nist.gov/vuln/detail/CVE-2026-9079 Signed-off-by: Bhavesh R Maheshwari Signed-off-by: Yoann Congal --- .../curl/curl/CVE-2026-9079.patch | 289 ++++++++++++++++++ meta/recipes-support/curl/curl_8.19.0.bb | 1 + 2 files changed, 290 insertions(+) create mode 100644 meta/recipes-support/curl/curl/CVE-2026-9079.patch diff --git a/meta/recipes-support/curl/curl/CVE-2026-9079.patch b/meta/recipes-support/curl/curl/CVE-2026-9079.patch new file mode 100644 index 00000000000..c62914d586b --- /dev/null +++ b/meta/recipes-support/curl/curl/CVE-2026-9079.patch @@ -0,0 +1,289 @@ +From a9140d59cfb67394656d400e0f5f511d3b312b09 Mon Sep 17 00:00:00 2001 +From: Daniel Stenberg +Date: Wed, 20 May 2026 13:39:25 +0200 +Subject: [PATCH] setopt: clear proxy auth properly on NULL + +Verify NULLed proxy credentials with test1648 + +Closes #21696 + +CVE: CVE-2026-9079 +Upstream-Status: Backport [https://github.com/curl/curl/commit/88c7e16cceec816a2df45c89] + +Signed-off-by: Bhavesh R Maheshwari +--- + lib/setopt.c | 12 ++-- + tests/data/Makefile.am | 2 +- + tests/data/test1648 | 63 +++++++++++++++++ + tests/libtest/Makefile.inc | 2 +- + tests/libtest/lib1648.c | 135 +++++++++++++++++++++++++++++++++++++ + 5 files changed, 206 insertions(+), 8 deletions(-) + create mode 100644 tests/data/test1648 + create mode 100644 tests/libtest/lib1648.c + +diff --git a/lib/setopt.c b/lib/setopt.c +index a7f8a7071f..02e9a23094 100644 +--- a/lib/setopt.c ++++ b/lib/setopt.c +@@ -1694,16 +1694,16 @@ static CURLcode setopt_cptr_proxy(struct Curl_easy *data, CURLoption option, + result = setstropt_userpwd(ptr, &u, &p); + + /* URL decode the components */ +- if(!result && u) { ++ if(!result) { + Curl_safefree(s->str[STRING_PROXYUSERNAME]); +- result = Curl_urldecode(u, 0, &s->str[STRING_PROXYUSERNAME], NULL, +- REJECT_ZERO); +- } +- if(!result && p) { + Curl_safefree(s->str[STRING_PROXYPASSWORD]); ++ if(u) ++ result = Curl_urldecode(u, 0, &s->str[STRING_PROXYUSERNAME], NULL, ++ REJECT_ZERO); ++ } ++ if(!result && p) + result = Curl_urldecode(p, 0, &s->str[STRING_PROXYPASSWORD], NULL, + REJECT_ZERO); +- } + curlx_free(u); + curlx_free(p); + break; +diff --git a/tests/data/Makefile.am b/tests/data/Makefile.am +index f9d20a9cc8..2c74a975df 100644 +--- a/tests/data/Makefile.am ++++ b/tests/data/Makefile.am +@@ -218,7 +218,7 @@ test1620 test1621 test1622 test1623 test1624 \ + \ + test1630 test1631 test1632 test1633 test1634 test1635 test1636 test1637 \ + \ +-test1640 test1641 test1642 test1643 test1647 \ ++test1640 test1641 test1642 test1643 test1647 test1648 \ + \ + test1650 test1651 test1652 test1653 test1654 test1655 test1656 test1657 \ + test1658 \ +diff --git a/tests/data/test1648 b/tests/data/test1648 +new file mode 100644 +index 0000000000..623f3c9a81 +--- /dev/null ++++ b/tests/data/test1648 +@@ -0,0 +1,63 @@ ++ ++ ++ ++ ++HTTP ++HTTP GET ++HTTP proxy ++HTTP proxy auth ++ ++ ++ ++# Server-side ++ ++ ++# this is returned first since we get no proxy-auth ++ ++HTTP/1.1 407 Authorization Required to proxy me my dear ++Proxy-Authenticate: Digest realm="weirdorealm", nonce="12345" ++Content-Length: 33 ++ ++And you should ignore this data. ++ ++ ++ ++ ++# Client-side ++ ++ ++http ++ ++# tool is what to use instead of 'curl' ++ ++lib%TESTNUMBER ++ ++ ++proxy ++ ++ ++HTTP proxy with auth, change proxy, clear auth ++ ++ ++%HOSTIP %HTTPPORT ++ ++ ++ ++# Verify data after the test has been "shot" ++ ++ ++GET http://example.com/ HTTP/1.1 ++Host: example.com ++Proxy-Authorization: Basic %b64[victim:secret]b64% ++Accept: */* ++Proxy-Connection: Keep-Alive ++ ++GET http://example.com/ HTTP/1.1 ++Host: example.com ++Accept: */* ++Proxy-Connection: Keep-Alive ++ ++ ++ ++ ++ +diff --git a/tests/libtest/Makefile.inc b/tests/libtest/Makefile.inc +index e938b87bc5..0803825e45 100644 +--- a/tests/libtest/Makefile.inc ++++ b/tests/libtest/Makefile.inc +@@ -100,7 +100,7 @@ TESTS_C = \ + lib1582.c lib1588.c \ + lib1591.c lib1592.c lib1593.c lib1594.c lib1597.c \ + lib1598.c lib1599.c \ +- lib1647.c \ ++ lib1647.c lib1648.c \ + lib1662.c \ + lib1900.c lib1901.c lib1902.c lib1903.c lib1905.c lib1906.c lib1907.c \ + lib1908.c lib1910.c lib1911.c lib1912.c lib1913.c \ +diff --git a/tests/libtest/lib1648.c b/tests/libtest/lib1648.c +new file mode 100644 +index 0000000000..e97b2bdc88 +--- /dev/null ++++ b/tests/libtest/lib1648.c +@@ -0,0 +1,135 @@ ++/*************************************************************************** ++ * _ _ ____ _ ++ * Project ___| | | | _ \| | ++ * / __| | | | |_) | | ++ * | (__| |_| | _ <| |___ ++ * \___|\___/|_| \_\_____| ++ * ++ * Copyright (C) Daniel Stenberg, , et al. ++ * ++ * This software is licensed as described in the file COPYING, which ++ * you should have received as part of this distribution. The terms ++ * are also available at https://curl.se/docs/copyright.html. ++ * ++ * You may opt to use, copy, modify, merge, publish, distribute and/or sell ++ * copies of the Software, and permit persons to whom the Software is ++ * furnished to do so, under the terms of the COPYING file. ++ * ++ * This software is distributed on an "AS IS" basis, WITHOUT WARRANTY OF ANY ++ * KIND, either express or implied. ++ * ++ * SPDX-License-Identifier: curl ++ * ++ ***************************************************************************/ ++/* ++ * URL = host ++ * arg2 = port ++ */ ++ ++#include "first.h" ++ ++/* this is meant to pick up the proxy from the environment variable */ ++static CURLcode init1648(CURL *curl, const char *url, const char *proxy) ++{ ++ CURLcode result = CURLE_OK; ++ ++ res_easy_setopt(curl, CURLOPT_URL, url); ++ if(result) ++ goto init_failed; ++ ++ res_easy_setopt(curl, CURLOPT_PROXY, proxy); ++ if(result) ++ goto init_failed; ++ ++ res_easy_setopt(curl, CURLOPT_VERBOSE, 1L); ++ if(result) ++ goto init_failed; ++ ++ return CURLE_OK; /* success */ ++ ++init_failed: ++ return result; /* failure */ ++} ++ ++static CURLcode run1648(CURL *curl, const char *url, const char *userpwd) ++{ ++ CURLcode result = CURLE_OK; ++ ++ result = init1648(curl, url, userpwd); ++ if(result) ++ return result; ++ ++ return curl_easy_perform(curl); ++} ++ ++#define GET_THIS "http://example.com/" ++ ++/* ++ * First get the URL over 'firstproxy' with auth. ++ * Then clear the auth and get the URL again over 'secondproxy'. ++ */ ++static CURLcode test_lib1648(const char *hostip) ++{ ++ CURLcode result = CURLE_OK; ++ CURL *curl = NULL; ++ struct curl_slist *host = NULL; ++ struct curl_slist *host2 = NULL; ++ char proxy1_resolve[128]; ++ char proxy2_resolve[128]; ++ char proxy1_connect[128]; ++ char proxy2_connect[128]; ++ ++ curl_msnprintf(proxy1_resolve, sizeof(proxy1_resolve), ++ "firstproxy:%s:%s", libtest_arg2, hostip); ++ curl_msnprintf(proxy2_resolve, sizeof(proxy2_resolve), ++ "secondproxy:%s:%s", libtest_arg2, hostip); ++ ++ /* we connect to the fake host name but the right port number */ ++ curl_msnprintf(proxy1_connect, sizeof(proxy1_connect), ++ "firstproxy:%s", libtest_arg2); ++ curl_msnprintf(proxy2_connect, sizeof(proxy2_connect), ++ "secondproxy:%s", libtest_arg2); ++ ++ res_global_init(CURL_GLOBAL_ALL); ++ if(result) ++ return result; ++ ++ curl = curl_easy_init(); ++ if(!curl) { ++ curl_mfprintf(stderr, "curl_easy_init() failed\n"); ++ curl_global_cleanup(); ++ return TEST_ERR_MAJOR_BAD; ++ } ++ ++ host = curl_slist_append(NULL, proxy1_resolve); ++ if(!host) ++ goto test_cleanup; ++ host2 = curl_slist_append(host, proxy2_resolve); ++ if(!host2) ++ goto test_cleanup; ++ host = host2; ++ ++ start_test_timing(); ++ ++ easy_setopt(curl, CURLOPT_RESOLVE, host); ++ easy_setopt(curl, CURLOPT_PROXYUSERPWD, "victim:secret"); ++ ++ curl_mprintf("--- First get over %s\n", proxy1_connect); ++ result = run1648(curl, GET_THIS, proxy1_connect); ++ if(result) ++ goto test_cleanup; ++ ++ easy_setopt(curl, CURLOPT_PROXYUSERPWD, NULL); ++ ++ curl_mprintf("--- Then over '%s'\n", proxy2_connect); ++ result = run1648(curl, GET_THIS, proxy2_connect); ++ ++test_cleanup: ++ ++ /* proper cleanup sequence - type PB */ ++ ++ curl_easy_cleanup(curl); ++ curl_global_cleanup(); ++ curl_slist_free_all(host); ++ return result; ++} +-- +2.43.0 + diff --git a/meta/recipes-support/curl/curl_8.19.0.bb b/meta/recipes-support/curl/curl_8.19.0.bb index 3695f8d083d..cd56e2aaaf3 100644 --- a/meta/recipes-support/curl/curl_8.19.0.bb +++ b/meta/recipes-support/curl/curl_8.19.0.bb @@ -34,6 +34,7 @@ SRC_URI = " \ file://CVE-2026-9080.patch \ file://CVE-2026-9545-01.patch \ file://CVE-2026-9545-02.patch \ + file://CVE-2026-9079.patch \ " SRC_URI:append:class-nativesdk = " \ From patchwork Thu Sep 17 22:06:41 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 98627 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 8392EC982E1 for ; Thu, 17 Sep 2026 22:08:28 +0000 (UTC) Received: from mail-wm2-f13.google.com (mail-wm2-f13.google.com [74.125.225.141]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.1701.1789682901167350169 for ; Thu, 17 Sep 2026 15:08:21 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=PEkiDJtO; spf=pass (domain: smile.fr, ip: 74.125.225.141, mailfrom: yoann.congal@smile.fr) Received: by mail-wm2-f13.google.com with SMTP id 5b1f17b1804b1-49e66390995so565235e9.2 for ; Thu, 17 Sep 2026 15:08:20 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1789682899; x=1790287699; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=K1BtABK3eX9UJhHU4jN+1m7P4zg3dQPs59KjuIJsJvs=; b=PEkiDJtOFTSAPlWaRkHKtI0y1Yru/qhhWwD0DfffoHfaOPSmfTUx0nmF/yUONY7oCP tJNaqSumOb/4Hw7xrNuNFpxlAnbCYCA5HcAsa6Z9lFEeI7XNaHWqhUtO4BEOjjPvp1s6 1OFlKs4x0+95OqKNWscbFp4rj/cJ65V4oHjdI= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1789682899; x=1790287699; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=K1BtABK3eX9UJhHU4jN+1m7P4zg3dQPs59KjuIJsJvs=; b=d4UDhhn/6VD0RkPwJ/lEI6kx4oPIrxVxBguqfgCh7upE1WOLlB25J9+pRiizcLLAgu Kz3srzzWDn6JBcdBT2b0FABflnW6hYXK157wfZV/bmSsUE70uQOs9g6lKp5NCQpPXvuJ Zf3I8TdqPzSE4dSyCTu25Kt2R+h78FhqBz/59ketnhzEsOgYEF5UP4hcy71o27ZuKnsR /tICOYTR3LbKlpNOMe7lKGd7Og5h+6HBPx4BKsj+FnD0f000sjWon2fcLY4xqtfTTvOV EZTqo+1vSYWcyhTo4CK8m6z1OTDbYUVGPx1RH8Lhvbmv5oyRcPSX56j1B7H1W0WkdmaA 84XA== X-Gm-Message-State: AFuF++kKDA08mIHjDcF4bmVPAHmxQn5x9ijAmkRMx7l0DJHvt0T72KsU aqXQzAnRJFrn062022iRm5pYCiyhQu3x5maLoi+08W4CCb9HzqkCSw/kpr7m9MhLWc2k7JX8qo+ KwmKgKfw= X-Gm-Gg: AYBFou0xe8GjAj4reU46KOKlDL8QBMhE3yjMoBo1ppSOh46xUIqjdTea6OFB6nFXc2A H+vR3G7lNKMRGp34t6HwDOut8C8nl/U9RSiHIFXsVyXAtesPRQQQv2oNeg03CXb5ekuYFuxOEkh YhRRQm9/1aASJwd7DOLk7fKqloNmuzbkDDTeVB552b4RIcDweF3MjDAj7jzHG+WhCf3prgkIO0X xgx6VD52qB66hkGDjOo8sww4pzPYx5+V3RXLyqqpkMfmZMx773LbVXyH13LRghptBbaFg9o+Aal R5Kh/kqja2Fw9RbxNhUItgfN8btSc87C/sRgxBXH9tQ6XLaZ/cmF5D6HkrtIH03GxzTz+cp3SwE tZboJEHnGQ5bVlk7TN9Vd0a42G9R22ssh9VgZ9ualrtJeP1+rhGDn1WZM7GEEg9cBmv/n+m/J9S sT4KvH47MBz5/aFdJY38NtbecQkFu9w7nSDUgyY3N8bcWiLglATFAwEzS8aXLbQHaIQmpRoU0kd +20yIY3SUEbwunPSZiHdXUE9hZYY1N+8dpLO8y0UQlPCj1C6UilVT9xkrOwPPpbjC5pAhffHLdo BsNuaoAtCQ== X-Received: by 2002:a05:600c:820e:b0:49e:67bf:7e97 with SMTP id 5b1f17b1804b1-49fc5714c2dmr2819975e9.10.1789682899461; Thu, 17 Sep 2026 15:08:19 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-49fc471b9a2sm8984075e9.0.2026.09.17.15.08.19 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Thu, 17 Sep 2026 15:08:19 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][wrynose 56/79] curl: set CVE_STATUS for CVE-2026-8458 Date: Fri, 18 Sep 2026 00:06:41 +0200 Message-ID: <93c410c455b92a2b1fe3b77347e57d02f344056b.1789681419.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Thu, 17 Sep 2026 22:08:28 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/246151 From: Devansh Patel CVE-2026-8458 allows a Negotiate-authenticated connection to be incorrectly reused for a request using a different SASL service name. Wrynose uses curl 8.19.0, which is within the affected version range. The vulnerable code path on Linux requires both Negotiate authentication and GSSAPI support, represented by the negotiate-auth and krb5 PACKAGECONFIG options. The upstream fix [1] stores the SASL service name in struct Curl_creds and includes it in connection-reuse comparisons. However, struct Curl_creds was introduced by the credential-management rework in [2], after curl 8.19.0. Therefore, the security fix cannot be cleanly backported without introducing a substantial credential-management refactor. Use a conditional CVE_STATUS as the least invasive solution. Report the CVE as unpatched when both krb5 and negotiate-auth are enabled. Otherwise, mark it not-applicable-config because the vulnerable GSSAPI-backed Negotiate implementation is not built. The default Wrynose configuration enables negotiate-auth but does not enable krb5. References: [1] https://github.com/curl/curl/commit/5e99b73cf441d9c369768b9cd48b5389b9a2503d [2] https://github.com/curl/curl/commit/8f71d0fde515aa4c68002477356c35bd79927729 [3] https://curl.se/docs/CVE-2026-8458.html Signed-off-by: Devansh Patel Signed-off-by: Yoann Congal --- meta/recipes-support/curl/curl_8.19.0.bb | 1 + 1 file changed, 1 insertion(+) diff --git a/meta/recipes-support/curl/curl_8.19.0.bb b/meta/recipes-support/curl/curl_8.19.0.bb index cd56e2aaaf3..dfc28539380 100644 --- a/meta/recipes-support/curl/curl_8.19.0.bb +++ b/meta/recipes-support/curl/curl_8.19.0.bb @@ -50,6 +50,7 @@ CVE_STATUS[CVE-2026-8924] = "not-applicable-config: public suffix list support i CVE_STATUS[CVE-2026-10536] = "${@bb.utils.contains('PACKAGECONFIG', 'nghttp2', 'unpatched', 'not-applicable-config: applicable only with HTTP/2', d)}" CVE_STATUS[CVE-2026-9547] = "not-applicable-config: vulnerable libssh backend is not enabled by the recipe" CVE_STATUS[CVE-2026-12064] = "${@bb.utils.contains('PACKAGECONFIG', 'libssh2', 'unpatched', 'not-applicable-config: SCP/SFTP support is not enabled in PACKAGECONFIG', d)}" +CVE_STATUS[CVE-2026-8458] = "${@bb.utils.contains('PACKAGECONFIG', 'krb5 negotiate-auth', 'unpatched', 'not-applicable-config: applicable only with GSS-API-backed Negotiate authentication', d)}" inherit autotools pkgconfig binconfig multilib_header ptest From patchwork Thu Sep 17 22:06:42 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 98628 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 8E515C982E2 for ; Thu, 17 Sep 2026 22:08:28 +0000 (UTC) Received: from mail-wm2-f12.google.com (mail-wm2-f12.google.com [74.125.225.140]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.1702.1789682901772741043 for ; Thu, 17 Sep 2026 15:08:22 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=ptalHHiS; spf=pass (domain: smile.fr, ip: 74.125.225.140, mailfrom: yoann.congal@smile.fr) Received: by mail-wm2-f12.google.com with SMTP id 5b1f17b1804b1-49cd4ba9f68so1481905e9.1 for ; Thu, 17 Sep 2026 15:08:21 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1789682900; x=1790287700; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=XG3HsL2GvE3NLczUFPbWuudQTEQ5TY3mc37bdjbw8N0=; b=ptalHHiSF/Y034xNIn5OfUxPEy/cU468ht+bFPyOnzqvUj18Gtn+naTYoPA9IUnwVD wPl25mv4BF4k39F4SHODxM9faTrgpMWUrhWLqkokYdWYG4/XOspGCqgVuCJ5w0Nfg89k 7VDbb3WQBeLTjFPigRvHp9stb6fXTBk8T5hTk= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1789682900; x=1790287700; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=XG3HsL2GvE3NLczUFPbWuudQTEQ5TY3mc37bdjbw8N0=; b=TOnvDmi97JCD1XVxBb60thuVHb7hCvxVyR9jH78NCc4CqY80JV6xWX7lqSWiVnPfTv MaKdSrSHBBVq5Rh7fPzTeYeynmvrzEoz79zA6ciELHBexSwE4WUXtjijAw0rzPgnHD9t TnbWEpI3XsnPxGpm1JXW3dahhyJ3IcS4ysVU2HR2OpgpYH8ZsAtvOVINreHXdH1RJgVX yCqbBaXEdYQl4Eq+sfifE9dMu29FEmeeTRANasmSwAPI8FjlaftKavtvXppqLzJKWYZw itWwVeRhz0sGWlhV2vnOhC3VtrEadAMmXuLD/8qbrSq8bt7jvS6nasMjPzR2jZG5tVgh Q1QQ== X-Gm-Message-State: AFuF++kw4XC2Ttv6n8KuJ9EzFUa5XohE0f390qPhVaOV/zQiEA/T9soh HrjDbb3p6mlBb7XCRmgoDGkMcmKDXRc7cUZOGTJGjpWh7moH+xDLXCB+so/EIwCF+n1XvVzjwMP 3/Mkk1Cg= X-Gm-Gg: AYBFou3+rTqaI2ggfex7GjEXTtORlM8N8GvFmiLG/qoUpUP0hvZhpI/OV1iO6gn9apQ NFERIiYZa/VBirMvTjRKwwPBFpla+xIRMOM5CvTQpFUMkUcJRp3NzqVvVxCV8vZL0Oo/n5oh6kK 1EkgKtCuqwk4bpSwxBh8c/DRJ515i6Vhp9/uRhySqblkeqRTEqTob3gYtKdcykVk2jch/ilM2GV SZFWRpj7spTVYQmx8gx9vMjkqQXBSDFId0N9sMmzaQ+Pb2p1Geyg0w8KNpBUIS+YARSEAPXaKxF QPT51OaSYOtdBlfeMGJW7Rh3P64t9r6TnLZtzqv8m+Ozu8aWMFhzxX9MDpmfgIhis38Kjkm9lB7 o4PEbblmIpD1JegvETADLIAczGQfZEEXZPF5E1rtiICJYBbQbksevUP0JlnvYBUEtP139HXNwnE l8xOZ8DbXXr4i46ZSoKil2euQzpO9ZryzQ2r94gDDEHPTy84E+MdMyTROHeqkZaMVv2PoK89Rel P9BnG1cvtXl4iC4HUslNBdbL15FY3zarFQdKYNXTCv5/fLU3XJRRyHXt6WbkqFcpVNFHTxviU0T X-Received: by 2002:a05:600c:4e89:b0:49d:10d6:fd55 with SMTP id 5b1f17b1804b1-49fc5681267mr3262515e9.1.1789682899848; Thu, 17 Sep 2026 15:08:19 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-49fc471b9a2sm8984075e9.0.2026.09.17.15.08.19 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Thu, 17 Sep 2026 15:08:19 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][wrynose 57/79] curl: Security Fix for CVE-2026-13608 Date: Fri, 18 Sep 2026 00:06:42 +0200 Message-ID: X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Thu, 17 Sep 2026 22:08:28 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/246152 From: Siddharth Doshi Picking patch as per [1], and same patch is mentioned in [2] [1] https://curl.se/docs/CVE-2026-13608.html [2] https://security-tracker.debian.org/tracker/CVE-2026-13608 Signed-off-by: Siddharth Doshi Signed-off-by: Yoann Congal --- .../curl/curl/CVE-2026-13608.patch | 48 +++++++++++++++++++ meta/recipes-support/curl/curl_8.19.0.bb | 1 + 2 files changed, 49 insertions(+) create mode 100644 meta/recipes-support/curl/curl/CVE-2026-13608.patch diff --git a/meta/recipes-support/curl/curl/CVE-2026-13608.patch b/meta/recipes-support/curl/curl/CVE-2026-13608.patch new file mode 100644 index 00000000000..4df7595c8f0 --- /dev/null +++ b/meta/recipes-support/curl/curl/CVE-2026-13608.patch @@ -0,0 +1,48 @@ +From 25df759f0f0c1aeaee066a4502bb36a8a86fb22e Mon Sep 17 00:00:00 2001 +From: Daniel Stenberg +Date: Mon, 29 Jun 2026 10:44:47 +0200 +Subject: [PATCH 1/5] openldap: handle Curl_sasl_continue() returns better + +Similar to how it gets treated already in other protocol handlers. + +Follow-up to eeca818b1e8d1e61c2d4 + +Reported-by: Eunsoo Kim +Closes #22213 + +Upstream-Status: Backport [https://github.com/curl/curl/commit/ea71c3b6b60e563651ea8596a975aef0c8199519] +CVE: CVE-2026-13608 +Signed-off-by: Siddharth Doshi +--- + lib/openldap.c | 15 +++++++++++++-- + 1 file changed, 13 insertions(+), 2 deletions(-) + +diff --git a/lib/openldap.c b/lib/openldap.c +index 95f7681..4a1e93a 100644 +--- a/lib/openldap.c ++++ b/lib/openldap.c +@@ -778,8 +778,19 @@ static CURLcode oldap_state_sasl_resp(struct Curl_easy *data, + } + else { + result = Curl_sasl_continue(&li->sasl, data, code, &progress); +- if(!result && progress != SASL_INPROGRESS) +- oldap_state(data, li, OLDAP_STOP); ++ if(!result) { ++ switch(progress) { ++ case SASL_DONE: ++ oldap_state(data, li, OLDAP_STOP); /* Authenticated */ ++ break; ++ case SASL_IDLE: /* No mechanism left after cancellation */ ++ failf(data, "Authentication cancelled"); ++ result = CURLE_LOGIN_DENIED; ++ break; ++ default: ++ break; ++ } ++ } + } + + if(li->servercred) +-- +2.34.1 + diff --git a/meta/recipes-support/curl/curl_8.19.0.bb b/meta/recipes-support/curl/curl_8.19.0.bb index dfc28539380..21d887cb399 100644 --- a/meta/recipes-support/curl/curl_8.19.0.bb +++ b/meta/recipes-support/curl/curl_8.19.0.bb @@ -35,6 +35,7 @@ SRC_URI = " \ file://CVE-2026-9545-01.patch \ file://CVE-2026-9545-02.patch \ file://CVE-2026-9079.patch \ + file://CVE-2026-13608.patch \ " SRC_URI:append:class-nativesdk = " \ From patchwork Thu Sep 17 22:06:43 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 98623 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 49C0CC982DE for ; Thu, 17 Sep 2026 22:08:28 +0000 (UTC) Received: from mail-wm2-f13.google.com (mail-wm2-f13.google.com [74.125.225.141]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.1597.1789682902706543506 for ; Thu, 17 Sep 2026 15:08:23 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=wg6J/cEk; spf=pass (domain: smile.fr, ip: 74.125.225.141, mailfrom: yoann.congal@smile.fr) Received: by mail-wm2-f13.google.com with SMTP id 5b1f17b1804b1-49cd38e0e5dso1337495e9.2 for ; Thu, 17 Sep 2026 15:08:22 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1789682901; x=1790287701; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=ADqnn1iF7YT+dyVklB58tlGILiqXaspMRyJQWu9HjOI=; b=wg6J/cEkA1GiVuwMA0nVBYNuoMInwEeT6o6UmuxsumOkOWyw9eOxXV10IssjhNannN e8mtN4f81tJl6U0vR/dljq/hSR6Tn66BoJ8Rwn2DPlNn3RMISFVqqmI97lddRpKZnGk8 LefdztfhC02XoPt3VGeolHy19KqnGO/9CspRo= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1789682901; x=1790287701; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=ADqnn1iF7YT+dyVklB58tlGILiqXaspMRyJQWu9HjOI=; b=pQ7KoYb9SxlFZAWKSY8pSUlIaGkTy+0AAwVkkOBWLh9sq3A7I9uO2Newe5Z+2th0Yo QQKSJ66/QjuwCKGRCwEi4HxE2buoDOWYIybBARVrtYdCZVCB63VQGmOT0unxZQfVxWPZ +2OzkOFQwHIMR0w4AH2/Nlc0cJq5H53pHLpQ3y4b+1HBfsXZwD5kxN3ZuJMLYu+HzwIn toJOCC6GzJv68UQ2bzvQAfUcr7oIa6aG0KGBC0y38QQcg+I31Y3JcTU3SU0AhoRu/4BF 8FwgCGJrAz8ALdnZ9qzGi3f1O5TrTd11YnL2jjFzRJk2Pu5V1hxOPl84/LzBZO1BqGV/ Umaw== X-Gm-Message-State: AFuF++kjyBrU6N4O3huUCLWzqvKPl977jdCiGibWCv/NADqKrVQKlR4k afyVLUd52pi06kZSft8Q3jCUl1DVxIbawHlQZvkQtTVia3EZefv7RpTK/p3GPLsvHat1cZAebPG co/ZfzNo= X-Gm-Gg: AYBFou3PoUS+l1wShUhee0vksztALckR9FaNWh2woMobpqlqzDvvt15usUR1Lv1UF9e gjpz1dYs9KPno23wN9khVA6tV6em6C/f66qvCzFT2PGhDbVwvzwCm+RcQXMuei5a5dC+HGA7N71 PQ4q8TQgv6kJtV/JPRd2bUOZRAW46KgUWzFIS76T+isA+yquYUQ8WQMR/ImhEYHm4C2siMePhuA dJw6IoaHl9zyg80P3fKE4MRwGU4wK4BeQvt1JBipuYdArhnnNDpQYLrRpCVlhqikNpwm9aVMv8j z/rcox32SFw37+bmEE/lS8gkYdSxcoZ1PlLJlcsgJKtEJRAusaMeNiPpwt0XtMeLv/B8XaHoVAx PXFw4vd1CpdiMN+yHYuKZpNkAitIsR118n/T1XBhkUoTPWAfqfGwnRJECTkzRz3QsjXs4KieXTj Qj8NmDXeOAsEDExUsFwSpr6ea2zu0wnIGw30K6ASIBeb8LnsAb3PXRlwpM4sz4ztjw2Va5mLc7+ SUom6bpnXAg3j1o8ga8hTL2Dw1AgyXDIKuv8d5ZX/qu+Yxq2gf2AKrcNHRpWRWtEre22qVOWyo= X-Received: by 2002:a05:600c:1c09:b0:49f:bd3c:bc24 with SMTP id 5b1f17b1804b1-49fc57479c9mr4034725e9.31.1789682900797; Thu, 17 Sep 2026 15:08:20 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-49fc471b9a2sm8984075e9.0.2026.09.17.15.08.20 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Thu, 17 Sep 2026 15:08:20 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][wrynose 58/79] curl: Security Fix for CVE-2026-18924 Date: Fri, 18 Sep 2026 00:06:43 +0200 Message-ID: <9e18a7cafc1b5ef69205d36dd50e4f1c7eb89228.1789681419.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Thu, 17 Sep 2026 22:08:28 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/246153 From: Siddharth Doshi Picking patch as per [1], and same patch is mentioned in [2] [1] https://curl.se/docs/CVE-2026-18924.html [2] https://security-tracker.debian.org/tracker/CVE-2026-18924 Signed-off-by: Siddharth Doshi Signed-off-by: Yoann Congal --- .../curl/curl/CVE-2026-18924.patch | 39 +++++++++++++++++++ meta/recipes-support/curl/curl_8.19.0.bb | 1 + 2 files changed, 40 insertions(+) create mode 100644 meta/recipes-support/curl/curl/CVE-2026-18924.patch diff --git a/meta/recipes-support/curl/curl/CVE-2026-18924.patch b/meta/recipes-support/curl/curl/CVE-2026-18924.patch new file mode 100644 index 00000000000..fbf452e4e9c --- /dev/null +++ b/meta/recipes-support/curl/curl/CVE-2026-18924.patch @@ -0,0 +1,39 @@ +From 90325ff0444cbdff368bda5d26d6405a0bb6ee43 Mon Sep 17 00:00:00 2001 +From: Daniel Stenberg +Date: Wed, 5 Aug 2026 10:02:53 +0200 +Subject: [PATCH] http2: make server push transfers inherit share from parent + +Reported-by: Stephan Zeisberg +Closes #22488 + +Upstream-Status: Backport [https://github.com/curl/curl/commit/90325ff0444cbdff368bda5d26d6405a0bb6ee43] +CVE: CVE-2026-18924 +Signed-off-by: Siddharth Doshi +--- + lib/http2.c | 3 +++ + 1 file changed, 3 insertions(+) + +diff --git a/lib/http2.c b/lib/http2.c +index e1c5798..2ef1c28 100644 +--- a/lib/http2.c ++++ b/lib/http2.c +@@ -46,6 +46,7 @@ + #include "bufref.h" + #include "curlx/dynbuf.h" + #include "headers.h" ++#include "curl_share.h" + + #if (NGHTTP2_VERSION_NUM < 0x010c00) + #error too old nghttp2 version, upgrade! +@@ -709,6 +710,8 @@ static struct Curl_easy *h2_duphandle(struct Curl_cfilter *cf, + struct h2_stream_ctx *second_stream; + http2_data_setup(cf, second, &second_stream); + second->state.priority.weight = data->state.priority.weight; ++ if(data->share) ++ (void)Curl_share_easy_link(second, data->share); + } + return second; + } +-- +2.34.1 + diff --git a/meta/recipes-support/curl/curl_8.19.0.bb b/meta/recipes-support/curl/curl_8.19.0.bb index 21d887cb399..ccf8de0b90e 100644 --- a/meta/recipes-support/curl/curl_8.19.0.bb +++ b/meta/recipes-support/curl/curl_8.19.0.bb @@ -36,6 +36,7 @@ SRC_URI = " \ file://CVE-2026-9545-02.patch \ file://CVE-2026-9079.patch \ file://CVE-2026-13608.patch \ + file://CVE-2026-18924.patch \ " SRC_URI:append:class-nativesdk = " \ From patchwork Thu Sep 17 22:06:44 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 98629 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id E3F4DC982E5 for ; Thu, 17 Sep 2026 22:08:28 +0000 (UTC) Received: from mail-wm2-f13.google.com (mail-wm2-f13.google.com [74.125.225.141]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.1598.1789682903144730582 for ; Thu, 17 Sep 2026 15:08:23 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=mtPnRRJy; spf=pass (domain: smile.fr, ip: 74.125.225.141, mailfrom: yoann.congal@smile.fr) Received: by mail-wm2-f13.google.com with SMTP id 5b1f17b1804b1-49b965f447cso894735e9.3 for ; Thu, 17 Sep 2026 15:08:22 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1789682901; x=1790287701; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=LCWbq0xb8gkSNiooL/JJN/2siO+Hzlle7aYzpv46Ihg=; b=mtPnRRJy6cF2hT4yKgpRhrQGhxZa8gxK4SSNJxeXn1RbQ1s5xdOXa+CW3Cj4UtdWdC mKXCri2qaOizsEJYoovFM3Cdzx1D7E0Mrkek/Lx7LW5qLmIqR/b2ruI6mmQsENOZlmD+ VHYbStJNyZ5U2Bp8spmwhLBA8/zeWgsBpx8bA= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1789682901; x=1790287701; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=LCWbq0xb8gkSNiooL/JJN/2siO+Hzlle7aYzpv46Ihg=; b=xFqQicLoX6cU5VHhdL20aeuuLVf4uHVCaJXaafTmfV8FEB28UQKR7PcZnwqkECTOoZ sST6mazZJBiBNzRrryt5a0PKqKfJ31/IDXDQTuTQiri3HxqHZ0PbF8x89Qbd83OlZSsY 1jIrk2AtJSAXvEL+dUWyVypHEtrcdrE7mObIRIoWxbqWL3YCQcV/H7I+K7dvQ8FRRUFi jEmcWDIHDItdxQ0FELjj1i4xWKhNoaIzQsd+ADvpFsTW5AHYuebWhtir8mMmynbuDzHk 73LTYyiJI0vMwHcFMQpfBHAVRDntoKFj1oB/QJzsGOcw4Q87XzVaIhVb91vEen7c0x9I tIpQ== X-Gm-Message-State: AFuF++kpChSqvNBfghUa/6p96vIhOOb5DASy5awYaYVBRc8w7M+AtGxp SWgfChQxo67YSs7Gbr13pvZAI7qm+VKiXgK7s77BqWIuS1o2K2dGTlBq0yur6q/I6dPi5z7P4/s fKjl2YRc= X-Gm-Gg: AYBFou0o/oDCoyZYn7jCnDNBFsdNcgQEhZsTWuJd1c0lEVvjSCAfwsuaPyBb3yuF43m igngFlrJKUBYI65WLq4f36rYGdI8rp3s2ADjfpbjtRmI33ohAtcBo6vAcY5VNywJk8CeOvSXiWR YNiH/Bysmm1aLSCqcaqcNdUNvxdExImbScqjnkrsG5J1ZXmzCNpdm78d6xSDZ/4NyIyNJdbXGlG W7BAevY2nv7B4q7+SeK1hCre4PjiAUKm6nzF/97BmigrxlonIwkl5E7FBQ/OpPBGSJMHeuW9lif pIlXz2G/agBlYGrrxVOEo4OkomwwkZ4mVCKpvZmePh2y2E45Fd9egmk6RU6U2UmL4ufPxj891yD /VOk7cn+fuAaRvRAFuP3VPbk3lu/3CLhlbT/ihB+5KywN0hmGHFDvFi6luLRzin6MLgg6DhGvt+ LPDvbull/1h5PYENt4+nn+2hRiTMqtosRUtD7Jebsjq9n0hc6M7vRfD3pmjdlSl4wAQ+wZOAtIe 4cK1bHx4Rjw/C5n81WLnFDCF9cMtZ5UyBrYcU4PVbhWsb1fE1g7gKKh7OqxYH81pxtSoVsa8IQ= X-Received: by 2002:a05:600c:1d29:b0:49e:7c8c:361d with SMTP id 5b1f17b1804b1-49fc572b7afmr3464125e9.22.1789682901404; Thu, 17 Sep 2026 15:08:21 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-49fc471b9a2sm8984075e9.0.2026.09.17.15.08.21 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Thu, 17 Sep 2026 15:08:21 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][wrynose 59/79] curl: Security Fix for CVE-2026-80229 Date: Fri, 18 Sep 2026 00:06:44 +0200 Message-ID: X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Thu, 17 Sep 2026 22:08:28 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/246154 From: Siddharth Doshi Picking patch as per [1], and same patch is mentioned in [2] [1] https://curl.se/docs/CVE-2026-80229.html [2] https://security-tracker.debian.org/tracker/CVE-2026-80229 Signed-off-by: Siddharth Doshi Signed-off-by: Yoann Congal --- .../curl/curl/CVE-2026-80229.patch | 35 +++++++++++++++++++ meta/recipes-support/curl/curl_8.19.0.bb | 1 + 2 files changed, 36 insertions(+) create mode 100644 meta/recipes-support/curl/curl/CVE-2026-80229.patch diff --git a/meta/recipes-support/curl/curl/CVE-2026-80229.patch b/meta/recipes-support/curl/curl/CVE-2026-80229.patch new file mode 100644 index 00000000000..74be963fa4d --- /dev/null +++ b/meta/recipes-support/curl/curl/CVE-2026-80229.patch @@ -0,0 +1,35 @@ +From 272d5928188bc2171fdeba81027b24145a033fb2 Mon Sep 17 00:00:00 2001 +From: Daniel Stenberg +Date: Tue, 25 Aug 2026 11:14:30 +0200 +Subject: [PATCH 3/5] openssl: avoid conn reuse if provider is used + +Reported-by: Stanislav Fort + +Closes #22665 + +Upstream-Status: Backport [https://github.com/curl/curl/commit/7ea37abc6ac0120ba5f6d94be8d196f7cf1506bb] +CVE: CVE-2026-80229 +Signed-off-by: Siddharth Doshi +--- + lib/vtls/openssl.c | 5 +++++ + 1 file changed, 5 insertions(+) + +diff --git a/lib/vtls/openssl.c b/lib/vtls/openssl.c +index 9cbab14..1d0f7b7 100644 +--- a/lib/vtls/openssl.c ++++ b/lib/vtls/openssl.c +@@ -3753,6 +3753,11 @@ CURLcode Curl_ossl_ctx_init(struct ossl_ctx *octx, + ossl_strerror(ERR_peek_error(), error_buffer, sizeof(error_buffer))); + return CURLE_OUT_OF_MEMORY; + } ++#ifdef OPENSSL_HAS_PROVIDERS ++ if(data->state.libctx) ++ /* forbid connection reuse with provider/engine use */ ++ connclose(data->conn, "forbid connection reuse with provider/engine use"); ++#endif + + if(cb_setup) { + result = cb_setup(cf, data, cb_user_data); +-- +2.34.1 + diff --git a/meta/recipes-support/curl/curl_8.19.0.bb b/meta/recipes-support/curl/curl_8.19.0.bb index ccf8de0b90e..33aed045117 100644 --- a/meta/recipes-support/curl/curl_8.19.0.bb +++ b/meta/recipes-support/curl/curl_8.19.0.bb @@ -37,6 +37,7 @@ SRC_URI = " \ file://CVE-2026-9079.patch \ file://CVE-2026-13608.patch \ file://CVE-2026-18924.patch \ + file://CVE-2026-80229.patch \ " SRC_URI:append:class-nativesdk = " \ From patchwork Thu Sep 17 22:06:45 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 98622 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 31AF8C982DF for ; Thu, 17 Sep 2026 22:08:28 +0000 (UTC) Received: from mail-wm2-f12.google.com (mail-wm2-f12.google.com [74.125.225.140]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.1599.1789682903489584902 for ; Thu, 17 Sep 2026 15:08:23 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=o28mu0hK; spf=pass (domain: smile.fr, ip: 74.125.225.140, mailfrom: yoann.congal@smile.fr) Received: by mail-wm2-f12.google.com with SMTP id 5b1f17b1804b1-49cd38e0e5dso1337595e9.2 for ; Thu, 17 Sep 2026 15:08:23 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1789682902; x=1790287702; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=NN465glGkKmk84bB/xeQLsl+0wp/QW2mQUDbWiXOyM0=; b=o28mu0hKe/5qO4W9AxraN5YXhcKDBTDdAtejk5PIr0ItFLgJm+xW4UirqoLmAD+g8c JqAk+wnxF+XxMeHrXAsUyv5Or44hRgasGqm8kJvCPwE5ZxjgSWBmnMuhvZ5j492Y4pTo SMseUE/TG9FdFjiM2RlWuxkmlIkUG7qlR5O8o= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1789682902; x=1790287702; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=NN465glGkKmk84bB/xeQLsl+0wp/QW2mQUDbWiXOyM0=; b=kRe6RYSypkax6QwD00X0ux86jjBkQ6Ckch+KOPFPgQbxRhHvpEwVnVA8NrAt3lE74/ Dm1ElRgWJTXRpqQqGkZwbffLM4+0jD5ikySJT8UOGIeFQSVitBYhaOaFSM+Bb0eCwPwd A7elP4j3e4KbTLg6aTNQcR33ECqIkdQvlcieTsyeNxjrzHIyX4kZxQWikRvyanHx5E1i ifVoOdm5z/t21rXMs3X3jSKuXQMH42YH/Wer24eGb/iG8swBA8uZ2Aiove0UqiDKmcCm Q/PVC0VaUWR5ph/KPPYJZsOQN1XJp07PLqkJ3x9CnIokUQ1bKcXCZ68WiCxPwF/drpxB zZfA== X-Gm-Message-State: AFuF++nCvJOgwYz05q9KRPtQZqo0H5wfCgPo1Ejbq3ApsNc+1ryb1s90 XP3wPv5qWw8zefii8es9clkbhypDRjzNPpKiobAC2XCkJ/CXQCWn0dex8JTVq+Qxvp3F4LRNdrm JgGLEb0A= X-Gm-Gg: AYBFou2wAydY6e7a5KOZifqbWlJgUeGsCW0sfmkV2kaTxg18zNrYMK/MgESasZnaeWj 0UJD822Z4M5+QvwEkDeeWbVtyspaJSH7ajlre7xQe9pJ3ms49+3xxm8r3TBW0gbmhmsXWAfqkKd zjk2Y3Ck4CYM0YdDYIxT3D1fXJt6aF7FYUbPhwBICjHLwSw5doug1pBdaJEGECjQN9Gn8Fe2CDu 1Zw9CarHrUuoykgOPvc5LtjXnY3C02bvdxX2WdGkhaFT2LWABwTeWfK5ql41ZQ2w6BKMs/+clX+ IIQrDcUb57nN+3HkixbaF9NniiX9jKOsJU0UdaYXKg+fl/eNAw6AGzv2P2kAvMDzp7DNl0Y5wCL eEM9caEpOm9cfAgPjcaSK5hCLl/bcgr1qfAz/NCjeGVrZwnn58zQF+pyRehekyGKCOKuBpxEDoo jaKwL6SQ4c9v9eIJCikk5vKQIh3YjCbuMTLcphotvFbOohqJrjH0p/HK0pnAi6kbdXvf+3t5rDn uaz/ugIhb/tMRlJX3JbTfRvcUzVRIl0rV0zYGqII9EGgz5r3zul8exb6GmGptKLSK2+oM2zIpQ= X-Received: by 2002:a05:600c:8b81:b0:498:943:ccc0 with SMTP id 5b1f17b1804b1-49fc566ee41mr2933165e9.6.1789682901820; Thu, 17 Sep 2026 15:08:21 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-49fc471b9a2sm8984075e9.0.2026.09.17.15.08.21 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Thu, 17 Sep 2026 15:08:21 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][wrynose 60/79] curl: set CVE_STATUS for CVE-2026-82209 Date: Fri, 18 Sep 2026 00:06:45 +0200 Message-ID: <70c3dee9e7a58c14635b4f69c4c0a3843abad901.1789681419.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Thu, 17 Sep 2026 22:08:28 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/246155 From: Siddharth Doshi Analysis: - The problem only exists when curl is built with libpsl support enabled.[1] - The recipe is built with "--without-libpsl" option. - Hence, ignoring the CVE for this recipe. Reference: [1] https://curl.se/docs/CVE-2026-82209.html Signed-off-by: Siddharth Doshi Signed-off-by: Yoann Congal --- meta/recipes-support/curl/curl_8.19.0.bb | 1 + 1 file changed, 1 insertion(+) diff --git a/meta/recipes-support/curl/curl_8.19.0.bb b/meta/recipes-support/curl/curl_8.19.0.bb index 33aed045117..f6ddc4aa230 100644 --- a/meta/recipes-support/curl/curl_8.19.0.bb +++ b/meta/recipes-support/curl/curl_8.19.0.bb @@ -54,6 +54,7 @@ CVE_STATUS[CVE-2026-10536] = "${@bb.utils.contains('PACKAGECONFIG', 'nghttp2', ' CVE_STATUS[CVE-2026-9547] = "not-applicable-config: vulnerable libssh backend is not enabled by the recipe" CVE_STATUS[CVE-2026-12064] = "${@bb.utils.contains('PACKAGECONFIG', 'libssh2', 'unpatched', 'not-applicable-config: SCP/SFTP support is not enabled in PACKAGECONFIG', d)}" CVE_STATUS[CVE-2026-8458] = "${@bb.utils.contains('PACKAGECONFIG', 'krb5 negotiate-auth', 'unpatched', 'not-applicable-config: applicable only with GSS-API-backed Negotiate authentication', d)}" +CVE_STATUS[CVE-2026-82209] = "not-applicable-config: public suffix list support is disabled by the recipe with --without-libpsl" inherit autotools pkgconfig binconfig multilib_header ptest From patchwork Thu Sep 17 22:06:46 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 98630 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id D0AC5C982E3 for ; Thu, 17 Sep 2026 22:08:28 +0000 (UTC) Received: from mail-wm2-f13.google.com (mail-wm2-f13.google.com [74.125.225.141]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.1703.1789682904199347196 for ; Thu, 17 Sep 2026 15:08:24 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=aUVYcEh5; spf=pass (domain: smile.fr, ip: 74.125.225.141, mailfrom: yoann.congal@smile.fr) Received: by mail-wm2-f13.google.com with SMTP id 5b1f17b1804b1-49e6c0fce17so585965e9.1 for ; Thu, 17 Sep 2026 15:08:23 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1789682902; x=1790287702; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=Gvp3XspO1ivs5u3HH4ocGU72XQPtTCQk42il3b+Zbio=; b=aUVYcEh5SqoPkZiCSEsY9a5igWDIb9w6SnEqWYBOj86sPYXOtECg8UuTmKbPKwoupW QdCR2WNlAtzrvzlC8YaWlLc957CqdIyCD8tXckIGaWkF0FHNa1G65o10RLnVVXGWBatz WZfHqDiUnCy5ZyJbiNNv8qSuUaTSpfvcjkc60= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1789682902; x=1790287702; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=Gvp3XspO1ivs5u3HH4ocGU72XQPtTCQk42il3b+Zbio=; b=fLfOqW4w9db93fZV5pMc3yPTYeItycNibAAHQNsM1pzG9/JMu0c/s99FsoRnPjRzvN 9x1FiJYX0SmOq7fHVV1ErSOI7/G79fLtatrO+n9M7JoPS2895h2Be/UyR22rntE3BJ1V aPq7Vwc7sTertGxH8AEMke6XaGcjjNjg1fkJPenP/WCKOpe77HcxOVMjIq8ntexu9/0s JgxNV2zOQYXX9HsZ84Z/oigjhOacfYTvV/3ONA+E4Q0cYsi0wZNKsGvIyulxNSUBlRoh 1czpXDK1BZA4eo728iv4YqPg1iZo51kgTDWO+LWtjaVy6fl41odsszNRmqE03L+VKTxL m0uA== X-Gm-Message-State: AFuF++k/pYRvV/iMC4lM6i4HgNjcoEvuc67Uw3AkGVQX+VTcjaM2x/Dm 0lOfqPvw2G0PkQEhMnKBhu9KkwCQGlLxKA6lfvlIU5PVbABXpAhnZMW0k26yC2jkmnL0TK4K3eY hQxG2KRg= X-Gm-Gg: AYBFou09GvAJmYEv5vHQT8JV3w4LdxJ1JCQOS07X8ws/4NmMsUJdNPMQUB0ct9l6LtC /wrMYvjnwIBydtpoqCSdUomcBUvjmo7nLkjitST7WWQ51k9r3/dTH21MSWPVSwwhL3MvH5mbTkK 3rt+0iLBe6DpTuK3bzf8pEWlfWOQNvQy+DNk8UFsoT6hHfjKkAxuxqyKNmsUtwnQNOSdXkSQTdc tCde3BG2cYVFJ/voQqm+XFkH3q4uvz5zCuLQsguCrSvGOw5ZDi69Th5geGWH7d4Faj8I7MBPU6e Weqb/RsUtgX5FbWtd7/J624XrjEsO538yAn1+Y61ON4zjHGALIgz3x42IkYMvywqj+9JfnjoOiH MJke72FCKsVqI2LSfz9qXJrxn/TGwZwfG9viFkdc112/HNZoR1GnNvOc6bexmPjadklleVR3pDJ T3b1o+o81pEy7khXyRsU2QPlK/Awkh3q0dd3Tg3qLy9uIvAUsyHuenbItkjx6JlLo8EuJjwFUcV tRrdWxxDfrJeV0i7sHMqqXmTHsbQsWcae086j17u71E2OSoreUd3TadWohE7GqR2fH1N44uw6U= X-Received: by 2002:a05:600c:3f18:b0:49e:6c47:1433 with SMTP id 5b1f17b1804b1-49fc5868a9cmr2686635e9.33.1789682902315; Thu, 17 Sep 2026 15:08:22 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-49fc471b9a2sm8984075e9.0.2026.09.17.15.08.21 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Thu, 17 Sep 2026 15:08:21 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][wrynose 61/79] curl: patch CVE-2026-9546 Date: Fri, 18 Sep 2026 00:06:46 +0200 Message-ID: X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Thu, 17 Sep 2026 22:08:28 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/246156 From: Peter Marko Pick patch per [1]. Pick also a precondition patch (containing if clause to else which is added by the actual patch). Resolve conflicts in test makefiles caused by differences in available test suites. [1] https://curl.se/docs/CVE-2026-9546.html Signed-off-by: Peter Marko Signed-off-by: Yoann Congal [YC: refreshed patches on Makefile test lists] --- .../curl/curl/CVE-2026-9546-01.patch | 227 ++++++++++++++++++ .../curl/curl/CVE-2026-9546-02.patch | 218 +++++++++++++++++ meta/recipes-support/curl/curl_8.19.0.bb | 2 + 3 files changed, 447 insertions(+) create mode 100644 meta/recipes-support/curl/curl/CVE-2026-9546-01.patch create mode 100644 meta/recipes-support/curl/curl/CVE-2026-9546-02.patch diff --git a/meta/recipes-support/curl/curl/CVE-2026-9546-01.patch b/meta/recipes-support/curl/curl/CVE-2026-9546-01.patch new file mode 100644 index 00000000000..74dc7015559 --- /dev/null +++ b/meta/recipes-support/curl/curl/CVE-2026-9546-01.patch @@ -0,0 +1,227 @@ +From fa057ea3dedb04f93672ec95ee964f1f02ec0ecf Mon Sep 17 00:00:00 2001 +From: Daniel Stenberg +Date: Wed, 15 Apr 2026 08:11:33 +0200 +Subject: [PATCH] transfer: clear the old autoreferer + +Verify in test 2505 + +Closes #21322 + +CVE: CVE-2026-9546 +Upstream-Status: Backport [https://github.com/curl/curl/commit/fa057ea3dedb04f93672ec95ee964f1f02ec0ecf] +Signed-off-by: Peter Marko +--- + lib/setopt.c | 1 - + lib/transfer.c | 5 +++ + tests/data/Makefile.am | 2 +- + tests/data/test2505 | 67 +++++++++++++++++++++++++++++++++++ + tests/libtest/Makefile.inc | 2 +- + tests/libtest/lib2505.c | 71 ++++++++++++++++++++++++++++++++++++++ + 6 files changed, 145 insertions(+), 3 deletions(-) + create mode 100644 tests/data/test2505 + create mode 100644 tests/libtest/lib2505.c + +diff --git a/lib/setopt.c b/lib/setopt.c +index dae4218b70..e832ef1afd 100644 +--- a/lib/setopt.c ++++ b/lib/setopt.c +@@ -2015,7 +2015,6 @@ static CURLcode setopt_cptr(struct Curl_easy *data, CURLoption option, + * String to set in the HTTP Referer: field. + */ + result = Curl_setstropt(&s->str[STRING_SET_REFERER], ptr); +- Curl_bufref_set(&data->state.referer, s->str[STRING_SET_REFERER], 0, NULL); + break; + + case CURLOPT_USERAGENT: +diff --git a/lib/transfer.c b/lib/transfer.c +index a2fce9331b..fd1a903dab 100644 +--- a/lib/transfer.c ++++ b/lib/transfer.c +@@ -535,6 +535,11 @@ CURLcode Curl_pretransfer(struct Curl_easy *data) + data->state.authproxy.want = data->set.proxyauth; + Curl_safefree(data->info.wouldredirect); + Curl_data_priority_clear_state(data); ++ if(data->set.http_auto_referer) ++ Curl_bufref_free(&data->state.referer); ++ if(data->set.str[STRING_SET_REFERER]) ++ Curl_bufref_set(&data->state.referer, data->set.str[STRING_SET_REFERER], ++ 0, NULL); + + if(data->state.httpreq == HTTPREQ_PUT) + data->state.infilesize = data->set.filesize; +diff --git a/tests/data/Makefile.am b/tests/data/Makefile.am +index 1e84b26820..238da5331c 100644 +--- a/tests/data/Makefile.am ++++ b/tests/data/Makefile.am +@@ -265,7 +265,7 @@ test2309 \ + \ + test2400 test2401 test2402 test2403 test2404 test2405 test2406 test2407 \ + \ +-test2500 test2501 test2502 test2503 test2504 test2506 \ ++test2500 test2501 test2502 test2503 test2504 test2505 test2506 \ + \ + test2600 test2601 test2602 test2603 test2604 test2605 \ + \ +diff --git a/tests/data/test2505 b/tests/data/test2505 +new file mode 100644 +index 0000000000..8fac590b37 +--- /dev/null ++++ b/tests/data/test2505 +@@ -0,0 +1,67 @@ ++ ++ ++ ++ ++HTTP ++referer ++autoreferer ++ ++ ++ ++# Server-side ++ ++ ++HTTP/1.1 301 redirect ++Date: Tue, 09 Nov 2010 14:49:00 GMT ++Server: server.example.com ++Content-Length: 47 ++Location: %TESTNUMBER0002 ++ ++file contents should appear once for each file ++ ++ ++ ++HTTP/1.1 200 OK ++Date: Tue, 09 Nov 2010 14:49:00 GMT ++Server: server.example.com ++Content-Length: 47 ++ ++file contents should appear once for each file ++ ++ ++ ++# Client-side ++ ++ ++http ++ ++ ++lib%TESTNUMBER ++ ++ ++verify CURLOPT_AUTOREFERER switched off ++ ++ ++http://%HOSTIP:%HTTPPORT ++ ++ ++ ++# Verify data after the test has been "shot" ++ ++ ++GET / HTTP/1.1 ++Host: %HOSTIP:%HTTPPORT ++Accept: */* ++ ++GET /%TESTNUMBER0002 HTTP/1.1 ++Host: %HOSTIP:%HTTPPORT ++Accept: */* ++Referer: http://%HOSTIP:%HTTPPORT/ ++ ++GET / HTTP/1.1 ++Host: %HOSTIP:%HTTPPORT ++Accept: */* ++ ++ ++ ++ +diff --git a/tests/libtest/Makefile.inc b/tests/libtest/Makefile.inc +index 249c6fda87..bdf8a1dbea 100644 +--- a/tests/libtest/Makefile.inc ++++ b/tests/libtest/Makefile.inc +@@ -113,7 +113,7 @@ TESTS_C = \ + lib2023.c lib2032.c lib2082.c \ + lib2301.c lib2302.c lib2304.c lib2306.c lib2308.c lib2309.c \ + lib2402.c lib2404.c lib2405.c \ +- lib2502.c lib2504.c lib2506.c \ ++ lib2502.c lib2504.c lib2505.c lib2506.c \ + lib2700.c \ + lib3010.c lib3025.c lib3026.c lib3027.c lib3033.c lib3034.c \ + lib3100.c lib3101.c lib3102.c lib3103.c lib3104.c lib3105.c \ +diff --git a/tests/libtest/lib2505.c b/tests/libtest/lib2505.c +new file mode 100644 +index 0000000000..c170259874 +--- /dev/null ++++ b/tests/libtest/lib2505.c +@@ -0,0 +1,71 @@ ++/*************************************************************************** ++ * _ _ ____ _ ++ * Project ___| | | | _ \| | ++ * / __| | | | |_) | | ++ * | (__| |_| | _ <| |___ ++ * \___|\___/|_| \_\_____| ++ * ++ * Copyright (C) Linus Nielsen Feltzing ++ * ++ * This software is licensed as described in the file COPYING, which ++ * you should have received as part of this distribution. The terms ++ * are also available at https://curl.se/docs/copyright.html. ++ * ++ * You may opt to use, copy, modify, merge, publish, distribute and/or sell ++ * copies of the Software, and permit persons to whom the Software is ++ * furnished to do so, under the terms of the COPYING file. ++ * ++ * This software is distributed on an "AS IS" basis, WITHOUT WARRANTY OF ANY ++ * KIND, either express or implied. ++ * ++ * SPDX-License-Identifier: curl ++ * ++ ***************************************************************************/ ++#include "first.h" ++ ++#include "testtrace.h" ++ ++static size_t sink2505(char *ptr, size_t size, size_t nmemb, void *ud) ++{ ++ (void)ptr; ++ (void)ud; ++ return size * nmemb; ++} ++ ++static CURLcode test_lib2505(const char *URL) ++{ ++ CURL *curl; ++ CURLcode result = CURLE_OUT_OF_MEMORY; ++ ++ if(curl_global_init(CURL_GLOBAL_ALL) != CURLE_OK) { ++ curl_mfprintf(stderr, "curl_global_init() failed\n"); ++ return TEST_ERR_MAJOR_BAD; ++ } ++ ++ curl = curl_easy_init(); ++ if(!curl) { ++ curl_mfprintf(stderr, "curl_easy_init() failed\n"); ++ curl_global_cleanup(); ++ return TEST_ERR_MAJOR_BAD; ++ } ++ ++ test_setopt(curl, CURLOPT_WRITEFUNCTION, sink2505); ++ test_setopt(curl, CURLOPT_AUTOREFERER, 1L); ++ test_setopt(curl, CURLOPT_FOLLOWLOCATION, 1L); ++ test_setopt(curl, CURLOPT_URL, URL); ++ ++ result = curl_easy_perform(curl); ++ curl_mprintf("req1=%d\n", (int)result); ++ ++ test_setopt(curl, CURLOPT_FOLLOWLOCATION, 0L); ++ test_setopt(curl, CURLOPT_URL, URL); ++ ++ result = curl_easy_perform(curl); ++ curl_mprintf("req2=%d\n", (int)result); ++ ++test_cleanup: ++ curl_easy_cleanup(curl); ++ curl_global_cleanup(); ++ ++ return result; ++} diff --git a/meta/recipes-support/curl/curl/CVE-2026-9546-02.patch b/meta/recipes-support/curl/curl/CVE-2026-9546-02.patch new file mode 100644 index 00000000000..d4842824ff7 --- /dev/null +++ b/meta/recipes-support/curl/curl/CVE-2026-9546-02.patch @@ -0,0 +1,218 @@ +From 862e8a74a84478d82973471b4f49dc2746c1780e Mon Sep 17 00:00:00 2001 +From: Daniel Stenberg +Date: Mon, 25 May 2026 16:43:00 +0200 +Subject: [PATCH] transfer: clear referer when set to NULL + +Verify in test 1649 + +Closes #21741 + +CVE: CVE-2026-9546 +Upstream-Status: Backport [https://github.com/curl/curl/commit/862e8a74a84478d82973471b4f49dc2746c1780e] +Signed-off-by: Peter Marko +--- + lib/transfer.c | 2 + + tests/data/Makefile.am | 2 +- + tests/data/test1649 | 55 +++++++++++++++++++++++ + tests/libtest/Makefile.inc | 2 +- + tests/libtest/lib1649.c | 90 ++++++++++++++++++++++++++++++++++++++ + 5 files changed, 149 insertions(+), 2 deletions(-) + create mode 100644 tests/data/test1649 + create mode 100644 tests/libtest/lib1649.c + +diff --git a/lib/transfer.c b/lib/transfer.c +index 9998d2d..9b55913 100644 +--- a/lib/transfer.c ++++ b/lib/transfer.c +@@ -540,6 +540,8 @@ CURLcode Curl_pretransfer(struct Curl_easy *data) + if(data->set.str[STRING_SET_REFERER]) + Curl_bufref_set(&data->state.referer, data->set.str[STRING_SET_REFERER], + 0, NULL); ++ else ++ Curl_bufref_free(&data->state.referer); + + if(data->state.httpreq == HTTPREQ_PUT) + data->state.infilesize = data->set.filesize; +diff --git a/tests/data/Makefile.am b/tests/data/Makefile.am +index deb635e..7c3766c 100644 +--- a/tests/data/Makefile.am ++++ b/tests/data/Makefile.am +@@ -218,7 +218,7 @@ test1620 test1621 test1622 test1623 test1624 \ + \ + test1630 test1631 test1632 test1633 test1634 test1635 test1636 test1637 \ + \ +-test1640 test1641 test1642 test1643 test1647 test1648 \ ++test1640 test1641 test1642 test1643 test1647 test1648 test1649 \ + \ + test1650 test1651 test1652 test1653 test1654 test1655 test1656 test1657 \ + test1658 \ +diff --git a/tests/data/test1649 b/tests/data/test1649 +new file mode 100644 +index 0000000..d2fd779 +--- /dev/null ++++ b/tests/data/test1649 +@@ -0,0 +1,55 @@ ++ ++ ++ ++ ++HTTP ++Referer ++ ++ ++ ++# Server-side ++ ++ ++# this is returned first since we get no proxy-auth ++ ++HTTP/1.1 200 OK ++Content-Length: 6 ++ ++hello ++ ++ ++ ++ ++# Client-side ++ ++ ++http ++ ++ ++ ++lib%TESTNUMBER ++ ++ ++Set referer first then NULL it ++ ++ ++http://%HOSTIP:%HTTPPORT ++ ++ ++ ++# Verify data after the test has been "shot" ++ ++ ++GET / HTTP/1.1 ++Host: %HOSTIP:%HTTPPORT ++Accept: */* ++Referer: https://secret.example.com/ ++ ++GET / HTTP/1.1 ++Host: %HOSTIP:%HTTPPORT ++Accept: */* ++ ++ ++ ++ ++ +diff --git a/tests/libtest/Makefile.inc b/tests/libtest/Makefile.inc +index 655c32d..d7af26f 100644 +--- a/tests/libtest/Makefile.inc ++++ b/tests/libtest/Makefile.inc +@@ -100,7 +100,7 @@ TESTS_C = \ + lib1582.c lib1588.c \ + lib1591.c lib1592.c lib1593.c lib1594.c lib1597.c \ + lib1598.c lib1599.c \ +- lib1647.c lib1648.c \ ++ lib1647.c lib1648.c lib1649.c \ + lib1662.c \ + lib1900.c lib1901.c lib1902.c lib1903.c lib1905.c lib1906.c lib1907.c \ + lib1908.c lib1910.c lib1911.c lib1912.c lib1913.c \ +diff --git a/tests/libtest/lib1649.c b/tests/libtest/lib1649.c +new file mode 100644 +index 0000000..2dd66c0 +--- /dev/null ++++ b/tests/libtest/lib1649.c +@@ -0,0 +1,90 @@ ++/*************************************************************************** ++ * _ _ ____ _ ++ * Project ___| | | | _ \| | ++ * / __| | | | |_) | | ++ * | (__| |_| | _ <| |___ ++ * \___|\___/|_| \_\_____| ++ * ++ * Copyright (C) Daniel Stenberg, , et al. ++ * ++ * This software is licensed as described in the file COPYING, which ++ * you should have received as part of this distribution. The terms ++ * are also available at https://curl.se/docs/copyright.html. ++ * ++ * You may opt to use, copy, modify, merge, publish, distribute and/or sell ++ * copies of the Software, and permit persons to whom the Software is ++ * furnished to do so, under the terms of the COPYING file. ++ * ++ * This software is distributed on an "AS IS" basis, WITHOUT WARRANTY OF ANY ++ * KIND, either express or implied. ++ * ++ * SPDX-License-Identifier: curl ++ * ++ ***************************************************************************/ ++ ++#include "first.h" ++ ++/* this is meant to pick up the proxy from the environment variable */ ++static CURLcode init1649(CURL *curl, const char *url) ++{ ++ CURLcode result = CURLE_OK; ++ ++ res_easy_setopt(curl, CURLOPT_URL, url); ++ if(result) ++ goto init_failed; ++ ++ res_easy_setopt(curl, CURLOPT_VERBOSE, 1L); ++ if(result) ++ goto init_failed; ++ ++ return CURLE_OK; /* success */ ++ ++init_failed: ++ return result; /* failure */ ++} ++ ++static CURLcode run1649(CURL *curl, const char *url) ++{ ++ CURLcode result = CURLE_OK; ++ ++ result = init1649(curl, url); ++ if(result) ++ return result; ++ ++ return curl_easy_perform(curl); ++} ++ ++static CURLcode test_lib1649(const char *URL) ++{ ++ CURLcode result = CURLE_OK; ++ CURL *curl = NULL; ++ ++ res_global_init(CURL_GLOBAL_ALL); ++ if(result) ++ return result; ++ ++ curl = curl_easy_init(); ++ if(!curl) { ++ curl_mfprintf(stderr, "curl_easy_init() failed\n"); ++ curl_global_cleanup(); ++ return TEST_ERR_MAJOR_BAD; ++ } ++ ++ start_test_timing(); ++ ++ easy_setopt(curl, CURLOPT_REFERER, "https://secret.example.com/"); ++ ++ result = run1649(curl, URL); ++ if(result) ++ goto test_cleanup; ++ ++ /* reset it */ ++ easy_setopt(curl, CURLOPT_REFERER, NULL); ++ ++ result = run1649(curl, URL); ++ ++test_cleanup: ++ curl_easy_cleanup(curl); ++ curl_global_cleanup(); ++ return result; ++} diff --git a/meta/recipes-support/curl/curl_8.19.0.bb b/meta/recipes-support/curl/curl_8.19.0.bb index f6ddc4aa230..fd0fbcea692 100644 --- a/meta/recipes-support/curl/curl_8.19.0.bb +++ b/meta/recipes-support/curl/curl_8.19.0.bb @@ -38,6 +38,8 @@ SRC_URI = " \ file://CVE-2026-13608.patch \ file://CVE-2026-18924.patch \ file://CVE-2026-80229.patch \ + file://CVE-2026-9546-01.patch \ + file://CVE-2026-9546-02.patch \ " SRC_URI:append:class-nativesdk = " \ From patchwork Thu Sep 17 22:06:47 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 98618 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 0AC26C982DB for ; Thu, 17 Sep 2026 22:08:28 +0000 (UTC) Received: from mail-wm2-f13.google.com (mail-wm2-f13.google.com [74.125.225.141]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.1704.1789682904444864849 for ; Thu, 17 Sep 2026 15:08:24 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=ho7AR8lf; spf=pass (domain: smile.fr, ip: 74.125.225.141, mailfrom: yoann.congal@smile.fr) Received: by mail-wm2-f13.google.com with SMTP id 5b1f17b1804b1-49e83a388f8so738115e9.1 for ; Thu, 17 Sep 2026 15:08:24 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1789682903; x=1790287703; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=H6l4IHoIrXc3kKykRGa1qoQ/kdKe1A+8mInMQ+KCFis=; b=ho7AR8lfzwj9gWBeLvQBcuYB07BbZvAKf7GsKufkbb13LTxTZLCHrSuLUzcu29hjTL AEHer2Cg3O8wloK+dkoxH+rw4jf/GRnCnMOO/ZJveg7jV2X/ZiIQ/lL4gjB01CUI0pqk fCb/RO1RjdCuwaysrpIzqn9OG8ycus3GVWo1o= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1789682903; x=1790287703; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=H6l4IHoIrXc3kKykRGa1qoQ/kdKe1A+8mInMQ+KCFis=; b=CznY7QDs35C8i+8WAWHINda4dtMSTDWoE/h8szTSPw1f1HCkzroSwKH8JDqWq+pRxu tXa/IfrTfmqjkiuk0BTICZgFdJqzopO8Rjn6U1zcWFbnr4/WU7U+L0EQQLu4O4C1VW2Y JXX65J9f0zrIE5Bh78mMCtyMFsXMp2HYbM9qrlUtmyAOiB8xgwY02wrmHIDdugDXzNRI pz81ZIRETrYpKfUKv6+InzjIsVqvo5QPRgNlu0NkuQ/L4xpYex4QDYogW38gJM+uJNW+ qZdl2OjWfSGjXbYK+lhdxmJWPElfY3wjvqVlSPFPi8+ilI1OsQ+jcPE0QhVIJKHTlLW8 L4tA== X-Gm-Message-State: AFuF++m93rRFpu7Nr0pEu0kbfHeEbJXfptOguZYg/1Cga7DIeS+IOBmg PxYGS0vieof4ijvEl6+rvKiRMePYedS0vcbMCVj74s1q4KnpD7st04quCDKiiGunylyoiRx7Lq/ 6iJ9Yg9E= X-Gm-Gg: AYBFou2As4ocwpreR4oUOSJC3Brnr4YRZ0Dytb1jmI6YLIvsps6/vexoS4zZDctOaQQ tJ72UXsQ9wKbj8Bg6Q6g5LskzEv6HvPHzFuScFoFtDUazuQjgR55zxc9+ZvTITGy1BzdVq6e/KQ yWy4UUh3og3/g+oi1XsNT413LR1kgX3wa8NjCX6vBHG6ShzR6reWlHiQoYSNn2MDpXnKoYxo+mR B05gkj3Xt/ocLVWz8dh1Fx/EezLnQNJIiSk9Rg/CVJ9LQJd3vUzhSX2hWHKCjJXwrrmbtH2xUeV qq2wSrqNLmQab0pdghPKpBN5flcfbrOCzB5buTaxOEIaIsFU7rzok3dbea7nLH84NKdySvIjepN yVAk5qy7zYjiDUlghPllNXsrJLjFDbkfNNqeNowZMekkzo6XYuuQ/NKbp8pPoq8to33XQWH1y7o Aa7wzYGgHai9vv1pLuIbFzGRJvByhcaggeRfiOpdzh/3v0S1kJYa5HdbwhTKzOn5ZNGBP8DvQWc c6QiS7/Q7wg79o655FCQn8iItrHvjWmGeBG8uTX4DlZeqv/yLftD/gwEfIWfaMI0AQ+/cIcWB8= X-Received: by 2002:a05:600c:a14:b0:49d:1e09:694a with SMTP id 5b1f17b1804b1-49fc568f869mr3149405e9.11.1789682902731; Thu, 17 Sep 2026 15:08:22 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-49fc471b9a2sm8984075e9.0.2026.09.17.15.08.22 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Thu, 17 Sep 2026 15:08:22 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][wrynose 62/79] libpcap: Fix CVE-2026-0799 Date: Fri, 18 Sep 2026 00:06:47 +0200 Message-ID: X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Thu, 17 Sep 2026 22:08:28 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/246157 From: Jaipaul Cheernam NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-0799 Upstream-commit: https://github.com/the-tcpdump-group/libpcap/commit/48e8960a7108e9e828f9d7bdc7e97bdab841aec7 Signed-off-by: Jaipaul Cheernam Signed-off-by: Yoann Congal --- .../libpcap/libpcap/01-CVE-2026-0799.patch | 67 +++++++++++++++++++ .../libpcap/libpcap_1.10.6.bb | 1 + 2 files changed, 68 insertions(+) create mode 100644 meta/recipes-connectivity/libpcap/libpcap/01-CVE-2026-0799.patch diff --git a/meta/recipes-connectivity/libpcap/libpcap/01-CVE-2026-0799.patch b/meta/recipes-connectivity/libpcap/libpcap/01-CVE-2026-0799.patch new file mode 100644 index 00000000000..7c40faa608d --- /dev/null +++ b/meta/recipes-connectivity/libpcap/libpcap/01-CVE-2026-0799.patch @@ -0,0 +1,67 @@ +From 3c55fdefa576c7a06feab86a9e4341be414de49b Mon Sep 17 00:00:00 2001 +From: Denis Ovsienko +Date: Thu, 30 Jul 2026 13:33:41 +0100 +Subject: [PATCH] CVE-2026-0799: Access M[] safely in the BPF interpreter. + +Include Security identified and reported this problem as a potential +vulnerability in 2018 (case reference "I7"). Their work was sponsored +by Mozilla under the Secure Open Source program. The vulnerability has +been independently confirmed only recently. + +The current revision of pcapint_filter_with_aux_data() can, but does not +check whether a scratch memory register index is valid in the "ld M[k]", +"ldx M[k]", "st M[k]" and "stx M[k]" BPF instructions, and assumes this +is always the case. This holds for programs that have been generated or +validated by libpcap. + +However, this does not necessarily hold for programs that come via +pcap_offline_filter() or [deprecated] bpf_filter() from an external +source and have not been explicitly validated. If the interpreter +executes such a program with an invalid index, it will read/write the +process memory at arbitrary locations starting at the current stack +frame. Depending on the address, the memory layout and the OS, this can +result in stack buffer overflow, SIGSEGV, SIGBUS or other effects. To +fix this, in the interpreter reject the packet if the index is invalid. + +(backported from commit 569f8fd3524192acbabf93c9cd704471bb38f84a) + +(cherry picked from commit 48e8960a7108e9e828f9d7bdc7e97bdab841aec7) + +Notes on backporting to 1.10.6: + - The upstream CHANGES/changelog hunk is not backported. + +Upstream-Status: Backport [https://github.com/the-tcpdump-group/libpcap/commit/48e8960a7108e9e828f9d7bdc7e97bdab841aec7] +CVE: CVE-2026-0799 +Signed-off-by: Jaipaul Cheernam +--- +diff --git a/bpf_filter.c b/bpf_filter.c +index 9b899bbb..510dbd9c 100644 +--- a/bpf_filter.c ++++ b/bpf_filter.c +@@ -217,18 +217,26 @@ DIAG_ON_DEFAULT_ONLY_SWITCH + continue; + + case BPF_LD|BPF_MEM: ++ if (pc->k >= BPF_MEMWORDS) ++ return 0; + A = mem[pc->k]; + continue; + + case BPF_LDX|BPF_MEM: ++ if (pc->k >= BPF_MEMWORDS) ++ return 0; + X = mem[pc->k]; + continue; + + case BPF_ST: ++ if (pc->k >= BPF_MEMWORDS) ++ return 0; + mem[pc->k] = A; + continue; + + case BPF_STX: ++ if (pc->k >= BPF_MEMWORDS) ++ return 0; + mem[pc->k] = X; + continue; + diff --git a/meta/recipes-connectivity/libpcap/libpcap_1.10.6.bb b/meta/recipes-connectivity/libpcap/libpcap_1.10.6.bb index d381a4eb2fe..265c46e3bd0 100644 --- a/meta/recipes-connectivity/libpcap/libpcap_1.10.6.bb +++ b/meta/recipes-connectivity/libpcap/libpcap_1.10.6.bb @@ -12,6 +12,7 @@ DEPENDS = "flex-native bison-native" SRC_URI = "https://www.tcpdump.org/release/${BP}.tar.xz \ file://0001-Fix-error-messages-about-32-bit-integer-overflow.patch \ + file://01-CVE-2026-0799.patch \ " SRC_URI[sha256sum] = "ec97d1206bdd19cb6bdd043eaa9f0037aa732262ec68e070fd7c7b5f834d5dfc" From patchwork Thu Sep 17 22:06:48 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 98621 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 00347C982DA for ; Thu, 17 Sep 2026 22:08:28 +0000 (UTC) Received: from mail-wm2-f12.google.com (mail-wm2-f12.google.com [74.125.225.140]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.1601.1789682905204942546 for ; Thu, 17 Sep 2026 15:08:25 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=JbJEKRDa; spf=pass (domain: smile.fr, ip: 74.125.225.140, mailfrom: yoann.congal@smile.fr) Received: by mail-wm2-f12.google.com with SMTP id 5b1f17b1804b1-49b912d37b5so688105e9.2 for ; Thu, 17 Sep 2026 15:08:24 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1789682903; x=1790287703; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=87IQbpy1xCaNO801R4JFoPhJQXuVT/8yHgZbHcuOPfU=; b=JbJEKRDaljlYrbJBcGwrsXXfdR3IAddN4kQ2CWhpRFL1Bz8NEjTJA63oVsPWCuRxIO u8rfrhagvRBfJtUQs+2lzECAHVkIvkvlw5SlvX4YgeF3JGa/vp+QTXO4NRXBSKhjz/tn N7ClZzY3/Ct40OKAc2ft74N/bmlWdzGwg99xQ= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1789682903; x=1790287703; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=87IQbpy1xCaNO801R4JFoPhJQXuVT/8yHgZbHcuOPfU=; b=JN3PL2dovdO1KUtZAqK0gCns0EPKQvnbWS8WgWr5YvZTGG9q8WCEmpKADJzMNTfj0P clBBYkuCOTqDWhhK4EAO1EFO0FD8s/c/u6CJLf+pjtgqhNNRgg+7WsBzTAqVIA7SmDe5 4P1FsLmF10WoOP9HHjAa2aYAlV3hiY4LhuWXN/O15LzxSWoa30biJonYiIzbfbyizNNn FsazybRg4r7iWDaLqLltcrp4BRmWWMpddWtrvMmesNWMOXMTyhLcfH5N2BBkb7Z7/xv3 aHEB1HxU6dYa8KsTr4oLqlSL546zyPBvY33Auq/CyRNEr02eEMLZd+/AqP2OZQih2tni ccAA== X-Gm-Message-State: AFuF++kYOQcPdVagFb+j8pgp3zTKWYDclSkhKWh/YxYoHZ4IphDf3uWv UQZsMkQIlAwA14tivaA+E84L76EQ6mqZcfAvLC0/tpeUHNo7vNh3Cz3TjtmSB+xrTeqDFT5jz7+ QtT2TmX0= X-Gm-Gg: AYBFou3DbtWqjFATS5IQGcSq1rilTd1ye5FYv3JTBTVoslUPdETcgG7BhIRwT/4ooKy Dp3RVabltQ6NTOmqEG12CQNlhokFfA8VpV62XNAi3OQsKCCRNvkClCWv9OnF/zGn/Q8Da1l+Irs xoYkeLsqhvjIyp5FGMmBZ6I3K0A+VKA+or3YNOrttUJCa5gA9DYum647UHDZdIWZfsf5gM9cWUi PmFBMQT+C+MxgUrPKTfAPoghgSdjFQ+jmhKe2mWu0+qUWFl5pP6iCKlOa/hocPgkICjGW/yzwHD 4ZEPi4luQ3F0xT04b6W7n2UkiMuZbmvrNN5G4GKwYWJGgPhiwo2TXpHSR64b4JzRzpn9aipSMbz TUmmycCk8TbZaylpLA3weqIzQ3G9TVNVpjUBBY2HJNs73lDiUq2HJz4LmzoVopRHHbX5mZLHgTl sRlJFXAisNdeIWfPyudlPwrxYb7NsHZ+Pep1mRpVs9iY21VdtGJ29MOgzfCJ8T4jugqQDLLWRBE 3z7l30aylEw0fADlYbx9VI/okLkZxFFPG/vPWltWL6cDS0cZkWZDUn0dyk7+TJOzfUE/kNSCvY= X-Received: by 2002:a05:600c:3e0b:b0:49f:bc0d:2e9 with SMTP id 5b1f17b1804b1-49fc55954acmr8097805e9.0.1789682903210; Thu, 17 Sep 2026 15:08:23 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-49fc471b9a2sm8984075e9.0.2026.09.17.15.08.22 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Thu, 17 Sep 2026 15:08:22 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][wrynose 63/79] libpcap: Fix CVE-2026-31912 Date: Fri, 18 Sep 2026 00:06:48 +0200 Message-ID: <39828b678d7d8cc19af941ff5c3ffd93e9e15a24.1789681419.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Thu, 17 Sep 2026 22:08:27 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/246158 From: Jaipaul Cheernam NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-31912 Upstream-commit: https://github.com/the-tcpdump-group/libpcap/commit/d3f358d3cffbe1ecb94d5284b3e81f052a0adcb9 Signed-off-by: Jaipaul Cheernam Signed-off-by: Yoann Congal --- .../libpcap/libpcap/02-CVE-2026-31912.patch | 597 ++++++++++++++++++ .../libpcap/libpcap_1.10.6.bb | 1 + 2 files changed, 598 insertions(+) create mode 100644 meta/recipes-connectivity/libpcap/libpcap/02-CVE-2026-31912.patch diff --git a/meta/recipes-connectivity/libpcap/libpcap/02-CVE-2026-31912.patch b/meta/recipes-connectivity/libpcap/libpcap/02-CVE-2026-31912.patch new file mode 100644 index 00000000000..ceae734ff7b --- /dev/null +++ b/meta/recipes-connectivity/libpcap/libpcap/02-CVE-2026-31912.patch @@ -0,0 +1,597 @@ +From 09e04074ddfbca5fa33693c6e2d4f01a74857f65 Mon Sep 17 00:00:00 2001 +From: Denis Ovsienko +Date: Thu, 30 Jul 2026 13:33:55 +0100 +Subject: [PATCH] CVE-2026-31912: Mind the program bounds in + pcap_offline_filter(). + +The current revision of pcapint_filter_with_aux_data() does not know the +number of instructions in the filter program, it assumes the program +counter always remains within the bounds of the provided filter program +and always reaches a return instruction. This holds for programs that +have been generated or validated by libpcap. + +However, this does not necessarily hold for programs that come from an +external source via pcap_offline_filter() or [deprecated] bpf_filter() +and have not been explicitly validated. If the interpreter executes +such a program and advances the program counter beyond the last +instruction, it will be interpreting memory space after the filter +program as BPF instructions, which in the current implementation will +eventually cause either abort() (another commit addresses that) or +SIGSEGV. + +To fix the latter problem, in pcapint_filter_with_aux_data() add a +parameter for the number of instructions in the program and reject the +packet as soon as (or just before) the program counter goes out of +bounds. Update all incoming code paths to specify the length; also in +pcap_offline_filter(3PCAP) make it clear the function now requires the +'bf_len' member to be set correctly and uses it. + +(backported from commit d1209988c74dd9330659898d3b676ee6bbe1c551) + +(cherry picked from commit d3f358d3cffbe1ecb94d5284b3e81f052a0adcb9) + +Upstream-Status: Backport [https://github.com/the-tcpdump-group/libpcap/commit/d3f358d3cffbe1ecb94d5284b3e81f052a0adcb9] +CVE: CVE-2026-31912 + +Notes on backporting to 1.10.6: + - Adjusted the pcapint_filter() call sites in pcap-dag.c, pcap-netmap.c and + pcap-snf.c to the 1.10.6 code base. In 1.10.7 these were already touched by + the unrelated "low snaplen" fixes (commits d5192db3, fb87fdeb, b0caefe8), + which are not part of this CVE and are not backported here; only the new + bf_len argument is added to each call. + - In bpf_filter.c the scratch-memory-store zero-initialisation and the removal + of the stray BPF_S_ANC_* enum (1.10.7-only cleanups) are not present in + 1.10.6, so only the new pc0 declaration and bounds checks from this commit + are added. + - The upstream CHANGES/changelog hunk is not backported. + +Signed-off-by: Jaipaul Cheernam +--- +diff --git a/bpf_filter.c b/bpf_filter.c +index 510dbd9c..4f9adeea 100644 +--- a/bpf_filter.c ++++ b/bpf_filter.c +@@ -70,6 +70,24 @@ enum { + BPF_S_ANC_VLAN_TAG_PRESENT, + }; + ++/* ++ * Kernel BPF implementations tend to define BPF_MAXINSNS to 512 or 4096, the ++ * userland interpreter in libpcap is meant to support much longer filter ++ * programs. In the latter case it is important that BPF_MAXINSNS does not ++ * interfere with the safety checks in the validator and the interpreter: ++ * (BPF_MAXINSNS + UINT8_MAX) * sizeof(struct bpf_insn) < UINT32_MAX ++ * It makes the most sense to be able to interpret as many instructions as ++ * pcap_compile() can produce, without optimization, for a valid filter ++ * expression before it consumes as much memory as the current definitions of ++ * NCHUNKS and CHUNKSIZE() allow. For some expressions this can be almost ++ * 1.53 million instructions on a 64-bit machine and twice as many on a 32-bit ++ * machine. ++ */ ++#ifdef BPF_MAXINSNS ++#undef BPF_MAXINSNS ++#endif ++#define BPF_MAXINSNS 3060000U ++ + /* + * Execute the filter program starting at pc on the packet p + * wirelen is the length of the original packet +@@ -84,12 +102,14 @@ enum { + */ + #if defined(SKF_AD_VLAN_TAG_PRESENT) + u_int +-pcapint_filter_with_aux_data(const struct bpf_insn *pc, const u_char *p, +- u_int wirelen, u_int buflen, const struct pcap_bpf_aux_data *aux_data) ++pcapint_filter_with_aux_data(const struct bpf_insn *pc, const u_int proglen, ++ const u_char *p, const u_int wirelen, const u_int buflen, ++ const struct pcap_bpf_aux_data *aux_data) + #else + u_int +-pcapint_filter_with_aux_data(const struct bpf_insn *pc, const u_char *p, +- u_int wirelen, u_int buflen, const struct pcap_bpf_aux_data *aux_data _U_) ++pcapint_filter_with_aux_data(const struct bpf_insn *pc, const u_int proglen, ++ const u_char *p, const u_int wirelen, const u_int buflen, ++ const struct pcap_bpf_aux_data *aux_data _U_) + #endif + { + register uint32_t A, X; +@@ -99,13 +119,36 @@ pcapint_filter_with_aux_data(const struct bpf_insn *pc, const u_char *p, + if (pc == 0) + /* + * No filter means accept all. ++ * In this case the value of 'proglen' is irrelevant. + */ + return (u_int)-1; ++ if (proglen < 1 || proglen > BPF_MAXINSNS) ++ return 0; ++ ++ /* ++ * Require the current instruction pointer not to overflow for both the ++ * filter program (where the pointer will be dereferenced) and an ++ * immediately following margin (where it will be not). So long as the ++ * margin is large enough to represent the destination of any single ++ * conditional [forward] jump from within the filter program, a single ++ * guard prevents all filter program over-read attempts that result ++ * from the program running out of instructions before a BPF_RET or a ++ * conditional jump directing the interpreter beyond the program end. ++ * Unconditional jumps mean a larger problem space, which the BPF_JA ++ * case below addresses separately. ++ */ ++ const struct bpf_insn *pcend = pc + proglen; ++ if (pcend + UINT8_MAX < pc) ++ return 0; ++ + A = 0; + X = 0; ++ const struct bpf_insn *pc0 = pc; + --pc; + for (;;) { + ++pc; ++ if (pc >= pcend) ++ return 0; + switch (pc->code) { + + default: +@@ -241,6 +284,40 @@ DIAG_ON_DEFAULT_ONLY_SWITCH + continue; + + case BPF_JMP|BPF_JA: ++ /* ++ * The pointer (pc) decrements and increments in units ++ * of sizeof(struct bpf_insn) == 8 bytes. The number ++ * of units is in the [INT32_MIN, INT32_MAX] interval, ++ * hence the result can point before the beginning or ++ * beyond the end of the filter program and can under- ++ * or overflow; also on 32-bit architectures it can ++ * under- or overflow more than once and can test ++ * negative for underflow, overflow and out-of-range ++ * conditions after under- or overflowing at least ++ * once. ++ * ++ * However, it has been verified above that the program ++ * length is sufficiently small and the pointer does ++ * not wrap within the bounds of the filter program, so ++ * there is a one-to-one correspondence between BPF ++ * program counter values [0, proglen) and all valid ++ * values of the pointer. In other words, after this ++ * unconditional jump the pointer arithmetic result ++ * will be valid iff BPF program counter value will be ++ * valid. For the latter problem the solution is ++ * almost the same as in the validator. ++ * ++ * The main difference is that here the current value ++ * of BPF program counter is not a 32-bit unsigned ++ * variable, but a ptrdiff_t expression, which is ++ * 64-bit signed on 64-bit architectures and 32-bit ++ * signed on 32-bit architectures. However, the cast ++ * to 32-bit unsigned is safe in both cases because: ++ * pc0 <= pc < pc0 + proglen, therefore: ++ * 0 <= pc - pc0 < proglen <= BPF_MAXINSNS < INT32_MAX ++ */ ++ if ((bpf_u_int32)(pc - pc0) + 1 + pc->k >= proglen) ++ return 0; + /* + * XXX - we currently implement "ip6 protochain" + * with backward jumps, so sign-extend pc->k. +@@ -394,10 +471,10 @@ DIAG_ON_DEFAULT_ONLY_SWITCH + } + + u_int +-pcapint_filter(const struct bpf_insn *pc, const u_char *p, u_int wirelen, +- u_int buflen) ++pcapint_filter(const struct bpf_insn *pc, const u_int proglen, const u_char *p, ++ u_int wirelen, u_int buflen) + { +- return pcapint_filter_with_aux_data(pc, p, wirelen, buflen, NULL); ++ return pcapint_filter_with_aux_data(pc, proglen, p, wirelen, buflen, NULL); + } + + /* +@@ -417,7 +494,7 @@ pcapint_validate_filter(const struct bpf_insn *f, int len) + u_int i, from; + const struct bpf_insn *p; + +- if (len < 1) ++ if (len < 1 || (u_int)len > BPF_MAXINSNS || f + len < f) + return 0; + + for (i = 0; i < (u_int)len; ++i) { +@@ -483,33 +560,45 @@ pcapint_validate_filter(const struct bpf_insn *f, int len) + case BPF_JMP: + /* + * Check that jumps are within the code block, +- * and that unconditional branches don't go +- * backwards as a result of an overflow. ++ * regardless of the direction. libpcap uses ++ * backward jumps to implement the "protochain" ++ * primitive. All offsets that mean a backward ++ * jump in libpcap (whether in-range or not) in ++ * kernel BPF implementations mean out-of-range ++ * or overflow forward jumps -- kernel ++ * implementations must reject that. ++ * + * Unconditional branches have a 32-bit offset, + * so they could overflow; we check to make + * sure they don't. Conditional branches have + * an 8-bit offset, and the from address is <= +- * BPF_MAXINSNS, and we assume that BPF_MAXINSNS ++ * BPF_MAXINSNS, and we know that BPF_MAXINSNS + * is sufficiently small that adding 255 to it + * won't overflow. + * + * We know that len is <= BPF_MAXINSNS, and we +- * assume that BPF_MAXINSNS is < the maximum size ++ * know that BPF_MAXINSNS is < the maximum value + * of a u_int, so that i + 1 doesn't overflow. +- * +- * For userland, we don't know that the from +- * or len are <= BPF_MAXINSNS, but we know that +- * from <= len, and, except on a 64-bit system, +- * it's unlikely that len, if it truly reflects +- * the size of the program we've been handed, +- * will be anywhere near the maximum size of +- * a u_int. We also don't check for backward +- * branches, as we currently support them in +- * userland for the protochain operation. + */ + from = i + 1; + switch (BPF_OP(p->code)) { + case BPF_JA: ++ /* ++ * So long as both 'from' and bpf_insn.k are ++ * 32-bit unsigned, this check rejects any jump ++ * offset that points outside of the valid BPF ++ * address space of the filter program no ++ * matter whether signed interpretation of the ++ * offset is positive or negative. ++ * ++ * Note that this condition is necessary, but ++ * not sufficient to get correct results from ++ * respective pointer arithmetic in the process ++ * address space. Other necessary conditions ++ * are that BPF_MAXINSNS is correctly defined ++ * and enforced, and that the pointer does not ++ * overflow. ++ */ + if (from + p->k >= (u_int)len) + return 0; + break; +@@ -537,12 +626,14 @@ pcapint_validate_filter(const struct bpf_insn *f, int len) + + /* + * Exported because older versions of libpcap exported them. ++ * This function is deprecated and unsafe, use pcap_offline_filter() instead. + */ + u_int + bpf_filter(const struct bpf_insn *pc, const u_char *p, u_int wirelen, + u_int buflen) + { +- return pcapint_filter(pc, p, wirelen, buflen); ++ // The actual length of the filter program is not known. ++ return pcapint_filter(pc, BPF_MAXINSNS, p, wirelen, buflen); + } + + int +diff --git a/dlpisubs.c b/dlpisubs.c +index d4310de5..19934059 100644 +--- a/dlpisubs.c ++++ b/dlpisubs.c +@@ -203,7 +203,8 @@ pcap_process_pkts(pcap_t *p, pcap_handler callback, u_char *user, + bufp += caplen; + #endif + ++pd->stat.ps_recv; +- if (pcapint_filter(p->fcode.bf_insns, pk, origlen, caplen)) { ++ if (pcapint_filter(p->fcode.bf_insns, p->fcode.bf_len, ++ pk, origlen, caplen)) { + #ifdef HAVE_SYS_BUFMOD_H + pkthdr.ts.tv_sec = sbp->sbh_timestamp.tv_sec; + pkthdr.ts.tv_usec = sbp->sbh_timestamp.tv_usec; +diff --git a/pcap-bpf.c b/pcap-bpf.c +index 49bb273d..13f83930 100644 +--- a/pcap-bpf.c ++++ b/pcap-bpf.c +@@ -1372,7 +1372,8 @@ pcap_read_bpf(pcap_t *p, int cnt, pcap_handler callback, u_char *user) + #endif + */ + if (pb->filtering_in_kernel || +- pcapint_filter(p->fcode.bf_insns, datap, bhp->bh_datalen, caplen)) { ++ pcapint_filter(p->fcode.bf_insns, p->fcode.bf_len, ++ datap, bhp->bh_datalen, caplen)) { + struct pcap_pkthdr pkthdr; + #ifdef BIOCSTSTAMP + struct bintime bt; +diff --git a/pcap-bt-linux.c b/pcap-bt-linux.c +index 2fc51665..9f464e70 100644 +--- a/pcap-bt-linux.c ++++ b/pcap-bt-linux.c +@@ -396,7 +396,8 @@ DIAG_ON_SIGN_COMPARE + pkth.caplen+=sizeof(pcap_bluetooth_h4_header); + pkth.len = pkth.caplen; + if (handle->fcode.bf_insns == NULL || +- pcapint_filter(handle->fcode.bf_insns, pktd, pkth.len, pkth.caplen)) { ++ pcapint_filter(handle->fcode.bf_insns, handle->fcode.bf_len, ++ pktd, pkth.len, pkth.caplen)) { + callback(user, &pkth, pktd); + return 1; + } +diff --git a/pcap-bt-monitor-linux.c b/pcap-bt-monitor-linux.c +index dfba8051..cfe52498 100644 +--- a/pcap-bt-monitor-linux.c ++++ b/pcap-bt-monitor-linux.c +@@ -153,7 +153,8 @@ DIAG_ON_SIGN_COMPARE + bthdr->opcode = htons(hdr.opcode); + + if (handle->fcode.bf_insns == NULL || +- pcapint_filter(handle->fcode.bf_insns, pktd, pkth.len, pkth.caplen)) { ++ pcapint_filter(handle->fcode.bf_insns, handle->fcode.bf_len, ++ pktd, pkth.len, pkth.caplen)) { + callback(user, &pkth, pktd); + return 1; + } +diff --git a/pcap-dag.c b/pcap-dag.c +index 5ce15dd5..334a970c 100644 +--- a/pcap-dag.c ++++ b/pcap-dag.c +@@ -666,7 +666,9 @@ dag_read(pcap_t *p, int cnt, pcap_handler callback, u_char *user) + caplen = p->snapshot; + + /* Run the packet filter if there is one. */ +- if ((p->fcode.bf_insns == NULL) || pcapint_filter(p->fcode.bf_insns, dp, packet_len, caplen)) { ++ if ((p->fcode.bf_insns == NULL) || ++ pcapint_filter(p->fcode.bf_insns, p->fcode.bf_len, ++ dp, packet_len, caplen)) { + + /* convert between timestamp formats */ + register unsigned long long ts; +diff --git a/pcap-dbus.c b/pcap-dbus.c +index d29fb81d..b0f30f6f 100644 +--- a/pcap-dbus.c ++++ b/pcap-dbus.c +@@ -90,7 +90,8 @@ dbus_read(pcap_t *handle, int max_packets _U_, pcap_handler callback, u_char *us + + gettimeofday(&pkth.ts, NULL); + if (handle->fcode.bf_insns == NULL || +- pcapint_filter(handle->fcode.bf_insns, (u_char *)raw_msg, pkth.len, pkth.caplen)) { ++ pcapint_filter(handle->fcode.bf_insns, handle->fcode.bf_len, ++ (u_char *)raw_msg, pkth.len, pkth.caplen)) { + handlep->packets_read++; + callback(user, &pkth, (u_char *)raw_msg); + count++; +diff --git a/pcap-dpdk.c b/pcap-dpdk.c +index c78724e5..4fb8ffea 100644 +--- a/pcap-dpdk.c ++++ b/pcap-dpdk.c +@@ -405,7 +405,9 @@ static int pcap_dpdk_dispatch(pcap_t *p, int max_cnt, pcap_handler cb, u_char *c + + } + if (bp){ +- if (p->fcode.bf_insns==NULL || pcapint_filter(p->fcode.bf_insns, bp, pcap_header.len, pcap_header.caplen)){ ++ if (p->fcode.bf_insns==NULL || ++ pcapint_filter(p->fcode.bf_insns, p->fcode.bf_len, ++ bp, pcap_header.len, pcap_header.caplen)){ + cb(cb_arg, &pcap_header, bp); + }else{ + pd->bpf_drop++; +diff --git a/pcap-haiku.c b/pcap-haiku.c +index 609f585a..7b994fee 100644 +--- a/pcap-haiku.c ++++ b/pcap-haiku.c +@@ -112,8 +112,8 @@ pcap_read_haiku(pcap_t* handle, int maxPackets _U_, pcap_handler callback, + if (handle->fcode.bf_insns) { + // NB: pcapint_filter() takes the wire length and the captured + // length, not the snapshot length of the pcap_t handle. +- if (pcapint_filter(handle->fcode.bf_insns, buffer, wireLength, +- captureLength) == 0) ++ if (pcapint_filter(handle->fcode.bf_insns, handle->fcode.bf_len, ++ buffer, wireLength, captureLength) == 0) + goto drop; + } + +diff --git a/pcap-int.h b/pcap-int.h +index ce0ac698..3d466946 100644 +--- a/pcap-int.h ++++ b/pcap-int.h +@@ -579,13 +579,15 @@ struct pcap_bpf_aux_data { + * Filtering routine that takes the auxiliary data as an additional + * argument. + */ +-u_int pcapint_filter_with_aux_data(const struct bpf_insn *, +- const u_char *, u_int, u_int, const struct pcap_bpf_aux_data *); ++u_int pcapint_filter_with_aux_data(const struct bpf_insn *, const u_int, ++ const u_char *, const u_int, const u_int, ++ const struct pcap_bpf_aux_data *); + + /* + * Filtering routine that doesn't. + */ +-u_int pcapint_filter(const struct bpf_insn *, const u_char *, u_int, u_int); ++u_int pcapint_filter(const struct bpf_insn *, const u_int, const u_char *, ++ u_int, u_int); + + /* + * Routine to validate a BPF program. +diff --git a/pcap-linux.c b/pcap-linux.c +index 20802e43..7e04a041 100644 +--- a/pcap-linux.c ++++ b/pcap-linux.c +@@ -4279,6 +4279,7 @@ static int pcap_handle_packet_mmap( + aux_data.vlan_tag = tp_vlan_tci & 0x0fff; + + if (pcapint_filter_with_aux_data(handle->fcode.bf_insns, ++ handle->fcode.bf_len, + bp, + tp_len, + snaplen, +diff --git a/pcap-netfilter-linux.c b/pcap-netfilter-linux.c +index 344bae47..ade53ea6 100644 +--- a/pcap-netfilter-linux.c ++++ b/pcap-netfilter-linux.c +@@ -257,8 +257,8 @@ netfilter_read_linux(pcap_t *handle, int max_packets, pcap_handler callback, u_c + + gettimeofday(&pkth.ts, NULL); + if (handle->fcode.bf_insns == NULL || +- pcapint_filter(handle->fcode.bf_insns, payload, pkth.len, pkth.caplen)) +- { ++ pcapint_filter(handle->fcode.bf_insns, handle->fcode.bf_len, ++ payload, pkth.len, pkth.caplen)) { + handlep->packets_read++; + callback(user, &pkth, payload); + count++; +diff --git a/pcap-netmap.c b/pcap-netmap.c +index f17f36ca..925f677f 100644 +--- a/pcap-netmap.c ++++ b/pcap-netmap.c +@@ -79,7 +79,8 @@ pcap_netmap_filter(u_char *arg, struct pcap_pkthdr *h, const u_char *buf) + const struct bpf_insn *pc = p->fcode.bf_insns; + + ++pn->rx_pkts; +- if (pc == NULL || pcapint_filter(pc, buf, h->len, h->caplen)) ++ if (pc == NULL || ++ pcapint_filter(pc, p->fcode.bf_len, buf, h->len, h->caplen)) + pn->cb(pn->cb_arg, h, buf); + } + +diff --git a/pcap-npf.c b/pcap-npf.c +index f638bd80..38e985bd 100644 +--- a/pcap-npf.c ++++ b/pcap-npf.c +@@ -720,7 +720,8 @@ pcap_read_npf(pcap_t *p, int cnt, pcap_handler callback, u_char *user) + */ + if (pw->filtering_in_kernel || + p->fcode.bf_insns == NULL || +- pcapint_filter(p->fcode.bf_insns, datap, bhp->bh_datalen, caplen)) { ++ pcapint_filter(p->fcode.bf_insns, p->fcode.bf_len, ++ datap, bhp->bh_datalen, caplen)) { + #ifdef ENABLE_REMOTE + switch (p->rmt_samp.method) { + +diff --git a/pcap-rdmasniff.c b/pcap-rdmasniff.c +index fd6d6fa6..5f15d4c5 100644 +--- a/pcap-rdmasniff.c ++++ b/pcap-rdmasniff.c +@@ -170,7 +170,8 @@ rdmasniff_read(pcap_t *handle, int max_packets, pcap_handler callback, u_char *u + pktd = (u_char *) handle->buffer + wc.wr_id * RDMASNIFF_RECEIVE_SIZE; + + if (handle->fcode.bf_insns == NULL || +- pcapint_filter(handle->fcode.bf_insns, pktd, pkth.len, pkth.caplen)) { ++ pcapint_filter(handle->fcode.bf_insns, handle->fcode.bf_len, ++ pktd, pkth.len, pkth.caplen)) { + callback(user, &pkth, pktd); + ++priv->packets_recv; + ++count; +diff --git a/pcap-snf.c b/pcap-snf.c +index d08275ac..8a57eadd 100644 +--- a/pcap-snf.c ++++ b/pcap-snf.c +@@ -190,7 +190,8 @@ snf_read(pcap_t *p, int cnt, pcap_handler callback, u_char *user) + caplen = p->snapshot; + + if ((p->fcode.bf_insns == NULL) || +- pcapint_filter(p->fcode.bf_insns, req.pkt_addr, req.length, caplen)) { ++ pcapint_filter(p->fcode.bf_insns, p->fcode.bf_len, ++ req.pkt_addr, req.length, caplen)) { + hdr.ts = snf_timestamp_to_timeval(req.timestamp, p->opt.tstamp_precision); + hdr.caplen = caplen; + hdr.len = req.length; +diff --git a/pcap-usb-linux.c b/pcap-usb-linux.c +index bc39b1db..d219721a 100644 +--- a/pcap-usb-linux.c ++++ b/pcap-usb-linux.c +@@ -733,8 +733,8 @@ usb_read_linux_bin(pcap_t *handle, int max_packets _U_, pcap_handler callback, u + pkth.ts.tv_usec = info.hdr->ts_usec; + + if (handle->fcode.bf_insns == NULL || +- pcapint_filter(handle->fcode.bf_insns, handle->buffer, +- pkth.len, pkth.caplen)) { ++ pcapint_filter(handle->fcode.bf_insns, handle->fcode.bf_len, ++ handle->buffer, pkth.len, pkth.caplen)) { + handlep->packets_read++; + callback(user, &pkth, handle->buffer); + return 1; +@@ -921,8 +921,8 @@ usb_read_linux_mmap(pcap_t *handle, int max_packets, pcap_handler callback, u_ch + pkth.ts.tv_usec = hdr->ts_usec; + + if (handle->fcode.bf_insns == NULL || +- pcapint_filter(handle->fcode.bf_insns, (u_char*) hdr, +- pkth.len, pkth.caplen)) { ++ pcapint_filter(handle->fcode.bf_insns, handle->fcode.bf_len, ++ (u_char*) hdr, pkth.len, pkth.caplen)) { + handlep->packets_read++; + callback(user, &pkth, (u_char*) hdr); + packets++; +diff --git a/pcap.c b/pcap.c +index a076c5fb..6caa052b 100644 +--- a/pcap.c ++++ b/pcap.c +@@ -4349,7 +4349,7 @@ pcap_offline_filter(const struct bpf_program *fp, const struct pcap_pkthdr *h, + const struct bpf_insn *fcode = fp->bf_insns; + + if (fcode != NULL) +- return (pcapint_filter(fcode, pkt, h->len, h->caplen)); ++ return (pcapint_filter(fcode, fp->bf_len, pkt, h->len, h->caplen)); + else + return (0); + } +diff --git a/pcap_offline_filter.3pcap b/pcap_offline_filter.3pcap +index 94b9a719..c6d62dee 100644 +--- a/pcap_offline_filter.3pcap ++++ b/pcap_offline_filter.3pcap +@@ -17,7 +17,7 @@ + .\" WARRANTIES, INCLUDING, WITHOUT LIMITATION, THE IMPLIED WARRANTIES OF + .\" MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE. + .\" +-.TH PCAP_OFFLINE_FILTER 3PCAP "7 April 2014" ++.TH PCAP_OFFLINE_FILTER 3PCAP "12 March 2026" + .SH NAME + pcap_offline_filter \- check whether a filter matches a packet + .SH SYNOPSIS +@@ -45,10 +45,35 @@ points to the + structure for the packet, and + .I pkt + points to the data in the packet. ++.PP ++In the ++.B \%bpf_program ++structure the ++.B \%bf_insns ++member is either ++.B NULL ++(which means to reject all packets) or points to an array of one or more ++.B \%struct bpf_insn ++elements, in which case the ++.B \%bf_len ++member must be set to the number of elements (this is what ++.BR \%pcap_compile () ++produces). ++.PP ++The filter program must have been compiled for a link-layer header type ++that matches the packet data; also on Linux the filter must not use ++BPF extensions, see ++.BR \%pcap_compile () ++for more information. + .SH RETURN VALUE + .BR pcap_offline_filter () + returns the return value of the filter program. This will be zero if + the packet doesn't match the filter and non-zero if the packet matches + the filter. ++.SH BACKWARD COMPATIBILITY ++.PP ++In libpcap releases before 1.10.7 this function ignored the provided ++.B \%bf_len ++value. + .SH SEE ALSO + .BR pcap (3PCAP) +diff --git a/savefile.c b/savefile.c +index c711a81c..49ef52b6 100644 +--- a/savefile.c ++++ b/savefile.c +@@ -685,7 +685,8 @@ pcapint_offline_read(pcap_t *p, int cnt, pcap_handler callback, u_char *user) + * and, if it passes, process it. + */ + if ((fcode = p->fcode.bf_insns) == NULL || +- pcapint_filter(fcode, data, h.len, h.caplen)) { ++ pcapint_filter(fcode, p->fcode.bf_len, ++ data, h.len, h.caplen)) { + (*callback)(user, &h, data); + n++; /* count the packet */ + if (n >= cnt) diff --git a/meta/recipes-connectivity/libpcap/libpcap_1.10.6.bb b/meta/recipes-connectivity/libpcap/libpcap_1.10.6.bb index 265c46e3bd0..aa5265a54c7 100644 --- a/meta/recipes-connectivity/libpcap/libpcap_1.10.6.bb +++ b/meta/recipes-connectivity/libpcap/libpcap_1.10.6.bb @@ -13,6 +13,7 @@ DEPENDS = "flex-native bison-native" SRC_URI = "https://www.tcpdump.org/release/${BP}.tar.xz \ file://0001-Fix-error-messages-about-32-bit-integer-overflow.patch \ file://01-CVE-2026-0799.patch \ + file://02-CVE-2026-31912.patch \ " SRC_URI[sha256sum] = "ec97d1206bdd19cb6bdd043eaa9f0037aa732262ec68e070fd7c7b5f834d5dfc" From patchwork Thu Sep 17 22:06:49 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 98619 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id D9849C982D9 for ; Thu, 17 Sep 2026 22:08:27 +0000 (UTC) Received: from mail-wm2-f13.google.com (mail-wm2-f13.google.com [74.125.225.141]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.1603.1789682905387418468 for ; Thu, 17 Sep 2026 15:08:25 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=qwaa2AfB; spf=pass (domain: smile.fr, ip: 74.125.225.141, mailfrom: yoann.congal@smile.fr) Received: by mail-wm2-f13.google.com with SMTP id 5b1f17b1804b1-49e7bcb94d3so721715e9.2 for ; Thu, 17 Sep 2026 15:08:25 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1789682904; x=1790287704; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=nv++BhtfLV0gjZH9p6vlcNvo5sm0DsrYXfZ3yrR/pSU=; b=qwaa2AfBU9KSXW7H5q3DthHFMTmzxLM8bp+PVqobFqCB7hmC57E8Zw0jy+5Ia0oG8w eOfNpoOc8BfWgMKJkNmnpSi8fazL+pU0bLF4mnzhmuqwwUSZkJ224gx2ayFdyxh5/nNr Gnt+MTPh2DMlSlurzoCo8R4kDMCHlkEwm7mRA= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1789682904; x=1790287704; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=nv++BhtfLV0gjZH9p6vlcNvo5sm0DsrYXfZ3yrR/pSU=; b=P2vfjSXsLXg89LDC5lFedvxIvVllEGig7N5YwpBZQCsdtwbwwDz3xSL1WhW26bwner D9NmcV7rVMucbTb3Crl1lCCwrpiKGyDuesa2J+rosr2uBMFKFOax5iMlbjTy3SV8WSAm 5eV55D5di0N+RUZB6MbfDQWoPVFx/5sLJsSaoxht4adG2/mDZ7RoPmQBlrIknmlM0M0v Y4EU1eMHQsDT3autWd2qqReJ31TbR4tZgPWsDmH2tgdKSkwo2sBzZfjOOXGoLIdE7lm7 nS4KXUymlW0LRl4BXLA/yuFEb7ZiHGhlhgXxQGthH1sBDTkkoIxF+81FVfyCYQIS8Ydp igeg== X-Gm-Message-State: AFuF++nao7QUZoZis9r7XdZGqefLN7QrYPTuPNhRJdsW0Y8rzWAs8qsP +K23ceH/V9ykY3ef5eyZpNd1yAgt0uKqy73V2vcH8ZRCpdX1FEPq9Ek/UsIprP9ew7Jl4/MRViJ FgwsGA4k= X-Gm-Gg: AYBFou2vI+GdtnwUSwOLap5Upe1c6VihKWq88NYDKM8cMT5zwcvyD4W2y9es6XZKdrr /Jpzpf9l+Rur6clYWAwlKYFVIiIsc5fcv/DymZAiyVm8v9q5t2B8inRQV//nqkluVJvZJiM8I5Y SyiVq6xw6vPzCZsGJG+yqym5FwUAJxkF17JDso5xwpZPXCUUI7qX6yAItWFtfQ06656d0fDsZtj 9sxdkxHqA118HojiLVsMv+z5Ad1sd0Mb9kVHoMT57F1N3ulY2Br1s+cwCd6uVw8TooUQIvyWw5u PJwgoTHL3c7rkiLj7YWUgT6O48WjrWo9wHypQsgNhmIWisOR8hNwf+PYyVu5iKoGgX7U0nF9RfT yvYLcmPw/Mc2c2/xrDTrMtYnpLhS8B4tgnRdLIidVANX+9O8R9ypmBhkSE2WOf8D4IE/GPIZDAI cW0yP73ABlON+6xGJ9kVqPCaaBXppYj5P+uCKNbwxOCEq8oTXagDvS2AMoe2T1AhDCsVoppBNpG M9V4FWnMlDdygMqmXqBeJD14GAtpoDy+4KIu76kbIDme/UxMaaMhzKdTTg2AfpwEljqGhrkkDo= X-Received: by 2002:a05:600c:3556:b0:49c:ffab:551f with SMTP id 5b1f17b1804b1-49fc5737c38mr3286375e9.22.1789682903647; Thu, 17 Sep 2026 15:08:23 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-49fc471b9a2sm8984075e9.0.2026.09.17.15.08.23 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Thu, 17 Sep 2026 15:08:23 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][wrynose 64/79] libpcap: Fix CVE-2026-31911 Date: Fri, 18 Sep 2026 00:06:49 +0200 Message-ID: <566d5080a3946a9ad97cdefba6be8dc9da15c6ff.1789681419.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Thu, 17 Sep 2026 22:08:27 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/246159 From: Jaipaul Cheernam NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-31911 Upstream-commit: https://github.com/the-tcpdump-group/libpcap/commit/a715bcdde830299cba4171514385cb17ec19b6e9 Signed-off-by: Jaipaul Cheernam Signed-off-by: Yoann Congal --- .../libpcap/libpcap/03-CVE-2026-31911.patch | 45 +++++++++++++++++++ .../libpcap/libpcap_1.10.6.bb | 1 + 2 files changed, 46 insertions(+) create mode 100644 meta/recipes-connectivity/libpcap/libpcap/03-CVE-2026-31911.patch diff --git a/meta/recipes-connectivity/libpcap/libpcap/03-CVE-2026-31911.patch b/meta/recipes-connectivity/libpcap/libpcap/03-CVE-2026-31911.patch new file mode 100644 index 00000000000..1060b3c372a --- /dev/null +++ b/meta/recipes-connectivity/libpcap/libpcap/03-CVE-2026-31911.patch @@ -0,0 +1,45 @@ +From 0067e8fd1f3caf866da3d95508831389f3b20e11 Mon Sep 17 00:00:00 2001 +From: Denis Ovsienko +Date: Thu, 30 Jul 2026 13:34:08 +0100 +Subject: [PATCH] CVE-2026-31911: Fail opcodes safely in the BPF interpreter. + +This vulnerability has been discovered by FuzzAnything Organization. + +The current revision of pcapint_filter_with_aux_data() calls abort() if +the current instruction opcode is invalid, and assumes this never to be +the case. This holds for programs that have been generated by libpcap. + +However, this does not necessarily hold for programs that come from an +external source via pcap_offline_filter() or [deprecated] bpf_filter(). +Furthermore, this does not necessarily hold for programs that have been +validated by libpcap because the current revision of the validator has +gaps in the checks and accepts a number of invalid opcodes (another +commit addresses that). + +Thus in pcapint_filter_with_aux_data(), when the instruction opcode is +invalid, just reject the packet. + +(backported from commit 4ccb54bf4946d31a248ec93bdbeaabd97fb9d8f7) + +(cherry picked from commit a715bcdde830299cba4171514385cb17ec19b6e9) + +Notes on backporting to 1.10.6: + - The upstream CHANGES/changelog hunk is not backported. + +Upstream-Status: Backport [https://github.com/the-tcpdump-group/libpcap/commit/a715bcdde830299cba4171514385cb17ec19b6e9] +CVE: CVE-2026-31911 +Signed-off-by: Jaipaul Cheernam +--- +diff --git a/bpf_filter.c b/bpf_filter.c +index 4f9adeea..f8b842d6 100644 +--- a/bpf_filter.c ++++ b/bpf_filter.c +@@ -152,7 +152,7 @@ pcapint_filter_with_aux_data(const struct bpf_insn *pc, const u_int proglen, + switch (pc->code) { + + default: +- abort(); ++ return 0; + case BPF_RET|BPF_K: + return (u_int)pc->k; + diff --git a/meta/recipes-connectivity/libpcap/libpcap_1.10.6.bb b/meta/recipes-connectivity/libpcap/libpcap_1.10.6.bb index aa5265a54c7..da218bd87ba 100644 --- a/meta/recipes-connectivity/libpcap/libpcap_1.10.6.bb +++ b/meta/recipes-connectivity/libpcap/libpcap_1.10.6.bb @@ -14,6 +14,7 @@ SRC_URI = "https://www.tcpdump.org/release/${BP}.tar.xz \ file://0001-Fix-error-messages-about-32-bit-integer-overflow.patch \ file://01-CVE-2026-0799.patch \ file://02-CVE-2026-31912.patch \ + file://03-CVE-2026-31911.patch \ " SRC_URI[sha256sum] = "ec97d1206bdd19cb6bdd043eaa9f0037aa732262ec68e070fd7c7b5f834d5dfc" From patchwork Thu Sep 17 22:06:50 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 98620 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 171F0C982DD for ; Thu, 17 Sep 2026 22:08:28 +0000 (UTC) Received: from mail-wm2-f12.google.com (mail-wm2-f12.google.com [74.125.225.140]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.1604.1789682906112728356 for ; Thu, 17 Sep 2026 15:08:26 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=h7lD1Y8F; spf=pass (domain: smile.fr, ip: 74.125.225.140, mailfrom: yoann.congal@smile.fr) Received: by mail-wm2-f12.google.com with SMTP id 5b1f17b1804b1-49ccead2aecso578495e9.0 for ; Thu, 17 Sep 2026 15:08:25 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1789682904; x=1790287704; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=dr/PAf8qCEVEQ2LamWbc+s7h3RHTEZ8S5+8GYhyF+xs=; b=h7lD1Y8F84g6UtqQX6pGiHhb5SvD9M5PUtzrdyN9UBUJzVSGriF9ZvQFq2eI2O4IKj Z9CN0FRORZ1P/cR7nfTpcqj2IgUpzF4GAJ8bAB0qSamY6rxhMq+4Atr2MGHXYPXyaDjq GdvxLqjyzM84HgUFS+W2WSt57GBtI1p49wx8M= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1789682904; x=1790287704; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=dr/PAf8qCEVEQ2LamWbc+s7h3RHTEZ8S5+8GYhyF+xs=; b=UGvpYFWf5VFUTvhZZBE1QwkzD0emK0XaF3YzijKuW1XIpDcmXDIzn+Xfno+PfUOAdp uqexSnkNXcwE+Pxw5gcnXozyMdWvIj20o6xI15xtYFFAC3ZFL9zeects+Aqnsug1jnPP PAVwuRi5wgqMY2ScNYjGh2nMEl8WkZY0AYaThRtJ7FYrop7+MHUNhzghz5/nuXGIkPF8 WFEDxF9bm39FxKqzKewzuuMMZmlIQxnRW35KKRgrIyI/XBHELTJ0xaciMs1iuMFvJFae yFDP2XR8DY1R1eujQLZ8T/1s9VpW7aXI2gAWm/00ZFfa5Yi+Gqt8OYtZeG9RCgGfuWSO CnYA== X-Gm-Message-State: AFuF++llgq2azRcHsk8z9j8shQWwuPFr3v1FpT/zFmzjYhkfpIbqxlZ0 fRKED7XL7othsyrfBcRNazYWVnoZAfEsz+mPIqdEPyDb3qHIKMXubBICDIP85bxfOHhFkR9HV/G 1nENLRsw= X-Gm-Gg: AYBFou1HVvSWMRXa/PkCOB5QGGOnC65FnICv+vstn3RV7de61NtiVPXX5pfn9QFcFuf 3/B8Mgzb0K4KKj2LKvvbnYcqEVw88EdwMHanXV3Rxaub3I3Thw1HJHFBCbgD8yMbQg3oeryaetP yxufARpvfcIH/5ZE/rOBS9dZsseT9mbzqWJW9PeyJdgaYdDQ22oZPXRrmECT4BCouXHnflbfdx1 WYHsvslA9fUS1ZaWlj9m/EIU7r1TYeAlO38YBiaykkG8fH4HUkvUi3xE6eYBLN0QVRTOQYE51n/ F66+SH0dVLZJH62Ox2xXllfaJz4wiDnY0druxAvGqSDJNhmNvuCfFlPT5qQdMAVcWPrs1mu4o++ LEjrluUWvFrC8FB6e6kIfGKjNsartT20yuHD2im+Syu3KngwkVT/9ejXrIX0v0v847GTnKKp+yE di+lulJ675+N+EzLAKPxOC4FbxXtJ36gmSao3EDLuLUl3Mo/HHYmuXUpWoi1OsSi9X41AUjgayv 524w5qAr11c8hCCtrXSSGjJv51i6rjoR/M+udApQkHwK8SCh37H+RYtE3NZyrcoCMMYMNSR/RY= X-Received: by 2002:a05:600c:1382:b0:49d:1d7e:4085 with SMTP id 5b1f17b1804b1-49fc5750e24mr2590765e9.22.1789682904332; Thu, 17 Sep 2026 15:08:24 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-49fc471b9a2sm8984075e9.0.2026.09.17.15.08.23 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Thu, 17 Sep 2026 15:08:23 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][wrynose 65/79] libpcap: Fix CVE-2026-6244 Date: Fri, 18 Sep 2026 00:06:50 +0200 Message-ID: X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Thu, 17 Sep 2026 22:08:28 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/246160 From: Jaipaul Cheernam NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-6244 Upstream-commit: https://github.com/the-tcpdump-group/libpcap/commit/98bb921b141aa642faedbf2ac510541c76499a19 Signed-off-by: Jaipaul Cheernam Signed-off-by: Yoann Congal --- .../libpcap/libpcap/04-CVE-2026-6244.patch | 50 +++++++++++++++++++ .../libpcap/libpcap_1.10.6.bb | 1 + 2 files changed, 51 insertions(+) create mode 100644 meta/recipes-connectivity/libpcap/libpcap/04-CVE-2026-6244.patch diff --git a/meta/recipes-connectivity/libpcap/libpcap/04-CVE-2026-6244.patch b/meta/recipes-connectivity/libpcap/libpcap/04-CVE-2026-6244.patch new file mode 100644 index 00000000000..b7fec6b554d --- /dev/null +++ b/meta/recipes-connectivity/libpcap/libpcap/04-CVE-2026-6244.patch @@ -0,0 +1,50 @@ +From e2f4d78f71237c44f730fee11fa0497b756e9d81 Mon Sep 17 00:00:00 2001 +From: Denis Ovsienko +Date: Thu, 30 Jul 2026 13:34:21 +0100 +Subject: [PATCH] CVE-2026-6244: Avoid division by zero via + pcap_offline_filter(). + +The current revision of pcapint_filter_with_aux_data() for "div x" and +"mod x" correctly rejects the packet if X is zero, but for "div #k" and +"mod #k" it assumes that k is never zero. This holds for programs that +have been generated or validated by libpcap. + +However, this does not necessarily hold for programs that come from an +external source via pcap_offline_filter() or [deprecated] bpf_filter() +and have not been explicitly validated. If the interpreter executes +such a program, it can attempt a division by zero, which will typically +terminate the process via SIGFPE. + +To fix this problem, in pcapint_filter_with_aux_data() treat "div #k" +and "mod #k" the same way as "div x" and "mod x". + +(backported from commit 0b2b1ad4a1796513613ff68e9dc09049cc8e0af4) + +(cherry picked from commit 98bb921b141aa642faedbf2ac510541c76499a19) + +Notes on backporting to 1.10.6: + - The upstream CHANGES/changelog hunk is not backported. + +Upstream-Status: Backport [https://github.com/the-tcpdump-group/libpcap/commit/98bb921b141aa642faedbf2ac510541c76499a19] +CVE: CVE-2026-6244 +Signed-off-by: Jaipaul Cheernam +--- +diff --git a/bpf_filter.c b/bpf_filter.c +index f8b842d6..0178aae5 100644 +--- a/bpf_filter.c ++++ b/bpf_filter.c +@@ -420,10 +420,14 @@ DIAG_ON_DEFAULT_ONLY_SWITCH + continue; + + case BPF_ALU|BPF_DIV|BPF_K: ++ if (pc->k == 0) ++ return 0; + A /= pc->k; + continue; + + case BPF_ALU|BPF_MOD|BPF_K: ++ if (pc->k == 0) ++ return 0; + A %= pc->k; + continue; + diff --git a/meta/recipes-connectivity/libpcap/libpcap_1.10.6.bb b/meta/recipes-connectivity/libpcap/libpcap_1.10.6.bb index da218bd87ba..258a15f5bac 100644 --- a/meta/recipes-connectivity/libpcap/libpcap_1.10.6.bb +++ b/meta/recipes-connectivity/libpcap/libpcap_1.10.6.bb @@ -15,6 +15,7 @@ SRC_URI = "https://www.tcpdump.org/release/${BP}.tar.xz \ file://01-CVE-2026-0799.patch \ file://02-CVE-2026-31912.patch \ file://03-CVE-2026-31911.patch \ + file://04-CVE-2026-6244.patch \ " SRC_URI[sha256sum] = "ec97d1206bdd19cb6bdd043eaa9f0037aa732262ec68e070fd7c7b5f834d5dfc" From patchwork Thu Sep 17 22:06:51 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 98617 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id AF197C982D0 for ; Thu, 17 Sep 2026 22:08:27 +0000 (UTC) Received: from mail-wm2-f13.google.com (mail-wm2-f13.google.com [74.125.225.141]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.1605.1789682907176443558 for ; Thu, 17 Sep 2026 15:08:27 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=n6a/ikxs; spf=pass (domain: smile.fr, ip: 74.125.225.141, mailfrom: yoann.congal@smile.fr) Received: by mail-wm2-f13.google.com with SMTP id 5b1f17b1804b1-49cd5462b69so589385e9.1 for ; Thu, 17 Sep 2026 15:08:26 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1789682905; x=1790287705; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=xvoCvVqKwp0kRbUT0PPavSLMb9czOmuyic7G8fYjwM0=; b=n6a/ikxsPy6yMFohKpnARQvGBYWI7hp/jaACZBj5THNPn5XE/gYcMeVNFMKi3LQ5lw iKFtlXcOn9a3joqT6vU9SAYRWq3rgEiH97VSbLSrHpqKac/zeFHL+I7KDVyjO3Ekx1kc 50j2TBBwAcSS5SKGpFkbfuW7V6njO6nCT62TQ= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1789682905; x=1790287705; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=xvoCvVqKwp0kRbUT0PPavSLMb9czOmuyic7G8fYjwM0=; b=SiukbHf+PnqNGGKooscY7pHHi96XIQl9aTd51glhGaXb84+4J2ySNI/pHsrcaepmhR ZBbiY6Y5hLtXtO2Y83/MtVVuDKF9P/ESIPkblkXLzeguoiYdZ6+cMsJ98ZeiSmbng8Su iD6zqjSMiNc2foEECGPCYfoo82fyu0lC4D7XK+rpM1gzSliv9TZkPeCtynpPaHJ6iy+B Qsm7IbR2aFYF0Zxf85lSFqr/VKAcLg4B/OFsp0NaWaP1Pfp7yPzmLjtndEHJX2ErsEd0 GmtuneAZUxtaRrYKL8jjAz31BKHB//1kmGGQvthbCDQh7fPOFQEHVcnTGz+ucwaRHrSy P/Qg== X-Gm-Message-State: AFuF++nrX6SOgPe2Rh2u7OzgY/84c5ps6wi+RODPzRZlGce6vAGiQLdD mFgrHGlBRqcZN2HHoHyyedY7kbXNsmnjYcv1gIMlkO3N2aTxf2ZDybj3Sjq7h8Ro8dn56ViE7yS EelkaKD4= X-Gm-Gg: AYBFou0hdxl/1f5BNWrT/KTx4n3rmORUpq63g3GDzworh387lbY/oKEGEGbd7KVn4PY Ku9PNgPQ9m1Q8VAop8TceMZ/J5qrA66D8vzqYPvY3IgehHM46snTA4M+/57rRIVjQ2oLlw139um xf/9pZKrR6qH59uSRbzBv34FfzqF8IdXjjdJB8IfcmpVmz6sk7CcAwVWV/RkoYDEonIW1zcbn0M xygPNtFQiILv3jwYdrqQy6qBS4W30PtNVi9p4Igfq4gw4NCPJLDe98fdFbp/l1OzvWpQnyQd6YR 84txwUhO82QHvyQPH5RZI35pN8jOtfiT/E4t3ccActw4KjMqwskzEjDaky3ACyGSG3Md7y3zHRh rhhMilTBps3wpJrUcVtvBwuJeW9q3z1Dk0o9qBUYT4OQ0mlZQoyWFIf0qhfRuzgk1zUhqLRmBuG WdwQmCvWGzSUeazhMhZl8x5UlbA/HUvyIiDxL3LgaGm5Bu/ee5yVYNxRHXCC/C7+R8AZKDp3n74 p34x7bl4jhzMKR+rdvNrxSN7d0xWmXQYrK3rNxZo+MNbgbQLE2GoLvHwXMmKQYJZcIRA4Putmf7 Rz/u/59Elw== X-Received: by 2002:a05:600c:8709:b0:49d:870:7a69 with SMTP id 5b1f17b1804b1-49fc573514bmr6106915e9.12.1789682905338; Thu, 17 Sep 2026 15:08:25 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-49fc471b9a2sm8984075e9.0.2026.09.17.15.08.24 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Thu, 17 Sep 2026 15:08:24 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][wrynose 66/79] libpcap: Fix CVE-2026-6554 Date: Fri, 18 Sep 2026 00:06:51 +0200 Message-ID: X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Thu, 17 Sep 2026 22:08:27 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/246161 From: Jaipaul Cheernam NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-6554 Upstream-commit: https://github.com/the-tcpdump-group/libpcap/commit/ff3c83475ac303c6b681c52ad0b6e14795a8e0ce Signed-off-by: Jaipaul Cheernam Signed-off-by: Yoann Congal --- .../libpcap/libpcap/05-CVE-2026-6554.patch | 94 +++++++++++++++++++ .../libpcap/libpcap_1.10.6.bb | 1 + 2 files changed, 95 insertions(+) create mode 100644 meta/recipes-connectivity/libpcap/libpcap/05-CVE-2026-6554.patch diff --git a/meta/recipes-connectivity/libpcap/libpcap/05-CVE-2026-6554.patch b/meta/recipes-connectivity/libpcap/libpcap/05-CVE-2026-6554.patch new file mode 100644 index 00000000000..208225105d5 --- /dev/null +++ b/meta/recipes-connectivity/libpcap/libpcap/05-CVE-2026-6554.patch @@ -0,0 +1,94 @@ +From ee37e79521d28a04b09f5c37b835ae7955c15e75 Mon Sep 17 00:00:00 2001 +From: Denis Ovsienko +Date: Thu, 30 Jul 2026 13:34:33 +0100 +Subject: [PATCH] CVE-2026-6554: Limit "ja L" looping in pcap_offline_filter(). + +This vulnerability has been discovered by Kaixuan LI. + +The current revision of pcapint_filter_with_aux_data() assumes that any +"ja L" instruction in a filter program does not jump to itself or to a +prior instruction that is guaranteed to reach the same "ja L" again. +This holds for programs that have been generated by libpcap. + +However, this does not necessarily hold for programs that come from an +external source via pcap_offline_filter() or [deprecated] bpf_filter(). +If the interpreter executes such a program, upon reaching such an +instruction it will begin looping infinitely. + +To mitigate this problem, in pcapint_filter_with_aux_data() enforce a +hard-coded limit on the number of backward jumps per packet. Ibid., and +in pcapint_validate_filter() as well, reject the only immediately +detectable case of an infinite loop. + +(backported from commit 63c005c25aeabf1404968add49fc885da3e127e0) + +(cherry picked from commit ff3c83475ac303c6b681c52ad0b6e14795a8e0ce) + +Upstream-Status: Backport [https://github.com/the-tcpdump-group/libpcap/commit/ff3c83475ac303c6b681c52ad0b6e14795a8e0ce] +CVE: CVE-2026-6554 + +Notes on backporting to 1.10.6: + - The stray BPF_S_ANC_* enum removed upstream in 1.10.7 (commit ff47ba55) is + still present in 1.10.6, so the new MAX_BACKWARD_JUMPS define is added + alongside it instead of replacing it. + - The upstream CHANGES/changelog hunk is not backported. + +Signed-off-by: Jaipaul Cheernam +--- +diff --git a/bpf_filter.c b/bpf_filter.c +index 0178aae5..bc6d149f 100644 +--- a/bpf_filter.c ++++ b/bpf_filter.c +@@ -70,6 +70,8 @@ enum { + BPF_S_ANC_VLAN_TAG_PRESENT, + }; + ++#define MAX_BACKWARD_JUMPS 64U ++ + /* + * Kernel BPF implementations tend to define BPF_MAXINSNS to 512 or 4096, the + * userland interpreter in libpcap is meant to support much longer filter +@@ -144,6 +146,7 @@ pcapint_filter_with_aux_data(const struct bpf_insn *pc, const u_int proglen, + A = 0; + X = 0; + const struct bpf_insn *pc0 = pc; ++ unsigned backward_jumps = 0; + --pc; + for (;;) { + ++pc; +@@ -318,6 +321,17 @@ DIAG_ON_DEFAULT_ONLY_SWITCH + */ + if ((bpf_u_int32)(pc - pc0) + 1 + pc->k >= proglen) + return 0; ++ /* ++ * Terminate the program if this is a non-forward jump ++ * and is: ++ * - a guaranteed infinite loop because it jumps to ++ * itself (exactly the same as in the validator), or ++ * - a backward jump after many enough backward jumps ++ * already made for this packet. ++ */ ++ if ((bpf_int32)pc->k < 0 && ((bpf_int32)pc->k == -1 || ++ backward_jumps++ >= MAX_BACKWARD_JUMPS)) ++ return 0; + /* + * XXX - we currently implement "ip6 protochain" + * with backward jumps, so sign-extend pc->k. +@@ -605,6 +619,17 @@ pcapint_validate_filter(const struct bpf_insn *f, int len) + */ + if (from + p->k >= (u_int)len) + return 0; ++ /* ++ * The only type of infinite loop that can be ++ * detected in this function is a "ja L" that ++ * jumps to itself. For this only k == -1 ++ * needs to be tested because the check above ++ * has already rejected all other values that ++ * would wrap the pointer equivalently on ++ * 32-bit architectures. ++ */ ++ if ((bpf_int32)p->k == -1) ++ return 0; + break; + case BPF_JEQ: + case BPF_JGT: diff --git a/meta/recipes-connectivity/libpcap/libpcap_1.10.6.bb b/meta/recipes-connectivity/libpcap/libpcap_1.10.6.bb index 258a15f5bac..6ca75117e17 100644 --- a/meta/recipes-connectivity/libpcap/libpcap_1.10.6.bb +++ b/meta/recipes-connectivity/libpcap/libpcap_1.10.6.bb @@ -16,6 +16,7 @@ SRC_URI = "https://www.tcpdump.org/release/${BP}.tar.xz \ file://02-CVE-2026-31912.patch \ file://03-CVE-2026-31911.patch \ file://04-CVE-2026-6244.patch \ + file://05-CVE-2026-6554.patch \ " SRC_URI[sha256sum] = "ec97d1206bdd19cb6bdd043eaa9f0037aa732262ec68e070fd7c7b5f834d5dfc" From patchwork Thu Sep 17 22:06:52 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 98632 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 1461DC982E8 for ; Thu, 17 Sep 2026 22:08:29 +0000 (UTC) Received: from mail-wm2-f13.google.com (mail-wm2-f13.google.com [74.125.225.141]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.1706.1789682907540708641 for ; Thu, 17 Sep 2026 15:08:27 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=MZlNNOwc; spf=pass (domain: smile.fr, ip: 74.125.225.141, mailfrom: yoann.congal@smile.fr) Received: by mail-wm2-f13.google.com with SMTP id 5b1f17b1804b1-49b965f447cso895385e9.3 for ; Thu, 17 Sep 2026 15:08:27 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1789682906; x=1790287706; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=VDnTLCfR8jUVeChMzhH25soy8TKlLpe/oTHCDfePfUk=; b=MZlNNOwcYCY2v40Hf1iYDoR5zO+5zXNfjhxxZX4nL+LVkhBfXUuG85lPlkPz5OCnhU NqAoIJmDE+7/EUwNWdm8OGe6UC1mvdlg8ytSi6QzeMwlgP42Hp+aX2oNWLVCiKqihIu9 QS7yceliLtPFw6nCdL+3+js3cKfkWOvRTax08= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1789682906; x=1790287706; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=VDnTLCfR8jUVeChMzhH25soy8TKlLpe/oTHCDfePfUk=; b=bum0ncGkzVGSt4oBsQTXTLwDKaLpxxhecakHqMIFkkS+qEUAfmTlshVs/IeYuggGMZ 9WRg+T18ZJZHm7vsaUb5QHUJyRRn12lduKutuI5aghBtVYteM/wJaXqfz5HRM/sr21Ot FQk1kLftvZi0Np7hkUWxdbvlMckjPjrWV+3x8DtmRY/Q6vvZ1x5nHa7dbzv3OWlplOLb oKPtwrlnIx+VVov40EAg937TJk4A+nwB7XaPGkKXHeamPypiFNguqwyw6O+bvYA7OAU5 xQ2EkTDV56RxncOcgZuYGcLKxHkTwKX9l3Uol1hm+gDY8JLvg4whVW6NU7Azo3KYEu5Z ceag== X-Gm-Message-State: AFuF++kCzTcvNN41+9A58H4sx27q0VVoHJkXXs3Twh4Wygpe3q/1nekt Bx7jsVqd1FkV2c3bms/1fZgyv8wDyRzPfEpIYbeCt95URZzZiZYihMyLrDJMLcYr0TZSBwt94Mh aGv2mfFo= X-Gm-Gg: AYBFou3WM8PnEd7sgdOQAn7YHNYttAmrNnx/OsGy+9guu/3sJqORfh7KpOOPCZBHDoG rxSGu6Iv15uBBm/gKbOcdNBuP5mZIz/2Z7xvlMT3jdldjqJ7/wJhkaT3D90bWvrung2F9cLRdXW C5OGQbIEVuVUOa/YsZWKYByXjNUpShF24itrHH1eMj9N2jAuH53aF2aD7nIgN4l2VBs21Ctkb/e 86o+aL5DMitqrmn1vxPbZQ0ZYtBmBoL3mU1wcjAHFVoSro1TKSi1rx6AGiM2uMW0xmXB9IE2qkm +q+GZavA6TFiOaab9JkejjIk325TXH1KvI9h8dC7snFCKQEppzHOxhFd5j6T+ZM41D5EGzXvORI hIk5JC2YlTf2j/uNVkyEAlRxD02KmKBL7MNMWrZkUFkh0Tjqhz3Bf3K043mb8cEtuzXlinN5bQR e2DY1QhhMKKfJ7kWrmZdiRWWbeBOwj3Btxzx2rJ03mf23XRM4Qfvtffik1hWVt+yZ8nLIZDa4Fd StQRgsC4YT+UjcvtWEf4uSvdqTAki231FFRBryvUlD9B87Wed/EZT1wbgkmpvLHyk+wraeH8yg= X-Received: by 2002:a05:600c:6819:b0:49c:fa20:cbfc with SMTP id 5b1f17b1804b1-49fc5728f8fmr3223925e9.19.1789682905822; Thu, 17 Sep 2026 15:08:25 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-49fc471b9a2sm8984075e9.0.2026.09.17.15.08.25 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Thu, 17 Sep 2026 15:08:25 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][wrynose 67/79] libpcap: Fix CVE-2026-18313 Date: Fri, 18 Sep 2026 00:06:52 +0200 Message-ID: <42cbcfa507c1ecc140d2c9a62af48ab47385279d.1789681419.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Thu, 17 Sep 2026 22:08:29 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/246162 From: Jaipaul Cheernam NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-18313 Upstream-commit: https://github.com/the-tcpdump-group/libpcap/commit/f9775af1a0ec76db60c7213241e6b48f1be10ac7 Signed-off-by: Jaipaul Cheernam Signed-off-by: Yoann Congal --- .../libpcap/libpcap/06-CVE-2026-18313.patch | 90 +++++++++++++++++++ .../libpcap/libpcap_1.10.6.bb | 1 + 2 files changed, 91 insertions(+) create mode 100644 meta/recipes-connectivity/libpcap/libpcap/06-CVE-2026-18313.patch diff --git a/meta/recipes-connectivity/libpcap/libpcap/06-CVE-2026-18313.patch b/meta/recipes-connectivity/libpcap/libpcap/06-CVE-2026-18313.patch new file mode 100644 index 00000000000..eae9aaa989b --- /dev/null +++ b/meta/recipes-connectivity/libpcap/libpcap/06-CVE-2026-18313.patch @@ -0,0 +1,90 @@ +From b039b8b66616852673c21ec5c7e0bad3190eae59 Mon Sep 17 00:00:00 2001 +From: Denis Ovsienko +Date: Sat, 1 Aug 2026 18:24:48 +0100 +Subject: [PATCH] CVE-2026-18313: Fix a memory leak in rpcapd. + +This vulnerability was originally reported publicly, hence no credit is +given. + +daemon_unpackapplyfilter() can allocate a temporary buffer for up to +RPCAP_BPF_MAXINSNS (8192) BPF instructions (65536 bytes) per each +received RPCAP_MSG_UPDATEFILTER_REQ or RPCAP_MSG_STARTCAP_REQ message. +It never frees the memory, so repeated messages from a client will +eventually leak enough memory on the server to cause problems. This +holds for all connections that pass the validation and some connections +that do not. + +48 bytes in 1 blocks are definitely lost in loss record 2 of 2 + at 0x4844818: malloc (vg_replace_malloc.c:446) + by 0x111AAB: daemon_unpackapplyfilter (daemon.c:2372) + by 0x113279: daemon_msg_startcap_req.constprop.0 (daemon.c:2139) + by 0x114808: daemon_serviceloop (daemon.c:901) + by 0x115BC7: accept_connection (rpcapd.c:1321) + by 0x115BC7: accept_connections (rpcapd.c:1118) + by 0x115BC7: main_startup (rpcapd.c:709) + by 0x1112BD: main (rpcapd.c:567) + +To fix this, after a successful malloc() return exactly once, after the +free() call. + +(backported from commit 26a1c75702b105ac8788014f35f1b5c57fa6043b) + +(cherry picked from commit f9775af1a0ec76db60c7213241e6b48f1be10ac7) + +Upstream-Status: Backport [https://github.com/the-tcpdump-group/libpcap/commit/f9775af1a0ec76db60c7213241e6b48f1be10ac7] +CVE: CVE-2026-18313 + +Notes on backporting to 1.10.6: + - The upstream commit was made after the "bogus instructions" -> "invalid + instructions" message change (commit 836d0fd0), which is not backported. + The 1.10.6 wording ("The filter contains bogus instructions") is therefore + kept; only the memory-leak fix (goto free_and_return_status / free()) is + applied. + - The upstream CHANGES/changelog hunk is not backported. + +Signed-off-by: Jaipaul Cheernam +--- +diff --git a/rpcapd/daemon.c b/rpcapd/daemon.c +index 87274665..b720cc45 100644 +--- a/rpcapd/daemon.c ++++ b/rpcapd/daemon.c +@@ -2380,14 +2380,8 @@ daemon_unpackapplyfilter(PCAP_SOCKET sockctrl, SSL *ctrl_ssl, struct session *se + { + status = rpcapd_recv(sockctrl, ctrl_ssl, (char *) &insn, + sizeof(struct rpcap_filterbpf_insn), plenp, errmsgbuf); +- if (status == -1) +- { +- return -1; +- } +- if (status == -2) +- { +- return -2; +- } ++ if (status == -1 || status == -2) ++ goto free_and_return_status; + + bf_insn->code = ntohs(insn.code); + bf_insn->jf = insn.jf; +@@ -2403,16 +2397,19 @@ daemon_unpackapplyfilter(PCAP_SOCKET sockctrl, SSL *ctrl_ssl, struct session *se + if (bpf_validate(bf_prog.bf_insns, bf_prog.bf_len) == 0) + { + snprintf(errmsgbuf, PCAP_ERRBUF_SIZE, "The filter contains bogus instructions"); +- return -2; ++ status = -2; ++ goto free_and_return_status; + } + + if (pcap_setfilter(session->fp, &bf_prog)) + { + snprintf(errmsgbuf, PCAP_ERRBUF_SIZE, "RPCAP error: %s", pcap_geterr(session->fp)); +- return -2; ++ status = -2; + } + +- return 0; ++free_and_return_status: ++ free(bf_prog.bf_insns); ++ return status; + } + + static int diff --git a/meta/recipes-connectivity/libpcap/libpcap_1.10.6.bb b/meta/recipes-connectivity/libpcap/libpcap_1.10.6.bb index 6ca75117e17..859897acc56 100644 --- a/meta/recipes-connectivity/libpcap/libpcap_1.10.6.bb +++ b/meta/recipes-connectivity/libpcap/libpcap_1.10.6.bb @@ -17,6 +17,7 @@ SRC_URI = "https://www.tcpdump.org/release/${BP}.tar.xz \ file://03-CVE-2026-31911.patch \ file://04-CVE-2026-6244.patch \ file://05-CVE-2026-6554.patch \ + file://06-CVE-2026-18313.patch \ " SRC_URI[sha256sum] = "ec97d1206bdd19cb6bdd043eaa9f0037aa732262ec68e070fd7c7b5f834d5dfc" From patchwork Thu Sep 17 22:06:53 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 98634 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 20288C982E9 for ; Thu, 17 Sep 2026 22:08:29 +0000 (UTC) Received: from mail-wm2-f12.google.com (mail-wm2-f12.google.com [74.125.225.140]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.1707.1789682908307953812 for ; Thu, 17 Sep 2026 15:08:28 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=fzG5ZmEk; spf=pass (domain: smile.fr, ip: 74.125.225.140, mailfrom: yoann.congal@smile.fr) Received: by mail-wm2-f12.google.com with SMTP id 5b1f17b1804b1-49b912e2406so558215e9.1 for ; Thu, 17 Sep 2026 15:08:28 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1789682906; x=1790287706; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=n4aYrVo0FyrYdFQ1rC5mQnib+WAr+IdrBXTcbmZes5M=; b=fzG5ZmEkmCI6U5iLFMpGcHHlMlfnuOVCAzKOM+MIcthV2rttVSXuXXEicRHXytZrtH bSQgIs3AMqdJoOi5I3rsxmqVCLaw8hDCC3htSnusJdTfpoW1CErMxtA1dI4sXTSeTyoB Hsd9CacX9hA9JWqqJh+Zbp4kXm70wlXPpa/rg= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1789682906; x=1790287706; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=n4aYrVo0FyrYdFQ1rC5mQnib+WAr+IdrBXTcbmZes5M=; b=2EtF1XXC4eLM0LtABlxnCk5nFEPiVLVL/clRDPHMHJuSDV6Jg234OVFcglQ1HQ5Y7L TQ9N1q/B6BIoiETUxJ67OOLhRJIiCSdWb9Cg+0JMyuk+OMsPp8lbM41mrQrmgCLavwHD 6acv5MEpYrOGg57GAqk8jOJ+/YOIofVSr2XJSqnifS3akSLvyjf9ECoq0r/5GmHPAptT KzV6XMDuwBqF3o39Kfo/PcCm6UQ5+ZGH+WDu2vhH22OXVmLAdmzLedqaDunNLTwyF6fa ONMZj8nUQpoHoIMNcz7aRRKbYIZEfkwTpQgGMN8kQXcWvIG5prp9874V/46A1kZDM5Jb ZHeQ== X-Gm-Message-State: AFuF++mwEFl72OLpjd3iDXVQ3Nr1lkUHp9+y3MyVB5WcEvmU6n8ehScK PVbOhed+zGxvecLg6e+VkN2ZE1xKgZq/CYBq2xVmcUKi62kfxu3EW0yCXsky2+ea9IsGQpyxFM1 1m1HbVco= X-Gm-Gg: AYBFou2neHn+qu/jDpUTwWLUcfPna3Od///IPnvuC5NwHUEWCJy9aHA9xRWgg6kFClG wnKosZKjsy9jL3AWw+N0ossKLP0BZVPhTSVwbruQjyLUP2FacMnIh/tmGtaxi/BmvEc2F6rvnIN D8NKk7K1CWX7EZ6JMSLC8flBHyKLTHc8EHY2bz6G4srnUVJtjflG1eUtXQfHqTQeGNZq0EAebml 9XkSZ4mfXdaGppiB+JezzyUDLX0QaYS8iQG/Iarjle7BKexCcU3evjtxrB3vBakqS1mv7WrZGYk KLtKfzBytMrr7226dGaW+TqOtgqqrRnh+aX8+xDvdclF9NoD2cFDnrSjx6iMvgxJtYtc26QOH+9 hQ2apUOw2SYciyw7cF1iyvZN1K0vnVGpG/KrzybwgGz45DN6o8Kr5pE89snL5bp17AyEa0vHekM IIOwejqZtghAT1HiPwLDoyoBDmE3yR/zzuCrVrt5StOSJuo9YqvDKfPcn1hcqO8p6DDa3X3F1av sveM6v+B3F5t/uGJJmR3hs8ff8IfzKOobUNY5Wy/UZCiqgoCJ87ieob3jGaX/QtiKBO+W+18ug= X-Received: by 2002:a05:600c:1d06:b0:49e:8222:3451 with SMTP id 5b1f17b1804b1-49fc5001358mr5995185e9.14.1789682906450; Thu, 17 Sep 2026 15:08:26 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-49fc471b9a2sm8984075e9.0.2026.09.17.15.08.25 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Thu, 17 Sep 2026 15:08:25 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][wrynose 68/79] libpcap: Fix CVE-2026-18238 Date: Fri, 18 Sep 2026 00:06:53 +0200 Message-ID: X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Thu, 17 Sep 2026 22:08:29 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/246163 From: Jaipaul Cheernam NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-18238 Upstream-commit: https://github.com/the-tcpdump-group/libpcap/commit/b9590d482986d64673712460aae1d48d11fa0473 Signed-off-by: Jaipaul Cheernam Signed-off-by: Yoann Congal --- .../libpcap/libpcap/07-CVE-2026-18238.patch | 222 ++++++++++++++++++ .../libpcap/libpcap_1.10.6.bb | 1 + 2 files changed, 223 insertions(+) create mode 100644 meta/recipes-connectivity/libpcap/libpcap/07-CVE-2026-18238.patch diff --git a/meta/recipes-connectivity/libpcap/libpcap/07-CVE-2026-18238.patch b/meta/recipes-connectivity/libpcap/libpcap/07-CVE-2026-18238.patch new file mode 100644 index 00000000000..d664f5b358b --- /dev/null +++ b/meta/recipes-connectivity/libpcap/libpcap/07-CVE-2026-18238.patch @@ -0,0 +1,222 @@ +From 5aa9cfee8eb44967dec96199fde879022e4426d4 Mon Sep 17 00:00:00 2001 +From: Denis Ovsienko +Date: Sat, 8 Aug 2026 00:31:10 +0100 +Subject: [PATCH] CVE-2026-18238: Fix RPCAP_MSG_PACKET validation. + +This vulnerability was originally reported publicly, hence no credit is +given. + +When pcap_read_nocb_remote() validates a received message, it does not +verify that there is a complete RPCAP_MSG_PACKET header in the rpcap +general payload, also it uses an incorrect value to validate the length +declared in the RPCAP_MSG_PACKET header. The latter can lead the +protocol client to over-read the message buffer by 20 bytes, which in at +least one scenario can cause a SIGSEGV. + +Fix this problem, as well as a potential integer overflow in the UDP +code path on 32-bit architectures. To make message encoding and +validation easier to follow, re-jig a few variables and update comments. + +(backported from commit 2d67e814e8d3791a8b508c359f94688c5669cce9) + +(cherry picked from commit b9590d482986d64673712460aae1d48d11fa0473) + +Notes on backporting to 1.10.6: + - The upstream CHANGES/changelog hunk is not backported. + +Upstream-Status: Backport [https://github.com/the-tcpdump-group/libpcap/commit/b9590d482986d64673712460aae1d48d11fa0473] +CVE: CVE-2026-18238 +Signed-off-by: Jaipaul Cheernam +--- +diff --git a/pcap-rpcap.c b/pcap-rpcap.c +index 8f8960b9..b7f54641 100644 +--- a/pcap-rpcap.c ++++ b/pcap-rpcap.c +@@ -389,10 +389,9 @@ rpcap_deseraddr(struct rpcap_sockaddr *sockaddrin, struct sockaddr **sockaddrout + static int pcap_read_nocb_remote(pcap_t *p, struct pcap_pkthdr *pkt_header, u_char **pkt_data) + { + struct pcap_rpcap *pr = p->priv; /* structure used when doing a remote live capture */ +- struct rpcap_header *header; /* general header according to the RPCAP format */ +- struct rpcap_pkthdr *net_pkt_header; /* header of the packet, from the message */ ++ struct rpcap_header *gen_header; /* rpcap general header */ ++ struct rpcap_pkthdr *net_pkt_header; /* RPCAP_MSG_PACKET header */ + u_char *net_pkt_data; /* packet data from the message */ +- uint32 plen; + int retval = 0; /* generic return value */ + int msglen; + +@@ -449,13 +448,35 @@ static int pcap_read_nocb_remote(pcap_t *p, struct pcap_pkthdr *pkt_header, u_ch + return 0; + + /* +- * We have to define 'header' as a pointer to a larger buffer, +- * because in case of UDP we have to read all the message within a single call ++ * pcap_startcapture_remote() has pointed p->buffer to a buffer large ++ * enough to contain all of the following data at once: ++ * ++ * - a fixed-size rpcap general header ++ * - a fixed-size RPCAP_MSG_PACKET header ++ * - p->snapshot worth of bytes of a captured packet ++ * ++ * This is sufficient for all code paths below. + */ +- header = (struct rpcap_header *) p->buffer; ++ gen_header = (struct rpcap_header *)p->buffer; + net_pkt_header = (struct rpcap_pkthdr *) ((char *)p->buffer + sizeof(struct rpcap_header)); + net_pkt_data = (u_char *)p->buffer + sizeof(struct rpcap_header) + sizeof(struct rpcap_pkthdr); + ++ /* ++ * Step 1: to receive a message that does not immediately look ++ * malformed, consider it as a fixed-size rpcap general header followed ++ * by a variable-size rpcap general payload and require: ++ * ++ * - a complete rpcap general header to land in the buffer, and ++ * - the header to declare an rpcap general payload length that fits ++ * in the buffer after the header, and ++ * - the complete declared payload to land in the buffer after the ++ * header. ++ * ++ * Since this step loosely corresponds to rpcap_process_msg_header(), ++ * which among other things converts rpcap_header.plen to host byte ++ * order, mimic that as well to produce a valid argument for ++ * rpcap_check_msg_ver() later on. ++ */ + if (pr->rmt_flags & PCAP_OPENFLAG_DATATX_UDP) + { + /* Read the entire message from the network */ +@@ -471,6 +492,8 @@ static int pcap_read_nocb_remote(pcap_t *p, struct pcap_pkthdr *pkt_header, u_ch + /* Interrupted receive. */ + return 0; + } ++ ++ // Require a complete rpcap general header to be present. + if ((size_t)msglen < sizeof(struct rpcap_header)) + { + /* +@@ -480,8 +503,18 @@ static int pcap_read_nocb_remote(pcap_t *p, struct pcap_pkthdr *pkt_header, u_ch + "UDP packet message is shorter than an rpcap header"); + return -1; + } +- plen = ntohl(header->plen); +- if ((size_t)msglen < sizeof(struct rpcap_header) + plen) ++ gen_header->plen = ntohl(gen_header->plen); ++ ++ /* ++ * Validate the rpcap general payload length declared in the ++ * rpcap general header. Use subtraction to avoid an integer ++ * overflow: ++ * ++ * 0 <= gen_header->plen <= UINT32_MAX ++ * sizeof(struct rpcap_header) <= msglen <= p->bufsize ++ * p->bufsize is significantly less than UINT32_MAX ++ */ ++ if (gen_header->plen > (size_t)msglen - sizeof(struct rpcap_header)) + { + /* + * Message is shorter than the header claims it +@@ -496,6 +529,7 @@ static int pcap_read_nocb_remote(pcap_t *p, struct pcap_pkthdr *pkt_header, u_ch + { + int status; + ++ // Receive a complete rpcap general header from the network. + if ((size_t)p->cc < sizeof(struct rpcap_header)) + { + /* +@@ -515,27 +549,35 @@ static int pcap_read_nocb_remote(pcap_t *p, struct pcap_pkthdr *pkt_header, u_ch + return 0; + } + } ++ gen_header->plen = ntohl(gen_header->plen); + + /* +- * We have the header, so we know how long the +- * message payload is. The size we should get +- * is the size of the packet header plus the +- * size of the payload. ++ * Validate the rpcap general payload length declared in the ++ * rpcap general header. Use subtraction to avoid an integer ++ * overflow: ++ * ++ * 0 <= gen_header->plen <= UINT32_MAX ++ * sizeof(struct rpcap_header) < p->bufsize ++ * p->bufsize is significantly less than UINT32_MAX + */ +- plen = ntohl(header->plen); +- if (plen > p->bufsize - sizeof(struct rpcap_header)) ++ if (gen_header->plen > p->bufsize - sizeof(struct rpcap_header)) + { + /* + * This is bigger than the largest +- * record we'd expect. (We do it by +- * subtracting in order to avoid an +- * overflow.) ++ * record we'd expect. + */ + snprintf(p->errbuf, PCAP_ERRBUF_SIZE, + "Server sent us a message larger than the largest expected packet message"); + return -1; + } +- status = rpcap_read_packet_msg(pr, p, sizeof(struct rpcap_header) + plen); ++ ++ /* ++ * Receive the declared rpcap general payload from the network. ++ * ++ * p->cc == sizeof(struct rpcap_header) ++ * p->bp == p->buffer + sizeof(struct rpcap_header) ++ */ ++ status = rpcap_read_packet_msg(pr, p, sizeof(struct rpcap_header) + gen_header->plen); + if (status == -1) + { + /* Network error. */ +@@ -558,27 +600,36 @@ static int pcap_read_nocb_remote(pcap_t *p, struct pcap_pkthdr *pkt_header, u_ch + + /* + * We have the entire message. +- */ +- header->plen = plen; +- +- /* +- * Did the server specify the version we negotiated? ++ * Step 2: to validate the received message further, require: ++ * ++ * - the rpcap general header to have the correct version and type, and ++ * - the rpcap general payload to be large enough to contain at least a ++ * complete RPCAP_MSG_PACKET header, and ++ * - the RPCAP_MSG_PACKET header to declare an RPCAP_MSG_PACKET payload ++ * (i.e. the captured packet) length that fits in the rpcap general ++ * payload (not the entire buffer) after the RPCAP_MSG_PACKET header. + */ + if (rpcap_check_msg_ver(pr->rmt_sockdata, pr->data_ssl, pr->protocol_version, +- header, p->errbuf) == -1) +- { ++ gen_header, p->errbuf) == -1) ++ return 0; /* Return 'no packets received' */ ++ if (gen_header->type != RPCAP_MSG_PACKET) + return 0; /* Return 'no packets received' */ ++ if (gen_header->plen < sizeof(struct rpcap_pkthdr)) ++ { ++ snprintf(p->errbuf, PCAP_ERRBUF_SIZE, ++ "Received an incomplete RPCAP_MSG_PACKET header."); ++ return -1; + } +- + /* +- * Is this a RPCAP_MSG_PACKET message? ++ * Validate the RPCAP_MSG_PACKET payload length declared in the ++ * RPCAP_MSG_PACKET header. Use subtraction to avoid an integer ++ * overflow: ++ * ++ * 0 <= ntohl(net_pkt_header->caplen) <= UINT32_MAX ++ * sizeof(struct rpcap_pkthdr) <= gen_header->plen ++ * gen_header->plen is significantly less than UINT32_MAX + */ +- if (header->type != RPCAP_MSG_PACKET) +- { +- return 0; /* Return 'no packets received' */ +- } +- +- if (ntohl(net_pkt_header->caplen) > plen) ++ if (ntohl(net_pkt_header->caplen) > gen_header->plen - sizeof(struct rpcap_pkthdr)) + { + snprintf(p->errbuf, PCAP_ERRBUF_SIZE, + "Packet's captured data goes past the end of the received packet message."); diff --git a/meta/recipes-connectivity/libpcap/libpcap_1.10.6.bb b/meta/recipes-connectivity/libpcap/libpcap_1.10.6.bb index 859897acc56..2844f4b2a9b 100644 --- a/meta/recipes-connectivity/libpcap/libpcap_1.10.6.bb +++ b/meta/recipes-connectivity/libpcap/libpcap_1.10.6.bb @@ -18,6 +18,7 @@ SRC_URI = "https://www.tcpdump.org/release/${BP}.tar.xz \ file://04-CVE-2026-6244.patch \ file://05-CVE-2026-6554.patch \ file://06-CVE-2026-18313.patch \ + file://07-CVE-2026-18238.patch \ " SRC_URI[sha256sum] = "ec97d1206bdd19cb6bdd043eaa9f0037aa732262ec68e070fd7c7b5f834d5dfc" From patchwork Thu Sep 17 22:06:54 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 98638 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 1EC30C982D0 for ; Thu, 17 Sep 2026 22:08:39 +0000 (UTC) Received: from mail-wm2-f12.google.com (mail-wm2-f12.google.com [74.125.225.140]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.1708.1789682908717042740 for ; Thu, 17 Sep 2026 15:08:29 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=FbkYg7Yc; spf=pass (domain: smile.fr, ip: 74.125.225.140, mailfrom: yoann.congal@smile.fr) Received: by mail-wm2-f12.google.com with SMTP id 5b1f17b1804b1-49b912df756so782845e9.3 for ; Thu, 17 Sep 2026 15:08:28 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1789682907; x=1790287707; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=ruuTStQRB+KjBtaQkrKADrCVYxt6Bjqe/tmPU17X5E8=; b=FbkYg7YcVr35yKvtJLoEkWVapVSpuGmoVu3ycinIXqbD54vC2Es8fiwteJtsllwLR1 BT7O25uAM+CmHyRNlISibQ5RNDFUpFBOwkrhXi29jRUQyc+fOd9Yux7Xj5umpHfeownV xlGgbgMxdOn6jH6g2e6cCAPUERS3wPFZDyLnI= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1789682907; x=1790287707; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=ruuTStQRB+KjBtaQkrKADrCVYxt6Bjqe/tmPU17X5E8=; b=W7xRQEiLL56O2pcOsH6JSn4hSlEti+jAMCZMuS/XzgIDZwLqWrWdvMG7iggfy6PzKF FwNKmFPEDM3np2bqyurtLLXDQIBfjdkRqBzBFI/gLUpl+tye7Ga1m3vYuntYoTxT/ol/ uqr+UksF1kSjoMx8+R5kXW41lvEMD6oxU6/ZtXJH5dh4Nj8gVvVzR+Sz8p+dgm3bou+j O+aedzZxscMz1ASa0oPUGclvABavId34aB5RRNCmQWd8Rhhvjpa/AvjIovh5o8WLD9Dp M5ScvM6ZnSVJseEWbyCB4Q5FT7xW51HRuG7rF7jZEY/qcw9WHOi62N3PTivkGSZgDo9I hScg== X-Gm-Message-State: AFuF++l1EcG8CNkcRw+HmeMRhQtokJ5CMkIAYSMUtEuLKk/me0UHDtyq D6SyB9FGPtyD0eHqwrI9G08OZ0Wgtkr4+/KJ06Ixe1G9D/cd2BValc0ruXLgVUCWn3l2PR3cCUW VPzVQ0Y8= X-Gm-Gg: AYBFou1BPCJ+uChxmHQRUI88gfa5VZdbE2sAiGwqgpa7TJHH0Gu982wSgn0e+f8o0hN ykYF8JMVqZP/YKQgrLKoAT0j5+yCtY1CY/LqrlUzxSuPvXA6X4QqbC5oMDlv/rAwwosReDgZ0ck 3G7qNSmUAixf2fzSgF8e23f3jFEI3Hi9JWa4vzTmbVTpVyh91cgCbwveKC3ZnYCf1rygNqtfOUP hb88kr/1WiDuEv4aSVhHWl1cKOnupf5wSjE8t86x71ec/tLq+bxK7oivSLOPRJLF3hZfMhWoDh0 L0J4E0yLbOQ1HbpUATdXGj0GWNAYfNsXW1AqmZNL5ifbNrUtiKDY2ZQCksPtURBagYk+Yu9xnoe iamkNv5skFBr+OFCiMtoXMXDpZ67Y/csLS4ElouAv7gK3mp2nYv8pdIvLLer398RhcE77xWhHmo /98ruF1nseFFrRTjAhtfiM6rFnOPD6ZyTYMNCQS0KKwjCkozDZNxltQ3tH9oDvJNx9ifxpvcgeK hCSLN6LsQHjs6cHRmH0ytUx7kgYI8fFlWoDr9fRwcl79J/6cz3vykME81ELfPb9LyXFr9XEykYH yh9ciqsKWQ== X-Received: by 2002:a05:600c:468c:b0:49d:16df:8521 with SMTP id 5b1f17b1804b1-49fc56811dcmr3710355e9.4.1789682906973; Thu, 17 Sep 2026 15:08:26 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-49fc471b9a2sm8984075e9.0.2026.09.17.15.08.26 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Thu, 17 Sep 2026 15:08:26 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][wrynose 69/79] ffmpeg: Fix for CVE-2026-64830 Date: Fri, 18 Sep 2026 00:06:54 +0200 Message-ID: <6dd7d1ab2558f450885ab6346fc1c1778da09264.1789681419.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Thu, 17 Sep 2026 22:08:39 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/246164 From: Bhavesh R Maheshwari Pick the patch from [1], also referenced in the NVD report [2]. [1] https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/dbd495f066a85ba96b17433f4306582aa37c3951 [2] https://nvd.nist.gov/vuln/detail/CVE-2026-64830 Signed-off-by: Bhavesh R Maheshwari Signed-off-by: Yoann Congal --- .../ffmpeg/ffmpeg/CVE-2026-64830.patch | 65 +++++++++++++++++++ .../recipes-multimedia/ffmpeg/ffmpeg_8.0.3.bb | 1 + 2 files changed, 66 insertions(+) create mode 100644 meta/recipes-multimedia/ffmpeg/ffmpeg/CVE-2026-64830.patch diff --git a/meta/recipes-multimedia/ffmpeg/ffmpeg/CVE-2026-64830.patch b/meta/recipes-multimedia/ffmpeg/ffmpeg/CVE-2026-64830.patch new file mode 100644 index 00000000000..79ed6a45f16 --- /dev/null +++ b/meta/recipes-multimedia/ffmpeg/ffmpeg/CVE-2026-64830.patch @@ -0,0 +1,65 @@ +From 0ae68ee7e1bc6e2bfde10c78ccc59aa9d99f4d43 Mon Sep 17 00:00:00 2001 +From: Pavel Kohout +Date: Mon, 29 Jun 2026 23:30:41 +0200 +Subject: [PATCH 1/9] avformat/vobsub: reuse subtitle streams and bound the + stream count + +Fixes: heap buffer overflow +Fixes: lqaO5R1BaZGO +Fixes: dbfe61100b (avformat/vobsub: fix several issues.) +Found-by: Pavel Kohout (Aisle Research) +Signed-off-by: Michael Niedermayer + +CVE: CVE-2026-64830 +Upstream-Status: Backport [https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/dbd495f066a85ba96b17433f4306582aa37c3951] + +Signed-off-by: Bhavesh R Maheshwari +--- + libavformat/mpeg.c | 18 ++++++++++++++++-- + 1 file changed, 16 insertions(+), 2 deletions(-) + +diff --git a/libavformat/mpeg.c b/libavformat/mpeg.c +index a7a2ef7..1ce4bf9 100644 +--- a/libavformat/mpeg.c ++++ b/libavformat/mpeg.c +@@ -841,6 +841,20 @@ static int vobsub_read_header(AVFormatContext *s) + } + + if (!st || st->id != stream_id) { ++ st = NULL; ++ for (i = 0; i < s->nb_streams; i++) { ++ if (s->streams[i]->id == stream_id) { ++ st = s->streams[i]; ++ break; ++ } ++ } ++ } ++ if (!st) { ++ if (s->nb_streams >= FF_ARRAY_ELEMS(vobsub->q)) { ++ av_log(s, AV_LOG_ERROR, "Maximum number of subtitle streams reached\n"); ++ ret = AVERROR_INVALIDDATA; ++ goto end; ++ } + st = avformat_new_stream(s, NULL); + if (!st) { + ret = AVERROR(ENOMEM); +@@ -865,14 +879,14 @@ static int vobsub_read_header(AVFormatContext *s) + timestamp = (hh*3600LL + mm*60LL + ss) * 1000LL + ms + delay; + timestamp = av_rescale_q(timestamp, av_make_q(1, 1000), st->time_base); + +- sub = ff_subtitles_queue_insert(&vobsub->q[s->nb_streams - 1], "", 0, 0); ++ sub = ff_subtitles_queue_insert(&vobsub->q[st->index], "", 0, 0); + if (!sub) { + ret = AVERROR(ENOMEM); + goto end; + } + sub->pos = pos; + sub->pts = timestamp; +- sub->stream_index = s->nb_streams - 1; ++ sub->stream_index = st->index; + + } else if (!strncmp(line, "alt:", 4)) { + const char *p = line + 4; +-- +2.43.0 + diff --git a/meta/recipes-multimedia/ffmpeg/ffmpeg_8.0.3.bb b/meta/recipes-multimedia/ffmpeg/ffmpeg_8.0.3.bb index 8a6eb4eb863..8c1969369b6 100644 --- a/meta/recipes-multimedia/ffmpeg/ffmpeg_8.0.3.bb +++ b/meta/recipes-multimedia/ffmpeg/ffmpeg_8.0.3.bb @@ -26,6 +26,7 @@ SRC_URI = "https://www.ffmpeg.org/releases/${BP}.tar.xz \ file://0001-fftools-resources-Fix-double-build-by-disabling-.d-f.patch \ file://0001-ffbuild-commonmak-Consolidate-pattern-rules-for-comp.patch \ file://0002-ffbuild-common.mak-ensure-target-directories-are-cre.patch \ + file://CVE-2026-64830.patch \ " SRC_URI[sha256sum] = "6136812ea6d4e68bdba27e33c2a94382711cdf4f8602ffef056ff792bd6f9818" From patchwork Thu Sep 17 22:06:55 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 98640 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id BD1DAC982DE for ; Thu, 17 Sep 2026 22:08:39 +0000 (UTC) Received: from mail-wm2-f12.google.com (mail-wm2-f12.google.com [74.125.225.140]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.1709.1789682909118750693 for ; Thu, 17 Sep 2026 15:08:29 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=cUQd+ENh; spf=pass (domain: smile.fr, ip: 74.125.225.140, mailfrom: yoann.congal@smile.fr) Received: by mail-wm2-f12.google.com with SMTP id 5b1f17b1804b1-49e6598dd44so654015e9.1 for ; Thu, 17 Sep 2026 15:08:28 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1789682907; x=1790287707; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=o5aL+fvqGYA3rcrCveOkhNH2DtGceknKLUuCvB57fmI=; b=cUQd+ENhASgEVj9mdoIvn12w4+tpmpZ7M+IeZu3kDLPwd76fglodUAsF62Sv6WfhKz XMPzXQt0wKAskz3x/nt2J0B9tKbsHhgy+UOlMUzJk+HasKRSLiALJzLrS6cvaeRpYt8E gcX1XXWasCWg/iFVSJO1hu5WZlP45RyA9Z3O8= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1789682907; x=1790287707; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=o5aL+fvqGYA3rcrCveOkhNH2DtGceknKLUuCvB57fmI=; b=XgNCC5NMTE42Ky7mKXONYX18bWlqUhsSlyslJJnlLwc6AS3sQg5ra7E0EVKzShrARW c4bKk4UwE/zu61bb+4meoicXDM42nkDrslzXURenALvbLG+YPdSa2/iY9kfMUJRR2mfR kMabTCgNFbhX3TQWC5WwrhL70TL8j+0qQT24js5FhyhKkpVAj4KMrvsS4xwUg2lRUwO8 1SwBrXSvdJutgJkzFqLBvVu6xcCdM75vGqwK+OPiqd7YfEKCrXy1X3T5CBWYH1tEAMzc 4UaDFeGOzu+2YozAENuWv4ZzHUOZNkLxRi5J6dmOdm2DMFE4j+UmI2k4Zs1YqRlQCF+W flkQ== X-Gm-Message-State: AFuF++kDeNTX7YVNZpBbj59uT4fT9BReEtmjsfUW/RWHaDS4yItwo77r Fz0uHuLUmWY1cl36YPzgvoyXqlBbzPHeNn9m51OcNS9W36NA33fzatc5OtFwdsjOLtu/nubY5i7 nGZ9CFt8= X-Gm-Gg: AYBFou0iSzxjWbDRu8/+4wt4tmm4wKOLX97uU2aSWwzfKCoXbD5CSIg/04DQdFAxIgW Tnvxp39rRGIbu3Q6Wt9tima5Fxavt7NRJT0NPTZ45gbQioqLInTKROOuzpnoIuCeVp7dfvd5+4d WpU2OEz1IxumOGMPEEwNM5nbNZzMWYT6wLIQMGO1/RrkkEKuRg/4nBFgxrYYxX0gUiBY0Goq7/C wPJoMkFFRuTLEMenjHaW48lVYG3HrIngM22rVmx7TF3JumC+kE7fUIe7P4wXBCal4BM5XJzWAVS uRMjj+rh168tK0uCvFCnE0pXlItB8WP4zyuuLFfPwob0c7UB+H7envrhE+x/bzzyFrfgzeiYnPG F6DFW+Cn0JfJljJ8dSEH9Z9Qhzch6HyeGu6HWcJKRcMzj1XSC3xRJKzKPPoOCaFBvO+A2dqqeo/ 91vK4Uc/d9XGMBJLsZlRVeh7cep3apJ2QL0b9Thuopl0BgCS0VcL8XGuKak7IshaxqUmivTN5Mh f5dYEeLuIIy73M7/Tg1Kyu2+4co4UA2uwPlssBhIfK5PWtIDOl0YxF/niWBQ1SPaa8WDsp+wNs= X-Received: by 2002:a05:600c:34c6:b0:49c:fa20:cc0a with SMTP id 5b1f17b1804b1-49fc5742ebamr2464465e9.33.1789682907438; Thu, 17 Sep 2026 15:08:27 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-49fc471b9a2sm8984075e9.0.2026.09.17.15.08.27 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Thu, 17 Sep 2026 15:08:27 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][wrynose 70/79] ffmpeg: Fix for CVE-2026-64831 Date: Fri, 18 Sep 2026 00:06:55 +0200 Message-ID: <93c481ea002a8defebf022155ebbc7226f989647.1789681419.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Thu, 17 Sep 2026 22:08:39 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/246165 From: Bhavesh R Maheshwari Pick the patch from [1], also referenced in the NVD report [2]. [1] https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/92737390dc133daadce47dd7d2ec8ef3d9ebcbed [2] https://nvd.nist.gov/vuln/detail/CVE-2026-64831 Signed-off-by: Bhavesh R Maheshwari Signed-off-by: Yoann Congal --- .../ffmpeg/ffmpeg/CVE-2026-64831.patch | 36 +++++++++++++++++++ .../recipes-multimedia/ffmpeg/ffmpeg_8.0.3.bb | 1 + 2 files changed, 37 insertions(+) create mode 100644 meta/recipes-multimedia/ffmpeg/ffmpeg/CVE-2026-64831.patch diff --git a/meta/recipes-multimedia/ffmpeg/ffmpeg/CVE-2026-64831.patch b/meta/recipes-multimedia/ffmpeg/ffmpeg/CVE-2026-64831.patch new file mode 100644 index 00000000000..29218b3608f --- /dev/null +++ b/meta/recipes-multimedia/ffmpeg/ffmpeg/CVE-2026-64831.patch @@ -0,0 +1,36 @@ +From 60044ad2b2dbd9a728a1471b0e36eed3157a6ad5 Mon Sep 17 00:00:00 2001 +From: Pavel Kohout +Date: Tue, 30 Jun 2026 21:55:49 +0200 +Subject: [PATCH] avcodec/vulkan_hevc: reject too many VPS HRD parameter sets + +Fixes: stack buffer overflow +Fixes: tD7Mj0ST7ND3 +Fixes: 82864c21112157951ce91b4430a9018edd02f5ab (vulkan_hevc: use VK_KHR_video_maintenance2 if available) +Found-by: Pavel Kohout (Aisle Research) +Signed-off-by: Michael Niedermayer + +CVE: CVE-2026-64831 +Upstream-Status: Backport [https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/92737390dc133daadce47dd7d2ec8ef3d9ebcbed] + +Signed-off-by: Bhavesh R Maheshwari +--- + libavcodec/vulkan_hevc.c | 3 +++ + 1 file changed, 3 insertions(+) + +diff --git a/libavcodec/vulkan_hevc.c b/libavcodec/vulkan_hevc.c +index 5e15c6b931..34676113a9 100644 +--- a/libavcodec/vulkan_hevc.c ++++ b/libavcodec/vulkan_hevc.c +@@ -875,6 +875,9 @@ static int vk_hevc_end_frame(AVCodecContext *avctx) + vksps_p.vcl_hdr, &vksps_p.ptl, &vksps_p.dpbm, + &vksps_p.pal, vksps_p.str, &vksps_p.ltr); + ++ if (sps->vps->vps_num_hrd_parameters > HEVC_MAX_SUB_LAYERS) ++ return AVERROR_INVALIDDATA; ++ + vkvps_p.sls = vkvps_ps; + set_vps(sps->vps, &vkvps, &vkvps_p.ptl, &vkvps_p.dpbm, + vkvps_p.hdr, vkvps_p.sls); +-- +2.43.0 + diff --git a/meta/recipes-multimedia/ffmpeg/ffmpeg_8.0.3.bb b/meta/recipes-multimedia/ffmpeg/ffmpeg_8.0.3.bb index 8c1969369b6..02b9cf65a5f 100644 --- a/meta/recipes-multimedia/ffmpeg/ffmpeg_8.0.3.bb +++ b/meta/recipes-multimedia/ffmpeg/ffmpeg_8.0.3.bb @@ -27,6 +27,7 @@ SRC_URI = "https://www.ffmpeg.org/releases/${BP}.tar.xz \ file://0001-ffbuild-commonmak-Consolidate-pattern-rules-for-comp.patch \ file://0002-ffbuild-common.mak-ensure-target-directories-are-cre.patch \ file://CVE-2026-64830.patch \ + file://CVE-2026-64831.patch \ " SRC_URI[sha256sum] = "6136812ea6d4e68bdba27e33c2a94382711cdf4f8602ffef056ff792bd6f9818" From patchwork Thu Sep 17 22:06:56 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 98643 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id E8D6FC982DF for ; Thu, 17 Sep 2026 22:08:39 +0000 (UTC) Received: from mail-wm2-f12.google.com (mail-wm2-f12.google.com [74.125.225.140]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.1710.1789682909752127090 for ; Thu, 17 Sep 2026 15:08:30 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=DKviWKvn; spf=pass (domain: smile.fr, ip: 74.125.225.140, mailfrom: yoann.congal@smile.fr) Received: by mail-wm2-f12.google.com with SMTP id 5b1f17b1804b1-49b912d3920so877205e9.1 for ; Thu, 17 Sep 2026 15:08:29 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1789682908; x=1790287708; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=6x8C4HMJL7SEOtTzwT1kc5qOyfkxghFDFhkQG2mQiFY=; b=DKviWKvnEp8vTz/WCV1MYO8Lwdn1P/6uQWj+6lp6hGcG9/+tEDFWj4t2hYzn21WuJu 24vTqoqgKZr48rmtM4dyA9D2yYxwSUdL9zTWsY1Xg7yv9vpXb3c7Ntx/wnaHlk/rrP86 jQ08LnTUPtg72voEcjTF3af/nCt+ZY8OYUTs0= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1789682908; x=1790287708; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=6x8C4HMJL7SEOtTzwT1kc5qOyfkxghFDFhkQG2mQiFY=; b=yOvKtjvyPgApFC/OZ8l4WEAcrwqnGAxL41N2Ax/861MdpNiubSWfI5aA7owOo9rJzM 0mqqVF93ZaQIUaJKCCLmgaaSl4KQmaSeMdCYAYiAYkJL6EOEthL524sDBlNDh0hjs2o2 HdbjTBe4ZmCRbT/xAOrmzK7HKz45Omot3Bo0EDB2UiF5PdXG1QfpmT1MSWvwnTsZgBN0 pmEs6bord5FOXiAP1+gplz7bhK39Nkjq1J0Yvo1ir/Wd0zC8DheqIBz5C/v7jqgfO6+o 1j38e+REJ8UpolaNvb1WlFBTFt9ZAeqytARyW2Bk4vH7G2qbN9pX/wAPdIGr2z3uhgfv /uCw== X-Gm-Message-State: AFuF++m3IBiL5zZU34fFS964mwS4V1Yngu/EjB66MNbbk1lL/gtiXrII 3XAgIRF+RfkhDiJ4uTElKbue0+wO1LX5gMeWTiFAYZtFuWLHQNSiXwqJZFSC+ur7Zd2BXPNlrdZ +ZuHmiXs= X-Gm-Gg: AYBFou2bAtd2VsebJywqHsDT47RhbA8JkK7z1DU0BFDdvQlzD8RswVE2eniXJdoyOK/ A66f7fOqD+kKal/OqX0fQnx55YLAe8yLhWtrgGvnEFGbf5KQXS8KoJUe00G2S04WIF+dM3/h8yI mhHNY0u2JhUX4J4Q814QlDnWjZ2yaUB85Mm3MOgsu51faa5J89X/b125dehX5razbGumnkgAu1e P+qikLWNJcPIgpk8CrOgPE4jgnLjTa0o4t4AxabqaypSv15yQjF3+oWGTnVepETGzvtykBwQTxz CX76cTJ2yrpX3dNOqRmo1Eyzlqfn2OvmxzPcK1j10ZRNl425CoyZpvROuFSQuznsO9gCOeZF7p6 woidyR2rYNS6+wRvZAT0G8uiibLKJGtXWVhA4sb89mcJ5VsjuGRdtsf7RvrE461oRDnPg/prh5b Jwfp0QBSWGa1QBBCHFz3sH9ReisdVvPqxw19bWvvcEGbSdeuwQfVmN+hMUc2WQfzXfSsHYywH79 7VkuzJxDw5ImkC2oc8Izhhi5rPiTRvVYwztLlaaFieWxU14VyeLdbBg7/bRZPV8fkOA7Jm8OZQi QmCR5ihYkw== X-Received: by 2002:a05:600c:1f8f:b0:49e:8354:26fb with SMTP id 5b1f17b1804b1-49fc574c729mr3407585e9.32.1789682908042; Thu, 17 Sep 2026 15:08:28 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-49fc471b9a2sm8984075e9.0.2026.09.17.15.08.27 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Thu, 17 Sep 2026 15:08:27 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][wrynose 71/79] ffmpeg: Fix for CVE-2026-64832 Date: Fri, 18 Sep 2026 00:06:56 +0200 Message-ID: <318ff4bc617515c33ec94af6b8468acbaa247323.1789681419.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Thu, 17 Sep 2026 22:08:39 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/246166 From: Bhavesh R Maheshwari Pick the patch from [1], also referenced in the NVD report [2]. [1] https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/4c6217477fc64305055b37d9d1d0d76d30e37f97 [2] https://nvd.nist.gov/vuln/detail/CVE-2026-64832 Signed-off-by: Bhavesh R Maheshwari Signed-off-by: Yoann Congal --- .../ffmpeg/ffmpeg/CVE-2026-64832.patch | 47 +++++++++++++++++++ .../recipes-multimedia/ffmpeg/ffmpeg_8.0.3.bb | 1 + 2 files changed, 48 insertions(+) create mode 100644 meta/recipes-multimedia/ffmpeg/ffmpeg/CVE-2026-64832.patch diff --git a/meta/recipes-multimedia/ffmpeg/ffmpeg/CVE-2026-64832.patch b/meta/recipes-multimedia/ffmpeg/ffmpeg/CVE-2026-64832.patch new file mode 100644 index 00000000000..28d6c0343f5 --- /dev/null +++ b/meta/recipes-multimedia/ffmpeg/ffmpeg/CVE-2026-64832.patch @@ -0,0 +1,47 @@ +From 55645f03fa9dc2e5ef5f79b875950391e920506b Mon Sep 17 00:00:00 2001 +From: Michael Niedermayer +Date: Tue, 30 Jun 2026 00:24:07 +0200 +Subject: [PATCH] avcodec/nvdec: don't double free the fdd-owned context on the + sep_ref error path + +Fixes: double free +Fixes: rpSz7v3yq2u8 +Fixes: 72982f8cb5dad6252a14226d28128313eed4a5ff (avcodec/nvdec: add support for separate reference frame) +Found-by: Pavel Kohout (Aisle Research) +Signed-off-by: Michael Niedermayer + +CVE: CVE-2026-64832 +Upstream-Status: Backport [https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/4c6217477fc64305055b37d9d1d0d76d30e37f97] + +Signed-off-by: Bhavesh R Maheshwari +--- + libavcodec/nvdec.c | 6 +----- + 1 file changed, 1 insertion(+), 5 deletions(-) + +diff --git a/libavcodec/nvdec.c b/libavcodec/nvdec.c +index 7c29f25718..787a9d7c28 100644 +--- a/libavcodec/nvdec.c ++++ b/libavcodec/nvdec.c +@@ -628,8 +628,7 @@ int ff_nvdec_start_frame_sep_ref(AVCodecContext *avctx, AVFrame *frame, int has_ + cf->ref_idx_ref = av_refstruct_pool_get(ctx->decoder_pool); + if (!cf->ref_idx_ref) { + av_log(avctx, AV_LOG_ERROR, "No decoder surfaces left\n"); +- ret = AVERROR(ENOMEM); +- goto fail; ++ return AVERROR(ENOMEM); + } + } + cf->ref_idx = *cf->ref_idx_ref; +@@ -639,9 +638,6 @@ int ff_nvdec_start_frame_sep_ref(AVCodecContext *avctx, AVFrame *frame, int has_ + } + + return 0; +-fail: +- nvdec_fdd_priv_free(cf); +- return ret; + } + + int ff_nvdec_end_frame(AVCodecContext *avctx) +-- +2.43.0 + diff --git a/meta/recipes-multimedia/ffmpeg/ffmpeg_8.0.3.bb b/meta/recipes-multimedia/ffmpeg/ffmpeg_8.0.3.bb index 02b9cf65a5f..4192b1a5c97 100644 --- a/meta/recipes-multimedia/ffmpeg/ffmpeg_8.0.3.bb +++ b/meta/recipes-multimedia/ffmpeg/ffmpeg_8.0.3.bb @@ -28,6 +28,7 @@ SRC_URI = "https://www.ffmpeg.org/releases/${BP}.tar.xz \ file://0002-ffbuild-common.mak-ensure-target-directories-are-cre.patch \ file://CVE-2026-64830.patch \ file://CVE-2026-64831.patch \ + file://CVE-2026-64832.patch \ " SRC_URI[sha256sum] = "6136812ea6d4e68bdba27e33c2a94382711cdf4f8602ffef056ff792bd6f9818" From patchwork Thu Sep 17 22:06:57 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 98646 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 02ECFC982E2 for ; Thu, 17 Sep 2026 22:08:40 +0000 (UTC) Received: from mail-wm2-f13.google.com (mail-wm2-f13.google.com [74.125.225.141]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.1711.1789682910277405407 for ; Thu, 17 Sep 2026 15:08:30 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=VKwiRGQh; spf=pass (domain: smile.fr, ip: 74.125.225.141, mailfrom: yoann.congal@smile.fr) Received: by mail-wm2-f13.google.com with SMTP id 5b1f17b1804b1-49b912d822dso780245e9.2 for ; Thu, 17 Sep 2026 15:08:30 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1789682908; x=1790287708; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=bGLtBz27fL0mASa1JK0nhht9u8A7ucM1rIGI/xQo3Sg=; b=VKwiRGQhNrRJrDincOE0n6TGxNBfAtE1E5RpwT0rcvHekrhzlEo2cyJYwvUWfjv95a 3ENfRO8DeQNIR8UOGUj6H3aAceKYX6cOc50OrC2a7D+ayBTQSLVmb16QHufWTA+JvvAA yb7WL1oVsX89RN5GqRdeoHQKZMjx05aWb0OaQ= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1789682908; x=1790287708; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=bGLtBz27fL0mASa1JK0nhht9u8A7ucM1rIGI/xQo3Sg=; b=VM1DkpBsJeDl7Jo/R2YiTDKHw41gTpbyZWHp6Ck9TAW0fBEzvmGMfOTgGEwLJOj4Gr lmWkVD+HaEorrsEoDAKEfFC03H0Hx2N3wj2tRHZy2Zs0xzt+p3P2sDq30EQp6ZNbAYvm a3iveyUPH1KpxlR14xFTNTPQyVX7V0xASoVtyttR3W1PLabfwWGJsDBgSLOVGosocIkn pV5Q1PXkq69c3GSHZEGByc8gZB6SCNlCiGIeQyC75aDZOo8KQ4BKAZx8GeOyFlsePHyr 6UCMmWTyWJoKqB+oV/+XWq4Zwdq8GvZGwLqa0nZxFmeCSrr6D7jFJEtJK7rr4nMfuN/+ r1sg== X-Gm-Message-State: AFuF++ncA5GRWpihw9zktvA/zuXzkw/hDU0vFIjpHFPDqsK717ErIU5j tXdHnW+mQ7mIqJynjqnsdifOyWvcS4MITaDhXS89Nrkn6ZzHqdeeEdarn4tNXcZIm3ggHgT4o3b TKey7wJM= X-Gm-Gg: AYBFou3T9hzEYyzYjbFhGmng5pbcueNIODaI+RWEvePMHxeVz4n7Uw4+ztfM17AFjTf a7YNgEjrF3e+81yz3B/5eYiDr8CEZ/ImIxiZdpQBm30xPTAhl9Fb+8w4+vZCw47vrMSpA9PA1Gw vBMIUJZ6YjWkewPNlRPLqw57HMy7+s6ZCw9nIS1rLTLzo0BjBc9tby0dK/uOrVY0yQyK8SF+iiw EcioX07GrrVUNZlZ9Qd1wHmv55TTlDPG6tpBe39KEN896j9jF5UFPIoEk2mDP4sCryEdYw3l6Mt sUogrw4G8IH79Z2vnf+es49jWHBL7tGcEAE1zVyf2jrL+1kN2cm3jd7x/MfYtceCD2WCRRDLLqk CNoLmYu3Ju+ifBwnkWdCVT1IKp1w3Khf8gYPTW/3t/u9KXdwjJJpOJK2+0YD0s4op/XgTRCQWHB o7uQUatOnpLAdqZ4R7mKPKCYc/NiMyNs6hV25f+HVGdYX2FiEa4cJ5mhsyAXF0WfIZ6B+ZR8JWp h0mFdXhSxLnzvePT5yl7N1GXs86IUghqOFwM8B8lY60n276kZz9SZJgNi+ceYhWVc6FzNVksgva 1Fotf2uesw== X-Received: by 2002:a05:600c:4eca:b0:49c:d818:8764 with SMTP id 5b1f17b1804b1-49fc56adf0emr3552235e9.11.1789682908502; Thu, 17 Sep 2026 15:08:28 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-49fc471b9a2sm8984075e9.0.2026.09.17.15.08.28 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Thu, 17 Sep 2026 15:08:28 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][wrynose 72/79] ffmpeg: Fix for CVE-2026-64833 Date: Fri, 18 Sep 2026 00:06:57 +0200 Message-ID: <59e03c4fb5a83a7d11c18638ca4d3b93d881e8c9.1789681419.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Thu, 17 Sep 2026 22:08:40 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/246167 From: Bhavesh R Maheshwari Pick the patch from [1], also referenced in the NVD report [2]. [1] https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/6f80e2765492700622596af720534cef33dd31b4 [2] https://nvd.nist.gov/vuln/detail/CVE-2026-64833 Signed-off-by: Bhavesh R Maheshwari Signed-off-by: Yoann Congal --- .../ffmpeg/ffmpeg/CVE-2026-64833.patch | 36 +++++++++++++++++++ .../recipes-multimedia/ffmpeg/ffmpeg_8.0.3.bb | 1 + 2 files changed, 37 insertions(+) create mode 100644 meta/recipes-multimedia/ffmpeg/ffmpeg/CVE-2026-64833.patch diff --git a/meta/recipes-multimedia/ffmpeg/ffmpeg/CVE-2026-64833.patch b/meta/recipes-multimedia/ffmpeg/ffmpeg/CVE-2026-64833.patch new file mode 100644 index 00000000000..407ebf0ece3 --- /dev/null +++ b/meta/recipes-multimedia/ffmpeg/ffmpeg/CVE-2026-64833.patch @@ -0,0 +1,36 @@ +From 9d412e4715b17404b5e4c6d9f0d2b5c1a100aa74 Mon Sep 17 00:00:00 2001 +From: Michael Niedermayer +Date: Tue, 30 Jun 2026 00:11:50 +0200 +Subject: [PATCH 2/9] avformat/spdifenc: bound DTS core_size against the packet + size in the HD path + +Fixes: out of array read +Fixes: yBSax492UIB9 +Fixes: 482d98f69b2 (spdifenc: IEC 61937 encapsulation of DTS-HD for HDMI) +Found-by: Pavel Kohout (Aisle Research) +Signed-off-by: Michael Niedermayer + +CVE: CVE-2026-64833 +Upstream-Status: Backport [https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/6f80e2765492700622596af720534cef33dd31b4] + +Signed-off-by: Bhavesh R Maheshwari +--- + libavformat/spdifenc.c | 2 +- + 1 file changed, 1 insertion(+), 1 deletion(-) + +diff --git a/libavformat/spdifenc.c b/libavformat/spdifenc.c +index ab3f73d..16eebda 100644 +--- a/libavformat/spdifenc.c ++++ b/libavformat/spdifenc.c +@@ -225,7 +225,7 @@ static int spdif_header_dts4(AVFormatContext *s, AVPacket *pkt, int core_size, + * (dtshd_fallback == 0) */ + ctx->dtshd_skip = 1; + } +- if (ctx->dtshd_skip && core_size) { ++ if (ctx->dtshd_skip && core_size && core_size <= pkt->size) { + pkt_size = core_size; + if (ctx->dtshd_fallback >= 0) + --ctx->dtshd_skip; +-- +2.43.0 + diff --git a/meta/recipes-multimedia/ffmpeg/ffmpeg_8.0.3.bb b/meta/recipes-multimedia/ffmpeg/ffmpeg_8.0.3.bb index 4192b1a5c97..35153b81a99 100644 --- a/meta/recipes-multimedia/ffmpeg/ffmpeg_8.0.3.bb +++ b/meta/recipes-multimedia/ffmpeg/ffmpeg_8.0.3.bb @@ -29,6 +29,7 @@ SRC_URI = "https://www.ffmpeg.org/releases/${BP}.tar.xz \ file://CVE-2026-64830.patch \ file://CVE-2026-64831.patch \ file://CVE-2026-64832.patch \ + file://CVE-2026-64833.patch \ " SRC_URI[sha256sum] = "6136812ea6d4e68bdba27e33c2a94382711cdf4f8602ffef056ff792bd6f9818" From patchwork Thu Sep 17 22:06:58 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 98636 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 27B9EC982D9 for ; Thu, 17 Sep 2026 22:08:39 +0000 (UTC) Received: from mail-wm2-f12.google.com (mail-wm2-f12.google.com [74.125.225.140]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.1606.1789682910568262308 for ; Thu, 17 Sep 2026 15:08:30 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=JRTQOuOz; spf=pass (domain: smile.fr, ip: 74.125.225.140, mailfrom: yoann.congal@smile.fr) Received: by mail-wm2-f12.google.com with SMTP id 5b1f17b1804b1-49e69b9e16aso1215025e9.1 for ; Thu, 17 Sep 2026 15:08:30 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1789682909; x=1790287709; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=3fNkoEPp8E7+aElQtdNDPV2RIlm9VBjzODsLQTrOOJY=; b=JRTQOuOzndpVfjGnjLcBlwufTrl9hyZ0Dc765x7l40gX/Pd/v55AjIuu8tZma8DLEr Vl/3YzdtRjT/SJJb28zC6YzXpIFgd0LAW7LAkewcURSkrxKc4Fv1VEEzVDVpCQt8UYWA Dz9h1PP5bseGFhMoe16H7TfhUcHpai33NLuWE= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1789682909; x=1790287709; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=3fNkoEPp8E7+aElQtdNDPV2RIlm9VBjzODsLQTrOOJY=; b=qlXijjxsrFugcvPFs45KouQyhLWajbNghtrBnb/OsSO7TJeq6pkkCUIW6av5SeoMu2 50gVLoK3crCW+AgxWk/5XA9qIstRdpBZgMFvzCrAACM8RuZ4FEURDrC44nsRvAum+FR1 zixo3FQw4G3Ma0Nvl3v4Z1BSG7Nt1dJIKGnYGn/fY7b1aRSX67LESowa15qNMZxtKjLC 961/QjjlyzEcksD23B4DbG6vaRaoQPH9EahY0qDjNR3W8kajMXImCezgzXYHPd+s54Pm O5u07QKBsIfrPLaVzbDC27U/3yxGzRTaYWHvvWqXlHjzTiAHKppxTUShsg5pvFOOjFlH j28g== X-Gm-Message-State: AFuF++moGa1UgYgmTBi9xIk4BDVtJuKn41EoN3E+r25sb7NSgEBRLQcO NHz9OK6UGpbHosDlcaqk00X2SX/JbRfRAnmovOdCnpTRvEzLESY50OzDpTS8e017EHmdpOWsBa/ 03czNDkk= X-Gm-Gg: AYBFou2zuJdM80u6tYTjQ2+df7QRkYUu6uev4YC7ZVWaRIzQN8/GvvVwCy5WSoulnUY 9hxMGyGhTakoDUELUyrRt+egLhwOxz2q+GUDYqOgsb+HHhuU+GiCIY+s0cpHn2RSyFR5nZ+/2zW Hlt/7BnNQ/1trtwGJtRDWRHvV79mBprNIf74t1C2Lyehyz3pTyIAq3RCx/zCk6w1+JtFsKU/WOw w0FG2ZBWdt8fnQOYea/8dmFTOKdhumL1nfDGlbHazZdE5CstRK64cABpg4hzlmRp+ROh+zcVltv rirKyr19kvFxbC0M+NUBBDvV1bz7UyrM/2ddVsJc7Woo8x9rqOPiDzB2qiOvdCXYKtz8eVyOqqT J4AtMnJtkr3IFlqLuTIWqUw2T2bH6ogCRLXuMuNpnCcOO8IjkqTaf9e2BpkxralP/8ijDfYfCt7 kCSRPWNX9+A/OPBeR0a0PkfMz/tLj5W+6EUMCvm9bw6D6otlLsS/sDGzIWzQw5L1ntYxwlmKiNi dcG1Wt3lYBz0kHKa1D9xvG6ycEtiMEuhn04bz5VnYLUul9x9/VFQm3wm9orDaAaxeMyMhO/olg= X-Received: by 2002:a05:600c:6206:b0:49c:fff9:f684 with SMTP id 5b1f17b1804b1-49fc5735339mr3214005e9.21.1789682908900; Thu, 17 Sep 2026 15:08:28 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-49fc471b9a2sm8984075e9.0.2026.09.17.15.08.28 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Thu, 17 Sep 2026 15:08:28 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][wrynose 73/79] ffmpeg: Fix for CVE-2026-64834 Date: Fri, 18 Sep 2026 00:06:58 +0200 Message-ID: X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Thu, 17 Sep 2026 22:08:39 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/246168 From: Bhavesh R Maheshwari Pick the patch from [1], also referenced in the NVD report [2]. [1] https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/11d5f475be95d22d5f0692220cc772b116abc632 [2] https://nvd.nist.gov/vuln/detail/CVE-2026-64834 Signed-off-by: Bhavesh R Maheshwari Signed-off-by: Yoann Congal --- .../ffmpeg/ffmpeg/CVE-2026-64834.patch | 36 +++++++++++++++++++ .../recipes-multimedia/ffmpeg/ffmpeg_8.0.3.bb | 1 + 2 files changed, 37 insertions(+) create mode 100644 meta/recipes-multimedia/ffmpeg/ffmpeg/CVE-2026-64834.patch diff --git a/meta/recipes-multimedia/ffmpeg/ffmpeg/CVE-2026-64834.patch b/meta/recipes-multimedia/ffmpeg/ffmpeg/CVE-2026-64834.patch new file mode 100644 index 00000000000..d4a44d293c2 --- /dev/null +++ b/meta/recipes-multimedia/ffmpeg/ffmpeg/CVE-2026-64834.patch @@ -0,0 +1,36 @@ +From 9ac8fe453e443c3fc07bf85099cc93ca100d302f Mon Sep 17 00:00:00 2001 +From: Pavel Kohout +Date: Tue, 30 Jun 2026 21:55:16 +0200 +Subject: [PATCH 3/9] avformat/rtpdec_asf: reject ASF objects smaller than + their header + +Fixes: infinite loop +Fixes: MzWwJdpZF2Ls +Fixes: c2f3eec445389d67afc8c699ba23915a20cae51c (Implement RTSP-MS/ASF packet parsing.) +Found-by: Pavel Kohout (Aisle Research) +Signed-off-by: Michael Niedermayer + +CVE: CVE-2026-64834 +Upstream-Status: Backport [https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/11d5f475be95d22d5f0692220cc772b116abc632] + +Signed-off-by: Bhavesh R Maheshwari +--- + libavformat/rtpdec_asf.c | 2 ++ + 1 file changed, 2 insertions(+) + +diff --git a/libavformat/rtpdec_asf.c b/libavformat/rtpdec_asf.c +index b3b346f..f7fa69e 100644 +--- a/libavformat/rtpdec_asf.c ++++ b/libavformat/rtpdec_asf.c +@@ -56,6 +56,8 @@ static int rtp_asf_fix_header(uint8_t *buf, int len) + uint64_t chunksize = AV_RL64(p + sizeof(ff_asf_guid)); + int skip = 6 * 8 + 3 * 4 + sizeof(ff_asf_guid) * 2; + if (memcmp(p, ff_asf_file_header, sizeof(ff_asf_guid))) { ++ if (chunksize < sizeof(ff_asf_guid) + 8) ++ return -1; + if (chunksize > end - p) + return -1; + p += chunksize; +-- +2.43.0 + diff --git a/meta/recipes-multimedia/ffmpeg/ffmpeg_8.0.3.bb b/meta/recipes-multimedia/ffmpeg/ffmpeg_8.0.3.bb index 35153b81a99..c00c3f32b78 100644 --- a/meta/recipes-multimedia/ffmpeg/ffmpeg_8.0.3.bb +++ b/meta/recipes-multimedia/ffmpeg/ffmpeg_8.0.3.bb @@ -30,6 +30,7 @@ SRC_URI = "https://www.ffmpeg.org/releases/${BP}.tar.xz \ file://CVE-2026-64831.patch \ file://CVE-2026-64832.patch \ file://CVE-2026-64833.patch \ + file://CVE-2026-64834.patch \ " SRC_URI[sha256sum] = "6136812ea6d4e68bdba27e33c2a94382711cdf4f8602ffef056ff792bd6f9818" From patchwork Thu Sep 17 22:06:59 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 98637 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 5F030C982DA for ; Thu, 17 Sep 2026 22:08:39 +0000 (UTC) Received: from mail-wm2-f12.google.com (mail-wm2-f12.google.com [74.125.225.140]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.1712.1789682911044575896 for ; Thu, 17 Sep 2026 15:08:31 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=KvTTM+Fs; spf=pass (domain: smile.fr, ip: 74.125.225.140, mailfrom: yoann.congal@smile.fr) Received: by mail-wm2-f12.google.com with SMTP id 5b1f17b1804b1-49e69b9e16aso1215045e9.1 for ; Thu, 17 Sep 2026 15:08:30 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1789682909; x=1790287709; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=2/95z/lUNITl6R/xcxplsTQsWVLilSANCmdgmfvni+Y=; b=KvTTM+FsZD2P0IVKBD09FsoEBQWnk0MtDJbL/B/Ay6GbU/rePqtwEJg2O575w0cg6J uf72+UQi6qkJBLBq36jc8KUDKmzeADwe/6b/DcGqW1lmk7EP0vuQTiJgT5XZoFWq3nP+ HFBu2eTEsluZs8v/jTd48pK/O0J+rIdgd82nM= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1789682909; x=1790287709; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=2/95z/lUNITl6R/xcxplsTQsWVLilSANCmdgmfvni+Y=; b=V4EywNG0qQRjhZ+fjj0gtDfNWuooL3sxu6A6Enfu5bBKW43DUSSP8zsgLbpzWUCNey ouxDVJF7VkAFKF8covRA0d4zQiuMWru8A/YZjpxMT/ED4UJFQOBnBBVKrFw6gpv9SfYr /IJj+BDZ7JXRrvNNzSKTE51PO4C4sMkpPmG8pEGvHkdvmHt1aAZgfKmJnWta0ZFlERug c7wwbAtDaYqwcRSXHZZsMWDi0zgOMvVNLzsEthMlDrs+cWC4uWR3yx9meKIXjO1MyDSU 4O3ZRh4YAiNGsGw60KQEwmnqpGfhWsa46qxyPMYC3StOD/AZJnX5Az3Az5lUpqcLFI6T 8n0Q== X-Gm-Message-State: AFuF++m157SVXYXIxaypGlRWrriq/79wdQksmnBNi/C6y+sjHE2zS7lz x00ODUHViO7RWtezz2uR8uOAqy3X0jyAH33BMo0Op7vBG4ViZwhlxcU7Q4XpwxA7r2Psw9k7E4l fMdS2OVU= X-Gm-Gg: AYBFou1NfvElL9vM0RUk65rTfVygEO1P1RNDN1lMz1ICtQfpPj2L13IBHtJRKyaymHs /z+bOV8Lf0xcNX31VKxiYpe+RWAJQVwxpfaoL2f5ZXL2fD3HLQ3TfeXd8mV+Nun9xmdoFEwC0YB qenkH+9QlYnQp4kx3KZrP+SWkfcRsQ/KpP5KTFIg1zF7MPuuCRvCgN8DLT3AEVffq9yEruTWhEX UEfF2qF6eGXL7yQjndb2j0FwKSE5h/ra4e5bNGkk68CxdG+wGUvcc5XjH3qD7nAun+55wObXbx2 XUnZh6RFNBKSZ2uAyxBJzTGlI1leP0QyvwKzjo4dFaJLSuw+cFI936T6ul01p0+GRmrE37TO8dF IfSUsNDcXjScCF98T+cv9bFtQnsozUcXJf3ntw2yvertHRkQWHxPuLv5GsevXxk2yz7ET1elfgZ Ogik7p6Y9QSIPv5GEN17Rx8EobDGUrPhgLx6NWXEXGbv4Zk4oNE7/TXnazgJGxRBE31xd2o8HTo PV3Av8R82R6Iku1JQkFIxOlsMoCukhK0X6a4pv4LOBREyrXq+DGSC5lmLC3tBOhgy2+H5qMGFU= X-Received: by 2002:a05:600c:1f87:b0:49d:99:1d98 with SMTP id 5b1f17b1804b1-49fc56ae924mr3944625e9.9.1789682909325; Thu, 17 Sep 2026 15:08:29 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-49fc471b9a2sm8984075e9.0.2026.09.17.15.08.28 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Thu, 17 Sep 2026 15:08:29 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][wrynose 74/79] ffmpeg: Fix for CVE-2026-64835 Date: Fri, 18 Sep 2026 00:06:59 +0200 Message-ID: <599f1e0f2f8726120db26817eab07b38aed60f02.1789681419.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Thu, 17 Sep 2026 22:08:39 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/246169 From: Bhavesh R Maheshwari Pick the patch from [1], also referenced in the NVD report [2]. [1] https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/1836ef96846937a6cc2443698a693104f5c0b21e [2] https://nvd.nist.gov/vuln/detail/CVE-2026-64835 Signed-off-by: Bhavesh R Maheshwari Signed-off-by: Yoann Congal --- .../ffmpeg/ffmpeg/CVE-2026-64835.patch | 45 +++++++++++++++++++ .../recipes-multimedia/ffmpeg/ffmpeg_8.0.3.bb | 1 + 2 files changed, 46 insertions(+) create mode 100644 meta/recipes-multimedia/ffmpeg/ffmpeg/CVE-2026-64835.patch diff --git a/meta/recipes-multimedia/ffmpeg/ffmpeg/CVE-2026-64835.patch b/meta/recipes-multimedia/ffmpeg/ffmpeg/CVE-2026-64835.patch new file mode 100644 index 00000000000..735bd1176f0 --- /dev/null +++ b/meta/recipes-multimedia/ffmpeg/ffmpeg/CVE-2026-64835.patch @@ -0,0 +1,45 @@ +From 99c7dfd80d63bf009a102d3278a9f98b2fe68002 Mon Sep 17 00:00:00 2001 +From: Pavel Kohout +Date: Mon, 29 Jun 2026 23:46:16 +0200 +Subject: [PATCH 4/9] avcodec/adx: sync decoder channel state on NEW_EXTRADATA + +Fixes: out of array access +Fixes: heaNtmHvklpe +Fixes: 92396cee602320c714713ca2d93b53684ad57000 (avformat: add CRI AAX demuxer) +Found-by: Pavel Kohout (Aisle Research) +Signed-off-by: Michael Niedermayer + +CVE: CVE-2026-64835 +Upstream-Status: Backport [https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/1836ef96846937a6cc2443698a693104f5c0b21e] + +Signed-off-by: Bhavesh R Maheshwari +--- + libavcodec/adxdec.c | 5 +++++ + 1 file changed, 5 insertions(+) + +diff --git a/libavcodec/adxdec.c b/libavcodec/adxdec.c +index 21be6fe..10fd81d 100644 +--- a/libavcodec/adxdec.c ++++ b/libavcodec/adxdec.c +@@ -172,6 +172,7 @@ static int adx_decode_frame(AVCodecContext *avctx, AVFrame *frame, + new_extradata = av_packet_get_side_data(avpkt, AV_PKT_DATA_NEW_EXTRADATA, + &new_extradata_size); + if (new_extradata && new_extradata_size > 0) { ++ int old_channels = c->channels; + int header_size; + if ((ret = adx_decode_header(avctx, new_extradata, + new_extradata_size, &header_size, +@@ -180,6 +181,10 @@ static int adx_decode_frame(AVCodecContext *avctx, AVFrame *frame, + return AVERROR_INVALIDDATA; + } + ++ c->channels = avctx->ch_layout.nb_channels; ++ c->header_parsed = 1; ++ if (old_channels != c->channels) ++ memset(c->prev, 0, sizeof(c->prev)); + c->eof = 0; + } + +-- +2.43.0 + diff --git a/meta/recipes-multimedia/ffmpeg/ffmpeg_8.0.3.bb b/meta/recipes-multimedia/ffmpeg/ffmpeg_8.0.3.bb index c00c3f32b78..8d3b0dd79e0 100644 --- a/meta/recipes-multimedia/ffmpeg/ffmpeg_8.0.3.bb +++ b/meta/recipes-multimedia/ffmpeg/ffmpeg_8.0.3.bb @@ -31,6 +31,7 @@ SRC_URI = "https://www.ffmpeg.org/releases/${BP}.tar.xz \ file://CVE-2026-64832.patch \ file://CVE-2026-64833.patch \ file://CVE-2026-64834.patch \ + file://CVE-2026-64835.patch \ " SRC_URI[sha256sum] = "6136812ea6d4e68bdba27e33c2a94382711cdf4f8602ffef056ff792bd6f9818" From patchwork Thu Sep 17 22:07:00 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 98639 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 7B71AC982DC for ; Thu, 17 Sep 2026 22:08:39 +0000 (UTC) Received: from mail-wm2-f13.google.com (mail-wm2-f13.google.com [74.125.225.141]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.1608.1789682911754695352 for ; Thu, 17 Sep 2026 15:08:32 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=RXyZ72u0; spf=pass (domain: smile.fr, ip: 74.125.225.141, mailfrom: yoann.congal@smile.fr) Received: by mail-wm2-f13.google.com with SMTP id 5b1f17b1804b1-49e71cdb22bso875715e9.2 for ; Thu, 17 Sep 2026 15:08:31 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1789682910; x=1790287710; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=4J1GC0Jmj9KVlGGucPQRAUoRKGCFPdiHm4ukC2wf1h4=; b=RXyZ72u0DWUcmG/QDa956k5KMhsNMsXTeltUVZ8x+6ZG4a2LWtKh1nldlarSZgwPTH 6tBXy5uiUJCYnU/QEJQlDKiwUFu+q173SRDNa+scnME5PwZC+/P8PoptDoQZfr5A3/aL zS46OIfWQHHO5RkxbzwccMTNxX0lqUeYkpZG0= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1789682910; x=1790287710; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=4J1GC0Jmj9KVlGGucPQRAUoRKGCFPdiHm4ukC2wf1h4=; b=YRd1CRf2FB67/CSWugN0tiuJ4WGqjdwOHI5r50AxR2i8YYizp2sJWr9JU12OoVActS OcW7HFyTHwybixgICmlJSouJ7fdaAufrnRgHw5g1bc0BCQ/HXPuEkDumZHIAEZNkWBeq dIx7B0DPF7++RkcODxh27lrDMUMeQJx2J81zQn/GPqONFcBDZU3pfTcWDQImTOKF2LDw +IDEXPGC2bA4a+Nydj91WAEjD+kPEkhzzWQh9ex/1YPgp+JNmJatePWC0k/yyur/5eUZ JBV0t8jY7pu2wcEEDlIa7aKDrUiEb5CjX7cJWV5KFAgLRkrz9GkiisK4VEF/Hw1SkyMM t/iQ== X-Gm-Message-State: AFuF++kVmheDntd8mWSL/ZtMpbXf3um4foKGDI2q20ZfEH+w7G7t9w0d mJZgtLM+AK/rOPmGB3Xm8nQ7P5VyC9ffpKa/fMTySfl3j7ITLteRG8vzLuNSimwQzCgjiCc+f2W ONRYV8bs= X-Gm-Gg: AYBFou0eLSfKqj06R8KOucxvvJJIthLglRyt7oc3QbcmVJHKRNzUcdzGdIZa+sys5hl QFcMK8tlXFAdZHgDypFs5cm08z1WTBfGOad9JVqOJcfRLhDZ3KyOIW+y3J3CRfWUeCeBN0U7g8F Imr5OhOEcc6NalvVKKGR6I1m/Vxub7zlBzxnldaPXvL3WoKcpp9mjviL3ih2MkAT3P6C7zMc975 IqKGVEgEXXPyW3C7Y/+3KgefLtciFjgrqlJIzq38gFU7tJzMaYXFFBWPEyCr9E5jVN9sI6Ig2Fm 2koy2SudU7FKdBkU7hui4CWXYzoUQQsslqPSWxkSwVQlo91+EEaj0MgWNg+xmkcKoCFL4wyTpug iBcPJlZ3K9V9beusOq7sfQeaDu2wyv6W6WO1lzowaCpqB55VZQyU7A8ahifhDy3bu4FYkgANaFO sjQ9O7cnKCcYlANetA35zYMfSmZcysgQKcNQhZHeoAal2N/TFdy4dehtIS+ZgYh4wTjTh6eQrPd Mo02GGTCvYyGHW7/nFYkj/VLz/O1XAL7Qmjk6OtQp4q0+VddwGHIiIXVQfw3ZCesogJxeJnTog= X-Received: by 2002:a05:600c:6309:b0:49e:6b55:22b8 with SMTP id 5b1f17b1804b1-49fc5669353mr3496705e9.4.1789682909986; Thu, 17 Sep 2026 15:08:29 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-49fc471b9a2sm8984075e9.0.2026.09.17.15.08.29 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Thu, 17 Sep 2026 15:08:29 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][wrynose 75/79] ffmpeg: Fix for CVE-2026-65703 Date: Fri, 18 Sep 2026 00:07:00 +0200 Message-ID: X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Thu, 17 Sep 2026 22:08:39 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/246170 From: Bhavesh R Maheshwari Pick the patch from [1], also referenced in the NVD report [2]. [1] https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/fd3ee52fab34d98a95b787d0b5ff45685766200c [2] https://nvd.nist.gov/vuln/detail/CVE-2026-65703 Signed-off-by: Bhavesh R Maheshwari Signed-off-by: Yoann Congal --- .../ffmpeg/ffmpeg/CVE-2026-65703.patch | 47 +++++++++++++++++++ .../recipes-multimedia/ffmpeg/ffmpeg_8.0.3.bb | 1 + 2 files changed, 48 insertions(+) create mode 100644 meta/recipes-multimedia/ffmpeg/ffmpeg/CVE-2026-65703.patch diff --git a/meta/recipes-multimedia/ffmpeg/ffmpeg/CVE-2026-65703.patch b/meta/recipes-multimedia/ffmpeg/ffmpeg/CVE-2026-65703.patch new file mode 100644 index 00000000000..67c319f17e7 --- /dev/null +++ b/meta/recipes-multimedia/ffmpeg/ffmpeg/CVE-2026-65703.patch @@ -0,0 +1,47 @@ +From d15f021e27bd2eb4b7aaeb4cc4f2f49ec3435f48 Mon Sep 17 00:00:00 2001 +From: Cloud-LHY +Date: Fri, 10 Jul 2026 04:07:04 +0200 +Subject: [PATCH 5/9] avcodec/tdsc: unref the reference frame before + reallocating on size change + +Fixes: out of array access +Fixes: tdsc_poc/ffmpeg-tdsc-linesize-report/poc.avi / gen_poc.py +Fixes: tdsc_resize_jpeg_oob.avi / tdsc-resize-stale-linesize-jpeg-oob-generate-poc.py +Fixes: p9xG4xGf9P7H +Fixes: HQL7a1WgTdHZ +Found-by: Cloud-LHY / Clouditera Security, Z.ai Security, NSFOCUS +Found-by: Adrian Junge (vurlo) + +CVE: CVE-2026-65703 +Upstream-Status: Backport [https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/fd3ee52fab34d98a95b787d0b5ff45685766200c] + +Signed-off-by: Bhavesh R Maheshwari +--- + libavcodec/tdsc.c | 8 ++++++-- + 1 file changed, 6 insertions(+), 2 deletions(-) + +diff --git a/libavcodec/tdsc.c b/libavcodec/tdsc.c +index 8baf8e9..ecd67da 100644 +--- a/libavcodec/tdsc.c ++++ b/libavcodec/tdsc.c +@@ -482,11 +482,15 @@ static int tdsc_parse_tdsf(AVCodecContext *avctx, int number_tiles) + return ret; + init_refframe = 1; + } +- ctx->refframe->width = ctx->width = w; +- ctx->refframe->height = ctx->height = h; ++ ctx->width = w; ++ ctx->height = h; + + /* Allocate the reference frame if not already done or on size change */ + if (init_refframe) { ++ av_frame_unref(ctx->refframe); ++ ctx->refframe->format = avctx->pix_fmt; ++ ctx->refframe->width = w; ++ ctx->refframe->height = h; + ret = av_frame_get_buffer(ctx->refframe, 0); + if (ret < 0) + return ret; +-- +2.43.0 + diff --git a/meta/recipes-multimedia/ffmpeg/ffmpeg_8.0.3.bb b/meta/recipes-multimedia/ffmpeg/ffmpeg_8.0.3.bb index 8d3b0dd79e0..8be6b423f75 100644 --- a/meta/recipes-multimedia/ffmpeg/ffmpeg_8.0.3.bb +++ b/meta/recipes-multimedia/ffmpeg/ffmpeg_8.0.3.bb @@ -32,6 +32,7 @@ SRC_URI = "https://www.ffmpeg.org/releases/${BP}.tar.xz \ file://CVE-2026-64833.patch \ file://CVE-2026-64834.patch \ file://CVE-2026-64835.patch \ + file://CVE-2026-65703.patch \ " SRC_URI[sha256sum] = "6136812ea6d4e68bdba27e33c2a94382711cdf4f8602ffef056ff792bd6f9818" From patchwork Thu Sep 17 22:07:01 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 98641 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 937CBC982DB for ; Thu, 17 Sep 2026 22:08:39 +0000 (UTC) Received: from mail-wr2-f12.google.com (mail-wr2-f12.google.com [74.125.225.76]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.1713.1789682912391738162 for ; Thu, 17 Sep 2026 15:08:32 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=D1WGzo2U; spf=pass (domain: smile.fr, ip: 74.125.225.76, mailfrom: yoann.congal@smile.fr) Received: by mail-wr2-f12.google.com with SMTP id ffacd0b85a97d-48583cc7ab1so22533f8f.2 for ; Thu, 17 Sep 2026 15:08:32 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1789682911; x=1790287711; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=Rf1ALEyz0CZS7amM9t+zJ4Xbf3YTvYiYq4rMFw2CE7s=; b=D1WGzo2UrPrA/6TCKNDUZeBwKp0RCaBQfsmkViAd36W/9aJDjGspXkqmY1uFFHFur7 OcdZ9+g7/SQUmLNZqAcYI29BmzrnLBKFyRBDiXHVX5ZUYLzMKkSsucoQlNyXLqlMEpMg I2KeJJgJv8OgjA3+63/qUEyGkq8hVlBvXG7QY= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1789682911; x=1790287711; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=Rf1ALEyz0CZS7amM9t+zJ4Xbf3YTvYiYq4rMFw2CE7s=; b=0QSQ9Jy0t5YGPloYLPT82n4H0bGmnLl/FaryzY1vSX6ZqlcGZEX3St+rp06yWIGqY9 sO08yIBuhMeEhk+MQw71wds0tAcegPQqDGQumuGX2tKFXlsXMUBOvHSvwKGYNysp9QBv 5CDGEJM4SBZFcqWPGyYMMncbF8PfA5nGVtMzdQX6DQg5yXASXk+ARCg0GaPVMArCWyDD lplfTWezOgeMe+aPkI8RyN/3qLRj2sBQCTi1iLB5CNjh/yjYiJ+U090GWP201UoUHhog HHPUTJa2iJ8mKhEVjbmgVTYSzWU2X4M4DJ4SuCru7SEKRXVC1UFgDF8k9wpVhxL04Kit c4hA== X-Gm-Message-State: AFuF++kKXFbkqO5S7Xeu6JP3w7jdiEcixZ/ZQZCLWbPHIEmMcdqkITuv 4+YAKXJp+mviPLBk1no8v5Ovg2iU4ei5T/8ToBlzGdDqTvWp/cRdnqVGCNigEMubrCy0RN1HP35 hUc2UtD8= X-Gm-Gg: AYBFou2QwDRPdx3PQBjO0nvdzxho77YW9TFMFSPf5gbcseFbejmTQJGutR8K7raBkpX B4rEEQzBedGYoAi01lwSXgdq6fD3ewSpRKpX2GpkKhkmG7VFIEFIWp2dmTHz7tuDfoFuposFslC /ZrP6qg7DUR+z9DBH7gy8LxAZdPjLzz8pcKtbiDpTAXEzXQ0Hay8R5KIBj9eKsB6CIdgH4Jrci6 buoDjHyY8IYSvrfGyCK4R/ha24MatTKckIqZbBSdHUjONuN2RHxQa1bRtbTjvI7xv7nOYS+JnsR 6klud0M+ckV6PV87ky/MTH2earCtOfNpQD1G9n2BySoz6BnRYqxOo9dp+sF2/GWd82kZVdnVK/x vyp1TuLrFvwH1AaT2B2B7QayKBvGb7/+L6FaozkjpiEiGaDR3qxL4w7tl/IypsllKgLbncCMSpB +qIBqhDMqWBdA4s4XyRfLLE6QF7eI3wpf0M32VM6BUzBKIqblvvSpifgWJMLAWHXxXPJi+xcWtq T8Z7wqRhzTLHKyHqZrIFCTF6MW/r0rQ+oXw2K6tFlgOQUuBP2n2+PM9ENBey3mNqp40FY4GftI= X-Received: by 2002:a05:600c:3b05:b0:49c:fa21:e746 with SMTP id 5b1f17b1804b1-49fc57570c8mr2823655e9.28.1789682910663; Thu, 17 Sep 2026 15:08:30 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-49fc471b9a2sm8984075e9.0.2026.09.17.15.08.30 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Thu, 17 Sep 2026 15:08:30 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][wrynose 76/79] ffmpeg: Fix for CVE-2026-65704 Date: Fri, 18 Sep 2026 00:07:01 +0200 Message-ID: <830483e7652ca5954c5dfcd660c2e5cbcc565891.1789681419.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Thu, 17 Sep 2026 22:08:39 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/246171 From: Bhavesh R Maheshwari Pick the patch from [1], also referenced in the NVD report [2]. [1] https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/de771bd52774a52d45b0e2c82e56995a1ef40df7 [2] https://nvd.nist.gov/vuln/detail/CVE-2026-65704 Signed-off-by: Bhavesh R Maheshwari Signed-off-by: Yoann Congal --- .../ffmpeg/ffmpeg/CVE-2026-65704.patch | 35 +++++++++++++++++++ .../recipes-multimedia/ffmpeg/ffmpeg_8.0.3.bb | 1 + 2 files changed, 36 insertions(+) create mode 100644 meta/recipes-multimedia/ffmpeg/ffmpeg/CVE-2026-65704.patch diff --git a/meta/recipes-multimedia/ffmpeg/ffmpeg/CVE-2026-65704.patch b/meta/recipes-multimedia/ffmpeg/ffmpeg/CVE-2026-65704.patch new file mode 100644 index 00000000000..223fd03c334 --- /dev/null +++ b/meta/recipes-multimedia/ffmpeg/ffmpeg/CVE-2026-65704.patch @@ -0,0 +1,35 @@ +From e6f2209a3ab20ef0489395697a1882e97658b5b9 Mon Sep 17 00:00:00 2001 +From: Michael Niedermayer +Date: Fri, 10 Jul 2026 04:07:35 +0200 +Subject: [PATCH 6/9] avformat/ty: don't let the Series2 AC3 trim underflow the + packet size + +Fixes: negative-size-param +Fixes: ty-s2-ac3-negative-size-single-file.ffconcat / create_poc.py +Fixes: g0qeE6KvrjZi +Found-by: Adrian Junge (vurlo) + +CVE: CVE-2026-65704 +Upstream-Status: Backport [https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/de771bd52774a52d45b0e2c82e56995a1ef40df7] + +Signed-off-by: Bhavesh R Maheshwari +--- + libavformat/ty.c | 2 +- + 1 file changed, 1 insertion(+), 1 deletion(-) + +diff --git a/libavformat/ty.c b/libavformat/ty.c +index 596e4cc..1f2b6f8 100644 +--- a/libavformat/ty.c ++++ b/libavformat/ty.c +@@ -577,7 +577,7 @@ static int demux_audio(AVFormatContext *s, TyRecHdr *rec_hdr, AVPacket *pkt) + if (ty->audio_type == TIVO_AUDIO_AC3 && + ty->tivo_series == TIVO_SERIES2) { + if (ty->ac3_pkt_size + pkt->size > AC3_PKT_LENGTH) { +- pkt->size -= 2; ++ pkt->size -= FFMIN(pkt->size, 2); + ty->ac3_pkt_size = 0; + } else { + ty->ac3_pkt_size += pkt->size; +-- +2.43.0 + diff --git a/meta/recipes-multimedia/ffmpeg/ffmpeg_8.0.3.bb b/meta/recipes-multimedia/ffmpeg/ffmpeg_8.0.3.bb index 8be6b423f75..82f4b221b75 100644 --- a/meta/recipes-multimedia/ffmpeg/ffmpeg_8.0.3.bb +++ b/meta/recipes-multimedia/ffmpeg/ffmpeg_8.0.3.bb @@ -33,6 +33,7 @@ SRC_URI = "https://www.ffmpeg.org/releases/${BP}.tar.xz \ file://CVE-2026-64834.patch \ file://CVE-2026-64835.patch \ file://CVE-2026-65703.patch \ + file://CVE-2026-65704.patch \ " SRC_URI[sha256sum] = "6136812ea6d4e68bdba27e33c2a94382711cdf4f8602ffef056ff792bd6f9818" From patchwork Thu Sep 17 22:07:02 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 98644 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id A41E1C982DD for ; Thu, 17 Sep 2026 22:08:39 +0000 (UTC) Received: from mail-wm2-f12.google.com (mail-wm2-f12.google.com [74.125.225.140]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.1714.1789682913282552678 for ; Thu, 17 Sep 2026 15:08:33 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=3ZJf9xFi; spf=pass (domain: smile.fr, ip: 74.125.225.140, mailfrom: yoann.congal@smile.fr) Received: by mail-wm2-f12.google.com with SMTP id 5b1f17b1804b1-49e69b9e16aso1215385e9.1 for ; Thu, 17 Sep 2026 15:08:33 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1789682911; x=1790287711; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=Xxi8Fftrvx98g33ZCUPJ4smMq4JlvFW5/63WdJdqeBM=; b=3ZJf9xFiwPb0A0NRRTAGaPIbaO31+4rJxFbGPtQifyPUvcIUfVz1yfEnE7b1Np0xMk 0tRZYghciw1tMWrsOsDtK1Gw2QKmk6FVHndExl8qKm671jZNKeCmFfwzOPIbCRsEPEev GG9NxVeEb+Y7el6PU41rs8hQRFo3jwhQ+ddOk= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1789682911; x=1790287711; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=Xxi8Fftrvx98g33ZCUPJ4smMq4JlvFW5/63WdJdqeBM=; b=N7jGfnnrUJQPYgvIUILEr0DAjg2nLiFFQB20SllsrC858wxBA7UD3qS+yhHZ/QB3J+ H4Ibz4/Y5yKhMv68pktts/YD2Ze5bF/BSJxh3Ap1gsI/TyFep8QBP+6X5g3t683mUleB 0CGkWaore3b4LcFjQERMuoKp0+WR7xuj4zgIq/XLLelNrRsbMoEPL1ZDGqitEuevdI4T pxJJINbAQHvsioaStD02wJGmr5/vJ96Jdq3DsVgBNIub+60EuWXk4fpECsNF4GoYukY7 KOj5juxLNNTYBH2JWJ/0CAksjvmLR5o7b0az5Speo/MazamasfGMMc64VPqXqN+LvEkX hdjw== X-Gm-Message-State: AFuF++lb0TdejhpxFLWRUWBFQwAIqqgFQ1mHMvYuwDbF8C/MtGY2Enlo QLAvuKGZkhapERzUROKqGHdz7TIRLQjNrsw+1RCgRJ0IrRu5FwEZlFDqf+btsU6S6DF8nQlMYYs daePWti4= X-Gm-Gg: AYBFou1+8ExteGKU5TC4vxY4bB+tnGmx0omjaCMv18kAJetnsMFomsLlxv8mU2GdIb7 lKw4FYLnRAFXTvnj2eAucRftqOMl+K27VJobif7NPFg5dj8lKODAbL34P83AcP/UQfpYSEF3ti0 v+Vw6MK1ImjCkGnnZ0RI4RnsYZBSrFNVv3TltXlo5n/PAYjR/HT5ofvqbiKTk35A0io1nlPvURo H6ZnVUTUog4fTnM5Z9gQHhd2TAL9RtQRBDTCaTUEw1u/PoXiGkMLVoimt4UZ57KBMTwYDpxS3fJ 8uKkTTEFFeVzuVdK4y/RyRpt037ZE5Onvxz8qf2q5xtKWNLnjknpHzcAMxFVwB7rIDd3rIvOYIh NETK+A+BqLQK2qxAQpR1S6Sq2NCq06vt+9qe6Na0j5UuzXsIu3nA7VfUwjs1VYSjanATm/qTz1W R+ALUx6Yzgyr9pZUXCQ9jtZZQf0OceKscxBzCP6Ty9GLUP1RmQ7BNonOr+haOrDwjfK7tbAAtD+ 3q+6brxpNjALlBU/l2IbQKYdK+fmdXWF59TcTecyS0YMLgsxLCfitv2JtmmKDs4FFdrogpRI9w= X-Received: by 2002:a05:600c:c8f:b0:49e:6c9b:4e94 with SMTP id 5b1f17b1804b1-49fc5743124mr3207435e9.28.1789682911457; Thu, 17 Sep 2026 15:08:31 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-49fc471b9a2sm8984075e9.0.2026.09.17.15.08.30 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Thu, 17 Sep 2026 15:08:30 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][wrynose 77/79] ffmpeg: Fix for CVE-2026-65705 Date: Fri, 18 Sep 2026 00:07:02 +0200 Message-ID: <637518b0c2e810265ec5bb801289a6f8f3883a70.1789681419.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Thu, 17 Sep 2026 22:08:39 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/246172 From: Bhavesh R Maheshwari Pick the patch from [1] and [2], mentioned in PR#23780 [3] which is referenced in the NVD report [4] [1] https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/24c322fdb232d0a3f3790d544dcb64e5c2138e79 [2] https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/f186c50cf53aec20e9a29059cb22ca3f2d59201c [3] https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23780 [4] https://nvd.nist.gov/vuln/detail/cve-2026-65705 Signed-off-by: Bhavesh R Maheshwari Signed-off-by: Yoann Congal --- .../ffmpeg/ffmpeg/CVE-2026-65705_p1.patch | 68 +++++++++++ .../ffmpeg/ffmpeg/CVE-2026-65705_p2.patch | 115 ++++++++++++++++++ .../recipes-multimedia/ffmpeg/ffmpeg_8.0.3.bb | 2 + 3 files changed, 185 insertions(+) create mode 100644 meta/recipes-multimedia/ffmpeg/ffmpeg/CVE-2026-65705_p1.patch create mode 100644 meta/recipes-multimedia/ffmpeg/ffmpeg/CVE-2026-65705_p2.patch diff --git a/meta/recipes-multimedia/ffmpeg/ffmpeg/CVE-2026-65705_p1.patch b/meta/recipes-multimedia/ffmpeg/ffmpeg/CVE-2026-65705_p1.patch new file mode 100644 index 00000000000..e331cb9646a --- /dev/null +++ b/meta/recipes-multimedia/ffmpeg/ffmpeg/CVE-2026-65705_p1.patch @@ -0,0 +1,68 @@ +From f73f6cd9a5f230ce02afbc6a74172400b92b1127 Mon Sep 17 00:00:00 2001 +From: Michael Niedermayer +Date: Sat, 11 Jul 2026 16:47:28 +0200 +Subject: [PATCH 7/9] avfilter/vf_floodfill: size the point stack for the + current frame + +Fixes: out of array access +Fixes: 8aj_floodfill_dynamic_size.pgm / 8aj_generate_floodfill_dynamic_size_pgm.py +Fixes: 3MleMXjGZvu3 +Found-by: Adrian Junge (vurlo) + +CVE: CVE-2026-65705 +Upstream-Status: Backport [https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/24c322fdb232d0a3f3790d544dcb64e5c2138e79] + +Signed-off-by: Bhavesh R Maheshwari +--- + libavfilter/vf_floodfill.c | 19 ++++++++++++++++--- + 1 file changed, 16 insertions(+), 3 deletions(-) + +diff --git a/libavfilter/vf_floodfill.c b/libavfilter/vf_floodfill.c +index 6d89963..e569d5f 100644 +--- a/libavfilter/vf_floodfill.c ++++ b/libavfilter/vf_floodfill.c +@@ -41,6 +41,7 @@ typedef struct FloodfillContext { + int nb_planes; + int back, front; + Points *points; ++ unsigned int points_size; + + int (*is_same)(const AVFrame *frame, int x, int y, + unsigned s0, unsigned s1, unsigned s2, unsigned s3); +@@ -271,9 +272,6 @@ static int config_input(AVFilterLink *inlink) + } + + s->front = s->back = 0; +- s->points = av_calloc(inlink->w * inlink->h, 4 * sizeof(Points)); +- if (!s->points) +- return AVERROR(ENOMEM); + + return 0; + } +@@ -292,8 +290,23 @@ static int filter_frame(AVFilterLink *link, AVFrame *frame) + int s3 = s->s[3]; + const int w = frame->width; + const int h = frame->height; ++ size_t nb_points, points_size; + int i, ret; + ++ if (w > UINT16_MAX + 1 || h > UINT16_MAX + 1 || ++ av_size_mult(w, h, &nb_points) < 0 || ++ av_size_mult(nb_points, 4 * sizeof(*s->points), &points_size) < 0) { ++ av_frame_free(&frame); ++ return AVERROR(EINVAL); ++ } ++ ++ av_fast_malloc(&s->points, &s->points_size, points_size); ++ if (!s->points) { ++ av_frame_free(&frame); ++ return AVERROR(ENOMEM); ++ } ++ s->front = s->back = 0; ++ + if (is_inside(s->x, s->y, w, h)) { + s->pick_pixel(frame, s->x, s->y, &s0, &s1, &s2, &s3); + +-- +2.43.0 + diff --git a/meta/recipes-multimedia/ffmpeg/ffmpeg/CVE-2026-65705_p2.patch b/meta/recipes-multimedia/ffmpeg/ffmpeg/CVE-2026-65705_p2.patch new file mode 100644 index 00000000000..91a304015f4 --- /dev/null +++ b/meta/recipes-multimedia/ffmpeg/ffmpeg/CVE-2026-65705_p2.patch @@ -0,0 +1,115 @@ +From 7f99588c7fc27526a2d73dddc91e4cd57a3b401c Mon Sep 17 00:00:00 2001 +From: Michael Niedermayer +Date: Sun, 12 Jul 2026 03:27:47 +0200 +Subject: [PATCH 8/9] avfilter/vf_floodfill: remove unneeded variables + +Signed-off-by: Michael Niedermayer + +CVE: CVE-2026-65705 +Upstream-Status: Backport [https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/f186c50cf53aec20e9a29059cb22ca3f2d59201c] + +Signed-off-by: Bhavesh R Maheshwari +--- + libavfilter/vf_floodfill.c | 35 ++++++++++++++++------------------- + 1 file changed, 16 insertions(+), 19 deletions(-) + +diff --git a/libavfilter/vf_floodfill.c b/libavfilter/vf_floodfill.c +index e569d5f..9bc72e2 100644 +--- a/libavfilter/vf_floodfill.c ++++ b/libavfilter/vf_floodfill.c +@@ -39,7 +39,6 @@ typedef struct FloodfillContext { + int d[4]; + + int nb_planes; +- int back, front; + Points *points; + unsigned int points_size; + +@@ -271,8 +270,6 @@ static int config_input(AVFilterLink *inlink) + } + } + +- s->front = s->back = 0; +- + return 0; + } + +@@ -292,6 +289,7 @@ static int filter_frame(AVFilterLink *link, AVFrame *frame) + const int h = frame->height; + size_t nb_points, points_size; + int i, ret; ++ int front = 0; + + if (w > UINT16_MAX + 1 || h > UINT16_MAX + 1 || + av_size_mult(w, h, &nb_points) < 0 || +@@ -305,7 +303,6 @@ static int filter_frame(AVFilterLink *link, AVFrame *frame) + av_frame_free(&frame); + return AVERROR(ENOMEM); + } +- s->front = s->back = 0; + + if (is_inside(s->x, s->y, w, h)) { + s->pick_pixel(frame, s->x, s->y, &s0, &s1, &s2, &s3); +@@ -323,9 +320,9 @@ static int filter_frame(AVFilterLink *link, AVFrame *frame) + goto end; + + if (s->is_same(frame, s->x, s->y, s0, s1, s2, s3)) { +- s->points[s->front].x = s->x; +- s->points[s->front].y = s->y; +- s->front++; ++ s->points[front].x = s->x; ++ s->points[front].y = s->y; ++ front++; + } + + if (ret = ff_inlink_make_frame_writable(link, &frame)) { +@@ -333,34 +330,34 @@ static int filter_frame(AVFilterLink *link, AVFrame *frame) + return ret; + } + +- while (s->front > s->back) { ++ while (front > 0) { + int x, y; + +- s->front--; +- x = s->points[s->front].x; +- y = s->points[s->front].y; ++ front--; ++ x = s->points[front].x; ++ y = s->points[front].y; + + if (s->is_same(frame, x, y, s0, s1, s2, s3)) { + s->set_pixel(frame, x, y, d0, d1, d2, d3); + + if (is_inside(x + 1, y, w, h)) { +- s->points[s->front] .x = x + 1; +- s->points[s->front++].y = y; ++ s->points[front] .x = x + 1; ++ s->points[front++].y = y; + } + + if (is_inside(x - 1, y, w, h)) { +- s->points[s->front] .x = x - 1; +- s->points[s->front++].y = y; ++ s->points[front] .x = x - 1; ++ s->points[front++].y = y; + } + + if (is_inside(x, y + 1, w, h)) { +- s->points[s->front] .x = x; +- s->points[s->front++].y = y + 1; ++ s->points[front] .x = x; ++ s->points[front++].y = y + 1; + } + + if (is_inside(x, y - 1, w, h)) { +- s->points[s->front] .x = x; +- s->points[s->front++].y = y - 1; ++ s->points[front] .x = x; ++ s->points[front++].y = y - 1; + } + } + } +-- +2.43.0 + diff --git a/meta/recipes-multimedia/ffmpeg/ffmpeg_8.0.3.bb b/meta/recipes-multimedia/ffmpeg/ffmpeg_8.0.3.bb index 82f4b221b75..e39961c6499 100644 --- a/meta/recipes-multimedia/ffmpeg/ffmpeg_8.0.3.bb +++ b/meta/recipes-multimedia/ffmpeg/ffmpeg_8.0.3.bb @@ -34,6 +34,8 @@ SRC_URI = "https://www.ffmpeg.org/releases/${BP}.tar.xz \ file://CVE-2026-64835.patch \ file://CVE-2026-65703.patch \ file://CVE-2026-65704.patch \ + file://CVE-2026-65705_p1.patch \ + file://CVE-2026-65705_p2.patch \ " SRC_URI[sha256sum] = "6136812ea6d4e68bdba27e33c2a94382711cdf4f8602ffef056ff792bd6f9818" From patchwork Thu Sep 17 22:07:03 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 98642 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 3527AC982D8 for ; Thu, 17 Sep 2026 22:08:39 +0000 (UTC) Received: from mail-wm2-f12.google.com (mail-wm2-f12.google.com [74.125.225.140]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.1715.1789682913807028718 for ; Thu, 17 Sep 2026 15:08:34 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=BbpF/rv2; spf=pass (domain: smile.fr, ip: 74.125.225.140, mailfrom: yoann.congal@smile.fr) Received: by mail-wm2-f12.google.com with SMTP id 5b1f17b1804b1-49e69b9e16aso1215425e9.1 for ; Thu, 17 Sep 2026 15:08:33 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1789682912; x=1790287712; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=6vHbFsWDvQzrLuLV4qIQEteJNE9lH7i4fpGBPwPjX1M=; b=BbpF/rv2UuHfndKFSTFNeSoVSt2KZ5sFXrWjOWu00SFjn/pPCGlEC2Yi1pCTl69s6Q jidDHBIO0o/4+JogbDqXuQDqTX16GCq+/EH8BWs6chKlSMZgLJl0LVN+u34keMsLxmB0 cR0sCZKNa2BJWP7vCD3dkoQ3NSABgGA+6ipBE= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1789682912; x=1790287712; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=6vHbFsWDvQzrLuLV4qIQEteJNE9lH7i4fpGBPwPjX1M=; b=MvtD73C4jwovSpnaDVDkcBJjyxpPadlqZ/QObrSCyQ/vKOwiTA65r779ztR9shHSum OmgOQXDzz/AQmQeB36qCBfZku+R1dO8jw8Ch8WU03omGPCI5EBpLuiaEyZS8O7DqoOtg B62jLEDPXkKHjl+vgG4wnXIgpfZp12zcYD/Xo1hKYZiw8SRoE6gasU0X5NhBUl92L2cG muZfw0G/0N2iRVSs7eZjWzStf7eEVs8irMcOpm0Cn3yW1LRIEgteV68X/8695mWs0RwO TDmITem9z0+qENHy0MVdnFUEaEnuBktqU9XcSne145eU5te7riCHTOUaCyCz0k1Etluh mZpQ== X-Gm-Message-State: AFuF++mmWgJwrp/zxe2XswTdtv1j1r7KJm3SCYwyESFNAd9339ew9cbW gXh+dnwU8ugeTkKnO4PQXsBapTaq9+jjHkEpagcjk1CgLeS5HQH07+J5KN+t+LKDTD9hwMva4tS 4ZYsi3ag= X-Gm-Gg: AYBFou2LiAiLky5eVnqoanOhLIDqr4qlumb2O1Vv0JIr3dcKUmUZHguPeu3TYCdwYAW 4ZgRelbhCanElFgwJVHLWubtRC/K+txsiPKqb9c7s+tiSdSymyPJr93LQXfQTQpugolUM5GNvvM CJxz/UEWyTKQjLfcWTnatmKf/HOAO0DIOrkleuPrTpjP9GFuAacv5R1h4voObj5qgOIttke2u4k g8f//mO7B0Fs8nOiWb7ZOY0Ix2eWydR6L0IDH8cK0DrZUp440ieiKgnNOcOAz9DO4JoYqYTIyNA B6pbt5WSh0Rv1/kWYfMvnP1t60ZBCmDqivRKX+n3KDwchl8jwqQjOJ9fw8prlzVmVTdWwFKWyRN mT8MrDSIKpUYlAS2vr7hFIQlWpQc0pk//8+Cewe/L1hOR0PKpJT19mHAhEIpD2KPz9dikqaj2zi gKFTBw5FXQrE8C5nXXQYCyASWyOJR7s/rnnjyJiIk05KTqFEC+6FzevGaUjPnbO2tNB7yz6Q0+/ 7M/2hq2RJ7V8Hc0m4TIJ3r4iYHcmtUejycFalnupZih8eWuHwb9l4xa8FqFM3Y6eLFbyEc2jWvk cd/8yRxBNw== X-Received: by 2002:a05:600d:4453:20b0:49c:fa21:1c7d with SMTP id 5b1f17b1804b1-49fc5a10ca6mr1597805e9.18.1789682912047; Thu, 17 Sep 2026 15:08:32 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-49fc471b9a2sm8984075e9.0.2026.09.17.15.08.31 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Thu, 17 Sep 2026 15:08:31 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][wrynose 78/79] ffmpeg: Fix for CVE-2026-65706 Date: Fri, 18 Sep 2026 00:07:03 +0200 Message-ID: X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Thu, 17 Sep 2026 22:08:39 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/246173 From: Bhavesh R Maheshwari Pick the patch from [1], also referenced in the NVD report [2]. [1] https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/a7e38b617b32f996beaa371bbf04b39907d7a527 [2] https://nvd.nist.gov/vuln/detail/CVE-2026-65706 Signed-off-by: Bhavesh R Maheshwari Signed-off-by: Yoann Congal --- .../ffmpeg/ffmpeg/CVE-2026-65706.patch | 52 +++++++++++++++++++ .../recipes-multimedia/ffmpeg/ffmpeg_8.0.3.bb | 1 + 2 files changed, 53 insertions(+) create mode 100644 meta/recipes-multimedia/ffmpeg/ffmpeg/CVE-2026-65706.patch diff --git a/meta/recipes-multimedia/ffmpeg/ffmpeg/CVE-2026-65706.patch b/meta/recipes-multimedia/ffmpeg/ffmpeg/CVE-2026-65706.patch new file mode 100644 index 00000000000..7311ed71c0c --- /dev/null +++ b/meta/recipes-multimedia/ffmpeg/ffmpeg/CVE-2026-65706.patch @@ -0,0 +1,52 @@ +From 825f9e837f88c0c6983b5ccb70f91a32e9168f3c Mon Sep 17 00:00:00 2001 +From: Michael Niedermayer +Date: Sat, 11 Jul 2026 16:46:39 +0200 +Subject: [PATCH 9/9] avfilter/vf_swaprect: size the temp row buffer for the + widest plane + +Fixes: out of array access +Fixes: 7aj_swaprect_odd17_nv12.nut / 7aj_generate_swaprect_odd17_nv12.py +Fixes: VRAXYvKtmKa8 +Found-by: Adrian Junge (vurlo) + +CVE: CVE-2026-65706 +Upstream-Status: Backport [https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/a7e38b617b32f996beaa371bbf04b39907d7a527] + +Signed-off-by: Bhavesh R Maheshwari +--- + libavfilter/vf_swaprect.c | 12 +++++++++++- + 1 file changed, 11 insertions(+), 1 deletion(-) + +diff --git a/libavfilter/vf_swaprect.c b/libavfilter/vf_swaprect.c +index 5d93f51..fe007ee 100644 +--- a/libavfilter/vf_swaprect.c ++++ b/libavfilter/vf_swaprect.c +@@ -200,6 +200,7 @@ static int config_input(AVFilterLink *inlink) + { + AVFilterContext *ctx = inlink->dst; + SwapRectContext *s = ctx->priv; ++ int size = 0; + + if (!s->w || !s->h || + !s->x1 || !s->y1 || +@@ -210,7 +211,16 @@ static int config_input(AVFilterLink *inlink) + av_image_fill_max_pixsteps(s->pixsteps, NULL, s->desc); + s->nb_planes = av_pix_fmt_count_planes(inlink->format); + +- s->temp = av_malloc_array(inlink->w, s->pixsteps[0]); ++ for (int p = 0; p < s->nb_planes; p++) { ++ int shift = p == 1 || p == 2 ? s->desc->log2_chroma_w : 0; ++ int width = AV_CEIL_RSHIFT(inlink->w, shift); ++ ++ if (width > INT_MAX / s->pixsteps[p]) ++ return AVERROR(EINVAL); ++ size = FFMAX(size, width * s->pixsteps[p]); ++ } ++ ++ s->temp = av_malloc(size); + if (!s->temp) + return AVERROR(ENOMEM); + +-- +2.43.0 + diff --git a/meta/recipes-multimedia/ffmpeg/ffmpeg_8.0.3.bb b/meta/recipes-multimedia/ffmpeg/ffmpeg_8.0.3.bb index e39961c6499..48ece247600 100644 --- a/meta/recipes-multimedia/ffmpeg/ffmpeg_8.0.3.bb +++ b/meta/recipes-multimedia/ffmpeg/ffmpeg_8.0.3.bb @@ -36,6 +36,7 @@ SRC_URI = "https://www.ffmpeg.org/releases/${BP}.tar.xz \ file://CVE-2026-65704.patch \ file://CVE-2026-65705_p1.patch \ file://CVE-2026-65705_p2.patch \ + file://CVE-2026-65706.patch \ " SRC_URI[sha256sum] = "6136812ea6d4e68bdba27e33c2a94382711cdf4f8602ffef056ff792bd6f9818" From patchwork Thu Sep 17 22:07:04 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 98645 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id E3B8BC982E0 for ; Thu, 17 Sep 2026 22:08:39 +0000 (UTC) Received: from mail-wm2-f13.google.com (mail-wm2-f13.google.com [74.125.225.141]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.1610.1789682914491559144 for ; Thu, 17 Sep 2026 15:08:34 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=2uNtvF9v; spf=pass (domain: smile.fr, ip: 74.125.225.141, mailfrom: yoann.congal@smile.fr) Received: by mail-wm2-f13.google.com with SMTP id 5b1f17b1804b1-49e71cdb22bso875905e9.2 for ; Thu, 17 Sep 2026 15:08:34 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1789682913; x=1790287713; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=SGJ1OSHGjpz7DTzH5AI4hCtSiKynSQ08s8HNonUOr3E=; b=2uNtvF9vg4GcdY5IerodjzwXBnqDAjF6xsu2G/lqLhzOK6J4PHxGmqwk55pYDHfG3+ uffSI69Aqd0SsI2Anw5qemYfWd+1+P3rzdcepJ/u8ekg3RI9zYMvRrODdbBm8eqALLcJ ChGgtqEmJTCh7MCaRPv+6ML8OVQwhSlW8sn/4= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1789682913; x=1790287713; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=SGJ1OSHGjpz7DTzH5AI4hCtSiKynSQ08s8HNonUOr3E=; b=Tnf8tEowDnFA84AhxzNRUBIRrvCm5shvMwk0+wJQw9aFj6TM8wp2E8EcMIN+BK7KYj uCIfxdT0CuhkKpJIEk+U2R8YpX5ScIrbUy1SYLZdS2xm4eMEEqUTSTT9frKrgt4nfLkA 9oO6kf5FlbVpCciM+H0ajdRwgsT5U9U4xQbW2eBt6xRH2ky+/2KATpO5cY8evFfnSl9S c6UiwRSaeMDHgYDKgY24+NZkJxELxqGgI3wJNgKzKXx+PlyEAclaIjsT3VSWRwcHtK3c +BVvXOOqt99I5HsbqTpBygZ9FKZXkWn0TM8zjaTSLT1GS7G8zmdNZ0cHqSg01zSwiYxt mibA== X-Gm-Message-State: AFuF++mJqXbi2F0e4YQQvidDUxTKvr08pphcTSv8CHLWo7p4IIseF9cQ GOuK8gH6zVOdZsELoTCB/9wYrBzycgUIWXUQLFrH+agZyegfY8XKbPOj5LhSHimYH9PYmDpAkrt RzhWYtpo= X-Gm-Gg: AYBFou0EfLBu6UXFx9xk2nrYsFz5cA3msZ0m4LtcG6IPYhHug+qIoHxgWDltOnrlBN2 gCzIq9htPEzhF+0CiIOAHljF/hYhp1F++KflWdP8i2rGP4VWZhF0h6J38ALXvvUQzZJ0qxGB6Sw 6TtBV/ixvGFw/T+tCsy1kzsiMjmM8XrQOwYyqtH5Yu0sjqNNQ+PKDTUEZmgsrArDPfhpyEtxEwk p2Op9TaxHya9KwueqY0aee72so3sT/oY8Yzcsxhm9W3gsp9eN1+RDUwndIKd/zBtayPtEkyEbPz 2jZMWyVujFYhl6e2hPeBEDr6LUX/+NPc8kHwm8PddNg+kWgl8wQoNdVXAa88ERL4CRhvrzSjC8r KBpznP32ZQKJgFBoSeMT8ZVjTg6F0gJTnOnpclrM8goAljj2t5M5A47mGtpYqp1qzF7TXhbSXfj gL0xTEZknpPqluxpkkDwuy1qPAlfilfSl61qKgZt2OMduP/AqfGUU8Np2dRow0i4J4t3jkqtqKn tw2kcWGRJiLhKQxPqilYt2Uwmx5aL2VdArFpMFc6kWZMtpi8Ydrt6ZlU/ndbWXExyOBFc2MuAY= X-Received: by 2002:a05:600c:5251:b0:49c:fa20:cc00 with SMTP id 5b1f17b1804b1-49fc5736898mr2841055e9.23.1789682912728; Thu, 17 Sep 2026 15:08:32 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-49fc471b9a2sm8984075e9.0.2026.09.17.15.08.32 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Thu, 17 Sep 2026 15:08:32 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][wrynose 79/79] mesa: align x86 mesa config with LLVM graphics Date: Fri, 18 Sep 2026 00:07:04 +0200 Message-ID: X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Thu, 17 Sep 2026 22:08:39 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/246174 From: AshishKumar Mishra This change makes the x86 and native mesa PACKAGECONFIG appends conditional on the same DISTRO_FEATURES check used by LLVM. As a result, graphics-related Mesa and LLVM options are only added when the distro explicitly enables a graphics stack, while leaving non-graphics minimal images unchanged. (cherry picked from commit 2cf81caa69474c5ec2397ca37622c86519791d44) Signed-off-by: AshishKumar Mishra Signed-off-by: Yoann Congal --- meta/recipes-graphics/mesa/mesa.bb | 8 ++++---- 1 file changed, 4 insertions(+), 4 deletions(-) diff --git a/meta/recipes-graphics/mesa/mesa.bb b/meta/recipes-graphics/mesa/mesa.bb index 66c8f9c3720..a646c16af75 100644 --- a/meta/recipes-graphics/mesa/mesa.bb +++ b/meta/recipes-graphics/mesa/mesa.bb @@ -13,10 +13,10 @@ PACKAGECONFIG = " \ zlib \ " -PACKAGECONFIG:append:x86 = " libclc gallium-llvm intel amd nouveau svga" -PACKAGECONFIG:append:x86-64 = " libclc gallium-llvm intel amd nouveau svga" -PACKAGECONFIG:append:i686 = " libclc gallium-llvm intel amd nouveau svga" -PACKAGECONFIG:append:class-native = " libclc gallium-llvm amd nouveau svga" +PACKAGECONFIG:append:x86 = "${@bb.utils.contains_any('DISTRO_FEATURES', 'opengl opencl vulkan', ' libclc gallium-llvm intel amd nouveau svga', '', d)}" +PACKAGECONFIG:append:x86-64 = "${@bb.utils.contains_any('DISTRO_FEATURES', 'opengl opencl vulkan', ' libclc gallium-llvm intel amd nouveau svga', '', d)}" +PACKAGECONFIG:append:i686 = "${@bb.utils.contains_any('DISTRO_FEATURES', 'opengl opencl vulkan', ' libclc gallium-llvm intel amd nouveau svga', '', d)}" +PACKAGECONFIG:append:class-native = "${@bb.utils.contains_any('DISTRO_FEATURES', 'opengl opencl vulkan', ' libclc gallium-llvm amd nouveau svga', '', d)}" GLPROVIDES = " \ ${@bb.utils.contains('PACKAGECONFIG', 'opengl', 'virtual/libgl', '', d)} \