* [oe][meta-oe][wrynose][PATCH 2/28] asyncmqtt: upgrade 10.3.0 -> 10.3.1
2026-09-02 10:04 [oe][meta-oe][wrynose][PATCH 1/28] libmxml: upgrade 4.0.4 -> 4.0.5 ankur.tyagi85
@ 2026-09-02 10:04 ` ankur.tyagi85
2026-09-02 10:04 ` [oe][meta-oe][wrynose][PATCH 3/28] php: upgrade 8.5.9 -> 8.5.10 ankur.tyagi85
` (25 subsequent siblings)
26 siblings, 0 replies; 28+ messages in thread
From: ankur.tyagi85 @ 2026-09-02 10:04 UTC (permalink / raw)
To: openembedded-devel; +Cc: Ankur Tyagi, Khem Raj
From: Ankur Tyagi <ankur.tyagi85@gmail.com>
Changelog:
https://github.com/redboltz/async_mqtt/releases/tag/10.3.1
Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
(cherry picked from commit 965ab7088da70d00d648216f54dbee88074cebe8)
Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
---
.../asyncmqtt/{asyncmqtt_10.3.0.bb => asyncmqtt_10.3.1.bb} | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
rename meta-oe/recipes-connectivity/asyncmqtt/{asyncmqtt_10.3.0.bb => asyncmqtt_10.3.1.bb} (87%)
diff --git a/meta-oe/recipes-connectivity/asyncmqtt/asyncmqtt_10.3.0.bb b/meta-oe/recipes-connectivity/asyncmqtt/asyncmqtt_10.3.1.bb
similarity index 87%
rename from meta-oe/recipes-connectivity/asyncmqtt/asyncmqtt_10.3.0.bb
rename to meta-oe/recipes-connectivity/asyncmqtt/asyncmqtt_10.3.1.bb
index 0e1e155356..ffa559e39e 100644
--- a/meta-oe/recipes-connectivity/asyncmqtt/asyncmqtt_10.3.0.bb
+++ b/meta-oe/recipes-connectivity/asyncmqtt/asyncmqtt_10.3.1.bb
@@ -7,7 +7,7 @@ LIC_FILES_CHKSUM = "file://LICENSE;md5=e4224ccaecb14d942c71d31bef20d78c"
CVE_PRODUCT = "async_mqtt"
SRC_URI = "git://github.com/redboltz/async_mqtt;protocol=http;branch=main;protocol=https;tag=${PV}"
-SRCREV = "7129d72c1b9adf159bc506206df3fb422bb9fb84"
+SRCREV = "0adc511b85358397d8ebb27c10f1ab62da3e3e05"
DEPENDS = "openssl boost"
^ permalink raw reply related [flat|nested] 28+ messages in thread* [oe][meta-oe][wrynose][PATCH 3/28] php: upgrade 8.5.9 -> 8.5.10
2026-09-02 10:04 [oe][meta-oe][wrynose][PATCH 1/28] libmxml: upgrade 4.0.4 -> 4.0.5 ankur.tyagi85
2026-09-02 10:04 ` [oe][meta-oe][wrynose][PATCH 2/28] asyncmqtt: upgrade 10.3.0 -> 10.3.1 ankur.tyagi85
@ 2026-09-02 10:04 ` ankur.tyagi85
2026-09-02 10:04 ` [oe][meta-networking][wrynose][PATCH 4/28] proftpd: upgrade 1.3.9c -> 1.3.9d ankur.tyagi85
` (24 subsequent siblings)
26 siblings, 0 replies; 28+ messages in thread
From: ankur.tyagi85 @ 2026-09-02 10:04 UTC (permalink / raw)
To: openembedded-devel; +Cc: Jason Schonberg, Khem Raj, Ankur Tyagi
From: Jason Schonberg <schonm@gmail.com>
This is a bug fix release.
Changelog: https://www.php.net/ChangeLog-8.php#8.5.10
Signed-off-by: Jason Schonberg <schonm@gmail.com>
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
(cherry picked from commit e5f8c8d53a49cc881dff5ce973fc21752bb50726)
Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
---
meta-oe/recipes-devtools/php/{php_8.5.9.bb => php_8.5.10.bb} | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
rename meta-oe/recipes-devtools/php/{php_8.5.9.bb => php_8.5.10.bb} (99%)
diff --git a/meta-oe/recipes-devtools/php/php_8.5.9.bb b/meta-oe/recipes-devtools/php/php_8.5.10.bb
similarity index 99%
rename from meta-oe/recipes-devtools/php/php_8.5.9.bb
rename to meta-oe/recipes-devtools/php/php_8.5.10.bb
index bc249fd0d3..aab18777c7 100644
--- a/meta-oe/recipes-devtools/php/php_8.5.9.bb
+++ b/meta-oe/recipes-devtools/php/php_8.5.10.bb
@@ -32,7 +32,7 @@ UPSTREAM_CHECK_REGEX = "releases/tag/php-(?P<pver>\d+(\.\d+)+)"
S = "${UNPACKDIR}/php-${PV}"
-SRC_URI[sha256sum] = "703c082ad9d2946ac647f3596812300d2c62b360d2f31a999021692a9b39476c"
+SRC_URI[sha256sum] = "d79bd4f3a9248e5cb5833766ba0d51cd35dd01b8727f23f30bcdba6fabc51d3e"
CVE_STATUS_GROUPS += "CVE_STATUS_PHP"
CVE_STATUS_PHP[status] = "fixed-version: The name of this product is exactly the same as github.com/emlog/emlog. CVE can be safely ignored."
^ permalink raw reply related [flat|nested] 28+ messages in thread* [oe][meta-networking][wrynose][PATCH 4/28] proftpd: upgrade 1.3.9c -> 1.3.9d
2026-09-02 10:04 [oe][meta-oe][wrynose][PATCH 1/28] libmxml: upgrade 4.0.4 -> 4.0.5 ankur.tyagi85
2026-09-02 10:04 ` [oe][meta-oe][wrynose][PATCH 2/28] asyncmqtt: upgrade 10.3.0 -> 10.3.1 ankur.tyagi85
2026-09-02 10:04 ` [oe][meta-oe][wrynose][PATCH 3/28] php: upgrade 8.5.9 -> 8.5.10 ankur.tyagi85
@ 2026-09-02 10:04 ` ankur.tyagi85
2026-09-02 10:04 ` [oe][meta-oe][wrynose][PATCH 5/28] capnproto: ignore CVE-2026-59704 ankur.tyagi85
` (23 subsequent siblings)
26 siblings, 0 replies; 28+ messages in thread
From: ankur.tyagi85 @ 2026-09-02 10:04 UTC (permalink / raw)
To: openembedded-devel; +Cc: Ankur Tyagi, Khem Raj
From: Ankur Tyagi <ankur.tyagi85@gmail.com>
Changelog:
https://github.com/proftpd/proftpd/blob/v1.3.9d/NEWS
Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
(cherry picked from commit f4b73e8ec1c5cbeac6a1cea104db3a30dadb41e3)
Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
---
.../proftpd/{proftpd_1.3.9c.bb => proftpd_1.3.9d.bb} | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
rename meta-networking/recipes-daemons/proftpd/{proftpd_1.3.9c.bb => proftpd_1.3.9d.bb} (99%)
diff --git a/meta-networking/recipes-daemons/proftpd/proftpd_1.3.9c.bb b/meta-networking/recipes-daemons/proftpd/proftpd_1.3.9d.bb
similarity index 99%
rename from meta-networking/recipes-daemons/proftpd/proftpd_1.3.9c.bb
rename to meta-networking/recipes-daemons/proftpd/proftpd_1.3.9d.bb
index 95c9f3919c..8172ba3018 100644
--- a/meta-networking/recipes-daemons/proftpd/proftpd_1.3.9c.bb
+++ b/meta-networking/recipes-daemons/proftpd/proftpd_1.3.9d.bb
@@ -4,7 +4,7 @@ HOMEPAGE = "http://www.proftpd.org"
LICENSE = "GPL-2.0-or-later"
LIC_FILES_CHKSUM = "file://COPYING;md5=fb0d1484d11915fa88a6a7702f1dc184"
-SRCREV = "78a1bea439969913d7002bfb16ee7f0f60e262b4"
+SRCREV = "f59f248e26bdfa514443e42bf72a145641df635d"
BRANCH = "1.3.9"
SRC_URI = "git://github.com/proftpd/proftpd.git;branch=${BRANCH};protocol=https;tag=v${PV} \
^ permalink raw reply related [flat|nested] 28+ messages in thread* [oe][meta-oe][wrynose][PATCH 5/28] capnproto: ignore CVE-2026-59704
2026-09-02 10:04 [oe][meta-oe][wrynose][PATCH 1/28] libmxml: upgrade 4.0.4 -> 4.0.5 ankur.tyagi85
` (2 preceding siblings ...)
2026-09-02 10:04 ` [oe][meta-networking][wrynose][PATCH 4/28] proftpd: upgrade 1.3.9c -> 1.3.9d ankur.tyagi85
@ 2026-09-02 10:04 ` ankur.tyagi85
2026-09-02 10:04 ` [oe][meta-oe][wrynose][PATCH 6/28] bubblewrap: mark CVE-2026-41163 patched ankur.tyagi85
` (22 subsequent siblings)
26 siblings, 0 replies; 28+ messages in thread
From: ankur.tyagi85 @ 2026-09-02 10:04 UTC (permalink / raw)
To: openembedded-devel; +Cc: Ankur Tyagi
From: Ankur Tyagi <ankur.tyagi85@gmail.com>
Details:
https://nvd.nist.gov/vuln/detail/cve-2026-59704
Fixes:
WARNING: capnproto-1.4.0-r0 do_sbom_cve_check_recipe: capnproto-1.4.0: Found unpatched CVEs: CVE-2026-59704
Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
---
meta-oe/recipes-devtools/capnproto/capnproto_1.4.0.bb | 1 +
1 file changed, 1 insertion(+)
diff --git a/meta-oe/recipes-devtools/capnproto/capnproto_1.4.0.bb b/meta-oe/recipes-devtools/capnproto/capnproto_1.4.0.bb
index 948ff80345..a42131b6e2 100644
--- a/meta-oe/recipes-devtools/capnproto/capnproto_1.4.0.bb
+++ b/meta-oe/recipes-devtools/capnproto/capnproto_1.4.0.bb
@@ -32,3 +32,4 @@ BBCLASSEXTEND = "native nativesdk"
CVE_STATUS[CVE-2026-32239] = "fixed-version: fixed in 1.4.0"
CVE_STATUS[CVE-2026-32240] = "fixed-version: fixed in 1.4.0"
+CVE_STATUS[CVE-2026-59704] = "cpe-incorrect: the vulnerability is in Cap, which is a different project"
^ permalink raw reply related [flat|nested] 28+ messages in thread* [oe][meta-oe][wrynose][PATCH 6/28] bubblewrap: mark CVE-2026-41163 patched
2026-09-02 10:04 [oe][meta-oe][wrynose][PATCH 1/28] libmxml: upgrade 4.0.4 -> 4.0.5 ankur.tyagi85
` (3 preceding siblings ...)
2026-09-02 10:04 ` [oe][meta-oe][wrynose][PATCH 5/28] capnproto: ignore CVE-2026-59704 ankur.tyagi85
@ 2026-09-02 10:04 ` ankur.tyagi85
2026-09-02 10:04 ` [oe][meta-oe][wrynose][PATCH 7/28] bcc: mark CVE-2024-2314 patched ankur.tyagi85
` (21 subsequent siblings)
26 siblings, 0 replies; 28+ messages in thread
From: ankur.tyagi85 @ 2026-09-02 10:04 UTC (permalink / raw)
To: openembedded-devel; +Cc: Ankur Tyagi
From: Ankur Tyagi <ankur.tyagi85@gmail.com>
Details:
https://nvd.nist.gov/vuln/detail/cve-2026-41163
Fixes:
WARNING: bubblewrap-0.11.2-r0 do_sbom_cve_check_recipe: bubblewrap-0.11.2: Found unpatched CVEs: CVE-2026-41163
Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
---
meta-oe/recipes-security/bubblewrap/bubblewrap_0.11.2.bb | 2 ++
1 file changed, 2 insertions(+)
diff --git a/meta-oe/recipes-security/bubblewrap/bubblewrap_0.11.2.bb b/meta-oe/recipes-security/bubblewrap/bubblewrap_0.11.2.bb
index 7e63435e90..c9aa04891b 100644
--- a/meta-oe/recipes-security/bubblewrap/bubblewrap_0.11.2.bb
+++ b/meta-oe/recipes-security/bubblewrap/bubblewrap_0.11.2.bb
@@ -23,3 +23,5 @@ PACKAGES += "${PN}-zsh-completion"
FILES:${PN}-zsh-completion = "${datadir}/zsh/site-functions"
BBCLASSEXTEND = "native"
+
+CVE_STATUS[CVE-2026-41163] = "fixed-version: fixed in 0.11.2"
^ permalink raw reply related [flat|nested] 28+ messages in thread* [oe][meta-oe][wrynose][PATCH 7/28] bcc: mark CVE-2024-2314 patched
2026-09-02 10:04 [oe][meta-oe][wrynose][PATCH 1/28] libmxml: upgrade 4.0.4 -> 4.0.5 ankur.tyagi85
` (4 preceding siblings ...)
2026-09-02 10:04 ` [oe][meta-oe][wrynose][PATCH 6/28] bubblewrap: mark CVE-2026-41163 patched ankur.tyagi85
@ 2026-09-02 10:04 ` ankur.tyagi85
2026-09-02 10:04 ` [oe][meta-webserver][wrynose][PATCH 8/28] cockpit: mark CVE-2024-2947 patched ankur.tyagi85
` (20 subsequent siblings)
26 siblings, 0 replies; 28+ messages in thread
From: ankur.tyagi85 @ 2026-09-02 10:04 UTC (permalink / raw)
To: openembedded-devel; +Cc: Ankur Tyagi
From: Ankur Tyagi <ankur.tyagi85@gmail.com>
Details:
https://nvd.nist.gov/vuln/detail/cve-2024-2314
Fixes:
WARNING: bcc-0.36.1-r0 do_sbom_cve_check_recipe: bcc-0.36.1: Found unpatched CVEs: CVE-2024-2314
Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
---
.../meta-python/recipes-devtools/bcc/bcc_0.36.1.bb | 2 ++
1 file changed, 2 insertions(+)
diff --git a/meta-oe/dynamic-layers/meta-python/recipes-devtools/bcc/bcc_0.36.1.bb b/meta-oe/dynamic-layers/meta-python/recipes-devtools/bcc/bcc_0.36.1.bb
index 0d8bee5da4..69f5916f94 100644
--- a/meta-oe/dynamic-layers/meta-python/recipes-devtools/bcc/bcc_0.36.1.bb
+++ b/meta-oe/dynamic-layers/meta-python/recipes-devtools/bcc/bcc_0.36.1.bb
@@ -95,3 +95,5 @@ COMPATIBLE_HOST = "(x86_64.*|aarch64.*|powerpc64.*|riscv64.*)-linux"
# path from the test binary
WARN_QA:append = "${@bb.utils.contains('PTEST_ENABLED', '1', ' buildpaths', '', d)}"
ERROR_QA:remove = "${@bb.utils.contains('PTEST_ENABLED', '1', 'buildpaths', '', d)}"
+
+CVE_STATUS[CVE-2024-2314] = "fixed-version: fixed in 0.36.1"
^ permalink raw reply related [flat|nested] 28+ messages in thread* [oe][meta-webserver][wrynose][PATCH 8/28] cockpit: mark CVE-2024-2947 patched
2026-09-02 10:04 [oe][meta-oe][wrynose][PATCH 1/28] libmxml: upgrade 4.0.4 -> 4.0.5 ankur.tyagi85
` (5 preceding siblings ...)
2026-09-02 10:04 ` [oe][meta-oe][wrynose][PATCH 7/28] bcc: mark CVE-2024-2314 patched ankur.tyagi85
@ 2026-09-02 10:04 ` ankur.tyagi85
2026-09-02 10:04 ` [oe][meta-oe][wrynose][PATCH 9/28] dool: patch CVE-2026-56651 ankur.tyagi85
` (19 subsequent siblings)
26 siblings, 0 replies; 28+ messages in thread
From: ankur.tyagi85 @ 2026-09-02 10:04 UTC (permalink / raw)
To: openembedded-devel; +Cc: Ankur Tyagi
From: Ankur Tyagi <ankur.tyagi85@gmail.com>
commit[1] fixing the CVE is part of the upstream version.
Details:
https://nvd.nist.gov/vuln/detail/cve-2024-2947
Fixes:
WARNING: cockpit-352-r0 do_sbom_cve_check_recipe: cockpit-352: Found unpatched CVEs: CVE-2024-2947
[1] https://github.com/cockpit-project/cockpit/commit/9c4cc9b6df632082538b53bdc8ee9ec1c5cad4da
Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
---
meta-webserver/recipes-webadmin/cockpit/cockpit_352.bb | 1 +
1 file changed, 1 insertion(+)
diff --git a/meta-webserver/recipes-webadmin/cockpit/cockpit_352.bb b/meta-webserver/recipes-webadmin/cockpit/cockpit_352.bb
index 6b1fdcaeb1..77156c0f85 100644
--- a/meta-webserver/recipes-webadmin/cockpit/cockpit_352.bb
+++ b/meta-webserver/recipes-webadmin/cockpit/cockpit_352.bb
@@ -199,3 +199,4 @@ do_install:append() {
}
CVE_PRODUCT = "cockpit-project:cockpit"
+CVE_STATUS[CVE-2024-2947] = "fixed-version: fixed in 352"
^ permalink raw reply related [flat|nested] 28+ messages in thread* [oe][meta-oe][wrynose][PATCH 9/28] dool: patch CVE-2026-56651
2026-09-02 10:04 [oe][meta-oe][wrynose][PATCH 1/28] libmxml: upgrade 4.0.4 -> 4.0.5 ankur.tyagi85
` (6 preceding siblings ...)
2026-09-02 10:04 ` [oe][meta-webserver][wrynose][PATCH 8/28] cockpit: mark CVE-2024-2947 patched ankur.tyagi85
@ 2026-09-02 10:04 ` ankur.tyagi85
2026-09-02 10:04 ` [oe][meta-oe][wrynose][PATCH 10/28] dool: patch CVE-2026-56652 ankur.tyagi85
` (18 subsequent siblings)
26 siblings, 0 replies; 28+ messages in thread
From: ankur.tyagi85 @ 2026-09-02 10:04 UTC (permalink / raw)
To: openembedded-devel; +Cc: Ankur Tyagi
From: Ankur Tyagi <ankur.tyagi85@gmail.com>
Details:
https://nvd.nist.gov/vuln/detail/cve-2026-56651
Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
---
.../dool/dool/CVE-2026-56651.patch | 47 +++++++++++++++++++
meta-oe/recipes-support/dool/dool_1.3.8.bb | 4 +-
2 files changed, 50 insertions(+), 1 deletion(-)
create mode 100644 meta-oe/recipes-support/dool/dool/CVE-2026-56651.patch
diff --git a/meta-oe/recipes-support/dool/dool/CVE-2026-56651.patch b/meta-oe/recipes-support/dool/dool/CVE-2026-56651.patch
new file mode 100644
index 0000000000..e367884ca9
--- /dev/null
+++ b/meta-oe/recipes-support/dool/dool/CVE-2026-56651.patch
@@ -0,0 +1,47 @@
+From f5eb4fbf3977d919a2e9da8b73985a29d2878e56 Mon Sep 17 00:00:00 2001
+From: =?UTF-8?q?Micha=C5=82=20Majchrowicz?= <sectroyer@gmail.com>
+Date: Thu, 18 Jun 2026 10:52:27 +0200
+Subject: [PATCH] Neutralize formula-prefixed CSV output
+MIME-Version: 1.0
+Content-Type: text/plain; charset=UTF-8
+Content-Transfer-Encoding: 8bit
+
+Signed-off-by: Michał Majchrowicz <sectroyer@gmail.com>
+(cherry picked from commit d5aa93b3d1939a83b2b10a7cd8af3c819930aea1)
+
+CVE: CVE-2026-56651
+Upstream-Status: Backport [https://github.com/scottchiefbaker/dool/commit/d5aa93b3d1939a83b2b10a7cd8af3c819930aea1]
+Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
+---
+ dool | 11 ++++++++++-
+ 1 file changed, 10 insertions(+), 1 deletion(-)
+
+diff --git a/dool b/dool
+index 634ed9d..fc1015d 100755
+--- a/dool
++++ b/dool
+@@ -3030,7 +3030,10 @@ def perform(update):
+
+ # Prep the line for the CSV file
+ if op.output and step == op.delay:
+- oline = oline + o.showcsv() + o.showcsvend(totlist, vislist)
++ csv_cell = o.showcsv()
++ if o.type == 's' and len(o.vars) == 1:
++ csv_cell = csv_quote_string_cell(csv_cell)
++ oline = oline + csv_cell + o.showcsvend(totlist, vislist)
+
+ ### Put the output in the csv file
+ if op.output and step == op.delay:
+@@ -3170,6 +3173,12 @@ def file_slurp(filename, size = -1):
+
+ return ret
+
++def csv_quote_string_cell(text):
++ "Quote free-form CSV string cells and neutralize spreadsheet formulas"
++ if text and text[0] in ('=', '+', '-', '@'):
++ text = "'" + text
++ return '"' + text.replace('"', '""') + '"'
++
+ # Make human readable device names that are shorter
+ #
+ # Example mappings:
diff --git a/meta-oe/recipes-support/dool/dool_1.3.8.bb b/meta-oe/recipes-support/dool/dool_1.3.8.bb
index 1c7350e871..787bdab4f2 100644
--- a/meta-oe/recipes-support/dool/dool_1.3.8.bb
+++ b/meta-oe/recipes-support/dool/dool_1.3.8.bb
@@ -9,7 +9,9 @@ LIC_FILES_CHKSUM = "file://LICENSE;md5=1ebbd3e34237af26da5dc08a4e440464"
DEPENDS += "asciidoc-native xmlto-native"
RDEPENDS:${PN} += "python3-core python3-misc python3-resource python3-shell python3-six python3-unixadmin"
-SRC_URI = "git://github.com/scottchiefbaker/dool.git;branch=next;protocol=https;tag=v${PV}"
+SRC_URI = "git://github.com/scottchiefbaker/dool.git;branch=next;protocol=https;tag=v${PV} \
+ file://CVE-2026-56651.patch \
+"
SRCREV = "b74503e2dfbca8ef01c284d40aa77dc82be308b9"
^ permalink raw reply related [flat|nested] 28+ messages in thread* [oe][meta-oe][wrynose][PATCH 10/28] dool: patch CVE-2026-56652
2026-09-02 10:04 [oe][meta-oe][wrynose][PATCH 1/28] libmxml: upgrade 4.0.4 -> 4.0.5 ankur.tyagi85
` (7 preceding siblings ...)
2026-09-02 10:04 ` [oe][meta-oe][wrynose][PATCH 9/28] dool: patch CVE-2026-56651 ankur.tyagi85
@ 2026-09-02 10:04 ` ankur.tyagi85
2026-09-02 10:04 ` [oe][meta-networking][wrynose][PATCH 11/28] dovecot: ignore already fixed CVEs ankur.tyagi85
` (17 subsequent siblings)
26 siblings, 0 replies; 28+ messages in thread
From: ankur.tyagi85 @ 2026-09-02 10:04 UTC (permalink / raw)
To: openembedded-devel; +Cc: Ankur Tyagi
From: Ankur Tyagi <ankur.tyagi85@gmail.com>
Details:
https://nvd.nist.gov/vuln/detail/cve-2026-56652
Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
---
.../dool/dool/CVE-2026-56652.patch | 35 +++++++++++++++++++
meta-oe/recipes-support/dool/dool_1.3.8.bb | 1 +
2 files changed, 36 insertions(+)
create mode 100644 meta-oe/recipes-support/dool/dool/CVE-2026-56652.patch
diff --git a/meta-oe/recipes-support/dool/dool/CVE-2026-56652.patch b/meta-oe/recipes-support/dool/dool/CVE-2026-56652.patch
new file mode 100644
index 0000000000..c6806ae0c5
--- /dev/null
+++ b/meta-oe/recipes-support/dool/dool/CVE-2026-56652.patch
@@ -0,0 +1,35 @@
+From d20ba041a0f4968fdbc2745827f9af676339924f Mon Sep 17 00:00:00 2001
+From: =?UTF-8?q?Micha=C5=82=20Majchrowicz?= <sectroyer@gmail.com>
+Date: Thu, 18 Jun 2026 19:20:30 +0200
+Subject: [PATCH] Refuse symlinked devel log files
+MIME-Version: 1.0
+Content-Type: text/plain; charset=UTF-8
+Content-Transfer-Encoding: 8bit
+
+Signed-off-by: Michał Majchrowicz <sectroyer@gmail.com>
+(cherry picked from commit 259fe40c7fa519020ef7a3f8ef8d61586b72ecc3)
+
+CVE: CVE-2026-56652
+Upstream-Status: Backport [https://github.com/scottchiefbaker/dool/commit/259fe40c7fa519020ef7a3f8ef8d61586b72ecc3]
+Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
+---
+ dool | 6 +++++-
+ 1 file changed, 5 insertions(+), 1 deletion(-)
+
+diff --git a/dool b/dool
+index fc1015d..2df407d 100755
+--- a/dool
++++ b/dool
+@@ -2132,7 +2132,11 @@ def devel_log(msg):
+ if not DEBUG_FH:
+ log_file = "/tmp/dool-devel.log"
+ print("Writing devel log: '%s'" % log_file)
+- DEBUG_FH = open(log_file, "w", 1)
++ flags = os.O_WRONLY | os.O_CREAT | os.O_TRUNC
++ if hasattr(os, 'O_NOFOLLOW'):
++ flags |= os.O_NOFOLLOW
++ fd = os.open(log_file, flags, 0o600)
++ DEBUG_FH = os.fdopen(fd, "w", 1)
+
+ # Print out the header line for the devel log
+ DEBUG_FH.write("|Time |Since Prev |Description|\n");
diff --git a/meta-oe/recipes-support/dool/dool_1.3.8.bb b/meta-oe/recipes-support/dool/dool_1.3.8.bb
index 787bdab4f2..2ab20a12e0 100644
--- a/meta-oe/recipes-support/dool/dool_1.3.8.bb
+++ b/meta-oe/recipes-support/dool/dool_1.3.8.bb
@@ -11,6 +11,7 @@ RDEPENDS:${PN} += "python3-core python3-misc python3-resource python3-shell pyth
SRC_URI = "git://github.com/scottchiefbaker/dool.git;branch=next;protocol=https;tag=v${PV} \
file://CVE-2026-56651.patch \
+ file://CVE-2026-56652.patch \
"
SRCREV = "b74503e2dfbca8ef01c284d40aa77dc82be308b9"
^ permalink raw reply related [flat|nested] 28+ messages in thread* [oe][meta-networking][wrynose][PATCH 11/28] dovecot: ignore already fixed CVEs
2026-09-02 10:04 [oe][meta-oe][wrynose][PATCH 1/28] libmxml: upgrade 4.0.4 -> 4.0.5 ankur.tyagi85
` (8 preceding siblings ...)
2026-09-02 10:04 ` [oe][meta-oe][wrynose][PATCH 10/28] dool: patch CVE-2026-56652 ankur.tyagi85
@ 2026-09-02 10:04 ` ankur.tyagi85
2026-09-02 10:04 ` [oe][meta-oe][wrynose][PATCH 12/28] editorconfig-core-c: ignore CVE-2024-53849 ankur.tyagi85
` (16 subsequent siblings)
26 siblings, 0 replies; 28+ messages in thread
From: ankur.tyagi85 @ 2026-09-02 10:04 UTC (permalink / raw)
To: openembedded-devel; +Cc: Ankur Tyagi
From: Ankur Tyagi <ankur.tyagi85@gmail.com>
Upstream has confirmed that these vulnerabilities are fixed,
and Debian has also identified the relevant commits:
CVE-2025-59028: https://security-tracker.debian.org/tracker/CVE-2025-59028
CVE-2025-59032: https://security-tracker.debian.org/tracker/CVE-2025-59032
CVE-2026-27859: https://security-tracker.debian.org/tracker/CVE-2026-27859
CVE-2026-27851: https://security-tracker.debian.org/tracker/CVE-2026-27851
CVE-2026-33603: https://security-tracker.debian.org/tracker/CVE-2026-33603
CVE-2026-40016: https://security-tracker.debian.org/tracker/CVE-2026-40016
CVE-2026-40020: https://security-tracker.debian.org/tracker/CVE-2026-40020
CVE-2026-42006: https://security-tracker.debian.org/tracker/CVE-2026-42006
Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
---
meta-networking/recipes-support/dovecot/dovecot_2.4.4.bb | 8 ++++++++
1 file changed, 8 insertions(+)
diff --git a/meta-networking/recipes-support/dovecot/dovecot_2.4.4.bb b/meta-networking/recipes-support/dovecot/dovecot_2.4.4.bb
index 6cac8de964..1edb8f50e3 100644
--- a/meta-networking/recipes-support/dovecot/dovecot_2.4.4.bb
+++ b/meta-networking/recipes-support/dovecot/dovecot_2.4.4.bb
@@ -86,3 +86,11 @@ CVE_STATUS[CVE-2026-0394] = "fixed-version: fixed since v2.4.1"
CVE_STATUS[CVE-2026-24031] = "fixed-version: fixed since v2.4.3"
CVE_STATUS[CVE-2026-27855] = "fixed-version: fixed since v2.4.3"
CVE_STATUS[CVE-2026-27860] = "fixed-version: fixed since v2.4.3"
+CVE_STATUS[CVE-2025-59028] = "fixed-version: fixed since v2.4.3"
+CVE_STATUS[CVE-2025-59032] = "fixed-version: fixed since v2.4.3"
+CVE_STATUS[CVE-2026-27859] = "fixed-version: fixed since v2.4.3"
+CVE_STATUS[CVE-2026-27851] = "fixed-version: fixed in v2.4.4"
+CVE_STATUS[CVE-2026-33603] = "fixed-version: fixed in v2.4.4"
+CVE_STATUS[CVE-2026-40016] = "fixed-version: fixed in v2.4.4"
+CVE_STATUS[CVE-2026-40020] = "fixed-version: fixed in v2.4.4"
+CVE_STATUS[CVE-2026-42006] = "fixed-version: fixed in v2.4.4"
^ permalink raw reply related [flat|nested] 28+ messages in thread* [oe][meta-oe][wrynose][PATCH 12/28] editorconfig-core-c: ignore CVE-2024-53849
2026-09-02 10:04 [oe][meta-oe][wrynose][PATCH 1/28] libmxml: upgrade 4.0.4 -> 4.0.5 ankur.tyagi85
` (9 preceding siblings ...)
2026-09-02 10:04 ` [oe][meta-networking][wrynose][PATCH 11/28] dovecot: ignore already fixed CVEs ankur.tyagi85
@ 2026-09-02 10:04 ` ankur.tyagi85
2026-09-02 10:04 ` [oe][meta-oe][wrynose][PATCH 13/28] editorconfig-core-c: patch CVE-2026-40489 ankur.tyagi85
` (15 subsequent siblings)
26 siblings, 0 replies; 28+ messages in thread
From: ankur.tyagi85 @ 2026-09-02 10:04 UTC (permalink / raw)
To: openembedded-devel; +Cc: Ankur Tyagi
From: Ankur Tyagi <ankur.tyagi85@gmail.com>
PR[1] mentioned in the NVD[2] is already part of the upstream version.
[1] https://github.com/editorconfig/editorconfig-core-c/pull/103
[2] https://nvd.nist.gov/vuln/detail/cve-2024-53849
Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
---
.../recipes-devtools/editorconfig/editorconfig-core-c_0.12.9.bb | 2 ++
1 file changed, 2 insertions(+)
diff --git a/meta-oe/recipes-devtools/editorconfig/editorconfig-core-c_0.12.9.bb b/meta-oe/recipes-devtools/editorconfig/editorconfig-core-c_0.12.9.bb
index c6db2ef38c..319c1724c0 100644
--- a/meta-oe/recipes-devtools/editorconfig/editorconfig-core-c_0.12.9.bb
+++ b/meta-oe/recipes-devtools/editorconfig/editorconfig-core-c_0.12.9.bb
@@ -15,3 +15,5 @@ DEPENDS = "pcre2"
do_install:append() {
sed -i -e 's|${STAGING_DIR_HOST}||g' ${D}${libdir}/cmake/EditorConfig/EditorConfigTargets.cmake
}
+
+CVE_STATUS[CVE-2024-53849] = "fixed-version: fixed since v0.12.7"
^ permalink raw reply related [flat|nested] 28+ messages in thread* [oe][meta-oe][wrynose][PATCH 13/28] editorconfig-core-c: patch CVE-2026-40489
2026-09-02 10:04 [oe][meta-oe][wrynose][PATCH 1/28] libmxml: upgrade 4.0.4 -> 4.0.5 ankur.tyagi85
` (10 preceding siblings ...)
2026-09-02 10:04 ` [oe][meta-oe][wrynose][PATCH 12/28] editorconfig-core-c: ignore CVE-2024-53849 ankur.tyagi85
@ 2026-09-02 10:04 ` ankur.tyagi85
2026-09-02 10:04 ` [oe][meta-networking][wrynose][PATCH 14/28] civetweb: ignore CVE-2026-5789 ankur.tyagi85
` (14 subsequent siblings)
26 siblings, 0 replies; 28+ messages in thread
From: ankur.tyagi85 @ 2026-09-02 10:04 UTC (permalink / raw)
To: openembedded-devel; +Cc: Ankur Tyagi
From: Ankur Tyagi <ankur.tyagi85@gmail.com>
Details:
https://nvd.nist.gov/vuln/detail/cve-2026-40489
Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
---
.../editorconfig-core-c/CVE-2026-40489.patch | 39 +++++++++++++++++++
.../editorconfig-core-c_0.12.9.bb | 4 +-
2 files changed, 42 insertions(+), 1 deletion(-)
create mode 100644 meta-oe/recipes-devtools/editorconfig/editorconfig-core-c/CVE-2026-40489.patch
diff --git a/meta-oe/recipes-devtools/editorconfig/editorconfig-core-c/CVE-2026-40489.patch b/meta-oe/recipes-devtools/editorconfig/editorconfig-core-c/CVE-2026-40489.patch
new file mode 100644
index 0000000000..e328052314
--- /dev/null
+++ b/meta-oe/recipes-devtools/editorconfig/editorconfig-core-c/CVE-2026-40489.patch
@@ -0,0 +1,39 @@
+From 4d5fcd42739f0ae349efe4e9208c0f109bb7c141 Mon Sep 17 00:00:00 2001
+From: Hong Xu <hong@topbug.net>
+Date: Tue, 14 Apr 2026 23:11:39 -0700
+Subject: [PATCH] Merge commit from fork
+
+Completes the buffer-overflow fix from #87, which bounded writes into
+`pcre_str` but left the initial `strcpy` of `pattern` into `l_pattern`
+at the top of `ec_glob` unguarded. Sufficiently long patterns smash the
+stack before any of the bounds-checked code runs.
+
+Fix CVE-2026-40489
+
+(cherry picked from commit 5159be88ad50641d9843289adda791ba300421ff)
+
+CVE: CVE-2026-40489
+Upstream-Status: Backport [https://github.com/editorconfig/editorconfig-core-c/commit/5159be88ad50641d9843289adda791ba300421ff]
+Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
+---
+ src/lib/ec_glob.c | 6 +++++-
+ 1 file changed, 5 insertions(+), 1 deletion(-)
+
+diff --git a/src/lib/ec_glob.c b/src/lib/ec_glob.c
+index d36076d..0e7f7ac 100644
+--- a/src/lib/ec_glob.c
++++ b/src/lib/ec_glob.c
+@@ -96,8 +96,12 @@ int ec_glob(const char *pattern, const char *string)
+ _Bool are_braces_paired = 1;
+ UT_array * nums; /* number ranges */
+ int ret = 0;
++ size_t pattern_len = strlen(pattern);
+
+- strcpy(l_pattern, pattern);
++ /* Reject patterns that would overflow l_pattern in the copy below. */
++ if (pattern_len >= sizeof(l_pattern))
++ return -1;
++ memcpy(l_pattern, pattern, pattern_len + 1);
+ p_pcre = pcre_str + 1;
+ pcre_str_end = pcre_str + 2 * PATTERN_MAX;
+
diff --git a/meta-oe/recipes-devtools/editorconfig/editorconfig-core-c_0.12.9.bb b/meta-oe/recipes-devtools/editorconfig/editorconfig-core-c_0.12.9.bb
index 319c1724c0..8d182d0cd0 100644
--- a/meta-oe/recipes-devtools/editorconfig/editorconfig-core-c_0.12.9.bb
+++ b/meta-oe/recipes-devtools/editorconfig/editorconfig-core-c_0.12.9.bb
@@ -4,7 +4,9 @@ SECTION = "libs"
LICENSE = "BSD-2-Clause"
LIC_FILES_CHKSUM = "file://LICENSE;md5=38f617473e9f7373b5e79baf437accf8"
-SRC_URI = "git://github.com/editorconfig/editorconfig-core-c.git;protocol=https;branch=master"
+SRC_URI = "git://github.com/editorconfig/editorconfig-core-c.git;protocol=https;branch=master \
+ file://CVE-2026-40489.patch \
+"
SRCREV = "e082c947e7f7b14240195d55c060a6e1eda1b0a1"
^ permalink raw reply related [flat|nested] 28+ messages in thread* [oe][meta-networking][wrynose][PATCH 14/28] civetweb: ignore CVE-2026-5789
2026-09-02 10:04 [oe][meta-oe][wrynose][PATCH 1/28] libmxml: upgrade 4.0.4 -> 4.0.5 ankur.tyagi85
` (11 preceding siblings ...)
2026-09-02 10:04 ` [oe][meta-oe][wrynose][PATCH 13/28] editorconfig-core-c: patch CVE-2026-40489 ankur.tyagi85
@ 2026-09-02 10:04 ` ankur.tyagi85
2026-09-02 10:04 ` [oe][meta-oe][wrynose][PATCH 15/28] eject: ignore CVE-2026-28065 ankur.tyagi85
` (13 subsequent siblings)
26 siblings, 0 replies; 28+ messages in thread
From: ankur.tyagi85 @ 2026-09-02 10:04 UTC (permalink / raw)
To: openembedded-devel; +Cc: Ankur Tyagi
From: Ankur Tyagi <ankur.tyagi85@gmail.com>
Details:
https://nvd.nist.gov/vuln/detail/cve-2026-5789
Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
---
meta-networking/recipes-connectivity/civetweb/civetweb_1.16.bb | 1 +
1 file changed, 1 insertion(+)
diff --git a/meta-networking/recipes-connectivity/civetweb/civetweb_1.16.bb b/meta-networking/recipes-connectivity/civetweb/civetweb_1.16.bb
index 0e13bc6deb..a22d08f05e 100644
--- a/meta-networking/recipes-connectivity/civetweb/civetweb_1.16.bb
+++ b/meta-networking/recipes-connectivity/civetweb/civetweb_1.16.bb
@@ -12,6 +12,7 @@ SRC_URI = "git://github.com/civetweb/civetweb.git;branch=master;protocol=https \
CVE_STATUS[CVE-2025-55763] = "fixed-version: The vulnerability is fixed in the used revision"
CVE_STATUS[CVE-2025-9648] = "fixed-version: The vulnerability is fixed in the used revision"
+CVE_STATUS[CVE-2026-5789] = "not-applicable-platform: Issue only applies on Windows"
# civetweb supports building with make or cmake (although cmake lacks few features)
inherit cmake
^ permalink raw reply related [flat|nested] 28+ messages in thread* [oe][meta-oe][wrynose][PATCH 15/28] eject: ignore CVE-2026-28065
2026-09-02 10:04 [oe][meta-oe][wrynose][PATCH 1/28] libmxml: upgrade 4.0.4 -> 4.0.5 ankur.tyagi85
` (12 preceding siblings ...)
2026-09-02 10:04 ` [oe][meta-networking][wrynose][PATCH 14/28] civetweb: ignore CVE-2026-5789 ankur.tyagi85
@ 2026-09-02 10:04 ` ankur.tyagi85
2026-09-02 10:04 ` [oe][meta-networking][wrynose][PATCH 16/28] firewalld: patch CVE-2026-4948 ankur.tyagi85
` (12 subsequent siblings)
26 siblings, 0 replies; 28+ messages in thread
From: ankur.tyagi85 @ 2026-09-02 10:04 UTC (permalink / raw)
To: openembedded-devel; +Cc: Ankur Tyagi
From: Ankur Tyagi <ankur.tyagi85@gmail.com>
Details:
https://nvd.nist.gov/vuln/detail/cve-2026-28065
Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
---
meta-oe/recipes-support/eject/eject_2.1.5.bb | 2 ++
1 file changed, 2 insertions(+)
diff --git a/meta-oe/recipes-support/eject/eject_2.1.5.bb b/meta-oe/recipes-support/eject/eject_2.1.5.bb
index aa0e86db12..90630ff791 100644
--- a/meta-oe/recipes-support/eject/eject_2.1.5.bb
+++ b/meta-oe/recipes-support/eject/eject_2.1.5.bb
@@ -34,3 +34,5 @@ ALTERNATIVE_PRIORITY[eject] = "100"
ALTERNATIVE:${PN}-doc = "eject.1"
ALTERNATIVE_LINK_NAME[eject.1] = "${mandir}/man1/eject.1"
+
+CVE_STATUS[CVE-2026-28065] = "cpe-incorrect: this CVE is for WordPress plugin or theme"
^ permalink raw reply related [flat|nested] 28+ messages in thread* [oe][meta-networking][wrynose][PATCH 16/28] firewalld: patch CVE-2026-4948
2026-09-02 10:04 [oe][meta-oe][wrynose][PATCH 1/28] libmxml: upgrade 4.0.4 -> 4.0.5 ankur.tyagi85
` (13 preceding siblings ...)
2026-09-02 10:04 ` [oe][meta-oe][wrynose][PATCH 15/28] eject: ignore CVE-2026-28065 ankur.tyagi85
@ 2026-09-02 10:04 ` ankur.tyagi85
2026-09-02 10:04 ` [oe][meta-oe][wrynose][PATCH 17/28] freeipmi: patch CVE-2026-50031 ankur.tyagi85
` (11 subsequent siblings)
26 siblings, 0 replies; 28+ messages in thread
From: ankur.tyagi85 @ 2026-09-02 10:04 UTC (permalink / raw)
To: openembedded-devel; +Cc: Ankur Tyagi
From: Ankur Tyagi <ankur.tyagi85@gmail.com>
Backport commit[1] identified by Debian as a fix.
Details:
https://nvd.nist.gov/vuln/detail/cve-2026-4948
[1] https://security-tracker.debian.org/tracker/CVE-2026-4948
Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
---
.../firewalld/files/CVE-2026-4948.patch | 38 +++++++++++++++++++
.../firewalld/firewalld_2.2.3.bb | 1 +
2 files changed, 39 insertions(+)
create mode 100644 meta-networking/dynamic-layers/meta-python/recipes-connectivity/firewalld/files/CVE-2026-4948.patch
diff --git a/meta-networking/dynamic-layers/meta-python/recipes-connectivity/firewalld/files/CVE-2026-4948.patch b/meta-networking/dynamic-layers/meta-python/recipes-connectivity/firewalld/files/CVE-2026-4948.patch
new file mode 100644
index 0000000000..6aa422e0c6
--- /dev/null
+++ b/meta-networking/dynamic-layers/meta-python/recipes-connectivity/firewalld/files/CVE-2026-4948.patch
@@ -0,0 +1,38 @@
+From 8e2d8aa579164220624d6cd6520d904fe27cfa48 Mon Sep 17 00:00:00 2001
+From: Sizhe Zhao <prc.zhao@outlook.com>
+Date: Tue, 31 Mar 2026 20:46:50 +0800
+Subject: [PATCH] fix(policy): use PK_ACTION_CONFIG for
+ set{ZoneSettings2,PolicySettings}
+
+Reference: https://access.redhat.com/security/cve/cve-2026-4948
+(cherry picked from commit 5fb3914ad830feff6cb2b0670457c60a323c6c6c)
+
+CVE: CVE-2026-4948
+Upstream-Status: Backport [https://github.com/firewalld/firewalld/commit/5fb3914ad830feff6cb2b0670457c60a323c6c6c]
+Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
+---
+ src/firewall/server/firewalld.py | 4 ++--
+ 1 file changed, 2 insertions(+), 2 deletions(-)
+
+diff --git a/src/firewall/server/firewalld.py b/src/firewall/server/firewalld.py
+index 62802528..9f969d8d 100644
+--- a/src/firewall/server/firewalld.py
++++ b/src/firewall/server/firewalld.py
+@@ -938,7 +938,7 @@ class FirewallD(DbusServiceObject):
+ log.debug1("getZoneSettings2(%s)", zone)
+ return self.fw.zone.get_config_with_settings_dict(zone)
+
+- @dbus_polkit_require_auth(config.dbus.PK_ACTION_CONFIG_INFO)
++ @dbus_polkit_require_auth(config.dbus.PK_ACTION_CONFIG)
+ @dbus_service_method(config.dbus.DBUS_INTERFACE_ZONE, in_signature="sa{sv}")
+ @dbus_handle_exceptions
+ def setZoneSettings2(self, zone, settings, sender=None):
+@@ -965,7 +965,7 @@ class FirewallD(DbusServiceObject):
+ log.debug1("policy.getPolicySettings(%s)", policy)
+ return self.fw.policy.get_config_with_settings_dict(policy)
+
+- @dbus_polkit_require_auth(config.dbus.PK_ACTION_CONFIG_INFO)
++ @dbus_polkit_require_auth(config.dbus.PK_ACTION_CONFIG)
+ @dbus_service_method(config.dbus.DBUS_INTERFACE_POLICY, in_signature="sa{sv}")
+ @dbus_handle_exceptions
+ def setPolicySettings(self, policy, settings, sender=None):
diff --git a/meta-networking/dynamic-layers/meta-python/recipes-connectivity/firewalld/firewalld_2.2.3.bb b/meta-networking/dynamic-layers/meta-python/recipes-connectivity/firewalld/firewalld_2.2.3.bb
index e77df2ddbb..a89b93248f 100644
--- a/meta-networking/dynamic-layers/meta-python/recipes-connectivity/firewalld/firewalld_2.2.3.bb
+++ b/meta-networking/dynamic-layers/meta-python/recipes-connectivity/firewalld/firewalld_2.2.3.bb
@@ -7,6 +7,7 @@ LIC_FILES_CHKSUM = "file://COPYING;md5=b234ee4d69f5fce4486a80fdaf4a4263"
SRC_URI = "\
https://github.com/${BPN}/${BPN}/releases/download/v${PV}/${BP}.tar.bz2 \
+ file://CVE-2026-4948.patch \
file://firewalld.init \
file://run-ptest \
"
^ permalink raw reply related [flat|nested] 28+ messages in thread* [oe][meta-oe][wrynose][PATCH 17/28] freeipmi: patch CVE-2026-50031
2026-09-02 10:04 [oe][meta-oe][wrynose][PATCH 1/28] libmxml: upgrade 4.0.4 -> 4.0.5 ankur.tyagi85
` (14 preceding siblings ...)
2026-09-02 10:04 ` [oe][meta-networking][wrynose][PATCH 16/28] firewalld: patch CVE-2026-4948 ankur.tyagi85
@ 2026-09-02 10:04 ` ankur.tyagi85
2026-09-02 10:05 ` [oe][meta-oe][wrynose][PATCH 18/28] haveged: ignore CVE-2026-41054 ankur.tyagi85
` (10 subsequent siblings)
26 siblings, 0 replies; 28+ messages in thread
From: ankur.tyagi85 @ 2026-09-02 10:04 UTC (permalink / raw)
To: openembedded-devel; +Cc: Ankur Tyagi
From: Ankur Tyagi <ankur.tyagi85@gmail.com>
Backport patches fixing bugs[1][2] associated with the CVE.
Details:
https://nvd.nist.gov/vuln/detail/cve-2026-50031
[1] https://savannah.gnu.org/bugs/index.php?68363
[2] https://savannah.gnu.org/bugs/index.php?68364
Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
---
.../freeipmi/freeipmi/CVE-2026-50031-1.patch | 33 +++++++++++++++++++
.../freeipmi/freeipmi/CVE-2026-50031-2.patch | 33 +++++++++++++++++++
.../freeipmi/freeipmi_1.6.17.bb | 5 ++-
3 files changed, 70 insertions(+), 1 deletion(-)
create mode 100644 meta-oe/recipes-support/freeipmi/freeipmi/CVE-2026-50031-1.patch
create mode 100644 meta-oe/recipes-support/freeipmi/freeipmi/CVE-2026-50031-2.patch
diff --git a/meta-oe/recipes-support/freeipmi/freeipmi/CVE-2026-50031-1.patch b/meta-oe/recipes-support/freeipmi/freeipmi/CVE-2026-50031-1.patch
new file mode 100644
index 0000000000..e73368f473
--- /dev/null
+++ b/meta-oe/recipes-support/freeipmi/freeipmi/CVE-2026-50031-1.patch
@@ -0,0 +1,33 @@
+From 651119e671c7a64e72a79218f87b9f397037383b Mon Sep 17 00:00:00 2001
+From: Albert Chu <chu11@llnl.gov>
+Date: Tue, 19 May 2026 14:44:41 -0700
+Subject: [PATCH] ipmi-oem: fix potential stack corruption
+
+Problem: A buffer was incorrectly defined with a length of 256 bytes
+when it should have been 65536 bytes.
+
+Update the buffer length.
+
+CVE: CVE-2026-50031
+Upstream-Status: Backport [https://cgit.git.savannah.gnu.org/cgit/freeipmi.git/commit/?id=f49a6076b640d802a9a80064089e772b4baa5335]
+
+Dropped changes done to the ChangeLog file.
+
+Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
+---
+ ipmi-oem/ipmi-oem-dell.c | 2 +-
+ 1 file changed, 1 insertion(+), 1 deletion(-)
+
+diff --git a/ipmi-oem/ipmi-oem-dell.c b/ipmi-oem/ipmi-oem-dell.c
+index cf3bad244..f322cdfb8 100644
+--- a/ipmi-oem/ipmi-oem-dell.c
++++ b/ipmi-oem/ipmi-oem-dell.c
+@@ -4207,7 +4207,7 @@ ipmi_oem_dell_set_web_server_config (ipmi_oem_state_data_t *state_data)
+ int
+ ipmi_oem_dell_get_active_directory_config (ipmi_oem_state_data_t *state_data)
+ {
+- uint8_t token_data[IPMI_OEM_MAX_BYTES];
++ uint8_t token_data[IPMI_OEM_DELL_TOKEN_DATA_MAX];
+ uint16_t expected_valid_field_mask = IPMI_OEM_DELL_EXTENDED_CONFIG_AD_CONFIGURATION_ALL_FIELD_MASK;
+ unsigned int token_data_read = 0;
+ unsigned int min_token_data_read = 0;
diff --git a/meta-oe/recipes-support/freeipmi/freeipmi/CVE-2026-50031-2.patch b/meta-oe/recipes-support/freeipmi/freeipmi/CVE-2026-50031-2.patch
new file mode 100644
index 0000000000..b44799cffc
--- /dev/null
+++ b/meta-oe/recipes-support/freeipmi/freeipmi/CVE-2026-50031-2.patch
@@ -0,0 +1,33 @@
+From 1a7113599aa8926f133b5686c7e9b460d009a4e0 Mon Sep 17 00:00:00 2001
+From: Albert Chu <chu11@llnl.gov>
+Date: Tue, 19 May 2026 15:53:50 -0700
+Subject: [PATCH] ipmi-oem: fix potential stack overflow
+
+Problem: A buffer could incorrectly be overflowed in a fujitsu
+command.
+
+Add a guardrail to ensure no overflow.
+
+CVE: CVE-2026-50031
+Upstream-Status: Backport [https://cgit.git.savannah.gnu.org/cgit/freeipmi.git/commit/?id=60dd7014c0b1402c881ef389f4e79ebb7a9e26c4]
+
+Dropped changes to the ChangeLog file.
+
+Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
+---
+ ipmi-oem/ipmi-oem-fujitsu.c | 2 ++
+ 1 file changed, 2 insertions(+)
+
+diff --git a/ipmi-oem/ipmi-oem-fujitsu.c b/ipmi-oem/ipmi-oem-fujitsu.c
+index 2f505229f..10220c9fc 100644
+--- a/ipmi-oem/ipmi-oem-fujitsu.c
++++ b/ipmi-oem/ipmi-oem-fujitsu.c
+@@ -1384,6 +1384,8 @@ ipmi_oem_fujitsu_get_sel_entry_long_text (ipmi_oem_state_data_t *state_data)
+ }
+
+ data_length = bytes_rs[15];
++ if (data_length > IPMI_OEM_FUJITSU_SEL_ENTRY_LONG_TEXT_MAX_DATA_LENGTH)
++ data_length = IPMI_OEM_FUJITSU_SEL_ENTRY_LONG_TEXT_MAX_DATA_LENGTH;
+
+ /* Every response should be NUL terminated, not just the last
+ * component.
diff --git a/meta-oe/recipes-support/freeipmi/freeipmi_1.6.17.bb b/meta-oe/recipes-support/freeipmi/freeipmi_1.6.17.bb
index 7970e0f563..f612caf3ac 100644
--- a/meta-oe/recipes-support/freeipmi/freeipmi_1.6.17.bb
+++ b/meta-oe/recipes-support/freeipmi/freeipmi_1.6.17.bb
@@ -13,7 +13,10 @@ LIC_FILES_CHKSUM = "file://COPYING;md5=d32239bcb673463ab874e80d47fae504 \
file://COPYING.pstdout;md5=d32239bcb673463ab874e80d47fae504 \
file://COPYING.sunbmc;md5=c03f21cd76ff5caba6b890d1213cbfbb"
-SRC_URI = "${GNU_MIRROR}/freeipmi/freeipmi-${PV}.tar.gz"
+SRC_URI = "${GNU_MIRROR}/freeipmi/freeipmi-${PV}.tar.gz \
+ file://CVE-2026-50031-1.patch \
+ file://CVE-2026-50031-2.patch \
+"
SRC_URI[sha256sum] = "16783d10faa28847a795cce0bf86deeaa72b8fbe71d1f0dc1101d13a6b501ec1"
DEPENDS = "libgcrypt"
^ permalink raw reply related [flat|nested] 28+ messages in thread* [oe][meta-oe][wrynose][PATCH 18/28] haveged: ignore CVE-2026-41054
2026-09-02 10:04 [oe][meta-oe][wrynose][PATCH 1/28] libmxml: upgrade 4.0.4 -> 4.0.5 ankur.tyagi85
` (15 preceding siblings ...)
2026-09-02 10:04 ` [oe][meta-oe][wrynose][PATCH 17/28] freeipmi: patch CVE-2026-50031 ankur.tyagi85
@ 2026-09-02 10:05 ` ankur.tyagi85
2026-09-02 10:05 ` [oe][meta-oe][wrynose][PATCH 19/28] gpm: ignore CVE-2025-4558 ankur.tyagi85
` (9 subsequent siblings)
26 siblings, 0 replies; 28+ messages in thread
From: ankur.tyagi85 @ 2026-09-02 10:05 UTC (permalink / raw)
To: openembedded-devel; +Cc: Ankur Tyagi
From: Ankur Tyagi <ankur.tyagi85@gmail.com>
Debian[1] also confirms the fixed version.
Details:
https://nvd.nist.gov/vuln/detail/cve-2026-41054
[1] https://security-tracker.debian.org/tracker/CVE-2026-41054
Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
---
meta-oe/recipes-extended/haveged/haveged_1.9.23.bb | 2 ++
1 file changed, 2 insertions(+)
diff --git a/meta-oe/recipes-extended/haveged/haveged_1.9.23.bb b/meta-oe/recipes-extended/haveged/haveged_1.9.23.bb
index 9dd5f4d378..e04bcb89c1 100644
--- a/meta-oe/recipes-extended/haveged/haveged_1.9.23.bb
+++ b/meta-oe/recipes-extended/haveged/haveged_1.9.23.bb
@@ -21,3 +21,5 @@ EXTRA_OECONF = "\
"
MIPS_INSTRUCTION_SET = "mips"
+
+CVE_STATUS[CVE-2026-41054] = "fixed-version: fixed since v1.9.21"
^ permalink raw reply related [flat|nested] 28+ messages in thread* [oe][meta-oe][wrynose][PATCH 19/28] gpm: ignore CVE-2025-4558
2026-09-02 10:04 [oe][meta-oe][wrynose][PATCH 1/28] libmxml: upgrade 4.0.4 -> 4.0.5 ankur.tyagi85
` (16 preceding siblings ...)
2026-09-02 10:05 ` [oe][meta-oe][wrynose][PATCH 18/28] haveged: ignore CVE-2026-41054 ankur.tyagi85
@ 2026-09-02 10:05 ` ankur.tyagi85
2026-09-02 10:05 ` [oe][meta-oe][wrynose][PATCH 20/28] gpsd: patch CVE-2026-58459 ankur.tyagi85
` (8 subsequent siblings)
26 siblings, 0 replies; 28+ messages in thread
From: ankur.tyagi85 @ 2026-09-02 10:05 UTC (permalink / raw)
To: openembedded-devel; +Cc: Ankur Tyagi
From: Ankur Tyagi <ankur.tyagi85@gmail.com>
Details:
https://nvd.nist.gov/vuln/detail/cve-2025-4558
Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
---
meta-oe/recipes-support/gpm/gpm_git.bb | 2 ++
1 file changed, 2 insertions(+)
diff --git a/meta-oe/recipes-support/gpm/gpm_git.bb b/meta-oe/recipes-support/gpm/gpm_git.bb
index 155e56bdef..9c07f334b0 100644
--- a/meta-oe/recipes-support/gpm/gpm_git.bb
+++ b/meta-oe/recipes-support/gpm/gpm_git.bb
@@ -42,3 +42,5 @@ do_install:append () {
}
SYSTEMD_SERVICE:${PN} = "gpm.service"
+
+CVE_STATUS[CVE-2025-4558] = "cpe-incorrect: this CVE is for GPM from WormHole Tech"
^ permalink raw reply related [flat|nested] 28+ messages in thread* [oe][meta-oe][wrynose][PATCH 20/28] gpsd: patch CVE-2026-58459
2026-09-02 10:04 [oe][meta-oe][wrynose][PATCH 1/28] libmxml: upgrade 4.0.4 -> 4.0.5 ankur.tyagi85
` (17 preceding siblings ...)
2026-09-02 10:05 ` [oe][meta-oe][wrynose][PATCH 19/28] gpm: ignore CVE-2025-4558 ankur.tyagi85
@ 2026-09-02 10:05 ` ankur.tyagi85
2026-09-02 10:05 ` [oe][meta-multimedia][wrynose][PATCH 21/28] gerbera: ignore CVE-2025-23386 ankur.tyagi85
` (7 subsequent siblings)
26 siblings, 0 replies; 28+ messages in thread
From: ankur.tyagi85 @ 2026-09-02 10:05 UTC (permalink / raw)
To: openembedded-devel; +Cc: Ankur Tyagi
From: Ankur Tyagi <ankur.tyagi85@gmail.com>
Details:
https://nvd.nist.gov/vuln/detail/cve-2026-58459
Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
---
.../gpsd/gpsd/CVE-2026-58459-1.patch | 48 +++++++++++++++
.../gpsd/gpsd/CVE-2026-58459-2.patch | 46 +++++++++++++++
.../gpsd/gpsd/CVE-2026-58459-3.patch | 58 +++++++++++++++++++
.../recipes-navigation/gpsd/gpsd_3.27.5.bb | 3 +
4 files changed, 155 insertions(+)
create mode 100644 meta-oe/recipes-navigation/gpsd/gpsd/CVE-2026-58459-1.patch
create mode 100644 meta-oe/recipes-navigation/gpsd/gpsd/CVE-2026-58459-2.patch
create mode 100644 meta-oe/recipes-navigation/gpsd/gpsd/CVE-2026-58459-3.patch
diff --git a/meta-oe/recipes-navigation/gpsd/gpsd/CVE-2026-58459-1.patch b/meta-oe/recipes-navigation/gpsd/gpsd/CVE-2026-58459-1.patch
new file mode 100644
index 0000000000..aec3acdeb2
--- /dev/null
+++ b/meta-oe/recipes-navigation/gpsd/gpsd/CVE-2026-58459-1.patch
@@ -0,0 +1,48 @@
+From 485b793ee3a54865ff9d8efffd2fe9a309666be0 Mon Sep 17 00:00:00 2001
+From: "Gary E. Miller" <gem@rellim.com>
+Date: Wed, 1 Jul 2026 17:55:57 -0700
+Subject: [PATCH 1/1] clients/gpsprof.py.in: Quote double quotes in title.
+
+Someone could use the double quote to break out of the
+string and add gnuplot commnds.
+
+For issue 404.
+Reported by: CuB3y0nd, and Wade Sparks <wsparks@vulncheck.com>
+
+(cherry picked from commit 5581ba196d826a984fbfaf792b7d58535f9911ce)
+
+CVE: CVE-2026-58459
+Upstream-Status: Backport [https://gitlab.com/gpsd/gpsd/-/commit/5581ba196d826a984fbfaf792b7d58535f9911ce]
+Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
+---
+ clients/gpsprof.py.in | 8 ++++++--
+ 1 file changed, 6 insertions(+), 2 deletions(-)
+
+diff --git a/clients/gpsprof.py.in b/clients/gpsprof.py.in
+index 5c18f50ff..261e72665 100644
+--- a/clients/gpsprof.py.in
++++ b/clients/gpsprof.py.in
+@@ -198,6 +198,10 @@ class plotter(object):
+ if 'subtype' in self.device:
+ desc += "\\n%s" % self.device['subtype']
+
++ # escape ", and \n, for gnuplot, to not break strings
++ desc = desc.replace('"', '\\042')
++ desc = desc.replace('\n', '')
++
+ return desc
+
+ def collect(self, verb, log_fp=None):
+@@ -1262,10 +1266,10 @@ if __name__ == '__main__':
+ # Ship the plot to standard output
+ if not options.title:
+ options.title = plot.whatami()
+- # escape " for gnuplot
+- options.title = options.title.replace('"', '\\"')
+ if options.subtitle:
+ options.title += '\\n' + options.subtitle
++ # escape " for gnuplot, to not break strings
++ options.title = options.title.replace('"', '\\042')
+ term_opts = ""
+ truecolor_terms = ['png', 'sixelgd', 'wxt']
+ if options.terminal in truecolor_terms:
diff --git a/meta-oe/recipes-navigation/gpsd/gpsd/CVE-2026-58459-2.patch b/meta-oe/recipes-navigation/gpsd/gpsd/CVE-2026-58459-2.patch
new file mode 100644
index 0000000000..dd50d27695
--- /dev/null
+++ b/meta-oe/recipes-navigation/gpsd/gpsd/CVE-2026-58459-2.patch
@@ -0,0 +1,46 @@
+From 6031dc96603d5537a650068a2f8d42ef90d9d32d Mon Sep 17 00:00:00 2001
+From: "Gary E. Miller" <gem@rellim.com>
+Date: Tue, 7 Jul 2026 13:41:54 -0700
+Subject: [PATCH] clients/gpsprof.py.in: Quote back ticks in title.
+
+Someone could use the back tick to break out of the string and add
+gnuplot commnds.
+
+For issue 404.
+Reported by: CuB3y0nd, and Wade Sparks <wsparks@vulncheck.com>
+
+(cherry picked from commit 1a6bb7bcbdf58aa940132e630870af061dc88537)
+
+CVE: CVE-2026-58459
+Upstream-Status: Backport [https://gitlab.com/gpsd/gpsd/-/commit/1a6bb7bcbdf58aa940132e630870af061dc88537]
+Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
+---
+ clients/gpsprof.py.in | 6 ++++--
+ 1 file changed, 4 insertions(+), 2 deletions(-)
+
+diff --git a/clients/gpsprof.py.in b/clients/gpsprof.py.in
+index 261e72665..202214769 100644
+--- a/clients/gpsprof.py.in
++++ b/clients/gpsprof.py.in
+@@ -198,8 +198,9 @@ class plotter(object):
+ if 'subtype' in self.device:
+ desc += "\\n%s" % self.device['subtype']
+
+- # escape ", and \n, for gnuplot, to not break strings
++ # escape ", `, and \n, for gnuplot, to not break strings
+ desc = desc.replace('"', '\\042')
++ desc = desc.replace('`', '\\140')
+ desc = desc.replace('\n', '')
+
+ return desc
+@@ -1268,8 +1269,9 @@ if __name__ == '__main__':
+ options.title = plot.whatami()
+ if options.subtitle:
+ options.title += '\\n' + options.subtitle
+- # escape " for gnuplot, to not break strings
++ # escape ", and`, for gnuplot, to not break strings
+ options.title = options.title.replace('"', '\\042')
++ options.title = options.title.replace('"', '\\140')
+ term_opts = ""
+ truecolor_terms = ['png', 'sixelgd', 'wxt']
+ if options.terminal in truecolor_terms:
diff --git a/meta-oe/recipes-navigation/gpsd/gpsd/CVE-2026-58459-3.patch b/meta-oe/recipes-navigation/gpsd/gpsd/CVE-2026-58459-3.patch
new file mode 100644
index 0000000000..a40edfe6d1
--- /dev/null
+++ b/meta-oe/recipes-navigation/gpsd/gpsd/CVE-2026-58459-3.patch
@@ -0,0 +1,58 @@
+From 54484dccf7265e51368eef03d99ea7a370c15e06 Mon Sep 17 00:00:00 2001
+From: "Gary E. Miller" <gem@rellim.com>
+Date: Tue, 7 Jul 2026 14:23:56 -0700
+Subject: [PATCH] clients/gpsprof.py.in: Quote back ticks in title.
+
+Second try. Also quote "terminal".
+
+Someone could use the back tick to break out of the string and add
+gnuplot commnds.
+
+For issue 404.
+Reported by: CuB3y0nd, and Wade Sparks <wsparks@vulncheck.com>
+
+(cherry picked from commit 4c06658e988f4ced1a7a574ce082a22ef625df56)
+
+CVE: CVE-2026-58459
+Upstream-Status: Backport [https://gitlab.com/gpsd/gpsd/-/commit/4c06658e988f4ced1a7a574ce082a22ef625df56]
+Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
+---
+ clients/gpsprof.py.in | 14 ++++++++++----
+ 1 file changed, 10 insertions(+), 4 deletions(-)
+
+diff --git a/clients/gpsprof.py.in b/clients/gpsprof.py.in
+index 202214769..e91367ee3 100644
+--- a/clients/gpsprof.py.in
++++ b/clients/gpsprof.py.in
+@@ -200,7 +200,7 @@ class plotter(object):
+
+ # escape ", `, and \n, for gnuplot, to not break strings
+ desc = desc.replace('"', '\\042')
+- desc = desc.replace('`', '\\140')
++ desc = desc.replace("\x60", '\\140')
+ desc = desc.replace('\n', '')
+
+ return desc
+@@ -1271,13 +1271,19 @@ if __name__ == '__main__':
+ options.title += '\\n' + options.subtitle
+ # escape ", and`, for gnuplot, to not break strings
+ options.title = options.title.replace('"', '\\042')
+- options.title = options.title.replace('"', '\\140')
++ options.title = options.title.replace("\x60", '\\140')
+ term_opts = ""
+ truecolor_terms = ['png', 'sixelgd', 'wxt']
+ if options.terminal in truecolor_terms:
+ term_opts = 'truecolor'
+- sys.stdout.write("set terminal %s size 800,950 %s\n"
+- "set termoption enhanced\n"
++
++ # escape ", `, and \n, for gnuplot, to not break strings
++ options.terminal = options.terminal.replace('"', '\\042')
++ options.terminal = options.terminal.replace("\x60", '\\140')
++ options.terminal = options.terminal.replace('\n', '')
++
++ sys.stdout.write('set terminal "%s" size 800,950 %s\n'
++ 'set termoption enhanced\n'
+ % (options.terminal, term_opts))
+ # double quotes on title so \n is parsed by gnuplot
+ sys.stdout.write('set title noenhanced "%s\\n\\n"\n' % options.title)
diff --git a/meta-oe/recipes-navigation/gpsd/gpsd_3.27.5.bb b/meta-oe/recipes-navigation/gpsd/gpsd_3.27.5.bb
index f7ca367fa4..7819dc532d 100644
--- a/meta-oe/recipes-navigation/gpsd/gpsd_3.27.5.bb
+++ b/meta-oe/recipes-navigation/gpsd/gpsd_3.27.5.bb
@@ -8,6 +8,9 @@ BUGTRACKER = "https://gitlab.com/gpsd/gpsd/-/issues"
HOMEPAGE = "https://gpsd.io/"
SRC_URI = "${SAVANNAH_GNU_MIRROR}/${BPN}/${BP}.tar.gz \
+ file://CVE-2026-58459-1.patch \
+ file://CVE-2026-58459-2.patch \
+ file://CVE-2026-58459-3.patch \
file://gpsd.init \
"
SRC_URI[sha256sum] = "409873f5048462ef1ac413a51ab35caa8b50b31be62b3347bee1cc2994e7c649"
^ permalink raw reply related [flat|nested] 28+ messages in thread* [oe][meta-multimedia][wrynose][PATCH 21/28] gerbera: ignore CVE-2025-23386
2026-09-02 10:04 [oe][meta-oe][wrynose][PATCH 1/28] libmxml: upgrade 4.0.4 -> 4.0.5 ankur.tyagi85
` (18 preceding siblings ...)
2026-09-02 10:05 ` [oe][meta-oe][wrynose][PATCH 20/28] gpsd: patch CVE-2026-58459 ankur.tyagi85
@ 2026-09-02 10:05 ` ankur.tyagi85
2026-09-02 10:05 ` [oe][meta-oe][wrynose][PATCH 22/28] hostapd: patch CVE-2026-58374 ankur.tyagi85
` (6 subsequent siblings)
26 siblings, 0 replies; 28+ messages in thread
From: ankur.tyagi85 @ 2026-09-02 10:05 UTC (permalink / raw)
To: openembedded-devel; +Cc: Ankur Tyagi
From: Ankur Tyagi <ankur.tyagi85@gmail.com>
Details:
https://nvd.nist.gov/vuln/detail/cve-2025-23386
This vulnerability is due to openSUSE specific packaging issue.
Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
---
meta-multimedia/recipes-multimedia/gerbera/gerbera_3.0.0.bb | 2 ++
1 file changed, 2 insertions(+)
diff --git a/meta-multimedia/recipes-multimedia/gerbera/gerbera_3.0.0.bb b/meta-multimedia/recipes-multimedia/gerbera/gerbera_3.0.0.bb
index fdbd91f9b0..403565b7fb 100644
--- a/meta-multimedia/recipes-multimedia/gerbera/gerbera_3.0.0.bb
+++ b/meta-multimedia/recipes-multimedia/gerbera/gerbera_3.0.0.bb
@@ -27,3 +27,5 @@ PACKAGECONFIG[magic] = "-DWITH_MAGIC=TRUE,-DWITH_MAGIC=FALSE,file"
PACKAGECONFIG[js] = "-DWITH_JS=TRUE,-DWITH_JS=FALSE,duktape"
SECURITY_CFLAGS:riscv64 = "${SECURITY_NOPIE_CFLAGS}"
+
+CVE_STATUS[CVE-2025-23386] = "not-applicable-platform: The vulnerability is openSUSE specific"
^ permalink raw reply related [flat|nested] 28+ messages in thread* [oe][meta-oe][wrynose][PATCH 22/28] hostapd: patch CVE-2026-58374
2026-09-02 10:04 [oe][meta-oe][wrynose][PATCH 1/28] libmxml: upgrade 4.0.4 -> 4.0.5 ankur.tyagi85
` (19 preceding siblings ...)
2026-09-02 10:05 ` [oe][meta-multimedia][wrynose][PATCH 21/28] gerbera: ignore CVE-2025-23386 ankur.tyagi85
@ 2026-09-02 10:05 ` ankur.tyagi85
2026-09-02 10:05 ` [oe][meta-oe][wrynose][PATCH 23/28] hdf5: patch CVE-2026-17572 ankur.tyagi85
` (5 subsequent siblings)
26 siblings, 0 replies; 28+ messages in thread
From: ankur.tyagi85 @ 2026-09-02 10:05 UTC (permalink / raw)
To: openembedded-devel; +Cc: Ankur Tyagi
From: Ankur Tyagi <ankur.tyagi85@gmail.com>
Apply hostapd patches recommended by upstream[1] as mentioned in the NVD[2]
[1] https://w1.fi/security/2026-1/
[2] https://nvd.nist.gov/vuln/detail/cve-2026-58374
Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
---
.../hostapd/hostapd/CVE-2026-58374-1.patch | 49 +++++++++++++++++++
.../hostapd/hostapd/CVE-2026-58374-2.patch | 43 ++++++++++++++++
.../hostapd/hostapd_2.11.bb | 2 +
3 files changed, 94 insertions(+)
create mode 100644 meta-oe/recipes-connectivity/hostapd/hostapd/CVE-2026-58374-1.patch
create mode 100644 meta-oe/recipes-connectivity/hostapd/hostapd/CVE-2026-58374-2.patch
diff --git a/meta-oe/recipes-connectivity/hostapd/hostapd/CVE-2026-58374-1.patch b/meta-oe/recipes-connectivity/hostapd/hostapd/CVE-2026-58374-1.patch
new file mode 100644
index 0000000000..9bb8974c50
--- /dev/null
+++ b/meta-oe/recipes-connectivity/hostapd/hostapd/CVE-2026-58374-1.patch
@@ -0,0 +1,49 @@
+From 7ab2de9eecf5409f6af1461cf89dbf217930bd45 Mon Sep 17 00:00:00 2001
+From: Jouni Malinen <jouni.malinen@oss.qualcomm.com>
+Date: Tue, 31 Mar 2026 23:24:04 +0300
+Subject: [PATCH] AP MLD: Fix link ID validation in Basic MLE parsing
+
+Link ID 15 can be indicated in the field, but that is not a valid value
+and must be rejected to avoid issues pointing beyond the array of links
+for a non-AP MLD. Without this, an invalid MLE could result in writing
+beyond the end of the buffer and causing process termination or
+unexpected behavior.
+
+Fixes: 5f5db9366cde ("AP: MLO: Process Multi-Link element from (Re)Association Request frame")
+Signed-off-by: Jouni Malinen <jouni.malinen@oss.qualcomm.com>
+
+CVE: CVE-2026-58374
+Upstream-Status: Backport [https://git.w1.fi/cgit/hostap/commit/?id=46dd5a4ffc9bcf44cf8fc45120b3e1e5ec922187]
+Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
+---
+ src/ap/ieee802_11_eht.c | 10 ++++++++--
+ 1 file changed, 8 insertions(+), 2 deletions(-)
+
+diff --git a/src/ap/ieee802_11_eht.c b/src/ap/ieee802_11_eht.c
+index b935ee8..804808c 100644
+--- a/src/ap/ieee802_11_eht.c
++++ b/src/ap/ieee802_11_eht.c
+@@ -1262,6 +1262,7 @@ u16 hostapd_process_ml_assoc_req(struct hostapd_data *hapd,
+ size_t sub_elem_len = *(pos + 1);
+ size_t sta_info_len;
+ u16 control;
++ u8 link_id;
+
+ wpa_printf(MSG_DEBUG, "MLD: sub element len=%zu",
+ sub_elem_len);
+@@ -1302,8 +1303,13 @@ u16 hostapd_process_ml_assoc_req(struct hostapd_data *hapd,
+ goto out;
+ }
+ control = WPA_GET_LE16(pos);
+- link_info = &info->links[control &
+- EHT_PER_STA_CTRL_LINK_ID_MSK];
++ link_id = control & BASIC_MLE_STA_CTRL_LINK_ID_MASK;
++ if (link_id >= MAX_NUM_MLD_LINKS) {
++ wpa_printf(MSG_DEBUG,
++ "MLD: Invalid Link ID in Per-STA Profile subelement");
++ goto out;
++ }
++ link_info = &info->links[link_id];
+ pos += 2;
+ ml_len -= 2;
+ sub_elem_len -= 2;
diff --git a/meta-oe/recipes-connectivity/hostapd/hostapd/CVE-2026-58374-2.patch b/meta-oe/recipes-connectivity/hostapd/hostapd/CVE-2026-58374-2.patch
new file mode 100644
index 0000000000..7881e687ff
--- /dev/null
+++ b/meta-oe/recipes-connectivity/hostapd/hostapd/CVE-2026-58374-2.patch
@@ -0,0 +1,43 @@
+From 86cefb9f27e0e2d31d857bea483b0735e6441801 Mon Sep 17 00:00:00 2001
+From: Jouni Malinen <jouni.malinen@oss.qualcomm.com>
+Date: Mon, 18 May 2026 15:45:15 +0300
+Subject: [PATCH] AP MLD: Verify AP MLD link ID validity before updating bitmap
+ of links
+
+Link ID is 0..14, so ignore value 15 if an invalid frame is processed.
+It does not look like the invalid value was actually used to reference
+any local array, but in any case, it is better to not mark an invalid
+link as being specified.
+
+Signed-off-by: Jouni Malinen <jouni.malinen@oss.qualcomm.com>
+
+CVE: CVE-2026-58374
+Upstream-Status: Backport [https://git.w1.fi/cgit/hostap/commit/?id=ce1a8612e309fe86133ecf05ffb452b0bdf3b035]
+Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
+---
+ src/ap/beacon.c | 5 ++++-
+ 1 file changed, 4 insertions(+), 1 deletion(-)
+
+diff --git a/src/ap/beacon.c b/src/ap/beacon.c
+index cec0c98..cc295c1 100644
+--- a/src/ap/beacon.c
++++ b/src/ap/beacon.c
+@@ -1305,6 +1305,7 @@ static bool parse_ml_probe_req(const struct ieee80211_eht_ml *ml, size_t ml_len,
+ for_each_element_id(sub, 0, pos, len) {
+ const struct ieee80211_eht_per_sta_profile *sta;
+ u16 sta_control;
++ u8 link_id;
+
+ if (*links == 0xffff)
+ *links = 0;
+@@ -1324,7 +1325,9 @@ static bool parse_ml_probe_req(const struct ieee80211_eht_ml *ml, size_t ml_len,
+ * partial profile was requested.
+ */
+ sta_control = le_to_host16(sta->sta_control);
+- *links |= BIT(sta_control & EHT_PER_STA_CTRL_LINK_ID_MSK);
++ link_id = sta_control & BASIC_MLE_STA_CTRL_LINK_ID_MASK;
++ if (link_id < MAX_NUM_MLD_LINKS)
++ *links |= BIT(link_id);
+ }
+
+ if (!for_each_element_completed(sub, pos, len)) {
diff --git a/meta-oe/recipes-connectivity/hostapd/hostapd_2.11.bb b/meta-oe/recipes-connectivity/hostapd/hostapd_2.11.bb
index ce1c145fd7..f98bad9ef6 100644
--- a/meta-oe/recipes-connectivity/hostapd/hostapd_2.11.bb
+++ b/meta-oe/recipes-connectivity/hostapd/hostapd_2.11.bb
@@ -15,6 +15,8 @@ SRC_URI = " \
file://hostapd.service \
file://CVE-2025-24912-01.patch \
file://CVE-2025-24912-02.patch \
+ file://CVE-2026-58374-1.patch \
+ file://CVE-2026-58374-2.patch \
"
^ permalink raw reply related [flat|nested] 28+ messages in thread* [oe][meta-oe][wrynose][PATCH 23/28] hdf5: patch CVE-2026-17572
2026-09-02 10:04 [oe][meta-oe][wrynose][PATCH 1/28] libmxml: upgrade 4.0.4 -> 4.0.5 ankur.tyagi85
` (20 preceding siblings ...)
2026-09-02 10:05 ` [oe][meta-oe][wrynose][PATCH 22/28] hostapd: patch CVE-2026-58374 ankur.tyagi85
@ 2026-09-02 10:05 ` ankur.tyagi85
2026-09-02 10:05 ` [oe][meta-oe][wrynose][PATCH 24/28] hdf5: patch CVE-2026-17573 ankur.tyagi85
` (4 subsequent siblings)
26 siblings, 0 replies; 28+ messages in thread
From: ankur.tyagi85 @ 2026-09-02 10:05 UTC (permalink / raw)
To: openembedded-devel; +Cc: Ankur Tyagi
From: Ankur Tyagi <ankur.tyagi85@gmail.com>
Backport patch from the PR[1] fixing the issue[2] mentioned in the NVD[3].
Debian[4] has also identified the commit.
[1] https://github.com/HDFGroup/hdf5/pull/6499
[2] https://github.com/HDFGroup/hdf5/issues/6501
[3] https://nvd.nist.gov/vuln/detail/cve-2026-17572
[4] https://security-tracker.debian.org/tracker/CVE-2026-17572
Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
---
.../hdf5/files/CVE-2026-17572.patch | 253 ++++++++++++++++++
meta-oe/recipes-support/hdf5/hdf5_2.0.0.bb | 1 +
2 files changed, 254 insertions(+)
create mode 100644 meta-oe/recipes-support/hdf5/files/CVE-2026-17572.patch
diff --git a/meta-oe/recipes-support/hdf5/files/CVE-2026-17572.patch b/meta-oe/recipes-support/hdf5/files/CVE-2026-17572.patch
new file mode 100644
index 0000000000..373a6c374e
--- /dev/null
+++ b/meta-oe/recipes-support/hdf5/files/CVE-2026-17572.patch
@@ -0,0 +1,253 @@
+From 606bb0a0282d0b056a3bdda1d489a608deee78d2 Mon Sep 17 00:00:00 2001
+From: Nayyar <nayyar@bugqore.com>
+Date: Tue, 14 Jul 2026 23:39:56 +0530
+Subject: [PATCH] reject SOHM list message count exceeding list_max (#6499)
+
+* bound SOHM list decode to list_max messages
+
+* Add tsohm test for out-of-range SOHM list message count
+
+Create a file with a shared-message list index, corrupt the on-disk
+message count so it exceeds list_max (repairing the table checksum),
+and confirm reopening rejects the file instead of overrunning the
+list image buffer and message array.
+
+---------
+
+Co-authored-by: H. Joe Lee <hyoklee@hdfgroup.org>
+Co-authored-by: Larry Knox <lrknox@hdfgroup.org>
+
+CVE: CVE-2026-17572
+Upstream-Status: Backport [https://github.com/HDFGroup/hdf5/commit/20f0b9564bc46154e60f8d35578720a599d41552]
+
+Dropped changes to the CHANGELOG file.
+
+Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
+---
+ src/H5SMcache.c | 14 ++++
+ test/tsohm.c | 173 ++++++++++++++++++++++++++++++++++++++++++++++++
+ 2 files changed, 187 insertions(+)
+
+diff --git a/src/H5SMcache.c b/src/H5SMcache.c
+index eb6d612a78..96687ffed9 100644
+--- a/src/H5SMcache.c
++++ b/src/H5SMcache.c
+@@ -489,6 +489,12 @@ H5SM__cache_list_verify_chksum(const void *_image, size_t H5_ATTR_UNUSED len, vo
+ assert(image);
+ assert(udata);
+
++ /* The buffer only holds list_max messages; a corrupted header whose message
++ * count exceeds that would size the checksum region past the end of it.
++ */
++ if (udata->header->num_messages > udata->header->list_max)
++ HGOTO_ERROR(H5E_SOHM, H5E_BADVALUE, FAIL, "number of SOHM messages exceeds list size");
++
+ /* Exact size with checksum at the end */
+ chk_size = H5SM_LIST_SIZE(udata->f, udata->header->num_messages);
+
+@@ -552,6 +558,14 @@ H5SM__cache_list_deserialize(const void *_image, size_t H5_ATTR_NDEBUG_UNUSED le
+ HGOTO_ERROR(H5E_SOHM, H5E_CANTLOAD, NULL, "bad SOHM list signature");
+ image += H5_SIZEOF_MAGIC;
+
++ /* The message array is sized for list_max entries; a list index always
++ * holds at most that many before it is promoted to a B-tree. Reject a
++ * corrupted header whose message count would drive the decode loop past
++ * the allocation and the input buffer.
++ */
++ if (udata->header->num_messages > udata->header->list_max)
++ HGOTO_ERROR(H5E_SOHM, H5E_CANTLOAD, NULL, "number of SOHM messages exceeds list size");
++
+ /* Read messages into the list array */
+ ctx.sizeof_addr = H5F_SIZEOF_ADDR(udata->f);
+ for (u = 0; u < udata->header->num_messages; u++) {
+diff --git a/test/tsohm.c b/test/tsohm.c
+index 1652c9b044..61036e7dc3 100644
+--- a/test/tsohm.c
++++ b/test/tsohm.c
+@@ -3702,6 +3702,175 @@ test_sohm_external_dtype(void)
+ free(orig);
+ } /* test_sohm_external_dtype */
+
++/*-------------------------------------------------------------------------
++ * Function: test_sohm_reject_bad_count
++ *
++ * Purpose: A shared-message list index holds at most list_max messages
++ * on disk before it is promoted to a B-tree, and both the list
++ * image buffer and the in-memory message array are sized for
++ * list_max entries. Corrupt the on-disk message count so it
++ * exceeds list_max and verify the list load rejects the file
++ * instead of sizing a read or indexing the array past its end.
++ *
++ *-------------------------------------------------------------------------
++ */
++static void
++test_sohm_reject_bad_count(void)
++{
++ hid_t fcpl_id = H5I_INVALID_HID;
++ hid_t fid = H5I_INVALID_HID;
++ hid_t sid = H5I_INVALID_HID;
++ hid_t did = H5I_INVALID_HID;
++ hsize_t dims[1] = {4};
++ FILE *fp = NULL;
++ uint8_t *buf = NULL;
++ long fsize = 0;
++ long table_off = -1;
++ unsigned list_max = 100;
++ uint32_t chksum;
++ size_t pos;
++ int i;
++ herr_t ret;
++
++ /* On-disk shared-message table layout for a file with a single index and
++ * 8-byte addresses: a 4-byte "SMTB" signature, one index record, then a
++ * 4-byte checksum. Within the record the 16-bit message count follows the
++ * (version, index type, message types, minimum size) prefix and the 16-bit
++ * list and B-tree cutoffs.
++ */
++ const size_t rec_size = 1 + 1 + 2 + 4 + 3 * 2 + 8 + 8; /* 30 */
++ const size_t table_body = (size_t)H5_SIZEOF_MAGIC + rec_size; /* 34 */
++ const size_t num_msgs_off = (size_t)H5_SIZEOF_MAGIC + (1 + 1 + 2 + 4 + 2 + 2); /* 16 */
++
++ MESSAGE(5, ("Testing rejection of an out-of-range SOHM list message count\n"));
++
++ /* Create a file whose single shared-message index is a list that can hold
++ * up to list_max messages before converting to a B-tree.
++ */
++ fcpl_id = H5Pcreate(H5P_FILE_CREATE);
++ CHECK_I(fcpl_id, "H5Pcreate");
++ ret = H5Pset_shared_mesg_nindexes(fcpl_id, 1);
++ CHECK_I(ret, "H5Pset_shared_mesg_nindexes");
++ ret = H5Pset_shared_mesg_index(fcpl_id, 0, H5O_SHMESG_SDSPACE_FLAG | H5O_SHMESG_DTYPE_FLAG, 1);
++ CHECK_I(ret, "H5Pset_shared_mesg_index");
++ ret = H5Pset_shared_mesg_phase_change(fcpl_id, list_max, 0);
++ CHECK_I(ret, "H5Pset_shared_mesg_phase_change");
++
++ fid = H5Fcreate(FILENAME, H5F_ACC_TRUNC, fcpl_id, H5P_DEFAULT);
++ CHECK_I(fid, "H5Fcreate");
++
++ /* Several datasets sharing one dataspace and datatype leave the index a
++ * list holding a couple of messages, well under list_max.
++ */
++ sid = H5Screate_simple(1, dims, NULL);
++ CHECK_I(sid, "H5Screate_simple");
++ for (i = 0; i < 5; i++) {
++ char name[16];
++
++ snprintf(name, sizeof(name), "dset%d", i);
++ did = H5Dcreate2(fid, name, H5T_NATIVE_INT, sid, H5P_DEFAULT, H5P_DEFAULT, H5P_DEFAULT);
++ CHECK_I(did, "H5Dcreate2");
++ ret = H5Dclose(did);
++ CHECK_I(ret, "H5Dclose");
++ }
++ ret = H5Sclose(sid);
++ CHECK_I(ret, "H5Sclose");
++ ret = H5Fclose(fid);
++ CHECK_I(ret, "H5Fclose");
++
++ /* Read the whole file so the shared-message table can be located and edited. */
++ fp = fopen(FILENAME, "rb");
++ CHECK_PTR(fp, "fopen");
++ if (fp) {
++ if (fseek(fp, 0, SEEK_END) != 0)
++ TestErrPrintf("fseek failed at line %d\n", __LINE__);
++ fsize = ftell(fp);
++ if (fsize <= (long)(table_body + 4))
++ TestErrPrintf("unexpected file size %ld at line %d\n", fsize, __LINE__);
++ rewind(fp);
++
++ buf = (uint8_t *)malloc((size_t)fsize);
++ CHECK_PTR(buf, "malloc");
++ if (buf && fread(buf, 1, (size_t)fsize, fp) != (size_t)fsize)
++ TestErrPrintf("fread failed at line %d\n", __LINE__);
++ if (fclose(fp) != 0)
++ TestErrPrintf("fclose failed at line %d\n", __LINE__);
++ fp = NULL;
++ }
++
++ /* Find the shared-message table by signature, confirming the match with the
++ * stored checksum so the correct bytes are edited.
++ */
++ for (pos = 0; buf && (pos + table_body + 4) <= (size_t)fsize; pos++) {
++ if (memcmp(buf + pos, H5SM_TABLE_MAGIC, (size_t)H5_SIZEOF_MAGIC) != 0)
++ continue;
++
++ chksum = (uint32_t)buf[pos + table_body] | ((uint32_t)buf[pos + table_body + 1] << 8) |
++ ((uint32_t)buf[pos + table_body + 2] << 16) | ((uint32_t)buf[pos + table_body + 3] << 24);
++ if (chksum == H5_checksum_metadata(buf + pos, table_body, 0)) {
++ table_off = (long)pos;
++ break;
++ }
++ }
++ if (table_off < 0)
++ TestErrPrintf("could not locate the shared-message table in %s\n", FILENAME);
++
++ if (buf && table_off >= 0) {
++ unsigned bad_count = list_max + 200; /* well past the list_max cutoff */
++ size_t base = (size_t)table_off;
++
++ /* Overwrite the 16-bit message count and repair the table checksum so
++ * the table loads and the corruption is only caught at the list.
++ */
++ buf[base + num_msgs_off] = (uint8_t)(bad_count & 0xff);
++ buf[base + num_msgs_off + 1] = (uint8_t)((bad_count >> 8) & 0xff);
++
++ chksum = H5_checksum_metadata(buf + base, table_body, 0);
++ buf[base + table_body] = (uint8_t)(chksum & 0xff);
++ buf[base + table_body + 1] = (uint8_t)((chksum >> 8) & 0xff);
++ buf[base + table_body + 2] = (uint8_t)((chksum >> 16) & 0xff);
++ buf[base + table_body + 3] = (uint8_t)((chksum >> 24) & 0xff);
++
++ fp = fopen(FILENAME, "r+b");
++ CHECK_PTR(fp, "fopen");
++ if (fp) {
++ if (fwrite(buf, 1, (size_t)fsize, fp) != (size_t)fsize)
++ TestErrPrintf("fwrite failed at line %d\n", __LINE__);
++ if (fclose(fp) != 0)
++ TestErrPrintf("fclose failed at line %d\n", __LINE__);
++ fp = NULL;
++ }
++
++ /* Reopen and share a new message, which protects the list and drives
++ * the vulnerable decode. The load should reject the file cleanly.
++ */
++ fid = H5Fopen(FILENAME, H5F_ACC_RDWR, H5P_DEFAULT);
++ CHECK_I(fid, "H5Fopen");
++ sid = H5Screate_simple(1, dims, NULL);
++ CHECK_I(sid, "H5Screate_simple");
++
++ H5E_BEGIN_TRY
++ {
++ did = H5Dcreate2(fid, "trigger", H5T_NATIVE_INT, sid, H5P_DEFAULT, H5P_DEFAULT, H5P_DEFAULT);
++ }
++ H5E_END_TRY
++
++ if (did >= 0) {
++ TestErrPrintf("dataset creation succeeded on a corrupted SOHM list at line %d\n", __LINE__);
++ H5Dclose(did);
++ }
++
++ ret = H5Sclose(sid);
++ CHECK_I(ret, "H5Sclose");
++ ret = H5Fclose(fid);
++ CHECK_I(ret, "H5Fclose");
++ }
++
++ free(buf);
++ ret = H5Pclose(fcpl_id);
++ CHECK_I(ret, "H5Pclose");
++} /* test_sohm_reject_bad_count */
++
+ /****************************************************************
+ **
+ ** test_sohm(): Main Shared Object Header Message testing routine.
+@@ -3755,6 +3924,10 @@ test_sohm(void H5_ATTR_UNUSED *params)
+
+ test_sohm_extend_dset(); /* Test extending shared datasets */
+ test_sohm_external_dtype(); /* Test using datatype in another file */
++
++ /* Editing the on-disk table in place needs the single-file sec2 layout */
++ if (default_driver)
++ test_sohm_reject_bad_count(); /* Test rejecting a bad SOHM list message count */
+ } /* test_sohm */
+
+ /*-------------------------------------------------------------------------
diff --git a/meta-oe/recipes-support/hdf5/hdf5_2.0.0.bb b/meta-oe/recipes-support/hdf5/hdf5_2.0.0.bb
index 20b2f1100e..cd489bdc3f 100644
--- a/meta-oe/recipes-support/hdf5/hdf5_2.0.0.bb
+++ b/meta-oe/recipes-support/hdf5/hdf5_2.0.0.bb
@@ -18,6 +18,7 @@ SRC_URI = "https://support.hdfgroup.org/releases/hdf5/v2_0/v2_0_0/downloads/${BP
file://0001-cmake-remove-build-flags.patch \
file://CVE-2026-26199.patch \
file://CVE-2026-26197.patch \
+ file://CVE-2026-17572.patch \
"
SRC_URI[sha256sum] = "f4c2edc5668fb846627182708dbe1e16c60c467e63177a75b0b9f12c19d7efed"
^ permalink raw reply related [flat|nested] 28+ messages in thread* [oe][meta-oe][wrynose][PATCH 24/28] hdf5: patch CVE-2026-17573
2026-09-02 10:04 [oe][meta-oe][wrynose][PATCH 1/28] libmxml: upgrade 4.0.4 -> 4.0.5 ankur.tyagi85
` (21 preceding siblings ...)
2026-09-02 10:05 ` [oe][meta-oe][wrynose][PATCH 23/28] hdf5: patch CVE-2026-17572 ankur.tyagi85
@ 2026-09-02 10:05 ` ankur.tyagi85
2026-09-02 10:05 ` [oe][meta-oe][wrynose][PATCH 25/28] hdf5: patch CVE-2026-17574 ankur.tyagi85
` (3 subsequent siblings)
26 siblings, 0 replies; 28+ messages in thread
From: ankur.tyagi85 @ 2026-09-02 10:05 UTC (permalink / raw)
To: openembedded-devel; +Cc: Ankur Tyagi
From: Ankur Tyagi <ankur.tyagi85@gmail.com>
Backport patch from the PR[1] fixing the issue[2] mentioned in the NVD[3].
Debian[4] has also identified the commit.
[1] https://github.com/HDFGroup/hdf5/pull/6160
[2] https://github.com/HDFGroup/hdf5/issues/6124
[3] https://nvd.nist.gov/vuln/detail/cve-2026-17573
[4] https://security-tracker.debian.org/tracker/CVE-2026-17573
Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
---
.../hdf5/files/CVE-2026-17573.patch | 53 +++++++++++++++++++
meta-oe/recipes-support/hdf5/hdf5_2.0.0.bb | 1 +
2 files changed, 54 insertions(+)
create mode 100644 meta-oe/recipes-support/hdf5/files/CVE-2026-17573.patch
diff --git a/meta-oe/recipes-support/hdf5/files/CVE-2026-17573.patch b/meta-oe/recipes-support/hdf5/files/CVE-2026-17573.patch
new file mode 100644
index 0000000000..3cfb52de42
--- /dev/null
+++ b/meta-oe/recipes-support/hdf5/files/CVE-2026-17573.patch
@@ -0,0 +1,53 @@
+From 856e7f1dd23e466ebeab5e454a5891b12e188f6a Mon Sep 17 00:00:00 2001
+From: jhendersonHDF <jhenderson@hdfgroup.org>
+Date: Tue, 27 Jan 2026 05:55:38 -0600
+Subject: [PATCH] Fix double-free issue in H5D__chunk_copy (#6160)
+
+Fix double-free caused by loss of buffer pointer after re-allocation
+
+Co-authored-by: Larry Knox <lrknox@hdfgroup.org>
+
+CVE: CVE-2026-17573
+Upstream-Status: Backport [https://github.com/HDFGroup/hdf5/commit/dd3080a58cc6bb86f3b34284399915da9e513262]
+
+Dropped changes to the CHANGELOG file.
+
+Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
+---
+ src/H5Dchunk.c | 5 ++---
+ 1 file changed, 2 insertions(+), 3 deletions(-)
+
+diff --git a/src/H5Dchunk.c b/src/H5Dchunk.c
+index f2a0e85c03..5ff537ebde 100644
+--- a/src/H5Dchunk.c
++++ b/src/H5Dchunk.c
+@@ -7034,7 +7034,7 @@ H5D__chunk_copy(H5F_t *f_src, H5O_layout_t *layout_src, H5F_t *f_dst, H5O_layout
+ const H5S_extent_t *ds_extent_src, H5T_t *dt_src, const H5O_pline_t *pline_src,
+ H5O_copy_t *cpy_info)
+ {
+- H5D_chunk_it_ud3_t udata; /* User data for iteration callback */
++ H5D_chunk_it_ud3_t udata = {0}; /* User data for iteration callback */
+ H5D_chk_idx_info_t idx_info_dst; /* Dest. chunked index info */
+ H5D_chk_idx_info_t idx_info_src; /* Source chunked index info */
+ int sndims; /* Rank of dataspace */
+@@ -7202,7 +7202,6 @@ H5D__chunk_copy(H5F_t *f_src, H5O_layout_t *layout_src, H5F_t *f_dst, H5O_layout
+ HGOTO_ERROR(H5E_RESOURCE, H5E_NOSPACE, FAIL, "memory allocation failed for raw data chunk");
+
+ /* Initialize the callback structure for the source */
+- memset(&udata, 0, sizeof udata);
+ udata.common.layout = &layout_src->u.chunk;
+ udata.common.storage = &layout_src->storage.u.chunk;
+ udata.file_src = f_src;
+@@ -7253,11 +7252,11 @@ H5D__chunk_copy(H5F_t *f_src, H5O_layout_t *layout_src, H5F_t *f_dst, H5O_layout
+ } /* end for */
+ }
+
++done:
+ /* I/O buffers may have been re-allocated */
+ buf = udata.buf;
+ bkg = udata.bkg;
+
+-done:
+ if (dt_dst && (H5T_close(dt_dst) < 0))
+ HDONE_ERROR(H5E_DATASET, H5E_CANTCLOSEOBJ, FAIL, "can't close temporary datatype");
+ if (dt_mem && (H5T_close(dt_mem) < 0))
diff --git a/meta-oe/recipes-support/hdf5/hdf5_2.0.0.bb b/meta-oe/recipes-support/hdf5/hdf5_2.0.0.bb
index cd489bdc3f..c49d5819be 100644
--- a/meta-oe/recipes-support/hdf5/hdf5_2.0.0.bb
+++ b/meta-oe/recipes-support/hdf5/hdf5_2.0.0.bb
@@ -19,6 +19,7 @@ SRC_URI = "https://support.hdfgroup.org/releases/hdf5/v2_0/v2_0_0/downloads/${BP
file://CVE-2026-26199.patch \
file://CVE-2026-26197.patch \
file://CVE-2026-17572.patch \
+ file://CVE-2026-17573.patch \
"
SRC_URI[sha256sum] = "f4c2edc5668fb846627182708dbe1e16c60c467e63177a75b0b9f12c19d7efed"
^ permalink raw reply related [flat|nested] 28+ messages in thread* [oe][meta-oe][wrynose][PATCH 25/28] hdf5: patch CVE-2026-17574
2026-09-02 10:04 [oe][meta-oe][wrynose][PATCH 1/28] libmxml: upgrade 4.0.4 -> 4.0.5 ankur.tyagi85
` (22 preceding siblings ...)
2026-09-02 10:05 ` [oe][meta-oe][wrynose][PATCH 24/28] hdf5: patch CVE-2026-17573 ankur.tyagi85
@ 2026-09-02 10:05 ` ankur.tyagi85
2026-09-02 10:05 ` [oe][meta-oe][wrynose][PATCH 26/28] hdf5: patch CVE-2026-19025 ankur.tyagi85
` (2 subsequent siblings)
26 siblings, 0 replies; 28+ messages in thread
From: ankur.tyagi85 @ 2026-09-02 10:05 UTC (permalink / raw)
To: openembedded-devel; +Cc: Ankur Tyagi
From: Ankur Tyagi <ankur.tyagi85@gmail.com>
Details:
https://nvd.nist.gov/vuln/detail/cve-2026-17574
Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
---
.../hdf5/files/CVE-2026-17574.patch | 65 +++++++++++++++++++
meta-oe/recipes-support/hdf5/hdf5_2.0.0.bb | 1 +
2 files changed, 66 insertions(+)
create mode 100644 meta-oe/recipes-support/hdf5/files/CVE-2026-17574.patch
diff --git a/meta-oe/recipes-support/hdf5/files/CVE-2026-17574.patch b/meta-oe/recipes-support/hdf5/files/CVE-2026-17574.patch
new file mode 100644
index 0000000000..0ae79a2811
--- /dev/null
+++ b/meta-oe/recipes-support/hdf5/files/CVE-2026-17574.patch
@@ -0,0 +1,65 @@
+From e374b227c277e100d9bfa3b1fe5c0b60cdff6c43 Mon Sep 17 00:00:00 2001
+From: tbeu <tbeu@users.noreply.github.com>
+Date: Thu, 28 May 2026 17:26:57 +0200
+Subject: [PATCH] Validate VL datatype type during decode and check file
+ pointer in H5T_set_loc (#6395)
+
+H5O__dtype_decode_helper() reads vlen.type from the file without
+validation. With corrupted HDF5 files (e.g. from fuzzing), this field
+can have an invalid value that is neither H5T_VLEN_SEQUENCE nor
+H5T_VLEN_STRING, which later triggers assert(0) in H5T__vlen_set_loc()
+(debug builds) or a NULL pointer dereference / SEGV in release builds.
+
+Fix by:
+1. Adding a validation check in H5O__dtype_decode_helper() immediately
+ after reading the vlen.type field, returning an error if the value
+ is invalid.
+2. Adding a NULL file pointer check in H5T_set_loc() before calling
+ H5T__vlen_set_loc() when loc == H5T_LOC_DISK, so the low-level
+ assert(file) invariant is never violated.
+
+This fixes the root cause at the decode level where the bad value
+enters the system, as requested in review of #6378 and #6385.
+
+Found by OSS-Fuzz via the matio fuzzer (ClusterFuzz testcase
+5366895365914624).
+
+(cherry picked from commit 3fa6ed6e9dfeebbc784e21d8c48e31e35a8042bc)
+
+CVE: CVE-2026-17574
+Upstream-Status: Backport [https://github.com/HDFGroup/hdf5/commit/3fa6ed6e9dfeebbc784e21d8c48e31e35a8042bc]
+Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
+---
+ src/H5Odtype.c | 2 ++
+ src/H5T.c | 5 +++++
+ 2 files changed, 7 insertions(+)
+
+diff --git a/src/H5Odtype.c b/src/H5Odtype.c
+index d6405cdb86..6e622f3ebc 100644
+--- a/src/H5Odtype.c
++++ b/src/H5Odtype.c
+@@ -751,6 +751,8 @@ H5O__dtype_decode_helper(unsigned *ioflags /*in,out*/, const uint8_t **pp, H5T_t
+ */
+ /* Set the type of VL information, either sequence or string */
+ dt->shared->u.vlen.type = (H5T_vlen_type_t)(flags & 0x0f);
++ if (dt->shared->u.vlen.type != H5T_VLEN_SEQUENCE && dt->shared->u.vlen.type != H5T_VLEN_STRING)
++ HGOTO_ERROR(H5E_DATATYPE, H5E_BADVALUE, FAIL, "invalid VL datatype type");
+ if (dt->shared->u.vlen.type == H5T_VLEN_STRING) {
+ dt->shared->u.vlen.pad = (H5T_str_t)((flags >> 4) & 0x0f);
+ dt->shared->u.vlen.cset = (H5T_cset_t)((flags >> 8) & 0x0f);
+diff --git a/src/H5T.c b/src/H5T.c
+index 3b2e391a53..e2c9ba9791 100644
+--- a/src/H5T.c
++++ b/src/H5T.c
+@@ -6953,6 +6953,11 @@ H5T_set_loc(H5T_t *dt, H5VL_object_t *file, H5T_loc_t loc)
+ ret_value = changed;
+ } /* end if */
+
++ /* Validate file pointer for disk-based VL types */
++ if (loc == H5T_LOC_DISK && NULL == file)
++ HGOTO_ERROR(H5E_DATATYPE, H5E_BADVALUE, FAIL,
++ "NULL file pointer for disk-based VL datatype");
++
+ /* Mark this VL sequence */
+ if ((changed = H5T__vlen_set_loc(dt, file, loc)) < 0)
+ HGOTO_ERROR(H5E_DATATYPE, H5E_CANTINIT, FAIL, "Unable to set VL location");
diff --git a/meta-oe/recipes-support/hdf5/hdf5_2.0.0.bb b/meta-oe/recipes-support/hdf5/hdf5_2.0.0.bb
index c49d5819be..8b5b842fa0 100644
--- a/meta-oe/recipes-support/hdf5/hdf5_2.0.0.bb
+++ b/meta-oe/recipes-support/hdf5/hdf5_2.0.0.bb
@@ -20,6 +20,7 @@ SRC_URI = "https://support.hdfgroup.org/releases/hdf5/v2_0/v2_0_0/downloads/${BP
file://CVE-2026-26197.patch \
file://CVE-2026-17572.patch \
file://CVE-2026-17573.patch \
+ file://CVE-2026-17574.patch \
"
SRC_URI[sha256sum] = "f4c2edc5668fb846627182708dbe1e16c60c467e63177a75b0b9f12c19d7efed"
^ permalink raw reply related [flat|nested] 28+ messages in thread* [oe][meta-oe][wrynose][PATCH 26/28] hdf5: patch CVE-2026-19025
2026-09-02 10:04 [oe][meta-oe][wrynose][PATCH 1/28] libmxml: upgrade 4.0.4 -> 4.0.5 ankur.tyagi85
` (23 preceding siblings ...)
2026-09-02 10:05 ` [oe][meta-oe][wrynose][PATCH 25/28] hdf5: patch CVE-2026-17574 ankur.tyagi85
@ 2026-09-02 10:05 ` ankur.tyagi85
2026-09-02 10:05 ` [oe][meta-networking][wrynose][PATCH 27/28] iftop: ignore CVE-2026-3824, CVE-2026-3825 and CVE-2026-3826 ankur.tyagi85
2026-09-02 10:05 ` [oe][meta-oe][wrynose][PATCH 28/28] iniparser: mark CVE-2025-0633 pached ankur.tyagi85
26 siblings, 0 replies; 28+ messages in thread
From: ankur.tyagi85 @ 2026-09-02 10:05 UTC (permalink / raw)
To: openembedded-devel; +Cc: Ankur Tyagi
From: Ankur Tyagi <ankur.tyagi85@gmail.com>
Backport patch from the PR[1] fixing the issue[2] mentioned in the NVD[3].
[1] https://github.com/HDFGroup/hdf5/pull/6508
[2] https://github.com/HDFGroup/hdf5/issues/6491
[3] https://nvd.nist.gov/vuln/detail/cve-2026-19025
Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
---
.../hdf5/files/CVE-2026-19025.patch | 112 ++++++++++++++++++
meta-oe/recipes-support/hdf5/hdf5_2.0.0.bb | 1 +
2 files changed, 113 insertions(+)
create mode 100644 meta-oe/recipes-support/hdf5/files/CVE-2026-19025.patch
diff --git a/meta-oe/recipes-support/hdf5/files/CVE-2026-19025.patch b/meta-oe/recipes-support/hdf5/files/CVE-2026-19025.patch
new file mode 100644
index 0000000000..075bcf7653
--- /dev/null
+++ b/meta-oe/recipes-support/hdf5/files/CVE-2026-19025.patch
@@ -0,0 +1,112 @@
+From 0cb26cd769d1da3f2ad2c3836dc1732309f935a7 Mon Sep 17 00:00:00 2001
+From: Matt L <124107509+mattjala@users.noreply.github.com>
+Date: Fri, 28 Aug 2026 13:49:02 -0500
+Subject: [PATCH] Fix CVE-2026-19025 (Reject chunked datasets with mismatched
+ chunk/dspace rank at open time) (#6508)
+
+* Reject chunked datasets with mismatched chunk/dspace rank
+
+H5D__chunk_construct() validates that the chunk layout dimensionality
+matches the dataspace rank, but that runs only at dataset creation time.
+When an existing dataset is opened, H5D__chunk_init() didn't repeat the
+check, so a file whose stored chunk rank disagreed with its dataspace rank
+was accepted. During chunk I/O the memory-selection rank (from the
+dataspace) and the file-selection rank (chunk ndims - 1) then differ, which
+produces a zero stride that causes a divide-by-zero in
+H5S__hyper_iter_get_seq_list().
+
+H5D__chunk_init() now performs the same dimensionality check on open (the
+stored chunk rank includes the extra element-size dimension, so it must be
+exactly one greater than the dataspace rank) and rejects a mismatch with an
+error.
+
+Added test_chunk_dims_mismatch() as a regression test in test/dsets.c
+
+Fixes #6491
+
+* Fix typo
+
+Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>
+
+* Clarify element-vs-byte wording
+
+* Validate chunk/dataspace rank at layout decode time
+
+Move the stored-chunk-rank vs dataspace-rank consistency check out of
+H5D__chunk_init() and into H5O__layout_decode(), so a malformed chunked
+layout is rejected as the message is decoded (mirroring the fill/datatype
+size check in the fill message decode).
+
+* Update release_docs/CHANGELOG.md
+
+Co-authored-by: Larry Knox <lrknox@hdfgroup.org>
+
+* Update CHANGELOG
+
+* Pin format version bounds in bad chunk layout generator
+
+---------
+
+Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>
+Co-authored-by: Larry Knox <lrknox@hdfgroup.org>
+
+CVE: CVE-2026-19025
+Upstream-Status: Backport [https://github.com/HDFGroup/hdf5/commit/b7b85e7abf9aa9b1dd9693523defa35217684eb2]
+
+Dropped changes to the test and CHANGELOG file.
+
+Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
+---
+ src/H5Olayout.c | 32 ++++++
+ 1 file changed, 32 insertions(+)
+
+diff --git a/src/H5Olayout.c b/src/H5Olayout.c
+index d230feb992..5dce35e916 100644
+--- a/src/H5Olayout.c
++++ b/src/H5Olayout.c
+@@ -23,6 +23,7 @@
+ #include "H5FLprivate.h" /* Free Lists */
+ #include "H5MMprivate.h" /* Memory management */
+ #include "H5Opkg.h" /* Object headers */
++#include "H5Sprivate.h" /* Dataspaces */
+
+ /* Local macros */
+
+@@ -561,6 +562,37 @@ H5O__layout_decode(H5F_t *f, H5O_t H5_ATTR_UNUSED *open_oh, unsigned H5_ATTR_UNU
+ }
+ }
+
++ /* For a chunked layout, the stored dimensionality includes an extra
++ * element-size dimension, so it must be exactly one greater than the
++ * dataspace rank. Validate that here
++ * to reject malformed files before the inconsistent
++ * ranks can cause problems during chunk I/O.
++ */
++ if (mesg->type == H5D_CHUNKED && open_oh != NULL) {
++ htri_t space_exists; /* Whether the dataspace message exists */
++
++ if ((space_exists = H5O_msg_exists_oh(open_oh, H5O_SDSPACE_ID)) < 0)
++ HGOTO_ERROR(H5E_OHDR, H5E_CANTGET, NULL, "can't check for dataspace message");
++ if (space_exists) {
++ H5S_extent_t *extent; /* Dataspace extent from the sibling message */
++ int rank; /* Dataspace rank */
++
++ if (NULL == (extent = (H5S_extent_t *)H5O_msg_read_oh(f, open_oh, H5O_SDSPACE_ID, NULL)))
++ HGOTO_ERROR(H5E_OHDR, H5E_CANTGET, NULL, "can't read dataspace message");
++
++ rank = H5S_extent_get_dims(extent, NULL, NULL);
++
++ /* Done with the sibling dataspace message */
++ H5O_msg_free(H5O_SDSPACE_ID, extent);
++
++ if (rank < 0)
++ HGOTO_ERROR(H5E_OHDR, H5E_CANTGET, NULL, "can't get dataspace rank");
++ if (mesg->u.chunk.ndims != (unsigned)rank + 1)
++ HGOTO_ERROR(H5E_OHDR, H5E_BADVALUE, NULL,
++ "dimensionality of chunks doesn't match the dataspace");
++ }
++ }
++
+ /* Set return value */
+ ret_value = mesg;
+
\ No newline at end of file
diff --git a/meta-oe/recipes-support/hdf5/hdf5_2.0.0.bb b/meta-oe/recipes-support/hdf5/hdf5_2.0.0.bb
index 8b5b842fa0..cf199375d3 100644
--- a/meta-oe/recipes-support/hdf5/hdf5_2.0.0.bb
+++ b/meta-oe/recipes-support/hdf5/hdf5_2.0.0.bb
@@ -21,6 +21,7 @@ SRC_URI = "https://support.hdfgroup.org/releases/hdf5/v2_0/v2_0_0/downloads/${BP
file://CVE-2026-17572.patch \
file://CVE-2026-17573.patch \
file://CVE-2026-17574.patch \
+ file://CVE-2026-19025.patch \
"
SRC_URI[sha256sum] = "f4c2edc5668fb846627182708dbe1e16c60c467e63177a75b0b9f12c19d7efed"
^ permalink raw reply related [flat|nested] 28+ messages in thread* [oe][meta-networking][wrynose][PATCH 27/28] iftop: ignore CVE-2026-3824, CVE-2026-3825 and CVE-2026-3826
2026-09-02 10:04 [oe][meta-oe][wrynose][PATCH 1/28] libmxml: upgrade 4.0.4 -> 4.0.5 ankur.tyagi85
` (24 preceding siblings ...)
2026-09-02 10:05 ` [oe][meta-oe][wrynose][PATCH 26/28] hdf5: patch CVE-2026-19025 ankur.tyagi85
@ 2026-09-02 10:05 ` ankur.tyagi85
2026-09-02 10:05 ` [oe][meta-oe][wrynose][PATCH 28/28] iniparser: mark CVE-2025-0633 pached ankur.tyagi85
26 siblings, 0 replies; 28+ messages in thread
From: ankur.tyagi85 @ 2026-09-02 10:05 UTC (permalink / raw)
To: openembedded-devel; +Cc: Ankur Tyagi
From: Ankur Tyagi <ankur.tyagi85@gmail.com>
Details:
https://nvd.nist.gov/vuln/detail/cve-2026-3824
https://nvd.nist.gov/vuln/detail/cve-2026-3825
https://nvd.nist.gov/vuln/detail/cve-2026-3826
Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
---
meta-networking/recipes-support/iftop/iftop_1.0pre4.bb | 3 +++
1 file changed, 3 insertions(+)
diff --git a/meta-networking/recipes-support/iftop/iftop_1.0pre4.bb b/meta-networking/recipes-support/iftop/iftop_1.0pre4.bb
index 4d9fea58e0..5971af2b3c 100644
--- a/meta-networking/recipes-support/iftop/iftop_1.0pre4.bb
+++ b/meta-networking/recipes-support/iftop/iftop_1.0pre4.bb
@@ -15,3 +15,6 @@ SRC_URI[sha256sum] = "f733eeea371a7577f8fe353d86dd88d16f5b2a2e702bd96f5ffb2c197d
inherit autotools-brokensep
+CVE_STATUS[CVE-2026-3824] = "cpe-incorrect: this CVE is for WellChoose"
+CVE_STATUS[CVE-2026-3825] = "cpe-incorrect: this CVE is for WellChoose"
+CVE_STATUS[CVE-2026-3826] = "cpe-incorrect: this CVE is for WellChoose"
^ permalink raw reply related [flat|nested] 28+ messages in thread* [oe][meta-oe][wrynose][PATCH 28/28] iniparser: mark CVE-2025-0633 pached
2026-09-02 10:04 [oe][meta-oe][wrynose][PATCH 1/28] libmxml: upgrade 4.0.4 -> 4.0.5 ankur.tyagi85
` (25 preceding siblings ...)
2026-09-02 10:05 ` [oe][meta-networking][wrynose][PATCH 27/28] iftop: ignore CVE-2026-3824, CVE-2026-3825 and CVE-2026-3826 ankur.tyagi85
@ 2026-09-02 10:05 ` ankur.tyagi85
26 siblings, 0 replies; 28+ messages in thread
From: ankur.tyagi85 @ 2026-09-02 10:05 UTC (permalink / raw)
To: openembedded-devel; +Cc: Ankur Tyagi
From: Ankur Tyagi <ankur.tyagi85@gmail.com>
Also mentioned in the release notes[1]
Detais:
https://nvd.nist.gov/vuln/detail/cve-2025-0633
[1] https://gitlab.com/iniparser/iniparser/-/releases/v4.2.6
Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
---
meta-oe/recipes-support/iniparser/iniparser_4.2.6.bb | 2 ++
1 file changed, 2 insertions(+)
diff --git a/meta-oe/recipes-support/iniparser/iniparser_4.2.6.bb b/meta-oe/recipes-support/iniparser/iniparser_4.2.6.bb
index 9ab713ee92..5958ecb9c6 100644
--- a/meta-oe/recipes-support/iniparser/iniparser_4.2.6.bb
+++ b/meta-oe/recipes-support/iniparser/iniparser_4.2.6.bb
@@ -15,3 +15,5 @@ EXTRA_OECMAKE = " \
"
FILES_${PN}-staticdev += "${libdir}/cmake/iniparser/iniparser-staticTargets*.cmake"
+
+CVE_STATUS[CVE-2025-0633] = "fixed-version: fixed in v4.2.6"
^ permalink raw reply related [flat|nested] 28+ messages in thread