From: "Mathieu Dubois-Briand" <mathieu.dubois-briand@bootlin.com>
To: "Adarsh Jagadish Kamini" <adarsh.jagadish.kamini@est.tech>,
<openembedded-core@lists.openembedded.org>
Subject: Re: [OE-core][PATCH] glibc: stable 2.43 branch updates
Date: Tue, 28 Jul 2026 06:43:43 +0200 [thread overview]
Message-ID: <DK9XHGRCG7LU.1L6EFEVZGMPXB@bootlin.com> (raw)
In-Reply-To: <20260727112902.1653529-1-adarsh.jagadish.kamini@est.tech>
On Mon Jul 27, 2026 at 1:29 PM CEST, Adarsh Jagadish Kamini wrote:
> Update SRCREV to pull the latest fixes from the upstream
> release/2.43/master branch, including fixes for the following CVEs:
>
> CVE-2026-5435 resolv: More types as unknown in ns_sprintrrf
> CVE-2026-5450 stdio-common: Fix buffer overflow in scanf %mc [BZ #34008]
> CVE-2026-5928 libio: Fix ungetwc operating on byte stream [BZ #33998]
> CVE-2026-6238 resolv: Fix buffer overreads in ns_sprintrrf
> CVE-2026-6791 posix: Fix stack overflow in wordexp tilde expansion (BZ 34091)
>
> Commits between the old SRCREV (e9517114ac) and the new SRCREV (1c9988e525):
>
> 1c9988e525 rtld: cache cpuid results on the stack for intel
> dae425b554 posix: Fix stack overflow in wordexp tilde expansion (BZ 34091, CVE-2026-6791)
> 8759917de5 resolv: Add test case tst-ns_sprintrr (bug 34033, bug 34069)
> 3a418da6a3 resolv: Fix buffer overreads in ns_sprintrrf (CVE-2026-6238)
> e64ae5a591 resolv: More types as unknown in ns_sprintrrf (CVE-2026-5435)
> c9225a3e73 resolv: Check for inet_ntop failure in ns_sprintrrf
> c46f7b2fd6 resolv: Improve formatting of unknown records in ns_sprintrrf
> 1d7d1a16b0 resolv: Fix ns_sprintrrf formatting of class, type values (bug 34289)
> 349297a4eb resolv: Declare __p_class_syms, __p_type_syms for internal use
> fdf10644d6 hppa: Fix missing call to __feraiseexcept (BZ 34306)
> a6fa9a9594 arm: Save/restore VFP registers in PLT trampolines (BZ 34144, BZ 15792)
> fe0ccc9564 iconv: Suppress intermediate errors with //TRANSLIT (bug 34236)
> 22f3d24a6b Hurd: restore some SIOC ioctls
> a13ebdbc7e Hurd: comment ioctls which cannot currently compile
> 446f708e4c Hurd: comment PF_ROUTE/AF_ROUTE defines
> ced45fd472 Hurd: comment PF_LINK/AF_LINK defines
> 89cbf46693 elf: don't clobber ld.so.conf in tst-glibc-hwcaps-prepend-cache [BZ #34210]
> 18b97b03b7 Rename __unused fields to __glibc_reserved.
> a47b5b2b3e math: Fix fma alignment when exponent difference is exactly 64 (BZ 34183)
> 4070d808be stdio-common: Fix buffer overflow in scanf %mc [BZ #34008]
> 2890b35cd3 libio: Fix ungetwc operating on byte stream [BZ #33998]
>
> Testing Results:
> Before After Diff
> PASS 6609 6611 +2
> XPASS 4 4 0
> FAIL 131 132 +1
> XFAIL 16 16 0
> UNSUPPORTED 554 555 +1
>
> Changes in testcases:
>
> testcase-name before after
> resolv/tst-ns_sprintrr(new) - PASS
> nptl/tst-robustpi7 PASS FAIL
>
> [Note: The uplift adds new testcases including resolv/tst-ns_sprintrr
> from commit 8759917de5, which passes, accounting for the PASS and
> UNSUPPORTED increases.
>
> nptl/tst-robustpi7 shows as PASS->FAIL, but it is a flaky test under
> QEMU user-mode emulation (PI robust-mutex handling). No nptl code was
> changed in the SRCREV range.]
>
> Signed-off-by: Adarsh Jagadish Kamini <adarsh.jagadish.kamini@est.tech>
> ---
Hi Adarsh,
Thanks for your patch, but this is not building at all. You will need to
refresh or drop some patches:
ERROR: nativesdk-glibc-2.43+git-r1 do_patch: Applying patch '/srv/pokybuild/yocto-worker/genericx86-64/build/layers/openembedded-core/meta/recipes-core/glibc/glibc/0023-CVE-2026-5450.patch' on target directory '/srv/pokybuild/yocto-worker/genericx86-64/build/build/tmp/work/x86_64-nativesdk-pokysdk-linux/nativesdk-glibc/2.43+git/sources/glibc-2.43+git'
https://autobuilder.yoctoproject.org/valkyrie/#/builders/4/builds/4241
Can you have a look at the issue?
Thanks,
Mathieu
--
Mathieu Dubois-Briand, Bootlin
Embedded Linux and Kernel engineering
https://bootlin.com
next prev parent reply other threads:[~2026-07-28 4:43 UTC|newest]
Thread overview: 10+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-07-27 11:29 [OE-core][PATCH] glibc: stable 2.43 branch updates Adarsh Jagadish Kamini
2026-07-28 4:43 ` Mathieu Dubois-Briand [this message]
2026-07-28 8:24 ` Adarsh Jagadish Kamini
2026-07-28 10:02 ` Adarsh Jagadish Kamini
-- strict thread matches above, loose matches on Subject: below --
2026-05-07 22:48 [PATCH] " Peter Marko
2026-05-11 16:39 ` [OE-core] " Randy MacLeod
2026-05-11 19:07 ` Marko, Peter
2026-05-14 13:02 ` Sundeep KOKKONDA
2026-04-08 9:16 Hemanth.KumarMD
2026-04-08 9:43 ` [OE-core] " Marko, Peter
2026-04-08 11:21 ` Hemanth Kumar M D
2026-04-08 11:28 ` Marko, Peter
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=DK9XHGRCG7LU.1L6EFEVZGMPXB@bootlin.com \
--to=mathieu.dubois-briand@bootlin.com \
--cc=adarsh.jagadish.kamini@est.tech \
--cc=openembedded-core@lists.openembedded.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.