All of lore.kernel.org
 help / color / mirror / Atom feed
From: ankur.tyagi85@gmail.com
To: openembedded-devel@lists.openembedded.org
Cc: Ankur Tyagi <ankur.tyagi85@gmail.com>
Subject: [oe][meta-networking][wrynose][PATCH 25/33] wolfssl: patch CVE-2026-6091
Date: Mon,  7 Sep 2026 22:23:09 +1200	[thread overview]
Message-ID: <20260907102318.2459883-25-ankur.tyagi85@gmail.com> (raw)
In-Reply-To: <20260907102318.2459883-1-ankur.tyagi85@gmail.com>

From: Ankur Tyagi <ankur.tyagi85@gmail.com>

Details:
https://nvd.nist.gov/vuln/detail/cve-2026-6091

Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
---
 .../wolfssl/files/CVE-2026-6091-1.patch       | 295 ++++++++++++++++++
 .../wolfssl/files/CVE-2026-6091-2.patch       |  30 ++
 .../wolfssl/files/CVE-2026-6091-3.patch       |  36 +++
 .../wolfssl/wolfssl_5.9.1.bb                  |   3 +
 4 files changed, 364 insertions(+)
 create mode 100644 meta-networking/recipes-connectivity/wolfssl/files/CVE-2026-6091-1.patch
 create mode 100644 meta-networking/recipes-connectivity/wolfssl/files/CVE-2026-6091-2.patch
 create mode 100644 meta-networking/recipes-connectivity/wolfssl/files/CVE-2026-6091-3.patch

diff --git a/meta-networking/recipes-connectivity/wolfssl/files/CVE-2026-6091-1.patch b/meta-networking/recipes-connectivity/wolfssl/files/CVE-2026-6091-1.patch
new file mode 100644
index 0000000000..644797266e
--- /dev/null
+++ b/meta-networking/recipes-connectivity/wolfssl/files/CVE-2026-6091-1.patch
@@ -0,0 +1,295 @@
+From 54bce5dd1dce8839ea64e0bddebe4c6f8fd2cc6c Mon Sep 17 00:00:00 2001
+From: Eric Blankenhorn <eric@wolfssl.com>
+Date: Wed, 8 Apr 2026 16:27:07 -0500
+Subject: [PATCH] Fix partial chain verification
+
+(cherry picked from commit a6fd25b94e0c03c1be265a4454390d7225e81129)
+
+CVE: CVE-2026-6091
+Upstream-Status: Backport [https://github.com/wolfSSL/wolfssl/commit/a6fd25b94e0c03c1be265a4454390d7225e81129]
+
+Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
+---
+ src/x509_str.c                 |  90 ++++++++++++++++++++++-
+ tests/api/test_ossl_x509_str.c | 127 +++++++++++++++++++++++++++++++++
+ 2 files changed, 216 insertions(+), 1 deletion(-)
+
+diff --git a/src/x509_str.c b/src/x509_str.c
+index 90113caed..01e975198 100644
+--- a/src/x509_str.c
++++ b/src/x509_str.c
+@@ -552,6 +552,53 @@ static int X509VerifyCertSetupRetry(WOLFSSL_X509_STORE_CTX* ctx,
+     return ret;
+ }
+ 
++/* Returns 1 if cur and x509 have identical DER encodings, 0 otherwise. */
++static int X509DerEquals(WOLFSSL_X509* cur, WOLFSSL_X509* x509)
++{
++    if (cur == NULL || cur->derCert == NULL ||
++        x509 == NULL || x509->derCert == NULL) {
++        return 0;
++    }
++    if (cur->derCert->length != x509->derCert->length)
++        return 0;
++    return XMEMCMP(cur->derCert->buffer, x509->derCert->buffer,
++                   x509->derCert->length) == 0;
++}
++
++/* Returns 1 if x509's DER matches an entry in either origTrustedSk (an
++ * immutable snapshot of the caller's trusted set captured before any
++ * intermediates were injected for this verification call) or in
++ * store->trusted.  Returns 0 otherwise.  Used by the
++ * X509_V_FLAG_PARTIAL_CHAIN fallback to confirm that a chain actually
++ * terminates at a caller-trusted certificate. */
++static int X509StoreCertIsTrusted(WOLFSSL_X509_STORE* store,
++        WOLFSSL_X509* x509, WOLF_STACK_OF(WOLFSSL_X509)* origTrustedSk)
++{
++    int i;
++    int n;
++
++    if (x509 == NULL || x509->derCert == NULL)
++        return 0;
++
++    if (origTrustedSk != NULL) {
++        n = wolfSSL_sk_X509_num(origTrustedSk);
++        for (i = 0; i < n; i++) {
++            if (X509DerEquals(wolfSSL_sk_X509_value(origTrustedSk, i), x509))
++                return 1;
++        }
++    }
++
++    if (store != NULL && store->trusted != NULL) {
++        n = wolfSSL_sk_X509_num(store->trusted);
++        for (i = 0; i < n; i++) {
++            if (X509DerEquals(wolfSSL_sk_X509_value(store->trusted, i), x509))
++                return 1;
++        }
++    }
++
++    return 0;
++}
++
+ /* Verifies certificate chain using WOLFSSL_X509_STORE_CTX
+  * returns 1 on success or <= 0 on failure.
+  */
+@@ -570,6 +617,7 @@ int wolfSSL_X509_verify_cert(WOLFSSL_X509_STORE_CTX* ctx)
+     WOLF_STACK_OF(WOLFSSL_X509)* certs = NULL;
+     WOLF_STACK_OF(WOLFSSL_X509)* certsToUse = NULL;
+     WOLF_STACK_OF(WOLFSSL_X509)* failedCerts = NULL;
++    WOLF_STACK_OF(WOLFSSL_X509)* origTrustedSk = NULL;
+     WOLFSSL_ENTER("wolfSSL_X509_verify_cert");
+ 
+     if (ctx == NULL || ctx->store == NULL || ctx->store->cm == NULL
+@@ -586,9 +634,37 @@ int wolfSSL_X509_verify_cert(WOLFSSL_X509_STORE_CTX* ctx)
+     if (certs == NULL &&
+         wolfSSL_sk_X509_num(ctx->ctxIntermediates) > 0) {
+         certsToUse = wolfSSL_sk_X509_new_null();
++        if (certsToUse == NULL) {
++            ret = WOLFSSL_FAILURE;
++            goto exit;
++        }
+         ret = addAllButSelfSigned(certsToUse, ctx->ctxIntermediates, NULL);
++        /* certsToUse holds only injected intermediates, none are trusted, so
++         * leave origTrustedSk NULL (empty snapshot). */
++        certs = certsToUse;
+     }
+     else {
++        /* Snapshot the caller-trusted entries before injecting the
++         * caller-supplied untrusted intermediates.  Only the entries already
++         * present count as trusted for the partial-chain check below, and
++         * we need a stable reference because X509VerifyCertSetupRetry may
++         * remove nodes from `certs` during chain building. */
++        if (certs != NULL && wolfSSL_sk_X509_num(certs) > 0) {
++            int j;
++            int n = wolfSSL_sk_X509_num(certs);
++            origTrustedSk = wolfSSL_sk_X509_new_null();
++            if (origTrustedSk == NULL) {
++                ret = WOLFSSL_FAILURE;
++                goto exit;
++            }
++            for (j = 0; j < n; j++) {
++                if (wolfSSL_sk_X509_push(origTrustedSk,
++                        wolfSSL_sk_X509_value(certs, j)) <= 0) {
++                    ret = WOLFSSL_FAILURE;
++                    goto exit;
++                }
++            }
++        }
+         /* Add the intermediates provided on init to the list of untrusted
+          * intermediates to be used */
+         ret = addAllButSelfSigned(certs, ctx->ctxIntermediates, &numInterAdd);
+@@ -677,9 +753,17 @@ int wolfSSL_X509_verify_cert(WOLFSSL_X509_STORE_CTX* ctx)
+              * a trusted CA in the CM */
+             ret = X509StoreVerifyCert(ctx);
+             if (ret != WOLFSSL_SUCCESS) {
++                /* WOLFSSL_PARTIAL_CHAIN may only terminate the chain at a
++                 * certificate the caller actually trusts.  The previous
++                 * "added == 1" guard merely confirmed that some untrusted
++                 * intermediate had been temporarily loaded into the
++                 * CertManager during chain building, which would accept
++                 * chains that never reach a trust anchor.  Verify that
++                 * ctx->current_cert is itself in the original trust set. */
+                 if (((ctx->flags & WOLFSSL_PARTIAL_CHAIN) ||
+                      (ctx->store->param->flags & WOLFSSL_PARTIAL_CHAIN)) &&
+-                    (added == 1)) {
++                    X509StoreCertIsTrusted(ctx->store, ctx->current_cert,
++                        origTrustedSk)) {
+                     wolfSSL_sk_X509_push(ctx->chain, ctx->current_cert);
+                     ret = WOLFSSL_SUCCESS;
+                 } else {
+@@ -749,6 +833,10 @@ exit:
+     if (certsToUse != NULL) {
+         wolfSSL_sk_X509_free(certsToUse);
+     }
++    if (origTrustedSk != NULL) {
++        /* Shallow free: only the snapshot's stack nodes, not the X509s. */
++        wolfSSL_sk_X509_free(origTrustedSk);
++    }
+ 
+     /* Enforce hostname / IP verification from X509_VERIFY_PARAM if set.
+      * Always check against the leaf (end-entity) certificate, captured in
+diff --git a/tests/api/test_ossl_x509_str.c b/tests/api/test_ossl_x509_str.c
+index 99b82877c..01ed9edfb 100644
+--- a/tests/api/test_ossl_x509_str.c
++++ b/tests/api/test_ossl_x509_str.c
+@@ -785,6 +785,127 @@ static int test_wolfSSL_X509_STORE_CTX_ex11(X509_STORE_test_data *testData)
+     return EXPECT_RESULT();
+ }
+ 
++static int test_wolfSSL_X509_STORE_CTX_ex_partial_chain_neg(
++    X509_STORE_test_data *testData)
++{
++    EXPECT_DECLS;
++    X509_STORE* store = NULL;
++    X509_STORE_CTX* ctx = NULL;
++    STACK_OF(X509)* untrusted = NULL;
++
++    /* Negative partial-chain test: with X509_V_FLAG_PARTIAL_CHAIN set, the
++     * intermediates are supplied ONLY as untrusted (passed through the
++     * X509_STORE_CTX_init "chain" argument and never added to the store).
++     * No certificate in the chain is in the store, so verification must
++     * fail.  Pre-fix, wolfSSL_X509_verify_cert would incorrectly accept
++     * this chain because its partial-chain fallback only checked that some
++     * intermediate had been temporarily loaded into the CertManager, not
++     * that any chain certificate was actually trusted. */
++    ExpectNotNull(store = X509_STORE_new());
++    /* Intentionally do NOT add x509CaInt, x509CaInt2, or x509Ca. */
++    ExpectIntEQ(X509_STORE_set_flags(store, X509_V_FLAG_PARTIAL_CHAIN), 1);
++
++    ExpectNotNull(untrusted = sk_X509_new_null());
++    ExpectIntGT(sk_X509_push(untrusted, testData->x509CaInt2), 0);
++    ExpectIntGT(sk_X509_push(untrusted, testData->x509CaInt), 0);
++
++    ExpectNotNull(ctx = X509_STORE_CTX_new());
++    ExpectIntEQ(X509_STORE_CTX_init(ctx, store, testData->x509Leaf, untrusted),
++        1);
++    /* Must NOT verify: partial-chain does not relax the trust requirement. */
++    ExpectIntNE(X509_verify_cert(ctx), 1);
++    /* Verify the failure is specifically due to missing trust anchor, not
++     * some unrelated error. */
++    ExpectIntEQ(X509_STORE_CTX_get_error(ctx),
++        X509_V_ERR_UNABLE_TO_GET_ISSUER_CERT_LOCALLY);
++
++    X509_STORE_CTX_free(ctx);
++    X509_STORE_free(store);
++    sk_X509_free(untrusted);
++    return EXPECT_RESULT();
++}
++
++static int test_wolfSSL_X509_STORE_CTX_ex_partial_chain_mixed(
++    X509_STORE_test_data *testData)
++{
++    EXPECT_DECLS;
++    X509_STORE* store = NULL;
++    X509_STORE_CTX* ctx = NULL;
++    STACK_OF(X509)* untrusted = NULL;
++
++    /* Mixed trusted-store + untrusted-chain partial-chain test: the store
++     * trusts an intermediate (x509CaInt2, the leaf's direct issuer), while
++     * an additional intermediate (x509CaInt) is supplied only as untrusted
++     * via the chain argument.  With X509_V_FLAG_PARTIAL_CHAIN, verification
++     * must succeed by terminating at the trusted intermediate.  This test
++     * exercises the snapshot-based trust check in X509StoreCertIsTrusted:
++     * the untrusted intermediate injected during verification must not be
++     * treated as a trust anchor, but the intermediate already in the store
++     * must be. */
++    ExpectNotNull(store = X509_STORE_new());
++    ExpectIntEQ(X509_STORE_add_cert(store, testData->x509CaInt2), 1);
++    ExpectIntEQ(X509_STORE_set_flags(store, X509_V_FLAG_PARTIAL_CHAIN), 1);
++
++    ExpectNotNull(untrusted = sk_X509_new_null());
++    ExpectIntGT(sk_X509_push(untrusted, testData->x509CaInt), 0);
++
++    ExpectNotNull(ctx = X509_STORE_CTX_new());
++    ExpectIntEQ(X509_STORE_CTX_init(ctx, store, testData->x509Leaf, untrusted),
++        1);
++    /* Must verify: chain terminates at trusted intermediate in the store. */
++    ExpectIntEQ(X509_verify_cert(ctx), 1);
++
++    X509_STORE_CTX_free(ctx);
++    X509_STORE_free(store);
++    sk_X509_free(untrusted);
++    return EXPECT_RESULT();
++}
++
++static int test_wolfSSL_X509_STORE_CTX_ex_partial_chain_untrusted_terminal(
++    X509_STORE_test_data *testData)
++{
++    EXPECT_DECLS;
++    X509_STORE* store = NULL;
++    X509_STORE_CTX* ctx = NULL;
++    STACK_OF(X509)* untrusted = NULL;
++
++    /* Partial-chain boundary test: the store trusts a CA (x509Ca) that is
++     * NOT reachable from the leaf given the supplied untrusted intermediates,
++     * and an untrusted intermediate (x509CaInt2) IS the terminal of the
++     * (truncated) chain.  With X509_V_FLAG_PARTIAL_CHAIN set, verification
++     * must FAIL because the chain terminates at an untrusted certificate.
++     *
++     * This test specifically targets the snapshot-based trust check in
++     * X509StoreCertIsTrusted.  Before addAllButSelfSigned injects
++     * x509CaInt2, origTrustedSk is snapshotted from the caller-trusted set
++     * and contains only x509Ca.  When the chain terminates at x509CaInt2,
++     * the trust check consults origTrustedSk (not the mutated working
++     * stack) and correctly finds no match.  A regression that consulted
++     * the post-injection working stack instead of the snapshot would
++     * incorrectly mark x509CaInt2 as trusted and cause verification to
++     * succeed. */
++    ExpectNotNull(store = X509_STORE_new());
++    ExpectIntEQ(X509_STORE_add_cert(store, testData->x509Ca), 1);
++    ExpectIntEQ(X509_STORE_set_flags(store, X509_V_FLAG_PARTIAL_CHAIN), 1);
++
++    /* Only x509CaInt2 supplied as untrusted; x509CaInt is intentionally
++     * withheld so the chain cannot actually reach the trusted x509Ca. */
++    ExpectNotNull(untrusted = sk_X509_new_null());
++    ExpectIntGT(sk_X509_push(untrusted, testData->x509CaInt2), 0);
++
++    ExpectNotNull(ctx = X509_STORE_CTX_new());
++    ExpectIntEQ(X509_STORE_CTX_init(ctx, store, testData->x509Leaf, untrusted),
++        1);
++    /* Must NOT verify: the chain terminal (x509CaInt2) is not in the
++     * original trust set, even though the store is non-empty. */
++    ExpectIntNE(X509_verify_cert(ctx), 1);
++
++    X509_STORE_CTX_free(ctx);
++    X509_STORE_free(store);
++    sk_X509_free(untrusted);
++    return EXPECT_RESULT();
++}
++
+ #ifdef HAVE_ECC
+ static int test_wolfSSL_X509_STORE_CTX_ex12(void)
+ {
+@@ -870,6 +991,12 @@ int test_wolfSSL_X509_STORE_CTX_ex(void)
+     ExpectIntEQ(test_wolfSSL_X509_STORE_CTX_ex9(&testData), 1);
+     ExpectIntEQ(test_wolfSSL_X509_STORE_CTX_ex10(&testData), 1);
+     ExpectIntEQ(test_wolfSSL_X509_STORE_CTX_ex11(&testData), 1);
++    ExpectIntEQ(test_wolfSSL_X509_STORE_CTX_ex_partial_chain_neg(&testData), 1);
++    ExpectIntEQ(test_wolfSSL_X509_STORE_CTX_ex_partial_chain_mixed(&testData),
++        1);
++    ExpectIntEQ(
++        test_wolfSSL_X509_STORE_CTX_ex_partial_chain_untrusted_terminal(
++            &testData), 1);
+ #ifdef HAVE_ECC
+     ExpectIntEQ(test_wolfSSL_X509_STORE_CTX_ex12(), 1);
+ #endif
diff --git a/meta-networking/recipes-connectivity/wolfssl/files/CVE-2026-6091-2.patch b/meta-networking/recipes-connectivity/wolfssl/files/CVE-2026-6091-2.patch
new file mode 100644
index 0000000000..373f942496
--- /dev/null
+++ b/meta-networking/recipes-connectivity/wolfssl/files/CVE-2026-6091-2.patch
@@ -0,0 +1,30 @@
+From 62e57461f512849af4f466f77594085c90ffad73 Mon Sep 17 00:00:00 2001
+From: Eric Blankenhorn <eric@wolfssl.com>
+Date: Tue, 14 Apr 2026 07:58:43 -0500
+Subject: [PATCH] Fix from review
+
+(cherry picked from commit c873f3f77da8273e160612468f08892b2ba0ed99)
+
+CVE: CVE-2026-6091
+Upstream-Status: Backport [https://github.com/wolfSSL/wolfssl/commit/c873f3f77da8273e160612468f08892b2ba0ed99]
+
+Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
+---
+ src/x509_str.c | 4 ++++
+ 1 file changed, 4 insertions(+)
+
+diff --git a/src/x509_str.c b/src/x509_str.c
+index 01e975198..67e3fcae6 100644
+--- a/src/x509_str.c
++++ b/src/x509_str.c
+@@ -765,6 +765,10 @@ int wolfSSL_X509_verify_cert(WOLFSSL_X509_STORE_CTX* ctx)
+                     X509StoreCertIsTrusted(ctx->store, ctx->current_cert,
+                         origTrustedSk)) {
+                     wolfSSL_sk_X509_push(ctx->chain, ctx->current_cert);
++                    /* Clear error set by the failed X509StoreVerifyCert
++                     * attempt; the partial-chain fallback accepted the
++                     * chain at a caller-trusted certificate. */
++                    ctx->error = 0;
+                     ret = WOLFSSL_SUCCESS;
+                 } else {
+                     X509VerifyCertSetupRetry(ctx, certs, failedCerts,
diff --git a/meta-networking/recipes-connectivity/wolfssl/files/CVE-2026-6091-3.patch b/meta-networking/recipes-connectivity/wolfssl/files/CVE-2026-6091-3.patch
new file mode 100644
index 0000000000..418e45fc13
--- /dev/null
+++ b/meta-networking/recipes-connectivity/wolfssl/files/CVE-2026-6091-3.patch
@@ -0,0 +1,36 @@
+From 13c4a12c9904a2e50d1729d8a6899f111f3bcd2a Mon Sep 17 00:00:00 2001
+From: Eric Blankenhorn <eric@wolfssl.com>
+Date: Tue, 14 Apr 2026 07:41:30 -0500
+Subject: [PATCH] Fix from review
+
+(cherry picked from commit 2b503dae543d09c63a08b1e24238e0e9ce1ac6c5)
+
+CVE: CVE-2026-6091
+Upstream-Status: Backport [https://github.com/wolfSSL/wolfssl/commit/2b503dae543d09c63a08b1e24238e0e9ce1ac6c5]
+
+Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
+---
+ tests/api/test_ossl_x509_str.c | 3 +++
+ 1 file changed, 3 insertions(+)
+
+diff --git a/tests/api/test_ossl_x509_str.c b/tests/api/test_ossl_x509_str.c
+index 01ed9edfb..14f3538a4 100644
+--- a/tests/api/test_ossl_x509_str.c
++++ b/tests/api/test_ossl_x509_str.c
+@@ -854,6 +854,7 @@ static int test_wolfSSL_X509_STORE_CTX_ex_partial_chain_mixed(
+         1);
+     /* Must verify: chain terminates at trusted intermediate in the store. */
+     ExpectIntEQ(X509_verify_cert(ctx), 1);
++    ExpectIntEQ(X509_STORE_CTX_get_error(ctx), X509_V_OK);
+ 
+     X509_STORE_CTX_free(ctx);
+     X509_STORE_free(store);
+@@ -899,6 +900,8 @@ static int test_wolfSSL_X509_STORE_CTX_ex_partial_chain_untrusted_terminal(
+     /* Must NOT verify: the chain terminal (x509CaInt2) is not in the
+      * original trust set, even though the store is non-empty. */
+     ExpectIntNE(X509_verify_cert(ctx), 1);
++    ExpectIntEQ(X509_STORE_CTX_get_error(ctx),
++        X509_V_ERR_UNABLE_TO_GET_ISSUER_CERT_LOCALLY);
+ 
+     X509_STORE_CTX_free(ctx);
+     X509_STORE_free(store);
diff --git a/meta-networking/recipes-connectivity/wolfssl/wolfssl_5.9.1.bb b/meta-networking/recipes-connectivity/wolfssl/wolfssl_5.9.1.bb
index e2bb53a646..139d73c572 100644
--- a/meta-networking/recipes-connectivity/wolfssl/wolfssl_5.9.1.bb
+++ b/meta-networking/recipes-connectivity/wolfssl/wolfssl_5.9.1.bb
@@ -19,6 +19,9 @@ SRC_URI = " \
     file://CVE-2026-10098-2.patch \
     file://CVE-2026-10512.patch \
     file://CVE-2026-55958.patch \
+    file://CVE-2026-6091-1.patch \
+    file://CVE-2026-6091-2.patch \
+    file://CVE-2026-6091-3.patch \
 "
 
 SRCREV = "1d363f3adceba9d1478230ede476a37b0dcdef24"


  parent reply	other threads:[~2026-09-07 10:24 UTC|newest]

Thread overview: 37+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-07 10:22 [oe][meta-oe][wrynose][PATCH 1/33] libnfs: patch CVE-2026-53689 ankur.tyagi85
2026-09-07 10:22 ` [oe][meta-oe][wrynose][PATCH 2/33] libnfs: patch CVE-2026-57918 ankur.tyagi85
2026-09-07 10:22 ` [oe][meta-oe][wrynose][PATCH 3/33] libssh: ignore CVE-2025-14821 ankur.tyagi85
2026-09-07 10:22 ` [oe][meta-oe][wrynose][PATCH 4/33] libssh: mark CVEs patched ankur.tyagi85
2026-09-07 10:22 ` [oe][meta-oe][wrynose][PATCH 5/33] libssh: ignore CVE-2025-59842 ankur.tyagi85
2026-09-15  1:29   ` Anuj Mittal
2026-09-15  1:54     ` Ankur Tyagi
2026-09-07 10:22 ` [oe][meta-networking][wrynose][PATCH 6/33] miniupnpd: patch CVE-2026-5720 ankur.tyagi85
2026-09-07 10:22 ` [oe][meta-python][wrynose][PATCH 7/33] python3-zeroconf: patch CVE-2026-47180 ankur.tyagi85
2026-09-07 10:22 ` [oe][meta-python][wrynose][PATCH 8/33] python3-zeroconf: patch CVE-2026-47183 ankur.tyagi85
2026-09-07 10:22 ` [oe][meta-python][wrynose][PATCH 9/33] python3-zeroconf: patch CVE-2026-47184 ankur.tyagi85
2026-09-07 10:22 ` [oe][meta-oe][wrynose][PATCH 10/33] valkey: mark CVE-2026-56684 and CVE-2026-63639 patched ankur.tyagi85
2026-09-07 10:22 ` [oe][meta-oe][wrynose][PATCH 11/33] libyang: patch CVE-2026-41401 ankur.tyagi85
2026-09-07 10:22 ` [oe][meta-networking][wrynose][PATCH 12/33] tinyproxy: patch CVE-2026-31842 ankur.tyagi85
2026-09-07 10:22 ` [oe][meta-networking][wrynose][PATCH 13/33] tinyproxy: patch CVE-2026-54387 ankur.tyagi85
2026-09-07 10:22 ` [oe][meta-networking][wrynose][PATCH 14/33] tinyproxy: patch CVE-2026-55202 ankur.tyagi85
2026-09-07 10:22 ` [oe][meta-webserver][wrynose][PATCH 15/33] nginx: mark CVE-2026-1642 patched ankur.tyagi85
2026-09-07 10:23 ` [oe][meta-networking][wrynose][PATCH 16/33] open62541: patch CVE-2026-11946 ankur.tyagi85
2026-09-07 10:23 ` [oe][meta-oe][wrynose][PATCH 17/33] smarty: mark CVEs patched ankur.tyagi85
2026-09-15  1:28   ` Anuj Mittal
2026-09-15  1:53     ` Ankur Tyagi
2026-09-07 10:23 ` [oe][meta-oe][wrynose][PATCH 18/33] tesseract: patch CVE-2026-73066 ankur.tyagi85
2026-09-07 10:23 ` [oe][meta-oe][wrynose][PATCH 19/33] tesseract: patch CVE-2026-73067 ankur.tyagi85
2026-09-07 10:23 ` [oe][meta-networking][wrynose][PATCH 20/33] wolfssl: mark CVEs patched ankur.tyagi85
2026-09-07 10:23 ` [oe][meta-networking][wrynose][PATCH 21/33] wolfssl: patch CVE-2026-10098 ankur.tyagi85
2026-09-07 10:23 ` [oe][meta-networking][wrynose][PATCH 22/33] wolfssl: patch CVE-2026-10512 ankur.tyagi85
2026-09-07 10:23 ` [oe][meta-networking][wrynose][PATCH 23/33] wolfssl: ignore CVE-2026-12340 ankur.tyagi85
2026-09-07 10:23 ` [oe][meta-networking][wrynose][PATCH 24/33] wolfssl: patch CVE-2026-55958 ankur.tyagi85
2026-09-07 10:23 ` ankur.tyagi85 [this message]
2026-09-07 10:23 ` [oe][meta-networking][wrynose][PATCH 26/33] wolfssl: patch CVE-2026-6092 ankur.tyagi85
2026-09-07 10:23 ` [oe][meta-networking][wrynose][PATCH 27/33] wolfssl: patch CVE-2026-6094 ankur.tyagi85
2026-09-07 10:23 ` [oe][meta-networking][wrynose][PATCH 28/33] wolfssl: patch CVE-2026-6291 ankur.tyagi85
2026-09-07 10:23 ` [oe][meta-networking][wrynose][PATCH 29/33] wolfssl: patch CVE-2026-6325 ankur.tyagi85
2026-09-07 10:23 ` [oe][meta-networking][wrynose][PATCH 30/33] wolfssl: patch CVE-2026-6412 ankur.tyagi85
2026-09-07 10:23 ` [oe][meta-networking][wrynose][PATCH 31/33] wolfssl: patch CVE-2026-6450 ankur.tyagi85
2026-09-07 10:23 ` [oe][meta-networking][wrynose][PATCH 32/33] wolfssl: patch CVE-2026-6731 ankur.tyagi85
2026-09-07 10:23 ` [oe][meta-networking][wrynose][PATCH 33/33] wolfssl: patch CVE-2026-7531 ankur.tyagi85

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260907102318.2459883-25-ankur.tyagi85@gmail.com \
    --to=ankur.tyagi85@gmail.com \
    --cc=openembedded-devel@lists.openembedded.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.