* [OE-core][wrynose][patch 1/3] p11-kit: upgrade 0.26.2 -> 0.26.4
@ 2026-08-14 10:19 Vijay Anusuri
2026-08-14 10:19 ` [OE-core][wrynose][patch 2/3] p11-kit: set status for CVE-2026-13757 Vijay Anusuri
2026-08-14 10:19 ` [OE-core][wrynose][patch 3/3] p11-kit: upgrade 0.26.4 -> 0.26.5 Vijay Anusuri
0 siblings, 2 replies; 6+ messages in thread
From: Vijay Anusuri @ 2026-08-14 10:19 UTC (permalink / raw)
To: openembedded-core; +Cc: Richard Purdie, Vijay Anusuri
From: Richard Purdie <richard.purdie@linuxfoundation.org>
ChangeLog:
https://github.com/p11-glue/p11-kit/releases/tag/0.26.4
https://github.com/p11-glue/p11-kit/releases/tag/0.26.3
Fixes CVE-2026-13757
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
(cherry picked from commit 4e58b57cdc5e25d6cb12b658f09fea7c91835430)
Signed-off-by: Vijay Anusuri <vanusuri@mvista.com>
---
.../p11-kit/{p11-kit_0.26.2.bb => p11-kit_0.26.4.bb} | 2 ++
1 file changed, 2 insertions(+)
rename meta/recipes-support/p11-kit/{p11-kit_0.26.2.bb => p11-kit_0.26.4.bb} (94%)
diff --git a/meta/recipes-support/p11-kit/p11-kit_0.26.2.bb b/meta/recipes-support/p11-kit/p11-kit_0.26.4.bb
similarity index 94%
rename from meta/recipes-support/p11-kit/p11-kit_0.26.2.bb
rename to meta/recipes-support/p11-kit/p11-kit_0.26.4.bb
index 5f553f11bb..ecf7500b13 100644
--- a/meta/recipes-support/p11-kit/p11-kit_0.26.2.bb
+++ b/meta/recipes-support/p11-kit/p11-kit_0.26.4.bb
@@ -13,6 +13,8 @@ DEPENDS:append = "${@' glib-2.0' if d.getVar('GTKDOC_ENABLED') == 'True' else ''
SRC_URI = "gitsm://github.com/p11-glue/p11-kit;branch=master;protocol=https;tag=${PV} \
"
SRCREV = "8e6e4e6d64d9fe91c62b0052c105b2b72d4c24ef"
+SRC_URI = "gitsm://github.com/p11-glue/p11-kit;branch=master;protocol=https;tag=${PV}"
+SRCREV = "a14788849d1ef44422d679534a13821eab5bb5f4"
PACKAGECONFIG ??= ""
PACKAGECONFIG[manpages] = "-Dman=true,-Dman=false,libxslt-native"
--
2.43.0
^ permalink raw reply related [flat|nested] 6+ messages in thread
* [OE-core][wrynose][patch 2/3] p11-kit: set status for CVE-2026-13757
2026-08-14 10:19 [OE-core][wrynose][patch 1/3] p11-kit: upgrade 0.26.2 -> 0.26.4 Vijay Anusuri
@ 2026-08-14 10:19 ` Vijay Anusuri
2026-08-14 10:19 ` [OE-core][wrynose][patch 3/3] p11-kit: upgrade 0.26.4 -> 0.26.5 Vijay Anusuri
1 sibling, 0 replies; 6+ messages in thread
From: Vijay Anusuri @ 2026-08-14 10:19 UTC (permalink / raw)
To: openembedded-core; +Cc: Peter Marko, Richard Purdie, Vijay Anusuri
From: Peter Marko <peter.marko@siemens.com>
This is a RedHat version-less CVE.
Per [1] this is fixed in 0.26.3.
[1] https://security-tracker.debian.org/tracker/CVE-2026-13757
Signed-off-by: Peter Marko <peter.marko@siemens.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
(cherry picked from commit 3bb664fbba47febc9c26dd7f7965e508870a023f)
Signed-off-by: Vijay Anusuri <vanusuri@mvista.com>
---
meta/recipes-support/p11-kit/p11-kit_0.26.4.bb | 1 +
1 file changed, 1 insertion(+)
diff --git a/meta/recipes-support/p11-kit/p11-kit_0.26.4.bb b/meta/recipes-support/p11-kit/p11-kit_0.26.4.bb
index ecf7500b13..9219e9eefc 100644
--- a/meta/recipes-support/p11-kit/p11-kit_0.26.4.bb
+++ b/meta/recipes-support/p11-kit/p11-kit_0.26.4.bb
@@ -46,3 +46,4 @@ BBCLASSEXTEND = "native nativesdk"
CFLAGS += "-Wno-error=incompatible-pointer-types"
CVE_STATUS[CVE-2026-2100] = "fixed-version: fixed since 0.26.2"
+CVE_STATUS[CVE-2026-13757] = "fixed-version: fixed since 0.26.3"
--
2.43.0
^ permalink raw reply related [flat|nested] 6+ messages in thread
* [OE-core][wrynose][patch 3/3] p11-kit: upgrade 0.26.4 -> 0.26.5
2026-08-14 10:19 [OE-core][wrynose][patch 1/3] p11-kit: upgrade 0.26.2 -> 0.26.4 Vijay Anusuri
2026-08-14 10:19 ` [OE-core][wrynose][patch 2/3] p11-kit: set status for CVE-2026-13757 Vijay Anusuri
@ 2026-08-14 10:19 ` Vijay Anusuri
2026-08-26 16:26 ` Vijay Anusuri
1 sibling, 1 reply; 6+ messages in thread
From: Vijay Anusuri @ 2026-08-14 10:19 UTC (permalink / raw)
To: openembedded-core; +Cc: Jaipaul Cheernam, Richard Purdie, Vijay Anusuri
From: Jaipaul Cheernam <jaipaul.cheernam@est.tech>
ChangeLog: https://github.com/p11-glue/p11-kit/releases/tag/0.26.5
0.26.5 (stable)
* rpc: guard against overflow when decoding nested attributes (CVE-2026-18938) [PR#777]
Signed-off-by: Jaipaul Cheernam <jaipaul.cheernam@est.tech>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
(cherry picked from commit 21a2c91ccca5257ede8994d30460b0dcda617c3a)
Signed-off-by: Vijay Anusuri <vanusuri@mvista.com>
---
.../p11-kit/{p11-kit_0.26.4.bb => p11-kit_0.26.5.bb} | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
rename meta/recipes-support/p11-kit/{p11-kit_0.26.4.bb => p11-kit_0.26.5.bb} (98%)
diff --git a/meta/recipes-support/p11-kit/p11-kit_0.26.4.bb b/meta/recipes-support/p11-kit/p11-kit_0.26.5.bb
similarity index 98%
rename from meta/recipes-support/p11-kit/p11-kit_0.26.4.bb
rename to meta/recipes-support/p11-kit/p11-kit_0.26.5.bb
index 9219e9eefc..8229cf96c9 100644
--- a/meta/recipes-support/p11-kit/p11-kit_0.26.4.bb
+++ b/meta/recipes-support/p11-kit/p11-kit_0.26.5.bb
@@ -14,7 +14,7 @@ SRC_URI = "gitsm://github.com/p11-glue/p11-kit;branch=master;protocol=https;tag=
"
SRCREV = "8e6e4e6d64d9fe91c62b0052c105b2b72d4c24ef"
SRC_URI = "gitsm://github.com/p11-glue/p11-kit;branch=master;protocol=https;tag=${PV}"
-SRCREV = "a14788849d1ef44422d679534a13821eab5bb5f4"
+SRCREV = "120050e353e8f43d7c40bbcc047f667f903f4de5"
PACKAGECONFIG ??= ""
PACKAGECONFIG[manpages] = "-Dman=true,-Dman=false,libxslt-native"
--
2.43.0
^ permalink raw reply related [flat|nested] 6+ messages in thread
* Re: [OE-core][wrynose][patch 3/3] p11-kit: upgrade 0.26.4 -> 0.26.5
2026-08-14 10:19 ` [OE-core][wrynose][patch 3/3] p11-kit: upgrade 0.26.4 -> 0.26.5 Vijay Anusuri
@ 2026-08-26 16:26 ` Vijay Anusuri
2026-08-26 16:46 ` Yoann Congal
0 siblings, 1 reply; 6+ messages in thread
From: Vijay Anusuri @ 2026-08-26 16:26 UTC (permalink / raw)
To: openembedded-core, Yoann Congal; +Cc: Jaipaul Cheernam, Richard Purdie
[-- Attachment #1: Type: text/plain, Size: 2044 bytes --]
Hi Yoann,
I couldn't find this patch in the wrynose-nut branch, while the other two
patches in the series are available.
Could you please check if this patch was missed during the merge?
Thanks & Regards,
Vijay
On Fri, Aug 14, 2026 at 3:50 PM Vijay Anusuri <vanusuri@mvista.com> wrote:
> From: Jaipaul Cheernam <jaipaul.cheernam@est.tech>
>
> ChangeLog: https://github.com/p11-glue/p11-kit/releases/tag/0.26.5
>
> 0.26.5 (stable)
> * rpc: guard against overflow when decoding nested attributes
> (CVE-2026-18938) [PR#777]
>
> Signed-off-by: Jaipaul Cheernam <jaipaul.cheernam@est.tech>
> Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
> (cherry picked from commit 21a2c91ccca5257ede8994d30460b0dcda617c3a)
> Signed-off-by: Vijay Anusuri <vanusuri@mvista.com>
> ---
> .../p11-kit/{p11-kit_0.26.4.bb => p11-kit_0.26.5.bb} | 2 +-
> 1 file changed, 1 insertion(+), 1 deletion(-)
> rename meta/recipes-support/p11-kit/{p11-kit_0.26.4.bb =>
> p11-kit_0.26.5.bb} (98%)
>
> diff --git a/meta/recipes-support/p11-kit/p11-kit_0.26.4.bb
> b/meta/recipes-support/p11-kit/p11-kit_0.26.5.bb
> similarity index 98%
> rename from meta/recipes-support/p11-kit/p11-kit_0.26.4.bb
> rename to meta/recipes-support/p11-kit/p11-kit_0.26.5.bb
> index 9219e9eefc..8229cf96c9 100644
> --- a/meta/recipes-support/p11-kit/p11-kit_0.26.4.bb
> +++ b/meta/recipes-support/p11-kit/p11-kit_0.26.5.bb
> @@ -14,7 +14,7 @@ SRC_URI = "gitsm://
> github.com/p11-glue/p11-kit;branch=master;protocol=https;tag=
> "
> SRCREV = "8e6e4e6d64d9fe91c62b0052c105b2b72d4c24ef"
> SRC_URI = "gitsm://
> github.com/p11-glue/p11-kit;branch=master;protocol=https;tag=${PV}
> <http://github.com/p11-glue/p11-kit;branch=master;protocol=https;tag=$%7BPV%7D>
> "
> -SRCREV = "a14788849d1ef44422d679534a13821eab5bb5f4"
> +SRCREV = "120050e353e8f43d7c40bbcc047f667f903f4de5"
>
> PACKAGECONFIG ??= ""
> PACKAGECONFIG[manpages] = "-Dman=true,-Dman=false,libxslt-native"
> --
> 2.43.0
>
>
[-- Attachment #2: Type: text/html, Size: 3782 bytes --]
^ permalink raw reply [flat|nested] 6+ messages in thread
* Re: [OE-core][wrynose][patch 3/3] p11-kit: upgrade 0.26.4 -> 0.26.5
2026-08-26 16:26 ` Vijay Anusuri
@ 2026-08-26 16:46 ` Yoann Congal
2026-08-26 16:49 ` Vijay Anusuri
0 siblings, 1 reply; 6+ messages in thread
From: Yoann Congal @ 2026-08-26 16:46 UTC (permalink / raw)
To: Vijay Anusuri, openembedded-core; +Cc: Jaipaul Cheernam, Richard Purdie
On Wed Aug 26, 2026 at 6:26 PM CEST, Vijay Anusuri wrote:
> Hi Yoann,
>
> I couldn't find this patch in the wrynose-nut branch, while the other two
> patches in the series are available.
>
> Could you please check if this patch was missed during the merge?
Hello,
What you saw is part of the series from Peter Marko that does not have
the 0.26.4 -> .5 upgrade.
I'll review my current -nut branch first to send a review series. Then
I'll add your "[wrynose][patch 3/3] p11-kit: upgrade 0.26.4 -> 0.26.5"
in the next series.
The queue is ~160 patches long right now, I can't take all of this in
one go.
Thanks for your attention and patience.
Regards,
>
>
> Thanks & Regards,
> Vijay
>
>
> On Fri, Aug 14, 2026 at 3:50 PM Vijay Anusuri <vanusuri@mvista.com> wrote:
>
>> From: Jaipaul Cheernam <jaipaul.cheernam@est.tech>
>>
>> ChangeLog: https://github.com/p11-glue/p11-kit/releases/tag/0.26.5
>>
>> 0.26.5 (stable)
>> * rpc: guard against overflow when decoding nested attributes
>> (CVE-2026-18938) [PR#777]
>>
>> Signed-off-by: Jaipaul Cheernam <jaipaul.cheernam@est.tech>
>> Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
>> (cherry picked from commit 21a2c91ccca5257ede8994d30460b0dcda617c3a)
>> Signed-off-by: Vijay Anusuri <vanusuri@mvista.com>
>> ---
>> .../p11-kit/{p11-kit_0.26.4.bb => p11-kit_0.26.5.bb} | 2 +-
>> 1 file changed, 1 insertion(+), 1 deletion(-)
>> rename meta/recipes-support/p11-kit/{p11-kit_0.26.4.bb =>
>> p11-kit_0.26.5.bb} (98%)
>>
>> diff --git a/meta/recipes-support/p11-kit/p11-kit_0.26.4.bb
>> b/meta/recipes-support/p11-kit/p11-kit_0.26.5.bb
>> similarity index 98%
>> rename from meta/recipes-support/p11-kit/p11-kit_0.26.4.bb
>> rename to meta/recipes-support/p11-kit/p11-kit_0.26.5.bb
>> index 9219e9eefc..8229cf96c9 100644
>> --- a/meta/recipes-support/p11-kit/p11-kit_0.26.4.bb
>> +++ b/meta/recipes-support/p11-kit/p11-kit_0.26.5.bb
>> @@ -14,7 +14,7 @@ SRC_URI = "gitsm://
>> github.com/p11-glue/p11-kit;branch=master;protocol=https;tag=
>> "
>> SRCREV = "8e6e4e6d64d9fe91c62b0052c105b2b72d4c24ef"
>> SRC_URI = "gitsm://
>> github.com/p11-glue/p11-kit;branch=master;protocol=https;tag=${PV}
>> <http://github.com/p11-glue/p11-kit;branch=master;protocol=https;tag=$%7BPV%7D>
>> "
>> -SRCREV = "a14788849d1ef44422d679534a13821eab5bb5f4"
>> +SRCREV = "120050e353e8f43d7c40bbcc047f667f903f4de5"
>>
>> PACKAGECONFIG ??= ""
>> PACKAGECONFIG[manpages] = "-Dman=true,-Dman=false,libxslt-native"
>> --
>> 2.43.0
>>
>>
--
Yoann Congal
Smile ECS
^ permalink raw reply [flat|nested] 6+ messages in thread
* Re: [OE-core][wrynose][patch 3/3] p11-kit: upgrade 0.26.4 -> 0.26.5
2026-08-26 16:46 ` Yoann Congal
@ 2026-08-26 16:49 ` Vijay Anusuri
0 siblings, 0 replies; 6+ messages in thread
From: Vijay Anusuri @ 2026-08-26 16:49 UTC (permalink / raw)
To: Yoann Congal; +Cc: openembedded-core, Jaipaul Cheernam, Richard Purdie
[-- Attachment #1: Type: text/plain, Size: 3151 bytes --]
Hi Yoann,
Thanks for the clarification.
Understood. I'll wait for the next review series. Thanks for taking care of
it, and I appreciate your time and effort.
Thanks & Regards,
Vijay
On Wed, Aug 26, 2026 at 10:17 PM Yoann Congal <yoann.congal@smile.fr> wrote:
> On Wed Aug 26, 2026 at 6:26 PM CEST, Vijay Anusuri wrote:
> > Hi Yoann,
> >
> > I couldn't find this patch in the wrynose-nut branch, while the other two
> > patches in the series are available.
> >
> > Could you please check if this patch was missed during the merge?
>
> Hello,
>
> What you saw is part of the series from Peter Marko that does not have
> the 0.26.4 -> .5 upgrade.
>
> I'll review my current -nut branch first to send a review series. Then
> I'll add your "[wrynose][patch 3/3] p11-kit: upgrade 0.26.4 -> 0.26.5"
> in the next series.
>
> The queue is ~160 patches long right now, I can't take all of this in
> one go.
>
> Thanks for your attention and patience.
>
> Regards,
>
> >
> >
> > Thanks & Regards,
> > Vijay
> >
> >
> > On Fri, Aug 14, 2026 at 3:50 PM Vijay Anusuri <vanusuri@mvista.com>
> wrote:
> >
> >> From: Jaipaul Cheernam <jaipaul.cheernam@est.tech>
> >>
> >> ChangeLog: https://github.com/p11-glue/p11-kit/releases/tag/0.26.5
> >>
> >> 0.26.5 (stable)
> >> * rpc: guard against overflow when decoding nested attributes
> >> (CVE-2026-18938) [PR#777]
> >>
> >> Signed-off-by: Jaipaul Cheernam <jaipaul.cheernam@est.tech>
> >> Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
> >> (cherry picked from commit 21a2c91ccca5257ede8994d30460b0dcda617c3a)
> >> Signed-off-by: Vijay Anusuri <vanusuri@mvista.com>
> >> ---
> >> .../p11-kit/{p11-kit_0.26.4.bb => p11-kit_0.26.5.bb} | 2 +-
> >> 1 file changed, 1 insertion(+), 1 deletion(-)
> >> rename meta/recipes-support/p11-kit/{p11-kit_0.26.4.bb =>
> >> p11-kit_0.26.5.bb} (98%)
> >>
> >> diff --git a/meta/recipes-support/p11-kit/p11-kit_0.26.4.bb
> >> b/meta/recipes-support/p11-kit/p11-kit_0.26.5.bb
> >> similarity index 98%
> >> rename from meta/recipes-support/p11-kit/p11-kit_0.26.4.bb
> >> rename to meta/recipes-support/p11-kit/p11-kit_0.26.5.bb
> >> index 9219e9eefc..8229cf96c9 100644
> >> --- a/meta/recipes-support/p11-kit/p11-kit_0.26.4.bb
> >> +++ b/meta/recipes-support/p11-kit/p11-kit_0.26.5.bb
> >> @@ -14,7 +14,7 @@ SRC_URI = "gitsm://
> >> github.com/p11-glue/p11-kit;branch=master;protocol=https;tag=
> >> "
> >> SRCREV = "8e6e4e6d64d9fe91c62b0052c105b2b72d4c24ef"
> >> SRC_URI = "gitsm://
> >> github.com/p11-glue/p11-kit;branch=master;protocol=https;tag=${PV}
> <http://github.com/p11-glue/p11-kit;branch=master;protocol=https;tag=$%7BPV%7D>
> >> <
> http://github.com/p11-glue/p11-kit;branch=master;protocol=https;tag=$%7BPV%7D
> >
> >> "
> >> -SRCREV = "a14788849d1ef44422d679534a13821eab5bb5f4"
> >> +SRCREV = "120050e353e8f43d7c40bbcc047f667f903f4de5"
> >>
> >> PACKAGECONFIG ??= ""
> >> PACKAGECONFIG[manpages] = "-Dman=true,-Dman=false,libxslt-native"
> >> --
> >> 2.43.0
> >>
> >>
>
>
> --
> Yoann Congal
> Smile ECS
>
>
[-- Attachment #2: Type: text/html, Size: 5492 bytes --]
^ permalink raw reply [flat|nested] 6+ messages in thread
end of thread, other threads:[~2026-08-26 16:50 UTC | newest]
Thread overview: 6+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-08-14 10:19 [OE-core][wrynose][patch 1/3] p11-kit: upgrade 0.26.2 -> 0.26.4 Vijay Anusuri
2026-08-14 10:19 ` [OE-core][wrynose][patch 2/3] p11-kit: set status for CVE-2026-13757 Vijay Anusuri
2026-08-14 10:19 ` [OE-core][wrynose][patch 3/3] p11-kit: upgrade 0.26.4 -> 0.26.5 Vijay Anusuri
2026-08-26 16:26 ` Vijay Anusuri
2026-08-26 16:46 ` Yoann Congal
2026-08-26 16:49 ` Vijay Anusuri
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.