From patchwork Wed Sep 23 09:10:03 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 98962 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id C2D88C98308 for ; Wed, 23 Sep 2026 09:11:23 +0000 (UTC) Received: from mail-wm2-f13.google.com (mail-wm2-f13.google.com [74.125.225.141]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.2910.1790154679081539472 for ; Wed, 23 Sep 2026 02:11:19 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=z2o23hPM; spf=pass (domain: smile.fr, ip: 74.125.225.141, mailfrom: yoann.congal@smile.fr) Received: by mail-wm2-f13.google.com with SMTP id 5b1f17b1804b1-49e721b5503so5648285e9.0 for ; Wed, 23 Sep 2026 02:11:18 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1790154677; x=1790759477; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=p1k89c+HjF1r8L1YEfsDallpilPWI6ndc4Xy6xccvEc=; b=z2o23hPMVaqUSuhboHR2GkZwRGHst1npaVleaO4w8iI7k2zeo6bXiWwsRaNn8zTt37 yXoOMcxFXAv7Yc3hjRNTT0u7H2sVij8skAKOJ9hWgLucgIw/E1Fc6CzA86UnjWGnNmg1 aQTLjL1J2BnvTH4hiy626/Fz/i/gND9HsWdyE= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1790154677; x=1790759477; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=p1k89c+HjF1r8L1YEfsDallpilPWI6ndc4Xy6xccvEc=; b=LRfEeoJ49TikL3l1RSgrBHPLBB4QEJ+wsC5dg2xPOjkJPmeXxoNYlJuRcannQcE5ta 8ExCpkw2UHCZBCjjRoowij/VeycYXFuDtDtrhQfFxS4agjxEqKcBNBsUV5FEamIJbhuL CzT+gfH5wb4Jzn7JS10pS8Hc+HzpLA2yenAY0upe0VfZc3H3Dx2TN5K3yJhU2/ngjzYj yfyV4+zI+X/yxSL2faaqNf2MqCATEEdRebpHtZK8dcFbs4j/I9mxfdjKF2l1XJErTPHc ubN+slBZiAr1EiJe4UyUIM9RlHvA65Hx3DJe1f32IHSM3U2D8mqsp1HXWGrRO5IPSLoU jYAg== X-Gm-Message-State: AFuF++nIyE/kxrc5k7Fs6dwZS6m1cowSwOY9QAhc5h76+azo60WbdD4a O9Jrc6FQaZHLOuipadQ21Q4MjoYdxE+82l+PLv7mxvrR11RvSAnNncGIhGB5JORCDCMuvTJSyMN GePCpUPQ= X-Gm-Gg: AYBFou2hrmoOWhrE3w1aJ7vWzP2tS/H3d22pOSogKVUWN/P7rVr9VXGHvEr4HMWAoZ6 kBif+NW/8sY0enDHvseYNnFhD8ZciwTbjw3nJr3vYP3U10qEyCwlkBl1FNVNO3HVeBCew6iRdla MefDgFlqp9plC0z29zSM8kWm8SU3xkT+Z3cWAByDXi5wI9LMz60Y8QkM+04H31hDkct1fK6AMG3 BQNnjrAz9xjg0+Q6/xNfICnYBjCY2cXA2mjR6rn/lPEn84VtJgN3DyWeuTajShq4UwqsSXjRHOy HYZ8JXu9Z4YhXanfmaWBd8vBxemxi/sWLwCkCIaRusZAWURV9NkXeRq4faftpLvDA+Hvrf1J9lM rxQjKsoiEDkcbnuVmE3wcZMlTVM+FI6Y9PcObwkBD+7F+hcZ528BVVibCOfz+BfYpHd66JtXI5W Tf2zuXGvRBYC4WypamxLwK4Eocyg71+1xrdZtnrYpL3H89WEKz1mrzurFoxz+lMnGuFvQeTPDLe OmVO1CophTjoo3h6ZQaX/b6zulV3HrGKlpYGk8h8Heny86MA5r3eVlEQQPHxb/7qqSTHWtU X-Received: by 2002:a05:600c:3ba4:b0:49f:ce72:dfe7 with SMTP id 5b1f17b1804b1-49fdf253077mr30607695e9.35.1790154677171; Wed, 23 Sep 2026 02:11:17 -0700 (PDT) Received: from FRSMI25-LASER.home (2a02-8440-b519-f416-8bed-8817-19fd-ccf7.rev.sfr.net. [2a02:8440:b519:f416:8bed:8817:19fd:ccf7]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-49fe2730da9sm14251525e9.4.2026.09.23.02.11.16 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 23 Sep 2026 02:11:16 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][scarthgap 01/48] wireless-regdb: upgrade 2026.05.30 -> 2026.09.03 Date: Wed, 23 Sep 2026 11:10:03 +0200 Message-ID: <4e12e3df374a64df09145656986f151656a47ab5.1790154074.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Wed, 23 Sep 2026 09:11:23 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/246463 From: Richard Purdie Signed-off-by: Richard Purdie (cherry picked from commit 7e92e1fe36a5767a7b31d96b9897357e0aa28cec) Signed-off-by: Ankur Tyagi Signed-off-by: Yoann Congal --- ...ireless-regdb_2026.05.30.bb => wireless-regdb_2026.09.03.bb} | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) rename meta/recipes-kernel/wireless-regdb/{wireless-regdb_2026.05.30.bb => wireless-regdb_2026.09.03.bb} (94%) diff --git a/meta/recipes-kernel/wireless-regdb/wireless-regdb_2026.05.30.bb b/meta/recipes-kernel/wireless-regdb/wireless-regdb_2026.09.03.bb similarity index 94% rename from meta/recipes-kernel/wireless-regdb/wireless-regdb_2026.05.30.bb rename to meta/recipes-kernel/wireless-regdb/wireless-regdb_2026.09.03.bb index e544b729656..ad84208f6e9 100644 --- a/meta/recipes-kernel/wireless-regdb/wireless-regdb_2026.05.30.bb +++ b/meta/recipes-kernel/wireless-regdb/wireless-regdb_2026.09.03.bb @@ -5,7 +5,7 @@ LICENSE = "ISC" LIC_FILES_CHKSUM = "file://LICENSE;md5=07c4f6dea3845b02a18dc00c8c87699c" SRC_URI = "https://www.kernel.org/pub/software/network/${BPN}/${BP}.tar.xz" -SRC_URI[sha256sum] = "8a27bfc081bafed8c24dd70fab0d96f098e5a0bfcd08d3da672595f225ab8993" +SRC_URI[sha256sum] = "b22e0901227b820cd1c280abe681a15b773a5103a5e10dc442e94ebb34cbf58d" inherit bin_package allarch From patchwork Wed Sep 23 09:10:04 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 98963 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id DAA83C9830C for ; Wed, 23 Sep 2026 09:11:23 +0000 (UTC) Received: from mail-wr2-f12.google.com (mail-wr2-f12.google.com [74.125.225.76]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.2814.1790154680015783005 for ; Wed, 23 Sep 2026 02:11:20 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=Ev+sRSvA; spf=pass (domain: smile.fr, ip: 74.125.225.76, mailfrom: yoann.congal@smile.fr) Received: by mail-wr2-f12.google.com with SMTP id ffacd0b85a97d-485b1d2874fso293847f8f.0 for ; Wed, 23 Sep 2026 02:11:19 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1790154678; x=1790759478; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=yjKRSN6RhPNxqLVAQH2Lb09RAELnorfAs/Av6yhAO8c=; b=Ev+sRSvArNVnWRqvEOEcvFPOrB4tWTdD8gl7R+YdTR1jqyzAp5GxVJ3Q8gqk2X+KaH gf6L10sHfQ0yDBFbTdhKBUu4MLdIvJhpBpJh4eLH+IYMiP88nv7UKetyxag3J1HvDfvN 8vCilfqLq2d4K8WzuX6bmUSn2ec3zletf9lhM= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1790154678; x=1790759478; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=yjKRSN6RhPNxqLVAQH2Lb09RAELnorfAs/Av6yhAO8c=; b=vrbeGszxQIXRm5veXWwtXog06l5CYbSan8lA0w8yXzjLBUs/zB+0U8rKZQU1TYeDo1 n3UPWfD1pcF6TTDxU0Q3yvbDek/8MIIOIkKeIL7a2+Oksr0hkg14H9cNC5v8pHaWxyLL BFWQfbcSHLoZMK2dkx1FWtFWtxMVpC9PCzdJGV5PDUnYEACuvT1j7bnMScBj7zgkCmVU RsOXminjxhHbV64N+o1+p0cZwXwXdWF17NjM+OFt2HJlofuvSNq/SQOn2BAXE4+qUzh/ UVQf1uBB6gyyJPbvIV3lwMM2OPMvR/e+h1u7/YTac4qxHvvuRT6RRjzlK7sSEwUcy8eu WZ2A== X-Gm-Message-State: AFuF++lAcsRWS8esZB3bwPlwTNYR/yiyKhhqiZ3GS0pa1keLSjcJ9RsN BW7eefyGzhyx42jSlyjhkejiYxKpr+cG9QCmcuBvyy5b2E3eBPbrltnDhJYgywtGnZMp6Dy3arB frh5eSzk= X-Gm-Gg: AYBFou3DnvcSv+pGNuutOSpHt5MXpfQoMs4fEZ55kedU7Z9vTomt9HsTX8UD52eEXo+ HCAMsvS81f5NUdlz6FjliEMbrGMWYt8IkKCFCzpsy2SUhUYmwtnYJ1NC5oR6WSKY5scQH7coYYb C1y9a4vaLPv1ygtjzGUMr/O7I9wvS8CvgPrjghwpTPHggVtVYOYulIvj4Sx0DL19BeN9qlxBXQH IBsQM1vP7583tITk8mv+tkgIr0qF4XF03mq2JTsaFxtmz4ppIAl9pgecuRm73ofGUmeElVJijnO SfQiKWUpDWKEEjLBorqh9qU4yXk9dx4bHfINGtWPj/GrucJjZIKfAqFloR7afyCc4RiL4QQh7Vi VhPzp0pbx7dyBOcLa1F7dk9AAyklC7YcBrvwOp+WE22DYRxf5ddNe9p93+8ZaDf4G6U0BzLcO3I fdJmfRE7Yyudsjg4iIhhH5mfQ407nMafIm18kahim9IEX8Zrej8x7g3S9pBwSTcsEDF4ZOiYP7l s/7yElATc9W/fJQMUgin3ifpJTULsfnHbDqxa7DoFA86rSrvz/PFuff17psrkfTC8wzYcPI6A== X-Received: by 2002:a05:600c:46d5:b0:49d:257c:a735 with SMTP id 5b1f17b1804b1-49fde497533mr28128815e9.11.1790154677966; Wed, 23 Sep 2026 02:11:17 -0700 (PDT) Received: from FRSMI25-LASER.home (2a02-8440-b519-f416-8bed-8817-19fd-ccf7.rev.sfr.net. [2a02:8440:b519:f416:8bed:8817:19fd:ccf7]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-49fe2730da9sm14251525e9.4.2026.09.23.02.11.17 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 23 Sep 2026 02:11:17 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][scarthgap 02/48] ca-certificates: upgrade 20260601 -> 20260816 Date: Wed, 23 Sep 2026 11:10:04 +0200 Message-ID: <31069b19cfd56f2995233033e2a54336ee6b0353.1790154074.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Wed, 23 Sep 2026 09:11:23 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/246464 From: Jaipaul Cheernam Source: debian/changelog ca-certificates (20260816) unstable; urgency=medium * Update Mozilla certificate authority bundle to version 2.90 The following certificate authorities were added (+): + "SECOM TLS ECC Root CA 2024" + "SECOM TLS RSA Root CA 2024" + "Telia EC TLS Root CA v3" + "Telia RSA TLS Root CA v3" The following certificate authorities were removed (-): - "Atos TrustedRoot 2011" - "Entrust Root Certification Authority" - "SecureSign Root CA12" - "ePKI Root Certification Authority" -- Julien Cristau Sun, 16 Aug 2026 23:04:36 +0200 Signed-off-by: Jaipaul Cheernam Signed-off-by: Mathieu Dubois-Briand Signed-off-by: Richard Purdie (cherry picked from commit e639396818e7152896e75364cff5fb97ae19cb32) Signed-off-by: Ankur Tyagi Signed-off-by: Yoann Congal --- ...vert-mozilla-certdata2pem.py-print-a-warning-for-e.patch | 6 +++--- ...date-ca-certificates-don-t-use-Debianisms-in-run-p.patch | 2 +- ...date-ca-certificates-use-relative-symlinks-from-ET.patch | 2 +- ...certificates_20260601.bb => ca-certificates_20260816.bb} | 2 +- 4 files changed, 6 insertions(+), 6 deletions(-) rename meta/recipes-support/ca-certificates/{ca-certificates_20260601.bb => ca-certificates_20260816.bb} (97%) diff --git a/meta/recipes-support/ca-certificates/ca-certificates/0001-Revert-mozilla-certdata2pem.py-print-a-warning-for-e.patch b/meta/recipes-support/ca-certificates/ca-certificates/0001-Revert-mozilla-certdata2pem.py-print-a-warning-for-e.patch index 1226508c983..001b4686246 100644 --- a/meta/recipes-support/ca-certificates/ca-certificates/0001-Revert-mozilla-certdata2pem.py-print-a-warning-for-e.patch +++ b/meta/recipes-support/ca-certificates/ca-certificates/0001-Revert-mozilla-certdata2pem.py-print-a-warning-for-e.patch @@ -1,4 +1,4 @@ -From 743774cd53ed1c45bb660eddacf6dadb5ee3e145 Mon Sep 17 00:00:00 2001 +From 8ea56b7d5eadb04309dc3cf1e6b0d94d1d053d80 Mon Sep 17 00:00:00 2001 From: Alexander Kanavin Date: Mon, 18 Oct 2021 12:05:49 +0200 Subject: [PATCH] Revert "mozilla/certdata2pem.py: print a warning for expired @@ -16,10 +16,10 @@ Signed-off-by: Alexander Kanavin 3 files changed, 1 insertion(+), 13 deletions(-) diff --git a/debian/changelog b/debian/changelog -index dbe3e9c..496e05d 100644 +index 7ad495f..058ef5e 100644 --- a/debian/changelog +++ b/debian/changelog -@@ -156,7 +156,6 @@ ca-certificates (20211004) unstable; urgency=low +@@ -234,7 +234,6 @@ ca-certificates (20211004) unstable; urgency=low - "Trustis FPS Root CA" - "Staat der Nederlanden Root CA - G3" * Blacklist expired root certificate "DST Root CA X3" (closes: #995432) diff --git a/meta/recipes-support/ca-certificates/ca-certificates/0001-update-ca-certificates-don-t-use-Debianisms-in-run-p.patch b/meta/recipes-support/ca-certificates/ca-certificates/0001-update-ca-certificates-don-t-use-Debianisms-in-run-p.patch index 1a29da756fc..dcfa3554117 100644 --- a/meta/recipes-support/ca-certificates/ca-certificates/0001-update-ca-certificates-don-t-use-Debianisms-in-run-p.patch +++ b/meta/recipes-support/ca-certificates/ca-certificates/0001-update-ca-certificates-don-t-use-Debianisms-in-run-p.patch @@ -1,4 +1,4 @@ -From 63086d41f76b1c3357e23c6509df72d3f75af20c Mon Sep 17 00:00:00 2001 +From bab2e13b69af12c1864cccf371ebc4ef57a6fec2 Mon Sep 17 00:00:00 2001 From: Ross Burton Date: Mon, 6 Jul 2015 15:19:41 +0100 Subject: [PATCH] ca-certificates: remove Debianism in run-parts invocation diff --git a/meta/recipes-support/ca-certificates/ca-certificates/0003-update-ca-certificates-use-relative-symlinks-from-ET.patch b/meta/recipes-support/ca-certificates/ca-certificates/0003-update-ca-certificates-use-relative-symlinks-from-ET.patch index 929945b56f9..4d97c81b0d7 100644 --- a/meta/recipes-support/ca-certificates/ca-certificates/0003-update-ca-certificates-use-relative-symlinks-from-ET.patch +++ b/meta/recipes-support/ca-certificates/ca-certificates/0003-update-ca-certificates-use-relative-symlinks-from-ET.patch @@ -1,4 +1,4 @@ -From a69933f96a8675369de702bdb55e57dc21f65e7f Mon Sep 17 00:00:00 2001 +From 8a5b4e2dd1479de0338db7a7234d037ef0f71c2f Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Andr=C3=A9=20Draszik?= Date: Wed, 28 Mar 2018 16:45:05 +0100 Subject: [PATCH] update-ca-certificates: use relative symlinks from diff --git a/meta/recipes-support/ca-certificates/ca-certificates_20260601.bb b/meta/recipes-support/ca-certificates/ca-certificates_20260816.bb similarity index 97% rename from meta/recipes-support/ca-certificates/ca-certificates_20260601.bb rename to meta/recipes-support/ca-certificates/ca-certificates_20260816.bb index b23f20a7828..33ca9291f4d 100644 --- a/meta/recipes-support/ca-certificates/ca-certificates_20260601.bb +++ b/meta/recipes-support/ca-certificates/ca-certificates_20260816.bb @@ -14,7 +14,7 @@ DEPENDS:class-nativesdk = "openssl-native" # Need rehash from openssl and run-parts from debianutils PACKAGE_WRITE_DEPS += "openssl-native debianutils-native" -SRC_URI[sha256sum] = "7ab6301f7f34eef90a4d278647c260bc0762e0e14561f4649854cf4b0d4bea21" +SRC_URI[sha256sum] = "d939bcdd0cb058712cf4175bac76997676eb8b68fe9473765e1b40fb3d5b186a" SRC_URI = "${DEBIAN_MIRROR}/main/c/ca-certificates/${BPN}_${PV}.tar.xz \ file://0001-update-ca-certificates-don-t-use-Debianisms-in-run-p.patch \ file://0003-update-ca-certificates-use-relative-symlinks-from-ET.patch \ From patchwork Wed Sep 23 09:10:05 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 98961 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 93A59C982FA for ; Wed, 23 Sep 2026 09:11:23 +0000 (UTC) Received: from mail-wm2-f13.google.com (mail-wm2-f13.google.com [74.125.225.141]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.2815.1790154680930186169 for ; Wed, 23 Sep 2026 02:11:21 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=EEsVSD/1; spf=pass (domain: smile.fr, ip: 74.125.225.141, mailfrom: yoann.congal@smile.fr) Received: by mail-wm2-f13.google.com with SMTP id 5b1f17b1804b1-49e721b5503so5648485e9.0 for ; Wed, 23 Sep 2026 02:11:20 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1790154679; x=1790759479; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=sNuG74WzTEl+YKyB0BBJ0j0ILPwsHE7qnTbG8ML1fZw=; b=EEsVSD/1xE0zYhvwwCKnaYv5HtlxFVPFmhzjy75KSI7vSfQPH07yiSuoLa03zLRuws ejEzkmldceeYxyY81DX5rBCKk4kwEyaUs4/XBTsXpb6PvD17qPzB8AztbLT86UjNvzcy r+PKFYgQvHVbcFmE3+QRrS71cJMcW1JWinc5Q= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1790154679; x=1790759479; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=sNuG74WzTEl+YKyB0BBJ0j0ILPwsHE7qnTbG8ML1fZw=; b=naCBimMBTkTTWDuafQEPRxo9Xym5ahUmNYZWEfOQM+M9EmYRmEfb0yXDciTRjQdf1H EEBEgc3LAXNEBnWLq5IJI2v2u1y+GOycrBlG4kB0g2IK30b/YKPOMahZXSGI4N53PzXI IPLUcTGUN38WNG8zQQ/bxFLQZ7C7sKSnKGwD4kn2h5jVnZzBZDW5qOqwglKDr4Dk54qm VqdJCv/+YLbCYrF8N8/y0SCie0n9TCOIv2lMG6DpBce4Wpfm/gQntJwGD9aVBDxnWh76 E8ezPlaGdvuLskqW20bLXndWufhDG0LWWaQKAmHfIwxiHQh09mcFIX8hR3ZjtQ9hUeH9 UOAA== X-Gm-Message-State: AFuF++kuQm62vovN88avhCF13iWyQ1SnBQJwnPSAhkPu1hGEheoquN07 F1Uf0PJTSnBfebe48gG+/KAvPIL3lz8De9n0Z5Rcx94VkFdUDK5AdoOJSM597bfK4uzO2FxoBmC nLiF3oBw= X-Gm-Gg: AYBFou2zYuQfLI4gHIe1Y9Tf17+Y8RTg4wdjH+U5dER9coy8EaEW8YIwQOY2TjuN027 MzlcgsUu50we+KnI8VnJk5wyPKeYvnoMJqIKd8QsN+L9giCaKvU2Dq38GU421ak1fpNUH/NrR2z r6DfFQdcUfKsY5wyK8vOYtCb0xPJrt/f9DmFwyGpm5GeKmanEA5L6C58cVfQlWa3JVA0ndg/bwd 46d7bpxAE/iIj9M0unzy+c5I6mFsVcbTwJ6Q/PChI5sSGZKwPYxHGAyhdYbIzCPbCBKvrdLrG/v Wdb6hJVMD6Vj9LhBtOhyZOB/xeddtbahPj2jf5hjOlIOfZTdKqe/jVW8wzGWX/VCZAbpg5lss7J 8wdv4nqTB6OtY/yd8bS1oX/eSZluj/VhlNNvDyJF2jHmRyrNCBPgdqJ6589J7KFX10uKSwMZrYD tmeDJ8r1E51up0gipX+hD77rgNXoalOkSQCsf2LdtAETk3D6FNg+LYFcofps5b7GBLygm9t+jUX w1LYJuS59y6WbjcrXlnrvGrGTMSyLFLbMQ7kjkSu5dpw+ghi2c/K1uV9e4qqKhsoVRGnOaU X-Received: by 2002:a05:600c:a307:b0:49f:e3f2:f5a3 with SMTP id 5b1f17b1804b1-49fe3f2f5d4mr2741905e9.0.1790154679163; Wed, 23 Sep 2026 02:11:19 -0700 (PDT) Received: from FRSMI25-LASER.home (2a02-8440-b519-f416-8bed-8817-19fd-ccf7.rev.sfr.net. [2a02:8440:b519:f416:8bed:8817:19fd:ccf7]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-49fe2730da9sm14251525e9.4.2026.09.23.02.11.18 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 23 Sep 2026 02:11:18 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][scarthgap 03/48] testimage: avoid symlinking missing qemu boot log Date: Wed, 23 Sep 2026 11:10:05 +0200 Message-ID: <6672769e251ab0dd42fc5f5cde99800ed5ba8289.1790154074.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Wed, 23 Sep 2026 09:11:23 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/246465 From: Peter Tatrai When qemu test runs only produce suffixed bootlog variants, the base bootlog path may not exist. os.symlink() creates a dangling symlink in the oeqa result log directory. Avoid advertising a boot log in the collected test results when that path does not exist. Guard the symlink creation and log a note instead. This is a partial backport of master commit 7a6596925cb0eb8dd48a0362a51875cdd60152bc. Only the symlink guard is picked here; the bootlog variant globbing from master is not applicable to scarthgap. Signed-off-by: Peter Tatrai Signed-off-by: Yoann Congal --- meta/classes-recipe/testimage.bbclass | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/meta/classes-recipe/testimage.bbclass b/meta/classes-recipe/testimage.bbclass index 33b1c13f9dd..744de5d7de7 100644 --- a/meta/classes-recipe/testimage.bbclass +++ b/meta/classes-recipe/testimage.bbclass @@ -395,7 +395,10 @@ def testimage_main(d): # Copy additional logs to tmp/log/oeqa so it's easier to find them targetdir = os.path.join(get_json_result_dir(d), d.getVar("PN")) os.makedirs(targetdir, exist_ok=True) - os.symlink(bootlog, os.path.join(targetdir, os.path.basename(bootlog))) + if os.path.exists(bootlog): + os.symlink(bootlog, os.path.join(targetdir, os.path.basename(bootlog))) + else: + bb.note("testimage: boot log not found at %s" % bootlog) os.symlink(d.getVar("BB_LOGFILE"), os.path.join(targetdir, os.path.basename(d.getVar("BB_LOGFILE") + "." + d.getVar('DATETIME')))) if not results or not complete: From patchwork Wed Sep 23 09:10:06 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 98960 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id A488CC982EA for ; Wed, 23 Sep 2026 09:11:23 +0000 (UTC) Received: from mail-wr2-f12.google.com (mail-wr2-f12.google.com [74.125.225.76]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.2816.1790154682740674134 for ; Wed, 23 Sep 2026 02:11:23 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=TAALMvdz; spf=pass (domain: smile.fr, ip: 74.125.225.76, mailfrom: yoann.congal@smile.fr) Received: by mail-wr2-f12.google.com with SMTP id ffacd0b85a97d-4843cedd129so470240f8f.0 for ; Wed, 23 Sep 2026 02:11:22 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1790154681; x=1790759481; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=53q2a3ZPJ439hiF9YD6a9pC2V4yAS14Be8yJrDJbJQ8=; b=TAALMvdzMyff+RfEmtsGSSI8l4S0vQ3E2PYpFPNgByLHH2se/wXzRsY+gFcn17kw0g 5kGzIcp8GBqbeb7bJIRmIAtF5CvFMaogWmCN95GV5Zvc40VyF3bBkyQssDOfycy11xq4 NHLkdJSbUOvHOFJXsHrxCE/nFjGY1m4SW9K90= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1790154681; x=1790759481; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=53q2a3ZPJ439hiF9YD6a9pC2V4yAS14Be8yJrDJbJQ8=; b=VIZqkrPxEfCPdxczi6sTq/JfAFNxh7w2dfT/uyv5fUOC6Epu9X8nr7LKOYPj2qqr+g y5B3p0Hep+J63t7nwpnF+hEb6a7dnhqnVb4AT/b0omxRm9oDo5iUvsejVAox4DH0ZXpA 8iZ/f1W+hW3xfJdN0zHcI9XSafkfyCeR1X/j3gu1/YBxThjcHXhwBhHGUSD23DmI9DFl A3KiDh0nnaynTUOYSq7oQPTrR+wsQHaIo9qxvcdl+HJuCA2fBrqQU/IeHxXJSVC7Tq7q knxeHNh3A/YTpGQjnBctJLHJ54HuqZMDNChxXh2gOCklPsZCMBRZu3CBsxzEg2hewrJg c/OA== X-Gm-Message-State: AFuF++mqK8UCsPM2I9IhiaN5DKuP9LUXQ2HPVAWLMTPeSIunATxHLXQB b/+U4dsTaJFSM8VgrLnq6o3dEMM7pP4xa79qORIzn+7avztCj3nxutblMy8J8A/qgIBiYGLk9fN 5QR8qEBE= X-Gm-Gg: AYBFou3XlRUmCkVvBnutJ+T2AnVUvCRXZMrudCKdcOi2Xm3tOPr6vJlGSJFGTEDsIxB NjhVzU2sSBWRMOK2XwggQ8NKZkOTMDkwLirD4Z/I1RxlpkF4ACALuEeMW4VEIfZFNRUCVdlYNsQ zu/ij/HCwaS1aj7YR/E2uqsTpFaqf76BYpWspASX0DYQ8dveq2QwNDzwoMCDZNXc+xd9axNMciz lrnQ2pRMop88FDC8Bj2SNqH253qYCTFtmx9LFZZIByvTgOatwl5tdlifqqRiKXq6HTIK/da0OJk 2HiisVDrXUB1bfdvppxufQk2u26W03BbT5MrfBxaq1cJ3g7dt+wuN3PBJRV9SyooJEMLQkXV7yC MtaGVnPwlstsjF4zkVgdAn6+E2K32BW9yZJ5V/ujQF7CKtLHwpGErd0Uk46PbHi3rD4GxVCkdES rBCWi24VM7RUyiijsbpO7NrNU/bVrLC5Qp8lO7xM4I1tHumzYeRTI7K6g4AVwfAhAFopRezHTw+ Lba7C5zBaiTPDCTo8F4Ip3Yo1pJQRgk7IpwdbrCelmEI3vzu/3B9+Qm4CXhPQGCpPnZBqWt X-Received: by 2002:a05:600c:608e:b0:49f:ce78:3570 with SMTP id 5b1f17b1804b1-49fdf0fee93mr30118295e9.33.1790154680868; Wed, 23 Sep 2026 02:11:20 -0700 (PDT) Received: from FRSMI25-LASER.home (2a02-8440-b519-f416-8bed-8817-19fd-ccf7.rev.sfr.net. [2a02:8440:b519:f416:8bed:8817:19fd:ccf7]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-49fe2730da9sm14251525e9.4.2026.09.23.02.11.19 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 23 Sep 2026 02:11:20 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][scarthgap 04/48] python3-pip: set CVE_STATUS for CVE-2018-20225 Date: Wed, 23 Sep 2026 11:10:06 +0200 Message-ID: <34c0972ffea7dcf4888e3bcfe0ce17206b32e408.1790154074.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Wed, 23 Sep 2026 09:11:23 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/246466 From: Hetvi Thakar Analysis: - NVD marks CVE-2018-20225 as disputed. [1] - pip searches all configured package indexes without priority and selects the highest matching version. --extra-index-url adds an equal-priority package source. [2] - Exploitation requires use of --extra-index-url and an attacker-published, higher-version package with the name of a private package. [1] - Upstream closed the related report as not planned, and Red Hat classified the issue as WONTFIX because this behavior is intentional. [3][4] - Record the disputed status; no source patch is available. Reference: [1] https://nvd.nist.gov/vuln/detail/CVE-2018-20225 [2] https://pip.pypa.io/en/stable/cli/pip_install/ [3] https://github.com/pypa/pip/issues/12874 [4] https://bugzilla.redhat.com/show_bug.cgi?id=1835736 Signed-off-by: Hetvi Thakar Signed-off-by: Yoann Congal --- meta/recipes-devtools/python/python3-pip_24.0.bb | 1 + 1 file changed, 1 insertion(+) diff --git a/meta/recipes-devtools/python/python3-pip_24.0.bb b/meta/recipes-devtools/python/python3-pip_24.0.bb index d535e1f53d7..709ec9f2b6c 100644 --- a/meta/recipes-devtools/python/python3-pip_24.0.bb +++ b/meta/recipes-devtools/python/python3-pip_24.0.bb @@ -45,6 +45,7 @@ do_install:append() { } CVE_PRODUCT = "pypa:pip" +CVE_STATUS[CVE-2018-20225] = "disputed: Exploitation requires use of --extra-index-url with a private package not present on the primary public index; pip intentionally selects the highest version across configured indexes" do_install:append(){ # pip vendors distlib which ships Windows launcher templates (*.exe). From patchwork Wed Sep 23 09:10:07 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 98969 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 546F5C9830C for ; Wed, 23 Sep 2026 09:11:34 +0000 (UTC) Received: from mail-wm2-f13.google.com (mail-wm2-f13.google.com [74.125.225.141]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.2817.1790154684380150459 for ; Wed, 23 Sep 2026 02:11:24 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=JH2bSH2V; spf=pass (domain: smile.fr, ip: 74.125.225.141, mailfrom: yoann.congal@smile.fr) Received: by mail-wm2-f13.google.com with SMTP id 5b1f17b1804b1-49d097b4939so3403125e9.0 for ; Wed, 23 Sep 2026 02:11:24 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1790154683; x=1790759483; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=CSPa6FdpPl84cGMx4k4JZlQeplDNbdORwd36YCwSEV4=; b=JH2bSH2VP4kif0fAMYsToYk5dp25+DVIV+VqCt8qg/HCNZ0mQc8zppZ4wbk/vH/2HM OT1sfW+6GwkYY+HldzMtDwLRu6+aDihfmrRAXKsCIg0fjO972sigtw1ocLwwG0pQDfOZ 7/KR6lFOTTL/9PtG2gNLQc4MXsmao6yy+Os2U= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1790154683; x=1790759483; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=CSPa6FdpPl84cGMx4k4JZlQeplDNbdORwd36YCwSEV4=; b=guFGo7qpVW9Td8iLtwAnHa1yPzYe1yZVN0HUQE5wUceTzRGCqJAy8J7fdXsFG5Xkkr go966XyDH66u7/+bs0xHPrPuFO7Jz3ksKLuG+3tth/jDvbRgjJQ5EixptzlZWhVWbeTT Ytv9J4vmSKtt93XkiMERDDGRpNz74cgSHPP89GI03gSQ7mNkJF6J3FWG8P+bCGSv6I3l f+2AUlxhLjyWWywhBnQWPdhEeH/NQTr1sAT1v8dK5XagR6EoECCNAYNlkQKCs/OvR5K3 wM1hWZyAmFsQoM3zPynrGSggZcDgQohhYtR4OwxXE4kCYJyZcaWsMnG0hekzwWoVKIDW I4PA== X-Gm-Message-State: AFuF++n9hRPEgdd7VaE7159cr6SY2fgjlvThqcF65tNVWiqAqWMj+fzs 9fqNA2/dX2/ne3l82dqIvvhg20ozlT0DhnUUdfnx4A71s2Cc8ZFettBXyfFlWMr/j+lVTAg6fgi Ky8qBEhU= X-Gm-Gg: AYBFou3nrJP9AgYy//wTelqCrtSQE+5GuXT6pFVOEPEoC33eSc36qcnNAhQkyymYvpb V2vUiFEWHq8JhNVEaLzO9yN3eopBM2a9pFzSumYEZheqT/0DroQjJn2kpGnIfb0JdPGRjJMR6oh DO6dZHSBW2eRVzbjJsYYKNMxRIilw0GD0stNoHlX787pCZvXljWRASdjdmR8NYJvcDTsfqQMLqf UM65Mc3n5VjY82lWVTTo6L8pgy1WtbLNK7o6G3iC6XVHkU77sHCK3HwxFt2doVz9I/n77Bgvh2o np7/D98W9XHbb5smrBjjKo2FWpND+XsXzywA5HLu+xJp86MRzJI704ua7q/wlJhJ+1NGtn/dpej T03mFfPrMDTSRRamh4Dz/YYjPAmV9UllSWjhuLs0s/Kna4CgfrjCkCPSO0Ug8mjtVWKG8jdccb0 NkrXHSl4zYp/F+VYZz0hIQhwYJejB1YOTyzGyf2jzr46jeFV/7Lf3OgmM/STO0o7m9d6WH1J38s JvestRp/GChX/ZMXdp3WaTBiQK1gMSo6ZeXgqPHsvu8pAAdAfL/0ov+yxtW/Kv3PoBpbFmTU/+A qByCKhA= X-Received: by 2002:a05:600c:8b83:b0:49e:7caa:e7b2 with SMTP id 5b1f17b1804b1-49fdf148f13mr25554175e9.29.1790154682605; Wed, 23 Sep 2026 02:11:22 -0700 (PDT) Received: from FRSMI25-LASER.home (2a02-8440-b519-f416-8bed-8817-19fd-ccf7.rev.sfr.net. [2a02:8440:b519:f416:8bed:8817:19fd:ccf7]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-49fe2730da9sm14251525e9.4.2026.09.23.02.11.21 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 23 Sep 2026 02:11:22 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][scarthgap 05/48] python3-ply: set status for CVE-2025-56005 Date: Wed, 23 Sep 2026 11:10:07 +0200 Message-ID: <9bce52b90a6783e0ba23ff048209ea88922fd1da.1790154074.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Wed, 23 Sep 2026 09:11:34 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/246467 From: Hetvi Thakar PLY 3.11 contains the picklefile parameter described by CVE-2025-56005, but exploitation requires an application to explicitly pass an attacker-controlled pickle file to yacc(). No OE-Core consumer uses this parameter. Ubuntu ignores the issue for the same reason [1], and NVD records the CVE as disputed [2]. [1] https://ubuntu.com/security/CVE-2025-56005 [2] https://nvd.nist.gov/vuln/detail/CVE-2025-56005 Signed-off-by: Hetvi Thakar Signed-off-by: Yoann Congal --- meta/recipes-devtools/python/python3-ply_3.11.bb | 1 + 1 file changed, 1 insertion(+) diff --git a/meta/recipes-devtools/python/python3-ply_3.11.bb b/meta/recipes-devtools/python/python3-ply_3.11.bb index 0855c871cf6..5bed977158b 100644 --- a/meta/recipes-devtools/python/python3-ply_3.11.bb +++ b/meta/recipes-devtools/python/python3-ply_3.11.bb @@ -16,5 +16,6 @@ RDEPENDS:${PN}:class-target += "\ " CVE_PRODUCT = "dabeaz:ply" +CVE_STATUS[CVE-2025-56005] = "disputed: Exploitation requires application-specific use of PLY's picklefile parameter with attacker-controlled pickle data" BBCLASSEXTEND = "native nativesdk" From patchwork Wed Sep 23 09:10:08 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 98972 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 5F973C9830D for ; Wed, 23 Sep 2026 09:11:34 +0000 (UTC) Received: from mail-wm2-f13.google.com (mail-wm2-f13.google.com [74.125.225.141]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.2911.1790154685470973260 for ; Wed, 23 Sep 2026 02:11:25 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=MGpAYJ+5; spf=pass (domain: smile.fr, ip: 74.125.225.141, mailfrom: yoann.congal@smile.fr) Received: by mail-wm2-f13.google.com with SMTP id 5b1f17b1804b1-49ccfd61ecaso5032495e9.3 for ; Wed, 23 Sep 2026 02:11:25 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1790154684; x=1790759484; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=EvDdPMtNQZQuVuFq59fxR6gufSP2ih6aK8F18UrRyLg=; b=MGpAYJ+5i44ApLkEhZhN0LZxT+ClGkKeWiEodNv9PrwJX+qwFb8PoUkGY6Jjb6tMBR IAKYzVKc9EezDdbAeVjl+0nmMxDE7IpvMG0cNBRyg3TWQi3rfxdOJPYFAlrWA0JOWk47 383RAsG9RhmUdMm5IXdmyT/1lOnv4z/hvRHDg= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1790154684; x=1790759484; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=EvDdPMtNQZQuVuFq59fxR6gufSP2ih6aK8F18UrRyLg=; b=yhbyeZ7zv8pVR9eE0NL3RpmrP/NsG9GJcH39r5MLs+r/KfJZwLvbmbsAq28E/lrGlB 5kmfSnsSesOqAuMPMGVfEVOr3+05cC7rhBt5ONMudd61YcHxqCbyI5ZiXd/oapKnPvoO d7YzDmFBv+dBzLUkh//sKlRu6mj2Ib9RE99XHij2S7UVBTELJ+l+3TzK09WITH2+SGoW lE+qpNIixjfQCF0FL0rTab816rIQAnrSxVSpKeugRCIIl33wQGg7UWaYSycOLqjQWYYm gjC6TcxIfM8uCf4y6nxgPb7Gl6HS1DIZOkkv/+vACcoTqrYIfRCZAjIwDR5tNs98Xvj6 1RJw== X-Gm-Message-State: AFuF++mg+1hA1bUOtI+RwCKrGAWiH4zlYaTo0RZBjFZ8CLIglwSACQP/ xSt/gpUzF0xwXHRLWPy4IRolAaiiR7PRd90LSp9dFMB+KwFZ91mr7cdkYKXGj2BnZjbAmDmPpk6 g0xhHTqM= X-Gm-Gg: AYBFou1X50WesTKTJ43iQi3fFNm5dYSXP7aX8CnPDRel9o4AHg+/5eAmABcejO+K2D0 4tw088akFVVcRQlulKNtwtVoy+WXcyyYBg1ZOHl9fH3E04yPHva+Auk6E7w9ztWvth9+iRFD9dz E/NWqCLk58jeYQrPdYfR9cZY/jFWmibvQf94kw1rQJsLW2m+8n5e1iv95Yy28kqUZxP1Ad5kVHi kFS3f+eSnrhK1QQUWygp/eCo2DfEPySa0M61dskpvGE3Zd0zWQQf19uhFQ5RFUdeXkysiG3jZYA Qm00sTxNv3sdzGsQ6/H/rqhpHWkMc4MjDYbTv00sDxuCLIx1r7103NZoxedtRJax2VWNg1+xbMD 2HkJbeMaGvxYoVqe+wR+V0MG5kWb6S9/CmoOTyM/uHsyiETIbSFS0CLZbsoKJR4wtbtdofTLHHj t7WAF81k1VR7Po0Wx05xZzdXSZHEXA8rVE4TpFatUHoBhonkcEvWgVoU77Wx07mnKov0Xr2XBUi +1+NVIr2BAiupqebNhFvnKuhevDIslfqrkq42bQLeyX6G7Hm2Ds6G7qpTziSBd7P5gcT6NZjMix Ip7IXco= X-Received: by 2002:a05:600d:444f:10b0:49c:fa21:e73c with SMTP id 5b1f17b1804b1-49fdf35725amr15822335e9.18.1790154683689; Wed, 23 Sep 2026 02:11:23 -0700 (PDT) Received: from FRSMI25-LASER.home (2a02-8440-b519-f416-8bed-8817-19fd-ccf7.rev.sfr.net. [2a02:8440:b519:f416:8bed:8817:19fd:ccf7]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-49fe2730da9sm14251525e9.4.2026.09.23.02.11.22 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 23 Sep 2026 02:11:23 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][scarthgap 06/48] kbd: Fix CVE-2026-72693 Date: Wed, 23 Sep 2026 11:10:08 +0200 Message-ID: X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Wed, 23 Sep 2026 09:11:34 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/246468 From: Vijay Anusuri Pick patch according to [1] [1] https://security-tracker.debian.org/tracker/CVE-2026-72693 [2] https://nvd.nist.gov/vuln/detail/CVE-2026-72693 [3] https://access.redhat.com/security/cve/cve-2026-72693 Signed-off-by: Vijay Anusuri Signed-off-by: Yoann Congal --- .../recipes-core/kbd/kbd/CVE-2026-72693.patch | 155 ++++++++++++++++++ meta/recipes-core/kbd/kbd_2.6.4.bb | 1 + 2 files changed, 156 insertions(+) create mode 100644 meta/recipes-core/kbd/kbd/CVE-2026-72693.patch diff --git a/meta/recipes-core/kbd/kbd/CVE-2026-72693.patch b/meta/recipes-core/kbd/kbd/CVE-2026-72693.patch new file mode 100644 index 00000000000..71cef126a6e --- /dev/null +++ b/meta/recipes-core/kbd/kbd/CVE-2026-72693.patch @@ -0,0 +1,155 @@ +From 78d5ae119742e87baa7dbe0f5c4107e7533fd698 Mon Sep 17 00:00:00 2001 +From: Alexey Gladkov +Date: Tue, 12 May 2026 10:20:50 +0200 +Subject: [PATCH] openvt: make -u process matching more conservative + +The -u mode relies on the current VT owner to decide which user should +be used for the new login session. Make that check stricter by requiring +a matching process owner and controlling terminal instead of relying on +the ownership of an inherited file descriptor. + +Also reject root as a pre-authenticated target and document the tighter +behavior in the man page. + +Signed-off-by: Alexey Gladkov + +Upstream-Status: Backport [https://github.com/legionus/kbd/commit/78d5ae119742e87baa7dbe0f5c4107e7533fd698] +CVE: CVE-2026-72693 +Signed-off-by: Vijay Anusuri +--- + docs/man/man1/openvt.1 | 10 +++++++ + src/openvt.c | 64 +++++++++++++++++++++++++++++++++++++----- + 2 files changed, 67 insertions(+), 7 deletions(-) + +diff --git a/docs/man/man1/openvt.1 b/docs/man/man1/openvt.1 +index 79bfe3f..074de96 100644 +--- a/docs/man/man1/openvt.1 ++++ b/docs/man/man1/openvt.1 +@@ -36,6 +36,8 @@ will be made the new current VT. + .I "\-u, \-\-user" + Figure out the owner of the current VT, and run login as that user. + Suitable to be called by init. Shouldn't be used with \fI\-c\fR or \fI\-l\fR. ++This option refuses to pre-authenticate root and requires a process owned by ++the VT owner whose controlling terminal is the current VT. + .TP + .I "\-l, \-\-login" + Make the command a login shell. A \- is prepended to the name of the command +@@ -64,6 +66,14 @@ If + is compiled with a getopt_long() and you wish to set + options to the command to be run, then you must supply + the end of options \-\- flag before the command. ++.PP ++The ++.B \-u ++option uses ++.BR "login -f" ++and therefore bypasses normal password authentication for the detected user. ++It is intended only for controlled init or keyboard-request configurations. ++Use a normal authenticated login command when authentication is required. + .SH EXAMPLES + .B openvt + can be used to start a shell on the next free VT, by using the command: +diff --git a/src/openvt.c b/src/openvt.c +index 5980361..b8436fe 100644 +--- a/src/openvt.c ++++ b/src/openvt.c +@@ -78,6 +78,51 @@ usage(int rc, const struct kbd_help *options) + exit(rc); + } + ++static int ++proc_pid_stat(const char *pid, uid_t *uid, dev_t *tty) ++{ ++ char filename[NAME_MAX + 12]; ++ char line[BUFSIZ]; ++ char *lp, *rp; ++ FILE *fp; ++ struct stat st; ++ long tty_nr; ++ ++ snprintf(filename, sizeof(filename), "/proc/%s/stat", pid); ++ fp = fopen(filename, "r"); ++ if (!fp) ++ return -1; ++ ++ if (fstat(fileno(fp), &st)) { ++ fclose(fp); ++ return -1; ++ } ++ ++ if (!fgets(line, sizeof(line), fp)) { ++ fclose(fp); ++ return -1; ++ } ++ fclose(fp); ++ ++ rp = strrchr(line, ')'); ++ if (!rp) ++ return -1; ++ ++ /* ++ * /proc//stat fields after comm are: ++ * state ppid pgrp session tty_nr ... ++ */ ++ if (!rp || sscanf(rp + 1, " %*c %*d %*d %*d %ld", &tty_nr) != 1) ++ return -1; ++ ++ if (tty_nr <= 0) ++ return -1; ++ ++ *uid = st.st_uid; ++ *tty = (dev_t) tty_nr; ++ return 0; ++} ++ + /* + * Support for Spawn_Console: openvt running from init + * added by Joshua Spoerri, Thu Jul 18 21:13:16 EDT 1996 +@@ -109,8 +154,7 @@ authenticate_user(int curvt) + DIR *dp; + struct dirent *dentp; + struct stat buf; +- dev_t console_dev; +- ino_t console_ino; ++ dev_t console_rdev; + uid_t console_uid; + char filename[NAME_MAX + 12]; + struct passwd *pwnam; +@@ -130,10 +174,12 @@ authenticate_user(int curvt) + kbd_error(EXIT_FAILURE, errsv, "%s", filename); + } + } +- console_dev = buf.st_dev; +- console_ino = buf.st_ino; ++ console_rdev = buf.st_rdev; + console_uid = buf.st_uid; + ++ if (console_uid == 0) ++ kbd_error(EXIT_FAILURE, 0, _("Refusing to pre-authenticate root on current tty.")); ++ + /* get the owner of current tty */ + if (!(pwnam = getpwuid(console_uid))) + kbd_error(EXIT_FAILURE, errno, "getpwuid"); +@@ -141,12 +187,16 @@ authenticate_user(int curvt) + /* check to make sure that user has a process on that tty */ + /* this will fail for example when X is running on the tty */ + while ((dentp = readdir(dp))) { +- sprintf(filename, "/proc/%s/fd/0", dentp->d_name); ++ uid_t proc_uid; ++ dev_t proc_tty; ++ ++ if (dentp->d_name[0] < '0' || dentp->d_name[0] > '9') ++ continue; + +- if (stat(filename, &buf)) ++ if (proc_pid_stat(dentp->d_name, &proc_uid, &proc_tty) < 0) + continue; + +- if (buf.st_dev == console_dev && buf.st_ino == console_ino && buf.st_uid == console_uid) ++ if (proc_uid == console_uid && proc_tty == console_rdev) + goto got_a_process; + } + +-- +2.43.0 + diff --git a/meta/recipes-core/kbd/kbd_2.6.4.bb b/meta/recipes-core/kbd/kbd_2.6.4.bb index 2331b51e595..489218a4029 100644 --- a/meta/recipes-core/kbd/kbd_2.6.4.bb +++ b/meta/recipes-core/kbd/kbd_2.6.4.bb @@ -25,6 +25,7 @@ RCONFLICTS:${PN} = "console-tools" SRC_URI = "${KERNELORG_MIRROR}/linux/utils/${BPN}/${BP}.tar.xz \ file://0001-Remove-non-free-Agafari-fonts.patch \ + file://CVE-2026-72693.patch \ " SRC_URI[sha256sum] = "519f8d087aecca7e0a33cd084bef92c066eb19731666653dcc70c9d71aa40926" From patchwork Wed Sep 23 09:10:09 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 98973 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 737DDC9830F for ; Wed, 23 Sep 2026 09:11:34 +0000 (UTC) Received: from mail-wr2-f12.google.com (mail-wr2-f12.google.com [74.125.225.76]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.2818.1790154686337391472 for ; Wed, 23 Sep 2026 02:11:26 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=dqgqEpI9; spf=pass (domain: smile.fr, ip: 74.125.225.76, mailfrom: yoann.congal@smile.fr) Received: by mail-wr2-f12.google.com with SMTP id ffacd0b85a97d-482f633ecdeso582253f8f.2 for ; Wed, 23 Sep 2026 02:11:26 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1790154684; x=1790759484; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=Q58tnZgvfmr5l/mNDQwSBOb89lI+xqNo+TgnJwg0S/U=; b=dqgqEpI9KyB1a+dtv8Y3kp1SP2ep3e5MwdzlTH3suTrq4cHQvcyhDPuTBPiuAqObnC ZqqJ3xwcz1+9aiqf216qFu9zElCFQiJu+jQAE3ztlKuID4rTKn4wPn3ry8K3r8J6b0lO S8dpTWia5gov4dZYsEzw2TwffSOzUO2ofcj0E= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1790154684; x=1790759484; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=Q58tnZgvfmr5l/mNDQwSBOb89lI+xqNo+TgnJwg0S/U=; b=dJgmIRfLFJ34CFD2ZWKy0UjxwS3EHyME2/sqiAPteN4Witb0D88dMYM4J6LHN5DnPa buM42lPNmnMCmLK2jOagRmJRZGHzYSB2WI7TMBFnTjLR0VbFQ8BB19se74wbbVAmpEiL cJdg3Jczix8NTqUPLAhaYkyudEYNQVmWPUyIuAeQnsVsP7g4sWMpJG8ur6kAFZhZpSvc QVxBORjgVe86OEQHmH8Zh5ZJmWEVkXp/WJQwO9Y/0YKX5fOUc8LEtywYcaBwua4AyMWI aJ2TBEd57cyK1ep+tBka+Q2KzKWhPLZkfAsEY9v3mZdCqkKcb0/Vki8RHkYjgDAtQp2u 2MSQ== X-Gm-Message-State: AFuF++l1fAEr5VzWdxIPEtDdvzfMKJ37cW4FR379/FKsUOcFqGkr7gIP /3eRxzpUoigPbn78QpDipCin9zeGUL2LzdMOqSfw1ejcbRpE+a7rGSz7zLnjD4bMNkPLf4FJ/id JE9U9P3I= X-Gm-Gg: AYBFou3E2buxZRoBeUrfjeglVug6F37pt+pmXWzIe0OvFFOaXKuENLleljgcBwQoJ7+ 1aEP576jezJq+ik7Um49l4yEY+VY4n/zX7TKDDyMGtr1oYo17mrTao3hJG78scusWadJJj/0uBz Q4EZq90D2O8HsrwRN7IKPoTY37KX8x/J0beFlrSrSEGDiD1LyOrzvaDMEH/W4g83qlHlmxeedbb SsZvwxCsaK+EuaHr9QybvdCM18UPPowMUc9KF9rZ1uxBOEnMM85cWwGFOfPei0SPJF6Ijo4CURq 9rVkg7iZkFbaztUpHfBN6dD0z1QqedTuZhQx4N2hoCZnZj67lojq2QGMl2f/TBUCe1lt9ydHMzb ZcopcsRD3UgRRtILbAgrxU1j3BtS6pySvaPp9+xoYfaImIYh+ITOUsHDYlN9FiOX7GVpVZZUPoU O/gBdoa4SrZuUw6NvUPeKB1lguXdc6HbgbHPJ930YohWB9WkHmryqMdituiAnME2RwsDWINTZ5S w5cELfPvw+HnBabXADreOb8nTX7CVsMp57DDBv6WJb3ES3XqOwEtCcU26bCoaoY6sxU0GZxwsY8 LWkM+XY= X-Received: by 2002:a05:600c:8b64:b0:499:8b13:3a98 with SMTP id 5b1f17b1804b1-49fdee0a0ebmr22001505e9.4.1790154684519; Wed, 23 Sep 2026 02:11:24 -0700 (PDT) Received: from FRSMI25-LASER.home (2a02-8440-b519-f416-8bed-8817-19fd-ccf7.rev.sfr.net. [2a02:8440:b519:f416:8bed:8817:19fd:ccf7]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-49fe2730da9sm14251525e9.4.2026.09.23.02.11.23 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 23 Sep 2026 02:11:24 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][scarthgap 07/48] gnutls: fix CVE-2026-33845 Date: Wed, 23 Sep 2026 11:10:09 +0200 Message-ID: X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Wed, 23 Sep 2026 09:11:34 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/246469 From: Adarsh Jagadish Kamini Backport patch to fix CVE-2026-33845. References: https://nvd.nist.gov/vuln/detail/CVE-2026-33845 Upstream fix: https://gitlab.com/gnutls/gnutls/-/commit/e5b72c53c7d789d19d1d1cd10b275e87d0415413 Signed-off-by: Adarsh Jagadish Kamini Signed-off-by: Yoann Congal --- .../gnutls/gnutls/CVE-2026-33845.patch | 190 ++++++++++++++++++ meta/recipes-support/gnutls/gnutls_3.8.4.bb | 1 + 2 files changed, 191 insertions(+) create mode 100644 meta/recipes-support/gnutls/gnutls/CVE-2026-33845.patch diff --git a/meta/recipes-support/gnutls/gnutls/CVE-2026-33845.patch b/meta/recipes-support/gnutls/gnutls/CVE-2026-33845.patch new file mode 100644 index 00000000000..13d1d9bf821 --- /dev/null +++ b/meta/recipes-support/gnutls/gnutls/CVE-2026-33845.patch @@ -0,0 +1,190 @@ +From d217d233d3eb5566a911dad11b639552d63acfac Mon Sep 17 00:00:00 2001 +From: Adarsh Jagadish Kamini +Date: Wed, 29 Jul 2026 08:54:58 +0000 +Subject: [PATCH] buffers: switch from end_offset over to frag_length + +Instead of maintaining an inclusive [start_offset, end_offset] range +when reassembling DTLS handshake, +track start_offset and a relative frag_length instead. + +You'd think it'd be a no-op, but it fixes: + +* 0-length fragments triggering completion if message was 1 byte long +* a remotely triggerable underflow and an ensuing heap overrun + +Reported-by: Joshua Rogers of AISLE Research Team +Fixes: #1811 +Fixes: CVE-2026-33845 +Fixes: GNUTLS-SA-2026-04-29-3 +CVSS: 7.5 High CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H +Signed-off-by: Alexander Sosedkin + +CVE: CVE-2026-33845 +Upstream-Status: Backport [https://gitlab.com/gnutls/gnutls/-/commit/e5b72c53c7d789d19d1d1cd10b275e87d0415413] + +Backport notes: adapted to the stable branch, no logic changes. +- lib/buffers.c: the local fragment-size variable is named frag_size here, + not frag_length as upstream; renamed accordingly. +- lib/buffers.c: merge_handshake_packet() has no recv_buf alias in this + branch, so recv_buf[pos] was expanded to + session->internals.handshake_recv_buffer[pos], which changes line wrapping. +- lib/gnutls_int.h: applies cleanly + +Assisted-by: kiro:claude-sonnet-4.6 +Signed-off-by: Adarsh Jagadish Kamini +--- + lib/buffers.c | 59 ++++++++++++++++++++++++++---------------------- + lib/gnutls_int.h | 4 ++-- + 2 files changed, 34 insertions(+), 29 deletions(-) + +diff --git a/lib/buffers.c b/lib/buffers.c +index 672380b05..ad59e4f14 100644 +--- a/lib/buffers.c ++++ b/lib/buffers.c +@@ -923,10 +923,7 @@ static int parse_handshake_header(gnutls_session_t session, mbuffer_st *bufel, + } + data_size = _mbuffer_get_udata_size(bufel) - handshake_header_size; + +- if (frag_size > 0) +- hsk->end_offset = hsk->start_offset + frag_size - 1; +- else +- hsk->end_offset = 0; ++ hsk->frag_length = frag_size; + + _gnutls_handshake_log( + "HSK[%p]: %s (%u) was received. Length %d[%d], frag offset %d, frag length: %d, sequence: %d\n", +@@ -940,9 +937,11 @@ static int parse_handshake_header(gnutls_session_t session, mbuffer_st *bufel, + + if (hsk->length > 0 && + (frag_size > data_size || +- (frag_size > 0 && hsk->end_offset >= hsk->length))) { ++ (frag_size > 0 && ++ hsk->start_offset + frag_size > hsk->length))) { + return gnutls_assert_val(GNUTLS_E_UNEXPECTED_PACKET_LENGTH); +- } else if (hsk->length == 0 && hsk->end_offset != 0 && ++ } else if (hsk->length == 0 && ++ hsk->start_offset + frag_size != hsk->start_offset && + hsk->start_offset != 0) + return gnutls_assert_val(GNUTLS_E_UNEXPECTED_PACKET_LENGTH); + +@@ -991,11 +990,10 @@ static int merge_handshake_packet(gnutls_session_t session, + hsk->data.length = hsk->length; + } + +- if (hsk->length > 0 && hsk->end_offset > 0 && +- hsk->end_offset - hsk->start_offset + 1 != hsk->length) { ++ if (hsk->length > 0 && hsk->frag_length > 0 && ++ hsk->frag_length != hsk->length) { + memmove(&hsk->data.data[hsk->start_offset], +- hsk->data.data, +- hsk->end_offset - hsk->start_offset + 1); ++ hsk->data.data, hsk->frag_length); + } + + session->internals.handshake_recv_buffer_size++; +@@ -1012,7 +1010,7 @@ static int merge_handshake_packet(gnutls_session_t session, + if (hsk->start_offset < + session->internals.handshake_recv_buffer[pos] + .start_offset && +- hsk->end_offset + 1 >= ++ hsk->start_offset + hsk->frag_length >= + session->internals.handshake_recv_buffer[pos] + .start_offset) { + memcpy(&session->internals.handshake_recv_buffer[pos] +@@ -1021,28 +1019,36 @@ static int merge_handshake_packet(gnutls_session_t session, + session->internals.handshake_recv_buffer[pos] + .start_offset = hsk->start_offset; + session->internals.handshake_recv_buffer[pos] +- .end_offset = MIN( +- hsk->end_offset, ++ .frag_length = MIN( ++ hsk->frag_length, + session->internals.handshake_recv_buffer[pos] +- .end_offset); +- } else if (hsk->end_offset > ++ .frag_length); ++ } else if (hsk->start_offset + hsk->frag_length > + session->internals.handshake_recv_buffer[pos] +- .end_offset && ++ .start_offset + ++ session->internals ++ .handshake_recv_buffer[pos] ++ .frag_length && + hsk->start_offset <= + session->internals.handshake_recv_buffer[pos] +- .end_offset + +- 1) { ++ .start_offset + ++ session->internals ++ .handshake_recv_buffer[pos] ++ .frag_length) { + memcpy(&session->internals.handshake_recv_buffer[pos] + .data.data[hsk->start_offset], + hsk->data.data, hsk->data.length); + +- session->internals.handshake_recv_buffer[pos] +- .end_offset = hsk->end_offset; + session->internals.handshake_recv_buffer[pos] + .start_offset = MIN( + hsk->start_offset, + session->internals.handshake_recv_buffer[pos] + .start_offset); ++ session->internals.handshake_recv_buffer[pos] ++ .frag_length = ++ hsk->start_offset + hsk->frag_length - ++ session->internals.handshake_recv_buffer[pos] ++ .start_offset; + } + _gnutls_handshake_buffer_clear(hsk); + } +@@ -1102,8 +1108,8 @@ static int get_last_packet(gnutls_session_t session, + } + + else if ((recv_buf[LAST_ELEMENT].start_offset == 0 && +- recv_buf[LAST_ELEMENT].end_offset == +- recv_buf[LAST_ELEMENT].length - 1) || ++ recv_buf[LAST_ELEMENT].frag_length == ++ recv_buf[LAST_ELEMENT].length) || + recv_buf[LAST_ELEMENT].length == 0) { + session->internals.dtls.hsk_read_seq++; + _gnutls_handshake_buffer_move(hsk, +@@ -1114,8 +1120,9 @@ static int get_last_packet(gnutls_session_t session, + /* if we don't have a complete handshake message, but we + * have queued data waiting, try again to reconstruct the + * handshake packet, using the queued */ +- if (recv_buf[LAST_ELEMENT].end_offset != +- recv_buf[LAST_ELEMENT].length - 1 && ++ if ((recv_buf[LAST_ELEMENT].start_offset + ++ recv_buf[LAST_ELEMENT].frag_length) != ++ recv_buf[LAST_ELEMENT].length && + record_check_unprocessed(session) > 0) + return gnutls_assert_val( + GNUTLS_E_INT_CHECK_AGAIN); +@@ -1302,9 +1309,7 @@ int _gnutls_parse_record_buffered_msgs(gnutls_session_t session) + &session->internals.record_buffer, + bufel, ret); + +- data_size = MIN(tmp.length, +- tmp.end_offset - +- tmp.start_offset + 1); ++ data_size = MIN(tmp.length, tmp.frag_length); + + ret = _gnutls_buffer_append_data( + &tmp.data, +diff --git a/lib/gnutls_int.h b/lib/gnutls_int.h +index 8cf9a8715..689dcdc41 100644 +--- a/lib/gnutls_int.h ++++ b/lib/gnutls_int.h +@@ -479,10 +479,10 @@ typedef struct { + uint16_t sequence; + + /* indicate whether that message is complete. +- * complete means start_offset == 0 and end_offset == length ++ * complete means start_offset == 0 and frag_length == length + */ + uint32_t start_offset; +- uint32_t end_offset; ++ uint32_t frag_length; /* used exclusively in DTLS reassembly */ + + uint8_t header[MAX_HANDSHAKE_HEADER_SIZE]; + int header_size; diff --git a/meta/recipes-support/gnutls/gnutls_3.8.4.bb b/meta/recipes-support/gnutls/gnutls_3.8.4.bb index 0aa1eef513f..6dbd11abaff 100644 --- a/meta/recipes-support/gnutls/gnutls_3.8.4.bb +++ b/meta/recipes-support/gnutls/gnutls_3.8.4.bb @@ -50,6 +50,7 @@ SRC_URI = "https://www.gnupg.org/ftp/gcrypt/gnutls/v${SHRT_VER}/gnutls-${PV}.tar file://CVE-2026-42011_p1.patch \ file://CVE-2026-42011_p2.patch \ file://CVE-2026-33846.patch \ + file://CVE-2026-33845.patch \ " SRC_URI[sha256sum] = "2bea4e154794f3f00180fa2a5c51fe8b005ac7a31cd58bd44cdfa7f36ebc3a9b" From patchwork Wed Sep 23 09:10:10 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 98966 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id C9165C982EA for ; Wed, 23 Sep 2026 09:11:33 +0000 (UTC) Received: from mail-wm2-f13.google.com (mail-wm2-f13.google.com [74.125.225.141]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.2912.1790154687178689165 for ; Wed, 23 Sep 2026 02:11:27 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=Mx7IhXvM; spf=pass (domain: smile.fr, ip: 74.125.225.141, mailfrom: yoann.congal@smile.fr) Received: by mail-wm2-f13.google.com with SMTP id 5b1f17b1804b1-49cd4ba9f68so7452325e9.1 for ; Wed, 23 Sep 2026 02:11:26 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1790154685; x=1790759485; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=ekfPxoRAjm/kidNkpnyOGVPU7xwLNbjhK0xD/orRBTQ=; b=Mx7IhXvMjWpnKKnhUF/07zFcHhsjmv6L+uztzsvYncwcwHG11BiLLjZzc0z7Zs8riO g3LFb+AnW7OlRCMdJDTZjWty6Ofhx0lpRGTWGasESJWprFg7Ep1hLwdkuMtiZ7QbvU2W 4IdT117Okte3oUPTk8Pml6a4ntu4CZRbzjdtg= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1790154685; x=1790759485; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=ekfPxoRAjm/kidNkpnyOGVPU7xwLNbjhK0xD/orRBTQ=; b=TiSwLPcinsFrbcKCc+ywNQJTwYI78H1lXkLO2xu9WIBAronFyv6vsimaIg+u+J6qNV eGDrgT1X6000zdf4L49eFplzvgT7PIpDwwE6eZNreRcSPbNX8ndaRf0+BpVpk5RioK7b SYBxKdKz3ldWtEIAwAdb9Hs3WIFEzEHoj2QYr6RabhwnyBDujf5NLFpcV59lMagrikkH gIltMQL2t6tx1Lb9rEXicBCgflvgG/+nUD8lwujHzNW8eiWZiYL23zWbJTNGCJHwvX8M Bu/FskwekYof1L01i07FWZ7VxUqYXDwuQd+ZCiMKsGKrrpg+jrAyyMhXZG8iaR0zvvdN ViTg== X-Gm-Message-State: AFuF++mdgGcEvCMG/p5BLXv5F4btHUsqojJb/k7qXbu15wY3YtqjCdeI gHoajBG5Jg52ULg6QXtBvuMnk3kl/xx0u5A9WTFp2tXzoOBK8pl4uS//1GFcVMOXVPekC5CAJMW +S19hBdI= X-Gm-Gg: AYBFou2MdrvwpMio88BdMu3b1XfZeJG9+LLWhd2wWwi0MAQrT3ihPJYVJP1gwWPPM7D /xr8Fg/OZwMgRalcnX2My56/h4z6VgPmx7PQs6VQhLZGakqyUKggX971ufb8ivtLVtDfhx4IulQ Z+YA9Bdi/KZwuw/6Tv2sSuGLR1NQYhrhlLVZcdQzbZX4DFESRuwut1XKmuXurPEdP8sf/N73ftm UqgEiT1D2t/6r3LERCCIF+hHCb0S4dB53F84G+ifarGIMGdJYlni5QTQbDwkVbvzUQZNYeV+nx7 +fH3SRUIYu3UFyyvlSYZloEt7XCGq5YV2O8oQkSDXdBKsP5ivDO23vtUIu2gkYjXU2BmzvAZPw3 4TPYCEiN2zFb3W8BEwEh9DaMYC2fvdBea6GiqmojoYJ30qro6VoEuKHI/ExFX5+T3ddeCAS+HVL 9hJOlL2/FLVJYDmGZHt1+URDbAK436zpkb5989C76KKGsXTeYCUzoICXeH5wlB5KssA5oIWuXjp fRkyR3RA9mTi1Vike5vB1qQoFZBh2kMcgqbuw0yvFosNzxfwqsoHoXjpB68qEwtM20I9O/s3w== X-Received: by 2002:a05:600c:6297:b0:49c:fe46:7219 with SMTP id 5b1f17b1804b1-49fdf12ba37mr21874895e9.20.1790154685370; Wed, 23 Sep 2026 02:11:25 -0700 (PDT) Received: from FRSMI25-LASER.home (2a02-8440-b519-f416-8bed-8817-19fd-ccf7.rev.sfr.net. [2a02:8440:b519:f416:8bed:8817:19fd:ccf7]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-49fe2730da9sm14251525e9.4.2026.09.23.02.11.24 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 23 Sep 2026 02:11:24 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][scarthgap 08/48] python3-mako: correct CVE_PRODUCT mapping Date: Wed, 23 Sep 2026 11:10:10 +0200 Message-ID: X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Wed, 23 Sep 2026 09:11:33 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/246470 From: Devansh Patel The inherited "python:Mako" mapping is not used for the packaged Mako source and causes its vulnerability records to be missed. Use "makotemplates:mako" for its historical NVD configuration identity and "sqlalchemy:mako" for the current NVD dictionary CPE, NVD configuration, and CNA affected-data identity. Backport note: this applies the metadata to Scarthgap Mako 1.3.2 rather than master 1.4.1; the older release exposes applicable unpatched records. Signed-off-by: Devansh Patel Signed-off-by: Richard Purdie (cherry picked from commit 76fc2046d3f251af34dd04f8fdcfc0c1d6016380) Signed-off-by: Devansh Patel Signed-off-by: Yoann Congal --- meta/recipes-devtools/python/python3-mako_1.3.2.bb | 2 ++ 1 file changed, 2 insertions(+) diff --git a/meta/recipes-devtools/python/python3-mako_1.3.2.bb b/meta/recipes-devtools/python/python3-mako_1.3.2.bb index 617bf33443c..21d37eab4eb 100644 --- a/meta/recipes-devtools/python/python3-mako_1.3.2.bb +++ b/meta/recipes-devtools/python/python3-mako_1.3.2.bb @@ -12,6 +12,8 @@ SRC_URI += "file://CVE-2026-41205.patch \ " SRC_URI[sha256sum] = "2a0c8ad7f6274271b3bb7467dd37cf9cc6dab4bc19cb69a4ef10669402de698e" +CVE_PRODUCT = "makotemplates:mako sqlalchemy:mako" + RDEPENDS:${PN} = "python3-html \ python3-markupsafe \ python3-netclient \ From patchwork Wed Sep 23 09:10:11 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 98965 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id E79EFC982FA for ; Wed, 23 Sep 2026 09:11:33 +0000 (UTC) Received: from mail-wm2-f12.google.com (mail-wm2-f12.google.com [74.125.225.140]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.2913.1790154689507539489 for ; Wed, 23 Sep 2026 02:11:29 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=yI68tUwH; spf=pass (domain: smile.fr, ip: 74.125.225.140, mailfrom: yoann.congal@smile.fr) Received: by mail-wm2-f12.google.com with SMTP id 5b1f17b1804b1-49b912d37b5so3842515e9.2 for ; Wed, 23 Sep 2026 02:11:29 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1790154688; x=1790759488; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=F65lNaWK8n1jyPnDlSRoNuXuSmGjAvkamxfjkdnPEuc=; b=yI68tUwHopaFDQd8H7gWRJ6D2syrXioGl4imcJAl8kEqmQBPTouXDs2I/5UaNG8jF9 NeNDt6jAdGujORvHYw8NEASHJ7zSqC6Eled+GtFAg44w5IgyPEDiy02F2Dy2YJLZuuCP O6ne5toh27PQBppQI0lzjQgeDUo7ZMBxfC1Ms= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1790154688; x=1790759488; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=F65lNaWK8n1jyPnDlSRoNuXuSmGjAvkamxfjkdnPEuc=; b=IgMUyajefkCC5OaC3Mkx6BYfnE+TsDx6GtmLqpBsviRoR8jU64zoamfNu+z+uLrSfV CEz+3WNJSpijPmIH3877KAOrCe0uXJrYeWq6lgwFCR1oRuzRpK6YY7YvxubOkLsZNuf/ 0aBLts2xGiTet5N3SOUkUj7KKXleRaIiHnX7FvPHXbixQcJdGt3lkkUHf/3m+dKteyp3 QnyN4Prl+m741RxklYgCReBPljQeMGN29hxoBG4X6PwjKyyF1kZIs9PnXO/EqXpEzko6 m0DlqVdEfCxcDLcaq9516ELpdVEE2JKM84CNSU/5nyp546FIqrCSVTst2CFN+qGQlipF nu2A== X-Gm-Message-State: AFuF++kfitLmZsOpSrgD/c1tRKoBEYr2VI6CWxUKmZ7eb8PKbAvRP2bn wif1JgYr1paxiQiRJ4WHBTt5DRzBCpMdpOCojIRYq1UAzXVY6bnGc+h1+FvECufN2pBuI2BsQez hzShTn/w= X-Gm-Gg: AYBFou0LZ1KslPcNWfVtKf/sjjrYpNa+tPWz/l4wVU+N616N5w9MoyAwj99r7Z/fMj+ PWfNaDrbYp737C6YjtEO6dqlnk6yyb1fHuPBaALM8088k1g/lIxMbzURqdt8u+y11QuGnJ+hv2d LuPZkS0fKmkypsbh0ahbaTj/2TEwM4MjBkYcBd7vMeIteNUFb0fUQZbypaPPTPDC8e82a/sjXvt LGuG0w46xFfNC4yujmvJ3BGE1jotxb0+1WzHL+CmJ808nlMAaY61tQn3GhTR8S1tM3Sl6A5Vx1I RTDnnbTZXeR85Efu5Wa1aPgG1E3lnapbpAoFU7p6nhi5z3nYHePKLbY1HCWTsHcU/PJV+ce3PPk rg79okVRoXu/YiYohW9dggrsZsgVsLgICXyYnB//bhCCDOSF/s36hMf9yRpWKFR+omTWTAzmDUb NozuXa+OTbsfIRYhCIksRdgXyfXdjOWUi53UTS+9smXDhD+SiTHfXsisLBeheAxRuz4LL8vfuZn tsYtQ5BdgSuY7hg2DFuXrPIOmJLR8XidgmqOLeKZdqzhEuXjs+EkRaxohiDBIjOffTWsfaf X-Received: by 2002:a05:600d:8643:20b0:49f:bc0d:2e9 with SMTP id 5b1f17b1804b1-49fdfd90205mr15431085e9.0.1790154687559; Wed, 23 Sep 2026 02:11:27 -0700 (PDT) Received: from FRSMI25-LASER.home (2a02-8440-b519-f416-8bed-8817-19fd-ccf7.rev.sfr.net. [2a02:8440:b519:f416:8bed:8817:19fd:ccf7]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-49fe2730da9sm14251525e9.4.2026.09.23.02.11.25 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 23 Sep 2026 02:11:27 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][scarthgap 09/48] python3-pip: Fix CVE-2026-13346 Date: Wed, 23 Sep 2026 11:10:11 +0200 Message-ID: X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Wed, 23 Sep 2026 09:11:33 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/246471 From: Hetvi Thakar This patch applies the upstream fix as referenced in [2], using the commit shown in [1]. [1] https://github.com/pypa/pip/commit/10dfb6b90054 [2] https://nvd.nist.gov/vuln/detail/CVE-2026-13346 Signed-off-by: Hetvi Thakar Signed-off-by: Yoann Congal --- .../python/python3-pip/CVE-2026-13346.patch | 223 ++++++++++++++++++ .../python/python3-pip_24.0.bb | 1 + 2 files changed, 224 insertions(+) create mode 100644 meta/recipes-devtools/python/python3-pip/CVE-2026-13346.patch diff --git a/meta/recipes-devtools/python/python3-pip/CVE-2026-13346.patch b/meta/recipes-devtools/python/python3-pip/CVE-2026-13346.patch new file mode 100644 index 00000000000..246f587a149 --- /dev/null +++ b/meta/recipes-devtools/python/python3-pip/CVE-2026-13346.patch @@ -0,0 +1,223 @@ +From e743e63ca083402fe0a344c4837cc6acf3081987 Mon Sep 17 00:00:00 2001 +From: Damian Shaw +Date: Tue, 30 Jun 2026 21:52:39 -0400 +Subject: [PATCH] Fix Link.filename decoding URL path twice (#14110) + +Link already percent-decodes the URL path into `self._path`, but +`Link.filename` decoded the basename again, so a doubly-encoded +separator was decoded twice: `%252F` became `%2F` in `__init__`, then +`/` in `filename`, turning the single component `a%2Fb.whl` into +`a/b.whl`. + +Drop the second decode, and add a `join_within_directory` helper so the +download-path joins treat the name as a single path component. + +CVE: CVE-2026-13346 +Upstream-Status: Backport [https://github.com/pypa/pip/commit/10dfb6b9005484578b386f64b9f36982e3dc6679] + +Backport Changes: +- Adapted imports and download call sites to pip 24.0. +- Secured pip 24.0 separate BatchDownloader path. +- Omitted tests absent from the pip 24.0 source archive. + +(cherry picked from commit 10dfb6b9005484578b386f64b9f36982e3dc6679) +Signed-off-by: Hetvi Thakar +--- + news/14110.bugfix.rst | 1 + + src/pip/_internal/models/link.py | 63 ++++++++++++++++++++----- + src/pip/_internal/network/download.py | 20 +++++--- + src/pip/_internal/operations/prepare.py | 6 +-- + 4 files changed, 69 insertions(+), 21 deletions(-) + create mode 100644 news/14110.bugfix.rst + +diff --git a/news/14110.bugfix.rst b/news/14110.bugfix.rst +new file mode 100644 +index 000000000..f7d4f7888 +--- /dev/null ++++ b/news/14110.bugfix.rst +@@ -0,0 +1 @@ ++Fix ``Link.filename`` decoding the URL path twice. +diff --git a/src/pip/_internal/models/link.py b/src/pip/_internal/models/link.py +index 73041b864..e4bd559bf 100644 +--- a/src/pip/_internal/models/link.py ++++ b/src/pip/_internal/models/link.py +@@ -13,6 +13,7 @@ from typing import ( + List, + Mapping, + NamedTuple, ++ NewType, + Optional, + Tuple, + Union, +@@ -36,6 +37,49 @@ if TYPE_CHECKING: + logger = logging.getLogger(__name__) + + ++# A single path component: percent-decoded once and reduced to a basename, so it ++# contains no path separator and is not a ``.`` or ``..`` reference. The empty ++# string means "no component". ++PathComponent = NewType("PathComponent", str) ++ ++ ++def _to_path_component(name: str) -> PathComponent: ++ """Reduce ``name`` to a single path component, or ``""`` if it has none. ++ ++ ``os.path.basename`` drops any directory part, drive letter, or separator; ++ a ``.``, ``..``, or empty result is not a component and becomes ``""``. ++ """ ++ name = os.path.basename(name) ++ if name in ("", os.curdir, os.pardir): ++ return PathComponent("") ++ ++ return PathComponent(name) ++ ++ ++def as_path_component(name: str) -> PathComponent: ++ """Like ``_to_path_component`` but reject the empty result. ++ ++ Use where a file is about to be written, so a missing name is an error ++ rather than a silent fallback to the directory itself. ++ """ ++ component = _to_path_component(name) ++ if not component: ++ raise ValueError(f"Unexpected file name derived from URL: {name!r}") ++ ++ return component ++ ++ ++def join_within_directory(directory: str, component: PathComponent) -> str: ++ """Join a single path ``component`` onto ``directory``. ++ ++ ``component`` is a :data:`PathComponent`, so by type it has no separator and ++ is not a ``.`` or ``..`` reference; the result can never escape ``directory``. ++ Requiring ``PathComponent`` rather than ``str`` lets the type checker enforce ++ at the call site that the name was reduced to a safe component beforehand. ++ """ ++ return os.path.join(directory, component) ++ ++ + # Order matters, earlier hashes have a precedence over later hashes for what + # we will pick to use. + _SUPPORTED_HASHES = ("sha512", "sha384", "sha256", "sha224", "sha1", "md5") +@@ -380,18 +424,13 @@ class Link(KeyBasedCompareMixin): + return self._url + + @property +- def filename(self) -> str: +- path = self.path.rstrip("/") +- name = posixpath.basename(path) +- if not name: +- # Make sure we don't leak auth information if the netloc +- # includes a username and password. +- netloc, user_pass = split_auth_from_netloc(self.netloc) +- return netloc +- +- name = urllib.parse.unquote(name) +- assert name, f"URL {self._url!r} produced no filename" +- return name ++ def filename(self) -> PathComponent: ++ name = _to_path_component(posixpath.basename(self.path.rstrip("/"))) ++ if name: ++ return name ++ ++ # No component in the path; fall back to the netloc, dropping any auth. ++ return _to_path_component(split_auth_from_netloc(self.netloc)[0]) + + @property + def file_path(self) -> str: +diff --git a/src/pip/_internal/network/download.py b/src/pip/_internal/network/download.py +index d1d43541e..3aec97e84 100644 +--- a/src/pip/_internal/network/download.py ++++ b/src/pip/_internal/network/download.py +@@ -11,7 +11,12 @@ from pip._vendor.requests.models import CONTENT_CHUNK_SIZE, Response + from pip._internal.cli.progress_bars import get_download_progress_renderer + from pip._internal.exceptions import NetworkConnectionError + from pip._internal.models.index import PyPI +-from pip._internal.models.link import Link ++from pip._internal.models.link import ( ++ Link, ++ PathComponent, ++ as_path_component, ++ join_within_directory, ++) + from pip._internal.network.cache import is_from_cache + from pip._internal.network.session import PipSession + from pip._internal.network.utils import HEADERS, raise_for_status, response_chunks +@@ -91,11 +96,14 @@ def parse_content_disposition(content_disposition: str, default_filename: str) - + return filename or default_filename + + +-def _get_http_response_filename(resp: Response, link: Link) -> str: ++def _get_http_response_filename(resp: Response, link: Link) -> PathComponent: + """Get an ideal filename from the given HTTP response, falling back to + the link filename if not provided. ++ ++ The result is validated as a single path component, so it can be joined onto ++ a download directory without escaping it. + """ +- filename = link.filename # fallback ++ filename: str = link.filename # fallback + # Have a look at the Content-Disposition header for a better guess + content_disposition = resp.headers.get("content-disposition") + if content_disposition: +@@ -109,7 +117,7 @@ def _get_http_response_filename(resp: Response, link: Link) -> str: + ext = os.path.splitext(resp.url)[1] + if ext: + filename += ext +- return filename ++ return as_path_component(filename) + + + def _http_get_download(session: PipSession, link: Link) -> Response: +@@ -140,7 +148,7 @@ class Downloader: + raise + + filename = _get_http_response_filename(resp, link) +- filepath = os.path.join(location, filename) ++ filepath = join_within_directory(location, filename) + + chunks = _prepare_download(resp, link, self._progress_bar) + with open(filepath, "wb") as content_file: +@@ -176,7 +184,7 @@ class BatchDownloader: + raise + + filename = _get_http_response_filename(resp, link) +- filepath = os.path.join(location, filename) ++ filepath = join_within_directory(location, filename) + + chunks = _prepare_download(resp, link, self._progress_bar) + with open(filepath, "wb") as content_file: +diff --git a/src/pip/_internal/operations/prepare.py b/src/pip/_internal/operations/prepare.py +index 956717d1e..0a9b39332 100644 +--- a/src/pip/_internal/operations/prepare.py ++++ b/src/pip/_internal/operations/prepare.py +@@ -26,7 +26,7 @@ from pip._internal.exceptions import ( + from pip._internal.index.package_finder import PackageFinder + from pip._internal.metadata import BaseDistribution, get_metadata_distribution + from pip._internal.models.direct_url import ArchiveInfo +-from pip._internal.models.link import Link ++from pip._internal.models.link import Link, join_within_directory + from pip._internal.models.wheel import Wheel + from pip._internal.network.download import BatchDownloader, Downloader + from pip._internal.network.lazy_wheel import ( +@@ -189,7 +189,7 @@ def _check_download_dir( + """Check download_dir for previously downloaded file with correct hash + If a correct file is found return its path else None + """ +- download_path = os.path.join(download_dir, link.filename) ++ download_path = join_within_directory(download_dir, link.filename) + + if not os.path.exists(download_path): + return None +@@ -666,7 +666,7 @@ class RequirementPreparer: + # No distribution was downloaded for this requirement. + return + +- download_location = os.path.join(self.download_dir, link.filename) ++ download_location = join_within_directory(self.download_dir, link.filename) + if not os.path.exists(download_location): + shutil.copy(req.local_file_path, download_location) + download_path = display_path(download_location) +-- +2.35.6 + diff --git a/meta/recipes-devtools/python/python3-pip_24.0.bb b/meta/recipes-devtools/python/python3-pip_24.0.bb index 709ec9f2b6c..818c92d8cd2 100644 --- a/meta/recipes-devtools/python/python3-pip_24.0.bb +++ b/meta/recipes-devtools/python/python3-pip_24.0.bb @@ -36,6 +36,7 @@ SRC_URI += "file://no_shebang_mangling.patch \ file://CVE-2026-8643.patch \ file://CVE-2026-8643-regression_p1.patch \ file://CVE-2026-8643-regression_p2.patch \ + file://CVE-2026-13346.patch \ " SRC_URI[sha256sum] = "ea9bd1a847e8c5774a5777bb398c19e80bcd4e2aa16a4b301b718fe6f593aba2" From patchwork Wed Sep 23 09:10:12 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 98970 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 00F16C98308 for ; Wed, 23 Sep 2026 09:11:34 +0000 (UTC) Received: from mail-wm2-f12.google.com (mail-wm2-f12.google.com [74.125.225.140]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.2819.1790154690899509076 for ; Wed, 23 Sep 2026 02:11:31 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=dEtjWp7a; spf=pass (domain: smile.fr, ip: 74.125.225.140, mailfrom: yoann.congal@smile.fr) Received: by mail-wm2-f12.google.com with SMTP id 5b1f17b1804b1-49b912df756so4669395e9.3 for ; Wed, 23 Sep 2026 02:11:30 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1790154689; x=1790759489; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=ULBQA17OEzhA1G8hbuORzyXr+QsNnBcp7HcQPUKDBEk=; b=dEtjWp7a59TVusQ8lTNSaWB3FubLlTp4hEZobxDYpi/Mg1w/gA/OMnyodfSiGkJOhT Xv+vndVw7VKZulIGQ1FgPRYiWVrNNCEEhhtJD20xyFUnPfwmiH6XOtdHWBfOjiNUb8Xk RHqLbRbl8/lgH3m2Ma5eosQ94p/vD5a71uWLo= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1790154689; x=1790759489; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=ULBQA17OEzhA1G8hbuORzyXr+QsNnBcp7HcQPUKDBEk=; b=uORUQvyBorfapB3QxiPJNuUvWDypNX1Y4zur0c2KD0HW/sdPekeWcBZI4nfEAcXlQi S+PAQTjHeNZJyH07szr1LLBrXTftjL2H6sa1c+nmxuojLCiYCSg+a4JRSJEzlulPim6S H4LOYLvllOOwRoDo/Fxwa0IEID+HgUjgCuwlmlKf25G80AAKD6YtWCmO+9v/QdTAXu28 3L8DL9HbhLCvc2UncOSiFvO2yDkSvl4QJ02sz1PiRa+7xmbvBTYP5KzDxpar1t3jv22O tjUPChvCv+aavOud/8Twj1Oz77pUzcnsJTZT+2BQOJRoZbP6UlEbR2C3pRooSyen4cq6 eDHA== X-Gm-Message-State: AFuF++mecOm+vdAhX/ixBsdxG36HSvyALTB/HC9u25m8kJDq0QSYdKbt Ayo65yFCtD4tr+88Z3fa+0K3o19Hphz4lM/7ABtT8QdmiKqIpOirOfAJ1Dbb1OMy+bXsXC5mqE0 afYX1110= X-Gm-Gg: AYBFou1ECtgzijUOy76KOUP/rLnnqofkuIsa9E95aaMa8suXiQPjbgKWHOY5HqCcOcl 2tFeWWRG1bIvPKiJ93S5+MTGa4HukiVybfs2PtiZULLZSJChiwo5C0niP1Qw/hac9NyGap0SFka 4xrk3bkKbvfeyhCYavED0mjmzUsClTr48fp2yCwufC5vG8CX2hWJOO/BVybyLng19o8wtE3wccR fdv+lR0N8DKbpey49PomqUPyuTAevb5nl5sikaOJbRqndhczzli1hQ7GXl0us/Nk1ndn4s/uZmc 84GlYyRzsi6J64+vJ97HsJy0xp84fsMIz40f9KpDkNwkupiHYJgohfGeFHHNLqVuuzI11VH7Blf 1oRTfOh9AvXBwUJNrxUl83YRKwSMdpQaFrZhRhl0AaUSRqlpMxq46V/NH47yz7QkR2Rpn9cQjSP 2kG2KpfpR2OpBEV/5Ur9fIDGIO0g6IphuhWskoqmR0ibUpJ4YlEExqu+suNRJOp46YR/FDKRBfs +XeLBlCiyksHWNapZAjS3ULg4wsQA/ap5qtvnTuf+k+dV47rteudFow4nxOHs2rtAAwIMr6 X-Received: by 2002:a05:600c:4e93:b0:49c:e27c:6b10 with SMTP id 5b1f17b1804b1-49fdee0a952mr24646705e9.3.1790154689137; Wed, 23 Sep 2026 02:11:29 -0700 (PDT) Received: from FRSMI25-LASER.home (2a02-8440-b519-f416-8bed-8817-19fd-ccf7.rev.sfr.net. [2a02:8440:b519:f416:8bed:8817:19fd:ccf7]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-49fe2730da9sm14251525e9.4.2026.09.23.02.11.27 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 23 Sep 2026 02:11:28 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][scarthgap 10/48] perl: Fix CVE-2026-19487 Date: Wed, 23 Sep 2026 11:10:12 +0200 Message-ID: <1453227f21f0cf3d769582dc10ca34f0169dd41d.1790154074.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Wed, 23 Sep 2026 09:11:34 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/246472 From: Jaipaul Cheernam Backport fix for CVE-2026-19487 - AHO-CORASICK regex engine bug Includes 5 regression test cases in t/re/re_tests. Tested by running re/pat.t on qemux86-64 target: 1267/1267 tests passed (only pre-existing TODOs as expected failures). NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-19487 Upstream-commit: https://github.com/Perl/perl5/commit/1a21abacaf6f684928bae8baaa153733c8c238eb Signed-off-by: Jaipaul Cheernam Signed-off-by: Yoann Congal --- .../perl/files/CVE-2026-19487.patch | 66 +++++++++++++++++++ meta/recipes-devtools/perl/perl_5.38.4.bb | 1 + 2 files changed, 67 insertions(+) create mode 100644 meta/recipes-devtools/perl/files/CVE-2026-19487.patch diff --git a/meta/recipes-devtools/perl/files/CVE-2026-19487.patch b/meta/recipes-devtools/perl/files/CVE-2026-19487.patch new file mode 100644 index 00000000000..86feedcda46 --- /dev/null +++ b/meta/recipes-devtools/perl/files/CVE-2026-19487.patch @@ -0,0 +1,66 @@ +From 46014ec220989897d7ea53ccc780cea767cc0862 Mon Sep 17 00:00:00 2001 +From: Yves Orton +Date: Fri, 7 Feb 2025 10:06:10 +0100 +Subject: [PATCH] regexec.c - Fix GH 22892 - AHO-CORASICK edge case issue + +In some circumstances the AHO-CORASICK logic wasn't matching properly +when there were two possibilities whose proper prefix matches a proper +suffix of a third possibilty, and one of those possibilities was shorter +than the other. + +This was because we were NOT resetting the 'failed' flag properly. +This bug must be rare because it took more than a decade for anyone +to notice. + +This patch fixes the problem by resetting the failed flag after a +successful transition. + +A good example of this problem is as follows: + + "ABCDE" =~ m/ABCF|BCDE|C/ + +This should match 'BCDE' and not 'C'. Because of the flag issue we were +matching 'C' instead. + +This fixes https://github.com/Perl/perl5/issues/22892 + +Note: t/re/re_tests hunk adjusted for 5.38.4 context (line numbers and +surrounding test data differ from upstream which targets a newer perl). + +Upstream-Status: Backport [https://github.com/Perl/perl5/commit/1a21abacaf6f684928bae8baaa153733c8c238eb] +CVE: CVE-2026-19487 +Signed-off-by: Jaipaul Cheernam +--- + regexec.c | 1 + + t/re/re_tests | 6 ++++++ + 2 files changed, 7 insertions(+) + +diff --git a/regexec.c b/regexec.c +index e96b622..1eb59bb 100644 +--- a/regexec.c ++++ b/regexec.c +@@ -3406,6 +3406,7 @@ S_find_byclass(pTHX_ regexp * prog, const regnode *c, char *s, + { + DEBUG_TRIE_EXECUTE_r( + Perl_re_printf( aTHX_ " - legal\n")); ++ failed = 0; + state = tmp; + break; + } +diff --git a/t/re/re_tests b/t/re/re_tests +index 10da625..eefa579 100644 +--- a/t/re/re_tests ++++ b/t/re/re_tests +@@ -2157,6 +2157,12 @@ AB\s+\x{100} AB \x{100}X y - - + /^(xa|(?:[Z=])*\1a){2}$/ xa=xaaa n - - # GH 10073 - RT72020 + /^(xa|(?:[Z=]|zzzz)*\1a){2}$/ xa=xaaa n - - # GH 10073 - RT72020 + ++ABCF|BCDE|C ABCDEX y $& BCDE - # GH 22892 - AHO-CORASICK bug ++ABCF|BCDE|C ABCDX y $& C - # GH 22892 - AHO-CORASICK bug ++ABCF|BCDE|C(G) ABCDE y $& BCDE - # GH 22892 - AHO-CORASICK bug ++ABCF|BCDE|C[Gg] ABCDE y $& BCDE - # GH 22892 - AHO-CORASICK bug ++ABCF|BCD[Ee]|C[Gg] ABCDE y $& BCDE - # GH 22892 - AHO-CORASICK bug ++ + # Keep these lines at the end of the file + # pat string y/n/etc expr expected-expr skip-reason comment + # vim: softtabstop=0 noexpandtab diff --git a/meta/recipes-devtools/perl/perl_5.38.4.bb b/meta/recipes-devtools/perl/perl_5.38.4.bb index b86c58f5402..8ce5d3f5d00 100644 --- a/meta/recipes-devtools/perl/perl_5.38.4.bb +++ b/meta/recipes-devtools/perl/perl_5.38.4.bb @@ -24,6 +24,7 @@ SRC_URI = "https://www.cpan.org/src/5.0/perl-${PV}.tar.gz;name=perl \ file://CVE-2026-57432-01.patch \ file://CVE-2026-57432-02.patch \ file://CVE-2025-40909.patch \ + file://CVE-2026-19487.patch \ " SRC_URI:append:class-native = " \ file://perl-configpm-switch.patch \ From patchwork Wed Sep 23 09:10:13 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 98967 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 19D35C98307 for ; Wed, 23 Sep 2026 09:11:34 +0000 (UTC) Received: from mail-wm2-f13.google.com (mail-wm2-f13.google.com [74.125.225.141]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.2821.1790154692353928319 for ; Wed, 23 Sep 2026 02:11:32 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=BQ8W+/6Q; spf=pass (domain: smile.fr, ip: 74.125.225.141, mailfrom: yoann.congal@smile.fr) Received: by mail-wm2-f13.google.com with SMTP id 5b1f17b1804b1-49e8185e037so3332585e9.3 for ; Wed, 23 Sep 2026 02:11:32 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1790154690; x=1790759490; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=YZURdTqaiH31JJNQ3B1BJACWdGR5CK9q+Ow/qXswR/Q=; b=BQ8W+/6QCYDuI0NXdfdBtszSuL4/LCIV//d8jjRueRLDnNNg8ggJmCK7MzbbP04ZGf swQPjPU+RhTmqz75HwYqGaUliMip622o9HYD1XyhC1QXEbBKddRa7Q8AB0b47glTVikw L0GKgkP50ztNmG5RQ7of8TOBLYbg2A42W6GUI= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1790154690; x=1790759490; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=YZURdTqaiH31JJNQ3B1BJACWdGR5CK9q+Ow/qXswR/Q=; b=YDrTQ0JhTo+ZL6qVKM/62kLImdxVYI14xdGgXqo56glAn6QR1cd/bfcrgf7rn+H/27 ROmbXYcRAlcY+tDpfeK1y/umDkCGPRnSp3FQj6yQeLzLH7qXRC6DPkHkOwGHPqpocXcL J+RRBZeoT877YJjbokyd8zTmsIDvb5TJSctVB+XVVoJQvADacwZ50YwXrmy5QKGCb/4g RQUaO7SOvWjwIh2clAsJweTlAmkbcB+ASG+V7/cEC61e/8shhLf7cB64y9WY8aGAICL3 PLLfZKd3IB1dPQhFUBsFajcA2B7vMrPO1CHpmy96kdR//T2CqIFw66MGST0rqcxyesJV 2/IQ== X-Gm-Message-State: AFuF++kxiaPH37omdyvfuClBWR5NRDUEB+S9jSu7+W5EmcSbM0oOtlRx 0quL7hsQ2pYuOfPaCwwNcdqB4R5vpP1zrhl8VAKTTLHdXrKLJmKnhahqvUw3SY27w792gHinK6D bvBo98Nw= X-Gm-Gg: AYBFou3kXoohidXP2UTdwlEOmGF0OJR8cx81IbwMQgnD75ndALAfIwoQHUI3OcMQyOY pIMr2arJWGlhfPIVeptGF43iKN7EgOIWSDHBF8TYpyqfeKev9G411n5qKSGnVcCCzLo5kW9K6z/ Dd6CA2kaLppkr6PgMO8qqmYYHGVw9LHvnMO7Mh8VkHSEFA40KXfYjsT1x934erPPqOuuKhZyqyN h5G2EZC2PjbR3PfDwIAqOypn1zoLbvw4K+Kp+7hWtBmjfTzF6tQRnWGaeBt/U/Fv8R4BPVEaXZ2 b3vTDm3CaVP8bpvxhi1spSue53lCXeZlkaQ9tf3YBiJaACBxjKvxH91IUYjj7JPKb3++TWri3FO J60knhsR5PIff5MZ40xmoNqMoch/FYpj5aUzjF5CfaXla3xsrn3evL5E0mxOE15C3niXUxgIUZv 2NUTW8GAq2mlgYV0lTgF3m715tNUeMOm54wd9f7cSwdpMeTx+aQfQYhiF2Y6RlrIy39f16dd+wu gp/Y1gUk3McL/EpHxKeZPdVzB6KN5EEN7rOvhkNHW6kWC5/1b9KFIcqSQKULK1JYLQW2w5tWckS EgztHk0= X-Received: by 2002:a05:600c:3e07:b0:49c:fc6c:be09 with SMTP id 5b1f17b1804b1-49fdf250b4fmr22831225e9.32.1790154690513; Wed, 23 Sep 2026 02:11:30 -0700 (PDT) Received: from FRSMI25-LASER.home (2a02-8440-b519-f416-8bed-8817-19fd-ccf7.rev.sfr.net. [2a02:8440:b519:f416:8bed:8817:19fd:ccf7]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-49fe2730da9sm14251525e9.4.2026.09.23.02.11.29 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 23 Sep 2026 02:11:29 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][scarthgap 11/48] vim: Fix for CVE-2026-73072 Date: Wed, 23 Sep 2026 11:10:13 +0200 Message-ID: X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Wed, 23 Sep 2026 09:11:34 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/246473 From: Hitendra Prajapati Pick the patch from [1], also referenced in the NVD report [2]. [1] https://github.com/vim/vim/commit/05c41c922309c7a11b6ec2f124be66551c90d66a [2] https://nvd.nist.gov/vuln/detail/CVE-2026-73072 Signed-off-by: Hitendra Prajapati Signed-off-by: Yoann Congal --- .../vim/files/CVE-2026-73072.patch | 64 +++++++++++++++++++ meta/recipes-support/vim/vim.inc | 1 + 2 files changed, 65 insertions(+) create mode 100644 meta/recipes-support/vim/files/CVE-2026-73072.patch diff --git a/meta/recipes-support/vim/files/CVE-2026-73072.patch b/meta/recipes-support/vim/files/CVE-2026-73072.patch new file mode 100644 index 00000000000..0ae3b2b49e6 --- /dev/null +++ b/meta/recipes-support/vim/files/CVE-2026-73072.patch @@ -0,0 +1,64 @@ +From 05c41c922309c7a11b6ec2f124be66551c90d66a Mon Sep 17 00:00:00 2001 +From: Yasuhiro Matsumoto +Date: Fri, 24 Jul 2026 00:58:37 +0900 +Subject: [PATCH] patch 9.2.0846: [security]: heap buffer overflow in + set_sofo() + +Problem: [security]: heap buffer overflow in set_sofo() + (Yazan Balawneh) +Solution: Reset sl_sal_first (Yasuhiro Matsumoto). + +A crafted spell file with an empty SN_SAL section before an SN_SOFO +section reaches set_sofo() with sl_sal_first[] already set to -1 by +set_sal_first(). The counting loop then under-counts colliding +multi-byte "from" characters, allocates an undersized list and writes +past its end. + +Github Security Advisory: +https://github.com/vim/vim/security/advisories/GHSA-9jqx-hgpr-6v64 + +Signed-off-by: Yasuhiro Matsumoto +Signed-off-by: Christian Brabandt + +CVE: CVE-2026-73072 +Upstream-Status: Backport [https://github.com/vim/vim/commit/05c41c922309c7a11b6ec2f124be66551c90d66a] +Signed-off-by: Hitendra Prajapati +--- + src/spellfile.c | 4 +++- + src/testdir/test_spellfile.vim | 5 +++++ + 2 files changed, 8 insertions(+), 1 deletion(-) + +diff --git a/src/spellfile.c b/src/spellfile.c +index b3ee9c0d63..a9f7e83752 100644 +--- a/src/spellfile.c ++++ b/src/spellfile.c +@@ -1433,7 +1433,9 @@ set_sofo(slang_T *lp, char_u *from, char_u *to) + gap->ga_len = 256; + + // First count the number of items for each list. Temporarily use +- // sl_sal_first[] for this. ++ // sl_sal_first[] for this. Reset it first: a preceding SN_SAL section ++ // may have set the entries to -1 via set_sal_first(). ++ vim_memset(lp->sl_sal_first, 0, sizeof(salfirst_T) * 256); + for (p = from, s = to; *p != NUL && *s != NUL; ) + { + c = mb_cptr2char_adv(&p); +diff --git a/src/testdir/test_spellfile.vim b/src/testdir/test_spellfile.vim +index 3a93883b4d..0b0cf42066 100644 +--- a/src/testdir/test_spellfile.vim ++++ b/src/testdir/test_spellfile.vim +@@ -319,6 +319,11 @@ func Test_spellfile_format_error() + " SN_SOFO: multi-byte characters in sofofrom and sofoto + call Spellfile_Test(0z0600000000080002CF810002CF82FF000000000000000000000000, '') + ++ " SN_SAL (empty) followed by SN_SOFO with two multi-byte 'from' characters ++ " sharing the same low byte. A preceding SN_SAL poisons sl_sal_first[], so ++ " without a reset set_sofo() under-counts and writes out of bounds. ++ call Spellfile_Test(0z05000000000300000006000000000A0004CAABCEAB00024142FF000000000000000000000000, '') ++ + " SN_COMPOUND: compmax is less than 2 + call Spellfile_Test(0z08000000000101, 'E759:') + +-- +2.34.1 + diff --git a/meta/recipes-support/vim/vim.inc b/meta/recipes-support/vim/vim.inc index a4f8162d31c..10f4ce15999 100644 --- a/meta/recipes-support/vim/vim.inc +++ b/meta/recipes-support/vim/vim.inc @@ -50,6 +50,7 @@ SRC_URI = "git://github.com/vim/vim.git;branch=master;protocol=https \ file://CVE-2026-59857.patch \ file://CVE-2026-59858.patch \ file://CVE-2026-57456.patch \ + file://CVE-2026-73072.patch \ " PV .= ".1683" From patchwork Wed Sep 23 09:10:14 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 98968 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 30639C9830B for ; Wed, 23 Sep 2026 09:11:34 +0000 (UTC) Received: from mail-wm2-f13.google.com (mail-wm2-f13.google.com [74.125.225.141]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.2915.1790154693231127143 for ; Wed, 23 Sep 2026 02:11:33 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=nI39h4t+; spf=pass (domain: smile.fr, ip: 74.125.225.141, mailfrom: yoann.congal@smile.fr) Received: by mail-wm2-f13.google.com with SMTP id 5b1f17b1804b1-49cc9f581c4so2338765e9.0 for ; Wed, 23 Sep 2026 02:11:33 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1790154691; x=1790759491; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=gECP0vMTob93gU6XpFcMbFFMb1herD1anlVWTXPP00w=; b=nI39h4t+Z0yuVPE72sT3SQJ+WIEiMH4kteN1kgJ6zLn91aurSNt5MyHCoEKHAKKfp0 F3E24UF6tzbSiS+XhZMeqkzDyj143DX4sRLSKLg61RfdrjVoUNAM8/lviXbn/wkbr+YG dToF7IknTtIUkkqFj/HctaMrXjCYNyHycIG9k= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1790154691; x=1790759491; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=gECP0vMTob93gU6XpFcMbFFMb1herD1anlVWTXPP00w=; b=FX1OHhcVHHy4+LZREsysd+EZySl89YVprvcmOq5fuh21SEJyIVxQifxq5VvwEdodvK eKhB0YEGBcs4jngCGM+ZxJPZioYz3OTRvt7U15SQ7aGy2BFXZZVYXr8YdF2mC/NT6f2U TPjjkOm9KUkeCvjMK5XXSNtFcudbtBg7G6BS92J17vE20Z7bVHT2XLY/UIoF4hxp5Q0A LD0HjHbhG72KxX5OEnXQaRsqfpAHSZ3+or1BABXwgtHH5BK6LlAZrY/iJLWo5j7ApaGp qRa7SzvKnrBCZPkFLNjspTLiU20vVUrd/qsVNxvfOCsBM0D+q/DryMjJIMip5XZAnQvy MPsg== X-Gm-Message-State: AFuF++mLl8j0P6gs59f4XiwIyYye7B7rgpP6ZUkICjAr/9HmPB5jCr5V GyYF+Ta2LP8GDV/Jt7T/b530PrApwgcNP3iYct3cIJayvr7iTbtWYBiVrHqjDIgYCdQi3wD1CZO GBNQV4aY= X-Gm-Gg: AYBFou3v2/Wc0wej5f28AuQYN6vOBA2/05vzS5L55FQ4TY+7T/cHScrm959WvF7apoN Wi511XGKo80cvonV+ocqbu3uFQBY8cb6HVAajJnsRqyMSaxQi3gN7tKX/sALcp9qwKbCfIuBDgY NCXRmDjH6M6T74i0H9t2sEVxxtmWY1bGwvhHhPHeX2k4LTPJNq2WQ8NQu2LkMqs/z4gkEk6+lWW ZDFWhWRLok2nv454sfBGrkrtzaxbPvtdju4MRvgJHBCIhdm44ixzmacsMn4KdhzEd7yo/YZ8vHj cP+ocYCrrqgwo4zMQsiOfLDvDGPumB4MHDwWKBrn5WABt0FqZ0/SFShK5PPXKafMZoIuKanpYiT xbcDb07gUn8neC3Xc4hb0urmGtif3OE2P730JI7fEcH1cmEqdZk5D5/AKn7x1r/2C23XZFPWVGe RBmcyzn8GGn1lCTolUWIdkB4UEezHLCb0K84kQATpdu3XPTgHGPvtWLtxTmMwu1/ePKE4PJS3X/ Oc1L1y6sOoRSfZpQYjOOX5Cw138ur2NM8GqeNdh9q3vLpF2a0pDRj5WYTBYqJeV6TjAyyTk X-Received: by 2002:a05:600c:621a:b0:49f:d69a:1a04 with SMTP id 5b1f17b1804b1-49fde4a12d1mr31396045e9.16.1790154691426; Wed, 23 Sep 2026 02:11:31 -0700 (PDT) Received: from FRSMI25-LASER.home (2a02-8440-b519-f416-8bed-8817-19fd-ccf7.rev.sfr.net. [2a02:8440:b519:f416:8bed:8817:19fd:ccf7]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-49fe2730da9sm14251525e9.4.2026.09.23.02.11.30 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 23 Sep 2026 02:11:31 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][scarthgap 12/48] vim: Fix for CVE-2026-73073 Date: Wed, 23 Sep 2026 11:10:14 +0200 Message-ID: X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Wed, 23 Sep 2026 09:11:34 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/246474 From: Hitendra Prajapati Pick the patch from [1], also referenced in the NVD report [2]. [1] https://github.com/vim/vim/commit/2f628d8104958fa7421664f792ca6d4f7a39a10f [2] https://nvd.nist.gov/vuln/detail/CVE-2026-73073 Signed-off-by: Hitendra Prajapati Signed-off-by: Yoann Congal --- .../vim/files/CVE-2026-73073.patch | 89 +++++++++++++++++++ meta/recipes-support/vim/vim.inc | 1 + 2 files changed, 90 insertions(+) create mode 100644 meta/recipes-support/vim/files/CVE-2026-73073.patch diff --git a/meta/recipes-support/vim/files/CVE-2026-73073.patch b/meta/recipes-support/vim/files/CVE-2026-73073.patch new file mode 100644 index 00000000000..932580d3a10 --- /dev/null +++ b/meta/recipes-support/vim/files/CVE-2026-73073.patch @@ -0,0 +1,89 @@ +From 2f628d8104958fa7421664f792ca6d4f7a39a10f Mon Sep 17 00:00:00 2001 +From: Yasuhiro Matsumoto +Date: Fri, 17 Jul 2026 09:11:42 +0900 +Subject: [PATCH] patch 9.2.0845: [security]: arbitrary Ex command execution + during C omni-completion + +Problem: [security]: arbitrary Ex command execution during C + omni-completion (Threonine) +Solution: Match tags typeref literally to block Ex command injection + (Yasuhiro Matsumoto). + +Escaping only "/" and "\" left the typeref able to break out of the +:vimgrep pattern without a "/": an unclosed "[" makes vimgrep's pattern +skipping fail, and the parser then treats a following "|" as a command +separator, so the tag value runs as Ex commands during C omni-completion. +Match the field literally with \V so no regex metacharacter can affect +pattern parsing. + +Github Security Advisory: +https://github.com/vim/vim/security/advisories/GHSA-cx73-phcg-3j5g + +Signed-off-by: Yasuhiro Matsumoto +Signed-off-by: Christian Brabandt + +CVE: CVE-2026-73073 +Upstream-Status: Backport [https://github.com/vim/vim/commit/2f628d8104958fa7421664f792ca6d4f7a39a10f] +Signed-off-by: Hitendra Prajapati +--- + runtime/autoload/ccomplete.vim | 5 ++++- + src/testdir/test_plugin_ccomplete.vim | 26 ++++++++++++++++++++++++++ + 2 files changed, 30 insertions(+), 1 deletion(-) + +diff --git a/runtime/autoload/ccomplete.vim b/runtime/autoload/ccomplete.vim +index 248d6f2e60..5a48581dcf 100644 +--- a/runtime/autoload/ccomplete.vim ++++ b/runtime/autoload/ccomplete.vim +@@ -592,8 +592,11 @@ def StructMembers( # {{{1 + if complete_check() + return [] + endif ++ # Match "typename" literally (\V): escaping alone is not enough, as e.g. ++ # an unclosed "[" makes vimgrep's pattern skipping fail and the rest of ++ # the tag value is then parsed as Ex commands. + execute 'silent! keepjumps noautocmd ' +- .. n .. 'vimgrep ' .. '/\t' .. escape(typename, '/\') .. '\(\t\|$\)/j ' ++ .. n .. 'vimgrep ' .. '/\t\V' .. escape(typename, '/\') .. '\m\(\t\|$\)/j ' + .. fnames + + qflist = getqflist() +diff --git a/src/testdir/test_plugin_ccomplete.vim b/src/testdir/test_plugin_ccomplete.vim +index a635bd50bd..c1754d17c1 100644 +--- a/src/testdir/test_plugin_ccomplete.vim ++++ b/src/testdir/test_plugin_ccomplete.vim +@@ -31,6 +31,32 @@ func Test_ccomplete_no_exec_via_typeref() + unlet! g:ccomplete_injected + endfunc + ++" Escaping "/" and "\" is not enough: with no "/" in the payload, an unclosed ++" "[" makes vimgrep's pattern skipping fail, and the command parser then treats ++" the first "|" as a command separator. The typeref must be matched literally. ++func Test_ccomplete_no_exec_via_typeref_bracket() ++ CheckUnix ++ let sentinel = tempname() ++ call delete(sentinel) ++ let tagsfile = s:WriteTags([ ++ \ "myvar\tmain.c\t/^x$/;\"\tv\ttyperef:struct:[|call system('touch " .. sentinel .. "')|####", ++ \ ]) ++ ++ let save_tags = &tags ++ let &tags = tagsfile ++ ++ new ++ call ccomplete#Complete(1, '') ++ call ccomplete#Complete(0, 'myvar.x') ++ ++ call assert_false(filereadable(sentinel), ++ \ 'typeref field was executed as an Ex command during omni-completion') ++ ++ bwipe! ++ let &tags = save_tags ++ call delete(sentinel) ++endfunc ++ + " A legitimate typeref must still drive struct-member completion: escaping the + " field value must not break the normal path. + func Test_ccomplete_typeref_completion_still_works() +-- +2.50.1 + diff --git a/meta/recipes-support/vim/vim.inc b/meta/recipes-support/vim/vim.inc index 10f4ce15999..3e90908264a 100644 --- a/meta/recipes-support/vim/vim.inc +++ b/meta/recipes-support/vim/vim.inc @@ -51,6 +51,7 @@ SRC_URI = "git://github.com/vim/vim.git;branch=master;protocol=https \ file://CVE-2026-59858.patch \ file://CVE-2026-57456.patch \ file://CVE-2026-73072.patch \ + file://CVE-2026-73073.patch \ " PV .= ".1683" From patchwork Wed Sep 23 09:10:15 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 98971 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 7EDC7C9830E for ; Wed, 23 Sep 2026 09:11:34 +0000 (UTC) Received: from mail-wm2-f12.google.com (mail-wm2-f12.google.com [74.125.225.140]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.2916.1790154693925546282 for ; Wed, 23 Sep 2026 02:11:34 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=YNHw+zUY; spf=pass (domain: smile.fr, ip: 74.125.225.140, mailfrom: yoann.congal@smile.fr) Received: by mail-wm2-f12.google.com with SMTP id 5b1f17b1804b1-49b912d8239so4799635e9.0 for ; Wed, 23 Sep 2026 02:11:33 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1790154692; x=1790759492; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=sv0q27QkT2mfynJsq6Dy7HtAfJhNKIgeTdRHLn5K6AY=; b=YNHw+zUYLAdob9ziwpQO1+FV3Voc2EBK/Gx/GEiE6fCqO4gvHIFzyBsKgi+dKblERI eIl+IhRRfRuhuMZzLOBAROHTivhqt7QH9/2UZrIkUmwpgfxqUVS1G+p5fZya/E6e0J4W baNatvBOI2+ZprRvBsYN66M9FZBmDNg3hHJQU= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1790154692; x=1790759492; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=sv0q27QkT2mfynJsq6Dy7HtAfJhNKIgeTdRHLn5K6AY=; b=0Eu3oMeWtRmSnNkhn8JSKE60nDvkvWOS9vV9VIxtwzLJZI7iCGJhWZC/zt3aJckWlC Lse/AGVEOU3oUnXMSXfa+tiEqeenkD5jUc8XfRPuauqrFHHhowUNc9pnCusD1gChdxCH j8NnLiBwmK364kvVx/Ok3KXNW8qVVoDVkv9VOd3s1/KML9SUKHGGliHWZZ7omxmqpuNv rwnoGFD40F1xXSEkv+KkIyARvsoB5IVEGgJIzgxPRBvI4alKSYkzc/6Zx/OH3+Lbfb21 KVD3g7qrZT+HooYJT9LpARHPTaPC1oiuMl4tDSH5AmYpKAlDC8pEYNJRzFXtIpeFR0Xi 8mOQ== X-Gm-Message-State: AFuF++kly/XdxdQBcAtvA0YabOmwEDhvHNUkWMk6FxXaHE3/T+CBZcgC gUMLYSjLWruer1jHem8AmqOt2ghTu+UlwEP3fFFK7ZoaZcIPofqA86OMRTdbhl9l89p+uCw3F72 kpgNnvUg= X-Gm-Gg: AYBFou2/V1LRH9qLrYRYEOU1MiOSbxUnIbiSBXl53We+/MTRcD/y/FJWOjBs/YSJC83 a7pCctZfafkwj0S15mPadFHmxbOxkaSREHVz9WKgyFXvEEv9XbYmpaASNKcH+wkb2Hewer6xlTY RX+zIPSx+NegzSwJHGpVOoMGBnmWFFNu6JIVCir8dlvFpqMcAIxzjiHENvRodUSAu/gG8k+KfDh 23CFrY700c+GbAFBvPSG9fU/pieBc1jBxrOMOD/ayoaKIXIF3AdFnr+OVNK6OHB51jN0KS7I/eD ZtPJ772xZNjS0zwuFlIch9StcmUn+lUMEq05Gmp8U1Vqc54oV7DIgHfjE9g4Iop0QfkckHpD3iA bnudOjVwbjUPwfsNEAyJc2vkEOfxWiJIr7VVTewaHXvwSf1lkCOhgtuISpkds2cp8ufFqvE8lhy 9NYiFpAufUFmfFgfOmqGjkIhUoPC7CnYaszivRQI7c7PeDORDh4/Pr/uhWyVmnl2HODW3egk7Uy S/3VJX8FipfVVxnoV04llQnBQm/cM4IMjxbJsajANuuCqG3Vxj7JJI17WK1jL1KYrLabM9RSzeQ fL2dHm0= X-Received: by 2002:a05:600c:1d1a:b0:49c:d019:70c5 with SMTP id 5b1f17b1804b1-49fdec98769mr25087755e9.0.1790154692165; Wed, 23 Sep 2026 02:11:32 -0700 (PDT) Received: from FRSMI25-LASER.home (2a02-8440-b519-f416-8bed-8817-19fd-ccf7.rev.sfr.net. [2a02:8440:b519:f416:8bed:8817:19fd:ccf7]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-49fe2730da9sm14251525e9.4.2026.09.23.02.11.31 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 23 Sep 2026 02:11:31 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][scarthgap 13/48] vim: Fix for CVE-2026-73074 Date: Wed, 23 Sep 2026 11:10:15 +0200 Message-ID: <61f5f1268344dac4696f6390e4a81b6ed324fd34.1790154074.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Wed, 23 Sep 2026 09:11:34 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/246475 From: Hitendra Prajapati Pick the patch from [1], also referenced in the NVD report [2]. [1] https://github.com/vim/vim/commit/a9336b476fd1a182e3f79b5f83c0ffb04f8a922b [2] https://nvd.nist.gov/vuln/detail/CVE-2026-73074 Signed-off-by: Hitendra Prajapati Signed-off-by: Yoann Congal --- .../vim/files/CVE-2026-73074.patch | 101 ++++++++++++++++++ meta/recipes-support/vim/vim.inc | 1 + 2 files changed, 102 insertions(+) create mode 100644 meta/recipes-support/vim/files/CVE-2026-73074.patch diff --git a/meta/recipes-support/vim/files/CVE-2026-73074.patch b/meta/recipes-support/vim/files/CVE-2026-73074.patch new file mode 100644 index 00000000000..3402b72bd27 --- /dev/null +++ b/meta/recipes-support/vim/files/CVE-2026-73074.patch @@ -0,0 +1,101 @@ +From a9336b476fd1a182e3f79b5f83c0ffb04f8a922b Mon Sep 17 00:00:00 2001 +From: Yasuhiro Matsumoto +Date: Thu, 23 Jul 2026 20:14:13 +0000 +Subject: [PATCH] patch 9.2.0841: [security]: heap overflow when adding > 65535 + text properties + +Problem: [security]: heap overflow when adding > 65535 text properties + (Wang1rrr). +Solution: Verify that the number of text properties falls within the + limit (Yasuhiro Matsumoto). + +Github Security Advisory: +https://github.com/vim/vim/security/advisories/GHSA-hm4g-pjfx-m27j + +Signed-off-by: Yasuhiro Matsumoto +Signed-off-by: Christian Brabandt + +CVE: CVE-2026-73074 +Upstream-Status: Backport [https://github.com/vim/vim/commit/a9336b476fd1a182e3f79b5f83c0ffb04f8a922b] +Signed-off-by: Hitendra Prajapati +--- + src/errors.h | 4 ++++ + src/po/vim.pot | 3 +++ + src/testdir/test_textprop.vim | 18 ++++++++++++++++++ + src/textprop.c | 7 +++++++ + 4 files changed, 32 insertions(+) + +diff --git a/src/errors.h b/src/errors.h +index 01ed16a035..5354e85f25 100644 +--- a/src/errors.h ++++ b/src/errors.h +@@ -3795,3 +3795,7 @@ EXTERN char e_socket_server_failed_connecting[] + EXTERN char e_socket_server_unavailable[] + INIT(= N_("E1567: Cannot start socket server, socket path is unavailable")); + #endif ++#ifdef FEAT_PROP_POPUP ++EXTERN char e_too_many_text_properties_on_a_single_line[] ++ INIT(= N_("E1580: Too many text properties on a single line")); ++#endif +diff --git a/src/po/vim.pot b/src/po/vim.pot +index be79cf0dab..100344e270 100644 +--- a/src/po/vim.pot ++++ b/src/po/vim.pot +@@ -8838,6 +8838,9 @@ msgstr "" + msgid "E1567: Cannot start socket server, socket path is unavailable" + msgstr "" + ++msgid "E1580: Too many text properties on a single line" ++msgstr "" ++ + #. type of cmdline window or 0 + #. result of cmdline window or 0 + #. buffer of cmdline window or NULL +diff --git a/src/testdir/test_textprop.vim b/src/testdir/test_textprop.vim +index b5c9f63f65..5a69ca75e7 100644 +--- a/src/testdir/test_textprop.vim ++++ b/src/testdir/test_textprop.vim +@@ -4781,4 +4781,22 @@ func Test_textprop_materialize_list() + call assert_equal([], prop_list(1, #{ids: 3->range()})) + endfunc + ++" Adding more than 65535 text properties to one line must be rejected instead ++" of wrapping the uint16_t property count and overflowing the allocation. ++func Test_prop_add_over_uint16_max() ++ CheckNotAsan ++ CheckNotValgrind ++ new ++ call setline(1, 'x') ++ call prop_type_add('overflow', {}) ++ for _ in range(0xffff) ++ call prop_add(1, 1, {'type': 'overflow', 'length': 0}) ++ endfor ++ call assert_equal(0xffff, prop_list(1)->len()) ++ call assert_fails("call prop_add(1, 1, {'type': 'overflow', 'length': 0})", 'E1580:') ++ call assert_equal(0xffff, prop_list(1)->len()) ++ call prop_type_delete('overflow') ++ bwipe! ++endfunc ++ + " vim: shiftwidth=2 sts=2 expandtab +diff --git a/src/textprop.c b/src/textprop.c +index a06605d3dd..1f06615dbc 100644 +--- a/src/textprop.c ++++ b/src/textprop.c +@@ -240,6 +240,13 @@ prop_add_one( + proplen = get_text_props(buf, lnum, &props, TRUE); + textlen = buf->b_ml.ml_line_len - proplen * sizeof(textprop_T); + ++ // prop_count is a uint16_t; stop before proplen + 1 wraps to zero. ++ if (proplen >= 0xffff) ++ { ++ emsg(_(e_too_many_text_properties_on_a_single_line)); ++ goto theend; ++ } ++ + if (lnum == start_lnum) + col = start_col; + else +-- +2.50.1 + diff --git a/meta/recipes-support/vim/vim.inc b/meta/recipes-support/vim/vim.inc index 3e90908264a..9ea050650f3 100644 --- a/meta/recipes-support/vim/vim.inc +++ b/meta/recipes-support/vim/vim.inc @@ -52,6 +52,7 @@ SRC_URI = "git://github.com/vim/vim.git;branch=master;protocol=https \ file://CVE-2026-57456.patch \ file://CVE-2026-73072.patch \ file://CVE-2026-73073.patch \ + file://CVE-2026-73074.patch \ " PV .= ".1683" From patchwork Wed Sep 23 09:10:16 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 98980 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id DFA23C9830B for ; Wed, 23 Sep 2026 09:11:44 +0000 (UTC) Received: from mail-wm2-f13.google.com (mail-wm2-f13.google.com [74.125.225.141]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.2917.1790154695303568339 for ; Wed, 23 Sep 2026 02:11:35 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=P13IJ3E8; spf=pass (domain: smile.fr, ip: 74.125.225.141, mailfrom: yoann.congal@smile.fr) Received: by mail-wm2-f13.google.com with SMTP id 5b1f17b1804b1-49b912d822dso4195815e9.2 for ; Wed, 23 Sep 2026 02:11:35 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1790154693; x=1790759493; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=adK+OfZ+1wPpZJz/FiWRmhy2wHUfcQi3HXF3iy9Dljs=; b=P13IJ3E80xsZdGxsBTJ0Nq2rLpLwQon2fs58LFEN9mh701YFHYNDYEl+9bHa4bCDbi pNtUXTNtyMpiipo94Br1cQFBkIg0j2xFP0CSpOXoNKb3C1zknno+5wXxNfLk8d6Pksdr sF12jR3HjOWYrxvVAQvP/9szarKfXP6LjHk3U= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1790154693; x=1790759493; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=adK+OfZ+1wPpZJz/FiWRmhy2wHUfcQi3HXF3iy9Dljs=; b=kYcC+FKUVYwPCOxPBVBS6kDgMB0zqvY1ffxbZlx8gSTku7B/lKCChTDqP9OZfrQ9Vy /aABkw/u5rhMWcwHiIHb7kMfyCB5GwBEHdBVh0gqo/25CdomKt9CLNgIlQn9k/yx2guH 1nL+QZMlTglHLH4RYVPKCmhSdpdAeokBLCuus5hYdo5icR9V0p3OAl/1v7cu45xO1GNf zrX+wfg2bGq0ePnr8UPAFVjo7N7+32l06HRexu08oeSrl6RJ/dOmrf6UmUxOsy3hP3ZC RU+pR9wh+SrNa19WI3jcC03GcNQVuWic2Q8ukphPXQVHpkyD9J/gw1gqGdKcdGsfMETh o8PA== X-Gm-Message-State: AFuF++kfbq9hb/oBq6cy12M9X/nKxx4uPUFBVfOwGqN0ABQsrvN83eVT L4RaglYqdSlshxazZP/vBZ7wtB+C/65EqdbC0q7G70BtgI2pxsLJFLsXA9Zn03RYz48j0lNLE39 Cc26wUGg= X-Gm-Gg: AYBFou0l8cdrELHhHrHCZDu3i/CdnHSHMIw/sPZJNy6A6+X2e8D+PJ1TXlVYBMzk08n kYVqaf4rQbgjovKMybg+/fHywSvNc/cU/6OC61qie6h4p5vXnfTZEN6glyfkRJVGRIldHwflEG8 m/QZTp21WwtwSqCKxmeSSvUcxi6xESVwUu0LNUFejHZG2EUwjQhJK1UMrY7mX2pmMYAi8lcdrgy LmkSrl12bbBYKZYCwD+bjpbXtT8Hswvi6eGRlpgpoGzWrYzGJvj/knm22cD241cX2h6Nr9GRVqW YvhTqhf97S6Tx6ah3SitdVFHpxNvTVwwZQi5B3nfD5LdOp8N9Eh5rI0N0TPlJNXiPxEDZy/Cz1W RIn6fOKAO65+MJ/EOoitwnidP7ldj6xkZ+CIjtble8qqS1B4SYCMY6Ryh30fbAZAFubKzYIwd8R vUMsWpq7n4C/uq+OFIUJFIUZ5BHriIQHkJl8TN99FvWcr9VnliEJjLk6kQxgYfhrBoAkwWp22VF FGNoqL/5cMWCTb7Rs70NdlNvdpINkoYV1tlBcCx/CLSa5u1EqavviQzznmQNE6l4XYtlZYTcIOo KgHR1yI= X-Received: by 2002:a05:600c:5020:b0:49f:d377:ac24 with SMTP id 5b1f17b1804b1-49fdeff8236mr25413395e9.3.1790154693495; Wed, 23 Sep 2026 02:11:33 -0700 (PDT) Received: from FRSMI25-LASER.home (2a02-8440-b519-f416-8bed-8817-19fd-ccf7.rev.sfr.net. [2a02:8440:b519:f416:8bed:8817:19fd:ccf7]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-49fe2730da9sm14251525e9.4.2026.09.23.02.11.32 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 23 Sep 2026 02:11:33 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][scarthgap 14/48] vim: Fix for CVE-2026-73077 Date: Wed, 23 Sep 2026 11:10:16 +0200 Message-ID: <62b60951830529d58bad8f64c9d0d217aa432c98.1790154074.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Wed, 23 Sep 2026 09:11:44 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/246476 From: Hitendra Prajapati Pick the patch from [1], also referenced in the NVD report [2]. [1] https://github.com/vim/vim/commit/c5a82fe013e73c98004ad7cd4f906b1ad1ed610e [2] https://nvd.nist.gov/vuln/detail/CVE-2026-73077 Signed-off-by: Hitendra Prajapati Signed-off-by: Yoann Congal --- .../vim/files/CVE-2026-73077.patch | 96 +++++++++++++++++++ meta/recipes-support/vim/vim.inc | 1 + 2 files changed, 97 insertions(+) create mode 100644 meta/recipes-support/vim/files/CVE-2026-73077.patch diff --git a/meta/recipes-support/vim/files/CVE-2026-73077.patch b/meta/recipes-support/vim/files/CVE-2026-73077.patch new file mode 100644 index 00000000000..6bf157a8083 --- /dev/null +++ b/meta/recipes-support/vim/files/CVE-2026-73077.patch @@ -0,0 +1,96 @@ +From c5a82fe013e73c98004ad7cd4f906b1ad1ed610e Mon Sep 17 00:00:00 2001 +From: Yasuhiro Matsumoto +Date: Thu, 23 Jul 2026 19:13:15 +0000 +Subject: [PATCH] patch 9.2.0839: [security]: arbitrary code execution via + keyword lookup + +Problem: [security]: arbitrary code execution via keyword lookup in + sh.vim, zsh.vim and ps1.vim filetype plugin + (manus-use) +Solution: For powershell, quote the commands using single quotes, for + sh/zsh pass the argument as a separate list item to term_start()/system() + (Yasuhiro Matsumoto). + +Github Security Advisory: +https://github.com/vim/vim/security/advisories/GHSA-r5v6-q6j8-8qw2 + +Signed-off-by: Yasuhiro Matsumoto +Signed-off-by: Christian Brabandt + +CVE: CVE-2026-73077 +Upstream-Status: Backport [https://github.com/vim/vim/commit/c5a82fe013e73c98004ad7cd4f906b1ad1ed610e] +Signed-off-by: Hitendra Prajapati +--- + runtime/ftplugin/ps1.vim | 5 +++-- + runtime/ftplugin/sh.vim | 5 +++-- + runtime/ftplugin/zsh.vim | 6 +++--- + 3 files changed, 9 insertions(+), 7 deletions(-) + +diff --git a/runtime/ftplugin/ps1.vim b/runtime/ftplugin/ps1.vim +index f1fe78df4c..9ff764a282 100644 +--- a/runtime/ftplugin/ps1.vim ++++ b/runtime/ftplugin/ps1.vim +@@ -6,6 +6,7 @@ + " 2024 May 23 by Riley Bruins ('commentstring') + " 2024 Sep 19 by Konfekt (simplify keywordprg #15696) + " 2025 Jul 22 by phanium (use :hor term #17822) ++" 2026 Jul 10 by Vim Project (quote K argument, prevent command injection) + + " Only do this when not done yet for this buffer + if exists("b:did_ftplugin") | finish | endif +@@ -52,9 +53,9 @@ endif + + if exists('s:pwsh_cmd') + if exists(':terminal') == 2 +- command! -buffer -nargs=1 GetHelp silent exe 'hor term ' . s:pwsh_cmd . ' -NoLogo -NoProfile -NonInteractive -ExecutionPolicy RemoteSigned -Command Get-Help -Full ""' . (executable('less') ? ' | less' : '') ++ command! -buffer -nargs=1 GetHelp call term_start([s:pwsh_cmd, '-NoLogo', '-NoProfile', '-NonInteractive', '-ExecutionPolicy', 'RemoteSigned', '-Command', "Get-Help -Full '" . substitute(, "'", "''", 'g') . "'" . (executable('less') ? ' | less' : '')]) + else +- command! -buffer -nargs=1 GetHelp echo system(s:pwsh_cmd . ' -NoLogo -NoProfile -NonInteractive -ExecutionPolicy RemoteSigned -Command Get-Help -Full ') ++ command! -buffer -nargs=1 GetHelp echo system([s:pwsh_cmd, '-NoLogo', '-NoProfile', '-NonInteractive', '-ExecutionPolicy', 'RemoteSigned', '-Command', "Get-Help -Full '" . substitute(, "'", "''", 'g') . "'"]) + endif + setlocal keywordprg=:GetHelp + let b:undo_ftplugin ..= " | setl kp< | sil! delc -buffer GetHelp" +diff --git a/runtime/ftplugin/sh.vim b/runtime/ftplugin/sh.vim +index 18cd219cdc..45e6f44fcf 100644 +--- a/runtime/ftplugin/sh.vim ++++ b/runtime/ftplugin/sh.vim +@@ -8,6 +8,7 @@ + " 2024 Dec 29 by Vim Project (improve setting shellcheck compiler) + " 2025 Mar 09 by Vim Project (set b:match_skip) + " 2025 Jul 22 by phanium (use :hor term #17822) ++" 2026 Jul 10 by Vim Project (pass K argument as a list, prevent shell injection) + + if exists("b:did_ftplugin") + finish +@@ -54,9 +55,9 @@ let s:is_kornshell = get(b:, "is_kornshell", get(g:, "is_kornshell", 0)) + + if s:is_bash + if exists(':terminal') == 2 +- command! -buffer -nargs=1 ShKeywordPrg silent exe ':hor term bash -c "help "" 2>/dev/null || man """' ++ command! -buffer -nargs=1 ShKeywordPrg call term_start(['bash', '-c', 'help "$1" 2>/dev/null || man "$1"', '--', ]) + else +- command! -buffer -nargs=1 ShKeywordPrg echo system('bash -c "help " 2>/dev/null || MANPAGER= man ""') ++ command! -buffer -nargs=1 ShKeywordPrg echo system(['bash', '-c', 'help "$1" 2>/dev/null || MANPAGER= man "$1"', '--', ]) + endif + setlocal keywordprg=:ShKeywordPrg + let b:undo_ftplugin ..= " | setl kp< | sil! delc -buffer ShKeywordPrg" +diff --git a/runtime/ftplugin/zsh.vim b/runtime/ftplugin/zsh.vim +index 65e9f377bf..8ee71c4e17 100644 +--- a/runtime/ftplugin/zsh.vim ++++ b/runtime/ftplugin/zsh.vim +@@ -22,9 +22,9 @@ let b:undo_ftplugin = "setl com< cms< fo< " + + if executable('zsh') && &shell !~# '/\%(nologin\|false\)$' + if exists(':terminal') == 2 +- command! -buffer -nargs=1 ZshKeywordPrg silent exe ':hor term zsh -c "autoload -Uz run-help; run-help "' +- else +- command! -buffer -nargs=1 ZshKeywordPrg echo system('MANPAGER= zsh -c "autoload -Uz run-help; run-help 2>/dev/null"') ++ command! -buffer -nargs=1 ZshKeywordPrg call term_start(['zsh', '-c', 'autoload -Uz run-help; run-help "$1"', '--', ]) ++ elseif has("patch-9.2.0250") ++ command! -buffer -nargs=1 ZshKeywordPrg echo system(['zsh', '-c', 'autoload -Uz run-help; MANPAGER= run-help "$1" 2>/dev/null', '--', ]) + endif + setlocal keywordprg=:ZshKeywordPrg + let b:undo_ftplugin .= '| setl keywordprg< | sil! delc -buffer ZshKeywordPrg' +-- +2.50.1 + diff --git a/meta/recipes-support/vim/vim.inc b/meta/recipes-support/vim/vim.inc index 9ea050650f3..91250ddc68a 100644 --- a/meta/recipes-support/vim/vim.inc +++ b/meta/recipes-support/vim/vim.inc @@ -53,6 +53,7 @@ SRC_URI = "git://github.com/vim/vim.git;branch=master;protocol=https \ file://CVE-2026-73072.patch \ file://CVE-2026-73073.patch \ file://CVE-2026-73074.patch \ + file://CVE-2026-73077.patch \ " PV .= ".1683" From patchwork Wed Sep 23 09:10:17 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 8bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 98983 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 05DAEC9830F for ; Wed, 23 Sep 2026 09:11:45 +0000 (UTC) Received: from mail-wm2-f13.google.com (mail-wm2-f13.google.com [74.125.225.141]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.2918.1790154696863680139 for ; Wed, 23 Sep 2026 02:11:37 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=vwZfBL26; spf=pass (domain: smile.fr, ip: 74.125.225.141, mailfrom: yoann.congal@smile.fr) Received: by mail-wm2-f13.google.com with SMTP id 5b1f17b1804b1-49e7d2bb404so2174415e9.1 for ; Wed, 23 Sep 2026 02:11:36 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1790154695; x=1790759495; darn=lists.openembedded.org; h=content-transfer-encoding:content-type:mime-version:references :in-reply-to:message-id:date:subject:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=tdCCJK5YEaCHUnOjYzU8jACNSzVRD93EJjYJ5covCb8=; b=vwZfBL26GBTP38e+46hqWwyoUEZa31oUE0vFUWNvkwEzK0sd5SN41jI9mzLoBEPEDH fGwX7x+uA1eKFgMiNjoj397Kt4pd0oprZnYFdhrUg87S2OPSiA9VLWh1tRXQwmJaKxdM b9KhLUSMN6/383I+IcKGUyDX+MDMzoY5OoMsQ= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1790154695; x=1790759495; h=content-transfer-encoding:content-type:mime-version:references :in-reply-to:message-id:date:subject:to:from:x-gm-gg :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to :content-type; bh=tdCCJK5YEaCHUnOjYzU8jACNSzVRD93EJjYJ5covCb8=; b=NSBMAOJt4+S9O24OSS+MsE95bTg2qVRFTjM1I7ddn1U53jC+z7NH83Rp8PPj0SgM2X Sp76HriLJgq9es8M+0o7tWErraduyQ2oF5mHa9iCKdbSpFkKra0iyJL3QmFoeJW7BLuL g5Q9ajekksyWf47PGjL81z3I24CK/INYW9awfxWIs7LS/DsDHqnVmK1aQFiYcWtMSNzC VlP/uOSYEY3M7B2aAsiZvKir3Bzgf44emQhSHCgcVKw2KYP0JzyU3CUrRZ3CAq8c+3YI s16TxWcHd0JFlLox5yLkQ5TDUA24uB/NlM6cofhuWLEj7++nHSmLBcwaFa6pL1nb7nrS 8woA== X-Gm-Message-State: AFuF++lNHQveuWaJLVRT34+ww1nIYYjJ2IuhUneboQBwMU0o2FP1x+Ej U7/dLbefKG8kFdA6I633m/ymaTXROA3OY0UQ95NJzugQU1v8HaEKPnRX+FZm//WhqX6OUcukl5p tRw+N1qk= X-Gm-Gg: AYBFou05nZC3nr7QP3FlNq05xBe7lsNVlwwE/eNFVkojfLL3dzBsR9A1PWVd4ONSoeD eCdIQcGrXvveBK9sPnW5t+zH2VKJTe7MllpVh3KZUQyL5FZZYpohAgzxtYTtRfjbg4YvDT64iFH r1hAAVW5ShPeSyAKW3dqmSm7mcfCS6D50ANUlecr2jtXh/qj9cHusBoeXWPkCjGQCXaIxB5hH+T P59RXMx1pcSiTvJms42w7GoG+ig9Ezmof2yLMqCTLDpqU5BLTfFQeJ0QljGw7G8J7TE5tdfcWUj 5uAhEwpsxjHMky36hIMn0QVOeMeebnN9AXN7VgxlZZPRTxbrPdtB8NEgINP2EUP2fu4cYzQuiS3 MnGpb0yl2DxRbuppcclDi6sIG48ywoHvEbiLz/QbjtunX/803velYBUiy5OdTyYlzOO5vL2Md7r 4VNBD3GVtUvl+H6SmyHi4MZfx4ddomfWB6H8GGaZcAL2lRtmGraagkZle32xKCJFdd3y08uxALt +oCYemUwZ1Bu2Hw/VvP4hG/tMhSViB37u6TRcmzyQbCP2d8I9tont/ojTVh/gWnKaa9ZjHt X-Received: by 2002:a05:600c:6087:b0:49d:2936:8ad1 with SMTP id 5b1f17b1804b1-49fde360163mr33509925e9.1.1790154695053; Wed, 23 Sep 2026 02:11:35 -0700 (PDT) Received: from FRSMI25-LASER.home (2a02-8440-b519-f416-8bed-8817-19fd-ccf7.rev.sfr.net. [2a02:8440:b519:f416:8bed:8817:19fd:ccf7]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-49fe2730da9sm14251525e9.4.2026.09.23.02.11.33 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 23 Sep 2026 02:11:34 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][scarthgap 15/48] vim: Fix for CVE-2026-73078 Date: Wed, 23 Sep 2026 11:10:17 +0200 Message-ID: <60254acd1a9ca4ce984bf4006b84e46f9727491f.1790154074.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Wed, 23 Sep 2026 09:11:45 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/246477 From: Hitendra Prajapati Pick the patch from [1], also referenced in the NVD report [2]. [1] https://github.com/vim/vim/commit/29c6fd090d4520592f8be7d9ec81190edf25ef69 [2] https://nvd.nist.gov/vuln/detail/CVE-2026-73078 Signed-off-by: Hitendra Prajapati Signed-off-by: Yoann Congal --- .../vim/files/CVE-2026-73078.patch | 94 +++++++++++++++++++ meta/recipes-support/vim/vim.inc | 1 + 2 files changed, 95 insertions(+) create mode 100644 meta/recipes-support/vim/files/CVE-2026-73078.patch diff --git a/meta/recipes-support/vim/files/CVE-2026-73078.patch b/meta/recipes-support/vim/files/CVE-2026-73078.patch new file mode 100644 index 00000000000..48b561d9e74 --- /dev/null +++ b/meta/recipes-support/vim/files/CVE-2026-73078.patch @@ -0,0 +1,94 @@ +From 29c6fd090d4520592f8be7d9ec81190edf25ef69 Mon Sep 17 00:00:00 2001 +From: Yasuhiro Matsumoto +Date: Mon, 6 Jul 2026 13:54:03 +0900 +Subject: [PATCH] patch 9.2.0840: [security]: code injection in netrw via + bookmarks + +Problem: [security]: code injection in netrw via bookmarks and history + (David Carliez) +Solution: Escape the '|' explicitly (Yasuhiro Matsumoto) + +The bookmark and history menu builders interpolate paths into :execute'd +:menu commands using g:netrw_menu_escape, which did not escape the Ex +command separator '|'. A crafted path could break out of the :menu command +and run arbitrary Ex/shell commands when the menu was built or triggered. + +Add '|' to g:netrw_menu_escape for the menu names, escape the :e right-hand +side with fnameescape(), and quote the netrw#MakeTgt() argument with +string() instead of raw single-quote interpolation. + +Github Security Advisory: +https://github.com/vim/vim/security/advisories/GHSA-rcr7-f3wr-22r2 + +Signed-off-by: Yasuhiro Matsumoto +Signed-off-by: Christian Brabandt + +CVE: CVE-2026-73078 +Upstream-Status: Backport [https://github.com/vim/vim/commit/29c6fd090d4520592f8be7d9ec81190edf25ef69] +Signed-off-by: Hitendra Prajapati +--- + runtime/pack/dist/opt/netrw/autoload/netrw.vim | 16 +++++++++------- + 1 file changed, 9 insertions(+), 7 deletions(-) + +diff --git a/runtime/pack/dist/opt/netrw/autoload/netrw.vim b/runtime/pack/dist/opt/netrw/autoload/netrw.vim +index 49ccebc07a..a3198dc689 100644 +--- a/runtime/pack/dist/opt/netrw/autoload/netrw.vim ++++ b/runtime/pack/dist/opt/netrw/autoload/netrw.vim +@@ -380,7 +380,7 @@ if has("win32") + else + call s:NetrwInit("g:netrw_glob_escape",'*[]?`{~$\') + endif +-call s:NetrwInit("g:netrw_menu_escape",'.&? \') ++call s:NetrwInit("g:netrw_menu_escape",'.&? \|') + call s:NetrwInit("s:netrw_map_escape","<|\n\r\\\\"") + if has("gui_running") && (&enc == 'utf-8' || &enc == 'utf-16' || &enc == 'ucs-4') + let s:treedepthstring= "│ " +@@ -3734,13 +3734,14 @@ function s:NetrwBookmarkMenu() + if exists("g:netrw_bookmarklist") && g:netrw_bookmarklist != [] && g:netrw_dirhistmax > 0 + let cnt= 1 + for bmd in g:netrw_bookmarklist +- let bmd= escape(bmd,g:netrw_menu_escape) ++ let ebmd= escape(bmd,g:netrw_menu_escape) ++ let fbmd= escape(fnameescape(bmd),'|') + + " show bookmarks for goto menu +- exe 'sil! menu '.g:NetrwMenuPriority.".2.".cnt." ".g:NetrwTopLvlMenu.'Bookmarks.'.bmd.' :e '.bmd."\" ++ exe 'sil! menu '.g:NetrwMenuPriority.".2.".cnt." ".g:NetrwTopLvlMenu.'Bookmarks.'.ebmd.' :e '.fbmd."\" + + " show bookmarks for deletion menu +- exe 'sil! menu '.g:NetrwMenuPriority.".8.2.".cnt." ".g:NetrwTopLvlMenu.'Bookmarks\ and\ History.Bookmark\ Delete.'.bmd.' '.cnt."mB" ++ exe 'sil! menu '.g:NetrwMenuPriority.".8.2.".cnt." ".g:NetrwTopLvlMenu.'Bookmarks\ and\ History.Bookmark\ Delete.'.ebmd.' '.cnt."mB" + let cnt= cnt + 1 + endfor + +@@ -3756,7 +3757,8 @@ function s:NetrwBookmarkMenu() + let priority = g:netrw_dirhistcnt + histcnt + if exists("g:netrw_dirhist_{cnt}") + let histdir= escape(g:netrw_dirhist_{cnt},g:netrw_menu_escape) +- exe 'sil! menu '.g:NetrwMenuPriority.".3.".priority." ".g:NetrwTopLvlMenu.'History.'.histdir.' :e '.histdir."\" ++ let ehistdir= escape(fnameescape(g:netrw_dirhist_{cnt}),'|') ++ exe 'sil! menu '.g:NetrwMenuPriority.".3.".priority." ".g:NetrwTopLvlMenu.'History.'.histdir.' :e '.ehistdir."\" + endif + let first = 0 + let cnt = ( cnt - 1 ) % g:netrw_dirhistmax +@@ -7104,7 +7106,7 @@ function s:NetrwTgtMenu() + let tgtdict[bmd]= cnt + let ebmd= escape(bmd,g:netrw_menu_escape) + " show bookmarks for goto menu +- exe 'sil! menu '.g:NetrwMenuPriority.".19.1.".cnt." ".g:NetrwTopLvlMenu.'Targets.'.ebmd." :call netrw#MakeTgt('".bmd."')\" ++ exe 'sil! menu '.g:NetrwMenuPriority.".19.1.".cnt." ".g:NetrwTopLvlMenu.'Targets.'.ebmd." :call netrw#MakeTgt(".escape(string(bmd),'|').")\" + let cnt= cnt + 1 + endfor + endif +@@ -7122,7 +7124,7 @@ function s:NetrwTgtMenu() + endif + let tgtdict[histentry] = histcnt + let ehistentry = escape(histentry,g:netrw_menu_escape) +- exe 'sil! menu '.g:NetrwMenuPriority.".19.2.".priority." ".g:NetrwTopLvlMenu.'Targets.'.ehistentry." :call netrw#MakeTgt('".histentry."')\" ++ exe 'sil! menu '.g:NetrwMenuPriority.".19.2.".priority." ".g:NetrwTopLvlMenu.'Targets.'.ehistentry." :call netrw#MakeTgt(".escape(string(histentry),'|').")\" + endif + let histcnt = histcnt + 1 + endwhile +-- +2.50.1 + diff --git a/meta/recipes-support/vim/vim.inc b/meta/recipes-support/vim/vim.inc index 91250ddc68a..0acf8247b72 100644 --- a/meta/recipes-support/vim/vim.inc +++ b/meta/recipes-support/vim/vim.inc @@ -54,6 +54,7 @@ SRC_URI = "git://github.com/vim/vim.git;branch=master;protocol=https \ file://CVE-2026-73073.patch \ file://CVE-2026-73074.patch \ file://CVE-2026-73077.patch \ + file://CVE-2026-73078.patch \ " PV .= ".1683" From patchwork Wed Sep 23 09:10:18 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 98981 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 1A176C9830E for ; Wed, 23 Sep 2026 09:11:45 +0000 (UTC) Received: from mail-wr2-f20.google.com (mail-wr2-f20.google.com [74.125.225.84]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.2919.1790154697919500065 for ; Wed, 23 Sep 2026 02:11:38 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=m+fVyoLr; spf=pass (domain: smile.fr, ip: 74.125.225.84, mailfrom: yoann.congal@smile.fr) Received: by mail-wr2-f20.google.com with SMTP id ffacd0b85a97d-482f6356256so246854f8f.1 for ; Wed, 23 Sep 2026 02:11:37 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1790154696; x=1790759496; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=53IqsA+Bt3WZtWzlmNe25467oUqJCdSmXzl2DtN5MbA=; b=m+fVyoLrbQ53YyzJbuhgpYyT2zp7NJUldsZzzJ1OulkeK09i4modLjO93kPUIf0zyb MC/qLbhJ00lc+TWcFQKrj/N1aKrJ6X4tWbsIWL0ivH20q204YmtIGRLXymHu5FslOh3c 7zzFnx8zm85+l9h/Y2AKc1pSDLuWyGFoJ5JZI= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1790154696; x=1790759496; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=53IqsA+Bt3WZtWzlmNe25467oUqJCdSmXzl2DtN5MbA=; b=CUjkWJd6KAeoWNxWF/yx+za9Hai81jqypc/EaZC2vGcpO2Yy299G8VPzk6o5wl8h/m I//AsOidqCBsPs4Y/W8oMOkTwjG9lvj41JQXflSBiUA+fOX31b3AjQztxAU2yxgpJqZm BQXfsc6/mlBksj7cBM0M6XaOkyqbfD2SruQkx8irr61niVJFiykPXghPSMHke9zgaVWJ Ft70LTEHaVQjlt1TwnBF0VQ2Wpume13idDmLqdeR/t2AttFZHvu7ubmnQ0CCvZvjJPtb 5FWHx0EDA5JYuLXjiuD4ZtNnKaP5jlXjvLOZJgPLWTU+Sg4wxfOKxF1po74C6/GybVvm kPKA== X-Gm-Message-State: AFuF++lRHfV0Pv5FrLzJPABKd5FgFBwl5YFFCZWT+drOQQ275ZaG8xO8 IVuKLGe394C/Xgk6+ST/cg4YfkBZCGBSOqCNt2zlVarCTZMmnadYCv3pHzfkI9UEDXVFvvpTst2 Ks5QhwNQ= X-Gm-Gg: AYBFou1Zq/lFXSfwFZfv4r0itTKvtjS/XWaejr2bl1ieAmttuBFylPkf1BXzPah+Tiz xZ09Ag3uo/BROwnRAHWFJoEipuZNJtnagVwzE4vn0aZUbyVrlzx2xHiI+WdKTD5N7h2F109Ovvf uIlcKjT8GVdt8K/8SOWiVas7yyvVPA2RQl/SvbujU5uQnHmbuMwksogvW3it6YV/Q59MUyanwmD V9oxRp2lL0WaQT+VRb51RM1/550k2fcWWIb0BWon1+KN2V56OfTYjjHh2ozFCw9zBpPrkhM1rEV 7JdM7WvI+5imMdxIyMRM04Jv+GDVP1l/HD3FNPQ5XBN6xtbzB9fQkYL4LIv20ZiTLSeGry4uBDB 0UkMtYJgMWRTxedc6/3WPCnX5quxXZL74fDnrnPyB9clh8rsGiNyvViH1qo/b9B9D40uQqL/HDG g+GZO6w4sZVNqWKIJsawB2PPgpwDtzHMPPL/VL0zA+JAnGLlLlRn6WTx7kviAqj1wnBhQxjWW2f bdbMA0iv/D/SdGkhIhh7myLRhvb/ijpUJKgYg0J+U0uFvll3Ld3lfGtQmNWTIfBzqxyRhnw X-Received: by 2002:a05:600c:46d5:b0:49d:257c:a735 with SMTP id 5b1f17b1804b1-49fde497533mr28139365e9.11.1790154695900; Wed, 23 Sep 2026 02:11:35 -0700 (PDT) Received: from FRSMI25-LASER.home (2a02-8440-b519-f416-8bed-8817-19fd-ccf7.rev.sfr.net. [2a02:8440:b519:f416:8bed:8817:19fd:ccf7]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-49fe2730da9sm14251525e9.4.2026.09.23.02.11.35 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 23 Sep 2026 02:11:35 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][scarthgap 16/48] cpio: patch CVE-2026-66485 Date: Wed, 23 Sep 2026 11:10:18 +0200 Message-ID: <090d104c522f4d1c3b99ab29f8214a1e14c3e36e.1790154074.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Wed, 23 Sep 2026 09:11:45 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/246478 From: Peter Marko Pick patch mentioned in NVD CVE description. Signed-off-by: Peter Marko Signed-off-by: Richard Purdie (From OE-Core rev: c105fbf82e2f50b05dc680e0601bf0ea3198e58c) Signed-off-by: Peter Marko Signed-off-by: Yoann Congal --- meta/recipes-extended/cpio/cpio_2.15.bb | 1 + .../cpio/files/CVE-2026-66485.patch | 210 ++++++++++++++++++ 2 files changed, 211 insertions(+) create mode 100644 meta/recipes-extended/cpio/files/CVE-2026-66485.patch diff --git a/meta/recipes-extended/cpio/cpio_2.15.bb b/meta/recipes-extended/cpio/cpio_2.15.bb index a5c9b76da20..f4b562fdc2c 100644 --- a/meta/recipes-extended/cpio/cpio_2.15.bb +++ b/meta/recipes-extended/cpio/cpio_2.15.bb @@ -9,6 +9,7 @@ LIC_FILES_CHKSUM = "file://COPYING;md5=f27defe1e96c2e1ecd4e0c9be8967949" SRC_URI = "${GNU_MIRROR}/cpio/cpio-${PV}.tar.gz \ file://run-ptest \ file://test.sh \ + file://CVE-2026-66485.patch \ " SRC_URI[sha256sum] = "efa50ef983137eefc0a02fdb51509d624b5e3295c980aa127ceee4183455499e" diff --git a/meta/recipes-extended/cpio/files/CVE-2026-66485.patch b/meta/recipes-extended/cpio/files/CVE-2026-66485.patch new file mode 100644 index 00000000000..f9c0f48281f --- /dev/null +++ b/meta/recipes-extended/cpio/files/CVE-2026-66485.patch @@ -0,0 +1,210 @@ +From 3cd514031371d8aeeaf2048aa10103e02831aaa9 Mon Sep 17 00:00:00 2001 +From: Sergey Poznyakoff +Date: Fri, 1 May 2026 08:19:41 +0300 +Subject: [PATCH] Minor fixes + +* src/makepath.c: Don't use alloca. +* src/userspec.c: Likewise. + +CVE: CVE-2026-66485 +Upstream-Status: Backport [https://git.savannah.gnu.org/cgit/cpio.git/commit/?id=3cd514031371d8aeeaf2048aa10103e02831aaa9] +Signed-off-by: Peter Marko +--- + src/makepath.c | 31 ++++++++++++++--------- + src/userspec.c | 67 +++++++++++++++++++++++++------------------------- + 2 files changed, 53 insertions(+), 45 deletions(-) + +diff --git a/src/makepath.c b/src/makepath.c +index 35dbc73..c6329bf 100644 +--- a/src/makepath.c ++++ b/src/makepath.c +@@ -47,24 +47,19 @@ + Return 0 if ARGPATH exists as a directory with the proper + ownership and permissions when done, otherwise 1. */ + +-int +-make_path (char const *argpath, +- uid_t owner, +- gid_t group, +- const char *verbose_fmt_string) ++static int ++make_path0 (char *dirpath, ++ uid_t owner, ++ gid_t group, ++ const char *verbose_fmt_string) + { +- char *dirpath; /* A copy we can scribble NULs on. */ + struct stat stats; +- int retval = 0; + mode_t tmpmode; + mode_t invert_permissions; + int we_are_root = getuid () == 0; +- dirpath = alloca (strlen (argpath) + 1); +- +- strcpy (dirpath, argpath); + + if (stat (dirpath, &stats)) +- { ++ { + tmpmode = MODE_RWX & ~ newdir_umask; + invert_permissions = we_are_root ? 0 : MODE_WXUSR & ~ tmpmode; + +@@ -157,5 +152,19 @@ make_path (char const *argpath, + + } + ++ return 0; ++} ++ ++int ++make_path (char const *argpath, ++ uid_t owner, ++ gid_t group, ++ const char *verbose_fmt_string) ++{ ++ char *dirpath = xstrdup (argpath); ++ int retval = make_path0 (dirpath, owner, group, verbose_fmt_string); ++ free (dirpath); + return retval; + } ++ ++ +diff --git a/src/userspec.c b/src/userspec.c +index 2a2b324..1a2bfa0 100644 +--- a/src/userspec.c ++++ b/src/userspec.c +@@ -19,7 +19,6 @@ + /* Written by David MacKenzie . */ + + #include +-#include + #include + #include + #include +@@ -33,18 +32,6 @@ + # define endgrent() + #endif + +-/* Perform the equivalent of the statement `dest = strdup (src);', +- but obtaining storage via alloca instead of from the heap. */ +- +-#define V_STRDUP(dest, src) \ +- do \ +- { \ +- int _len = strlen ((src)); \ +- (dest) = (char *) alloca (_len + 1); \ +- strcpy (dest, src); \ +- } \ +- while (0) +- + /* Return nonzero if STR represents an unsigned decimal integer, + otherwise return 0. */ + +@@ -57,6 +44,18 @@ isnumber_p (const char *str) + return 1; + } + ++static void ++store_string (char **bufptr, size_t *buflen, char *str) ++{ ++ size_t len = strlen (str) + 1; ++ if (len > *buflen) ++ { ++ *bufptr = xrealloc (*bufptr, len); ++ *buflen = len; ++ } ++ strcpy (*bufptr, str); ++} ++ + /* Extract from NAME, which has the form "[user][:.][group]", + a USERNAME, UID U, GROUPNAME, and GID G. + Either user or group, or both, must be present. +@@ -70,23 +69,21 @@ isnumber_p (const char *str) + Return NULL if successful, a static error message string if not. */ + + const char * +-parse_user_spec (const char *spec_arg, uid_t *uid, gid_t *gid, +- char **username_arg, char **groupname_arg) ++parse_user_spec0 (char *spec, uid_t *uid, gid_t *gid, ++ char **username_arg, char **groupname_arg) + { + static const char *tired = "virtual memory exhausted"; + const char *error_msg; +- char *spec; /* A copy we can write on. */ + struct passwd *pwd; + struct group *grp; + char *g, *u, *separator; +- char *groupname; ++ char *groupname = NULL; ++ size_t grouplen = 0; + + error_msg = NULL; + *username_arg = *groupname_arg = NULL; + groupname = NULL; + +- V_STRDUP (spec, spec_arg); +- + /* Find the separator if there is one. */ + separator = strchr (spec, ':'); + if (separator == NULL) +@@ -143,11 +140,12 @@ parse_user_spec (const char *spec_arg, uid_t *uid, gid_t *gid, + if (grp == NULL) + { + char nbuf[UINTMAX_STRSIZE_BOUND]; +- V_STRDUP (groupname, umaxtostr (pwd->pw_gid, nbuf)); ++ store_string (&groupname, &grouplen, ++ umaxtostr (pwd->pw_gid, nbuf)); + } + else + { +- V_STRDUP (groupname, grp->gr_name); ++ store_string (&groupname, &grouplen, grp->gr_name); + } + endgrent (); + } +@@ -178,7 +176,7 @@ parse_user_spec (const char *spec_arg, uid_t *uid, gid_t *gid, + endgrent (); /* Save a file descriptor. */ + + if (error_msg == NULL) +- V_STRDUP (groupname, g); ++ store_string (&groupname, &grouplen, g); + } + + if (error_msg == NULL) +@@ -191,23 +189,24 @@ parse_user_spec (const char *spec_arg, uid_t *uid, gid_t *gid, + } + + if (groupname != NULL && error_msg == NULL) +- { +- *groupname_arg = strdup (groupname); +- if (*groupname_arg == NULL) +- { +- if (*username_arg != NULL) +- { +- free (*username_arg); +- *username_arg = NULL; +- } +- error_msg = tired; +- } +- } ++ *groupname_arg = groupname; + } ++ else ++ free (groupname); + + return error_msg; + } + ++const char * ++parse_user_spec (const char *spec_arg, uid_t *uid, gid_t *gid, ++ char **username, char **groupname) ++{ ++ char *spec = xstrdup (spec_arg); ++ const char *retval = parse_user_spec0 (spec, uid, gid, username, groupname); ++ free (spec); ++ return retval; ++} ++ + #ifdef TEST + + #define NULL_CHECK(s) ((s) == NULL ? "(null)" : (s)) From patchwork Wed Sep 23 09:10:19 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 98974 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 76B87C982EA for ; Wed, 23 Sep 2026 09:11:44 +0000 (UTC) Received: from mail-wm2-f12.google.com (mail-wm2-f12.google.com [74.125.225.140]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.2822.1790154698527964404 for ; Wed, 23 Sep 2026 02:11:38 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=bf2DZgwY; spf=pass (domain: smile.fr, ip: 74.125.225.140, mailfrom: yoann.congal@smile.fr) Received: by mail-wm2-f12.google.com with SMTP id 5b1f17b1804b1-49b912df756so4670255e9.3 for ; Wed, 23 Sep 2026 02:11:38 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1790154697; x=1790759497; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=EPcrx/GoqK6sNW8ul6E4tcDcXoMSSYL5Ib87SqCDo0Y=; b=bf2DZgwYCs0owHA8qMSvy4cdrqJNurG5FipWVY7i19S3RUdU2AiPpusgSHnHdnv2UX gfNws+LgvSH+dZM+BPV9j3jlwEBtfagfxnoxaOkfZJMw/DtDoRqKYDqPIRFtNsBN+XdZ 7pdiQTih034u4ZyrUPRtT5UKNBGCL9h7R2mi0= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1790154697; x=1790759497; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=EPcrx/GoqK6sNW8ul6E4tcDcXoMSSYL5Ib87SqCDo0Y=; b=dBU2DWaN79fEFRp4X3bcQabLFTynujK2U3YJ6RB5mXH6q4O6t1Lhp80m+18FPTq4sq eUG3vzlq/PgD9twaU4/QiXkrRRpWoyfNB7KkGnfpnBfLkaALI4/8VVJOVeu0ewblHCMt XMrwFq4sJwlc+8s5hG9sWhyCLX4I1iBw2LFk+5hL0+46td+eLleNl4ZvRMYIJmMVYuBr SSnMXyE51eWFLzWEAa/BJiGWveOryqs3wBwlQsYVufjhl+A9EfnrqjGcdqxRsMbO7jJH oyq+x7aVh/UR38ux097vNMxKPWN4sgXiRd/n5p2UMXGrZapOAdyLgzadz/nJHhMA6Qqk wNSQ== X-Gm-Message-State: AFuF++ny9ZElxijrwQBwdCHr138Xc4Se4nRMDTtN2Or9E3Q64aEwAZG5 y3o2+fGAALvJDi1p+PJtfgs0juvLWDyuWwW8X9lZO20IvewhtszTOgJBASeCJTMA8j1msP9gSXR WDEPt1Ws= X-Gm-Gg: AYBFou1PqnUJRsWNA9t/UNJpf9PJ0pF8wAT3toALUzQzrdzxzbZJMKN5NLlVGGgTVv/ KZ4Jg4tmLBXLHvUngkxc+V0T7OJ2WRkFlCPehcbMKJCqy3s+4PhSnDJCAg5JcvKkoRufMEyMG8m KK0RbErX+VNe/M3LBRnbERO4YCXinHq6yYJf/NPboKN8C2rx1US0r1Hn8UtVY/kXzwqGvrwfBTr iuGwy8tgq4LC9CPsSphbKAOKDeURbt320daAQLJiXtUbpwrI81/di/doPQMJVVLwb26JA/P5C6g zH5Iur/YmVMu17q4a2qeN2lA0SC8NmtbbfEpa2fqGtMkBlZIHiMmyS+opj4eFfRqvzGtokBI9Pl uY27HP26QjsJJfIXNhltsgMOfyjZtGIb5+Udqsnlgi68GM09I/2s0QQ+odGcaBl2mnk1jfzNbSs otUbX16kk3IKFuMNAzS+ItRDm1iltlJpK08f3SI9Q7acgMRck2DCLlWWWbYx+kdrrKch4/c5Qru U1l9gC7dit8htg1BurA/yOPvY0gvH6TAGg69gU2s/bcl9GfJBu7dukAqozXb5BL1gJYKZRn X-Received: by 2002:a05:600c:3b98:b0:49d:462:6eda with SMTP id 5b1f17b1804b1-49fdf139f27mr26866615e9.28.1790154696764; Wed, 23 Sep 2026 02:11:36 -0700 (PDT) Received: from FRSMI25-LASER.home (2a02-8440-b519-f416-8bed-8817-19fd-ccf7.rev.sfr.net. [2a02:8440:b519:f416:8bed:8817:19fd:ccf7]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-49fe2730da9sm14251525e9.4.2026.09.23.02.11.36 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 23 Sep 2026 02:11:36 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][scarthgap 17/48] cpio: patch CVE-2026-66484 Date: Wed, 23 Sep 2026 11:10:19 +0200 Message-ID: X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Wed, 23 Sep 2026 09:11:44 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/246479 From: Peter Marko Pick patch mentioned in NVD CVE description. Signed-off-by: Peter Marko Signed-off-by: Richard Purdie (From OE-Core rev: a49025d54fe7723df999710e7a385aaeb42303a2) Signed-off-by: Peter Marko Signed-off-by: Yoann Congal [YC: fixed the CVE: tag] Signed-off-by: Yoann Congal --- meta/recipes-extended/cpio/cpio_2.15.bb | 1 + .../cpio/files/CVE-2026-66484.patch | 28 +++++++++++++++++++ 2 files changed, 29 insertions(+) create mode 100644 meta/recipes-extended/cpio/files/CVE-2026-66484.patch diff --git a/meta/recipes-extended/cpio/cpio_2.15.bb b/meta/recipes-extended/cpio/cpio_2.15.bb index f4b562fdc2c..62dcd444d5e 100644 --- a/meta/recipes-extended/cpio/cpio_2.15.bb +++ b/meta/recipes-extended/cpio/cpio_2.15.bb @@ -10,6 +10,7 @@ SRC_URI = "${GNU_MIRROR}/cpio/cpio-${PV}.tar.gz \ file://run-ptest \ file://test.sh \ file://CVE-2026-66485.patch \ + file://CVE-2026-66484.patch \ " SRC_URI[sha256sum] = "efa50ef983137eefc0a02fdb51509d624b5e3295c980aa127ceee4183455499e" diff --git a/meta/recipes-extended/cpio/files/CVE-2026-66484.patch b/meta/recipes-extended/cpio/files/CVE-2026-66484.patch new file mode 100644 index 00000000000..538f80daf9b --- /dev/null +++ b/meta/recipes-extended/cpio/files/CVE-2026-66484.patch @@ -0,0 +1,28 @@ +From e2b9cbdd3354d2b1569b7390d1bc15c1930559ad Mon Sep 17 00:00:00 2001 +From: Sergey Poznyakoff +Date: Thu, 23 Jul 2026 15:55:46 +0300 +Subject: [PATCH] The --no-absolute-filenames option affects hard link targets + too. + +* src/tar.c (stash_tar_linkname): Apply cpio_safer_name_suffix. + +CVE: CVE-2026-66484 +Upstream-Status: Backport [https://git.savannah.gnu.org/cgit/cpio.git/commit/?id=e2b9cbdd3354d2b1569b7390d1bc15c1930559ad] +Signed-off-by: Peter Marko +--- + src/tar.c | 2 ++ + 1 file changed, 2 insertions(+) + +diff --git a/src/tar.c b/src/tar.c +index 493f299..a1fc60a 100644 +--- a/src/tar.c ++++ b/src/tar.c +@@ -37,6 +37,8 @@ stash_tar_linkname (char *linkname) + + strncpy (hold_tar_linkname, linkname, TARLINKNAMESIZE); + hold_tar_linkname[TARLINKNAMESIZE] = '\0'; ++ cpio_safer_name_suffix (hold_tar_linkname, true, !no_abs_paths_flag, ++ false); + return hold_tar_linkname; + } + From patchwork Wed Sep 23 09:10:20 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 98975 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 9BB05C982FA for ; Wed, 23 Sep 2026 09:11:44 +0000 (UTC) Received: from mail-wm2-f12.google.com (mail-wm2-f12.google.com [74.125.225.140]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.2823.1790154699684732864 for ; Wed, 23 Sep 2026 02:11:40 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=JSo6oVlV; spf=pass (domain: smile.fr, ip: 74.125.225.140, mailfrom: yoann.congal@smile.fr) Received: by mail-wm2-f12.google.com with SMTP id 5b1f17b1804b1-49cd38e0e5dso8676615e9.2 for ; Wed, 23 Sep 2026 02:11:39 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1790154698; x=1790759498; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=tNvNV43hsG539j6oZEnTLX+KVcPCkVJmgxVQb+hpJ2w=; b=JSo6oVlVcEJU5FS82V26ZTHxe3MMUDHr2M3YQIderDxj7Xwr10MyY5oFNI1UtelyMy 0e6FDfp/dxmNNpLNActIkKWIyk52Qz0bIQSUkhB/ulm8BpKqi1/QXF4ZFyYcT5pUu9a9 GXaRzT0pD26niTJpRMyiLVlm8rtu7DFnaTSoo= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1790154698; x=1790759498; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=tNvNV43hsG539j6oZEnTLX+KVcPCkVJmgxVQb+hpJ2w=; b=iEAV8G9Vw3uRUc2q9zwR5ZypSIIp2JYfKrUPDWeQZXvJ1noBpjFmYoOcbPN2bd4UjG YfjyQhHdNKlNBtPrgUpOTTYNYXVK8ofMDANNbaggrlKENrVkWS04GUl5E0ffg7BVBuOK w+DIMtDjU/yrbAVi1LZnXVIEQLSa5BGM1IOAkZ8woWnhRt5sj+AAzw03LO9QufIVcvFY 5N04Qg69Kx50CtRGDOuJQUC+pgFPnypDKZLqWZMDUL0vQRSV+96tVxgJMSMWAI7D4GzN FM+BBBF0MEZ0ThZC7nSMoQPYGVeWyj8ku/ZyKLMzyMGISw9Nfpc0e2KhMC1FcXVIwyr5 X9YA== X-Gm-Message-State: AFuF++l3O8epiVzy6UyUzpsSKyMLPzOWkpFd1IQ5hWB1t2Nq2eJOzL/H Ay2lkeDps/UcQfEw9Y/PTSTj/ig4LFe2NpXkTDYHpLaeE8B1KqZb8DVF3//xHMQA6FwKRsCHC4g rdn9RJbw= X-Gm-Gg: AYBFou0LtmppG8FcO7yQ3ZLzU6O+0Nka4nuaCyIf9sIVHaMRz0fnYc0JkQzb3v8XxeK 7RaLPMOXb2IdCnkhqXxnYZa7Ys7PqgZ12+qkdSHiJYlPS6jEbk0o4YWzyhw1aGoJxzFH+3u73/O zV4fKDEfrdRtaSoB7D0AA9vBgPe+MSosU6YJEPPwmnVZwpUZoNphJMYzustNZTVq3SL2UkHRrZd Z8wBoGjS1tva7e5q2dItOAveEDiPhY+iHxkGuZ13q1sxDXW+A+Qoi1io9lkZg/bP5i7VxUpPTXb e4ji5qogzkloBGHMwvCjIDtzXFUJpfjD9gFLAio8xDTKwuJJsmzYenOuicJu6706wVSwKhBZRRx /+pqEIUJC5o1hRtZEyG0EUXM/BRV43bEfEEo/MFGeDaT3v3MNgfvikN1zleM/Df+RnYtMwBdOab D1ey6jtqxKKe2SQUoDfqVWMv47D2h8kRWQ3LZmQqOAYes1coYv9b6JZtIS9YM9GMvif2BtL75xZ 9a+SAHcJ663Bkg4+tiPgSs8IctsJ/O9pT2c4/gFRhcIZC6jh/qDPVV+KZWWIJD3Pm8VJUT8 X-Received: by 2002:a05:600c:19d2:b0:49c:cee0:e7c1 with SMTP id 5b1f17b1804b1-49fdf1370bcmr24496285e9.16.1790154697889; Wed, 23 Sep 2026 02:11:37 -0700 (PDT) Received: from FRSMI25-LASER.home (2a02-8440-b519-f416-8bed-8817-19fd-ccf7.rev.sfr.net. [2a02:8440:b519:f416:8bed:8817:19fd:ccf7]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-49fe2730da9sm14251525e9.4.2026.09.23.02.11.36 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 23 Sep 2026 02:11:37 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][scarthgap 18/48] wget: Fix CVE-2026-58470 Date: Wed, 23 Sep 2026 11:10:20 +0200 Message-ID: X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Wed, 23 Sep 2026 09:11:44 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/246480 From: Hetvi Thakar This patch applies the upstream fix as referenced in [2], using the commit shown in [1]. It also includes the upstream regression patch from commit shown in [3] which changes all three Content-Range conversions to strtoll(). [1] https://gitlab.com/gnuwget/wget/-/commit/43d3ba9336bc94937e6fae2365c6ffd30c34ffcf [2] https://nvd.nist.gov/vuln/detail/CVE-2026-58470 [3] https://gitlab.com/gnuwget/wget/-/commit/01ff771caac1958662ca8665eed2021ec386a7af Signed-off-by: Hetvi Thakar Signed-off-by: Yoann Congal --- .../wget/wget/CVE-2026-58470-regression.patch | 48 +++++++++++ .../wget/wget/CVE-2026-58470.patch | 79 +++++++++++++++++++ meta/recipes-extended/wget/wget_1.21.4.bb | 2 + 3 files changed, 129 insertions(+) create mode 100644 meta/recipes-extended/wget/wget/CVE-2026-58470-regression.patch create mode 100644 meta/recipes-extended/wget/wget/CVE-2026-58470.patch diff --git a/meta/recipes-extended/wget/wget/CVE-2026-58470-regression.patch b/meta/recipes-extended/wget/wget/CVE-2026-58470-regression.patch new file mode 100644 index 00000000000..c452261a9ac --- /dev/null +++ b/meta/recipes-extended/wget/wget/CVE-2026-58470-regression.patch @@ -0,0 +1,48 @@ +From 01ff771caac1958662ca8665eed2021ec386a7af Mon Sep 17 00:00:00 2001 +From: =?UTF-8?q?Tim=20R=C3=BChsen?= +Date: Wed, 12 Aug 2026 19:45:21 +0200 +Subject: [PATCH] * src/http.c (parse_content_range): Use strtoll instead of + strtol. + +CVE: CVE-2026-58470 +Upstream-Status: Backport [https://gitlab.com/gnuwget/wget/-/commit/01ff771caac1958662ca8665eed2021ec386a7af] + +(cherry picked from commit 01ff771caac1958662ca8665eed2021ec386a7af) +Signed-off-by: Hetvi Thakar +--- + src/http.c | 6 +++--- + 1 file changed, 3 insertions(+), 3 deletions(-) + +diff --git a/src/http.c b/src/http.c +index e5e75ee695..8170a43c27 100644 +--- a/src/http.c ++++ b/src/http.c +@@ -949,7 +949,7 @@ parse_content_range (const char *hdr, wgint *first_byte_ptr, + return false; + + errno = 0; +- num = strtol(hdr, &end, 10); ++ num = strtoll(hdr, &end, 10); + if (errno == ERANGE) + return false; + hdr = end; +@@ -959,7 +959,7 @@ parse_content_range (const char *hdr, wgint *first_byte_ptr, + *first_byte_ptr = num; + + errno = 0; +- num = strtol(hdr, &end, 10); ++ num = strtoll(hdr, &end, 10); + if (errno == ERANGE) + return false; + hdr = end; +@@ -976,7 +976,7 @@ parse_content_range (const char *hdr, wgint *first_byte_ptr, + else + { + errno = 0; +- num = strtol(hdr, NULL, 10); ++ num = strtoll(hdr, NULL, 10); + if (errno == ERANGE) + return false; + } +-- +2.35.6 diff --git a/meta/recipes-extended/wget/wget/CVE-2026-58470.patch b/meta/recipes-extended/wget/wget/CVE-2026-58470.patch new file mode 100644 index 00000000000..7ee4e87344e --- /dev/null +++ b/meta/recipes-extended/wget/wget/CVE-2026-58470.patch @@ -0,0 +1,79 @@ +From bfbab29e0a94160b283a8101e122d07684104955 Mon Sep 17 00:00:00 2001 +From: =?UTF-8?q?Tim=20R=C3=BChsen?= +Date: Mon, 29 Jun 2026 18:57:54 +0200 +Subject: [PATCH] * src/http.c (parse_content_range): Fix integer overflow + +Reported-by: TristanInSec@gmail.com + +CVE: CVE-2026-58470 +Upstream-Status: Backport [https://gitlab.com/gnuwget/wget/-/commit/43d3ba9336bc94937e6fae2365c6ffd30c34ffcf] + +(cherry picked from commit 43d3ba9336bc94937e6fae2365c6ffd30c34ffcf) +Signed-off-by: Hetvi Thakar +--- + src/http.c | 35 ++++++++++++++++++++++++----------- + 1 file changed, 24 insertions(+), 11 deletions(-) + +diff --git a/src/http.c b/src/http.c +index 116a93a3..4dc6b70f 100644 +--- a/src/http.c ++++ b/src/http.c +@@ -914,6 +914,7 @@ parse_content_range (const char *hdr, wgint *first_byte_ptr, + wgint *last_byte_ptr, wgint *entity_length_ptr) + { + wgint num; ++ char *end; + + /* Ancient versions of Netscape proxy server, presumably predating + rfc2068, sent out `Content-Range' without the "bytes" +@@ -932,27 +933,39 @@ parse_content_range (const char *hdr, wgint *first_byte_ptr, + } + if (!c_isdigit (*hdr)) + return false; +- for (num = 0; c_isdigit (*hdr); hdr++) +- num = 10 * num + (*hdr - '0'); +- if (*hdr != '-' || !c_isdigit (*(hdr + 1))) ++ ++ errno = 0; ++ num = strtol(hdr, &end, 10); ++ if (errno == ERANGE) ++ return false; ++ hdr = end; ++ ++ if (*hdr++ != '-' || !c_isdigit (*hdr)) + return false; + *first_byte_ptr = num; +- ++hdr; +- for (num = 0; c_isdigit (*hdr); hdr++) +- num = 10 * num + (*hdr - '0'); +- if (*hdr != '/') ++ ++ errno = 0; ++ num = strtol(hdr, &end, 10); ++ if (errno == ERANGE) ++ return false; ++ hdr = end; ++ ++ if (*hdr++ != '/') + return false; + *last_byte_ptr = num; +- if (!(c_isdigit (*(hdr + 1)) || *(hdr + 1) == '*')) ++ if (!(c_isdigit (*hdr) || *hdr == '*')) + return false; + if (*last_byte_ptr < *first_byte_ptr) + return false; +- ++hdr; + if (*hdr == '*') + num = -1; + else +- for (num = 0; c_isdigit (*hdr); hdr++) +- num = 10 * num + (*hdr - '0'); ++ { ++ errno = 0; ++ num = strtol(hdr, NULL, 10); ++ if (errno == ERANGE) ++ return false; ++ } + *entity_length_ptr = num; + if ((*entity_length_ptr <= *last_byte_ptr) && *entity_length_ptr != -1) + return false; diff --git a/meta/recipes-extended/wget/wget_1.21.4.bb b/meta/recipes-extended/wget/wget_1.21.4.bb index 8ae0bcf1f05..6ae0fc75b17 100644 --- a/meta/recipes-extended/wget/wget_1.21.4.bb +++ b/meta/recipes-extended/wget/wget_1.21.4.bb @@ -8,6 +8,8 @@ SRC_URI = "${GNU_MIRROR}/wget/wget-${PV}.tar.gz \ file://CVE-2026-58471.patch \ file://CVE-2026-58472.patch \ file://CVE-2026-58472-regression.patch \ + file://CVE-2026-58470.patch \ + file://CVE-2026-58470-regression.patch \ " SRC_URI[sha256sum] = "81542f5cefb8faacc39bbbc6c82ded80e3e4a88505ae72ea51df27525bcde04c" From patchwork Wed Sep 23 09:10:21 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 98979 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id B4053C98307 for ; Wed, 23 Sep 2026 09:11:44 +0000 (UTC) Received: from mail-wr2-f12.google.com (mail-wr2-f12.google.com [74.125.225.76]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.2920.1790154700984996218 for ; Wed, 23 Sep 2026 02:11:41 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=BVfej4Xm; spf=pass (domain: smile.fr, ip: 74.125.225.76, mailfrom: yoann.congal@smile.fr) Received: by mail-wr2-f12.google.com with SMTP id ffacd0b85a97d-485933b24c3so493610f8f.0 for ; Wed, 23 Sep 2026 02:11:40 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1790154699; x=1790759499; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=7nLB7QdJ23Lxe1oIga8kwFF+1Iw6bJAx/zANuuaE0Ac=; b=BVfej4XmC3DzEAw2SpZfyVitpW0QBbPOYoVD9Zc2iXfCJc1wO2qAS5j+W7jQtQDPb8 cqiQsJmWZTVU4QdFO/7BEwSqHRXHRFHar3+eaCegDi5LIFLIVJ77FTS7Z28wN4Z6GGKK CMg5cIeVMDzeZjhNx4dkHXuyyYdW9nnOPp8yc= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1790154699; x=1790759499; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=7nLB7QdJ23Lxe1oIga8kwFF+1Iw6bJAx/zANuuaE0Ac=; b=SxA9iZHgKCH3Xg7FOb6aX4GpIYD6rwBytb0u5YSlE9VKaqTw1LM4m/pKzAHWfx+aac 5tC8pcv5yupGThE1sAyrPiLBilWweQJKrw64oc3MnbA8E3smOFjVBGtKO+fGyyKgtgmh za7Xy1EULz2UGLz/nQl2ir9SYVLm5vzQEZnxNEwMQYHEQvOrPeafU5Yi4Ph0GUvDBq7D jnIOQS9An2uGBmzTch66pCTCYyCIgPrn+82WPA1NUdPkUbRPqsIpK9kGLYrbIhwSMk02 C2LY4mVPd3cedV15DHTqlIkk9D5XhHE4GVVl3aJLLphIUvlVcgR6Fxg6UZ7tfJhy0fjB 5odA== X-Gm-Message-State: AFuF++nTigihkrjaaRD3GQMU7BvsLKPStqlnhAklm4g2GHMNrhTQIG8h iut4HH0wb+5Vu59DLIpLW7x4lJ0zeVw4rFjaZBHoIuu29ngtsUM1b4fQkuDU5RoUQwWTCti8IWr BLh2HRQE= X-Gm-Gg: AYBFou0Jcmw16Wd1MGbSTJa7AZ6RdykvPp97JN20jzqyGQnbZjQ2o5IbTAW79qpqvrD 4+6BxtFB8Gfw1LsXBfcZNdABfMY9hVz+RAo4aTlRheaemgq+63kJFTpZ4PgMLleFqVxFMVlAcUT G9fJ/kmLdgz2rVcex6HDEHoE0MvnGQjcvfIvamnBVQWN0II956Ak4/LfkQIvviTfeE3xiWp7nSC /mcChnxcw9lPvi5mj+bkpaEJ2I2kEnIbedCxEmctIM18GQYHTBpdfVg9goxSQou4ihZ1RllQOut QkVP05r+zIODK5J6n6cTBlOlFMKwG2m7PZumVPNK5uuwowhj7GaXohzktOzVJ/QTgu4eQS+uPL/ g5Ds4qNbj3Dl1NsFtg+zisDsF5A7xKdxRU7R2uN7wUWCcDoXhO1tg/ZgSzHwOdXi5kM2zjRBb2S zB5+LVOSk2vuv7dyi4PBGGmr08DLfUAi4kqu9nljfiVibgbtHsVWM5T3hRhsBtblvYmT97qU1FR y3sMNFOhUXQm+Axwpmo9qtyjsYfcraxpVDTu7GxSpGd1e1H5XT8FNAQQGuG9LEbKbdpakkJXcgC lIW+1CTlVH6iM09ROw== X-Received: by 2002:a05:600c:a06:b0:49f:cbf1:e765 with SMTP id 5b1f17b1804b1-49fdec980bamr28645805e9.0.1790154699193; Wed, 23 Sep 2026 02:11:39 -0700 (PDT) Received: from FRSMI25-LASER.home (2a02-8440-b519-f416-8bed-8817-19fd-ccf7.rev.sfr.net. [2a02:8440:b519:f416:8bed:8817:19fd:ccf7]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-49fe2730da9sm14251525e9.4.2026.09.23.02.11.38 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 23 Sep 2026 02:11:38 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][scarthgap 19/48] gnutls: fix CVE-2026-5419 Date: Wed, 23 Sep 2026 11:10:21 +0200 Message-ID: <40a2e6160bd450599ca6ebc5fb308d38e5e7a888.1790154074.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Wed, 23 Sep 2026 09:11:44 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/246481 From: Jakub Szczudlo (Nokia) Backport patch to fix CVE-2026-5419. References: https://nvd.nist.gov/vuln/detail/CVE-2026-5419 Upstream fix: https://gitlab.com/gnutls/gnutls/-/commit/1e627aa5ad95c6dc0518d94e9a009997b081a1ab Tested with ptest Signed-off-by: Jakub Szczudlo Signed-off-by: Yoann Congal --- .../gnutls/gnutls/CVE-2026-5419.patch | 247 ++++++++++++++++++ meta/recipes-support/gnutls/gnutls_3.8.4.bb | 1 + 2 files changed, 248 insertions(+) create mode 100644 meta/recipes-support/gnutls/gnutls/CVE-2026-5419.patch diff --git a/meta/recipes-support/gnutls/gnutls/CVE-2026-5419.patch b/meta/recipes-support/gnutls/gnutls/CVE-2026-5419.patch new file mode 100644 index 00000000000..7a7f4469dd8 --- /dev/null +++ b/meta/recipes-support/gnutls/gnutls/CVE-2026-5419.patch @@ -0,0 +1,247 @@ +From 0ff1cf201404afc6b227f9ddfea376866770a9d3 Mon Sep 17 00:00:00 2001 +From: Daiki Ueno +Date: Fri, 4 Sep 2026 09:16:30 +0000 +Subject: [PATCH] gnutls_cipher_decrypt3: make PKCS#7 unpadding branch free + +This tries to make the logic of PKCS#7 padding removal constant-time, +by removing potential branching operations. + +CVE: CVE-2026-5419 +Upstream-Status: Backport [https://gitlab.com/gnutls/gnutls/-/commit/1e627aa5ad95c6dc0518d94e9a009997b081a1ab] + +Backport Changes: +- Adjusted the upstream hunk to match the GnuTLS 3.8.4 code layout. +- Drop .gitignore from the backport. + +Reported-by: Doria Tang of Stony Brook University +Fixes: #1815 +Fixes: CVE-2026-5419 +Fixes: GNUTLS-SA-2026-04-29-13 +CVSS: 3.7 Low CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N +Signed-off-by: Daiki Ueno +Signed-off-by: Jakub Szczudlo + +--- + lib/crypto-api.c | 53 ++++++++++++++++------ + lib/libgnutls.map | 2 + + tests/Makefile.am | 2 +- + tests/pkcs7-pad.c | 109 ++++++++++++++++++++++++++++++++++++++++++++++ + 4 files changed, 152 insertions(+), 14 deletions(-) + create mode 100644 tests/pkcs7-pad.c + +diff --git a/lib/crypto-api.c b/lib/crypto-api.c +index bb5c3ec..7ae0ef2 100644 +--- a/lib/crypto-api.c ++++ b/lib/crypto-api.c +@@ -497,6 +497,38 @@ error: + } + return ret; + } ++/* If succeeds, returns the number of padding bytes to be removed; ++ * zero otherwise. ++ */ ++unsigned int _gnutls_pkcs7_unpad(const uint8_t *block, unsigned int block_size) ++{ ++ uint8_t padding = block[block_size - 1]; ++ volatile unsigned int mask = ~0; ++ volatile unsigned int count = 0; ++ ++ /* Count consecutive PADDING bytes from the end, in a ++ * constant-time manner. ++ */ ++ for (size_t i = block_size; i > 0; i--) { ++ volatile unsigned int mask2; ++ ++ mask2 = -(unsigned int)(block[i - 1] == padding); ++ mask2 &= -(unsigned int)(count < padding); ++ ++ /* MASK is initially ~0 and will be flipped to 0 upon first ++ * non-padding bytes. ++ */ ++ mask &= mask2; ++ count += 1 & mask; ++ } ++ ++ /* PADDING == 0 is effectively excluded here, given COUNT ++ * will never be 0. ++ */ ++ mask = -(unsigned int)(count <= block_size); ++ mask &= -(unsigned int)(count == padding); ++ return count & mask; ++} + + /** + * gnutls_cipher_decrypt3: +@@ -532,22 +564,17 @@ int gnutls_cipher_decrypt3(gnutls_cipher_hd_t handle, const void *ctext, + if (_gnutls_cipher_type(h->ctx_enc.e) == CIPHER_BLOCK && + (flags & GNUTLS_CIPHER_PADDING_PKCS7)) { + uint8_t *p = ptext; +- uint8_t padding = p[*ptext_len - 1]; +- if (!padding || +- padding > _gnutls_cipher_get_block_size(h->ctx_enc.e)) { +- return gnutls_assert_val(GNUTLS_E_DECRYPTION_FAILED); +- } +- /* Check that the prior bytes are all PADDING */ +- for (size_t i = *ptext_len - padding; i < *ptext_len; i++) { +- if (padding != p[*ptext_len - 1]) { +- return gnutls_assert_val( +- GNUTLS_E_DECRYPTION_FAILED); +- } +- } ++ size_t block_size = _gnutls_cipher_get_block_size(h->ctx_enc.e); ++ uint8_t *block = &p[*ptext_len - block_size]; ++ unsigned int padding = _gnutls_pkcs7_unpad(block, block_size); ++ volatile unsigned int mask; ++ ++ mask = -(unsigned int)(padding == 0); ++ ret = GNUTLS_E_DECRYPTION_FAILED & mask; + *ptext_len -= padding; + } + +- return 0; ++ return ret; + } + + /** +diff --git a/lib/libgnutls.map b/lib/libgnutls.map +index b02babf..f269ff2 100644 +--- a/lib/libgnutls.map ++++ b/lib/libgnutls.map +@@ -1551,4 +1551,6 @@ GNUTLS_PRIVATE_3_4 { + _gnutls_pathbuf_append; + _gnutls_pathbuf_truncate; + _gnutls_pathbuf_deinit; ++ # needed by tests/pkcs7-pad ++ _gnutls_pkcs7_unpad; + } GNUTLS_3_4; +diff --git a/tests/Makefile.am b/tests/Makefile.am +index f227e92..32c5335 100644 +--- a/tests/Makefile.am ++++ b/tests/Makefile.am +@@ -238,7 +238,7 @@ ctests += mini-record-2 simple gnutls_hmac_fast set_pkcs12_cred cert certuniquei + x509cert-dntypes id-on-xmppAddr tls13-compat-mode ciphersuite-name \ + x509-upnconstraint xts-key-check cipher-padding pkcs7-verify-double-free \ + fips-rsa-sizes tls12-rehandshake-ticket pathbuf tls-force-ems \ +- psk-importer privkey-derive dh-compute2 ecdh-compute2 ++ psk-importer privkey-derive dh-compute2 ecdh-compute2 pkcs7-pad + + ctests += tls-channel-binding + +diff --git a/tests/pkcs7-pad.c b/tests/pkcs7-pad.c +new file mode 100644 +index 0000000..d4c3798 +--- /dev/null ++++ b/tests/pkcs7-pad.c +@@ -0,0 +1,109 @@ ++/* ++ * Copyright (C) 2026 Red Hat, Inc. ++ * ++ * This file is part of GnuTLS. ++ * ++ * GnuTLS is free software; you can redistribute it and/or modify it ++ * under the terms of the GNU General Public License as published by ++ * the Free Software Foundation; either version 3 of the License, or ++ * (at your option) any later version. ++ * ++ * GnuTLS is distributed in the hope that it will be useful, but ++ * WITHOUT ANY WARRANTY; without even the implied warranty of ++ * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU ++ * General Public License for more details. ++ * ++ * You should have received a copy of the GNU General Public License ++ * along with GnuTLS. If not, see . ++ */ ++ ++/* Test that _gnutls_pkcs7_unpad is branch-free, using valgrind */ ++ ++#ifdef HAVE_CONFIG_H ++#include "config.h" ++#endif ++ ++#include ++#include ++ ++#ifdef HAVE_VALGRIND_MEMCHECK_H ++#include ++#endif ++ ++#include "utils.h" ++ ++static inline void _gnutls_memory_mark_undefined(void *addr, size_t size) ++{ ++#ifdef HAVE_VALGRIND_MEMCHECK_H ++ if (RUNNING_ON_VALGRIND) ++ VALGRIND_MAKE_MEM_UNDEFINED(addr, size); ++#endif ++} ++ ++static inline void _gnutls_memory_mark_defined(void *addr, size_t size) ++{ ++#ifdef HAVE_VALGRIND_MEMCHECK_H ++ if (RUNNING_ON_VALGRIND) ++ VALGRIND_MAKE_MEM_DEFINED(addr, size); ++#endif ++} ++ ++extern unsigned int _gnutls_pkcs7_unpad(const uint8_t *block, ++ unsigned int block_size); ++ ++static unsigned int wrap_pkcs7_unpad(uint8_t *block, unsigned int block_size) ++{ ++ unsigned int padding; ++ ++ _gnutls_memory_mark_undefined(block, block_size); ++ ++ padding = _gnutls_pkcs7_unpad(block, block_size); ++ ++ _gnutls_memory_mark_defined(block, block_size); ++ _gnutls_memory_mark_defined(&padding, sizeof(padding)); ++ ++ return padding; ++} ++ ++#define PAD 5 ++ ++void doit(void) ++{ ++ uint8_t block[16]; ++ unsigned int padding; ++ ++ memset(block, 0xFF, sizeof(block)); ++ memset(&block[sizeof(block) - PAD], PAD, PAD); ++ ++ padding = wrap_pkcs7_unpad(block, sizeof(block)); ++ if (padding != PAD) ++ fail("padding should be %d\n", PAD); ++ ++ /* The last padding byte exceeds the block size */ ++ block[sizeof(block) - 1] = sizeof(block) + 1; ++ padding = wrap_pkcs7_unpad(block, sizeof(block)); ++ if (padding != 0) ++ fail("padding should be 0\n"); ++ block[sizeof(block) - 1] = PAD; ++ ++ /* The last padding byte is zero */ ++ block[sizeof(block) - 1] = 0; ++ padding = wrap_pkcs7_unpad(block, sizeof(block)); ++ if (padding != 0) ++ fail("padding should be 0\n"); ++ block[sizeof(block) - 1] = PAD; ++ ++ /* The first padding byte is invalid */ ++ block[sizeof(block) - PAD] = PAD + 1; ++ padding = wrap_pkcs7_unpad(block, sizeof(block)); ++ if (padding != 0) ++ fail("padding should be 0\n"); ++ block[sizeof(block) - PAD] = PAD; ++ ++ /* The byte before the first padding equals to PAD */ ++ block[sizeof(block) - PAD - 1] = PAD; ++ padding = wrap_pkcs7_unpad(block, sizeof(block)); ++ if (padding != PAD) ++ fail("padding should be %d\n", PAD); ++ block[sizeof(block) - PAD - 1] = 0xFF; ++} +-- +2.43.0 + diff --git a/meta/recipes-support/gnutls/gnutls_3.8.4.bb b/meta/recipes-support/gnutls/gnutls_3.8.4.bb index 6dbd11abaff..641289be134 100644 --- a/meta/recipes-support/gnutls/gnutls_3.8.4.bb +++ b/meta/recipes-support/gnutls/gnutls_3.8.4.bb @@ -51,6 +51,7 @@ SRC_URI = "https://www.gnupg.org/ftp/gcrypt/gnutls/v${SHRT_VER}/gnutls-${PV}.tar file://CVE-2026-42011_p2.patch \ file://CVE-2026-33846.patch \ file://CVE-2026-33845.patch \ + file://CVE-2026-5419.patch \ " SRC_URI[sha256sum] = "2bea4e154794f3f00180fa2a5c51fe8b005ac7a31cd58bd44cdfa7f36ebc3a9b" From patchwork Wed Sep 23 09:10:22 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 98976 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id C32DCC98308 for ; Wed, 23 Sep 2026 09:11:44 +0000 (UTC) Received: from mail-wm2-f12.google.com (mail-wm2-f12.google.com [74.125.225.140]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.2921.1790154701905312175 for ; Wed, 23 Sep 2026 02:11:42 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=o4yguigI; spf=pass (domain: smile.fr, ip: 74.125.225.140, mailfrom: yoann.congal@smile.fr) Received: by mail-wm2-f12.google.com with SMTP id 5b1f17b1804b1-49b91369d18so4540955e9.0 for ; Wed, 23 Sep 2026 02:11:41 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1790154700; x=1790759500; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=xT3dcrLX5cRuY9vO/bWRk1wfXfmMkEz5uPzrrFArt9Y=; b=o4yguigIb4J+IxJAtaGNmswEyih1XMi0QFl2ecf/tGYl3XOk00rvS6qRXXR+539isW /FNKNtqw5zHVUlI6420LS/wYoVzmNxBHFWNKQ5r/+h2MlKze7kKzl/ZYRjK3H+qlahaH GehsM038VFTL6FhfLYrngbbxx/jJQC6uipmv8= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1790154700; x=1790759500; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=xT3dcrLX5cRuY9vO/bWRk1wfXfmMkEz5uPzrrFArt9Y=; b=ePZdr91E+12twNVlWORIAeUxRZC7/9Eat7pcGdCnqUg2suZxDPnimK+t1Nnm/KJH0k ZyzRCWMPoihJFCUwmHMUYxlKIQtQiBsQDDWaal7bAbjlc9f4nkoySioCUftgNe7oU07J JzFid4aXLKT/wN6084ZzoU0axx60gjMlJ8GwGUBO9QCK16nmRicXh/oLhBX8nHVinfnU oaaMJN5dtYuIR+DMW1lEW45xM+gCB+Qvkra/8T5wGa7UEBHPcKCfDGs3tLKnH2SX1JMR Ur1sEhrLAKynR30nGyp/V1fkZnSrNzr0/i+gRGxfdVpvDoS6gQIC5BWXy0bdRvnMCz/v gabQ== X-Gm-Message-State: AFuF++kdlJZALrpz2rFfaqU2CbbxEalCVTLiq0+4v1iG34UKTaG8p1xW itFpOZXLrHYy3Iw/xFK0DCEPyDqmkpx3cZKKzjFZNwd+57973CohmAWXtaxIU36TdRiShkk4G6j oJwrO6yE= X-Gm-Gg: AYBFou3s4KPe52+KHOw5Bx+oFgnIWTrw8MRN/p4zg/JT9y5PKp+TIavT5dzmiQrU6ux MQtqJ7bQjcy4fUpC/FLna92MoB1x7C/TtgrJtdST0MXBe3qXnPEzuMF86YC++kmNc10vOXBe7I9 Ct+RO+jZCxn34ctvUsdUVte2MmqS5P2N6Y/9bEtGDlaQerNf4IBkzP3GatM2pqI+pJ0pjsp0l4E 6H/2Qet1IAHgdIPhQw7bkWpsR0wedXhEprkPpY4X2YgMQqHQ4bg6iTimYZpbeEerM1wZQPel2tX wvej+HNJmJLbzhujJeIDD8VRwxQcd6H9eVhHZ+/EyGTmHOU+ERuFHMWaq7nzfN3TGosXtbAJ+4v pMbaEMhqHlntBAS1xzigZ8LpSGQ0zc4/ub3pIjiza0+0fEKYBsNu33pPzPseyzjnwrxxLQZEPyk hrx2Y/AoPaq7k2n3ITw0fcRbQ7WVzYXZnex6/PhJ1If84WVgFLHPYvX03d/kC5XssQyV+euipg0 cgNf7fDaO8rdeGhr1KPlewJEPQ/VHkaJpewYs8cGy8WD2eLYQSu8HAKz43gZ7lJ4ou0Re6T6rC7 rW/ihLU= X-Received: by 2002:a05:600c:4455:b0:49e:660a:935e with SMTP id 5b1f17b1804b1-49fdf14fa54mr23209415e9.29.1790154700065; Wed, 23 Sep 2026 02:11:40 -0700 (PDT) Received: from FRSMI25-LASER.home (2a02-8440-b519-f416-8bed-8817-19fd-ccf7.rev.sfr.net. [2a02:8440:b519:f416:8bed:8817:19fd:ccf7]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-49fe2730da9sm14251525e9.4.2026.09.23.02.11.39 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 23 Sep 2026 02:11:39 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][scarthgap 20/48] curl: set CVE_STATUS for CVE-2026-8458 Date: Wed, 23 Sep 2026 11:10:22 +0200 Message-ID: X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Wed, 23 Sep 2026 09:11:44 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/246482 From: Devansh Patel CVE-2026-8458 allows a Negotiate-authenticated connection to be incorrectly reused for a request using a different SASL service name. Scarthgap uses curl 8.7.1, which is within the affected version range. The vulnerable code path on Linux requires both Negotiate authentication and GSSAPI support, represented by the negotiate-auth and krb5 PACKAGECONFIG options. The upstream fix [1] stores the SASL service name in struct Curl_creds and includes it in connection-reuse comparisons. However, struct Curl_creds was introduced by the credential-management rework in [2], after curl 8.7.1. Therefore, the security fix cannot be cleanly backported without introducing a substantial credential-management refactor. Use a conditional CVE_STATUS as the least invasive solution. Report the CVE as unpatched when both krb5 and negotiate-auth are enabled. Otherwise, mark it not-applicable-config because the vulnerable GSSAPI-backed Negotiate implementation is not built. The default Scarthgap configuration enables negotiate-auth but does not enable krb5. References: [1] https://github.com/curl/curl/commit/5e99b73cf441d9c369768b9cd48b5389b9a2503d [2] https://github.com/curl/curl/commit/8f71d0fde515aa4c68002477356c35bd79927729 [3] https://curl.se/docs/CVE-2026-8458.html Signed-off-by: Devansh Patel Signed-off-by: Yoann Congal --- meta/recipes-support/curl/curl_8.7.1.bb | 1 + 1 file changed, 1 insertion(+) diff --git a/meta/recipes-support/curl/curl_8.7.1.bb b/meta/recipes-support/curl/curl_8.7.1.bb index 365f02ad596..f2479a33643 100644 --- a/meta/recipes-support/curl/curl_8.7.1.bb +++ b/meta/recipes-support/curl/curl_8.7.1.bb @@ -57,6 +57,7 @@ CVE_STATUS[CVE-2025-0725] = "not-applicable-config: gzip decompression of conten CVE_STATUS[CVE-2025-5025] = "${@bb.utils.contains('PACKAGECONFIG', 'openssl', 'not-applicable-config: applicable only with wolfssl','unpatched',d)}" CVE_STATUS[CVE-2025-10966] = "${@bb.utils.contains('PACKAGECONFIG', 'openssl', 'not-applicable-config: applicable only with wolfssl','unpatched',d)}" CVE_STATUS[CVE-2026-10536] = "${@bb.utils.contains('PACKAGECONFIG', 'nghttp2', 'unpatched', 'not-applicable-config: applicable only with HTTP/2', d)}" +CVE_STATUS[CVE-2026-8458] = "${@bb.utils.contains('PACKAGECONFIG', 'krb5 negotiate-auth', 'unpatched', 'not-applicable-config: applicable only with GSS-API-backed Negotiate authentication', d)}" inherit autotools pkgconfig binconfig multilib_header ptest From patchwork Wed Sep 23 09:10:23 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 98977 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id D12B7C9830C for ; Wed, 23 Sep 2026 09:11:44 +0000 (UTC) Received: from mail-wm2-f13.google.com (mail-wm2-f13.google.com [74.125.225.141]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.2824.1790154702926029669 for ; Wed, 23 Sep 2026 02:11:43 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=YEPVETr1; spf=pass (domain: smile.fr, ip: 74.125.225.141, mailfrom: yoann.congal@smile.fr) Received: by mail-wm2-f13.google.com with SMTP id 5b1f17b1804b1-49cc9f581c4so2339295e9.0 for ; Wed, 23 Sep 2026 02:11:42 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1790154701; x=1790759501; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=T9H3u0FhrHWhuEACS/puMRQevHOwzCisEuBnQHMu1rs=; b=YEPVETr1MGByosimlD+CvqhrzaMQUsma16yaVnZn2RIDSF3d4JetkIbBsRVVfcSYHm rjpz5rGUVhQOx3bjbS1EWxzwjFdzHB0z+INnLDOXtatPUrY+95cAjnF9xbOey9riu6iV V7m9OcHZn0guelKhEGPZq3djWc16VPSXEeOH4= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1790154701; x=1790759501; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=T9H3u0FhrHWhuEACS/puMRQevHOwzCisEuBnQHMu1rs=; b=p5d6oQ0qFwUyvmSpWPl/f4prpMTEMZPDbZubq/n4bsDx8Qa1CjMM2ayxxSM4seHsH7 iI4Ba4wzBlgPIzEn05EYCRXclIVk5+0UjxBC+ZZFOlNPYJQpZfT9rrXkihu4u0FKCPIh IFhWBKwjBAkmaUnNMsQtwUyeKtE1DAE/9S+o+oaL5h2pJZugS1JWrbnCkVahwjJSWe59 1HOHmO96lTBy2WrIuKIC7zMjQ0wcTbhIXudY7uhpbah1VLON4GAb1y8NvKom2yxJa17I h7noVb6Ryb3cL01R2Iyv8nOU6pEXBL1Z4SAUUe4LUG3JePkQcwIKRZXY5FRcsSBe4/9D sfUw== X-Gm-Message-State: AFuF++lYBiwwNlQOh8MjbE+U5Nb5p2l0TrxuLj9EmJPJFQQl1w8hhCWO DsGUW6vvRrHFfcx0JBkh9qeZ85cfyPpa0r2thiIt3aVP9ZjLxbEFxXhPY46Mr8NF7HNg6/+svY9 ujresliE= X-Gm-Gg: AYBFou1hHjf1uRn55Hq6itRIpAJOXNCNAi7wTijEV3o8vRFWzxb4d69uPBnvXmfna1J qQTIrmFzpBk2viqlyELKLgN5lmx5iICr6x48wiBSe7d6yptA98c7qBina1C6BMSeFwvx9Zupu7r eJI7tgnobV7AQTE+DYFHxItbRHcfDEB7gKkDKfeARsN6E1DXsxg7ZMDuMgMXTpHsSX/BSOPdjlq UosbBfXxWFoW0VOKfqlU0L7mpAFigK6KvRZj92TAKhl1S6B+gPW7bDpskuNTEk7Axsk0EksScMX XEkEAFRn8q+grjsxbE3RQja9VAhr03nx9rFMOPKxYAz6RykWrxdgTKpsycJPtbfht0N6Ci3mTGn ccHRDPEiYzdR+wyuLhV4U6cd/G41jqykzoEKjUaOoYxiSFeXLay6Bha96+DD5qjv6vFuOzj6zDD kgdhKxlmNtc7gPNxwwEctgAsbtJAML8LIEVhBVfN9yB4hB2FGzvDVQnfMQcphe8cMrCNVfca4QM jnkxyyXXZmFWNNgivDuCe71SwUeCUSxn4yZv5qaT6IExEFYec8SCpQVAuaxuBxJ7BBVYVQK X-Received: by 2002:a05:600c:1f90:b0:49e:6836:5386 with SMTP id 5b1f17b1804b1-49fde20e848mr27511995e9.0.1790154701041; Wed, 23 Sep 2026 02:11:41 -0700 (PDT) Received: from FRSMI25-LASER.home (2a02-8440-b519-f416-8bed-8817-19fd-ccf7.rev.sfr.net. [2a02:8440:b519:f416:8bed:8817:19fd:ccf7]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-49fe2730da9sm14251525e9.4.2026.09.23.02.11.40 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 23 Sep 2026 02:11:40 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][scarthgap 21/48] vim: Fix CVE-2026-52858 regression Date: Wed, 23 Sep 2026 11:10:23 +0200 Message-ID: X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Wed, 23 Sep 2026 09:11:44 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/246483 From: Devansh Patel This patch fixes a regression introduced by the CVE-2026-52858 fix already carried by OE-Core in commit [1]. The original security fix added the g:pythoncomplete_allow_import opt-in, but the documented behavior was broken because vim was not imported in the completion class scope. This patch applies upstream Vim patch 9.2.0568 to restore that behavior. [1] https://github.com/openembedded/openembedded-core/commit/1c08fa48b6765ace24a261ecf43f871e850cee88 [2] https://github.com/vim/vim/commit/4b850457e12e1a678dd209f2868154f7553cbf8d [3] https://github.com/vim/vim/commit/868ad62cb8bf8038322eab2badd31bd98b02b9df [4] https://github.com/vim/vim/security/advisories/GHSA-52mc-rq6p-rc7c Signed-off-by: Devansh Patel Signed-off-by: Yoann Congal --- .../vim/files/CVE-2026-52858-regression.patch | 94 +++++++++++++++++++ meta/recipes-support/vim/vim.inc | 1 + 2 files changed, 95 insertions(+) create mode 100644 meta/recipes-support/vim/files/CVE-2026-52858-regression.patch diff --git a/meta/recipes-support/vim/files/CVE-2026-52858-regression.patch b/meta/recipes-support/vim/files/CVE-2026-52858-regression.patch new file mode 100644 index 00000000000..d3b11a62629 --- /dev/null +++ b/meta/recipes-support/vim/files/CVE-2026-52858-regression.patch @@ -0,0 +1,94 @@ +From 8075209bb1e721ca89c2e7fd5d216d7fe2bd3ea6 Mon Sep 17 00:00:00 2001 +From: thinca +Date: Sun, 31 May 2026 12:33:07 +0000 +Subject: [PATCH] patch 9.2.0568: pythoncomplete: g:pythoncomplete_allow_import + had no effect + +Problem: The security patch 9.2.0561 added a vim.eval() call inside + Completer.evalsource() to honor g:pythoncomplete_allow_import. + But the 'vim' module is only imported inside the outer + vimcomplete() / vimpy3complete() function, not at the script's + top level, so referring to it from a Completer method raises + NameError. The surrounding bare 'except' silently swallows + the error and leaves allow_imports at 0, meaning the opt-in + never takes effect -- 'import os' (and any other + buffer-level import) is always skipped, no candidates are + produced for 'os.<...>' and + Test_popup_and_preview_autocommand() fails on the Windows + CI matrix (Linux skips the test because Python 2 is absent). +Solution: Re-import 'vim' at the top of evalsource() in both + pythoncomplete.vim and python3complete.vim so the eval reads + the global, and set g:pythoncomplete_allow_import = 1 in the + test (it is the opt-in intended for callers that trust the + buffer contents) (thinca). + +closes: #20386 + +CVE: CVE-2026-52858 +Upstream-Status: Backport [https://github.com/vim/vim/commit/868ad62cb8bf8038322eab2badd31bd98b02b9df] + +Backport Changes: +- Omitted src/version.c because the Scarthgap recipe remains at Vim 9.1.1683; + the upstream version-table hunk targets Vim 9.2 and conflicted during + cherry-pick, while the runtime and test changes applied unchanged. + +Signed-off-by: thinca +Signed-off-by: Christian Brabandt +(cherry picked from commit 868ad62cb8bf8038322eab2badd31bd98b02b9df) +Signed-off-by: Devansh Patel +--- + runtime/autoload/python3complete.vim | 3 +++ + runtime/autoload/pythoncomplete.vim | 3 +++ + src/testdir/test_popup.vim | 4 ++++ + 3 files changed, 10 insertions(+) + +diff --git a/runtime/autoload/python3complete.vim b/runtime/autoload/python3complete.vim +index a0314242b..bdabf62c8 100644 +--- a/runtime/autoload/python3complete.vim ++++ b/runtime/autoload/python3complete.vim +@@ -158,6 +158,9 @@ class Completer(object): + self.parser = PyParser() + + def evalsource(self,text,line=0): ++ # vim is imported locally in vimpy3complete(); re-import here so the ++ # vim.eval() below works (otherwise NameError, silently caught). ++ import vim + sc = self.parser.parse(text,line) + try: allow_imports = int( + vim.eval("get(g:, 'pythoncomplete_allow_import', 0)")) +diff --git a/runtime/autoload/pythoncomplete.vim b/runtime/autoload/pythoncomplete.vim +index 39b1efd29..761488244 100644 +--- a/runtime/autoload/pythoncomplete.vim ++++ b/runtime/autoload/pythoncomplete.vim +@@ -172,6 +172,9 @@ class Completer(object): + self.parser = PyParser() + + def evalsource(self,text,line=0): ++ # vim is imported locally in vimcomplete(); re-import here so the ++ # vim.eval() below works (otherwise NameError, silently caught). ++ import vim + sc = self.parser.parse(text,line) + try: allow_imports = int( + vim.eval("get(g:, 'pythoncomplete_allow_import', 0)")) +diff --git a/src/testdir/test_popup.vim b/src/testdir/test_popup.vim +index fac2a7592..55c2f232d 100644 +--- a/src/testdir/test_popup.vim ++++ b/src/testdir/test_popup.vim +@@ -723,6 +723,9 @@ func Test_popup_and_preview_autocommand() + au! + au BufAdd * nested tab sball + augroup END ++ " Let pythoncomplete follow the buffer's 'import os' (off by default ++ " since v9.2.0561) so 'os.' can be completed. ++ let g:pythoncomplete_allow_import = 1 + set omnifunc=pythoncomplete#Complete + call setline(1, 'import os') + " make the line long +@@ -745,6 +748,7 @@ func Test_popup_and_preview_autocommand() + augroup END + augroup! MyBufAdd + bw! ++ unlet g:pythoncomplete_allow_import + endfunc + + func s:run_popup_and_previewwindow_dump(lines, dumpfile) diff --git a/meta/recipes-support/vim/vim.inc b/meta/recipes-support/vim/vim.inc index 0acf8247b72..5a34c1fa35f 100644 --- a/meta/recipes-support/vim/vim.inc +++ b/meta/recipes-support/vim/vim.inc @@ -34,6 +34,7 @@ SRC_URI = "git://github.com/vim/vim.git;branch=master;protocol=https \ file://CVE-2026-46483.patch \ file://CVE-2026-28420.patch \ file://CVE-2026-52858.patch \ + file://CVE-2026-52858-regression.patch \ file://CVE-2026-52859.patch \ file://CVE-2026-52860.patch \ file://CVE-2026-28422.patch \ From patchwork Wed Sep 23 09:10:24 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 98978 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id EB9DDC9830D for ; Wed, 23 Sep 2026 09:11:44 +0000 (UTC) Received: from mail-wm2-f12.google.com (mail-wm2-f12.google.com [74.125.225.140]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.2922.1790154703675841979 for ; Wed, 23 Sep 2026 02:11:43 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=OxO9zXPQ; spf=pass (domain: smile.fr, ip: 74.125.225.140, mailfrom: yoann.congal@smile.fr) Received: by mail-wm2-f12.google.com with SMTP id 5b1f17b1804b1-49b912d37b5so3843795e9.2 for ; Wed, 23 Sep 2026 02:11:43 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1790154702; x=1790759502; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=Kr/h0A+ETkvns0fCZNrdF5zQsnX/lAr9mCObyQaCU70=; b=OxO9zXPQETvcGLdA0prrJH0rCiWvJfa9O+XRcCBNc36m7JZxcwdDZIaCdAFhzOub0o kCPIXDaIICTByrXQIHpKBN4OQULzXNSQ4/qCI9K5aCQM/atmPWE9i1ymdvc+IDsD7HeF 5D8AQzx/brNj3SpJrpoind/SfTnOLKCd/nkxM= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1790154702; x=1790759502; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=Kr/h0A+ETkvns0fCZNrdF5zQsnX/lAr9mCObyQaCU70=; b=bkyY/qAH0Z67je96/aPFx7PeHPttrRXtkplDcUoqZQ9rqzXV/URhUY+Q4bE5orix3n yELh3WzTaHEA81+P7o0mORdaobRY108ezIcApw91ho2xKEcV/YyItVRH6tAU25kFDxmC oUX7rJm8nWZ5blUAooxRSKi2RTaf3WmYZbJrdDIzcAFXfV1vGqsnrQDCjhm77K3k6g5Z WWM8PbHyJHBX9NfLyAdzK8QxEhgqW72c0ixlBIiVvThKKdxv6MOBFGCdexARB7EO3c/X gbCz5Ban9szAX9PVI1B17EX5UkbhTFKZJo9qHt9mcO0w8yOFsJKDYpewOGANZQw9I0oK ekZA== X-Gm-Message-State: AFuF++m4r/cmWVpBN1gYduYCBF+I33T5Xf7p9BHKX7c8vTAoe7z26apr QBu9/7DKBkls3dWB1mLSnIR2Cvta0BugVQ0b5yVVsJ3vi1Z0ib4PHq2MCZWWFNwNtUKUHkIcGKS YLmaYNpQ= X-Gm-Gg: AYBFou1jW0XoTDNY/9BSQChRQ8zmUIZI2LLkJzqhoK7SzzYLuQHxOkCYZS7hBQ4RmA4 ox0DZp0tBd6mm5IJTm18vYg7ooodLpIxLPYmqgYjFCxhL91AmRlMQnoYh+O5SWDXURNKN7+2gF8 0a7BJLff35T9CHAqbyD9in2axn34bUfFVvrFcnPscUIXXb8EuWZ5QTKOInjqnJEq7pALT4V3/wX Y7/Ukx2Z5UBJoOLd1m5wy2qWiZ84CGd3jwMNMSnpxsAfMsQ5VSejbOX5d4bmWYMmyL8q1+KpGnl VvCjp1ZIq9Ql5zQhUhvCf6DJ9MOiO4EGhmKAZFchi9IETVKk3sFuCz3CWyvTNrazn/unPB/VHuE iUa0zuLgrqfUjzmrQeWMNPYQeWcIosCsaZmR6g8mVxRUYYyg2C3Wg4UsjgxGuq4emBgGhLT0lCz C9RYsrzfrfIT2GqwNUbkAkYNW9Vr4dLBy15PAOi2MMN/g8zkj7KsVIHCQw7C80LAucrVfACayFI zyRMCJ0B4A5gMcDQ19eNoI3zfxKi/R+lB6vVZejnirf91d9ps2M4myKFBlRsOpiZtSIsQT0 X-Received: by 2002:a05:600c:19cf:b0:49f:ce78:356f with SMTP id 5b1f17b1804b1-49fdf0feeddmr26267205e9.32.1790154701920; Wed, 23 Sep 2026 02:11:41 -0700 (PDT) Received: from FRSMI25-LASER.home (2a02-8440-b519-f416-8bed-8817-19fd-ccf7.rev.sfr.net. [2a02:8440:b519:f416:8bed:8817:19fd:ccf7]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-49fe2730da9sm14251525e9.4.2026.09.23.02.11.41 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 23 Sep 2026 02:11:41 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][scarthgap 22/48] improve_kernel_cve_report: validate that cve details field exists Date: Wed, 23 Sep 2026 11:10:24 +0200 Message-ID: X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Wed, 23 Sep 2026 09:11:44 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/246484 From: Daniel Turull Check if the cve information has the details field to avoid crashing Signed-off-by: Daniel Turull Signed-off-by: Mathieu Dubois-Briand Signed-off-by: Richard Purdie (cherry picked from commit 80ff4903ea1b839f9cd9393b314c3adfbb80b765) Signed-off-by: Yoann Congal --- scripts/contrib/improve_kernel_cve_report.py | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/scripts/contrib/improve_kernel_cve_report.py b/scripts/contrib/improve_kernel_cve_report.py index 3a15b1ed26e..dc961d59389 100755 --- a/scripts/contrib/improve_kernel_cve_report.py +++ b/scripts/contrib/improve_kernel_cve_report.py @@ -362,7 +362,7 @@ def cve_update(cve_data, cve, entry): if entry['status'] == "Unpatched" and cve_data[cve]['status'] == "Patched": # Backported-patch (e.g. vendor kernel repo with cherry-picked CVE patch) # has priority over unpatch from CNA - if cve_data[cve]['detail'] == "backported-patch": + if "detail" in cve_data and cve_data[cve]['detail'] == "backported-patch": return logging.warning("CVE entry %s update from Patched to Unpatched from the scan result", cve) cve_data[cve] = copy_data(cve_data[cve], entry) From patchwork Wed Sep 23 09:10:25 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 98982 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 25D9AC98310 for ; Wed, 23 Sep 2026 09:11:45 +0000 (UTC) Received: from mail-wm2-f13.google.com (mail-wm2-f13.google.com [74.125.225.141]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.2825.1790154704437413649 for ; Wed, 23 Sep 2026 02:11:44 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=rK5DccH/; spf=pass (domain: smile.fr, ip: 74.125.225.141, mailfrom: yoann.congal@smile.fr) Received: by mail-wm2-f13.google.com with SMTP id 5b1f17b1804b1-49e7d2bb404so2174715e9.1 for ; Wed, 23 Sep 2026 02:11:44 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1790154703; x=1790759503; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=ERdyuwfWxXAt5hzGKW33Sn540WPLwfT/SY/IPEqWssU=; b=rK5DccH/46nwytrB9xkMc87KKkF/aE79Jq9uVSbGDQrBzXKPPXDWPMGYtgZ5L0z56I +zFyRwOBnB7UzDv0keQx9Ukxzb4NOTmilX9SZ1eye4lMW8dMrMVsXZoYQ4bvZVpbtKfm dz3nUW1VEimgB5HydYZvfB+f++MwnyIjtMCEM= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1790154703; x=1790759503; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=ERdyuwfWxXAt5hzGKW33Sn540WPLwfT/SY/IPEqWssU=; b=YfYFtAtYi4ES0JePIO02cKssEwdr+vnlGdWBV0eXmyP8jgsU0XLt7aWMPPCirkXQ1L +GzFcHnaX6H3HuiFUkh+jjN7hIS7/3qmDvEe/Gsljvv/8EpGWGgQkmqWMW9g47Dbd3x1 swEdYeXq6/yrW5LcObkrSPMyRjHIeFbjOFLS+AQhmp9BO+7EbrbnH9lHv6I+HXHAYcN5 c0sPGVdWil/ryZzwry1gd1R734Q4v04/jJtxw91ByxYNZmLklTB5dIAXQcjTiGCg1pme nYtEEBiYdGlHCwT+m6vFgOk0fYMnUo1S5m6xcMc/y/YA0YRx5gNMJ/+jjB+VcLAR9MvC Losg== X-Gm-Message-State: AFuF++lTKcnCT6+jPN9GR0onI07X8fXviMWfxiSZhbgexuFIpYqCb+TR rm4ciJ5t/VRmtCccDxgqPBNPHjHHpJngm+YpG0TC5RYT9A6LYbbiIHeW68ADW/wxV36bwm5w7IQ ewSi9YGQ= X-Gm-Gg: AYBFou3Nb8WgVNCUbIRWrrBwijD6kUpMu4OUA/ReJhAuFLcWXj73JgrbzYA3ybQJtMc J3V28VzCRHxkdY8oTvFxq5YVOhcyAANWpMv3QESceo8B7TrQ0r/ZPNwUzS2YOXlFA5DbW1xt9mF 4SJ5Nde/+msH8KJfqXsUBspnbsqjvFd2nrh4zySLJCmRDbKmPppSj5THvpoE6aVAUGx6P9y2QIe 15X6UV6kFFV1oRbiYnEt4m2/7Px0aqKcrxutTclUb4N688+A9UvlL5Hy92MurZK8FQBCfwYY4i1 bdbpkfwYX5GBP6q3Jq0slEEGX1lbnSxlot8qTNuUZoKwqV9uU8KZyqew9oYYxXC7Avy4tx0151D ZM8YQDVdPSHuR4cyVMlEpK5UW2/kCt0/huMvjWGJ5/baduqTwRwfubNgfKK5fOgwgeVzHhttbgs zgDnBqT1CP8giQL5sJe1h0hE4PMlocMsZ5vR86Rbk+1bYukEdTVeF1R5/BVJCEiDfSqDrRKX5WT yIN7rH5yR566D69vYItnqkfAfgMEnC1XRk3cCoeyo1R1ZgG8RrvEJlf/KmJCquXyNSZBZom X-Received: by 2002:a05:600c:c176:b0:49e:6865:904e with SMTP id 5b1f17b1804b1-49fde49755dmr28698115e9.12.1790154702718; Wed, 23 Sep 2026 02:11:42 -0700 (PDT) Received: from FRSMI25-LASER.home (2a02-8440-b519-f416-8bed-8817-19fd-ccf7.rev.sfr.net. [2a02:8440:b519:f416:8bed:8817:19fd:ccf7]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-49fe2730da9sm14251525e9.4.2026.09.23.02.11.42 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 23 Sep 2026 02:11:42 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][scarthgap 23/48] improve_kernel_cve_report: fix backported-patch check Date: Wed, 23 Sep 2026 11:10:25 +0200 Message-ID: X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Wed, 23 Sep 2026 09:11:45 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/246485 From: Hiago De Franco The guard added in 80ff4903ea tests "detail" in cve_data, but cve_data is keyed by CVE id, so it asks whether a CVE literally named "detail" was scanned. That is never true, the condition short-circuits, and the guard never runs: a CVE_STATUS[CVE-...] = "backported-patch" set for a vendor cherry-picked patch is silently overwritten to Unpatched by the CNA. Use .get() on the entry instead. Guard the fallthrough warning the same way, it makes the same assumption. Tested against a qemuarm64 linux-yocto report (6.6.142+git, 16221 entries, 4313 of them with no detail). Current master and this version produce identical output, 18773 entries with no difference. Adding CVE_STATUS[CVE-2024-42067] = "backported-patch" to that report then makes the only difference between them: master overwrites it to Unpatched, this version keeps it Patched. The pre-80ff4903ea code aborts on the same report with "KeyError: 'detail'". AI-Generated: Uses Claude (claude-opus-5) Fixes: 80ff4903ea1b ("improve_kernel_cve_report: validate that cve details field exists") Signed-off-by: Hiago De Franco Signed-off-by: Richard Purdie (cherry picked from commit f5da16b0d3c8f889dab061ba1d8808aba95d4c67) Signed-off-by: Yoann Congal --- scripts/contrib/improve_kernel_cve_report.py | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/scripts/contrib/improve_kernel_cve_report.py b/scripts/contrib/improve_kernel_cve_report.py index dc961d59389..dd59d93146f 100755 --- a/scripts/contrib/improve_kernel_cve_report.py +++ b/scripts/contrib/improve_kernel_cve_report.py @@ -362,7 +362,7 @@ def cve_update(cve_data, cve, entry): if entry['status'] == "Unpatched" and cve_data[cve]['status'] == "Patched": # Backported-patch (e.g. vendor kernel repo with cherry-picked CVE patch) # has priority over unpatch from CNA - if "detail" in cve_data and cve_data[cve]['detail'] == "backported-patch": + if cve_data[cve].get('detail') == "backported-patch": return logging.warning("CVE entry %s update from Patched to Unpatched from the scan result", cve) cve_data[cve] = copy_data(cve_data[cve], entry) @@ -381,7 +381,7 @@ def cve_update(cve_data, cve, entry): logging.debug("CVE entry %s updated from Unpatched to Ignored", cve) return logging.warning("Unhandled CVE entry update for %s %s from %s %s to %s", - cve, cve_data[cve]['status'], cve_data[cve]['detail'], entry['status'], entry['detail']) + cve, cve_data[cve]['status'], cve_data[cve].get('detail'), entry['status'], entry['detail']) def main(): parser = argparse.ArgumentParser( From patchwork Wed Sep 23 09:10:26 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 98986 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 593BFC98307 for ; Wed, 23 Sep 2026 09:11:55 +0000 (UTC) Received: from mail-wm2-f13.google.com (mail-wm2-f13.google.com [74.125.225.141]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.2826.1790154706718536707 for ; Wed, 23 Sep 2026 02:11:47 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=m0BVq6BY; spf=pass (domain: smile.fr, ip: 74.125.225.141, mailfrom: yoann.congal@smile.fr) Received: by mail-wm2-f13.google.com with SMTP id 5b1f17b1804b1-49e7d2bb404so2174865e9.1 for ; Wed, 23 Sep 2026 02:11:46 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1790154705; x=1790759505; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=Fq83uRJeePn3LYxbdaxaHbmSs/6aOotf0a1MEkZKyYg=; b=m0BVq6BYitvlnIvfeOkurH2bKSC1Dl+TaH3CDxs7BWVgJ7JHnA+T56ABChVZLuAZ2p s+UbnAC+DYDxZkWfORAhOHFq/+Z2/h2rDJS+KJ8H10xZ/2+FjcPoZ4HkMzL73Q8hA4Vm ehwcDX+jOyByngNJv8AMZ6xFBvWhj5XRMosuo= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1790154705; x=1790759505; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=Fq83uRJeePn3LYxbdaxaHbmSs/6aOotf0a1MEkZKyYg=; b=qkurYU9PEm7Z+z1xE/c95wQGIzipWB6lAhKTgIeuHWkfyyTw60QP5ykZQABVisZBu/ TP4t575cybMVN1xHrHr+ZSAY1aJzxoAW7nkMvkxCdFdKZUIT/cXZFANhNaLijubwvrKe pUsDKBhj4ncTcSr3nHDMWWt4BmJ/mdX0E4dCEFdfAkZK6ijEMr1TpJWycvPqoODM3Wp5 iYqoJ1LmYgb2QRo6d68lhjqYIz8RT7wL5DHb0R/8nw+sTkEng06jDi9LbfNta+cw/eY2 +EUueuJw1VubYHweBUqOYHJeQ5J2Jf7h6if62aPZ8+8FqHFkSk8FaKRwgrWj9cEIJ45z m/jg== X-Gm-Message-State: AFuF++mG+y0zbplgMg6VjmpBk18D/frNXqeON9nPpbhbh9O6B8ZWSPba Fbi2gJhgCDFD2Aces/Tk28PosBmduD0NnvfSaPo8dQRdQXbWW52KVzXtJY69C7Y+Ae+Oo16ovcP JjWlQ5sA= X-Gm-Gg: AYBFou0RrO83DQ68FxSANFWQT0HoFBeP9PXsA9OHeWY0U5rrfv9M3GXIz9opx7NjTg/ uh3/hH8olv1vYuTpZEpR/h8zSEEGdQxdtrgJRZMRIB1E0WsyEy4rp57hUmecG+vyIgn8o2jIOt4 exZBg4O1xTm0NLjCXhd821xpzp/6fzknGEhaNZv1Xr2ztHfk8l3sak/XccnD5Tq0rO43HvBycZZ PzDMOimRi2cgjZigQhfC6ccEwi0bn7EtzPVI8hmDSVxYWZNsKgXxW5HWT+ZdO0iKGMu84AWRCte IhX6ioQ3cYuTPNIrmuwelaVvRhZ+LnC2xIzVFaOH9a7ujsv9QAXHNOcDoSi3arCTv37LT3V4hJ4 b2Elh7hlqstfsdcv3IxaVXx6VFHvodBYYk3E57vU2h+0lbZRjKxwkRNMsPgO2iv2UcXRw4Ekunc O97m/JahIIqJS6FV+xlggWzRMdl7pdyWzG8EWHntNaRYWpwIZ2Iug724Pd8jURr8aMCHHDenrQU RPs/NGOhsFKeh8K0BzUPx0iYXFQFf7Q7hbv8m0F2NJ4bzRnie7LCXjFSBiAyAbvcgPxgWlh X-Received: by 2002:a05:600c:4745:b0:49e:6581:7baf with SMTP id 5b1f17b1804b1-49fde3601bdmr30087365e9.2.1790154704910; Wed, 23 Sep 2026 02:11:44 -0700 (PDT) Received: from FRSMI25-LASER.home (2a02-8440-b519-f416-8bed-8817-19fd-ccf7.rev.sfr.net. [2a02:8440:b519:f416:8bed:8817:19fd:ccf7]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-49fe2730da9sm14251525e9.4.2026.09.23.02.11.43 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 23 Sep 2026 02:11:44 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][scarthgap 24/48] libxfont: Fix CVE-2026-56001 Date: Wed, 23 Sep 2026 11:10:26 +0200 Message-ID: <5a5af4e7c55a26951827622143831d89db2f4ad5.1790154074.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Wed, 23 Sep 2026 09:11:55 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/246486 From: Vijay Anusuri Pick patch according to [2] [1] https://nvd.nist.gov/vuln/detail/CVE-2026-56001 [2] https://security-tracker.debian.org/tracker/CVE-2026-56001 Signed-off-by: Vijay Anusuri Signed-off-by: Yoann Congal --- .../xorg-lib/libxfont/CVE-2026-56001.patch | 87 +++++++++++++++++++ .../xorg-lib/libxfont_1.5.4.bb | 3 + 2 files changed, 90 insertions(+) create mode 100644 meta/recipes-graphics/xorg-lib/libxfont/CVE-2026-56001.patch diff --git a/meta/recipes-graphics/xorg-lib/libxfont/CVE-2026-56001.patch b/meta/recipes-graphics/xorg-lib/libxfont/CVE-2026-56001.patch new file mode 100644 index 00000000000..1de7f3e0372 --- /dev/null +++ b/meta/recipes-graphics/xorg-lib/libxfont/CVE-2026-56001.patch @@ -0,0 +1,87 @@ +From be0b08e2d354138d3222b4490e2a77c6ee42f778 Mon Sep 17 00:00:00 2001 +From: Peter Hutterer +Date: Mon, 1 Jun 2026 16:46:10 +1000 +Subject: [PATCH] bitscale: fix integer overflow in BitmapScaleBitmaps + bytestoalloc + +bytestoalloc is declared as unsigned int (32-bit). When the sum of +per-glyph byte counts exceeds 2^32, the value wraps around and calloc() +allocates a buffer that is too small. The subsequent ScaleBitmap loop +then writes past the end of the allocated buffer. + +Change bytestoalloc from unsigned int to size_t to match the actual +allocation size type, and add an explicit overflow check in the +accumulation loop to bail out if the total would exceed SIZE_MAX. + +This vulnerability was discovered by: +Anonymous working with TrendAI Zero Day Initiative + +CVE-2026-56001/ZDI-CAN-30558 + +Assisted-by: Claude:claude-opus-4-6 +Signed-off-by: Peter Hutterer +Part-of: + +Note: 'SIZE_MAX' is defined in header ''. Add '#include +' to fix build failure. + +Upstream-Status: Backport [import from debian libxfont1 1.5.2-4+deb9u1 +Upstream commit https://gitlab.freedesktop.org/xorg/lib/libxfont/-/commit/be0b08e2d354138d3222b4490e2a77c6ee42f778] +CVE: CVE-2026-56001 +Signed-off-by: Vijay Anusuri +--- + src/bitmap/bitscale.c | 24 +++++++++++++++++++++--- + 1 file changed, 21 insertions(+), 3 deletions(-) + +diff --git a/src/bitmap/bitscale.c b/src/bitmap/bitscale.c +index 13ed924..32144d6 100644 +--- a/src/bitmap/bitscale.c ++++ b/src/bitmap/bitscale.c +@@ -38,6 +38,7 @@ from The Open Group. + #include + #include + #include ++#include + + #ifndef MAX + #define MAX(a,b) (((a)>(b)) ? a : b) +@@ -1459,7 +1460,7 @@ BitmapScaleBitmaps(FontPtr pf, /* scaled font */ + opci; + FontInfoPtr pfi; + int glyph; +- unsigned bytestoalloc = 0; ++ size_t bytestoalloc = 0; + int firstCol, lastCol, firstRow, lastRow; + + double xform[4], inv_xform[4]; +@@ -1486,8 +1487,25 @@ BitmapScaleBitmaps(FontPtr pf, /* scaled font */ + glyph = pf->glyph; + for (i = 0; i < nchars; i++) + { +- if ((pci = ACCESSENCODING(bitmapFont->encoding, i))) +- bytestoalloc += BYTES_FOR_GLYPH(pci, glyph); ++ if ((pci = ACCESSENCODING(bitmapFont->encoding, i))) { ++ size_t glyphsize = BYTES_FOR_GLYPH(pci, glyph); ++ if (bytestoalloc > SIZE_MAX - glyphsize) { ++ fprintf(stderr, ++ "Error: bitmap allocation overflow for scaled font\n"); ++ goto bail; ++ } ++ bytestoalloc += glyphsize; ++ } ++ } ++ ++ /* Reject unreasonably large bitmap allocations that could result ++ * from malicious fonts with extreme scale factors. 256 MiB is ++ * far beyond any legitimate scaled bitmap font. */ ++#define BITMAP_SCALE_MAX_ALLOC (256 * 1024 * 1024) ++ if (bytestoalloc > BITMAP_SCALE_MAX_ALLOC) { ++ fprintf(stderr, ++ "Error: scaled bitmap size %zu exceeds limit\n", bytestoalloc); ++ goto bail; + } + + /* Do we add the font malloc stuff for VALUE ADDED ? */ +-- +2.43.0 + diff --git a/meta/recipes-graphics/xorg-lib/libxfont_1.5.4.bb b/meta/recipes-graphics/xorg-lib/libxfont_1.5.4.bb index fa6585d6dce..1173794f8d6 100644 --- a/meta/recipes-graphics/xorg-lib/libxfont_1.5.4.bb +++ b/meta/recipes-graphics/xorg-lib/libxfont_1.5.4.bb @@ -19,6 +19,9 @@ XORG_EXT = "tar.bz2" BBCLASSEXTEND = "native" +SRC_URI += "file://CVE-2026-56001.patch \ + " + SRC_URI[md5sum] = "16eaf156edd79b68038b6a7c44aa9e9b" SRC_URI[sha256sum] = "1a7f7490774c87f2052d146d1e0e64518d32e6848184a18654e8d0bb57883242" From patchwork Wed Sep 23 09:10:27 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 98988 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 66563C9830B for ; Wed, 23 Sep 2026 09:11:55 +0000 (UTC) Received: from mail-wm2-f13.google.com (mail-wm2-f13.google.com [74.125.225.141]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.2923.1790154708317102070 for ; Wed, 23 Sep 2026 02:11:48 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=lxUufxj0; spf=pass (domain: smile.fr, ip: 74.125.225.141, mailfrom: yoann.congal@smile.fr) Received: by mail-wm2-f13.google.com with SMTP id 5b1f17b1804b1-49e69b9e16aso5744355e9.1 for ; Wed, 23 Sep 2026 02:11:48 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1790154706; x=1790759506; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=ZwchotgcaIhwZq85Fiuu8sJWB5nULsjhKtRbBMSf1IA=; b=lxUufxj0UwBCJ+Rkv7tEr0MWVR1o7dSXaEmIXn87KiUo8sn55x7eRT7llhcv2FcKqn 6HGMnWPjZMU+sQkevw/dpapik1X596DJWVQVuNJEtS2mjXJIYQI2gwZOCu3XUpIVl1k/ J0tEjRygMxbDGgBRvebZ1W3miHEmDKCFeH3oM= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1790154706; x=1790759506; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=ZwchotgcaIhwZq85Fiuu8sJWB5nULsjhKtRbBMSf1IA=; b=Onf6uESBaR2M5GhYaaECF+o2MsqqsaNemod59MWZpJqVDET9P0K6WQyQ5u/9ZbpulP 7oN3j23VCgnhZoTGI0v/2bYVgsIqo1gGP1+zp7Z+9ZJKiisRRcbOGFbFNLN636G7vEp7 UAcqvn4GIkPahiG32p4wtx1NvK8A4r+k2n5UqP4CXbtRxn4J+ppr6rZJtlGBoWMSurYG apF6kre0sw1MGfjd6fleFDfHuU8fd+Ft4YjTG3hMO3+Uvsei3recFtQrMcD4ovys/jNi cSy8jyNTzbS273K6QFMBgdDPGfffoMTtlUnQq8QlA3R78yIIQNolHp6qnXTczWRQVCMb VOsg== X-Gm-Message-State: AFuF++mJFV1SyphvB+yTe7oohv3GkNZA/6uPNylZXU2NlBpuy5kca7Sg aHztDIoBkwRJ1PFx5JM/4EN7zKLC47QrzEgT0G0MKRZoPuFeANtWM1M2xWyDsZ6dUSHzemRTMHb psdp3RfA= X-Gm-Gg: AYBFou1xm/EQB7aFoAGU1jQI+rwIDx1Zp19Jvh/2FDQhmY5In5R/KLrp1Q+o9/56x3J 51kg44nKEyUmk9covfnwVipPLzSIzOF0eH/OVP/KPrRoQ3MzvYBDOS4qrsW9YTGp6lWaN8QvQ4K TClML8Vc5TPgZ5sP30cIvjZTjchPWrI7M4C/ALOFZ7d0eq4FaH306wKvWvS+PM6pvljvTocpSzH al3JA7FNwDsHh+8V+41niZ4yp3sh3aUvozqWCnggPRBjH06LABFo4fs5H1qPkcPqffu/2t3fY81 A40VshiV/3un+Ph255yg2iDq89o0KrUGEZsF3gjjH+FzjKFXJLOsr4WxX2T6UBuP78GIpALl/42 C3sH6sGm7RT1pfBFK/rn8+eQPoZrJuVAHpudNrtkc2r5QJbNCW5x40AzOEuk3Xvzr3tFMuibqr3 8SFjbQWY/BTZkezP/0RbkwsaJh8Ow/SZXacW/GYdmtlrQ6NXuZ8fhHbnHSDEVO8MNJkcofpIr3C LXDDUiof+zFm89Um6lUzAuNXdnbbVwcUSKhBmvXFAwJm8zROCJcFY/8znF6FxL4fqeNi58b X-Received: by 2002:a05:600c:8b6f:b0:49c:fff9:f684 with SMTP id 5b1f17b1804b1-49fdf13502amr26399825e9.21.1790154706407; Wed, 23 Sep 2026 02:11:46 -0700 (PDT) Received: from FRSMI25-LASER.home (2a02-8440-b519-f416-8bed-8817-19fd-ccf7.rev.sfr.net. [2a02:8440:b519:f416:8bed:8817:19fd:ccf7]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-49fe2730da9sm14251525e9.4.2026.09.23.02.11.45 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 23 Sep 2026 02:11:45 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][scarthgap 25/48] libxfont: Fix CVE-2026-56002 Date: Wed, 23 Sep 2026 11:10:27 +0200 Message-ID: <9f95815832f8c2753fd6d91c4719764e81ee5b81.1790154074.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Wed, 23 Sep 2026 09:11:55 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/246487 From: Vijay Anusuri Pick patch according to [2] [1] https://nvd.nist.gov/vuln/detail/CVE-2026-56002 [2] https://security-tracker.debian.org/tracker/CVE-2026-56002 Signed-off-by: Vijay Anusuri Signed-off-by: Yoann Congal --- .../xorg-lib/libxfont/CVE-2026-56002.patch | 150 ++++++++++++++++++ .../xorg-lib/libxfont_1.5.4.bb | 1 + 2 files changed, 151 insertions(+) create mode 100644 meta/recipes-graphics/xorg-lib/libxfont/CVE-2026-56002.patch diff --git a/meta/recipes-graphics/xorg-lib/libxfont/CVE-2026-56002.patch b/meta/recipes-graphics/xorg-lib/libxfont/CVE-2026-56002.patch new file mode 100644 index 00000000000..cef8a06a686 --- /dev/null +++ b/meta/recipes-graphics/xorg-lib/libxfont/CVE-2026-56002.patch @@ -0,0 +1,150 @@ +From b4389e0b1d84a690b819bb27b1439968811a3674 Mon Sep 17 00:00:00 2001 +From: Peter Hutterer +Date: Mon, 1 Jun 2026 16:48:40 +1000 +Subject: [PATCH] pcfread: validate bitmap sizes and offsets against per-glyph + metrics + +pcfReadFont() uses bitmapSizes[] read directly from the PCF file to +allocate the repadded bitmap buffer. However, per-glyph metrics (also +from the file) control how much data RepadBitmap() writes. A malicious +PCF font can declare a small bitmapSizes[] value while having per-glyph +metrics that require more space, causing a heap buffer overflow. + +A similar issue happens with the encoding offsets: pcfReadFont reads +encoding offsets from the PCF file and uses them to index into the +metrics array without bounds checking. A crafted font can set an +encoding offset larger than nmetrics, causing an out-of-bounds pointer +that is later dereferenced when glyphs are accessed through the encoding +table. + +And the no-repad bitmap path (when PCF_GLYPH_PAD matches the requested +glyph pad) only validated that each glyph's offset was within the bitmap +buffer, but did not check that the full glyph extent (offset + +BYTES_PER_ROW * height) fits within the buffer. A crafted font with a +glyph offset near the end of a small bitmap buffer but large glyph +metrics causes a heap buffer over-read when the glyph is later rendered. + +This vulnerability was discovered by: + Anonymous working with TrendAI Zero Day Initiative + +CVE-2026-56002/ZDI-CAN-30559 + +Assisted-by: Claude:claude-opus-4-6 +Signed-off-by: Peter Hutterer +Part-of: + +Note: 'INT_MAX' is defined in header ''. Add '#include +' to fix build failure. + +Upstream-Status: Backport [import from debian libxfont1 1.5.2-4+deb9u1 +Upstream commit https://gitlab.freedesktop.org/xorg/lib/libxfont/-/commit/b4389e0b1d84a690b819bb27b1439968811a3674] +CVE: CVE-2026-56002 +Signed-off-by: Vijay Anusuri +--- + src/bitmap/pcfread.c | 60 +++++++++++++++++++++++++++++++++++++++++--- + 1 file changed, 57 insertions(+), 3 deletions(-) + +diff --git a/src/bitmap/pcfread.c b/src/bitmap/pcfread.c +index 4a372c5..0cc9777 100644 +--- a/src/bitmap/pcfread.c ++++ b/src/bitmap/pcfread.c +@@ -45,6 +45,7 @@ from The Open Group. + #include + #include + #include ++#include + + void + pcfError(const char* message, ...) +@@ -529,25 +530,74 @@ pcfReadFont(FontPtr pFont, FontFilePtr file, + int old, + new; + xCharInfo *metric; ++ int srcPad = PCF_GLYPH_PAD(format); + +- sizepadbitmaps = bitmapSizes[PCF_SIZE_TO_INDEX(glyph)]; +- padbitmaps = malloc(sizepadbitmaps); ++ /* Compute the actual required size from per-glyph metrics instead ++ * of trusting the file's bitmapSizes[] value, which may be smaller ++ * than the actual data written by RepadBitmap. */ ++ sizepadbitmaps = 0; ++ for (i = 0; i < nbitmaps; i++) { ++ int w, h, glyphBytes; ++ metric = &metrics[i].metrics; ++ w = metric->rightSideBearing - metric->leftSideBearing; ++ h = metric->ascent + metric->descent; ++ glyphBytes = BYTES_PER_ROW(w, glyph) * h; ++ if (glyphBytes < 0 || (glyphBytes > 0 && sizepadbitmaps > INT_MAX - glyphBytes)) { ++ pcfError("pcfReadFont(): bitmap size overflow\n"); ++ goto Bail; ++ } ++ sizepadbitmaps += glyphBytes; ++ } ++ padbitmaps = malloc(sizepadbitmaps ? sizepadbitmaps : 1); + if (!padbitmaps) { + pcfError("pcfReadFont(): Couldn't allocate padbitmaps (%d)\n", sizepadbitmaps); + goto Bail; + } + new = 0; + for (i = 0; i < nbitmaps; i++) { ++ int srcGlyphBytes; ++ + old = offsets[i]; + metric = &metrics[i].metrics; ++ ++ /* Validate source offset and source glyph size against the ++ * source bitmap buffer to prevent out-of-bounds reads. */ ++ srcGlyphBytes = BYTES_PER_ROW( ++ metric->rightSideBearing - metric->leftSideBearing, ++ srcPad) * (metric->ascent + metric->descent); ++ if (old < 0 || old > sizebitmaps || ++ srcGlyphBytes < 0 || srcGlyphBytes > sizebitmaps - old) { ++ pcfError("pcfReadFont(): bitmap offset/size out of bounds\n"); ++ free(padbitmaps); ++ goto Bail; ++ } ++ + offsets[i] = new; + new += RepadBitmap(bitmaps + old, padbitmaps + new, +- PCF_GLYPH_PAD(format), glyph, ++ srcPad, glyph, + metric->rightSideBearing - metric->leftSideBearing, + metric->ascent + metric->descent); + } + free(bitmaps); + bitmaps = padbitmaps; ++ } else { ++ /* Validate offsets and full glyph extents against bitmap buffer */ ++ for (i = 0; i < nbitmaps; i++) { ++ int glyphBytes; ++ xCharInfo *metric = &metrics[i].metrics; ++ ++ glyphBytes = BYTES_PER_ROW( ++ metric->rightSideBearing - metric->leftSideBearing, ++ glyph) * (metric->ascent + metric->descent); ++ if (offsets[i] >= (CARD32)sizebitmaps || ++ glyphBytes < 0 || ++ glyphBytes > sizebitmaps - (int)offsets[i]) { ++ pcfError("pcfReadFont(): bitmap offset/size out of bounds " ++ "(offset %u, size %d, total %d)\n", ++ offsets[i], glyphBytes, sizebitmaps); ++ goto Bail; ++ } ++ } + } + for (i = 0; i < nbitmaps; i++) + metrics[i].bits = bitmaps + offsets[i]; +@@ -622,6 +672,10 @@ pcfReadFont(FontPtr pFont, FontFilePtr file, + if (IS_EOF(file)) goto Bail; + if (encodingOffset == 0xFFFF) { + pFont->info.allExist = FALSE; ++ } else if (encodingOffset >= nmetrics) { ++ pcfError("pcfReadFont(): encoding offset %d out of range (nmetrics=%d)\n", ++ encodingOffset, nmetrics); ++ goto Bail; + } else { + if(!encoding[SEGMENT_MAJOR(i)]) { + encoding[SEGMENT_MAJOR(i)]= +-- +2.43.0 + diff --git a/meta/recipes-graphics/xorg-lib/libxfont_1.5.4.bb b/meta/recipes-graphics/xorg-lib/libxfont_1.5.4.bb index 1173794f8d6..e7a426c32a9 100644 --- a/meta/recipes-graphics/xorg-lib/libxfont_1.5.4.bb +++ b/meta/recipes-graphics/xorg-lib/libxfont_1.5.4.bb @@ -20,6 +20,7 @@ XORG_EXT = "tar.bz2" BBCLASSEXTEND = "native" SRC_URI += "file://CVE-2026-56001.patch \ + file://CVE-2026-56002.patch \ " SRC_URI[md5sum] = "16eaf156edd79b68038b6a7c44aa9e9b" From patchwork Wed Sep 23 09:10:28 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 98989 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 75A78C9830C for ; Wed, 23 Sep 2026 09:11:55 +0000 (UTC) Received: from mail-wm2-f12.google.com (mail-wm2-f12.google.com [74.125.225.140]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.2924.1790154709045105077 for ; Wed, 23 Sep 2026 02:11:49 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=jjGx+N0R; spf=pass (domain: smile.fr, ip: 74.125.225.140, mailfrom: yoann.congal@smile.fr) Received: by mail-wm2-f12.google.com with SMTP id 5b1f17b1804b1-49e620fa473so3850435e9.1 for ; Wed, 23 Sep 2026 02:11:48 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1790154707; x=1790759507; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=kJfDTy5m+36UU8CokyU12u5ANhhkfWhV2hCnYJeRjN0=; b=jjGx+N0Rp5lP1kHxFYYDQEw1LXANc2o6vvcmTXIjZm91wKP3CbWfjysUTjeuAFKKBN g5XuzV1G/z81ppAdj3DdM/tTwS+NbOCInRk+nUggxXDp4FQ/OQsStl0Y+nl00PaqqWx0 6IkK2yU0icXo2HxPnNkZEf2UuaZfw4kECn8tc= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1790154707; x=1790759507; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=kJfDTy5m+36UU8CokyU12u5ANhhkfWhV2hCnYJeRjN0=; b=nEn6+zahV7Pm8GKJHo+5Azt7fDXx3Zzodin1OqRzqH0J/WFR49wbBmZz0mQ/LaRTaf 51kEOUnokdCNE0jAfjPyOU3ImSmdsmYKCpLqSz+88TQplUMwSlKtc6Uq9FpSpr15OLUc pxy8pWBaG3TRJ7EThgZLHH2pKQjLsgsM3FiMaJfXkRRgEc87h5pt+NPuYN/Yg0mrA3b+ 5OwFmeHf61klsuU2dRDbZYueECR3mCqFHX2+/xG7NvBvECwBpe0kpZ0mZ/WpXxE5Opc8 cBbo6jBD0eL6eIFlv6/iyGKg0ubJvcOyQS42nypfXwjWQFwXblkfmYrWYF4cXXZD2rma +Z7A== X-Gm-Message-State: AFuF++l5voWTsLIsgENhphoQwxI2Sca6g2ZiDqu0ASymqUTUqt6PIhjA wWktsxWzpFpbbSQhaBYiKq5G2Wd3FhvFn/JhmNA8r88/n8/s68rqw+lhG8F5yt/LFCohczaspNY LdXPsjbQ= X-Gm-Gg: AYBFou1s08hsDy9jNT5b9S9UF355PkNewXO+ndLcqFI6QXllSjqrHRLBomKhsw4tGYh r023Rx4lELrc5XdR0ms4rIRQSyZ4rhmFSG6YhTMi2RSzQh3IS1eFKp2A5RnsHIW76bsvMtoj1H/ HRuSSAj7YEwUMQu5WiPnR5Ar/mSy80kRVwe1Qu0Cs2hSnKjf9KRLNS2CoDroBIdoptuxx1iJ2cH q0wux2k6/jvRZdZO0l5p1ztgel5ByQXCnh/oN8PYC1TBnjc1Emt8o/+l7rBBYNvbDt++NhHzlVR l5AAikd57jNDMJYG9eoCwmwLdbvVrz2Bxe4vbnXlvtcWdtG9vq+It223oirfO8IF3aBZG3EaeGT 8nK30txNZ0aRrHq9RE6Dvj1pR6xvAz4jMGheO7VZHCH8aVg+KznXTix55Aag+9V1TDUh3wBMG39 MXJzEc5IJEfD07fs2/G74rn8PbIaniqd+db0gHuhQ4lhQPQjnNv4ZfzkmVI6mF01yQtCvAR8iDK OqHv3x5v9Y9texoxqYagirUPK0ZxBwcdcaRf4zbnQ2YFYtyF1zg7Lh1Z5C7OePeu1tIzL9yT6Du d8hBEqQ= X-Received: by 2002:a05:600c:4743:b0:49f:bd0d:59f5 with SMTP id 5b1f17b1804b1-49fdf13542cmr24037145e9.18.1790154707189; Wed, 23 Sep 2026 02:11:47 -0700 (PDT) Received: from FRSMI25-LASER.home (2a02-8440-b519-f416-8bed-8817-19fd-ccf7.rev.sfr.net. [2a02:8440:b519:f416:8bed:8817:19fd:ccf7]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-49fe2730da9sm14251525e9.4.2026.09.23.02.11.46 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 23 Sep 2026 02:11:46 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][scarthgap 26/48] libxfont: Fix CVE-2026-56003 Date: Wed, 23 Sep 2026 11:10:28 +0200 Message-ID: <8a7e8d6249d0c0669d9ec6034317cf1e7ce96cc7.1790154074.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Wed, 23 Sep 2026 09:11:55 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/246488 From: Vijay Anusuri Pick patch according to [2] [1] https://nvd.nist.gov/vuln/detail/CVE-2026-56003 [2] https://security-tracker.debian.org/tracker/CVE-2026-56003 Signed-off-by: Vijay Anusuri Signed-off-by: Yoann Congal --- .../xorg-lib/libxfont/CVE-2026-56003.patch | 114 ++++++++++++++++++ .../xorg-lib/libxfont_1.5.4.bb | 1 + 2 files changed, 115 insertions(+) create mode 100644 meta/recipes-graphics/xorg-lib/libxfont/CVE-2026-56003.patch diff --git a/meta/recipes-graphics/xorg-lib/libxfont/CVE-2026-56003.patch b/meta/recipes-graphics/xorg-lib/libxfont/CVE-2026-56003.patch new file mode 100644 index 00000000000..0092c712d44 --- /dev/null +++ b/meta/recipes-graphics/xorg-lib/libxfont/CVE-2026-56003.patch @@ -0,0 +1,114 @@ +From dff957a5158da038a282a59a31fe736702732939 Mon Sep 17 00:00:00 2001 +From: Peter Hutterer +Date: Mon, 1 Jun 2026 16:49:55 +1000 +Subject: [PATCH] bitscale: add bounds check to computeProps for property + buffer + +ComputeScaledProperties allocates a fixed-size property buffer of 70 +slots. computeProps iterates the source font's properties and writes 1 +slot for unscaled properties or 2 slots for scaledX/scaledY properties, +with no bounds check. A malicious font with many duplicate properties +matching fontPropTable entries can overflow the allocated buffer. + +Fix this by passing the remaining buffer capacity to computeProps and +checking it before each write. Properties that would exceed the buffer +are silently skipped. + +The function is also restructured to handle the buffer writes for +scaledX/scaledY inside the switch cases directly, rather than in a +separate block after the switch. This makes the control flow clearer and +ensures the bounds check covers all writes. + +This vulnerability was discovered by: +Anonymous working with TrendAI Zero Day Initiative + +CVE-2026-56003/ZDI-CAN-30560 + +Assisted-by: Claude:claude-opus-4-6 +Signed-off-by: Peter Hutterer +Part-of: + +Upstream-Status: Backport [https://gitlab.freedesktop.org/xorg/lib/libxfont/-/commit/dff957a5158da038a282a59a31fe736702732939] +CVE: CVE-2026-56003 +Signed-off-by: Vijay Anusuri +--- + src/bitmap/bitscale.c | 39 ++++++++++++++++++++------------------- + 1 file changed, 20 insertions(+), 19 deletions(-) + +diff --git a/src/bitmap/bitscale.c b/src/bitmap/bitscale.c +index 32144d6..2affc11 100644 +--- a/src/bitmap/bitscale.c ++++ b/src/bitmap/bitscale.c +@@ -513,7 +513,8 @@ static int + computeProps(FontPropPtr pf, char *wasStringProp, + FontPropPtr npf, char *isStringProp, + unsigned int nprops, double xfactor, double yfactor, +- double sXfactor, double sYfactor) ++ double sXfactor, double sYfactor, ++ int maxprops) + { + int n; + int count; +@@ -528,14 +529,26 @@ computeProps(FontPropPtr pf, char *wasStringProp, + + switch (t->type) { + case scaledX: +- npf->value = doround(xfactor * (double)pf->value); +- rawfactor = sXfactor; +- break; + case scaledY: +- npf->value = doround(yfactor * (double)pf->value); +- rawfactor = sYfactor; ++ if (count + 2 > maxprops) ++ continue; ++ npf->value = (t->type == scaledX) ++ ? doround(xfactor * (double)pf->value) ++ : doround(yfactor * (double)pf->value); ++ rawfactor = (t->type == scaledX) ? sXfactor : sYfactor; ++ npf->name = pf->name; ++ npf++; ++ count++; ++ npf->value = doround(rawfactor * (double)pf->value); ++ npf->name = rawFontPropTable[t - fontPropTable].atom; ++ npf++; ++ count++; ++ *isStringProp++ = *wasStringProp; ++ *isStringProp++ = *wasStringProp; + break; + case unscaled: ++ if (count + 1 > maxprops) ++ continue; + npf->value = pf->value; + npf->name = pf->name; + npf++; +@@ -545,18 +558,6 @@ computeProps(FontPropPtr pf, char *wasStringProp, + default: + break; + } +- if (t->type != unscaled) +- { +- npf->name = pf->name; +- npf++; +- count++; +- npf->value = doround(rawfactor * (double)pf->value); +- npf->name = rawFontPropTable[t - fontPropTable].atom; +- npf++; +- count++; +- *isStringProp++ = *wasStringProp; +- *isStringProp++ = *wasStringProp; +- } + } + return count; + } +@@ -671,7 +672,7 @@ ComputeScaledProperties(FontInfoPtr sourceFontInfo, /* the font to be scaled */ + n = NPROPS; + n += computeProps(sourceFontInfo->props, sourceFontInfo->isStringProp, + fp, isStringProp, sourceFontInfo->nprops, dx, dy, +- sdx, sdy); ++ sdx, sdy, nProps - NPROPS); + return n; + } + +-- +2.43.0 + diff --git a/meta/recipes-graphics/xorg-lib/libxfont_1.5.4.bb b/meta/recipes-graphics/xorg-lib/libxfont_1.5.4.bb index e7a426c32a9..5f1af82ac4b 100644 --- a/meta/recipes-graphics/xorg-lib/libxfont_1.5.4.bb +++ b/meta/recipes-graphics/xorg-lib/libxfont_1.5.4.bb @@ -21,6 +21,7 @@ BBCLASSEXTEND = "native" SRC_URI += "file://CVE-2026-56001.patch \ file://CVE-2026-56002.patch \ + file://CVE-2026-56003.patch \ " SRC_URI[md5sum] = "16eaf156edd79b68038b6a7c44aa9e9b" From patchwork Wed Sep 23 09:10:29 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 98984 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 25A65C982EA for ; Wed, 23 Sep 2026 09:11:55 +0000 (UTC) Received: from mail-wm2-f13.google.com (mail-wm2-f13.google.com [74.125.225.141]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.2925.1790154709865248313 for ; Wed, 23 Sep 2026 02:11:50 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=v21JMR1Y; spf=pass (domain: smile.fr, ip: 74.125.225.141, mailfrom: yoann.congal@smile.fr) Received: by mail-wm2-f13.google.com with SMTP id 5b1f17b1804b1-49b912d822dso4197905e9.2 for ; Wed, 23 Sep 2026 02:11:49 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1790154708; x=1790759508; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=LUZ/oZXOQ1qsiFz5NSzTUcxGxOWSkM7/wh0LvOArpBE=; b=v21JMR1YDbyuzubfXFxH9A/jOu9ayt+hAEBqsjauIZPJRTnMxi2WjtoSjxRA0EhdmU CfXIZiUiuWVS117yr7sMzgo8I+HfmtdlY8r3spDFfV16Gw5ekWzJUoSN2j3YX4zZHFAs GcYRNp7Vp58DCsPxQs1GeQ5sqEsCitP6xphuE= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1790154708; x=1790759508; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=LUZ/oZXOQ1qsiFz5NSzTUcxGxOWSkM7/wh0LvOArpBE=; b=PcoUz4fcmIvrttuRf+Zlrdc07OBr+AeDI3ddOK/eyJ2bvKoL0Y3y97vERPPOJq8ffb xE11CygYLRANfVNTg10NfLO+5uAmWKA3HjmBdVIyJCRHiwsAYiehFsVmySKA2KTZvzHn 1zcE48OKlvoHeCvjVHSckJGh5L3QDiGcaLvSCXuphl1sbUUCVJRxsajqmcfbE6jrafVw DGpsbhwXFZ7vWAop1H5X34/heUwejHgZOW7oqWcxL0uTkbru/e1vqludD0LX3PqOTb6M jmlVti/6+oI3pTFhrBil6sG5U//hn/FtUhI0v5f0KlP51QqKHqCNzQG53XskFWuVOd+B e4BA== X-Gm-Message-State: AFuF++mVpegCr9hm+UnbKoCOQzRvdjiUDAWvYNOYnlygAPAKyr32tlTb rRkkWQg2apwKnE16Ntk5bmdjn7hMGUdDGFpZQpLwZBELSQAIvAOl10lQ25+iS24WVxzjlR17xGE gj4MFIuA= X-Gm-Gg: AYBFou1RgNsRH4dX/2E41jgo4/w2ntU7lnKhMC64I6OLv2E38PZferbp9r1UUQHPMr8 jbwdndmUcToVo3ZSp5ZziAMSVqyF+NUsOrac+omepGPq1MKSY9BVkhGyuG2aD9YrMeYXMNVwkxv 9Py3TJKU4+yvugIIC9YY2yBJzQqSju7M5w3g0+cymw9SfmFiZmK2E0VyuM3JqfJ1QXsbavW/FJ3 uyoDLKJx9+sdJTSsv3fOZUpX7Jj51nK8vfQiUc/6YQbIS4mrpQt9Q14GDAriWyPU46G18JOQr5H VYxQoRoSn6NIFvs4MvQ4K0oJG81wtgKT9CN0ejbm3DO2vOGKTD5yonALB1ZxpDQIN8+i1QofW3G UFRdbBe7j0KnE8Su9GDxfdoOKSoHJ7AXpQkiOD4fV5NZUPLBnwRb/FbzEqCkf0TNC8Nk0axpaFt PYTKOSisNGoLfFIv5HpyThMcub9naPDsPsRSgH6/ezX5488Cis0+mLe2EPCzp+rN66no/Ul5sQd fjGuc68uzmreYy7f9bSbB1mhXYZk4tJw6x9QnyC5Pd17FVaCIa5lsnf4fkx6qZVAe3o6GfB9fGX 2PKHuUU= X-Received: by 2002:a05:600c:3e0b:b0:49d:827:e5b6 with SMTP id 5b1f17b1804b1-49fdf134f93mr25826245e9.20.1790154707979; Wed, 23 Sep 2026 02:11:47 -0700 (PDT) Received: from FRSMI25-LASER.home (2a02-8440-b519-f416-8bed-8817-19fd-ccf7.rev.sfr.net. [2a02:8440:b519:f416:8bed:8817:19fd:ccf7]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-49fe2730da9sm14251525e9.4.2026.09.23.02.11.47 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 23 Sep 2026 02:11:47 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][scarthgap 27/48] golang: fix homepage Date: Wed, 23 Sep 2026 11:10:29 +0200 Message-ID: X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Wed, 23 Sep 2026 09:11:55 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/246489 From: Peter Marko Leading space leads to SPDX document validation errors in some tools. Example: SchemaError: \" http://golang.org/\" is not valid under any of the schemas listed in the 'anyOf' keyword (components -> ... -> externalReferences -> 0 -> url) Signed-off-by: Peter Marko Signed-off-by: Richard Purdie (From OE-Core rev: cbf36f436b477d81b58ff605846a2482308aefa) Signed-off-by: Peter Marko Signed-off-by: Yoann Congal --- meta/recipes-devtools/go/go-binary-native_1.22.12.bb | 2 +- meta/recipes-devtools/go/go-common.inc | 2 +- 2 files changed, 2 insertions(+), 2 deletions(-) diff --git a/meta/recipes-devtools/go/go-binary-native_1.22.12.bb b/meta/recipes-devtools/go/go-binary-native_1.22.12.bb index dd84021cc9e..5dfb3133f6b 100644 --- a/meta/recipes-devtools/go/go-binary-native_1.22.12.bb +++ b/meta/recipes-devtools/go/go-binary-native_1.22.12.bb @@ -1,7 +1,7 @@ # This recipe is for bootstrapping our go-cross from a prebuilt binary of Go from golang.org. SUMMARY = "Go programming language compiler (upstream binary for bootstrap)" -HOMEPAGE = " http://golang.org/" +HOMEPAGE = "http://golang.org/" LICENSE = "BSD-3-Clause" LIC_FILES_CHKSUM = "file://LICENSE;md5=5d4950ecb7b26d2c5e4e7b4e0dd74707" diff --git a/meta/recipes-devtools/go/go-common.inc b/meta/recipes-devtools/go/go-common.inc index a39dea6c1cb..62b31f1762f 100644 --- a/meta/recipes-devtools/go/go-common.inc +++ b/meta/recipes-devtools/go/go-common.inc @@ -9,7 +9,7 @@ DESCRIPTION = " The Go programming language is an open source project to make \ fast, statically typed, compiled language that feels like a\ dynamically typed, interpreted language." -HOMEPAGE = " http://golang.org/" +HOMEPAGE = "http://golang.org/" LICENSE = "BSD-3-Clause" inherit goarch From patchwork Wed Sep 23 09:10:30 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 98987 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 38784C98308 for ; Wed, 23 Sep 2026 09:11:55 +0000 (UTC) Received: from mail-wm2-f12.google.com (mail-wm2-f12.google.com [74.125.225.140]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.2926.1790154710578381259 for ; Wed, 23 Sep 2026 02:11:50 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=eemARZAF; spf=pass (domain: smile.fr, ip: 74.125.225.140, mailfrom: yoann.congal@smile.fr) Received: by mail-wm2-f12.google.com with SMTP id 5b1f17b1804b1-49ce364488dso2016745e9.0 for ; Wed, 23 Sep 2026 02:11:50 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1790154709; x=1790759509; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=dJKZOZueEmOWrYweoIyN90xkli5NqDmr/Kjq7NcYSik=; b=eemARZAF4R18teSQa4rjpcTAun+QAuIPl4n+0a0Iy0vyEGzEKqSCE6pMk+NA4RZ1Ww +YYKami4o4RZ/XYNZcOOHV8XbJQ1LxeEGWqPTJIzqbd0EQzXm3POAyLHLgKqAEf+XA6O kS5aqgScz223EESkq0ovlGJuPYDoC5slRFo1I= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1790154709; x=1790759509; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=dJKZOZueEmOWrYweoIyN90xkli5NqDmr/Kjq7NcYSik=; b=MsPDFzxdcUlL/V4Q0fEATyNknFo2jjNrget7NnRUiGt5BhqnK9KsgFXzkdnIhb0QIQ UObpqDEgnEaIUs1L+uzbVjHVwxduMlaRBSAbj6KIUii3o1z+ezk93iN/alhvpMirbSOL Hzv0e+m1Hi6VTtvhHbeYgb7rBJjXY+pyroBOGis8E2TVXMdQVIpQW6KcPp1eppIegydH ir+CP9eYqDTCByIYlN73eQ04CL3T4P9pl8G1xo6215mbdrGFCklLYyzno/xT856p1TkQ OTMR2p2SlyBTcxnE9K5VhFeXStBQOY2FrAGL8NOHzzwnOTab+AtKAwkTjIj9B1Vj1j0l owVw== X-Gm-Message-State: AFuF++n47o3lqbVhuoTBGKCjdLk7xbkiZz4dlZuPCKB8lDNvYuaekner n/m3s/WKjSOG1sGe30F2+mmS8kah9xZQcObExQoC5wGRz86Kn9+cJqLiHu+DwEjXMClqUMztC09 PCVE+S/E= X-Gm-Gg: AYBFou3xM0oogn+E0h23us6z3GTuqRU7/tVwEplXCWE90SF/lwa7qGopyqxFg7IJslm wn67p/QBPd9nNbVfeg6pUq2LMmzfo3wFGMFIwM+kOqX74Ga1FQco5mH9WopUgTNBmMRMgVjde+8 UOUSx+pqauEWDxeQ0uPQw8Od5XKcEpeVRdxsBpFDMG386Skn7b4ern9t9ea00bBkNEomtKWuBfS JMW49J8V9eg9JNiJ9PVca9yRVda4s242o3LG9eGYXxwuPF9VgmEyiSbgwKOmDOHUk2f6LfUdVAK 95ouBFxu/8KtEspftakkgRWP4yDp3Em27NpfYiW1XLwT3l3JlRnzLDdMeYMMP3bxKLdPs9Q//cT GjdUPlTf2PkY4WLnQgGIdgeQP8M+Skg+u2qAiNkXxTnmwzGdql9c1oAHw8hlY53Jg3ylGRC0YQ3 ZegcTmqYjHRB3b2/qpcFKATEqQP/q7FbLiApAZK6KsNuPNtEIa+DDE4TOHh5YfEgFyMwXu9OOpN jD2AU7W1tcDlTINouO34ky+zYpitB9CWRZVhkdZTXlkTYW0tUN9nUunJEqYrRUCiYHEYjkY X-Received: by 2002:a05:600d:4447:10b0:49e:63cc:6324 with SMTP id 5b1f17b1804b1-49fde371b57mr20047985e9.6.1790154708849; Wed, 23 Sep 2026 02:11:48 -0700 (PDT) Received: from FRSMI25-LASER.home (2a02-8440-b519-f416-8bed-8817-19fd-ccf7.rev.sfr.net. [2a02:8440:b519:f416:8bed:8817:19fd:ccf7]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-49fe2730da9sm14251525e9.4.2026.09.23.02.11.48 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 23 Sep 2026 02:11:48 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][scarthgap 28/48] python3-certifi: fix homepage Date: Wed, 23 Sep 2026 11:10:30 +0200 Message-ID: <758899639692fb76e28f3914f75249957c0b3600.1790154074.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Wed, 23 Sep 2026 09:11:55 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/246490 From: Peter Marko Leading space leads to SPDX document validation errors in some tools. Example: SchemaError: \" http://certifi.io/\" is not valid under any of the schemas listed in the 'anyOf' keyword (components -> ... -> externalReferences -> 0 -> url) Signed-off-by: Peter Marko Signed-off-by: Richard Purdie (From OE-Core rev: ee556d1e1cc16327e0a11207e90ac61d9f1577f3) Signed-off-by: Peter Marko Signed-off-by: Yoann Congal --- meta/recipes-devtools/python/python3-certifi_2024.2.2.bb | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/meta/recipes-devtools/python/python3-certifi_2024.2.2.bb b/meta/recipes-devtools/python/python3-certifi_2024.2.2.bb index b3d6cf080cc..617b597a40e 100644 --- a/meta/recipes-devtools/python/python3-certifi_2024.2.2.bb +++ b/meta/recipes-devtools/python/python3-certifi_2024.2.2.bb @@ -2,7 +2,7 @@ SUMMARY = "Python package for providing Mozilla's CA Bundle." DESCRIPTION = "This installable Python package contains a CA Bundle that you can reference in your \ Python code. This is useful for verifying HTTP requests, for example. This is the same CA Bundle \ which ships with the Requests codebase, and is derived from Mozilla Firefox's canonical set." -HOMEPAGE = " http://certifi.io/" +HOMEPAGE = "http://certifi.io/" LICENSE = "ISC" LIC_FILES_CHKSUM = "file://LICENSE;md5=11618cb6a975948679286b1211bd573c" From patchwork Wed Sep 23 09:10:31 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 98985 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 1A33FC982FA for ; Wed, 23 Sep 2026 09:11:55 +0000 (UTC) Received: from mail-wm2-f13.google.com (mail-wm2-f13.google.com [74.125.225.141]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.2827.1790154713677520175 for ; Wed, 23 Sep 2026 02:11:54 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=wcSIlMiZ; spf=pass (domain: smile.fr, ip: 74.125.225.141, mailfrom: yoann.congal@smile.fr) Received: by mail-wm2-f13.google.com with SMTP id 5b1f17b1804b1-49cd38e0e5dso8678905e9.2 for ; Wed, 23 Sep 2026 02:11:53 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1790154712; x=1790759512; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=i0ULtBs/MD2J1N2HwL1nZ1fJS1ujkPA5We07sdW/E90=; b=wcSIlMiZHxTa1R/b0dloI8QnXEPEuel85YNFtGReHsN2J8u+CAKsgPtdOKJjGZnGmB NGbD7NZ0QnGo0FA4eWRijv+9vDLLAoJ/x4Sd/xLtyC/vZ65eeu4F5DJugmcpa4Zf6v/V 6vvCeXkxshBxbBZ/uKVyjQQmsehc/aLjjnovQ= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1790154712; x=1790759512; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=i0ULtBs/MD2J1N2HwL1nZ1fJS1ujkPA5We07sdW/E90=; b=IxWZ8JAY5PiRpJhjggU0GUw8pYf/mS3ls57WCbHeQHJtOo1uNiDobl5tyUA6wGt1sj h3+VLoysfLs4vqkyEBhjAm3Uh0+VssN98OzHVvSsSlt6IRQ+ZXC1BxHm3DVkvavjGKHo 01RMLy33vc8ZWHyXIc8fK3w1uzfVkiU+QELl7Cf0dc4nH0fzWi0KwiUXSFxOygHzmtaa 5XdQeW4Gvd5cyRNLgZxUXLHuVhNw4hcY2Nbq9P4EJLnHtKY5q6XIy6MDJtssZszOvUWR CwpZTFbbYHJzcMCtj22Zgy+rzROh2lG8pf8Zzno3M9fLr655zIJvjEPJcW1WPtODpYex ZTwg== X-Gm-Message-State: AFuF++mSdja+C2E0eaxlURL6BFtUrJS91UpdnflWohU7qW0Jb7avEOqk UsPLK+q7629PvxKY/9ZIaF/wSoadOD7H9vgg+lKj889vEnDX7ik8vLDo++r09Ehkn7oXOkwsr/F v5FFACIM= X-Gm-Gg: AYBFou3BLGFQdDQeXVmZv2f92/degFIKLRilAMoQbY+a+klOr/8UXf0lVouzE6FuCF6 PgZ1+P+SF/9x4S7HRsqOb6JwdIRoPtg5DE7ZveClPaLFCBqxjF2NA7GtQsApETQh2Hc6cIReUUq RQDo4uBICXuBjx7784zl7+k5amiPfbrwlt91ks4XXeowbAtyz90mZMSVnAovMghBWjc9WRtjA+u BOJXAo4HKK4XfrMoc0HqzQazYKXPJmtODJFaAz9h/9B1z2QUboUSll6bA7vI2cGulqc20NHONn1 fFMT/XkMgqymWAR8cTPXWJRApwhM2kaJWS9SXvk7gGi4xH9bb4A8pkmP935uJdzonCg2NCw2mdp VyUoQVEyuQK80LyIqUn8O4ZeJ2ARTzRY4MUWKdBJa2BQNkvDh2wodNW6FcNH8e2egm44vmTNzpY +l8/sR64AqdUH5pS3478E3RZ725dPKkVYnpNnqgNfJTyFSWk1IZfekQtGCmY1YUTVc1vN7D6rW0 ukbxBFan6+X0G5fh+2NcZgPc+lyeso0ylPGa5aj4Ji0J5TQyhpDhHiE2iOCPjsmDv/wbihgf9Pm clLXO28= X-Received: by 2002:a05:600c:8b21:b0:49c:f512:2361 with SMTP id 5b1f17b1804b1-49fdf1087edmr24776495e9.14.1790154711650; Wed, 23 Sep 2026 02:11:51 -0700 (PDT) Received: from FRSMI25-LASER.home (2a02-8440-b519-f416-8bed-8817-19fd-ccf7.rev.sfr.net. [2a02:8440:b519:f416:8bed:8817:19fd:ccf7]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-49fe2730da9sm14251525e9.4.2026.09.23.02.11.49 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 23 Sep 2026 02:11:51 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][scarthgap 29/48] gcc: Upgrade to GCC 13.5 Date: Wed, 23 Sep 2026 11:10:31 +0200 Message-ID: <1260b53b4ab29913e429fe403240356a7cd9aeec.1790154074.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Wed, 23 Sep 2026 09:11:55 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/246491 From: Hemanth Kumar M D This is a bugfix release in GCC-13 release series with 266 bugfixes https://gcc.gnu.org/bugzilla/buglist.cgi?bug_status=RESOLVED&resolution=FIXED&target_milestone=13.5 Docs: https://gcc.gnu.org/onlinedocs/13.5.0/ Dropped the following patches: 0028-libcody-Make-it-buildable-by-C-11-to-C-26.patch https://github.com/gcc-mirror/gcc/commit/51b9a0f7dfd2441a30e0ebfd4b30f18f86b4ea54 0029-build-Remove-INCLUDE_MEMORY-PR117737.patch https://github.com/gcc-mirror/gcc/commit/9239757a9c6e3a6e8d94d56803329d556ec914d7 0030-build-Move-sstream-include-above-safe-ctype.h-PR1177.patch https://github.com/gcc-mirror/gcc/commit/9239757a9c6e3a6e8d94d56803329d556ec914d7 GCC 13.4 GCC 13.5 Diff No. of expected passes 179388 179928 +540 No. of unexpected failures 26 27 +1 No. of expected failures 1416 1416 0 No. of unsupported tests 2230 2241 +11 Signed-off-by: Hemanth Kumar M D Signed-off-by: Yoann Congal --- meta/conf/distro/include/maintainers.inc | 2 +- .../gcc/{gcc-13.4.inc => gcc-13.5.inc} | 9 +- ...ian_13.4.bb => gcc-cross-canadian_13.5.bb} | 0 .../{gcc-cross_13.4.bb => gcc-cross_13.5.bb} | 0 ...-crosssdk_13.4.bb => gcc-crosssdk_13.5.bb} | 0 ...cc-runtime_13.4.bb => gcc-runtime_13.5.bb} | 0 ...itizers_13.4.bb => gcc-sanitizers_13.5.bb} | 0 ...{gcc-source_13.4.bb => gcc-source_13.5.bb} | 0 ...dy-Make-it-buildable-by-C-11-to-C-26.patch | 257 ------------------ ...build-Remove-INCLUDE_MEMORY-PR117737.patch | 46 ---- ...am-include-above-safe-ctype.h-PR1177.patch | 54 ---- .../gcc/{gcc_13.4.bb => gcc_13.5.bb} | 0 ...initial_13.4.bb => libgcc-initial_13.5.bb} | 0 .../gcc/{libgcc_13.4.bb => libgcc_13.5.bb} | 0 ...ibgfortran_13.4.bb => libgfortran_13.5.bb} | 0 15 files changed, 4 insertions(+), 364 deletions(-) rename meta/recipes-devtools/gcc/{gcc-13.4.inc => gcc-13.5.inc} (93%) rename meta/recipes-devtools/gcc/{gcc-cross-canadian_13.4.bb => gcc-cross-canadian_13.5.bb} (100%) rename meta/recipes-devtools/gcc/{gcc-cross_13.4.bb => gcc-cross_13.5.bb} (100%) rename meta/recipes-devtools/gcc/{gcc-crosssdk_13.4.bb => gcc-crosssdk_13.5.bb} (100%) rename meta/recipes-devtools/gcc/{gcc-runtime_13.4.bb => gcc-runtime_13.5.bb} (100%) rename meta/recipes-devtools/gcc/{gcc-sanitizers_13.4.bb => gcc-sanitizers_13.5.bb} (100%) rename meta/recipes-devtools/gcc/{gcc-source_13.4.bb => gcc-source_13.5.bb} (100%) delete mode 100644 meta/recipes-devtools/gcc/gcc/0028-libcody-Make-it-buildable-by-C-11-to-C-26.patch delete mode 100644 meta/recipes-devtools/gcc/gcc/0029-build-Remove-INCLUDE_MEMORY-PR117737.patch delete mode 100644 meta/recipes-devtools/gcc/gcc/0030-build-Move-sstream-include-above-safe-ctype.h-PR1177.patch rename meta/recipes-devtools/gcc/{gcc_13.4.bb => gcc_13.5.bb} (100%) rename meta/recipes-devtools/gcc/{libgcc-initial_13.4.bb => libgcc-initial_13.5.bb} (100%) rename meta/recipes-devtools/gcc/{libgcc_13.4.bb => libgcc_13.5.bb} (100%) rename meta/recipes-devtools/gcc/{libgfortran_13.4.bb => libgfortran_13.5.bb} (100%) diff --git a/meta/conf/distro/include/maintainers.inc b/meta/conf/distro/include/maintainers.inc index 3a51ad2139c..a9b7be3bf75 100644 --- a/meta/conf/distro/include/maintainers.inc +++ b/meta/conf/distro/include/maintainers.inc @@ -190,7 +190,7 @@ RECIPE_MAINTAINER:pn-gcc-cross-canadian-${TRANSLATED_TARGET_ARCH} = "Khem Raj -Date: Fri, 21 Nov 2025 16:25:58 +0100 -Subject: [PATCH] libcody: Make it buildable by C++11 to C++26 - -The following builds with -std=c++11 and c++14 and c++17 and c++20 and c++23 -and c++26. - -I see the u8 string literals are mixed e.g. with strerror, so in --fexec-charset=IBM1047 there will still be garbage, so am not 100% sure if -the u8 literals everywhere are worth it either. - -2025-11-21 Jakub Jelinek - - * cody.hh (S2C): For __cpp_char8_t >= 201811 use char8_t instead of - char in argument type. - (MessageBuffer::Space): Revert 2025-11-15 change. - (MessageBuffer::Append): For __cpp_char8_t >= 201811 add overload - with char8_t const * type of first argument. - (Packet::Packet): Similarly for first argument. - * client.cc (CommunicationError, Client::ProcessResponse, - Client::Connect, ConnectResponse, PathnameResponse, OKResponse, - IncludeTranslateResponse): Cast u8 string literals to (const char *) - where needed. - * server.cc (Server::ProcessRequests, ConnectRequest): Likewise. - -Signed-off-by: Martin Jansa -Upstream-Status: Backport [07a767c7a50d1daae8ef7d4aba73fe53ad40c0b7] ---- - libcody/client.cc | 36 +++++++++++++++++++----------------- - libcody/cody.hh | 22 ++++++++++++++++++++++ - libcody/server.cc | 28 ++++++++++++++-------------- - 3 files changed, 55 insertions(+), 31 deletions(-) - -diff --git a/libcody/client.cc b/libcody/client.cc -index ae69d190cb77..147fecdbe500 100644 ---- a/libcody/client.cc -+++ b/libcody/client.cc -@@ -97,7 +97,7 @@ int Client::CommunicateWithServer () - - static Packet CommunicationError (int err) - { -- std::string e {u8"communication error:"}; -+ std::string e {(const char *) u8"communication error:"}; - e.append (strerror (err)); - - return Packet (Client::PC_ERROR, std::move (e)); -@@ -110,33 +110,34 @@ Packet Client::ProcessResponse (std::vector &words, - { - if (e == EINVAL) - { -- std::string msg (u8"malformed string '"); -+ std::string msg ((const char *) u8"malformed string '"); - msg.append (words[0]); -- msg.append (u8"'"); -+ msg.append ((const char *) u8"'"); - return Packet (Client::PC_ERROR, std::move (msg)); - } - else -- return Packet (Client::PC_ERROR, u8"missing response"); -+ return Packet (Client::PC_ERROR, (const char *) u8"missing response"); - } - - Assert (!words.empty ()); -- if (words[0] == u8"ERROR") -+ if (words[0] == (const char *) u8"ERROR") - return Packet (Client::PC_ERROR, -- words.size () == 2 ? words[1]: u8"malformed error response"); -+ words.size () == 2 ? words[1] -+ : (const char *) u8"malformed error response"); - - if (isLast && !read.IsAtEnd ()) - return Packet (Client::PC_ERROR, -- std::string (u8"unexpected extra response")); -+ std::string ((const char *) u8"unexpected extra response")); - - Assert (code < Detail::RC_HWM); - Packet result (responseTable[code] (words)); - result.SetRequest (code); - if (result.GetCode () == Client::PC_ERROR && result.GetString ().empty ()) - { -- std::string msg {u8"malformed response '"}; -+ std::string msg {(const char *) u8"malformed response '"}; - - read.LexedLine (msg); -- msg.append (u8"'"); -+ msg.append ((const char *) u8"'"); - result.GetString () = std::move (msg); - } - else if (result.GetCode () == Client::PC_CONNECT) -@@ -199,7 +200,7 @@ Packet Client::Connect (char const *agent, char const *ident, - size_t alen, size_t ilen) - { - write.BeginLine (); -- write.AppendWord (u8"HELLO"); -+ write.AppendWord ((const char *) u8"HELLO"); - write.AppendInteger (Version); - write.AppendWord (agent, true, alen); - write.AppendWord (ident, true, ilen); -@@ -211,7 +212,8 @@ Packet Client::Connect (char const *agent, char const *ident, - // HELLO $version $agent [$flags] - Packet ConnectResponse (std::vector &words) - { -- if (words[0] == u8"HELLO" && (words.size () == 3 || words.size () == 4)) -+ if (words[0] == (const char *) u8"HELLO" -+ && (words.size () == 3 || words.size () == 4)) - { - char *eptr; - unsigned long val = strtoul (words[1].c_str (), &eptr, 10); -@@ -247,7 +249,7 @@ Packet Client::ModuleRepo () - // PATHNAME $dir | ERROR - Packet PathnameResponse (std::vector &words) - { -- if (words[0] == u8"PATHNAME" && words.size () == 2) -+ if (words[0] == (const char *) u8"PATHNAME" && words.size () == 2) - return Packet (Client::PC_PATHNAME, std::move (words[1])); - - return Packet (Client::PC_ERROR, u8""); -@@ -256,7 +258,7 @@ Packet PathnameResponse (std::vector &words) - // OK or ERROR - Packet OKResponse (std::vector &words) - { -- if (words[0] == u8"OK") -+ if (words[0] == (const char *) u8"OK") - return Packet (Client::PC_OK); - else - return Packet (Client::PC_ERROR, -@@ -319,11 +321,11 @@ Packet Client::IncludeTranslate (char const *include, Flags flags, size_t ilen) - // PATHNAME $cmifile - Packet IncludeTranslateResponse (std::vector &words) - { -- if (words[0] == u8"BOOL" && words.size () == 2) -+ if (words[0] == (const char *) u8"BOOL" && words.size () == 2) - { -- if (words[1] == u8"FALSE") -- return Packet (Client::PC_BOOL, 0); -- else if (words[1] == u8"TRUE") -+ if (words[1] == (const char *) u8"FALSE") -+ return Packet (Client::PC_BOOL); -+ else if (words[1] == (const char *) u8"TRUE") - return Packet (Client::PC_BOOL, 1); - else - return Packet (Client::PC_ERROR, u8""); -diff --git a/libcody/cody.hh b/libcody/cody.hh -index 789ce9e70b75..93bce93aa94d 100644 ---- a/libcody/cody.hh -+++ b/libcody/cody.hh -@@ -47,12 +47,21 @@ namespace Detail { - - // C++11 doesn't have utf8 character literals :( - -+#if __cpp_char8_t >= 201811 -+template -+constexpr char S2C (char8_t const (&s)[I]) -+{ -+ static_assert (I == 2, "only single octet strings may be converted"); -+ return s[0]; -+} -+#else - template - constexpr char S2C (char const (&s)[I]) - { - static_assert (I == 2, "only single octet strings may be converted"); - return s[0]; - } -+#endif - - /// Internal buffering class. Used to concatenate outgoing messages - /// and Lex incoming ones. -@@ -123,6 +132,13 @@ public: - Space (); - Append (str, maybe_quote, len); - } -+#if __cpp_char8_t >= 201811 -+ void AppendWord (char8_t const *str, bool maybe_quote = false, -+ size_t len = ~size_t (0)) -+ { -+ AppendWord ((const char *) str, maybe_quote, len); -+ } -+#endif - /// Add a word as with AppendWord - /// @param str the string to append - /// @param maybe_quote string might need quoting, as for Append -@@ -264,6 +280,12 @@ public: - : string (s), cat (STRING), code (c) - { - } -+#if __cpp_char8_t >= 201811 -+ Packet (unsigned c, const char8_t *s) -+ : string ((const char *) s), cat (STRING), code (c) -+ { -+ } -+#endif - Packet (unsigned c, std::vector &&v) - : vector (std::move (v)), cat (VECTOR), code (c) - { -diff --git a/libcody/server.cc b/libcody/server.cc -index e2fa069bb933..c18469fae843 100644 ---- a/libcody/server.cc -+++ b/libcody/server.cc -@@ -36,12 +36,12 @@ static RequestPair - const requestTable[Detail::RC_HWM] = - { - // Same order as enum RequestCode -- RequestPair {u8"HELLO", nullptr}, -- RequestPair {u8"MODULE-REPO", ModuleRepoRequest}, -- RequestPair {u8"MODULE-EXPORT", ModuleExportRequest}, -- RequestPair {u8"MODULE-IMPORT", ModuleImportRequest}, -- RequestPair {u8"MODULE-COMPILED", ModuleCompiledRequest}, -- RequestPair {u8"INCLUDE-TRANSLATE", IncludeTranslateRequest}, -+ RequestPair {(const char *) u8"HELLO", nullptr}, -+ RequestPair {(const char *) u8"MODULE-REPO", ModuleRepoRequest}, -+ RequestPair {(const char *) u8"MODULE-EXPORT", ModuleExportRequest}, -+ RequestPair {(const char *) u8"MODULE-IMPORT", ModuleImportRequest}, -+ RequestPair {(const char *) u8"MODULE-COMPILED", ModuleCompiledRequest}, -+ RequestPair {(const char *) u8"INCLUDE-TRANSLATE", IncludeTranslateRequest}, - }; - } - -@@ -135,21 +135,21 @@ void Server::ProcessRequests (void) - std::string msg; - - if (err > 0) -- msg = u8"error processing '"; -+ msg = (const char *) u8"error processing '"; - else if (ix >= Detail::RC_HWM) -- msg = u8"unrecognized '"; -+ msg = (const char *) u8"unrecognized '"; - else if (IsConnected () && ix == Detail::RC_CONNECT) -- msg = u8"already connected '"; -+ msg = (const char *) u8"already connected '"; - else if (!IsConnected () && ix != Detail::RC_CONNECT) -- msg = u8"not connected '"; -+ msg = (const char *) u8"not connected '"; - else -- msg = u8"malformed '"; -+ msg = (const char *) u8"malformed '"; - - read.LexedLine (msg); -- msg.append (u8"'"); -+ msg.append ((const char *) u8"'"); - if (err > 0) - { -- msg.append (u8" "); -+ msg.append ((const char *) u8" "); - msg.append (strerror (err)); - } - resolver->ErrorResponse (this, std::move (msg)); -@@ -176,7 +176,7 @@ Resolver *ConnectRequest (Server *s, Resolver *r, - return nullptr; - - if (words.size () == 3) -- words.emplace_back (u8""); -+ words.emplace_back ((const char *) u8""); - unsigned version = ParseUnsigned (words[1]); - if (version == ~0u) - return nullptr; diff --git a/meta/recipes-devtools/gcc/gcc/0029-build-Remove-INCLUDE_MEMORY-PR117737.patch b/meta/recipes-devtools/gcc/gcc/0029-build-Remove-INCLUDE_MEMORY-PR117737.patch deleted file mode 100644 index d784edefd76..00000000000 --- a/meta/recipes-devtools/gcc/gcc/0029-build-Remove-INCLUDE_MEMORY-PR117737.patch +++ /dev/null @@ -1,46 +0,0 @@ -From b3f1b9e2aa079f8ec73e3cb48143a16645c49566 Mon Sep 17 00:00:00 2001 -From: Andrew Pinski -Date: Fri, 22 Nov 2024 09:31:44 -0800 -Subject: [PATCH] build: Remove INCLUDE_MEMORY [PR117737] - -Since diagnostic.h is included in over half of the sources, requiring to `#define INCLUDE_MEMORY` -does not make sense. Instead lets unconditionally include memory in system.h. - -The majority of this patch is just removing `#define INCLUDE_MEMORY` from the sources which currently -have it. - -This should also fix the mingw build issue but I have not tried it. - -Signed-off-by: Andrew Pinski -Signed-off-by: Martin Jansa -Upstream-Status: Backport [gcc-15.1.0 b3f1b9e2aa07 partial, only the gcc/system.h change] ---- - gcc/system.h | 8 +------- - 1 file changed, 1 insertion(+), 7 deletions(-) - -diff --git a/gcc/system.h b/gcc/system.h -index c18c7c5ec58d..c209871df72d 100644 ---- a/gcc/system.h -+++ b/gcc/system.h -@@ -222,6 +222,7 @@ extern int fprintf_unlocked (FILE *, const char *, ...); - #ifdef INCLUDE_FUNCTIONAL - # include - #endif -+# include - # include - # include - # include -@@ -758,13 +759,6 @@ private: - #define LIKELY(x) (__builtin_expect ((x), 1)) - #define UNLIKELY(x) (__builtin_expect ((x), 0)) - --/* Some of the headers included by can use "abort" within a -- namespace, e.g. "_VSTD::abort();", which fails after we use the -- preprocessor to redefine "abort" as "fancy_abort" below. */ -- --#ifdef INCLUDE_MEMORY --# include --#endif - - #ifdef INCLUDE_MUTEX - # include diff --git a/meta/recipes-devtools/gcc/gcc/0030-build-Move-sstream-include-above-safe-ctype.h-PR1177.patch b/meta/recipes-devtools/gcc/gcc/0030-build-Move-sstream-include-above-safe-ctype.h-PR1177.patch deleted file mode 100644 index 270c91c345b..00000000000 --- a/meta/recipes-devtools/gcc/gcc/0030-build-Move-sstream-include-above-safe-ctype.h-PR1177.patch +++ /dev/null @@ -1,54 +0,0 @@ -From ac90b5c413c1565fb37cf79b92f6859b3852254a Mon Sep 17 00:00:00 2001 -From: Andrew Pinski -Date: Mon, 25 Nov 2024 14:03:27 -0800 -Subject: [PATCH] build: Move sstream include above safe-ctype.h {PR117771] - -sstream in some versions of libstdc++ include locale which might not have been -included yet. safe-ctype.h defines the toupper, tolower, etc. as macros so the -c++ header files needed to be included before hand as comment in system.h says: -/* Include C++ standard headers before "safe-ctype.h" to avoid GCC - poisoning the ctype macros through safe-ctype.h */ - -I don't understand how it was working before when memory was included after -safe-ctype.h rather than before. But this makes sstream consistent with the -other C++ headers. - -Pushed as obvious after a build for riscv64-elf. - -gcc/ChangeLog: - - PR target/117771 - * system.h: Move the include of sstream above safe-ctype.h. - -Signed-off-by: Andrew Pinski -Signed-off-by: Martin Jansa -Upstream-Status: Backport [gcc-15.1.0 f6e00226a4ca63e76e3e0b3a09a4ce6223980981] ---- - gcc/system.h | 7 +++---- - 1 file changed, 3 insertions(+), 4 deletions(-) - -diff --git a/gcc/system.h b/gcc/system.h -index 33245e76a986..ff983986153c 100644 ---- a/gcc/system.h -+++ b/gcc/system.h -@@ -222,6 +222,9 @@ extern int fprintf_unlocked (FILE *, const char *, ...); - #ifdef INCLUDE_FUNCTIONAL - # include - #endif -+#ifdef INCLUDE_SSTREAM -+# include -+#endif - # include - # include - # include -@@ -742,10 +745,6 @@ extern int vsnprintf (char *, size_t, const char *, va_list); - # include - #endif - --#ifdef INCLUDE_SSTREAM --# include --#endif -- - #ifdef INCLUDE_MALLOC_H - #if defined(HAVE_MALLINFO) || defined(HAVE_MALLINFO2) - #include diff --git a/meta/recipes-devtools/gcc/gcc_13.4.bb b/meta/recipes-devtools/gcc/gcc_13.5.bb similarity index 100% rename from meta/recipes-devtools/gcc/gcc_13.4.bb rename to meta/recipes-devtools/gcc/gcc_13.5.bb diff --git a/meta/recipes-devtools/gcc/libgcc-initial_13.4.bb b/meta/recipes-devtools/gcc/libgcc-initial_13.5.bb similarity index 100% rename from meta/recipes-devtools/gcc/libgcc-initial_13.4.bb rename to meta/recipes-devtools/gcc/libgcc-initial_13.5.bb diff --git a/meta/recipes-devtools/gcc/libgcc_13.4.bb b/meta/recipes-devtools/gcc/libgcc_13.5.bb similarity index 100% rename from meta/recipes-devtools/gcc/libgcc_13.4.bb rename to meta/recipes-devtools/gcc/libgcc_13.5.bb diff --git a/meta/recipes-devtools/gcc/libgfortran_13.4.bb b/meta/recipes-devtools/gcc/libgfortran_13.5.bb similarity index 100% rename from meta/recipes-devtools/gcc/libgfortran_13.4.bb rename to meta/recipes-devtools/gcc/libgfortran_13.5.bb From patchwork Wed Sep 23 09:10:32 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 98994 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id B26B2C9830B for ; Wed, 23 Sep 2026 09:12:05 +0000 (UTC) Received: from mail-wm2-f12.google.com (mail-wm2-f12.google.com [74.125.225.140]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.2828.1790154716015873304 for ; Wed, 23 Sep 2026 02:11:56 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=cmD/FpSF; spf=pass (domain: smile.fr, ip: 74.125.225.140, mailfrom: yoann.congal@smile.fr) Received: by mail-wm2-f12.google.com with SMTP id 5b1f17b1804b1-49cd4ba9f68so7457865e9.1 for ; Wed, 23 Sep 2026 02:11:55 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1790154714; x=1790759514; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=1yabCpIs1VnOtM4u0n156MGPtR4sOIPFzoZF6mYhfpY=; b=cmD/FpSFnw01BEIM0qtX0fl0E8ZKLq7GnU4V0+XfFZKwm6QKYzbxa8+kaplKim+FRz /d0WlBce0pXoU5tO0Lgfhkq7yUW/vTxdk6bdB5nO19FtWfy3trFYTifQPMQgHCUkAWUz dkRDqQ2e1LLlFWJ5GS4pwMCl9jxLc2zsjvRlU= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1790154714; x=1790759514; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=1yabCpIs1VnOtM4u0n156MGPtR4sOIPFzoZF6mYhfpY=; b=N8GLtiHnyJbbMqVTXhqG5Bz9TI0SUofArS3BAY8lGJ44D+UY1KCNXwyyZjc01u5a3f kp0Z2aofhPMUaMMtlCf1zVVBKUH9xB2yJtu88viTju90/8opt11/G+fiMFqucay5oorm YFPCsnIa53nnU2za5vKM7LZanYcqmbv+z7cIn3D+QeZms/RtqScuQreBYzTzuUTZXRpz Q8VAsCUG6nqugxmSsRPMh38dT4NUG/1KlTRTYzfWjKTBPrJxlr4uCWO5UpEHLX2C7z8f HIaWUNHNhOY7iux03MsKYjnHsCOhcrDIhd61amZHGRaqEHsjraUkffMGuQSIBNyKU7KQ B4ew== X-Gm-Message-State: AFuF++koerCem5HYnLZShKKqy9MCfuvvV0an/Z2xyp2Ro0YkpURRNOto uKjP7Yaox4XhxIRlzVcY4lRrrlIoTay6pCPZU9MTplnBPudaCznva+/Wbv2L4aC2Q7FksGqP3tX 8fyRxgMI= X-Gm-Gg: AYBFou1o8mtttTeLoXPwQZzHdnwy+xzuWpXefm6EPi3xC8/3/EAWcstZ0v3OppdpLjL UolHgszEIUGDhhU1IPSNwReCwmgYgut7WE5gZ420wyatNjW3sTp12ddGRRd7ts8MrfrjGQDiNwH IIaaSQVO0IGq6mYaMDdJqTM+SoUlv9X88dj+2QESUIf+4EYA3QoMe2q578a/EwF73pVr4EjvVF7 Qzs+ZBRrE46nJAl7y/2J4Rttv/MqeYi0vGFbS2pH+1WMmlTFfBOiy/BPoQfEjXDBKsOmQ5eGQVY nPNqXx1dmqArfGp10/Cds7WIETQVfOov3y7YHp4enp9PL3nwgiqd5pQNbjuAwtqEl5KTfJb2V2m YPpKya7QoIL4crelcwYAsoXRUDLA+K3Zh6kHB1qmw4VJsBnzKwuqRwkVMwuXgTK6jZ0I5T/dEGE ll+7GLkyhY8/8RaENDiMQnEmNL9dZcEc1xYtCbdAB8rEjY2KGgGowlNzXCWoTRQoqmbF45UROvo IHZTHRpJGCZkd4fHsrQ7TDE0EhI3skutgIzYzQpya8jNHWcLipEj911GyhEDg01nlFoJuap X-Received: by 2002:a05:600c:3e10:b0:49c:fc6e:8cb4 with SMTP id 5b1f17b1804b1-49fdf13951bmr23881485e9.24.1790154714169; Wed, 23 Sep 2026 02:11:54 -0700 (PDT) Received: from FRSMI25-LASER.home (2a02-8440-b519-f416-8bed-8817-19fd-ccf7.rev.sfr.net. [2a02:8440:b519:f416:8bed:8817:19fd:ccf7]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-49fe2730da9sm14251525e9.4.2026.09.23.02.11.52 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 23 Sep 2026 02:11:53 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][scarthgap 30/48] python3-git: fix CVE-2026-42215 Date: Wed, 23 Sep 2026 11:10:32 +0200 Message-ID: X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Wed, 23 Sep 2026 09:12:05 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/246492 From: Darsh Kelaiya This patch applies the upstream 3.1.47 backport for CVE-2026-42215. The upstream fix merge is referenced in [1], and the public CVE advisory is referenced in [2]. The individual backported commits are referenced in [3] and [4]. [1] https://github.com/gitpython-developers/GitPython/commit/0f68db0710f9125762fca5dbc2328593537ae923 [2] https://nvd.nist.gov/vuln/detail/CVE-2026-42215 [3] https://github.com/gitpython-developers/GitPython/commit/142195888e713542189533a52cdfc333f05c3af6 [4] https://github.com/gitpython-developers/GitPython/commit/43d92dec4683568d11495956dd556161f17c3ea8 Signed-off-by: Darsh Kelaiya Signed-off-by: Yoann Congal --- .../python3-git/CVE-2026-42215_p1.patch | 61 +++++++++++++++++++ .../python3-git/CVE-2026-42215_p2.patch | 47 ++++++++++++++ .../python/python3-git_3.1.42.bb | 2 + 3 files changed, 110 insertions(+) create mode 100644 meta/recipes-devtools/python/python3-git/CVE-2026-42215_p1.patch create mode 100644 meta/recipes-devtools/python/python3-git/CVE-2026-42215_p2.patch diff --git a/meta/recipes-devtools/python/python3-git/CVE-2026-42215_p1.patch b/meta/recipes-devtools/python/python3-git/CVE-2026-42215_p1.patch new file mode 100644 index 00000000000..9d5f10c6943 --- /dev/null +++ b/meta/recipes-devtools/python/python3-git/CVE-2026-42215_p1.patch @@ -0,0 +1,61 @@ +From 341a49149a37762e12b10eb70605b54f4abfb54d Mon Sep 17 00:00:00 2001 +From: w +Date: Mon, 20 Apr 2026 23:29:50 -0400 +Subject: [PATCH] Block unsafe underscored git kwargs / Fix for + GHSA-rpm5-65cw-6hj4 + +CVE: CVE-2026-42215 +Upstream-Status: Backport [https://github.com/gitpython-developers/GitPython/commit/142195888e713542189533a52cdfc333f05c3af6] + +Backport Changes: +- Omit regression tests because the Scarthgap PyPI source + archive does not include the upstream test suite. + +(cherry picked from commit 142195888e713542189533a52cdfc333f05c3af6) +Signed-off-by: Darsh Kelaiya +--- + git/cmd.py | 21 +++++++++++++-------- + 1 file changed, 13 insertions(+), 8 deletions(-) + +diff --git a/git/cmd.py b/git/cmd.py +index f58e6df5..874acb43 100644 +--- a/git/cmd.py ++++ b/git/cmd.py +@@ -540,6 +540,12 @@ class Git(LazyMixin): + f"The `{protocol}::` protocol looks suspicious, use `allow_unsafe_protocols=True` to allow it." + ) + ++ @classmethod ++ def _canonicalize_option_name(cls, option: str) -> str: ++ """Normalize an option or kwarg name for unsafe-option checks.""" ++ option_name = option.lstrip("-").split("=", 1)[0].split(None, 1)[0] ++ return dashify(option_name) ++ + @classmethod + def check_unsafe_options(cls, options: List[str], unsafe_options: List[str]) -> None: + """Check for unsafe options. +@@ -547,15 +553,14 @@ class Git(LazyMixin): + Some options that are passed to `git ` can be used to execute + arbitrary commands, this are blocked by default. + """ +- # Options can be of the form `foo` or `--foo bar` `--foo=bar`, +- # so we need to check if they start with "--foo" or if they are equal to "foo". +- bare_unsafe_options = [option.lstrip("-") for option in unsafe_options] ++ # Options can be of the form `foo`, `--foo`, `--foo bar`, or `--foo=bar`. ++ canonical_unsafe_options = {cls._canonicalize_option_name(option): option for option in unsafe_options} + for option in options: +- for unsafe_option, bare_option in zip(unsafe_options, bare_unsafe_options): +- if option.startswith(unsafe_option) or option == bare_option: +- raise UnsafeOptionError( +- f"{unsafe_option} is not allowed, use `allow_unsafe_options=True` to allow it." +- ) ++ unsafe_option = canonical_unsafe_options.get(cls._canonicalize_option_name(option)) ++ if unsafe_option is not None: ++ raise UnsafeOptionError( ++ f"{unsafe_option} is not allowed, use `allow_unsafe_options=True` to allow it." ++ ) + + class AutoInterrupt: + """Process wrapper that terminates the wrapped process on finalization. +-- +2.35.6 diff --git a/meta/recipes-devtools/python/python3-git/CVE-2026-42215_p2.patch b/meta/recipes-devtools/python/python3-git/CVE-2026-42215_p2.patch new file mode 100644 index 00000000000..cef3fe6b015 --- /dev/null +++ b/meta/recipes-devtools/python/python3-git/CVE-2026-42215_p2.patch @@ -0,0 +1,47 @@ +From 3385ff27397b58288d922838e8d2eae87d7534fd Mon Sep 17 00:00:00 2001 +From: w +Date: Tue, 21 Apr 2026 12:03:20 -0400 +Subject: [PATCH] git.cmd: harden unsafe option canonicalization and isolate + push test cases + +CVE: CVE-2026-42215 +Upstream-Status: Backport [https://github.com/gitpython-developers/GitPython/commit/43d92dec4683568d11495956dd556161f17c3ea8] + +Backport Changes: +- Omit regression test updates because the Scarthgap PyPI + source archive does not include the upstream test suite. + +(cherry picked from commit 43d92dec4683568d11495956dd556161f17c3ea8) +Signed-off-by: Darsh Kelaiya +--- + git/cmd.py | 15 ++++++++++++--- + 1 file changed, 12 insertions(+), 3 deletions(-) + +diff --git a/git/cmd.py b/git/cmd.py +index 69756216..73b4c052 100644 +--- a/git/cmd.py ++++ b/git/cmd.py +@@ -542,9 +542,18 @@ class Git(LazyMixin): + + @classmethod + def _canonicalize_option_name(cls, option: str) -> str: +- """Normalize an option or kwarg name for unsafe-option checks.""" +- option_name = option.lstrip("-").split("=", 1)[0].split(None, 1)[0] +- return dashify(option_name) ++ """Return the option name used for unsafe-option checks. ++ ++ Examples: ++ ``"--upload-pack=/tmp/helper"`` -> ``"upload-pack"`` ++ ``"upload_pack"`` -> ``"upload-pack"`` ++ ``"--config core.filemode=false"`` -> ``"config"`` ++ """ ++ option_name = option.lstrip("-").split("=", 1)[0] ++ option_tokens = option_name.split(None, 1) ++ if not option_tokens: ++ return "" ++ return dashify(option_tokens[0]) + + @classmethod + def check_unsafe_options(cls, options: List[str], unsafe_options: List[str]) -> None: +-- +2.35.6 diff --git a/meta/recipes-devtools/python/python3-git_3.1.42.bb b/meta/recipes-devtools/python/python3-git_3.1.42.bb index 8c130cf63b4..38fbd8a078b 100644 --- a/meta/recipes-devtools/python/python3-git_3.1.42.bb +++ b/meta/recipes-devtools/python/python3-git_3.1.42.bb @@ -19,6 +19,8 @@ SRC_URI += "file://CVE-2026-42284.patch \ file://CVE-2026-44243_p2.patch \ file://CVE-2026-44244_p1.patch \ file://CVE-2026-44244_p2.patch \ + file://CVE-2026-42215_p1.patch \ + file://CVE-2026-42215_p2.patch \ " SRC_URI[sha256sum] = "2d99869e0fef71a73cbd242528105af1d6c1b108c60dfabd994bf292f76c3ceb" From patchwork Wed Sep 23 09:10:33 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 98992 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id BF972C98308 for ; Wed, 23 Sep 2026 09:12:05 +0000 (UTC) Received: from mail-wm2-f12.google.com (mail-wm2-f12.google.com [74.125.225.140]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.2930.1790154718096834259 for ; Wed, 23 Sep 2026 02:11:58 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=Ohx/fljL; spf=pass (domain: smile.fr, ip: 74.125.225.140, mailfrom: yoann.congal@smile.fr) Received: by mail-wm2-f12.google.com with SMTP id 5b1f17b1804b1-49b912d37b5so3845615e9.2 for ; Wed, 23 Sep 2026 02:11:57 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1790154716; x=1790759516; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=gJfJ5Q/HZPO6KbD981RWdPHdpMCy0Fg3pT7+jC0tYtA=; b=Ohx/fljLdUQZqdH+rDQVVmMLAQj59k6z2ptxjlIyXRT8jseIvYVpgT469YKq2j90Bk cz7ZtkQwliUsmqlQBhm+xinL4QkTaQi7Fter4YEktNN8JJNPHRKul16Qy8EL6r+0k1pv Qpu+sIXO4Yl7+rjSH5A4eVE4yDHu8dRy3DCrY= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1790154716; x=1790759516; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=gJfJ5Q/HZPO6KbD981RWdPHdpMCy0Fg3pT7+jC0tYtA=; b=HwJnmzkGfFBsUkv6T6Fje2SEfSbEcgCZiVw4SgERnYiURZ2FGp8Nj0gtE5K9rxC5lT j8BZflX5LvxvrHzkaeJOqSOrjn2N3fc+hAwT4TyV4bue4yl0Z3raQ0h4095aUmbxyPia Jv4iUg7TnznqrMvYWlaMBWW671Hs77/60PU4umKihkhMUnj8Cx9VxNEGjPfTs8eqpS8Z h1bvNjfZd4kHzc3UC5ebeP1H7zoNWai81TVJAIi4BV+R1McSAvIwOxr+mj5Qn8ixP9TF 1XL8iKQ+KJ+iu74aqm+6gJtQgmrBapFCF+eC53iar6XibMIRlm1CK4FDHJYcF8cUo37A okBw== X-Gm-Message-State: AFuF++nFtra3qGrsTsapqYnYD6SMHZi7DZt1mX/dCw74+FlJeFED9eXU 5LLe+3KK+VZRKbubFwziUt2C+S5p/SVtuMHXal3qzEe07b4yQt2KRvwj5FCH0dhFatg+p1/XWOe dRE6cu3s= X-Gm-Gg: AYBFou0rM3vP05poKQ/UcAhlXIQypRuYTHpfJc1N6ByzDrjrKqXUN+4f9MbimACj8yl tMlDAIGXFwKq7iogqKCTTOBGRqul9TMJ+2f09GgVzORdVPMcnYBaRC01p8EC5uxPy1N5W7jnIVo gjeOqUr8jPKg/6sBq+AYEKKsWWEjzG1KF/CF+fVh9eyYYSUwCXUahJMGZewuXNuDVjsqao528GH o3lgG/qXfDOp6IKrSWhjy3xLXiqsy28iOiOPtqYSSgCYOQrhMcbNhKhjzKihkFfzSSuVon5uZ3q n/tH0ZmT2oT0lM2dUkK7y0JfeabEkmlMEuBsvHm2HzQ+Kccd0j7tlW+5wZhXACLpOYmykeTsa4G Twh0J8ZQ8nfNlFj2IbMHXOn4gkM0lDUjEM6mnl5S1RlB2ukDTBHSHza9L2WsY32SHyHhqE6wx1L idwyER/5q9L0mEMTRjSv5uVAgOYUFvD4x32m7UDNUxIncpfns5YoWUUpMq21hwiAY3+Fx/uFqa8 wsgAT85oJL7uHBdPIhXb93L67t+8A5O4EZs9IqHhr3/SlQVp7oVn0av+/uDsVyT/yzSpIQe/xG2 aDWst2E= X-Received: by 2002:a05:600c:3b84:b0:49c:ff8d:b548 with SMTP id 5b1f17b1804b1-49fdecd5957mr29436575e9.11.1790154716289; Wed, 23 Sep 2026 02:11:56 -0700 (PDT) Received: from FRSMI25-LASER.home (2a02-8440-b519-f416-8bed-8817-19fd-ccf7.rev.sfr.net. [2a02:8440:b519:f416:8bed:8817:19fd:ccf7]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-49fe2730da9sm14251525e9.4.2026.09.23.02.11.54 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 23 Sep 2026 02:11:55 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][scarthgap 31/48] scripts/install-buildtools: Update to 5.0.20 Date: Wed, 23 Sep 2026 11:10:33 +0200 Message-ID: <955e0ed1c6651f0a1d18d0c9bee5f6ef494cd189.1790154074.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Wed, 23 Sep 2026 09:12:05 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/246493 From: Yoann Congal Update to the 5.0.20 release of the 5.0 series for buildtools Signed-off-by: Yoann Congal --- scripts/install-buildtools | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/scripts/install-buildtools b/scripts/install-buildtools index 65200e0cf49..f33f192e468 100755 --- a/scripts/install-buildtools +++ b/scripts/install-buildtools @@ -57,8 +57,8 @@ logger = scriptutils.logger_create(PROGNAME, stream=sys.stdout) DEFAULT_INSTALL_DIR = os.path.join(os.path.split(scripts_path)[0],'buildtools') DEFAULT_BASE_URL = 'https://downloads.yoctoproject.org/releases/yocto' -DEFAULT_RELEASE = 'yocto-5.0.19' -DEFAULT_INSTALLER_VERSION = '5.0.19' +DEFAULT_RELEASE = 'yocto-5.0.20' +DEFAULT_INSTALLER_VERSION = '5.0.20' DEFAULT_BUILDDATE = '202110XX' # Python version sanity check From patchwork Wed Sep 23 09:10:34 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 98995 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id D380FC9830C for ; Wed, 23 Sep 2026 09:12:05 +0000 (UTC) Received: from mail-wm2-f13.google.com (mail-wm2-f13.google.com [74.125.225.141]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.2931.1790154719461847047 for ; Wed, 23 Sep 2026 02:11:59 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=n8gDcwPn; spf=pass (domain: smile.fr, ip: 74.125.225.141, mailfrom: yoann.congal@smile.fr) Received: by mail-wm2-f13.google.com with SMTP id 5b1f17b1804b1-49b912d3931so4776065e9.3 for ; Wed, 23 Sep 2026 02:11:59 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1790154718; x=1790759518; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=drGwC4eMyxlu2SEFRs/EPJszD+oNO4HA6d08cOR+CxA=; b=n8gDcwPnFoCb5ADbpNsOBybEv7gNfsAmldyiov6xAf1GEu0ftL3uO+UCi39ml580Y2 UKaQkaV1ASN1+kD23E43zG1qCPNEzqg9cRb/XOV65/iZXbbqztQ+CHQ68VN9LCGt2VRU 96uAMN2AUhI3LCDBwGkrzI0gD61HV5WT16gJM= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1790154718; x=1790759518; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=drGwC4eMyxlu2SEFRs/EPJszD+oNO4HA6d08cOR+CxA=; b=p6HjtB1DxfXPKpt0KBOn7LPC3dO+rcdpgHna1DL62kc5te7PI4pvyExxwpWzATivfw YJHJfqgtLvP3AZfJNUCZjm7AazouwUAWWhBgcvLd45clnRED6/TikqTB3/OXtdXEnNDY 4pQfuq7cXBscaAjHJ6/3rXHr/PZzPTOTUU5XCR/VlmOxgGa/YPtZgcLm7Dz+uhE4QDRh 77YBpbkoa0YYEjgQfZ46WZcQeN1dB2PRQP9HXCE7AB3pcdkvQRROdHixIdsqMPnHle9G 7uDH9euKVwTb25i2AvBCzfL3oIBh+OkanIhL+sJ9Roe9oWdwjmQNZDDCxrCrMnoccBqB Aw9g== X-Gm-Message-State: AFuF++ljeKTMWVaTW3xa+rVRZ5RlkSJEWh3g8IrRt8ZAUB9zSQMge53m JsiuIvUuXNxuEYM8lC+lkbn5OAsG3LygHmzk8xe2RTAia4cAhXnMIbdY+Y5l8IxOp0OB6SUpKQA TUKfMQtE= X-Gm-Gg: AYBFou2lf+lr/rMuIeLsQGltKFIvMr3Zc180zbMP4SaBf7Wr19aDcK9VxXl0Cwd5zB/ BFZ3QSjjSlUF0ZEl37zBlS6CM7S1xLYTiP1J8HOWFLcnmeM7kMfw4AQbGtNJaPk35x580x1uPeX X+EQaZ1995aJzMbM4y3zeIcXeRRN6yBneebbsZEtruYZFA6i9Y/N0RMu5a2YxADWeWlS+RNHEnR g+zmobIVCBETDt9XGI+QNiQUguH9WCrnPDYlmAalWHh/gr6DRGTz2Rr9VxjONefwTfZ1plGKl9Y UZ4Ak7ESuGSV7R9F3aiH1x1WKfian8ymwTqTvQvap05WOs9DGTM3efBmVX1Njcpw3f4Fle3aKet dQK1p4pIlVRgQEkP1M3vDKbYa4Q7t1uy5djwTjbWjzYA3k6+7f2C9l+sk3x7fQezbnaTOxpApfQ Rc3ZLglTPha0lQN4Lb1BtjCfKOSNn2fmfIqlKxc0Yo0+BrTYhJSxo++dBp89AcQmFY5clCr42X1 4JdROthd/5rORpQT24cqJtxsE9svn0To67nlU6SX2m8BKwHbsY2dwovcAyg/r7KxdJ6hOMJwct8 m3EVAfs= X-Received: by 2002:a05:600c:a307:b0:49f:e3f2:f5a3 with SMTP id 5b1f17b1804b1-49fe3f2f5d4mr2769935e9.0.1790154717624; Wed, 23 Sep 2026 02:11:57 -0700 (PDT) Received: from FRSMI25-LASER.home (2a02-8440-b519-f416-8bed-8817-19fd-ccf7.rev.sfr.net. [2a02:8440:b519:f416:8bed:8817:19fd:ccf7]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-49fe2730da9sm14251525e9.4.2026.09.23.02.11.56 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 23 Sep 2026 02:11:57 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][scarthgap 32/48] spdx30_tasks: Fix SPDX_CUSTOM_ANNOTATION_VARS implementation Date: Wed, 23 Sep 2026 11:10:34 +0200 Message-ID: X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Wed, 23 Sep 2026 09:12:05 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/246494 From: Stefano Tondo Fix incorrect function call when processing SPDX_CUSTOM_ANNOTATION_VARS. The code was calling new_annotation() as a standalone function, but it should be called as a method on the build_objset object. Error: new_annotation(d, build_objset, build, ...) Corrected to: build_objset.new_annotation(d, build_objset, build, ...) This bug would cause a NameError at runtime if SPDX_CUSTOM_ANNOTATION_VARS was set to a non-empty value, preventing SPDX document generation. The fix aligns with how new_annotation() is called elsewhere in the codebase and matches the SBOMObjset class method signature. Signed-off-by: Stefano Tondo Signed-off-by: Mathieu Dubois-Briand (cherry picked from commit 52ab3b640c6bb7ece34cb4ea6026fd6375f17af4) Cc: Joshua Watt Signed-off-by: Yoann Congal [YC: Link: https://lore.kernel.org/all/CAJdd5GaqcWujQae-GXQpcgAGtosHe7_X0T%2B8LyOfrr8-mOgzLA@mail.gmail.com/ ] --- meta/lib/oe/spdx30_tasks.py | 4 +- meta/lib/oeqa/selftest/cases/spdx.py | 74 ++++++++++++++++++++++++++++ 2 files changed, 75 insertions(+), 3 deletions(-) diff --git a/meta/lib/oe/spdx30_tasks.py b/meta/lib/oe/spdx30_tasks.py index b43d626df36..0e9c6faf5cc 100644 --- a/meta/lib/oe/spdx30_tasks.py +++ b/meta/lib/oe/spdx30_tasks.py @@ -517,9 +517,7 @@ def create_spdx(d): build_objset.set_is_native(is_native) for var in (d.getVar("SPDX_CUSTOM_ANNOTATION_VARS") or "").split(): - new_annotation( - d, - build_objset, + build_objset.new_annotation( build, "%s=%s" % (var, d.getVar(var)), oe.spdx30.AnnotationType.other, diff --git a/meta/lib/oeqa/selftest/cases/spdx.py b/meta/lib/oeqa/selftest/cases/spdx.py index 3373988ca40..5f75b077252 100644 --- a/meta/lib/oeqa/selftest/cases/spdx.py +++ b/meta/lib/oeqa/selftest/cases/spdx.py @@ -343,3 +343,77 @@ class SPDX30Check(SPDX3CheckBase, OESelftestTestCase): value, ["enabled", "disabled"], f"Unexpected PACKAGECONFIG value '{value}' for {key}" ) + + def test_custom_annotation_vars(self): + """ + Test that SPDX_CUSTOM_ANNOTATION_VARS properly creates annotations + without runtime errors. This is a regression test for the bug where + new_annotation() was called as a standalone function instead of as + a method on build_objset, causing a NameError. + + The test verifies: + 1. The build completes successfully (no NameError) + 2. Each configured annotation variable appears exactly once + 3. The annotation values match the configured variables + + We check for exact equality (not >=) to prevent regressions where + one annotation might appear multiple times while another is missing. + """ + ANNOTATION_VAR1 = "TestAnnotation1" + ANNOTATION_VAR2 = "TestAnnotation2" + + # This will fail with NameError if new_annotation() is called incorrectly + objset = self.check_recipe_spdx( + "base-files", + "{DEPLOY_DIR_SPDX}/{MACHINE_ARCH}/recipes/recipe-base-files.spdx.json", + extraconf=textwrap.dedent( + f"""\ + ANNOTATION1 = "{ANNOTATION_VAR1}" + ANNOTATION2 = "{ANNOTATION_VAR2}" + SPDX_CUSTOM_ANNOTATION_VARS = "ANNOTATION1 ANNOTATION2" + """ + ), + ) + + # If we got here, the build succeeded (no NameError) + # Now verify the annotations were actually created + + # Find the build element + build = None + for o in objset.foreach_type(oe.spdx30.build_Build): + build = o + break + + self.assertIsNotNone(build, "Unable to find Build element") + + # Find annotation objects that reference our build + found_annotations = [] + for obj in objset.objects: # <-- Remove parentheses + if isinstance(obj, oe.spdx30.Annotation): + if hasattr(obj, "subject") and build._id == obj.subject._id: + found_annotations.append(obj) + + # Check each annotation separately to ensure exactly one occurrence of each + annotation1_count = 0 + annotation2_count = 0 + + for annotation in found_annotations: + if hasattr(annotation, "statement"): + if f"ANNOTATION1={ANNOTATION_VAR1}" in annotation.statement: + annotation1_count += 1 + self.logger.info(f"Found ANNOTATION1: {annotation.statement}") + if f"ANNOTATION2={ANNOTATION_VAR2}" in annotation.statement: + annotation2_count += 1 + self.logger.info(f"Found ANNOTATION2: {annotation.statement}") + + # Each annotation should appear exactly once + self.assertEqual( + annotation1_count, + 1, + f"Expected exactly 1 occurrence of ANNOTATION1, found {annotation1_count}", + ) + self.assertEqual( + annotation2_count, + 1, + f"Expected exactly 1 occurrence of ANNOTATION2, found {annotation2_count}", + ) From patchwork Wed Sep 23 09:10:35 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 98990 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 7A83DC982FA for ; Wed, 23 Sep 2026 09:12:05 +0000 (UTC) Received: from mail-wm2-f12.google.com (mail-wm2-f12.google.com [74.125.225.140]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.2831.1790154721603854442 for ; Wed, 23 Sep 2026 02:12:01 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=UgeF+LDj; spf=pass (domain: smile.fr, ip: 74.125.225.140, mailfrom: yoann.congal@smile.fr) Received: by mail-wm2-f12.google.com with SMTP id 5b1f17b1804b1-49ccead2aecso2911075e9.0 for ; Wed, 23 Sep 2026 02:12:01 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1790154720; x=1790759520; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=wtrnI8d8Nu6VarTVw/f516xLkysqwscMSo181+GAnlw=; b=UgeF+LDjnvfhdGlFnGAPfTULqelR8AyMs7Fzps9KydFugmRrrVPi611/rLeIHUc07V iYKicFAZtQCSqWM7Nh9kCF6yOBRniWx4G6jMXYQqB+og846ZaHWEhisdG5Xsj6fFoirH 4vqDfVdpRx7CVaIFsvHHPHRzH4ELzhrsUpQoM= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1790154720; x=1790759520; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=wtrnI8d8Nu6VarTVw/f516xLkysqwscMSo181+GAnlw=; b=H3VhSRtmvFkBHTINVRm3Rmzr5YfbGND9UhI59VJJQqhw7gJ7l1m9KPrTD4ngebaNEb ie2VbdZwYrQj6SNzo/abk22BsQu9nKNOT5EQQtdVONIxnk2+lxVDfqKZnf0RwrN2+s6v s4XE7MQ8n5dg1FWShECkBhMHdPKxQjASzBXXXMRDUBFcgXJLmjetzzFvfGjL4NAW1+qV NBPKE4AlgXs68SFRPmh+q4Ll07cATE++dcd941WRKyjL15l6KEy/M8W2M8EePpwV745G 704QEi4aRJ0PznDWAcPHIK9BXPPddxPGGVNdF1Ds5ztbJ6/IK87JxazW3TpTHbSFh1TM R1kg== X-Gm-Message-State: AFuF++nIDvu4nzAziAnSPy4lFSOKvmZhlkyJIgX8FLraRy1GOp6XkfJX vTwhKVJeW/h70R/UZKkfxg/rZagyuTphux4fHcoWHM+sxoVwC0U3GsqyvNp8qlbzZXK/FoO1x/x aAs0ZrWM= X-Gm-Gg: AYBFou3XHR0bHaF8TjYsTL8UOjjxiGnsDJ0bV1o8Yj4CwruT+78ZdwV19Edk4SlRJ/I SPNRv1+1B7EcphHWfM+6SHzwIkGeChPH6UyjEO+3gfPjjW7sdW9WTT03FwzBXE4nY6ASsFSy/ma YW9NlxqhSooO7j0wJRLoYEPh/29UyT7+quSyL0n/b3k+7tJvnBz54RLp6ZWuaOFh37faW8XvMoZ yM3VPi2Z8Bm75LW8X3EOzntr5Ikbj6HgXjZRe7qr+7/4oqBEfuaiJBBkntX0UkQ+NIpbGT6hXfc 0dBpoHbgDBQ4mhTuztW1WzMIlmtgCtWkfHYEP/j8w5PEfCpzdbnc7VN9e1dVVlMopg6K5UHJAaZ ucVKuspMA0SCaRuxPmPx+X68STlUtynoSZEtEvtlm6uFb3hfsxz0C5cIbunPsMgbOZk1aP7v9sb qxIasZf65zpomENrrRivQd7bjuw3iVvPKxg2T99WLfUKZKCUtdyBhT6EpVYv4RJDT1OzkKDuU9L PbcS/w8e4reFuy8bHCzfmU7L7NaWIBHtG/hwYM/W+cISTmXnoelVpn/cSaWO3cakyWdfzzSJDg/ WUZ4xCdGITDXjh8/61s= X-Received: by 2002:a05:600c:1549:b0:49f:ce73:7ac with SMTP id 5b1f17b1804b1-49fdf352358mr23220625e9.35.1790154719451; Wed, 23 Sep 2026 02:11:59 -0700 (PDT) Received: from FRSMI25-LASER.home (2a02-8440-b519-f416-8bed-8817-19fd-ccf7.rev.sfr.net. [2a02:8440:b519:f416:8bed:8817:19fd:ccf7]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-49fe2730da9sm14251525e9.4.2026.09.23.02.11.57 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 23 Sep 2026 02:11:59 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][scarthgap 33/48] python3: skip ptest incompatible with ptest-runner >= 2.5.0 Date: Wed, 23 Sep 2026 11:10:35 +0200 Message-ID: <4e337750e8031603c9678206374741e5bf035e2d.1790154074.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Wed, 23 Sep 2026 09:12:05 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/246495 From: Yoann Congal With ptest-runner >= 2.5.0, ptests run with PYTHONUNBUFFERED="1" envvar to unbuffer the python output (to fix AB-INT timeout issues). A python3 test, "test_cmd_line.test_non_interactive_output_buffering", expects buffered output and fails on unbuffered output, skip it. See https://github.com/python/cpython/issues/128377. Note: upstream fix also skip it on PYTHONUNBUFFERED!=0: https://github.com/python/cpython/commit/30268b5d2fbb1a5e6c876f0cdc4cbdb5d93315e6 Signed-off-by: Yoann Congal --- meta/recipes-devtools/python/python3_3.12.14.bb | 6 ++++++ 1 file changed, 6 insertions(+) diff --git a/meta/recipes-devtools/python/python3_3.12.14.bb b/meta/recipes-devtools/python/python3_3.12.14.bb index 7ee32601cd3..14be125180b 100644 --- a/meta/recipes-devtools/python/python3_3.12.14.bb +++ b/meta/recipes-devtools/python/python3_3.12.14.bb @@ -260,6 +260,12 @@ SKIPPED_TESTS = " \ --ignore test.test_tracemalloc.TestCAPI.test_tracemalloc_track_race \ " +# With ptest-runner >= 2.5.0, ptests run with PYTHONUNBUFFERED="1" envvar. +# test_cmd_line.test_non_interactive_output_buffering expects buffered ouput, +# skip it. +# See: https://github.com/python/cpython/issues/128377 +SKIPPED_TESTS += "--ignore test.test_cmd_line.CmdLineTest.test_non_interactive_output_buffering" + SKIPPED_TESTS:append:class-target:libc-musl = " \ -x test__locale \ -x test_c_locale_coercion \ From patchwork Wed Sep 23 09:10:36 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 98993 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 887EBC98307 for ; Wed, 23 Sep 2026 09:12:05 +0000 (UTC) Received: from mail-wm2-f12.google.com (mail-wm2-f12.google.com [74.125.225.140]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.2934.1790154723365992868 for ; Wed, 23 Sep 2026 02:12:03 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=wRKcnGfu; spf=pass (domain: smile.fr, ip: 74.125.225.140, mailfrom: yoann.congal@smile.fr) Received: by mail-wm2-f12.google.com with SMTP id 5b1f17b1804b1-49b912e2406so3115755e9.1 for ; Wed, 23 Sep 2026 02:12:03 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1790154722; x=1790759522; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=mX2jC0E9/FOn9xm+GEH6q1vkYb9/MdRRNQuZEZJ7pnY=; b=wRKcnGfu/nZ40olIYMl3a5Kmzd1vfQhdwkl/U6nuZgv+w7lGkJWLckmYMoRiS4Ifhw tocTf7MMMFut/vdA3qXxj0tFb7hiSme6Vw9MNEfVcdUg9KsVLuxiE4X8uRjSxZMPaC/9 eMeFi9VCi59O3KUm+5O36zj+5I6tTdn9JNJJ4= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1790154722; x=1790759522; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=mX2jC0E9/FOn9xm+GEH6q1vkYb9/MdRRNQuZEZJ7pnY=; b=EcViMvhgfEWlvFlkMBTFgHAeocQNeGGHoQG1tvLfCunsyTc9EleGaOHwLya7BliKy5 k4wkMTMXGpDoj7ePdETDvkIZ5JmnDHuapVj77IEC3S1PQloZoPWJcwxnjTglhvEI0Je5 sD9im7TrykNbwO8Fhhy7XelM6NQWzQQahQsivd8JKUixG0NJLNqBfrwGy86viuKBl9S8 U+8HhoZk0akbERmGsgsvClOiJV4OQIZACnQpURvaEdpA4A6zLgWb1iYOn6jevrXiTGv2 kC6+b9sQnOiyhpeZ60bM9E0BDzTlI9TCIypxSxpEVmFS5aNQUW2RKJX8ptORfVmHyo6m fuVg== X-Gm-Message-State: AFuF++kK5lp3fXDwrkr+7p3MDt7vri4rKLp2+K7PaiVwPTORFlYoLS6e qoEWfKsGUeN/1LahRwaa5Du51rm6rZrIx0bQkukqWuodU8DMaSpn4Nm1QZfavGXyBX6ZPPARF8V 1wUjpmes= X-Gm-Gg: AYBFou39QMlGqvG/F1jPYMS7VDGGdfjugk7TeUoeg6L1k+Oz1U8SpwGsXgu/VTQRlua N6S6iIPXC0w8II0xCGPuOwdsPa62KkaA2nmS3sAT4kQakP71zu7zMqxIQf9OI3w7A6ei1G0IXi8 IqfVgCyCCxFEzTSnJdS8IgQ8ftC4v3GtCEjqiDyFimrqBJ+Qi7PgjJhETfhKGOxDrX6VVLGTuhQ a2m0dCl3hmBgos9v9aw0iMTx3RUu18ijLnlqU4csQKBXL2DP4cnwD9nVX3IV0m49CtFEN8g4Z5A Dhm/aUQB14di6O3+ZqS2cErFQBXaRsTJQ6Hq68N7KxOsl3grjPtv3z/mCFEoOg95Ds4750nu8WC 060tntVe33ngoEpnvRdVOi73RjQh/wBvosHG2bDdSXNppnj1/KL4A+GdQ8qlHcQtWwttP+TQJE/ rfymxPY1ATHfcb/RufNRy1E+qF0E8BFfcLZ2idwZos+u7Q92eB62ReRLe6cL4kk/r8lFvy9Q5kU cbtv6aQI/0aTF9wbFMJ9GcGA5OlLQu3NpfXSRzzgVo0OUFcCfD/4lJr7Hn+G/nI7eYUg+TvmUaR 81G53L9L X-Received: by 2002:a05:600c:4745:b0:49e:6581:7baf with SMTP id 5b1f17b1804b1-49fde3601bdmr30100875e9.2.1790154721727; Wed, 23 Sep 2026 02:12:01 -0700 (PDT) Received: from FRSMI25-LASER.home (2a02-8440-b519-f416-8bed-8817-19fd-ccf7.rev.sfr.net. [2a02:8440:b519:f416:8bed:8817:19fd:ccf7]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-49fe2730da9sm14251525e9.4.2026.09.23.02.12.00 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 23 Sep 2026 02:12:01 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][scarthgap 34/48] ptest-runner: upgrade 2.4.5 -> 2.4.5.1 Date: Wed, 23 Sep 2026 11:10:36 +0200 Message-ID: <6688fc0df342dfb75061647462e36590dc5175ca.1790154074.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Wed, 23 Sep 2026 09:12:05 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/246496 From: Wang Mingyu This is 2 commits squashed: | ptest-runner: upgrade 2.4.5 -> 2.5.1 | | Signed-off-by: Wang Mingyu | Signed-off-by: Mathieu Dubois-Briand | Signed-off-by: Richard Purdie | (cherry picked from commit d4497ba3fed93807f59c00925056aa21e72c2189) |ptest-runner: correct PV from 2.5.1 to 2.4.5.1 | |2.4.5.1 is an actual version, 2.5.1 was a typo mistake. |That merged less than an hour ago, so no one should |trip over version going backwards hopefully. | |Signed-off-by: Alexander Kanavin |Signed-off-by: Richard Purdie |(cherry picked from commit d5e0f51bccae7410b10c98a93fa5853155c2f59e) Changelog: https://git.yoctoproject.org/ptest-runner2/log/?h=v2.4.5.1 * Makefile: use pkg-config to obtain libcheck flags * Makefile: remove redundant rule * README.md: Add my cc to be aware of patches * README: Update mailing list address for patches + add git command Signed-off-by: Yoann Congal --- .../{ptest-runner_2.4.5.bb => ptest-runner_2.4.5.1.bb} | 3 +-- 1 file changed, 1 insertion(+), 2 deletions(-) rename meta/recipes-support/ptest-runner/{ptest-runner_2.4.5.bb => ptest-runner_2.4.5.1.bb} (94%) diff --git a/meta/recipes-support/ptest-runner/ptest-runner_2.4.5.bb b/meta/recipes-support/ptest-runner/ptest-runner_2.4.5.1.bb similarity index 94% rename from meta/recipes-support/ptest-runner/ptest-runner_2.4.5.bb rename to meta/recipes-support/ptest-runner/ptest-runner_2.4.5.1.bb index d28ae7ca91b..9f6bb399b40 100644 --- a/meta/recipes-support/ptest-runner/ptest-runner_2.4.5.bb +++ b/meta/recipes-support/ptest-runner/ptest-runner_2.4.5.1.bb @@ -7,8 +7,7 @@ HOMEPAGE = "http://git.yoctoproject.org/cgit/cgit.cgi/ptest-runner2/about/" LICENSE = "GPL-2.0-or-later" LIC_FILES_CHKSUM = "file://LICENSE;md5=751419260aa954499f7abaabaa882bbe" -SRCREV = "aea9f42f87f2a78a973ae22cade8e45259f754e1" -PV .= "+git" +SRCREV = "c99e8c2737ff802f110612cc2d90c60233c33255" SRC_URI = "git://git.yoctoproject.org/ptest-runner2;branch=master;protocol=https \ " From patchwork Wed Sep 23 09:10:37 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 98991 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 6CCD6C982EA for ; Wed, 23 Sep 2026 09:12:05 +0000 (UTC) Received: from mail-wm2-f13.google.com (mail-wm2-f13.google.com [74.125.225.141]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.2935.1790154724595376056 for ; Wed, 23 Sep 2026 02:12:04 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=VgB5U74x; spf=pass (domain: smile.fr, ip: 74.125.225.141, mailfrom: yoann.congal@smile.fr) Received: by mail-wm2-f13.google.com with SMTP id 5b1f17b1804b1-49cd5462b69so3482875e9.1 for ; Wed, 23 Sep 2026 02:12:04 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1790154723; x=1790759523; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=rXbk7/mq6TpPAyxucG7gQwGeu7iOKTSm/zjV3lKRaTM=; b=VgB5U74xY6BF6baZj4c2cf9/IslY12/ItPs0yl6jxMfDYAH4/PyJ3SPngxeGvvEll+ Ypq42fqmMgus5Dr7LI3qc34jClWMx0QwJVSBduWnM3eBO0oa5TQJeOE4sWrelBkM31Gx IlNOHHtM5yMhQp+y8QD3FKjHhbkFkFBaRA4fI= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1790154723; x=1790759523; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=rXbk7/mq6TpPAyxucG7gQwGeu7iOKTSm/zjV3lKRaTM=; b=kHTHZVwiUe7Le90tdcvPudotqegBxcDluH7+CIxeCMDZQXkX1qCd8Ke4N75RxgVwyJ YCga+63vItMqXDn+Eh/d73wsaACgNYlN49hDsGpvfqON/f4+vTFiDXrnRFc7Ire3Z2sS 6kggMQLWfUKAlEmayR6vs/RG/qFsGuep6etTa0qmdWKpyDsHemZUMzw8fcni8gDgcxgZ oT4aNmutko88dphugkHNgOxpMUbWcwzB+erjLKtR6teMue4lpYm0PCdQXSetwDWQhnWm jRN2z5GVqJB3ldZ1Gfq1CHSvXZ9sYl6IgYUrRUDT5l4GkbSrWWDl9PhPvIvWid5CoOdP 7y2A== X-Gm-Message-State: AFuF++l2H5TDRHw84rf6zZSvkGh97DYYe+OzFKmChTduaCePA2BPkJI6 DIgnDYx7EggrL32+4HwC3Ch2pA2mFghDXyubUt8QTo3iaW7GUnVjLGgrDkI/BYUdNSgzY0+BoWq OB80lXMc= X-Gm-Gg: AYBFou0l+0+uH/NjBpPuKz/jKS3wMy+mLIdMufYpmKnNuukt3+KmROtH1sWkTn88tyv lJzgDzMqdBWa/xuAxOTUJfHfGF7JQaDK63Fxohq76+11k1zRaLICIluGQihkP5gvqrDSWVhPNwb ijGEWN4HGqxmHKqDFcgjThN8JcDMDa9grFxsynoakf44eTd1B1bnXxDnrOLGGfIkOyYrSOIPqxl 4SmIRxZRO/rJcI8vKj2WUlww+uWATT/+sVUYUyE1HLtSQHHPxGm4zbaZtMl+1m8MI9uW3sVHkiK bCVflG8WnOY+QdtpBKXelpdXMmHlnrUA3Ni50uwkzBQHkXtD8zSKruWRdja4tpI5NPIu28X9v1A 5SvTLRlswe8mR05hd11w0LpLIBhf4Lf0bpjf9qmNKTwKB2qj7RYcDsrw8fFvz3tzeJ977MREHME SZOWDc4TwQj7hE/oTYDpA05IoSKqw9JyoUEBxTSkQTlhebU9GYY6/uTnfCpUX3OBboW6ZKVk8YI DFPv0NsZKWK5Y+quQ7yxDAw1iLaijWq4I+0PY/kzrl60aGSb0KBZ7IxZOzIkPYaBHpdknCV X-Received: by 2002:a05:600d:8643:20b0:49f:bc0d:2e9 with SMTP id 5b1f17b1804b1-49fdfd90205mr15451355e9.0.1790154722785; Wed, 23 Sep 2026 02:12:02 -0700 (PDT) Received: from FRSMI25-LASER.home (2a02-8440-b519-f416-8bed-8817-19fd-ccf7.rev.sfr.net. [2a02:8440:b519:f416:8bed:8817:19fd:ccf7]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-49fe2730da9sm14251525e9.4.2026.09.23.02.12.01 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 23 Sep 2026 02:12:02 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][scarthgap 35/48] ptest-runner: Upgrade 2.4.5.1 -> 2.5.0 Date: Wed, 23 Sep 2026 11:10:37 +0200 Message-ID: <62d96e61678773686773203216f924d34a47160b.1790154074.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Wed, 23 Sep 2026 09:12:05 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/246497 From: Yoann Congal Changelog: - utils.c: Fix dirname() handling in run_ptests() - ptest-runner-collect-system-data: add info to logs - main.c: Set PYTHONUNBUFFERED in the environment - utils.c: print a message when a timeout occurs - main.c: Add print_helptext() for detailed help - main.print_usage: Remove unused argument list of -l Signed-off-by: Yoann Congal Signed-off-by: Mathieu Dubois-Briand Signed-off-by: Richard Purdie (cherry picked from commit 869d70d46c8e31cfc380b5143059cab3713cae26) Signed-off-by: Yoann Congal --- .../{ptest-runner_2.4.5.1.bb => ptest-runner_2.5.0.bb} | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) rename meta/recipes-support/ptest-runner/{ptest-runner_2.4.5.1.bb => ptest-runner_2.5.0.bb} (95%) diff --git a/meta/recipes-support/ptest-runner/ptest-runner_2.4.5.1.bb b/meta/recipes-support/ptest-runner/ptest-runner_2.5.0.bb similarity index 95% rename from meta/recipes-support/ptest-runner/ptest-runner_2.4.5.1.bb rename to meta/recipes-support/ptest-runner/ptest-runner_2.5.0.bb index 9f6bb399b40..b52f327af97 100644 --- a/meta/recipes-support/ptest-runner/ptest-runner_2.4.5.1.bb +++ b/meta/recipes-support/ptest-runner/ptest-runner_2.5.0.bb @@ -7,7 +7,7 @@ HOMEPAGE = "http://git.yoctoproject.org/cgit/cgit.cgi/ptest-runner2/about/" LICENSE = "GPL-2.0-or-later" LIC_FILES_CHKSUM = "file://LICENSE;md5=751419260aa954499f7abaabaa882bbe" -SRCREV = "c99e8c2737ff802f110612cc2d90c60233c33255" +SRCREV = "7429fdd52abb5b08a9e8acef14b1bc4604f09c8f" SRC_URI = "git://git.yoctoproject.org/ptest-runner2;branch=master;protocol=https \ " From patchwork Wed Sep 23 09:10:38 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 98996 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id E3C27C9830D for ; Wed, 23 Sep 2026 09:12:05 +0000 (UTC) Received: from mail-wm2-f13.google.com (mail-wm2-f13.google.com [74.125.225.141]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.2834.1790154725254964015 for ; Wed, 23 Sep 2026 02:12:05 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=QBOFrR4H; spf=pass (domain: smile.fr, ip: 74.125.225.141, mailfrom: yoann.congal@smile.fr) Received: by mail-wm2-f13.google.com with SMTP id 5b1f17b1804b1-49b912e64ccso4214155e9.0 for ; Wed, 23 Sep 2026 02:12:05 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1790154723; x=1790759523; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=q7u2CsiNHsuIPqphWTiTSTZimYJUZSCplu70NQsBXiw=; b=QBOFrR4HC2KG4v+t5Pr/lMnRA/YR/7jpP+6tK4JZ4CP/XUqXEBylRCBAgVdELD6Czx QyYG32KFHEEHXafU17lCxBI9dPDb9PI8xFb7WRsH7u9QXoLZeFFvgKXMMQm9L0pTwnjx sevMOurmLV2cnkgSbJrNRYLzmf+PloxQSvl9U= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1790154723; x=1790759523; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=q7u2CsiNHsuIPqphWTiTSTZimYJUZSCplu70NQsBXiw=; b=LkSgwxaeicV6MLoKEPUbYDzTOm/AqHo24rWX4+gXlWYp7ggWuoZqejvyyj8bughEcL R45HZMnonW0pNF/hnMv7NB7cWXN4fYttVm0ZnqbkzmvbKeI6MM+LZvWGtWznvb47VSb4 gGmhOuZnYxDc3YYgDkJD/ITUAW6KkIU0x8HM5Muxhn41AXxi7FPSKwy+0vsHKREcbsNa EukFFwoq8yVqigR5YEcuRyTNQiOY+8REKUjwKLFdLgENT8J15t+AXYpADirt14WHAkxh tXZFUzTKuN2jyULtU9CW9T8DppvZNH3wJtj2uBn9viQGw+en5n2Y+O4Z6vdZ8h8uR/td 4ZBQ== X-Gm-Message-State: AFuF++ktD6tuy5sWXIAWWVdODZsvPKhS9+Bm/C1X3OJduC4125wHpB3s uVjSUVll4lYP6tTtMJSpqWCMNA0vuPoaW/PohIaSR9RP724Xw72iaCbLfy3BkMBxdRhKp/0iOTF Iv9KJCWQ= X-Gm-Gg: AYBFou3x3fS/jxgQOgd2mDdEXlO44YcxCX6l42XfiYHld5cYzF3e4uE4c6OoU2Fn5jH Ep29pk7X+FO3ZQbJmk04X28lcdHpG+Pjcqsctxw7HSjBrgrqi605N0BW7BdABqcT/lxdfGfxqzJ hiJGn6YUt8vSQzhSIyFbz5MKPt4hHb4rJn+NS3vw0PMEtQByd5ms26rZ6bdta35chJMV6RjBGH/ ebAAduebPbeUMJBSB+Fj/U7VbjTStjjMk5ytP5oejaxdOdJvFTJ4a/Uwnm3i+wMD1g+VpnRAfIp 7KIM7CtY4rxYvt0/GplC43krPa3QTuZI7axg3dPaCQNkazg025ZYxLYJ/lcA1SjYJKSMLxWtoq2 Wq9CIrxgpl7WSy6m+EQETeyMgerzu8aa9ftfq09USym0ZJ0EGYSAy0VMjJ3KhDUPMKABuUXoQZ5 VDFwm9MQIDj/14EKUsFcNOFUREPljeSxsBuwTdldMGkArVleIdrpBzMzPDd14fzUZt9eeyO7veX OZa9WFCROMwcq6Zbfn2CIVh1LiZbsd+3lTb0NdGpVngN1qVRWfMl4jLOe3CB+1Mw2xFnTxIBg== X-Received: by 2002:a05:600c:1d2a:b0:499:a277:e8b5 with SMTP id 5b1f17b1804b1-49fdeffce6bmr30256645e9.3.1790154723507; Wed, 23 Sep 2026 02:12:03 -0700 (PDT) Received: from FRSMI25-LASER.home (2a02-8440-b519-f416-8bed-8817-19fd-ccf7.rev.sfr.net. [2a02:8440:b519:f416:8bed:8817:19fd:ccf7]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-49fe2730da9sm14251525e9.4.2026.09.23.02.12.02 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 23 Sep 2026 02:12:03 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][scarthgap 36/48] ptest-runner: Upgrade 2.5.0 -> 2.5.1 Date: Wed, 23 Sep 2026 11:10:38 +0200 Message-ID: X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Wed, 23 Sep 2026 09:12:05 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/246498 From: Richard Purdie Pull in buffering fix: """ When running slow ptests, we can see an issue where the tests are writing output but it doesn't make it to the process (e.g. ssh connection) running ptest-runner. The issue is that the standard buffering for non-interactive terminals is 8kb and some ptests don't output enough data to trigger a write. This can lead to the controlling connection timing out. This change forces the output streams to be line buffered in all cases. Most ptest output would contain newlines so this should work well. stderr can be unbuffered by default but making it consistent here seems the best approach. Testing with this change on slow ptest runs (e.g. qemu emulated) showed much more consistent data with this change. """ Signed-off-by: Richard Purdie (cherry picked from commit b57105311f1c5fd879dd58fa1de8862ebad989c1) Signed-off-by: Yoann Congal --- .../{ptest-runner_2.5.0.bb => ptest-runner_2.5.1.bb} | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) rename meta/recipes-support/ptest-runner/{ptest-runner_2.5.0.bb => ptest-runner_2.5.1.bb} (95%) diff --git a/meta/recipes-support/ptest-runner/ptest-runner_2.5.0.bb b/meta/recipes-support/ptest-runner/ptest-runner_2.5.1.bb similarity index 95% rename from meta/recipes-support/ptest-runner/ptest-runner_2.5.0.bb rename to meta/recipes-support/ptest-runner/ptest-runner_2.5.1.bb index b52f327af97..4bf4827bb89 100644 --- a/meta/recipes-support/ptest-runner/ptest-runner_2.5.0.bb +++ b/meta/recipes-support/ptest-runner/ptest-runner_2.5.1.bb @@ -7,7 +7,7 @@ HOMEPAGE = "http://git.yoctoproject.org/cgit/cgit.cgi/ptest-runner2/about/" LICENSE = "GPL-2.0-or-later" LIC_FILES_CHKSUM = "file://LICENSE;md5=751419260aa954499f7abaabaa882bbe" -SRCREV = "7429fdd52abb5b08a9e8acef14b1bc4604f09c8f" +SRCREV = "afe64efbb3f028e898fa9a5efcdc3010ebdf283c" SRC_URI = "git://git.yoctoproject.org/ptest-runner2;branch=master;protocol=https \ " From patchwork Wed Sep 23 09:10:39 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 99001 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 08DA3C98308 for ; Wed, 23 Sep 2026 09:12:16 +0000 (UTC) Received: from mail-wm2-f12.google.com (mail-wm2-f12.google.com [74.125.225.140]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.2836.1790154726075804652 for ; Wed, 23 Sep 2026 02:12:06 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=tcOv+NtS; spf=pass (domain: smile.fr, ip: 74.125.225.140, mailfrom: yoann.congal@smile.fr) Received: by mail-wm2-f12.google.com with SMTP id 5b1f17b1804b1-49d1fb0cf5eso4523645e9.3 for ; Wed, 23 Sep 2026 02:12:05 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1790154724; x=1790759524; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=KRBaUH478EaABtyvYdPzfJVUQ6uQSq7JcwO6hlXaHqI=; b=tcOv+NtSJhDaR3gO28CuTQ0l5TwgfNTgkfk3wVzYQrsXYp5J53odVU0cEDvAUnAeD0 yup0idXj3gCqDjFyUH3kF4ZdanANn7+GkoNrv3id7HQXoylz4rmlAn+hNqHEJrEt3POd +gCKEj0A5FTt784BIy6hP5tHk85DAfaa+Ly+g= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1790154724; x=1790759524; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=KRBaUH478EaABtyvYdPzfJVUQ6uQSq7JcwO6hlXaHqI=; b=ghSxPvoHpTza1gtVu0WSDk9PB5g2oQuotqwxrsyWLISvHCOd8D5DIpXYQ3l6yrun+L G3cOrEl5JKNlowktY/E7wKPFyDthk/qJCwcYmdwpkVKw5xeACKrbwgFkMIlTGmXhw4kW w6z6M6tUIpQiPjR6EYTxwJ+NtCRdxpQcas6GWG9fBoX7Fo1eZBdi18UBd+brZu4RIXBG nQ+ZR1sQEGpuZJ3ruXi0Y23tVxn7zv+169PZCTe3dZYN5PLynRxXIFbKM5Tp+gBIFAVz QkdLksH6Yj9tJuTBT7Hph/ygf4vhloXn5P3Chiv0yVSau2WYfR8JyxubJtjFWMhKLSck Txlw== X-Gm-Message-State: AFuF++mJOSVU4IcNo+KE92CPoqm6Sz7Ep6Q83jQuG6arMi4mgSPNzavd KAEOUhkkIdoOhls37WmCW1bOEdpwE7Qa/N8+vlgjJ2KXPP5RggnHJIhrb3Ex6JMMLywFBmb/nhq 8CGcPNZA= X-Gm-Gg: AYBFou2HKU+f1ivdpf1GQPoaRrzqHtoyrmVn3c4V5xis5bMJCdadPdyqhQN2RJOy3VE KVHZDAC39LeCxbRD+UDl5SwBloHDdK4v8Mv32qgxY8loAKmVdRkXR9u6WobT9Rsut0PmxcJA5oT 1+b78fu1vR/zRrjTnJUw0SOdeRiDvrMIHvUzO683+WzsW6MxvXSTJ8HCsQ6h59tr47cX4sTzeR4 jGzUFjRNligf5od3ulfdiQEGo8GLR137RcN/eqKeLQcVQHtU/1gL8e0FOwK6Gb+5+IfOVYpEeFz yNULdzHuEoXFWeAX79N7y5TTo7bfItVIjNKVXDo4DyWxqAytkqTJ8NNTwgf3X7TRSvXAfWA5eR+ M6uSUj9UPF9AhStBY55SP9WFSx5uos7Oh+pH0FPJxy/hVq93iy0vFEfskieY/fVnmZhUD5tUIFo z3wbLlCeng3uBkCwlRT3wnlVb/wm76Rzxw5n/3vquwqeCAHBBkJS93Zmt8TsdVlj7dIhsxmt17f t/Qn66ygqmg4yimo7wzva0R3KEoXqtvmwS+siI/+asDggU2VkTEMeAG+fNTeTQNY+m9i74XP2on xACy/j8= X-Received: by 2002:a05:600c:c176:b0:49f:c451:b4ab with SMTP id 5b1f17b1804b1-49fdf152561mr24568985e9.29.1790154724303; Wed, 23 Sep 2026 02:12:04 -0700 (PDT) Received: from FRSMI25-LASER.home (2a02-8440-b519-f416-8bed-8817-19fd-ccf7.rev.sfr.net. [2a02:8440:b519:f416:8bed:8817:19fd:ccf7]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-49fe2730da9sm14251525e9.4.2026.09.23.02.12.03 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 23 Sep 2026 02:12:04 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][scarthgap 37/48] pseudo: Add in openat2, exec and linkat fixes Date: Wed, 23 Sep 2026 11:10:39 +0200 Message-ID: X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Wed, 23 Sep 2026 09:12:16 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/246499 From: Richard Purdie Pull in: * linkat: Fix AT_EMPTY_PATH handling * makewrappers/openat2: Add noignore_path option * pseudo_util: Correctly free memory allocated by pseudo_setupenvp * exec*: Replace bash workaround to avoid memory corruption * pseudo_util: Clean up memory handling for setupenvp results * pseudo_util: Avoid a memory leak in pseudo_dropenv() * pseudo_util: Ensure pseudo_setupenvp handles memory consistently * pseudo_util: Avoid accidental free calls for without_libpseudo() * pseudo.h: Avoid accessing unallocated memory [YOCTO #16316] Signed-off-by: Richard Purdie (cherry picked from commit 90f823defa32477c9dbd91d264f581fdf0ee4068) Signed-off-by: Yoann Congal --- meta/recipes-devtools/pseudo/pseudo_git.bb | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/meta/recipes-devtools/pseudo/pseudo_git.bb b/meta/recipes-devtools/pseudo/pseudo_git.bb index 3d7dd62448f..7b1177f7970 100644 --- a/meta/recipes-devtools/pseudo/pseudo_git.bb +++ b/meta/recipes-devtools/pseudo/pseudo_git.bb @@ -12,9 +12,9 @@ SRC_URI:append:class-nativesdk = " \ file://older-glibc-symbols.patch" SRC_URI[prebuilt.sha256sum] = "ed9f456856e9d86359f169f46a70ad7be4190d6040282b84c8d97b99072485aa" -SRCREV = "823895ba708c63f6ae4dcbfc266210f26c02c698" +SRCREV = "ca47829825f297d7bf83665c0541a9de4aa78009" S = "${WORKDIR}/git" -PV = "1.9.8" +PV = "1.9.8+git" # largefile and 64bit time_t support adds these macros via compiler flags globally # remove them for pseudo since pseudo intercepts some of the functions which will be From patchwork Wed Sep 23 09:10:40 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 99000 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 1A45EC98307 for ; Wed, 23 Sep 2026 09:12:16 +0000 (UTC) Received: from mail-wr2-f12.google.com (mail-wr2-f12.google.com [74.125.225.76]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.2938.1790154726897643437 for ; Wed, 23 Sep 2026 02:12:07 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=lMa3lS2A; spf=pass (domain: smile.fr, ip: 74.125.225.76, mailfrom: yoann.congal@smile.fr) Received: by mail-wr2-f12.google.com with SMTP id ffacd0b85a97d-4843f22dc83so544359f8f.1 for ; Wed, 23 Sep 2026 02:12:06 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1790154725; x=1790759525; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=R+IjiI8FhWPZ4XaKKtCK9i5jcoOkkIztEiwwMzAs8H8=; b=lMa3lS2AUkliL7x4esbuspW4r4O0HGgHBXaKaN9K/hSgqPYAX4iPLTKJACpMmrZnHx RS0/7QrBnclFdTaCb7ldoqNhloHVAOkSsogGxkRtvrJw34Z/TWgu4jezeKBuDsLVznSB TGJIljUXZRE7ZWCb3oG0iD8V4i4FMFpA5rKj0= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1790154725; x=1790759525; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=R+IjiI8FhWPZ4XaKKtCK9i5jcoOkkIztEiwwMzAs8H8=; b=bhoC8fOaGnaziEqhiiwO38b0VNQNsiD+2YGBDU0drKjFRNFG1F/z0IupWF7gXVjtT5 VM248KABxpXPsaRQFbCPdrSMuEUvVjcOMGtc9aZBs61rhZL2smXjELy6KWQDmgAHAA9Z LKjhxMwEo0vaqlrp28MPcU5ahlkfqx5C1uGAPOFTrX5ETw5IadRzCOKQakP2OIeEI4m6 xLyfiehvEjR4OQO99jtu2xffphJ+kYHykA1po6g8ju7ZAI9WDj3/xn+8UiGUZG8Utap2 xrOgPO5LsIPd8Ak8kCjCgqt3PMep7SjN1AI6rYfJX9GudHE4Qss6CXrPpu6FT1ZbFLtE WeAQ== X-Gm-Message-State: AFuF++ladMFlgo0qha8ADcrhKKGvvYDo4w5AeLeIgxk/H9IT3aKctUJ8 QmRhwLKVNQYVlfR6vOe72aZQf7+Tie22ROV43SdjlMlGeJ2gIHW41NgVMt3bHI37ZLWmhuZWS9a 4qjr56KE= X-Gm-Gg: AYBFou2jwgnpBtTNqr8+boxfVGPzg8yb1xiWKMT0l/4XzFnaz7Z7US7a61GTzYHa99+ pv0HQhqlTPAWr5qlS2hHLN1xLF9InN65p8lS4czIVgLWV+5XDM51AbdToEhzhunw9w8SvkLuewx UTniDPTX3TWzZeKQUvFFd4u1pjTuz6//lHiBAJzZ+5Ln57NeADRcYzHPXz88TTZd5OQHNpKWGXg yUrE/kA+wCWT0V8Iq0001gdHK3udkp3X4L2yVnnZ9HsEdtNOqB7wy1hBR0+kiUk89G0Dm3C3sXy fjhTHXaZVJhme3nrBFKcOW7gS2JdsMn7xdk1/sGaUUlLuy3a/Vu5T1CH5e9gDevNoQNm1AZGGBv iw/LDrAiYF6DHYTAWWBsLPrSBwBYIFKaMVzsgy7Je5rZJUNzrUjvHAJ0lzi77X3llUGR2C8Xm9N Al+NvFSnWPREKVu0jtZbO6A1XWFc5uJ/3ERiQb1nphFDz6dTgGnqBVfYjix8hBXfnUxlI85bsBV Kb2I0/4dNUtR/2UEXmo0sQh0i8gsTq7orsF4RIbn5jBNVqpsufO3+zTOfTDdoL9ITPZgqRl X-Received: by 2002:a05:600c:3ba3:b0:49e:69ff:c6b1 with SMTP id 5b1f17b1804b1-49fdf2512b9mr31099605e9.31.1790154725084; Wed, 23 Sep 2026 02:12:05 -0700 (PDT) Received: from FRSMI25-LASER.home (2a02-8440-b519-f416-8bed-8817-19fd-ccf7.rev.sfr.net. [2a02:8440:b519:f416:8bed:8817:19fd:ccf7]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-49fe2730da9sm14251525e9.4.2026.09.23.02.12.04 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 23 Sep 2026 02:12:04 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][scarthgap 38/48] pseudo: Update to 1.9.10 Date: Wed, 23 Sep 2026 11:10:40 +0200 Message-ID: X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Wed, 23 Sep 2026 09:12:16 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/246500 From: Richard Purdie Pulls in various important fixes: Makefile.in: Bump to 1.9.10 test: various: Move to makefile compilation test-bash-exec-env: Add bash env test case test/test-openat2-func.c: Remove unusuaed saved_errno pseudo_util.c: strchr now returns const char pseudo_client: remove the unused pseudo_prefix_dir_fd pseudo_client: step around all of pseudo's own fds in closefrom pseudo_client: step fully past pseudo's own fds when computing startfd makewrappers: Avoid efault workaround if using AT_EMPTY_PATH ports/linux/guts: Add __open64_2 wrapper Makefile.in: Bump to 1.9.9 Signed-off-by: Richard Purdie (cherry picked from commit 4232a7cc5fa28828fdf3223b3c0a6432c8c1e670) Signed-off-by: Yoann Congal --- meta/recipes-devtools/pseudo/pseudo_git.bb | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/meta/recipes-devtools/pseudo/pseudo_git.bb b/meta/recipes-devtools/pseudo/pseudo_git.bb index 7b1177f7970..22d9006f797 100644 --- a/meta/recipes-devtools/pseudo/pseudo_git.bb +++ b/meta/recipes-devtools/pseudo/pseudo_git.bb @@ -12,9 +12,9 @@ SRC_URI:append:class-nativesdk = " \ file://older-glibc-symbols.patch" SRC_URI[prebuilt.sha256sum] = "ed9f456856e9d86359f169f46a70ad7be4190d6040282b84c8d97b99072485aa" -SRCREV = "ca47829825f297d7bf83665c0541a9de4aa78009" +SRCREV = "2a5521e9573049864e07907415f1fee28232d90c" S = "${WORKDIR}/git" -PV = "1.9.8+git" +PV = "1.9.10" # largefile and 64bit time_t support adds these macros via compiler flags globally # remove them for pseudo since pseudo intercepts some of the functions which will be From patchwork Wed Sep 23 09:10:41 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 98999 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 2C73DC9830B for ; Wed, 23 Sep 2026 09:12:16 +0000 (UTC) Received: from mail-wm2-f13.google.com (mail-wm2-f13.google.com [74.125.225.141]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.2939.1790154727905872143 for ; Wed, 23 Sep 2026 02:12:08 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=oUROZg0o; spf=pass (domain: smile.fr, ip: 74.125.225.141, mailfrom: yoann.congal@smile.fr) Received: by mail-wm2-f13.google.com with SMTP id 5b1f17b1804b1-49b912d391aso4464565e9.2 for ; Wed, 23 Sep 2026 02:12:07 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1790154726; x=1790759526; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=PlIf/bF9PMaAhJNtVvya0Gb17zg5Hh9zS2Xjh82ZbUQ=; b=oUROZg0og+a5yd52xnOgP2d+J6FzFnU483Y5AJW9+suVtXSCM966qfhdtAop2aau7N lg/PxxwLnTc90xIbx7IfIwEpLauzN9m3csz/tV3LC3mt+BqDFBN1vMyuIZsyox6qCE2p quEcGUcSBTwRXvpNxEazAmN/m2tZ/z2Yhwr8M= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1790154726; x=1790759526; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=PlIf/bF9PMaAhJNtVvya0Gb17zg5Hh9zS2Xjh82ZbUQ=; b=NnAmmE6uks4f5XE4Z4IguhgCVEqEGm6h4HK3tZiP6d6OHj5NHAmugSs0HxxCNaLtp4 AxuOwzbF+3FQBMUXqL04Uf4UDrCDjFIzEsbObEa69Q24b/AhIfuDOLzhIHqhELNf/Dr2 jzdLMoH1gCsF/XL6/sp21yhqXg9Bg0jjzDttssHO4YdjaRacev/FAIEM3T08G+7hlmpT AmrESc7EwSa60Qip6PPAqYPzVstJyk3vKYH4yPHmP1Rdu/8X9Kf2YcOfHmkYvT52JRSs qADQ62S7QfBRRV6eEB27LYEqYb+vN4qYn/LrpsFDDDTvmqtcaU7nCRbRNeWkIgMYZTkm VEFg== X-Gm-Message-State: AFuF++kMhsWTnIgYCJbRBP2RkUQIA7K35gLXGnEzYSsLgrWmn6MPIaip fR0Am+WloifMS5LCTOajL0R1dqEuDiPMtSKm02YtXKuomMIU7SDQzhGab8c05x2nKwFrZDmjI/e W+40tjIs= X-Gm-Gg: AYBFou00IkHJyjn2rIfmXlC6mX3CezI94g/gC7/RGV4tPbx1OnrSnYOVyXlzdXEYbka UrbTYoIRglh39qiIqK5iuAWoFH0rd7kem3BuszYFcERdl947XF4/VF6ZnZ8CM5wBTPHg96SEq2z jEUE2Pn5ZNlTNClmmw5A4sOqm4GUm61+J693+7K8xqR/wHxHEcaSicu/mErL8UoVKJ4bKlKC+Np 96iLOXNjtXAcjED6NR5w7OhHNJDgQfsHOcHNXAqSz4CYpQzeMYKTut6CQnvx3K7XjSIRAugIrW9 ABsF0ZgJKSYAg6PNsEOhKbyaUNZP2Bnr/lOdPp+Iiu3l3m/3lTLQge1q7GtKU2l1jSWkZqamRx+ M5K5d8ORX87y5SjsNqp+Pb4E0I6LMlJpOU4xoATUnYoazDODDXZXLeYFX0fP40j3ooTxOX7Ucjg v+WLA/wUc/pPHePLcRxFZv5gF7W1/TKHPByHXhz7cc42ia/oZUuU/iCKbj5A6mKu3PBb4MqDLUt 6Fl0dKZa2nyFb2x12mlV+xeQwAyGNPEeiOveKpOgRT7iuxd02/pecqizmm4LZc1EDjRj6li X-Received: by 2002:a05:600c:8b64:b0:499:8b13:3a98 with SMTP id 5b1f17b1804b1-49fdee0a0ebmr22026155e9.4.1790154726095; Wed, 23 Sep 2026 02:12:06 -0700 (PDT) Received: from FRSMI25-LASER.home (2a02-8440-b519-f416-8bed-8817-19fd-ccf7.rev.sfr.net. [2a02:8440:b519:f416:8bed:8817:19fd:ccf7]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-49fe2730da9sm14251525e9.4.2026.09.23.02.12.05 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 23 Sep 2026 02:12:05 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][scarthgap 39/48] pseudo: 1.9.10 -> 1.9.11 Date: Wed, 23 Sep 2026 11:10:41 +0200 Message-ID: <2d50a4b12798e57a6d7900de2cb2b6b4edcb77e9.1790154074.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Wed, 23 Sep 2026 09:12:16 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/246501 From: Richard Purdie Adds suport for a working close_range() intercept. Signed-off-by: Richard Purdie (cherry picked from commit 9a68d3f4bd0e80ea7e1ea745b6a10acd341dc7d8) Signed-off-by: Yoann Congal --- meta/recipes-devtools/pseudo/pseudo_git.bb | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/meta/recipes-devtools/pseudo/pseudo_git.bb b/meta/recipes-devtools/pseudo/pseudo_git.bb index 22d9006f797..1320d19ad49 100644 --- a/meta/recipes-devtools/pseudo/pseudo_git.bb +++ b/meta/recipes-devtools/pseudo/pseudo_git.bb @@ -12,9 +12,9 @@ SRC_URI:append:class-nativesdk = " \ file://older-glibc-symbols.patch" SRC_URI[prebuilt.sha256sum] = "ed9f456856e9d86359f169f46a70ad7be4190d6040282b84c8d97b99072485aa" -SRCREV = "2a5521e9573049864e07907415f1fee28232d90c" +SRCREV = "ba8887e5f1e922f866681ec7dec1a00b602a9328" S = "${WORKDIR}/git" -PV = "1.9.10" +PV = "1.9.11" # largefile and 64bit time_t support adds these macros via compiler flags globally # remove them for pseudo since pseudo intercepts some of the functions which will be From patchwork Wed Sep 23 09:10:42 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 98998 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id D4D13C982EA for ; Wed, 23 Sep 2026 09:12:15 +0000 (UTC) Received: from mail-wr2-f12.google.com (mail-wr2-f12.google.com [74.125.225.76]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.2839.1790154730663486476 for ; Wed, 23 Sep 2026 02:12:10 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=FRPy81/8; spf=pass (domain: smile.fr, ip: 74.125.225.76, mailfrom: yoann.congal@smile.fr) Received: by mail-wr2-f12.google.com with SMTP id ffacd0b85a97d-482f635552aso601958f8f.2 for ; Wed, 23 Sep 2026 02:12:10 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1790154729; x=1790759529; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=glZDvkks9W6kXLd5kO+ZVizDm70lE3W86F6L1K7+8vk=; b=FRPy81/8qezU9iXk5tAxqL7e627Iit7I98bQ8+vZ+NabD3qAy0GmuPK8eo4/bigEj/ NGPbFGHV5enjs1/u3jK+8Wrn3icfiWbBJDof5A0Ah5mFJM0X5C9Uauuxet3Pk0Y6fhxC OzfGy42z+ZmUggJhq9HjQnL1kD4C8xFzcevWI= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1790154729; x=1790759529; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=glZDvkks9W6kXLd5kO+ZVizDm70lE3W86F6L1K7+8vk=; b=V7WJ+nVE72Grwp2iksrfDoCeGs8CU5vk1+0x5rF1E/deuYMZ9E6Bktw/06cukNggEg N4sjCH9P9CjWxIUXRk3phDHUjBGln7+YCP7jK2e+mZI258GS5HfbTb6Gu9faULwZ09j6 1nUY0sL6nbIbOi5Dow9F5iQI9spC2akG6kzG8OnJA8Ema1guvY18VK+Z10kPfbWZMx77 wUj7CSXzlTjQKr7YPMGHJhpR2wu1VuUErK6PuFYiI8oJasltx9fvnACwNgBSMKgZ0jW6 SGW1/qr5Caumf2rEoS5NakUuuYbP2+T+3+31UoZXP4kcOfudIxX4GOuk2zu4F9w/zjz1 n4jg== X-Gm-Message-State: AFuF++mMMpjxJDvCNYOTI/5hPyQpbHiPH3LhygZynXhmzRBsh5o+c9Uv Atj9EiUtyXEOya43D+YbOF0ssW/Seauy6uLRT94B3l4VKxnAcqzFGVmwLB6ZKt/MB4o9YJKidIJ YO/25HE4= X-Gm-Gg: AYBFou3FJFPWL3+ClNKiRSScAtPAhoZ7TbV8rABolZ+lKuUJi3FhK1Gk5T26/b27LLK bOqsqSpYlity+XbGROK8/BdAl6WQKogZK0Tlu7Qpb+8W7dVryhSPffUrOZTJ1MbsmZkwrBQEk8v uvkyHYZ3OAGMCdsxVFbrhvGph4Lk7OCXDH+YXn9PXri88p3BcHmdIbgXi0VjsRocmkMJ69aX1No XXNvV4xbcygZOllEGNwV73CWXF1hoPBC2c7X28cTzvBuxCSTb3ef1i1uywfy0t0oqDouM4Nq64c mJ9LYstBJCOGlxCR9q+maVmDeu6VchBGQlHH9LptiL5PuSFXYMcnr6xtAT5iCPKuNm+wm5miao1 sh42jeNz51jG3rbu49/6KO7/9HQR/XQCtloc8yUd+rjvYWBOKVJtbfPKdBHKu2LpA5NFC7cMSux 1ddbEahYi0jzwzGekX5/EV0rFDBsCps3xcjNb72kXwMF1AxKdY68wy8icjEEvS/rnyWf5stXkKN /RgTEiBO/9uCbf7g5znzTKjWtYbb6O5n++p3r9PRwR8zX1oD8yEhHqgqx8/iOgTaXhlkaaz X-Received: by 2002:a05:600c:3e0b:b0:49d:827:e5b6 with SMTP id 5b1f17b1804b1-49fdf134f93mr25844725e9.20.1790154728799; Wed, 23 Sep 2026 02:12:08 -0700 (PDT) Received: from FRSMI25-LASER.home (2a02-8440-b519-f416-8bed-8817-19fd-ccf7.rev.sfr.net. [2a02:8440:b519:f416:8bed:8817:19fd:ccf7]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-49fe2730da9sm14251525e9.4.2026.09.23.02.12.06 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 23 Sep 2026 02:12:08 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][scarthgap 40/48] libslirp: patch CVE-2026-9539 Date: Wed, 23 Sep 2026 11:10:42 +0200 Message-ID: <2ab23c37a6799af522f8be006615bc7def95c37a.1790154074.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Wed, 23 Sep 2026 09:12:15 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/246502 From: Peter Marko Pick patch from NVD report. Signed-off-by: Peter Marko Signed-off-by: Yoann Congal --- .../slirp/libslirp/CVE-2026-9539.patch | 122 ++++++++++++++++++ .../slirp/libslirp_git.bb | 5 +- 2 files changed, 126 insertions(+), 1 deletion(-) create mode 100644 meta/recipes-connectivity/slirp/libslirp/CVE-2026-9539.patch diff --git a/meta/recipes-connectivity/slirp/libslirp/CVE-2026-9539.patch b/meta/recipes-connectivity/slirp/libslirp/CVE-2026-9539.patch new file mode 100644 index 00000000000..192d2b4b26f --- /dev/null +++ b/meta/recipes-connectivity/slirp/libslirp/CVE-2026-9539.patch @@ -0,0 +1,122 @@ +From 927bca7344e31fd58e2f7afaca784aad4400eb84 Mon Sep 17 00:00:00 2001 +From: Samuel Thibault +Date: Sat, 23 May 2026 22:06:59 +0200 +Subject: [PATCH] oob: cap urgent data count to what is actually available + +so_urgc is provided by the guest sender, so can arbitrary and beyond +what we actually have. Worse, this can lead to an sb_cc integer +underflow leading to leaking gigabytes of data. + +Fixes #93 + +Signed-off-by: Samuel Thibault + +CVE: CVE-2026-9539 +Upstream-Status: Backport [https://gitlab.freedesktop.org/slirp/libslirp/-/commit/927bca7344e31fd58e2f7afaca784aad4400eb84] +Signed-off-by: Peter Marko +--- + src/socket.c | 40 +++++++++++++++++++++++----------------- + 1 file changed, 23 insertions(+), 17 deletions(-) + +diff --git a/src/socket.c b/src/socket.c +index 77c5cf6..c491d0f 100644 +--- a/src/socket.c ++++ b/src/socket.c +@@ -337,7 +337,8 @@ int sorecvoob(struct socket *so) + int sosendoob(struct socket *so) + { + struct sbuf *sb = &so->so_rcv; +- char buff[2048]; /* XXX Shouldn't be sending more oob data than this */ ++ uint32_t urgc = so->so_urgc; ++ char buff[2048]; + + int n; + +@@ -345,12 +346,15 @@ int sosendoob(struct socket *so) + DEBUG_ARG("so = %p", so); + DEBUG_ARG("sb->sb_cc = %d", sb->sb_cc); + +- if (so->so_urgc > sizeof(buff)) +- so->so_urgc = sizeof(buff); /* XXXX */ ++ if (urgc > sizeof(buff)) ++ urgc = sizeof(buff); ++ ++ if (urgc > sb->sb_cc) ++ urgc = sb->sb_cc; + + if (sb->sb_rptr < sb->sb_wptr) { + /* We can send it directly */ +- n = slirp_send(so, sb->sb_rptr, so->so_urgc, ++ n = slirp_send(so, sb->sb_rptr, urgc, + (MSG_OOB)); /* |MSG_DONTWAIT)); */ + } else { + /* +@@ -358,7 +362,6 @@ int sosendoob(struct socket *so) + * we must copy all data to a linear buffer then + * send it all + */ +- uint32_t urgc = so->so_urgc; /* Amount of room left in buff */ + int len = (sb->sb_data + sb->sb_datalen) - sb->sb_rptr; + if (len > urgc) { + len = urgc; +@@ -403,7 +406,7 @@ int sosendoob(struct socket *so) + */ + int sowrite(struct socket *so) + { +- int n, nn; ++ int n, nn, noob = 0; + struct sbuf *sb = &so->so_rcv; + int len = sb->sb_cc; + struct iovec iov[2]; +@@ -413,16 +416,20 @@ int sowrite(struct socket *so) + + if (so->so_urgc) { + uint32_t expected = so->so_urgc; +- if (sosendoob(so) < expected) { +- /* Treat a short write as a fatal error too, +- * rather than continuing on and sending the urgent +- * data as if it were non-urgent and leaving the +- * so_urgc count wrong. +- */ ++ int noob = sosendoob(so); ++ ++ if (noob <= 0) + goto err_disconnected; +- } ++ ++ if (noob < expected) ++ /* Short write: either we have not yet received all ++ * urgent data, or the socket buffers are full. Leave ++ * it for later when we have data or have room. */ ++ return noob; ++ + if (sb->sb_cc == 0) +- return 0; ++ /* Nothing left to write actually */ ++ return noob; + } + + /* +@@ -453,12 +460,11 @@ int sowrite(struct socket *so) + } else + n = 1; + } +- /* Check if there's urgent data to send, and if so, send it */ + + nn = slirp_send(so, iov[0].iov_base, iov[0].iov_len, 0); + /* This should never happen, but people tell me it does *shrug* */ + if (nn < 0 && (errno == EAGAIN || errno == EINTR)) +- return 0; ++ return noob; + + if (nn <= 0) { + goto err_disconnected; +@@ -485,7 +491,7 @@ int sowrite(struct socket *so) + if ((so->so_state & SS_FWDRAIN) && sb->sb_cc == 0) + sofcantsendmore(so); + +- return nn; ++ return noob + nn; + + err_disconnected: + DEBUG_MISC(" --- sowrite disconnected, so->so_state = %x, errno = %d", diff --git a/meta/recipes-connectivity/slirp/libslirp_git.bb b/meta/recipes-connectivity/slirp/libslirp_git.bb index 334b786b9b7..820cd6e4f0c 100644 --- a/meta/recipes-connectivity/slirp/libslirp_git.bb +++ b/meta/recipes-connectivity/slirp/libslirp_git.bb @@ -4,7 +4,10 @@ HOMEPAGE = "https://gitlab.freedesktop.org/slirp/libslirp" LICENSE = "BSD-3-Clause & MIT" LIC_FILES_CHKSUM = "file://COPYRIGHT;md5=bca0186b14e6b05e338e729f106db727" -SRC_URI = "git://gitlab.freedesktop.org/slirp/libslirp.git;protocol=https;branch=master" +SRC_URI = "\ + git://gitlab.freedesktop.org/slirp/libslirp.git;protocol=https;branch=master \ + file://CVE-2026-9539.patch \ +" SRCREV = "3ad1710a96678fe79066b1469cead4058713a1d9" PV = "4.7.0" S = "${WORKDIR}/git" From patchwork Wed Sep 23 09:10:43 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 98997 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id EE69EC982FA for ; Wed, 23 Sep 2026 09:12:15 +0000 (UTC) Received: from mail-wm2-f12.google.com (mail-wm2-f12.google.com [74.125.225.140]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.2840.1790154733746531338 for ; Wed, 23 Sep 2026 02:12:14 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=VnPOtyrA; spf=pass (domain: smile.fr, ip: 74.125.225.140, mailfrom: yoann.congal@smile.fr) Received: by mail-wm2-f12.google.com with SMTP id 5b1f17b1804b1-49ce364488dso2018265e9.0 for ; Wed, 23 Sep 2026 02:12:13 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1790154732; x=1790759532; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=BmREq0njeEq7KfZ1Nu4DIz0g5GRYWBE8x/MT63tSh6Y=; b=VnPOtyrAqzesZssWFLZNZ8IzFnjhJ/CaALw7mQUdGAUiMGpzSxfMkNY1vf7+kVbdj3 V44k9NPJiRIv7h1JsJRXow/zQPXtBO+DD5FiJ/XvW4FrTFyI6/XARkKCj3VejW6U20rb 1oT8V1uTmsxuWYXSqZHEi3RZ4m9iewRWg9mjE= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1790154732; x=1790759532; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=BmREq0njeEq7KfZ1Nu4DIz0g5GRYWBE8x/MT63tSh6Y=; b=aH9Vr7CWO5vajOFKI+FRBEU2aseIsIT02XWgRthea9T8LNUOy2w/FvHF+BIGxkVtjS 01J/FSfjuRzxrVndcrQMEGwvGxoZUHgz1w2tzGiAY8a42ilJBay5I+XuKzN2H+nbIs4r Rabdksb1W0f6xoW+52fc0ZWKRVrsyTQemP2Jj10B77hmVTehgqC0MQxHKFLwklEQRDGb NuJ5BSe4pPSNZ9D2/OVffWtnuTMdOx+yrRFMmEbv3l+8sNxwK3ajlIsjzgolaHvHEfvl 2EFqP/exkCPocq9U9LHAYtUJvOHjWjLbJzEOgGo2qfml2RadwHVZ3EX+yPii4tbgn4pQ 8sFA== X-Gm-Message-State: AFuF++nNuUQib+issfTw8T9IEZu9BmG5YZH12SOVLypB90Ms4Mx9ANKj 7uzy/8VNsptyeGVqxnnUSYJWbaVOznEELfEcxSRMgfGyuFUHx+2Fp/TjmsGuXgyjB4pEGh2p1fE 6rMs+3BI= X-Gm-Gg: AYBFou3UXlWk6X1bIWWjpaSLRdRp5NP91oCdXmbAItzRcC/VSMKu76HjMKIPDZRKRWM c4lWGK9X6qqojQG/WNGdd9Sal9RGvme+QuXTOd9uoi4Fl81eTdgEnEKP/hJ6M8iIpXT28XsgGZ2 CbOmHDDIKbtNxFj8tozpkgPGsYykNwExw+SK4DMFsSNgY6fe7emVAUjwrOqwYRkyzauHEFUjChp h2MiutnXGcs9ZT6hWnlzGhcSeqcliTejtMw8qdDHjLeJv9P4OdhffyMKM2bH2HXrnptwwpbnBvq vW8mxv4Iy849twpTmAe2iHTM/ua+vTV2XLuF3ej93o6ipBzFBKI8szGEt3E23FSa/O/w7GZYQlD tpNj5emZFLSRHHq6EXJM7DPzmX33VXxC3mMbvZgdMcmM5xyBjHsxkwc2exbjw8mIfzAYlrarY85 rg0VMwZlys94T/fddqPbn+Ygpka04suCshOMatQgB2T8gFhoQEPhMyyqnZJfgD3lv4BRalzcdmD NFzC4Jgpbv5ZC307k4Oz00J3og1shFP3NqjoEaZFiUeHKr9hs13C8iimFySyOn662HyIpVx X-Received: by 2002:a05:600c:6087:b0:49d:2936:8ad1 with SMTP id 5b1f17b1804b1-49fde360163mr33542035e9.1.1790154731942; Wed, 23 Sep 2026 02:12:11 -0700 (PDT) Received: from FRSMI25-LASER.home (2a02-8440-b519-f416-8bed-8817-19fd-ccf7.rev.sfr.net. [2a02:8440:b519:f416:8bed:8817:19fd:ccf7]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-49fe2730da9sm14251525e9.4.2026.09.23.02.12.10 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 23 Sep 2026 02:12:11 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][scarthgap 41/48] rootfs.py: fix run-postinsts removal on multilib images Date: Wed, 23 Sep 2026 11:10:43 +0200 Message-ID: <2522a1ad4fb66af0a9ca146ca7a88aece8f471da.1790154074.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Wed, 23 Sep 2026 09:12:15 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/246503 From: Kyungjik Min ROOTFS_BOOTSTRAP_INSTALL in image.bbclass unconditionally stages run-postinsts into every image. When no delayed postinsts remain, _uninstall_unneeded() is supposed to remove it again, but the removal call used the bare "run-postinsts" package name without applying MLPREFIX. On a multilib image (e.g. lib32-core-image-minimal), the package that is actually installed is lib32-run-postinsts, so the unprefixed removal silently matches nothing and run-postinsts leaks into the final image manifest, along with its now-pointless init script / systemd unit. Expand MLPREFIX before removing the package, matching the pattern already used elsewhere in oe-core (e.g. oe/package.py) for package-name lookups that need to work across multilib variants. Signed-off-by: Kyungjik Min Signed-off-by: Mathieu Dubois-Briand Signed-off-by: Richard Purdie (cherry picked from commit dfa5673907bdc5211671ecdfce8ab1fb332eae48) Signed-off-by: Yoann Congal --- meta/lib/oe/rootfs.py | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/meta/lib/oe/rootfs.py b/meta/lib/oe/rootfs.py index 5abce4ad7d5..e8e6841113e 100644 --- a/meta/lib/oe/rootfs.py +++ b/meta/lib/oe/rootfs.py @@ -266,7 +266,8 @@ class Rootfs(object, metaclass=ABCMeta): delayed_postinsts = self._get_delayed_postinsts() if delayed_postinsts is None: if os.path.exists(self.d.expand("${IMAGE_ROOTFS}${sysconfdir}/init.d/run-postinsts")) or os.path.exists(self.d.expand("${IMAGE_ROOTFS}${systemd_system_unitdir}/run-postinsts.service")): - self.pm.remove(["run-postinsts"]) + mlprefix = self.d.getVar('MLPREFIX') or "" + self.pm.remove([mlprefix + "run-postinsts"]) image_rorfs = bb.utils.contains("IMAGE_FEATURES", "read-only-rootfs", True, False, self.d) and \ From patchwork Wed Sep 23 09:10:44 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 99006 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 7256FC9830B for ; Wed, 23 Sep 2026 09:12:26 +0000 (UTC) Received: from mail-wm2-f13.google.com (mail-wm2-f13.google.com [74.125.225.141]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.2941.1790154736389634243 for ; Wed, 23 Sep 2026 02:12:16 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=QXPJcET+; spf=pass (domain: smile.fr, ip: 74.125.225.141, mailfrom: yoann.congal@smile.fr) Received: by mail-wm2-f13.google.com with SMTP id 5b1f17b1804b1-49e721b5503so5656865e9.0 for ; Wed, 23 Sep 2026 02:12:16 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1790154735; x=1790759535; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=5hf1YZcQrZkOqitVDWJXah3+N5yWa1M6QMoi7JlYYHI=; b=QXPJcET+Fkd6LG5wrqoC9MVEGZPV54m7JuFeZX9jY/lyJ6HtsoOY6YhJNB86igaOm/ uoIN+wiL5ibc+DWqpiJHpPjaW8buPNAv8C7HJB+uk1pKycZ0CJVrEYzGFeIa9Ys6ozFh b+DxYt55mjgBdhn++6/fzb0Bqyc1TUQb1HLns= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1790154735; x=1790759535; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=5hf1YZcQrZkOqitVDWJXah3+N5yWa1M6QMoi7JlYYHI=; b=eT8rGgvMI/K3o1UnPx6Y6DSr446YSZhNJGCYw+Tvb96fuCBN8wKUHdDtelcxBgI4mi xcIAGrlknCZ3nOans9e57+UYWbrt7AeK6A4hw7pNC8EoN5dXnAu1yeohFujxCBx7AXal c5LyxrL4OuWEOD03d74Ba92oK9xyemtT6nhVB0R/0NiqDBNhICI1QhJkLAGuECVeElMN v/MW/vBi7lMEcbwtA+UjWKzYbmwW/oajkRdDf4jfaiQml2W3W89/SIsKDQXBoYRuokK0 8Ak5jYxqx0tA/DPhxdKz9+7ZzMeeUzdsMiQBoHQPE7/dVpfZGhNmG2lxhFipQPV6VH/H t9vg== X-Gm-Message-State: AFuF++kU0HKnjpv122RFLicvdt6aFwn8skwj2Gv6J3Ft346EweIVdv/P vD5rPe0O9bxv1hVe0vt2MGafyYE3TAps6zxz5CuqzRB4OEZvBlOUnPppf++YPV1jKfyjRGrXAkv q6UDO6RQ= X-Gm-Gg: AYBFou1MM8bMaFC+o47v8swU6y0zMTUiFflOTy2nc6E2th7sm/czU4MWAoTFuQlo4Dt Sp3XUlWkRXifnwsl3cvBa5trEgbzv3fbgtjNSPc0IpGbTmfB7DqobVjkVEe6xpPT8znB/DOEYLn cgnSO9lAc+RzdwRkLoYSc4mdjuq/PXxOHHSq6aYLrmmqLIZI5gxUygzliKCbV11oQG+qTubPDmz IXQTHigbvGfuleNGOgbBmtJ8D7JivOjDbl5ky+amEl1HqgijdnlHlujQ+5YsnbWabPhJNdsimgF tnxgO0A9+rwDYvJidgXVu2dLYKxdrNa9qMVrfuJdHHRmLvOHT7nB68v69D+x05Lg7jstUM12tCg /VEVuYZ/Bf8PiRTryIaf8Ci6UUBFox/AvdjJ5Ire1oze4JOlLKzQc0wSqhqm9cyOsyCZWeypoC7 Ru/92l86wkgdBSp+pMC0NvB9fOJz6aHzpXUcXbl9CHaRFoag4D7r7p+OPfdKo+IKzz7X1UuIjRZ hnmjWbavmlUB/zOzdi9nVQZlukkHS06lw+dy8QbhG/N48V02ro3ePbcJ4OZ+7tqJCvAQwdt X-Received: by 2002:a05:600c:1f91:b0:49c:fc6c:be19 with SMTP id 5b1f17b1804b1-49fdf24fa11mr25899295e9.31.1790154734553; Wed, 23 Sep 2026 02:12:14 -0700 (PDT) Received: from FRSMI25-LASER.home (2a02-8440-b519-f416-8bed-8817-19fd-ccf7.rev.sfr.net. [2a02:8440:b519:f416:8bed:8817:19fd:ccf7]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-49fe2730da9sm14251525e9.4.2026.09.23.02.12.12 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 23 Sep 2026 02:12:14 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][scarthgap 42/48] python3-cryptography: Fix CVE-2026-34073 Date: Wed, 23 Sep 2026 11:10:44 +0200 Message-ID: X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Wed, 23 Sep 2026 09:12:26 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/246504 From: Vijay Anusuri Pick patch according to [2] [1] https://nvd.nist.gov/vuln/detail/cve-2026-34073 [2] https://bugzilla.suse.com/show_bug.cgi?id=CVE-2026-34073 Signed-off-by: Vijay Anusuri Signed-off-by: Yoann Congal --- .../python3-cryptography/CVE-2026-34073.patch | 167 ++++++++++++++++++ .../python/python3-cryptography_42.0.5.bb | 1 + 2 files changed, 168 insertions(+) create mode 100644 meta/recipes-devtools/python/python3-cryptography/CVE-2026-34073.patch diff --git a/meta/recipes-devtools/python/python3-cryptography/CVE-2026-34073.patch b/meta/recipes-devtools/python/python3-cryptography/CVE-2026-34073.patch new file mode 100644 index 00000000000..9f144fa7094 --- /dev/null +++ b/meta/recipes-devtools/python/python3-cryptography/CVE-2026-34073.patch @@ -0,0 +1,167 @@ +From 6d97887956a05b3aaed262793710f07568026b72 Mon Sep 17 00:00:00 2001 +From: William Woodruff +Date: Wed, 25 Mar 2026 18:52:17 -0400 +Subject: [PATCH] Further restrict DNS wildcards in name constraint matching + (#14542) + +* Further restruct DNS wildcards in name constraint matching + +Signed-off-by: William Woodruff + +* Bump limbo + +Signed-off-by: William Woodruff + +Upstream-Status: Backport [import from suse https://download.opensuse.org/distribution/leap-micro/6.1/product/repo/openSUSE-Leap-Micro-6.1-x86_64-Source/src/python-cryptography-42.0.4-slfo.1.1_6.1.src.rpm +Upstream commit https://github.com/pyca/cryptography/commit/6d97887956a05b3aaed262793710f07568026b72] +CVE: CVE-2026-34073 +Signed-off-by: Vijay Anusuri +--- + .../cryptography-x509-verification/src/lib.rs | 5 +- + .../src/types.rs | 89 ++++++++++++------- + 2 files changed, 62 insertions(+), 32 deletions(-) + +diff --git a/src/rust/cryptography-x509-verification/src/lib.rs b/src/rust/cryptography-x509-verification/src/lib.rs +index 5ded892..f49f618 100644 +--- a/src/rust/cryptography-x509-verification/src/lib.rs ++++ b/src/rust/cryptography-x509-verification/src/lib.rs +@@ -20,11 +20,12 @@ use cryptography_x509::{ + oid::{NAME_CONSTRAINTS_OID, SUBJECT_ALTERNATIVE_NAME_OID}, + }; + ++use types::{DNSPattern}; ++ + use crate::certificate::cert_is_self_issued; + use crate::ops::{CryptoOps, VerificationCertificate}; + use crate::policy::Policy; + use crate::trust_store::Store; +-use crate::types::DNSName; + use crate::types::{DNSConstraint, IPAddress, IPConstraint}; + use crate::ApplyNameConstraintStatus::{Applied, Skipped}; + +@@ -108,7 +109,7 @@ impl<'a, 'chain> NameChain<'a, 'chain> { + + match (constraint, san) { + (GeneralName::DNSName(pattern), GeneralName::DNSName(name)) => { +- match (DNSConstraint::new(pattern.0), DNSName::new(name.0)) { ++ match (DNSConstraint::new(pattern.0), DNSPattern::new(name.0)) { + (Some(pattern), Some(name)) => Ok(Applied(pattern.matches(&name))), + (_, None) => Err(ValidationError::Other(format!( + "unsatisfiable DNS name constraint: malformed SAN {}", +diff --git a/src/rust/cryptography-x509-verification/src/types.rs b/src/rust/cryptography-x509-verification/src/types.rs +index f564715..d82936e 100644 +--- a/src/rust/cryptography-x509-verification/src/types.rs ++++ b/src/rust/cryptography-x509-verification/src/types.rs +@@ -129,35 +129,45 @@ impl<'a> DNSConstraint<'a> { + DNSName::new(pattern).map(Self) + } + +- /// Returns true if this `DNSConstraint` matches the given name. ++ /// Returns true if this `DNSConstraint` matches the given `DNSPattern`. + /// + /// Constraint matching is defined by RFC 5280: any DNS name that can + /// be constructed by simply adding zero or more labels to the left-hand + /// side of the name satisfies the name constraint. + /// +- /// ```rust +- /// # use cryptography_x509_verification::types::{DNSConstraint, DNSName}; +- /// let example_com = DNSName::new("example.com").unwrap(); +- /// let badexample_com = DNSName::new("badexample.com").unwrap(); +- /// let foo_example_com = DNSName::new("foo.example.com").unwrap(); +- /// assert!(DNSConstraint::new(example_com.as_str()).unwrap().matches(&example_com)); +- /// assert!(DNSConstraint::new(example_com.as_str()).unwrap().matches(&foo_example_com)); +- /// assert!(!DNSConstraint::new(example_com.as_str()).unwrap().matches(&badexample_com)); +- /// ``` +- pub fn matches(&self, name: &DNSName<'_>) -> bool { +- // NOTE: This may seem like an obtuse way to perform label matching, +- // but it saves us a few allocations: doing a substring check instead +- // would require us to clone each string and do case normalization. +- // Note also that we check the length in advance: Rust's zip +- // implementation terminates with the shorter iterator, so we need +- // to first check that the candidate name is at least as long as +- // the constraint it's matching against. +- name.as_str().len() >= self.0.as_str().len() +- && self +- .0 +- .rlabels() +- .zip(name.rlabels()) +- .all(|(a, o)| a.eq_ignore_ascii_case(o)) ++ /// On top of what RFC 5280 specifies, we define behavior for wildcard ++ /// patterns (which are not covered by RFC 5280): a wildcard pattern ++ /// matches a constraint if the pattern matches the constraint's inner name, ++ /// _or_ if the pattern's inner name matches the constraint. ++ /// This allows us to reject DNS names like `*.example.com` when ++ /// the constraint is `example.com` or `bar.example.com`. ++ pub fn matches(&self, name: &DNSPattern<'_>) -> bool { ++ match name { ++ DNSPattern::Exact(name) => { ++ // NOTE: This may seem like an obtuse way to perform label matching, ++ // but it saves us a few allocations: doing a substring check instead ++ // would require us to clone each string and do case normalization. ++ // Note also that we check the length in advance: Rust's zip ++ // implementation terminates with the shorter iterator, so we need ++ // to first check that the candidate name is at least as long as ++ // the constraint it's matching against. ++ name.as_str().len() >= self.0.as_str().len() ++ && self ++ .0 ++ .rlabels() ++ .zip(name.rlabels()) ++ .all(|(a, o)| a.eq_ignore_ascii_case(o)) ++ } ++ DNSPattern::Wildcard(inner) => { ++ // NOTE: This check is not as simple as a single pattern match, ++ // since we need two subtly distinct cases here: ++ // 1. Constraint `bar.example.com` on `*.example.com` ++ // 2. Constraint `example.com` on `*.example.com` ++ // The first cases is handled by `DNSPattern::matches`, and the second is handled ++ // by `DNSConstraint::matches`. ++ name.matches(&self.0) || self.matches(&DNSPattern::Exact(inner.clone())) ++ } ++ } + } + } + +@@ -456,14 +466,33 @@ mod tests { + let example_com = DNSConstraint::new("example.com").unwrap(); + + // Exact domain and arbitrary subdomains match. +- assert!(example_com.matches(&DNSName::new("example.com").unwrap())); +- assert!(example_com.matches(&DNSName::new("foo.example.com").unwrap())); +- assert!(example_com.matches(&DNSName::new("foo.bar.baz.quux.example.com").unwrap())); ++ assert!(example_com.matches(&DNSPattern::new("example.com").unwrap())); ++ assert!(example_com.matches(&DNSPattern::new("foo.example.com").unwrap())); ++ assert!(example_com.matches(&DNSPattern::new("foo.bar.baz.quux.example.com").unwrap())); + + // Parent domains, distinct domains, and substring domains do not match. +- assert!(!example_com.matches(&DNSName::new("com").unwrap())); +- assert!(!example_com.matches(&DNSName::new("badexample.com").unwrap())); +- assert!(!example_com.matches(&DNSName::new("wrong.com").unwrap())); ++ assert!(!example_com.matches(&DNSPattern::new("com").unwrap())); ++ assert!(!example_com.matches(&DNSPattern::new("badexample.com").unwrap())); ++ assert!(!example_com.matches(&DNSPattern::new("wrong.com").unwrap())); ++ } ++ ++ #[test] ++ fn test_dnsconstraint_matches_wildcard() { ++ let com = DNSConstraint::new("com").unwrap(); ++ let example_com = DNSConstraint::new("example.com").unwrap(); ++ let bar_example_com = DNSConstraint::new("bar.example.com").unwrap(); ++ let baz_bar_example_com = DNSConstraint::new("baz.bar.example.com").unwrap(); ++ let any_example_com = DNSPattern::new("*.example.com").unwrap(); ++ ++ assert!(com.matches(&any_example_com)); ++ assert!(example_com.matches(&any_example_com)); ++ assert!(bar_example_com.matches(&any_example_com)); ++ ++ // A constraint on `baz.bar.example.com` doesn't match `*.example.com`, ++ // since `baz.bar.example.com` matches zero or more sublabels of ++ // `baz.bar.example.com` while `*.example.com` matches exactly one ++ // sublabel of `example.com`. ++ assert!(!baz_bar_example_com.matches(&any_example_com)); + } + + #[test] +-- +2.43.0 + diff --git a/meta/recipes-devtools/python/python3-cryptography_42.0.5.bb b/meta/recipes-devtools/python/python3-cryptography_42.0.5.bb index 10ce753eac3..01382219fa8 100644 --- a/meta/recipes-devtools/python/python3-cryptography_42.0.5.bb +++ b/meta/recipes-devtools/python/python3-cryptography_42.0.5.bb @@ -12,6 +12,7 @@ SRC_URI[sha256sum] = "6fe07eec95dfd477eb9530aef5bead34fec819b3aaf6c5bd6d20565da6 SRC_URI += "file://0001-pyproject.toml-remove-benchmark-disable-option.patch \ file://CVE-2026-26007.patch \ + file://CVE-2026-34073.patch \ file://check-memfree.py \ file://run-ptest \ " From patchwork Wed Sep 23 09:10:45 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 99008 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 880B5C9830C for ; Wed, 23 Sep 2026 09:12:26 +0000 (UTC) Received: from mail-wm2-f12.google.com (mail-wm2-f12.google.com [74.125.225.140]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.2942.1790154739367501415 for ; Wed, 23 Sep 2026 02:12:19 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=G1ojmTcq; spf=pass (domain: smile.fr, ip: 74.125.225.140, mailfrom: yoann.congal@smile.fr) Received: by mail-wm2-f12.google.com with SMTP id 5b1f17b1804b1-49b912e4b11so3747595e9.3 for ; Wed, 23 Sep 2026 02:12:19 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1790154738; x=1790759538; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=koEG/G5B+5VoW2Wo0QiU1INLVjkFeZux68F0agyW0eQ=; b=G1ojmTcq0LSPWe55ybg6+F5QNLeRa/e9Ch3aMzOa8xYgpwHVA6IdILnkswxK8MHyln BwRIQeiEcqyPiGGJJ5J1rro/dUY2bCFo+mDaJJElDq64qRHThv9b2NjgKD/N2Vu8kQ5r bd+7cY3e3+XbEpA8/nKiO3JOEcpnTOzD8sCZs= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1790154738; x=1790759538; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=koEG/G5B+5VoW2Wo0QiU1INLVjkFeZux68F0agyW0eQ=; b=Kpm3HaWEkQs0PlnlzUZ4cRHW/ZTgFo8mmkkXM1D1qV7lXchSQuTy5l3ykZfe+5qycs qOWE0FWPJ3LuKhegF6LF9W6k+65ZRn92zc7fGnz+zC8JVmi5kO/Ba0APbnk2GSOvcJ3G 7QBAUZRt0MXxwCSEQe5kPairZ9Iud3SOS880epO7cAsTjnk6MH/ZpjwBGgDKvfQ7sJDa R4PI1pBvkv000H0flq4VzO+HYH2NfdduN+t6i8UdL3kVV9TO7eTllfj4AfwVv7uAOZOM kDHrqK1RoyJCiMNPyVDJa4cvYslrbMrWkOl0yUAw52iCaouWn85OKk60DLGpKa8Fkzzz pMEA== X-Gm-Message-State: AFuF++npIeU3X5tyfDKOA0YwM1e8kT8anMHvgefEW0zV8MPbT7d1xklJ zyi/WmLjPeXPv0YVlfmuf+FgpmMDOgppT9McEEuaGfyJF9F1SvZA3l6s7pI+xDeGwDDkvnPU+i9 YB2DdCwA= X-Gm-Gg: AYBFou1DEWqa7Yay8W65TJa3ekoXheCKTqMBk1OmIi6xwLzWvAKiqo0zOFHZywYD8SF 3JKBYMIwqKT+JM3zqjvUg1b11mpwcMnH3ErWlBfZUsUqzrl6xXmEvjWGyfFOr8z/H6Ay8QC1NLO F4D+OGWMncs4IZ2WUMxOGsb3Qq+aoItkUlxx0nX2ZQx5cZFjfY99KBdLupQxjz86AEQN/sRa/Y/ y30nBe03oKKayzn8JdkWrPgh0yboOSYUkr+qKEML2yL0/txiSktMxU44IVpJ9CliKjgBeAECsqB hgUjpVa7wY17VsNBOtP6H7kjRqRvfxv4IwPop4A2Zf3w2x5+II2RFSBeOdJye1j3raqBiVBMtsK kt2VKvVju4lwC1Y65NmGLa25flUkdoRGDHqy/hqVlcenkSAjOS2gln17mKjzsdzu1axePGipGwk 7J+Gi9Mx1RjQT+f/0ZDrmJT0t2fI2sZHIG0UZjLNGlaLtFCFY6MNYfK+cMMO9pBEJShnOiVp1qW ThElMZZejDw+0CM7idErPlau/26m/N4vhWrNNKpnANzSH1C9wiAs6MhXMHfq5JLylkx08jD X-Received: by 2002:a05:600c:3b1b:b0:49e:7a00:b9a5 with SMTP id 5b1f17b1804b1-49fdee0b08fmr24520005e9.4.1790154737522; Wed, 23 Sep 2026 02:12:17 -0700 (PDT) Received: from FRSMI25-LASER.home (2a02-8440-b519-f416-8bed-8817-19fd-ccf7.rev.sfr.net. [2a02:8440:b519:f416:8bed:8817:19fd:ccf7]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-49fe2730da9sm14251525e9.4.2026.09.23.02.12.14 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 23 Sep 2026 02:12:17 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][scarthgap 43/48] python3-cryptography: Fix CVE-2026-69248 Date: Wed, 23 Sep 2026 11:10:45 +0200 Message-ID: X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Wed, 23 Sep 2026 09:12:26 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/246505 From: Vijay Anusuri Pick patch according to [2] [1] https://nvd.nist.gov/vuln/detail/cve-2026-69248 [2] https://security-tracker.debian.org/tracker/CVE-2026-69248 Signed-off-by: Vijay Anusuri Signed-off-by: Yoann Congal --- .../python3-cryptography/CVE-2026-69248.patch | 299 ++++++++++++++++++ .../python/python3-cryptography_42.0.5.bb | 1 + 2 files changed, 300 insertions(+) create mode 100644 meta/recipes-devtools/python/python3-cryptography/CVE-2026-69248.patch diff --git a/meta/recipes-devtools/python/python3-cryptography/CVE-2026-69248.patch b/meta/recipes-devtools/python/python3-cryptography/CVE-2026-69248.patch new file mode 100644 index 00000000000..659d1bf72ae --- /dev/null +++ b/meta/recipes-devtools/python/python3-cryptography/CVE-2026-69248.patch @@ -0,0 +1,299 @@ +From 4d035a4225965edeffd312079a510ef25fcfdcb2 Mon Sep 17 00:00:00 2001 +From: William Woodruff +Date: Thu, 21 May 2026 20:44:05 -0400 +Subject: [PATCH] x509: distinguish NC kinds when evaluating wildcard DNS SANs + (#14888) + +* x509: distinguish NC kinds when evaluating wildcard DNS SANs + +* Bump x509-limbo + +Note: SUSE patch CVE-2026-69248-distingush-nc-kinds-wildcard-sans.patch was adapted to our version where required. + +Upstream-Status: Backport [import from suse https://download.opensuse.org/distribution/leap-micro/6.1/product/repo/openSUSE-Leap-Micro-6.1-x86_64-Source/src/python-cryptography-42.0.4-slfo.1.1_6.1.src.rpm +Upstream commit https://github.com/pyca/cryptography/commit/4d035a4225965edeffd312079a510ef25fcfdcb2] +CVE: CVE-2026-69248 +Signed-off-by: Vijay Anusuri +--- + .../cryptography-x509-verification/src/lib.rs | 37 +++- + .../src/types.rs | 165 ++++++++++++------ + 2 files changed, 145 insertions(+), 57 deletions(-) + +diff --git a/src/rust/cryptography-x509-verification/src/lib.rs b/src/rust/cryptography-x509-verification/src/lib.rs +index f49f618..a505349 100644 +--- a/src/rust/cryptography-x509-verification/src/lib.rs ++++ b/src/rust/cryptography-x509-verification/src/lib.rs +@@ -101,6 +101,7 @@ impl<'a, 'chain> NameChain<'a, 'chain> { + + fn evaluate_single_constraint( + &self, ++ kind: SubtreeKind, + constraint: &GeneralName<'chain>, + san: &GeneralName<'chain>, + budget: &mut Budget, +@@ -109,8 +110,18 @@ impl<'a, 'chain> NameChain<'a, 'chain> { + + match (constraint, san) { + (GeneralName::DNSName(pattern), GeneralName::DNSName(name)) => { ++ // NOTE: A DNS SAN can be a wildcard pattern (e.g. `*.foo.com`) ++ // rather than an ordinary DNS name. A wildcard represents a ++ // *set* of names, so the check depends on which subtree we're ++ // evaluating: a `permittedSubtrees` constraint must contain ++ // *every* name the wildcard can expand to, whereas an ++ // `excludedSubtrees` constraint matches if it overlaps the ++ // wildcard at all. We dispatch on `kind` accordingly. + match (DNSConstraint::new(pattern.0), DNSPattern::new(name.0)) { +- (Some(pattern), Some(name)) => Ok(Applied(pattern.matches(&name))), ++ (Some(pattern), Some(name)) => Ok(Applied(match kind { ++ SubtreeKind::Permitted => pattern.permits(&name), ++ SubtreeKind::Excluded => pattern.excludes(&name), ++ })), + (_, None) => Err(ValidationError::Other(format!( + "unsatisfiable DNS name constraint: malformed SAN {}", + name.0 +@@ -155,7 +166,12 @@ impl<'a, 'chain> NameChain<'a, 'chain> { + let mut permit = true; + if let Some(permitted_subtrees) = &constraints.permitted_subtrees { + for p in permitted_subtrees.unwrap_read().clone() { +- let status = self.evaluate_single_constraint(&p.base, &san, budget)?; ++ let status = self.evaluate_single_constraint( ++ SubtreeKind::Permitted, ++ &p.base, ++ &san, ++ budget, ++ )?; + if status.is_applied() { + permit = status.is_match(); + if permit { +@@ -173,7 +189,12 @@ impl<'a, 'chain> NameChain<'a, 'chain> { + + if let Some(excluded_subtrees) = &constraints.excluded_subtrees { + for e in excluded_subtrees.unwrap_read().clone() { +- let status = self.evaluate_single_constraint(&e.base, &san, budget)?; ++ let status = self.evaluate_single_constraint( ++ SubtreeKind::Excluded, ++ &e.base, ++ &san, ++ budget, ++ )?; + if status.is_match() { + return Err(ValidationError::Other( + "excluded name constraint matched SAN".into(), +@@ -207,6 +228,16 @@ struct ChainBuilder<'a, 'chain, B: CryptoOps> { + store: &'a Store<'chain, B>, + } + ++/// Identifies which kind of name constraint subtree a SAN is being evaluated ++/// against. The two subtree kinds use different matching semantics for ++/// wildcard DNS SANs (containment vs. overlap); see [`DNSConstraint::permits`] ++/// and [`DNSConstraint::excludes`]. ++#[derive(Clone, Copy)] ++enum SubtreeKind { ++ Permitted, ++ Excluded, ++} ++ + // When applying a name constraint, we need to distinguish between a few different scenarios: + // * `Applied(true)`: The name constraint is the same type as the SAN and matches. + // * `Applied(false)`: The name constraint is the same type as the SAN and does not match. +diff --git a/src/rust/cryptography-x509-verification/src/types.rs b/src/rust/cryptography-x509-verification/src/types.rs +index d82936e..c0b72e3 100644 +--- a/src/rust/cryptography-x509-verification/src/types.rs ++++ b/src/rust/cryptography-x509-verification/src/types.rs +@@ -129,44 +129,69 @@ impl<'a> DNSConstraint<'a> { + DNSName::new(pattern).map(Self) + } + +- /// Returns true if this `DNSConstraint` matches the given `DNSPattern`. ++ /// Returns true if the given exact `DNSName` falls within this ++ /// constraint's subtree. + /// +- /// Constraint matching is defined by RFC 5280: any DNS name that can +- /// be constructed by simply adding zero or more labels to the left-hand +- /// side of the name satisfies the name constraint. ++ /// Per RFC 5280, a name satisfies the constraint if it can be constructed ++ /// by adding zero or more labels to the left-hand side of the constraint's ++ /// name (i.e. it is the constraint's name, or a subdomain of it). ++ fn contains(&self, name: &DNSName<'_>) -> bool { ++ // NOTE: This may seem like an obtuse way to perform label matching, ++ // but it saves us a few allocations: doing a substring check instead ++ // would require us to clone each string and do case normalization. ++ // Note also that we check the length in advance: Rust's zip ++ // implementation terminates with the shorter iterator, so we need ++ // to first check that the candidate name is at least as long as ++ // the constraint it's matching against. ++ name.as_str().len() >= self.0.as_str().len() ++ && self ++ .0 ++ .rlabels() ++ .zip(name.rlabels()) ++ .all(|(a, o)| a.eq_ignore_ascii_case(o)) ++ } ++ ++ /// Returns true if the given `DNSPattern` is permitted by this constraint, ++ /// for use with a `permittedSubtrees` name constraint. + /// +- /// On top of what RFC 5280 specifies, we define behavior for wildcard +- /// patterns (which are not covered by RFC 5280): a wildcard pattern +- /// matches a constraint if the pattern matches the constraint's inner name, +- /// _or_ if the pattern's inner name matches the constraint. +- /// This allows us to reject DNS names like `*.example.com` when +- /// the constraint is `example.com` or `bar.example.com`. +- pub fn matches(&self, name: &DNSPattern<'_>) -> bool { +- match name { +- DNSPattern::Exact(name) => { +- // NOTE: This may seem like an obtuse way to perform label matching, +- // but it saves us a few allocations: doing a substring check instead +- // would require us to clone each string and do case normalization. +- // Note also that we check the length in advance: Rust's zip +- // implementation terminates with the shorter iterator, so we need +- // to first check that the candidate name is at least as long as +- // the constraint it's matching against. +- name.as_str().len() >= self.0.as_str().len() +- && self +- .0 +- .rlabels() +- .zip(name.rlabels()) +- .all(|(a, o)| a.eq_ignore_ascii_case(o)) +- } +- DNSPattern::Wildcard(inner) => { +- // NOTE: This check is not as simple as a single pattern match, +- // since we need two subtly distinct cases here: +- // 1. Constraint `bar.example.com` on `*.example.com` +- // 2. Constraint `example.com` on `*.example.com` +- // The first cases is handled by `DNSPattern::matches`, and the second is handled +- // by `DNSConstraint::matches`. +- name.matches(&self.0) || self.matches(&DNSPattern::Exact(inner.clone())) +- } ++ /// A pattern is permitted only if *every* name it can represent falls ++ /// within the constraint's subtree. An exact name is permitted by ordinary ++ /// subtree containment (per RFC 5280). ++ /// ++ /// Wildcard patterns are not covered by RFC 5280; we define their behavior ++ /// here. A wildcard pattern `*.X` is permitted only if its base name `X` ++ /// itself falls within the constraint's subtree. This is stricter than ++ /// mere overlap: `*.example.com` is *not* permitted by `foo.example.com`, ++ /// since it can also expand to a sibling such as `bar.example.com` that ++ /// lies outside the permitted subtree. ++ pub fn permits(&self, pattern: &DNSPattern<'_>) -> bool { ++ match pattern { ++ DNSPattern::Exact(name) => self.contains(name), ++ DNSPattern::Wildcard(base) => self.contains(base), ++ } ++ } ++ ++ /// Returns true if the given `DNSPattern` is excluded by this constraint, ++ /// for use with an `excludedSubtrees` name constraint. ++ /// ++ /// A pattern is excluded if *any* name it can represent falls within the ++ /// constraint's subtree. An exact name is excluded by ordinary subtree ++ /// containment (per RFC 5280). ++ /// ++ /// Wildcard patterns are not covered by RFC 5280; we define their behavior ++ /// here. A wildcard pattern `*.X` is excluded if it overlaps the subtree ++ /// at all, which happens in two subtly distinct cases: ++ /// ++ /// 1. The constraint is more specific than the wildcard, e.g. constraint ++ /// `bar.example.com` and pattern `*.example.com` (which can expand to ++ /// `bar.example.com`). This is handled by `DNSPattern::matches`. ++ /// 2. The wildcard's base name falls within the subtree, e.g. constraint ++ /// `example.com` and pattern `*.example.com`. This is handled by ++ /// `DNSConstraint::contains`. ++ pub fn excludes(&self, pattern: &DNSPattern<'_>) -> bool { ++ match pattern { ++ DNSPattern::Exact(name) => self.contains(name), ++ DNSPattern::Wildcard(base) => pattern.matches(&self.0) || self.contains(base), + } + } + } +@@ -462,37 +487,69 @@ mod tests { + } + + #[test] +- fn test_dnsconstraint_matches() { ++ fn test_dnsconstraint_exact() { + let example_com = DNSConstraint::new("example.com").unwrap(); + +- // Exact domain and arbitrary subdomains match. +- assert!(example_com.matches(&DNSPattern::new("example.com").unwrap())); +- assert!(example_com.matches(&DNSPattern::new("foo.example.com").unwrap())); +- assert!(example_com.matches(&DNSPattern::new("foo.bar.baz.quux.example.com").unwrap())); ++ // For exact patterns, `permits` and `excludes` behave identically: ++ // the pattern must fall within the constraint's subtree. ++ for permitted in [ ++ "example.com", ++ "foo.example.com", ++ "foo.bar.baz.quux.example.com", ++ ] { ++ let pattern = DNSPattern::new(permitted).unwrap(); ++ assert!(example_com.permits(&pattern)); ++ assert!(example_com.excludes(&pattern)); ++ } + + // Parent domains, distinct domains, and substring domains do not match. +- assert!(!example_com.matches(&DNSPattern::new("com").unwrap())); +- assert!(!example_com.matches(&DNSPattern::new("badexample.com").unwrap())); +- assert!(!example_com.matches(&DNSPattern::new("wrong.com").unwrap())); ++ for rejected in ["com", "badexample.com", "wrong.com"] { ++ let pattern = DNSPattern::new(rejected).unwrap(); ++ assert!(!example_com.permits(&pattern)); ++ assert!(!example_com.excludes(&pattern)); ++ } ++ } ++ ++ #[test] ++ fn test_dnsconstraint_permits_wildcard() { ++ let com = DNSConstraint::new("com").unwrap(); ++ let example_com = DNSConstraint::new("example.com").unwrap(); ++ let foo_example_com = DNSConstraint::new("foo.example.com").unwrap(); ++ let any_example_com = DNSPattern::new("*.example.com").unwrap(); ++ ++ // A wildcard `*.example.com` is permitted only by constraints whose ++ // subtree contains *every* name the wildcard can expand to, i.e. those ++ // that contain `example.com` itself. ++ assert!(com.permits(&any_example_com)); ++ assert!(example_com.permits(&any_example_com)); ++ ++ // A constraint more specific than the wildcard's base does *not* ++ // permit it: the wildcard can expand to siblings outside the subtree ++ // (e.g. `*.example.com` can be `bar.example.com`, which lies outside ++ // `foo.example.com`). ++ assert!(!foo_example_com.permits(&any_example_com)); + } + + #[test] +- fn test_dnsconstraint_matches_wildcard() { ++ fn test_dnsconstraint_excludes_wildcard() { + let com = DNSConstraint::new("com").unwrap(); + let example_com = DNSConstraint::new("example.com").unwrap(); + let bar_example_com = DNSConstraint::new("bar.example.com").unwrap(); + let baz_bar_example_com = DNSConstraint::new("baz.bar.example.com").unwrap(); + let any_example_com = DNSPattern::new("*.example.com").unwrap(); + +- assert!(com.matches(&any_example_com)); +- assert!(example_com.matches(&any_example_com)); +- assert!(bar_example_com.matches(&any_example_com)); +- +- // A constraint on `baz.bar.example.com` doesn't match `*.example.com`, +- // since `baz.bar.example.com` matches zero or more sublabels of +- // `baz.bar.example.com` while `*.example.com` matches exactly one +- // sublabel of `example.com`. +- assert!(!baz_bar_example_com.matches(&any_example_com)); ++ // A wildcard `*.example.com` is excluded by any constraint whose ++ // subtree it overlaps, including constraints more specific than the ++ // wildcard's base. ++ assert!(com.excludes(&any_example_com)); ++ assert!(example_com.excludes(&any_example_com)); ++ assert!(bar_example_com.excludes(&any_example_com)); ++ ++ // A constraint on `baz.bar.example.com` doesn't overlap ++ // `*.example.com`, since `baz.bar.example.com` matches zero or more ++ // sublabels of `baz.bar.example.com` while `*.example.com` matches ++ // exactly one sublabel of `example.com`. ++ assert!(!baz_bar_example_com.excludes(&any_example_com)); + } + + #[test] +-- +2.43.0 + diff --git a/meta/recipes-devtools/python/python3-cryptography_42.0.5.bb b/meta/recipes-devtools/python/python3-cryptography_42.0.5.bb index 01382219fa8..8148ec0ba56 100644 --- a/meta/recipes-devtools/python/python3-cryptography_42.0.5.bb +++ b/meta/recipes-devtools/python/python3-cryptography_42.0.5.bb @@ -13,6 +13,7 @@ SRC_URI[sha256sum] = "6fe07eec95dfd477eb9530aef5bead34fec819b3aaf6c5bd6d20565da6 SRC_URI += "file://0001-pyproject.toml-remove-benchmark-disable-option.patch \ file://CVE-2026-26007.patch \ file://CVE-2026-34073.patch \ + file://CVE-2026-69248.patch \ file://check-memfree.py \ file://run-ptest \ " From patchwork Wed Sep 23 09:10:46 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 99007 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 980F1C9830E for ; Wed, 23 Sep 2026 09:12:26 +0000 (UTC) Received: from mail-wm2-f12.google.com (mail-wm2-f12.google.com [74.125.225.140]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.2943.1790154741139607423 for ; Wed, 23 Sep 2026 02:12:21 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=im5JA/ge; spf=pass (domain: smile.fr, ip: 74.125.225.140, mailfrom: yoann.congal@smile.fr) Received: by mail-wm2-f12.google.com with SMTP id 5b1f17b1804b1-49b912d37b5so3848095e9.2 for ; Wed, 23 Sep 2026 02:12:20 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1790154739; x=1790759539; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=QM6jFYeAmAImReTNVdlsdt8b/Jed7tWmnNTrVoKP6eg=; b=im5JA/geui1yFOPqQWSHeBIZyaeBPIiI6R2wAkwznBGhlx3BeC6c779u94H5odvFPw jlJIUrIpzquaHf+dKu66P8zqi3pd1r+tnhj3dRSHpQqjSmO/urwo32BHzA4MB6gSeDjK 0AirZ5IFRDXu3AhqgFAsCDnhB0BGys4gysGkg= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1790154739; x=1790759539; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=QM6jFYeAmAImReTNVdlsdt8b/Jed7tWmnNTrVoKP6eg=; b=1SB3Y5IvtEz4uHAU9FLPrRPbnNaPBoRcX4Vhb2HHk3cYCOxxtnf7kwnyZtzT8I96v+ 3QoIhchvvsJP9ZHo6OvEC4Ilc0HjR0inN+O5Xzvdcy8WcaQboWMzA5JXUFLZSafQaYiq S6t5Jt6AsunBESPqx6nOlEIwV7X5lNZTskRSCOn897i1Foa/+tnZSvpTr4nsTCfU6qrd e9YwP26Uf3ah3FyU+LKox7utbg4l/n4763cMZDPkFovLFWfUzzArJN34+5BfeuDJSOeJ o8vvQURaUKDREcCFUeQUBs5PceTGyGWBxbn02F5t7kc3r5EuUsBhPF+nT+TYPiRq3ABb o0rw== X-Gm-Message-State: AFuF++kl6qSl5wJfD2R643hOSndInCgvyMtHaO/fv01z9BB0D23lC56X 4S0vel21w1QcVJUveYHiCKvvSP0gXbOaNCHiyNFvxZt48KeuNucFda5PtMCxVGpiiERq/EYF0jq /mb7rz40= X-Gm-Gg: AYBFou3JabR++IqRe+CiP7NgpozvrYiTRUbkC3ZwItxR2Cy0p5pYUqX8QlZpEha32V+ CByjKcSZMqBvk/NiBBK2jEmJVrrPt4aYUR10ZzuInS/4o7afpUnasSofBFNC+NzP60iael2qHio QJkvHhWX80YzVos6qKGB0c808yK2TCbdRpdMoyXPKlcJSSj6zHfxHtrLf14WyTEFpgouE0rROiQ jLZDq4HnfSq4idQs7n4Ueyp5hp162Q9yRIKt6ZjzKQ1bPQt61qF2IR/N+XeJv6p3sZqRLh4wuwk lSvIGNEjCurFaIAJ4Iqn2NUsXVOfcKs1JyGJUBjDAG+wMikTlKe13P4UxfoaAzPukHPLVxwxLhu L+kSHeUanfrLPrCUnRwIxxt+4zWFlPWyVbbpNHyEUHLdu6uZ5l6yUiaRoi1SU1c2fcewFylYrPs 4UQBI4jEdq4zigXoJh7WnpFErSPZehGEQyNY/km9ucpCdEGtR79XNkbdrBiB5M7slOVe9cbIh5T kkZQJyaoMSbtUJaH2ZIQnptSkUhtUZ4n2zJKlStOOeqwjozS6kmTwJ64aI7iG87xF+nzVxq X-Received: by 2002:a05:600c:1c22:b0:49f:bc28:e8b1 with SMTP id 5b1f17b1804b1-49fdece7477mr32143495e9.14.1790154739284; Wed, 23 Sep 2026 02:12:19 -0700 (PDT) Received: from FRSMI25-LASER.home (2a02-8440-b519-f416-8bed-8817-19fd-ccf7.rev.sfr.net. [2a02:8440:b519:f416:8bed:8817:19fd:ccf7]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-49fe2730da9sm14251525e9.4.2026.09.23.02.12.17 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 23 Sep 2026 02:12:18 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][scarthgap 44/48] python3-cryptography: Fix CVE-2026-69249 Date: Wed, 23 Sep 2026 11:10:46 +0200 Message-ID: X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Wed, 23 Sep 2026 09:12:26 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/246506 From: Vijay Anusuri Pick patch according to [2] [1] https://nvd.nist.gov/vuln/detail/cve-2026-69249 [2] https://security-tracker.debian.org/tracker/CVE-2026-69249 Signed-off-by: Vijay Anusuri Signed-off-by: Yoann Congal --- .../python3-cryptography/CVE-2026-69249.patch | 354 ++++++++++++++++++ .../python/python3-cryptography_42.0.5.bb | 1 + 2 files changed, 355 insertions(+) create mode 100644 meta/recipes-devtools/python/python3-cryptography/CVE-2026-69249.patch diff --git a/meta/recipes-devtools/python/python3-cryptography/CVE-2026-69249.patch b/meta/recipes-devtools/python/python3-cryptography/CVE-2026-69249.patch new file mode 100644 index 00000000000..db4f06067c7 --- /dev/null +++ b/meta/recipes-devtools/python/python3-cryptography/CVE-2026-69249.patch @@ -0,0 +1,354 @@ +From 4a12cf49675a184e47f912b00b04f3a629283582 Mon Sep 17 00:00:00 2001 +From: William Woodruff +Date: Sat, 6 Jun 2026 23:30:03 -0400 +Subject: [PATCH] Add a signature validation budget during path construction + (#14960) + +* Add a signature validation budget during path construction + +This extends our existing NC budget check to include a budget +for signature validations. If a path construction exceeds the +budget by performing more than the allowed number of signature +validation steps, the entire construction fails. + +For now, our budget is 128 signature validations. This is +consistent with (higher than) Go and rustls-webpki, which +both set a limit of 100. Like Go, we attempt to make the "best" +use of our signature budget by ordering by likelihood, using +AKI/SKI match as the strongest signal of fitness. + +* Bump limbo + +* Temporary commit + +* Revert "Temporary commit" + +This reverts commit bcdb6808562a8b8f484f85d21cb201cfdb2bbbd7. + +* Fudge a coverage test into place + +* Coverage for the coverage god + +Note: SUSE patch CVE-2026-69249-signature-validation-budget.patch was adapted to our codebase where required. The budget-handling hunks that are not present in the backported patch are already available in our existing codebase, so those changes were not applied again. + +Additionally, add tests for the ValidationError Display implementation +to align with corresponding upstream commit. + +Upstream-Status: Backport [import from suse https://download.opensuse.org/distribution/leap-micro/6.1/product/repo/openSUSE-Leap-Micro-6.1-x86_64-Source/src/python-cryptography-42.0.4-slfo.1.1_6.1.src.rpm +Upstream commit https://github.com/pyca/cryptography/commit/4a12cf49675a184e47f912b00b04f3a629283582] +CVE: CVE-2026-69249 +Signed-off-by: Vijay Anusuri +--- + .../cryptography-x509-verification/src/lib.rs | 209 +++++++++++++++++- + .../src/policy/mod.rs | 8 +- + 2 files changed, 208 insertions(+), 9 deletions(-) + +diff --git a/src/rust/cryptography-x509-verification/src/lib.rs b/src/rust/cryptography-x509-verification/src/lib.rs +index a505349..334eed4 100644 +--- a/src/rust/cryptography-x509-verification/src/lib.rs ++++ b/src/rust/cryptography-x509-verification/src/lib.rs +@@ -15,9 +15,12 @@ use std::vec; + + use cryptography_x509::extensions::{DuplicateExtensionsError, Extensions}; + use cryptography_x509::{ +- extensions::{NameConstraints, SubjectAlternativeName}, ++ extensions::{AuthorityKeyIdentifier, NameConstraints, SubjectAlternativeName}, + name::GeneralName, +- oid::{NAME_CONSTRAINTS_OID, SUBJECT_ALTERNATIVE_NAME_OID}, ++}; ++use cryptography_x509::oid::{ ++ AUTHORITY_KEY_IDENTIFIER_OID, NAME_CONSTRAINTS_OID, SUBJECT_ALTERNATIVE_NAME_OID, ++ SUBJECT_KEY_IDENTIFIER_OID, + }; + + use types::{DNSPattern}; +@@ -40,15 +43,23 @@ pub enum ValidationError { + + struct Budget { + name_constraint_checks: usize, ++ signature_checks: usize, + } + + impl Budget { +- // Same limit as other validators ++ // The maximum number of name constraint checks performed when attempting ++ // path construction. This is the same limit as other validators. + const DEFAULT_NAME_CONSTRAINT_CHECK_LIMIT: usize = 1 << 20; + ++ // The maximum number of signature verifications performed when attempting ++ // path construction. The is similar to other validators: ++ // both Go and rustls-webpki pick 100. ++ const DEFAULT_SIGNATURE_CHECK_LIMIT: usize = 1 << 7; ++ + fn new() -> Budget { + Budget { + name_constraint_checks: Self::DEFAULT_NAME_CONSTRAINT_CHECK_LIMIT, ++ signature_checks: Self::DEFAULT_SIGNATURE_CHECK_LIMIT, + } + } + +@@ -61,6 +72,15 @@ impl Budget { + ))?; + Ok(()) + } ++ ++ fn signature_check(&mut self) -> Result<(), ValidationError> { ++ self.signature_checks = self.signature_checks.checked_sub(1).ok_or_else(|| { ++ ValidationError::FatalError( ++ "Exceeded maximum signature check limit", ++ ) ++ })?; ++ Ok(()) ++ } + } + + impl From for ValidationError { +@@ -270,18 +290,57 @@ impl<'a, 'chain, B: CryptoOps> ChainBuilder<'a, 'chain, B> { + } + } + ++ /// Identify and return potential issuers for `cert`, considering ++ /// candidates from both the trusted store and untrusted intermediate set. ++ /// Trusted candidates are returned before untrusted intermediate ++ /// candidates, and both groups are opportunisitically ordered by ++ /// "likeliness" in terms of AKI/SKI match. + fn potential_issuers( + &'a self, + cert: &'a VerificationCertificate<'chain, B>, +- ) -> impl Iterator> + '_ { +- // TODO: Optimizations: +- // * Search by AKI and other identifiers? +- self.store ++ cert_extensions: &Extensions<'chain>, ++ ) -> Vec<&'a VerificationCertificate<'chain, B>> { ++ let mut candidates: Vec<&'a VerificationCertificate<'chain, B>> = self ++ .store + .get_by_subject(&cert.certificate().tbs_cert.issuer) + .iter() + .chain(self.intermediates.iter().filter(|&candidate| { + candidate.certificate().subject() == cert.certificate().issuer() + })) ++ .collect(); ++ ++ let want_kid: Option<&[u8]> = cert_extensions ++ .get_extension(&AUTHORITY_KEY_IDENTIFIER_OID) ++ .and_then(|ext| ext.value::>().ok()) ++ .and_then(|aki| aki.key_identifier); ++ ++ // This mirrors Go's `findPotentialParents`: we have a global ++ // signature budget, so we want to bucket candidates by likeliness ++ // to avoid wasting budget on (potentially adversarial) name collisions. ++ // ++ // Observe that we use a stable sort to preserve trusted candidates ++ // before untrusted candidates in each likeliness bucket. In other ++ // words, we always try a likely trusted candidate over an equally ++ // likely untrusted one. ++ // ++ // See: ++ candidates.sort_by_key(|candidate| { ++ let have_kid: Option<&[u8]> = ++ candidate.certificate().extensions().ok().and_then(|exts| { ++ exts.get_extension(&SUBJECT_KEY_IDENTIFIER_OID) ++ .and_then(|ext| ext.value::<&[u8]>().ok()) ++ }); ++ ++ match (want_kid, have_kid) { ++ // cert AKID matches candidate SKID, highest likelihood. ++ (Some(want), Some(have)) if want == have => 0, ++ // cert AKID and candidate SKID don't match, lowest likelihood. ++ (Some(_), Some(_)) => 2, ++ // cert AKID and/or candidate SKID is not present, medium likelihood. ++ _ => 1u8, ++ } ++ }); ++ candidates + } + + fn build_chain_inner( +@@ -314,7 +373,8 @@ impl<'a, 'chain, B: CryptoOps> ChainBuilder<'a, 'chain, B> { + // Otherwise, we collect a list of potential issuers for this cert, + // and continue with the first that verifies. + let mut last_err: Option = None; +- for issuing_cert_candidate in self.potential_issuers(working_cert) { ++ for issuing_cert_candidate in self.potential_issuers(working_cert, working_cert_extensions) ++ { + // A candidate issuer is said to verify if it both + // signs for the working certificate and conforms to the + // policy. +@@ -324,6 +384,7 @@ impl<'a, 'chain, B: CryptoOps> ChainBuilder<'a, 'chain, B> { + working_cert.certificate(), + current_depth, + &issuer_extensions, ++ budget, + ) { + Ok(_) => { + match self.build_chain_inner( +@@ -417,3 +478,135 @@ impl<'a, 'chain, B: CryptoOps> ChainBuilder<'a, 'chain, B> { + Ok(chain) + } + } ++ ++#[cfg(test)] ++mod tests { ++ use asn1::ParseError; ++ use cryptography_x509::certificate::Certificate; ++ use cryptography_x509::oid::SUBJECT_ALTERNATIVE_NAME_OID; ++ ++ use crate::certificate::tests::PublicKeyErrorOps; ++ use crate::ops::{CryptoOps, VerificationCertificate}; ++ use crate::policy::{Policy, PolicyDefinition, Subject}; ++ use crate::trust_store::Store; ++ use crate::types::DNSName; ++ use crate::{Budget, ChainBuilder, NameChain, ValidationError}; ++ ++ #[test] ++ fn test_validationerror_display() { ++ let err = ValidationError::Malformed( ++ ParseError::new(asn1::ParseErrorKind::InvalidLength), ++ ); ++ assert_eq!(err.to_string(), "ASN.1 parsing error: invalid length"); ++ ++ let err = ValidationError::ExtensionError{ ++ oid: SUBJECT_ALTERNATIVE_NAME_OID, ++ reason: "duplicate extension", ++ }; ++ assert_eq!( ++ err.to_string(), ++ "invalid extension: 2.5.29.17: duplicate extension" ++ ); ++ ++ let err = ValidationError::FatalError("oops"); ++ assert_eq!(err.to_string(), "fatal error: oops"); ++ } ++ ++ /// A `CryptoOps` whose public key extraction and signature verification ++ /// always succeed, so that `valid_issuer` can be driven to completion ++ /// without real cryptographic material. ++ struct NullOps; ++ ++ impl CryptoOps for NullOps { ++ type Key = (); ++ type Err = (); ++ type CertificateExtra = (); ++ type PolicyExtra = (); ++ ++ fn public_key(&self, _cert: &Certificate<'_>) -> Result { ++ Ok(()) ++ } ++ ++ fn verify_signed_by( ++ &self, ++ _cert: &Certificate<'_>, ++ _key: &Self::Key, ++ ) -> Result<(), Self::Err> { ++ Ok(()) ++ } ++ ++ fn clone_public_key(_key: &Self::Key) -> Self::Key {} ++ ++ fn clone_extra(_extra: &Self::CertificateExtra) -> Self::CertificateExtra {} ++ } ++ ++ #[test] ++ fn test_clone() { ++ assert_eq!(NullOps::clone_public_key(&()), ()); ++ assert_eq!(NullOps::clone_extra(&()), ()); ++ } ++ ++ // A self-issued ("looping") CA certificate that is its own issuer. ++ fn looping_ca_pem() -> pem::Pem { ++ pem::parse( ++ "-----BEGIN CERTIFICATE----- ++MIIBcjCCARmgAwIBAgIBATAKBggqhkjOPQQDAjAhMR8wHQYDVQQDDBZsb29waW5n ++IHNlbGYtc2lnbmVkIENBMB4XDTIzMTIzMTAwMDAwMFoXDTI0MDEzMTAwMDAwMFow ++ITEfMB0GA1UEAwwWbG9vcGluZyBzZWxmLXNpZ25lZCBDQTBZMBMGByqGSM49AgEG ++CCqGSM49AwEHA0IABKAoXUGnHdfXJbSXjRjeW+PCVHmlo4KEki69N5pJUA0QyQMR ++v9ySOMnWf3Ea7TR4g3zdguwTP7LdpSku3uR1QkmjQjBAMA8GA1UdEwEB/wQFMAMB ++Af8wDgYDVR0PAQH/BAQDAgGGMB0GA1UdDgQWBBR23MGdG1Ma9iR+3CxKTafD/OE0 ++dTAKBggqhkjOPQQDAgNHADBEAiA4RCr07KfZdM16VfGNZAQFjvC60SWIU3RRVY/L ++qolIOwIgCaIgj9ipK0Q0p+45UJiq+L/ncrxsweJkFq/UYubzhX0= ++-----END CERTIFICATE-----", ++ ) ++ .unwrap() ++ } ++ ++ /// Exercises our pathlen overflow error scenario. ++ /// ++ /// This condition is logically unreachable from Python, since ++ /// we unconditionally limit signature checks to a number smaller ++ /// than `u8::MAX`, meaning that we always exhaust the signature budget ++ /// before potentially exhausting the pathlen budget. ++ /// ++ /// To test that directly, we manually lift the signature budget ++ /// and start our pathlen state right at `u8::MAX`, guaranteeing ++ /// an overflow on the immediate chain building step. ++ #[test] ++ fn test_build_chain_inner_depth_overflow() { ++ let pem = looping_ca_pem(); ++ let ca = asn1::parse_single::>(pem.contents()).unwrap(); ++ let ca_exts = ca.extensions().ok().unwrap(); ++ ++ // The same self-issued CA is both the working certificate and its own ++ // (only) candidate issuer, so the search recurses on itself. ++ let working = VerificationCertificate::::new(&ca, ()); ++ let intermediates = [VerificationCertificate::::new(&ca, ())]; ++ let store: Store<'_, NullOps> = Store::new([]); ++ ++ let subject = Subject::DNS(DNSName::new("example.com").unwrap()); ++ let time = asn1::DateTime::new(2024, 1, 1, 0, 0, 0).unwrap(); ++ let policy_def = ++ PolicyDefinition::server(NullOps, subject, time, Some(u8::MAX), None, None).unwrap(); ++ let policy = Policy::new(&policy_def, ()); ++ ++ let builder = ChainBuilder::new(&intermediates, &policy, &store); ++ let mut budget = Budget { ++ name_constraint_checks: usize::MAX, ++ signature_checks: usize::MAX, ++ }; ++ ++ let name_chain = NameChain::new::(None, &ca_exts, false) ++ .ok() ++ .unwrap(); ++ let err = builder ++ .build_chain_inner(&working, u8::MAX, &ca_exts, name_chain, &mut budget) ++ .unwrap_err(); ++ ++ assert!(matches!( ++ err.kind, ++ ValidationError::Other(msg) if msg.contains("current depth calculation overflowed") ++ )); ++ } ++} +diff --git a/src/rust/cryptography-x509-verification/src/policy/mod.rs b/src/rust/cryptography-x509-verification/src/policy/mod.rs +index d5a199d..5bdc8d5 100644 +--- a/src/rust/cryptography-x509-verification/src/policy/mod.rs ++++ b/src/rust/cryptography-x509-verification/src/policy/mod.rs +@@ -25,7 +25,7 @@ use once_cell::sync::Lazy; + use crate::ops::CryptoOps; + use crate::policy::extension::{ca, common, ee, Criticality, ExtensionPolicy, ExtensionValidator}; + use crate::types::{DNSName, DNSPattern, IPAddress}; +-use crate::{ValidationError, VerificationCertificate}; ++use crate::{Budget, ValidationError, VerificationCertificate}; + + // SubjectPublicKeyInfo AlgorithmIdentifier constants, as defined in CA/B 7.1.3.1. + +@@ -463,10 +463,16 @@ impl<'a, B: CryptoOps> Policy<'a, B> { + child: &Certificate<'_>, + current_depth: u8, + issuer_extensions: &Extensions<'_>, ++ budget: &mut Budget, + ) -> Result<(), ValidationError> { + // The issuer needs to be a valid CA at the current depth. + self.permits_ca(issuer.certificate(), current_depth, issuer_extensions)?; + ++ // Charge the (potentially expensive) signature verification against the ++ // budget before performing it, bounding the total work an attacker can ++ // force during chain building. ++ budget.signature_check()?; ++ + // CA/B 7.1.3.1 SubjectPublicKeyInfo + // NOTE: We check the issuer's SPKI here, since the issuer is + // definitionally a CA and thus subject to CABF key requirements. +-- +2.43.0 + diff --git a/meta/recipes-devtools/python/python3-cryptography_42.0.5.bb b/meta/recipes-devtools/python/python3-cryptography_42.0.5.bb index 8148ec0ba56..899332123fc 100644 --- a/meta/recipes-devtools/python/python3-cryptography_42.0.5.bb +++ b/meta/recipes-devtools/python/python3-cryptography_42.0.5.bb @@ -14,6 +14,7 @@ SRC_URI += "file://0001-pyproject.toml-remove-benchmark-disable-option.patch \ file://CVE-2026-26007.patch \ file://CVE-2026-34073.patch \ file://CVE-2026-69248.patch \ + file://CVE-2026-69249.patch \ file://check-memfree.py \ file://run-ptest \ " From patchwork Wed Sep 23 09:10:47 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 99003 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 2D223C982FA for ; Wed, 23 Sep 2026 09:12:26 +0000 (UTC) Received: from mail-wm2-f13.google.com (mail-wm2-f13.google.com [74.125.225.141]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.2843.1790154741858295228 for ; Wed, 23 Sep 2026 02:12:22 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=oE2J0WO1; spf=pass (domain: smile.fr, ip: 74.125.225.141, mailfrom: yoann.congal@smile.fr) Received: by mail-wm2-f13.google.com with SMTP id 5b1f17b1804b1-49e721b5503so5657545e9.0 for ; Wed, 23 Sep 2026 02:12:21 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1790154740; x=1790759540; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=qFjIm41PCn/v34mzQG/gZlENNac9G1Z2HGZpDOVuRZg=; b=oE2J0WO19c1wIvgwnUOnmYbbXDKUW4IdbX19xYYBJP51YkaOo2Jnzt2JlOy3Cj55If lXfXx6oLchveF4qRgwoEIs6nt4R9ZXiK9+/4l8p4rbNvmRUQ48a8urGZ6Zexrko7VNp3 7IMNwc2WCGDfdTvRpYdM1MPYshosgorCBxO64= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1790154740; x=1790759540; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=qFjIm41PCn/v34mzQG/gZlENNac9G1Z2HGZpDOVuRZg=; b=GMY6ivN7jtiwYaLsumja2rE0zh72ApoyrcmOyC0Gz575q72DsHWCPnY6OlIeCFJXAY N6cM04Z1Dwm30CMzxWEBKFmfErFTlAGj5M8/2y4qauMDCmTOll4QieBHAXuXxDRcpvHY y5OQMQRTDNfwIksGC3TxPv/40f3+XWGRJS5uTZWfxZDC44gH5gTrAWQNu+4WGcrQXv7O 9PHPmK4u9uhIVw47SHA//OBsNmr4L7f6DyePCc5hLgbZbmEd2zOm0OCWNw9okiaV7QPk CibCl8TAviKKkM5U6VusRGYzUvim7QzIYCXnS4RJHlIsW8oz48QcbG/n/JmV6qpSaF5O /YKw== X-Gm-Message-State: AFuF++lP0kNb6lbU++hAeZH1GZN+EaPEdSCgGTNCnKkBNuer7sXq9h2T H2wi9CF+J1K+0nurwxFgWo17/rfz9X/AxM6DVtwJgRl7sawHqU/BLSN91uyaGaSmKdpehyysRDS vZqNDM0o= X-Gm-Gg: AYBFou1ODGNHuVSYkUc3/RuoS77yfBYvxUACvgO+Kk61KuS8qM2mVTEzyUBd9zDHFTM MpgOkhyB8DF7Vmv5CFMX5rCELxT7b/3nx2ER9mDIR2EDELOoZe+26t+hA2mWwVgUtyHlnKtNRO+ rMl1CSjgs2TIFoYPrjhbpvDxbWp7hnejh+LdRzwR/ZRS1YNlQOmwnGlbZ29tJyMsU3DB85QpMzB JDEbQUiGR1F2eUZggIkLhemqbRPlB38Kh5B+qcBu1J3x2/capQuQVRz7h0jU7kfi/lBmcaYIN0p 6jhSO3SrNpJXa3YTIOVrYzyaaURlWI+qKShpkUj0K27vMS2bJjsk4UC7FfPSSyzGyoa5J3Exrub 7tCKJCaV3GkRfkC0Es3rai5dRfO13hNFJjixlj+GLyORhgRTGfFEe+wnS/Vimb0l71MtBv61ypQ o3J4PsyWYtYBOndpmdYp0TvMLg0s3GOUg+V5qolsc/8CN6SeOV2gHnGm0iZ/ZQPMdj+CIWUWwuU Xuam172vx9LE5v2WvUSN4n2P6zfoCY74gMbx85iTttVGcrEkP1rZCMLYR8GhqHbjCAFGHGv X-Received: by 2002:a05:600c:500d:b0:49d:28c4:b304 with SMTP id 5b1f17b1804b1-49fdf1485e3mr24931425e9.29.1790154740097; Wed, 23 Sep 2026 02:12:20 -0700 (PDT) Received: from FRSMI25-LASER.home (2a02-8440-b519-f416-8bed-8817-19fd-ccf7.rev.sfr.net. [2a02:8440:b519:f416:8bed:8817:19fd:ccf7]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-49fe2730da9sm14251525e9.4.2026.09.23.02.12.19 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 23 Sep 2026 02:12:19 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][scarthgap 45/48] curl: Security Fix for CVE-2026-13608 Date: Wed, 23 Sep 2026 11:10:47 +0200 Message-ID: X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Wed, 23 Sep 2026 09:12:26 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/246507 From: Siddharth Doshi Picking patch as per [1], and same patch is mentioned in [2] [1] https://curl.se/docs/CVE-2026-13608.html [2] https://security-tracker.debian.org/tracker/CVE-2026-13608 Signed-off-by: Siddharth Doshi Signed-off-by: Yoann Congal --- .../curl/curl/CVE-2026-13608.patch | 48 +++++++++++++++++++ meta/recipes-support/curl/curl_8.7.1.bb | 1 + 2 files changed, 49 insertions(+) create mode 100644 meta/recipes-support/curl/curl/CVE-2026-13608.patch diff --git a/meta/recipes-support/curl/curl/CVE-2026-13608.patch b/meta/recipes-support/curl/curl/CVE-2026-13608.patch new file mode 100644 index 00000000000..bb1662fa4c0 --- /dev/null +++ b/meta/recipes-support/curl/curl/CVE-2026-13608.patch @@ -0,0 +1,48 @@ +From 25df759f0f0c1aeaee066a4502bb36a8a86fb22e Mon Sep 17 00:00:00 2001 +From: Daniel Stenberg +Date: Mon, 29 Jun 2026 10:44:47 +0200 +Subject: [PATCH 1/5] openldap: handle Curl_sasl_continue() returns better + +Similar to how it gets treated already in other protocol handlers. + +Follow-up to eeca818b1e8d1e61c2d4 + +Reported-by: Eunsoo Kim +Closes #22213 + +Upstream-Status: Backport [https://github.com/curl/curl/commit/ea71c3b6b60e563651ea8596a975aef0c8199519] +CVE: CVE-2026-13608 +Signed-off-by: Siddharth Doshi +--- + lib/openldap.c | 15 +++++++++++++-- + 1 file changed, 13 insertions(+), 2 deletions(-) + +diff --git a/lib/openldap.c b/lib/openldap.c +index 47266f6..b566d1a 100644 +--- a/lib/openldap.c ++++ b/lib/openldap.c +@@ -682,8 +682,19 @@ static CURLcode oldap_state_sasl_resp(struct Curl_easy *data, + } + else { + result = Curl_sasl_continue(&li->sasl, data, code, &progress); +- if(!result && progress != SASL_INPROGRESS) +- oldap_state(data, OLDAP_STOP); ++ if(!result) { ++ switch(progress) { ++ case SASL_DONE: ++ oldap_state(data, li, OLDAP_STOP); /* Authenticated */ ++ break; ++ case SASL_IDLE: /* No mechanism left after cancellation */ ++ failf(data, "Authentication cancelled"); ++ result = CURLE_LOGIN_DENIED; ++ break; ++ default: ++ break; ++ } ++ } + } + + if(li->servercred) +-- +2.34.1 + diff --git a/meta/recipes-support/curl/curl_8.7.1.bb b/meta/recipes-support/curl/curl_8.7.1.bb index f2479a33643..3f44cf02d31 100644 --- a/meta/recipes-support/curl/curl_8.7.1.bb +++ b/meta/recipes-support/curl/curl_8.7.1.bb @@ -41,6 +41,7 @@ SRC_URI = " \ file://CVE-2026-5545.patch \ file://CVE-2026-6253.patch \ file://CVE-2026-4873.patch \ + file://CVE-2026-13608.patch \ " SRC_URI:append:class-nativesdk = " \ From patchwork Wed Sep 23 09:10:48 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 99005 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 40F3BC98308 for ; Wed, 23 Sep 2026 09:12:26 +0000 (UTC) Received: from mail-wm2-f12.google.com (mail-wm2-f12.google.com [74.125.225.140]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.2844.1790154742843308926 for ; Wed, 23 Sep 2026 02:12:23 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=Ak1TOGy9; spf=pass (domain: smile.fr, ip: 74.125.225.140, mailfrom: yoann.congal@smile.fr) Received: by mail-wm2-f12.google.com with SMTP id 5b1f17b1804b1-49b912d37b6so3523175e9.0 for ; Wed, 23 Sep 2026 02:12:22 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1790154741; x=1790759541; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=cNMQAkxz12NFSeN3eoDwFlPhL4l17v3wO0WOwdmh+zU=; b=Ak1TOGy9xcuBSNr3ib8uTSIYN8V5W3VR+f1HI0xnBXSKd07hSUTfkhSov8LSMLvLAh cl2D4+tmObU02XYD+xi8hdkuWnYSQgST0PSQaou4Mf9AxYS8rP1Mdx+fzcNJbUdmjgqS nRAB05P7xi3PO5Yy1EpHoNBOHeXhp84B5Bb4I= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1790154741; x=1790759541; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=cNMQAkxz12NFSeN3eoDwFlPhL4l17v3wO0WOwdmh+zU=; b=Ad0pZrGFtscbrPpruNpkYWlyglM25y2YWUeLxTJIIRzgghG5ij6t1Sh3D0iqhbYuWp IICE4QgbdLz+s2j/Da9XnAyANZeR+bbZLr4c6+imFRvyi673QYAhHioo7xIsFIcKUvt9 l1I6zhjYTaBpbiuee5Tq6PQhE1VpVe3DszdIWtvzBvnHnMIIPLzAUcBK+twk9XV86gm4 0zmi5H+NZwkVUCNAYvqsVHLRMg+8vb+Traqdi/JhcEClBhqKd4YNGa3CRHsO4zlO2C5j sn2Ia45DzYysJwzJAn07AjqFOTBlAdKWOJE4t/JZxCtW0zStbLfn73OqOC2Tf4xuKGjV J+ZQ== X-Gm-Message-State: AFuF++kB93ftKxweE+G9oz7nfEwI5HiFn0y4cBnRPB9Qw2VD258HfpRb iEeUn+NGCSJZpHXzgI+YGb2qNwG7+pRvj724iB4/aU5sycCx9PvmnFSG9hPomoRQQDCTqvH8JOm CcDC/6gs= X-Gm-Gg: AYBFou2oWoozbPqTWFF4XLnJQ3XZrQnv8jUMRSsIJsYGaHmGlyOma2CTXFxurws5Phc lN2SlXEYJifn1bVRElc8jA0YvtsL8UkH7ex3EbKNKLFnMP2ff5BH/WkUaOufy7R1QBfxYxLreq1 qOYpS1jYVGOx/NV9srSVNTVK6dpCoyaYbE3mjtbC1q0ByMoJn4GZNbcZSuXcnIY/7joCJTDywmd MLSSSEzKJvEJ/oz8v4mPI38Zrb8JPhj9DBQfg1BPCUW55MD9vOf+xcuFgbbUwjcdmMa/lwFzXlB +mMLC2rLt4suzR8iKLlJRULPz1Jk6t90WvqbVYbA0VSwIjygxF/b9zvgy3b+GgZeLk4mUJbFIg/ 25wlHLYZuDH0z07Hwi0eFZsGiKqO08zo2daGwcmOokbmwip/I4SPUhkfOVcDTukTMvbre81RSz+ toh084JEuwjVWKO8VUKbEz/ZnfXFMfeQLpeaqj75uvNcLkXDsC/oTS57lTbHeipcotsWhdiMAtA +a8aDagXxnq+u7mZP8cHyPqJHDp2f3YcAoi6Dmms+EoiLCd/OMKpJLeVk1nlhqIhH8S61cJ X-Received: by 2002:a05:600c:1908:b0:49f:ce78:3560 with SMTP id 5b1f17b1804b1-49fdee0a35emr21455475e9.17.1790154741005; Wed, 23 Sep 2026 02:12:21 -0700 (PDT) Received: from FRSMI25-LASER.home (2a02-8440-b519-f416-8bed-8817-19fd-ccf7.rev.sfr.net. [2a02:8440:b519:f416:8bed:8817:19fd:ccf7]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-49fe2730da9sm14251525e9.4.2026.09.23.02.12.20 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 23 Sep 2026 02:12:20 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][scarthgap 46/48] curl: Security Fix for CVE-2026-18924 Date: Wed, 23 Sep 2026 11:10:48 +0200 Message-ID: <8305fd4d8e6e4a7a4435989c57fedd470306f0e6.1790154074.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Wed, 23 Sep 2026 09:12:26 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/246508 From: Siddharth Doshi Picking patch as per [1], and same patch is mentioned in [2] [1] https://curl.se/docs/CVE-2026-18924.html [2] https://security-tracker.debian.org/tracker/CVE-2026-18924 Signed-off-by: Siddharth Doshi Signed-off-by: Yoann Congal --- .../curl/curl/CVE-2026-18924.patch | 39 +++++++++++++++++++ meta/recipes-support/curl/curl_8.7.1.bb | 1 + 2 files changed, 40 insertions(+) create mode 100644 meta/recipes-support/curl/curl/CVE-2026-18924.patch diff --git a/meta/recipes-support/curl/curl/CVE-2026-18924.patch b/meta/recipes-support/curl/curl/CVE-2026-18924.patch new file mode 100644 index 00000000000..28934ababee --- /dev/null +++ b/meta/recipes-support/curl/curl/CVE-2026-18924.patch @@ -0,0 +1,39 @@ +From 90325ff0444cbdff368bda5d26d6405a0bb6ee43 Mon Sep 17 00:00:00 2001 +From: Daniel Stenberg +Date: Wed, 5 Aug 2026 10:02:53 +0200 +Subject: [PATCH] http2: make server push transfers inherit share from parent + +Reported-by: Stephan Zeisberg +Closes #22488 + +Upstream-Status: Backport [https://github.com/curl/curl/commit/90325ff0444cbdff368bda5d26d6405a0bb6ee43] +CVE: CVE-2026-18924 +Signed-off-by: Siddharth Doshi +--- + lib/http2.c | 3 +++ + 1 file changed, 3 insertions(+) + +diff --git a/lib/http2.c b/lib/http2.c +index 99d7f3b..e6305c9 100644 +--- a/lib/http2.c ++++ b/lib/http2.c +@@ -47,6 +47,7 @@ + #include "transfer.h" + #include "dynbuf.h" + #include "headers.h" ++#include "curl_share.h" + /* The last 3 #include files should be in this order */ + #include "curl_printf.h" + #include "curl_memory.h" +@@ -776,6 +777,8 @@ static struct Curl_easy *h2_duphandle(struct Curl_cfilter *cf, + second->req.p.http = http; + http2_data_setup(cf, second, &second_stream); + second->state.priority.weight = data->state.priority.weight; ++ if(data->share) ++ (void)Curl_share_easy_link(second, data->share); + } + } + return second; +-- +2.34.1 + diff --git a/meta/recipes-support/curl/curl_8.7.1.bb b/meta/recipes-support/curl/curl_8.7.1.bb index 3f44cf02d31..905d0b47335 100644 --- a/meta/recipes-support/curl/curl_8.7.1.bb +++ b/meta/recipes-support/curl/curl_8.7.1.bb @@ -42,6 +42,7 @@ SRC_URI = " \ file://CVE-2026-6253.patch \ file://CVE-2026-4873.patch \ file://CVE-2026-13608.patch \ + file://CVE-2026-18924.patch \ " SRC_URI:append:class-nativesdk = " \ From patchwork Wed Sep 23 09:10:49 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 99002 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 3A8C6C982EA for ; Wed, 23 Sep 2026 09:12:26 +0000 (UTC) Received: from mail-wm2-f13.google.com (mail-wm2-f13.google.com [74.125.225.141]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.2845.1790154743754618547 for ; Wed, 23 Sep 2026 02:12:24 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=DJO0MbVN; spf=pass (domain: smile.fr, ip: 74.125.225.141, mailfrom: yoann.congal@smile.fr) Received: by mail-wm2-f13.google.com with SMTP id 5b1f17b1804b1-49b965f447cso4941645e9.3 for ; Wed, 23 Sep 2026 02:12:23 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1790154742; x=1790759542; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=gO6T6To7ScCHifdr+P3FY9+1kOCOBdbzf0CsbNLJv/4=; b=DJO0MbVNaW6S8f5WD+bDhiDNOQnw6b82bOVqaev/7N7n7DSgZPCu8ihYjKe780kRI/ 43wXYdo5kP28R2opR48XNGRR6sV0fCcyRmi3DyzlpWhArl3S7/lDaP0N6T/lZ0q5nPG6 YjkTcB8SCfORCn65BkZN89flObRSBPOTZuaPg= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1790154742; x=1790759542; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=gO6T6To7ScCHifdr+P3FY9+1kOCOBdbzf0CsbNLJv/4=; b=tDyHtOXHTKQOBJ/xrKMDJyjhdxB/ky8jkBJ9h1owQWdaJV870sCGMMuf2j0QWLaMuJ XMHjnYK3nSGvvurf9UI+qUiODLzClbKbKC/wxKXzUBYT2WIK66MM//3NRc6hn2aW/U9s LCgWMa4pWG9U+v4U45mUMo/c7Lu3aOxpesoTZvKpdIHFELtEj9jrxIPGKGaBNAKxVXq2 PuCvarVWh5BCBKO1oc+S3GeBuRzaLJn0+9lxQOAm4ROijUJWlcR+C4HlX8n65MzzWu9j S/m2dsbqLJYHU/zEW/635S9VPtwzdNe5x0msL6ZFdrXFHN469xUcTrUbKuO28xNTGLBx OzpQ== X-Gm-Message-State: AFuF++nY61epAaY4zNHsGuT/oRQKM9DI1ZZMKeKOUce1fsHsV8+1kzT+ G/gjloY4eFdO4ytxmhl9Yn7S3Ym9G8SCw9i8Ev+DMBAT/hh9NF7M6FY1ZjaUmpBP2NZ3raJYFAQ Z6HLJ1D8= X-Gm-Gg: AYBFou0GLBUG8rlI2ofY9MCpQusGX7cYMCgZV8mmYMwcVJ67BbOE/NpwtfRufBpXHPw Mp49G6kDMuYmqb11szI/BOxAoAaiWG3yef+3w9Lppp5DUKNSbgux8Rfr7CDMu1FR9BFuAiTKb9D suU1KwbRopWZ7hkdoLcBV2yga6+oJf2Kw0a9DMLWeRdOZuWiOKt0C4ZV7fngwS9SQePbJWVD/mg QgO2dAnicDBeYZqy31AuNdazLOUhnPHMIHCdvmiMZLl3gyOxCxVKJ26lgnvLefidwNNt3z7NdIW PTIOp3OnjbMX5tHRrd63jD5WJ6xAEuVnFJhgVcM3JgVpczpmDLDKQRUx2gc8pJRPp/k3hqoeaAD SCumTuCCm8ogqZfApUXRvlQREJFIDYTIv/oRctHcSkiTf+eZYJFm6wOjkpHhHVlHWOAEUdYozdJ VoN70mobIm+6NxECm9r3Jjf/x03EW0KWZEPQ6QMgUGHzsMJY6t99GK6rpABHjLg3H+/AKpIggFi YSaQ9PBGvr97gvJ1inhobqhFCpRJZlyOPNL3HiaPULXO5kS8tzDkGUqRrXseooinjlTWLGs X-Received: by 2002:a05:600c:6091:b0:49d:39:90ba with SMTP id 5b1f17b1804b1-49fdee0bb6fmr25209965e9.3.1790154742000; Wed, 23 Sep 2026 02:12:22 -0700 (PDT) Received: from FRSMI25-LASER.home (2a02-8440-b519-f416-8bed-8817-19fd-ccf7.rev.sfr.net. [2a02:8440:b519:f416:8bed:8817:19fd:ccf7]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-49fe2730da9sm14251525e9.4.2026.09.23.02.12.21 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 23 Sep 2026 02:12:21 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][scarthgap 47/48] curl: set CVE_STATUS for CVE-2026-82209 Date: Wed, 23 Sep 2026 11:10:49 +0200 Message-ID: <9468a21bb23307f8d1b5cb35bf9410fdd34b10c3.1790154074.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Wed, 23 Sep 2026 09:12:26 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/246509 From: Siddharth Doshi Analysis: - The problem only exists when curl is built with libpsl support enabled.[1] - The recipe is built with "--without-libpsl" option. - Hence, ignoring the CVE for this recipe. Reference: [1] https://curl.se/docs/CVE-2026-82209.html Signed-off-by: Siddharth Doshi Signed-off-by: Yoann Congal --- meta/recipes-support/curl/curl_8.7.1.bb | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/meta/recipes-support/curl/curl_8.7.1.bb b/meta/recipes-support/curl/curl_8.7.1.bb index 905d0b47335..34bdd21b77b 100644 --- a/meta/recipes-support/curl/curl_8.7.1.bb +++ b/meta/recipes-support/curl/curl_8.7.1.bb @@ -60,7 +60,7 @@ CVE_STATUS[CVE-2025-5025] = "${@bb.utils.contains('PACKAGECONFIG', 'openssl', 'n CVE_STATUS[CVE-2025-10966] = "${@bb.utils.contains('PACKAGECONFIG', 'openssl', 'not-applicable-config: applicable only with wolfssl','unpatched',d)}" CVE_STATUS[CVE-2026-10536] = "${@bb.utils.contains('PACKAGECONFIG', 'nghttp2', 'unpatched', 'not-applicable-config: applicable only with HTTP/2', d)}" CVE_STATUS[CVE-2026-8458] = "${@bb.utils.contains('PACKAGECONFIG', 'krb5 negotiate-auth', 'unpatched', 'not-applicable-config: applicable only with GSS-API-backed Negotiate authentication', d)}" - +CVE_STATUS[CVE-2026-82209] = "not-applicable-config: public suffix list support is disabled by the recipe with --without-libpsl" inherit autotools pkgconfig binconfig multilib_header ptest From patchwork Wed Sep 23 09:10:50 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 99004 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 58C6BC98307 for ; Wed, 23 Sep 2026 09:12:26 +0000 (UTC) Received: from mail-wm2-f13.google.com (mail-wm2-f13.google.com [74.125.225.141]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.2944.1790154744807095959 for ; Wed, 23 Sep 2026 02:12:25 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=eI9Jsllx; spf=pass (domain: smile.fr, ip: 74.125.225.141, mailfrom: yoann.congal@smile.fr) Received: by mail-wm2-f13.google.com with SMTP id 5b1f17b1804b1-49cc9f581c4so2342395e9.0 for ; Wed, 23 Sep 2026 02:12:24 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1790154743; x=1790759543; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=ScJJ8mffQPxpH3Exsunanxo08v4Z+2DF0ScW1l3dgSU=; b=eI9JsllxXaBL6igTVTCyjfUv8Zd2RlQTCp/9tE55oKaTPMlvpt6/ZfTJ87qUi+JJTi 8WFuZqdvWeez0Hepgapz62yHSr90JkOktRSsjlH86wvyX6fBEQGunTwsadAp4XiKOnKx EGuvbiwvdRCxdqTjEByGibeNlBtcujCpBLQuU= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1790154743; x=1790759543; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=ScJJ8mffQPxpH3Exsunanxo08v4Z+2DF0ScW1l3dgSU=; b=GIRB0ZHfFK641QmpxgIgP1gDjXSA3sF3VFYP9Z7Gqq0bES0odN8qQvPcssKUWRS+lP Fwh2FnpMt+rUzajEHJYsh7wF5vRvvfoF2P/RFVh/HHzbl5XQeALXaru+TgqRkoOH5CoM LmRmcIqKpy/aQvnTBcAigkTmVRzZtY14JfMRPp7tdtZCW9NXi0xvhXgoUN+QwT9QXfMD xjpknKereinW6lg2OzFzselP6aH8fe3fh8L/Hk/19/gGTMA2zLDY3RQjd3Zz4t0d1qGy BgasjwrPeViTIUWwaOQEFh5BfEdsopUGL9jQkGdC/q7Vvkhe9xaL4PU/5sQ+ZN/gm3Ir +Y/Q== X-Gm-Message-State: AFuF++nWSVEcEug+7DwjkdgzHCiIxzPoOSglsCAXpUFYLAQddfKvigYk HUXy8PJWowG4qk/47Hv87TwEl6LqxQppz7w3MUAf0vi+YnDu9AYSlray7lQpqQPM91sqZr/koNZ NfKeu2+c= X-Gm-Gg: AYBFou1+Nnbztga4d0X3dOcRo9OahtdRDLWGaTANNEkwbzt4lZKGqQiqVFUumiFpD34 vIdjktHG9fK8C+0uz5pnLyTLIxPGXvDv0m9bVxkwiHIQmjI3KIXjBcsLULCeX7EELTtLqA7jXbs 2bqKnyr4DzFjsUiZX2S1OTQSwslllh0JpJzjJWYYPc0BXywF5+3B8J3JoSqWZozCSxxIA2kq7HK ZTYutpl1Atj4HaaD3l20143aXbBt0OOY8cS5RVUlvGWfHboOcJZsBdk8wFAHwJ0ymroKCiKCDgR xEIVpSHxOks/uXRSJVwy3E8Wm7wWyzvrs7oMp3TPS2p6GOi79I+JabPSaplXJ6Tcz7mk5rQPHr3 6O/sGBF6wAFRDlFnxQotF4/hCd8yCQV07oLeHpAzD+CJXi8nqNKUkm8q9pKKpMC+95tTFyfUeAb XKyHiAWSVgxJCDjXgH8NywJBABvJznWGP9guMjQeB2J/8fO0lV+aOoePktYoSc/HFp+SM843cvD 5Ca5vOstaoWReAvMfoQGBbt1LNq7bTtuEED+RhGgAlpcFhs9NEYO2irgxTvmCQBVk2HG9Lz X-Received: by 2002:a05:600c:1f90:b0:49e:6836:5386 with SMTP id 5b1f17b1804b1-49fde20e848mr27541615e9.0.1790154742962; Wed, 23 Sep 2026 02:12:22 -0700 (PDT) Received: from FRSMI25-LASER.home (2a02-8440-b519-f416-8bed-8817-19fd-ccf7.rev.sfr.net. [2a02:8440:b519:f416:8bed:8817:19fd:ccf7]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-49fe2730da9sm14251525e9.4.2026.09.23.02.12.22 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 23 Sep 2026 02:12:22 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][scarthgap 48/48] time64: enable 64-bit time/file-offset flags for 32-bit nativesdk Date: Wed, 23 Sep 2026 11:10:50 +0200 Message-ID: <70778df2c2882f1abbdd4dd2f8d229ade720d8a4.1790154074.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Wed, 23 Sep 2026 09:12:26 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/246510 From: Peter Tatrai When SDKMACHINE is set to i686 or i586, nativesdk binaries are compiled as 32-bit. Without -D_TIME_BITS=64 and -D_FILE_OFFSET_BITS=64, stat() and time-related syscalls use 32-bit types, causing EOVERFLOW on filesystems with large inode numbers (e.g. container overlay filesystems) and Y2038 issues. Add SDK_CC_ARCH appends for class-nativesdk:i686 and class-nativesdk:i586 using GLIBC_64BIT_TIME_FLAGS, mirroring how target architectures are handled. The existing GLIBC_64BIT_TIME_FLAGS:pn-glibc override only matches the target recipe, not the class extended nativesdk-glibc, so an additional pn-nativesdk-glibc override is needed here. This is required on scarthgap but not on master/wrynose, because scarthgap carries glibc 2.39, which predates glibc commit a4ed0471d717 ("Always define __USE_TIME_BITS64 when 64 bit time_t is used"). In 2.39 the header redirect turns sigtimedwait into an alias of __sigtimedwait64, which then collides with glibc's own weak_alias() and fails to assemble: Error: symbol '__sigtimedwait64' is already defined Also exclude nativesdk-mingw-w64-runtime. The MinGW runtime provides the Windows CRT rather than glibc, and _FILE_OFFSET_BITS=64 changes its stat declarations. That causes conflicting declarations for wstat when building the CRT itself. Signed-off-by: Peter Tatrai Signed-off-by: Richard Purdie (cherry picked from commit d9f62a45555673842021d5746437e66c40d3f3cc) Signed-off-by: Peter Tatrai Signed-off-by: Yoann Congal --- meta/conf/distro/include/time64.inc | 17 +++++++++++++++++ 1 file changed, 17 insertions(+) diff --git a/meta/conf/distro/include/time64.inc b/meta/conf/distro/include/time64.inc index dd29105db44..c2a4feab24b 100644 --- a/meta/conf/distro/include/time64.inc +++ b/meta/conf/distro/include/time64.inc @@ -32,6 +32,23 @@ GLIBC_64BIT_TIME_FLAGS:pn-pulseaudio = "" # libsanitizer/sanitizer_common/sanitizer_platform_limits_posix.cpp GLIBC_64BIT_TIME_FLAGS:pn-gcc-sanitizers = "" +# Apply the same flags to nativesdk packages when building for a 32-bit SDK +# host (i686, i586). +SDK_CC_ARCH:append:class-nativesdk:i686 = "${GLIBC_64BIT_TIME_FLAGS}" +SDK_CC_ARCH:append:class-nativesdk:i586 = "${GLIBC_64BIT_TIME_FLAGS}" + +# Recipes which implement or wrap the libc APIs themselves must not be built +# with these flags, as the redirections glibc performs would collide with the +# symbols the recipes define (e.g. "symbol '__sigtimedwait64' is already +# defined" in nativesdk-glibc, or duplicate creat64/fopen64 in +# nativesdk-pseudo). The pn- overrides above only match the target recipes, so +# the class extended variants have to be listed separately. +GLIBC_64BIT_TIME_FLAGS:pn-nativesdk-glibc = "" +GLIBC_64BIT_TIME_FLAGS:pn-nativesdk-pseudo = "" +# The MinGW runtime provides the Windows CRT rather than glibc. These flags +# change its stat declarations and cause conflicting types in the CRT sources. +GLIBC_64BIT_TIME_FLAGS:pn-nativesdk-mingw-w64-runtime = "" + # Caused by the flags exceptions above INSANE_SKIP:append:pn-gcc-sanitizers = " 32bit-time" INSANE_SKIP:append:pn-glibc = " 32bit-time"