From patchwork Wed Sep 23 10:40:15 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Ankur Tyagi X-Patchwork-Id: 99013 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id C9F51C982FA for ; Wed, 23 Sep 2026 10:41:04 +0000 (UTC) Received: from mail-pz2-f41.google.com (mail-pz2-f41.google.com [74.125.228.41]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.4261.1790160063246948064 for ; Wed, 23 Sep 2026 03:41:03 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@gmail.com header.s=20251104 header.b=kLHMkMy4; spf=pass (domain: gmail.com, ip: 74.125.228.41, mailfrom: ankur.tyagi85@gmail.com) Received: by mail-pz2-f41.google.com with SMTP id d2e1a72fcca58-8631d0023daso420149b3a.2 for ; Wed, 23 Sep 2026 03:41:03 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1790160062; x=1790764862; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:from:to:cc:subject:date:message-id:reply-to:content-type; bh=DrZphn7M2yZUxStEGfwKl5jBXS/BJdY9IICXfWJGmg4=; b=kLHMkMy4qAndH8DvVTbqpQiKUfvi2ECQDixPqhm1kLE8iJrKmbZc0/cnxm/RINkHno qB4pH3WE7iKF545P0KuT+ZrHl5EqjKKD/dLleYfKNwJD0G80D8M49O4tiqK5fPKk1qRg nhanhragsdwaBvyLnez/6pqKG6pXbr3zxBAZnzsI9BvQPtiN9oyq9+Gqhuefwg/2WiGv iCm++DxcU2W3wWnZ00C2fJuDBaNTNG2nE701iFLH6IZ7HEEGIqTupDQVXUFikS1yzsHp T7aIF9xi6sSysUxPXoWgITv3n1RJcW6A71VfAe28lOH5dvnHm0rsNIGh59HV5mAKDzwe 84oQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1790160062; x=1790764862; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:x-gm-gg:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to:content-type; bh=DrZphn7M2yZUxStEGfwKl5jBXS/BJdY9IICXfWJGmg4=; b=cydn5bbS0pFkXesXVMLprzN05qpU0qYYc7KXS7DXZ5izcwHIYjrpS1Ri9KKOTeNmH/ 3cBV1wCaIlFLqQwaLt/I84AYOs1iIEhhZT7L5xCfnYrYPPmIJUFVC/r+MnBplCOJf8Fo q1KlYfBZqEw9kq/A7c83Ls3hOkg+tbm88Xlk2znqHjd51iuYIreGPV/xJTqchKUB7m5B eQgk34/Oiflq/UJ7DSBidx3k2Rjkc3GPeur/y2jhmXbxxS5Qs7n8TAngZNVvIkt7LWuy rdHMzPotdDyhT5768rhe+YdsoFNOD3oeW5p9hKukOX9I9c1QR8/fD6vL4ksAw754xmcT mT4Q== X-Gm-Message-State: AFuF++kGkATsmyJQIHhUvXqN3Hul6+Rvedk/74NjPdqM6z6lA+nqQD65 WlHYhxGJm6yeIn4V7zo0NJBXhItHoGqZ2nq33p+2ASmPjRYQVt5SEMPrDfnTLA== X-Gm-Gg: AYBFou3OYxUZjoO8CNAj9ZkfxyVewsxwJi9N/P1mbOLj7PIlMw3GlGHRPR+kFOY8J/m oAwUMDc8Qcm/o1FWsHmqkQMLg/m+c4EHM5WrYytEuI+JOoUk+fH13N4xqcyDzgGLce9Aqcpmpq2 PaNPvztmw+S8i65AhrLet7q1DUdftWByz8glVfWsJHkDoW7+5nB1pWzw25p1Vad1pNT3tV2g0UF JN5gINX+4+lQAYdkQS4rgI/x6YqDTJgWBFA3/2d35WOrcqXILAjHNjM/EWBciMJG4CwjbtXFnM5 UJo6MpnaXSYkPl7m57guTZbgPsC4KpmuUO7uEeRYB/AHbn36YyZtuXd2Fr2OJzrg99w72+1N4cS BPHUBuIdnrLdpWIMO3F2o/sgRyq8n5YawLHNFflP7oxUX0Ws5YQEnB61Tbjqy0tgncx76fMET9Y hGtKl2dqwjqSwydgRLcn3rNhEPqs3754T/NYD2Pda2jz6WpDGqi3mzyhzHGDeMVSk4KG0r1x9K1 LPH/T4UHnkt1HNCre/AD9m6Fb116nunfg== X-Received: by 2002:a05:6a20:914e:b0:3db:3d0b:31fd with SMTP id adf61e73a8af0-3ddf7ca7ba0mr2003869637.1.1790160062436; Wed, 23 Sep 2026 03:41:02 -0700 (PDT) Received: from NVAPF55DW0D-IPD.. ([203.211.104.195]) by smtp.gmail.com with ESMTPSA id d2e1a72fcca58-87d1d5c1646sm1035870b3a.30.2026.09.23.03.41.00 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 23 Sep 2026 03:41:02 -0700 (PDT) From: ankur.tyagi85@gmail.com To: openembedded-devel@lists.openembedded.org Cc: Ankur Tyagi Subject: [oe][meta-oe][wrynose][PATCH 1/42] c-ares: mark CVEs fixed Date: Wed, 23 Sep 2026 22:40:15 +1200 Message-ID: <20260923104056.457360-1-ankur.tyagi85@gmail.com> X-Mailer: git-send-email 2.43.0 MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Wed, 23 Sep 2026 10:41:04 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-devel/message/130188 From: Ankur Tyagi CVE-2026-33630, CVE-2026-69184 and CVE-2026-69186 were fixed in v1.34.7[1] Details: https://nvd.nist.gov/vuln/detail/cve-2026-33630 https://nvd.nist.gov/vuln/detail/cve-2026-69184 https://nvd.nist.gov/vuln/detail/cve-2026-69186 [1]https://github.com/c-ares/c-ares/releases/tag/v1.34.7 Signed-off-by: Ankur Tyagi --- meta-oe/recipes-support/c-ares/c-ares_1.34.8.bb | 3 +++ 1 file changed, 3 insertions(+) diff --git a/meta-oe/recipes-support/c-ares/c-ares_1.34.8.bb b/meta-oe/recipes-support/c-ares/c-ares_1.34.8.bb index 058f3666e7..b86b0976c2 100644 --- a/meta-oe/recipes-support/c-ares/c-ares_1.34.8.bb +++ b/meta-oe/recipes-support/c-ares/c-ares_1.34.8.bb @@ -30,3 +30,6 @@ FILES:${PN}-utils = "${bindir}" BBCLASSEXTEND = "native nativesdk" CVE_STATUS[CVE-2025-31498] = "fixed-version: Fixed since 1.34.5" +CVE_STATUS[CVE-2026-33630] = "fixed-version: Fixed since 1.34.7" +CVE_STATUS[CVE-2026-69184] = "fixed-version: Fixed since 1.34.7" +CVE_STATUS[CVE-2026-69186] = "fixed-version: Fixed since 1.34.7" From patchwork Wed Sep 23 10:40:16 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Ankur Tyagi X-Patchwork-Id: 99014 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id A9CE2C982EA for ; Wed, 23 Sep 2026 10:41:14 +0000 (UTC) Received: from mail-pz2-f41.google.com (mail-pz2-f41.google.com [74.125.228.41]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.4149.1790160065099702655 for ; Wed, 23 Sep 2026 03:41:05 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@gmail.com header.s=20251104 header.b=OQREIxrW; spf=pass (domain: gmail.com, ip: 74.125.228.41, mailfrom: ankur.tyagi85@gmail.com) Received: by mail-pz2-f41.google.com with SMTP id d2e1a72fcca58-8623e5d435cso247843b3a.1 for ; Wed, 23 Sep 2026 03:41:05 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1790160064; x=1790764864; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=+C8i4eE/l0tyvQoCQ7yXFUHJdJ4sfG0AA5yiFQ9puow=; b=OQREIxrWnsvV4xQJTdarEg+uTjNMGQOv2/WArY8hZmT+DQ3YwCpUBZ4ruQgKx60tgb Ho21JmMiXpAM/EwUiBCvZ6c1AWKyPs3PD0TPgXCxHa2S6VLZTTP8eDJS8+BkXPpHa3B3 DNLkI9OAREWK9r5iOmdx2gWcM4HPbcMD9aeVhHw4EXeUuXYi0/piGHvao2PVYVJml7dF dqMu2GZ6Se+yaxZQqW5jCi8/IFJVWhZsqCx6ImwrWQWcrJLF5U1JiAW7VdRsV7VOc6bi 1UjmA7+V7J8ImWP9HgXCpLieP0BaMP2s7c9hzuFsVprrQFU54T9SICMyYR1uBK0hDDTA Me6A== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1790160064; x=1790764864; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=+C8i4eE/l0tyvQoCQ7yXFUHJdJ4sfG0AA5yiFQ9puow=; b=ynXm6p5C33jinTUDfvaN/gLJrTGZXcvBHOIEJvSjoMftFyM3etfdL1q3hlXVUXHcqm TzJcb/gAoUWLHpp5XKxS2M9nGPeUlS06LT0W1fB7zONuZSkye1EQ6XJzQfOwukMoWqvc Y0pd2Nv+KHDeEmp3Oyg+VSYysK77CKHMhZN81h/Uv2dYGKYTHh5f694ZEAyINT0cWsGV utCnYUwKqP0sxlLcriF1xGmfBSfjR3PtaVYy3gnnD1Wd+vQkWIoZUVTZ1HfLSQctHOsI NSNc6afkfu2bG50geR5jgleWghF9HfPme6Nro0wta6Y/pHMty5gFGbAf5zgFHu/kZmkz Q7hg== X-Gm-Message-State: AFuF++kpj9gPs3eB0uUoWv+mL8AefcrOvwgcEDEViADPOLNwlgE68Wr9 Z9RDKWS0N0WfXuStl612Yo0BS7ukDecW34g0hvjly5bttS3jU1jIPK/GtN8wEA== X-Gm-Gg: AYBFou0NHmiP0ZOuRM+7FU21y9000elGniKX7D82nUKbK2lq8Kswcm1Q6bF3+yjUNXS PNcr22JPyaYCJjBuyXZGysEEVq8k3hz6UqwoKy4qQUtyQdRo7Wzte1WSjTNgG0mxRji/BG1Q3dl ESycyzEW29Gh9YtZsUiQGa4ubql6NHjdDgXu1vhGpO5ej6AAmP90QUT97SB8iyOwHtxtyCl7ToO lGfUjDJkBqJTbHV8bwfjSixMm9SWe6/Crp9CaM6ECspi5zvMf3XnEs31Rl9KaJ2ntDQgy1qD1p3 gW+7ICkboDdxYrP+SOvwoZ60/nx3Bo7mld+C/f9ZgBoi6CAgHWtPrVmXl84knGIjNkn9RWxxNo+ aon6JzaTYYM3lrjOparyjRVGVloVMs4uAjRDQx0ibnmD0dqeMTP5f6hQQecMT9zIpwqPRb8bVIW BYSPEAnVI7bBNpavLJV9N2c9rDFL4yse4mTJlLk1v24FCWL9xFccVw3zRvHfaR8ZD4r2CkW1+cD Is9q0/NT30FGzXs4pRsQ1I= X-Received: by 2002:a05:6a00:4f84:b0:874:705d:f634 with SMTP id d2e1a72fcca58-87d24c67d88mr1446473b3a.14.1790160064298; Wed, 23 Sep 2026 03:41:04 -0700 (PDT) Received: from NVAPF55DW0D-IPD.. ([203.211.104.195]) by smtp.gmail.com with ESMTPSA id d2e1a72fcca58-87d1d5c1646sm1035870b3a.30.2026.09.23.03.41.02 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 23 Sep 2026 03:41:04 -0700 (PDT) From: ankur.tyagi85@gmail.com To: openembedded-devel@lists.openembedded.org Cc: Ankur Tyagi Subject: [oe][meta-oe][wrynose][PATCH 2/42] cjose: mark CVE-2026-53938 and CVE-2026-53939 fixed Date: Wed, 23 Sep 2026 22:40:16 +1200 Message-ID: <20260923104056.457360-2-ankur.tyagi85@gmail.com> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260923104056.457360-1-ankur.tyagi85@gmail.com> References: <20260923104056.457360-1-ankur.tyagi85@gmail.com> MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Wed, 23 Sep 2026 10:41:14 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-devel/message/130189 From: Ankur Tyagi Details: https://nvd.nist.gov/vuln/detail/cve-2026-53938 https://nvd.nist.gov/vuln/detail/cve-2026-53939 Signed-off-by: Ankur Tyagi --- meta-oe/recipes-support/cjose/cjose_0.6.2.8.bb | 2 ++ 1 file changed, 2 insertions(+) diff --git a/meta-oe/recipes-support/cjose/cjose_0.6.2.8.bb b/meta-oe/recipes-support/cjose/cjose_0.6.2.8.bb index 492ee0d143..594dadd686 100644 --- a/meta-oe/recipes-support/cjose/cjose_0.6.2.8.bb +++ b/meta-oe/recipes-support/cjose/cjose_0.6.2.8.bb @@ -11,3 +11,5 @@ DEPENDS = "openssl libcheck jansson" inherit pkgconfig autotools +CVE_STATUS[CVE-2026-53938] = "fixed-version: Fixed since v0.6.2.5" +CVE_STATUS[CVE-2026-53939] = "fixed-version: Fixed since v0.6.2.6" From patchwork Wed Sep 23 10:40:17 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Ankur Tyagi X-Patchwork-Id: 99019 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 23E9EC9830B for ; Wed, 23 Sep 2026 10:41:15 +0000 (UTC) Received: from mail-pz2-f12.google.com (mail-pz2-f12.google.com [74.125.228.12]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.4264.1790160066918960275 for ; Wed, 23 Sep 2026 03:41:06 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@gmail.com header.s=20251104 header.b=akzI1zUq; spf=pass (domain: gmail.com, ip: 74.125.228.12, mailfrom: ankur.tyagi85@gmail.com) Received: by mail-pz2-f12.google.com with SMTP id d2e1a72fcca58-8692a8568e9so378422b3a.3 for ; Wed, 23 Sep 2026 03:41:06 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1790160066; x=1790764866; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=dVbtBaNwpv8HfDqPpzzqu+2kp03or2TKGArYN1K/5iA=; b=akzI1zUqlljZL1AG8Krb0MVPbnrtQBalBoGKoWHfwUHXX00HSks3BraKMthma0ruG5 tJXyTx+B+gJ7wMSNpN9kJ4pjUdIHpSUOIj+0YLAcVwEwOeUeCdzfccLyl+VtYgGmHz3/ VtCzZEb1d0KVKm5Lfa+kt/MU3vWzZtohXVtN3WEKCdSW1hlMNEHY/PsC6/NQ+616TPkp iOxLifukapddoPdu0hT62V1XP2BpcckWoh3n+X+5lnXhqEeNUmYj2myiICGtfkxM2VQg g1CVRjXc97VogrVpAZTERLjzI6u4ZfWEHTWEPIh4r1vhkXLPg6mqradxdMcQ4cvE92y7 9txA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1790160066; x=1790764866; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=dVbtBaNwpv8HfDqPpzzqu+2kp03or2TKGArYN1K/5iA=; b=DiRTx0Rho5XRE5Zprc96Gz12vPFWGdlAs24mQ/1tt6kAlwny+BW1uD9gLUUYGxIUR/ iq7oUYix3bx3aiSoyQdGskTQlCO2y9J9w55hibJT5ZdRM8ie7+AZ1AVL4XOCMtwq9LKs SgPXTJ0KbC3PWHR9G7at27Z8+nUKX/7DM/sM/gHM4swzP/X53RSWnvyBxQnNHHX/QHxw jzm5+VJxkoH0N7J8j+2USrsg1e0Rdq3asoW2FTCRy/AZpJf8g+R8swNGSR2idv4gX4EF rHXBKuWeVFaIhatobKiukgAU8RmZKcI5xuKZ7/UXWtQoOLKxtcXXfAb0mq4MTp2KOFY1 K7Sw== X-Gm-Message-State: AFuF++kiKbl9aeMdD/ZXhGfiqwF1ASTwhalepb9UP4os3CEr2EkpjfXD zGdXZ8+7t0hJl/H9Ww2Zuaplwpl8hLfIe1Z6QCn757uls4vi0uIllsCnXuQmtQ== X-Gm-Gg: AYBFou2CRnBMctlOM2OvbpVNhji7rAPfIV7pEdyMizUO0IJKUGhMiox0W5iVyaWq/ag fhXTOYrvXfdz0aD9mZ5lAs+O2D7nzEYNBApraqz9s9swSKO16mzcNOm4iCL07M2kblD5N81w7Ev s20661/fNSs6pkCVO8JetU1YIIpoEVvBkAwUAbxgcQs55hYaQxcYQw5AEKVprWAhU8YnlrW6huQ j3/VoQjpl5BXDzNMR/SSN6cqHgETsJYz0sUXa7Cm8k5cHBi7FfsneJxGXda0RJEYAbVe5nj6iZf L6Y70yOdxsSn0Q+5RdMuoQHCpb9vNNZ4YpXV0lTzunria8/6/IX4woWHD1rfulzCDAcEOsaCZfJ W/OSIKLRGSwHGecVmrJLeSmzNS3P2z1Brp3cM5g4HhSRBiSitjNbYftHLVsZGP+JypTnEzmotMe 7FBV1wWiZe0g3e+6+6i8Spl1BxY9iVfglOOtPcEHEFNxdnyolhiT8rxGubdB+OIN2WqTem3AdoQ ieuC0ytdpq6/UtKrvf6WT8= X-Received: by 2002:a05:6a00:1c90:b0:878:3538:8f77 with SMTP id d2e1a72fcca58-87d1b89fd9emr1763881b3a.37.1790160066159; Wed, 23 Sep 2026 03:41:06 -0700 (PDT) Received: from NVAPF55DW0D-IPD.. ([203.211.104.195]) by smtp.gmail.com with ESMTPSA id d2e1a72fcca58-87d1d5c1646sm1035870b3a.30.2026.09.23.03.41.04 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 23 Sep 2026 03:41:05 -0700 (PDT) From: ankur.tyagi85@gmail.com To: openembedded-devel@lists.openembedded.org Cc: Ankur Tyagi Subject: [oe][meta-oe][wrynose][PATCH 3/42] cjson: patch CVE-2026-87933 Date: Wed, 23 Sep 2026 22:40:17 +1200 Message-ID: <20260923104056.457360-3-ankur.tyagi85@gmail.com> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260923104056.457360-1-ankur.tyagi85@gmail.com> References: <20260923104056.457360-1-ankur.tyagi85@gmail.com> MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Wed, 23 Sep 2026 10:41:15 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-devel/message/130190 From: Ankur Tyagi Details: https://nvd.nist.gov/vuln/detail/cve-2026-87933 Signed-off-by: Ankur Tyagi --- .../cjson/cjson/CVE-2026-87933.patch | 110 ++++++++++++++++++ .../recipes-devtools/cjson/cjson_1.7.19.bb | 1 + 2 files changed, 111 insertions(+) create mode 100644 meta-oe/recipes-devtools/cjson/cjson/CVE-2026-87933.patch diff --git a/meta-oe/recipes-devtools/cjson/cjson/CVE-2026-87933.patch b/meta-oe/recipes-devtools/cjson/cjson/CVE-2026-87933.patch new file mode 100644 index 0000000000..3972e5eafc --- /dev/null +++ b/meta-oe/recipes-devtools/cjson/cjson/CVE-2026-87933.patch @@ -0,0 +1,110 @@ +From a1b370963c98e1374e5538e97841f9d476a8932e Mon Sep 17 00:00:00 2001 +From: lilu5458 +Date: Wed, 16 Sep 2026 09:55:35 +0800 +Subject: [PATCH] Fix: heap-use-after-free in merge_patch when patch is subtree + of target (#1065) + +When cJSONUtils_MergePatch(target, patch) is called with a non-object +patch (scalar, array, or NULL) that happens to be a subtree of target, +merge_patch() called cJSON_Delete(target) first, which freed the patch +memory, and then cJSON_Duplicate(patch, 1) read the already-freed memory, +triggering a heap-use-after-free (detected by AddressSanitizer at +cJSON_Duplicate_rec, cJSON.c:2808). + +Fix: duplicate the patch first into a local variable, then delete the +target, then return the duplicate. This matches the Option B approach +proposed in issue #1060. + +Verified locally: +- Reproduced the UAF with a minimal PoC under ASan before the fix. +- After the fix the PoC runs cleanly (exit 0, correct result [1,2,3]). +- Added a regression unit test + (merge_patch_should_not_read_freed_memory_when_patch_is_subtree). +- Full ctest suite passes (22/22 tests). + +Fixes #1060 + +Signed-off-by: lilu +(cherry picked from commit 6d9f2443ab071f86e5d9b43025a40929ec41c46c) + +CVE: CVE-2026-87933 +Upstream-Status: Backport [https://github.com/DaveGamble/cJSON/commit/6d9f2443ab071f86e5d9b43025a40929ec41c46c] + +Signed-off-by: Ankur Tyagi +--- + cJSON_Utils.c | 8 ++++++-- + tests/old_utils_tests.c | 34 ++++++++++++++++++++++++++++++++++ + 2 files changed, 40 insertions(+), 2 deletions(-) + +diff --git a/cJSON_Utils.c b/cJSON_Utils.c +index 8fa24f8..6f41875 100644 +--- a/cJSON_Utils.c ++++ b/cJSON_Utils.c +@@ -1324,9 +1324,13 @@ static cJSON *merge_patch(cJSON *target, const cJSON * const patch, const cJSON_ + + if (!cJSON_IsObject(patch)) + { +- /* scalar value, array or NULL, just duplicate */ ++ /* scalar value, array or NULL, just duplicate. ++ * Duplicate the patch first in case it is a subtree of target, ++ * otherwise cJSON_Delete(target) would free the patch memory ++ * and the subsequent cJSON_Duplicate would read freed memory. */ ++ cJSON *duplicate = cJSON_Duplicate(patch, 1); + cJSON_Delete(target); +- return cJSON_Duplicate(patch, 1); ++ return duplicate; + } + + if (!cJSON_IsObject(target)) +diff --git a/tests/old_utils_tests.c b/tests/old_utils_tests.c +index 690dbb5..bdc7393 100644 +--- a/tests/old_utils_tests.c ++++ b/tests/old_utils_tests.c +@@ -189,6 +189,39 @@ static void merge_tests(void) + } + } + ++static void merge_patch_should_not_read_freed_memory_when_patch_is_subtree(void) ++{ ++ /* When patch is a subtree of target, merge_patch must duplicate the patch ++ * before deleting target. Otherwise cJSON_Delete(target) frees the patch ++ * memory and the subsequent cJSON_Duplicate reads freed memory (UAF). ++ * See CVE candidate: heap-use-after-free in merge_patch (cJSON_Utils.c). */ ++ cJSON *target = cJSON_Parse("{\"a\":[1,2,3]}"); ++ cJSON *patch = cJSON_GetObjectItem(target, "a"); ++ cJSON *result = NULL; ++ cJSON *first = NULL; ++ cJSON *second = NULL; ++ cJSON *third = NULL; ++ ++ TEST_ASSERT_NOT_NULL(target); ++ TEST_ASSERT_NOT_NULL(patch); ++ ++ /* patch (array [1,2,3]) is a subtree of target. This used to trigger ++ * heap-use-after-free under AddressSanitizer before the fix. */ ++ result = cJSONUtils_MergePatch(target, patch); ++ TEST_ASSERT_NOT_NULL(result); ++ TEST_ASSERT_TRUE(cJSON_IsArray(result)); ++ TEST_ASSERT_EQUAL_INT(3, cJSON_GetArraySize(result)); ++ ++ first = cJSON_GetArrayItem(result, 0); ++ second = cJSON_GetArrayItem(result, 1); ++ third = cJSON_GetArrayItem(result, 2); ++ TEST_ASSERT_EQUAL_INT(1, first->valueint); ++ TEST_ASSERT_EQUAL_INT(2, second->valueint); ++ TEST_ASSERT_EQUAL_INT(3, third->valueint); ++ ++ cJSON_Delete(result); ++} ++ + static void generate_merge_tests(void) + { + size_t i = 0; +@@ -219,6 +252,7 @@ int main(void) + RUN_TEST(misc_tests); + RUN_TEST(sort_tests); + RUN_TEST(merge_tests); ++ RUN_TEST(merge_patch_should_not_read_freed_memory_when_patch_is_subtree); + RUN_TEST(generate_merge_tests); + + return UNITY_END(); diff --git a/meta-oe/recipes-devtools/cjson/cjson_1.7.19.bb b/meta-oe/recipes-devtools/cjson/cjson_1.7.19.bb index d914018331..b4e57d7297 100644 --- a/meta-oe/recipes-devtools/cjson/cjson_1.7.19.bb +++ b/meta-oe/recipes-devtools/cjson/cjson_1.7.19.bb @@ -7,6 +7,7 @@ LIC_FILES_CHKSUM = "file://LICENSE;md5=218947f77e8cb8e2fa02918dc41c50d0" SRC_URI = "git://github.com/DaveGamble/cJSON.git;branch=master;protocol=https \ file://run-ptest \ file://0001-allow-build-with-cmake-4.patch \ + file://CVE-2026-87933.patch \ " SRCREV = "c859b25da02955fef659d658b8f324b5cde87be3" From patchwork Wed Sep 23 10:40:18 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Ankur Tyagi X-Patchwork-Id: 99017 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 46A1AC9830D for ; Wed, 23 Sep 2026 10:41:15 +0000 (UTC) Received: from mail-pz2-f12.google.com (mail-pz2-f12.google.com [74.125.228.12]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.4151.1790160068701342925 for ; Wed, 23 Sep 2026 03:41:08 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@gmail.com header.s=20251104 header.b=ChvvPczW; spf=pass (domain: gmail.com, ip: 74.125.228.12, mailfrom: ankur.tyagi85@gmail.com) Received: by mail-pz2-f12.google.com with SMTP id d2e1a72fcca58-85a4329731cso436973b3a.3 for ; Wed, 23 Sep 2026 03:41:08 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1790160068; x=1790764868; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=jM7jxai5MMWzj3o7rFdt9F08P2fE2/Py+HJznOj0i9s=; b=ChvvPczWd4VPwV9afSWzE6G+HWicnAVSZMBDcN+mdPm/GoNwHFxgQPtCkBBRcGT7Y4 MZSS3zOLnbRKQrb+og8djpcTpScEB/ERfsf1Vn7jMAco4T7C3xyMuyE672EnMyEgFXVM w1hayx/SeVO9KkENyY7bz8qiniUpp/jVxBiGNX42HEoTQHNtkc9MGCJyavwRXtT0CcyX SwqVIhR4NwtGRcbxz0I1hEZqxipxBe0iRg7tPD//oVRsYszRJ1w+DBBRJGFi/sGxdvwf +K0bwQQ6AOGqpeMWUOX8DNTqSb+ezSSXob5b0/rD2V6kq3Q6j/KsrSXbd36iCEAHDCKB CFWA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1790160068; x=1790764868; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=jM7jxai5MMWzj3o7rFdt9F08P2fE2/Py+HJznOj0i9s=; b=ASJ7vL037FJe333l3vJZzwG47eTKW7zTpAXLO0hUt3Oq11mI6+Ux3GIkgp+9itkWxT EclAkX7JPMSdwvysVq0LgVFK1aCcoKOBvASOQi3zUJ20RaYAKXjZbse7VuObkPYyDaX+ O1LGPZapon5UqFmqVBKBc+IyUF7HcshhyDx8w7myeesJwiI1ltln+h15WxtSXlcCZcrE o8qjAFIk4J2p3SUHp+PxF/KZYr/Tozy0dorEuzLOoIwHfv+HigXHQC9+wn79gM9+O0I9 AxcT2S4GRCMycrOhi5oRDZMLPdtwTcztRxX0VO5NuDnVtYXLPsCJpcAcysD1wLHFiAJB 3DoQ== X-Gm-Message-State: AFuF++liN7zI+c2+La+pb3KO/tMyAPY12YMlAK/nfb5iNJ7Cyoo3/iRp oDf2Qplq6qjRI1l4kPvlb8//VAxGjBYcOQCOvwQqxMq1jk0Dxb0HjRde4HzP2g== X-Gm-Gg: AYBFou1CwqWLTsCvG7pgtVQ0Rrd7n0xGgsZYjkj5xDAVNnln8y9lTwODNlCFqB3ycRc Qm0S/jkpwuecCeiKEYYfWpssgDCBvheK6rvCbafjPmRVGXWiYqrSaeWfWyyPSjyaLHEXFVHUE1j 6YnK7z/l64j9y4++XcG77RsK1QB7Q9vPxcTNtbPX5d96DuvptxG1Y0ZLe7oWFfdPEarVwPtGOjg u5Zk9SkslmONz/L976un/jKNfI2lXQ6jWr7Lcm6qV3CUNJ+tP1oudLqnHh/F090ht5HynrctVR+ vPINA71oFPs+E1DVOlc8CZQmGGiboZVohUegkTpEgw9FiT8fOiDztlTDmwMgpTznfGcUyCXgK/l /8C6ei5Wt2pYlEEnxE6EEaa/kzqlQgpZXPwYW8Q437Pmznv0iWfvX83uKRkEcrWNzkohyT3q+xy 3UdFyaFzAXCdWNq2lVtqzmH98wXluB8kbeVFgH75gnV4X3hLWua8SSxY4en5Lj3gQoTFVTx4+4T axHuF4smiANQJlObO9DQEz/1di9IPmDig== X-Received: by 2002:a05:6a00:1709:b0:860:507d:503e with SMTP id d2e1a72fcca58-87d1b0b57cfmr2034052b3a.20.1790160068018; Wed, 23 Sep 2026 03:41:08 -0700 (PDT) Received: from NVAPF55DW0D-IPD.. ([203.211.104.195]) by smtp.gmail.com with ESMTPSA id d2e1a72fcca58-87d1d5c1646sm1035870b3a.30.2026.09.23.03.41.06 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 23 Sep 2026 03:41:07 -0700 (PDT) From: ankur.tyagi85@gmail.com To: openembedded-devel@lists.openembedded.org Cc: Ankur Tyagi Subject: [oe][meta-oe][wrynose][PATCH 4/42] colord: ignore CVE-2026-85062 Date: Wed, 23 Sep 2026 22:40:18 +1200 Message-ID: <20260923104056.457360-4-ankur.tyagi85@gmail.com> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260923104056.457360-1-ankur.tyagi85@gmail.com> References: <20260923104056.457360-1-ankur.tyagi85@gmail.com> MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Wed, 23 Sep 2026 10:41:15 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-devel/message/130191 From: Ankur Tyagi Details: https://nvd.nist.gov/vuln/detail/cve-2026-85062 Signed-off-by: Ankur Tyagi --- meta-oe/recipes-support/colord/colord.bb | 1 + 1 file changed, 1 insertion(+) diff --git a/meta-oe/recipes-support/colord/colord.bb b/meta-oe/recipes-support/colord/colord.bb index e918500161..f129eb32a9 100644 --- a/meta-oe/recipes-support/colord/colord.bb +++ b/meta-oe/recipes-support/colord/colord.bb @@ -54,3 +54,4 @@ do_install:append() { USERADD_PACKAGES = "${PN}" USERADD_PARAM:${PN} = "--system --user-group --shell /bin/false --no-create-home --home-dir ${localstatedir}/lib/colord colord" +CVE_STATUS[CVE-2026-85062] = "cpe-incorrect: this CVE is for JavaScript colord tool" From patchwork Wed Sep 23 10:40:19 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Ankur Tyagi X-Patchwork-Id: 99015 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id A8C84C982FA for ; Wed, 23 Sep 2026 10:41:14 +0000 (UTC) Received: from mail-pz2-f40.google.com (mail-pz2-f40.google.com [74.125.228.40]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.4266.1790160070724947168 for ; Wed, 23 Sep 2026 03:41:10 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@gmail.com header.s=20251104 header.b=kiCdJC2L; spf=pass (domain: gmail.com, ip: 74.125.228.40, mailfrom: ankur.tyagi85@gmail.com) Received: by mail-pz2-f40.google.com with SMTP id 41be03b00d2f7-cc7641d03a5so67240a12.0 for ; Wed, 23 Sep 2026 03:41:10 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1790160070; x=1790764870; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=k0BDQUyjQL8FParzXempzndDMUeJIJq6BsD3VEsPJs0=; b=kiCdJC2LbUj4uQVV2vwloPe/pLhxTZxyAYYoumcbVoLrW9s+Lh3D2xPk1tiEdABRxj wp0HKLSZJEhzLRLUoHEn0x/uuGVG7nGM3L+V/5PMX63UtedTqdAc1tZ3zJcdis8dosmF LjUawH5EoIMxJ+HZyFUvVjc8xWp3Fq3Ui4V5Ax9Lxa8m+4yPRWGtKii5rfPa4CAJAn0h Q8bnNCymxGiXACsVrx7c3s+KfjAaYFE0uBJGCFQjm9byFEt2pCewMOcQLcJKX9XZj2XI veT3zWK0/Sfo5W1PSpKulUAjcXWdRRl47B0fhyn+7FEq2lTzAuCTp+/ggVJsimrQBW5L tbtQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1790160070; x=1790764870; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=k0BDQUyjQL8FParzXempzndDMUeJIJq6BsD3VEsPJs0=; b=PaExvKNcFCVkiUCCvCVDDexkkoDrRvtCPVQY4CCcGRS78G8KlNvva5G/gbZwnFukkU XhfVxAh6u9Uk+nB9ANEQsSe+7sHsttBQX3o/LJAu/p/PirLtipoosqwO/lR98sfM6rfU e41mVfaKwnqqU7dYiQKhsBzqLQAYeKisWk+vtYjIxdvFsCOBaMbm7pqWMLO3YtP9VabI lXf4z9ePfjQXmbI6fc5Sg/nl88pdaW0sP0k2BfFQkb9twFIYWtMOmSqZpd+xIWXAdcCU nl0h3Ele3EtM0uojqvVA6U94B2ZVsEMSK9WdjlXpXHjVG43UIa6F2gg6hJ3SW70BeI+x eHBg== X-Gm-Message-State: AFuF++nQ/uYz1+vlHRWlzEGxqnWizyfWdOTwWR9Adop1sRhA0aNXMQwL bBDRBEVPz/IrTHhCiM+miK9q7ANt7wKjh43ZHjy8uFzjwRK6hzytCXkUHUQu7Q== X-Gm-Gg: AYBFou2zunWKxDbMeiG0bwmA0qcKs/+69Qejb5u+E+rb6JNB7HmId5UrnHVVFOnFPyE qPd+JCV2aYfm3AvyZPhtNnJvoRZjsEJiuZuxIDmBnEdePRU7qs5s0/M+4VtzZQ4bQUGAmtQSXIC 7/MZkIsqjMK+UK5uqB9EauQc24Jiw6YUq2SK6ezmwadPfflJiTEGbBSUyVUOXN24CZ2uF2LnKqq jUjXFvQBk/EA9UviwZGEY20w47r0PQofydIeGE8B4osxpfCJqS3wP/303QK623KTHbQNhbOCszx +W5DtMBwm07m4oAqFld3F5xOaUxdh3qw6+7ui7iHFxKyUahr/QKsaxGpSKlbdGjntnyBbaW0iul I4DlW/Vsl3yReIrmLv+kzj+NgiuRKvQiLvZI+fxoAXn6FI4h5v4krrvD5g2jGVmvUGdeqcAnAdi YKZjYVjQhZWrtUW5OqgWlrd9hawRO4/6+r9om93A0u84/r0xbmrkhF7L3pIbDAkGWXCt1DUxAX9 rDKNuPDMvO0TQMM+xc3stip++qrj4q3zw== X-Received: by 2002:a05:6a20:7d8b:b0:3d1:deec:9265 with SMTP id adf61e73a8af0-3ddf7caac5dmr2436133637.6.1790160069818; Wed, 23 Sep 2026 03:41:09 -0700 (PDT) Received: from NVAPF55DW0D-IPD.. ([203.211.104.195]) by smtp.gmail.com with ESMTPSA id d2e1a72fcca58-87d1d5c1646sm1035870b3a.30.2026.09.23.03.41.08 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 23 Sep 2026 03:41:09 -0700 (PDT) From: ankur.tyagi85@gmail.com To: openembedded-devel@lists.openembedded.org Cc: Ankur Tyagi Subject: [oe][meta-oe][wrynose][PATCH 5/42] flatcc: patch CVE-2026-90786 Date: Wed, 23 Sep 2026 22:40:19 +1200 Message-ID: <20260923104056.457360-5-ankur.tyagi85@gmail.com> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260923104056.457360-1-ankur.tyagi85@gmail.com> References: <20260923104056.457360-1-ankur.tyagi85@gmail.com> MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Wed, 23 Sep 2026 10:41:14 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-devel/message/130192 From: Ankur Tyagi Details: https://nvd.nist.gov/vuln/detail/cve-2026-90786 Signed-off-by: Ankur Tyagi --- .../flatcc/flatcc/CVE-2026-90786.patch | 40 +++++++++++++++++++ meta-oe/recipes-devtools/flatcc/flatcc_git.bb | 1 + 2 files changed, 41 insertions(+) create mode 100644 meta-oe/recipes-devtools/flatcc/flatcc/CVE-2026-90786.patch diff --git a/meta-oe/recipes-devtools/flatcc/flatcc/CVE-2026-90786.patch b/meta-oe/recipes-devtools/flatcc/flatcc/CVE-2026-90786.patch new file mode 100644 index 0000000000..a1e6b16695 --- /dev/null +++ b/meta-oe/recipes-devtools/flatcc/flatcc/CVE-2026-90786.patch @@ -0,0 +1,40 @@ +From bb5238cd959e88c590b413d3b105562e6d1c5114 Mon Sep 17 00:00:00 2001 +From: =?UTF-8?q?Mikkel=20Fahn=C3=B8e=20J=C3=B8rgensen?= +Date: Tue, 4 Aug 2026 19:53:26 +0200 +Subject: [PATCH] Fail early on duplicate symbols to aovid triggering unhandled + assertions in release build (closes #387) + +(cherry picked from commit 8b19ba4e992ebcad7f5970704d1afc5507fa5205) + +CVE: CVE-2026-90786 +Upstream-Status: Backport [https://github.com/jimjag/flatcc/commit/8b19ba4e992ebcad7f5970704d1afc5507fa5205] + +Signed-off-by: Ankur Tyagi +--- + src/compiler/semantics.c | 6 ++++++ + 1 file changed, 6 insertions(+) + +diff --git a/src/compiler/semantics.c b/src/compiler/semantics.c +index 6c56c37..21ff948 100644 +--- a/src/compiler/semantics.c ++++ b/src/compiler/semantics.c +@@ -1351,6 +1351,8 @@ static int process_table(fb_parser_t *P, fb_compound_type_t *ct) + id_failed = 1; + } + } ++ // Ordering assumes there are no duplicates so conservatively abort on error. ++ if (P->failed) return P->failed; + /* Order in which data is ordered in binary buffer. */ + if (ct->metadata_flags & fb_f_original_order) { + ct->ordered_members = original_order_members(P, (fb_member_t *)ct->members); +@@ -1821,6 +1823,10 @@ int fb_build_schema(fb_parser_t *P) + #endif + } + } ++ ++ /* Semantic analysis assumes no duplicates so conservatibely abort on error. */ ++ if (P->failed) return P->failed; ++ + install_known_attributes(P); + + if (!P->opts.hide_later_enum) { diff --git a/meta-oe/recipes-devtools/flatcc/flatcc_git.bb b/meta-oe/recipes-devtools/flatcc/flatcc_git.bb index a4bdda162d..a6bf3c1cf4 100644 --- a/meta-oe/recipes-devtools/flatcc/flatcc_git.bb +++ b/meta-oe/recipes-devtools/flatcc/flatcc_git.bb @@ -12,6 +12,7 @@ SRC_URI = " \ git://github.com/dvidelabs/flatcc.git;protocol=https;branch=master \ file://0001-Check-for-C-standard-version-23-for-__fallthrough__.patch \ file://0002-allow-build-with-cmake-4.patch \ + file://CVE-2026-90786.patch \ " SRCREV = "1653ec964730ec7d9892a08a1695ada6d20f5196" From patchwork Wed Sep 23 10:40:20 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Ankur Tyagi X-Patchwork-Id: 99016 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id CEED8C98309 for ; Wed, 23 Sep 2026 10:41:14 +0000 (UTC) Received: from mail-pz2-f12.google.com (mail-pz2-f12.google.com [74.125.228.12]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.4269.1790160072543930406 for ; Wed, 23 Sep 2026 03:41:12 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@gmail.com header.s=20251104 header.b=e4ZEWNhK; spf=pass (domain: gmail.com, ip: 74.125.228.12, mailfrom: ankur.tyagi85@gmail.com) Received: by mail-pz2-f12.google.com with SMTP id d2e1a72fcca58-8693af0d7c4so486952b3a.3 for ; Wed, 23 Sep 2026 03:41:12 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1790160072; x=1790764872; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=y7OH3N97cuSGJS7QQOhStfEz4BBpeRTGHIEiPXRXI0k=; b=e4ZEWNhKBrHp63Og1r34LqPMepVVu+POFGn3L87AdZh1KeoyKiEUSyigcfY6tp/WG6 jTN6JQ3Z4/wQzYBs4Mosk0xG+tUy55hYN0eTpppQ9Il/zFLEg7IQBiusBq4Xzj0YqpUm m98MuX+fcXA8jnLhsQB4doHzL2bPmMC+388+m+xOqZr9MbtSa0ZrDhOqsCf981AEWl4d UIRnLcKc7HQjlDPd+YFWTsOYH37+cePEMP0UvqcsnUMr/DdMoknsT8eANZ96wv9xrn+K lAhZQ644GGgZhTn7nzjpDrOAaGGFJf0GflqgUnJGv86xM0U7mHW/ng0T1iCuS5qXc2P9 /6fg== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1790160072; x=1790764872; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=y7OH3N97cuSGJS7QQOhStfEz4BBpeRTGHIEiPXRXI0k=; b=fZlaCFyJYGjHk3b45VKeb7pjfH/j3hM0eiBqxnpRldO/Oo5DJ4cM4IdAU6o7kga8cV QTqGBXLwzXO/llMY6sjm4Ch2srHgWOw06mPUl6x+BoltSIPojFeEOAZQBP/jZ4xR7qWI SHp7TPNAwDWVzXZxlV3KQKZzJdrjyeyLYlAbr0RhaUg7I8o3qb7RtgTgGqMNroPTSc7w oF+O7kjCdgrDxZkLeJrTnDh6YWdFksQl5nBJKWRcZ2Npwc8vcICOR8Y92jKc1ZJmHAjT Ecff5feEEGTnk4j363cxITRmnxNNfrlZzvY+eA8US2Ynv0JX4Ph2hIu26a107D45/gsu 5Svw== X-Gm-Message-State: AFuF++nz4O8RvTTiT2h5hTrJNyWnu95Gzbqt+/SPraF3O9BN536sOJYH 3f0LfK86dAbVnKT9Im9RaHCds8zj++5y+0Mzl2TcYlNR1fRW2CvI2Gu3GFNjig== X-Gm-Gg: AYBFou14rzsWKzV9VrEQp+KqMYDSU69XsWePZbjDk66feHyNMpqZpPFECZDWaxQ3nwP E9KtV4p8sRXW3NEdwTDdAH7KUScT4YRcZcC83CUJxSdWxvrIz6+MP53QaDq98m+7Tlf/nfn2lXn rCNKNagczIUeXfQRNFq9tj8quxYU3p6DpETP97v5OAQv6na3r/PfYPXc4aYBJ4nRKuerboRVvGK prTanziwjewrYjEwIxCPJGdrC5oj42OjwMAtSGsNgyxY0smVpviRUNPWJBITswQjRlp6b5/mp0A FYSfgLdwmfxGLspPV+3F9cKeENGBh0WDwu9vNwUTwfhCHtBkfRd7AuC1xj2r3h6ISkKGoczo2q/ FbarNipG+JRVPFMHWjBKEwH6bXiqMtSJXxD+tEIfp0nb82+ZP91jxldLAdNtI2QxYlZPCdkh5l8 MzOlcntGCBobbpq3o/Q/q1X5DNOiFsR+L3T1m0Xho4N7o3x45RUtEYZOKcldCDWC7rUc/kYB79j fB3+fQtGwBveAWQJprJMvA= X-Received: by 2002:a05:6a21:3949:b0:3dd:85a8:4c61 with SMTP id adf61e73a8af0-3ddf7ec2abcmr2019559637.40.1790160071842; Wed, 23 Sep 2026 03:41:11 -0700 (PDT) Received: from NVAPF55DW0D-IPD.. ([203.211.104.195]) by smtp.gmail.com with ESMTPSA id d2e1a72fcca58-87d1d5c1646sm1035870b3a.30.2026.09.23.03.41.10 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 23 Sep 2026 03:41:11 -0700 (PDT) From: ankur.tyagi85@gmail.com To: openembedded-devel@lists.openembedded.org Cc: Ankur Tyagi Subject: [oe][meta-oe][wrynose][PATCH 6/42] flatcc: patch CVE-2026-90785 Date: Wed, 23 Sep 2026 22:40:20 +1200 Message-ID: <20260923104056.457360-6-ankur.tyagi85@gmail.com> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260923104056.457360-1-ankur.tyagi85@gmail.com> References: <20260923104056.457360-1-ankur.tyagi85@gmail.com> MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Wed, 23 Sep 2026 10:41:14 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-devel/message/130193 From: Ankur Tyagi Details: https://nvd.nist.gov/vuln/detail/cve-2026-90785 Signed-off-by: Ankur Tyagi --- .../flatcc/flatcc/CVE-2026-90785.patch | 29 +++++++++++++++++++ meta-oe/recipes-devtools/flatcc/flatcc_git.bb | 1 + 2 files changed, 30 insertions(+) create mode 100644 meta-oe/recipes-devtools/flatcc/flatcc/CVE-2026-90785.patch diff --git a/meta-oe/recipes-devtools/flatcc/flatcc/CVE-2026-90785.patch b/meta-oe/recipes-devtools/flatcc/flatcc/CVE-2026-90785.patch new file mode 100644 index 0000000000..82f4f9e02f --- /dev/null +++ b/meta-oe/recipes-devtools/flatcc/flatcc/CVE-2026-90785.patch @@ -0,0 +1,29 @@ +From d44946b10f4da3c2c7b46e0a58bb86f9b5e9f342 Mon Sep 17 00:00:00 2001 +From: =?UTF-8?q?Mikkel=20Fahn=C3=B8e=20J=C3=B8rgensen?= +Date: Tue, 4 Aug 2026 20:01:22 +0200 +Subject: [PATCH] Avoid processing structs recursively if recursion already + detected (closes #388) + +(cherry picked from commit f705032346ee39efd7d3848c50b73d455d28d06d) + +CVE: CVE-2026-90785 +Upstream-Status: Backport [https://github.com/dvidelabs/flatcc/commit/f705032346ee39efd7d3848c50b73d455d28d06d] +Signed-off-by: Ankur Tyagi +--- + src/compiler/semantics.c | 3 +++ + 1 file changed, 3 insertions(+) + +diff --git a/src/compiler/semantics.c b/src/compiler/semantics.c +index 21ff948..2b49eee 100644 +--- a/src/compiler/semantics.c ++++ b/src/compiler/semantics.c +@@ -505,6 +505,9 @@ static int analyze_struct(fb_parser_t *P, fb_compound_type_t *ct) + uint16_t align; + fb_token_t *t; + ++ /* Avoid triggering assertions on already detected circular references. */ ++ if (P->failed) return P->failed; ++ + assert(ct->symbol.kind == fb_is_struct); + + assert(!(ct->symbol.flags & fb_circular_open)); diff --git a/meta-oe/recipes-devtools/flatcc/flatcc_git.bb b/meta-oe/recipes-devtools/flatcc/flatcc_git.bb index a6bf3c1cf4..b3cf7bed04 100644 --- a/meta-oe/recipes-devtools/flatcc/flatcc_git.bb +++ b/meta-oe/recipes-devtools/flatcc/flatcc_git.bb @@ -13,6 +13,7 @@ SRC_URI = " \ file://0001-Check-for-C-standard-version-23-for-__fallthrough__.patch \ file://0002-allow-build-with-cmake-4.patch \ file://CVE-2026-90786.patch \ + file://CVE-2026-90785.patch \ " SRCREV = "1653ec964730ec7d9892a08a1695ada6d20f5196" From patchwork Wed Sep 23 10:40:21 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Ankur Tyagi X-Patchwork-Id: 99018 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 5EE66C9830C for ; Wed, 23 Sep 2026 10:41:15 +0000 (UTC) Received: from mail-pz2-f12.google.com (mail-pz2-f12.google.com [74.125.228.12]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.4154.1790160074833925782 for ; Wed, 23 Sep 2026 03:41:14 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@gmail.com header.s=20251104 header.b=IY/drrjg; spf=pass (domain: gmail.com, ip: 74.125.228.12, mailfrom: ankur.tyagi85@gmail.com) Received: by mail-pz2-f12.google.com with SMTP id d2e1a72fcca58-85469b35611so371329b3a.0 for ; Wed, 23 Sep 2026 03:41:14 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1790160074; x=1790764874; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=TSx+GrMSwZt31iocE2rZKIHpTFuC84BRfeEtkhsKecs=; b=IY/drrjg+b7Mz2PeM1YiWvRaRdACI7QjvlAla9e60OqL63gMjDS9ndwTwOgig8GPDn jREEdgf4h4D3ma5Bh6qAv/8Pd2jZOfJB30ohW7tk2S9JCcZrxlibfMn//VPbrEDbz9Kb v/kKCg5/0rPLLAfrxwTJsRzs+9P15fi/SiEXNS7gnwqIvgimPvp7NBwXewWND2kIW7OR YQWLGOENIwUs4rFWEV2kprtJsf/93SvruqMyP2tAMRKY336gUK1In9RNUgfobhNmia01 2RY2R02yY+RcNnZpvZwdfXiV461akp8WKwyWPPLOITXzpqLOPj4HAVHjpCYE3y9tAJp0 EuaQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1790160074; x=1790764874; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=TSx+GrMSwZt31iocE2rZKIHpTFuC84BRfeEtkhsKecs=; b=MlG+Iynx46Rcc0hqb8YvCNlUDF58cA98qgb2YzXAGrbC3uNW3zxyMYcI0hrg2YB8Y9 wFyF/FU/qhvsT07euDdE8cTBviFpcTmA1zFncgDoqeJPfS+KqKHfpBfLgaPoLfXvJQMq phFyrb8tIDro3RYe3r+0bXuyzzH/kM2AkVv86a6KsTpPHZnHF0wgaLPfpxq7Wejat1KT 39foWQpwFmnYzxP+E+r9U+IuyIMUF8757rl87fivP1i0VWfrkCMgFTg4zElW2S6cs1oI 2K0qZkx9GAAETal+vi9EACPCwS8wyo0VZ6pngr+QmAMtF86LE9cLCePuXWup5AboRfy4 eL+Q== X-Gm-Message-State: AFuF++l4mq+NjaI6VjmLrMZI6HNHjB6+uUKPfJR33shW/u9kJfjeoZtN kYTr29BekG2M/SIbp71TelFbu5PqTDxUSFqMUBLhBvcGLdNQnTj2gdy2jvepIg== X-Gm-Gg: AYBFou03G5w6gsYRbqx+VUnv6EXBSPmiMr5COlt3FU98Uo5iaczbtWjGPm5UVaoe3H3 GUEjGfFa+uq21RQ05UmizbN5kdu6UfAoAIpqXT5BF0RSiOAYH+QosSU5Amu7fuWYhKJ24B/m1C7 AV9zKE+SM6J7RJhXW4meyReoiUQIjmW4fgruQ46WWOTkiZe9mpYKTu1n9tlNyQIXShm1VSLg2aZ gCjoOBcvtJePblbLfRctfhJgJpiRiSXKl1b+N8RP8yU6DwiUdNX+nShUvetjrCC5K2WoBk186g5 aRjhyHmxS8UydIAgBK3Bk3ein9mRtaSa2Z7K5vlQIvo/Piw4mvg/KGbbRO/kLNok/d+KixWV68u U2mHKyiKDqHMdIXYuXNoHgDJ6hOmzs90BtQLQUatdDmyHOkBC70gb3rlBo0pOQPxRam2fIo7Nk/ ElJ03Yn/tesY2NvfrhrbUtaC6V7UQxMSoXA7UsH/OGGfkYGARAKYywuvXkhXXSh2s/qx/eglM3g XsQ5CWPwWaTmg82aQO6/Uo= X-Received: by 2002:a05:6a00:3d11:b0:874:706d:962d with SMTP id d2e1a72fcca58-87d1c9bda24mr2008603b3a.31.1790160074165; Wed, 23 Sep 2026 03:41:14 -0700 (PDT) Received: from NVAPF55DW0D-IPD.. ([203.211.104.195]) by smtp.gmail.com with ESMTPSA id d2e1a72fcca58-87d1d5c1646sm1035870b3a.30.2026.09.23.03.41.12 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 23 Sep 2026 03:41:13 -0700 (PDT) From: ankur.tyagi85@gmail.com To: openembedded-devel@lists.openembedded.org Cc: Ankur Tyagi Subject: [oe][meta-multimedia][wrynose][PATCH 7/42] fluidsynth: mark CVEs fixed Date: Wed, 23 Sep 2026 22:40:21 +1200 Message-ID: <20260923104056.457360-7-ankur.tyagi85@gmail.com> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260923104056.457360-1-ankur.tyagi85@gmail.com> References: <20260923104056.457360-1-ankur.tyagi85@gmail.com> MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Wed, 23 Sep 2026 10:41:15 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-devel/message/130194 From: Ankur Tyagi Release note[1] also confirms the fix. Details: https://nvd.nist.gov/vuln/detail/cve-2026-58264 https://nvd.nist.gov/vuln/detail/cve-2026-61714 https://nvd.nist.gov/vuln/detail/cve-2026-61720 https://nvd.nist.gov/vuln/detail/cve-2026-61721 https://nvd.nist.gov/vuln/detail/cve-2026-61722 https://nvd.nist.gov/vuln/detail/cve-2026-61723 [1]https://github.com/FluidSynth/fluidsynth/releases/tag/v2.5.6 Signed-off-by: Ankur Tyagi --- .../recipes-multimedia/fluidsynth/fluidsynth_2.5.7.bb | 6 ++++++ 1 file changed, 6 insertions(+) diff --git a/meta-multimedia/recipes-multimedia/fluidsynth/fluidsynth_2.5.7.bb b/meta-multimedia/recipes-multimedia/fluidsynth/fluidsynth_2.5.7.bb index 8bf40cbb51..43b9e0c870 100644 --- a/meta-multimedia/recipes-multimedia/fluidsynth/fluidsynth_2.5.7.bb +++ b/meta-multimedia/recipes-multimedia/fluidsynth/fluidsynth_2.5.7.bb @@ -40,3 +40,9 @@ PACKAGECONFIG[sdl] = "-Denable-sdl3=ON,-Denable-sdl3=OFF,libsdl3" PACKAGECONFIG[sndfile] = "-Denable-libsndfile=ON,-Denable-libsndfile=OFF,libsndfile1" PACKAGECONFIG[systemd] = "-Denable-systemd=ON,-Denable-systemd=OFF,systemd" +CVE_STATUS[CVE-2026-58264] = "fixed-version: fixed since v2.5.6" +CVE_STATUS[CVE-2026-61714] = "fixed-version: fixed since v2.5.6" +CVE_STATUS[CVE-2026-61720] = "fixed-version: fixed since v2.5.6" +CVE_STATUS[CVE-2026-61721] = "fixed-version: fixed since v2.5.6" +CVE_STATUS[CVE-2026-61722] = "fixed-version: fixed since v2.5.6" +CVE_STATUS[CVE-2026-61723] = "fixed-version: fixed since v2.5.6" From patchwork Wed Sep 23 10:40:22 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Ankur Tyagi X-Patchwork-Id: 99020 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 5C20CC98309 for ; Wed, 23 Sep 2026 10:41:25 +0000 (UTC) Received: from mail-pz2-f12.google.com (mail-pz2-f12.google.com [74.125.228.12]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.4158.1790160076666288927 for ; Wed, 23 Sep 2026 03:41:16 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@gmail.com header.s=20251104 header.b=ZrJoScJ2; spf=pass (domain: gmail.com, ip: 74.125.228.12, mailfrom: ankur.tyagi85@gmail.com) Received: by mail-pz2-f12.google.com with SMTP id d2e1a72fcca58-85469f204f6so410434b3a.2 for ; Wed, 23 Sep 2026 03:41:16 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1790160076; x=1790764876; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=9/IEcVz+VfmcH/APiQK/xL7wTzW/WraiMfmZmM1SDpk=; b=ZrJoScJ2ZUF/+dTypq/yIbC8TxXVZr6saxzm8b0ulz+402uGp5p1I8CbnTmYpPCdKf vhB54vKkEWkEOrSmLGKcIPOCRHsqG8ej7cd4k54aXWpBE4/Byaoe8xiQsiP3eN5Ugici HB7Ycuo24NyutqJqBd+dw0BgYtZexOsv2gt9juf0rb6HPcuAQ85sgulMS5bu6zGiULVn q4uhsSKPjXlbcHR9Vz6IcBxW+pTvosnMi9Ya/u4BlozQ59BC8dTHF12iHT3qo9OCunun GxEXwrKSq6MsKTOPXAx/7huUc1rAOFlzI1RfSYNU/zBlCMpZ4gRClUL2QAqlGdQ6Pa0x L7GA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1790160076; x=1790764876; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=9/IEcVz+VfmcH/APiQK/xL7wTzW/WraiMfmZmM1SDpk=; b=EqmGKSTrH6pRMss3ycnd+hCUScPzYk+mfcBKV+hoYAcU9L5HPauk33sIkwtTsCVzFa jDi/E8l/2t9LBP+d7miWIoMXvIRJ0wPNX+07R817/eDTCmJr20Gd13iBT2ATCIlA2miD U2L3mrOegLBX4ewNEQxRGGaGCaMr/KUrliiaSMqa98KbgjPScDtFU3dPzjH6eJgubAyT YT/xiZwOSwpYok3Cj3dDtN87mxy4+v7qGCx9usYaLbbVx8KfQMRmPvj6GjYbMD6EqGCD SOCgyTxPKV6ft6ve8wMKVWHRMJN6qsxZLNdX2L7j1NAeerqB/1a8/rQg1exxep1PtCCy x6ww== X-Gm-Message-State: AFuF++myn6UK8yedfGHf0xRRLntsyTrEdDhdSfwnzO3h8zoSSmKjr7pI 75Qc7uraRRm9pezswzLHxPGVxFAUQs85k/9mRBHTdK2Kehxx/HA01/y8NJmuQA== X-Gm-Gg: AYBFou3els2qksrCLgEli6eWyAKO2YiRFfkymB6vuaLt1b9R+4UjCVppSxY/h4VzoFS qG5ANWETyle7F98cJf+eePxwi/DF2BSpFVm95tjyYhjW0FErOHEFgW7Ikq0f/i3qzIgjXcm344e gy61t6Qc0yn9cfJNAv6W9pwYUeIel/toZkvZojx93ssy5oxym/zRsQA/dyGT48zA8RpOsvLpRPv tRsfn6z1bCKTIpYumn0/R7ktl9ftnUiEifIEEaYZxrWVavg57WqGW1gc+/HJTDCkPNIE4lcWJma vovrB1yTAcVMdMi41JQ177LLRMzfaqv4MfWDP0GSr0u8M1z/wQXtV1dANn4OzEkxW1+b+w31V6g MaklSNMmWvvTNg7gwHxhLxOgHuSvMFsyfaZL80KZHn2EWnyu4KMpzZcrWaFCIvhSUbF/nzLgvQw 5m9LDvUZFBk+j3QWNlX7MoFjH4l6rGv59ZL+OYSS1Dhs2MLhWKIR7HQl84QYrqZ82/JO/2K+hnr 55NiuJXpdvcc99Ib9Otv1c= X-Received: by 2002:a05:6a00:2ea0:b0:878:3658:23db with SMTP id d2e1a72fcca58-87d1d9d2934mr2028704b3a.52.1790160075964; Wed, 23 Sep 2026 03:41:15 -0700 (PDT) Received: from NVAPF55DW0D-IPD.. ([203.211.104.195]) by smtp.gmail.com with ESMTPSA id d2e1a72fcca58-87d1d5c1646sm1035870b3a.30.2026.09.23.03.41.14 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 23 Sep 2026 03:41:15 -0700 (PDT) From: ankur.tyagi85@gmail.com To: openembedded-devel@lists.openembedded.org Cc: Ankur Tyagi Subject: [oe][meta-oe][wrynose][PATCH 8/42] freeipmi: patch CVE-2026-85509 Date: Wed, 23 Sep 2026 22:40:22 +1200 Message-ID: <20260923104056.457360-8-ankur.tyagi85@gmail.com> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260923104056.457360-1-ankur.tyagi85@gmail.com> References: <20260923104056.457360-1-ankur.tyagi85@gmail.com> MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Wed, 23 Sep 2026 10:41:25 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-devel/message/130195 From: Ankur Tyagi Backport commit from v1.6.19 matching NVD description. Details: https://nvd.nist.gov/vuln/detail/cve-2026-85509 Signed-off-by: Ankur Tyagi --- .../freeipmi/freeipmi/CVE-2026-85509.patch | 54 +++++++++++++++++++ .../freeipmi/freeipmi_1.6.17.bb | 1 + 2 files changed, 55 insertions(+) create mode 100644 meta-oe/recipes-support/freeipmi/freeipmi/CVE-2026-85509.patch diff --git a/meta-oe/recipes-support/freeipmi/freeipmi/CVE-2026-85509.patch b/meta-oe/recipes-support/freeipmi/freeipmi/CVE-2026-85509.patch new file mode 100644 index 0000000000..71de8a533c --- /dev/null +++ b/meta-oe/recipes-support/freeipmi/freeipmi/CVE-2026-85509.patch @@ -0,0 +1,54 @@ +From f0360d8816918c1f8de6aa8ea7cbe2ee51971a32 Mon Sep 17 00:00:00 2001 +From: Albert L Chu +Date: Tue, 11 Aug 2026 14:24:56 -0700 +Subject: [PATCH] libfreeipmi: clamp count_returned in _read_fru_data before + memcpy + +_read_fru_data reads FRU inventory in chunks, requesting at most +count_to_read (<= IPMI_FRU_COUNT_TO_READ_BLOCK_SIZE, 16) bytes per +iteration and copying the response into a fixed stack buffer frubuf. +The BMC-supplied count_returned was validated only as non-zero and as +equal to the returned data length -- never against the number of bytes +requested. A malicious or malfunctioning BMC returning more bytes than +were asked for (up to 255) with a matching payload passes both existing +checks, so memcpy(frubuf + num_bytes_read, buf, count_returned) writes +past the intended chunk and can advance num_bytes_read beyond +fru_read_bytes, overflowing the stack frubuf buffer. + +Reject count_returned > count_to_read before the memcpy. + +Assisted-by: Claude (Opus 4.8) +(cherry picked from commit b7d4f1021c89a9a5dede0f481b10d438a9e18e23) + +CVE: CVE-2026-85509 +Upstream-Status: Backport [https://cgit.git.savannah.gnu.org/cgit/freeipmi.git/commit/?h=freeipmi-1-6-19&id=b7d4f1021c89a9a5dede0f481b10d438a9e18e23] + +Dropped changes to the ChangeLog file. + +Signed-off-by: Ankur Tyagi +--- + libfreeipmi/fru/ipmi-fru.c | 11 +++++++++++ + 1 file changed, 11 insertions(+) + +diff --git a/libfreeipmi/fru/ipmi-fru.c b/libfreeipmi/fru/ipmi-fru.c +index f9dc8866d..bf35911c0 100644 +--- a/libfreeipmi/fru/ipmi-fru.c ++++ b/libfreeipmi/fru/ipmi-fru.c +@@ -488,6 +488,17 @@ _read_fru_data (ipmi_fru_ctx_t ctx, + goto cleanup; + } + ++ /* The BMC must not return more bytes than were requested. A ++ * larger count_returned would advance num_bytes_read past ++ * fru_read_bytes and overflow frubuf via the memcpy below, so ++ * reject it rather than trust the device-supplied count. ++ */ ++ if (count_returned > count_to_read) ++ { ++ FRU_SET_ERRNUM (ctx, IPMI_FRU_ERR_IPMI_ERROR); ++ goto cleanup; ++ } ++ + memcpy (frubuf + num_bytes_read, + buf, + count_returned); diff --git a/meta-oe/recipes-support/freeipmi/freeipmi_1.6.17.bb b/meta-oe/recipes-support/freeipmi/freeipmi_1.6.17.bb index f612caf3ac..ee0c05fb6f 100644 --- a/meta-oe/recipes-support/freeipmi/freeipmi_1.6.17.bb +++ b/meta-oe/recipes-support/freeipmi/freeipmi_1.6.17.bb @@ -16,6 +16,7 @@ LIC_FILES_CHKSUM = "file://COPYING;md5=d32239bcb673463ab874e80d47fae504 \ SRC_URI = "${GNU_MIRROR}/freeipmi/freeipmi-${PV}.tar.gz \ file://CVE-2026-50031-1.patch \ file://CVE-2026-50031-2.patch \ + file://CVE-2026-85509.patch \ " SRC_URI[sha256sum] = "16783d10faa28847a795cce0bf86deeaa72b8fbe71d1f0dc1101d13a6b501ec1" From patchwork Wed Sep 23 10:40:23 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Ankur Tyagi X-Patchwork-Id: 99022 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id B7405C9830B for ; Wed, 23 Sep 2026 10:41:25 +0000 (UTC) Received: from mail-pf1-f170.google.com (mail-pf1-f170.google.com [209.85.210.170]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.4277.1790160078611672763 for ; Wed, 23 Sep 2026 03:41:18 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@gmail.com header.s=20251104 header.b=RbdHz1V2; spf=pass (domain: gmail.com, ip: 209.85.210.170, mailfrom: ankur.tyagi85@gmail.com) Received: by mail-pf1-f170.google.com with SMTP id d2e1a72fcca58-86ec25cf7ecso1427150b3a.1 for ; Wed, 23 Sep 2026 03:41:18 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1790160078; x=1790764878; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=3OgFOYGy+ifwZfxBoY6i+IgUL+IQZy3pF7DlbrLZWY4=; b=RbdHz1V2Q1x69qBlB+GZAMzbYGwfV5bAV1G3N9NIJMfX1MrLZ4LJQ/2ql2kWiQ7R9L iUHi9AFhcuaBHpRpJnQ5UGUOJmSKKZAOC2t953VQK41EI56Zv3Mt4UzeIrjw07YFQO/Q uHi+cG0CWGP+fnF4bIn46FERFfx3yTKaZ9GWS0UjP29KgH7Wp/ngtm96ZLJJvpI2VpmN eg2pMwtV+r/eZ/wuiZRtu8+lCCTa7Y7wlD498rxk11nWpjQ30kT6Ir3smT2KNgHu1rQ2 LM6aR2taFat0d/vsd/Mn0hw/NwQi43yq5qP4avF25YQTGgDtcauERbc3JKXte7WvbQwF fLKg== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1790160078; x=1790764878; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=3OgFOYGy+ifwZfxBoY6i+IgUL+IQZy3pF7DlbrLZWY4=; b=Bu5zDKTHRjU4IAzh9TMdQ0NKdw3hPjEOJ2Spp/8XJWJWaljp115Qv+ogPdjDNWgYQA F7MsAO0Cb2UvNdSbTH2BrSMq9dpJAZaKQWwi6B5oMv0D6txjHjhTM7H5rc/kiY36Zz2s dVQtDaJPCJ4VNSqmzFis5s5H42ZJk9G7otnKNknH4GLz28Dq/+sbsMVmm15TPt8SPX69 SYY6dpRgjp5G+aLK/49/3i6VjNeYtL/eaMuOB9iCSbFAHsLEYk781cBW+5sBZ6i+nk7F T3XEjxzo6JYQqqnaVDmGOyoDmd5Ae283cUmYwDj+OUDX2rddaoiYU2nR8f16/s4OcrH/ vFRw== X-Gm-Message-State: AFuF++kY9V30uHczuroW6DKHrnUqXJ9NVkJeZ+LShGiVGNLb1tNN6sIA Z5dY3yOHvraJns5MetcoQiQgS8OQt50JTmLvHuq5gprPbInrwQAsPte7rHK/KA== X-Gm-Gg: AYBFou01Me+xEJrifBXRQIp4cfUtYIkGwhKWNl+aZoeqbUVHuRdiQ8nb8lXWCTdzCU4 RP9bqbV40PqOCowkE0lT7c9DkbfXM4nsfIAMJbj1s92PAJcd2sSgZbODVfHE53sRkwxLftk5WpW Bg/YK0VrYMg7rGW8hpa7pLASWC0Pa7R9cKk0Zd3dKpzx90nx3Z2qIE8uv2q+aIIQs9xa2u0PtV6 JfH/X2FToFFZ5MUI+vGcgDeMoyt9BLTfxx9pzmSXD0fpzo27S+oO4R/eDuHlxu+PS39TFLcbt15 oTqDtts8yuu2+4U8jbCfGU7uVRFXTzNCJK20CJW2on8544LR/fN389IZTXdOg5v5U7sIpO5K1+M Glhq/gqBQ2kNCYGRGRF2E2jBJNMKGoIYbAqbIId7B+tiGC8WQl3JAhr/d5KWbHb1ss2oaJCznNc xzLxJEqCHxjv+mkEFP4K2QS1kA65hbg+uE38vWpcClSq49U+6PH9xY+VIZk220Gd4tpg35e/4WN 7Z/21XpJvVsOSnEROwkfSQ= X-Received: by 2002:a05:6a00:a96:b0:857:73c3:446a with SMTP id d2e1a72fcca58-87c8452ed05mr2839118b3a.25.1790160077926; Wed, 23 Sep 2026 03:41:17 -0700 (PDT) Received: from NVAPF55DW0D-IPD.. ([203.211.104.195]) by smtp.gmail.com with ESMTPSA id d2e1a72fcca58-87d1d5c1646sm1035870b3a.30.2026.09.23.03.41.16 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 23 Sep 2026 03:41:17 -0700 (PDT) From: ankur.tyagi85@gmail.com To: openembedded-devel@lists.openembedded.org Cc: Ankur Tyagi Subject: [oe][meta-oe][wrynose][PATCH 9/42] freeipmi: patch CVE-2026-85508 Date: Wed, 23 Sep 2026 22:40:23 +1200 Message-ID: <20260923104056.457360-9-ankur.tyagi85@gmail.com> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260923104056.457360-1-ankur.tyagi85@gmail.com> References: <20260923104056.457360-1-ankur.tyagi85@gmail.com> MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Wed, 23 Sep 2026 10:41:25 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-devel/message/130196 From: Ankur Tyagi Backport commit from v1.6.19 matching NVD description. Details: https://nvd.nist.gov/vuln/detail/cve-2026-85508 Signed-off-by: Ankur Tyagi --- .../freeipmi/freeipmi/CVE-2026-85508.patch | 51 +++++++++++++++++++ .../freeipmi/freeipmi_1.6.17.bb | 1 + 2 files changed, 52 insertions(+) create mode 100644 meta-oe/recipes-support/freeipmi/freeipmi/CVE-2026-85508.patch diff --git a/meta-oe/recipes-support/freeipmi/freeipmi/CVE-2026-85508.patch b/meta-oe/recipes-support/freeipmi/freeipmi/CVE-2026-85508.patch new file mode 100644 index 0000000000..80d2e53eea --- /dev/null +++ b/meta-oe/recipes-support/freeipmi/freeipmi/CVE-2026-85508.patch @@ -0,0 +1,51 @@ +From 4525750676ebf8dcf96a04bcd8cd59767581c44c Mon Sep 17 00:00:00 2001 +From: Albert L Chu +Date: Tue, 18 Aug 2026 12:44:01 -0700 +Subject: [PATCH] ipmi-oem: bound Dell CMC-IPv6-info accumulation loop against + buffer size + +_output_dell_system_info_cmc_ipv6_info accumulates configuration +parameter data from four get-system-info responses into a 256-byte +cmc_ipv6_info stack buffer, copying (len - 1) bytes per iteration at a +running offset with no check against the destination size. The response +field is BMC-controlled and can legitimately return up to 128 bytes per +call, so a malicious BMC returning large blocks overflows the stack +buffer with attacker-controlled data starting on the third iteration. + +Reject any copy whose cumulative length would exceed sizeof +(cmc_ipv6_info) before the memcpy, mirroring the existing invalid-length +error path. + +Assisted-by: Claude (Opus 4.8) +(cherry picked from commit b34841134f3d3206840de06fb152ae3ee0b8bcff) + +CVE: CVE-2026-85508 +Upstream-Status: Backport [https://cgit.git.savannah.gnu.org/cgit/freeipmi.git/commit/?h=freeipmi-1-6-19&id=b34841134f3d3206840de06fb152ae3ee0b8bcff] + +Dropped changes to the ChangeLog file. + +Signed-off-by: Ankur Tyagi +--- + ipmi-oem/ipmi-oem-dell.c | 9 +++++++++ + 1 file changed, 9 insertions(+) + +diff --git a/ipmi-oem/ipmi-oem-dell.c b/ipmi-oem/ipmi-oem-dell.c +index f322cdfb8..ff2d39b1c 100644 +--- a/ipmi-oem/ipmi-oem-dell.c ++++ b/ipmi-oem/ipmi-oem-dell.c +@@ -1220,6 +1220,15 @@ _output_dell_system_info_cmc_ipv6_info (ipmi_oem_state_data_t *state_data) + goto cleanup; + } + ++ if ((cmc_ipv6_info_len + (len - 1)) > sizeof (cmc_ipv6_info)) ++ { ++ pstdout_fprintf (state_data->pstate, ++ stderr, ++ "ipmi_cmd_get_system_info_parameters: invalid buffer length returned: %d\n", ++ len); ++ goto cleanup; ++ } ++ + memcpy (&cmc_ipv6_info[cmc_ipv6_info_len], + configuration_parameter_data + 1, /* remove set selector */ + len - 1); diff --git a/meta-oe/recipes-support/freeipmi/freeipmi_1.6.17.bb b/meta-oe/recipes-support/freeipmi/freeipmi_1.6.17.bb index ee0c05fb6f..8fa615c13a 100644 --- a/meta-oe/recipes-support/freeipmi/freeipmi_1.6.17.bb +++ b/meta-oe/recipes-support/freeipmi/freeipmi_1.6.17.bb @@ -17,6 +17,7 @@ SRC_URI = "${GNU_MIRROR}/freeipmi/freeipmi-${PV}.tar.gz \ file://CVE-2026-50031-1.patch \ file://CVE-2026-50031-2.patch \ file://CVE-2026-85509.patch \ + file://CVE-2026-85508.patch \ " SRC_URI[sha256sum] = "16783d10faa28847a795cce0bf86deeaa72b8fbe71d1f0dc1101d13a6b501ec1" From patchwork Wed Sep 23 10:40:24 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Ankur Tyagi X-Patchwork-Id: 99023 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id D0191C9830C for ; Wed, 23 Sep 2026 10:41:25 +0000 (UTC) Received: from mail-pz2-f41.google.com (mail-pz2-f41.google.com [74.125.228.41]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.4162.1790160080838704844 for ; Wed, 23 Sep 2026 03:41:20 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@gmail.com header.s=20251104 header.b=cB9i6vWr; spf=pass (domain: gmail.com, ip: 74.125.228.41, mailfrom: ankur.tyagi85@gmail.com) Received: by mail-pz2-f41.google.com with SMTP id d2e1a72fcca58-85469f20513so446076b3a.0 for ; Wed, 23 Sep 2026 03:41:20 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1790160080; x=1790764880; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=PNT73KzDZtsUMuSNfr0Zd2l7NPt0adjhqwXgtje7z4E=; b=cB9i6vWrRgMdDGxQiphLEAB68IoSwP1hK9vltZ6ecnrUBmW78sX4PckTvNOFBMoLaP trHb5ScXTvVIqm1u0vW6CSs5ta5u5fQ9Kbl9zkG0JD7o4PjxXhAz2RHNU4mNK214WUjk DQJveD82rdcT65DTcueJWLgiSwx7nGeFxwQqyxv88PHktmX2rr/5KocGiiBnwFT0s6uB F/c+1PCxK/oI7vnm3oWV3qaOtDyKWbaWuIol0Jkzuyjwps4JlkgEfQ4q1yai1UrtBwXH FSMuz2tEw48smbBORMc+EjMwoI7Ee+X872okWgKcV13Cb846vfpzxVVnJmLz9o6BK+OJ T5hA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1790160080; x=1790764880; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=PNT73KzDZtsUMuSNfr0Zd2l7NPt0adjhqwXgtje7z4E=; b=l7vUYBfEvNMH10EPwfkRIUxhBRSeA4O8CVfOehkW1ionhzL7vUmqSEXLVEGGFw5x7h mMyRdRN15toPlzd6MAYPJy4ckMYBGnWOZiWMD4QXGPh6fdkfK8hLizJSEQUdOGW9FscK sheArhD4pi0C1NAt5L4SGlxLGhXM38+nNgwf4Qop6F+DEt8OlNPZaQgTTPyaR9TUAW5/ 98pv5iJuJLmLa6ILhJSbTVI7robJGf8itVj+JjD61Cnz99VrzkrzqzMxN5C8BNxA5KG7 JFyLR/5G3EPu89WIKpiQ/l8rbYCVGi4g9keFv0EWmT2/1ZlScTj3BP8jF/o6ku7Mmr1U xesQ== X-Gm-Message-State: AFuF++nXTxDW1HfzK2+bHFDIJ/6YzNezI9o3jRbTdE9mDOoVAmBy6pJm Y9aR4xtazAe05nvIsFSHDIpM2Vz6Di5aEA6/EF7r0K8rn7yLOugMXc9EQcIZIQ== X-Gm-Gg: AYBFou17B4PHqGHQnPzjVIeyiCbLhVi3Ab8N+H8wOFqMcOtOD7g4tc3xqF6HUKuZicb mDxGK53B6LSspGBmNVjgFJEFbMlt6xzblc84DX2aIKacY6P2aN9lw/cjLKai/pjXjIUj23WnvcH XMeQDgA6rY8Op1Mb7J2PCqYF8zUNjMe6dhQgaLJRJdK3NzU+KXGy2DdZWtqrdkUyZUxIY8aPDI3 nO3z7Ndwl2pwy7/hUtoHjohBPMRQSwy0BQZyDDj8ewATEEFvIdLrDVlE6Rfg1GbcyGy3ZfMSlwt U8kHKEAqYAU8U/ZChex3J7t5m+Z01FKvknLExY8EQQN/DKNY7COUTO6SOtsPIDy0fPaSaPa22XQ gqoMF/zENZ62MnnoIvXbqnPheOrO9OFvSzbz0y/iSkFfOTYbK3fD6if79ZpLkUm0cYf82+dDHoy ApC+tczNxfH5J4MwndG7+1QPhnsmXRXD4ys6tEz2TwyH13O4MFBcSZLyGDR2cP3aEgwXVRRSubQ VD2xUn3FVWNIL41/CDF8gg= X-Received: by 2002:a05:6a00:4612:b0:845:c694:5c3d with SMTP id d2e1a72fcca58-87d1a6b1b95mr2002802b3a.1.1790160080182; Wed, 23 Sep 2026 03:41:20 -0700 (PDT) Received: from NVAPF55DW0D-IPD.. ([203.211.104.195]) by smtp.gmail.com with ESMTPSA id d2e1a72fcca58-87d1d5c1646sm1035870b3a.30.2026.09.23.03.41.18 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 23 Sep 2026 03:41:19 -0700 (PDT) From: ankur.tyagi85@gmail.com To: openembedded-devel@lists.openembedded.org Cc: Ankur Tyagi Subject: [oe][meta-oe][wrynose][PATCH 10/42] freeipmi: patch CVE-2026-85507 Date: Wed, 23 Sep 2026 22:40:24 +1200 Message-ID: <20260923104056.457360-10-ankur.tyagi85@gmail.com> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260923104056.457360-1-ankur.tyagi85@gmail.com> References: <20260923104056.457360-1-ankur.tyagi85@gmail.com> MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Wed, 23 Sep 2026 10:41:25 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-devel/message/130197 From: Ankur Tyagi Backport commit from v1.6.19 matching NVD description. Details: https://nvd.nist.gov/vuln/detail/cve-2026-85507 Signed-off-by: Ankur Tyagi --- .../freeipmi/freeipmi/CVE-2026-85507.patch | 50 +++++++++++++++++++ .../freeipmi/freeipmi_1.6.17.bb | 1 + 2 files changed, 51 insertions(+) create mode 100644 meta-oe/recipes-support/freeipmi/freeipmi/CVE-2026-85507.patch diff --git a/meta-oe/recipes-support/freeipmi/freeipmi/CVE-2026-85507.patch b/meta-oe/recipes-support/freeipmi/freeipmi/CVE-2026-85507.patch new file mode 100644 index 0000000000..f0bea66599 --- /dev/null +++ b/meta-oe/recipes-support/freeipmi/freeipmi/CVE-2026-85507.patch @@ -0,0 +1,50 @@ +From fa27bdb4a6df199b5a60c078ed1ce78936b6276f Mon Sep 17 00:00:00 2001 +From: Albert L Chu +Date: Tue, 18 Aug 2026 12:56:55 -0700 +Subject: [PATCH] ipmi-oem: bound Dell CMC-info accumulation loop against + buffer size + +_output_dell_system_info_cmc_info accumulates configuration parameter +data from four get-system-info responses into a 256-byte cmc_info stack +buffer, copying (len - 1) bytes per iteration at a running offset with no +check against the destination size. The response field is BMC-controlled +and can legitimately return up to 128 bytes per call, so a malicious BMC +returning large blocks overflows the stack buffer with attacker-controlled +data starting on the third iteration. + +Reject any copy whose cumulative length would exceed sizeof (cmc_info) +before the memcpy, mirroring the existing invalid-length error path. + +Assisted-by: Claude (Opus 4.8) +(cherry picked from commit 65759a170b0179b15a9bd3483ddc067e337bd150) + +CVE: CVE-2026-85507 +Upstream-Status: Backport [https://cgit.git.savannah.gnu.org/cgit/freeipmi.git/commit/?h=freeipmi-1-6-19&id=65759a170b0179b15a9bd3483ddc067e337bd150] + +Dropped changes to the ChangeLog file. + +Signed-off-by: Ankur Tyagi +--- + ipmi-oem/ipmi-oem-dell.c | 9 +++++++++ + 1 file changed, 9 insertions(+) + +diff --git a/ipmi-oem/ipmi-oem-dell.c b/ipmi-oem/ipmi-oem-dell.c +index ff2d39b1c..19c962cb1 100644 +--- a/ipmi-oem/ipmi-oem-dell.c ++++ b/ipmi-oem/ipmi-oem-dell.c +@@ -937,6 +937,15 @@ _output_dell_system_info_cmc_info (ipmi_oem_state_data_t *state_data) + goto cleanup; + } + ++ if ((cmc_info_len + (len - 1)) > sizeof (cmc_info)) ++ { ++ pstdout_fprintf (state_data->pstate, ++ stderr, ++ "ipmi_cmd_get_system_info_parameters: invalid buffer length returned: %d\n", ++ len); ++ goto cleanup; ++ } ++ + memcpy (&cmc_info[cmc_info_len], + configuration_parameter_data + 1, /* remove set selector */ + len - 1); diff --git a/meta-oe/recipes-support/freeipmi/freeipmi_1.6.17.bb b/meta-oe/recipes-support/freeipmi/freeipmi_1.6.17.bb index 8fa615c13a..06fc6ca174 100644 --- a/meta-oe/recipes-support/freeipmi/freeipmi_1.6.17.bb +++ b/meta-oe/recipes-support/freeipmi/freeipmi_1.6.17.bb @@ -18,6 +18,7 @@ SRC_URI = "${GNU_MIRROR}/freeipmi/freeipmi-${PV}.tar.gz \ file://CVE-2026-50031-2.patch \ file://CVE-2026-85509.patch \ file://CVE-2026-85508.patch \ + file://CVE-2026-85507.patch \ " SRC_URI[sha256sum] = "16783d10faa28847a795cce0bf86deeaa72b8fbe71d1f0dc1101d13a6b501ec1" From patchwork Wed Sep 23 10:40:25 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Ankur Tyagi X-Patchwork-Id: 99021 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 5A879C982EA for ; Wed, 23 Sep 2026 10:41:25 +0000 (UTC) Received: from mail-pz2-f42.google.com (mail-pz2-f42.google.com [74.125.228.42]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.4163.1790160082744259992 for ; Wed, 23 Sep 2026 03:41:22 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@gmail.com header.s=20251104 header.b=J1YK2lhb; spf=pass (domain: gmail.com, ip: 74.125.228.42, mailfrom: ankur.tyagi85@gmail.com) Received: by mail-pz2-f42.google.com with SMTP id 41be03b00d2f7-cc4aa0f1766so552717a12.0 for ; Wed, 23 Sep 2026 03:41:22 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1790160082; x=1790764882; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=GyMAYTrCHT8kx2wJ9DfBdg+KJnRt90lQrD6WHFSjccY=; b=J1YK2lhbOFzxz5Gzbfd6hM1hs9BEp6XsGQNWc7DnCdpHq86Jv+4zF2x7h55tcBaisB ZeAuUW1SvhhECoceDX9tRYmPdT0Kl+ZDFNfWW5tFOa4HYQGuzErss31V/ioTsXgH9p0v eZPYhKPjYOSZGVi3827hVI9a4YEqoNIfwbuM/ArikVKvLVGHfQ1knRHg5Rdn2/NvJ5RJ +8JKI1cKMpxBllwQK3P8tyjVLzGjORJOSh76MyX6XoQ0U9iuKDkP0iMd4vgquqxhVHkF YIqlvzBk2GRjNTRODaujKY1dyQEkL5J9u9Ch6ZnCyWxYAkEqB4PUSSkqG+xUHes0tu/v VLcQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1790160082; x=1790764882; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=GyMAYTrCHT8kx2wJ9DfBdg+KJnRt90lQrD6WHFSjccY=; b=itZ9hY9xu1YaQagsSzii+7wof3kF0gtc05u1xmHLl4uTrxRpUksyRW9S5CqzhzWemj EgQIVIEim66L8r5zxqmngOKhA4hV3myak7iABHQLTJPlOzfeAOsK89kbKiCbYBddIfE8 Q6TS7AHF/Z3CUaaRSaA5mbDJ61SrFF81Jm+z8ebuT/Ke0OyPRidMpJyeD8DBYNxjrd4N FkeKBpQ58VoCHSLaBuCbW4Hw4IGPGlsr2DicRdtM7a/HIByQPNmFHdlagTjrWdM8nRbK i4I0YcVMB3AYzrOwZRhwVjXdc3xeHt4IJof9ivlZClTF++R93vCbaF0snETFyjCmunV8 C9/g== X-Gm-Message-State: AFuF++k5oo0JuoJUPZMSO7v/ruDsbHRFb6YaWOF9WODpIihiQsDFh/vw nTme5SQZvxPHevVCCw7lgq157Siw1fGsbiKGlQlqfAC+hlktuk9iAeCFzRI0NQ== X-Gm-Gg: AYBFou1MR9oL+/O4OhYBFViBxI3cNsYdg6Wr8EtkBDilH5gHcrQEL0717m4BSCGZLqV xzTLX9JNxZPl5QnoJu9KwaEJzE5GNp8z5LEUWXQTAOxBnHSWGU3CyBdLWRi+OUxnG3JJ8VQEWRo UNpWpxn0KWlCSInylSGtceTrc8iGTGhqjYSjH9Pl7/rzk39u0lnsHnZPHKacOfbt201BzHhUSx5 l0ykKInbhsaFZgVCmPXgFT5cictW/UGyBdVAdsAWlj7brwsoPdSgMnN36beGqjPnt/N+mrVlsGF riYMWq6Nd+6UcJMM6ZyMC8ZCobAZKGXgHCL8KHqFo0E4zRbzIhLou2yisriyRUxuYO2dfxi+wMS Ga2jUFLL2ZJMBeXTqjO4y0cDuqGaXsRSMYQyCR6mJuu9R0aqu+A8nR9Q/5FvHlyeoIYEs5TSptk 15TE9p22YxjD05xaDw6JNMcKLQZDPRYLXjbnT5XzxfspyN4OwGgEW703+AuCLB+QjJDBXo0rNP2 eyzN0/O2F7xk8bTDIO8mwHPD4+WmT8Bvw== X-Received: by 2002:a05:6a21:b84:b0:3dd:85a9:55a9 with SMTP id adf61e73a8af0-3ddf826330amr2018565637.34.1790160082095; Wed, 23 Sep 2026 03:41:22 -0700 (PDT) Received: from NVAPF55DW0D-IPD.. ([203.211.104.195]) by smtp.gmail.com with ESMTPSA id d2e1a72fcca58-87d1d5c1646sm1035870b3a.30.2026.09.23.03.41.20 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 23 Sep 2026 03:41:21 -0700 (PDT) From: ankur.tyagi85@gmail.com To: openembedded-devel@lists.openembedded.org Cc: Ankur Tyagi Subject: [oe][meta-oe][wrynose][PATCH 11/42] freeipmi: patch CVE-2026-85506 Date: Wed, 23 Sep 2026 22:40:25 +1200 Message-ID: <20260923104056.457360-11-ankur.tyagi85@gmail.com> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260923104056.457360-1-ankur.tyagi85@gmail.com> References: <20260923104056.457360-1-ankur.tyagi85@gmail.com> MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Wed, 23 Sep 2026 10:41:25 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-devel/message/130198 From: Ankur Tyagi Backport commit from v1.6.19 matching NVD description. Details: https://nvd.nist.gov/vuln/detail/cve-2026-85506 Signed-off-by: Ankur Tyagi --- .../freeipmi/freeipmi/CVE-2026-85506.patch | 51 +++++++++++++++++++ .../freeipmi/freeipmi_1.6.17.bb | 1 + 2 files changed, 52 insertions(+) create mode 100644 meta-oe/recipes-support/freeipmi/freeipmi/CVE-2026-85506.patch diff --git a/meta-oe/recipes-support/freeipmi/freeipmi/CVE-2026-85506.patch b/meta-oe/recipes-support/freeipmi/freeipmi/CVE-2026-85506.patch new file mode 100644 index 0000000000..267754ec9a --- /dev/null +++ b/meta-oe/recipes-support/freeipmi/freeipmi/CVE-2026-85506.patch @@ -0,0 +1,51 @@ +From 8652f7ca02cb6920c7a4c89add8effa6e9419ec7 Mon Sep 17 00:00:00 2001 +From: Albert L Chu +Date: Tue, 18 Aug 2026 14:09:35 -0700 +Subject: [PATCH] ipmi-oem: bound Dell iDRAC-info accumulation loop against + buffer size + +_get_dell_system_info_idrac_info accumulates configuration parameter data +from three get-system-info responses into a 256-byte idrac_info stack +buffer, copying (len - 1) bytes per iteration at a running offset with no +check against the destination size. The response field is BMC-controlled +and can legitimately return up to 128 bytes per call, so a malicious BMC +returning large blocks overflows the stack buffer with attacker-controlled +data on the third iteration. This helper is also reached via +dell get-system-info mac-addresses. + +Reject any copy whose cumulative length would exceed sizeof (idrac_info) +before the memcpy, mirroring the existing invalid-length error path. + +Assisted-by: Claude (Opus 4.8) +(cherry picked from commit 301458ac7b230dbfa42e73ee2c2959e4bbaecf30) + +CVE: CVE-2026-85506 +Upstream-Status: Backport [https://cgit.git.savannah.gnu.org/cgit/freeipmi.git/commit/?h=freeipmi-1-6-19&id=301458ac7b230dbfa42e73ee2c2959e4bbaecf30] + +Dropped changes to the ChangeLog file. + +Signed-off-by: Ankur Tyagi +--- + ipmi-oem/ipmi-oem-dell.c | 9 +++++++++ + 1 file changed, 9 insertions(+) + +diff --git a/ipmi-oem/ipmi-oem-dell.c b/ipmi-oem/ipmi-oem-dell.c +index 19c962cb1..f8e5ae165 100644 +--- a/ipmi-oem/ipmi-oem-dell.c ++++ b/ipmi-oem/ipmi-oem-dell.c +@@ -595,6 +595,15 @@ _get_dell_system_info_idrac_info (ipmi_oem_state_data_t *state_data, + goto cleanup; + } + ++ if ((idrac_info_len + (len - 1)) > sizeof (idrac_info)) ++ { ++ pstdout_fprintf (state_data->pstate, ++ stderr, ++ "ipmi_cmd_get_system_info_parameters: invalid buffer length returned: %d\n", ++ len); ++ goto cleanup; ++ } ++ + memcpy (&idrac_info[idrac_info_len], + configuration_parameter_data + 1, /* remove set selector */ + len - 1); diff --git a/meta-oe/recipes-support/freeipmi/freeipmi_1.6.17.bb b/meta-oe/recipes-support/freeipmi/freeipmi_1.6.17.bb index 06fc6ca174..8438a517ec 100644 --- a/meta-oe/recipes-support/freeipmi/freeipmi_1.6.17.bb +++ b/meta-oe/recipes-support/freeipmi/freeipmi_1.6.17.bb @@ -19,6 +19,7 @@ SRC_URI = "${GNU_MIRROR}/freeipmi/freeipmi-${PV}.tar.gz \ file://CVE-2026-85509.patch \ file://CVE-2026-85508.patch \ file://CVE-2026-85507.patch \ + file://CVE-2026-85506.patch \ " SRC_URI[sha256sum] = "16783d10faa28847a795cce0bf86deeaa72b8fbe71d1f0dc1101d13a6b501ec1" From patchwork Wed Sep 23 10:40:26 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Ankur Tyagi X-Patchwork-Id: 99024 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 757D6C982FA for ; Wed, 23 Sep 2026 10:41:25 +0000 (UTC) Received: from mail-pz2-f41.google.com (mail-pz2-f41.google.com [74.125.228.41]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.4165.1790160084743051211 for ; Wed, 23 Sep 2026 03:41:24 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@gmail.com header.s=20251104 header.b=XCgbmv2h; spf=pass (domain: gmail.com, ip: 74.125.228.41, mailfrom: ankur.tyagi85@gmail.com) Received: by mail-pz2-f41.google.com with SMTP id d2e1a72fcca58-86efece610cso402067b3a.0 for ; Wed, 23 Sep 2026 03:41:24 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1790160084; x=1790764884; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=3A6axOm4CHcUGmPnwRchf67ER29TLSp6J6xw15vbdVc=; b=XCgbmv2hnlau2Xi1ec2hANuIUEL+ktI+ep5hik+wTYRcX42Dr7HrJQEoXDk6T8pzzQ UKyVRTwQu/6b1o5cXqTB3XKPlQ3z8BgLC8GFaWQwq2aIiS4ssrXnPDykxENvcz8/aIil M8oSPNEoPyo9VFvm9ZXyTkJH2lFi3jG1xHpXhvJduM580HZqPn5riFdUTQAHbiBvHEi5 SAajOzfkRyi/gHt5QTAq6sFyyeVKodemG3G9jDf7UKeHFls58IBGOEfb0BJ5BvL4N2Ja 6Hen+aDotBu3Hpm9V35hJtT0wBufmmtInG45gjas6iZt3FxBWna4z95HTif/UZ0W20g7 aZeg== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1790160084; x=1790764884; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=3A6axOm4CHcUGmPnwRchf67ER29TLSp6J6xw15vbdVc=; b=MaA063lEZ+h1fHlxjT2jCbMUD38XnidPM812bFsMK8yIwP9AEqA/kO0/Sn/SVK7ee2 SjmwJpKOwhyzLW3lM8mXIDbRknELJkGbiJTmqyamodjesMAhai3iYKDDGS3f55o+dfmn BfX1k08pwH8nCqUmxz8S62w5ijBbSfKNkY87EmKMRbDH111IDWhioJhCtclZs3oxyLuf 48GehtHBzxyrmwAiOhDTlxGPW8qbX/IMV4VTPWA+/16AfF2ICpP/ihOnAWs+p1SBYJhB zHVIWlWRm4NqKvyyJzOGmegox6WM31of9CQZKybNh3xJnkUlKVbpPZpHVMxZDrecw6lh mWDw== X-Gm-Message-State: AFuF++kl+5YQm5z+pcUUJPMMMtjkwtG1623fy+PtE60q/beCVWRAuH34 98RLNSDxvFktcMCKKAv+sChg/JyaqRLluv9znIWv5M4MUTaxJD4fdEq9CKJbSw== X-Gm-Gg: AYBFou1W+9ChklSJ4HXH7A9YMf2SwqQfsOiCzO/zoJ+6fRuob0TjkqWIrVNLs/R+PUW e267xfeBGk7XSfFhiJpTHiaYXzBlRL/vpl7drRINHEqSjWw+ly4Eahy3XYK97oDg0SCCOnh2Vpf StK5eYsoeNhT78AxabxyjFAiH7zRls/qUjY4tkWwTtILzAbsdq7bSmZK4fDfKbIeeX6g3cjnTnN 9y3uveTSpZem8AoK5MTwwVLd0VeRuYu8YR/CBmXuPeMES1dGkIcqQHhoWA3EHePblyJBxa/IDlo W3tj8uv21Wip/LzNL2gt8J/EC4kNvlreqRxI87m3vpcqyS6oMKFXEWTWORiqeSs9sf9cy1zsd51 Zu59SlRvnQV0dQ/62aGciAFDq+rHpQwQ7zzRv2IQYoQUqFs/kUzJXiuZAN8unYZeLhCIHILYJAt czAJQAtkEVk+grRTgUUbKN+L/jv+l5A3kWWKvMbf2WQmpCpeeuEjvaixoljqwHgBbjQoERRXzfO q0ZThzo48aqqPWZfLbB20vm3KNIUNmQcA== X-Received: by 2002:a05:6a00:1707:b0:874:708d:b633 with SMTP id d2e1a72fcca58-87d1bfad49emr1940866b3a.31.1790160084064; Wed, 23 Sep 2026 03:41:24 -0700 (PDT) Received: from NVAPF55DW0D-IPD.. ([203.211.104.195]) by smtp.gmail.com with ESMTPSA id d2e1a72fcca58-87d1d5c1646sm1035870b3a.30.2026.09.23.03.41.22 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 23 Sep 2026 03:41:23 -0700 (PDT) From: ankur.tyagi85@gmail.com To: openembedded-devel@lists.openembedded.org Cc: Ankur Tyagi Subject: [oe][meta-oe][wrynose][PATCH 12/42] freeipmi: patch CVE-2026-85505 Date: Wed, 23 Sep 2026 22:40:26 +1200 Message-ID: <20260923104056.457360-12-ankur.tyagi85@gmail.com> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260923104056.457360-1-ankur.tyagi85@gmail.com> References: <20260923104056.457360-1-ankur.tyagi85@gmail.com> MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Wed, 23 Sep 2026 10:41:25 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-devel/message/130199 From: Ankur Tyagi Backport commit from v1.6.19 matching NVD description. Details: https://nvd.nist.gov/vuln/detail/cve-2026-85505 Signed-off-by: Ankur Tyagi --- .../freeipmi/freeipmi/CVE-2026-85505.patch | 49 +++++++++++++++++++ .../freeipmi/freeipmi_1.6.17.bb | 1 + 2 files changed, 50 insertions(+) create mode 100644 meta-oe/recipes-support/freeipmi/freeipmi/CVE-2026-85505.patch diff --git a/meta-oe/recipes-support/freeipmi/freeipmi/CVE-2026-85505.patch b/meta-oe/recipes-support/freeipmi/freeipmi/CVE-2026-85505.patch new file mode 100644 index 0000000000..e27b8a976d --- /dev/null +++ b/meta-oe/recipes-support/freeipmi/freeipmi/CVE-2026-85505.patch @@ -0,0 +1,49 @@ +From e479401fcd9588f1ffb7444e09b97afc29f21f82 Mon Sep 17 00:00:00 2001 +From: Albert L Chu +Date: Mon, 17 Aug 2026 16:55:00 -0700 +Subject: [PATCH] ipmi-oem: clamp Fujitsu SEL long-text truncate copy to actual + data + +ipmi_oem_fujitsu_get_sel_entry_long_text, in the "truncate if there is +overflow" branch, copied a fixed +IPMI_OEM_FUJITSU_SEL_ENTRY_LONG_TEXT_MAX_DATA_LENGTH - offset bytes from +&bytes_rs[16] into data_buf regardless of how many bytes the BMC +actually returned. bytes_rs is filled only to rs_len and is not +memset, so a short response left the memcpy reading uninitialized stack +past the real data. The read stayed within the 256-byte bytes_rs and +the data_buf destination, so it was an uninitialized read, not an +out-of-bounds access. + +The truncate branch is entered only when offset + component_length +exceeds data_length, so data_length - offset is both the number of bytes +needed to fill data_buf to data_length and strictly less than +component_length (= strlen of the NUL-terminated response data), hence +always within the received bytes. Copy that amount instead of the fixed +maximum. + +Assisted-by: Claude (Opus 4.8) +(cherry picked from commit 8e0e908c5f11f3ccbf128e09af58568767e6367c) + +CVE: CVE-2026-85505 +Upstream-Status: Backport [https://cgit.git.savannah.gnu.org/cgit/freeipmi.git/commit/?h=freeipmi-1-6-19&id=8e0e908c5f11f3ccbf128e09af58568767e6367c] + +Dropped changes to the ChangeLog file. + +Signed-off-by: Ankur Tyagi +--- + ipmi-oem/ipmi-oem-fujitsu.c | 2 +- + 1 file changed, 1 insertion(+), 1 deletion(-) + +diff --git a/ipmi-oem/ipmi-oem-fujitsu.c b/ipmi-oem/ipmi-oem-fujitsu.c +index 10220c9fc..57d04a0bf 100644 +--- a/ipmi-oem/ipmi-oem-fujitsu.c ++++ b/ipmi-oem/ipmi-oem-fujitsu.c +@@ -1400,7 +1400,7 @@ ipmi_oem_fujitsu_get_sel_entry_long_text (ipmi_oem_state_data_t *state_data) + { + memcpy (data_buf + offset, + &bytes_rs[16], +- IPMI_OEM_FUJITSU_SEL_ENTRY_LONG_TEXT_MAX_DATA_LENGTH - offset); ++ data_length - offset); + offset = data_length; + } + else diff --git a/meta-oe/recipes-support/freeipmi/freeipmi_1.6.17.bb b/meta-oe/recipes-support/freeipmi/freeipmi_1.6.17.bb index 8438a517ec..a3a5fb5af0 100644 --- a/meta-oe/recipes-support/freeipmi/freeipmi_1.6.17.bb +++ b/meta-oe/recipes-support/freeipmi/freeipmi_1.6.17.bb @@ -20,6 +20,7 @@ SRC_URI = "${GNU_MIRROR}/freeipmi/freeipmi-${PV}.tar.gz \ file://CVE-2026-85508.patch \ file://CVE-2026-85507.patch \ file://CVE-2026-85506.patch \ + file://CVE-2026-85505.patch \ " SRC_URI[sha256sum] = "16783d10faa28847a795cce0bf86deeaa72b8fbe71d1f0dc1101d13a6b501ec1" From patchwork Wed Sep 23 10:40:27 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Ankur Tyagi X-Patchwork-Id: 99028 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id CB7E1C982EA for ; Wed, 23 Sep 2026 10:41:35 +0000 (UTC) Received: from mail-pz2-f42.google.com (mail-pz2-f42.google.com [74.125.228.42]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.4279.1790160086692404644 for ; Wed, 23 Sep 2026 03:41:26 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@gmail.com header.s=20251104 header.b=NCqXZ5/N; spf=pass (domain: gmail.com, ip: 74.125.228.42, mailfrom: ankur.tyagi85@gmail.com) Received: by mail-pz2-f42.google.com with SMTP id 41be03b00d2f7-cc4aa0f1766so552739a12.0 for ; Wed, 23 Sep 2026 03:41:26 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1790160086; x=1790764886; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=9azdClPeK74WUp2u9Ixn/x5DTm5IsoE1mZwzYFBgMMA=; b=NCqXZ5/NpwjKVzFpouKifnZAW1V5YogTTHKhVTYmEV9tVyAGSI+eOTuKnbEgdUb01W bSmaciZAblKSaGnLToMOeXNSu7shpGjUlBEY45wEBgTFALW5G+qjfHQY90/J8hqG9PIe Leu7Jh7bAi6D6SQi9oZkaaH6S2EsH/bhmRJJpVZLRIKnz6pLK2cKMXAlD6C3Juvv+5xJ gZgC++zNtn9CxVMnx9iNnwEZSnM2VnUgMZpcV2mzT1mqM6pn279kv7q040uceefv11J6 PIenW993zdFO/DTSuxhvrfJaKBblSi5qBn3VVoh+jj0L9+nGFH1XnL7TVX+qeP+ExQQV tPQw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1790160086; x=1790764886; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=9azdClPeK74WUp2u9Ixn/x5DTm5IsoE1mZwzYFBgMMA=; b=IuJEiOdTyelb2Pg3rdVidGDxW3Y0lLEu6aGVJ2o3txqnsVidl5V4yugg9R505snuDT XAL6VICj70C0dysz35/6k/oHb2TAJBrT2erUsaxYQn9FbxnyP4ZAv+Z0FE/jjCfmUW4r W7uJCMbo5MhhN1oWJU4ts+a0NFAGL0NAKNhoXPQ+C7M/howwxr7Vg9kkpyCFM7dOn73U n4shNRBBV0aRj4bcO7pUK17T7gJiV6r1XpciZL9nQWWz/NuCfqLK0XPRUu7Q039uXUM3 vJqtxwiujXPEYUte3cQ8g9SgF3oNsKouusOXcMxAJgBCDs94Ac5OMKnPtkeGB9S1FdZf NLkw== X-Gm-Message-State: AFuF++lHdw6hHO7ipaLrk/+XcAZCrMcMqZ+b/Hwq/aTLcjHUUqb6SOdg 56lvEMoHByisrwiFAdpq+D/dHRKtvOrZ0J4ZDgJIP4QN17PSoa4iTJvQz7543g== X-Gm-Gg: AYBFou0xwARpd0ewaC8y8Y2O0/M2lkBTMX+ZphWirbrvgNp12t9Gp1++Tyst/UUC+9q RgfXTy4CnoL8a7UB/awvy0/yTD7dNeHwZUoGL3KkqwczoBDJxU1Q2opn1zRpdd0GqJiwdDUJoY0 7rhN/eCE5gwKeOrsltsFuSFJ86FXUuWpm4QCQv+Y6FCR/oh8pjZJTlVkYA8j+dIQ7EqyhDKpWMG BAW5OMl7yGM62XbKQwLq9lFnFtJIBFfz/WANU1+GUmqiwzELqne+bQFrR4corYqyPJ0Oy91c+pV UPPxT/xifyTfYiTUlPX/98W9CXTi544WoVpuER6+LifVFNl2V4NxAOfUgwvp8CpkFE3PwxmMcs4 bke1DZPJK/5c9WhqzzKW+xbFLLP7mXYs/OXR9+XRwjetBdYNK/Pfd7y8C7GiM+PIai5gUI6NnDh ZF0iLkGi0LMA8YD0F1d6MY+h5a69YBjXtKidaeOS2UKk0G9o5B+9fHKLjOZPdIOnsqQd9bmiVpu jV1SyoPX/Tl/+PI0mRHOVhSxATlqfycAg== X-Received: by 2002:a05:6a20:3d08:b0:3dd:7a92:77bf with SMTP id adf61e73a8af0-3ddf79f1a9dmr2498090637.0.1790160086014; Wed, 23 Sep 2026 03:41:26 -0700 (PDT) Received: from NVAPF55DW0D-IPD.. ([203.211.104.195]) by smtp.gmail.com with ESMTPSA id d2e1a72fcca58-87d1d5c1646sm1035870b3a.30.2026.09.23.03.41.24 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 23 Sep 2026 03:41:25 -0700 (PDT) From: ankur.tyagi85@gmail.com To: openembedded-devel@lists.openembedded.org Cc: Ankur Tyagi Subject: [oe][meta-oe][wrynose][PATCH 13/42] freeipmi: patch CVE-2026-85504 Date: Wed, 23 Sep 2026 22:40:27 +1200 Message-ID: <20260923104056.457360-13-ankur.tyagi85@gmail.com> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260923104056.457360-1-ankur.tyagi85@gmail.com> References: <20260923104056.457360-1-ankur.tyagi85@gmail.com> MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Wed, 23 Sep 2026 10:41:35 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-devel/message/130200 From: Ankur Tyagi Backport commit from v1.6.19 matching NVD description. Details: https://nvd.nist.gov/vuln/detail/cve-2026-85504 Signed-off-by: Ankur Tyagi --- .../freeipmi/freeipmi/CVE-2026-85504.patch | 93 +++++++++++++++++++ .../freeipmi/freeipmi_1.6.17.bb | 1 + 2 files changed, 94 insertions(+) create mode 100644 meta-oe/recipes-support/freeipmi/freeipmi/CVE-2026-85504.patch diff --git a/meta-oe/recipes-support/freeipmi/freeipmi/CVE-2026-85504.patch b/meta-oe/recipes-support/freeipmi/freeipmi/CVE-2026-85504.patch new file mode 100644 index 0000000000..d0614beb17 --- /dev/null +++ b/meta-oe/recipes-support/freeipmi/freeipmi/CVE-2026-85504.patch @@ -0,0 +1,93 @@ +From 23bdae46ad532196ccd8a85d8a5c771e2aea1339 Mon Sep 17 00:00:00 2001 +From: Albert L Chu +Date: Tue, 25 Aug 2026 11:40:41 -0700 +Subject: [PATCH] libfreeipmi: bound Fujitsu SEL long-text responses + +Reject short and oversized Fujitsu iRMC responses and cap each text chunk before copying it into the fixed-size output buffer. + +Assisted-by: Codex, GPT-5.6-SOL +(cherry picked from commit 29fa34264e1eff685dcb9e0176e1eea0a6788e59) + +CVE: CVE-2026-85504 +Upstream-Status: Backport [https://cgit.git.savannah.gnu.org/cgit/freeipmi.git/commit/?h=freeipmi-1-6-19&id=29fa34264e1eff685dcb9e0176e1eea0a6788e590] + +Dropped changes to the ChangeLog file. + +Signed-off-by: Ankur Tyagi +--- + .../sel/ipmi-sel-string-fujitsu-irmc-common.c | 41 +++++++++++-------- + 1 file changed, 24 insertions(+), 17 deletions(-) + +diff --git a/libfreeipmi/sel/ipmi-sel-string-fujitsu-irmc-common.c b/libfreeipmi/sel/ipmi-sel-string-fujitsu-irmc-common.c +index f514a56c5..24aa94fb7 100644 +--- a/libfreeipmi/sel/ipmi-sel-string-fujitsu-irmc-common.c ++++ b/libfreeipmi/sel/ipmi-sel-string-fujitsu-irmc-common.c +@@ -80,10 +80,10 @@ _ipmi_sel_oem_fujitsu_get_sel_entry_long_text (ipmi_sel_ctx_t ctx, + uint8_t severity = 0; + char data_buf[IPMI_OEM_FUJITSU_SEL_ENTRY_LONG_TEXT_MAX_DATA_LENGTH + 1]; + char string_buf[IPMI_OEM_FUJITSU_SEL_ENTRY_LONG_TEXT_MAX_STRING_LENGTH + 1]; +- uint8_t data_length; ++ unsigned int data_length; + uint8_t max_read_length; +- uint8_t offset = 0; +- uint8_t component_length = 0; ++ unsigned int offset = 0; ++ size_t component_length = 0; + const char *css_str = NULL; + const char *severity_str = NULL; + int rv = -1; +@@ -208,8 +208,10 @@ _ipmi_sel_oem_fujitsu_get_sel_entry_long_text (ipmi_sel_ctx_t ctx, + "[Fujitsu OEM decoding requires administrator privilege]"); + goto out; + } +- goto cleanup; + } ++ ++ SEL_SET_ERRNUM (ctx, IPMI_SEL_ERR_IPMI_ERROR); ++ goto cleanup; + } + + /* Get severity and CSS flag only once */ +@@ -224,24 +226,29 @@ _ipmi_sel_oem_fujitsu_get_sel_entry_long_text (ipmi_sel_ctx_t ctx, + + data_length = bytes_rs[15]; + ++ if (data_length > IPMI_OEM_FUJITSU_SEL_ENTRY_LONG_TEXT_MAX_DATA_LENGTH ++ || offset > data_length) ++ { ++ SEL_SET_ERRNUM (ctx, IPMI_SEL_ERR_IPMI_ERROR); ++ goto cleanup; ++ } ++ + bytes_rs[rs_len-1] = '\0'; /* just to be sure it's terminated */ + component_length = strlen ((char *)bytes_rs + 16); + +- /* achu: truncate if there is overflow */ +- if (offset + component_length > data_length) +- { +- memcpy (data_buf + offset, +- &bytes_rs[16], +- IPMI_OEM_FUJITSU_SEL_ENTRY_LONG_TEXT_MAX_DATA_LENGTH - offset); +- offset = data_length; +- } +- else ++ if (component_length > (data_length - offset)) ++ component_length = data_length - offset; ++ ++ if (!component_length && offset < data_length) + { +- memcpy (data_buf + offset, +- &bytes_rs[16], +- component_length); +- offset += component_length; ++ SEL_SET_ERRNUM (ctx, IPMI_SEL_ERR_IPMI_ERROR); ++ goto cleanup; + } ++ ++ memcpy (data_buf + offset, ++ &bytes_rs[16], ++ component_length); ++ offset += component_length; + } + + if (css == IPMI_OEM_FUJITSU_CSS_COMPONENT) diff --git a/meta-oe/recipes-support/freeipmi/freeipmi_1.6.17.bb b/meta-oe/recipes-support/freeipmi/freeipmi_1.6.17.bb index a3a5fb5af0..aea282803a 100644 --- a/meta-oe/recipes-support/freeipmi/freeipmi_1.6.17.bb +++ b/meta-oe/recipes-support/freeipmi/freeipmi_1.6.17.bb @@ -21,6 +21,7 @@ SRC_URI = "${GNU_MIRROR}/freeipmi/freeipmi-${PV}.tar.gz \ file://CVE-2026-85507.patch \ file://CVE-2026-85506.patch \ file://CVE-2026-85505.patch \ + file://CVE-2026-85504.patch \ " SRC_URI[sha256sum] = "16783d10faa28847a795cce0bf86deeaa72b8fbe71d1f0dc1101d13a6b501ec1" From patchwork Wed Sep 23 10:40:28 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Ankur Tyagi X-Patchwork-Id: 99029 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 57C06C9830C for ; Wed, 23 Sep 2026 10:41:36 +0000 (UTC) Received: from mail-pz2-f12.google.com (mail-pz2-f12.google.com [74.125.228.12]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.4281.1790160088657878401 for ; Wed, 23 Sep 2026 03:41:28 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@gmail.com header.s=20251104 header.b=DULjNTnj; spf=pass (domain: gmail.com, ip: 74.125.228.12, mailfrom: ankur.tyagi85@gmail.com) Received: by mail-pz2-f12.google.com with SMTP id d2e1a72fcca58-85469b35611so371417b3a.0 for ; Wed, 23 Sep 2026 03:41:28 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1790160088; x=1790764888; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=wSPu3qUC03RBj/ZWXgO1GbDMJvMS1uirg2SZFJB/Q24=; b=DULjNTnjgpYj1bmC5ESVQox4JNowiqcybnjLBYLa3U3Vk3yRHUJznWCBiEx8aD4dlN Xz9WwDoWQyQ+iyyWG9yczVlRz5k4ZDkNsDDqOBPgM2JdlBwUyIipIZ3kCTtH797CRAjc yXW1IxO/BjudDvEp6OAJcz+Fg+PC1FaTGEsXpe6kADgIuFNexvY2wlHN2E+PsINBxZRd 6Vijwa25nZsQgYh5ZI++VHn5W6HUcseB+5Iq3qAG0OQNcXTVen6FCTnHWUp4ZZLVWuGh AVqFJ/MmtVOOS9noQHu5LUMUp1Y9FXUqVhUU+0/1Bf+wPzLpf+6nWc8POfOqNF2/1s/p tMVA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1790160088; x=1790764888; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=wSPu3qUC03RBj/ZWXgO1GbDMJvMS1uirg2SZFJB/Q24=; b=rXPMJke70VcJ9y3ozYv/S7RjyrdgCjppflbW1zvVegzy2im94c4QanQ07TTNe7Nsjz LI9P7tMbUbhwnEjWNcYoETjMMK1DDGxp7VZ2AT+WijNzAZKQ+FyvXWoPScm9CKETKQyj a9jS168DWDT8jHOQYZKRQNgHOV9bFrQR4XPuqa+bOXK1C4qH7q099poTobMbt45cxCKW y3YXI3acHGgcF2XOcglswbRrZJuoc/MghhNOGg8tfbvEuKXVqRYtgZGzd1oj5BASwF/N EIrQ0ddUlcQvLo2DUMmHbORnoHtW+D7vYmtM6rmq+wMBvw3+dqu+EA78enMWuUpNAo1q 9frQ== X-Gm-Message-State: AFuF++mtMmzD0G+1rJ8uZR1RCAM3820+cCcg/Wn0oS9+g4EzKCx6aYha CAUZBgIKdat7VYNZ0qhP6DECTrmgbYwkg1rX7uqt6hP4q76EuocsjmoLQRLmIg== X-Gm-Gg: AYBFou1a/EgcPHSihbmma9jaB1l2X6iM8ryWObRQp4P3CY1tNcciplP4eK/MAIGc4Ol oVS5riecweuh7TISY8S3NZOP3Be0wONMu3E00Z9xeQgrjSsPTZ8e5nC0GIxwj5cog52sQo8QWi/ xk95u5v/Xdcvht91NNIP+rwDlev/Ns8+a7/gA7QwzntJ6q/sO9MBiKJhRdlanmuGThyLNct29Mt xCCk8gu/J1FIL5/OZ6FCiQmda64TcV6wDxWzMHPfGd54av0tdNTlcCpY/FcDyNjf7pHDwDcEbCX KAZ3eSm4FPxq9WTMatj6C7p7p0MEli8M0t2T4BnobnlGDWWnWH5grt+u3Y9thd6HrbCvPu4LKd4 mYBKioPTEo1zIE9yfb6vveyvWX+8WEuYZePGV4TkrPZ8sCE3RE06msUSsrNrPgxhwN+fgjbaGvM MUXU3l040w2k/1u7ocjJ5i9Aufdl5GkNAXai+AF2A8t4KsOdqyZDpDON2tH92oP9dVrNu85MPa7 neypEtQzOLIN4angRPVrYE= X-Received: by 2002:a05:6a21:e109:b0:3dd:a008:dc3f with SMTP id adf61e73a8af0-3ddf81fb471mr2113883637.45.1790160087889; Wed, 23 Sep 2026 03:41:27 -0700 (PDT) Received: from NVAPF55DW0D-IPD.. ([203.211.104.195]) by smtp.gmail.com with ESMTPSA id d2e1a72fcca58-87d1d5c1646sm1035870b3a.30.2026.09.23.03.41.26 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 23 Sep 2026 03:41:27 -0700 (PDT) From: ankur.tyagi85@gmail.com To: openembedded-devel@lists.openembedded.org Cc: Ankur Tyagi Subject: [oe][meta-multimedia][wrynose][PATCH 14/42] libde265: patch CVE-2026-54240 and CVE-2026-54241 Date: Wed, 23 Sep 2026 22:40:28 +1200 Message-ID: <20260923104056.457360-14-ankur.tyagi85@gmail.com> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260923104056.457360-1-ankur.tyagi85@gmail.com> References: <20260923104056.457360-1-ankur.tyagi85@gmail.com> MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Wed, 23 Sep 2026 10:41:36 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-devel/message/130201 From: Ankur Tyagi Debian identified same commit as fix for both CVE[1][2] [1]https://security-tracker.debian.org/tracker/CVE-2026-54240 [2]https://security-tracker.debian.org/tracker/CVE-2026-54241 Details: https://nvd.nist.gov/vuln/detail/cve-2026-54240 https://nvd.nist.gov/vuln/detail/cve-2026-54241 Signed-off-by: Ankur Tyagi --- .../CVE-2026-54240-CVE-2026-54241.patch | 426 ++++++++++++++++++ .../libde265/libde265_1.0.19.bb | 1 + 2 files changed, 427 insertions(+) create mode 100644 meta-multimedia/recipes-multimedia/libde265/libde265/CVE-2026-54240-CVE-2026-54241.patch diff --git a/meta-multimedia/recipes-multimedia/libde265/libde265/CVE-2026-54240-CVE-2026-54241.patch b/meta-multimedia/recipes-multimedia/libde265/libde265/CVE-2026-54240-CVE-2026-54241.patch new file mode 100644 index 0000000000..cbeeb95884 --- /dev/null +++ b/meta-multimedia/recipes-multimedia/libde265/libde265/CVE-2026-54240-CVE-2026-54241.patch @@ -0,0 +1,426 @@ +From 14750b5cde9b6d5fe9086771482c05552bc8093b Mon Sep 17 00:00:00 2001 +From: Dirk Farin +Date: Wed, 3 Jun 2026 16:44:32 +0200 +Subject: [PATCH] fix pixel-accessor integer overflow on large frames + (GHSA-ccfw-29x7-rrx3) + +The de265_image::get_image_plane_at_pos*() accessors computed the pixel +offset `xpos + ypos*stride` in signed 32-bit int. For frames where +width*height exceeds INT32_MAX (e.g. 46344x46344, both within the existing +<=65535 limit), ypos*stride wraps negative and the returned pointer lands +~2 GB before the buffer -> heap out-of-bounds read/write. This is independent +of the earlier allocation fix (GHSA-vv8h-932h-7r86), which only widened the +buffer size, not the offset arithmetic. + +Widen the image stride to ptrdiff_t (members, get_image_stride/get_luma_stride/ +get_chroma_stride, set_image_plane) so all pixel-offset math is evaluated in +64 bits. The public C API (de265_get/set_image_plane) keeps int for ABI; the +narrowing at that boundary is safe (stride <= ~65552). + +The same 32-bit-stride / absolute-coordinate pattern existed in several scalar +paths that the accessors don't cover; widen those too: + - sao.cc: SAO offset indexing, and the inputCopy allocation+memcpy size + (an int size_t under-allocation -> heap write) + - motion.cc: mc_luma/mc_chroma reference-plane access (ref_stride, src_stride) + - intrapred.h: intra reference-border fill + - sei.cc: decoded-picture-hash MD5/CRC/checksum + - image-io.cc: YUV plane read and write +The deblock kernels, SIMD layer (acceleration.h) and per-block code already +use ptrdiff_t or only small block-local offsets and need no change. + +Also store pic_width/height_in_luma_samples as uint16_t (the value is +provably <= MAX_PICTURE_WIDTH = 65535 after validation) so PicSizeInSamplesY +needs only a single uint32_t cast instead of int*int (which was signed-overflow +UB on the same trigger); add static_asserts tying the limits to the storage. + +Verified: girlshy bit-exact single- and multi-threaded; ASan+UBSan PoC against +the get_image_plane_at_pos sink crashes pre-fix (UBSan signed-overflow at the +accessor + ASan wild write) and is clean post-fix. + +(cherry picked from commit bdca87569b9c63c2a7054d90ae4462dbb78d159a) + +CVE: CVE-2026-54240 CVE-2026-54241 +Upstream-Status: Backport [https://github.com/strukturag/libde265/commit/bdca87569b9c63c2a7054d90ae4462dbb78d159a] + +Signed-off-by: Ankur Tyagi +--- + libde265/de265.cc | 2 +- + libde265/image-io.cc | 4 ++-- + libde265/image.cc | 2 +- + libde265/image.h | 21 +++++++++++---------- + libde265/intrapred.h | 2 +- + libde265/motion.cc | 8 ++++---- + libde265/sao.cc | 18 +++++++++--------- + libde265/sei.cc | 18 ++++++++++-------- + libde265/sps.cc | 4 ++-- + libde265/sps.h | 11 +++++++++-- + 10 files changed, 50 insertions(+), 40 deletions(-) + +diff --git a/libde265/de265.cc b/libde265/de265.cc +index 48e38a01..02b2d5fd 100644 +--- a/libde265/de265.cc ++++ b/libde265/de265.cc +@@ -678,7 +678,7 @@ LIBDE265_API const uint8_t* de265_get_image_plane(const de265_image* img, int ch + + uint8_t* data = img->pixels_confwin[channel]; + +- if (stride) *stride = img->get_image_stride(channel) * ((de265_get_bits_per_pixel(img, channel)+7) / 8); ++ if (stride) *stride = static_cast(img->get_image_stride(channel) * ((de265_get_bits_per_pixel(img, channel)+7) / 8)); + + return data; + } +diff --git a/libde265/image-io.cc b/libde265/image-io.cc +index f15234b6..14ca95f0 100644 +--- a/libde265/image-io.cc ++++ b/libde265/image-io.cc +@@ -76,7 +76,7 @@ de265_image* ImageSource_YUV::read_next_image() + // --- load image --- + + uint8_t* p; +- int stride; ++ ptrdiff_t stride; + + p = img->get_image_plane(0); stride = img->get_image_stride(0); + for (uint32_t y=0;yget_width(); + int height= img->get_height(); +diff --git a/libde265/image.cc b/libde265/image.cc +index 94f3c974..59a19184 100644 +--- a/libde265/image.cc ++++ b/libde265/image.cc +@@ -184,7 +184,7 @@ de265_image_allocation de265_image::default_image_allocation = { + }; + + +-void de265_image::set_image_plane(int cIdx, uint8_t* mem, int stride, void *userdata) ++void de265_image::set_image_plane(int cIdx, uint8_t* mem, ptrdiff_t stride, void *userdata) + { + pixels[cIdx] = mem; + plane_user_data[cIdx] = userdata; +diff --git a/libde265/image.h b/libde265/image.h +index e0f1db24..114f41e4 100644 +--- a/libde265/image.h ++++ b/libde265/image.h +@@ -26,6 +26,7 @@ + #endif + + #include ++#include + #include + #include + #include +@@ -235,11 +236,11 @@ struct de265_image { + /* */ uint8_t* get_image_plane(int cIdx) { return pixels[cIdx]; } + const uint8_t* get_image_plane(int cIdx) const { return pixels[cIdx]; } + +- void set_image_plane(int cIdx, uint8_t* mem, int stride, void *userdata); ++ void set_image_plane(int cIdx, uint8_t* mem, ptrdiff_t stride, void *userdata); + + uint8_t* get_image_plane_at_pos(int cIdx, int xpos,int ypos) + { +- int stride = get_image_stride(cIdx); ++ ptrdiff_t stride = get_image_stride(cIdx); + return pixels[cIdx] + xpos + ypos*stride; + } + +@@ -248,38 +249,38 @@ struct de265_image { + template + pixel_t* get_image_plane_at_pos_NEW(int cIdx, int xpos,int ypos) + { +- int stride = get_image_stride(cIdx); ++ ptrdiff_t stride = get_image_stride(cIdx); + return (pixel_t*)(pixels[cIdx] + (xpos + ypos*stride)*sizeof(pixel_t)); + } + + const uint8_t* get_image_plane_at_pos(int cIdx, int xpos,int ypos) const + { +- int stride = get_image_stride(cIdx); ++ ptrdiff_t stride = get_image_stride(cIdx); + return pixels[cIdx] + xpos + ypos*stride; + } + + void* get_image_plane_at_pos_any_depth(int cIdx, int xpos,int ypos) + { +- int stride = get_image_stride(cIdx); ++ ptrdiff_t stride = get_image_stride(cIdx); + return pixels[cIdx] + ((xpos + ypos*stride) << bpp_shift[cIdx]); + } + + const void* get_image_plane_at_pos_any_depth(int cIdx, int xpos,int ypos) const + { +- int stride = get_image_stride(cIdx); ++ ptrdiff_t stride = get_image_stride(cIdx); + return pixels[cIdx] + ((xpos + ypos*stride) << bpp_shift[cIdx]); + } + + /* Number of pixels in one row (not number of bytes). + */ +- int get_image_stride(int cIdx) const ++ ptrdiff_t get_image_stride(int cIdx) const + { + if (cIdx==0) return stride; + else return chroma_stride; + } + +- int get_luma_stride() const { return stride; } +- int get_chroma_stride() const { return chroma_stride; } ++ ptrdiff_t get_luma_stride() const { return stride; } ++ ptrdiff_t get_chroma_stride() const { return chroma_stride; } + + int get_width (int cIdx=0) const { return cIdx==0 ? width : chroma_width; } + int get_height(int cIdx=0) const { return cIdx==0 ? height : chroma_height; } +@@ -333,7 +334,7 @@ private: + int width = 0, height = 0; // size in luma pixels + + int chroma_width = 0, chroma_height = 0; +- int stride = 0, chroma_stride = 0; ++ ptrdiff_t stride = 0, chroma_stride = 0; + + public: + uint8_t BitDepth_Y = 0, BitDepth_C = 0; +diff --git a/libde265/intrapred.h b/libde265/intrapred.h +index 9b17f75b..a256cb3a 100644 +--- a/libde265/intrapred.h ++++ b/libde265/intrapred.h +@@ -533,7 +533,7 @@ void intra_border_computer::fill_from_image() + assert(nT<=32); + + pixel_t* image; +- int stride; ++ ptrdiff_t stride; + image = (pixel_t*)img->get_image_plane(cIdx); + stride = img->get_image_stride(cIdx); + +diff --git a/libde265/motion.cc b/libde265/motion.cc +index c62c24c3..14e920e1 100644 +--- a/libde265/motion.cc ++++ b/libde265/motion.cc +@@ -50,7 +50,7 @@ void mc_luma(const base_context* ctx, + const seq_parameter_set* sps, int mv_x, int mv_y, + int xP,int yP, + int16_t* out, int out_stride, +- const pixel_t* ref, int ref_stride, ++ const pixel_t* ref, ptrdiff_t ref_stride, + int nPbW, int nPbH, int bitDepth_L) + { + int xFracL = mv_x & 3; +@@ -129,7 +129,7 @@ void mc_luma(const base_context* ctx, + pixel_t padbuf[(MAX_CU_SIZE+16)*(MAX_CU_SIZE+7)]; + + const pixel_t* src_ptr; +- int src_stride; ++ ptrdiff_t src_stride; + + if (-extra_left + xIntOffsL >= 0 && + -extra_top + yIntOffsL >= 0 && +@@ -181,7 +181,7 @@ void mc_chroma(const base_context* ctx, + int mv_x, int mv_y, + int xP,int yP, + int16_t* out, int out_stride, +- const pixel_t* ref, int ref_stride, ++ const pixel_t* ref, ptrdiff_t ref_stride, + int nPbWC, int nPbHC, int bit_depth_C) + { + // chroma sample interpolation process (8.5.3.2.2.2) +@@ -227,7 +227,7 @@ void mc_chroma(const base_context* ctx, + pixel_t padbuf[(MAX_CU_SIZE+16)*(MAX_CU_SIZE+3)]; + + const pixel_t* src_ptr; +- int src_stride; ++ ptrdiff_t src_stride; + + int extra_top = 1; + int extra_left = 1; +diff --git a/libde265/sao.cc b/libde265/sao.cc +index a0db84b2..579dcef2 100644 +--- a/libde265/sao.cc ++++ b/libde265/sao.cc +@@ -28,8 +28,8 @@ + template + void apply_sao_internal(de265_image* img, int xCtb,int yCtb, + const slice_segment_header* shdr, int cIdx, int nSW,int nSH, +- const pixel_t* in_img, int in_stride, +- /* */ pixel_t* out_img, int out_stride) ++ const pixel_t* in_img, ptrdiff_t in_stride, ++ /* */ pixel_t* out_img, ptrdiff_t out_stride) + { + const sao_info* saoinfo = img->get_sao_info(xCtb,yCtb); + +@@ -77,7 +77,7 @@ void apply_sao_internal(de265_image* img, int xCtb,int yCtb, + + if (SaoTypeIdx==2) { + int hPos[2], vPos[2]; +- int vPosStride[2]; // vPos[] multiplied by image stride ++ ptrdiff_t vPosStride[2]; // vPos[] multiplied by image stride + int SaoEoClass = (saoinfo->SaoEoClass >> (2*cIdx)) & 0x3; + + switch (SaoEoClass) { +@@ -266,8 +266,8 @@ void apply_sao_internal(de265_image* img, int xCtb,int yCtb, + template + void apply_sao(de265_image* img, int xCtb,int yCtb, + const slice_segment_header* shdr, int cIdx, int nSW,int nSH, +- const pixel_t* in_img, int in_stride, +- /* */ pixel_t* out_img, int out_stride) ++ const pixel_t* in_img, ptrdiff_t in_stride, ++ /* */ pixel_t* out_img, ptrdiff_t out_stride) + { + if (img->high_bit_depth(cIdx)) { + apply_sao_internal(img,xCtb,yCtb, shdr,cIdx,nSW,nSH, +@@ -332,8 +332,8 @@ void apply_sample_adaptive_offset_sequential(de265_image* img) + return; + } + +- int lumaImageSize = img->get_image_stride(0) * img->get_height(0) * img->get_bytes_per_pixel(0); +- int chromaImageSize = img->get_image_stride(1) * img->get_height(1) * img->get_bytes_per_pixel(1); ++ size_t lumaImageSize = static_cast(img->get_image_stride(0)) * img->get_height(0) * img->get_bytes_per_pixel(0); ++ size_t chromaImageSize = static_cast(img->get_image_stride(1)) * img->get_height(1) * img->get_bytes_per_pixel(1); + + uint8_t* inputCopy = new uint8_t[ libde265_max(lumaImageSize, chromaImageSize) ]; + if (inputCopy == nullptr) { +@@ -347,10 +347,10 @@ void apply_sample_adaptive_offset_sequential(de265_image* img) + + for (int cIdx=0;cIdxget_image_stride(cIdx); ++ ptrdiff_t stride = img->get_image_stride(cIdx); + int height = img->get_height(cIdx); + +- memcpy(inputCopy, img->get_image_plane(cIdx), stride * height * img->get_bytes_per_pixel(cIdx)); ++ memcpy(inputCopy, img->get_image_plane(cIdx), static_cast(stride) * height * img->get_bytes_per_pixel(cIdx)); + + for (int yCtb=0; yCtb(data); +- int stride16 = stride / 2; ++ ptrdiff_t stride16 = stride / 2; + for (int y=0; y> 8 ) ^ ( y >> 8 ); +@@ -224,7 +225,7 @@ static inline uint16_t crc_process_byte_parallel(uint16_t crc, uint8_t byte) + (t << 12)) & 0xFFFF; + } + +-static uint32_t compute_CRC_8bit_fast(const uint8_t* data,int w,int h,int stride, int bit_depth) ++static uint32_t compute_CRC_8bit_fast(const uint8_t* data,int w,int h,ptrdiff_t stride, int bit_depth) + { + raw_hash_data raw_data(w,stride); + +@@ -250,7 +251,7 @@ static uint32_t compute_CRC_8bit_fast(const uint8_t* data,int w,int h,int stride + } + + +-static void compute_MD5(uint8_t* data,int w,int h,int stride, uint8_t* result, int bit_depth) ++static void compute_MD5(uint8_t* data,int w,int h,ptrdiff_t stride, uint8_t* result, int bit_depth) + { + MD5_CTX md5; + MD5_Init(&md5); +@@ -289,7 +290,8 @@ static de265_error process_sei_decoded_picture_hash(const sei_message* sei, de26 + int nHashes = img->get_sps().chroma_format_idc==0 ? 1 : 3; + for (int i=0;iget_width(i); + h = img->get_height(i); +diff --git a/libde265/sps.cc b/libde265/sps.cc +index aa871a09..a29a3c0a 100644 +--- a/libde265/sps.cc ++++ b/libde265/sps.cc +@@ -570,7 +570,7 @@ de265_error seq_parameter_set::compute_derived_values(bool sanitize_values) + PicHeightInCtbsY = ceil_div(pic_height_in_luma_samples,CtbSizeY); + PicSizeInMinCbsY = PicWidthInMinCbsY * PicHeightInMinCbsY; + PicSizeInCtbsY = PicWidthInCtbsY * PicHeightInCtbsY; +- PicSizeInSamplesY = pic_width_in_luma_samples * pic_height_in_luma_samples; ++ PicSizeInSamplesY = static_cast(pic_width_in_luma_samples) * pic_height_in_luma_samples; + + if (chroma_format_idc==0 || separate_colour_plane_flag) { + CtbWidthC = 0; +@@ -1325,7 +1325,7 @@ de265_error seq_parameter_set::write(error_queue* errqueue, CABAC_encoder& out) + PicHeightInCtbsY = ceil_div(pic_height_in_luma_samples,CtbSizeY); + PicSizeInMinCbsY = PicWidthInMinCbsY * PicHeightInMinCbsY; + PicSizeInCtbsY = PicWidthInCtbsY * PicHeightInCtbsY; +- PicSizeInSamplesY = pic_width_in_luma_samples * pic_height_in_luma_samples; ++ PicSizeInSamplesY = static_cast(pic_width_in_luma_samples) * pic_height_in_luma_samples; + if (chroma_format_idc==0 || separate_colour_plane_flag) { + CtbWidthC = 0; + CtbHeightC = 0; +diff --git a/libde265/sps.h b/libde265/sps.h +index c8be9788..5cb0b46c 100644 +--- a/libde265/sps.h ++++ b/libde265/sps.h +@@ -39,6 +39,13 @@ constexpr int MAX_NUM_LT_REF_PICS_SPS = 32; + constexpr int MAX_PICTURE_WIDTH = 65535; + constexpr int MAX_PICTURE_HEIGHT = 65535; + ++// pic_width/height_in_luma_samples are stored as uint16_t and PicSizeInSamplesY as uint32_t, ++// so these limits must keep width/height in 16 bits and their product in 32 bits. ++static_assert(MAX_PICTURE_WIDTH <= 0xFFFF, "picture width must fit in uint16_t"); ++static_assert(MAX_PICTURE_HEIGHT <= 0xFFFF, "picture height must fit in uint16_t"); ++static_assert((uint64_t)MAX_PICTURE_WIDTH * MAX_PICTURE_HEIGHT <= 0xFFFFFFFFu, ++ "total luma sample count must fit in uint32_t"); ++ + enum { + CHROMA_MONO = 0, + CHROMA_420 = 1, +@@ -111,8 +118,8 @@ public: + uint8_t chroma_format_idc; // [0;3] + + bool separate_colour_plane_flag; +- int pic_width_in_luma_samples; +- int pic_height_in_luma_samples; ++ uint16_t pic_width_in_luma_samples; // <= MAX_PICTURE_WIDTH (validated on parse) ++ uint16_t pic_height_in_luma_samples; // <= MAX_PICTURE_HEIGHT (validated on parse) + bool conformance_window_flag; + + int conf_win_left_offset; diff --git a/meta-multimedia/recipes-multimedia/libde265/libde265_1.0.19.bb b/meta-multimedia/recipes-multimedia/libde265/libde265_1.0.19.bb index 07d108b915..d696b4b996 100644 --- a/meta-multimedia/recipes-multimedia/libde265/libde265_1.0.19.bb +++ b/meta-multimedia/recipes-multimedia/libde265/libde265_1.0.19.bb @@ -12,6 +12,7 @@ SRC_URI = "git://github.com/strukturag/libde265.git;branch=master;protocol=https file://CVE-2026-49295.patch \ file://CVE-2026-49337.patch \ file://CVE-2026-49346.patch \ + file://CVE-2026-54240-CVE-2026-54241.patch \ " SRCREV = "824b4138ecd51611d7073f1b50d5d6f982609b06" From patchwork Wed Sep 23 10:40:29 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Ankur Tyagi X-Patchwork-Id: 99027 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 72460C9830D for ; Wed, 23 Sep 2026 10:41:36 +0000 (UTC) Received: from mail-pz2-f41.google.com (mail-pz2-f41.google.com [74.125.228.41]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.4282.1790160090735276336 for ; Wed, 23 Sep 2026 03:41:30 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@gmail.com header.s=20251104 header.b=WAhb0asv; spf=pass (domain: gmail.com, ip: 74.125.228.41, mailfrom: ankur.tyagi85@gmail.com) Received: by mail-pz2-f41.google.com with SMTP id d2e1a72fcca58-85469f20513so446125b3a.0 for ; Wed, 23 Sep 2026 03:41:30 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1790160090; x=1790764890; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=YNtD4fpe/jm0FpYrQuG+XrYpmc5ErEi8i3qs3xQBZi8=; b=WAhb0asvD5uapzeBZlPLQtlKJWzHEcyR/j2SSob6XK0mGXEuh+cssU6y81fXRM39nW +nDfA6jqgqGdu1CbEZ81gprtaSqeCnlYTWQsIapJuEsOrpM/qWJg4SXoUCmsnpLy1I6s oE5rtFjpGplx9YVKicOH6SWVLs50lNRChBYe7IVFCpnSHKad16TeTFU9m/MRDf6+JexA OrylUf8whypK5zbRCJwWYwxcqEYKBEU5JVt8cpkSjIHhXstNoLW6UGJ87rpBS4Blc182 8QHMX6IyDIhkokr2heozNhYLgFCoZfWJbgxheChJfXDuWqUHtoH8AOcSFIax7+LnUgtZ ocsw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1790160090; x=1790764890; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=YNtD4fpe/jm0FpYrQuG+XrYpmc5ErEi8i3qs3xQBZi8=; b=r6i+CUlZGtlxwRn2aBIW+TzKmp0mf85u8tRSoZxqe1EpcmSXXFFl7k8eRwim6OvFt6 JKODnWdaDDwPQ6LiQ6IFMHriFAll+B9WTMaR5OatwfgO7NYCByzX7POgPBDYuJi6N3hv OHT/YsZgz4bInFLgXtQ3R2rFxfhWFHPvYmqabAdyv+wrUd/gqz0jpwB/e6n5LC4rprW9 Xg8Oz2yWgNl9/xZI1tfM79DZfewH9gf9eioAzv0MtUzoSG5lWB1dVb00RLWv/hpsj92q Fql+QkkOafry8FyQ1Jx38CMvz34VF4waPdFdRBozTZSbVABN4JgA0QeqpBW9ZUAhXsL7 aWAA== X-Gm-Message-State: AFuF++njJqsAAbVA6qYK9K+6AT++vCltAuriahaQ4tX8rZtGmrLJZ16H 6OsiSZ/NddiPbYaGSGUXystc+47yGX6y/aC5gFqL5fr68kPyzL4LjqJ0S39AZA== X-Gm-Gg: AYBFou3IBYh74Pp/vRHayJQcobLcwmGHpjzP4RDn/owDXMqGD3oaxsMGjUG/63/kdVG x0tM4cwP83conPPsrQe1EOZxREjQHPnOASMsX16b/FZU7/OJnIc9fuU5nBdtVI80ozWjpAHdku9 nrbU2eTuWbs+M2ZfeRwtR/2fTR/NU+VYWJivy6zx3mY+bJRT3es4iyrb0A/27P8k3TPWBFfhP9f iyYufA5Giy88W0cJ3tMB6jiOVng7tAcQtqP6ck+WlhJ8t24x2FOB1ltA6prLr7ANDkDY+gGItqz iB4M6y8oacfjphcOMfV8XadVybUs1pWYXTuhG1LHUW5QvYjgvfLFyBh1V2FXLA6Y5fmbIzTWZde +l3hHrS3nAxSG4eBX7AWpEUC/tMZE0zVdUe7EjeQPmv0AHL+//9cvVcn/jRAn/rnh6+V0/Qi5MO ppP0wZwQiTtGrME+wvIkKsA8fJypyXOv0vYC3GiFHG2mbqZuKwWzeFcDGBpc3gAq/UsTuXg1XfT FCkXpX6tKMlbEfNCgXWVhs= X-Received: by 2002:a05:6a00:174c:b0:878:34b8:2325 with SMTP id d2e1a72fcca58-87d1d1c3b0dmr2133930b3a.45.1790160090092; Wed, 23 Sep 2026 03:41:30 -0700 (PDT) Received: from NVAPF55DW0D-IPD.. ([203.211.104.195]) by smtp.gmail.com with ESMTPSA id d2e1a72fcca58-87d1d5c1646sm1035870b3a.30.2026.09.23.03.41.28 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 23 Sep 2026 03:41:29 -0700 (PDT) From: ankur.tyagi85@gmail.com To: openembedded-devel@lists.openembedded.org Cc: Ankur Tyagi Subject: [oe][meta-multimedia][wrynose][PATCH 15/42] libheif: ignore CVE-2026-84383 Date: Wed, 23 Sep 2026 22:40:29 +1200 Message-ID: <20260923104056.457360-15-ankur.tyagi85@gmail.com> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260923104056.457360-1-ankur.tyagi85@gmail.com> References: <20260923104056.457360-1-ankur.tyagi85@gmail.com> MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Wed, 23 Sep 2026 10:41:36 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-devel/message/130202 From: Ankur Tyagi Details: https://nvd.nist.gov/vuln/detail/cve-2026-84383 Signed-off-by: Ankur Tyagi --- meta-multimedia/recipes-multimedia/libheif/libheif_1.21.2.bb | 2 ++ 1 file changed, 2 insertions(+) diff --git a/meta-multimedia/recipes-multimedia/libheif/libheif_1.21.2.bb b/meta-multimedia/recipes-multimedia/libheif/libheif_1.21.2.bb index 165ed0ad2a..70176c7c52 100644 --- a/meta-multimedia/recipes-multimedia/libheif/libheif_1.21.2.bb +++ b/meta-multimedia/recipes-multimedia/libheif/libheif_1.21.2.bb @@ -34,3 +34,5 @@ PACKAGECONFIG[jpeg2000] = "-DWITH_OpenJPEG_ENCODER=ON -DWITH_OpenJPEG_DECODER=ON PACKAGECONFIG[openh264] = ",,openh264" FILES:${PN} += "${libdir}/libheif ${datadir}/thumbnailers ${libdir}/gdk-pixbuf*" + +CVE_STATUS[CVE-2026-84383] = "cpe-incorrect: This vulnerability was introduced in v1.22" From patchwork Wed Sep 23 10:40:30 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Ankur Tyagi X-Patchwork-Id: 99025 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id D8090C98309 for ; Wed, 23 Sep 2026 10:41:35 +0000 (UTC) Received: from mail-pz2-f41.google.com (mail-pz2-f41.google.com [74.125.228.41]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.4283.1790160092604044569 for ; Wed, 23 Sep 2026 03:41:32 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@gmail.com header.s=20251104 header.b=pVUBoHUV; spf=pass (domain: gmail.com, ip: 74.125.228.41, mailfrom: ankur.tyagi85@gmail.com) Received: by mail-pz2-f41.google.com with SMTP id d2e1a72fcca58-85469f204f6so410495b3a.2 for ; Wed, 23 Sep 2026 03:41:32 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1790160092; x=1790764892; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=+/xEvWCHM8LUQY9AKXFyTgZC0Xfn4h2Z3SX/LiCVg9o=; b=pVUBoHUVVy/+slvaVaRvQnwHog/91Sh+WgoOo8DJpLESSOCkk6QrtsW7ZNa+cmKkbh Hf+j/gV5bQH/eBufYCWuRC669K8XldP4FOyF0igzYyT2UhxftIYl9/jO+wAvvYWf8IXp wcCcWdEXOVz92hMVnUS+TGRp95Sc36ReQY5D8xDiOEvcsaMrua371vl5C6vE4ViWKrKa 4dZq0BRquQHT7/N7f9sZ/32KRJX6Joo3xq1FNvHhHv2/3xtr0tjv8xVkrsXrNfY93K/E TuEvLWK/8rkNMLQp6Dn3pTXopjT55nFUSaSkxG+vWkjrTmHs1GL399wsysyIxnn6QHx7 +vZg== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1790160092; x=1790764892; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=+/xEvWCHM8LUQY9AKXFyTgZC0Xfn4h2Z3SX/LiCVg9o=; b=uzOxRi6Xvs8hYQ0EcNacDUlDpn5SqjBr3H8QW/l7F4jwqDycHQZANa9ZSlUg+l7XYH Qd6szZiOJYCd3w23RSE/woRwaWXmia6Mtbf8qmKOyAspRJqTwEvxB30AMfN/UHSNmWID xrsy5+Ao+UDyTseoWgFRVFzBoEkCL87Ubq3gzbu0QLCHR6ut+WKsQYlhKuS+Zccydd7h iLLMBIwlZft1DvEKL2Tg8jTIpyHtiL5DR3VWlYgAnvDWJM1mGBdhq1lVBySd0TMRZPrk NMI7dYU+fI51TK9D/RG3tLsuqjGfk3G+o6Lsc2GNNwFI+VaGrqPfCxdis0i9fSigYoux pKHg== X-Gm-Message-State: AFuF++lOfRrxYeGFf+y5bFfA5rffoTZY0KZmqr7khln31XaTQWuWeubb NMzY8XrF6BDThN5PC9aELU/JJAMIXGllfUHff7Gyt7hGhw2aDuV146z9/rAfVw== X-Gm-Gg: AYBFou3jZwjRIfNfZL0IMjkkvlqR8mmfEs2GyxzY9t5CcIBaKSIMmoPoCjLgEk5WeWf 7uSFqw5GuP6eCD/o0C5RE+Gx0k3hbAy2nbrSECwR/Z2CG46DC3FgkSvYda81WDWgV6u//HBKxZB KFod+psK8m/zpJWqd29ECzfTG0wm5oA8FjP+NtSHJOc+3rT4XvGXix7lq5f6WwIWfrQq6cRLXNn 6M5zX17Fy4sxCn291sEYVuZUmEHGIgSQDj2cRDHWQW5EDd0w8LHrWvstKfwUWVucN1jzGP2Ou9e WWAttMovRTDi5H9Xq2Sr6x2zssE+2vFGD4nYHtmETdj4KN6fOpO2bWQbk1C1baZSeHF9/5Qq0Iv hkzZhu/B4tCeUOKA44FmrorROrK6KLMm/4m4Mz4Ohl9a3+uPLmUbcla4ccKBFhjO5QOQ6iOMfP+ ozKdU8SRif2gKp09oRSDpfNBge16u7h2YwSijf5wc4r1GGfxsXzYE6MScb+bLHJxannTzQZWa+/ SawwROTegveusKH5/ABXm3zrmk+jStHPg== X-Received: by 2002:a05:6a00:4304:b0:870:c2db:da53 with SMTP id d2e1a72fcca58-87d1b2b0a52mr1729534b3a.23.1790160091926; Wed, 23 Sep 2026 03:41:31 -0700 (PDT) Received: from NVAPF55DW0D-IPD.. ([203.211.104.195]) by smtp.gmail.com with ESMTPSA id d2e1a72fcca58-87d1d5c1646sm1035870b3a.30.2026.09.23.03.41.30 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 23 Sep 2026 03:41:31 -0700 (PDT) From: ankur.tyagi85@gmail.com To: openembedded-devel@lists.openembedded.org Cc: Ankur Tyagi Subject: [oe][meta-oe][wrynose][PATCH 16/42] libwebsockets: patch CVE-2026-19773 Date: Wed, 23 Sep 2026 22:40:30 +1200 Message-ID: <20260923104056.457360-16-ankur.tyagi85@gmail.com> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260923104056.457360-1-ankur.tyagi85@gmail.com> References: <20260923104056.457360-1-ankur.tyagi85@gmail.com> MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Wed, 23 Sep 2026 10:41:35 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-devel/message/130203 From: Ankur Tyagi Details: https://nvd.nist.gov/vuln/detail/cve-2026-19773 Signed-off-by: Ankur Tyagi --- .../libwebsockets/CVE-2026-19773.patch | 31 +++++++++++++++++++ .../libwebsockets/libwebsockets_4.5.8.bb | 1 + 2 files changed, 32 insertions(+) create mode 100644 meta-oe/recipes-connectivity/libwebsockets/libwebsockets/CVE-2026-19773.patch diff --git a/meta-oe/recipes-connectivity/libwebsockets/libwebsockets/CVE-2026-19773.patch b/meta-oe/recipes-connectivity/libwebsockets/libwebsockets/CVE-2026-19773.patch new file mode 100644 index 0000000000..74908c5437 --- /dev/null +++ b/meta-oe/recipes-connectivity/libwebsockets/libwebsockets/CVE-2026-19773.patch @@ -0,0 +1,31 @@ +From 998a9af40aa6c2ddcb91c662d6585ea80ab52f85 Mon Sep 17 00:00:00 2001 +From: Andy Green +Date: Fri, 3 Jul 2026 18:43:25 +0100 +Subject: [PATCH] zdi-can-31036: h2 bounds check on server + +This vulnerability was discovered by: +Maher Azzouzi working with TrendAI Zero Day Initiative + +(cherry picked from commit 824151862f37bc72f46d9a3e01d5b9408d313a0b) + +CVE: CVE-2026-19773 +Upstream-Status: Backport [https://github.com/warmcat/libwebsockets/commit/824151862f37bc72f46d9a3e01d5b9408d313a0b] +Signed-off-by: Ankur Tyagi +--- + lib/roles/h2/hpack.c | 3 +++ + 1 file changed, 3 insertions(+) + +diff --git a/lib/roles/h2/hpack.c b/lib/roles/h2/hpack.c +index 1025faa6f..863eb88c9 100644 +--- a/lib/roles/h2/hpack.c ++++ b/lib/roles/h2/hpack.c +@@ -274,6 +274,9 @@ static int lws_frag_append(struct lws *wsi, unsigned char c) + { + struct allocated_headers *ah = wsi->http.ah; + ++ if ((unsigned int)ah->pos >= wsi->a.context->max_http_header_data) ++ return 1; ++ + ah->data[ah->pos++] = (char)c; + ah->frags[ah->nfrag].len++; + diff --git a/meta-oe/recipes-connectivity/libwebsockets/libwebsockets_4.5.8.bb b/meta-oe/recipes-connectivity/libwebsockets/libwebsockets_4.5.8.bb index bca2663419..6a3d0b4033 100644 --- a/meta-oe/recipes-connectivity/libwebsockets/libwebsockets_4.5.8.bb +++ b/meta-oe/recipes-connectivity/libwebsockets/libwebsockets_4.5.8.bb @@ -10,6 +10,7 @@ SRCREV = "fbb0baf6af9c4324f0f1591734c78b0089b599d4" SRC_URI = " \ git://github.com/warmcat/libwebsockets.git;protocol=https;branch=v4.5-stable;tag=v${PV} \ file://CVE-2026-10650.patch \ + file://CVE-2026-19773.patch \ " UPSTREAM_CHECK_URI = "https://github.com/warmcat/${BPN}/releases" From patchwork Wed Sep 23 10:40:31 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Ankur Tyagi X-Patchwork-Id: 99026 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 38F15C9830B for ; Wed, 23 Sep 2026 10:41:36 +0000 (UTC) Received: from mail-pz2-f41.google.com (mail-pz2-f41.google.com [74.125.228.41]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.4169.1790160094886418627 for ; Wed, 23 Sep 2026 03:41:34 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@gmail.com header.s=20251104 header.b=disb3Am4; spf=pass (domain: gmail.com, ip: 74.125.228.41, mailfrom: ankur.tyagi85@gmail.com) Received: by mail-pz2-f41.google.com with SMTP id d2e1a72fcca58-8692a8568e9so378586b3a.3 for ; Wed, 23 Sep 2026 03:41:34 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1790160094; x=1790764894; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=Leet9VqSkoS/0wdHq4QzIAVMYrHTW2gM2qLhsfTjB4U=; b=disb3Am4/08UjUrolFDHkjFzR3SbxvzmBdZLcQwhsgVj6E0AKcWSr+UVivvlBM6509 4ZNu2DXl8gvj10e1lMalnP1z/a/vAPfffp0mBMYClPYBpG3gWZQLjTnxQGHQrPuGQ3iy lQoi/sC0D7Pp3ar5cMAh8OPSaQJgVoJHRVqo3v++w3E+zLpS2vxCq1VxOZ/mjjV7kmaQ QG4EhHhvkI7neW/idR/SXEZgvbmgggZ3sUByQWY6bVv8HiNfBkma1+Rz7vRKQInnO7UQ lbD+U8ngDifkw40/UgxG/iWD/Wfa3NCeSc/kkyLKFW38b79hxhhztHUORx7fYe2daCK/ 83Ow== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1790160094; x=1790764894; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=Leet9VqSkoS/0wdHq4QzIAVMYrHTW2gM2qLhsfTjB4U=; b=FoQ9Xmm/AxxxD1Dx1aU1z2CmmIA7FpjRfgHNbmXW8S3pTKZgvhEceJIFDy4oim7YwR RDBbNCOfHru6dg/XE86kMQ6GFrxLfEWKb+dRxzlUYOChbD3tmV30y/uvgqHsAcHqaRsR GFSp57PEJeQGiawu8NIfUcFpFqgxQcpLFRp6FYiKV1f1Q6ZgA/lQSMHHYWwRkN5NreDo gY1v+B6tkyYNXZ7ZF21FB7e8+Wyy5xI21E8Koq8KskDehXOL79krHMizX2Djg/j/H/Q2 hO0OQd7BxNtkTIGD58mhbQgbyYOnUqMia1GzZHqTX8/jQWSFtdXHmvXhwWT4kg4X4KO1 aPiA== X-Gm-Message-State: AFuF++kNFZc+LkkOV7+au74JCvghSkCz5Hz05Qivak1EjKhaUQDP7LQk 7DMy/1S06Qp+ogxtK24ynu+eIlPX3mvv7h94IPkQRbNvljL+fiNjcalXG5N6gg== X-Gm-Gg: AYBFou2uaQEA+J125hzXJsAcgP4xzc07zQJMKNmr6tIJ5Sdx3G9yC34m44+v62fWX7e AYt542raMmz8aDFa+7M1GHZ6PJs2TiFBafw6cKnyxtQd+8wwmZjeMDjtv4aQuKfxN9hFFzRB+Nn HI/zAXKs+gBKD4AVVPhJNp/w3tmw4+vpXUQsHn6Dvc8INNEEU9F9SwnyRFfyJ+0XrP8+1LFFKHL xoj8ezLesh8UQ42T4DhXYB3PUS7X8WjGGKEzo9cmUJf1xKjNudDhgofRn2xVBetM28UexxiUNpv l5RNu9r4+N3EMjBXap3tYC/Xxu9bXP05pqFk9+6keEUH7dBbrv5NpJEihSftmcWoR45sLWOo/X7 w21BjwMEpxa1Ee3xJnFGQu5TQjHVm30/yblcmW20Lr7mh6xBOnQsOhWeOgisSXyEclSmXjOAbIu t9WxkD8SSBf7iVUBlnyb6BdSePtBpRo4ae4KXy47RIQbDRGoqCUkEhDhDjj8NghqwoEzTNfKfZ/ 93OjAR7V9PxMhjJPt/LjNdaunJezBiDMg== X-Received: by 2002:a05:6a00:399f:b0:878:3538:8f7a with SMTP id d2e1a72fcca58-87d1baae9demr2051376b3a.40.1790160094255; Wed, 23 Sep 2026 03:41:34 -0700 (PDT) Received: from NVAPF55DW0D-IPD.. ([203.211.104.195]) by smtp.gmail.com with ESMTPSA id d2e1a72fcca58-87d1d5c1646sm1035870b3a.30.2026.09.23.03.41.32 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 23 Sep 2026 03:41:33 -0700 (PDT) From: ankur.tyagi85@gmail.com To: openembedded-devel@lists.openembedded.org Cc: Wang Mingyu , Khem Raj , Ankur Tyagi Subject: [oe][meta-oe][wrynose][PATCH 17/42] faad2: upgrade 2.11.2 -> 2.11.3 Date: Wed, 23 Sep 2026 22:40:31 +1200 Message-ID: <20260923104056.457360-17-ankur.tyagi85@gmail.com> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260923104056.457360-1-ankur.tyagi85@gmail.com> References: <20260923104056.457360-1-ankur.tyagi85@gmail.com> MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Wed, 23 Sep 2026 10:41:36 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-devel/message/130204 From: Wang Mingyu Signed-off-by: Wang Mingyu Signed-off-by: Khem Raj (cherry picked from commit c8d2af3641e1d694ee4eb6215a2f813b4390f1de) Changelog: https://github.com/knik0/faad2/blob/2.11.3/ChangeLog Signed-off-by: Ankur Tyagi --- .../faad2/{faad2_2.11.2.bb => faad2_2.11.3.bb} | 6 ++---- 1 file changed, 2 insertions(+), 4 deletions(-) rename meta-oe/recipes-multimedia/faad2/{faad2_2.11.2.bb => faad2_2.11.3.bb} (81%) diff --git a/meta-oe/recipes-multimedia/faad2/faad2_2.11.2.bb b/meta-oe/recipes-multimedia/faad2/faad2_2.11.3.bb similarity index 81% rename from meta-oe/recipes-multimedia/faad2/faad2_2.11.2.bb rename to meta-oe/recipes-multimedia/faad2/faad2_2.11.3.bb index 83fcaa248d..8dd09439f7 100644 --- a/meta-oe/recipes-multimedia/faad2/faad2_2.11.2.bb +++ b/meta-oe/recipes-multimedia/faad2/faad2_2.11.3.bb @@ -7,10 +7,8 @@ LIC_FILES_CHKSUM = "file://COPYING;md5=381c8cbe277a7bc1ee2ae6083a04c958" LICENSE_FLAGS = "commercial" -PV .= "+git" - -SRC_URI = "git://github.com/knik0/faad2.git;branch=master;protocol=https" -SRCREV = "673a22a3c7c33e96e2ff7aae7c4d2bc190dfbf92" +SRC_URI = "git://github.com/knik0/faad2.git;branch=master;protocol=https;tag=${PV}" +SRCREV = "6918ebb51b8f7e86278da15884bd7114e4b9661e" inherit cmake From patchwork Wed Sep 23 10:40:32 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Ankur Tyagi X-Patchwork-Id: 99031 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 67676C982FA for ; Wed, 23 Sep 2026 10:41:46 +0000 (UTC) Received: from mail-pz2-f12.google.com (mail-pz2-f12.google.com [74.125.228.12]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.4286.1790160097198239854 for ; Wed, 23 Sep 2026 03:41:37 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@gmail.com header.s=20251104 header.b=SxA9PUSw; spf=pass (domain: gmail.com, ip: 74.125.228.12, mailfrom: ankur.tyagi85@gmail.com) Received: by mail-pz2-f12.google.com with SMTP id d2e1a72fcca58-85469b2e1d5so435051b3a.1 for ; Wed, 23 Sep 2026 03:41:37 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1790160096; x=1790764896; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=h6enS8Gjl5jR2WaReTZRQu4+oEFV7IviOs11sy0WnPw=; b=SxA9PUSwG/bpTvI4JYPGS9K3XkQefMdTW65ABNvRaeY6P4+ei1kF1ZbWzbuA0FuukJ pYISD902a3LxWQNjjvtQIfhIr1nyI+ZgoFqX3iLLWv6eaCqhIKJVj7Zren6KyDgF5Mrx +imHaxGZYPGPJEXrKDiSO+YzfdyPOUWp8BYKyb/LYWAG2zRp/QG7kd+opDnMNDK62qux 5wyvmna6GM3Fnrg6HZ7+YPaA3/7BDmpP6G+T8QHFGcXflTl/4livuaEHZwQYA7+B+EA2 NxNqkSOQnaUwjrJpAkwPY5172kPHNmqWOkvmJ9RmQw8Cp5rCpqSJ37CVcv3DmmnGc80H pcng== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1790160096; x=1790764896; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=h6enS8Gjl5jR2WaReTZRQu4+oEFV7IviOs11sy0WnPw=; b=Lz4GkZIl28q2bW9n3gfTUuDXh9uxYEz4OGuKvPfBd8aBA6AKCA4PIWfJWXvXLsUWxq uw0pCOus0dklFgn+fg4S3irqwAYGzkDoj8p4GMWuJU2WbritmWKJTZs0aHrWWipvPW2M yd8ISdwrgeeScObEnLPDEkEN4gzFeTjqQ/RX33vmqcIMk4P39fS5l7QrCMJ61KkekgD/ t+M397qsE848Kz04exDfTQmHTZ+XbfrRk80dD/923bpPcAgeMIofxoBb52zDoEqw+Nei 2UT9aIINXS6HM8I6woDcRtQHA72+bOaSgEjkIksNZe113BfFhBgrO9KH+s7QEFmixuRk +nag== X-Gm-Message-State: AFuF++nTm1Vmo6hbjggu2DcPxbkfA9Ucve+1Fjjn8/gWBqLpxWsRTRY/ Dy2rqikIp7AXhkoZbp5fWY79xNVB3eN1+Ggqgg1TZbdMA4ye+ugpSCMOV2Gp4w== X-Gm-Gg: AYBFou0E6UzaARLr+3O1srObnXFBvFfjarLEcOjeiQkDqkwvV3NoRzNwu5GeUVvuost Df+7s6EBXcVRenaZS5YO5gCgerVs/DfO3VFCHlOOLMcF4vt4lPFv8TR3mtNlS5ZhbztV4V7Us0h qE0XLPNIKKF4rkkLh9GxlH4hsNiKMUdBOPFk/xGKm4sX/LhIQDYXMJXii+Y8uKrntB180zyLV99 jnnz2VWz8C4doG2AQeJoaQgHI7qK5ekLW7MLsrEdGQWjne0P8Px3Molb3hllT46Phc+MoKCGmmv n6HyJwNI/ae180UIrO4a8F+KelwjVUn8qN5XwdyEG2Bd3fdoym63btUP8AvsQLAq5DKajRymg29 VOZv0AVAjOwgPsoK46I/goYyszTRsh11BTC32GNCqJJP6fnKMImllgYfMoRZUxOJ7TUO/LCQt9t k7n4/pCqEiBmr5N/4kAS8+vgcD6KsiY9Tt2CyFcVmJZTXt61tYz+u2swO/qdjPltWU6YpkaH41k XZfR996fIjt5c1Iv9uIvCU= X-Received: by 2002:a05:6a00:7601:b0:87d:d1bc:334b with SMTP id d2e1a72fcca58-87dd1bc39efmr543207b3a.55.1790160096552; Wed, 23 Sep 2026 03:41:36 -0700 (PDT) Received: from NVAPF55DW0D-IPD.. ([203.211.104.195]) by smtp.gmail.com with ESMTPSA id d2e1a72fcca58-87d1d5c1646sm1035870b3a.30.2026.09.23.03.41.34 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 23 Sep 2026 03:41:36 -0700 (PDT) From: ankur.tyagi85@gmail.com To: openembedded-devel@lists.openembedded.org Cc: Wang Mingyu , Khem Raj , Ankur Tyagi Subject: [oe][meta-oe][wrynose][PATCH 18/42] libmxml: upgrade 4.0.4 -> 4.0.5 Date: Wed, 23 Sep 2026 22:40:32 +1200 Message-ID: <20260923104056.457360-18-ankur.tyagi85@gmail.com> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260923104056.457360-1-ankur.tyagi85@gmail.com> References: <20260923104056.457360-1-ankur.tyagi85@gmail.com> MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Wed, 23 Sep 2026 10:41:46 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-devel/message/130205 From: Wang Mingyu Signed-off-by: Wang Mingyu Signed-off-by: Khem Raj (cherry picked from commit 7e505c34533b265a6da539126f4b25b9c6843f40) Changelog: https://github.com/michaelrsweet/mxml/releases/tag/v4.0.5 Signed-off-by: Ankur Tyagi --- .../libmxml/{libmxml_4.0.4.bb => libmxml_4.0.5.bb} | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) rename meta-oe/recipes-support/libmxml/{libmxml_4.0.4.bb => libmxml_4.0.5.bb} (92%) diff --git a/meta-oe/recipes-support/libmxml/libmxml_4.0.4.bb b/meta-oe/recipes-support/libmxml/libmxml_4.0.5.bb similarity index 92% rename from meta-oe/recipes-support/libmxml/libmxml_4.0.4.bb rename to meta-oe/recipes-support/libmxml/libmxml_4.0.5.bb index d692774f08..01142f6f0d 100644 --- a/meta-oe/recipes-support/libmxml/libmxml_4.0.4.bb +++ b/meta-oe/recipes-support/libmxml/libmxml_4.0.5.bb @@ -4,8 +4,8 @@ LIC_FILES_CHKSUM = "file://LICENSE;md5=86d3f3a95c324c9479bd8986968f4327" HOMEPAGE = "https://www.msweet.org/mxml/" BUGTRACKER = "https://github.com/michaelrsweet/mxml/issues" -SRC_URI = "git://github.com/michaelrsweet/mxml.git;branch=master;protocol=https" -SRCREV = "0d5afc4278d7a336d554602b951c2979c3f8f296" +SRC_URI = "git://github.com/michaelrsweet/mxml.git;branch=master;protocol=https;tag=v${PV}" +SRCREV = "18d5c7dd9c71ebc1d3f21fe1e0614300babdda84" # Package does not support out of tree builds. inherit autotools-brokensep From patchwork Wed Sep 23 10:40:33 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Ankur Tyagi X-Patchwork-Id: 99034 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 9E3B5C982EA for ; Wed, 23 Sep 2026 10:41:46 +0000 (UTC) Received: from mail-pz2-f43.google.com (mail-pz2-f43.google.com [74.125.228.43]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.4172.1790160099902570181 for ; Wed, 23 Sep 2026 03:41:39 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@gmail.com header.s=20251104 header.b=pvBt1c4m; spf=pass (domain: gmail.com, ip: 74.125.228.43, mailfrom: ankur.tyagi85@gmail.com) Received: by mail-pz2-f43.google.com with SMTP id d2e1a72fcca58-8631d0023daso420374b3a.2 for ; Wed, 23 Sep 2026 03:41:39 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1790160099; x=1790764899; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=gzuVRgFbfErwU27QhoMx+gfRv0ELjGjCcBmOzW7EjEU=; b=pvBt1c4mDfEhm4AGE64Ne5/rygsc3od8T6Udo6LaIVGEL1E2obvIgfjWlR/DiKVnS5 cr6abVyzyYIKeU/HBwKbCXOO9oIJueYGdOhvpRq7CI8Oo4GWWH7LJjVhhzrTJWl9MsP+ ae4Qu2dW9BwK5tPZzjUlSb/we3F0djZzzm9yWuc/WjmCFvS67QGzH8j1o05hXr71eKUl 9+r3iQMG7dBCJBYDORZI8pdILLpkGQhhKqV+eVC8r5ILEsXfVvf0JJitpG214vKiofuV Gt6viUQoBXTmfFNGly7CSKuETeavWwQGja/c/ulCYktY17yUdYjk4Xw1BQWbGbRGxRuY kKUw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1790160099; x=1790764899; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=gzuVRgFbfErwU27QhoMx+gfRv0ELjGjCcBmOzW7EjEU=; b=uNzPhYy9F/DD4ACAeVU7QuDPdcVzKJXSZMgU9LgVNf8JE6vGiJ/KsVVC9HMdYEEN06 ceyI/v/ofkWD5eshFfRzpHCLjwkawt73mkoglF2pdDipZDpVbyWOfzU7j4XyIgBU5ReN lTOVSRzJ7tJl7u6k7X8k5vv38JUIp/EogEXWv5wC0buhktcGNjd9An/O+L9vO0HgWkix QUSUh9brIRpMCCBsrHDABmGUKlfQ9uYz4drsaZD/ZcWVCuVsTiipnOhF0Xx8wsuo7y7S RDk1+LXEN3c2HrHWR5y8WdwxJmNr4BxHW8zzzkBZ+Udq5MUc5CigeCqf63x0KgzbJH53 M++A== X-Gm-Message-State: AFuF++lxKhil2h2YipTALai+Z4CfNao3rl/XYU6jinedWE0SxpBUjX3x O81t+BEnUozq+nAcAHB8jbq/yLYd/xM0G2hVcwtWSPhuMamEf3zYCWq0A/Buuw== X-Gm-Gg: AYBFou1T8mAf3Rgsn8o0CvAVRte6sV56qvYU4CZUTJA0MVBmWjC7hyorDMU9bgxKrRV /aaNs7tzS9kKBBEqBYQWsG20Oxkd7HD0rxuguHDbE5KEmtYGlauUHymIvBXYgpuwkbjo5FZJdr0 3XLjaJIH/AmxU5//+2M8GlHgWNz2Bu1f5ph9fu5sN5LDj594T7D3TXp9to8tX1FeVEhMm4LAXBY KtBX+2DCXtvIch3u1m3GGCQCTFyoCv1OcklG5rNgNYDo0t2e8Urbe8VYir53gmogqqM00ZzrNP0 dsjU9/zbAEJPh4BadAp0juCHQKEq247roApsfvkXE+B9u3GNwIJirbZnr02ozYtxYpFuocn4k6Q BSShJTyRuVoq0lx2gRYBlEok5kSIaJd0tkT+QQnLSy4+XZm0flr/8hDQrEyRUsDbjzZft0DR1y3 7ZF/GsYH7DgJ6QZnYcHaES2/Of10XpuZFyp8+kcxcgvNtWCpMQjBt8xrRlj6YKyBMzgJb3BaFOW U3OEQpZ/xo04PTIU0c+lE8eyQF05q4HOQ== X-Received: by 2002:a05:6a00:2191:b0:86b:43f6:67c4 with SMTP id d2e1a72fcca58-87d1a7aecf9mr2057562b3a.1.1790160099246; Wed, 23 Sep 2026 03:41:39 -0700 (PDT) Received: from NVAPF55DW0D-IPD.. ([203.211.104.195]) by smtp.gmail.com with ESMTPSA id d2e1a72fcca58-87d1d5c1646sm1035870b3a.30.2026.09.23.03.41.36 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 23 Sep 2026 03:41:38 -0700 (PDT) From: ankur.tyagi85@gmail.com To: openembedded-devel@lists.openembedded.org Cc: Wang Mingyu , Khem Raj , Ankur Tyagi Subject: [oe][meta-networking][wrynose][PATCH 19/42] nanomsg: upgrade 1.2.2 -> 1.2.4 Date: Wed, 23 Sep 2026 22:40:33 +1200 Message-ID: <20260923104056.457360-19-ankur.tyagi85@gmail.com> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260923104056.457360-1-ankur.tyagi85@gmail.com> References: <20260923104056.457360-1-ankur.tyagi85@gmail.com> MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Wed, 23 Sep 2026 10:41:46 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-devel/message/130206 From: Wang Mingyu Signed-off-by: Wang Mingyu Signed-off-by: Khem Raj (cherry picked from commit c347929f84c0aa0f7994307acb88351d787a0496) Changelog: https://github.com/nanomsg/nanomsg/releases/tag/1.2.3 https://github.com/nanomsg/nanomsg/releases/tag/1.2.4 Signed-off-by: Ankur Tyagi --- .../nanomsg/{nanomsg_1.2.2.bb => nanomsg_1.2.4.bb} | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) rename meta-networking/recipes-connectivity/nanomsg/{nanomsg_1.2.2.bb => nanomsg_1.2.4.bb} (94%) diff --git a/meta-networking/recipes-connectivity/nanomsg/nanomsg_1.2.2.bb b/meta-networking/recipes-connectivity/nanomsg/nanomsg_1.2.4.bb similarity index 94% rename from meta-networking/recipes-connectivity/nanomsg/nanomsg_1.2.2.bb rename to meta-networking/recipes-connectivity/nanomsg/nanomsg_1.2.4.bb index f291326c80..95b81869b5 100644 --- a/meta-networking/recipes-connectivity/nanomsg/nanomsg_1.2.2.bb +++ b/meta-networking/recipes-connectivity/nanomsg/nanomsg_1.2.4.bb @@ -9,11 +9,11 @@ LIC_FILES_CHKSUM = "file://COPYING;md5=587b3fd7fd291e418ff4d2b8f3904755" SECTION = "libs/networking" -SRC_URI = "git://github.com/nanomsg/nanomsg.git;protocol=https;branch=master \ +SRC_URI = "git://github.com/nanomsg/nanomsg.git;protocol=https;branch=master;tag=${PV} \ file://run-ptest \ " -SRCREV = "ccd7f20c1b756f7041598383baffcdc326246db7" +SRCREV = "e6d0b8ddfc780eb89f8f6ef305e92c19e76bed6b" inherit cmake pkgconfig ptest From patchwork Wed Sep 23 10:40:34 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Ankur Tyagi X-Patchwork-Id: 99032 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id BE747C9830C for ; Wed, 23 Sep 2026 10:41:46 +0000 (UTC) Received: from mail-pz2-f12.google.com (mail-pz2-f12.google.com [74.125.228.12]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.4173.1790160102276610302 for ; Wed, 23 Sep 2026 03:41:42 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@gmail.com header.s=20251104 header.b=F9FxrZFK; spf=pass (domain: gmail.com, ip: 74.125.228.12, mailfrom: ankur.tyagi85@gmail.com) Received: by mail-pz2-f12.google.com with SMTP id d2e1a72fcca58-85469b2e1d5so435085b3a.1 for ; Wed, 23 Sep 2026 03:41:42 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1790160102; x=1790764902; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=hJUj2vV21/fjwzeOa5mXf3YH5LEV4qKJrM/0/46oLZE=; b=F9FxrZFKVixfEqJlqpO1OGrfV9RzJFIX0Q83+8IGvcPTutVMCu63HqVe8poynawRH+ 5l4g+POSjDf1IVH2T0Zu01jI+M0MBOzIrss9mNzsv+VY4m12OEE/Zda2xiGSQWY6Y/81 xBfoulny0qO+uO8jPZumfnUvBvIEohZO45OV2q52cpd/A/Hc+vezZ0WEldhuYtdSr2pJ IDftpGC9ZdQmJLPFkH7xlYEWiwsQvWKBVU5lb3IkdU+iV+1h4im82KpkKyn+SltTgGJQ 15OM+U+eAIkmVBsXdQLoDyJajdth0sa94s1yYJw9O91vpxAUrDc8fiSAnW0G+ojU83Gx +2TQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1790160102; x=1790764902; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=hJUj2vV21/fjwzeOa5mXf3YH5LEV4qKJrM/0/46oLZE=; b=K4vVweFkWwSz4AevwqWDNvR663H8aQKAAuYEbwVI6l6DTo5jquB8Y8dLRm8abiQUjZ EJRLxUKrA23WLAlulF47N/t69H2tAOsz5N4QhdmYC7nAIe/2DM1fVEm51oz44DAmB2KA 3eHPM2urji4w9aLoCgdiDHvD8PxHhRKWEJKGM8h3+26LsDgA3fG8uzVlwqqBxfbaHFgA neG9KlRU8HS8lKbtFur/Y4CEbcfGOUQG3ngRlKzxpZBEkkQVG85Y+U6AufiCt/+5jE/q ERBV1NSos2axk5CTqiLzPDIF0V6/tQiDmGq6+0CLUPa2mpE4wuuS3+ECYJXE4V+o3Nvl 0pyg== X-Gm-Message-State: AFuF++lg0K97xLiz7Bi10dIsxPsuvXVylN7q0OxJ7AtZXtUn0JDIoF1i To+LjjJUfFGAZU34QHnoAuXtlbJvFnPEYMKBx+I0B9ka0jW8e2dZ0N3FeVPUCA== X-Gm-Gg: AYBFou2XiCIXR5VbHsvQ38qm2VqFKYy3zIBIkpN+LWEpVxVFD+hDvSps1qVQbumsIWD FS9+8hW+89VjXr8jwDc50pcjHGErAncNnTrMAFMeLUzqkYH9btHc5kRasN3A+zAZfECVadYlTST 2CKU1Lat/Fo1p5REv9tqm3fMfgjQi+arFfeDSZtmSsDb5BwLbF5TFwlUPuXpUw7fXpKKLSiG7S+ 4IR3lYNIExpDkq0B+uw/yv2t40kYHoyo+r1jPEmxOdbvmwmr/muVLd0O8uFvIiVgOswNdzDgBB6 66sCEMXVqNtiYMK0JqNR2Zjy+CzQjoIKSIaJiNJ/a0eVh0aobcvIBEHrow9pSfnC/Q9eobbFkvn hD4dm2/Ei4EKiCWNMG/nCQ2Cj/Do7mKTUIDEAleK65O5+AdoBYjfzxUSOQct+QCwFw1VhlOfj9v mdPzaefjK5dj/T9G1TCKmgRomJHS3nZN19Nqx2dKEuV04hSal48HkO8427Q8ON9p/0wj/uhG5t3 JBtQrajsOIEfRrHJ6djxf8= X-Received: by 2002:a05:6a00:408a:b0:874:705d:f653 with SMTP id d2e1a72fcca58-87d1b3b33ecmr1808154b3a.33.1790160101609; Wed, 23 Sep 2026 03:41:41 -0700 (PDT) Received: from NVAPF55DW0D-IPD.. ([203.211.104.195]) by smtp.gmail.com with ESMTPSA id d2e1a72fcca58-87d1d5c1646sm1035870b3a.30.2026.09.23.03.41.39 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 23 Sep 2026 03:41:41 -0700 (PDT) From: ankur.tyagi85@gmail.com To: openembedded-devel@lists.openembedded.org Cc: Nate Kent , Khem Raj , Ankur Tyagi Subject: [oe][meta-networking][wrynose][PATCH 20/42] nanomsg: upgrade 1.2.4 -> 1.2.5 Date: Wed, 23 Sep 2026 22:40:34 +1200 Message-ID: <20260923104056.457360-20-ankur.tyagi85@gmail.com> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260923104056.457360-1-ankur.tyagi85@gmail.com> References: <20260923104056.457360-1-ankur.tyagi85@gmail.com> MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Wed, 23 Sep 2026 10:41:46 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-devel/message/130207 From: Nate Kent Minor security fix for people using IPC transport. Changelogs: * https://github.com/nanomsg/nanomsg/releases/tag/1.2.5 Signed-off-by: Nate Kent Signed-off-by: Khem Raj (cherry picked from commit 510601e79436e2120c0596dc6a53a0f503dde5b6) Signed-off-by: Ankur Tyagi --- .../nanomsg/{nanomsg_1.2.4.bb => nanomsg_1.2.5.bb} | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) rename meta-networking/recipes-connectivity/nanomsg/{nanomsg_1.2.4.bb => nanomsg_1.2.5.bb} (96%) diff --git a/meta-networking/recipes-connectivity/nanomsg/nanomsg_1.2.4.bb b/meta-networking/recipes-connectivity/nanomsg/nanomsg_1.2.5.bb similarity index 96% rename from meta-networking/recipes-connectivity/nanomsg/nanomsg_1.2.4.bb rename to meta-networking/recipes-connectivity/nanomsg/nanomsg_1.2.5.bb index 95b81869b5..cfd79487e9 100644 --- a/meta-networking/recipes-connectivity/nanomsg/nanomsg_1.2.4.bb +++ b/meta-networking/recipes-connectivity/nanomsg/nanomsg_1.2.5.bb @@ -13,7 +13,7 @@ SRC_URI = "git://github.com/nanomsg/nanomsg.git;protocol=https;branch=master;tag file://run-ptest \ " -SRCREV = "e6d0b8ddfc780eb89f8f6ef305e92c19e76bed6b" +SRCREV = "85856cb785ba6dd38c5e9757298a54d1bca55580" inherit cmake pkgconfig ptest From patchwork Wed Sep 23 10:40:35 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Ankur Tyagi X-Patchwork-Id: 99030 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 678F9C98309 for ; Wed, 23 Sep 2026 10:41:46 +0000 (UTC) Received: from mail-pz2-f12.google.com (mail-pz2-f12.google.com [74.125.228.12]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.4290.1790160104187289327 for ; Wed, 23 Sep 2026 03:41:44 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@gmail.com header.s=20251104 header.b=jqPGB+9B; spf=pass (domain: gmail.com, ip: 74.125.228.12, mailfrom: ankur.tyagi85@gmail.com) Received: by mail-pz2-f12.google.com with SMTP id d2e1a72fcca58-85469d249c4so585000b3a.2 for ; Wed, 23 Sep 2026 03:41:44 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1790160103; x=1790764903; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=1860Bo3u/KAWbijMeeUKDnuPGDUaoqOvM0dGu1vMVmU=; b=jqPGB+9BKcoUbqKTOmUQevJOqZhnDEc6sOcRPmOZO3cIfrbJrS/XYgpXa2uiMsD+7N TX2NOwSfnQoNdzw3caAdfWVrIeXWLvljtcIJ6TeYoQsO2fmdVAtzycZ0YS+uIqYhe5Ad bcYI+zBYxrMGtcm2TnNbEa2nDaRAFZpERqqjRZNV6L0hU5KGEBnzhQQ7h+32QjBy0bmk dNu7MPY8TaV/47f6PUDU3utSn87tpdWWkZ+Z5CvSYrdwvBmbSIRFZGyYYl+01VHa38bU ou1vGL0rG3aUMFXvSVWcwQwdAGQ075EigsBfYT3jRB0jgp7/4sqBZ+OhbnljcMwrZgAs 86VA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1790160103; x=1790764903; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=1860Bo3u/KAWbijMeeUKDnuPGDUaoqOvM0dGu1vMVmU=; b=AwWtwuZnkVyrbV3MPWcdTTmu/abH45nOI4d/XbxCVMk8wflKciwFk3b3hRxSBWiA2K xeaSsUlxlIIXBD41sC5NDULprgPhjWs52ZjOJM3D/X0pR1ivYDSYJITFI6bFZQW7/UMJ RXmkeyvNDfy7lLvZjg2oKzvrycMuVsiHW5u7W9cMa/rFrcWS0t9eTF8EvRS8DFCWi/Cp CeocxipbXTpaTFuOFdrg/aHT7roWg/qCE8VKWxxCrRRYVaVArWr7jTWquimg35AMPr5j nQVq6kqD0ChDYJyew32lrpC33n+LICu8p+R/KZhv9zSyuEiDnhdpRbz5evT+WfQws6Os DR6Q== X-Gm-Message-State: AFuF++lvZPFRt4Zg654BHl84AgcLTVVnrS4xC22CLZIZ3puAOyO+07XB v5VjsZ9wopGOlEkLnaB5oZU3vi/btRg+2HtFSrfHTmm8lq+dYydgs96s+v2fEw== X-Gm-Gg: AYBFou2qp0u6ElmRku2a3cepJLOwH9YJI8zZQWtJ8sPPsXkn9fM7PmDy8D562fBkKkR aso1qKvO5BKj+H3h1vXFuB3uHZKeCmhxv63wX+4Pv5KotwfKrSy5ZcsztT7dP1j6qwLFfeQHULS QbiskNgsi58rYw+cpNQYk0tag9FIgVPSRvQ/dgAUUABha/oH4sZXAokoIlcjPnTywWcSZT2FWVM 6Ir3NcB4ZeEpUgHtoTe0a31k3tvC4wVEkQ+g7CUzCIoHuZ7jiG0z0sF0IwT2xaNblpAgjc2epXJ exLSJjKbCptfyueX/czA/3EGyPsWnw12bzodlZuJ18HDOj8ZRJkqzNMZV/vgSF6T18m9sZBDdEP d9BxsVFK6qWr8PKrjVwsEmG8WQ/Kqvas2MPz42u7bi6kcJlkj5+B+ClVzH5MSF/vEDXF2p3Huzi FHGjrRLNTCtUUuGXAu012bO18TLJSmrYMbegdbg77i05cRmhRBeutraogM1mjm0YNQEYImnoFWc 4fc2y4l6lyTTGgCQhJhqZ0fAIpTmflIzH5Y X-Received: by 2002:a05:6a00:2d94:b0:878:34d7:6a26 with SMTP id d2e1a72fcca58-87d1c9c6e36mr1748939b3a.40.1790160103471; Wed, 23 Sep 2026 03:41:43 -0700 (PDT) Received: from NVAPF55DW0D-IPD.. ([203.211.104.195]) by smtp.gmail.com with ESMTPSA id d2e1a72fcca58-87d1d5c1646sm1035870b3a.30.2026.09.23.03.41.41 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 23 Sep 2026 03:41:43 -0700 (PDT) From: ankur.tyagi85@gmail.com To: openembedded-devel@lists.openembedded.org Cc: Ankur Tyagi Subject: [oe][meta-multimedia][wrynose][PATCH 21/42] libopenmpt: upgrade 0.8.4 -> 0.8.6 Date: Wed, 23 Sep 2026 22:40:35 +1200 Message-ID: <20260923104056.457360-21-ankur.tyagi85@gmail.com> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260923104056.457360-1-ankur.tyagi85@gmail.com> References: <20260923104056.457360-1-ankur.tyagi85@gmail.com> MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Wed, 23 Sep 2026 10:41:46 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-devel/message/130208 From: Ankur Tyagi License-Update: copyright year updated[1] Changelog: https://lib.openmpt.org/libopenmpt/2026/03/22/security-updates-0.8.5-0.7.18-0.6.27-0.5.41-0.4.53/ https://lib.openmpt.org/libopenmpt/2026/03/24/security-updates-0.8.6-0.7.19-0.6.28-0.5.42-0.4.54/ [1]https://github.com/OpenMPT/openmpt/commit/3d93be10ca24e4b953fe6adb960ccfb9e30f88fa Signed-off-by: Ankur Tyagi --- .../libopenmpt/{libopenmpt_0.8.4.bb => libopenmpt_0.8.6.bb} | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) rename meta-multimedia/recipes-multimedia/libopenmpt/{libopenmpt_0.8.4.bb => libopenmpt_0.8.6.bb} (95%) diff --git a/meta-multimedia/recipes-multimedia/libopenmpt/libopenmpt_0.8.4.bb b/meta-multimedia/recipes-multimedia/libopenmpt/libopenmpt_0.8.6.bb similarity index 95% rename from meta-multimedia/recipes-multimedia/libopenmpt/libopenmpt_0.8.4.bb rename to meta-multimedia/recipes-multimedia/libopenmpt/libopenmpt_0.8.6.bb index 37264423c4..bf563b8be1 100644 --- a/meta-multimedia/recipes-multimedia/libopenmpt/libopenmpt_0.8.4.bb +++ b/meta-multimedia/recipes-multimedia/libopenmpt/libopenmpt_0.8.6.bb @@ -7,14 +7,14 @@ HOMEPAGE = "https://lib.openmpt.org/libopenmpt/" SECTION = "libs" LICENSE = "BSD-3-Clause" -LIC_FILES_CHKSUM = "file://LICENSE;md5=979c86485a65d11403e9bf083b9a0812" +LIC_FILES_CHKSUM = "file://LICENSE;md5=f801f6aa19d904b2b8fa8383a34f771b" DEPENDS = "virtual/libiconv" SRC_URI = "https://lib.openmpt.org/files/libopenmpt/src/libopenmpt-${PV}+release.autotools.tar.gz \ file://run-ptest \ " -SRC_URI[sha256sum] = "627f9bf11aacae615a1f2c982c7e88cb21f11b2d6f0267946f7c82c5eae4943b" +SRC_URI[sha256sum] = "caa2fa959e389f4374d9e2df3af5c633452c12dd80442cba2e89cb7ff2b93c5b" S = "${UNPACKDIR}/libopenmpt-${PV}+release.autotools" From patchwork Wed Sep 23 10:40:36 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Ankur Tyagi X-Patchwork-Id: 99033 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id CDC2FC9830B for ; Wed, 23 Sep 2026 10:41:46 +0000 (UTC) Received: from mail-pz2-f41.google.com (mail-pz2-f41.google.com [74.125.228.41]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.4174.1790160106448138846 for ; Wed, 23 Sep 2026 03:41:46 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@gmail.com header.s=20251104 header.b=qpBHN39y; spf=pass (domain: gmail.com, ip: 74.125.228.41, mailfrom: ankur.tyagi85@gmail.com) Received: by mail-pz2-f41.google.com with SMTP id d2e1a72fcca58-8692a856865so353389b3a.2 for ; Wed, 23 Sep 2026 03:41:46 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1790160106; x=1790764906; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=/AvpKqoclm5C2c3KvBouB9VSCyiEaBHb93ovK3CGqFc=; b=qpBHN39ysy4npwhd5dq5iS0k1w8ZDCNUdpL03oc3rwFitPUrdbJknAbljOEdsOMcm7 OuVLxQso9s38zkXw9uu5JJ39nN61Y65TtSG9ybAtxRZCTCXqaf1XDwSCfZ8v6czaUmqN fyO23km/J/mvLLx6476ywUOexumag7TRQ7XL6W+dYH8jb2/aNdLeDvvqO1ep7zzxdmeG 0HJ9WTGf2bcy1HHVff5Qc/U42E4B8RgNlbhZEiJix4uUbP5sifcywEgkFmDKXU1yrPRL QLhVaU6hXr5MdbtVDRBIftW1eiy65lp2YeSGTL2g+O4Qdbktmxj807l/LctJrs5lJzUk lrYg== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1790160106; x=1790764906; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=/AvpKqoclm5C2c3KvBouB9VSCyiEaBHb93ovK3CGqFc=; b=J78S8k8ZxXEw1YyeE2u/Tb6Ko8gjC8IF/FqeYd6Uxq5ZCtsPCwwMo8M0staiutE92O mART1sW7sQCyc3kM+16s4zkZRYZji9Az2eWWzlMBk2gFF+Q9nD0K6cWR4QRivGgLusQx XKJyvIXo4ItmVhlHQ3pwqzjV+1STMpPfjLkcty9KykvvZHN9tpaw2gW5C21QFkdMT3le AO+RFA6Kl6yQRwwMthZ8pfcVAqyOW7AGsqitf0jhAzda5sLi8ZF27rw1vjy+t12jlbwA Pi/AgorlFhNt6Sjecx6UtCf/XSs5QAmb5srgMyafBmUE93b7mGJG+FkXJX9y+gljbDdy av3w== X-Gm-Message-State: AFuF++nnlhDfwbbEAOCFFL+JovyiXcZjQ21rDfAGsRmkGouiFAWJ5/yt qZc+aE3wmPO6Wy0KGvqjtK4hEY0IifXjPC/c1cDK/uff772kM9AOuU2p+q9dbg== X-Gm-Gg: AYBFou1D+BhgqxjhSsDpGOAEGmf/eGQJelhO7CRs8x75pCJlPGnMcme3U+ZXqQRA1kK NUpmHiBF8+gHN4XdfhUx3MMuPOugPF3Ttp8oh/bKrieVpSwcdxOzNJIQQZxsxyDQKLNafEGN2Z7 yVRbRbVA0GJTLQbPKKBtSjrpqxq5pjHFrir/UtJxuMku+J+MagTo6O+fafo9kx9hdOGwa14WcDX XPWgW7pNfDZYaX80YbnFHBgRq4v6Ly3a1aLojXGL405n8KXmaNnj/vYi/Q1D9Pm7A+kOOt8v6Py clzI1qBmjD67/9m0Ms61a60ziEU7U37L0qKpYZvwxY/8eF03w/J+eWQ89QjOo9jmvnxhgJ6Ripa 1YYXkVHtPzWbkjLxrqxwsERcf2E/VJEAl8PIF+qIg1cGo4coj2bTxLS8mAEAa5rar4R1NfuXN88 8vKTWhqosfF2ThUkVFwqWMsOi3GuRlPozOvlxJtgTPtOF8S6acxXBxVtZIMYESm0FvwxPXX1VQl so5jFOW689I7UzfDwEcNt8= X-Received: by 2002:a05:6a00:ad1:b0:872:dc9a:7f79 with SMTP id d2e1a72fcca58-87d18d6dcccmr2122012b3a.6.1790160105862; Wed, 23 Sep 2026 03:41:45 -0700 (PDT) Received: from NVAPF55DW0D-IPD.. ([203.211.104.195]) by smtp.gmail.com with ESMTPSA id d2e1a72fcca58-87d1d5c1646sm1035870b3a.30.2026.09.23.03.41.43 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 23 Sep 2026 03:41:45 -0700 (PDT) From: ankur.tyagi85@gmail.com To: openembedded-devel@lists.openembedded.org Cc: Leon Anavi , Khem Raj , Ankur Tyagi Subject: [oe][meta-python][wrynose][PATCH 22/42] python3-tzdata: Upgrade 2026.3 -> 2026.4 Date: Wed, 23 Sep 2026 22:40:36 +1200 Message-ID: <20260923104056.457360-22-ankur.tyagi85@gmail.com> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260923104056.457360-1-ankur.tyagi85@gmail.com> References: <20260923104056.457360-1-ankur.tyagi85@gmail.com> MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Wed, 23 Sep 2026 10:41:46 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-devel/message/130209 From: Leon Anavi Upgrade to release 2026.4: - Canada's Northwest Territories moved to permanent -06 on 2026-08-21. - Obsolescent settings like TZ="EST5EDT" now conform better to POSIX. - Fix security, performance and porting bugs in zic and localtime. This work was sponsored by GOVCERT.LU. Signed-off-by: Leon Anavi Signed-off-by: Khem Raj (cherry picked from commit 76eef1fd48d2a7ab321bb26a265bcf949b627a1a) Signed-off-by: Ankur Tyagi --- .../{python3-tzdata_2026.3.bb => python3-tzdata_2026.4.bb} | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) rename meta-python/recipes-devtools/python/{python3-tzdata_2026.3.bb => python3-tzdata_2026.4.bb} (86%) diff --git a/meta-python/recipes-devtools/python/python3-tzdata_2026.3.bb b/meta-python/recipes-devtools/python/python3-tzdata_2026.4.bb similarity index 86% rename from meta-python/recipes-devtools/python/python3-tzdata_2026.3.bb rename to meta-python/recipes-devtools/python/python3-tzdata_2026.4.bb index 3284b1bb51..91679e8bee 100644 --- a/meta-python/recipes-devtools/python/python3-tzdata_2026.3.bb +++ b/meta-python/recipes-devtools/python/python3-tzdata_2026.4.bb @@ -5,7 +5,7 @@ LIC_FILES_CHKSUM = "file://LICENSE;md5=804220b73c90950be376e7ff7b2066bb \ file://licenses/LICENSE_APACHE;md5=86d3f3a95c324c9479bd8986968f4327 \ " -SRC_URI[sha256sum] = "4a1518b8993086a7982523e071643f3c0e5f213e75b21318e78bcabfff9d1415" +SRC_URI[sha256sum] = "f1b8bd365d8d210c55353f4d7f8d6d8561c0ba50d704b700d195a9424bba0d79" inherit pypi python_setuptools_build_meta ptest-python-pytest From patchwork Wed Sep 23 10:40:37 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Ankur Tyagi X-Patchwork-Id: 99036 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id C6663C98309 for ; Wed, 23 Sep 2026 10:41:56 +0000 (UTC) Received: from mail-pz2-f12.google.com (mail-pz2-f12.google.com [74.125.228.12]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.4291.1790160108530871346 for ; Wed, 23 Sep 2026 03:41:48 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@gmail.com header.s=20251104 header.b=rD5sEpW9; spf=pass (domain: gmail.com, ip: 74.125.228.12, mailfrom: ankur.tyagi85@gmail.com) Received: by mail-pz2-f12.google.com with SMTP id d2e1a72fcca58-85469b35611so371527b3a.0 for ; Wed, 23 Sep 2026 03:41:48 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1790160108; x=1790764908; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=dlbAlYpjSI7sRfD6Xmw1JfSXiKSeISL5eTJpnfovEsY=; b=rD5sEpW9vHm7z3kE4+8THBed1/dn4QV0lIZc1Rvq9/vQhVJ4tfai11VDq8f47rlUq7 aDU25HXCtxk++4v7W6rHE9OiNLUOuIrsyEFveq8aUvAh8lbOz7A5+HXdX4Sk3odIYiCk qFcl+x/8eVVg/0G2ISAwzzeH2eAJQHUhov5S2bwpB/m9+Gk91tckIAcZ1ojwzguUY3Hz z82z/YyWJzx5GjjO04MpQU76Cqjxtisu+/uNRCGt6ai6jzs4pT0n4zL4pLGWVmc5QSvL bUpLPjw70Z/F6E+7IfYNZjS5ZL9Cjw4iel1nG7/M9CZWrF058yidzbH0ZifPoj8LQBdp Xhxg== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1790160108; x=1790764908; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=dlbAlYpjSI7sRfD6Xmw1JfSXiKSeISL5eTJpnfovEsY=; b=ObhgSVpShTHNqLRfPANGbXOKAKDFrxtqR0vjEFMNO9ytIdqeuh1h5R7bP/pH3sz9Gl GhFgIRZLT8zYDR6Y2EbUCr74MfniaO90c8RdCEu5anQmKiykyPvLajUyyzOXxHqZjksX g0WKtsZR7YvOSF08TZTZB8pPNgLDH8cqO+HTseUzFzkzloArOqX92B73z5d7H/KqZFXT CQsiec/RkQazyuJvT9W515+Hvvfl5OC/oz3eX+S6/5R2M5T0u6dWVk1QFHsj7x0Ru8Ep 7NLkyC9CxOw/FZB5QkUIJI6sPwLZWlC0nH25ac9qmwUNZFqSf/tsYMHk9vHLpdMKjgW6 2A5A== X-Gm-Message-State: AFuF++laa0v+xEnkfzvlpjuCgsNPTzlNsz4nzEqYyJl2lGVc5mNmZF+2 12j8PixN4x7X0hf/L+j6GF2ZiH096cC6ODgn9MdcIOzvaRfyTpp1mXfNyAlXqQ== X-Gm-Gg: AYBFou2e5/h23W06BKgFDIEmzqblYJ26ZqbHj05majegA0Z7H1klvkxZvzCLiGXn36a 0TQkfC+N/nCmtfw2rzlYd2Tghe18kkD0DJi317j9WDaPolzRT+TJymI+sJJebFhcXizwb+P157Y 4BUNtQGnHPYJ16iYYNrwS+yV4DshTI+TWO4c6mgZyQqNhDSNCFjo0JlH1NXwQR1wwoX/0pI9shI v5qUdDy02IF34rvZawJhw3fV5fHlUSvT5+4XSYDSPIvRz0tH/fXbNsfiIzAw9IDPd+w/KUU300S QbwLNInfNwvI6PJIcgywPwL5RtoJbM3ZxvAOf/tI7AVwMqS3X0vgw89zmZKjtiqMclxuUOzOzGi 68ZwkAHyDN0cqyVHcWMh2e0W7wMzrQjODL4v8ahQhNuP+UY/uEOVq26OI2sIMtVoJx90KUVyht2 IXeK3pP/qw6Ex2riSG5SMEqdNq88D0vqZG2paMsYithOsQzwr2XoSzle4x6PUPoeGOCV9eEF+C1 fL2YlvMn0d26c/CTHQmON1z3LoF8hhDNw== X-Received: by 2002:a05:6a00:3494:b0:871:85a7:7af6 with SMTP id d2e1a72fcca58-87d1b6a0a17mr2007777b3a.23.1790160107888; Wed, 23 Sep 2026 03:41:47 -0700 (PDT) Received: from NVAPF55DW0D-IPD.. ([203.211.104.195]) by smtp.gmail.com with ESMTPSA id d2e1a72fcca58-87d1d5c1646sm1035870b3a.30.2026.09.23.03.41.46 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 23 Sep 2026 03:41:47 -0700 (PDT) From: ankur.tyagi85@gmail.com To: openembedded-devel@lists.openembedded.org Cc: Ankur Tyagi Subject: [oe][meta-oe][wrynose][PATCH 23/42] smarty: mark CVEs patched Date: Wed, 23 Sep 2026 22:40:37 +1200 Message-ID: <20260923104056.457360-23-ankur.tyagi85@gmail.com> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260923104056.457360-1-ankur.tyagi85@gmail.com> References: <20260923104056.457360-1-ankur.tyagi85@gmail.com> MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Wed, 23 Sep 2026 10:41:56 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-devel/message/130210 From: Ankur Tyagi CVE-2024-35226[1], CVE-2026-62992[2], CVE-2026-62996[3] are patched in current version. Details: https://nvd.nist.gov/vuln/detail/cve-2024-35226 https://nvd.nist.gov/vuln/detail/cve-2026-62992 https://nvd.nist.gov/vuln/detail/cve-2026-62996 [1]https://github.com/smarty-php/smarty/commit/0be92bc8a6fb83e6e0d883946f7e7c09ba4e857a [2]https://github.com/smarty-php/smarty/commit/99c048ce7a590c519b79fbd38ad0143a08183a1f [3]https://github.com/smarty-php/smarty/commit/3c9f77a2e06ce319ae0092496af32cc8f3adc52e Signed-off-by: Ankur Tyagi --- meta-oe/recipes-support/smarty/smarty_5.8.4.bb | 4 ++++ 1 file changed, 4 insertions(+) diff --git a/meta-oe/recipes-support/smarty/smarty_5.8.4.bb b/meta-oe/recipes-support/smarty/smarty_5.8.4.bb index dcb7c85a80..0c1487f1df 100644 --- a/meta-oe/recipes-support/smarty/smarty_5.8.4.bb +++ b/meta-oe/recipes-support/smarty/smarty_5.8.4.bb @@ -35,3 +35,7 @@ FILES:${PN} += "${datadir}/php/smarty3/" RDEPENDS:${PN} = "php" CVE_PRODUCT = "smarty:smarty smarty-php:smarty" + +CVE_STATUS[CVE-2024-35226] = "fixed-version: fixed since v5.2.0" +CVE_STATUS[CVE-2026-62992] = "fixed-version: fixed since v5.8.2" +CVE_STATUS[CVE-2026-62996] = "fixed-version: fixed in v5.8.4" From patchwork Wed Sep 23 10:40:38 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Ankur Tyagi X-Patchwork-Id: 99038 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 3DC7DC9830B for ; Wed, 23 Sep 2026 10:41:57 +0000 (UTC) Received: from mail-pf1-f177.google.com (mail-pf1-f177.google.com [209.85.210.177]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.4292.1790160110330296138 for ; Wed, 23 Sep 2026 03:41:50 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@gmail.com header.s=20251104 header.b=p1EEqqNS; spf=pass (domain: gmail.com, ip: 209.85.210.177, mailfrom: ankur.tyagi85@gmail.com) Received: by mail-pf1-f177.google.com with SMTP id d2e1a72fcca58-86ec25cf7ecso1427272b3a.1 for ; Wed, 23 Sep 2026 03:41:50 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1790160110; x=1790764910; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=o3ZY2jy+57PoDgATXl/fwk2Wlwl4im4j0ZNO0xztVI0=; b=p1EEqqNSucSSVpPhZnplAK3WIZE1EptFze/pLCuKJp7wjzQWDcWIpqDzZDBFkjkOBm LNo8+bC+3rsM4wYZ2WQYjvlns8c1xVNA+mi1erSAmpRK6159BVbJOIe+s8n3jTHDwC/x HGDTa3f4AY49+GCurvpvq+rgPpt2y9bX5X6GbUjaPQr6521P9hXci+kUG6mHHNRqjTfY Ekor2YE/zhmGkgQU9E/DTH7LGGP3net15LxPdjKdpPrEDSJ79li16d1PXrk/iL5+5uRe 7CnI5vV+nLIKTQ/iOHg+IezhH+/gnaKFaTpOKhn0WDidHLkzckHdvijusfL/B2iOO49t LtRA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1790160110; x=1790764910; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=o3ZY2jy+57PoDgATXl/fwk2Wlwl4im4j0ZNO0xztVI0=; b=UYrsJTLl1ghYWPFdVRu98oMluyGk0/m39FABpMBMBYZC3SKzqcaL+9Va6s+MWDcHSo RprwZWdkWJXItHq9RnpOdbCueXpQ3WomhOH2yLvadfTEYnYoep5yrGuOaC14AW0eMts1 AZwU5JurmiYdfd5hd62AiNqygAdNFN8Bha/x5DM/bJHHXlbYY9nayroE3MwbWWnavtTu u2PC6L5Q2JOQrycAH9VrJWSaE8KpHN/ip+ASaS3ysai0CdeAE8YbQzXzAhMG5s8S/FhS 33c26uMLwN3GPb3ZApeZvRnLf+zwJRJNtuwvDRQGXRtK2i0ibkVelyjUCRaPkWxPLVxO Mn5g== X-Gm-Message-State: AFuF++lHsnDqaQ4GzwAni136TBenVr/8cTTmmKVeXDN3jBK0pJxmEKcc dNnfhbI81Fx3rULtsq4jE83xQsVKf33tnCMQ4cM9CBZPc9/TUgPjyzt+qwHHEQ== X-Gm-Gg: AYBFou29o0HS145gePVpQZCMJ2HImiRkH7b2se/IAdQA9cHtVRnjdhG2mzMq00k2X+q 1UHCLo4AHzI8IR8AhD7zZkUl2kpMwM8vP2Resi0AqjTYvXMB+84KnpGNr5jpukM/yTV0JZIG18T r02v43mzf08DTa67aCV22e8DrPzrBojkjAd1V25z05zwky9ujhhwvjSXHMJ3qRlqUQWYdWsFTZb Dzyinpxpo1x8yzXrIgeyLbUxht8J6kt4OJV2Lbs15/DHm4jWlKVIkBzIcqUJOJ+lBtrdGkDq14/ 8I/+C45i0b8WswIUlnEKHkQKql3MW95f6TEgaTcgW4AIxIx6Bz+anWbI5z7LqYcv14T87Kuxj+2 IId/sMwiACufccLurXmuuxIl2adVcBPyJdHnY96hDcD5p4BkpP4bfWnXdPnFgFfMp+4y+Nhj7EB D5yaWo44MMIi3dcr4StFvuYU34dkq04Y/lZvgAeveztJgV4UVj/NwgnepvFk7k2HldT7rbaIG4f NUIKRLpOqctE4y4VeUFw/4= X-Received: by 2002:a05:6a00:1a02:b0:871:a6f5:693a with SMTP id d2e1a72fcca58-87c8298f91cmr2310465b3a.11.1790160109681; Wed, 23 Sep 2026 03:41:49 -0700 (PDT) Received: from NVAPF55DW0D-IPD.. ([203.211.104.195]) by smtp.gmail.com with ESMTPSA id d2e1a72fcca58-87d1d5c1646sm1035870b3a.30.2026.09.23.03.41.48 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 23 Sep 2026 03:41:49 -0700 (PDT) From: ankur.tyagi85@gmail.com To: openembedded-devel@lists.openembedded.org Cc: Ankur Tyagi Subject: [oe][meta-oe][wrynose][PATCH 24/42] libssh: ignore CVE-2026-59842 Date: Wed, 23 Sep 2026 22:40:38 +1200 Message-ID: <20260923104056.457360-24-ankur.tyagi85@gmail.com> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260923104056.457360-1-ankur.tyagi85@gmail.com> References: <20260923104056.457360-1-ankur.tyagi85@gmail.com> MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Wed, 23 Sep 2026 10:41:57 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-devel/message/130211 From: Ankur Tyagi The vulnerability exists in GSSAPI key exchange introduced in v0.12.0[1] Also confirmed by libssh security advisory[2] Details: https://nvd.nist.gov/vuln/detail/cve-2026-59842 [1]https://gitlab.com/libssh/libssh-mirror/-/commit/88c2ea6752fab7b3da9cc4c51eaf632361a44080 [2]https://www.libssh.org/security/advisories/CVE-2026-59842.txt Signed-off-by: Ankur Tyagi --- meta-oe/recipes-support/libssh/libssh_0.11.5.bb | 1 + 1 file changed, 1 insertion(+) diff --git a/meta-oe/recipes-support/libssh/libssh_0.11.5.bb b/meta-oe/recipes-support/libssh/libssh_0.11.5.bb index 752bded528..49ffd29403 100644 --- a/meta-oe/recipes-support/libssh/libssh_0.11.5.bb +++ b/meta-oe/recipes-support/libssh/libssh_0.11.5.bb @@ -58,3 +58,4 @@ CVE_STATUS[CVE-2026-59847] = "fixed-version: fixed in v0.11.5" CVE_STATUS[CVE-2026-59848] = "fixed-version: fixed in v0.11.5" CVE_STATUS[CVE-2026-59849] = "fixed-version: fixed in v0.11.5" CVE_STATUS[CVE-2026-59850] = "fixed-version: fixed in v0.11.5" +CVE_STATUS[CVE-2026-59842] = "cpe-incorrect: the current version (0.11.5) is not affected" From patchwork Wed Sep 23 10:40:39 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Ankur Tyagi X-Patchwork-Id: 99037 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 4DB0EC9830C for ; Wed, 23 Sep 2026 10:41:57 +0000 (UTC) Received: from mail-pz2-f43.google.com (mail-pz2-f43.google.com [74.125.228.43]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.4293.1790160112749085340 for ; Wed, 23 Sep 2026 03:41:52 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@gmail.com header.s=20251104 header.b=g07ZJG8H; spf=pass (domain: gmail.com, ip: 74.125.228.43, mailfrom: ankur.tyagi85@gmail.com) Received: by mail-pz2-f43.google.com with SMTP id d2e1a72fcca58-8623e5d435cso247957b3a.1 for ; Wed, 23 Sep 2026 03:41:52 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1790160112; x=1790764912; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=22PIhhhtrrEAnJMy61c99rwBaZVQ24XfDHsj365IUU8=; b=g07ZJG8HbkYU6pXJC7giIOUyd7CP8AXF4ycGAwmw7w6b7caCKtJ1u1YNyC/omWXpYU JFV+vRTnIZCtnSsd2RFNytFgYC+ugMAioP7gbsMMFGbJ0D/5RwbNTD8OpJWvM39I9sLN R9auqG0EqjwyQKb78xJ0ddWpBV2lKnwTPb1w1599swITHQQM66vpV8zFSFT+rHC8tKxV euaBIZlmbWdwzj81mmm5KZdHZP18vWtp5iLmbvVOuTaaYBfz7OUwXdJMxYMxvbqouQpL MJSc6FwRRx4kIDiWied2wxQRi5eQlNHKWB1n3IE40mQDCumcXGxdAdoLZUBegkttTT4M QVGw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1790160112; x=1790764912; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=22PIhhhtrrEAnJMy61c99rwBaZVQ24XfDHsj365IUU8=; b=yP8vlUly0Ss6b+k0keDQp+aR+x5eY+8q+CE9pmy+cMjzw9UwVG6j1GlCSXr48iybYR 9NUN8T+oFln0haOqbEHo0ugKNTqLHNXCIcUzj5aRH8ea9DqWqlG4kB15F1JElgyM8e24 4e5EM6Fte/+PHKDOzEA7FdGpNNNvZqJPq2yCvOz242j5X5DAczMkcpHC2Ej51sAjOaUk BfO1CVxPdb3/RCPQsXZzEL6Cuuj7bpdrH1QauJz8ET8nWQRwLmd23K3jfIx7q6Zi/zpy zZT7CA5fHNQCkQ9+si+vG+c0f6GukoQ+708+Efub1ulpd0mHC3UUgKK0hA91ldTulJPd BIgg== X-Gm-Message-State: AFuF++nY1iLksnYZrsXZTSO+Xr6exvz6oHKG+3yYy6NAecveN1b8d9JH WLX7jIVQupSFeUBd2mFGM5WILJwphUdxuKP2SVjDPSIkMuGbDhfRCOKUW2sJQg== X-Gm-Gg: AYBFou2GXY6sRoSmEzF9uK0dTBWlFjy+v11VyeENue5Ay//6w9C5VUW4pjCrNQej23a H5XBDu4MUOWwvP5fQ1Io0NfVIxnNmySwKv4GNKj+TYQenA12W0gIOAF2MGftbbJYGjrG0t9h/8E y9n3osYPuxSjHlbvK6PWgbCx6URdGmdR0EcYB6Qfee06Cuu+JEOPZNDHTloDslerBn6H0qLa8tR ZMtdRve0Tq/GWKqCQXT4CUj5abjZok6dVyTGuzjGe3CdTW/C++yZoDSpgFmQfpXbNkUjNjjidT6 sQxVCU6tO2lKcLUBVAZ0D6u578zkiL9FXoKQvJFoYVbPleGMersyCKH2Zl2j8KNsTPFeue8q2w7 Dc7aT+vL81v+FL344wCxL8aA0bmmDVAMAPCNGsVHklJC8pr1l8eF3h1ZoPXsuk4sszOtAa/FVVN fN7D37bas8sNJI85YjijbEnD0nhIm/js8a8vE+TBoyDlJhxmHbzfJsm5icTsifsFZSO18ZTqM23 gqmClpvg411PaJB2rPPs17F5otwxZsDYA== X-Received: by 2002:a05:6a00:4c91:b0:878:3704:e0ec with SMTP id d2e1a72fcca58-87d24c6887dmr1402546b3a.18.1790160111976; Wed, 23 Sep 2026 03:41:51 -0700 (PDT) Received: from NVAPF55DW0D-IPD.. ([203.211.104.195]) by smtp.gmail.com with ESMTPSA id d2e1a72fcca58-87d1d5c1646sm1035870b3a.30.2026.09.23.03.41.50 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 23 Sep 2026 03:41:51 -0700 (PDT) From: ankur.tyagi85@gmail.com To: openembedded-devel@lists.openembedded.org Cc: Ankur Tyagi Subject: [oe][meta-networking][wrynose][PATCH 25/42] ntopng: ignore CVE-2026-84989 Date: Wed, 23 Sep 2026 22:40:39 +1200 Message-ID: <20260923104056.457360-25-ankur.tyagi85@gmail.com> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260923104056.457360-1-ankur.tyagi85@gmail.com> References: <20260923104056.457360-1-ankur.tyagi85@gmail.com> MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Wed, 23 Sep 2026 10:41:57 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-devel/message/130212 From: Ankur Tyagi Details: https://nvd.nist.gov/vuln/detail/cve-2026-84989 Signed-off-by: Ankur Tyagi --- meta-networking/recipes-support/ntopng/ntopng_6.6.bb | 2 ++ 1 file changed, 2 insertions(+) diff --git a/meta-networking/recipes-support/ntopng/ntopng_6.6.bb b/meta-networking/recipes-support/ntopng/ntopng_6.6.bb index 3c039781d8..57d2848ace 100644 --- a/meta-networking/recipes-support/ntopng/ntopng_6.6.bb +++ b/meta-networking/recipes-support/ntopng/ntopng_6.6.bb @@ -49,3 +49,5 @@ do_configure:prepend() { } SYSTEMD_SERVICE:${PN} = "ntopng.service" + +CVE_STATUS[CVE-2026-84989] = "cpe-incorrect: This vulnerability was introduced in v6.7" From patchwork Wed Sep 23 10:40:40 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Ankur Tyagi X-Patchwork-Id: 99035 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id C6628C982FA for ; Wed, 23 Sep 2026 10:41:56 +0000 (UTC) Received: from mail-pf1-f181.google.com (mail-pf1-f181.google.com [209.85.210.181]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.4175.1790160114582416909 for ; Wed, 23 Sep 2026 03:41:54 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@gmail.com header.s=20251104 header.b=J1kGf+yD; spf=pass (domain: gmail.com, ip: 209.85.210.181, mailfrom: ankur.tyagi85@gmail.com) Received: by mail-pf1-f181.google.com with SMTP id d2e1a72fcca58-853e2610bb4so985547b3a.0 for ; Wed, 23 Sep 2026 03:41:54 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1790160114; x=1790764914; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=LrVD3FYHMCNipLDCuqzOOamFAF7U3OC3+4rS77NFgYk=; b=J1kGf+yDI79IdS5g9gqNVM5qV5d6TosvhBCH5FCw7aPHmag0GYQy92lvSXqu+gUiGx Lzufx7KcSl287jhoeS8rpYqRvMcktFhULn68JcwBhYPfJTLS7YR6xJoSg4w5/mJPKtz2 vsmOFdK21FyVFQ8CqeYsaViQs/w+3Ukg/owfWKaoOBR2ubMT4S6+rXshrfratpZDU4fj mhdtaKW4TvNxC3qaKrWkDDhtQQHt/Xh9JhMOAtVCK9ZnaiVE/sTFgZLIsT3ej/pKSmbt ln/ezVDWVAlHgt2MXrwmgv/MTPBTtaiLiM0Ida1+DF0hRQOrgKvV0ocVVZ8TRfnNScoL RS5g== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1790160114; x=1790764914; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=LrVD3FYHMCNipLDCuqzOOamFAF7U3OC3+4rS77NFgYk=; b=Kb2FNBLCaTAU4+5c0R36C+Kt/bXdidqa7BCnYQG26xvUu0K6WmZgLsOByzydZAiYN1 bXytJsvH9ikeq0DedWnCKjp3a5CUBLz7oe3JA6HO2Md8If7WgrZ76/ppg/OSV8QpJpbA tWA8JxfHO0UnWkUrd4Kxm22pAZxuxw0VXaIX5GgvrCGeHI0fj1WsZui+tL7BLtQotqh4 r0C6nxcnioSOWM65gIOne8E65QW/V/l6cpEkQuKEEn4L5obvd4kDLavTpwxYwACnWi1T KawqSCLOOYMwtvMDFnr5Yw6vClidOMDUUTg+fMPFD031LkWjYA8LP0Li6CB+Q9Xmvhrs IDdg== X-Gm-Message-State: AFuF++lN/fe1ld/nTMr7RChaUWb7nfuvTzrF6t2/ZBHWTvCV15M3m3AL JExfNYwTsJzUaYmsa2Myf4KwvmDVf2d56X/sjQtdD7lNheR55oAY4/frCia0Pg== X-Gm-Gg: AYBFou3T0bNf6zemCGaIZVizd8QxqFKdaOhUMixdi5bRllx3zaBFh65+TFw5b4e6+zb +JZGQU97sa7gqLXJsUWvgtLuh/+SxD8KI34oL5hlzwxaQQjSQSb7Q+UPCqtUfBA+i4qNcSMS07d ia5wZftSDa384HRApBphkSWd0LThIacqxG3SPLEmbV86E0x3TIKBrHcKJB0TDaT/u3CBmhR4UP1 YZwHtX0+hmg5bElrrhPsxAOCAPMOrcLhjGO7xz4jxEZfksOKQR2yEC7UMFQv3q/CA2zkWmTl5Me /hkYJhn7maM22cFh2/LqYV8PAjM7nQPQiohKRj/elhIisslvr0mFblyPpPH1aeseJMdL+5yakCG Rwly3qBBdTVO/3coJ6o8PJiwaCgH2Fn4R1dtoTLPZMhkCpAZPsBG4/rs9Qpn83xOsewL/lV2KuE wKEFoctiAOrSxYwoLN3nVa8duYd8Tb25rjeJhHiTJPW8eBFN8qJoo3coiuJM9HFW7cD+Ns5VAq+ 2IR3TZnZ4AGo7cS4Az7qls= X-Received: by 2002:a05:6a00:14c4:b0:874:72b6:7daa with SMTP id d2e1a72fcca58-87c84e181c5mr2660366b3a.37.1790160113894; Wed, 23 Sep 2026 03:41:53 -0700 (PDT) Received: from NVAPF55DW0D-IPD.. ([203.211.104.195]) by smtp.gmail.com with ESMTPSA id d2e1a72fcca58-87d1d5c1646sm1035870b3a.30.2026.09.23.03.41.52 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 23 Sep 2026 03:41:53 -0700 (PDT) From: ankur.tyagi85@gmail.com To: openembedded-devel@lists.openembedded.org Cc: Ankur Tyagi Subject: [oe][meta-networking][wrynose][PATCH 26/42] ntopng: patch CVE-2026-84990 Date: Wed, 23 Sep 2026 22:40:40 +1200 Message-ID: <20260923104056.457360-26-ankur.tyagi85@gmail.com> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260923104056.457360-1-ankur.tyagi85@gmail.com> References: <20260923104056.457360-1-ankur.tyagi85@gmail.com> MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Wed, 23 Sep 2026 10:41:56 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-devel/message/130213 From: Ankur Tyagi Details: https://nvd.nist.gov/vuln/detail/cve-2026-84990 Signed-off-by: Ankur Tyagi --- .../ntopng/files/CVE-2026-84990.patch | 53 +++++++++++++++++++ .../recipes-support/ntopng/ntopng_6.6.bb | 1 + 2 files changed, 54 insertions(+) create mode 100644 meta-networking/recipes-support/ntopng/files/CVE-2026-84990.patch diff --git a/meta-networking/recipes-support/ntopng/files/CVE-2026-84990.patch b/meta-networking/recipes-support/ntopng/files/CVE-2026-84990.patch new file mode 100644 index 0000000000..0b443e3050 --- /dev/null +++ b/meta-networking/recipes-support/ntopng/files/CVE-2026-84990.patch @@ -0,0 +1,53 @@ +From 2f36e393fc35f576d7c447af337848e81990b084 Mon Sep 17 00:00:00 2001 +From: Alfredo Cardigliano +Date: Fri, 17 Jul 2026 11:51:03 +0200 +Subject: [PATCH] Add admin check in conf backup listing and download + +(cherry picked from commit f912ee93bc143330b6ff3bb946ee7211e5ee9e1a) + +CVE: CVE-2026-84990 +Upstream-Status: Backport [https://github.com/ntop/ntopng/commit/f912ee93bc143330b6ff3bb946ee7211e5ee9e1a] +Signed-off-by: Ankur Tyagi +--- + .../rest/v2/get/system/configurations/download_backup.lua | 5 +++++ + .../v2/get/system/configurations/list_available_backups.lua | 6 ++++++ + 2 files changed, 11 insertions(+) + +diff --git a/scripts/lua/rest/v2/get/system/configurations/download_backup.lua b/scripts/lua/rest/v2/get/system/configurations/download_backup.lua +index 1603a94c48..404b09ed97 100644 +--- a/scripts/lua/rest/v2/get/system/configurations/download_backup.lua ++++ b/scripts/lua/rest/v2/get/system/configurations/download_backup.lua +@@ -12,6 +12,11 @@ local backup_config = require("backup_config") + + -- ############################################## + ++if not isAdministratorOrPrintErr() then ++ rest_utils.answer(rest_utils.consts.err.not_granted) ++ return ++end ++ + local download = _GET["download"] + local epoch = _GET["epoch"] + +diff --git a/scripts/lua/rest/v2/get/system/configurations/list_available_backups.lua b/scripts/lua/rest/v2/get/system/configurations/list_available_backups.lua +index d901a876b0..8a08ad15d5 100644 +--- a/scripts/lua/rest/v2/get/system/configurations/list_available_backups.lua ++++ b/scripts/lua/rest/v2/get/system/configurations/list_available_backups.lua +@@ -8,11 +8,17 @@ package.path = dirs.installdir .. "/scripts/lua/modules/system_config/?.lua;" .. + + -- ############################################## + ++require "lua_utils" + local backup_config = require("backup_config") + local rest_utils = require("rest_utils") + + -- ############################################## + ++if not isAdministratorOrPrintErr() then ++ rest_utils.answer(rest_utils.consts.err.not_granted) ++ return ++end ++ + local rc = rest_utils.consts.success.ok + + local order = _GET["order"] or "desc" diff --git a/meta-networking/recipes-support/ntopng/ntopng_6.6.bb b/meta-networking/recipes-support/ntopng/ntopng_6.6.bb index 57d2848ace..11c4a2d3b6 100644 --- a/meta-networking/recipes-support/ntopng/ntopng_6.6.bb +++ b/meta-networking/recipes-support/ntopng/ntopng_6.6.bb @@ -18,6 +18,7 @@ SRC_URI = "gitsm://github.com/ntop/ntopng;protocol=https;branch=6.6-stable \ file://0001-configure.ac.in-Allow-dynamic-linking-against-ndpi-3.patch \ file://0001-luaengine-Use-lua-5.5-API-signature-for-lua_newstate.patch \ file://ntopng.service \ + file://CVE-2026-84990.patch \ " # don't use the lua under thirdparty as it supports cross compiling badly From patchwork Wed Sep 23 10:40:41 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Ankur Tyagi X-Patchwork-Id: 99039 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id E0681C982EA for ; Wed, 23 Sep 2026 10:41:56 +0000 (UTC) Received: from mail-pz2-f41.google.com (mail-pz2-f41.google.com [74.125.228.41]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.4295.1790160116397381312 for ; Wed, 23 Sep 2026 03:41:56 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@gmail.com header.s=20251104 header.b=emT23Ibf; spf=pass (domain: gmail.com, ip: 74.125.228.41, mailfrom: ankur.tyagi85@gmail.com) Received: by mail-pz2-f41.google.com with SMTP id d2e1a72fcca58-8674704dab1so756856b3a.2 for ; Wed, 23 Sep 2026 03:41:56 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1790160116; x=1790764916; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=TYu+ricJBAMwz3NudQS1clyMUIT8AKW95aEp4chE+Hg=; b=emT23IbftIlPq7UJnEw3UdDJeXAqK9xYMql/y4/LGnkJwl+Yn+vO+o453NZ2WMPh+U oS0S6Lh0gAGzb0KP7WfSP5ALEYppkeHk+VstOaizK07no2zMxmvmNbqlFOhCDpvI059/ ZYqqq/usTDZzgZ6wPeiLS87Op7SDoBd56Bd6yYk425wT818XKWiWp6NLUsHDEq00L0Pi GpnwxIyAtkTXp3Xj22dTpzCzVKXJd4Ui5RcO+Hbw5N2CpSjiqkz/YEai4Bzh9LE1bngA Wz7Jq0Se8e9THcx428itLPjZ2/Vr4NN/RmyGsMCwG7Z3PSMJ+KLp0a0CYeHbJQF9VvU0 af1A== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1790160116; x=1790764916; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=TYu+ricJBAMwz3NudQS1clyMUIT8AKW95aEp4chE+Hg=; b=nqF0NZOmxl2BS68dzzl3Jn2NuvmT624d2x50plIOoO/n1/6Sk1Asmb7p6XOXueJnde OC4oWvDOO/rEbR/IpFaLIlA4jPAeJ6zanX0GOPyfJMBf8FhjmTp+Bec+dJMhuiaOAoXl fDKzdq2Zus3PG5YuuNZd2VhJiFtzKBcLO2XIvJ3oCSGL2hdIVw+qbiRL4iHtc9WtaIlu XEaq3we6OlEkeJHGEUa75g0pqE/4MBQbiE9PDL++YR+TcQWhIia1K+90VXybaEgCbsyS uxxPWuWDcekWoMyNUehMWJkbZt9isyMpjE6tSUrE3re69RhvSyXauxjhuWdr8DKRZQzn DlsQ== X-Gm-Message-State: AFuF++kpctQ8qPsBKyXteGjefvQCqITydHQYTj0qZE+MykuqtVr1JMbK 79aEi4u+h7jVrgCi9gCzqhmMP0UWGNdJKpOj00Z+PicVpOstNssfKu8m+jP+qA== X-Gm-Gg: AYBFou19OvwifPi4duurDGXbnCX9kRqJGwq0GQEAv8/GU0OrsrTaSG0QhP1PWQpR6Dv mhYkdL8FNXNQ2KzV4dpeCkccdeRQZQWVDRQ94CCSNnvmKxRUGUtf4AYgmAl8MATq2/nOzNyUbzk eaF8S5drRLipFbl+LqctItDnumP2n3UFVWgTEIcuabHbvlWCiGuLtVjj4Iq4VLLM7FNHeJ1o0ne CyWOmPeqD1G4vjmoC24CcI48Kv18KyLmvpbFGFl8dy6ASl/ZU8+zgN2I9EArBYfJviAMF8Sse0q jvRTsl5bU8cjjWsUxBkbWWwWf/LUZXU1B6avDtlB77jmGGPATkwRNpEP3EpaKO/kWFV9YqkpIU0 lgDBEChn5XseDhxat+hLKiVp55NM/W7Rfrh6u7oY3FaD969VsHX879aUvRdrjrEwu9FZBpJeyFF XCWT35+ZVhrFM07IOhJFD8crX3pBjOVcr6DIm6jV5e8qGoj0ah5Nn8Ni6p4KaHCr95KOcNnF9Pr U0c8tCob2b/eQPFChUWqoE= X-Received: by 2002:a05:6a00:3316:b0:87b:b7ca:20be with SMTP id d2e1a72fcca58-87d1cccc3dfmr1896923b3a.37.1790160115807; Wed, 23 Sep 2026 03:41:55 -0700 (PDT) Received: from NVAPF55DW0D-IPD.. ([203.211.104.195]) by smtp.gmail.com with ESMTPSA id d2e1a72fcca58-87d1d5c1646sm1035870b3a.30.2026.09.23.03.41.54 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 23 Sep 2026 03:41:55 -0700 (PDT) From: ankur.tyagi85@gmail.com To: openembedded-devel@lists.openembedded.org Cc: Ankur Tyagi Subject: [oe][meta-networking][wrynose][PATCH 27/42] ntopng: patch CVE-2026-86090 and CVE-2026-86091 Date: Wed, 23 Sep 2026 22:40:41 +1200 Message-ID: <20260923104056.457360-27-ankur.tyagi85@gmail.com> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260923104056.457360-1-ankur.tyagi85@gmail.com> References: <20260923104056.457360-1-ankur.tyagi85@gmail.com> MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Wed, 23 Sep 2026 10:41:56 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-devel/message/130214 From: Ankur Tyagi Details: https://nvd.nist.gov/vuln/detail/cve-2026-86090 https://nvd.nist.gov/vuln/detail/cve-2026-86091 Signed-off-by: Ankur Tyagi --- .../files/CVE-2026-86090-CVE-2026-86091.patch | 67 +++++++++++++++++++ .../recipes-support/ntopng/ntopng_6.6.bb | 1 + 2 files changed, 68 insertions(+) create mode 100644 meta-networking/recipes-support/ntopng/files/CVE-2026-86090-CVE-2026-86091.patch diff --git a/meta-networking/recipes-support/ntopng/files/CVE-2026-86090-CVE-2026-86091.patch b/meta-networking/recipes-support/ntopng/files/CVE-2026-86090-CVE-2026-86091.patch new file mode 100644 index 0000000000..a8a3ba72ac --- /dev/null +++ b/meta-networking/recipes-support/ntopng/files/CVE-2026-86090-CVE-2026-86091.patch @@ -0,0 +1,67 @@ +From c6f4d42e1bb029463f927532819c5f5b331ea066 Mon Sep 17 00:00:00 2001 +From: Alfredo Cardigliano +Date: Thu, 16 Jul 2026 14:42:29 +0200 +Subject: [PATCH] Fix user capability check for deleting notification endpoints + and pools + +(cherry picked from commit 7d830f31af367745431c5d92e2e82fc432f6bdd8) + +CVE: CVE-2026-86090 CVE-2026-86091 +Upstream-Status: Backport [https://github.com/ntop/ntopng/commit/7d830f31af367745431c5d92e2e82fc432f6bdd8] +Signed-off-by: Ankur Tyagi +--- + scripts/lua/modules/pools/pools_rest_utils.lua | 5 +++++ + scripts/lua/rest/v2/delete/endpoints.lua | 6 ++++++ + scripts/lua/rest/v2/delete/recipients.lua | 6 ++++++ + 3 files changed, 17 insertions(+) + +diff --git a/scripts/lua/modules/pools/pools_rest_utils.lua b/scripts/lua/modules/pools/pools_rest_utils.lua +index 9b692ea5db..73f08e0c8d 100644 +--- a/scripts/lua/modules/pools/pools_rest_utils.lua ++++ b/scripts/lua/modules/pools/pools_rest_utils.lua +@@ -452,6 +452,11 @@ end + + -- @brief Get all pools of all the available (currently implemented) pool instances + function pools_rest_utils.delete_all_instances_pools() ++ if not auth.has_capability(auth.capabilities.pools) then ++ rest_utils.answer(rest_utils.consts.err.not_granted) ++ return ++ end ++ + local all_instances = pools_lua_utils.all_pool_instances_factory() + + for _, instance in pairs(all_instances) do +diff --git a/scripts/lua/rest/v2/delete/endpoints.lua b/scripts/lua/rest/v2/delete/endpoints.lua +index 31852cedab..6d25c01953 100644 +--- a/scripts/lua/rest/v2/delete/endpoints.lua ++++ b/scripts/lua/rest/v2/delete/endpoints.lua +@@ -10,6 +10,12 @@ package.path = dirs.installdir .. "/scripts/lua/modules/notifications/?.lua;" .. + local rest_utils = require "rest_utils" + local endpoints = require("endpoints") + local recipients = require "recipients" ++local auth = require "auth" ++ ++if not auth.has_capability(auth.capabilities.notifications) then ++ rest_utils.answer(rest_utils.consts.err.not_granted) ++ return ++end + + endpoints.reset_configs() + recipients.cleanup() +diff --git a/scripts/lua/rest/v2/delete/recipients.lua b/scripts/lua/rest/v2/delete/recipients.lua +index cbdffcae4c..14b3956498 100644 +--- a/scripts/lua/rest/v2/delete/recipients.lua ++++ b/scripts/lua/rest/v2/delete/recipients.lua +@@ -8,6 +8,12 @@ package.path = dirs.installdir .. "/scripts/lua/modules/notifications/?.lua;" .. + + local rest_utils = require "rest_utils" + local recipients = require "recipients" ++local auth = require "auth" ++ ++if not auth.has_capability(auth.capabilities.notifications) then ++ rest_utils.answer(rest_utils.consts.err.not_granted) ++ return ++end + + recipients.cleanup() + rest_utils.answer(rest_utils.consts.success.ok) diff --git a/meta-networking/recipes-support/ntopng/ntopng_6.6.bb b/meta-networking/recipes-support/ntopng/ntopng_6.6.bb index 11c4a2d3b6..c3bcb9844f 100644 --- a/meta-networking/recipes-support/ntopng/ntopng_6.6.bb +++ b/meta-networking/recipes-support/ntopng/ntopng_6.6.bb @@ -19,6 +19,7 @@ SRC_URI = "gitsm://github.com/ntop/ntopng;protocol=https;branch=6.6-stable \ file://0001-luaengine-Use-lua-5.5-API-signature-for-lua_newstate.patch \ file://ntopng.service \ file://CVE-2026-84990.patch \ + file://CVE-2026-86090-CVE-2026-86091.patch \ " # don't use the lua under thirdparty as it supports cross compiling badly From patchwork Wed Sep 23 10:40:42 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Ankur Tyagi X-Patchwork-Id: 99041 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 46852C982FA for ; Wed, 23 Sep 2026 10:42:07 +0000 (UTC) Received: from mail-pz2-f41.google.com (mail-pz2-f41.google.com [74.125.228.41]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.4176.1790160118979077571 for ; Wed, 23 Sep 2026 03:41:59 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@gmail.com header.s=20251104 header.b=UBHsfJXc; spf=pass (domain: gmail.com, ip: 74.125.228.41, mailfrom: ankur.tyagi85@gmail.com) Received: by mail-pz2-f41.google.com with SMTP id d2e1a72fcca58-85469f20513so446251b3a.0 for ; Wed, 23 Sep 2026 03:41:58 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1790160118; x=1790764918; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=TSMeNgG9DxaVhfWLsx1U9cv/Qx1zpuE5IVasfU0Nn6g=; b=UBHsfJXcavCl5w7h8olPPOexyNrAFL0SFyEJxZDkgAR5hwzA+8h2JscOaipfLCpF38 +bXAv/LYb8E88yI26iOvP9LFmZybQcbVA4KldsfLNfU8pw5kR0aTqBp1uw5KKUtzC8h9 2Hpx4w+Y7fNyd/0sPHgyN69fhI5IB4WSOT13BncL7k6V8OJa94LTKsxY6537mDEKSqCW PaxRbtAhFO98SOKA2YsCuK1lhFnFyfZlvZNrhslV5Zzf881WDlY+jqWVVJiWQdoD4iAQ 42Uvc6bnfjbGQ6fxeLwyVPGTZOjiMh3CGRNRrd4iYo6oBTX2w9zgpyOP1qMZurDCLf5Z fbNA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1790160118; x=1790764918; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=TSMeNgG9DxaVhfWLsx1U9cv/Qx1zpuE5IVasfU0Nn6g=; b=yw712Hnyxwg1l8venclmiNjGiAqRq/Xg060lF+ZWDQB3q3AbTbZn7p9+lzbaTlymPa uwsL4sL73KQzU2Nk7W5fk/T/2n7/RlnBYGvgC2wdADUaf2Bu+Jod8swPkMax6XJeOBxO SwDlun+kgziGpBNxAD9WznacH4IziavVJ6AcHsVIEh3i7EXh+Vh91MzF/6o+KqCqIbSR c/bzYD6a6mJ4H9ZJaGNYIsI1vNzV/jn8O+QtwIpLF7vk9OGKM9NNfUNo/TOTutDD47J8 6dEmE7WaC7AmTbaRPqUQZ3bAMBGaZUdHxrbkJroc0Zg73sebzYbX1lYevw6udIz+HbQ1 X0Ng== X-Gm-Message-State: AFuF++lvxpgbiIYZFUnmPzw6CDpTeIvX7+FQ0t/wHQgR0ohnVBgxVmri AIrzI/FAwQJLm5XmsvD+Znx0UF9AA0BuPzMsUM4IEXAo3PhJ56PKKJqDMZsnmg== X-Gm-Gg: AYBFou0n7/+UuEDDWYcMCkHC5md5Z/dvZbK9PS6bt3g1Xq1drR0kzZjjDe8ecyG6xUb 02uBRFOWJ23ed/d16FfEXJ/TkBnBfX3QuvUqYjeg4QYZANl17VHqSJ725ei1hGBWoedXolIVsp7 ImmO1q6ORFh2DRrYp0L8VuN2hHAiY5xyKXCg2pRfmyCYWQHauFHBda+CVGQE2tgHg9v/mEirb0b zPw9qbr8BvP1iZnNpwhGlU9aVVfqRhKWJKeZc/w9M5P7prCaJdSwY1lgOYFd0nTfLCpYlEtMok2 +hHdQh/YDQs+pb3rX8QDlEfkud9+Tl0up+pVC5vg3+91vGPFWf8CgR+73vJHTo+mbThHydPF8mA gql1P9G4AMgiPhKbGzsqoPXLr3Qn253eyMwAIJpk3pCaCP7dvlNF2D9yrN63gZjmI1h/vLOqtnL ig0TuLSp59jpXCt0gR0BwbCcPCKKPaNyGY8YNTR/YlNzwVIrtc3dnQTy0O2gl3QktSfae/+oFPP CEm/Ozlj0loKMwvIAZM/zo= X-Received: by 2002:a05:6a00:2e25:b0:87d:fa7:87c7 with SMTP id d2e1a72fcca58-87d1b6a9ebamr1916817b3a.25.1790160118368; Wed, 23 Sep 2026 03:41:58 -0700 (PDT) Received: from NVAPF55DW0D-IPD.. ([203.211.104.195]) by smtp.gmail.com with ESMTPSA id d2e1a72fcca58-87d1d5c1646sm1035870b3a.30.2026.09.23.03.41.56 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 23 Sep 2026 03:41:58 -0700 (PDT) From: ankur.tyagi85@gmail.com To: openembedded-devel@lists.openembedded.org Cc: Devansh Patel , Khem Raj , Ankur Tyagi Subject: [oe][meta-oe][wrynose][PATCH 28/42] ldns: correct CVE_PRODUCT mapping Date: Wed, 23 Sep 2026 22:40:42 +1200 Message-ID: <20260923104056.457360-28-ankur.tyagi85@gmail.com> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260923104056.457360-1-ankur.tyagi85@gmail.com> References: <20260923104056.457360-1-ankur.tyagi85@gmail.com> MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Wed, 23 Sep 2026 10:42:07 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-devel/message/130215 From: Devansh Patel The default product-only mapping generates a vendor-wildcard CPE. nlnetlabs:ldns is the active NVD dictionary CPE and configuration identity for the packaged NLnet Labs source. This changes the generated product identity to an exact CPE, but the frozen sbom-cve-check database leaves the eight-entry CVE report unchanged, with no current CVE delta. Signed-off-by: Devansh Patel Signed-off-by: Khem Raj (cherry picked from commit fe530d55ef61d61e8620c45c96c0abe009d595b2) Signed-off-by: Ankur Tyagi --- meta-oe/recipes-devtools/ldns/ldns_1.9.2.bb | 2 ++ 1 file changed, 2 insertions(+) diff --git a/meta-oe/recipes-devtools/ldns/ldns_1.9.2.bb b/meta-oe/recipes-devtools/ldns/ldns_1.9.2.bb index 8b3b9bd9de..6e50cc2b1e 100644 --- a/meta-oe/recipes-devtools/ldns/ldns_1.9.2.bb +++ b/meta-oe/recipes-devtools/ldns/ldns_1.9.2.bb @@ -6,6 +6,8 @@ LIC_FILES_CHKSUM = "file://LICENSE;md5=34330f15b2b4abbbaaa7623f79a6a019" SRC_URI = "https://www.nlnetlabs.nl/downloads/ldns/ldns-${PV}.tar.gz" SRC_URI[sha256sum] = "b524fa21994b6e834200ceb8c27f1b84bda5982fe35706f058196c079db94d5d" +CVE_PRODUCT = "nlnetlabs:ldns" + DEPENDS = "openssl" inherit autotools-brokensep From patchwork Wed Sep 23 10:40:43 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Ankur Tyagi X-Patchwork-Id: 99043 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 886EBC9830B for ; Wed, 23 Sep 2026 10:42:07 +0000 (UTC) Received: from mail-pz2-f41.google.com (mail-pz2-f41.google.com [74.125.228.41]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.4297.1790160121589532641 for ; Wed, 23 Sep 2026 03:42:01 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@gmail.com header.s=20251104 header.b=JDyRdU+7; spf=pass (domain: gmail.com, ip: 74.125.228.41, mailfrom: ankur.tyagi85@gmail.com) Received: by mail-pz2-f41.google.com with SMTP id d2e1a72fcca58-85469e211a0so468034b3a.1 for ; Wed, 23 Sep 2026 03:42:01 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1790160121; x=1790764921; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=71S0SZEDaeFRtx2Wmh7C01Ku70zlgIeEf+7xFqct504=; b=JDyRdU+7s16EG74uIjy4jucNfgGSBKy9LkdiRPcbb1JawbLoqa+cRojU8Cg9hzYH7H r0Uh6S4WUC391J+tDk5Hl1UK7A+G1PN3BGIEmLArZ3kkt/E3bY7S15CHihjIVCaEywFM cfGai8D97lzrTTn3foWikCqpchiSv6vXwj7xYl0dyZVHIwJ92+cA47wCuHWnKXlKAiKe ukco5GMERkZ+lMrGRa1/ikSool3bcxAEbgD+0Ir/XPltkmRO0YSIksCxS/jXWuYX/4c7 6GriwxGspLnuPnkYx0MQzAnd24kTFwdb5s6naowIQjMF27+0kifBLSrhcNdo9ASzbiAG iMRA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1790160121; x=1790764921; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=71S0SZEDaeFRtx2Wmh7C01Ku70zlgIeEf+7xFqct504=; b=Y1sXKTS8wnpMC/GR5pIRRPyvv+JnYmes0DSV740Qxi2qsnC/G2978GtEqtgIg1PDAa a75/9WxRbWDnK3TD01UUyu1Wk1290+s0PIZdzpUL3RwjrFKvgMC2DwU0/Ihr3PhCllbX Q6KXzmMrX+MrfVs9qOvB+aWLlf0h+GECiGSCXnqj9Wd+oXbRtOOQnDMJcqTafNiz6iI5 2nEjkK8I3xtpZWRmrE0jV7NimFkZGXdQzINj9RBeKAbZ5D0RgTmthkoAEQCfpRyy0Sqa 4QlRZ2NB6SAkpr/UAzfcTqbWB04YBqX6WdCEuyR2K+I9H2PmWzIMuP20tE+BOzrAhXxt JAtQ== X-Gm-Message-State: AFuF++najZ6JUI3fLNidYM0SjGTNpd9rxNoygZVx0q1m9ZtEgnAp2p5j BGHvVnv0p6JG5DdVldExkd8kmOjgT4XDxUwAhv8xUpKKTy64RLBqkB+F9y/b6w== X-Gm-Gg: AYBFou3ucDZIbPkqddtrti0cdlqofP4OxPQA2bTDepvNhvDHkzIlfNFbkdFuRHjFW8+ 2bcKA3ULiYg64NkUYp2GqE/JAHXSlosbNHrBFN86oKuKb1oKsfAR4ERy6H3SElsgvNZsqZkNu8t Q5abJRZUmB2+Gdn54PGx/QsQ944LmvvjSWm1RZZEFEBGnqEC15Z3mL7Cg9GgblGAh+js1N8ECer zQiI6l0x1INHrpEK6H5MPuSX5vM2XVKWQ2BU+x1eW+Y8hC8XBFN9Xh+TX7vv4SDXvmx23huiZ8R e5WTalOm/n796XtC/fBKnUjhlW1kDqsVEpqQVSILFBjlE/mHyPdU8jMhXfw0IkBTSialVJvhiHW xnnxppJuscjG95ldJYABHuvgc6lNu/Zffr7p5X3QLHKKZdeCMZog+3hqtelqXJJgKu0FG8VSKve 4oLRpkbDYj8RFMpEHwPL1VBjjsmgu/NOJRNki7lue3Y7Kmugh+B3rZODYw6mgIrZF8PYEakH+fF UAmlbmY87/fuYfqHZqza0s= X-Received: by 2002:a05:6a00:1f14:b0:878:3811:238 with SMTP id d2e1a72fcca58-87d1c1babf7mr2034335b3a.52.1790160120970; Wed, 23 Sep 2026 03:42:00 -0700 (PDT) Received: from NVAPF55DW0D-IPD.. ([203.211.104.195]) by smtp.gmail.com with ESMTPSA id d2e1a72fcca58-87d1d5c1646sm1035870b3a.30.2026.09.23.03.41.58 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 23 Sep 2026 03:42:00 -0700 (PDT) From: ankur.tyagi85@gmail.com To: openembedded-devel@lists.openembedded.org Cc: Devansh Patel , Khem Raj , Ankur Tyagi Subject: [oe][meta-networking][wrynose][PATCH 29/42] dnsmasq: correct CVE_PRODUCT mapping Date: Wed, 23 Sep 2026 22:40:43 +1200 Message-ID: <20260923104056.457360-29-ankur.tyagi85@gmail.com> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260923104056.457360-1-ankur.tyagi85@gmail.com> References: <20260923104056.457360-1-ankur.tyagi85@gmail.com> MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Wed, 23 Sep 2026 10:42:07 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-devel/message/130216 From: Devansh Patel The default product-only mapping generates vendor-wildcard CPEs for the recipe's Simon Kelley source. dnsmasq:dnsmasq is an NVD configuration identity and CNA affected-data identity; the_kelleys:dnsmasq is an NVD configuration identity; and thekelleys:dnsmasq is an active NVD dictionary CPE and configuration identity with CNA affected-data records. This changes the generated product identities. With the frozen sbom-cve-check database, the 48-entry CVE report is unchanged, so this is an identity correction with no CVE delta. Signed-off-by: Devansh Patel Signed-off-by: Khem Raj (cherry picked from commit 8dffafdd1dcf46ea5d544044a238364eed6d0535) Signed-off-by: Ankur Tyagi --- meta-networking/recipes-support/dnsmasq/dnsmasq_2.93.bb | 2 ++ 1 file changed, 2 insertions(+) diff --git a/meta-networking/recipes-support/dnsmasq/dnsmasq_2.93.bb b/meta-networking/recipes-support/dnsmasq/dnsmasq_2.93.bb index 765287018b..a01507de01 100644 --- a/meta-networking/recipes-support/dnsmasq/dnsmasq_2.93.bb +++ b/meta-networking/recipes-support/dnsmasq/dnsmasq_2.93.bb @@ -18,6 +18,8 @@ SRC_URI = "http://www.thekelleys.org.uk/dnsmasq/${@['archive/', ''][float(d.getV " SRC_URI[sha256sum] = "cc967771abdafeb43d10db18932d6b59fd4bed2c69c22acf8cb96aff6920d55f" +CVE_PRODUCT = "dnsmasq:dnsmasq the_kelleys:dnsmasq thekelleys:dnsmasq" + inherit pkgconfig update-rc.d systemd INITSCRIPT_NAME = "dnsmasq" From patchwork Wed Sep 23 10:40:44 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Ankur Tyagi X-Patchwork-Id: 99042 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id A6FD8C982EA for ; Wed, 23 Sep 2026 10:42:07 +0000 (UTC) Received: from mail-pz2-f43.google.com (mail-pz2-f43.google.com [74.125.228.43]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.4298.1790160124138223011 for ; Wed, 23 Sep 2026 03:42:04 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@gmail.com header.s=20251104 header.b=dRvquSnL; spf=pass (domain: gmail.com, ip: 74.125.228.43, mailfrom: ankur.tyagi85@gmail.com) Received: by mail-pz2-f43.google.com with SMTP id d2e1a72fcca58-85f0fc1fd8eso392199b3a.1 for ; Wed, 23 Sep 2026 03:42:04 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1790160123; x=1790764923; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=hzt3lpckQfouMtE3FT8Vfh3aKm1kjcWy6VoKBWzqgxQ=; b=dRvquSnLlCIh/wFHfRWxyekvGOScm4iE1SdMwtTfgWH73p2Z9kqI8LX3CKOQDfGfGb yBh01eJfVuGMhYkJWzrrR31rODKDsC68fFwSWjl5QVoM+7XUAY2Bnw1tqu4Qgga7b6/K UOR/MiX5M5fGkj8ixP0l/3w53t53QN9VDooDEV4puhhVibdT5RrAVwibDEvEP+JTPThD bce9KX2tL7sM5ZwZYF7oV/WNePbV6lbv8aAhHeOR2tAKrUZDNAzsghBLXbwqngzVGTeZ G/GIZbND61QVPdQfprlfRH8Q7w5Yr8ZxKE30FsHG+NPfHgb6mJkHFZM+mnWHi7ZrxvQw zL/g== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1790160123; x=1790764923; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=hzt3lpckQfouMtE3FT8Vfh3aKm1kjcWy6VoKBWzqgxQ=; b=V4AZDn2KGkaei6Q5DVVz/h6v7b6vqT/AL6wsk2Zs8RTbHhSIgLqusTLRAIwY5QrIBE JWimjtVRKpIzVPbtiW2SC5J3xXPIo+J/ZRAV5EVsuGa7ThuhirviNN0j4HPaYmLeWjKG 1WbyR+mbZe9D4P9uFd/5r8HP5OfFzH8C1icn7msaPu7PyvY0M2r0TEYkv4UQV6vJPUxz V7vwKodciFDwgfpPeVG5DP7B1EanofpJk9WuYFXUEp11JUh1DsEWzMWmTiYgNKRHQyMU hHSsJ93o3F2v+89HUuCIXAa8Cf+Wpe03LPB529WC2wbIWOa8PJ/EOwjihpJonr5LR6c5 Hluw== X-Gm-Message-State: AFuF++kHzhLer8lX5NJM2IEgDPTEU0bZm5AY9VBw6UDajon4W+wqdn+z lXZaRjq+lDzhE/2io18TQTWuuycWxCXl7p9hb6q7RagdYisXIJrt6z8z+bDEng== X-Gm-Gg: AYBFou27DqgLkVoqxkAT63DWZyVgQ0DfZjG37E3uHISi2WI8U4UEEkHRmonRAiJcF6K ibDvDtYisO3m6wXM+PXZmO2dI1on9O1eBXIfAXHpnUu+m/QV5VC0t4dOti614f1q20BwT1uykpT lS2BDCCgF26hOe3WjW1I3CLC7/2IkTnXWW+IuEGddeZyshLe5xBnFU12XAbK63m9jrEvT3riFFE C9rLkMsqLr6Q7hLjvFcuWfU6smUbI09jwJYUfU8maQ3c4J36n8t2LRTxKVQLwVw6IdWobo3QFT/ 6rRCDsnQpGF1VCPdjemX4NepoDftAV9rkJYZ3TNm12xFhuR9k1Mu724lvr44QfSCLJm4ONz1TVj 6g5ReDen69mJWNgmhaBtK+JCnpUN4xh5epxsVllh1GY9hAgUskZ6tIjewy9JXHK7+ffJRlnGyvC QcBJP+05kOZ7E6vtiB1pipKLBWDGot0PJdZ5Ub9XfEZ4F1nDpxZE0bBUq93tY+UY2QwyeEsSdTn jff+yJYCOYNNgaa3QAsrNX+fSQ7tFXu9A== X-Received: by 2002:a05:6a20:7fa9:b0:3dd:a197:7369 with SMTP id adf61e73a8af0-3ddf82eecbemr2237614637.66.1790160123517; Wed, 23 Sep 2026 03:42:03 -0700 (PDT) Received: from NVAPF55DW0D-IPD.. ([203.211.104.195]) by smtp.gmail.com with ESMTPSA id d2e1a72fcca58-87d1d5c1646sm1035870b3a.30.2026.09.23.03.42.01 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 23 Sep 2026 03:42:03 -0700 (PDT) From: ankur.tyagi85@gmail.com To: openembedded-devel@lists.openembedded.org Cc: Devansh Patel , Khem Raj , Ankur Tyagi Subject: [oe][meta-oe][wrynose][PATCH 30/42] jq: correct CVE_PRODUCT mapping Date: Wed, 23 Sep 2026 22:40:44 +1200 Message-ID: <20260923104056.457360-30-ankur.tyagi85@gmail.com> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260923104056.457360-1-ankur.tyagi85@gmail.com> References: <20260923104056.457360-1-ankur.tyagi85@gmail.com> MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Wed, 23 Sep 2026 10:42:07 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-devel/message/130217 From: Devansh Patel The default product-only mapping generates a vendor-wildcard CPE. Use jq_project:jq for the historical NVD dictionary CPE and configuration identity carrying two jq 1.5 CVEs, and jqlang:jq for the active NVD dictionary CPE and configuration identity plus CNA affected-data identity used by the current upstream. This changes the generated identities to two exact CPEs, but the frozen sbom-cve-check database leaves the 26-entry CVE report unchanged, with no current CVE delta. Signed-off-by: Devansh Patel Signed-off-by: Khem Raj (cherry picked from commit 5d23770adc80e996393fcf6ffec23cdae43cfa48) Signed-off-by: Ankur Tyagi --- meta-oe/recipes-devtools/jq/jq_1.8.1.bb | 2 ++ 1 file changed, 2 insertions(+) diff --git a/meta-oe/recipes-devtools/jq/jq_1.8.1.bb b/meta-oe/recipes-devtools/jq/jq_1.8.1.bb index 9d4ae74c00..af9704420c 100644 --- a/meta-oe/recipes-devtools/jq/jq_1.8.1.bb +++ b/meta-oe/recipes-devtools/jq/jq_1.8.1.bb @@ -32,6 +32,8 @@ SRC_URI = "git://github.com/jqlang/jq.git;protocol=https;branch=master;tag=jq-${ CVE_STATUS[CVE-2025-49014] = "fixed-version: fixed in v1.8.1" +CVE_PRODUCT = "jq_project:jq jqlang:jq" + inherit autotools ptest UPSTREAM_CHECK_GITTAGREGEX = "${BPN}-(?P\d+(\.\d+)+)" From patchwork Wed Sep 23 10:40:45 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Ankur Tyagi X-Patchwork-Id: 99040 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 468A3C98309 for ; Wed, 23 Sep 2026 10:42:07 +0000 (UTC) Received: from mail-pz2-f41.google.com (mail-pz2-f41.google.com [74.125.228.41]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.4180.1790160126683214645 for ; Wed, 23 Sep 2026 03:42:06 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@gmail.com header.s=20251104 header.b=dy6Jmm/w; spf=pass (domain: gmail.com, ip: 74.125.228.41, mailfrom: ankur.tyagi85@gmail.com) Received: by mail-pz2-f41.google.com with SMTP id d2e1a72fcca58-85469a3490bso682597b3a.3 for ; Wed, 23 Sep 2026 03:42:06 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1790160126; x=1790764926; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=lwHEKeljfrIBlrpa6d4rv58MTJU9l5fI1un5MJYrJkQ=; b=dy6Jmm/wwvSaq4jfErRXqduvS+DwYNteR1m58q1fjhCZNqSEngaBX7OebIF7riejGi rZpRxMJUoIpioQ2/NWTXCYdFvdQszrigZGeFHJOlXJxMqU3gGpM3K38ZP1RYsuJWUZz2 yA2+UAtvzNeep8KpVu4rMB68Z6L1QZFPNi5fVirUFcKJDJvJiYy733Usu6WFmsF7hB34 WcHKSjvuR2lQT0Qdu0uFAnMjfEUhDHIpzuAIudJ+D2Oc+GR0fD5A1M4mg0ieShKNljsA BekwWvUR4EG4m/mxFzSR8NlG+/lxn8v1+AO2LvvGgZ//HTrXkXm53PtABbF6XznV1/yr auqg== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1790160126; x=1790764926; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=lwHEKeljfrIBlrpa6d4rv58MTJU9l5fI1un5MJYrJkQ=; b=wPl5Hvyz4WmP1uT4aNT+cteXUY0681pZ0KwTYxeK10FsqwyIeHNStX5y7OrVf3zec2 6SUlZfoMzRLf5bZn20f+sELgOCHbFc4/J2cGAr+q6pDz0tMH3iL3tFHL/YwWQ82wTgBF /BNu12S42dFTDDvEXflOGltVjFCRfvevEBQo307EAEl/v5IqbI9hxpuDKruFP0icthNU V63B2wGkvD9w96aQDjA429y0dcigX8M27qIj56nB4OpIjbyDtxtyJbRN8tvirztA2IYE HV+ruTffvg2Ji5gkc4O3//7ipPK3F8+JFOR2CjwbVtcF7rDYB70EIKVYOvz4bJuMXdlK ICVQ== X-Gm-Message-State: AFuF++k01Zhdfj/Z/DORq0dVz1LXNDsoawZDxd6jvzKvg1UmsBCQP6uR 7bv4EGtmK4eESCgon5LX4cP5SY/ixO+5GOhz+5sM3HVDEEbKgUpm1Kb+eKBfTQ== X-Gm-Gg: AYBFou3Jo1mcQV1+leLUjZ/RT23ZmcVxYiNFBR43RwaV0XZ2m4VxFAoxHoZUtPF5tKJ IBPgVyH8I7uva7H9RwtxWHbgJ1Ap4j551aGVgjkMSoTrYHYOsRqSk2zqubVZ3m1BC50+mVLvBXQ BFFu0iHsssZhH1QcqglasyVsgKcWrXOxXiaAWb23M5/bWsP/K+2XBfqMvxUhksYODu1xtriqZ+P O4n+KgdECzpiyWniU1Aml1fI7BdUq+kNM74niYIg6MJxbqoZ5Nid7BcFPCIPZ9o2H9uuU5kPDtS mF02v3ot70iz7WDaLsRCau8FseeTlJPk7deoOQQ6G37giN9+VS4XAaZDHiydx/UMgytxwvP2VIL ANH1mQcbDPvGTE8f2YynNjD+P9tmUt+poJgZTersPw5jJ+syLPuhdBSMNbX3tUX5NPueiJJLMGf 8n7kIKXKMPOPZ6Msl6As7zgcAw/cPdOoQa9AIm3O9bDasUYvg2KhAJIBvTQ3203ph8aJuKJJ0hP dcoGpyzP6xIjOYevb8AU54= X-Received: by 2002:a05:6a00:340a:b0:878:34d7:6983 with SMTP id d2e1a72fcca58-87d1c3b6320mr1831941b3a.49.1790160126043; Wed, 23 Sep 2026 03:42:06 -0700 (PDT) Received: from NVAPF55DW0D-IPD.. ([203.211.104.195]) by smtp.gmail.com with ESMTPSA id d2e1a72fcca58-87d1d5c1646sm1035870b3a.30.2026.09.23.03.42.03 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 23 Sep 2026 03:42:05 -0700 (PDT) From: ankur.tyagi85@gmail.com To: openembedded-devel@lists.openembedded.org Cc: Devansh Patel , Khem Raj , Ankur Tyagi Subject: [oe][meta-python][wrynose][PATCH 31/42] python3-twisted: correct CVE_PRODUCT mapping Date: Wed, 23 Sep 2026 22:40:45 +1200 Message-ID: <20260923104056.457360-31-ankur.tyagi85@gmail.com> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260923104056.457360-1-ankur.tyagi85@gmail.com> References: <20260923104056.457360-1-ankur.tyagi85@gmail.com> MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Wed, 23 Sep 2026 10:42:07 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-devel/message/130218 From: Devansh Patel The product-only "twisted" value emits a wildcard-vendor identity instead of the active identity assigned to the packaged Twisted source. Use "twisted:twisted" for its NVD dictionary CPE, NVD configuration, and CNA affected-data identities. With sbom-cve-check 1.3.3 and the pinned database snapshots, the generated product identity changes; the current CVE report is unchanged. Signed-off-by: Devansh Patel Signed-off-by: Khem Raj (cherry picked from commit 2aa82f4b3376cb6946d054bfc674dfa711c112f1) Signed-off-by: Ankur Tyagi --- meta-python/recipes-devtools/python/python3-twisted_25.5.0.bb | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/meta-python/recipes-devtools/python/python3-twisted_25.5.0.bb b/meta-python/recipes-devtools/python/python3-twisted_25.5.0.bb index 3b49f56093..9b40191964 100644 --- a/meta-python/recipes-devtools/python/python3-twisted_25.5.0.bb +++ b/meta-python/recipes-devtools/python/python3-twisted_25.5.0.bb @@ -16,7 +16,7 @@ SRC_URI += "file://CVE-2026-42304_p1.patch \ SRC_URI[sha256sum] = "1deb272358cb6be1e3e8fc6f9c8b36f78eb0fa7c2233d2dbe11ec6fee04ea316" -CVE_PRODUCT = "twisted" +CVE_PRODUCT = "twisted:twisted" inherit pypi python_hatchling From patchwork Wed Sep 23 10:40:46 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Ankur Tyagi X-Patchwork-Id: 99046 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 9D2B2C98309 for ; Wed, 23 Sep 2026 10:42:17 +0000 (UTC) Received: from mail-pz2-f40.google.com (mail-pz2-f40.google.com [74.125.228.40]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.4181.1790160129164454377 for ; Wed, 23 Sep 2026 03:42:09 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@gmail.com header.s=20251104 header.b=DGLI19t5; spf=pass (domain: gmail.com, ip: 74.125.228.40, mailfrom: ankur.tyagi85@gmail.com) Received: by mail-pz2-f40.google.com with SMTP id 41be03b00d2f7-cc75e33cc69so358498a12.0 for ; Wed, 23 Sep 2026 03:42:09 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1790160128; x=1790764928; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=8EYv4sClpI5QZTfkw0/7ygjTYKBjL8hp557KICEI1TQ=; b=DGLI19t5NHml55dA1yMaNRbZBbX4BjV3JwpKi81nk479+F5gfxwy3SIXYdA5F4tkju FiwXNHechRmuD2vO2v+Nn1fbaFt8lbNbbK9XTPXYONdcyrUpRIuetR+MEBKTMMS7ClEJ 3A03sW+0I14jsf3E8XXpFo2VltFs84gK9DoqjJInqRsG0gzZi7FHUkdtrb+omLMMJRKp H5C7iMx/oJBoVaQMKy9lWLpFRxQjVEwWsXweb/C19dLuxJVeL4tSLyip4qGoqT6MVWOX KBiBe2C+lGviNz6Z4VGwPOMvmBdv5AKbi/Qf5gTkOsFgaLq2RQ09GMgS/TF4+VPK5KIX z9CA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1790160128; x=1790764928; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=8EYv4sClpI5QZTfkw0/7ygjTYKBjL8hp557KICEI1TQ=; b=PAaeCOU1H3aJYJmT6P48PG8mgtIpj3HSYL0xpvlEs9XVdPu3A92Zl5uv78VOvdg5Gs jnvPFpDUPLc3Z9d/WnkX55hAfJC0aCH3vyTs2EqEpJkT2uOj24O+sLMaisLw/0OBCwre wHf/hamuExW0uS9d9vW+cPVz4OvcaudR+1EJrzsO/ZtWGMsCAC+sB1pwOOsEfM93qIx/ wnnzTlz2RE9/NQeMrO6v7Pbhf40K7DIjzQKTxenxtPTbO47F/2zOKqN+MZCOO7dSGqi3 u2p81DJZuf4cs4yZKZkzp51TacXhdMEwYQBwncnBpPDzGCV2sVBv3Eyf+tTI5pLHPD1c XA3A== X-Gm-Message-State: AFuF++luqAoIuVJzng+5R3ovqDMIMM4l6Nvrvt6zboWqM5oQBzWEz7fx XDJC7HNBL0APa2p+14uWiH6HgBIegMrdfmUJb2hgs6vPcPyuER68GhEqdLGSHA== X-Gm-Gg: AYBFou2D6VGOPmyOc/SYCC6DTBbThU5hlPc1fenu6639VZqQcFx45ksI18A5zmd7mn5 RmMAf2Z0RqBZo9ZbPwe9d82zTQUoamlz9oV9/PCaY7GGqXX2lWcaBOtWd9IY7iUpwaRJBVlAmer ErWi5twshBpkJUCjCbxLOxn9Pqv+lM+dVYT+UX8p0vi4RBfUHwVye5qMsQ341sUrys6GXpBui/A CKhkdwAoYVA4/SSPRVbzEIlSgn1DiFugCO1nPItV9j9NylwGuqmtA3NCbB0KTKJQU6va+Fs7A/l 8Js9GqmhJqM81tXUp7/XHdmE8DFCwhu8e8/12BiCBcXH/jrgs04vfWwxISgjvIyiOU00jwCw4Cb wTjJydeLlNCMwpMuRaUXlA3JTgkHbZMlinb+vDkiHCyC2EUQg6dNgGYSujqYZaq8gbPmxgf+rtI jWbNqPwuVbye8e0cIoA+K24vx7WgDLYB5hofMJYuo4rfEj4TthCtjXPuourzogweqzrfKlgtjy6 ghVjN9lVtwwAZS14x4T+PtUvnA6ng7uFA== X-Received: by 2002:a05:6a21:e089:b0:3dd:a195:dd50 with SMTP id adf61e73a8af0-3ddf827f04cmr2357096637.50.1790160128575; Wed, 23 Sep 2026 03:42:08 -0700 (PDT) Received: from NVAPF55DW0D-IPD.. ([203.211.104.195]) by smtp.gmail.com with ESMTPSA id d2e1a72fcca58-87d1d5c1646sm1035870b3a.30.2026.09.23.03.42.06 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 23 Sep 2026 03:42:08 -0700 (PDT) From: ankur.tyagi85@gmail.com To: openembedded-devel@lists.openembedded.org Cc: Devansh Patel , Khem Raj , Ankur Tyagi Subject: [oe][meta-oe][wrynose][PATCH 32/42] php: correct CVE_PRODUCT mapping Date: Wed, 23 Sep 2026 22:40:46 +1200 Message-ID: <20260923104056.457360-32-ankur.tyagi85@gmail.com> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260923104056.457360-1-ankur.tyagi85@gmail.com> References: <20260923104056.457360-1-ankur.tyagi85@gmail.com> MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Wed, 23 Sep 2026 10:42:17 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-devel/message/130219 From: Devansh Patel The default product-only mapping generates a vendor-wildcard CPE. php:php is the active NVD dictionary CPE and configuration identity. php_group:php preserves historical NVD configurations and current authoritative PHP Security CNA affected data for the same php-src source; it is not an NVD dictionary CPE. This changes the generated identities to two exact CPEs, but the frozen sbom-cve-check database leaves the 731-entry CVE report unchanged, with no current CVE delta. Signed-off-by: Devansh Patel Signed-off-by: Khem Raj (cherry picked from commit 4b8eedb7d26387005924e6035f178b1d56dd33e9) Signed-off-by: Ankur Tyagi --- meta-oe/recipes-devtools/php/php_8.5.10.bb | 2 ++ 1 file changed, 2 insertions(+) diff --git a/meta-oe/recipes-devtools/php/php_8.5.10.bb b/meta-oe/recipes-devtools/php/php_8.5.10.bb index aab18777c7..130a98f634 100644 --- a/meta-oe/recipes-devtools/php/php_8.5.10.bb +++ b/meta-oe/recipes-devtools/php/php_8.5.10.bb @@ -34,6 +34,8 @@ S = "${UNPACKDIR}/php-${PV}" SRC_URI[sha256sum] = "d79bd4f3a9248e5cb5833766ba0d51cd35dd01b8727f23f30bcdba6fabc51d3e" +CVE_PRODUCT = "php:php php_group:php" + CVE_STATUS_GROUPS += "CVE_STATUS_PHP" CVE_STATUS_PHP[status] = "fixed-version: The name of this product is exactly the same as github.com/emlog/emlog. CVE can be safely ignored." CVE_STATUS_PHP = " \ From patchwork Wed Sep 23 10:40:47 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Ankur Tyagi X-Patchwork-Id: 99045 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id DD759C9830B for ; Wed, 23 Sep 2026 10:42:17 +0000 (UTC) Received: from mail-pz2-f43.google.com (mail-pz2-f43.google.com [74.125.228.43]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.4182.1790160131573397641 for ; Wed, 23 Sep 2026 03:42:11 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@gmail.com header.s=20251104 header.b=hJZGaKA5; spf=pass (domain: gmail.com, ip: 74.125.228.43, mailfrom: ankur.tyagi85@gmail.com) Received: by mail-pz2-f43.google.com with SMTP id d2e1a72fcca58-8693af0d7c4so487324b3a.3 for ; Wed, 23 Sep 2026 03:42:11 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1790160131; x=1790764931; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=bQjEYnH5Tfxy/GFKuNJKlGNvoONra3aljAhIX6cnrBY=; b=hJZGaKA5KGmokYP4lMaiaVbDndsC4Kakb3iFGzsJy6s1O/3WROX7YPAMZPU/IuXxiX TKptURiJkUj6MxPEtAz5whDwsp67Wi7mDIANBDHxLmwCK/87X/KVwjQtsKbv+4ZMVK3h 424pPSWmMguFLw3HNuT2QhzQXHxnAda2G37Lyeks2V5+mL3bK2dsfkB4GhiZ1+RDtIsv ELcnxY7xBJmf80wj+KYynXZbus6zuDKQkzItT9ngc+PWJ7SFrNr6t5yvmvnO0nG2Bd99 cjA8v72y3BO2Trj1KSl4G0/nWA9+HqADZX33QJeFsixCRH8cmquKFq+XVZFdcCoDH0CM UMjA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1790160131; x=1790764931; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=bQjEYnH5Tfxy/GFKuNJKlGNvoONra3aljAhIX6cnrBY=; b=BcvaVK7XDMTWdkttTuhRiHfTbw/afbN1YQV8Bgi8F5W285D/pjiaR+SXNoj/jtdnfa TQS0EUdDfkAWvCUIEA0hCSmvtxWypYdXuuMtPR/rAsQUKh1W3bX6+fSLyJwdj5D3YReA 6EITeE+gE5QAYB7ATUIa3F8kXdw1ONYsuTyzmCncwhnZiK4TWN5CL7uIlWjxO5B3IuxR NJzb2XUo0AuQ/3bavzzi6gKTZiqfNDn/rLoiRsoN9o9TuBpk6YzCyD5umRWV8MJGZXAB T0Cyc+PVsQGrGEYm6WObHUmp41hn04jMuyIoIUyomxHW5ThYYjghi3R8tkaxQLHLkLI+ v58w== X-Gm-Message-State: AFuF++m8x4PhT4PeyvPzqf/UXjyQnntF7F6BAD5CKZM+ucQLaH275q5a 3jjKo2OR+qupSq4Gc0KHwnuqmLN2xwPcDz1HqfXGtQ/zpP+7SfuvXPgqASSXqw== X-Gm-Gg: AYBFou2qtCOgNljhA+lXYq785PCGi+9xNo4uIG5f1dcEdNNz5SkV1chQfGPB9seSYRk +6gA2VTLjLyxIg4tYezq4G/y8K3cKUpk4nIzakFeL/G0zlx5tsGgZkzspVbGBKRyQhVT+IEAWaA KRCebgmp3wyZ9HdafuDbngaYrx/+EYNF6nWH1RQgbt75jVZnStFo3XsWc+SI3BGEjTg8MPkG6vA ywfEExXox2lsqFQYYbVgRAVo4FmQEKM+WOQHN4OXN9Te8mQbl1V9QwtHWS1jGy4OaJdNkBkzeYV 8qEp/W6naD2BiXqVZeFHOpzv/SPh0gXd90fgJzT23mkEZKYR8S2sjhgRnIRmj2AGmmKcJxSdzEm n+1rCAgFbIrfY3rPLFY+NKToPRn32J88m677GB5lG5k+8dVCikltAoI+AAyeuOqw0uUNrQZajJu 7erYo0HZZd1PZ1TcMk//514pGNodHhSQySyNszQsT25Bvp+1Wv9CRHT+7VbeneN9wpExQpsXe2t WwnWHFH3Q+kLnVsNoo+3Cc= X-Received: by 2002:a05:6a00:3404:b0:857:72ba:ff0c with SMTP id d2e1a72fcca58-87d1978581cmr2044950b3a.20.1790160130987; Wed, 23 Sep 2026 03:42:10 -0700 (PDT) Received: from NVAPF55DW0D-IPD.. ([203.211.104.195]) by smtp.gmail.com with ESMTPSA id d2e1a72fcca58-87d1d5c1646sm1035870b3a.30.2026.09.23.03.42.08 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 23 Sep 2026 03:42:10 -0700 (PDT) From: ankur.tyagi85@gmail.com To: openembedded-devel@lists.openembedded.org Cc: Devansh Patel , Khem Raj , Ankur Tyagi Subject: [oe][meta-python][wrynose][PATCH 33/42] python3-ldap: correct python-ldap CVE_PRODUCT mapping Date: Wed, 23 Sep 2026 22:40:47 +1200 Message-ID: <20260923104056.457360-33-ankur.tyagi85@gmail.com> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260923104056.457360-1-ankur.tyagi85@gmail.com> References: <20260923104056.457360-1-ankur.tyagi85@gmail.com> MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Wed, 23 Sep 2026 10:42:17 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-devel/message/130220 From: Devansh Patel The current "python-ldap" mapping generates a vendor-wildcard product identity for the packaged Python binding. Use "python-ldap:python-ldap" so it matches the NVD dictionary CPE and configuration identity. The generated product identity changes, but sbom-cve-check 1.3.3 reports no CVE delta with the pinned databases. Signed-off-by: Devansh Patel Signed-off-by: Khem Raj (cherry picked from commit ffc1c4a3184e5bb55f3be713363eeffb33fd8e82) Signed-off-by: Ankur Tyagi --- meta-python/recipes-networking/python/python3-ldap_3.4.5.bb | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/meta-python/recipes-networking/python/python3-ldap_3.4.5.bb b/meta-python/recipes-networking/python/python3-ldap_3.4.5.bb index 5a176b5208..623b14c31a 100644 --- a/meta-python/recipes-networking/python/python3-ldap_3.4.5.bb +++ b/meta-python/recipes-networking/python/python3-ldap_3.4.5.bb @@ -29,4 +29,4 @@ RDEPENDS:${PN} = " \ python3-unittest \ " -CVE_PRODUCT = "python-ldap" +CVE_PRODUCT = "python-ldap:python-ldap" From patchwork Wed Sep 23 10:40:48 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Ankur Tyagi X-Patchwork-Id: 99047 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 1069DC9830C for ; Wed, 23 Sep 2026 10:42:18 +0000 (UTC) Received: from mail-pz2-f40.google.com (mail-pz2-f40.google.com [74.125.228.40]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.4184.1790160134074231087 for ; Wed, 23 Sep 2026 03:42:14 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@gmail.com header.s=20251104 header.b=ZqkbuRjL; spf=pass (domain: gmail.com, ip: 74.125.228.40, mailfrom: ankur.tyagi85@gmail.com) Received: by mail-pz2-f40.google.com with SMTP id 41be03b00d2f7-cc74520b20bso248530a12.1 for ; Wed, 23 Sep 2026 03:42:14 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1790160133; x=1790764933; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=WPXG1iL1QSayKU3dSCpJ53msntwPv1/Iqr8mVa076AA=; b=ZqkbuRjL7x7AK1xwQRnCJAkujk3vnywNuZStEH7/fjwt8prwPWt4E/Ydopp3xn2IUn nqZE1pp2whI6LF3gWh+1/0WcHc7gSjnqm+Y+RGWVwAWxgGJVruRy1FSdD8io5D73a4/y 8jetPP+vUXtNe6Kb4rvttkLz2HIY4Jy6S9Ov9yE57QdRG3dh3EGdZQvufPzBQbHGfdmG /QR+0KEbFyLPPqn8Q1BY/huI9qQ0X/gP2DQExaI2CaPd4pBrS2tnmKgedTj6gaRSRMQO l0yD9QzS6CUDk+ow1YFGfDCQJ+EBNxYVb4KE45HM20tKNhvnaWIvQ83yf1KJeU32Sp18 uvLg== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1790160133; x=1790764933; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=WPXG1iL1QSayKU3dSCpJ53msntwPv1/Iqr8mVa076AA=; b=rKakV/BqlxpKq12vu/UyzCcNlpPWbFvrgt/FXB+3QU1fP+X0P1xb2pXQXB+gulv4e3 XfvzVUqpKaalpxiNuBUd3px2tof5t9yIcC+KVt14Yb/Hlqa+8sw1HNo+NEyDT+M4W0V/ /7EgvHmWXqcFOgpaxJKqXqA1m/N7bcZ5+XYIOn0O9PpL92MUpmajVnrMoXbVk50OdMA2 WVdMjjavwueGQFVPN1pWDzXvGs5RLepfTrPYjMM9am8/adoibXtPL14svsVoGZkomRZG KfMfVXV1y0lcy/xVD8Nh8Ltj78v0/+SPM5Vm4KlzB0YlN1yeq+oIXCrVkh6BQQnUIDU4 6FOw== X-Gm-Message-State: AFuF++nBn4SleYe4F+PqRYyZzHam0E5fpgVGXmFaTPt5aAE7y0ntezrf d5GhD1o8PCITWKrU6CTTQgQluo+XMqJ/n6SNKGWYwW+8uCGdXV7YeQuRrks/rw== X-Gm-Gg: AYBFou2ZdAOBAqu8QqEKHt7bMXfWdhMiQIaesMYiG1oiMbt6lP+4WrL590mTRoKBQ5N DXYy9FKVRTVTC7oWUfNiJ5Dpd/sDyqtcqa4F7CZ5LYXm510KjZ9naap8oL3oBUHJANP5tv2tXwC MDD1WsCDIQ6WOGkfffiP6LIsGkoBG+IzDj3XIf8COrBe7kpjMaOyitQBO2lXare7r7H1xwWGzEg eqE8pLPZ0GxMZWRvM8xgZl24iciGW8FGZ1fyGJEEqojBmBU06An2zTeoVcIEoPJ0HP7YP6s9HkY M1Li0r+9XEFR4zFhoSjAqXGpB2oyDhSsXqLQ7sMj2T7avKrU7CgkBpv76DXeU9V70TZA2+OYtnK qedKYLnPfsEaj5aTluWTCsPsohijodVw3u0HqSF42BTNXALJLYIHCaCFb/9WXeUDqubzHOMQmiU 3Uyncbz5InCKTPdJG77zcAnaco8kEHUV8lYtueUcPPbCW5EoMUNEuZWMLccrbfuMTW/K7PKjapa c3sZzTmBvc5J0Tu6jhwRgw= X-Received: by 2002:a05:6a21:1398:b0:3dd:a196:ffcd with SMTP id adf61e73a8af0-3ddf8354fd9mr1560845637.29.1790160133430; Wed, 23 Sep 2026 03:42:13 -0700 (PDT) Received: from NVAPF55DW0D-IPD.. ([203.211.104.195]) by smtp.gmail.com with ESMTPSA id d2e1a72fcca58-87d1d5c1646sm1035870b3a.30.2026.09.23.03.42.11 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 23 Sep 2026 03:42:13 -0700 (PDT) From: ankur.tyagi85@gmail.com To: openembedded-devel@lists.openembedded.org Cc: Devansh Patel , Khem Raj , Ankur Tyagi Subject: [oe][meta-oe][wrynose][PATCH 34/42] mariadb: correct CVE_PRODUCT mapping Date: Wed, 23 Sep 2026 22:40:48 +1200 Message-ID: <20260923104056.457360-34-ankur.tyagi85@gmail.com> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260923104056.457360-1-ankur.tyagi85@gmail.com> References: <20260923104056.457360-1-ankur.tyagi85@gmail.com> MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Wed, 23 Sep 2026 10:42:18 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-devel/message/130221 From: Devansh Patel The default product-only mapping generates a vendor-wildcard CPE. mariadb:mariadb is the active NVD dictionary CPE and configuration identity, and is also used by CNA affected data for the packaged MariaDB source. Deprecated mariadb_project records describe a separate Node.js connector. This changes the generated product identity to an exact CPE, but the frozen sbom-cve-check database leaves the 420-entry CVE report unchanged, with no current CVE delta. Signed-off-by: Devansh Patel Signed-off-by: Khem Raj (cherry picked from commit 099991739cb0805e63a11076d268dc7a99da8d1b) Signed-off-by: Ankur Tyagi --- meta-oe/recipes-dbs/mysql/mariadb_11.4.12.bb | 2 ++ 1 file changed, 2 insertions(+) diff --git a/meta-oe/recipes-dbs/mysql/mariadb_11.4.12.bb b/meta-oe/recipes-dbs/mysql/mariadb_11.4.12.bb index b1d1355e2b..71c91f0b2f 100644 --- a/meta-oe/recipes-dbs/mysql/mariadb_11.4.12.bb +++ b/meta-oe/recipes-dbs/mysql/mariadb_11.4.12.bb @@ -1,5 +1,7 @@ require mariadb.inc +CVE_PRODUCT = "mariadb:mariadb" + inherit ptest inherit useradd From patchwork Wed Sep 23 10:40:49 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Ankur Tyagi X-Patchwork-Id: 99044 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 9CAA8C982EA for ; Wed, 23 Sep 2026 10:42:17 +0000 (UTC) Received: from mail-pz2-f43.google.com (mail-pz2-f43.google.com [74.125.228.43]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.4301.1790160136483613815 for ; Wed, 23 Sep 2026 03:42:16 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@gmail.com header.s=20251104 header.b=iRH2nAp3; spf=pass (domain: gmail.com, ip: 74.125.228.43, mailfrom: ankur.tyagi85@gmail.com) Received: by mail-pz2-f43.google.com with SMTP id d2e1a72fcca58-8633a38df87so365869b3a.2 for ; Wed, 23 Sep 2026 03:42:16 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1790160136; x=1790764936; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=tifWFHRLR3GAf7fwoy5DFJwBVGY/sdZOIOxHCLVHr98=; b=iRH2nAp3SwPiW9VMVdXrGUU8v5XSqiVmtsVrQzJT1rj4bZNF55IIiqY3ZedwtRfN15 x+J6Ol6o3THuGS3X/cfWoz+6MvqfLhAf1eqoNVpMYFVuzK0OJJiTqpWaj/A+lsivBcYn BNpkgC5h5k7zwltqLDYramnFiB99x+2KfahxeKV2nq9Xx226vyRm6rHpACE4Lk7ItrDy JAwxPXcw+A4Dp577OzH3MrNszK70wAgZrjhL1hF4sv1YAwcvNqJe+7nI3iXuu5bKmAhs C89SgJt5hAHZih4+QTb/c59ZdsMe7sO14zlAsTmxUonORQShU9zx0IOVz5Ek5eoqxa43 uULw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1790160136; x=1790764936; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=tifWFHRLR3GAf7fwoy5DFJwBVGY/sdZOIOxHCLVHr98=; b=Xjzxk8sMh2wams3Q3kae5jtX90R8fvqC6ArGAMFlquTtyJDbj3wwJKjaOVZnY3Hfzz Z2pvnXpgMkcMJqGrUGBDJmVE9C+P2K/XiCgQE3NEd4jVVlTtwkX7qLDBmY/2V7WiqEcZ pNUC4QarkICB5yo375oWVZllk5lx/6aRs+0W9DDnsZ2yKAZkgh2fTbj9WGKovWa5pu2a gBYV4hxwCxDaEr+Ox0mgq0LI5dSx8GarrOmIdTIVGT/hY7nNfj4YPVRvr01aU6WqETMr LPHzXpAa9UKXUbksgOlbaGgrIfFmh0cYD4VEPy7BluBpV2w1NtYM00JcyBFYZ0Lxrtu0 ChCA== X-Gm-Message-State: AFuF++kgmc9neT1iQtrMWQ3CCa4FXfES+jg6iQeDHgWm94mtzIhGJieO Z0AOR4z3/R+aQVB+Ko4cu/fZHU2KVe3Y/8Nw1CZL6WRoRQnr07Am+pcREEY1lw== X-Gm-Gg: AYBFou1CDYIRbr45rxhr9q8b1przR3dq5Jxe2gGhWCXPJ8JgTjUMipIWlNH6OyP81Mx l1gzidf1zxfG/V2R4VR7XbYxLp+5cfC8vyEkml03dsTzmWflVFbiHa9qVJyyOnmlQJTqqur4zsB VVW/ZISBr2Fnt8VXYh1PwO/U1TIVYbI9xeJOxnb26S/Z1gUq8/OBRm/LLa80oed8p6CkHN6EDRS 0+yJN7vlaBG90YE4yjpOVUfGTqD6NZ3VPi5GhqjXYHLmjXyAywDHsVztIkPDxFEVmIc6dRlfAuc J3fCagtJIvmW3BtSRyXYLVeWx5nbTvVfrueRm4YT30eOeIArDpMCS14yxcGYpIl1pThVBQqdXzU Ue2QTIazBdhp879rcNVUNCs7P+zj/wD9XQDHdPE8dc2EX2W4+AFUMcyiIMxYtlyk8Z9+YDm4/4d 1VyTpzmD0A/3Dt7PSYPxBO09h060S5nqe8ncSO/QIMoAxPXF0NB8LoLQbZeNbjzJrE5aRBm1+yV FFzTjC66jSzSnK9gfgPgWY= X-Received: by 2002:a05:6a00:464e:b0:869:9298:ba50 with SMTP id d2e1a72fcca58-87d16eb422amr2170060b3a.0.1790160135837; Wed, 23 Sep 2026 03:42:15 -0700 (PDT) Received: from NVAPF55DW0D-IPD.. ([203.211.104.195]) by smtp.gmail.com with ESMTPSA id d2e1a72fcca58-87d1d5c1646sm1035870b3a.30.2026.09.23.03.42.13 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 23 Sep 2026 03:42:15 -0700 (PDT) From: ankur.tyagi85@gmail.com To: openembedded-devel@lists.openembedded.org Cc: Devansh Patel , Khem Raj , Ankur Tyagi Subject: [oe][meta-oe][wrynose][PATCH 35/42] libssh: correct CVE_PRODUCT mapping Date: Wed, 23 Sep 2026 22:40:49 +1200 Message-ID: <20260923104056.457360-35-ankur.tyagi85@gmail.com> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260923104056.457360-1-ankur.tyagi85@gmail.com> References: <20260923104056.457360-1-ankur.tyagi85@gmail.com> MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Wed, 23 Sep 2026 10:42:17 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-devel/message/130222 From: Devansh Patel The default product-only mapping generates a vendor-wildcard CPE. libssh:libssh is the active NVD dictionary CPE and configuration identity for the packaged libssh source. This changes the generated product identity to an exact CPE, but the frozen sbom-cve-check database leaves the 48-entry CVE report unchanged, with no current CVE delta. Signed-off-by: Devansh Patel Signed-off-by: Khem Raj (cherry picked from commit f1c88ff462d97215b87e29719506d50c4d020978) Signed-off-by: Ankur Tyagi --- meta-oe/recipes-support/libssh/libssh_0.11.5.bb | 1 + 1 file changed, 1 insertion(+) diff --git a/meta-oe/recipes-support/libssh/libssh_0.11.5.bb b/meta-oe/recipes-support/libssh/libssh_0.11.5.bb index 49ffd29403..e0dafb47ad 100644 --- a/meta-oe/recipes-support/libssh/libssh_0.11.5.bb +++ b/meta-oe/recipes-support/libssh/libssh_0.11.5.bb @@ -15,6 +15,7 @@ SRC_URI:append:toolchain-clang = " file://0001-CompilerChecks.cmake-drop-Wunused SRCREV = "a09fdd00416e53b6ed436df6ff14339a4f884601" +CVE_PRODUCT = "libssh:libssh" inherit cmake ptest From patchwork Wed Sep 23 10:40:50 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Ankur Tyagi X-Patchwork-Id: 99049 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id F249EC98309 for ; Wed, 23 Sep 2026 10:42:27 +0000 (UTC) Received: from mail-pz2-f12.google.com (mail-pz2-f12.google.com [74.125.228.12]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.4304.1790160138904140024 for ; Wed, 23 Sep 2026 03:42:18 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@gmail.com header.s=20251104 header.b=izXJ2FHe; spf=pass (domain: gmail.com, ip: 74.125.228.12, mailfrom: ankur.tyagi85@gmail.com) Received: by mail-pz2-f12.google.com with SMTP id d2e1a72fcca58-85469e25400so405221b3a.0 for ; Wed, 23 Sep 2026 03:42:18 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1790160138; x=1790764938; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=S65oGOjDejyz7Z+oaYfkCqfFs8TakFqwN0brlJaPnf8=; b=izXJ2FHeHJ6mivJtjZtZGx8I3TnzxRpeJ2fQ/N4iJbD9QAuYkdR9HROtk3H87eK/w8 imbIkQ/GZE8z2+91neK4tMNE33kcvub5zdvJKH1Wan8oJJwRyAkFflOcTOZVyJgacToQ HBXxYp6gteA4/oK6k6FR9XjtnqlyrDtUpU5mJawXvYBVxgzgPZrM2wMFmC/7WV2qD61A /5OZq/GVxZ1py0bzJ3QxgB37MdqicUu9pexR61wWNEqLd7QomC2PGu762tKPqKQVAnmZ XAa3xBKEnQKShIseWldhqft+zYAK2clduNdyNYS7O4W4r8iaPSR6j9MFCSauYsX9h5vv bTfA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1790160138; x=1790764938; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=S65oGOjDejyz7Z+oaYfkCqfFs8TakFqwN0brlJaPnf8=; b=DWyIs1ARuwXbDkT1/QhQqY3Zc/djNTilf8KQ/W7A6+XNjMHVelHTz7e+vJWwGaetDW h8zmYHzs5b8S9U8HoP7oWMzrVqf7qTA3tjz5GpZSb9A0sCChZ8FrGUJFRAyH44Lq5Q7S rm0jXg/HNJQvLGww7WNDn+hUt+/j3EE0knmQsHe4v1vagA1/xiRZsG9CNMwUaF5T3Ok0 h6ZkaCdR5is/KGTAKbz9uOoXhX+3kX2ALgdaqLNFg6B27virgDYXH2VOUD8AzyeJGBk0 L1aSX+FB/Gw3+oohOLbfyWewPMLLF3NO8O+s+95r4nWyDbQiqUlQ+9LrssJ5lOWo5TFb IpQQ== X-Gm-Message-State: AFuF++mb+48WFSJy/Qfg/W2vjZlYhXEujxHwa3y2/rY4+5bguYob/xM4 s9H+mVP63q9AZ6OddEPXQt7p2b8UwDaOvlfVEPl56sgCmP1SYSZfFyVZY8pZLw== X-Gm-Gg: AYBFou1DgTL7ZsUdWbu5uh8H2/4urbKD/0rV4v6To1JM11hmb/p7Fqxj+K11q8OvpU6 xy8ACGL9SQK4Y0Maq2Gl9mTJJbE7hwo8t4tzn+AIOVpLYD+sPHebj7f83NA6TFPXY0wTCvyMpN7 sw8ja89UuA2SZwmF25Td4iPOOyj1zI6wVLPtXhzRygI8u7pZqLrwJwQSn2XzygmWYuosgc6BUQP MqpCa810YG+VVksEJHh3heV02Wj2eDkGGWG14FfvN65QdWrU6obt6c04BdKhyIxa/+trm54aGTK +BfgZXB7gDRDNThxgBsiVHZQx0y0CJg9WpLJFMRZJaQLhE/2A9RhQ/OgDmlRvgNUVDdhiX0CWOe K+0jzYXo0TsVaZDOh+b7KZEYpDHKSn7fpebBF4wcbwm7hjXYhBqaqUz8VxMAfmPWOXDjfvKfIk0 HK3n+LqfoyOrXaR1kB4yRF6t0sQGSiqe5hCYHRJiR9st+61o9CrLZjV4f2LoBf2qOIENetQOac3 3/z6AWEvzC69bKp43nA8cmRU+a+LpSrjtg3 X-Received: by 2002:a05:6a00:1f14:b0:878:34d7:69aa with SMTP id d2e1a72fcca58-87d1ccc6e73mr1730943b3a.49.1790160138253; Wed, 23 Sep 2026 03:42:18 -0700 (PDT) Received: from NVAPF55DW0D-IPD.. ([203.211.104.195]) by smtp.gmail.com with ESMTPSA id d2e1a72fcca58-87d1d5c1646sm1035870b3a.30.2026.09.23.03.42.16 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 23 Sep 2026 03:42:17 -0700 (PDT) From: ankur.tyagi85@gmail.com To: openembedded-devel@lists.openembedded.org Cc: Devansh Patel , Khem Raj , Ankur Tyagi Subject: [oe][meta-python][wrynose][PATCH 36/42] python3-flask-user: correct CVE_PRODUCT mapping Date: Wed, 23 Sep 2026 22:40:50 +1200 Message-ID: <20260923104056.457360-36-ankur.tyagi85@gmail.com> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260923104056.457360-1-ankur.tyagi85@gmail.com> References: <20260923104056.457360-1-ankur.tyagi85@gmail.com> MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Wed, 23 Sep 2026 10:42:27 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-devel/message/130223 From: Devansh Patel The current "flask-user" mapping emits the wildcard-vendor *:flask-user CPE instead of the exact NVD identity for the packaged lingthio/Flask-User source. Use "flask-user_project:flask-user", which is both an NVD dictionary CPE and an NVD configuration identity. CNA affected data uses "n/a:Flask-User" and remains covered by scanner aliases. With sbom-cve-check 1.3.3 and the pinned 2026-08-12 data, the generated identity changes but CVE-2021-23401 remains reported as affected. Signed-off-by: Devansh Patel Signed-off-by: Khem Raj (cherry picked from commit 3874342e002c8693e6c53eee5f775bec9bb3a7d6) Signed-off-by: Ankur Tyagi --- .../recipes-devtools/python/python3-flask-user_0.6.19.bb | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/meta-python/recipes-devtools/python/python3-flask-user_0.6.19.bb b/meta-python/recipes-devtools/python/python3-flask-user_0.6.19.bb index 68d7361519..c05c74b5c4 100644 --- a/meta-python/recipes-devtools/python/python3-flask-user_0.6.19.bb +++ b/meta-python/recipes-devtools/python/python3-flask-user_0.6.19.bb @@ -11,7 +11,7 @@ SRC_URI[sha256sum] = "601abcc0343dfbae0c56273d98362d5cdc266ac84d20b3f65a212e4a2c PYPI_PACKAGE = "Flask-User" UPSTREAM_CHECK_PYPI_PACKAGE = "${PYPI_PACKAGE}" -CVE_PRODUCT = "flask-user" +CVE_PRODUCT = "flask-user_project:flask-user" inherit pypi setuptools3 From patchwork Wed Sep 23 10:40:51 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Ankur Tyagi X-Patchwork-Id: 99051 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 46AE4C982EA for ; Wed, 23 Sep 2026 10:42:28 +0000 (UTC) Received: from mail-pf1-f171.google.com (mail-pf1-f171.google.com [209.85.210.171]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.4189.1790160141672098366 for ; Wed, 23 Sep 2026 03:42:21 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@gmail.com header.s=20251104 header.b=MD/u0NIp; spf=pass (domain: gmail.com, ip: 209.85.210.171, mailfrom: ankur.tyagi85@gmail.com) Received: by mail-pf1-f171.google.com with SMTP id d2e1a72fcca58-86ec25cf7ecso1427458b3a.1 for ; Wed, 23 Sep 2026 03:42:21 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1790160141; x=1790764941; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=WaKaJ33yZWmu4mwV7pgg8TioTuYh2MY89vZi4i75kJI=; b=MD/u0NIpCuZQGPxrqPPlHOPjFnXYTBrr+6gpqTMg2WQnvXtHz70QD0XFBbFIv8zToS 8cci3krJcwqR7x11TgL+s2nPQLzCiSqh+s5wufwEJUvmlxoiFMEI0QQK4dooKF2Dssc/ FO2DIL8FN7BkFXgZ1QbdJNoIglGdlHgHh142h2Ky4j1pmMUsKp0a6J9Z/68RZ44d1QFn mW78t9yz+6KSA4Xp4FD5dcK+SzROCM+CwtEGkzJIm94TM0FuFNt9f0NeU2suhKISPk42 ky0d8OLRVJsmbZli3sdbAbCP03cnB/r6Stb9TCPx3kefHseOXrgZtySxslv3MpnTLulx GHBg== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1790160141; x=1790764941; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=WaKaJ33yZWmu4mwV7pgg8TioTuYh2MY89vZi4i75kJI=; b=soK1ilzkE5wMqK4JUlmoBhPHoghjNk5iQSAVTafl7EXL+bVUHyb1gjMheicm8YbqDm SUDVjTEzdF4YDB3gD7ufk26EG0uJV+ak/tpeb95dUb7k6Wx4bQLyjbwIL1RyPPuOB57g lS40MONCzUntjhCgpBu+0c+Aymj/xX18Dr71LWAurwIGYQLyi+jjNI4a935/4pq1sVPf 8hacp741ADf/ZkOI3IcrTwD7rZS8hI56wSBBU+9tkCqIyqdWaHZIn9ctresDtpyJu8wD 7FgiYU+fuIX/SeTD6fDXuwrZNeVw3XYfXJ7p6cTW4PaQ4fiuEpdJBBqBaIdKV5i8gbuD lvYA== X-Gm-Message-State: AFuF++ksrYZHNApqN7o/BxvPTvsgCx6zua/odtlxRmr/XxC35AD/CTBg MKf4jUAtJKcKHwzy4ETGz36NjGIB4FqC9APq9+U5pCg7nHDLyAe89aDHOzO9sw== X-Gm-Gg: AYBFou0GhqaP0mrqPpAgm9c7S6hbBVNnYHdcDf/LJ/Neicf7PDOmqhGiViHETaEvDak /jIdy8rSN4rPdgTub2uo38XoqLZQ33QMBmA9tRdODZRS4OWSQR5CqAyo10GWDhFOQn5EIbf+kED spK/er//64G7Pyq677/r/2wmZIb6mglhN/RpKIwJubERHBISi/ST4RhUUZDLsVO069vKgPnLw71 DUNvxyX/u3DZZgn/TwwCVVtuNLRTFmJ1Ize8nMOht/WiIh4CVQ5qiGA3RK4dPPA1JD66aNrMbTk NCmvnAwT1s5OOdUckaUkdsX8qG0oCx55rCw9JSwOIcpO3DgVvJdgLM4N5vc3YGQi/P5KOT8vTCo bRwqhVfI4++MOyz3HdoALunAjeD1ZFZN1N8Y+AV6IBqbZ3JheuFtUseCU1zJcOIUXC/l3s+RIFF J0ts06mj5u5O5hCJ5KBueYfTM9szJlFvl29fnLjoavX+IURXK+YpmElHBlx3L3OgDfjdjPm7QIB LYAnCIO82sXHFRQCWOsqLc= X-Received: by 2002:a05:6a00:f95:b0:877:ce59:bd6 with SMTP id d2e1a72fcca58-87c822aa47emr2716040b3a.1.1790160140972; Wed, 23 Sep 2026 03:42:20 -0700 (PDT) Received: from NVAPF55DW0D-IPD.. ([203.211.104.195]) by smtp.gmail.com with ESMTPSA id d2e1a72fcca58-87d1d5c1646sm1035870b3a.30.2026.09.23.03.42.18 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 23 Sep 2026 03:42:20 -0700 (PDT) From: ankur.tyagi85@gmail.com To: openembedded-devel@lists.openembedded.org Cc: Devansh Patel , Khem Raj , Ankur Tyagi Subject: [oe][meta-python][wrynose][PATCH 37/42] python3-aiohttp: correct CVE_PRODUCT mapping Date: Wed, 23 Sep 2026 22:40:51 +1200 Message-ID: <20260923104056.457360-37-ankur.tyagi85@gmail.com> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260923104056.457360-1-ankur.tyagi85@gmail.com> References: <20260923104056.457360-1-ankur.tyagi85@gmail.com> MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Wed, 23 Sep 2026 10:42:28 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-devel/message/130224 From: Devansh Patel The current "aiohttp" mapping emits the wildcard-vendor *:aiohttp CPE instead of the exact NVD identity for the packaged aio-libs/aiohttp source. Use "aiohttp:aiohttp", which is both an NVD dictionary CPE and an NVD configuration identity. CNA affected data uses "aio-libs:aiohttp" and remains covered by scanner aliases. With sbom-cve-check 1.3.3 and the pinned 2026-08-12 data, the generated identity changes but the current CVE report does not. Signed-off-by: Devansh Patel Signed-off-by: Khem Raj (cherry picked from commit 33d7be43195b58c66f6ef32d1f4837af085b37ac) Signed-off-by: Ankur Tyagi --- meta-python/recipes-devtools/python/python3-aiohttp_3.13.5.bb | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/meta-python/recipes-devtools/python/python3-aiohttp_3.13.5.bb b/meta-python/recipes-devtools/python/python3-aiohttp_3.13.5.bb index b9d08ac97b..67dd8a1e40 100644 --- a/meta-python/recipes-devtools/python/python3-aiohttp_3.13.5.bb +++ b/meta-python/recipes-devtools/python/python3-aiohttp_3.13.5.bb @@ -19,7 +19,7 @@ SRC_URI += " \ file://CVE-2026-54280.patch \ " -CVE_PRODUCT = "aiohttp" +CVE_PRODUCT = "aiohttp:aiohttp" CVE_STATUS_GROUPS = "CVE_AIOHTTP_FIX_3_13_4" CVE_AIOHTTP_FIX_3_13_4[status] = "fixed-version: fixed in 3.13.4" CVE_AIOHTTP_FIX_3_13_4 = "CVE-2026-22815 CVE-2026-34513 CVE-2026-34514 \ From patchwork Wed Sep 23 10:40:52 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Ankur Tyagi X-Patchwork-Id: 99050 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 6685EC9830B for ; Wed, 23 Sep 2026 10:42:28 +0000 (UTC) Received: from mail-pz2-f12.google.com (mail-pz2-f12.google.com [74.125.228.12]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.4305.1790160144192751829 for ; Wed, 23 Sep 2026 03:42:24 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@gmail.com header.s=20251104 header.b=HYlaLxnu; spf=pass (domain: gmail.com, ip: 74.125.228.12, mailfrom: ankur.tyagi85@gmail.com) Received: by mail-pz2-f12.google.com with SMTP id d2e1a72fcca58-8692a856865so353573b3a.2 for ; Wed, 23 Sep 2026 03:42:24 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1790160143; x=1790764943; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=aG15hR5mcbGlWAufTqxFlnyLU6O90y/1iwEQVsPLkZA=; b=HYlaLxnu+5w0+qPHbIA5zuUp7iLQLFXbWWOJmGI/TCQ6KAABU6WZkJPYJYZPydg7Eg tw3jHbO02GuKCbjEwE5xF8Njog8GE0E3i7VUzbX7hYnWJrRk+CgGSvggqosU2u85IFEB u/7RtbkcvtcSzrZOddagyPndkWlReA4I7dS9wnWJHmiDaNqFwIYlIRAzRdwZykNPqDyy m+QrzUijrSb40agO705aYVpWuA5GOXwANeojSq3jrNxo7iq4/aIkYHSeyY3VST9PWDV9 tJVA5EryfydCySGcrxXbRnVphOSVJNAGdyA+Y/J8znbxpufbpvjcH3S4rvipfOOu3EO1 sbvQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1790160143; x=1790764943; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=aG15hR5mcbGlWAufTqxFlnyLU6O90y/1iwEQVsPLkZA=; b=VVWlSoCGVUQcqLYijDg34hM46wCfMiw+A6RNIUGw5CvFDUvOIYjRD3SjGhpKnyrCWn a2lVgZCGvBpENpY9Nq1Gqwtkka4R3Z39kDwARauU62UJeazWmB0y2uShdgi7Xfupo8Wa oCCR+BFKOEMYQEYt1z/B4qdaKItnviOWMP8dhp8VgUHcitnH7vjbk78Fn2Bf2I2mWqVV lZU4wAjUmOafe6/VLbtOzfDISHI2K9QoaPSEULEv9Nv/S9R5V1pXvSYYROfMMpr2wXqN 5QGgtmKithPy8AsQfArsUpcpu2PTmhOBCmkngyskg/DM4x0oA7HCkytZOJ0W9bcysAOi k7Yg== X-Gm-Message-State: AFuF++k+/NTKYMZmgVqjZbA0CBKxJvPCZ3fAdZu4rifDJC+ubDXFd2yX ZmR72fFEKqwS/AjZ/bV25A2b0S7OY3a7+eu83YH6Tkx2O1RSel/YZexf1uqWFg== X-Gm-Gg: AYBFou0J/reypJG8kYygSg0uidmMj6xS360MvBeIhqNMNEub2fI6Ty6Io6WfpFFMQJJ F9aB0Cxal1tBAtHh+UgmceEgARDz3Gb2l2D6wrqBsB/UuLdPIyKZ+dJhJSO41y9TCQu2+UH8evN OaY95WG2owEkywTAsMWVu4+wOnzDO8rTEaZsDyJo4RvmKP4htUjBxifVLSzWB6fO9fTyb5TKtUg LYiytq3hTs17h7uoix/Q7KIR6db6N7FtGooNfHAWcbvvIQR4EbF/t02moDnzBs5VAaMNPxw++ga pRhYXqa8NdLznw2SbCwowHrTnZwevJfJMjwgTqdVKaf3aQhQVk3d9AvAqrp/v2EKGe5z9B2UKXg N6phE3C8A3AMmTVp7GLgShdLRueLAQn3RavtQM5t6BNI48w8SdeCBzbD6bc84PibJDo2ZNKDkGw aR+kYga/r5L27ztEc636B7Zjm79O9TMUGsCQi4nzJDUZcmId6DJD4M8VHsYSNuYSVZBYIKS6N6x BCiain6mQhh+zjluYaT4a4= X-Received: by 2002:a05:6a00:8014:b0:86c:79f5:281 with SMTP id d2e1a72fcca58-87d19370de3mr2064650b3a.13.1790160143527; Wed, 23 Sep 2026 03:42:23 -0700 (PDT) Received: from NVAPF55DW0D-IPD.. ([203.211.104.195]) by smtp.gmail.com with ESMTPSA id d2e1a72fcca58-87d1d5c1646sm1035870b3a.30.2026.09.23.03.42.21 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 23 Sep 2026 03:42:23 -0700 (PDT) From: ankur.tyagi85@gmail.com To: openembedded-devel@lists.openembedded.org Cc: Devansh Patel , Khem Raj , Ankur Tyagi Subject: [oe][meta-python][wrynose][PATCH 38/42] python3-werkzeug: correct CVE_PRODUCT mapping Date: Wed, 23 Sep 2026 22:40:52 +1200 Message-ID: <20260923104056.457360-38-ankur.tyagi85@gmail.com> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260923104056.457360-1-ankur.tyagi85@gmail.com> References: <20260923104056.457360-1-ankur.tyagi85@gmail.com> MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Wed, 23 Sep 2026 10:42:28 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-devel/message/130225 From: Devansh Patel The current product-only "werkzeug" mapping emits a wildcard-vendor identity instead of the exact identities assigned to the packaged Pallets source. Use "pallets:werkzeug" for the CNA affected-data identity and "palletsprojects:werkzeug" for the NVD dictionary CPE and configuration identity. This changes the generated product identity, but sbom-cve-check 1.3.3 with the pinned databases leaves the current CVE report unchanged. Signed-off-by: Devansh Patel Signed-off-by: Khem Raj (cherry picked from commit fd0b8a36e6bbce468654cb917254cd9c32ef923c) Signed-off-by: Ankur Tyagi --- meta-python/recipes-devtools/python/python3-werkzeug_3.1.8.bb | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/meta-python/recipes-devtools/python/python3-werkzeug_3.1.8.bb b/meta-python/recipes-devtools/python/python3-werkzeug_3.1.8.bb index 4e1be5cb2f..fae4de2a3f 100644 --- a/meta-python/recipes-devtools/python/python3-werkzeug_3.1.8.bb +++ b/meta-python/recipes-devtools/python/python3-werkzeug_3.1.8.bb @@ -12,7 +12,7 @@ LIC_FILES_CHKSUM = "file://LICENSE.txt;md5=5dc88300786f1c214c1e9827a5229462" SRC_URI[sha256sum] = "9bad61a4268dac112f1c5cd4630a56ede601b6ed420300677a869083d70a4c44" -CVE_PRODUCT = "werkzeug" +CVE_PRODUCT = "pallets:werkzeug palletsprojects:werkzeug" inherit pypi python_flit_core From patchwork Wed Sep 23 10:40:53 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Ankur Tyagi X-Patchwork-Id: 99048 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id F1D23C982FA for ; Wed, 23 Sep 2026 10:42:27 +0000 (UTC) Received: from mail-pz2-f41.google.com (mail-pz2-f41.google.com [74.125.228.41]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.4192.1790160146578185144 for ; Wed, 23 Sep 2026 03:42:26 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@gmail.com header.s=20251104 header.b=rYOF+jBk; spf=pass (domain: gmail.com, ip: 74.125.228.41, mailfrom: ankur.tyagi85@gmail.com) Received: by mail-pz2-f41.google.com with SMTP id d2e1a72fcca58-86212a185dcso578711b3a.1 for ; Wed, 23 Sep 2026 03:42:26 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1790160146; x=1790764946; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=6oODtCWMSTJpLAE1P86XTxOTwW0ptBmn7n8wUDl3Jj8=; b=rYOF+jBkh1du7N8i8elem2dZYyUCXh4ModH+FVJJ9TvLRZr7+qNVXE8I6pjQgUXRTt HjphKrN572GQe+wtrYe1vw0racgDo3d3p5xGPFkLAE9tpzAfY+o/Sij6oG4g9+Yy3xhZ h4CkLFG0GNdcf7nLSoCpcgBdgUe8sAYYeMPJR7q4HcEMBr0nG1Oy+gozrDN6quTXmEsZ j+Bm55TYdgGpMV7zcPqjDo77GUQZgr5Np5in61RVa6nAd1ps5b6PXnk9Q81dBUyCX/cp 6srXicSg191lnvy38kPi3+SU2TEs3AkdEhcL9uPp4NyJSqLY78Vx7txzUV43zhcqCT69 3GRg== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1790160146; x=1790764946; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=6oODtCWMSTJpLAE1P86XTxOTwW0ptBmn7n8wUDl3Jj8=; b=FNY34Dd3GZ0VqxJFsruU1VV7an+o7gmLsiwCuCPp32Pql7Rs8Yk2VkQB/cXW+kssDs MVCMtEiv4zoKHt7ql3/DIlAeVKQP9aXyFt5hb/ab+a7g92y62FEhmKwqxDvNFRtHJy0P kWnTjUCK8eTCshv9ex04Qk5M88GP6MOKBlyBP/YIjaAE3pJ3qzxuobc2mIErl8EyF7cH oJ3S+coSo2KXBHSFcQi/oWtpvEwoanucy0Y+bD4WZZFJT10/Q+7Amq8wh6h8N88S6d4H 1PrV/V/GVIyCuvC60A7uCzzhzwSEfVxXRItEyQ8aQ5onamTxCe8YROVQkgRj3k0CvPyW re9Q== X-Gm-Message-State: AFuF++nXkXS+KWhvE6fXPMnqbTmytE/4YVIXc29FbOLQ69sSS5aoozbb b2PPiiBv8ylf7cnImcIAQmeey0CD0H9vs7lnOq4XX2iGzGx8i74q2G08WPg4pg== X-Gm-Gg: AYBFou225qLtZVw28Wh74BKWdHpKQJIyFHv9/o+Pb74G03AE4QxYnW1pcC1Rz6xbzZD NNFaHoafBaE2uVDnzojXP0bigi9bjxhburzuL0xEq34Q2fo09hrLNanQT8/dcEbojQwP+mW55mB 0jKSZ7NQjcTL4dM3LH/NP7IyyYCg9MuOVkHxpS3I3R649Sq+kW2h0YJpjyOz1/Aie/VNrkHkMe0 m9Ds8BMaqFg1HStnT6bGhoYEekZMxd7izTDVfup4N7zbtqTcE1QoB/eADfDqe3RDeX+NVfeccHa 0jz+IXkamjBZkURRGgO1Ls6uFn4LcEiKAywysRkukhTsi3M25EiuRABNZ4im+hMAV2uUfH1hEi0 HIe95r9g1HyL1EdeugBQNYdBh+eTBTC82gJnXUgioyCWARqE7/rOrn52blNvJ3v35b50Siqs+0W rmcYAHPVuzst8Wug32nnWQXG7n/7FM0a5vJD6qxzVi5svhetoUlZI+eQlFmrEJdnMSQBpJa2UCb CQVaV6U465ys2YFBFaPyB8= X-Received: by 2002:a05:6a00:3919:b0:86b:922d:6aa with SMTP id d2e1a72fcca58-87d1a5ad93cmr1757574b3a.1.1790160146001; Wed, 23 Sep 2026 03:42:26 -0700 (PDT) Received: from NVAPF55DW0D-IPD.. ([203.211.104.195]) by smtp.gmail.com with ESMTPSA id d2e1a72fcca58-87d1d5c1646sm1035870b3a.30.2026.09.23.03.42.23 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 23 Sep 2026 03:42:25 -0700 (PDT) From: ankur.tyagi85@gmail.com To: openembedded-devel@lists.openembedded.org Cc: Devansh Patel , Khem Raj , Ankur Tyagi Subject: [oe][meta-python][wrynose][PATCH 39/42] python3-flask: correct CVE_PRODUCT mapping Date: Wed, 23 Sep 2026 22:40:53 +1200 Message-ID: <20260923104056.457360-39-ankur.tyagi85@gmail.com> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260923104056.457360-1-ankur.tyagi85@gmail.com> References: <20260923104056.457360-1-ankur.tyagi85@gmail.com> MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Wed, 23 Sep 2026 10:42:27 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-devel/message/130226 From: Devansh Patel The current "flask" mapping emits the wildcard-vendor *:flask CPE instead of the exact NVD identity for the packaged pallets/flask source. Use "palletsprojects:flask", which is both an NVD dictionary CPE and an NVD configuration identity. CNA affected data uses "pallets:flask" and "The Pallets Project:Flask", which remain covered by scanner aliases. With sbom-cve-check 1.3.3 and the pinned 2026-08-12 data, the generated identity changes but the current CVE report does not. Signed-off-by: Devansh Patel Signed-off-by: Khem Raj (cherry picked from commit 6cbb85db1a06202d3e2422d51f6c31dae7bbc881) Signed-off-by: Ankur Tyagi --- meta-python/recipes-devtools/python/python3-flask_3.1.3.bb | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/meta-python/recipes-devtools/python/python3-flask_3.1.3.bb b/meta-python/recipes-devtools/python/python3-flask_3.1.3.bb index 559f781e7e..1e3890e7f5 100644 --- a/meta-python/recipes-devtools/python/python3-flask_3.1.3.bb +++ b/meta-python/recipes-devtools/python/python3-flask_3.1.3.bb @@ -8,7 +8,7 @@ LIC_FILES_CHKSUM = "file://LICENSE.txt;md5=ffeffa59c90c9c4a033c7574f8f3fb75" SRC_URI[sha256sum] = "0ef0e52b8a9cd932855379197dd8f94047b359ca0a78695144304cb45f87c9eb" -CVE_PRODUCT = "flask" +CVE_PRODUCT = "palletsprojects:flask" inherit pypi python_flit_core ptest-python-pytest From patchwork Wed Sep 23 10:40:54 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Ankur Tyagi X-Patchwork-Id: 99052 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 582D6C982EA for ; Wed, 23 Sep 2026 10:42:38 +0000 (UTC) Received: from mail-pz2-f12.google.com (mail-pz2-f12.google.com [74.125.228.12]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.4193.1790160148997723969 for ; Wed, 23 Sep 2026 03:42:29 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@gmail.com header.s=20251104 header.b=ENvWS+3E; spf=pass (domain: gmail.com, ip: 74.125.228.12, mailfrom: ankur.tyagi85@gmail.com) Received: by mail-pz2-f12.google.com with SMTP id d2e1a72fcca58-85469b35611so371731b3a.0 for ; Wed, 23 Sep 2026 03:42:28 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1790160148; x=1790764948; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=aRBfwQQd5KBzoYBcY10UxDu+nmP/ZlliUGQBaNOGdSM=; b=ENvWS+3Ef9DLogTar6xya8eQhBtljjqLCl2xakABuowBarVFdsyKlIicvVFxNisE6q 4Ryu9i+HzLxc4xj7C66A9RcMMXVf3CA56suIK+dsouFzLx3RROAM+HdAiAaGj8vSuSgx gGPcgRI9X8C8i+yMU7oWWighJI/qrcv3BG/blaCN17U4ySDOwpTZV08lL5jyxG8M2A9Z pAFXfOSmziylB+xyRXvlPPMkCn8G9UMA9LSkH11Du3boAPe92fVUZSEsmSszALRFmaWl xqJQjv2rmqAym/FV+unk9yFRoEysA5dppfeO6YlIKRyQZpzKF/yRLoxGs1Fwnnn3btc6 FMpg== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1790160148; x=1790764948; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=aRBfwQQd5KBzoYBcY10UxDu+nmP/ZlliUGQBaNOGdSM=; b=2kBOxUTO5sjdwqkj4EddmB/Fmw9LFf9i/yiad1lOB+BeiRx8kuFU0Av53k1CateFye ATYB60/9flcMDxznRr+FcmegK4lf1TEySOzsGr+CUK7Ib3AHw9b1v1zEkqrFJ1UpIFxq EokV6/b2DWvNVCYzmdIAgfPD9EZn60g8L00P9jGSih+lFfqJ8ZHIUArvnvos9yAN/xXn KVUe/FsKQcgFd4gIWV3nOx7fjIUHgPiCtRcpBCD8/4gpGFSIfx/6ApmAxOhc1jL2rDjq aGJIMfA7+91dtY63M97YNo2xbKPR4yZ/mwU42pCEcGjr7F3WYvEtNOmAio3CF/65LkbC y//w== X-Gm-Message-State: AFuF++nCnuRhYDEe2hwfFovUQmwIOaEDWj2lkX+lM2HhR1b7Sf4gX1bf JPWi0wAtGz2iXHHe6pK6rX24kKD3AZ1CaU/Ncn2oMAFVkJgwTeIooajAevxJTw== X-Gm-Gg: AYBFou3dBUegBJC+rAnE3VUr3ZagEbaN9QtWXJv7E7yYrbSdNCmR4q7TgO3ia3okE/c wEF5XyHQnvEf5wle5ndpGKb5Lm8gRWhuuTzrFJw78RSxhOiQKz9glQVPdjyPfZXztsBG9sd0xRT NicjVtNx5X6eF9gcbyQda85lLLuqSQGfXLXPvQJEozFWcqsLecjd3abc6tS1owbQ9YKESjQP7v3 wuXrvMaoBy7zyOo3W+7KH+wD9N5dHrVsVLKL93ivDIbvVF5+THBlZPiF6vhH3bOluXOhUm8omSn xqjL4RMVXLlQFvXnTPV/mVFdXFAw4YQ1inXuQytLiyT5zxMTxP0Uc1XJyz3e+D8kIPdrw8UIR9L QESXLWIzyRPEV4suAuD+SJkwmNISWdCUm9rytO5QGrMuNyIwwRDIPV5Yf2X4yCICO0/yzSkbxHH p9/rmAOhEn8qB9tpHnEfcPzVLZYRlclWPUw+p3sORZpgNXmdqMgmqU6kcn1yozse161i+qXTqbE IJwloUwZxoGwKgnD+GlnPs= X-Received: by 2002:a05:6a00:1a03:b0:87d:3894:1994 with SMTP id d2e1a72fcca58-87d389421c6mr1310911b3a.49.1790160148395; Wed, 23 Sep 2026 03:42:28 -0700 (PDT) Received: from NVAPF55DW0D-IPD.. ([203.211.104.195]) by smtp.gmail.com with ESMTPSA id d2e1a72fcca58-87d1d5c1646sm1035870b3a.30.2026.09.23.03.42.26 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 23 Sep 2026 03:42:28 -0700 (PDT) From: ankur.tyagi85@gmail.com To: openembedded-devel@lists.openembedded.org Cc: Devansh Patel , Khem Raj , Ankur Tyagi Subject: [oe][meta-python][wrynose][PATCH 40/42] python3-twitter: correct Tweepy CVE_PRODUCT mapping Date: Wed, 23 Sep 2026 22:40:54 +1200 Message-ID: <20260923104056.457360-40-ankur.tyagi85@gmail.com> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260923104056.457360-1-ankur.tyagi85@gmail.com> References: <20260923104056.457360-1-ankur.tyagi85@gmail.com> MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Wed, 23 Sep 2026 10:42:38 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-devel/message/130227 From: Devansh Patel The product-only "tweepy" value emits a wildcard-vendor identity and hides the distinct NVD identities assigned to the packaged Tweepy source. Use "josh_roesslein:tweepy" for its NVD dictionary CPE and "tweepy:tweepy" for the NVD configuration-only identity. With sbom-cve-check 1.3.3 and the pinned database snapshots, the generated product identity changes; the current CVE report is unchanged. Signed-off-by: Devansh Patel Signed-off-by: Khem Raj (cherry picked from commit 46ca829b6566349ed02dd9bd4209d3c7ff50586b) Signed-off-by: Ankur Tyagi --- meta-python/recipes-devtools/python/python3-twitter_4.16.0.bb | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/meta-python/recipes-devtools/python/python3-twitter_4.16.0.bb b/meta-python/recipes-devtools/python/python3-twitter_4.16.0.bb index ad05e0ac47..bece398e3c 100644 --- a/meta-python/recipes-devtools/python/python3-twitter_4.16.0.bb +++ b/meta-python/recipes-devtools/python/python3-twitter_4.16.0.bb @@ -18,5 +18,5 @@ RDEPENDS:${PN} += "\ python3-six \ " -CVE_PRODUCT = "tweepy" +CVE_PRODUCT = "josh_roesslein:tweepy tweepy:tweepy" CVE_STATUS[CVE-2012-5825] = "fixed-version: The vulnerability has been fixed since v3.1.0" From patchwork Wed Sep 23 10:40:55 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Ankur Tyagi X-Patchwork-Id: 99053 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 67BCCC982FA for ; Wed, 23 Sep 2026 10:42:38 +0000 (UTC) Received: from mail-pz2-f40.google.com (mail-pz2-f40.google.com [74.125.228.40]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.4306.1790160151624420651 for ; Wed, 23 Sep 2026 03:42:31 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@gmail.com header.s=20251104 header.b=pKlvmWe6; spf=pass (domain: gmail.com, ip: 74.125.228.40, mailfrom: ankur.tyagi85@gmail.com) Received: by mail-pz2-f40.google.com with SMTP id d2e1a72fcca58-8748f34b1f2so433751b3a.0 for ; Wed, 23 Sep 2026 03:42:31 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1790160151; x=1790764951; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=PBOlZYakJTeItuWBXbxFRqepudTuhK8bj/ZDlf59yEY=; b=pKlvmWe64VE6NlV4wSkRKs2+iWM6gSYdEUa6WQGhNbOfvJ2bOj1XWgSCI+8v0RM58Z jJpBTtC2JmO7FLvT/CehvqJLTTiWaa6UCcqUd8IM4No703aPkI0eYrK680jjxrKGLSRm ENCME81bK+6yEzWKxI8/J0T85zlZB7JkznbBm2Y/KLZiFI7SeYekSOkrnDZ5ns8F9oF1 i1zTbYw6J+DEY/dN30KXw+iP/ZQ1/WweEZv1vmlpoDopYybLx11XKx626mi/oo/KhIko J33JgVhtz8vZOuUGw0QoLseMfXIdP0PhCjeN/QQhTfyYJKhCRkWpWaCMfgCFTeaYKjyq 3xhQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1790160151; x=1790764951; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=PBOlZYakJTeItuWBXbxFRqepudTuhK8bj/ZDlf59yEY=; b=WY9zYShzlva5IBsRhy+wNvXh8+gbGAAYUSTE3cPa8NEKJSpYOcQc2G8j/qYnyDuOsR 2JQv5TihCP4ipFSZM+gf5BQoHxTBx6uheOcVq2zliHlxtGEC/mjTawLTViK5LjL1rb4Y Bw7xiWq0UGQDefZ+k4fmZce8cVN4eReKmxWfCInIWYeA8ulO8GEBbbQF+GKi7CGvqhKS ByET6+6tuMeWZcd8FULr7nQQzgD2UvebAwv28S2YHO2EhYIyDzTn+J3YR/fvRr5b7qXr PwtUf01B5+mNZDdFVUMdZLGUZX9MT1pJysAMEkVlVaYen3uaO5MxKlEaeAYuZHlHqjTW ZGYg== X-Gm-Message-State: AFuF++kbjVwyIXzA6f8bKOye8l1ntrjYyC9h2PJUsmspcn/hJq1h3WEo efqsG/xFdxjPyAzpTQ55Xk4seRjd3nxKMC6eruZI/nDyygNdhKYqIDD/enCb9g== X-Gm-Gg: AYBFou1dKEdxAnzK8rxvc+WsbjxZysI3aLgyk3blMFdi4KYu8e6Mg4UIIkReOp5KW3s x0ZcwQTQJc1H4AP3uzfkkvDYkc+IQ4+kjVbGHK9O/xqa0JsRinUUsHT3vytPcfVHW9+NWs8wR7a 1iUrYOsnOeI4jXYoyIguEBSvttQypwgYcHW1mKh3nCF2y55xM94OWjM0L09l80C6THH6sIER3f1 0w5dUykYAjChUjgn1zjpZGOztc21jt0CIQp4eop+j+ZywPCO2w5MUeyz8P22SQSHsUYgc4kKZVC 4KzQP8I7aEfeaaEsaOVaKHv8+8ja721zHC06VNPU+Qg5ogXQxiaWC+1pm4sq5L2JzwTDi8HZ2pM FN1OMNNxbd5omKEPGR3GJWEE+97RhScGMNJueR+J6K8Is2e0ZmCEho7kQAowu2tnnWU4L3fm+7x PShM/OoKEc2Ieo5EgAPo4WuNa39VIarmWTVKerHMivdnw9Skt8qR0qCTWIqCMSHgUMGiUnO1/mR 6Yv7Wj8u19hpfnEDZRWIXg= X-Received: by 2002:a05:6a00:438c:b0:874:705d:f651 with SMTP id d2e1a72fcca58-87d1b3b1e39mr1925036b3a.31.1790160151001; Wed, 23 Sep 2026 03:42:31 -0700 (PDT) Received: from NVAPF55DW0D-IPD.. ([203.211.104.195]) by smtp.gmail.com with ESMTPSA id d2e1a72fcca58-87d1d5c1646sm1035870b3a.30.2026.09.23.03.42.28 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 23 Sep 2026 03:42:30 -0700 (PDT) From: ankur.tyagi85@gmail.com To: openembedded-devel@lists.openembedded.org Cc: Devansh Patel , Khem Raj , Ankur Tyagi Subject: [oe][meta-python][wrynose][PATCH 41/42] python3-ujson: add CVE_PRODUCT mapping Date: Wed, 23 Sep 2026 22:40:55 +1200 Message-ID: <20260923104056.457360-41-ankur.tyagi85@gmail.com> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260923104056.457360-1-ankur.tyagi85@gmail.com> References: <20260923104056.457360-1-ankur.tyagi85@gmail.com> MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Wed, 23 Sep 2026 10:42:38 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-devel/message/130228 From: Devansh Patel The current inherited "python:ujson" mapping does not match the UltraJSON identities used by NVD and CVE List V5, so source-aligned CVEs are missed. Use "ultrajson:ultrajson" for the CNA affected-data identity and "ultrajson_project:ultrajson" for the NVD dictionary CPE and configuration identity. Signed-off-by: Devansh Patel Signed-off-by: Khem Raj (cherry picked from commit 7a393253ec09d90c67043201bb0f29e7613930a6) Signed-off-by: Ankur Tyagi --- meta-python/recipes-devtools/python/python3-ujson_5.12.1.bb | 2 ++ 1 file changed, 2 insertions(+) diff --git a/meta-python/recipes-devtools/python/python3-ujson_5.12.1.bb b/meta-python/recipes-devtools/python/python3-ujson_5.12.1.bb index 89311254a8..abcda88c8b 100644 --- a/meta-python/recipes-devtools/python/python3-ujson_5.12.1.bb +++ b/meta-python/recipes-devtools/python/python3-ujson_5.12.1.bb @@ -8,6 +8,8 @@ SRC_URI += "file://CVE-2026-54911.patch" SRC_URI[sha256sum] = "5b7e96406c301a1366534479a7352ec40ec68bb327c0c119091635acd5925e35" +CVE_PRODUCT = "ultrajson:ultrajson ultrajson_project:ultrajson" + inherit pypi ptest-python-pytest python_setuptools_build_meta # let OE do the strip operation From patchwork Wed Sep 23 10:40:56 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Ankur Tyagi X-Patchwork-Id: 99054 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 96B1DC98309 for ; Wed, 23 Sep 2026 10:42:38 +0000 (UTC) Received: from mail-pz2-f12.google.com (mail-pz2-f12.google.com [74.125.228.12]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.4307.1790160154100859863 for ; Wed, 23 Sep 2026 03:42:34 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@gmail.com header.s=20251104 header.b=k8e6MftF; spf=pass (domain: gmail.com, ip: 74.125.228.12, mailfrom: ankur.tyagi85@gmail.com) Received: by mail-pz2-f12.google.com with SMTP id d2e1a72fcca58-8693af0d7c4so487476b3a.3 for ; Wed, 23 Sep 2026 03:42:34 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1790160153; x=1790764953; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=t4dJk3pgpSyPa5IIgpnm6ukA0Iw2kx8nb0J697Cjo8o=; b=k8e6MftFvIioVoH0XBmKnrWjuP6OPRdCvKQGqmhMnVdUeGyzfnZy303Cn5JCO16TwT GXLR5beHiv22q7ACjvL+SPsivQXzUyx02Tt2epA8cLpvD/li7rS+1heM4JWY92rx1nel l3M0bs6eetjQsfMapQU1DU/L3RI1/JR/4AiGBUh/8dMA2PuCuxdQl5wCH25XUgPJI874 pj1LwDjMx7OhK6i5ne1i8eZWoqCzEk3CVeLCJN1rxe2b2GDd7SgU2tDpLzJu3GP4rFIv 7XlhZ8G8Z6jUXymep5VxZzrsNSnIBY30WwLQpMmePh0ENb7xC/FH8HP73OKzbT5+jyms 57Yg== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1790160153; x=1790764953; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=t4dJk3pgpSyPa5IIgpnm6ukA0Iw2kx8nb0J697Cjo8o=; b=j/ueYcI2tuHiVX28G9J1+Hw8Bi+oSEasulyZwBjf0+nhS4eHLfMSdQjcBqW9f+8OeJ S4F+5vunNS7S+ELGDT0RykwFde/LHAlCWmQ0ZWnQoVDq7tVIhK+KweL2yzfJQnK3Rhpw nD9SMAouRkipaTuxG0xIck8RJ71uUoPkhhDoHAGMXS0wLJIhDjpYp0grlpmhys/3iS2K 5Aa89KQPd3SvCqdEptsEhGXiS8V0rvCQWsY1qZTvfZtcvKK4HJpa+P6e24p+dTEVpv5G Gr3lWWtNqPEz9sMaykxcBZg1dMnA0k+V5tU7ZW/Skvm8i/Zezgg2p6D/SIM4enrD1wR1 NLNg== X-Gm-Message-State: AFuF++npaVO5Z+7rKFGZASXx1mZXF4LfPLNCqpaFT2qp6YIk4R7STXlu 41I3Tm0awNnh4pd5grjsjU/X//EgO3TCXSgoCsidTNl8AGANHChEp6NG/lhgug== X-Gm-Gg: AYBFou1t0z2ahqh3k1Z/oV9sF0uRCJMRVfMdIXcaH3uooTBg3D4FIMn+RLgQfoyun6P 97rKlWccdh6IGX1B/W92ITIC+DbE+OjrbRRekSGGAath6KiAoNQVEVWZ+2i/vdEb9CyyJFUTln9 iVVng9KH9sptwgR1ALl081V7Bwo6nJXGdl+keKv3XN+7XwFO0dqY1DlHEktqJBGJlzec3dq1AYn /RScZen/tzs8C9FsJPmTYaobScIwIxtT7BMfVEQO4IqMecHSa7frePlIFkvf/Wiurve0zmTir+D 3gM2xdlXeIKUR98JawCzkMNpuP830FTyC3YGwF18nXHmHcohIygiH3YIMK+WDei36wt9liQL5Ab jPgnwNCN800D+4TbMHI0USX+b2vKyWAhox6uXFJ0KuPvli5Lm5LgHoh0Gp/mpuJHYFyutnPQHX/ I2mI0g06nVhbyzHtvz7QK+jkPTWL1rWZCr+1W8CrR07LMBIkpHPJ19u7/CUhOrQuaoEhWqOPy9g NQXr8lEGmMszFOJqVqd47x0YU2RJ41IKw== X-Received: by 2002:a05:6a20:734b:b0:3dd:a197:cf36 with SMTP id adf61e73a8af0-3ddf82e3484mr1985496637.90.1790160153478; Wed, 23 Sep 2026 03:42:33 -0700 (PDT) Received: from NVAPF55DW0D-IPD.. ([203.211.104.195]) by smtp.gmail.com with ESMTPSA id d2e1a72fcca58-87d1d5c1646sm1035870b3a.30.2026.09.23.03.42.31 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 23 Sep 2026 03:42:33 -0700 (PDT) From: ankur.tyagi85@gmail.com To: openembedded-devel@lists.openembedded.org Cc: Devansh Patel , Khem Raj , Ankur Tyagi Subject: [oe][meta-python][wrynose][PATCH 42/42] python3-waitress: correct CVE_PRODUCT mapping Date: Wed, 23 Sep 2026 22:40:56 +1200 Message-ID: <20260923104056.457360-42-ankur.tyagi85@gmail.com> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260923104056.457360-1-ankur.tyagi85@gmail.com> References: <20260923104056.457360-1-ankur.tyagi85@gmail.com> MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Wed, 23 Sep 2026 10:42:38 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-devel/message/130229 From: Devansh Patel The current product-only "waitress" mapping emits a wildcard-vendor identity instead of the exact identities assigned to the packaged Pylons source. Use "pylons:waitress" for the CNA affected-data identity and "agendaless:waitress" for the NVD dictionary CPE and configuration identity. This changes the generated product identity, but sbom-cve-check 1.3.3 with the pinned databases leaves the current CVE report unchanged. Signed-off-by: Devansh Patel Signed-off-by: Khem Raj (cherry picked from commit ae093476ee04288893bec6d37bb15802210ded2e) Signed-off-by: Ankur Tyagi --- meta-python/recipes-devtools/python/python3-waitress_3.0.2.bb | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/meta-python/recipes-devtools/python/python3-waitress_3.0.2.bb b/meta-python/recipes-devtools/python/python3-waitress_3.0.2.bb index cc705f4efe..1a30e3a058 100644 --- a/meta-python/recipes-devtools/python/python3-waitress_3.0.2.bb +++ b/meta-python/recipes-devtools/python/python3-waitress_3.0.2.bb @@ -6,7 +6,7 @@ SECTION = "devel/python" LICENSE = "ZPL-2.1" LIC_FILES_CHKSUM = "file://LICENSE.txt;md5=78ccb3640dc841e1baecb3e27a6966b2" -CVE_PRODUCT = "waitress" +CVE_PRODUCT = "pylons:waitress agendaless:waitress" RDEPENDS:${PN} += " \ python3-logging \