* [OE-core][scarthgap 00/31] Patch review
@ 2026-07-26 8:29 Yoann Congal
2026-07-26 8:29 ` [OE-core][scarthgap 01/31] scripts/install-buildtools: Update to 5.0.19 Yoann Congal
` (30 more replies)
0 siblings, 31 replies; 32+ messages in thread
From: Yoann Congal @ 2026-07-26 8:29 UTC (permalink / raw)
To: openembedded-core
Please review this set of changes for scarthgap and have comments back by
end of day Tuesday, July 28.
Passed a-full on autobuilder:
https://autobuilder.yoctoproject.org/valkyrie/#/builders/29/builds/4287
The following changes since commit 3217490cc554069ae53aa54cf8ad7327ce85fa10:
glibc-testsuite: Do not generate SPDX (2026-07-21 20:32:51 +0200)
are available in the Git repository at:
https://git.openembedded.org/openembedded-core-contrib stable/scarthgap-nut
https://git.openembedded.org/openembedded-core-contrib/log/?h=stable/scarthgap-nut
for you to fetch changes up to 762321beb0260b1411c7f98f13458ec99a118280:
bzip2: fix 'bzip2 --version > /tmp/aaa 2>&1' hang (2026-07-25 23:57:45 +0200)
----------------------------------------------------------------
Bruce Ashfield (2):
linux-yocto/6.6: update to v6.6.143
linux-yocto/6.6: update to v6.6.144
Darsh Kelaiya (1):
gzip: Fix CVE-2026-41991
Deepak Rathore (13):
cups: fix CVE-2026-27447
cups: fix CVE-2026-41079
cups: fix CVE-2026-34978
cups: fix CVE-2026-34980
cups: fix CVE-2026-34979
cups: fix CVE-2026-34990
cups: fix CVE-2026-39314
cups: fix CVE-2026-39316
glib-2.0: fix CVE-2026-58010
glib-2.0: fix CVE-2026-58011
glib-2.0: fix CVE-2026-58012
glib-2.0: fix CVE-2026-58013
glib-2.0: fix CVE-2026-58014
Devansh Patel (8):
libxml2: Fix CVE-2026-11979
openssh: Fix CVE-2026-59999
openssh: Fix CVE-2026-59997
openssh: Fix CVE-2026-59996
openssh: Fix CVE-2026-59995
openssh: Fix CVE-2026-60001
openssh: Fix CVE-2026-60002
openssh: Fix CVE-2026-60000
Enoch Ng (1):
libxpm: fix CVE-2026-4367
Hongxu Jia (1):
bzip2: fix 'bzip2 --version > /tmp/aaa 2>&1' hang
Sudhir Dumbhare (3):
gnutls: set status for CVE-2026-3832
gnutls: fix CVE-2026-42009
libpng: Fix CVE-2026-34757
Yoann Congal (2):
scripts/install-buildtools: Update to 5.0.19
linux-yocto/6.6: update CVE exclusions (6.6.144)
.../openssh/openssh/CVE-2026-59995.patch | 42 +
.../openssh/openssh/CVE-2026-59996.patch | 37 +
.../openssh/openssh/CVE-2026-59997.patch | 58 +
.../openssh/openssh/CVE-2026-59999.patch | 36 +
.../openssh/openssh/CVE-2026-60000.patch | 140 ++
.../openssh/openssh/CVE-2026-60001.patch | 130 ++
.../openssh/openssh/CVE-2026-60002.patch | 226 +++
.../openssh/openssh_9.6p1.bb | 7 +
.../glib-2.0/glib-2.0/CVE-2026-58010.patch | 113 ++
.../glib-2.0/glib-2.0/CVE-2026-58011.patch | 78 ++
.../glib-2.0/glib-2.0/CVE-2026-58012.patch | 228 ++++
.../glib-2.0/glib-2.0/CVE-2026-58013.patch | 140 ++
.../glib-2.0/glib-2.0/CVE-2026-58014.patch | 106 ++
meta/recipes-core/glib-2.0/glib-2.0_2.78.6.bb | 5 +
.../libxml/libxml2/CVE-2026-11979.patch | 70 +
meta/recipes-core/libxml/libxml2_2.12.10.bb | 1 +
...-fix-bzip2-version-tmp-aaa-will-hang.patch | 65 +
meta/recipes-extended/bzip2/bzip2_1.0.8.bb | 1 +
meta/recipes-extended/cups/cups.inc | 12 +
.../cups/CVE-2026-27447-regression_p1.patch | 33 +
.../cups/CVE-2026-27447-regression_p2.patch | 46 +
.../cups/cups/CVE-2026-27447.patch | 108 ++
.../cups/cups/CVE-2026-34978.patch | 107 ++
.../cups/cups/CVE-2026-34979.patch | 61 +
.../cups/CVE-2026-34980-regression_p1.patch | 31 +
.../cups/CVE-2026-34980-regression_p2.patch | 75 +
.../cups/cups/CVE-2026-34980.patch | 85 ++
.../cups/cups/CVE-2026-34990.patch | 351 +++++
.../cups/cups/CVE-2026-39314.patch | 45 +
.../cups/cups/CVE-2026-39316.patch | 40 +
.../cups/cups/CVE-2026-41079.patch | 71 +
.../gzip/gzip-1.13/CVE-2026-41991.patch | 75 +
meta/recipes-extended/gzip/gzip_1.13.bb | 1 +
...67-Out-of-bounds-read-in-xpmNextWord.patch | 140 ++
.../xorg-lib/libxpm_3.5.17.bb | 1 +
.../linux/cve-exclusion_6.6.inc | 1216 ++++++++++++++---
.../linux/linux-yocto-rt_6.6.bb | 6 +-
.../linux/linux-yocto-tiny_6.6.bb | 6 +-
meta/recipes-kernel/linux/linux-yocto_6.6.bb | 28 +-
.../libpng/files/CVE-2026-34757_p1.patch | 521 +++++++
.../libpng/files/CVE-2026-34757_p2.patch | 484 +++++++
.../libpng/libpng_1.6.42.bb | 4 +-
.../gnutls/gnutls/CVE-2026-42009_p1.patch | 66 +
.../gnutls/gnutls/CVE-2026-42009_p2.patch | 47 +
meta/recipes-support/gnutls/gnutls_3.8.4.bb | 4 +
scripts/install-buildtools | 4 +-
46 files changed, 4964 insertions(+), 187 deletions(-)
create mode 100644 meta/recipes-connectivity/openssh/openssh/CVE-2026-59995.patch
create mode 100644 meta/recipes-connectivity/openssh/openssh/CVE-2026-59996.patch
create mode 100644 meta/recipes-connectivity/openssh/openssh/CVE-2026-59997.patch
create mode 100644 meta/recipes-connectivity/openssh/openssh/CVE-2026-59999.patch
create mode 100644 meta/recipes-connectivity/openssh/openssh/CVE-2026-60000.patch
create mode 100644 meta/recipes-connectivity/openssh/openssh/CVE-2026-60001.patch
create mode 100644 meta/recipes-connectivity/openssh/openssh/CVE-2026-60002.patch
create mode 100644 meta/recipes-core/glib-2.0/glib-2.0/CVE-2026-58010.patch
create mode 100644 meta/recipes-core/glib-2.0/glib-2.0/CVE-2026-58011.patch
create mode 100644 meta/recipes-core/glib-2.0/glib-2.0/CVE-2026-58012.patch
create mode 100644 meta/recipes-core/glib-2.0/glib-2.0/CVE-2026-58013.patch
create mode 100644 meta/recipes-core/glib-2.0/glib-2.0/CVE-2026-58014.patch
create mode 100644 meta/recipes-core/libxml/libxml2/CVE-2026-11979.patch
create mode 100644 meta/recipes-extended/bzip2/bzip2/0001-fix-bzip2-version-tmp-aaa-will-hang.patch
create mode 100644 meta/recipes-extended/cups/cups/CVE-2026-27447-regression_p1.patch
create mode 100644 meta/recipes-extended/cups/cups/CVE-2026-27447-regression_p2.patch
create mode 100644 meta/recipes-extended/cups/cups/CVE-2026-27447.patch
create mode 100644 meta/recipes-extended/cups/cups/CVE-2026-34978.patch
create mode 100644 meta/recipes-extended/cups/cups/CVE-2026-34979.patch
create mode 100644 meta/recipes-extended/cups/cups/CVE-2026-34980-regression_p1.patch
create mode 100644 meta/recipes-extended/cups/cups/CVE-2026-34980-regression_p2.patch
create mode 100644 meta/recipes-extended/cups/cups/CVE-2026-34980.patch
create mode 100644 meta/recipes-extended/cups/cups/CVE-2026-34990.patch
create mode 100644 meta/recipes-extended/cups/cups/CVE-2026-39314.patch
create mode 100644 meta/recipes-extended/cups/cups/CVE-2026-39316.patch
create mode 100644 meta/recipes-extended/cups/cups/CVE-2026-41079.patch
create mode 100644 meta/recipes-extended/gzip/gzip-1.13/CVE-2026-41991.patch
create mode 100644 meta/recipes-graphics/xorg-lib/libxpm/0001-Fix-CVE-2026-4367-Out-of-bounds-read-in-xpmNextWord.patch
create mode 100644 meta/recipes-multimedia/libpng/files/CVE-2026-34757_p1.patch
create mode 100644 meta/recipes-multimedia/libpng/files/CVE-2026-34757_p2.patch
create mode 100644 meta/recipes-support/gnutls/gnutls/CVE-2026-42009_p1.patch
create mode 100644 meta/recipes-support/gnutls/gnutls/CVE-2026-42009_p2.patch
^ permalink raw reply [flat|nested] 32+ messages in thread
* [OE-core][scarthgap 01/31] scripts/install-buildtools: Update to 5.0.19
2026-07-26 8:29 [OE-core][scarthgap 00/31] Patch review Yoann Congal
@ 2026-07-26 8:29 ` Yoann Congal
2026-07-26 8:29 ` [OE-core][scarthgap 02/31] linux-yocto/6.6: update to v6.6.143 Yoann Congal
` (29 subsequent siblings)
30 siblings, 0 replies; 32+ messages in thread
From: Yoann Congal @ 2026-07-26 8:29 UTC (permalink / raw)
To: openembedded-core
From: Yoann Congal <yoann.congal@smile.fr>
Update to the 5.0.19 release of the 5.0 series for buildtools
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
---
scripts/install-buildtools | 4 ++--
1 file changed, 2 insertions(+), 2 deletions(-)
diff --git a/scripts/install-buildtools b/scripts/install-buildtools
index 24cb3099453..65200e0cf49 100755
--- a/scripts/install-buildtools
+++ b/scripts/install-buildtools
@@ -57,8 +57,8 @@ logger = scriptutils.logger_create(PROGNAME, stream=sys.stdout)
DEFAULT_INSTALL_DIR = os.path.join(os.path.split(scripts_path)[0],'buildtools')
DEFAULT_BASE_URL = 'https://downloads.yoctoproject.org/releases/yocto'
-DEFAULT_RELEASE = 'yocto-5.0.18'
-DEFAULT_INSTALLER_VERSION = '5.0.18'
+DEFAULT_RELEASE = 'yocto-5.0.19'
+DEFAULT_INSTALLER_VERSION = '5.0.19'
DEFAULT_BUILDDATE = '202110XX'
# Python version sanity check
^ permalink raw reply related [flat|nested] 32+ messages in thread
* [OE-core][scarthgap 02/31] linux-yocto/6.6: update to v6.6.143
2026-07-26 8:29 [OE-core][scarthgap 00/31] Patch review Yoann Congal
2026-07-26 8:29 ` [OE-core][scarthgap 01/31] scripts/install-buildtools: Update to 5.0.19 Yoann Congal
@ 2026-07-26 8:29 ` Yoann Congal
2026-07-26 8:29 ` [OE-core][scarthgap 03/31] linux-yocto/6.6: update to v6.6.144 Yoann Congal
` (28 subsequent siblings)
30 siblings, 0 replies; 32+ messages in thread
From: Yoann Congal @ 2026-07-26 8:29 UTC (permalink / raw)
To: openembedded-core
From: Bruce Ashfield <bruce.ashfield@gmail.com>
Updating linux-yocto/6.6 to the latest korg -stable release that comprises
the following commits:
d1cfde2d5d15 Linux 6.6.143
726abf975668 netfilter: require Ethernet MAC header before using eth_hdr()
05bd072e97fe x86/CPU/AMD: Rename init_amd_zn() to init_amd_zen_common()
4a83b435acf8 x86/CPU/AMD: Call the spectral chicken in the Zen2 init function
5e0c93dca433 x86/CPU/AMD: Move the Zen3 BTC_NO detection to the Zen3 init function
217f53b5e3c6 Revert "selftest/ptp: update ptp selftest to exercise the gettimex options"
189c7e57826f mptcp: fix missing wakeups in edge scenarios
c12e67a0ef93 mptcp: add-addr: always drop other suboptions
1111ab94fd49 arm64: errata: Mitigate TLBI errata on Microsoft Azure Cobalt 100 CPU
e5b6bdc3d8b8 arm64: errata: Mitigate TLBI errata on NVIDIA Olympus CPU
e717a4d08779 arm64: errata: Mitigate TLBI errata on various Arm CPUs
baf63e6a6435 arm64: cputype: Add C1-Premium definitions
1e4a5225b4d3 arm64: cputype: Add C1-Ultra definitions
f58e88f8653f arm64: cputype: Add NVIDIA Olympus definitions
2602d4b53925 ALSA: hda/hdmi: Add quirk for TUXEDO IBS14G6
9aa7edc1347b ipvs: skip ipv6 extension headers for csum checks
2de5c8eea0a9 net: bonding: fix use-after-free in bond_xmit_broadcast()
8fe0231adebe RDMA/umem: Fix truncation for block sizes >= 4G
3faebd387ed1 RDMA: Move DMA block iterator logic into dedicated files
a7c6be320c0e RDMA/umem: fix kernel-doc warnings
09dc18894148 RDMA: During rereg_mr ensure that REREG_ACCESS is compatible
09b8a7aa5a34 hv_netvsc: use kmap_local_page in netvsc_copy_to_send_buf
77b73b54801a mm/memory-failure: fix hugetlb_lock AA deadlock in get_huge_page_for_hwpoison
252bb328b36f mm/memory-failure: fix missing ->mf_stats count in hugetlb poison
05f1ad6d62a3 mm/hugetlb: rename folio_putback_active_hugetlb() to folio_putback_hugetlb()
471f5d78ea4b mm/migrate: don't call folio_putback_active_hugetlb() on dst hugetlb folio
411fa5113da0 mm/hugetlb: rename isolate_hugetlb() to folio_isolate_hugetlb()
eb8a8124484d netfilter: nft_fib: fix stale stack leak via the OIFNAME register
46582b0fd381 usb: typec: ucsi: Don't update power_supply on power role change if not connected
c91ea13375f7 serial: qcom_geni: fix kfifo underflow when flush precedes DMA completion IRQ
d3e9b79aa794 scsi: target: iscsi: Fix CRC overread and double-free in iscsit_handle_text_cmd()
b4621e5ef634 thunderbolt: property: Cap recursion depth in __tb_property_parse_dir()
078c11224c7f usb: typec: ucsi: Check if power role change actually happened before handling
e15c414092b3 usb: gadget: uvc: hold opts->lock across XU walks in uvc_function_bind
5542d2c35930 usb: dwc3: xilinx: fix error handling in zynqmp init error paths
b987f380620b usb: musb: omap2430: Fix use-after-free in omap2430_probe()
a9c22e0f93ba tty: serial: samsung: Remove redundant port lock acquisition in rx helpers
8809b7941c4a tty: serial: samsung: use u32 for register interactions
33da47d4a003 serial: samsung_tty: Use port lock wrappers
1cdb07d8946c ALSA: firewire-motu: Protect register DSP event queue positions
b3f4f82d1315 memfd: deny writeable mappings when implying SEAL_WRITE
2619d9d2aac3 iio: dac: ad5686: fix ref bit initialization for single-channel parts
f8dcef820161 usb: cdns3: plat: fix leaked usb2_phy initialization on usb3_phy acquisition failure
e85bc501947f iio: chemical: scd30: fix division by zero in write_raw
73d8bf36f217 iio: chemical: scd30: Use guard(mutex) to allow early returns
86298fb6829c iio: gyro: adis16260: fix division by zero in write_raw
b35e71b7cc7a mptcp: handle first subflow closing consistently
792fa6eee73e Bluetooth: hci_qca: Convert timeout from jiffies to ms
c3fc351d256c Bluetooth: hci_qca: Migrate to serdev specific shutdown function
123724bb6ee5 serdev: Provide a bustype shutdown function
ca2f48b9c03d serdev: make serdev_bus_type const
c0e37017a452 mm/damon/sysfs-schemes: delete tried region in regions_rmdirs()
e7af1b15c884 mm/memory: fix spurious warning when unmapping device-private/exclusive pages
fe76413677e7 mptcp: do not drop partial packets
293b0e63136b mptcp: introduce the mptcp_init_skb helper
681d14ef45b1 iio: adc: npcm: fix unbalanced clk_disable_unprepare()
4ed1366f9f90 iio: adc: npcm: Convert to platform remove callback returning void
d766a49d9b55 arm64: tlb: Flush walk cache when unsharing PMD tables
4c29603498b0 octeontx2-pf: avoid double free of pool->stack on AQ init failure
26342087fac9 af_unix: Fix UAF read of tail->len in unix_stream_data_wait()
db9389042db4 af_unix: Cache state->msg in unix_stream_read_generic().
c2c764b00c0f rxrpc: Fix RESPONSE packet verification to extract skb to a linear buffer
a05bf6d9e621 rxrpc: Fix DATA decrypt vs splice() by copying data to buffer in recvmsg
7713f4aafb57 net: hsr: defer node table free until after RCU readers
1dca7e491f07 ipv6: ioam: add NULL check for idev in ipv6_hop_ioam()
dcc42d701529 ipv6/addrconf: annotate data-races around devconf fields (II)
ada8dcfd5298 mptcp: pm: fix ADD_ADDR timer infinite retry on option space insufficient
04318e252c58 ice: fix VF queue configuration with low MTU values
d37a60086ee7 selftests: mptcp: drop nanoseconds width specifier
00ffe9893f4b mptcp: reset rcv wnd on disconnect
1521fecf44fc mptcp: cleanup fallback dummy mapping generation
78f9d747f386 mptcp: use plain bool instead of custom binary enum
e043017ac429 octeontx2-af: CGX: add bounds check to cgx_speed_mbps index
1132ca7a1ba8 octeontx2-af: replace deprecated strncpy with strscpy
557edaf01062 platform/x86/intel/vsec: Fix enable_cnt imbalance on PCIe error recovery
969bc6370334 smb: client: require net admin for CIFS SWN netlink
e19eff331240 genetlink: Use internal flags for multicast groups
14897ef9341c cgroup/cpuset: Reset DL migration state on can_attach() failure
850452af77f5 ksmbd: fix OOB write in QUERY_INFO for compound requests
6d8f52f3f80a fbdev/vt8500lcdfb: Initialize fb_ops with fbdev macros
666bd0598f37 ipmi:ssif: NULL thread on error
318a0403b270 ipmi:ssif: Remove unnecessary indention
ae9d4caf6f13 mm/huge_memory: update file PMD counter before folio_put()
310a8cc74612 soc: qcom: ice: Fix race between qcom_ice_probe() and of_qcom_ice_get()
428a33573dcb mm/hugetlb: avoid false positive lockdep assertion
000e8f55fbc7 driver core: reject devices with unregistered buses
b5fa9e32fb67 fs/fcntl: fix SOFTIRQ-unsafe lock order in fasync signaling
201151e120f0 drm/amd/display: Use krealloc_array() in dal_vector_reserve()
7fc4fab4acc3 drm/amd/display: Fix NULL deref and buffer over-read in SDP debugfs
4d1c3c26c2ab drm/amd/display: Clamp VBIOS HDMI retimer register count to array size
79e0273272a0 drm/amd/display: Clamp HDMI HDCP2 rx_id_list read to buffer size
3fe2c6af3f51 drm/amdgpu: restart the CS if some parts of the VM are still invalidated
16dad1fb0d78 drm/amdkfd: Fix buffer overflow in SDMA queue checkpoint/restore on GFX11
62bd09e23a23 drm/amdkfd: fix NULL dereference in get_queue_ids()
d54a221b0f3c slimbus: qcom-ngd-ctrl: Avoid ABBA on tx_lock/ctrl->lock
9f4a76c7e9fa slimbus: qcom-ngd-ctrl: fix OF node refcount
fc261397295b thunderbolt: Limit XDomain response copy to actual frame size
0dd61ba03d05 thunderbolt: Validate XDomain request packet size before type cast
5db10c8ad8c0 thunderbolt: Clamp XDomain response data copy to allocation size
4d0b1524caad thunderbolt: Bound root directory content to block size
5f56bc6bddff thunderbolt: Reject zero-length property entries in validator
7dd9a42b044a sctp: stream: fully roll back denied add-stream state
e97c2a535e23 sctp: diag: reject stale associations in dump_one path
7e60d675288d mmc: sdhci: add signal voltage switch in sdhci_resume_host
b46521877611 mmc: renesas_sdhi: Add OF entry for RZ/G2H SoC
6dc14b9b431e mmc: litex_mmc: Set mandatory idle clocks before CMD0
30e727657185 mmc: core: Fix host controller programming for fixed driver type
8d6e1dd3ad13 mm/hugetlb: restore reservation on error in hugetlb folio copy paths
f0ca9c7f44a9 octeontx2-af: fix memory leak in rvu_setup_hw_resources()
033d498b0f47 nvmem: layouts: onie-tlv: fix hang on unknown types
e7cf30aa5f1f net: rds: clear i_sends on setup unwind
1ccad3ee7998 net: mv643xx: fix OF node refcount
a629418d463f net: bonding: fix NULL pointer dereference in bond_do_ioctl()
c090df5be6bc net/mlx5: Reorder completion before putting command entry in cmd_work_handler
8fb4a23df5b7 misc: fastrpc: Fix NULL pointer dereference in rpmsg callback
d3e26df2e8eb misc: fastrpc: fix DMA address corruption due to find_vma misuse
8b080c891831 misc: fastrpc: fix use-after-free race in fastrpc_map_create
df08fadcf0e5 misc: fastrpc: fix use-after-free of fastrpc_user in workqueue context
6560be3f6a5b ipc/shm: serialize orphan cleanup with shm_nattch updates
7a395a147f06 Input: atkbd - skip deactivate for HONOR BCC-N's internal keyboard
81d60181ed55 Input: atkbd - add DMI quirk for Lenovo Yoga Air 14 (83QK)
2d175d6aae9c i2c: tegra: Fix NOIRQ suspend/resume
5bebff5e8492 i2c: stm32f7: fix timing computation ignoring i2c-analog-filter
7107627b8b35 i2c: qcom-cci: Fix NULL pointer dereference in cci_remove()
dd92773d4d9c fuse: reject fuse_notify() pagecache ops on directories
254c469a404a pidfd: refuse access to tasks that have started exiting harder
0e823ca0e739 inet: frags: fix use-after-free caused by the fqdir_pre_exit() flush
c1234229399f IB/isert: Reject login PDUs shorter than ISER_HEADERS_LEN
1a418ad0e5e5 bnxt_en: Fix NULL pointer dereference
6f5285a6054a ASoC: fsl_sai: Fix 32 slots TDM broken by integer shift UB in xMR write
dfd853197615 vsock/vmci: fix sk_ack_backlog leak on failed handshake
688fcac7054a wifi: nl80211: reject oversized EMA RNR lists
eb13ab2f66e2 selftests: mptcp: add test for extra_subflows underflow on userspace PM
026c4a70e2a9 mptcp: sockopt: check timestamping ret value
b1fd13074f22 mptcp: allow subflow rcv wnd to shrink
907ac6b1658e mptcp: close TOCTOU race while computing rcv_wnd
f2c9012fc115 mptcp: fix retransmission loop when csum is enabled
c2e3aadc8fef ARM: 9475/1: entry: use byte load for KASAN VMAP stack shadow
b6290cc96dc8 ARM: 9474/1: io: avoid KASAN instrumentation of raw halfword I/O
c35c0763af34 ARM: socfpga: Fix OF node refcount leak in SMP setup
1b585673a224 udp: clear skb->dev before running a sockmap verdict
0c2821665ff7 zram: fix use-after-free in zram_bvec_write_partial()
0d64bc200ebe RDMA/srp: bound SRP_RSP sense copy by the received length
5c97ae9382de mm/damon/ops-common: call folio_test_lru() after folio_get()
5242b5f3c77f drm/amd/display: Reject gpio_bitshift >= 32 in bios_parser_get_gpio_pin_info()
898bd0ccfed7 drm/virtio: fix dma_fence refcount leak on error in virtio_gpu_dma_fence_wait()
e2331730175f ALSA: timer: Fix UAF at snd_timer_user_params()
a1288cd700f7 USB: serial: kl5kusb105: fix bulk-out buffer overflow
f71f8f99a9cd USB: serial: option: add usb-id for Dell Wireless DW5826e-m
4cb722747ed2 USB: serial: io_ti: fix heap overflow in build_i2c_fw_hdr()
d92f17af7097 USB: serial: io_ti: fix heap overflow in get_manuf_info()
aa82a078f70f xfrm: espintcp: do not reuse an in-progress partial send
0da2e073f9cb ksmbd: fix use-after-free of a deferred file_lock on double SMB2_CANCEL
07c33be968d9 drm/i915/gem: Fix phys BO pread/pwrite with offset
033d39e41fc3 KVM: Don't WARN if memory is dirtied without a vCPU when the VM is dying
88520b2fecc4 mmc: litex_mmc: Use DIV_ROUND_UP for more accurate clock calculation
1e927a468500 tracing/probes: Point the error offset correctly for eprobe argument error
214a2042b16b Bluetooth: L2CAP: reject BR/EDR signaling packets over MTUsig
1338ee049a89 Bluetooth: hci_sync: reject oversized Broadcast Announcement prepend
8767fe4079af netfilter: nft_tunnel: fix use-after-free on object destroy
e0ce103e89d6 drm/vc4: fix krealloc() memory leak
ed3e134700a2 drm/virtio: Fix driver removal with disabled KMS
c5f438dd2fd8 clk: qcom: dispcc-sc8280xp: Don't park mdp_clk_src at registration time
5e1c1d22268a netfilter: ctnetlink: ensure safe access to master conntrack
5f82b02b4059 ipv6: Fix a potential NPD in cleanup_prefix_route()
ccdd7f1949bb net: mvpp2: build skb from XDP-adjusted data on XDP_PASS
580f92f27cb8 net: mvpp2: refill RX buffers before XDP or skb use
26c0986cb613 net: mvpp2: Add metadata support for xdp mode
3b8b0c3631b1 net: mvpp2: limit XDP frame size to the RX buffer
bede0f481b91 net: mvpp2: sync RX data at the hardware packet offset
cd513e43b4b2 netfilter: nft_exthdr: fix register tracking for F_PRESENT flag
8a81e336da68 netfilter: nf_log: validate MAC header was set before dumping it
a0d16941adf3 netfilter: x_tables: avoid leaking percpu counter pointers
29d8cc44bbdf netfilter: nf_conntrack: destroy stale expectfn expectations on unregister
eb7e77342e3e rds: mark snapshot pages dirty in rds_info_getsockopt()
f513f308cc4b ip6_vti: fix incorrect tunnel matching in vti6_tnl_lookup()
0f22412a2f4f net/rds: fix NULL deref in rds_ib_send_cqe_handler() on masked atomic completion
b903e9b5629e net: guard timestamp cmsgs to real error queue skbs
8ce96f118264 sctp: fix uninit-value in __sctp_rcv_asconf_lookup()
22f4ee66614e r8152: handle the return value of usb_reset_device()
25fdf5369853 net: openvswitch: fix possible kfree_skb of ERR_PTR
0bfa7bba1f41 ipv6: sit: reload inner IPv6 header after GSO offloads
41781f278930 net/mlx5: Fix slab-out-of-bounds in mlx5_query_nic_vport_mac_list
2047c2aa0963 net: qrtr: fix refcount saturation and potential UAF in qrtr_port_remove
12fb84dc4dc8 net: phy: clean the sfp upstream if phy probing fails
838f411b8ef8 net/mlx4: avoid GCC 10 __bad_copy_from() false positive
ecfe9171b26a tcp: restrict SO_ATTACH_FILTER to priv users
10def23b67b4 ASoC: wm_adsp: Fix NULL dereference when removing firmware controls
7db09011ce62 gpio: mvebu: fix NULL pointer dereference in suspend/resume
07a18f5c90dd netlabel: validate unlabeled address and mask attribute lengths
42827d03f800 xfrm: policy: fix use-after-free on inexact bin in xfrm_policy_bysel_ctx()
f4e4b98cee82 iomap: don't revert iov_iter on partially completed buffered writes
fed65bc9de8e arm64: tlb: Optimize ARM64_WORKAROUND_REPEAT_TLBI
b7d3add1884c arm64: tlb: Allow XZR argument to TLBI ops
523bc49979b9 KVM: arm64: Remove VPIPT I-cache handling
d30aac0fa00c tap: free page on error paths in tap_get_user_xdp()
ceafb893b12f net: skbuff: fix missing zerocopy reference in pskb_carve helpers
9eaa4e8d5561 tools/rv: Fix cleanup after failed trace setup
7fce959e9be3 usb: gadget: u_ether: Fix NULL pointer deref in eth_get_drvinfo
36c41e9724c9 usb: gadget: f_ncm: Fix net_device lifecycle with device_move
d68b621bb5a4 ALSA: PCM: Fix wait queue list corruption in snd_pcm_drain() on linked streams
c12c4cae0cd7 time: Fix off-by-one in settimeofday() usec validation
f4aae11abb44 signal: clear JOBCTL_PENDING_MASK for caller in zap_other_threads()
6e39863cefe4 ipmi: Fix rcu_read_unlock to srcu_read_unlock in handle_read_event_rsp
2afc9e684dc7 sctp: purge outqueue on stale COOKIE-ECHO handling
6d6e42e8e17f net/802/mrp: fix vector attribute parsing in mrp_pdu_parse_vecattr
1a827b95e62b ieee802154: 6lowpan: only accept IPv6 packets in lowpan_xmit()
9db4dd019a6b vxlan: vnifilter: fix spurious notification on VNI update
5a7ad529fd53 vxlan: vnifilter: send notification on VNI add
e4e7428349d9 octeontx2-af: npc: Fix CPT channel mask in npc_install_flow
72775977e89c net: ethernet: mtk_eth_soc: Fix use-after-free in metadata dst teardown
cecdc6574a82 ptp: vclock: Switch from RCU to SRCU
8ff85dbabbbf ipv4: restrict IPOPT_SSRR and IPOPT_LSRR options
ba760c38b38b Bluetooth: MGMT: Fix backward compatibility with userspace
0622e527a31d Bluetooth: fix memory leak in error path of hci_alloc_dev()
691f14b6a48b Bluetooth: bnep: reject short frames before parsing
10e90715e68f Bluetooth: bnep: fix incorrect length parsing in bnep_rx_frame() extension handling
98377e6b1a1a Bluetooth: RFCOMM: validate skb length in MCC handlers
74c08e4db35a Bluetooth: MGMT: validate advertising TLV before type checks
de31973ef00e Bluetooth: RFCOMM: hold listener socket in rfcomm_connect_ind()
28a6a3762796 net: fec: fix pinctrl default state restore order on resume
caeb42f28f00 net: lan743x: permit VLAN-tagged packets up to configured MTU
74e02121be1d net: garp: fix unsigned integer underflow in garp_pdu_parse_attr
271355c2ef61 hsr: Remove WARN_ONCE() in hsr_addr_is_self().
91cdbb9b308f net: Annotate sk->sk_write_space() for UDP SOCKMAP.
daf5a9eef894 pcnet32: stop holding device spin lock during napi_complete_done
e732c4444bcf drm/imx: Fix three kernel-doc warnings in dcss-scaler.c
06ce6fc106b1 6lowpan: fix off-by-one in multicast context address compression
8b136f18ac4b net/sched: act_api: use RCU with deferred freeing for action lifecycle
b4892561552d dm cache policy smq: check allocation under invalidate lock
afd64b59c3de netfilter: bridge: make ebt_snat ARP rewrite writable
af80f78ce984 netfilter: nft_ct: bail out on template ct in get eval
7c34f9130529 netfilter: conntrack_irc: fix possible out-of-bounds read
0f8ba5e4c53d netfilter: synproxy: add mutex to guard hook reference counting
c6376b9b1b4d ipvs: clear the svc scheduler ptr early on edit
8122abd4fd92 netfilter: xt_NFQUEUE: prefer raw_smp_processor_id
945a86b21b40 ksmbd: fix NULL-deref of opinfo->conn in oplock/lease break notifiers
9a0dc9279d09 tee: optee: prevent use-after-free when the client exits before the supplicant
5d27d2ffe487 net/smc: fix sleep-inside-lock in __smc_setsockopt() causing local DoS
2a613bf49702 ipv6: mcast: Fix use-after-free when processing MLD queries
aa6ef7340169 i2c: dev: prevent integer overflow in I2C_TIMEOUT ioctl
067579d5cf8c Disable -Wattribute-alias for clang-23 and newer
b26849cffaa7 hwmon: (pmbus/core) Protect regulator operations with mutex
d859e53596d1 RDMA/rxe: Fix "trying to register non-static key in rxe_qp_do_cleanup" bug
7502c1cf303b Bluetooth: hci_conn: fix potential UAF in set_cig_params_sync
90dbad14b109 USB: serial: mct_u232: fix memory corruption with small endpoint
f8b8f1d4bb76 bpf: Free reuseport cBPF prog after RCU grace period.
37f488be2a82 usb: core: Fix SuperSpeed root hub wMaxPacketSize
ff3c2b623bfa HID: core: Fix size_t specifier in hid_report_raw_event()
9e36568e67f8 HID: pass the buffer size to hid_report_raw_event
20a816422e98 HID: core: Add printk_ratelimited variants to hid_warn() etc
bb2040484f90 serial: zs: Convert to use a platform device
c9e78361fe92 serial: dz: Convert to use a platform device
5fc2943ad6a1 serial: dz: Fix bootconsole handover lockup
bef9e8bdbc60 xhci: tegra: Fix ghost USB device on dual-role port unplug
8a65db5edd7b USB: serial: digi_acceleport: fix memory corruption with small endpoints
fbf718d5afe2 landlock: Fix handling of disconnected directories
0e96cd314c0d x86/kexec: Disable KCOV instrumentation after load_segments()
a55618c0f4ce Bluetooth: hci_sync: fix UAF in hci_le_create_cis_sync
4bcaa59f403d USB: serial: cypress_m8: fix memory corruption with small endpoint
36f07474f2b9 serial: zs: Switch to using channel reset
633a33fe1a34 serial: zs: Fix bootconsole handover lockup
6f22119afe53 serial: dz: Fix bootconsole message clobbering at chip reset
a8bd09d3d843 drm/amdkfd: Check for pdd drm file first in CRIU restore path
4e5f808b4541 drm/amdkfd: fix a vulnerability of integer overflow in kfd debugger
6495cc09f7e6 drm/amdkfd: fix NULL pointer bug in svm_range_set_attr
c33322ef3ce5 serial: fsl_lpuart: fix rx buffer and DMA map leaks in start_rx_dma
ea7bdbee9fc3 serial: zs: Fix swapped RI/DSR modem line transition counting
4860f9821baf serial: sh-sci: fix memory region release in error path
70982b7ac673 serial: qcom-geni: fix UART_RX_PAR_EN bit position
3c29f8af029b serial: altera_jtaguart: handle uart_add_one_port() failures
a1b9535768ed drm/amd/pm/si: Disregard vblank time when no displays are connected
28b22dbaf407 drm/i915: Fix potential UAF in TTM object purge
049a6b474823 drm/hyperv: validate VMBus packet size in receive callback
1fb565b77b8f drm/hyperv: validate resolution_count and fix WIN8 fallback
edd06675a023 scsi: target: iscsi: Validate CHAP_R length before base64 decode
4e9f0c4a645c scsi: target: iscsi: Bound iscsi_encode_text_output() appends to rsp_buf
163bd704d751 scsi: scsi_transport_fc: Widen FPIN pname walker counter to u32
0e3c6e5a8fc1 scsi: fcoe: Reject FIP descriptors with zero fip_dlen in CVL walker
5506c825f14d thunderbolt: property: Reject dir_len < 4 to prevent size_t underflow
8d4a758b407a thunderbolt: property: Reject u32 wrap in tb_property_entry_valid()
e835bf9a055f usb: gadget: f_fs: copy only received bytes on short ep0 read
a183b47fee46 usb: gadget: dummy_hcd: Reject hub port requests for non-existent ports
046870ff6b6f usb: gadget: composite: fix integer underflow in WebUSB GET_URL handling
5d39924ae38c usb: gadget: f_hid: fix device reference leak in hidg_alloc()
085652fda7f3 usb: gadget: net2280: Fix double free in probe error path
70bb9a2661d3 USB: serial: mct_u232: fix missing interrupt-in transfer sanity check
be3a1ed4ae51 USB: serial: mxuport: fix memory corruption with small endpoint
0bde5431037a USB: serial: keyspan: fix missing indat transfer sanity check
be50533fe706 USB: serial: cypress_m8: validate interrupt packet headers
ffb739a49186 USB: serial: belkin_sa: validate interrupt status length
37a2ac9f5125 USB: serial: option: add missing RSVD(5) flag for Rolling RW135R-GL
5a0e65d56ffd USB: serial: option: add MeiG SRM813Q
17587492179c usb: usbtmc: reject interrupt endpoints with small wMaxPacketSize
5de7df75ef3a usb: usbtmc: check URB actual_length for interrupt-IN notifications
a0638db2340e usbip: vudc: Fix use after free bug in vudc_remove due to race condition
02c76e026c06 usb: storage: Add quirks for PNY Elite Portable SSD
aec4d38ac605 USB: quirks: add NO_LPM for Lenovo ThinkPad USB-C Dock Gen2 hub controllers
e21f5abf80ad usb: core: Fix up Interrupt IN endpoints with bogus wBytesPerInterval
028cc2555eca usb: chipidea: core: convert ci_role_switch to local variable
6dd5c0ea139b tty: serial: pch_uart: add check for dma_alloc_coherent()
68f603bb8622 counter: Fix refcount leak in counter_alloc() error path
9fa854ea4318 comedi: comedi_test: Fix limiting of convert_arg in waveform_ai_cmdtest()
422af0f9ce0c comedi: comedi_test: fix check for valid scan_begin_src in waveform_ai_cmdtest()
2ad3397f3cc5 Input: synaptics - add LEN2058 to SMBus passlist for ThinkPad E490
e9b62996ba53 Input: atmel_mxt_ts - fix boundary check in mxt_prepare_cfg_mem
0fe08c5776a7 ksmbd: OOB read regression in smb_check_perm_dacl() ACE-walk loops
ba451cf21f1d Input: xpad - add support for ASUS ROG RAIKIRI II
6e6de3eba8e4 Input: xpad - add "Nova 2 Lite" from GameSir
322e48187e02 xfrm: esp: restore combined single-frag length gate
d780c61bd2ef ASoC: qcom: q6asm-dai: do not set stream state in event and trigger callbacks
ed4e2ff1ddd1 ASoC: qcom: q6asm-dai: close stream only when running
2bb6d82b586e netfilter: conntrack: tcp: do not force CLOSE on invalid-seq RST without direction check
32aa292fbcb9 xfrm: ah: use skb_to_full_sk in async output callbacks
00f2c451e57d xfrm: route MIGRATE notifications to caller's netns
c4cc6b3b0013 nfc: hci: fix out-of-bounds read in HCP header parsing
1552b979a0b6 iommu, debugobjects: avoid gcc-16.1 section mismatch warnings
ed598de9f615 HID: wacom: Fix OOB write in wacom_hid_set_device_mode()
f1e89a943ee5 ip6: vti: Use ip6_tnl.net in vti6_changelink().
48ce101cd630 xfrm: input: hold netns during deferred transport reinjection
a29768d56eb3 ipv6: validate extension header length before copying to cmsg
1acfb7d9c6fc ip6: vti: Use ip6_tnl.net in vti6_siocdevprivate().
12d957979e4a ipv6: exthdrs: refresh nh after handling HAO option
f21a9285147a ASoC: qcom: q6asm-dai: fix error handling in prepare and set_params
bddaa4dfc7f3 ipv6: exthdrs: refresh nh pointer after ipv6_hop_jumbo()
679e13a65e68 macsec: fix replay protection at XPN lower-PN wrap
96b72672ce84 bpf: sockmap: fix tail fragment offset in bpf_msg_push_data
48b0aa9c08a3 Input: elan_i2c - validate firmware size before use
0584af4fe40f usb: dwc2: Fix use after free in debug code
c28bfafa9d70 usb: cdns3: plat: fix unbalanced pm_runtime_forbid() call permanently leaks the runtime PM usage counter across bind/unbind cycles
96291794d162 usb: cdns3: gadget: fix request skipping after clearing halt
9a3860454bdf USB: serial: omninet: fix memory corruption with small endpoint
29783e6b6ec0 iio: buffer: hw-consumer: fix use-after-free in error path
d291f76e4231 iio: light: cm3323: fix reg_conf not being initialized correctly
d534936cf3ac iio: magnetometer: st_magn: fix default DRDY pin selection for LIS2MDL
c43741113cd6 iio: temperature: tsys01: fix broken PROM checksum validation
b5d9befff543 iio: ssp_sensors: cancel delayed work_refresh on remove
31bbd4b87dd6 iio: gyro: itg3200: fix i2c read into the wrong stack location
d434a6abd101 iio: adc: viperboard: Fix error handling in vprbrd_iio_read_raw
1c375f2c4a7a iio: dac: ad5686: acquire lock when doing powerdown control
99d8feee7560 iio: dac: ad5686: fix input raw value check
9a8fca2af3aa iio: dac: max5821: fix return value check in powerdown sync
baff1f00d8b5 iio: adc: xilinx-xadc: Fix sequencer mode in postdisable for dual mux
7b9dcbe89d7a wireguard: send: append trailer after expanding head
a452ca80b7ad KVM: SVM: Flush the current TLB when transitioning from xAVIC => x2AVIC
c881af73ae98 KVM: arm64: PMU: Preserve AArch32 counter low bits
ecc9635e7501 USB: cdc-acm: Fix bit overlap and move quirk definitions to header
15b1723c1472 parport: Fix race between port and client registration
bcfb4833cd40 Input: xpad - fix out-of-bounds access for Share button
35f68f36d988 Bluetooth: ISO: serialize iso_sock_clear_timer with socket lock
119fb6f80c44 Bluetooth: ISO: fix UAF in iso_recv_frame
d313683d6ccd Bluetooth: HIDP: fix missing length checks in hidp_input_report()
63cd225cc13d Bluetooth: L2CAP: fix chan ref leak in l2cap_chan_timeout() on !conn
89dec9204171 Bluetooth: L2CAP: use chan timer to close channels in cleanup_listen()
8776032fe989 auxdisplay: line-display: fix OOB read on zero-length message_store()
157ce2c6836c ipc: limit next_id allocation to the valid ID range
7c58c55a2a16 hpfs: fix a crash if hpfs_map_dnode_bitmap fails
dcd2b02b095f Bluetooth: btusb: Allow firmware re-download when version matches
4c52e31e9ea6 HID: quirks: Add ALWAYS_POLL quirk for SIGMACHIP USB mouse
0cd7b3a15a49 Input: ims-pcu - fix usb_free_coherent() size in ims_pcu_buffers_free()
060fca8e0983 media: rc: igorplugusb: fix control request setup packet
9b3145b3001f USB: serial: safe_serial: fix memory corruption with small endpoint
156b6f0aec61 usb: typec: ucsi: validate connector number in ucsi_connector_change()
0af00f1459f5 usb: typec: tcpm/tcpci_maxim: validate header NDO against RX_BYTE_CNT
5cd0e7ac4eef usb: typec: wcove: don't write past struct pd_message in wcove_read_rx_buffer()
70e7045849e9 usb: typec: altmodes/displayport: validate count before reading Status Update VDO
592cbdc644c6 usb: typec: ucsi: displayport: NAK DP_CMD_CONFIGURE without a payload VDO
3f432b820306 usb: typec: ucsi: ccg: reject firmware images without a ':' record header
d42ac0bfb6a1 iio: imu: st_lsm6dsx: fix stack leak in tagged FIFO buffer
d1c9c79eb06e soc/tegra: pmc: Fix unsafe generic_handle_irq() call
0bb1522d3081 hwmon: (pmbus/adm1266) serialize NVMEM blackbox read with pmbus_lock
96852c116071 hwmon: (pmbus/adm1266) serialize GPIO PMBus accesses with pmbus_lock
7e2476057950 x86/kexec: add a sanity check on previous kernel's ima kexec buffer
566db3370f12 of/kexec: refactor ima_get_kexec_buffer() to use ima_validate_range()
43308106a176 ima: verify the previous kernel's IMA buffer lies in addressable RAM
e1d839efc1e4 phy: mscc: Use PHY_ID_MATCH_EXACT for VSC8584, VSC8582, VSC8575, VSC856X
64858b76ec67 arm64: io: Extract user memory type in ioremap_prot()
4356c4d85050 arm64: io: Rename ioremap_prot() to __ioremap_prot()
05ff52238039 drm/i915/psr: Apply Intel DPCD workaround when SDP on prior line used
45e27857b24e drm/dp: Add eDP 1.5 bit definition
ac7045d3f6d3 drm/i915/psr: Read Intel DPCD workaround register
28557e9deb23 drm/i915/psr: Add defininitions for INTEL_WA_REGISTER_CAPS DPCD register
22ee4010866d inet: frags: flush pending skbs in fqdir_pre_exit()
e0fc5427d6a8 inet: frags: add inet_frag_queue_flush()
711ebd961190 drm, fbcon, vga_switcheroo: Avoid race condition in fbcon setup
f707f53f9ff5 drm/fbdev-helper: Set and clear VGA switcheroo client from fb_info
228cc232079d media: rc: ttusbir: fix inverted error logic
a7becb58f6b8 media: rc: fix race between unregister and urb/irq callbacks
3edb8ebbf79b mm/page_alloc: clear page->private in free_pages_prepare()
a9393751ecf7 batman-adv: bla: avoid double decrement of bla.num_requests
99f17d1cdb37 batman-adv: tt: avoid empty VLAN responses
65a1e67339aa batman-adv: tt: fix TOCTOU race for reported vlans
5bc2d50fb66b batman-adv: tp_meter: directly shut down timer on cleanup
3c19cb8a84ef net: af_key: zero aligned sockaddr tail in PF_KEY exports
100953b5011d batman-adv: tp_meter: avoid role confusion in tp_list
cf12f8881832 batman-adv: iv: recover OGM scheduling after forward packet error
13493b00dd1e batman-adv: tvlv: reject oversized TVLV packets
2a8c9e865291 batman-adv: bla: avoid NULL-ptr deref for claim via dropped interface
a5904f2c92b0 batman-adv: tt: reject oversized local TVLV buffers
fcedc98bd03c batman-adv: tvlv: abort OGM send on tvlv append failure
31dcb9711abd batman-adv: v: stop OGMv2 on disabled interface
ae1ada0af162 perf: Fix dangling cgroup pointer in cpuctx
1488367423a6 net: skbuff: fix pskb_carve leaking zcopy pages
c87cd3cb3096 ipv6: fix possible infinite loop in fib6_select_path()
279853aec9f5 ipv6: fix possible infinite loop in rt6_fill_node()
634a9af8a26a sctp: fix race between sctp_wait_for_connect and peeloff
95e414f83243 net: mana: Add NULL guards in teardown path to prevent panic on attach failure
88403b42faa8 gpio: rockchip: convert bank->clk to devm_clk_get_enabled()
6319b38fe69f Bluetooth: L2CAP: Fix possible crash on l2cap_ecred_conn_rsp
cc2b4f749de0 Bluetooth: l2cap: clear chan->ident on ECRED reconfiguration success
97e06791368c ipv6: rpl: fix hdrlen overflow in ipv6_rpl_srh_decompress()
65674d2489a1 ethtool: eeprom: add more safeties to EEPROM Netlink fallback
091b58d9a65b ethtool: eeprom: add missing ethnl_ops_begin() / _complete() during fallback
f4d78a81f57d bonding: refuse to enslave CAN devices
b06203ac5f12 Bluetooth: 6lowpan: check skb_clone() return value in send_mcast_pkt()
5fe860af8630 ASoC: codecs: simple-mux: Fix enum control bounds check
3127a884525d ksmbd: fix FSCTL permission bypass by adding a permission check for FSCTL_SET_SPARSE
e917d0c69f01 tunnels: do not assume transport header in iptunnel_pmtud_check_icmp()
dc3bfa050f87 vxlan: do not reuse cached ip_hdr() value after skb_tunnel_check_pmtu()
76cd9398a047 tunnels: load network headers after skb_cow() in iptunnel_pmtud_build_icmp[v6]()
5165922a8b5c gpio: mxc: fix irq_high handling
a4b64f3e9c7b net: hsr: fix potential OOB access in supervision frame handling
e9e1dbdee16e ASoC: Intel: bytcht_es8316: Fix MCLK leak on init errors
8e59d4d0dcde ipv4: free net->ipv4.sysctl_local_reserved_ports after unregister_net_sysctl_table()
15fb19af49f2 scsi: core: Run queues for all non-SDEV_DEL devices from scsi_run_host_queues
cd691beafea0 net/iucv: fix locking in .getsockopt
ed7a75831301 net/smc: Do not re-initialize smc hashtables
e523bb6d1de3 net: netlink: don't set nsid on local notifications
490a6ef32ab2 net: netlink: fix sending unassigned nsid after assigned one
20f977a75333 vsock: keep poll shutdown state consistent
60d9c0d6cdde tun: free page on build_skb failure in tun_xdp_one()
5b34f9e4fe2f tun: free page on short-frame rejection in tun_xdp_one()
b80ef316e978 netfilter: nf_tables: fix dst corruption in same register operation
ce0712149e21 netfilter: bitwise: add support for doing AND, OR and XOR directly
45cb4821021e netfilter: bitwise: rename some boolean operation functions
a27cb7325a6c netfilter: ebtables: fix OOB read in compat_mtw_from_user
21994d11461b netfilter: xt_cpu: prefer raw_smp_processor_id
af2c22ccb1f6 netfilter: synproxy: refresh tcphdr after skb_ensure_writable
d0cbeaa85b58 nfc: nxp-nci: i2c: use rising-edge IRQ on ACPI systems
fccd685b32df xfrm: Check for underflow in xfrm_state_mtu
ee2d1a8a1833 nfc: llcp: Fix use-after-free race in nfc_llcp_recv_cc()
e00f50f86977 nfc: llcp: Fix use-after-free in llcp_sock_release()
67cca9df4d17 net: cpsw_new: Fix potential unregister of netdev that has not been registered yet
4f33d74ccf69 bcache: fix uninitialized closure object
b4a659bae3b8 drm: Remove plane hsub/vsub alignment requirement for core helpers
6c153d97c100 net/sched: sch_sfb: Replace direct dequeue call with peek and qdisc_dequeue_peeked
963537a26fd8 net: mctp: ensure our nlmsg responses are initialised
5df49f0579f7 net/sched: cls_fw: fix NULL dereference of "old" filters before change()
d883312061cc Input: usbtouchscreen - clamp NEXIO data_len/x_len to URB buffer size
Signed-off-by: Bruce Ashfield <bruce.ashfield@gmail.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
---
.../linux/linux-yocto-rt_6.6.bb | 6 ++--
.../linux/linux-yocto-tiny_6.6.bb | 6 ++--
meta/recipes-kernel/linux/linux-yocto_6.6.bb | 28 +++++++++----------
3 files changed, 20 insertions(+), 20 deletions(-)
diff --git a/meta/recipes-kernel/linux/linux-yocto-rt_6.6.bb b/meta/recipes-kernel/linux/linux-yocto-rt_6.6.bb
index c3200cfd3fe..e5a3882efea 100644
--- a/meta/recipes-kernel/linux/linux-yocto-rt_6.6.bb
+++ b/meta/recipes-kernel/linux/linux-yocto-rt_6.6.bb
@@ -14,13 +14,13 @@ python () {
raise bb.parse.SkipRecipe("Set PREFERRED_PROVIDER_virtual/kernel to linux-yocto-rt to enable it")
}
-SRCREV_machine ?= "1ceada58731a98237f70384921758a4df3951960"
-SRCREV_meta ?= "4a6f16d14b76e28ab7615c88e2fbdf95ee15fc98"
+SRCREV_machine ?= "fcddef60733f35eb43e4f8d5c7fd23d1c5bc4b24"
+SRCREV_meta ?= "b32016757524151fa9577e2c13b2fcc0355a076f"
SRC_URI = "git://git.yoctoproject.org/linux-yocto.git;branch=${KBRANCH};name=machine;protocol=https \
git://git.yoctoproject.org/yocto-kernel-cache;type=kmeta;name=meta;branch=yocto-6.6;destsuffix=${KMETA};protocol=https"
-LINUX_VERSION ?= "6.6.142"
+LINUX_VERSION ?= "6.6.143"
LIC_FILES_CHKSUM = "file://COPYING;md5=6bc538ed5bd9a7fc9398086aedcd7e46"
diff --git a/meta/recipes-kernel/linux/linux-yocto-tiny_6.6.bb b/meta/recipes-kernel/linux/linux-yocto-tiny_6.6.bb
index 563598a2bde..ed4b0c67ae7 100644
--- a/meta/recipes-kernel/linux/linux-yocto-tiny_6.6.bb
+++ b/meta/recipes-kernel/linux/linux-yocto-tiny_6.6.bb
@@ -8,7 +8,7 @@ require recipes-kernel/linux/linux-yocto.inc
# CVE exclusions
include recipes-kernel/linux/cve-exclusion_6.6.inc
-LINUX_VERSION ?= "6.6.142"
+LINUX_VERSION ?= "6.6.143"
LIC_FILES_CHKSUM = "file://COPYING;md5=6bc538ed5bd9a7fc9398086aedcd7e46"
DEPENDS += "${@bb.utils.contains('ARCH', 'x86', 'elfutils-native', '', d)}"
@@ -17,8 +17,8 @@ DEPENDS += "openssl-native util-linux-native"
KMETA = "kernel-meta"
KCONF_BSP_AUDIT_LEVEL = "2"
-SRCREV_machine ?= "66e051144e21d531fa26ef67476dfdefbfc119a2"
-SRCREV_meta ?= "4a6f16d14b76e28ab7615c88e2fbdf95ee15fc98"
+SRCREV_machine ?= "14b1b02cc139bf807405c9ad97a799a1dbfc0e4d"
+SRCREV_meta ?= "b32016757524151fa9577e2c13b2fcc0355a076f"
PV = "${LINUX_VERSION}+git"
diff --git a/meta/recipes-kernel/linux/linux-yocto_6.6.bb b/meta/recipes-kernel/linux/linux-yocto_6.6.bb
index 07a06f18529..c682d6ff17a 100644
--- a/meta/recipes-kernel/linux/linux-yocto_6.6.bb
+++ b/meta/recipes-kernel/linux/linux-yocto_6.6.bb
@@ -18,25 +18,25 @@ KBRANCH:qemux86-64 ?= "v6.6/standard/base"
KBRANCH:qemuloongarch64 ?= "v6.6/standard/base"
KBRANCH:qemumips64 ?= "v6.6/standard/mti-malta64"
-SRCREV_machine:qemuarm ?= "d81ffd8843535762fecf5aa5fb2ca7d2c4343038"
-SRCREV_machine:qemuarm64 ?= "1f7f3a52dacadfcc75863f25252a534b06fdaeeb"
-SRCREV_machine:qemuloongarch64 ?= "a8a7d078f151a24e01d4501853c88c6b08c9cad9"
-SRCREV_machine:qemumips ?= "4410226fddf113b89cceb26e7ee5ca5bb70c55fb"
-SRCREV_machine:qemuppc ?= "8f8faf1fe9183f295901f8f2b8916ff54f4a4bfb"
-SRCREV_machine:qemuriscv64 ?= "a8a7d078f151a24e01d4501853c88c6b08c9cad9"
-SRCREV_machine:qemuriscv32 ?= "a8a7d078f151a24e01d4501853c88c6b08c9cad9"
-SRCREV_machine:qemux86 ?= "a8a7d078f151a24e01d4501853c88c6b08c9cad9"
-SRCREV_machine:qemux86-64 ?= "a8a7d078f151a24e01d4501853c88c6b08c9cad9"
-SRCREV_machine:qemumips64 ?= "14ca63e9f1ce2090e189c16b1024ed3df8f833f0"
-SRCREV_machine ?= "a8a7d078f151a24e01d4501853c88c6b08c9cad9"
-SRCREV_meta ?= "4a6f16d14b76e28ab7615c88e2fbdf95ee15fc98"
+SRCREV_machine:qemuarm ?= "900d4f2a9c0cd33b2f32053ea438c709ca4fc69c"
+SRCREV_machine:qemuarm64 ?= "5f9c75b34f19ebfb1ac2cf26b0cdf1e637b0a67b"
+SRCREV_machine:qemuloongarch64 ?= "d7c355e593fea6abba6099c009d0b4ec566ffba1"
+SRCREV_machine:qemumips ?= "d066c05c4207d69ff781175fbd4544af3a57a6e4"
+SRCREV_machine:qemuppc ?= "c9444b37f0f19f6f7186e4936f940b2e29cef806"
+SRCREV_machine:qemuriscv64 ?= "d7c355e593fea6abba6099c009d0b4ec566ffba1"
+SRCREV_machine:qemuriscv32 ?= "d7c355e593fea6abba6099c009d0b4ec566ffba1"
+SRCREV_machine:qemux86 ?= "d7c355e593fea6abba6099c009d0b4ec566ffba1"
+SRCREV_machine:qemux86-64 ?= "d7c355e593fea6abba6099c009d0b4ec566ffba1"
+SRCREV_machine:qemumips64 ?= "4c96d4f0d9ae5848015aa021c683bc1c68b596ee"
+SRCREV_machine ?= "d7c355e593fea6abba6099c009d0b4ec566ffba1"
+SRCREV_meta ?= "b32016757524151fa9577e2c13b2fcc0355a076f"
# set your preferred provider of linux-yocto to 'linux-yocto-upstream', and you'll
# get the <version>/base branch, which is pure upstream -stable, and the same
# meta SRCREV as the linux-yocto-standard builds. Select your version using the
# normal PREFERRED_VERSION settings.
BBCLASSEXTEND = "devupstream:target"
-SRCREV_machine:class-devupstream ?= "924b4a879cbb75aef37c160b955b92f6894b11a4"
+SRCREV_machine:class-devupstream ?= "d1cfde2d5d15be14123bdd1689162bd27f995a90"
PN:class-devupstream = "linux-yocto-upstream"
KBRANCH:class-devupstream = "v6.6/base"
@@ -44,7 +44,7 @@ SRC_URI = "git://git.yoctoproject.org/linux-yocto.git;name=machine;branch=${KBRA
git://git.yoctoproject.org/yocto-kernel-cache;type=kmeta;name=meta;branch=yocto-6.6;destsuffix=${KMETA};protocol=https"
LIC_FILES_CHKSUM = "file://COPYING;md5=6bc538ed5bd9a7fc9398086aedcd7e46"
-LINUX_VERSION ?= "6.6.142"
+LINUX_VERSION ?= "6.6.143"
PV = "${LINUX_VERSION}+git"
^ permalink raw reply related [flat|nested] 32+ messages in thread
* [OE-core][scarthgap 03/31] linux-yocto/6.6: update to v6.6.144
2026-07-26 8:29 [OE-core][scarthgap 00/31] Patch review Yoann Congal
2026-07-26 8:29 ` [OE-core][scarthgap 01/31] scripts/install-buildtools: Update to 5.0.19 Yoann Congal
2026-07-26 8:29 ` [OE-core][scarthgap 02/31] linux-yocto/6.6: update to v6.6.143 Yoann Congal
@ 2026-07-26 8:29 ` Yoann Congal
2026-07-26 8:29 ` [OE-core][scarthgap 04/31] linux-yocto/6.6: update CVE exclusions (6.6.144) Yoann Congal
` (27 subsequent siblings)
30 siblings, 0 replies; 32+ messages in thread
From: Yoann Congal @ 2026-07-26 8:29 UTC (permalink / raw)
To: openembedded-core
From: Bruce Ashfield <bruce.ashfield@gmail.com>
Updating linux-yocto/6.6 to the latest korg -stable release that comprises
the following commits:
da47cbc254661 Linux 6.6.144
6848a6e39cac4 crypto: qat - remove unused character device and IOCTLs
1a42f84b0f6b5 crypto: qat - Return pointer directly in adf_ctl_alloc_resources
30d648e225447 crypto: qat - Replace kzalloc() + copy_from_user() with memdup_user()
c0b8e6eea1b2b Documentation: ioctl-number: Extend "Include File" column width
802e113cf120d drivers/base/memory: set mem->altmap after successful device registration
511d2b92f8d20 serial: 8250_dw: unregister 8250 port if clk_notifier_register() fails
851e1847f881e serial: qcom_geni: Fix RX DMA stall when SE_DMA_RX_LEN_IN is zero
36599894fa853 ksmbd: fix out-of-bounds read in smb_check_perm_dacl()
2ef8f2a5695ae NFS: Prevent resource leak in nfs_alloc_server()
6c344fff2feff NFSv4/pNFS: reject zero-length r_addr in nfs4_decode_mp_ds_addr
abc978daffd26 nfsd: check get_user() return when reading princhashlen
1e96239fddcef nfsd: fix posix_acl leak on SETACL decode failure
1e04be34cafae NFSD: Fix SECINFO_NO_NAME decode error cleanup
1a7ee9f9f3957 fbdev: modedb: Fix misaligned fields in the 1920x1080-60 mode
c7dc382439f7b fbdev: modedb: fix a possible UAF in fb_find_mode()
7640b4f68acb5 fbdev: Fix fb_new_modelist to prevent null-ptr-deref in fb_videomode_to_var
c04d606f8b35e power: reset: linkstation-poweroff: fix use-after-free in the linkstation_poweroff_init()
889c2a9c59897 KVM: SVM: Fix page overflow in sev_dbg_crypt() for ENCRYPT path
d18756b12aab3 KVM: x86: hyper-v: Bound the bank index when querying sparse banks
b84f46179c806 9p: avoid putting oldfid in p9_client_walk() error path
c5a125eadba05 ocfs2: reject oversized group bitmap descriptors
ddf13f91ca82c rpmsg: char: Fix use-after-free on probe error path
fbaf509ad7cb2 fpga: region: fix use-after-free in child_regions_with_firmware()
44567537a2623 irqchip/imgpdc: Fix resource leak, add missing chained handler cleanup on remove
7e37e9b3e82ad pNFS: Fix use-after-free in pnfs_update_layout()
eaca7dae02fab tipc: fix slab-use-after-free Read in tipc_aead_decrypt_done
96e545410c4f7 blk-cgroup: fix UAF in __blkcg_rstat_flush()
508a0139d3bf6 hdlc_ppp: sync per-proto timers before freeing hdlc state
4fe388218826d gfs2: fix use-after-free in gfs2_qd_dealloc
8e0abc17fbd7e exfat: fix potential use-after-free in exfat_find_dir_entry()
ab465495b1ed5 MIPS: DEC: Prevent initial console buffer from landing in XKPHYS
81fc9a13acae9 bpf: use kvfree() for replaced sysctl write buffer
fda128096fc84 f2fs: keep atomic write retry from zeroing original data
7e4d8f98be63f f2fs: fix incorrect FI_NO_EXTENT handling in __destroy_extent_node()
1ddf3fd21c4c6 f2fs: validate ACL entry sizes in f2fs_acl_from_disk()
24f8c87070c3e f2fs: fix to round down start offset of fallocate for pin file
13e4b59d3a941 f2fs: validate compress cache inode only when enabled
bd499f138ccf7 wifi: iwlwifi: mvm: fix race condition in PTP removal
2b2060c2075a7 wifi: rtw88: usb: fix memory leaks on USB write failures
6579dcb5e0f74 wifi: rtw88: increase TX report timeout to fix race condition
16eef2a52687b wifi: rtlwifi: rtl8821ae: Fix C2H bit location in RX descriptor
318703b6f71d1 wifi: ath11k: fix warning when unbinding
a2e631fa91bb2 wifi: mt76: mt76x2u: Add support for ELECOM WDC-867SU3S
35ab4db86774d keys: Pin request_key_auth payload in instantiate paths
5966e4e2ba213 KEYS: fix overflow in keyctl_pkey_params_get_2()
03ef56495f0be err.h: use __always_inline on all error pointer helpers
5267eab88fa4c fbdev: fix use-after-free in store_modes()
06f6dd2ff2bd0 NTB: epf: Avoid pci_iounmap() with offset when PEER_SPAD and CONFIG share BAR
15fd83a1e42ed apparmor: fix use-after-free in rawdata dedup loop
faea60deaa05c apparmor: mediate the implicit connect of TCP fast open sendmsg
0eb4c16c4adb2 net: skmsg: preserve sg.copy across SG transforms
e28e7fd34c449 mac802154: llsec: add skb_cow_data() before in-place crypto
82c17e13d404f af_unix: Set gc_in_progress to true in unix_gc().
5f0b95ef68ab9 nvmet-tcp: fix race between ICReq handling and queue teardown
e8852ae29868e ntfs3: reject direct userspace writes to reserved $LX* xattrs
ce494707a9c07 ipv4: account for fraggap on the paged allocation path
f79f0db614160 inet: add indirect call wrapper for getfrag() calls
65fb14cbebb0c ipv6: account for fraggap on the paged allocation path
2660bd8333ab6 batman-adv: tvlv: avoid race of cifsnotfound handler state
9c9f4e69368a4 batman-adv: tvlv: enforce 2-byte alignment
d7fdbab25eae6 batman-adv: dat: prevent false sharing between VLANs
a8da361cdd929 batman-adv: tt: track roam count per VID
e82a02a0c1aa2 batman-adv: tt: don't merge change entries with different VIDs
0e868200cf042 batman-adv: tp_meter: handle overlapping packets
31dec4dc86cf6 batman-adv: tp_meter: prevent parallel modifications of last_recv
be3af0c705a13 batman-adv: tp_meter: annotate last_recv_time access with READ/WRITE_ONCE
f8c499fd275e5 batman-adv: tp_meter: restrict number of unacked list entries
97644fdaaf644 batman-adv: v: prevent OGM aggregation on disabled hardif
3af7f10d5fe44 batman-adv: frag: avoid underflow of TTL
cb96aa1737200 batman-adv: frag: ensure fragment is writable before modifying TTL
5263ff0bbd132 batman-adv: fix (m|b)cast csum after decrementing TTL
4741001ca0b04 batman-adv: ensure bcast is writable before modifying TTL
29f59324e61fc batman-adv: tp_meter: initialize last_recv_time during init
b88f8f4e5e78e batman-adv: prevent ELP transmission interval underflow
b5cf66cdc49b1 batman-adv: bla: annotate lasttime access with READ/WRITE_ONCE
75445cf501ac7 batman-adv: tp_meter: add only finished tp_vars to lists
4774a32baec46 batman-adv: tp_meter: handle seqno wrap-around for fast recovery detection
ec8ef37fea33c batman-adv: tp_meter: fix fast recovery precondition
cd74176cf1685 batman-adv: tp_meter: avoid divide-by-zero for dec_cwnd
f58e5df92180e batman-adv: tp_meter: avoid window underflow
774d22045a8fa batman-adv: tp_meter: initialize dec_cwnd explicitly
0c610db91bbde batman-adv: tp_meter: initialize dup_acks explicitly
edae04afb11f6 batman-adv: tp_meter: keep unacked list in ascending ordered
bc6c380c1159d selinux: fix overlayfs mmap() and mprotect() access checks
41c5b269af8b1 lsm: add backing_file LSM hooks
ba3ebdd89fa20 fs: prepare for adding LSM blob to backing_file
922a03b26e354 Bluetooth: btmtk: accept too short WMT FUNC_CTRL events
36c85f7029484 Bluetooth: btmtk: validate WMT event SKB length before struct access
7536ebe0473d9 Revert "ptp: add testptp mask test"
48b91ed7e22bb KVM: x86/mmu: Ensure hugepage is in by slot before checking max mapping level
9291654d69e08 KVM: x86: Fix shadow paging use-after-free due to unexpected role
2de4db145b299 eventpoll: fix ep_remove struct eventpoll / struct file UAF
a0e685da1efe0 eventpoll: move epi_fget() up
20423e2c1c84a eventpoll: rename ep_remove_safe() back to ep_remove()
0a4a2db528b0e eventpoll: drop vestigial __ prefix from ep_remove_{file,epi}()
f484ab90b2290 eventpoll: kill __ep_remove()
903070f8f3552 eventpoll: split __ep_remove()
ff4fe83a9aabb eventpoll: use hlist_is_singular_node() in __ep_remove()
44e8907b81fea file: add fput() cleanup helper
2181a09ba980f virtiofs: fix UAF on submount umount
cd923dadefadb media: vidtv: fix NULL pointer dereference in vidtv_mux_push_si
d2bbbb6c55812 ksmbd: reject non-VALID session in compound request branch
8232fca738011 vc_screen: fix null-ptr-deref in vcs_notifier() during concurrent vcs_write
08fbcba06e968 scripts/sorttable: Fix endianness handling in build-time mcount sort
80514e97c50ab scripts/sorttable: Allow matches to functions before function entry
9ba53f9808e1e scripts/sorttable: Use normal sort if theres no relocs in the mcount section
e115e9fa69b48 ftrace: Check against is_kernel_text() instead of kaslr_offset()
379e755ec2c54 ftrace: Test mcount_loc addr before calling ftrace_call_addr()
bf802b936a7b2 ftrace: Do not over-allocate ftrace memory
4c30b173b6176 ftrace: Have ftrace pages output reflect freed pages
dc06779d338de ftrace: Update the mcount_loc check of skipped entries
4893af6318fe8 scripts/sorttable: Zero out weak functions in mcount_loc table
bbfbacec9e000 scripts/sorttable: Always use an array for the mcount_loc sorting
38be2ffe9808b scripts/sorttable: Have mcount rela sort use direct values
fe0434d604a94 arm64: scripts/sorttable: Implement sorting mcount_loc at boot for arm64
8297f13962063 scripts/sorttable: Use a structure of function pointers for elf helpers
ff7e015d63849 scripts/sorttable: Get start/stop_mcount_loc from ELF file directly
ecbb09356560c scripts/sorttable: Move code from sorttable.h into sorttable.c
7fbddce9a2685 scripts/sorttable: Use uint64_t for mcount sorting
23b5a9659a27d scripts/sorttable: Add helper functions for Elf_Sym
8cd6caaa4a244 scripts/sorttable: Add helper functions for Elf_Shdr
a03240485cf57 scripts/sorttable: Add helper functions for Elf_Ehdr
1dd7def1ae877 scripts/sorttable: Convert Elf_Sym MACRO over to a union
1afca399cc4d5 scripts/sorttable: Replace Elf_Shdr Macro with a union
7ce5ed40d976e scripts/sorttable: Convert Elf_Ehdr to union
e6bb2482b5b17 scripts/sorttable: Make compare_extable() into two functions
d5e14532a8b86 scripts/sorttable: Have the ORC code use the _r() functions to read
4f2fba2de0620 scripts/sorttable: Remove unneeded Elf_Rel
c13a4c1fd1b74 scripts/sorttable: Remove unused write functions
d9e259e63b36b scripts/sorttable: Remove unused macro defines
030fe3e9d8abd fuse: re-lock request before replacing page cache folio
fe95e90559bce slimbus: qcom-ngd-ctrl: Balance pm_runtime enablement for NGD
e65ae7c948640 slimbus: qcom-ngd-ctrl: Fix up platform_driver registration
5d1ae4e17a3ec rxrpc: Fix the ACK parser to extract the SACK table for parsing
09c9b92c20104 net: phonet: free phonet_device after RCU grace period
210ac54bdd8df phonet: Pass net and ifindex to phonet_address_notify().
cf30797ea8cea phonet: Pass ifindex to fill_addr().
6707d7e0b7174 locking/rtmutex: Skip remove_waiter() when waiter is not enqueued
67fde21e4522e Drivers: hv: vmbus: Improve the logic of reserving fb_mmio on Gen2 VMs
5df8310a41391 hv: utils: handle and propagate errors in kvp_register
23e5a1b9ae954 mptcp: pm: fix extra_subflows underflow on userspace PM subflow creation
4830fb44d12f5 netfilter: nf_tables: always walk all pending catchall elements
7109d69bec6ed dlm: prevent NPD when writing a positive value to event_done
c84860dac7af7 regulator: core: fix locking in regulator_resolve_supply() error path
c2716362ec335 ring-buffer: Remove ring_buffer_read_prepare_sync()
f155b8f1c9576 selftests/bpf: Update comments find_equal_scalars->sync_linked_regs
8e655dbef4c9e selftests/bpf: Tests for per-insn sync_linked_regs() precision tracking
78da8e1be90c5 bpf: Remove mark_precise_scalar_ids()
0252b9d262222 bpf: Track equal scalars history on per-instruction level
b741c9c6ef59f af_unix: Reject SIOCATMARK on non-stream sockets
f68f34033d403 selftests/bpf: Add test to ensure kprobe_multi is not sleepable
89327ed787746 bpf: Reject sleepable kprobe_multi programs at attach time
eb045714bc6a2 agp/amd64: Fix broken error propagation in agp_amd64_probe()
1078ae8175777 net: qualcomm: rmnet: fix endpoint use-after-free in rmnet_dellink()
1c4ffe6b4f043 i2c: stub: Reject I2C block transfers with invalid length
c19b360fa10c5 RDMA/bnxt_re: zero shared page before exposing to userspace
218c24bfc3334 KVM: VMX: Update SVI during runtime APICv activation
de1ba6c93868f ARM: fix branch predictor hardening
1f7cc85046f1c ARM: fix hash_name() fault
98b209cd62ef9 ARM: allow __do_kernel_fault() to report execution of memory faults
89b37df6f805f ARM: group is_permission_fault() with is_translation_fault()
5d95f6b267f3d debugobjects: Dont call fill_pool() in early boot hardirq context
a3383df76f0d7 debugobjects: Do not fill_pool() if pi_blocked_on
c8cd2ca8f085c debugobjects: Use LD_WAIT_CONFIG instead of LD_WAIT_SLEEP
0d2a64411b097 debugobjects: Allow to refill the pool before SYSTEM_SCHEDULING
40fe77146137b batman-adv: tt: prevent TVLV entry number overflow
abb069fdf51a9 drm/v3d: Skip CSD when it has zeroed workgroups
756724002c5a6 drm/v3d: Store the active job inside the queue's state
f4b6b4af7ef06 ip6_vti: set netns_immutable on the fallback device.
499c6b43a79dd drm/amd/display: Bound VBIOS record-chain walk loops
b685d6ef6f07a net/sched: fix pedit partial COW leading to page cache corruption
8bef2f840b43e fuse: limit FUSE_NOTIFY_RETRIEVE to uptodate folios
Signed-off-by: Bruce Ashfield <bruce.ashfield@gmail.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
---
.../linux/linux-yocto-rt_6.6.bb | 6 ++--
.../linux/linux-yocto-tiny_6.6.bb | 6 ++--
meta/recipes-kernel/linux/linux-yocto_6.6.bb | 28 +++++++++----------
3 files changed, 20 insertions(+), 20 deletions(-)
diff --git a/meta/recipes-kernel/linux/linux-yocto-rt_6.6.bb b/meta/recipes-kernel/linux/linux-yocto-rt_6.6.bb
index e5a3882efea..cb8d8c418f1 100644
--- a/meta/recipes-kernel/linux/linux-yocto-rt_6.6.bb
+++ b/meta/recipes-kernel/linux/linux-yocto-rt_6.6.bb
@@ -14,13 +14,13 @@ python () {
raise bb.parse.SkipRecipe("Set PREFERRED_PROVIDER_virtual/kernel to linux-yocto-rt to enable it")
}
-SRCREV_machine ?= "fcddef60733f35eb43e4f8d5c7fd23d1c5bc4b24"
-SRCREV_meta ?= "b32016757524151fa9577e2c13b2fcc0355a076f"
+SRCREV_machine ?= "d7fbdb4e5e7a35bdb8bb87d159204d74ef130a32"
+SRCREV_meta ?= "a77e1b965423603456f2d9dbf3de53bb8a3d75af"
SRC_URI = "git://git.yoctoproject.org/linux-yocto.git;branch=${KBRANCH};name=machine;protocol=https \
git://git.yoctoproject.org/yocto-kernel-cache;type=kmeta;name=meta;branch=yocto-6.6;destsuffix=${KMETA};protocol=https"
-LINUX_VERSION ?= "6.6.143"
+LINUX_VERSION ?= "6.6.144"
LIC_FILES_CHKSUM = "file://COPYING;md5=6bc538ed5bd9a7fc9398086aedcd7e46"
diff --git a/meta/recipes-kernel/linux/linux-yocto-tiny_6.6.bb b/meta/recipes-kernel/linux/linux-yocto-tiny_6.6.bb
index ed4b0c67ae7..73d971f7eee 100644
--- a/meta/recipes-kernel/linux/linux-yocto-tiny_6.6.bb
+++ b/meta/recipes-kernel/linux/linux-yocto-tiny_6.6.bb
@@ -8,7 +8,7 @@ require recipes-kernel/linux/linux-yocto.inc
# CVE exclusions
include recipes-kernel/linux/cve-exclusion_6.6.inc
-LINUX_VERSION ?= "6.6.143"
+LINUX_VERSION ?= "6.6.144"
LIC_FILES_CHKSUM = "file://COPYING;md5=6bc538ed5bd9a7fc9398086aedcd7e46"
DEPENDS += "${@bb.utils.contains('ARCH', 'x86', 'elfutils-native', '', d)}"
@@ -17,8 +17,8 @@ DEPENDS += "openssl-native util-linux-native"
KMETA = "kernel-meta"
KCONF_BSP_AUDIT_LEVEL = "2"
-SRCREV_machine ?= "14b1b02cc139bf807405c9ad97a799a1dbfc0e4d"
-SRCREV_meta ?= "b32016757524151fa9577e2c13b2fcc0355a076f"
+SRCREV_machine ?= "25b07b85b558f3587c11c9363cccd9cb93fcef45"
+SRCREV_meta ?= "a77e1b965423603456f2d9dbf3de53bb8a3d75af"
PV = "${LINUX_VERSION}+git"
diff --git a/meta/recipes-kernel/linux/linux-yocto_6.6.bb b/meta/recipes-kernel/linux/linux-yocto_6.6.bb
index c682d6ff17a..64609554ee2 100644
--- a/meta/recipes-kernel/linux/linux-yocto_6.6.bb
+++ b/meta/recipes-kernel/linux/linux-yocto_6.6.bb
@@ -18,25 +18,25 @@ KBRANCH:qemux86-64 ?= "v6.6/standard/base"
KBRANCH:qemuloongarch64 ?= "v6.6/standard/base"
KBRANCH:qemumips64 ?= "v6.6/standard/mti-malta64"
-SRCREV_machine:qemuarm ?= "900d4f2a9c0cd33b2f32053ea438c709ca4fc69c"
-SRCREV_machine:qemuarm64 ?= "5f9c75b34f19ebfb1ac2cf26b0cdf1e637b0a67b"
-SRCREV_machine:qemuloongarch64 ?= "d7c355e593fea6abba6099c009d0b4ec566ffba1"
-SRCREV_machine:qemumips ?= "d066c05c4207d69ff781175fbd4544af3a57a6e4"
-SRCREV_machine:qemuppc ?= "c9444b37f0f19f6f7186e4936f940b2e29cef806"
-SRCREV_machine:qemuriscv64 ?= "d7c355e593fea6abba6099c009d0b4ec566ffba1"
-SRCREV_machine:qemuriscv32 ?= "d7c355e593fea6abba6099c009d0b4ec566ffba1"
-SRCREV_machine:qemux86 ?= "d7c355e593fea6abba6099c009d0b4ec566ffba1"
-SRCREV_machine:qemux86-64 ?= "d7c355e593fea6abba6099c009d0b4ec566ffba1"
-SRCREV_machine:qemumips64 ?= "4c96d4f0d9ae5848015aa021c683bc1c68b596ee"
-SRCREV_machine ?= "d7c355e593fea6abba6099c009d0b4ec566ffba1"
-SRCREV_meta ?= "b32016757524151fa9577e2c13b2fcc0355a076f"
+SRCREV_machine:qemuarm ?= "3adc19c1e1e3ee865f9b0d7bc0fedd0e4aeee995"
+SRCREV_machine:qemuarm64 ?= "39a4fe09d3d795042cc14eb3c78f6a03874c48df"
+SRCREV_machine:qemuloongarch64 ?= "2baf8e92ef6ad38945005adf39342b9efb4509ec"
+SRCREV_machine:qemumips ?= "ba0b8f925ec8b5926c6c2ddbc2c2c77305324bab"
+SRCREV_machine:qemuppc ?= "66c01b44545110249c940f865c4ed10d4d315b29"
+SRCREV_machine:qemuriscv64 ?= "2baf8e92ef6ad38945005adf39342b9efb4509ec"
+SRCREV_machine:qemuriscv32 ?= "2baf8e92ef6ad38945005adf39342b9efb4509ec"
+SRCREV_machine:qemux86 ?= "2baf8e92ef6ad38945005adf39342b9efb4509ec"
+SRCREV_machine:qemux86-64 ?= "2baf8e92ef6ad38945005adf39342b9efb4509ec"
+SRCREV_machine:qemumips64 ?= "1793417d6568e244579278e6f1fc7107987946f5"
+SRCREV_machine ?= "2baf8e92ef6ad38945005adf39342b9efb4509ec"
+SRCREV_meta ?= "a77e1b965423603456f2d9dbf3de53bb8a3d75af"
# set your preferred provider of linux-yocto to 'linux-yocto-upstream', and you'll
# get the <version>/base branch, which is pure upstream -stable, and the same
# meta SRCREV as the linux-yocto-standard builds. Select your version using the
# normal PREFERRED_VERSION settings.
BBCLASSEXTEND = "devupstream:target"
-SRCREV_machine:class-devupstream ?= "d1cfde2d5d15be14123bdd1689162bd27f995a90"
+SRCREV_machine:class-devupstream ?= "da47cbc254661aa66d61ef061485a7080305c4be"
PN:class-devupstream = "linux-yocto-upstream"
KBRANCH:class-devupstream = "v6.6/base"
@@ -44,7 +44,7 @@ SRC_URI = "git://git.yoctoproject.org/linux-yocto.git;name=machine;branch=${KBRA
git://git.yoctoproject.org/yocto-kernel-cache;type=kmeta;name=meta;branch=yocto-6.6;destsuffix=${KMETA};protocol=https"
LIC_FILES_CHKSUM = "file://COPYING;md5=6bc538ed5bd9a7fc9398086aedcd7e46"
-LINUX_VERSION ?= "6.6.143"
+LINUX_VERSION ?= "6.6.144"
PV = "${LINUX_VERSION}+git"
^ permalink raw reply related [flat|nested] 32+ messages in thread
* [OE-core][scarthgap 04/31] linux-yocto/6.6: update CVE exclusions (6.6.144)
2026-07-26 8:29 [OE-core][scarthgap 00/31] Patch review Yoann Congal
` (2 preceding siblings ...)
2026-07-26 8:29 ` [OE-core][scarthgap 03/31] linux-yocto/6.6: update to v6.6.144 Yoann Congal
@ 2026-07-26 8:29 ` Yoann Congal
2026-07-26 8:29 ` [OE-core][scarthgap 05/31] libxml2: Fix CVE-2026-11979 Yoann Congal
` (26 subsequent siblings)
30 siblings, 0 replies; 32+ messages in thread
From: Yoann Congal @ 2026-07-26 8:29 UTC (permalink / raw)
To: openembedded-core
From: Yoann Congal <yoann.congal@smile.fr>
$ ./meta/recipes-kernel/linux/generate-cve-exclusions.py .../cvelistV5/ 6.6.144 > meta/recipes-kernel/linux/cve-exclusion_6.6.inc
Generated at 2026-07-23 08:09:32.765073+00:00 for kernel version 6.6.144
From cvelistV5 cve_2026-07-23_0700Z
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
---
.../linux/cve-exclusion_6.6.inc | 1216 ++++++++++++++---
1 file changed, 1052 insertions(+), 164 deletions(-)
diff --git a/meta/recipes-kernel/linux/cve-exclusion_6.6.inc b/meta/recipes-kernel/linux/cve-exclusion_6.6.inc
index 2a194e7c84d..fd17e611a4b 100644
--- a/meta/recipes-kernel/linux/cve-exclusion_6.6.inc
+++ b/meta/recipes-kernel/linux/cve-exclusion_6.6.inc
@@ -1,11 +1,11 @@
# Auto-generated CVE metadata, DO NOT EDIT BY HAND.
-# Generated at 2026-07-07 17:39:10.952928+00:00 for kernel version 6.6.142
-# From cvelistV5 cve_2026-07-07_1600Z
+# Generated at 2026-07-23 08:09:32.765073+00:00 for kernel version 6.6.144
+# From cvelistV5 cve_2026-07-23_0700Z
python check_kernel_cve_status_version() {
- this_version = "6.6.142"
+ this_version = "6.6.144"
kernel_version = d.getVar("LINUX_VERSION")
if kernel_version != this_version:
bb.warn("Kernel CVE status needs updating: generated for %s but kernel is %s" % (this_version, kernel_version))
@@ -15132,7 +15132,7 @@ CVE_STATUS[CVE-2024-58091] = "fixed-version: only affects 6.11 onwards"
CVE_STATUS[CVE-2024-58092] = "fixed-version: only affects 6.8 onwards"
-# CVE-2024-58093 needs backporting (fixed from 6.15)
+CVE_STATUS[CVE-2024-58093] = "cpe-stable-backport: Backported in 6.6.87"
# CVE-2024-58094 needs backporting (fixed from 6.15)
@@ -15520,7 +15520,7 @@ CVE_STATUS[CVE-2025-21815] = "fixed-version: only affects 6.7 onwards"
CVE_STATUS[CVE-2025-21816] = "cpe-stable-backport: Backported in 6.6.93"
-CVE_STATUS[CVE-2025-21817] = "fixed-version: only affects 6.13.2 onwards"
+CVE_STATUS[CVE-2025-21817] = "fixed-version: only affects 6.12.96 onwards"
CVE_STATUS[CVE-2025-21819] = "cpe-stable-backport: Backported in 6.6.78"
@@ -16142,7 +16142,7 @@ CVE_STATUS[CVE-2025-22128] = "fixed-version: only affects 6.8 onwards"
# CVE-2025-23130 needs backporting (fixed from 6.15)
-# CVE-2025-23131 may need backporting (fixed from 6.6.144)
+CVE_STATUS[CVE-2025-23131] = "cpe-stable-backport: Backported in 6.6.144"
# CVE-2025-23132 needs backporting (fixed from 6.15)
@@ -19764,7 +19764,7 @@ CVE_STATUS[CVE-2025-68294] = "fixed-version: only affects 6.15 onwards"
CVE_STATUS[CVE-2025-68295] = "cpe-stable-backport: Backported in 6.6.119"
-# CVE-2025-68296 may need backporting (fixed from 6.6.143)
+CVE_STATUS[CVE-2025-68296] = "cpe-stable-backport: Backported in 6.6.143"
CVE_STATUS[CVE-2025-68297] = "cpe-stable-backport: Backported in 6.6.119"
@@ -19958,7 +19958,7 @@ CVE_STATUS[CVE-2025-68734] = "cpe-stable-backport: Backported in 6.6.117"
CVE_STATUS[CVE-2025-68735] = "fixed-version: only affects 6.10 onwards"
-# CVE-2025-68736 may need backporting (fixed from 6.6.143)
+CVE_STATUS[CVE-2025-68736] = "cpe-stable-backport: Backported in 6.6.143"
CVE_STATUS[CVE-2025-68737] = "fixed-version: only affects 6.18 onwards"
@@ -20022,7 +20022,7 @@ CVE_STATUS[CVE-2025-68766] = "cpe-stable-backport: Backported in 6.6.120"
CVE_STATUS[CVE-2025-68767] = "cpe-stable-backport: Backported in 6.6.120"
-# CVE-2025-68768 may need backporting (fixed from 6.6.143)
+CVE_STATUS[CVE-2025-68768] = "cpe-stable-backport: Backported in 6.6.143"
CVE_STATUS[CVE-2025-68769] = "cpe-stable-backport: Backported in 6.6.120"
@@ -21098,7 +21098,7 @@ CVE_STATUS[CVE-2026-23275] = "fixed-version: only affects 6.13 onwards"
CVE_STATUS[CVE-2026-23277] = "cpe-stable-backport: Backported in 6.6.130"
-# CVE-2026-23278 may need backporting (fixed from 6.6.144)
+CVE_STATUS[CVE-2026-23278] = "cpe-stable-backport: Backported in 6.6.144"
CVE_STATUS[CVE-2026-23279] = "cpe-stable-backport: Backported in 6.6.130"
@@ -21230,7 +21230,7 @@ CVE_STATUS[CVE-2026-23344] = "fixed-version: only affects 6.19 onwards"
CVE_STATUS[CVE-2026-23345] = "fixed-version: only affects 6.13 onwards"
-# CVE-2026-23346 may need backporting (fixed from 6.6.143)
+CVE_STATUS[CVE-2026-23346] = "cpe-stable-backport: Backported in 6.6.143"
CVE_STATUS[CVE-2026-23347] = "cpe-stable-backport: Backported in 6.6.130"
@@ -21546,7 +21546,7 @@ CVE_STATUS[CVE-2026-31417] = "cpe-stable-backport: Backported in 6.6.134"
CVE_STATUS[CVE-2026-31418] = "cpe-stable-backport: Backported in 6.6.134"
-# CVE-2026-31419 may need backporting (fixed from 6.6.143)
+CVE_STATUS[CVE-2026-31419] = "cpe-stable-backport: Backported in 6.6.143"
# CVE-2026-31420 needs backporting (fixed from 7.0)
@@ -21572,7 +21572,7 @@ CVE_STATUS[CVE-2026-31430] = "cpe-stable-backport: Backported in 6.6.135"
CVE_STATUS[CVE-2026-31431] = "cpe-stable-backport: Backported in 6.6.137"
-# CVE-2026-31432 may need backporting (fixed from 6.6.143)
+CVE_STATUS[CVE-2026-31432] = "cpe-stable-backport: Backported in 6.6.143"
CVE_STATUS[CVE-2026-31433] = "cpe-stable-backport: Backported in 6.6.131"
@@ -21680,7 +21680,7 @@ CVE_STATUS[CVE-2026-31484] = "fixed-version: only affects 6.19 onwards"
CVE_STATUS[CVE-2026-31485] = "cpe-stable-backport: Backported in 6.6.131"
-# CVE-2026-31486 may need backporting (fixed from 6.6.143)
+CVE_STATUS[CVE-2026-31486] = "cpe-stable-backport: Backported in 6.6.143"
# CVE-2026-31487 needs backporting (fixed from 7.0)
@@ -22294,7 +22294,7 @@ CVE_STATUS[CVE-2026-43008] = "fixed-version: only affects 6.19 onwards"
# CVE-2026-43009 needs backporting (fixed from 7.0)
-# CVE-2026-43010 may need backporting (fixed from 6.6.144)
+CVE_STATUS[CVE-2026-43010] = "cpe-stable-backport: Backported in 6.6.144"
CVE_STATUS[CVE-2026-43011] = "cpe-stable-backport: Backported in 6.6.134"
@@ -22312,7 +22312,7 @@ CVE_STATUS[CVE-2026-43017] = "cpe-stable-backport: Backported in 6.6.134"
CVE_STATUS[CVE-2026-43018] = "cpe-stable-backport: Backported in 6.6.134"
-# CVE-2026-43019 may need backporting (fixed from 6.6.143)
+CVE_STATUS[CVE-2026-43019] = "cpe-stable-backport: Backported in 6.6.143"
CVE_STATUS[CVE-2026-43020] = "cpe-stable-backport: Backported in 6.6.134"
@@ -22450,7 +22450,7 @@ CVE_STATUS[CVE-2026-43086] = "cpe-stable-backport: Backported in 6.6.136"
CVE_STATUS[CVE-2026-43087] = "fixed-version: only affects 6.19 onwards"
-# CVE-2026-43088 may need backporting (fixed from 6.6.143)
+CVE_STATUS[CVE-2026-43088] = "cpe-stable-backport: Backported in 6.6.143"
CVE_STATUS[CVE-2026-43089] = "cpe-stable-backport: Backported in 6.6.136"
@@ -22506,7 +22506,7 @@ CVE_STATUS[CVE-2026-43114] = "cpe-stable-backport: Backported in 6.6.136"
# CVE-2026-43115 needs backporting (fixed from 7.0)
-# CVE-2026-43116 may need backporting (fixed from 6.6.143)
+CVE_STATUS[CVE-2026-43116] = "cpe-stable-backport: Backported in 6.6.143"
CVE_STATUS[CVE-2026-43117] = "cpe-stable-backport: Backported in 6.6.136"
@@ -22530,7 +22530,7 @@ CVE_STATUS[CVE-2026-43124] = "cpe-stable-backport: Backported in 6.6.128"
CVE_STATUS[CVE-2026-43128] = "cpe-stable-backport: Backported in 6.6.128"
-# CVE-2026-43129 may need backporting (fixed from 6.6.143)
+CVE_STATUS[CVE-2026-43129] = "cpe-stable-backport: Backported in 6.6.143"
CVE_STATUS[CVE-2026-43130] = "cpe-stable-backport: Backported in 6.6.128"
@@ -22710,7 +22710,7 @@ CVE_STATUS[CVE-2026-43217] = "fixed-version: only affects 6.15 onwards"
CVE_STATUS[CVE-2026-43218] = "cpe-stable-backport: Backported in 6.6.128"
-# CVE-2026-43219 may need backporting (fixed from 6.6.143)
+CVE_STATUS[CVE-2026-43219] = "cpe-stable-backport: Backported in 6.6.143"
CVE_STATUS[CVE-2026-43220] = "cpe-stable-backport: Backported in 6.6.140"
@@ -22752,7 +22752,7 @@ CVE_STATUS[CVE-2026-43238] = "cpe-stable-backport: Backported in 6.6.128"
CVE_STATUS[CVE-2026-43239] = "cpe-stable-backport: Backported in 6.6.128"
-# CVE-2026-43240 may need backporting (fixed from 6.6.143)
+CVE_STATUS[CVE-2026-43240] = "cpe-stable-backport: Backported in 6.6.143"
CVE_STATUS[CVE-2026-43241] = "cpe-stable-backport: Backported in 6.6.128"
@@ -22878,7 +22878,7 @@ CVE_STATUS[CVE-2026-43301] = "fixed-version: only affects 6.8 onwards"
CVE_STATUS[CVE-2026-43302] = "cpe-stable-backport: Backported in 6.6.128"
-# CVE-2026-43303 may need backporting (fixed from 6.6.143)
+CVE_STATUS[CVE-2026-43303] = "cpe-stable-backport: Backported in 6.6.143"
CVE_STATUS[CVE-2026-43304] = "cpe-stable-backport: Backported in 6.6.128"
@@ -22894,7 +22894,7 @@ CVE_STATUS[CVE-2026-43307] = "fixed-version: only affects 6.12 onwards"
# CVE-2026-43310 needs backporting (fixed from 7.0)
-# CVE-2026-43311 may need backporting (fixed from 6.6.143)
+CVE_STATUS[CVE-2026-43311] = "cpe-stable-backport: Backported in 6.6.143"
CVE_STATUS[CVE-2026-43312] = "cpe-stable-backport: Backported in 6.6.128"
@@ -22934,7 +22934,7 @@ CVE_STATUS[CVE-2026-43329] = "cpe-stable-backport: Backported in 6.6.134"
CVE_STATUS[CVE-2026-43330] = "cpe-stable-backport: Backported in 6.6.134"
-# CVE-2026-43331 may need backporting (fixed from 6.6.143)
+CVE_STATUS[CVE-2026-43331] = "cpe-stable-backport: Backported in 6.6.143"
CVE_STATUS[CVE-2026-43332] = "cpe-stable-backport: Backported in 6.6.134"
@@ -23114,7 +23114,7 @@ CVE_STATUS[CVE-2026-43419] = "cpe-stable-backport: Backported in 6.6.130"
CVE_STATUS[CVE-2026-43420] = "cpe-stable-backport: Backported in 6.6.130"
-# CVE-2026-43421 may need backporting (fixed from 6.6.143)
+CVE_STATUS[CVE-2026-43421] = "cpe-stable-backport: Backported in 6.6.143"
CVE_STATUS[CVE-2026-43424] = "cpe-stable-backport: Backported in 6.6.130"
@@ -23308,7 +23308,7 @@ CVE_STATUS[CVE-2026-45848] = "cpe-stable-backport: Backported in 6.6.128"
CVE_STATUS[CVE-2026-45849] = "cpe-stable-backport: Backported in 6.6.128"
-# CVE-2026-45850 may need backporting (fixed from 6.6.143)
+CVE_STATUS[CVE-2026-45850] = "cpe-stable-backport: Backported in 6.6.143"
CVE_STATUS[CVE-2026-45851] = "cpe-stable-backport: Backported in 6.6.128"
@@ -23468,7 +23468,7 @@ CVE_STATUS[CVE-2026-45928] = "fixed-version: only affects 6.8 onwards"
CVE_STATUS[CVE-2026-45929] = "fixed-version: only affects 6.16 onwards"
-# CVE-2026-45930 may need backporting (fixed from 6.6.143)
+CVE_STATUS[CVE-2026-45930] = "cpe-stable-backport: Backported in 6.6.143"
CVE_STATUS[CVE-2026-45931] = "fixed-version: only affects 6.14 onwards"
@@ -23714,7 +23714,7 @@ CVE_STATUS[CVE-2026-46052] = "cpe-stable-backport: Backported in 6.6.140"
CVE_STATUS[CVE-2026-46053] = "cpe-stable-backport: Backported in 6.6.140"
-# CVE-2026-46054 may need backporting (fixed from 6.6.144)
+CVE_STATUS[CVE-2026-46054] = "cpe-stable-backport: Backported in 6.6.144"
CVE_STATUS[CVE-2026-46055] = "fixed-version: only affects 7.0 onwards"
@@ -23790,7 +23790,7 @@ CVE_STATUS[CVE-2026-46089] = "cpe-stable-backport: Backported in 6.6.140"
CVE_STATUS[CVE-2026-46091] = "cpe-stable-backport: Backported in 6.6.140"
-# CVE-2026-46092 needs backporting (fixed from 7.1)
+CVE_STATUS[CVE-2026-46092] = "cpe-stable-backport: Backported in 6.6.140"
CVE_STATUS[CVE-2026-46093] = "fixed-version: only affects 6.9 onwards"
@@ -23876,7 +23876,7 @@ CVE_STATUS[CVE-2026-46133] = "cpe-stable-backport: Backported in 6.6.140"
CVE_STATUS[CVE-2026-46134] = "fixed-version: only affects 6.14 onwards"
-# CVE-2026-46135 may need backporting (fixed from 6.6.144)
+CVE_STATUS[CVE-2026-46135] = "cpe-stable-backport: Backported in 6.6.144"
CVE_STATUS[CVE-2026-46136] = "cpe-stable-backport: Backported in 6.6.140"
@@ -23886,7 +23886,7 @@ CVE_STATUS[CVE-2026-46138] = "cpe-stable-backport: Backported in 6.6.140"
CVE_STATUS[CVE-2026-46139] = "fixed-version: only affects 6.12.23 onwards"
-# CVE-2026-46140 may need backporting (fixed from 6.6.144)
+CVE_STATUS[CVE-2026-46140] = "cpe-stable-backport: Backported in 6.6.144"
CVE_STATUS[CVE-2026-46141] = "fixed-version: only affects 6.18 onwards"
@@ -24086,7 +24086,7 @@ CVE_STATUS[CVE-2026-46240] = "fixed-version: only affects 6.18.16 onwards"
# CVE-2026-46241 needs backporting (fixed from 7.1)
-# CVE-2026-46242 may need backporting (fixed from 6.6.144)
+CVE_STATUS[CVE-2026-46242] = "cpe-stable-backport: Backported in 6.6.144"
CVE_STATUS[CVE-2026-46243] = "cpe-stable-backport: Backported in 6.6.142"
@@ -24106,7 +24106,7 @@ CVE_STATUS[CVE-2026-46250] = "cpe-stable-backport: Backported in 6.6.128"
CVE_STATUS[CVE-2026-46251] = "cpe-stable-backport: Backported in 6.6.128"
-# CVE-2026-46252 may need backporting (fixed from 6.6.144)
+CVE_STATUS[CVE-2026-46252] = "cpe-stable-backport: Backported in 6.6.144"
CVE_STATUS[CVE-2026-46253] = "cpe-stable-backport: Backported in 6.6.128"
@@ -24242,11 +24242,11 @@ CVE_STATUS[CVE-2026-46318] = "fixed-version: only affects 6.19 onwards"
CVE_STATUS[CVE-2026-46319] = "cpe-stable-backport: Backported in 6.6.141"
-# CVE-2026-46320 may need backporting (fixed from 6.6.143)
+CVE_STATUS[CVE-2026-46320] = "cpe-stable-backport: Backported in 6.6.143"
-# CVE-2026-46321 may need backporting (fixed from 6.6.143)
+CVE_STATUS[CVE-2026-46321] = "cpe-stable-backport: Backported in 6.6.143"
-# CVE-2026-46322 may need backporting (fixed from 6.6.143)
+CVE_STATUS[CVE-2026-46322] = "cpe-stable-backport: Backported in 6.6.143"
CVE_STATUS[CVE-2026-46323] = "cpe-stable-backport: Backported in 6.6.142"
@@ -24264,7 +24264,7 @@ CVE_STATUS[CVE-2026-46329] = "fixed-version: only affects 6.12 onwards"
# CVE-2026-46330 needs backporting (fixed from 7.0)
-# CVE-2026-46331 may need backporting (fixed from 6.6.144)
+CVE_STATUS[CVE-2026-46331] = "cpe-stable-backport: Backported in 6.6.144"
CVE_STATUS[CVE-2026-46332] = "fixed-version: only affects 6.12 onwards"
@@ -24278,17 +24278,17 @@ CVE_STATUS[CVE-2026-52906] = "fixed-version: only affects 6.19 onwards"
CVE_STATUS[CVE-2026-52907] = "fixed-version: only affects 6.19 onwards"
-# CVE-2026-52908 may need backporting (fixed from 6.6.143)
+CVE_STATUS[CVE-2026-52908] = "cpe-stable-backport: Backported in 6.6.143"
-# CVE-2026-52909 may need backporting (fixed from 6.6.144)
+CVE_STATUS[CVE-2026-52909] = "cpe-stable-backport: Backported in 6.6.144"
-# CVE-2026-52910 may need backporting (fixed from 6.6.143)
+CVE_STATUS[CVE-2026-52910] = "cpe-stable-backport: Backported in 6.6.143"
CVE_STATUS[CVE-2026-52911] = "cpe-stable-backport: Backported in 6.6.141"
CVE_STATUS[CVE-2026-52912] = "cpe-stable-backport: Backported in 6.6.142"
-# CVE-2026-52913 may need backporting (fixed from 6.6.143)
+CVE_STATUS[CVE-2026-52913] = "cpe-stable-backport: Backported in 6.6.143"
CVE_STATUS[CVE-2026-52914] = "cpe-stable-backport: Backported in 6.6.142"
@@ -24296,7 +24296,7 @@ CVE_STATUS[CVE-2026-52915] = "cpe-stable-backport: Backported in 6.6.142"
CVE_STATUS[CVE-2026-52916] = "cpe-stable-backport: Backported in 6.6.142"
-# CVE-2026-52917 may need backporting (fixed from 6.6.143)
+CVE_STATUS[CVE-2026-52917] = "cpe-stable-backport: Backported in 6.6.143"
CVE_STATUS[CVE-2026-52918] = "cpe-stable-backport: Backported in 6.6.142"
@@ -24308,21 +24308,21 @@ CVE_STATUS[CVE-2026-52921] = "cpe-stable-backport: Backported in 6.6.142"
CVE_STATUS[CVE-2026-52922] = "cpe-stable-backport: Backported in 6.6.142"
-# CVE-2026-52923 may need backporting (fixed from 6.6.143)
+CVE_STATUS[CVE-2026-52923] = "cpe-stable-backport: Backported in 6.6.143"
-# CVE-2026-52924 may need backporting (fixed from 6.6.143)
+CVE_STATUS[CVE-2026-52924] = "cpe-stable-backport: Backported in 6.6.143"
CVE_STATUS[CVE-2026-52925] = "cpe-stable-backport: Backported in 6.6.141"
CVE_STATUS[CVE-2026-52926] = "cpe-stable-backport: Backported in 6.6.142"
-# CVE-2026-52927 may need backporting (fixed from 6.6.143)
+CVE_STATUS[CVE-2026-52927] = "cpe-stable-backport: Backported in 6.6.143"
-# CVE-2026-52928 may need backporting (fixed from 6.6.144)
+CVE_STATUS[CVE-2026-52928] = "cpe-stable-backport: Backported in 6.6.144"
-# CVE-2026-52929 may need backporting (fixed from 6.6.143)
+CVE_STATUS[CVE-2026-52929] = "cpe-stable-backport: Backported in 6.6.143"
-# CVE-2026-52930 may need backporting (fixed from 6.6.143)
+CVE_STATUS[CVE-2026-52930] = "cpe-stable-backport: Backported in 6.6.143"
CVE_STATUS[CVE-2026-52931] = "cpe-stable-backport: Backported in 6.6.142"
@@ -24330,9 +24330,9 @@ CVE_STATUS[CVE-2026-52932] = "fixed-version: only affects 6.15 onwards"
CVE_STATUS[CVE-2026-52933] = "cpe-stable-backport: Backported in 6.6.140"
-# CVE-2026-52934 may need backporting (fixed from 6.6.143)
+CVE_STATUS[CVE-2026-52934] = "cpe-stable-backport: Backported in 6.6.143"
-# CVE-2026-52935 may need backporting (fixed from 6.6.143)
+CVE_STATUS[CVE-2026-52935] = "cpe-stable-backport: Backported in 6.6.143"
CVE_STATUS[CVE-2026-52936] = "cpe-stable-backport: Backported in 6.6.141"
@@ -24340,25 +24340,25 @@ CVE_STATUS[CVE-2026-52936] = "cpe-stable-backport: Backported in 6.6.141"
CVE_STATUS[CVE-2026-52938] = "fixed-version: only affects 7.0 onwards"
-# CVE-2026-52939 may need backporting (fixed from 6.6.143)
+CVE_STATUS[CVE-2026-52939] = "cpe-stable-backport: Backported in 6.6.143"
CVE_STATUS[CVE-2026-52940] = "fixed-version: only affects 6.17 onwards"
CVE_STATUS[CVE-2026-52941] = "cpe-stable-backport: Backported in 6.6.142"
-# CVE-2026-52942 may need backporting (fixed from 6.6.143)
+CVE_STATUS[CVE-2026-52942] = "cpe-stable-backport: Backported in 6.6.143"
-# CVE-2026-52943 may need backporting (fixed from 6.6.143)
+CVE_STATUS[CVE-2026-52943] = "cpe-stable-backport: Backported in 6.6.143"
-# CVE-2026-52944 may need backporting (fixed from 6.6.143)
+CVE_STATUS[CVE-2026-52944] = "cpe-stable-backport: Backported in 6.6.143"
CVE_STATUS[CVE-2026-52945] = "fixed-version: only affects 6.15.3 onwards"
-# CVE-2026-52946 may need backporting (fixed from 6.6.143)
+CVE_STATUS[CVE-2026-52946] = "cpe-stable-backport: Backported in 6.6.143"
-# CVE-2026-52947 may need backporting (fixed from 6.6.143)
+CVE_STATUS[CVE-2026-52947] = "cpe-stable-backport: Backported in 6.6.143"
-# CVE-2026-52948 may need backporting (fixed from 6.6.143)
+CVE_STATUS[CVE-2026-52948] = "cpe-stable-backport: Backported in 6.6.143"
CVE_STATUS[CVE-2026-52949] = "fixed-version: only affects 6.15 onwards"
@@ -24622,7 +24622,7 @@ CVE_STATUS[CVE-2026-53077] = "cpe-stable-backport: Backported in 6.6.141"
CVE_STATUS[CVE-2026-53079] = "fixed-version: only affects 6.19 onwards"
-# CVE-2026-53080 may need backporting (fixed from 6.6.143)
+CVE_STATUS[CVE-2026-53080] = "cpe-stable-backport: Backported in 6.6.143"
CVE_STATUS[CVE-2026-53081] = "fixed-version: only affects 6.11 onwards"
@@ -24724,23 +24724,23 @@ CVE_STATUS[CVE-2026-53128] = "cpe-stable-backport: Backported in 6.6.141"
CVE_STATUS[CVE-2026-53130] = "cpe-stable-backport: Backported in 6.6.141"
-# CVE-2026-53131 may need backporting (fixed from 6.6.143)
+CVE_STATUS[CVE-2026-53131] = "cpe-stable-backport: Backported in 6.6.143"
# CVE-2026-53132 needs backporting (fixed from 7.1)
-# CVE-2026-53133 may need backporting (fixed from 6.6.143)
+CVE_STATUS[CVE-2026-53133] = "cpe-stable-backport: Backported in 6.6.143"
-# CVE-2026-53134 may need backporting (fixed from 6.6.143)
+CVE_STATUS[CVE-2026-53134] = "cpe-stable-backport: Backported in 6.6.143"
-# CVE-2026-53135 may need backporting (fixed from 6.6.143)
+CVE_STATUS[CVE-2026-53135] = "cpe-stable-backport: Backported in 6.6.143"
-# CVE-2026-53136 may need backporting (fixed from 6.6.143)
+CVE_STATUS[CVE-2026-53136] = "cpe-stable-backport: Backported in 6.6.143"
-# CVE-2026-53137 may need backporting (fixed from 6.6.143)
+CVE_STATUS[CVE-2026-53137] = "cpe-stable-backport: Backported in 6.6.143"
-# CVE-2026-53138 may need backporting (fixed from 6.6.144)
+CVE_STATUS[CVE-2026-53138] = "cpe-stable-backport: Backported in 6.6.144"
-# CVE-2026-53139 may need backporting (fixed from 6.6.144)
+CVE_STATUS[CVE-2026-53139] = "cpe-stable-backport: Backported in 6.6.144"
CVE_STATUS[CVE-2026-53140] = "fixed-version: only affects 6.8 onwards"
@@ -24748,57 +24748,55 @@ CVE_STATUS[CVE-2026-53141] = "fixed-version: only affects 6.14 onwards"
CVE_STATUS[CVE-2026-53142] = "fixed-version: only affects 6.8 onwards"
-# CVE-2026-53143 may need backporting (fixed from 6.6.143)
+CVE_STATUS[CVE-2026-53143] = "cpe-stable-backport: Backported in 6.6.143"
-# CVE-2026-53144 may need backporting (fixed from 6.6.143)
+CVE_STATUS[CVE-2026-53144] = "cpe-stable-backport: Backported in 6.6.143"
CVE_STATUS[CVE-2026-53145] = "fixed-version: only affects 6.18.32 onwards"
-# CVE-2026-53146 may need backporting (fixed from 6.6.143)
+CVE_STATUS[CVE-2026-53146] = "cpe-stable-backport: Backported in 6.6.143"
-# CVE-2026-53147 may need backporting (fixed from 6.6.143)
+CVE_STATUS[CVE-2026-53147] = "cpe-stable-backport: Backported in 6.6.143"
-# CVE-2026-53148 may need backporting (fixed from 6.6.143)
+CVE_STATUS[CVE-2026-53148] = "cpe-stable-backport: Backported in 6.6.143"
-# CVE-2026-53149 may need backporting (fixed from 6.6.143)
+CVE_STATUS[CVE-2026-53149] = "cpe-stable-backport: Backported in 6.6.143"
-# CVE-2026-53150 may need backporting (fixed from 6.6.143)
+CVE_STATUS[CVE-2026-53150] = "cpe-stable-backport: Backported in 6.6.143"
-# CVE-2026-53151 may need backporting (fixed from 6.6.144)
+CVE_STATUS[CVE-2026-53151] = "cpe-stable-backport: Backported in 6.6.144"
CVE_STATUS[CVE-2026-53152] = "fixed-version: only affects 6.12.78 onwards"
CVE_STATUS[CVE-2026-53153] = "fixed-version: only affects 6.13 onwards"
-# CVE-2026-53154 may need backporting (fixed from 6.6.143)
+CVE_STATUS[CVE-2026-53154] = "cpe-stable-backport: Backported in 6.6.143"
CVE_STATUS[CVE-2026-53155] = "fixed-version: only affects 6.19 onwards"
# CVE-2026-53156 needs backporting (fixed from 7.1)
-# CVE-2026-53157 may need backporting (fixed from 6.6.144)
+CVE_STATUS[CVE-2026-53157] = "cpe-stable-backport: Backported in 6.6.144"
-# CVE-2026-53158 may need backporting (fixed from 6.6.143)
+CVE_STATUS[CVE-2026-53158] = "cpe-stable-backport: Backported in 6.6.143"
-# CVE-2026-53159 may need backporting (fixed from 6.6.143)
+CVE_STATUS[CVE-2026-53159] = "cpe-stable-backport: Backported in 6.6.143"
-# CVE-2026-53160 may need backporting (fixed from 6.6.143)
+CVE_STATUS[CVE-2026-53160] = "cpe-stable-backport: Backported in 6.6.143"
-# CVE-2026-53161 may need backporting (fixed from 6.6.143)
+CVE_STATUS[CVE-2026-53161] = "cpe-stable-backport: Backported in 6.6.143"
CVE_STATUS[CVE-2026-53162] = "fixed-version: only affects 6.16 onwards"
-# CVE-2026-53163 may need backporting (fixed from 6.6.144)
+CVE_STATUS[CVE-2026-53163] = "cpe-stable-backport: Backported in 6.6.144"
CVE_STATUS[CVE-2026-53164] = "fixed-version: only affects 6.16 onwards"
CVE_STATUS[CVE-2026-53165] = "fixed-version: only affects 7.0 onwards"
-# CVE-2026-53166 may need backporting (fixed from 6.7)
+CVE_STATUS[CVE-2026-53167] = "cpe-stable-backport: Backported in 6.6.144"
-# CVE-2026-53167 may need backporting (fixed from 6.6.144)
-
-# CVE-2026-53168 may need backporting (fixed from 6.6.143)
+CVE_STATUS[CVE-2026-53168] = "cpe-stable-backport: Backported in 6.6.143"
CVE_STATUS[CVE-2026-53169] = "fixed-version: only affects 6.19 onwards"
@@ -24814,9 +24812,9 @@ CVE_STATUS[CVE-2026-53174] = "fixed-version: only affects 6.19 onwards"
CVE_STATUS[CVE-2026-53175] = "fixed-version: only affects 6.12.93 onwards"
-# CVE-2026-53176 may need backporting (fixed from 6.6.143)
+CVE_STATUS[CVE-2026-53176] = "cpe-stable-backport: Backported in 6.6.143"
-# CVE-2026-53177 may need backporting (fixed from 6.6.143)
+CVE_STATUS[CVE-2026-53177] = "cpe-stable-backport: Backported in 6.6.143"
# CVE-2026-53178 needs backporting (fixed from 7.1)
@@ -24824,25 +24822,25 @@ CVE_STATUS[CVE-2026-53175] = "fixed-version: only affects 6.12.93 onwards"
CVE_STATUS[CVE-2026-53180] = "fixed-version: only affects 6.9 onwards"
-# CVE-2026-53181 may need backporting (fixed from 6.6.143)
+CVE_STATUS[CVE-2026-53181] = "cpe-stable-backport: Backported in 6.6.143"
-# CVE-2026-53182 may need backporting (fixed from 6.6.143)
+CVE_STATUS[CVE-2026-53182] = "cpe-stable-backport: Backported in 6.6.143"
-# CVE-2026-53183 may need backporting (fixed from 6.6.143)
+CVE_STATUS[CVE-2026-53183] = "cpe-stable-backport: Backported in 6.6.143"
-# CVE-2026-53184 may need backporting (fixed from 6.6.143)
+CVE_STATUS[CVE-2026-53184] = "cpe-stable-backport: Backported in 6.6.143"
-# CVE-2026-53185 may need backporting (fixed from 6.6.143)
+CVE_STATUS[CVE-2026-53185] = "cpe-stable-backport: Backported in 6.6.143"
-# CVE-2026-53186 may need backporting (fixed from 6.6.143)
+CVE_STATUS[CVE-2026-53186] = "cpe-stable-backport: Backported in 6.6.143"
CVE_STATUS[CVE-2026-53187] = "fixed-version: only affects 6.17 onwards"
CVE_STATUS[CVE-2026-53188] = "fixed-version: only affects 6.15 onwards"
-# CVE-2026-53189 may need backporting (fixed from 6.6.143)
+CVE_STATUS[CVE-2026-53189] = "cpe-stable-backport: Backported in 6.6.143"
-# CVE-2026-53190 may need backporting (fixed from 6.6.143)
+CVE_STATUS[CVE-2026-53190] = "cpe-stable-backport: Backported in 6.6.143"
CVE_STATUS[CVE-2026-53191] = "fixed-version: only affects 6.12 onwards"
@@ -24850,17 +24848,17 @@ CVE_STATUS[CVE-2026-53192] = "fixed-version: only affects 6.12 onwards"
CVE_STATUS[CVE-2026-53193] = "fixed-version: only affects 6.12 onwards"
-# CVE-2026-53194 may need backporting (fixed from 6.6.143)
+CVE_STATUS[CVE-2026-53194] = "cpe-stable-backport: Backported in 6.6.143"
-# CVE-2026-53195 may need backporting (fixed from 6.6.143)
+CVE_STATUS[CVE-2026-53195] = "cpe-stable-backport: Backported in 6.6.143"
-# CVE-2026-53196 may need backporting (fixed from 6.6.143)
+CVE_STATUS[CVE-2026-53196] = "cpe-stable-backport: Backported in 6.6.143"
CVE_STATUS[CVE-2026-53197] = "fixed-version: only affects 6.14 onwards"
-# CVE-2026-53198 may need backporting (fixed from 6.6.143)
+CVE_STATUS[CVE-2026-53198] = "cpe-stable-backport: Backported in 6.6.143"
-# CVE-2026-53199 may need backporting (fixed from 6.6.143)
+CVE_STATUS[CVE-2026-53199] = "cpe-stable-backport: Backported in 6.6.143"
CVE_STATUS[CVE-2026-53200] = "fixed-version: only affects 6.19 onwards"
@@ -24876,57 +24874,57 @@ CVE_STATUS[CVE-2026-53205] = "fixed-version: only affects 6.12.30 onwards"
CVE_STATUS[CVE-2026-53206] = "fixed-version: only affects 6.19 onwards"
-# CVE-2026-53207 may need backporting (fixed from 6.6.143)
+CVE_STATUS[CVE-2026-53207] = "cpe-stable-backport: Backported in 6.6.143"
-# CVE-2026-53208 may need backporting (fixed from 6.6.143)
+CVE_STATUS[CVE-2026-53208] = "cpe-stable-backport: Backported in 6.6.143"
-# CVE-2026-53209 may need backporting (fixed from 6.6.143)
+CVE_STATUS[CVE-2026-53209] = "cpe-stable-backport: Backported in 6.6.143"
CVE_STATUS[CVE-2026-53210] = "fixed-version: only affects 6.8 onwards"
CVE_STATUS[CVE-2026-53211] = "fixed-version: only affects 6.18 onwards"
-# CVE-2026-53212 may need backporting (fixed from 6.6.143)
+CVE_STATUS[CVE-2026-53212] = "cpe-stable-backport: Backported in 6.6.143"
-# CVE-2026-53213 may need backporting (fixed from 6.6.143)
+CVE_STATUS[CVE-2026-53213] = "cpe-stable-backport: Backported in 6.6.143"
-# CVE-2026-53214 may need backporting (fixed from 6.6.143)
+CVE_STATUS[CVE-2026-53214] = "cpe-stable-backport: Backported in 6.6.143"
-# CVE-2026-53215 may need backporting (fixed from 6.6.143)
+CVE_STATUS[CVE-2026-53215] = "cpe-stable-backport: Backported in 6.6.143"
-# CVE-2026-53216 may need backporting (fixed from 6.6.143)
+CVE_STATUS[CVE-2026-53216] = "cpe-stable-backport: Backported in 6.6.143"
-# CVE-2026-53217 may need backporting (fixed from 6.6.143)
+CVE_STATUS[CVE-2026-53217] = "cpe-stable-backport: Backported in 6.6.143"
-# CVE-2026-53218 may need backporting (fixed from 6.6.143)
+CVE_STATUS[CVE-2026-53218] = "cpe-stable-backport: Backported in 6.6.143"
-# CVE-2026-53219 may need backporting (fixed from 6.6.143)
+CVE_STATUS[CVE-2026-53219] = "cpe-stable-backport: Backported in 6.6.143"
# CVE-2026-53220 needs backporting (fixed from 7.1)
-# CVE-2026-53221 may need backporting (fixed from 6.6.143)
+CVE_STATUS[CVE-2026-53221] = "cpe-stable-backport: Backported in 6.6.143"
CVE_STATUS[CVE-2026-53222] = "fixed-version: only affects 6.18 onwards"
-# CVE-2026-53223 may need backporting (fixed from 6.6.143)
+CVE_STATUS[CVE-2026-53223] = "cpe-stable-backport: Backported in 6.6.143"
# CVE-2026-53224 needs backporting (fixed from 7.1)
-# CVE-2026-53225 may need backporting (fixed from 6.6.143)
+CVE_STATUS[CVE-2026-53225] = "cpe-stable-backport: Backported in 6.6.143"
# CVE-2026-53226 needs backporting (fixed from 7.1)
-# CVE-2026-53227 may need backporting (fixed from 6.6.143)
+CVE_STATUS[CVE-2026-53227] = "cpe-stable-backport: Backported in 6.6.143"
-# CVE-2026-53228 may need backporting (fixed from 6.6.143)
+CVE_STATUS[CVE-2026-53228] = "cpe-stable-backport: Backported in 6.6.143"
# CVE-2026-53229 needs backporting (fixed from 7.1)
-# CVE-2026-53230 may need backporting (fixed from 6.6.143)
+CVE_STATUS[CVE-2026-53230] = "cpe-stable-backport: Backported in 6.6.143"
CVE_STATUS[CVE-2026-53231] = "fixed-version: only affects 7.0 onwards"
-# CVE-2026-53232 needs backporting (fixed from 7.1)
+CVE_STATUS[CVE-2026-53232] = "cpe-stable-backport: Backported in 6.6.143"
CVE_STATUS[CVE-2026-53233] = "fixed-version: only affects 6.12 onwards"
@@ -24934,47 +24932,47 @@ CVE_STATUS[CVE-2026-53234] = "fixed-version: only affects 6.12 onwards"
CVE_STATUS[CVE-2026-53235] = "fixed-version: only affects 6.10 onwards"
-# CVE-2026-53236 may need backporting (fixed from 6.6.143)
+CVE_STATUS[CVE-2026-53236] = "cpe-stable-backport: Backported in 6.6.143"
-# CVE-2026-53237 may need backporting (fixed from 6.6.143)
+CVE_STATUS[CVE-2026-53237] = "cpe-stable-backport: Backported in 6.6.143"
-# CVE-2026-53238 may need backporting (fixed from 6.6.143)
+CVE_STATUS[CVE-2026-53238] = "cpe-stable-backport: Backported in 6.6.143"
-# CVE-2026-53239 may need backporting (fixed from 6.6.143)
+CVE_STATUS[CVE-2026-53239] = "cpe-stable-backport: Backported in 6.6.143"
CVE_STATUS[CVE-2026-53240] = "fixed-version: only affects 6.14 onwards"
CVE_STATUS[CVE-2026-53241] = "fixed-version: only affects 6.10 onwards"
-# CVE-2026-53242 may need backporting (fixed from 6.6.143)
+CVE_STATUS[CVE-2026-53242] = "cpe-stable-backport: Backported in 6.6.143"
CVE_STATUS[CVE-2026-53243] = "fixed-version: only affects 7.0.10 onwards"
CVE_STATUS[CVE-2026-53244] = "fixed-version: only affects 7.0 onwards"
-# CVE-2026-53245 may need backporting (fixed from 6.6.143)
+CVE_STATUS[CVE-2026-53245] = "cpe-stable-backport: Backported in 6.6.143"
# CVE-2026-53246 needs backporting (fixed from 7.1)
-# CVE-2026-53247 may need backporting (fixed from 6.6.143)
+CVE_STATUS[CVE-2026-53247] = "cpe-stable-backport: Backported in 6.6.143"
CVE_STATUS[CVE-2026-53248] = "fixed-version: only affects 6.15 onwards"
-# CVE-2026-53249 may need backporting (fixed from 6.6.143)
+CVE_STATUS[CVE-2026-53249] = "cpe-stable-backport: Backported in 6.6.143"
CVE_STATUS[CVE-2026-53250] = "fixed-version: only affects 6.8 onwards"
CVE_STATUS[CVE-2026-53251] = "fixed-version: only affects 6.12.2 onwards"
-# CVE-2026-53252 may need backporting (fixed from 6.6.143)
+CVE_STATUS[CVE-2026-53252] = "cpe-stable-backport: Backported in 6.6.143"
-# CVE-2026-53253 may need backporting (fixed from 6.6.143)
+CVE_STATUS[CVE-2026-53253] = "cpe-stable-backport: Backported in 6.6.143"
-# CVE-2026-53254 may need backporting (fixed from 6.6.143)
+CVE_STATUS[CVE-2026-53254] = "cpe-stable-backport: Backported in 6.6.143"
-# CVE-2026-53255 may need backporting (fixed from 6.6.143)
+CVE_STATUS[CVE-2026-53255] = "cpe-stable-backport: Backported in 6.6.143"
-# CVE-2026-53256 may need backporting (fixed from 6.6.143)
+CVE_STATUS[CVE-2026-53256] = "cpe-stable-backport: Backported in 6.6.143"
CVE_STATUS[CVE-2026-53257] = "fixed-version: only affects 6.16 onwards"
@@ -24988,31 +24986,31 @@ CVE_STATUS[CVE-2026-53261] = "fixed-version: only affects 6.7 onwards"
# CVE-2026-53262 needs backporting (fixed from 7.1)
-# CVE-2026-53263 may need backporting (fixed from 6.6.143)
+CVE_STATUS[CVE-2026-53263] = "cpe-stable-backport: Backported in 6.6.143"
-# CVE-2026-53264 may need backporting (fixed from 6.6.143)
+CVE_STATUS[CVE-2026-53264] = "cpe-stable-backport: Backported in 6.6.143"
-# CVE-2026-53265 may need backporting (fixed from 6.6.143)
+CVE_STATUS[CVE-2026-53265] = "cpe-stable-backport: Backported in 6.6.143"
-# CVE-2026-53266 may need backporting (fixed from 6.6.143)
+CVE_STATUS[CVE-2026-53266] = "cpe-stable-backport: Backported in 6.6.143"
-# CVE-2026-53267 may need backporting (fixed from 6.6.143)
+CVE_STATUS[CVE-2026-53267] = "cpe-stable-backport: Backported in 6.6.143"
-# CVE-2026-53268 may need backporting (fixed from 6.6.143)
+CVE_STATUS[CVE-2026-53268] = "cpe-stable-backport: Backported in 6.6.143"
-# CVE-2026-53269 may need backporting (fixed from 6.6.143)
+CVE_STATUS[CVE-2026-53269] = "cpe-stable-backport: Backported in 6.6.143"
-# CVE-2026-53270 may need backporting (fixed from 6.6.143)
+CVE_STATUS[CVE-2026-53270] = "cpe-stable-backport: Backported in 6.6.143"
-# CVE-2026-53271 may need backporting (fixed from 6.6.143)
+CVE_STATUS[CVE-2026-53271] = "cpe-stable-backport: Backported in 6.6.143"
# CVE-2026-53272 needs backporting (fixed from 7.1)
-# CVE-2026-53273 may need backporting (fixed from 6.6.143)
+CVE_STATUS[CVE-2026-53273] = "cpe-stable-backport: Backported in 6.6.143"
-# CVE-2026-53274 may need backporting (fixed from 6.6.143)
+CVE_STATUS[CVE-2026-53274] = "cpe-stable-backport: Backported in 6.6.143"
-# CVE-2026-53275 may need backporting (fixed from 6.6.143)
+CVE_STATUS[CVE-2026-53275] = "cpe-stable-backport: Backported in 6.6.143"
CVE_STATUS[CVE-2026-53276] = "fixed-version: only affects 6.19 onwards"
@@ -25112,19 +25110,19 @@ CVE_STATUS[CVE-2026-53323] = "fixed-version: only affects 6.15 onwards"
CVE_STATUS[CVE-2026-53324] = "fixed-version: only affects 6.13 onwards"
-# CVE-2026-53325 may need backporting (fixed from 6.6.144)
+CVE_STATUS[CVE-2026-53325] = "cpe-stable-backport: Backported in 6.6.144"
CVE_STATUS[CVE-2026-53326] = "fixed-version: only affects 6.19 onwards"
-# CVE-2026-53327 may need backporting (fixed from 6.6.144)
+CVE_STATUS[CVE-2026-53327] = "cpe-stable-backport: Backported in 6.6.144"
CVE_STATUS[CVE-2026-53328] = "fixed-version: only affects 6.12 onwards"
-# CVE-2026-53329 may need backporting (fixed from 6.6.143)
+CVE_STATUS[CVE-2026-53329] = "cpe-stable-backport: Backported in 6.6.143"
# CVE-2026-53330 needs backporting (fixed from 7.1)
-# CVE-2026-53331 may need backporting (fixed from 6.6.143)
+CVE_STATUS[CVE-2026-53331] = "cpe-stable-backport: Backported in 6.6.143"
# CVE-2026-53332 needs backporting (fixed from 7.1)
@@ -25134,13 +25132,13 @@ CVE_STATUS[CVE-2026-53334] = "fixed-version: only affects 6.18 onwards"
CVE_STATUS[CVE-2026-53335] = "fixed-version: only affects 6.18 onwards"
-# CVE-2026-53336 may need backporting (fixed from 6.6.143)
+CVE_STATUS[CVE-2026-53336] = "cpe-stable-backport: Backported in 6.6.143"
-# CVE-2026-53337 may need backporting (fixed from 6.6.143)
+CVE_STATUS[CVE-2026-53337] = "cpe-stable-backport: Backported in 6.6.143"
CVE_STATUS[CVE-2026-53338] = "fixed-version: only affects 6.16 onwards"
-# CVE-2026-53339 may need backporting (fixed from 6.6.143)
+CVE_STATUS[CVE-2026-53339] = "cpe-stable-backport: Backported in 6.6.143"
CVE_STATUS[CVE-2026-53340] = "fixed-version: only affects 6.14 onwards"
@@ -25148,43 +25146,933 @@ CVE_STATUS[CVE-2026-53341] = "fixed-version: only affects 6.11 onwards"
CVE_STATUS[CVE-2026-53342] = "fixed-version: only affects 6.16 onwards"
-# CVE-2026-53343 may need backporting (fixed from 6.6.143)
+CVE_STATUS[CVE-2026-53343] = "cpe-stable-backport: Backported in 6.6.143"
CVE_STATUS[CVE-2026-53344] = "fixed-version: only affects 6.19 onwards"
-# CVE-2026-53345 may need backporting (fixed from 6.6.143)
+CVE_STATUS[CVE-2026-53345] = "cpe-stable-backport: Backported in 6.6.143"
CVE_STATUS[CVE-2026-53346] = "fixed-version: only affects 6.12 onwards"
-# CVE-2026-53347 may need backporting (fixed from 6.6.143)
+CVE_STATUS[CVE-2026-53347] = "cpe-stable-backport: Backported in 6.6.143"
CVE_STATUS[CVE-2026-53348] = "fixed-version: only affects 6.19 onwards"
-# CVE-2026-53349 may need backporting (fixed from 6.6.143)
+CVE_STATUS[CVE-2026-53349] = "cpe-stable-backport: Backported in 6.6.143"
-# CVE-2026-53350 may need backporting (fixed from 6.6.143)
+CVE_STATUS[CVE-2026-53350] = "cpe-stable-backport: Backported in 6.6.143"
CVE_STATUS[CVE-2026-53351] = "fixed-version: only affects 7.0 onwards"
-# CVE-2026-53352 may need backporting (fixed from 6.6.143)
+CVE_STATUS[CVE-2026-53352] = "cpe-stable-backport: Backported in 6.6.143"
-# CVE-2026-53353 may need backporting (fixed from 6.6.143)
+CVE_STATUS[CVE-2026-53353] = "cpe-stable-backport: Backported in 6.6.143"
-# CVE-2026-53354 may need backporting (fixed from 6.6.143)
+CVE_STATUS[CVE-2026-53354] = "cpe-stable-backport: Backported in 6.6.143"
-# CVE-2026-53355 may need backporting (fixed from 6.6.143)
+CVE_STATUS[CVE-2026-53355] = "cpe-stable-backport: Backported in 6.6.143"
-# CVE-2026-53356 may need backporting (fixed from 6.6.143)
+CVE_STATUS[CVE-2026-53356] = "cpe-stable-backport: Backported in 6.6.143"
CVE_STATUS[CVE-2026-53357] = "cpe-stable-backport: Backported in 6.6.142"
-# CVE-2026-53358 may need backporting (fixed from 6.6.143)
+CVE_STATUS[CVE-2026-53358] = "cpe-stable-backport: Backported in 6.6.143"
-# CVE-2026-53359 may need backporting (fixed from 6.6.144)
+CVE_STATUS[CVE-2026-53359] = "cpe-stable-backport: Backported in 6.6.144"
CVE_STATUS[CVE-2026-53360] = "fixed-version: only affects 6.10 onwards"
-# CVE-2026-53361 may need backporting (fixed from 6.6.144)
+CVE_STATUS[CVE-2026-53361] = "cpe-stable-backport: Backported in 6.6.144"
+
+CVE_STATUS[CVE-2026-53362] = "cpe-stable-backport: Backported in 6.6.144"
+
+CVE_STATUS[CVE-2026-53363] = "fixed-version: only affects 6.14 onwards"
+
+CVE_STATUS[CVE-2026-53364] = "fixed-version: only affects 6.16.4 onwards"
+
+CVE_STATUS[CVE-2026-53365] = "fixed-version: only affects 6.7 onwards"
+
+CVE_STATUS[CVE-2026-53366] = "cpe-stable-backport: Backported in 6.6.144"
+
+CVE_STATUS[CVE-2026-53367] = "fixed-version: only affects 6.17.10 onwards"
+
+# CVE-2026-53368 needs backporting (fixed from 7.1)
+
+CVE_STATUS[CVE-2026-53369] = "cpe-stable-backport: Backported in 6.6.140"
+
+CVE_STATUS[CVE-2026-53370] = "fixed-version: only affects 6.16 onwards"
+
+CVE_STATUS[CVE-2026-53371] = "fixed-version: only affects 6.18 onwards"
+
+CVE_STATUS[CVE-2026-53372] = "fixed-version: only affects 6.13 onwards"
+
+CVE_STATUS[CVE-2026-53373] = "fixed-version: only affects 6.19 onwards"
+
+CVE_STATUS[CVE-2026-53374] = "cpe-stable-backport: Backported in 6.6.140"
+
+CVE_STATUS[CVE-2026-53375] = "cpe-stable-backport: Backported in 6.6.140"
+
+CVE_STATUS[CVE-2026-53376] = "cpe-stable-backport: Backported in 6.6.140"
+
+# CVE-2026-53377 needs backporting (fixed from 7.1)
+
+CVE_STATUS[CVE-2026-53378] = "fixed-version: only affects 6.19 onwards"
+
+CVE_STATUS[CVE-2026-53379] = "cpe-stable-backport: Backported in 6.6.140"
+
+CVE_STATUS[CVE-2026-53380] = "fixed-version: only affects 6.19 onwards"
+
+CVE_STATUS[CVE-2026-53381] = "cpe-stable-backport: Backported in 6.6.144"
+
+CVE_STATUS[CVE-2026-53382] = "cpe-stable-backport: Backported in 6.6.144"
+
+CVE_STATUS[CVE-2026-53383] = "cpe-stable-backport: Backported in 6.6.144"
+
+CVE_STATUS[CVE-2026-53384] = "cpe-stable-backport: Backported in 6.6.144"
+
+CVE_STATUS[CVE-2026-53385] = "cpe-stable-backport: Backported in 6.6.144"
+
+CVE_STATUS[CVE-2026-53386] = "fixed-version: only affects 6.9 onwards"
+
+CVE_STATUS[CVE-2026-53387] = "fixed-version: only affects 6.8 onwards"
+
+CVE_STATUS[CVE-2026-53388] = "cpe-stable-backport: Backported in 6.6.144"
+
+CVE_STATUS[CVE-2026-53389] = "fixed-version: only affects 6.7 onwards"
+
+CVE_STATUS[CVE-2026-53390] = "cpe-stable-backport: Backported in 6.6.144"
+
+CVE_STATUS[CVE-2026-53391] = "cpe-stable-backport: Backported in 6.6.144"
+
+# CVE-2026-53392 needs backporting (fixed from 7.2rc1)
+
+# CVE-2026-53393 needs backporting (fixed from 7.2rc1)
+
+CVE_STATUS[CVE-2026-53394] = "fixed-version: only affects 6.10 onwards"
+
+CVE_STATUS[CVE-2026-53395] = "fixed-version: only affects 7.0 onwards"
+
+CVE_STATUS[CVE-2026-53396] = "fixed-version: only affects 6.19 onwards"
+
+CVE_STATUS[CVE-2026-53397] = "cpe-stable-backport: Backported in 6.6.144"
+
+CVE_STATUS[CVE-2026-53398] = "cpe-stable-backport: Backported in 6.6.144"
+
+# CVE-2026-53399 needs backporting (fixed from 7.2rc1)
+
+# CVE-2026-53400 needs backporting (fixed from 7.2rc1)
+
+# CVE-2026-53401 needs backporting (fixed from 7.2rc1)
+
+# CVE-2026-53402 needs backporting (fixed from 7.2rc1)
+
+CVE_STATUS[CVE-2026-53403] = "cpe-stable-backport: Backported in 6.6.144"
+
+CVE_STATUS[CVE-2026-63793] = "fixed-version: only affects 7.1 onwards"
+
+CVE_STATUS[CVE-2026-63794] = "cpe-stable-backport: Backported in 6.6.144"
+
+CVE_STATUS[CVE-2026-63795] = "cpe-stable-backport: Backported in 6.6.144"
+
+CVE_STATUS[CVE-2026-63796] = "cpe-stable-backport: Backported in 6.6.144"
+
+CVE_STATUS[CVE-2026-63797] = "cpe-stable-backport: Backported in 6.6.144"
+
+CVE_STATUS[CVE-2026-63798] = "cpe-stable-backport: Backported in 6.6.144"
+
+CVE_STATUS[CVE-2026-63799] = "fixed-version: only affects 6.19 onwards"
+
+CVE_STATUS[CVE-2026-63800] = "cpe-stable-backport: Backported in 6.6.144"
+
+CVE_STATUS[CVE-2026-63801] = "cpe-stable-backport: Backported in 6.6.144"
+
+CVE_STATUS[CVE-2026-63802] = "cpe-stable-backport: Backported in 6.6.144"
+
+CVE_STATUS[CVE-2026-63803] = "cpe-stable-backport: Backported in 6.6.144"
+
+CVE_STATUS[CVE-2026-63804] = "cpe-stable-backport: Backported in 6.6.144"
+
+# CVE-2026-63805 needs backporting (fixed from 7.2rc1)
+
+# CVE-2026-63806 needs backporting (fixed from 7.2rc1)
+
+CVE_STATUS[CVE-2026-63807] = "cpe-stable-backport: Backported in 6.6.144"
+
+CVE_STATUS[CVE-2026-63808] = "cpe-stable-backport: Backported in 6.6.144"
+
+CVE_STATUS[CVE-2026-63809] = "cpe-stable-backport: Backported in 6.6.144"
+
+# CVE-2026-63810 needs backporting (fixed from 7.2rc1)
+
+# CVE-2026-63811 needs backporting (fixed from 7.2rc1)
+
+CVE_STATUS[CVE-2026-63812] = "cpe-stable-backport: Backported in 6.6.144"
+
+CVE_STATUS[CVE-2026-63813] = "fixed-version: only affects 7.0 onwards"
+
+CVE_STATUS[CVE-2026-63814] = "cpe-stable-backport: Backported in 6.6.144"
+
+# CVE-2026-63815 needs backporting (fixed from 7.2rc1)
+
+# CVE-2026-63816 needs backporting (fixed from 7.2rc1)
+
+CVE_STATUS[CVE-2026-63817] = "cpe-stable-backport: Backported in 6.6.144"
+
+# CVE-2026-63818 needs backporting (fixed from 7.2rc1)
+
+# CVE-2026-63819 needs backporting (fixed from 7.2rc1)
+
+CVE_STATUS[CVE-2026-63820] = "fixed-version: only affects 7.0 onwards"
+
+CVE_STATUS[CVE-2026-63821] = "cpe-stable-backport: Backported in 6.6.144"
+
+CVE_STATUS[CVE-2026-63822] = "cpe-stable-backport: Backported in 6.6.144"
+
+CVE_STATUS[CVE-2026-63823] = "cpe-stable-backport: Backported in 6.6.144"
+
+CVE_STATUS[CVE-2026-63824] = "cpe-stable-backport: Backported in 6.6.144"
+
+# CVE-2026-63825 needs backporting (fixed from 7.2rc1)
+
+CVE_STATUS[CVE-2026-63826] = "cpe-stable-backport: Backported in 6.6.144"
+
+CVE_STATUS[CVE-2026-63827] = "cpe-stable-backport: Backported in 6.6.144"
+
+CVE_STATUS[CVE-2026-63828] = "cpe-stable-backport: Backported in 6.6.144"
+
+# CVE-2026-63829 needs backporting (fixed from 7.2rc1)
+
+CVE_STATUS[CVE-2026-63830] = "cpe-stable-backport: Backported in 6.6.144"
+
+CVE_STATUS[CVE-2026-63831] = "cpe-stable-backport: Backported in 6.6.144"
+
+CVE_STATUS[CVE-2026-63832] = "fixed-version: only affects 6.12.13 onwards"
+
+CVE_STATUS[CVE-2026-63833] = "cpe-stable-backport: Backported in 6.6.144"
+
+CVE_STATUS[CVE-2026-63834] = "cpe-stable-backport: Backported in 6.6.144"
+
+CVE_STATUS[CVE-2026-63835] = "cpe-stable-backport: Backported in 6.6.144"
+
+CVE_STATUS[CVE-2026-63836] = "cpe-stable-backport: Backported in 6.6.144"
+
+CVE_STATUS[CVE-2026-63837] = "fixed-version: only affects 6.17 onwards"
+
+CVE_STATUS[CVE-2026-63838] = "cpe-stable-backport: Backported in 6.6.141"
+
+CVE_STATUS[CVE-2026-63839] = "fixed-version: only affects 6.17 onwards"
+
+CVE_STATUS[CVE-2026-63840] = "fixed-version: only affects 7.0 onwards"
+
+CVE_STATUS[CVE-2026-63841] = "fixed-version: only affects 6.14 onwards"
+
+CVE_STATUS[CVE-2026-63842] = "fixed-version: only affects 6.9 onwards"
+
+CVE_STATUS[CVE-2026-63843] = "fixed-version: only affects 6.7 onwards"
+
+CVE_STATUS[CVE-2026-63844] = "cpe-stable-backport: Backported in 6.6.141"
+
+CVE_STATUS[CVE-2026-63845] = "cpe-stable-backport: Backported in 6.6.141"
+
+CVE_STATUS[CVE-2026-63846] = "cpe-stable-backport: Backported in 6.6.141"
+
+CVE_STATUS[CVE-2026-63847] = "cpe-stable-backport: Backported in 6.6.141"
+
+CVE_STATUS[CVE-2026-63848] = "cpe-stable-backport: Backported in 6.6.141"
+
+CVE_STATUS[CVE-2026-63849] = "fixed-version: only affects 6.14 onwards"
+
+CVE_STATUS[CVE-2026-63850] = "fixed-version: only affects 6.9 onwards"
+
+CVE_STATUS[CVE-2026-63851] = "fixed-version: only affects 6.7 onwards"
+
+CVE_STATUS[CVE-2026-63852] = "cpe-stable-backport: Backported in 6.6.141"
+
+# CVE-2026-63853 needs backporting (fixed from 7.1)
+
+CVE_STATUS[CVE-2026-63854] = "cpe-stable-backport: Backported in 6.6.141"
+
+CVE_STATUS[CVE-2026-63855] = "cpe-stable-backport: Backported in 6.6.141"
+
+CVE_STATUS[CVE-2026-63856] = "cpe-stable-backport: Backported in 6.6.141"
+
+CVE_STATUS[CVE-2026-63857] = "fixed-version: only affects 6.11 onwards"
+
+# CVE-2026-63858 needs backporting (fixed from 7.1)
+
+CVE_STATUS[CVE-2026-63859] = "fixed-version: only affects 6.11 onwards"
+
+CVE_STATUS[CVE-2026-63860] = "cpe-stable-backport: Backported in 6.6.141"
+
+CVE_STATUS[CVE-2026-63861] = "cpe-stable-backport: Backported in 6.6.141"
+
+CVE_STATUS[CVE-2026-63862] = "cpe-stable-backport: Backported in 6.6.141"
+
+CVE_STATUS[CVE-2026-63863] = "fixed-version: only affects 7.0 onwards"
+
+CVE_STATUS[CVE-2026-63864] = "fixed-version: only affects 6.19 onwards"
+
+CVE_STATUS[CVE-2026-63865] = "cpe-stable-backport: Backported in 6.6.141"
+
+CVE_STATUS[CVE-2026-63866] = "fixed-version: only affects 6.15 onwards"
+
+CVE_STATUS[CVE-2026-63867] = "cpe-stable-backport: Backported in 6.6.143"
+
+CVE_STATUS[CVE-2026-63868] = "cpe-stable-backport: Backported in 6.6.143"
+
+CVE_STATUS[CVE-2026-63869] = "fixed-version: only affects 6.7 onwards"
+
+CVE_STATUS[CVE-2026-63870] = "cpe-stable-backport: Backported in 6.6.143"
+
+# CVE-2026-63871 needs backporting (fixed from 7.1)
+
+# CVE-2026-63872 needs backporting (fixed from 7.1)
+
+CVE_STATUS[CVE-2026-63873] = "fixed-version: only affects 6.16 onwards"
+
+CVE_STATUS[CVE-2026-63874] = "fixed-version: only affects 6.15 onwards"
+
+CVE_STATUS[CVE-2026-63875] = "cpe-stable-backport: Backported in 6.6.143"
+
+CVE_STATUS[CVE-2026-63876] = "cpe-stable-backport: Backported in 6.6.143"
+
+CVE_STATUS[CVE-2026-63877] = "cpe-stable-backport: Backported in 6.6.143"
+
+CVE_STATUS[CVE-2026-63878] = "fixed-version: only affects 6.18 onwards"
+
+# CVE-2026-63879 needs backporting (fixed from 7.1)
+
+CVE_STATUS[CVE-2026-63880] = "fixed-version: only affects 6.18 onwards"
+
+CVE_STATUS[CVE-2026-63881] = "cpe-stable-backport: Backported in 6.6.143"
+
+CVE_STATUS[CVE-2026-63882] = "cpe-stable-backport: Backported in 6.6.143"
+
+CVE_STATUS[CVE-2026-63883] = "cpe-stable-backport: Backported in 6.6.143"
+
+CVE_STATUS[CVE-2026-63884] = "cpe-stable-backport: Backported in 6.6.143"
+
+CVE_STATUS[CVE-2026-63885] = "fixed-version: only affects 6.18.32 onwards"
+
+CVE_STATUS[CVE-2026-63886] = "cpe-stable-backport: Backported in 6.6.143"
+
+CVE_STATUS[CVE-2026-63887] = "cpe-stable-backport: Backported in 6.6.143"
+
+CVE_STATUS[CVE-2026-63888] = "cpe-stable-backport: Backported in 6.6.143"
+
+CVE_STATUS[CVE-2026-63889] = "cpe-stable-backport: Backported in 6.6.143"
+
+CVE_STATUS[CVE-2026-63890] = "cpe-stable-backport: Backported in 6.6.143"
+
+CVE_STATUS[CVE-2026-63891] = "cpe-stable-backport: Backported in 6.6.143"
+
+CVE_STATUS[CVE-2026-63892] = "cpe-stable-backport: Backported in 6.6.143"
+
+CVE_STATUS[CVE-2026-63893] = "cpe-stable-backport: Backported in 6.6.143"
+
+CVE_STATUS[CVE-2026-63894] = "fixed-version: only affects 6.9 onwards"
+
+CVE_STATUS[CVE-2026-63895] = "cpe-stable-backport: Backported in 6.6.143"
+
+CVE_STATUS[CVE-2026-63896] = "cpe-stable-backport: Backported in 6.6.143"
+
+CVE_STATUS[CVE-2026-63897] = "cpe-stable-backport: Backported in 6.6.143"
+
+CVE_STATUS[CVE-2026-63898] = "cpe-stable-backport: Backported in 6.6.143"
+
+CVE_STATUS[CVE-2026-63899] = "cpe-stable-backport: Backported in 6.6.143"
+
+CVE_STATUS[CVE-2026-63900] = "cpe-stable-backport: Backported in 6.6.143"
+
+CVE_STATUS[CVE-2026-63901] = "cpe-stable-backport: Backported in 6.6.143"
+
+CVE_STATUS[CVE-2026-63902] = "cpe-stable-backport: Backported in 6.6.143"
+
+CVE_STATUS[CVE-2026-63903] = "cpe-stable-backport: Backported in 6.6.143"
+
+CVE_STATUS[CVE-2026-63904] = "cpe-stable-backport: Backported in 6.6.143"
+
+CVE_STATUS[CVE-2026-63905] = "cpe-stable-backport: Backported in 6.6.143"
+
+CVE_STATUS[CVE-2026-63906] = "cpe-stable-backport: Backported in 6.6.143"
+
+CVE_STATUS[CVE-2026-63907] = "fixed-version: only affects 6.19 onwards"
+
+CVE_STATUS[CVE-2026-63908] = "cpe-stable-backport: Backported in 6.6.143"
+
+CVE_STATUS[CVE-2026-63909] = "cpe-stable-backport: Backported in 6.6.143"
+
+CVE_STATUS[CVE-2026-63910] = "fixed-version: only affects 7.0 onwards"
+
+CVE_STATUS[CVE-2026-63911] = "fixed-version: only affects 6.14 onwards"
+
+CVE_STATUS[CVE-2026-63912] = "cpe-stable-backport: Backported in 6.6.143"
+
+CVE_STATUS[CVE-2026-63913] = "cpe-stable-backport: Backported in 6.6.143"
+
+CVE_STATUS[CVE-2026-63914] = "cpe-stable-backport: Backported in 6.6.143"
+
+CVE_STATUS[CVE-2026-63915] = "cpe-stable-backport: Backported in 6.6.143"
+
+CVE_STATUS[CVE-2026-63916] = "cpe-stable-backport: Backported in 6.6.143"
+
+CVE_STATUS[CVE-2026-63917] = "cpe-stable-backport: Backported in 6.6.143"
+
+CVE_STATUS[CVE-2026-63918] = "fixed-version: only affects 6.12 onwards"
+
+CVE_STATUS[CVE-2026-63919] = "cpe-stable-backport: Backported in 6.6.143"
+
+CVE_STATUS[CVE-2026-63920] = "cpe-stable-backport: Backported in 6.6.143"
+
+CVE_STATUS[CVE-2026-63921] = "cpe-stable-backport: Backported in 6.6.143"
+
+CVE_STATUS[CVE-2026-63922] = "cpe-stable-backport: Backported in 6.6.143"
+
+CVE_STATUS[CVE-2026-63923] = "fixed-version: only affects 6.13 onwards"
+
+CVE_STATUS[CVE-2026-63924] = "cpe-stable-backport: Backported in 6.6.143"
+
+CVE_STATUS[CVE-2026-63925] = "cpe-stable-backport: Backported in 6.6.143"
+
+CVE_STATUS[CVE-2026-63926] = "cpe-stable-backport: Backported in 6.6.143"
+
+CVE_STATUS[CVE-2026-63927] = "cpe-stable-backport: Backported in 6.6.143"
+
+CVE_STATUS[CVE-2026-63928] = "cpe-stable-backport: Backported in 6.6.143"
+
+CVE_STATUS[CVE-2026-63929] = "fixed-version: only affects 6.11 onwards"
+
+CVE_STATUS[CVE-2026-63930] = "cpe-stable-backport: Backported in 6.6.143"
+
+CVE_STATUS[CVE-2026-63931] = "cpe-stable-backport: Backported in 6.6.143"
+
+CVE_STATUS[CVE-2026-63932] = "fixed-version: only affects 6.16 onwards"
+
+CVE_STATUS[CVE-2026-63933] = "cpe-stable-backport: Backported in 6.6.143"
+
+CVE_STATUS[CVE-2026-63934] = "cpe-stable-backport: Backported in 6.6.143"
+
+CVE_STATUS[CVE-2026-63935] = "fixed-version: only affects 7.0 onwards"
+
+CVE_STATUS[CVE-2026-63936] = "fixed-version: only affects 6.11 onwards"
+
+CVE_STATUS[CVE-2026-63937] = "fixed-version: only affects 6.11 onwards"
+
+CVE_STATUS[CVE-2026-63938] = "fixed-version: only affects 6.11 onwards"
+
+CVE_STATUS[CVE-2026-63939] = "fixed-version: only affects 6.11 onwards"
+
+# CVE-2026-63940 needs backporting (fixed from 7.1)
+
+CVE_STATUS[CVE-2026-63941] = "fixed-version: only affects 6.11 onwards"
+
+CVE_STATUS[CVE-2026-63942] = "cpe-stable-backport: Backported in 6.6.143"
+
+CVE_STATUS[CVE-2026-63943] = "cpe-stable-backport: Backported in 6.6.143"
+
+CVE_STATUS[CVE-2026-63944] = "cpe-stable-backport: Backported in 6.6.143"
+
+CVE_STATUS[CVE-2026-63945] = "cpe-stable-backport: Backported in 6.6.143"
+
+CVE_STATUS[CVE-2026-63946] = "cpe-stable-backport: Backported in 6.6.143"
+
+CVE_STATUS[CVE-2026-63947] = "cpe-stable-backport: Backported in 6.6.143"
+
+CVE_STATUS[CVE-2026-63948] = "cpe-stable-backport: Backported in 6.6.143"
+
+CVE_STATUS[CVE-2026-63949] = "cpe-stable-backport: Backported in 6.6.143"
+
+CVE_STATUS[CVE-2026-63950] = "fixed-version: only affects 6.15 onwards"
+
+CVE_STATUS[CVE-2026-63951] = "fixed-version: only affects 6.19 onwards"
+
+CVE_STATUS[CVE-2026-63952] = "cpe-stable-backport: Backported in 6.6.143"
+
+CVE_STATUS[CVE-2026-63953] = "fixed-version: only affects 6.19 onwards"
+
+CVE_STATUS[CVE-2026-63954] = "cpe-stable-backport: Backported in 6.6.143"
+
+CVE_STATUS[CVE-2026-63955] = "fixed-version: only affects 6.19 onwards"
+
+CVE_STATUS[CVE-2026-63956] = "cpe-stable-backport: Backported in 6.6.143"
+
+CVE_STATUS[CVE-2026-63957] = "cpe-stable-backport: Backported in 6.6.143"
+
+CVE_STATUS[CVE-2026-63958] = "cpe-stable-backport: Backported in 6.6.143"
+
+CVE_STATUS[CVE-2026-63959] = "cpe-stable-backport: Backported in 6.6.143"
+
+CVE_STATUS[CVE-2026-63960] = "cpe-stable-backport: Backported in 6.6.143"
+
+CVE_STATUS[CVE-2026-63961] = "cpe-stable-backport: Backported in 6.6.143"
+
+# CVE-2026-63962 needs backporting (fixed from 7.1)
+
+# CVE-2026-63963 needs backporting (fixed from 7.1)
+
+CVE_STATUS[CVE-2026-63964] = "cpe-stable-backport: Backported in 6.6.143"
+
+CVE_STATUS[CVE-2026-63965] = "fixed-version: only affects 6.16 onwards"
+
+CVE_STATUS[CVE-2026-63966] = "fixed-version: only affects 6.15 onwards"
+
+CVE_STATUS[CVE-2026-63967] = "cpe-stable-backport: Backported in 6.6.143"
+
+CVE_STATUS[CVE-2026-63968] = "cpe-stable-backport: Backported in 6.6.143"
+
+CVE_STATUS[CVE-2026-63969] = "cpe-stable-backport: Backported in 6.6.143"
+
+CVE_STATUS[CVE-2026-63970] = "fixed-version: only affects 6.7 onwards"
+
+CVE_STATUS[CVE-2026-63971] = "cpe-stable-backport: Backported in 6.6.143"
+
+CVE_STATUS[CVE-2026-63972] = "fixed-version: only affects 6.18.33 onwards"
+
+CVE_STATUS[CVE-2026-63973] = "cpe-stable-backport: Backported in 6.6.143"
+
+# CVE-2026-63974 needs backporting (fixed from 7.1)
+
+CVE_STATUS[CVE-2026-63975] = "cpe-stable-backport: Backported in 6.6.143"
+
+CVE_STATUS[CVE-2026-63976] = "cpe-stable-backport: Backported in 6.6.143"
+
+CVE_STATUS[CVE-2026-63977] = "fixed-version: only affects 6.18 onwards"
+
+# CVE-2026-63978 needs backporting (fixed from 7.1)
+
+# CVE-2026-63979 needs backporting (fixed from 7.1)
+
+CVE_STATUS[CVE-2026-63980] = "fixed-version: only affects 6.7 onwards"
+
+CVE_STATUS[CVE-2026-63981] = "fixed-version: only affects 6.19 onwards"
+
+CVE_STATUS[CVE-2026-63982] = "fixed-version: only affects 6.19 onwards"
+
+# CVE-2026-63983 needs backporting (fixed from 7.1)
+
+CVE_STATUS[CVE-2026-63984] = "cpe-stable-backport: Backported in 6.6.143"
+
+CVE_STATUS[CVE-2026-63985] = "cpe-stable-backport: Backported in 6.6.143"
+
+CVE_STATUS[CVE-2026-63986] = "fixed-version: only affects 6.14 onwards"
+
+CVE_STATUS[CVE-2026-63987] = "fixed-version: only affects 6.11 onwards"
+
+CVE_STATUS[CVE-2026-63988] = "fixed-version: only affects 6.15 onwards"
+
+CVE_STATUS[CVE-2026-63989] = "fixed-version: only affects 6.15 onwards"
+
+CVE_STATUS[CVE-2026-63990] = "cpe-stable-backport: Backported in 6.6.143"
+
+CVE_STATUS[CVE-2026-63991] = "cpe-stable-backport: Backported in 6.6.143"
+
+CVE_STATUS[CVE-2026-63992] = "cpe-stable-backport: Backported in 6.6.143"
+
+CVE_STATUS[CVE-2026-63993] = "cpe-stable-backport: Backported in 6.6.143"
+
+CVE_STATUS[CVE-2026-63994] = "cpe-stable-backport: Backported in 6.6.143"
+
+CVE_STATUS[CVE-2026-63995] = "fixed-version: only affects 6.11 onwards"
+
+CVE_STATUS[CVE-2026-63996] = "fixed-version: only affects 6.11 onwards"
+
+CVE_STATUS[CVE-2026-63997] = "fixed-version: only affects 6.11 onwards"
+
+CVE_STATUS[CVE-2026-63998] = "fixed-version: only affects 6.11 onwards"
+
+# CVE-2026-63999 may need backporting (fixed from 6.7)
+
+CVE_STATUS[CVE-2026-64000] = "cpe-stable-backport: Backported in 6.6.143"
+
+# CVE-2026-64001 needs backporting (fixed from 7.1)
+
+CVE_STATUS[CVE-2026-64002] = "cpe-stable-backport: Backported in 6.6.143"
+
+CVE_STATUS[CVE-2026-64003] = "cpe-stable-backport: Backported in 6.6.143"
+
+CVE_STATUS[CVE-2026-64004] = "cpe-stable-backport: Backported in 6.6.143"
+
+CVE_STATUS[CVE-2026-64005] = "cpe-stable-backport: Backported in 6.6.143"
+
+CVE_STATUS[CVE-2026-64006] = "cpe-stable-backport: Backported in 6.6.143"
+
+CVE_STATUS[CVE-2026-64007] = "cpe-stable-backport: Backported in 6.6.143"
+
+CVE_STATUS[CVE-2026-64008] = "fixed-version: only affects 6.18 onwards"
+
+CVE_STATUS[CVE-2026-64009] = "cpe-stable-backport: Backported in 6.6.143"
+
+CVE_STATUS[CVE-2026-64010] = "cpe-stable-backport: Backported in 6.6.143"
+
+CVE_STATUS[CVE-2026-64011] = "cpe-stable-backport: Backported in 6.6.143"
+
+CVE_STATUS[CVE-2026-64012] = "cpe-stable-backport: Backported in 6.6.143"
+
+CVE_STATUS[CVE-2026-64013] = "fixed-version: only affects 6.15 onwards"
+
+CVE_STATUS[CVE-2026-64014] = "cpe-stable-backport: Backported in 6.6.143"
+
+CVE_STATUS[CVE-2026-64015] = "cpe-stable-backport: Backported in 6.6.142"
+
+CVE_STATUS[CVE-2026-64016] = "fixed-version: only affects 6.18.33 onwards"
+
+# CVE-2026-64017 may need backporting (fixed from 6.7)
+
+CVE_STATUS[CVE-2026-64018] = "cpe-stable-backport: Backported in 6.6.142"
+
+CVE_STATUS[CVE-2026-64019] = "fixed-version: only affects 6.17 onwards"
+
+CVE_STATUS[CVE-2026-64020] = "fixed-version: only affects 6.17 onwards"
+
+CVE_STATUS[CVE-2026-64021] = "fixed-version: only affects 6.13 onwards"
+
+CVE_STATUS[CVE-2026-64022] = "fixed-version: only affects 6.16 onwards"
+
+CVE_STATUS[CVE-2026-64023] = "fixed-version: only affects 6.16 onwards"
+
+CVE_STATUS[CVE-2026-64024] = "fixed-version: only affects 6.10 onwards"
+
+CVE_STATUS[CVE-2026-64025] = "cpe-stable-backport: Backported in 6.6.142"
+
+CVE_STATUS[CVE-2026-64026] = "cpe-stable-backport: Backported in 6.6.143"
+
+CVE_STATUS[CVE-2026-64027] = "fixed-version: only affects 6.13 onwards"
+
+CVE_STATUS[CVE-2026-64028] = "cpe-stable-backport: Backported in 6.6.142"
+
+CVE_STATUS[CVE-2026-64029] = "cpe-stable-backport: Backported in 6.6.142"
+
+CVE_STATUS[CVE-2026-64030] = "fixed-version: only affects 6.15 onwards"
+
+CVE_STATUS[CVE-2026-64031] = "fixed-version: only affects 6.15 onwards"
+
+CVE_STATUS[CVE-2026-64032] = "cpe-stable-backport: Backported in 6.6.142"
+
+CVE_STATUS[CVE-2026-64033] = "cpe-stable-backport: Backported in 6.6.142"
+
+CVE_STATUS[CVE-2026-64034] = "cpe-stable-backport: Backported in 6.6.142"
+
+CVE_STATUS[CVE-2026-64035] = "fixed-version: only affects 6.16 onwards"
+
+# CVE-2026-64036 needs backporting (fixed from 7.1)
+
+CVE_STATUS[CVE-2026-64037] = "fixed-version: only affects 6.15 onwards"
+
+# CVE-2026-64038 needs backporting (fixed from 7.1)
+
+CVE_STATUS[CVE-2026-64039] = "cpe-stable-backport: Backported in 6.6.142"
+
+CVE_STATUS[CVE-2026-64040] = "fixed-version: only affects 6.15 onwards"
+
+CVE_STATUS[CVE-2026-64041] = "fixed-version: only affects 6.18 onwards"
+
+CVE_STATUS[CVE-2026-64042] = "fixed-version: only affects 6.19 onwards"
+
+CVE_STATUS[CVE-2026-64043] = "fixed-version: only affects 6.16 onwards"
+
+CVE_STATUS[CVE-2026-64044] = "fixed-version: only affects 6.16 onwards"
+
+CVE_STATUS[CVE-2026-64045] = "fixed-version: only affects 6.16 onwards"
+
+CVE_STATUS[CVE-2026-64046] = "cpe-stable-backport: Backported in 6.6.142"
+
+CVE_STATUS[CVE-2026-64047] = "cpe-stable-backport: Backported in 6.6.142"
+
+CVE_STATUS[CVE-2026-64048] = "cpe-stable-backport: Backported in 6.6.142"
+
+CVE_STATUS[CVE-2026-64049] = "fixed-version: only affects 6.17 onwards"
+
+CVE_STATUS[CVE-2026-64050] = "fixed-version: only affects 6.18 onwards"
+
+CVE_STATUS[CVE-2026-64051] = "cpe-stable-backport: Backported in 6.6.142"
+
+CVE_STATUS[CVE-2026-64052] = "fixed-version: only affects 6.8 onwards"
+
+CVE_STATUS[CVE-2026-64053] = "fixed-version: only affects 6.11 onwards"
+
+CVE_STATUS[CVE-2026-64054] = "fixed-version: only affects 6.13 onwards"
+
+CVE_STATUS[CVE-2026-64055] = "cpe-stable-backport: Backported in 6.6.142"
+
+CVE_STATUS[CVE-2026-64056] = "cpe-stable-backport: Backported in 6.6.142"
+
+CVE_STATUS[CVE-2026-64057] = "fixed-version: only affects 6.14 onwards"
+
+CVE_STATUS[CVE-2026-64058] = "fixed-version: only affects 6.12 onwards"
+
+CVE_STATUS[CVE-2026-64059] = "fixed-version: only affects 6.12 onwards"
+
+# CVE-2026-64060 needs backporting (fixed from 7.1)
+
+CVE_STATUS[CVE-2026-64061] = "fixed-version: only affects 6.12 onwards"
+
+CVE_STATUS[CVE-2026-64062] = "fixed-version: only affects 6.10 onwards"
+
+CVE_STATUS[CVE-2026-64063] = "fixed-version: only affects 6.12 onwards"
+
+CVE_STATUS[CVE-2026-64064] = "fixed-version: only affects 6.8 onwards"
+
+CVE_STATUS[CVE-2026-64065] = "fixed-version: only affects 6.12 onwards"
+
+CVE_STATUS[CVE-2026-64066] = "fixed-version: only affects 6.12 onwards"
+
+CVE_STATUS[CVE-2026-64067] = "fixed-version: only affects 6.10 onwards"
+
+CVE_STATUS[CVE-2026-64068] = "fixed-version: only affects 6.10 onwards"
+
+CVE_STATUS[CVE-2026-64069] = "fixed-version: only affects 6.14 onwards"
+
+# CVE-2026-64070 needs backporting (fixed from 7.1)
+
+CVE_STATUS[CVE-2026-64071] = "fixed-version: only affects 6.13 onwards"
+
+CVE_STATUS[CVE-2026-64072] = "fixed-version: only affects 6.18 onwards"
+
+CVE_STATUS[CVE-2026-64073] = "cpe-stable-backport: Backported in 6.6.142"
+
+CVE_STATUS[CVE-2026-64074] = "fixed-version: only affects 6.15 onwards"
+
+CVE_STATUS[CVE-2026-64075] = "fixed-version: only affects 6.14 onwards"
+
+# CVE-2026-64076 needs backporting (fixed from 7.1)
+
+# CVE-2026-64077 needs backporting (fixed from 7.1)
+
+# CVE-2026-64078 needs backporting (fixed from 7.1)
+
+# CVE-2026-64079 needs backporting (fixed from 7.1)
+
+CVE_STATUS[CVE-2026-64080] = "fixed-version: only affects 6.15 onwards"
+
+CVE_STATUS[CVE-2026-64081] = "fixed-version: only affects 6.15 onwards"
+
+# CVE-2026-64082 needs backporting (fixed from 7.1)
+
+CVE_STATUS[CVE-2026-64083] = "cpe-stable-backport: Backported in 6.6.142"
+
+CVE_STATUS[CVE-2026-64084] = "cpe-stable-backport: Backported in 6.6.142"
+
+CVE_STATUS[CVE-2026-64085] = "cpe-stable-backport: Backported in 6.6.142"
+
+CVE_STATUS[CVE-2026-64086] = "cpe-stable-backport: Backported in 6.6.142"
+
+CVE_STATUS[CVE-2026-64087] = "cpe-stable-backport: Backported in 6.6.142"
+
+CVE_STATUS[CVE-2026-64088] = "cpe-stable-backport: Backported in 6.6.142"
+
+CVE_STATUS[CVE-2026-64089] = "cpe-stable-backport: Backported in 6.6.142"
+
+CVE_STATUS[CVE-2026-64090] = "cpe-stable-backport: Backported in 6.6.143"
+
+CVE_STATUS[CVE-2026-64091] = "cpe-stable-backport: Backported in 6.6.143"
+
+CVE_STATUS[CVE-2026-64092] = "cpe-stable-backport: Backported in 6.6.142"
+
+CVE_STATUS[CVE-2026-64093] = "cpe-stable-backport: Backported in 6.6.143"
+
+CVE_STATUS[CVE-2026-64094] = "cpe-stable-backport: Backported in 6.6.143"
+
+CVE_STATUS[CVE-2026-64095] = "cpe-stable-backport: Backported in 6.6.143"
+
+CVE_STATUS[CVE-2026-64096] = "cpe-stable-backport: Backported in 6.6.142"
+
+CVE_STATUS[CVE-2026-64097] = "cpe-stable-backport: Backported in 6.6.142"
+
+CVE_STATUS[CVE-2026-64098] = "cpe-stable-backport: Backported in 6.6.142"
+
+CVE_STATUS[CVE-2026-64099] = "fixed-version: only affects 6.8 onwards"
+
+CVE_STATUS[CVE-2026-64100] = "fixed-version: only affects 6.17 onwards"
+
+CVE_STATUS[CVE-2026-64101] = "fixed-version: only affects 6.15 onwards"
+
+CVE_STATUS[CVE-2026-64102] = "cpe-stable-backport: Backported in 6.6.142"
+
+CVE_STATUS[CVE-2026-64103] = "cpe-stable-backport: Backported in 6.6.142"
+
+CVE_STATUS[CVE-2026-64104] = "fixed-version: only affects 6.13.8 onwards"
+
+CVE_STATUS[CVE-2026-64105] = "fixed-version: only affects 6.10 onwards"
+
+CVE_STATUS[CVE-2026-64106] = "cpe-stable-backport: Backported in 6.6.142"
+
+CVE_STATUS[CVE-2026-64107] = "fixed-version: only affects 6.19 onwards"
+
+CVE_STATUS[CVE-2026-64108] = "cpe-stable-backport: Backported in 6.6.142"
+
+CVE_STATUS[CVE-2026-64109] = "cpe-stable-backport: Backported in 6.6.143"
+
+CVE_STATUS[CVE-2026-64110] = "fixed-version: only affects 6.16 onwards"
+
+CVE_STATUS[CVE-2026-64111] = "fixed-version: only affects 6.8 onwards"
+
+# CVE-2026-64112 needs backporting (fixed from 7.1)
+
+CVE_STATUS[CVE-2026-64113] = "cpe-stable-backport: Backported in 6.6.142"
+
+CVE_STATUS[CVE-2026-64114] = "cpe-stable-backport: Backported in 6.6.142"
+
+CVE_STATUS[CVE-2026-64115] = "cpe-stable-backport: Backported in 6.6.142"
+
+CVE_STATUS[CVE-2026-64116] = "cpe-stable-backport: Backported in 6.6.143"
+
+# CVE-2026-64117 needs backporting (fixed from 7.1)
+
+CVE_STATUS[CVE-2026-64118] = "cpe-stable-backport: Backported in 6.6.142"
+
+CVE_STATUS[CVE-2026-64119] = "fixed-version: only affects 6.11.3 onwards"
+
+CVE_STATUS[CVE-2026-64120] = "fixed-version: only affects 6.16 onwards"
+
+CVE_STATUS[CVE-2026-64121] = "cpe-stable-backport: Backported in 6.6.142"
+
+CVE_STATUS[CVE-2026-64122] = "fixed-version: only affects 6.18.14 onwards"
+
+CVE_STATUS[CVE-2026-64123] = "cpe-stable-backport: Backported in 6.6.143"
+
+CVE_STATUS[CVE-2026-64124] = "fixed-version: only affects 6.16 onwards"
+
+CVE_STATUS[CVE-2026-64125] = "cpe-stable-backport: Backported in 6.6.142"
+
+CVE_STATUS[CVE-2026-64126] = "cpe-stable-backport: Backported in 6.6.142"
+
+CVE_STATUS[CVE-2026-64127] = "fixed-version: only affects 6.10 onwards"
+
+CVE_STATUS[CVE-2026-64128] = "cpe-stable-backport: Backported in 6.6.142"
+
+CVE_STATUS[CVE-2026-64129] = "fixed-version: only affects 6.19 onwards"
+
+CVE_STATUS[CVE-2026-64130] = "fixed-version: only affects 6.18 onwards"
+
+CVE_STATUS[CVE-2026-64131] = "cpe-stable-backport: Backported in 6.6.143"
+
+CVE_STATUS[CVE-2026-64132] = "fixed-version: only affects 6.9 onwards"
+
+CVE_STATUS[CVE-2026-64133] = "cpe-stable-backport: Backported in 6.6.142"
+
+CVE_STATUS[CVE-2026-64134] = "cpe-stable-backport: Backported in 6.6.142"
+
+CVE_STATUS[CVE-2026-64135] = "cpe-stable-backport: Backported in 6.6.142"
+
+CVE_STATUS[CVE-2026-64136] = "cpe-stable-backport: Backported in 6.6.142"
+
+CVE_STATUS[CVE-2026-64137] = "cpe-stable-backport: Backported in 6.6.143"
+
+# CVE-2026-64138 needs backporting (fixed from 7.1)
+
+CVE_STATUS[CVE-2026-64139] = "cpe-stable-backport: Backported in 6.6.142"
+
+CVE_STATUS[CVE-2026-64140] = "fixed-version: only affects 7.0 onwards"
+
+CVE_STATUS[CVE-2026-64141] = "cpe-stable-backport: Backported in 6.6.142"
+
+CVE_STATUS[CVE-2026-64142] = "fixed-version: only affects 6.11 onwards"
+
+CVE_STATUS[CVE-2026-64143] = "fixed-version: only affects 6.19 onwards"
+
+CVE_STATUS[CVE-2026-64144] = "cpe-stable-backport: Backported in 6.6.142"
+
+CVE_STATUS[CVE-2026-64145] = "fixed-version: only affects 6.13 onwards"
+
+# CVE-2026-64146 needs backporting (fixed from 7.1)
+
+CVE_STATUS[CVE-2026-64147] = "cpe-stable-backport: Backported in 6.6.142"
+
+CVE_STATUS[CVE-2026-64148] = "cpe-stable-backport: Backported in 6.6.142"
+
+CVE_STATUS[CVE-2026-64149] = "fixed-version: only affects 6.18 onwards"
+
+CVE_STATUS[CVE-2026-64150] = "fixed-version: only affects 6.16 onwards"
+
+CVE_STATUS[CVE-2026-64151] = "fixed-version: only affects 6.19 onwards"
+
+CVE_STATUS[CVE-2026-64152] = "fixed-version: only affects 7.0 onwards"
+
+CVE_STATUS[CVE-2026-64153] = "cpe-stable-backport: Backported in 6.6.142"
+
+# CVE-2026-64154 needs backporting (fixed from 7.1)
+
+CVE_STATUS[CVE-2026-64155] = "cpe-stable-backport: Backported in 6.6.142"
+
+CVE_STATUS[CVE-2026-64156] = "fixed-version: only affects 6.14 onwards"
+
+CVE_STATUS[CVE-2026-64157] = "fixed-version: only affects 6.10.8 onwards"
+
+CVE_STATUS[CVE-2026-64158] = "fixed-version: only affects 6.8 onwards"
+
+CVE_STATUS[CVE-2026-64159] = "fixed-version: only affects 6.10.8 onwards"
+
+# CVE-2026-64160 needs backporting (fixed from 7.1)
+
+CVE_STATUS[CVE-2026-64161] = "fixed-version: only affects 6.18 onwards"
+
+CVE_STATUS[CVE-2026-64162] = "fixed-version: only affects 6.16 onwards"
+
+CVE_STATUS[CVE-2026-64163] = "cpe-stable-backport: Backported in 6.6.142"
+
+CVE_STATUS[CVE-2026-64164] = "cpe-stable-backport: Backported in 6.6.142"
+
+CVE_STATUS[CVE-2026-64165] = "cpe-stable-backport: Backported in 6.6.142"
+
+CVE_STATUS[CVE-2026-64166] = "cpe-stable-backport: Backported in 6.6.142"
+
+CVE_STATUS[CVE-2026-64167] = "fixed-version: only affects 6.19 onwards"
+
+CVE_STATUS[CVE-2026-64168] = "cpe-stable-backport: Backported in 6.6.142"
+
+CVE_STATUS[CVE-2026-64169] = "fixed-version: only affects 6.12 onwards"
+
+CVE_STATUS[CVE-2026-64170] = "cpe-stable-backport: Backported in 6.6.142"
+
+CVE_STATUS[CVE-2026-64171] = "fixed-version: only affects 7.0 onwards"
+
+CVE_STATUS[CVE-2026-64172] = "fixed-version: only affects 6.17 onwards"
+
+CVE_STATUS[CVE-2026-64173] = "cpe-stable-backport: Backported in 6.6.142"
+
+CVE_STATUS[CVE-2026-64174] = "cpe-stable-backport: Backported in 6.6.142"
+
+CVE_STATUS[CVE-2026-64175] = "fixed-version: only affects 6.15 onwards"
+
+CVE_STATUS[CVE-2026-64176] = "fixed-version: only affects 6.17.9 onwards"
+
+CVE_STATUS[CVE-2026-64177] = "cpe-stable-backport: Backported in 6.6.142"
+
+CVE_STATUS[CVE-2026-64178] = "cpe-stable-backport: Backported in 6.6.142"
+
+CVE_STATUS[CVE-2026-64179] = "cpe-stable-backport: Backported in 6.6.142"
+
+CVE_STATUS[CVE-2026-64180] = "fixed-version: only affects 6.8 onwards"
+
+CVE_STATUS[CVE-2026-64181] = "fixed-version: only affects 6.18 onwards"
+
+CVE_STATUS[CVE-2026-64182] = "cpe-stable-backport: Backported in 6.6.142"
+
+CVE_STATUS[CVE-2026-64183] = "cpe-stable-backport: Backported in 6.6.142"
+
+CVE_STATUS[CVE-2026-64184] = "cpe-stable-backport: Backported in 6.6.142"
+
+CVE_STATUS[CVE-2026-64185] = "cpe-stable-backport: Backported in 6.6.142"
+
+CVE_STATUS[CVE-2026-64186] = "fixed-version: only affects 6.17 onwards"
+
+# CVE-2026-64187 needs backporting (fixed from 7.2rc4)
+
+CVE_STATUS[CVE-2026-64188] = "cpe-stable-backport: Backported in 6.6.144"
+
+# CVE-2026-64189 needs backporting (fixed from 7.2rc2)
+
+# CVE-2026-64190 needs backporting (fixed from 7.1)
+
+CVE_STATUS[CVE-2026-64191] = "cpe-stable-backport: Backported in 6.6.144"
+
+# CVE-2026-64192 needs backporting (fixed from 7.2rc2)
+
+# CVE-2026-64205 needs backporting (fixed from 7.2rc1)
+
+# CVE-2026-64206 needs backporting (fixed from 7.2rc3)
+
+CVE_STATUS[CVE-2026-64207] = "fixed-version: only affects 6.17 onwards"
-# CVE-2026-53362 may need backporting (fixed from 6.6.144)
+# CVE-2026-64600 needs backporting (fixed from 7.2rc4)
^ permalink raw reply related [flat|nested] 32+ messages in thread
* [OE-core][scarthgap 05/31] libxml2: Fix CVE-2026-11979
2026-07-26 8:29 [OE-core][scarthgap 00/31] Patch review Yoann Congal
` (3 preceding siblings ...)
2026-07-26 8:29 ` [OE-core][scarthgap 04/31] linux-yocto/6.6: update CVE exclusions (6.6.144) Yoann Congal
@ 2026-07-26 8:29 ` Yoann Congal
2026-07-26 8:29 ` [OE-core][scarthgap 06/31] openssh: Fix CVE-2026-59999 Yoann Congal
` (25 subsequent siblings)
30 siblings, 0 replies; 32+ messages in thread
From: Yoann Congal @ 2026-07-26 8:29 UTC (permalink / raw)
To: openembedded-core
From: Devansh Patel <devanshp@cisco.com>
This patch applies the upstream fix as referenced in [2],
using the commit shown in [1].
[1] https://gitlab.gnome.org/GNOME/libxml2/-/commit/c2e233fc1b341685fc99621b2768b503f777a72e
[2] https://nvd.nist.gov/vuln/detail/CVE-2026-11979
Signed-off-by: Devansh Patel <devanshp@cisco.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
---
.../libxml/libxml2/CVE-2026-11979.patch | 70 +++++++++++++++++++
meta/recipes-core/libxml/libxml2_2.12.10.bb | 1 +
2 files changed, 71 insertions(+)
create mode 100644 meta/recipes-core/libxml/libxml2/CVE-2026-11979.patch
diff --git a/meta/recipes-core/libxml/libxml2/CVE-2026-11979.patch b/meta/recipes-core/libxml/libxml2/CVE-2026-11979.patch
new file mode 100644
index 00000000000..427026b345f
--- /dev/null
+++ b/meta/recipes-core/libxml/libxml2/CVE-2026-11979.patch
@@ -0,0 +1,70 @@
+From d8566dd918c612078dfb3ee1a95d7bb6f0656bfe Mon Sep 17 00:00:00 2001
+From: Daniel Garcia Moreno <daniel.garcia@suse.com>
+Date: Fri, 22 May 2026 12:21:20 +0200
+Subject: [PATCH] xmlcatalog: overflow check for large --shell commands
+
+Fix https://gitlab.gnome.org/GNOME/libxml2/-/work_items/1124
+
+CVE: CVE-2026-11979
+Upstream-Status: Backport [https://gitlab.gnome.org/GNOME/libxml2/-/commit/c2e233fc1b341685fc99621b2768b503f777a72e]
+
+Backport Changes:
+- The commit modifies test/catalogs/test.sh.
+- test/catalogs/test.sh does not exist in the libxml2 v2.12.10
+ source used in Scarthgap and was introduced later version
+ libxml2 v2.14.0 [1].
+- The test changes were omitted; only the required fix in
+ xmlcatalog.c was backported.
+
+[1] https://gitlab.gnome.org/GNOME/libxml2/-/commit/f06fc933cdaea2ce8e9cea275fdbf4edb85f9837
+
+(cherry picked from commit c2e233fc1b341685fc99621b2768b503f777a72e)
+Signed-off-by: Devansh Patel <devanshp@cisco.com>
+---
+ xmlcatalog.c | 16 ++++++++++++++++
+ 1 file changed, 16 insertions(+)
+
+diff --git a/xmlcatalog.c b/xmlcatalog.c
+index 588802b41..51569b879 100644
+--- a/xmlcatalog.c
++++ b/xmlcatalog.c
+@@ -114,6 +114,12 @@ static void usershell(void) {
+ (*cur != '\n') && (*cur != '\r')) {
+ if (*cur == 0)
+ break;
++ /* Do not read beyond the command array capacity */
++ if (i >= (int)sizeof(command) - 2) {
++ printf("Invalid command %s\n", cur);
++ i = 0;
++ break;
++ }
+ command[i++] = *cur++;
+ }
+ command[i] = 0;
+@@ -131,6 +137,11 @@ static void usershell(void) {
+ while ((*cur != '\n') && (*cur != '\r') && (*cur != 0)) {
+ if (*cur == 0)
+ break;
++ if (i >= (int)sizeof(arg) - 2) {
++ printf("Invalid arg %s\n", arg);
++ i = 0;
++ break;
++ }
+ arg[i++] = *cur++;
+ }
+ arg[i] = 0;
+@@ -143,6 +154,11 @@ static void usershell(void) {
+ cur = arg;
+ memset(argv, 0, sizeof(argv));
+ while (*cur != 0) {
++ if (i >= (int)sizeof(argv) / (int)sizeof(char*)) {
++ printf("Too much arguments\n");
++ break;
++ }
++
+ while ((*cur == ' ') || (*cur == '\t')) cur++;
+ if (*cur == '\'') {
+ cur++;
+--
+2.35.6
+
diff --git a/meta/recipes-core/libxml/libxml2_2.12.10.bb b/meta/recipes-core/libxml/libxml2_2.12.10.bb
index 2bfa78324f6..d476ba14b6e 100644
--- a/meta/recipes-core/libxml/libxml2_2.12.10.bb
+++ b/meta/recipes-core/libxml/libxml2_2.12.10.bb
@@ -31,6 +31,7 @@ SRC_URI += "http://www.w3.org/XML/Test/xmlts20130923.tar;subdir=${BP};name=testt
file://CVE-2026-0992-02.patch \
file://CVE-2026-0992-03.patch \
file://CVE-2026-1757.patch \
+ file://CVE-2026-11979.patch \
"
SRC_URI[archive.sha256sum] = "c3d8c0c34aa39098f66576fe51969db12a5100b956233dc56506f7a8679be995"
^ permalink raw reply related [flat|nested] 32+ messages in thread
* [OE-core][scarthgap 06/31] openssh: Fix CVE-2026-59999
2026-07-26 8:29 [OE-core][scarthgap 00/31] Patch review Yoann Congal
` (4 preceding siblings ...)
2026-07-26 8:29 ` [OE-core][scarthgap 05/31] libxml2: Fix CVE-2026-11979 Yoann Congal
@ 2026-07-26 8:29 ` Yoann Congal
2026-07-26 8:29 ` [OE-core][scarthgap 07/31] openssh: Fix CVE-2026-59997 Yoann Congal
` (24 subsequent siblings)
30 siblings, 0 replies; 32+ messages in thread
From: Yoann Congal @ 2026-07-26 8:29 UTC (permalink / raw)
To: openembedded-core
From: Devansh Patel <devanshp@cisco.com>
This patch applies the upstream OpenSSH 10.4 backport for
CVE-2026-59999. The upstream fix commit is referenced in [1],
and the public CVE advisory is referenced in [2].
[1] https://github.com/openssh/openssh-portable/commit/8dfe7ed6e2fd988de08df508355a196b956b2753
[2] https://nvd.nist.gov/vuln/detail/CVE-2026-59999
Signed-off-by: Devansh Patel <devanshp@cisco.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
---
.../openssh/openssh/CVE-2026-59999.patch | 36 +++++++++++++++++++
.../openssh/openssh_9.6p1.bb | 1 +
2 files changed, 37 insertions(+)
create mode 100644 meta/recipes-connectivity/openssh/openssh/CVE-2026-59999.patch
diff --git a/meta/recipes-connectivity/openssh/openssh/CVE-2026-59999.patch b/meta/recipes-connectivity/openssh/openssh/CVE-2026-59999.patch
new file mode 100644
index 00000000000..89b7aa9c7f4
--- /dev/null
+++ b/meta/recipes-connectivity/openssh/openssh/CVE-2026-59999.patch
@@ -0,0 +1,36 @@
+From 1c719fa7d0fb0aa335f0e8d5db5d5e5d01c894e5 Mon Sep 17 00:00:00 2001
+From: "djm@openbsd.org" <djm@openbsd.org>
+Date: Sun, 31 May 2026 04:47:29 +0000
+Subject: [PATCH] upstream: DisableForwarding=yes didn't override
+ PermitTunnel=yes
+
+Reported independently by Huzaifa Sidhpurwala of Redhat and Marko
+Jevtic; ok markus@
+
+CVE: CVE-2026-59999
+Upstream-Status: Backport [https://github.com/openssh/openssh-portable/commit/8dfe7ed6e2fd988de08df508355a196b956b2753]
+
+Backport Changes:
+- Retained the Scarthgap serverloop.c OpenBSD revision identifier because
+ the 10.4 identifier does not describe the older source baseline.
+
+OpenBSD-Commit-ID: b5c13f0746cf079b21f8deba47407fad49ccbf4c
+(cherry picked from commit 8dfe7ed6e2fd988de08df508355a196b956b2753)
+Signed-off-by: Devansh Patel <devanshp@cisco.com>
+---
+ serverloop.c | 2 +-
+ 1 file changed, 1 insertion(+), 1 deletion(-)
+
+diff --git a/serverloop.c b/serverloop.c
+index f3683c2e4..c1fe99d12 100644
+--- a/serverloop.c
++++ b/serverloop.c
+@@ -531,7 +531,7 @@ server_request_tun(struct ssh *ssh)
+ ssh_packet_send_debug(ssh, "Unsupported tunnel device mode.");
+ return NULL;
+ }
+- if ((options.permit_tun & mode) == 0) {
++ if ((options.permit_tun & mode) == 0 || options.disable_forwarding) {
+ ssh_packet_send_debug(ssh, "Server has rejected tunnel device "
+ "forwarding");
+ return NULL;
diff --git a/meta/recipes-connectivity/openssh/openssh_9.6p1.bb b/meta/recipes-connectivity/openssh/openssh_9.6p1.bb
index 4ab3174924c..b6eda3607a9 100644
--- a/meta/recipes-connectivity/openssh/openssh_9.6p1.bb
+++ b/meta/recipes-connectivity/openssh/openssh_9.6p1.bb
@@ -37,6 +37,7 @@ SRC_URI = "http://ftp.openbsd.org/pub/OpenBSD/OpenSSH/portable/openssh-${PV}.tar
file://CVE-2026-35385.patch \
file://CVE-2026-35414-CVE-2026-35387.patch \
file://CVE-2026-35388.patch \
+ file://CVE-2026-59999.patch \
"
SRC_URI[sha256sum] = "910211c07255a8c5ad654391b40ee59800710dd8119dd5362de09385aa7a777c"
^ permalink raw reply related [flat|nested] 32+ messages in thread
* [OE-core][scarthgap 07/31] openssh: Fix CVE-2026-59997
2026-07-26 8:29 [OE-core][scarthgap 00/31] Patch review Yoann Congal
` (5 preceding siblings ...)
2026-07-26 8:29 ` [OE-core][scarthgap 06/31] openssh: Fix CVE-2026-59999 Yoann Congal
@ 2026-07-26 8:29 ` Yoann Congal
2026-07-26 8:29 ` [OE-core][scarthgap 08/31] openssh: Fix CVE-2026-59996 Yoann Congal
` (23 subsequent siblings)
30 siblings, 0 replies; 32+ messages in thread
From: Yoann Congal @ 2026-07-26 8:29 UTC (permalink / raw)
To: openembedded-core
From: Devansh Patel <devanshp@cisco.com>
This patch applies the upstream OpenSSH 10.4 backport for
CVE-2026-59997. The upstream fix commit is referenced in [1],
and the public CVE advisory is referenced in [2].
[1] https://github.com/openssh/openssh-portable/commit/e9916c44c1324ab9ab022719e4df08a390a83014
[2] https://nvd.nist.gov/vuln/detail/CVE-2026-59997
Signed-off-by: Devansh Patel <devanshp@cisco.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
---
.../openssh/openssh/CVE-2026-59997.patch | 58 +++++++++++++++++++
.../openssh/openssh_9.6p1.bb | 1 +
2 files changed, 59 insertions(+)
create mode 100644 meta/recipes-connectivity/openssh/openssh/CVE-2026-59997.patch
diff --git a/meta/recipes-connectivity/openssh/openssh/CVE-2026-59997.patch b/meta/recipes-connectivity/openssh/openssh/CVE-2026-59997.patch
new file mode 100644
index 00000000000..aa171def018
--- /dev/null
+++ b/meta/recipes-connectivity/openssh/openssh/CVE-2026-59997.patch
@@ -0,0 +1,58 @@
+From 3011cbb6bb73f3f3dc90fa1d48736803fa407509 Mon Sep 17 00:00:00 2001
+From: "djm@openbsd.org" <djm@openbsd.org>
+Date: Fri, 5 Jun 2026 08:53:07 +0000
+Subject: [PATCH] upstream: pass >9 commandline arguments to the internal-sftp
+ server,
+
+previously they were silently dropped; reported by Steve Caffrey ok deraadt@
+
+CVE: CVE-2026-59997
+Upstream-Status: Backport [https://github.com/openssh/openssh-portable/commit/e9916c44c1324ab9ab022719e4df08a390a83014]
+
+Backport Changes:
+- Retained the Scarthgap session.c OpenBSD revision identifier because the
+ 10.4 identifier does not describe the older source baseline.
+
+OpenBSD-Commit-ID: ee6cd5430a3ca027c3223af54b58ad3cc7ccd624
+(cherry picked from commit e9916c44c1324ab9ab022719e4df08a390a83014)
+Signed-off-by: Devansh Patel <devanshp@cisco.com>
+---
+ session.c | 19 ++++++++++---------
+ 1 file changed, 10 insertions(+), 9 deletions(-)
+
+diff --git a/session.c b/session.c
+index eb932b8bf..1a01ecf74 100644
+--- a/session.c
++++ b/session.c
+@@ -1650,21 +1650,22 @@ do_child(struct ssh *ssh, Session *s, const char *command)
+ exit(1);
+ } else if (s->is_subsystem == SUBSYSTEM_INT_SFTP) {
+ extern int optind, optreset;
+- int i;
+- char *p, *args;
++ int sftp_argc;
++ char **sftp_argv;
+
+ setproctitle("%s@%s", s->pw->pw_name, INTERNAL_SFTP_NAME);
+- args = xstrdup(command ? command : "sftp-server");
+- for (i = 0, (p = strtok(args, " ")); p; (p = strtok(NULL, " ")))
+- if (i < ARGV_MAX - 1)
+- argv[i++] = p;
+- argv[i] = NULL;
++ if (argv_split(command == NULL ? "sftp-server" : command,
++ &sftp_argc, &sftp_argv, 1) != 0) {
++ error("internal error: can't split internal-sftp "
++ "arguments");
++ exit(1);
++ }
+ optind = optreset = 1;
+- __progname = argv[0];
++ __progname = sftp_argv[0];
+ #ifdef WITH_SELINUX
+ ssh_selinux_change_context("sftpd_t");
+ #endif
+- exit(sftp_server_main(i, argv, s->pw));
++ exit(sftp_server_main(sftp_argc, sftp_argv, s->pw));
+ }
+
+ fflush(NULL);
diff --git a/meta/recipes-connectivity/openssh/openssh_9.6p1.bb b/meta/recipes-connectivity/openssh/openssh_9.6p1.bb
index b6eda3607a9..4c8604f4b74 100644
--- a/meta/recipes-connectivity/openssh/openssh_9.6p1.bb
+++ b/meta/recipes-connectivity/openssh/openssh_9.6p1.bb
@@ -38,6 +38,7 @@ SRC_URI = "http://ftp.openbsd.org/pub/OpenBSD/OpenSSH/portable/openssh-${PV}.tar
file://CVE-2026-35414-CVE-2026-35387.patch \
file://CVE-2026-35388.patch \
file://CVE-2026-59999.patch \
+ file://CVE-2026-59997.patch \
"
SRC_URI[sha256sum] = "910211c07255a8c5ad654391b40ee59800710dd8119dd5362de09385aa7a777c"
^ permalink raw reply related [flat|nested] 32+ messages in thread
* [OE-core][scarthgap 08/31] openssh: Fix CVE-2026-59996
2026-07-26 8:29 [OE-core][scarthgap 00/31] Patch review Yoann Congal
` (6 preceding siblings ...)
2026-07-26 8:29 ` [OE-core][scarthgap 07/31] openssh: Fix CVE-2026-59997 Yoann Congal
@ 2026-07-26 8:29 ` Yoann Congal
2026-07-26 8:29 ` [OE-core][scarthgap 09/31] openssh: Fix CVE-2026-59995 Yoann Congal
` (22 subsequent siblings)
30 siblings, 0 replies; 32+ messages in thread
From: Yoann Congal @ 2026-07-26 8:29 UTC (permalink / raw)
To: openembedded-core
From: Devansh Patel <devanshp@cisco.com>
This patch applies the upstream OpenSSH 10.4 backport for
CVE-2026-59996. The upstream fix commit is referenced in [1],
and the public CVE advisory is referenced in [2].
[1] https://github.com/openssh/openssh-portable/commit/36480181fa22f98e180b4f9e10203480c0346c78
[2] https://nvd.nist.gov/vuln/detail/CVE-2026-59996
Signed-off-by: Devansh Patel <devanshp@cisco.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
---
.../openssh/openssh/CVE-2026-59996.patch | 37 +++++++++++++++++++
.../openssh/openssh_9.6p1.bb | 1 +
2 files changed, 38 insertions(+)
create mode 100644 meta/recipes-connectivity/openssh/openssh/CVE-2026-59996.patch
diff --git a/meta/recipes-connectivity/openssh/openssh/CVE-2026-59996.patch b/meta/recipes-connectivity/openssh/openssh/CVE-2026-59996.patch
new file mode 100644
index 00000000000..b13390b25b7
--- /dev/null
+++ b/meta/recipes-connectivity/openssh/openssh/CVE-2026-59996.patch
@@ -0,0 +1,37 @@
+From 762b3d438547893d62ce3e147dce6cef14697b09 Mon Sep 17 00:00:00 2001
+From: "djm@openbsd.org" <djm@openbsd.org>
+Date: Sun, 28 Jun 2026 23:47:16 +0000
+Subject: [PATCH] upstream: resist that return ".." via remote glob during
+
+remote/remote copies, similar to fixes for bz3871 for remote/local copies.
+From Swival scanner
+
+CVE: CVE-2026-59996
+Upstream-Status: Backport [https://github.com/openssh/openssh-portable/commit/36480181fa22f98e180b4f9e10203480c0346c78]
+
+Backport Changes:
+- Retained the Scarthgap scp.c OpenBSD revision identifier because the
+ 10.4 identifier does not describe the older source baseline.
+
+OpenBSD-Commit-ID: c0c20a1b746db55c08e53658bf21ea9405b300a5
+(cherry picked from commit 36480181fa22f98e180b4f9e10203480c0346c78)
+Signed-off-by: Devansh Patel <devanshp@cisco.com>
+---
+ scp.c | 4 ++++
+ 1 file changed, 4 insertions(+)
+
+diff --git a/scp.c b/scp.c
+index 2c21fa19a..00d87517d 100644
+--- a/scp.c
++++ b/scp.c
+@@ -2043,6 +2043,10 @@ throughlocal_sftp(struct sftp_conn *from, struct sftp_conn *to,
+ goto out;
+ }
+
++ /* Special handling for source of '..' */
++ if (strcmp(filename, "..") == 0)
++ filename = "."; /* Download to dest, not dest/.. */
++
+ if (targetisdir)
+ abs_dst = sftp_path_append(target, filename);
+ else
diff --git a/meta/recipes-connectivity/openssh/openssh_9.6p1.bb b/meta/recipes-connectivity/openssh/openssh_9.6p1.bb
index 4c8604f4b74..8f44d4b9878 100644
--- a/meta/recipes-connectivity/openssh/openssh_9.6p1.bb
+++ b/meta/recipes-connectivity/openssh/openssh_9.6p1.bb
@@ -39,6 +39,7 @@ SRC_URI = "http://ftp.openbsd.org/pub/OpenBSD/OpenSSH/portable/openssh-${PV}.tar
file://CVE-2026-35388.patch \
file://CVE-2026-59999.patch \
file://CVE-2026-59997.patch \
+ file://CVE-2026-59996.patch \
"
SRC_URI[sha256sum] = "910211c07255a8c5ad654391b40ee59800710dd8119dd5362de09385aa7a777c"
^ permalink raw reply related [flat|nested] 32+ messages in thread
* [OE-core][scarthgap 09/31] openssh: Fix CVE-2026-59995
2026-07-26 8:29 [OE-core][scarthgap 00/31] Patch review Yoann Congal
` (7 preceding siblings ...)
2026-07-26 8:29 ` [OE-core][scarthgap 08/31] openssh: Fix CVE-2026-59996 Yoann Congal
@ 2026-07-26 8:29 ` Yoann Congal
2026-07-26 8:29 ` [OE-core][scarthgap 10/31] openssh: Fix CVE-2026-60001 Yoann Congal
` (21 subsequent siblings)
30 siblings, 0 replies; 32+ messages in thread
From: Yoann Congal @ 2026-07-26 8:29 UTC (permalink / raw)
To: openembedded-core
From: Devansh Patel <devanshp@cisco.com>
This patch applies the upstream OpenSSH 10.4 backport for
CVE-2026-59995. The upstream fix commit is referenced in [1],
and the public CVE advisory is referenced in [2].
[1] https://github.com/openssh/openssh-portable/commit/1b39f39657d2e58f8ec57341581a39bbf0be645b
[2] https://nvd.nist.gov/vuln/detail/CVE-2026-59995
Signed-off-by: Devansh Patel <devanshp@cisco.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
---
.../openssh/openssh/CVE-2026-59995.patch | 42 +++++++++++++++++++
.../openssh/openssh_9.6p1.bb | 1 +
2 files changed, 43 insertions(+)
create mode 100644 meta/recipes-connectivity/openssh/openssh/CVE-2026-59995.patch
diff --git a/meta/recipes-connectivity/openssh/openssh/CVE-2026-59995.patch b/meta/recipes-connectivity/openssh/openssh/CVE-2026-59995.patch
new file mode 100644
index 00000000000..9b6fee198ff
--- /dev/null
+++ b/meta/recipes-connectivity/openssh/openssh/CVE-2026-59995.patch
@@ -0,0 +1,42 @@
+From b340eaa274a7e7dffea03bcb62169249bbddab37 Mon Sep 17 00:00:00 2001
+From: "djm@openbsd.org" <djm@openbsd.org>
+Date: Mon, 29 Jun 2026 01:47:21 +0000
+Subject: [PATCH] upstream: avoid download to server-controlled path when
+ performing
+
+download on the commandline. From Swival scanner
+
+CVE: CVE-2026-59995
+Upstream-Status: Backport [https://github.com/openssh/openssh-portable/commit/1b39f39657d2e58f8ec57341581a39bbf0be645b]
+
+Backport Changes:
+- Retained the Scarthgap sftp.c OpenBSD revision identifier because the
+ 10.4 identifier does not describe the older source baseline.
+
+OpenBSD-Commit-ID: d1b2c44305fdfe6d51eed9ecc727e59478bf311f
+(cherry picked from commit 1b39f39657d2e58f8ec57341581a39bbf0be645b)
+Signed-off-by: Devansh Patel <devanshp@cisco.com>
+---
+ sftp.c | 9 ++-------
+ 1 file changed, 2 insertions(+), 7 deletions(-)
+
+diff --git a/sftp.c b/sftp.c
+index c609b4153..487e53976 100644
+--- a/sftp.c
++++ b/sftp.c
+@@ -2268,13 +2268,8 @@ interactive_loop(struct sftp_conn *conn, char *file1, char *file2)
+ return (-1);
+ }
+ } else {
+- /* XXX this is wrong wrt quoting */
+- snprintf(cmd, sizeof cmd, "get%s %s%s%s",
+- global_aflag ? " -a" : "", dir,
+- file2 == NULL ? "" : " ",
+- file2 == NULL ? "" : file2);
+- err = parse_dispatch_command(conn, cmd,
+- &remote_path, startdir, 1, 0);
++ err = process_get(conn, dir, file2, remote_path, 0, 0,
++ global_aflag, 0);
+ free(dir);
+ free(startdir);
+ free(remote_path);
diff --git a/meta/recipes-connectivity/openssh/openssh_9.6p1.bb b/meta/recipes-connectivity/openssh/openssh_9.6p1.bb
index 8f44d4b9878..37f4dc20dd9 100644
--- a/meta/recipes-connectivity/openssh/openssh_9.6p1.bb
+++ b/meta/recipes-connectivity/openssh/openssh_9.6p1.bb
@@ -40,6 +40,7 @@ SRC_URI = "http://ftp.openbsd.org/pub/OpenBSD/OpenSSH/portable/openssh-${PV}.tar
file://CVE-2026-59999.patch \
file://CVE-2026-59997.patch \
file://CVE-2026-59996.patch \
+ file://CVE-2026-59995.patch \
"
SRC_URI[sha256sum] = "910211c07255a8c5ad654391b40ee59800710dd8119dd5362de09385aa7a777c"
^ permalink raw reply related [flat|nested] 32+ messages in thread
* [OE-core][scarthgap 10/31] openssh: Fix CVE-2026-60001
2026-07-26 8:29 [OE-core][scarthgap 00/31] Patch review Yoann Congal
` (8 preceding siblings ...)
2026-07-26 8:29 ` [OE-core][scarthgap 09/31] openssh: Fix CVE-2026-59995 Yoann Congal
@ 2026-07-26 8:29 ` Yoann Congal
2026-07-26 8:29 ` [OE-core][scarthgap 11/31] openssh: Fix CVE-2026-60002 Yoann Congal
` (20 subsequent siblings)
30 siblings, 0 replies; 32+ messages in thread
From: Yoann Congal @ 2026-07-26 8:29 UTC (permalink / raw)
To: openembedded-core
From: Devansh Patel <devanshp@cisco.com>
This patch applies the upstream OpenSSH 10.4 backport for
CVE-2026-60001. The upstream fix commit is referenced in [1],
and the public CVE advisory is referenced in [2].
[1] https://github.com/openssh/openssh-portable/commit/d43ba60c91cb323ca921049b7d43b1908c318454
[2] https://nvd.nist.gov/vuln/detail/CVE-2026-60001
Signed-off-by: Devansh Patel <devanshp@cisco.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
---
.../openssh/openssh/CVE-2026-60001.patch | 130 ++++++++++++++++++
.../openssh/openssh_9.6p1.bb | 1 +
2 files changed, 131 insertions(+)
create mode 100644 meta/recipes-connectivity/openssh/openssh/CVE-2026-60001.patch
diff --git a/meta/recipes-connectivity/openssh/openssh/CVE-2026-60001.patch b/meta/recipes-connectivity/openssh/openssh/CVE-2026-60001.patch
new file mode 100644
index 00000000000..ff1d14c7c9b
--- /dev/null
+++ b/meta/recipes-connectivity/openssh/openssh/CVE-2026-60001.patch
@@ -0,0 +1,130 @@
+From ef41798b35a53757f8aa08ad14ee1463b0fe9b15 Mon Sep 17 00:00:00 2001
+From: "djm@openbsd.org" <djm@openbsd.org>
+Date: Mon, 6 Jul 2026 07:44:48 +0000
+Subject: [PATCH] upstream: Fix cases in GSSAPI and keyboard-interactive
+
+authentication where the minimum per-attempt delay was not being enforced.
+
+Reported by Orange Cyberdefense Vulnerability Team
+
+CVE: CVE-2026-60001
+Upstream-Status: Backport [https://github.com/openssh/openssh-portable/commit/d43ba60c91cb323ca921049b7d43b1908c318454]
+
+Backport Changes:
+- Kept Scarthgap's PRIVSEP(ssh_gssapi_userok()) interface and GSSAPI
+ display-name recording while adding the upstream failure-delay calls;
+ mm_ssh_gssapi_userok() belongs to the later split-sshd architecture.
+- Retained the Scarthgap OpenBSD revision identifiers in auth.h,
+ auth2-chall.c, auth2-gss.c, and auth2.c.
+
+OpenBSD-Commit-ID: c40bd35cc2428fcaccad7a141703c28baa6da01e
+(cherry picked from commit d43ba60c91cb323ca921049b7d43b1908c318454)
+Signed-off-by: Devansh Patel <devanshp@cisco.com>
+---
+ auth.h | 1 +
+ auth2-chall.c | 4 ++++
+ auth2-gss.c | 7 +++++++
+ auth2.c | 10 ++++++++--
+ 4 files changed, 20 insertions(+), 2 deletions(-)
+
+diff --git a/auth.h b/auth.h
+index 6d2d39762..9ad4898c5 100644
+--- a/auth.h
++++ b/auth.h
+@@ -173,6 +173,7 @@ void auth_log(struct ssh *, int, int, const char *, const char *);
+ void auth_maxtries_exceeded(struct ssh *) __attribute__((noreturn));
+ void userauth_finish(struct ssh *, int, const char *, const char *);
+ int auth_root_allowed(struct ssh *, const char *);
++void auth_failure_delay(Authctxt *, double);
+
+ char *auth2_read_banner(void);
+ int auth2_methods_valid(const char *, int);
+diff --git a/auth2-chall.c b/auth2-chall.c
+index 021df8291..20e70d222 100644
+--- a/auth2-chall.c
++++ b/auth2-chall.c
+@@ -296,6 +296,7 @@ input_userauth_info_response(int type, u_int32_t seq, struct ssh *ssh)
+ u_int i, nresp;
+ const char *devicename = NULL;
+ char **response = NULL;
++ double tstart = monotime_double();
+
+ if (authctxt == NULL)
+ fatal_f("no authctxt");
+@@ -354,6 +355,9 @@ input_userauth_info_response(int type, u_int32_t seq, struct ssh *ssh)
+ auth2_challenge_start(ssh);
+ }
+ }
++
++ if (!authenticated)
++ auth_failure_delay(authctxt, tstart);
+ userauth_finish(ssh, authenticated, "keyboard-interactive",
+ devicename);
+ return 0;
+diff --git a/auth2-gss.c b/auth2-gss.c
+index f72a38998..195578bcf 100644
+--- a/auth2-gss.c
++++ b/auth2-gss.c
+@@ -255,6 +255,7 @@ input_gssapi_exchange_complete(int type, u_int32_t plen, struct ssh *ssh)
+ Authctxt *authctxt = ssh->authctxt;
+ int r, authenticated;
+ const char *displayname;
++ double tstart = monotime_double();
+
+ if (authctxt == NULL || (authctxt->methoddata == NULL && !use_privsep))
+ fatal("No authentication or GSSAPI context");
+@@ -268,6 +269,8 @@ input_gssapi_exchange_complete(int type, u_int32_t plen, struct ssh *ssh)
+ fatal_fr(r, "parse packet");
+
+ authenticated = PRIVSEP(ssh_gssapi_userok(authctxt->user));
++ if (!authenticated)
++ auth_failure_delay(authctxt, tstart);
+
+ if ((!use_privsep || mm_is_monitor()) &&
+ (displayname = ssh_gssapi_displayname()) != NULL)
+@@ -293,6 +296,7 @@ input_gssapi_mic(int type, u_int32_t plen, struct ssh *ssh)
+ const char *displayname;
+ u_char *p;
+ size_t len;
++ double tstart = monotime_double();
+
+ if (authctxt == NULL || (authctxt->methoddata == NULL && !use_privsep))
+ fatal("No authentication or GSSAPI context");
+@@ -320,6 +324,9 @@ input_gssapi_mic(int type, u_int32_t plen, struct ssh *ssh)
+ sshbuf_free(b);
+ free(mic.value);
+
++ if (!authenticated)
++ auth_failure_delay(authctxt, tstart);
++
+ if ((!use_privsep || mm_is_monitor()) &&
+ (displayname = ssh_gssapi_displayname()) != NULL)
+ auth2_record_info(authctxt, "%s", displayname);
+diff --git a/auth2.c b/auth2.c
+index 271789a77..18077d625 100644
+--- a/auth2.c
++++ b/auth2.c
+@@ -265,6 +265,12 @@ ensure_minimum_time_since(double start, double seconds)
+ nanosleep(&ts, NULL);
+ }
+
++void
++auth_failure_delay(Authctxt *authctxt, double tstart)
++{
++ ensure_minimum_time_since(tstart, user_specific_delay(authctxt->user));
++}
++
+ static int
+ input_userauth_request(int type, u_int32_t seq, struct ssh *ssh)
+ {
+@@ -348,8 +354,8 @@ input_userauth_request(int type, u_int32_t seq, struct ssh *ssh)
+ authenticated = m->userauth(ssh, method);
+ }
+ if (!authctxt->authenticated && strcmp(method, "none") != 0)
+- ensure_minimum_time_since(tstart,
+- user_specific_delay(authctxt->user));
++ auth_failure_delay(authctxt, tstart);
++
+ userauth_finish(ssh, authenticated, method, NULL);
+ r = 0;
+ out:
diff --git a/meta/recipes-connectivity/openssh/openssh_9.6p1.bb b/meta/recipes-connectivity/openssh/openssh_9.6p1.bb
index 37f4dc20dd9..0d9d33c4597 100644
--- a/meta/recipes-connectivity/openssh/openssh_9.6p1.bb
+++ b/meta/recipes-connectivity/openssh/openssh_9.6p1.bb
@@ -41,6 +41,7 @@ SRC_URI = "http://ftp.openbsd.org/pub/OpenBSD/OpenSSH/portable/openssh-${PV}.tar
file://CVE-2026-59997.patch \
file://CVE-2026-59996.patch \
file://CVE-2026-59995.patch \
+ file://CVE-2026-60001.patch \
"
SRC_URI[sha256sum] = "910211c07255a8c5ad654391b40ee59800710dd8119dd5362de09385aa7a777c"
^ permalink raw reply related [flat|nested] 32+ messages in thread
* [OE-core][scarthgap 11/31] openssh: Fix CVE-2026-60002
2026-07-26 8:29 [OE-core][scarthgap 00/31] Patch review Yoann Congal
` (9 preceding siblings ...)
2026-07-26 8:29 ` [OE-core][scarthgap 10/31] openssh: Fix CVE-2026-60001 Yoann Congal
@ 2026-07-26 8:29 ` Yoann Congal
2026-07-26 8:29 ` [OE-core][scarthgap 12/31] openssh: Fix CVE-2026-60000 Yoann Congal
` (19 subsequent siblings)
30 siblings, 0 replies; 32+ messages in thread
From: Yoann Congal @ 2026-07-26 8:29 UTC (permalink / raw)
To: openembedded-core
From: Devansh Patel <devanshp@cisco.com>
This patch applies the upstream OpenSSH 10.4 backport for
CVE-2026-60002. The upstream fix commit is referenced in [1],
and the public CVE advisory is referenced in [2].
[1] https://github.com/openssh/openssh-portable/commit/e8bdfb151a356d0171fea4194dd205fbb252be23
[2] https://nvd.nist.gov/vuln/detail/CVE-2026-60002
Signed-off-by: Devansh Patel <devanshp@cisco.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
---
.../openssh/openssh/CVE-2026-60002.patch | 226 ++++++++++++++++++
.../openssh/openssh_9.6p1.bb | 1 +
2 files changed, 227 insertions(+)
create mode 100644 meta/recipes-connectivity/openssh/openssh/CVE-2026-60002.patch
diff --git a/meta/recipes-connectivity/openssh/openssh/CVE-2026-60002.patch b/meta/recipes-connectivity/openssh/openssh/CVE-2026-60002.patch
new file mode 100644
index 00000000000..9e94e772618
--- /dev/null
+++ b/meta/recipes-connectivity/openssh/openssh/CVE-2026-60002.patch
@@ -0,0 +1,226 @@
+From 767104acedd68c317b9d8fb603561e1a8be9e76a Mon Sep 17 00:00:00 2001
+From: "djm@openbsd.org" <djm@openbsd.org>
+Date: Mon, 6 Jul 2026 07:49:58 +0000
+Subject: [PATCH] upstream: fix ownership and lifetime of several bits of
+ client
+
+state that need to persist for the life of the connection, especially the
+cached hostkey that was being incorrectly freed early on some paths, possibly
+allowing its use after free.
+
+Reported by Zhenpeng (Leo) Lin from depthfirst.com
+
+CVE: CVE-2026-60002
+Upstream-Status: Backport [https://github.com/openssh/openssh-portable/commit/e8bdfb151a356d0171fea4194dd205fbb252be23]
+
+Backport Changes:
+- Retained Scarthgap's valid_hostname() and valid_ruser() helpers when
+ relocating ssh_conn_info_free() from ssh.c to sshconnect.c.
+- Retained Scarthgap's ext-info-c proposal handling while applying the
+ upstream connection-state ownership and lifetime changes.
+- Retained the Scarthgap OpenBSD revision identifiers in ssh.c,
+ sshconnect.c, sshconnect.h, and sshconnect2.c.
+
+OpenBSD-Commit-ID: faaa6ad72e7d69d41fa8b197b606265b7d9bc73f
+(cherry picked from commit e8bdfb151a356d0171fea4194dd205fbb252be23)
+Signed-off-by: Devansh Patel <devanshp@cisco.com>
+---
+ ssh.c | 24 ++----------------------
+ sshconnect.c | 47 +++++++++++++++++++++++++++++++++++++++++++++--
+ sshconnect.h | 7 +++++--
+ sshconnect2.c | 20 +++++++++++---------
+ 4 files changed, 63 insertions(+), 35 deletions(-)
+
+diff --git a/ssh.c b/ssh.c
+index 9c49f98a8..aecdb79ea 100644
+--- a/ssh.c
++++ b/ssh.c
+@@ -606,26 +606,6 @@ set_addrinfo_port(struct addrinfo *addrs, int port)
+ }
+ }
+
+-static void
+-ssh_conn_info_free(struct ssh_conn_info *cinfo)
+-{
+- if (cinfo == NULL)
+- return;
+- free(cinfo->conn_hash_hex);
+- free(cinfo->shorthost);
+- free(cinfo->uidstr);
+- free(cinfo->keyalias);
+- free(cinfo->thishost);
+- free(cinfo->host_arg);
+- free(cinfo->portstr);
+- free(cinfo->remhost);
+- free(cinfo->remuser);
+- free(cinfo->homedir);
+- free(cinfo->locuser);
+- free(cinfo->jmphost);
+- free(cinfo);
+-}
+-
+ static int
+ valid_hostname(const char *s)
+ {
+@@ -1771,8 +1751,8 @@ main(int ac, char **av)
+ ssh_signal(SIGCHLD, main_sigchld_handler);
+
+ /* Log into the remote system. Never returns if the login fails. */
+- ssh_login(ssh, &sensitive_data, host, (struct sockaddr *)&hostaddr,
+- options.port, pw, timeout_ms, cinfo);
++ ssh_login(ssh, &sensitive_data, host, &hostaddr, options.port,
++ pw, timeout_ms, cinfo);
+
+ /* We no longer need the private host keys. Clear them now. */
+ if (sensitive_data.nkeys != 0) {
+diff --git a/sshconnect.c b/sshconnect.c
+index bd077c75c..7823b6782 100644
+--- a/sshconnect.c
++++ b/sshconnect.c
+@@ -83,6 +83,49 @@ extern char *__progname;
+ static int show_other_keys(struct hostkeys *, struct sshkey *);
+ static void warn_changed_key(struct sshkey *);
+
++void
++ssh_conn_info_free(struct ssh_conn_info *cinfo)
++{
++ if (cinfo == NULL)
++ return;
++ free(cinfo->conn_hash_hex);
++ free(cinfo->shorthost);
++ free(cinfo->uidstr);
++ free(cinfo->keyalias);
++ free(cinfo->thishost);
++ free(cinfo->host_arg);
++ free(cinfo->portstr);
++ free(cinfo->remhost);
++ free(cinfo->remuser);
++ free(cinfo->homedir);
++ free(cinfo->locuser);
++ free(cinfo->jmphost);
++ freezero(cinfo, sizeof(*cinfo));
++}
++
++struct ssh_conn_info *
++ssh_conn_info_dup(const struct ssh_conn_info *cinfo)
++{
++ struct ssh_conn_info *ret;
++
++ if (cinfo == NULL)
++ return NULL;
++ ret = xcalloc(1, sizeof(*ret));
++ ret->conn_hash_hex = xstrdup(cinfo->conn_hash_hex);
++ ret->shorthost = xstrdup(cinfo->shorthost);
++ ret->uidstr = xstrdup(cinfo->uidstr);
++ ret->keyalias = xstrdup(cinfo->keyalias);
++ ret->thishost = xstrdup(cinfo->thishost);
++ ret->host_arg = xstrdup(cinfo->host_arg);
++ ret->portstr = xstrdup(cinfo->portstr);
++ ret->remhost = xstrdup(cinfo->remhost);
++ ret->remuser = xstrdup(cinfo->remuser);
++ ret->homedir = xstrdup(cinfo->homedir);
++ ret->locuser = xstrdup(cinfo->locuser);
++ ret->jmphost = xstrdup(cinfo->jmphost);
++ return ret;
++}
++
+ /* Expand a proxy command */
+ static char *
+ expand_proxy_command(const char *proxy_command, const char *user,
+@@ -1559,8 +1602,8 @@ out:
+ */
+ void
+ ssh_login(struct ssh *ssh, Sensitive *sensitive, const char *orighost,
+- struct sockaddr *hostaddr, u_short port, struct passwd *pw, int timeout_ms,
+- const struct ssh_conn_info *cinfo)
++ struct sockaddr_storage *hostaddr, u_short port, struct passwd *pw,
++ int timeout_ms, const struct ssh_conn_info *cinfo)
+ {
+ char *host;
+ char *server_user, *local_user;
+diff --git a/sshconnect.h b/sshconnect.h
+index 79d35cc19..da2a73f5a 100644
+--- a/sshconnect.h
++++ b/sshconnect.h
+@@ -71,7 +71,7 @@ int ssh_connect(struct ssh *, const char *, const char *,
+ void ssh_kill_proxy_command(void);
+
+ void ssh_login(struct ssh *, Sensitive *, const char *,
+- struct sockaddr *, u_short, struct passwd *, int,
++ struct sockaddr_storage *, u_short, struct passwd *, int,
+ const struct ssh_conn_info *);
+
+ int verify_host_key(char *, struct sockaddr *, struct sshkey *,
+@@ -80,7 +80,7 @@ int verify_host_key(char *, struct sockaddr *, struct sshkey *,
+ void get_hostfile_hostname_ipaddr(char *, struct sockaddr *, u_short,
+ char **, char **);
+
+-void ssh_kex2(struct ssh *ssh, char *, struct sockaddr *, u_short,
++void ssh_kex2(struct ssh *ssh, char *, struct sockaddr_storage *, u_short,
+ const struct ssh_conn_info *);
+
+ void ssh_userauth2(struct ssh *ssh, const char *, const char *,
+@@ -94,3 +94,6 @@ void maybe_add_key_to_agent(const char *, struct sshkey *,
+ void load_hostkeys_command(struct hostkeys *, const char *,
+ const char *, const struct ssh_conn_info *,
+ const struct sshkey *, const char *);
++
++void ssh_conn_info_free(struct ssh_conn_info *);
++struct ssh_conn_info *ssh_conn_info_dup(const struct ssh_conn_info *);
+diff --git a/sshconnect2.c b/sshconnect2.c
+index a296c9b8c..9efb3da8a 100644
+--- a/sshconnect2.c
++++ b/sshconnect2.c
+@@ -89,7 +89,7 @@ extern Options options;
+ */
+
+ static char *xxx_host;
+-static struct sockaddr *xxx_hostaddr;
++static struct sockaddr_storage xxx_hostaddr;
+ static const struct ssh_conn_info *xxx_conn_info;
+ static int key_type_allowed(struct sshkey *, const char *);
+
+@@ -105,7 +105,7 @@ verify_host_key_callback(struct sshkey *hostkey, struct ssh *ssh)
+ fatal("Server host key %s not in HostKeyAlgorithms",
+ sshkey_ssh_name(hostkey));
+ }
+- if (verify_host_key(xxx_host, xxx_hostaddr, hostkey,
++ if (verify_host_key(xxx_host, (struct sockaddr *)&xxx_hostaddr, hostkey,
+ xxx_conn_info) != 0)
+ fatal("Host key verification failed.");
+ return 0;
+@@ -222,16 +222,16 @@ order_hostkeyalgs(char *host, struct sockaddr *hostaddr, u_short port,
+ }
+
+ void
+-ssh_kex2(struct ssh *ssh, char *host, struct sockaddr *hostaddr, u_short port,
+- const struct ssh_conn_info *cinfo)
++ssh_kex2(struct ssh *ssh, char *host, struct sockaddr_storage *hostaddr,
++ u_short port, const struct ssh_conn_info *cinfo)
+ {
+ char *myproposal[PROPOSAL_MAX];
+ char *s, *all_key, *hkalgs = NULL;
+ int r, use_known_hosts_order = 0;
+
+- xxx_host = host;
+- xxx_hostaddr = hostaddr;
+- xxx_conn_info = cinfo;
++ xxx_host = xstrdup(host);
++ xxx_hostaddr = *hostaddr;
++ xxx_conn_info = ssh_conn_info_dup(cinfo);
+
+ if (options.rekey_limit || options.rekey_interval)
+ ssh_packet_set_rekey_limits(ssh, options.rekey_limit,
+@@ -257,8 +257,10 @@ ssh_kex2(struct ssh *ssh, char *host, struct sockaddr *hostaddr, u_short port,
+ if ((s = kex_names_cat(options.kex_algorithms, "ext-info-c")) == NULL)
+ fatal_f("kex_names_cat");
+
+- if (use_known_hosts_order)
+- hkalgs = order_hostkeyalgs(host, hostaddr, port, cinfo);
++ if (use_known_hosts_order) {
++ hkalgs = order_hostkeyalgs(host, (struct sockaddr *)hostaddr,
++ port, cinfo);
++ }
+
+ kex_proposal_populate_entries(ssh, myproposal, s, options.ciphers,
+ options.macs, compression_alg_list(options.compression),
diff --git a/meta/recipes-connectivity/openssh/openssh_9.6p1.bb b/meta/recipes-connectivity/openssh/openssh_9.6p1.bb
index 0d9d33c4597..708399e8022 100644
--- a/meta/recipes-connectivity/openssh/openssh_9.6p1.bb
+++ b/meta/recipes-connectivity/openssh/openssh_9.6p1.bb
@@ -42,6 +42,7 @@ SRC_URI = "http://ftp.openbsd.org/pub/OpenBSD/OpenSSH/portable/openssh-${PV}.tar
file://CVE-2026-59996.patch \
file://CVE-2026-59995.patch \
file://CVE-2026-60001.patch \
+ file://CVE-2026-60002.patch \
"
SRC_URI[sha256sum] = "910211c07255a8c5ad654391b40ee59800710dd8119dd5362de09385aa7a777c"
^ permalink raw reply related [flat|nested] 32+ messages in thread
* [OE-core][scarthgap 12/31] openssh: Fix CVE-2026-60000
2026-07-26 8:29 [OE-core][scarthgap 00/31] Patch review Yoann Congal
` (10 preceding siblings ...)
2026-07-26 8:29 ` [OE-core][scarthgap 11/31] openssh: Fix CVE-2026-60002 Yoann Congal
@ 2026-07-26 8:29 ` Yoann Congal
2026-07-26 8:29 ` [OE-core][scarthgap 13/31] cups: fix CVE-2026-27447 Yoann Congal
` (18 subsequent siblings)
30 siblings, 0 replies; 32+ messages in thread
From: Yoann Congal @ 2026-07-26 8:29 UTC (permalink / raw)
To: openembedded-core
From: Devansh Patel <devanshp@cisco.com>
This patch applies the upstream OpenSSH 10.4 backport for
CVE-2026-60000. The upstream fix commit is referenced in [1],
and the public CVE advisory is referenced in [2].
[1] https://github.com/openssh/openssh-portable/commit/5d04ca6af739b82fd30d84d2783ca802ebfa1192
[2] https://nvd.nist.gov/vuln/detail/CVE-2026-60000
Signed-off-by: Devansh Patel <devanshp@cisco.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
---
.../openssh/openssh/CVE-2026-60000.patch | 140 ++++++++++++++++++
.../openssh/openssh_9.6p1.bb | 1 +
2 files changed, 141 insertions(+)
create mode 100644 meta/recipes-connectivity/openssh/openssh/CVE-2026-60000.patch
diff --git a/meta/recipes-connectivity/openssh/openssh/CVE-2026-60000.patch b/meta/recipes-connectivity/openssh/openssh/CVE-2026-60000.patch
new file mode 100644
index 00000000000..9c25786ced0
--- /dev/null
+++ b/meta/recipes-connectivity/openssh/openssh/CVE-2026-60000.patch
@@ -0,0 +1,140 @@
+From 055316632809a2e2e58eac2020699b52187d1b11 Mon Sep 17 00:00:00 2001
+From: "djm@openbsd.org" <djm@openbsd.org>
+Date: Mon, 6 Jul 2026 07:53:30 +0000
+Subject: [PATCH] upstream: Fix multiple RFC 4462 (GSSAPIAuthentication)
+ compliance
+
+problems
+
+1) Remove an early failure return for GSSAPI authentication attempts
+made for invalid accounts that yielded different behaviour for
+valid vs invalid accounts.
+
+2) Fix a situation where some GSSAPI requestes were not correctly
+subjected to MaxAuthTries.
+
+3) Fix a moderate pre-authentication resource DoS related to #2.
+
+Add missing logging for error cases.
+
+Report and fixes from Manfred Kaiser, milCERT AT
+
+CVE: CVE-2026-60000
+Upstream-Status: Backport [https://github.com/openssh/openssh-portable/commit/5d04ca6af739b82fd30d84d2783ca802ebfa1192]
+
+Backport Changes:
+- Kept Scarthgap's PRIVSEP(ssh_gssapi_server_ctx()) interface and its
+ authentication-context guard while applying the upstream RFC 4462 state,
+ failure, logging, and MaxAuthTries changes.
+- Retained the Scarthgap auth2-gss.c OpenBSD revision identifier.
+
+OpenBSD-Commit-ID: ca0acdd64eea435d6f89534538a9eb404a5629d3
+(cherry picked from commit 5d04ca6af739b82fd30d84d2783ca802ebfa1192)
+Signed-off-by: Devansh Patel <devanshp@cisco.com>
+---
+ auth2-gss.c | 53 ++++++++++++++++++++++++-----------------------------
+ 1 file changed, 24 insertions(+), 29 deletions(-)
+
+diff --git a/auth2-gss.c b/auth2-gss.c
+index 195578bcf..6846eae5b 100644
+--- a/auth2-gss.c
++++ b/auth2-gss.c
+@@ -110,12 +110,6 @@ userauth_gssapi(struct ssh *ssh, const char *method)
+ return (0);
+ }
+
+- if (!authctxt->valid || authctxt->user == NULL) {
+- debug2_f("disabled because of invalid user");
+- free(doid);
+- return (0);
+- }
+-
+ if (GSS_ERROR(PRIVSEP(ssh_gssapi_server_ctx(&ctxt, &goid)))) {
+ if (ctxt != NULL)
+ ssh_gssapi_delete_ctx(&ctxt);
+@@ -177,8 +171,14 @@ input_gssapi_token(int type, u_int32_t plen, struct ssh *ssh)
+ (r = sshpkt_send(ssh)) != 0)
+ fatal_fr(r, "send ERRTOK packet");
+ }
++ logit("Failed gssapi-with-mic for %s%.100s "
++ "from %.200s port %d ssh2",
++ authctxt->valid ? "" : "invalid user ",
++ authctxt->user,
++ ssh_remote_ipaddr(ssh), ssh_remote_port(ssh));
+ authctxt->postponed = 0;
+ ssh_dispatch_set(ssh, SSH2_MSG_USERAUTH_GSSAPI_TOKEN, NULL);
++ ssh_dispatch_set(ssh, SSH2_MSG_USERAUTH_GSSAPI_ERRTOK, NULL);
+ userauth_finish(ssh, 0, "gssapi-with-mic", NULL);
+ } else {
+ if (send_tok.length != 0) {
+@@ -190,14 +190,18 @@ input_gssapi_token(int type, u_int32_t plen, struct ssh *ssh)
+ fatal_fr(r, "send TOKEN packet");
+ }
+ if (maj_status == GSS_S_COMPLETE) {
+- ssh_dispatch_set(ssh, SSH2_MSG_USERAUTH_GSSAPI_TOKEN, NULL);
+- if (flags & GSS_C_INTEG_FLAG)
+- ssh_dispatch_set(ssh, SSH2_MSG_USERAUTH_GSSAPI_MIC,
++ ssh_dispatch_set(ssh,
++ SSH2_MSG_USERAUTH_GSSAPI_TOKEN, NULL);
++ /* note: keep ERRTOK handler as per RFC 4462 s3.4 */
++ if (flags & GSS_C_INTEG_FLAG) {
++ ssh_dispatch_set(ssh,
++ SSH2_MSG_USERAUTH_GSSAPI_MIC,
+ &input_gssapi_mic);
+- else
++ } else {
+ ssh_dispatch_set(ssh,
+ SSH2_MSG_USERAUTH_GSSAPI_EXCHANGE_COMPLETE,
+ &input_gssapi_exchange_complete);
++ }
+ }
+ }
+
+@@ -209,10 +213,6 @@ static int
+ input_gssapi_errtok(int type, u_int32_t plen, struct ssh *ssh)
+ {
+ Authctxt *authctxt = ssh->authctxt;
+- Gssctxt *gssctxt;
+- gss_buffer_desc send_tok = GSS_C_EMPTY_BUFFER;
+- gss_buffer_desc recv_tok;
+- OM_uint32 maj_status;
+ int r;
+ u_char *p;
+ size_t len;
+@@ -220,26 +220,21 @@ input_gssapi_errtok(int type, u_int32_t plen, struct ssh *ssh)
+ if (authctxt == NULL || (authctxt->methoddata == NULL && !use_privsep))
+ fatal("No authentication or GSSAPI context");
+
+- gssctxt = authctxt->methoddata;
+- if ((r = sshpkt_get_string(ssh, &p, &len)) != 0 ||
++ /* Minimal error handling - just cancel auth and return FAILURE */
++ if ((r = sshpkt_get_string_direct(ssh, NULL, NULL)) != 0 ||
+ (r = sshpkt_get_end(ssh)) != 0)
+ fatal_fr(r, "parse packet");
+- recv_tok.value = p;
+- recv_tok.length = len;
+-
+- /* Push the error token into GSSAPI to see what it says */
+- maj_status = PRIVSEP(ssh_gssapi_accept_ctx(gssctxt, &recv_tok,
+- &send_tok, NULL));
+-
+- free(recv_tok.value);
+
+- /* We can't return anything to the client, even if we wanted to */
++ logit("Failed gssapi-with-mic for %s%.100s from %.200s port %d ssh2",
++ authctxt->valid ? "" : "invalid user ",
++ authctxt->user,
++ ssh_remote_ipaddr(ssh), ssh_remote_port(ssh));
++ authctxt->postponed = 0;
+ ssh_dispatch_set(ssh, SSH2_MSG_USERAUTH_GSSAPI_TOKEN, NULL);
+ ssh_dispatch_set(ssh, SSH2_MSG_USERAUTH_GSSAPI_ERRTOK, NULL);
+-
+- /* The client will have already moved on to the next auth */
+-
+- gss_release_buffer(&maj_status, &send_tok);
++ ssh_dispatch_set(ssh, SSH2_MSG_USERAUTH_GSSAPI_MIC, NULL);
++ ssh_dispatch_set(ssh, SSH2_MSG_USERAUTH_GSSAPI_EXCHANGE_COMPLETE, NULL);
++ userauth_finish(ssh, 0, "gssapi-with-mic", NULL);
+ return 0;
+ }
+
diff --git a/meta/recipes-connectivity/openssh/openssh_9.6p1.bb b/meta/recipes-connectivity/openssh/openssh_9.6p1.bb
index 708399e8022..ba8aaad9bbb 100644
--- a/meta/recipes-connectivity/openssh/openssh_9.6p1.bb
+++ b/meta/recipes-connectivity/openssh/openssh_9.6p1.bb
@@ -43,6 +43,7 @@ SRC_URI = "http://ftp.openbsd.org/pub/OpenBSD/OpenSSH/portable/openssh-${PV}.tar
file://CVE-2026-59995.patch \
file://CVE-2026-60001.patch \
file://CVE-2026-60002.patch \
+ file://CVE-2026-60000.patch \
"
SRC_URI[sha256sum] = "910211c07255a8c5ad654391b40ee59800710dd8119dd5362de09385aa7a777c"
^ permalink raw reply related [flat|nested] 32+ messages in thread
* [OE-core][scarthgap 13/31] cups: fix CVE-2026-27447
2026-07-26 8:29 [OE-core][scarthgap 00/31] Patch review Yoann Congal
` (11 preceding siblings ...)
2026-07-26 8:29 ` [OE-core][scarthgap 12/31] openssh: Fix CVE-2026-60000 Yoann Congal
@ 2026-07-26 8:29 ` Yoann Congal
2026-07-26 8:29 ` [OE-core][scarthgap 14/31] cups: fix CVE-2026-41079 Yoann Congal
` (17 subsequent siblings)
30 siblings, 0 replies; 32+ messages in thread
From: Yoann Congal @ 2026-07-26 8:29 UTC (permalink / raw)
To: openembedded-core
From: Deepak Rathore <deeratho@cisco.com>
Pick the upstream backport [1] for CVE-2026-27447 as mentioned in [2], where
the scheduler treated local user and group names as case-insensitive.
Also include the two upstream regression fixes that followed the CVE
fix:
- CVE-2026-27447-regression_p1.patch [3] fixes a cupsd crash when the
referenced user does not exist on the server. This regression was
reported in OpenPrinting/cups Issue [5].
- CVE-2026-27447-regression_p2.patch [4] fixes unauthenticated print
policies for non-local accounts. This regression was reported in
OpenPrinting/cups Issue [6].
[1] https://github.com/OpenPrinting/cups/commit/a0c62c1e69604ff061089b750073199fab5a1beb
[2] https://security-tracker.debian.org/tracker/CVE-2026-27447
[3] https://github.com/OpenPrinting/cups/commit/6d97ee39fedf12a7a5429a74f4156ef9bb67f562
[4] https://github.com/OpenPrinting/cups/commit/849fba7d7a1144e48d45c5e6ba2504765912ece0
[5] https://github.com/OpenPrinting/cups/issues/1555
[6] https://github.com/OpenPrinting/cups/issues/1557
Signed-off-by: Deepak Rathore <deeratho@cisco.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
---
meta/recipes-extended/cups/cups.inc | 3 +
.../cups/CVE-2026-27447-regression_p1.patch | 33 ++++++
.../cups/CVE-2026-27447-regression_p2.patch | 46 ++++++++
.../cups/cups/CVE-2026-27447.patch | 108 ++++++++++++++++++
4 files changed, 190 insertions(+)
create mode 100644 meta/recipes-extended/cups/cups/CVE-2026-27447-regression_p1.patch
create mode 100644 meta/recipes-extended/cups/cups/CVE-2026-27447-regression_p2.patch
create mode 100644 meta/recipes-extended/cups/cups/CVE-2026-27447.patch
diff --git a/meta/recipes-extended/cups/cups.inc b/meta/recipes-extended/cups/cups.inc
index c7475d2b813..ec9392b73dd 100644
--- a/meta/recipes-extended/cups/cups.inc
+++ b/meta/recipes-extended/cups/cups.inc
@@ -20,6 +20,9 @@ SRC_URI = "${GITHUB_BASE_URI}/download/v${PV}/cups-${PV}-source.tar.gz \
file://CVE-2025-58436.patch \
file://CVE-2025-61915.patch \
file://0001-conf.c-Fix-stopping-scheduler-on-unknown-directive.patch \
+ file://CVE-2026-27447.patch \
+ file://CVE-2026-27447-regression_p1.patch \
+ file://CVE-2026-27447-regression_p2.patch \
"
GITHUB_BASE_URI = "https://github.com/OpenPrinting/cups/releases"
diff --git a/meta/recipes-extended/cups/cups/CVE-2026-27447-regression_p1.patch b/meta/recipes-extended/cups/cups/CVE-2026-27447-regression_p1.patch
new file mode 100644
index 00000000000..d581ee36fdf
--- /dev/null
+++ b/meta/recipes-extended/cups/cups/CVE-2026-27447-regression_p1.patch
@@ -0,0 +1,33 @@
+From 6d97ee39fedf12a7a5429a74f4156ef9bb67f562 Mon Sep 17 00:00:00 2001
+From: Zdenek Dohnal <zdohnal@redhat.com>
+Date: Wed, 22 Apr 2026 12:40:14 +0200
+Subject: [PATCH] Fix cupsd crash if user does not exist on server
+
+CVE: CVE-2026-27447
+Upstream-Status: Backport [https://github.com/OpenPrinting/cups/commit/6d97ee39fedf12a7a5429a74f4156ef9bb67f562]
+
+Backport Changes:
+- Omit the upstream CHANGES.md release-note hunk because Yocto patch metadata
+ carries the CVE details and the target source release-note sections differ.
+
+(cherry picked from commit 6d97ee39fedf12a7a5429a74f4156ef9bb67f562)
+Signed-off-by: Deepak Rathore <deeratho@cisco.com>
+---
+ scheduler/auth.c | 2 +-
+ 1 file changed, 1 insertion(+), 1 deletion(-)
+
+diff --git a/scheduler/auth.c b/scheduler/auth.c
+index 1678a29..4798e86 100644
+--- a/scheduler/auth.c
++++ b/scheduler/auth.c
+@@ -1810,7 +1810,7 @@ cupsdIsAuthorized(cupsd_client_t *con, /* I - Connection */
+ name;
+ name = (char *)cupsArrayNext(best->names))
+ {
+- if (!_cups_strcasecmp(name, "@OWNER") && owner &&
++ if (!_cups_strcasecmp(name, "@OWNER") && owner && pw &&
+ !strcmp(pw->pw_name, ownername))
+ return (HTTP_OK);
+ else if (!_cups_strcasecmp(name, "@SYSTEM"))
+--
+2.43.7
diff --git a/meta/recipes-extended/cups/cups/CVE-2026-27447-regression_p2.patch b/meta/recipes-extended/cups/cups/CVE-2026-27447-regression_p2.patch
new file mode 100644
index 00000000000..e46db92c760
--- /dev/null
+++ b/meta/recipes-extended/cups/cups/CVE-2026-27447-regression_p2.patch
@@ -0,0 +1,46 @@
+From 849fba7d7a1144e48d45c5e6ba2504765912ece0 Mon Sep 17 00:00:00 2001
+From: Michael R Sweet <msweet@msweet.org>
+Date: Fri, 24 Apr 2026 14:06:06 -0400
+Subject: [PATCH] Fix unauthenticated print policies (Issue #1557)
+
+CVE: CVE-2026-27447
+Upstream-Status: Backport [https://github.com/OpenPrinting/cups/commit/849fba7d7a1144e48d45c5e6ba2504765912ece0]
+
+Backport Changes:
+- Omit the upstream CHANGES.md release-note hunk because Yocto patch metadata
+ carries the CVE details and the target source release-note sections differ.
+
+(cherry picked from commit 849fba7d7a1144e48d45c5e6ba2504765912ece0)
+Signed-off-by: Deepak Rathore <deeratho@cisco.com>
+---
+ scheduler/auth.c | 7 +++++--
+ 1 file changed, 5 insertions(+), 2 deletions(-)
+
+diff --git a/scheduler/auth.c b/scheduler/auth.c
+index 4798e86..1dd520d 100644
+--- a/scheduler/auth.c
++++ b/scheduler/auth.c
+@@ -1810,8 +1810,9 @@ cupsdIsAuthorized(cupsd_client_t *con, /* I - Connection */
+ name;
+ name = (char *)cupsArrayNext(best->names))
+ {
+- if (!_cups_strcasecmp(name, "@OWNER") && owner && pw &&
+- !strcmp(pw->pw_name, ownername))
++ if (!_cups_strcasecmp(name, "@OWNER") && owner &&
++ ((pw && !strcmp(pw->pw_name, ownername)) ||
++ (!pw && type == CUPSD_AUTH_NONE && !_cups_strcasecmp(username, ownername))))
+ return (HTTP_OK);
+ else if (!_cups_strcasecmp(name, "@SYSTEM"))
+ {
+@@ -1825,6 +1826,8 @@ cupsdIsAuthorized(cupsd_client_t *con, /* I - Connection */
+ }
+ else if (pw && !strcmp(pw->pw_name, name))
+ return (HTTP_OK);
++ else if (!pw && type == CUPSD_AUTH_NONE && !_cups_strcasecmp(username, name))
++ return (HTTP_STATUS_OK);
+ }
+
+ for (name = (char *)cupsArrayFirst(best->names);
+--
+2.43.7
+
diff --git a/meta/recipes-extended/cups/cups/CVE-2026-27447.patch b/meta/recipes-extended/cups/cups/CVE-2026-27447.patch
new file mode 100644
index 00000000000..1614faa7f17
--- /dev/null
+++ b/meta/recipes-extended/cups/cups/CVE-2026-27447.patch
@@ -0,0 +1,108 @@
+From 37b8a4387864eded1a15a45db8950a23e5c610d2 Mon Sep 17 00:00:00 2001
+From: Michael R Sweet <msweet@msweet.org>
+Date: Tue, 31 Mar 2026 14:04:21 -0400
+Subject: [PATCH] CVE-2026-27447: The scheduler treated local user and group
+ names as case-insensitive.
+
+CVE: CVE-2026-27447
+Upstream-Status: Backport [https://github.com/OpenPrinting/cups/commit/a0c62c1e69604ff061089b750073199fab5a1beb]
+
+Backport Changes:
+- Rebase scheduler/auth.c context to the CUPS 2.4.11 source carried by this
+ recipe.
+- Omit the upstream CHANGES.md release-note hunk because Yocto patch metadata
+ carries the CVE details and the target source release-note sections differ.
+
+(cherry picked from commit a0c62c1e69604ff061089b750073199fab5a1beb)
+Signed-off-by: Deepak Rathore <deeratho@cisco.com>
+---
+ scheduler/auth.c | 31 +++++++++++++++----------------
+ 1 file changed, 15 insertions(+), 16 deletions(-)
+
+diff --git a/scheduler/auth.c b/scheduler/auth.c
+index d0430b4..1678a29 100644
+--- a/scheduler/auth.c
++++ b/scheduler/auth.c
+@@ -1,7 +1,7 @@
+ /*
+ * Authorization routines for the CUPS scheduler.
+ *
+- * Copyright © 2020-2024 by OpenPrinting.
++ * Copyright © 2020-2026 by OpenPrinting.
+ * Copyright © 2007-2019 by Apple Inc.
+ * Copyright © 1997-2007 by Easy Software Products, all rights reserved.
+ *
+@@ -1159,7 +1159,7 @@ cupsdCheckGroup(
+ group = getgrnam(groupname);
+ endgrent();
+
+- if (group != NULL)
++ if (user && group)
+ {
+ /*
+ * Group exists, check it...
+@@ -1173,7 +1173,7 @@ cupsdCheckGroup(
+ * User appears in the group membership...
+ */
+
+- if (!_cups_strcasecmp(username, group->gr_mem[i]))
++ if (!strcmp(user->pw_name, group->gr_mem[i]))
+ return (1);
+ }
+
+@@ -1184,25 +1184,24 @@ cupsdCheckGroup(
+ * belongs to...
+ */
+
+- if (user)
+- {
+- int ngroups; /* Number of groups */
++ int ngroups; /* Number of groups */
+ # ifdef __APPLE__
+- int groups[2048]; /* Groups that user belongs to */
++ int groups[2048]; /* Groups that user belongs to */
+ # else
+- gid_t groups[2048]; /* Groups that user belongs to */
++ gid_t groups[2048]; /* Groups that user belongs to */
+ # endif /* __APPLE__ */
+
+- ngroups = (int)(sizeof(groups) / sizeof(groups[0]));
++ ngroups = (int)(sizeof(groups) / sizeof(groups[0]));
+ # ifdef __APPLE__
+- getgrouplist(username, (int)user->pw_gid, groups, &ngroups);
++ getgrouplist(user->pw_name, (int)user->pw_gid, groups, &ngroups);
+ # else
+- getgrouplist(username, user->pw_gid, groups, &ngroups);
++ getgrouplist(user->pw_name, user->pw_gid, groups, &ngroups);
+ #endif /* __APPLE__ */
+
+- for (i = 0; i < ngroups; i ++)
+- if ((int)groupid == (int)groups[i])
+- return (1);
++ for (i = 0; i < ngroups; i ++)
++ {
++ if ((int)groupid == (int)groups[i])
++ return (1);
+ }
+ #endif /* HAVE_GETGROUPLIST */
+ }
+@@ -1812,7 +1811,7 @@ cupsdIsAuthorized(cupsd_client_t *con, /* I - Connection */
+ name = (char *)cupsArrayNext(best->names))
+ {
+ if (!_cups_strcasecmp(name, "@OWNER") && owner &&
+- !_cups_strcasecmp(username, ownername))
++ !strcmp(pw->pw_name, ownername))
+ return (HTTP_OK);
+ else if (!_cups_strcasecmp(name, "@SYSTEM"))
+ {
+@@ -1824,7 +1823,7 @@ cupsdIsAuthorized(cupsd_client_t *con, /* I - Connection */
+ if (cupsdCheckGroup(username, pw, name + 1))
+ return (HTTP_OK);
+ }
+- else if (!_cups_strcasecmp(username, name))
++ else if (pw && !strcmp(pw->pw_name, name))
+ return (HTTP_OK);
+ }
+
+--
+2.43.7
^ permalink raw reply related [flat|nested] 32+ messages in thread
* [OE-core][scarthgap 14/31] cups: fix CVE-2026-41079
2026-07-26 8:29 [OE-core][scarthgap 00/31] Patch review Yoann Congal
` (12 preceding siblings ...)
2026-07-26 8:29 ` [OE-core][scarthgap 13/31] cups: fix CVE-2026-27447 Yoann Congal
@ 2026-07-26 8:29 ` Yoann Congal
2026-07-26 8:29 ` [OE-core][scarthgap 15/31] cups: fix CVE-2026-34978 Yoann Congal
` (16 subsequent siblings)
30 siblings, 0 replies; 32+ messages in thread
From: Yoann Congal @ 2026-07-26 8:29 UTC (permalink / raw)
To: openembedded-core
From: Deepak Rathore <deeratho@cisco.com>
Pick the upstream fix [1] for CVE-2026-41079 as referenced by Debian [2].
[1] https://github.com/OpenPrinting/cups/commit/b7c2525a885f528d243c3a92197ca99609b3f080
[2] https://security-tracker.debian.org/tracker/CVE-2026-41079
Signed-off-by: Deepak Rathore <deeratho@cisco.com>
[YC: reverted modified indentation in imported patch]
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
---
meta/recipes-extended/cups/cups.inc | 1 +
.../cups/cups/CVE-2026-41079.patch | 71 +++++++++++++++++++
2 files changed, 72 insertions(+)
create mode 100644 meta/recipes-extended/cups/cups/CVE-2026-41079.patch
diff --git a/meta/recipes-extended/cups/cups.inc b/meta/recipes-extended/cups/cups.inc
index ec9392b73dd..f74bcaffab5 100644
--- a/meta/recipes-extended/cups/cups.inc
+++ b/meta/recipes-extended/cups/cups.inc
@@ -23,6 +23,7 @@ SRC_URI = "${GITHUB_BASE_URI}/download/v${PV}/cups-${PV}-source.tar.gz \
file://CVE-2026-27447.patch \
file://CVE-2026-27447-regression_p1.patch \
file://CVE-2026-27447-regression_p2.patch \
+ file://CVE-2026-41079.patch \
"
GITHUB_BASE_URI = "https://github.com/OpenPrinting/cups/releases"
diff --git a/meta/recipes-extended/cups/cups/CVE-2026-41079.patch b/meta/recipes-extended/cups/cups/CVE-2026-41079.patch
new file mode 100644
index 00000000000..87a7e42316b
--- /dev/null
+++ b/meta/recipes-extended/cups/cups/CVE-2026-41079.patch
@@ -0,0 +1,71 @@
+From a331e93e2f9baf411715ef69ae19b73827da23d7 Mon Sep 17 00:00:00 2001
+From: Michael R Sweet <msweet@msweet.org>
+Date: Mon, 13 Apr 2026 11:50:23 -0400
+Subject: [PATCH] Limit num_bytes for SNMP string values.
+
+CVE: CVE-2026-41079
+Upstream-Status: Backport [https://github.com/OpenPrinting/cups/commit/b7c2525a885f528d243c3a92197ca99609b3f080]
+
+(cherry picked from commit b7c2525a885f528d243c3a92197ca99609b3f080)
+Signed-off-by: Deepak Rathore <deeratho@cisco.com>
+---
+ cups/snmp-private.h | 6 +++---
+ cups/snmp.c | 8 ++++++--
+ 2 files changed, 9 insertions(+), 5 deletions(-)
+
+diff --git a/cups/snmp-private.h b/cups/snmp-private.h
+index 52b8740..015f53e 100644
+--- a/cups/snmp-private.h
++++ b/cups/snmp-private.h
+@@ -1,7 +1,7 @@
+ /*
+ * Private SNMP definitions for CUPS.
+ *
+- * Copyright © 2020-2024 by OpenPrinting.
++ * Copyright © 2020-2026 by OpenPrinting.
+ * Copyright © 2007-2014 by Apple Inc.
+ * Copyright © 2006-2007 by Easy Software Products, all rights reserved.
+ *
+@@ -58,9 +58,9 @@ typedef enum cups_asn1_e cups_asn1_t; /**** ASN1 request/object types ****/
+
+ typedef struct cups_snmp_string_s /**** String value ****/
+ {
+- unsigned char bytes[CUPS_SNMP_MAX_STRING];
+- /* Bytes in string */
+ unsigned num_bytes; /* Number of bytes */
++ unsigned char bytes[CUPS_SNMP_MAX_STRING + 1];
++ /* Bytes in string */
+ } cups_snmp_string_t;
+
+ union cups_snmp_value_u /**** Object value ****/
+diff --git a/cups/snmp.c b/cups/snmp.c
+index 54e348f..2fcb38d 100644
+--- a/cups/snmp.c
++++ b/cups/snmp.c
+@@ -1,7 +1,7 @@
+ /*
+ * SNMP functions for CUPS.
+ *
+- * Copyright © 2020-2024 by OpenPrinting.
++ * Copyright © 2020-2026 by OpenPrinting.
+ * Copyright © 2007-2019 by Apple Inc.
+ * Copyright © 2006-2007 by Easy Software Products, all rights reserved.
+ *
+@@ -1042,10 +1042,14 @@ asn1_decode_snmp(unsigned char *buffer, /* I - Buffer */
+ case CUPS_ASN1_OCTET_STRING :
+ case CUPS_ASN1_BIT_STRING :
+ case CUPS_ASN1_HEX_STRING :
+- packet->object_value.string.num_bytes = length;
+ asn1_get_string(&bufptr, bufend, length,
+ (char *)packet->object_value.string.bytes,
+ sizeof(packet->object_value.string.bytes));
++
++ if (length >= sizeof(packet->object_value.string.bytes))
++ packet->object_value.string.num_bytes = sizeof(packet->object_value.string.bytes) - 1;
++ else
++ packet->object_value.string.num_bytes = length;
+ break;
+
+ case CUPS_ASN1_OID :
+--
+2.43.7
^ permalink raw reply related [flat|nested] 32+ messages in thread
* [OE-core][scarthgap 15/31] cups: fix CVE-2026-34978
2026-07-26 8:29 [OE-core][scarthgap 00/31] Patch review Yoann Congal
` (13 preceding siblings ...)
2026-07-26 8:29 ` [OE-core][scarthgap 14/31] cups: fix CVE-2026-41079 Yoann Congal
@ 2026-07-26 8:29 ` Yoann Congal
2026-07-26 8:29 ` [OE-core][scarthgap 16/31] cups: fix CVE-2026-34980 Yoann Congal
` (15 subsequent siblings)
30 siblings, 0 replies; 32+ messages in thread
From: Yoann Congal @ 2026-07-26 8:29 UTC (permalink / raw)
To: openembedded-core
From: Deepak Rathore <deeratho@cisco.com>
Pick the upstream patch [1] as mentioned in [2].
[1] https://github.com/OpenPrinting/cups/commit/730347c5bbd5e1271149c6739aa858c0c83a7568
[2] https://security-tracker.debian.org/tracker/CVE-2026-34978
Signed-off-by: Deepak Rathore <deeratho@cisco.com>
[YC: reverted upstream patch indentation]
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
---
meta/recipes-extended/cups/cups.inc | 1 +
.../cups/cups/CVE-2026-34978.patch | 107 ++++++++++++++++++
2 files changed, 108 insertions(+)
create mode 100644 meta/recipes-extended/cups/cups/CVE-2026-34978.patch
diff --git a/meta/recipes-extended/cups/cups.inc b/meta/recipes-extended/cups/cups.inc
index f74bcaffab5..5e272dbcf6b 100644
--- a/meta/recipes-extended/cups/cups.inc
+++ b/meta/recipes-extended/cups/cups.inc
@@ -24,6 +24,7 @@ SRC_URI = "${GITHUB_BASE_URI}/download/v${PV}/cups-${PV}-source.tar.gz \
file://CVE-2026-27447-regression_p1.patch \
file://CVE-2026-27447-regression_p2.patch \
file://CVE-2026-41079.patch \
+ file://CVE-2026-34978.patch \
"
GITHUB_BASE_URI = "https://github.com/OpenPrinting/cups/releases"
diff --git a/meta/recipes-extended/cups/cups/CVE-2026-34978.patch b/meta/recipes-extended/cups/cups/CVE-2026-34978.patch
new file mode 100644
index 00000000000..5929268f4fa
--- /dev/null
+++ b/meta/recipes-extended/cups/cups/CVE-2026-34978.patch
@@ -0,0 +1,107 @@
+From ab6ab965de6890aed4df39c97f7cd708fd5cb00c Mon Sep 17 00:00:00 2001
+From: Michael R Sweet <msweet@msweet.org>
+Date: Tue, 31 Mar 2026 14:18:26 -0400
+Subject: [PATCH] Fix RSS notifier.
+
+CVE: CVE-2026-34978
+Upstream-Status: Backport [https://github.com/OpenPrinting/cups/commit/730347c5bbd5e1271149c6739aa858c0c83a7568]
+
+Backport Changes:
+- Rebase scheduler/ipp.c subscription context to the CUPS 2.4.11 source
+ carried by this recipe.
+- Omit the upstream CHANGES.md release-note hunk because Yocto patch metadata
+ carries the CVE details and the target source release-note sections differ.
+- Omit the upstream scheduler/ipp.c copyright-year-only header update because
+ this backport carries only the functional changes needed for CUPS 2.4.11.
+
+(cherry picked from commit 730347c5bbd5e1271149c6739aa858c0c83a7568)
+Signed-off-by: Deepak Rathore <deeratho@cisco.com>
+---
+ notifier/rss.c | 20 ++++++++++++++------
+ scheduler/ipp.c | 12 ++++++++++++
+ 2 files changed, 26 insertions(+), 6 deletions(-)
+
+diff --git a/notifier/rss.c b/notifier/rss.c
+index f17e1494c..250ad877e 100644
+--- a/notifier/rss.c
++++ b/notifier/rss.c
+@@ -1,11 +1,12 @@
+ /*
+ * RSS notifier for CUPS.
+ *
+- * Copyright © 2020-2024 by OpenPrinting.
+- * Copyright 2007-2015 by Apple Inc.
+- * Copyright 2007 by Easy Software Products.
++ * Copyright © 2020-2026 by OpenPrinting.
++ * Copyright © 2007-2015 by Apple Inc.
++ * Copyright © 2007 by Easy Software Products.
+ *
+- * Licensed under Apache License v2.0. See the file "LICENSE" for more information.
++ * Licensed under Apache License v2.0. See the file "LICENSE" for more
++ * information.
+ */
+
+ /*
+@@ -80,6 +81,7 @@ main(int argc, /* I - Number of command-line arguments */
+ http_status_t status; /* HTTP GET/PUT status code */
+ char filename[1024], /* Local filename */
+ newname[1024]; /* filename.N */
++ struct stat fileinfo; /* Local file information */
+ cups_lang_t *language; /* Language information */
+ ipp_attribute_t *printer_up_time, /* Timestamp on event */
+ *notify_sequence_number,/* Sequence number */
+@@ -111,9 +113,9 @@ main(int argc, /* I - Number of command-line arguments */
+
+ if (httpSeparateURI(HTTP_URI_CODING_ALL, argv[1], scheme, sizeof(scheme),
+ username, sizeof(username), host, sizeof(host), &port,
+- resource, sizeof(resource)) < HTTP_URI_OK)
++ resource, sizeof(resource)) < HTTP_URI_OK || strstr(resource, "../") != NULL)
+ {
+- fprintf(stderr, "ERROR: Bad RSS URI \"%s\"!\n", argv[1]);
++ fprintf(stderr, "ERROR: Bad RSS URI \"%s\".\n", argv[1]);
+ return (1);
+ }
+
+@@ -209,6 +211,12 @@ main(int argc, /* I - Number of command-line arguments */
+ snprintf(filename, sizeof(filename), "%s/rss%s", cachedir, resource);
+ snprintf(newname, sizeof(newname), "%s.N", filename);
+
++ if (!lstat(filename, &fileinfo) && !S_ISREG(fileinfo.st_mode))
++ {
++ fprintf(stderr, "ERROR: Local RSS path \"%s\" is not a file.\n", filename);
++ return (1);
++ }
++
+ httpAssembleURIf(HTTP_URI_CODING_ALL, baseurl, sizeof(baseurl), "http",
+ NULL, server_name, atoi(server_port), "/rss%s", resource);
+ }
+diff --git a/scheduler/ipp.c b/scheduler/ipp.c
+index 2d80a960e..2dc7376c1 100644
+--- a/scheduler/ipp.c
++++ b/scheduler/ipp.c
+@@ -1985,6 +1985,12 @@ add_job_subscriptions(
+ "notify-status-code", IPP_ATTRIBUTES);
+ return;
+ }
++ else if (!strcmp(scheme, "rss") && strstr(resource, "../") != NULL)
++ {
++ send_ipp_status(con, IPP_STATUS_ERROR_NOT_POSSIBLE, _("Bad notify-recipient-uri URI \"%s\"."), recipient);
++ ippAddInteger(con->response, IPP_TAG_SUBSCRIPTION, IPP_TAG_ENUM, "notify-status-code", IPP_STATUS_ERROR_ATTRIBUTES_OR_VALUES);
++ return;
++ }
+ }
+ else if (!strcmp(attr->name, "notify-pull-method") &&
+ attr->value_tag == IPP_TAG_KEYWORD)
+@@ -6010,6 +6016,12 @@ create_subscriptions(
+ "notify-status-code", IPP_ATTRIBUTES);
+ return;
+ }
++ else if (!strcmp(scheme, "rss") && strstr(resource, "../") != NULL)
++ {
++ send_ipp_status(con, IPP_STATUS_ERROR_NOT_POSSIBLE, _("Bad notify-recipient-uri URI \"%s\"."), recipient);
++ ippAddInteger(con->response, IPP_TAG_SUBSCRIPTION, IPP_TAG_ENUM, "notify-status-code", IPP_STATUS_ERROR_ATTRIBUTES_OR_VALUES);
++ return;
++ }
+ }
+ else if (!strcmp(attr->name, "notify-pull-method") &&
+ attr->value_tag == IPP_TAG_KEYWORD)
^ permalink raw reply related [flat|nested] 32+ messages in thread
* [OE-core][scarthgap 16/31] cups: fix CVE-2026-34980
2026-07-26 8:29 [OE-core][scarthgap 00/31] Patch review Yoann Congal
` (14 preceding siblings ...)
2026-07-26 8:29 ` [OE-core][scarthgap 15/31] cups: fix CVE-2026-34978 Yoann Congal
@ 2026-07-26 8:29 ` Yoann Congal
2026-07-26 8:29 ` [OE-core][scarthgap 17/31] cups: fix CVE-2026-34979 Yoann Congal
` (14 subsequent siblings)
30 siblings, 0 replies; 32+ messages in thread
From: Yoann Congal @ 2026-07-26 8:29 UTC (permalink / raw)
To: openembedded-core
From: Deepak Rathore <deeratho@cisco.com>
Pick the upstream fix [1] for CVE-2026-34980 as mentioned in [2], where
the scheduler did not filter control characters from option values.
Also include the upstream regression fixes that followed the CVE fix:
- CVE-2026-34980-regression_p1.patch [3] fixes filter PPD keyword
processing. The CVE fix parsed PPD keywords into a temporary array,
but the loop did not advance the keyword pointer. This regression was
reported in OpenPrinting/cups Issue [4].
- CVE-2026-34980-regression_p2.patch [5] fixes a get_options() regression
where the option-value parser did not advance the input pointer for
whitespace/control-character paths.
[1] https://github.com/OpenPrinting/cups/commit/8d0f51cac24cb5bf949c5b6a221e51a150d982e3
[2] https://security-tracker.debian.org/tracker/CVE-2026-34980
[3] https://github.com/OpenPrinting/cups/commit/3f2bdc293243bca938c6de23ba50e6d783189629
[4] https://github.com/OpenPrinting/cups/issues/1562
[5] https://github.com/OpenPrinting/cups/commit/da0ff58c041f7ee129c3c2c72fb14df1f1e4069a
Signed-off-by: Deepak Rathore <deeratho@cisco.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
---
meta/recipes-extended/cups/cups.inc | 3 +
.../cups/CVE-2026-34980-regression_p1.patch | 31 +++++++
.../cups/CVE-2026-34980-regression_p2.patch | 75 ++++++++++++++++
.../cups/cups/CVE-2026-34980.patch | 85 +++++++++++++++++++
4 files changed, 194 insertions(+)
create mode 100644 meta/recipes-extended/cups/cups/CVE-2026-34980-regression_p1.patch
create mode 100644 meta/recipes-extended/cups/cups/CVE-2026-34980-regression_p2.patch
create mode 100644 meta/recipes-extended/cups/cups/CVE-2026-34980.patch
diff --git a/meta/recipes-extended/cups/cups.inc b/meta/recipes-extended/cups/cups.inc
index 5e272dbcf6b..7a8b845953c 100644
--- a/meta/recipes-extended/cups/cups.inc
+++ b/meta/recipes-extended/cups/cups.inc
@@ -25,6 +25,9 @@ SRC_URI = "${GITHUB_BASE_URI}/download/v${PV}/cups-${PV}-source.tar.gz \
file://CVE-2026-27447-regression_p2.patch \
file://CVE-2026-41079.patch \
file://CVE-2026-34978.patch \
+ file://CVE-2026-34980.patch \
+ file://CVE-2026-34980-regression_p1.patch \
+ file://CVE-2026-34980-regression_p2.patch \
"
GITHUB_BASE_URI = "https://github.com/OpenPrinting/cups/releases"
diff --git a/meta/recipes-extended/cups/cups/CVE-2026-34980-regression_p1.patch b/meta/recipes-extended/cups/cups/CVE-2026-34980-regression_p1.patch
new file mode 100644
index 00000000000..483d695a93a
--- /dev/null
+++ b/meta/recipes-extended/cups/cups/CVE-2026-34980-regression_p1.patch
@@ -0,0 +1,31 @@
+From 3f2bdc293243bca938c6de23ba50e6d783189629 Mon Sep 17 00:00:00 2001
+From: Michael R Sweet <msweet@msweet.org>
+Date: Tue, 28 Apr 2026 17:42:41 -0400
+Subject: [PATCH] Fix filter PPD keyword processing (Issue #1562)
+
+CVE: CVE-2026-34980
+Upstream-Status: Backport [https://github.com/OpenPrinting/cups/commit/3f2bdc293243bca938c6de23ba50e6d783189629]
+
+(cherry picked from commit 3f2bdc293243bca938c6de23ba50e6d783189629)
+Signed-off-by: Deepak Rathore <deeratho@cisco.com>
+---
+ scheduler/job.c | 2 +-
+ 1 file changed, 1 insertion(+), 1 deletion(-)
+
+diff --git a/scheduler/job.c b/scheduler/job.c
+index 895b2d9..915ba94 100644
+--- a/scheduler/job.c
++++ b/scheduler/job.c
+@@ -5419,7 +5419,7 @@ update_job(cupsd_job_t *job) /* I - Job to check */
+ keywords = NULL;
+ num_keywords = cupsParseOptions(message, 0, &keywords);
+
+- for (i = 0, keyword = keywords; i < num_keywords; i ++)
++ for (i = 0, keyword = keywords; i < num_keywords; i ++, keyword ++)
+ {
+ /*
+ * Filter out "special" PPD keywords...
+--
+2.43.7
+
+
diff --git a/meta/recipes-extended/cups/cups/CVE-2026-34980-regression_p2.patch b/meta/recipes-extended/cups/cups/CVE-2026-34980-regression_p2.patch
new file mode 100644
index 00000000000..739938c9a59
--- /dev/null
+++ b/meta/recipes-extended/cups/cups/CVE-2026-34980-regression_p2.patch
@@ -0,0 +1,75 @@
+From da0ff58c041f7ee129c3c2c72fb14df1f1e4069a Mon Sep 17 00:00:00 2001
+From: Michael R Sweet <msweet@msweet.org>
+Date: Wed, 8 Apr 2026 16:42:48 -0400
+Subject: [PATCH] Fix get_options regression (Issue #1532)
+
+CVE: CVE-2026-34980
+Upstream-Status: Backport [https://github.com/OpenPrinting/cups/commit/da0ff58c041f7ee129c3c2c72fb14df1f1e4069a]
+
+(cherry picked from commit da0ff58c041f7ee129c3c2c72fb14df1f1e4069a)
+Signed-off-by: Deepak Rathore <deeratho@cisco.com>
+---
+ scheduler/job.c | 4 ++--
+ test/5.5-lp.sh | 10 +++++-----
+ 2 files changed, 7 insertions(+), 7 deletions(-)
+
+diff --git a/scheduler/job.c b/scheduler/job.c
+index 6b9d366..cf019e1 100644
+--- a/scheduler/job.c
++++ b/scheduler/job.c
+@@ -4144,7 +4144,7 @@ get_options(cupsd_job_t *job, /* I - Job */
+ case IPP_TAG_CHARSET :
+ case IPP_TAG_LANGUAGE :
+ case IPP_TAG_URI :
+- for (valptr = attr->values[i].string.text; *valptr;)
++ for (valptr = attr->values[i].string.text; *valptr; valptr ++)
+ {
+ /*
+ * Convert tabs and newlines to spaces, filter out control chars,
+@@ -4159,7 +4159,7 @@ get_options(cupsd_job_t *job, /* I - Job */
+ {
+ if (strchr("\\\'\"", *valptr))
+ *optptr++ = '\\';
+- *optptr++ = *valptr++;
++ *optptr++ = *valptr;
+ }
+ }
+
+diff --git a/test/5.5-lp.sh b/test/5.5-lp.sh
+index 25e9d65..fe60890 100644
+--- a/test/5.5-lp.sh
++++ b/test/5.5-lp.sh
+@@ -2,7 +2,7 @@
+ #
+ # Test the lp command.
+ #
+-# Copyright © 2020-2024 by OpenPrinting.
++# Copyright © 2020-2026 by OpenPrinting.
+ # Copyright © 2007-2019 by Apple Inc.
+ # Copyright © 1997-2005 by Easy Software Products, all rights reserved.
+ #
+@@ -72,8 +72,8 @@ echo ""
+
+ echo "LP Flood Test ($1 times in parallel)"
+ echo ""
+-echo " lp -d Test1 testfile.jpg"
+-echo " lp -d Test2 testfile.jpg"
++echo " lp -d Test1 -t 'Flood Test N' testfile.jpg"
++echo " lp -d Test2 -t 'Flood Test N' testfile.jpg"
+ i=0
+ pids=""
+ while test $i -lt $1; do
+@@ -83,9 +83,9 @@ while test $i -lt $1; do
+ j=`expr $j + 1`
+ done
+
+- $runcups $VALGRIND ../systemv/lp -d Test1 ../examples/testfile.jpg 2>&1 &
++ $runcups $VALGRIND ../systemv/lp -d Test1 -t "Flood Test $j" ../examples/testfile.jpg 2>&1 &
+ pids="$pids $!"
+- $runcups $VALGRIND ../systemv/lp -d Test2 ../examples/testfile.jpg 2>&1 &
++ $runcups $VALGRIND ../systemv/lp -d Test2 -t "Flood Test $j" ../examples/testfile.jpg 2>&1 &
+ pids="$pids $!"
+
+ i=`expr $i + 1`
+--
+2.43.7
diff --git a/meta/recipes-extended/cups/cups/CVE-2026-34980.patch b/meta/recipes-extended/cups/cups/CVE-2026-34980.patch
new file mode 100644
index 00000000000..c38cc2c9e38
--- /dev/null
+++ b/meta/recipes-extended/cups/cups/CVE-2026-34980.patch
@@ -0,0 +1,85 @@
+From e206c7643a7574cab2e9457eac4c9f755dbf44ff Mon Sep 17 00:00:00 2001
+From: Michael R Sweet <msweet@msweet.org>
+Date: Tue, 31 Mar 2026 14:45:13 -0400
+Subject: [PATCH] Filter out control characters from option values.
+
+CVE: CVE-2026-34980
+Upstream-Status: Backport [https://github.com/OpenPrinting/cups/commit/8d0f51cac24cb5bf949c5b6a221e51a150d982e3]
+
+Backport Changes:
+- Rebase scheduler/job.c option-handling context to the CUPS 2.4.11
+ source carried by this recipe.
+- Omit the upstream CHANGES.md release-note hunk because Yocto patch metadata
+ carries the CVE details and the target source release-note sections differ.
+
+(cherry picked from commit 8d0f51cac24cb5bf949c5b6a221e51a150d982e3)
+Signed-off-by: Deepak Rathore <deeratho@cisco.com>
+---
+ scheduler/job.c | 41 +++++++++++++++++++++++++++++++++++------
+ 1 file changed, 35 insertions(+), 6 deletions(-)
+
+diff --git a/scheduler/job.c b/scheduler/job.c
+index 822a247..895b2d9 100644
+--- a/scheduler/job.c
++++ b/scheduler/job.c
+@@ -4121,9 +4121,21 @@ get_options(cupsd_job_t *job, /* I - Job */
+ case IPP_TAG_URI :
+ for (valptr = attr->values[i].string.text; *valptr;)
+ {
+- if (strchr(" \t\n\\\'\"", *valptr))
+- *optptr++ = '\\';
+- *optptr++ = *valptr++;
++ /*
++ * Convert tabs and newlines to spaces, filter out control chars,
++ * and escape \, ', and ".
++ */
++
++ if (isspace(*valptr & 255))
++ {
++ *optptr++ = ' ';
++ }
++ else if ((*valptr & 255) >= ' ' && *valptr != 0x7f)
++ {
++ if (strchr("\\\'\"", *valptr))
++ *optptr++ = '\\';
++ *optptr++ = *valptr++;
++ }
+ }
+
+ *optptr = '\0';
+@@ -5394,13 +5409,30 @@ update_job(cupsd_job_t *job) /* I - Job to check */
+ else if (loglevel == CUPSD_LOG_PPD)
+ {
+ /*
+- * Set attribute(s)...
++ * Set PPD keyword(s)/value(s)...
+ */
+
++ int i, /* Looping var */
++ num_keywords; /* Number of keywords */
++ cups_option_t *keywords, /* Keywords */
++ *keyword; /* Current keyword */
++
+ cupsdLogJob(job, CUPSD_LOG_DEBUG, "PPD: %s", message);
+
+- job->num_keywords = cupsParseOptions(message, job->num_keywords,
+- &job->keywords);
++ keywords = NULL;
++ num_keywords = cupsParseOptions(message, 0, &keywords);
++
++ for (i = 0, keyword = keywords; i < num_keywords; i ++)
++ {
++ /*
++ * Filter out "special" PPD keywords...
++ */
++
++ if (strcmp(keyword->name, "cupsFilter") && strcmp(keyword->name, "cupsFilter2") && strcmp(keyword->name, "cupsFinishingTemplate") && strcmp(keyword->name, "cupsIPPFinishings") && strcmp(keyword->name, "cupsIPPReason") && strcmp(keyword->name, "cupsMarkerName") && strcmp(keyword->name, "cupsMaxSize") && strncmp(keyword->name, "cupsMediaQualifier", 18) && strcmp(keyword->name, "cupsMinSize") && strcmp(keyword->name, "cupsPageSizeCategory") && strcmp(keyword->name, "cupsPortMonitor") && strcmp(keyword->name, "cupsPreFilter") && strcmp(keyword->name, "cupsPrintQuality") && strcmp(keyword->name, "APPrinterPreset"))
++ job->num_keywords = cupsAddOption(keyword->name, keyword->value, job->num_keywords, &job->keywords);
++ }
++
++ cupsFreeOptions(num_keywords, keywords);
+ }
+ else
+ {
+--
+2.43.7
^ permalink raw reply related [flat|nested] 32+ messages in thread
* [OE-core][scarthgap 17/31] cups: fix CVE-2026-34979
2026-07-26 8:29 [OE-core][scarthgap 00/31] Patch review Yoann Congal
` (15 preceding siblings ...)
2026-07-26 8:29 ` [OE-core][scarthgap 16/31] cups: fix CVE-2026-34980 Yoann Congal
@ 2026-07-26 8:29 ` Yoann Congal
2026-07-26 8:29 ` [OE-core][scarthgap 18/31] cups: fix CVE-2026-34990 Yoann Congal
` (13 subsequent siblings)
30 siblings, 0 replies; 32+ messages in thread
From: Yoann Congal @ 2026-07-26 8:29 UTC (permalink / raw)
To: openembedded-core
From: Deepak Rathore <deeratho@cisco.com>
Pick the upstream patch [1] as mentioned in [2].
[1] https://github.com/OpenPrinting/cups/commit/0ff8897367c7341f2500770c3977038cdd7c0214
[2] https://security-tracker.debian.org/tracker/CVE-2026-34979
Signed-off-by: Deepak Rathore <deeratho@cisco.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
---
meta/recipes-extended/cups/cups.inc | 1 +
.../cups/cups/CVE-2026-34979.patch | 61 +++++++++++++++++++
2 files changed, 62 insertions(+)
create mode 100644 meta/recipes-extended/cups/cups/CVE-2026-34979.patch
diff --git a/meta/recipes-extended/cups/cups.inc b/meta/recipes-extended/cups/cups.inc
index 7a8b845953c..a0ac1a26129 100644
--- a/meta/recipes-extended/cups/cups.inc
+++ b/meta/recipes-extended/cups/cups.inc
@@ -28,6 +28,7 @@ SRC_URI = "${GITHUB_BASE_URI}/download/v${PV}/cups-${PV}-source.tar.gz \
file://CVE-2026-34980.patch \
file://CVE-2026-34980-regression_p1.patch \
file://CVE-2026-34980-regression_p2.patch \
+ file://CVE-2026-34979.patch \
"
GITHUB_BASE_URI = "https://github.com/OpenPrinting/cups/releases"
diff --git a/meta/recipes-extended/cups/cups/CVE-2026-34979.patch b/meta/recipes-extended/cups/cups/CVE-2026-34979.patch
new file mode 100644
index 00000000000..38ac7b6e918
--- /dev/null
+++ b/meta/recipes-extended/cups/cups/CVE-2026-34979.patch
@@ -0,0 +1,61 @@
+From 471b4dc802455c7c59f9fd594fec8b6f3acb0db5 Mon Sep 17 00:00:00 2001
+From: Michael R Sweet <msweet@msweet.org>
+Date: Tue, 31 Mar 2026 14:50:06 -0400
+Subject: [PATCH] Expand allocation of options string.
+
+CVE: CVE-2026-34979
+Upstream-Status: Backport [https://github.com/OpenPrinting/cups/commit/0ff8897367c7341f2500770c3977038cdd7c0214]
+
+Backport Changes:
+- Rebase scheduler/job.c IPP length context to the CUPS 2.4.11 source
+ carried by this recipe.
+- Omit the upstream CHANGES.md release-note hunk because Yocto patch metadata
+ carries the CVE details and the target source release-note sections differ.
+
+(cherry picked from commit 0ff8897367c7341f2500770c3977038cdd7c0214)
+Signed-off-by: Deepak Rathore <deeratho@cisco.com>
+---
+ scheduler/job.c | 16 ++++------------
+ 1 file changed, 4 insertions(+), 12 deletions(-)
+
+diff --git a/scheduler/job.c b/scheduler/job.c
+index 915ba94..880c25f 100644
+--- a/scheduler/job.c
++++ b/scheduler/job.c
+@@ -4195,18 +4195,6 @@ ipp_length(ipp_t *ipp) /* I - IPP request */
+
+ for (attr = ipp->attrs; attr != NULL; attr = attr->next)
+ {
+- /*
+- * Skip attributes that won't be sent to filters...
+- */
+-
+- if (attr->value_tag == IPP_TAG_NOVALUE ||
+- attr->value_tag == IPP_TAG_MIMETYPE ||
+- attr->value_tag == IPP_TAG_NAMELANG ||
+- attr->value_tag == IPP_TAG_TEXTLANG ||
+- attr->value_tag == IPP_TAG_URI ||
+- attr->value_tag == IPP_TAG_URISCHEME)
+- continue;
+-
+ /*
+ * Add space for a leading space and commas between each value.
+ * For the first attribute, the leading space isn't used, so the
+@@ -4282,10 +4270,14 @@ ipp_length(ipp_t *ipp) /* I - IPP request */
+
+ case IPP_TAG_TEXT :
+ case IPP_TAG_NAME :
++ case IPP_TAG_TEXTLANG :
++ case IPP_TAG_NAMELANG :
++ case IPP_TAG_MIMETYPE :
+ case IPP_TAG_KEYWORD :
+ case IPP_TAG_CHARSET :
+ case IPP_TAG_LANGUAGE :
+ case IPP_TAG_URI :
++ case IPP_TAG_URISCHEME :
+ /*
+ * Strings can contain characters that need quoting. We need
+ * at least 2 * len + 2 characters to cover the quotes and
+--
+2.43.7
+
^ permalink raw reply related [flat|nested] 32+ messages in thread
* [OE-core][scarthgap 18/31] cups: fix CVE-2026-34990
2026-07-26 8:29 [OE-core][scarthgap 00/31] Patch review Yoann Congal
` (16 preceding siblings ...)
2026-07-26 8:29 ` [OE-core][scarthgap 17/31] cups: fix CVE-2026-34979 Yoann Congal
@ 2026-07-26 8:29 ` Yoann Congal
2026-07-26 8:29 ` [OE-core][scarthgap 19/31] cups: fix CVE-2026-39314 Yoann Congal
` (12 subsequent siblings)
30 siblings, 0 replies; 32+ messages in thread
From: Yoann Congal @ 2026-07-26 8:29 UTC (permalink / raw)
To: openembedded-core
From: Deepak Rathore <deeratho@cisco.com>
Pick the upstream patch [1] as mentioned in [2].
[1] https://github.com/OpenPrinting/cups/commit/e052dc44da9d12adfbebc51de4975fbadb2ce356
[2] https://security-tracker.debian.org/tracker/CVE-2026-34990
Signed-off-by: Deepak Rathore <deeratho@cisco.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
---
meta/recipes-extended/cups/cups.inc | 1 +
.../cups/cups/CVE-2026-34990.patch | 351 ++++++++++++++++++
2 files changed, 352 insertions(+)
create mode 100644 meta/recipes-extended/cups/cups/CVE-2026-34990.patch
diff --git a/meta/recipes-extended/cups/cups.inc b/meta/recipes-extended/cups/cups.inc
index a0ac1a26129..1cef1e71fe4 100644
--- a/meta/recipes-extended/cups/cups.inc
+++ b/meta/recipes-extended/cups/cups.inc
@@ -29,6 +29,7 @@ SRC_URI = "${GITHUB_BASE_URI}/download/v${PV}/cups-${PV}-source.tar.gz \
file://CVE-2026-34980-regression_p1.patch \
file://CVE-2026-34980-regression_p2.patch \
file://CVE-2026-34979.patch \
+ file://CVE-2026-34990.patch \
"
GITHUB_BASE_URI = "https://github.com/OpenPrinting/cups/releases"
diff --git a/meta/recipes-extended/cups/cups/CVE-2026-34990.patch b/meta/recipes-extended/cups/cups/CVE-2026-34990.patch
new file mode 100644
index 00000000000..0a8c0930657
--- /dev/null
+++ b/meta/recipes-extended/cups/cups/CVE-2026-34990.patch
@@ -0,0 +1,351 @@
+From 48648896ca7faa8f105eee7b7a8d86c42e0fa796 Mon Sep 17 00:00:00 2001
+From: Michael R Sweet <msweet@msweet.org>
+Date: Tue, 31 Mar 2026 15:55:50 -0400
+Subject: [PATCH] Don't allow local certificates over the loopback
+ interface, drop support for writing to plain files.
+
+CVE: CVE-2026-34990
+Upstream-Status: Backport [https://github.com/OpenPrinting/cups/commit/e052dc44da9d12adfbebc51de4975fbadb2ce356]
+
+Backport Changes:
+- Preserve the existing CVE-2025-61915 PeerCred disable guard while changing
+ localhost checks to AF_LOCAL.
+- Keep the CUPS 2.4.11 empty device-uri validation path separate and add a
+ dedicated rejection for non-IPP/IPPS schemes instead of folding both checks
+ into one upstream condition.
+- Omit the upstream CHANGES.md release-note hunk because Yocto patch metadata
+ carries the CVE details and the target source release-note sections differ.
+
+(cherry picked from commit e052dc44da9d12adfbebc51de4975fbadb2ce356)
+Signed-off-by: Deepak Rathore <deeratho@cisco.com>
+---
+ cups/auth.c | 30 ++++++--------------------
+ scheduler/auth.c | 9 ++++----
+ scheduler/client.c | 4 +--
+ scheduler/ipp.c | 8 ++++++-
+ scheduler/job.c | 46 ++++++++++++++++++++++-------------------
+ test/4.2-cups-printer-ops.test | 6 ++---
+ test/5.1-lpadmin.sh | 14 ++++++------
+ 7 files changed, 56 insertions(+), 61 deletions(-)
+
+diff --git a/cups/auth.c b/cups/auth.c
+index 5cb4194..14661c7 100644
+--- a/cups/auth.c
++++ b/cups/auth.c
+@@ -1,7 +1,7 @@
+ /*
+ * Authentication functions for CUPS.
+ *
+- * Copyright © 2020-2024 by OpenPrinting.
++ * Copyright © 2020-2026 by OpenPrinting.
+ * Copyright © 2007-2019 by Apple Inc.
+ * Copyright © 1997-2007 by Easy Software Products.
+ *
+@@ -92,7 +92,6 @@ static void cups_gss_printf(OM_uint32 major_status, OM_uint32 minor_status,
+ # define cups_gss_printf(major, minor, message)
+ # endif /* DEBUG */
+ #endif /* HAVE_GSSAPI */
+-static int cups_is_local_connection(http_t *http);
+ static int cups_local_auth(http_t *http);
+
+
+@@ -948,14 +947,6 @@ cups_gss_printf(OM_uint32 major_status,/* I - Major status code */
+ # endif /* DEBUG */
+ #endif /* HAVE_GSSAPI */
+
+-static int /* O - 0 if not a local connection */
+- /* 1 if local connection */
+-cups_is_local_connection(http_t *http) /* I - HTTP connection to server */
+-{
+- if (!httpAddrLocalhost(http->hostaddr) && _cups_strcasecmp(http->hostname, "localhost") != 0)
+- return 0;
+- return 1;
+-}
+
+ /*
+ * 'cups_local_auth()' - Get the local authorization certificate if
+@@ -967,13 +958,7 @@ static int /* O - 0 if available */
+ /* -1 error */
+ cups_local_auth(http_t *http) /* I - HTTP connection to server */
+ {
+-#if defined(_WIN32) || defined(__EMX__)
+- /*
+- * Currently _WIN32 and OS-2 do not support the CUPS server...
+- */
+-
+- return (1);
+-#else
++#if !_WIN32 && !__EMX__ && defined(AF_LOCAL)
+ int pid; /* Current process ID */
+ FILE *fp; /* Certificate file */
+ char trc[16], /* Try Root Certificate parameter */
+@@ -998,7 +983,7 @@ cups_local_auth(http_t *http) /* I - HTTP connection to server */
+ * See if we are accessing localhost...
+ */
+
+- if (!cups_is_local_connection(http))
++ if (httpAddrFamily(httpGetAddress(http)) != AF_LOCAL)
+ {
+ DEBUG_puts("8cups_local_auth: Not a local connection!");
+ return (1);
+@@ -1072,15 +1057,14 @@ cups_local_auth(http_t *http) /* I - HTTP connection to server */
+ }
+ # endif /* HAVE_AUTHORIZATION_H */
+
+-# if defined(SO_PEERCRED) && defined(AF_LOCAL)
++# ifdef SO_PEERCRED
+ /*
+ * See if we can authenticate using the peer credentials provided over a
+ * domain socket; if so, specify "PeerCred username" as the authentication
+ * information...
+ */
+
+- if (http->hostaddr->addr.sa_family == AF_LOCAL &&
+- !getenv("GATEWAY_INTERFACE") && /* Not via CGI programs... */
++ if (!getenv("GATEWAY_INTERFACE") && /* Not via CGI programs... */
+ cups_auth_find(www_auth, "PeerCred"))
+ {
+ /*
+@@ -1104,7 +1088,7 @@ cups_local_auth(http_t *http) /* I - HTTP connection to server */
+ return (0);
+ }
+ }
+-# endif /* SO_PEERCRED && AF_LOCAL */
++# endif /* SO_PEERCRED */
+
+ if ((schemedata = cups_auth_find(www_auth, "Local")) == NULL)
+ return (1);
+@@ -1164,7 +1148,7 @@ cups_local_auth(http_t *http) /* I - HTTP connection to server */
+ return (0);
+ }
+ }
++#endif /* !_WIN32 && !__EMX__ && AF_LOCAL */
+
+ return (1);
+-#endif /* _WIN32 || __EMX__ */
+ }
+diff --git a/scheduler/auth.c b/scheduler/auth.c
+index 1dd520d..56855fc 100644
+--- a/scheduler/auth.c
++++ b/scheduler/auth.c
+@@ -318,7 +318,7 @@ cupsdAuthorize(cupsd_client_t *con) /* I - Client connection */
+ }
+ #ifdef HAVE_AUTHORIZATION_H
+ else if (!strncmp(authorization, "AuthRef ", 8) &&
+- httpAddrLocalhost(httpGetAddress(con->http)))
++ httpAddrFamily(httpGetAddress(con->http)) == AF_LOCAL)
+ {
+ OSStatus status; /* Status */
+ char authdata[HTTP_MAX_VALUE];
+@@ -399,7 +399,8 @@ cupsdAuthorize(cupsd_client_t *con) /* I - Client connection */
+ #endif /* HAVE_AUTHORIZATION_H */
+ #if defined(SO_PEERCRED) && defined(AF_LOCAL)
+- else if (PeerCred != CUPSD_PEERCRED_OFF && !strncmp(authorization, "PeerCred ", 9) &&
+- con->http->hostaddr->addr.sa_family == AF_LOCAL && con->best)
++ else if (PeerCred != CUPSD_PEERCRED_OFF &&
++ !strncmp(authorization, "PeerCred ", 9) &&
++ httpAddrFamily(httpGetAddress(con->http)) == AF_LOCAL && con->best)
+ {
+ /*
+ * Use peer credentials from domain socket connection...
+@@ -483,7 +483,7 @@ cupsdAuthorize(cupsd_client_t *con) /* I - Client connection */
+ }
+ #endif /* SO_PEERCRED && AF_LOCAL */
+ else if (!strncmp(authorization, "Local", 5) &&
+- httpAddrLocalhost(httpGetAddress(con->http)))
++ httpAddrFamily(httpGetAddress(con->http)) == AF_LOCAL)
+ {
+ /*
+ * Get Local certificate authentication data...
+diff --git a/scheduler/client.c b/scheduler/client.c
+index 779404c..dea9da0 100644
+--- a/scheduler/client.c
++++ b/scheduler/client.c
+@@ -2173,7 +2173,7 @@ cupsdSendHeader(
+ strlcpy(auth_str, "Negotiate", sizeof(auth_str));
+ }
+
+- if (con->best && !con->is_browser && !_cups_strcasecmp(httpGetHostname(con->http, NULL, 0), "localhost"))
++ if (con->best && !con->is_browser && httpAddrFamily(httpGetAddress(con->http)) == AF_LOCAL)
+ {
+ /*
+ * Add a "trc" (try root certification) parameter for local
+@@ -2193,7 +2193,7 @@ cupsdSendHeader(
+ auth_size = sizeof(auth_str) - (size_t)(auth_key - auth_str);
+
+ #if defined(SO_PEERCRED) && defined(AF_LOCAL)
+- if (PeerCred != CUPSD_PEERCRED_OFF && httpAddrFamily(httpGetAddress(con->http)) == AF_LOCAL)
++ if (PeerCred != CUPSD_PEERCRED_OFF)
+ {
+ strlcpy(auth_key, ", PeerCred", auth_size);
+ auth_key += 10;
+diff --git a/scheduler/ipp.c b/scheduler/ipp.c
+index b0d1f5b..11dcd39 100644
+--- a/scheduler/ipp.c
++++ b/scheduler/ipp.c
+@@ -5561,7 +5561,7 @@ create_local_printer(
+ * Require local access to create a local printer...
+ */
+
+- if (!httpAddrLocalhost(httpGetAddress(con->http)))
++ if (httpAddrFamily(httpGetAddress(con->http)) != AF_LOCAL)
+ {
+ send_ipp_status(con, IPP_STATUS_ERROR_FORBIDDEN, _("Only local users can create a local printer."));
+ return;
+@@ -5634,6 +5634,12 @@ create_local_printer(
+
+ return;
+ }
++ else if (strncmp(ptr, "ipp://", 6) && strncmp(ptr, "ipps://", 7))
++ {
++ send_ipp_status(con, IPP_STATUS_ERROR_NOT_POSSIBLE, _("Bad device-uri \"%s\"."), ptr);
++
++ return;
++ }
+
+ printer_geo_location = ippFindAttribute(con->request, "printer-geo-location", IPP_TAG_URI);
+ printer_info = ippFindAttribute(con->request, "printer-info", IPP_TAG_TEXT);
+diff --git a/scheduler/job.c b/scheduler/job.c
+index 880c25f..6c033de 100644
+--- a/scheduler/job.c
++++ b/scheduler/job.c
+@@ -1164,35 +1164,39 @@ cupsdContinueJob(cupsd_job_t *job) /* I - Job */
+ }
+ else
+ {
++ char scheme[32], /* URI scheme */
++ userpass[32], /* URI username:password */
++ host[256], /* URI hostname */
++ resource[1024]; /* URI resource path (filename) */
++ int port; /* URI port number */
++
++ httpSeparateURI(HTTP_URI_CODING_ALL, job->printer->device_uri, scheme, sizeof(scheme), userpass, sizeof(userpass), host, sizeof(host), &port, resource, sizeof(resource));
++
+ job->print_pipes[0] = -1;
+- if (!strcmp(job->printer->device_uri, "file:/dev/null") ||
+- !strcmp(job->printer->device_uri, "file:///dev/null"))
+- job->print_pipes[1] = -1;
+- else
++ job->print_pipes[1] = -1;
++
++ if (strcmp(resource, "/dev/null"))
+ {
+- if (!strncmp(job->printer->device_uri, "file:/dev/", 10))
+- job->print_pipes[1] = open(job->printer->device_uri + 5,
+- O_WRONLY | O_EXCL);
+- else if (!strncmp(job->printer->device_uri, "file:///dev/", 12))
+- job->print_pipes[1] = open(job->printer->device_uri + 7,
+- O_WRONLY | O_EXCL);
+- else if (!strncmp(job->printer->device_uri, "file:///", 8))
+- job->print_pipes[1] = open(job->printer->device_uri + 7,
+- O_WRONLY | O_CREAT | O_TRUNC, 0600);
+- else
+- job->print_pipes[1] = open(job->printer->device_uri + 5,
+- O_WRONLY | O_CREAT | O_TRUNC, 0600);
++ if (!FileDevice)
++ {
++ abort_message = "Stopping job because file: output is disabled.";
+
+- if (job->print_pipes[1] < 0)
++ goto abort_job;
++ }
++ else if ((job->print_pipes[1] = open(resource, O_WRONLY | O_EXCL)) < 0)
+ {
+- abort_message = "Stopping job because the scheduler could not "
+- "open the output file.";
++ abort_message = "Stopping job because the scheduler could not open the output file.";
+
+ goto abort_job;
+ }
++ else
++ {
++ /*
++ * Close this file on execute...
++ */
+
+- fcntl(job->print_pipes[1], F_SETFD,
+- fcntl(job->print_pipes[1], F_GETFD) | FD_CLOEXEC);
++ fcntl(job->print_pipes[1], F_SETFD, fcntl(job->print_pipes[1], F_GETFD) | FD_CLOEXEC);
++ }
+ }
+ }
+ }
+diff --git a/test/4.2-cups-printer-ops.test b/test/4.2-cups-printer-ops.test
+index 1a011e0..945a9bb 100644
+--- a/test/4.2-cups-printer-ops.test
++++ b/test/4.2-cups-printer-ops.test
+@@ -1,7 +1,7 @@
+ #
+ # Verify that the CUPS printer operations work.
+ #
+-# Copyright © 2020-2024 by OpenPrinting.
++# Copyright © 2020-2026 by OpenPrinting.
+ # Copyright © 2007-2019 by Apple Inc.
+ # Copyright © 2001-2006 by Easy Software Products. All rights reserved.
+ #
+@@ -180,7 +180,7 @@
+ ATTR uri printer-uri $method://$hostname:$port/printers/Test2
+
+ GROUP printer
+- ATTR uri device-uri file:/tmp/Test2
++ ATTR uri device-uri file:///dev/null
+ ATTR enum printer-state 3
+ ATTR boolean printer-is-accepting-jobs true
+
+@@ -206,7 +206,7 @@
+ ATTR uri printer-uri $method://$hostname:$port/printers/Test1
+
+ GROUP printer
+- ATTR uri device-uri file:/tmp/Test1
++ ATTR uri device-uri file:///dev/null
+ ATTR enum printer-state 3
+ ATTR boolean printer-is-accepting-jobs true
+ ATTR text printer-info "Test Printer 1"
+diff --git a/test/5.1-lpadmin.sh b/test/5.1-lpadmin.sh
+index aa39800..36f2822 100644
+--- a/test/5.1-lpadmin.sh
++++ b/test/5.1-lpadmin.sh
+@@ -2,7 +2,7 @@
+ #
+ # Test the lpadmin command.
+ #
+-# Copyright © 2020-2024 by OpenPrinting.
++# Copyright © 2020-2026 by OpenPrinting.
+ # Copyright © 2007-2018 by Apple Inc.
+ # Copyright © 1997-2005 by Easy Software Products, all rights reserved.
+ #
+@@ -12,8 +12,8 @@
+
+ echo "Add Printer Test"
+ echo ""
+-echo " lpadmin -p Test3 -v file:/dev/null -E -m drv:///sample.drv/deskjet.ppd"
+-$runcups $VALGRIND ../systemv/lpadmin -p Test3 -v file:/dev/null -E -m drv:///sample.drv/deskjet.ppd 2>&1
++echo " lpadmin -p Test3 -v file:///dev/null -E -m drv:///sample.drv/deskjet.ppd"
++$runcups $VALGRIND ../systemv/lpadmin -p Test3 -v file:///dev/null -E -m drv:///sample.drv/deskjet.ppd 2>&1
+ if test $? != 0; then
+ echo " FAILED"
+ exit 1
+@@ -29,8 +29,8 @@ echo ""
+
+ echo "Modify Printer Test"
+ echo ""
+-echo " lpadmin -p Test3 -v file:/tmp/Test3 -o PageSize=A4"
+-$runcups $VALGRIND ../systemv/lpadmin -p Test3 -v file:/tmp/Test3 -o PageSize=A4 2>&1
++echo " lpadmin -p Test3 -v file:///dev/null -o PageSize=A4"
++$runcups $VALGRIND ../systemv/lpadmin -p Test3 -v file:///dev/null -o PageSize=A4 2>&1
+ if test $? != 0; then
+ echo " FAILED"
+ exit 1
+@@ -65,8 +65,8 @@ echo ""
+
+ echo "Add a printer for cupSNMP/IPPSupplies test"
+ echo ""
+-echo " lpadmin -p Test4 -E -v file:/dev/null -m drv:///sample.drv/zebra.ppd"
+-$runcups $VALGRIND ../systemv/lpadmin -p Test4 -E -v file:/dev/null -m drv:///sample.drv/zebra.ppd 2>&1
++echo " lpadmin -p Test4 -E -v file:///dev/null -m drv:///sample.drv/zebra.ppd"
++$runcups $VALGRIND ../systemv/lpadmin -p Test4 -E -v file:///dev/null -m drv:///sample.drv/zebra.ppd 2>&1
+ if test $? != 0; then
+ echo " FAILED"
+ exit 1
+--
+2.43.7
^ permalink raw reply related [flat|nested] 32+ messages in thread
* [OE-core][scarthgap 19/31] cups: fix CVE-2026-39314
2026-07-26 8:29 [OE-core][scarthgap 00/31] Patch review Yoann Congal
` (17 preceding siblings ...)
2026-07-26 8:29 ` [OE-core][scarthgap 18/31] cups: fix CVE-2026-34990 Yoann Congal
@ 2026-07-26 8:29 ` Yoann Congal
2026-07-26 8:29 ` [OE-core][scarthgap 20/31] cups: fix CVE-2026-39316 Yoann Congal
` (11 subsequent siblings)
30 siblings, 0 replies; 32+ messages in thread
From: Yoann Congal @ 2026-07-26 8:29 UTC (permalink / raw)
To: openembedded-core
From: Deepak Rathore <deeratho@cisco.com>
Pick the upstream patch [1] as mentioned in [2].
[1] https://github.com/OpenPrinting/cups/commit/928a86b1b794f738f0a3dc87561b2e054bff7ce4
[2] https://security-tracker.debian.org/tracker/CVE-2026-39314
Signed-off-by: Deepak Rathore <deeratho@cisco.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
---
meta/recipes-extended/cups/cups.inc | 1 +
.../cups/cups/CVE-2026-39314.patch | 45 +++++++++++++++++++
2 files changed, 46 insertions(+)
create mode 100644 meta/recipes-extended/cups/cups/CVE-2026-39314.patch
diff --git a/meta/recipes-extended/cups/cups.inc b/meta/recipes-extended/cups/cups.inc
index 1cef1e71fe4..575dbf9c577 100644
--- a/meta/recipes-extended/cups/cups.inc
+++ b/meta/recipes-extended/cups/cups.inc
@@ -30,6 +30,7 @@ SRC_URI = "${GITHUB_BASE_URI}/download/v${PV}/cups-${PV}-source.tar.gz \
file://CVE-2026-34980-regression_p2.patch \
file://CVE-2026-34979.patch \
file://CVE-2026-34990.patch \
+ file://CVE-2026-39314.patch \
"
GITHUB_BASE_URI = "https://github.com/OpenPrinting/cups/releases"
diff --git a/meta/recipes-extended/cups/cups/CVE-2026-39314.patch b/meta/recipes-extended/cups/cups/CVE-2026-39314.patch
new file mode 100644
index 00000000000..f8d1a69f56e
--- /dev/null
+++ b/meta/recipes-extended/cups/cups/CVE-2026-39314.patch
@@ -0,0 +1,45 @@
+From 65c463ada188915d6700d92ce48a9a14949ca413 Mon Sep 17 00:00:00 2001
+From: Michael R Sweet <msweet@msweet.org>
+Date: Sun, 5 Apr 2026 10:45:25 -0400
+Subject: [PATCH] Range check job-password-supported.
+
+CVE: CVE-2026-39314
+Upstream-Status: Backport [https://github.com/OpenPrinting/cups/commit/928a86b1b794f738f0a3dc87561b2e054bff7ce4]
+
+Backport Changes:
+- Rebase cups/ppd-cache.c context to the CUPS 2.4.11 source carried by
+ this recipe.
+- Omit the upstream CHANGES.md release-note hunk because Yocto patch metadata
+ carries the CVE details and the target source release-note sections differ.
+
+(cherry picked from commit 928a86b1b794f738f0a3dc87561b2e054bff7ce4)
+Signed-off-by: Deepak Rathore <deeratho@cisco.com>
+---
+ cups/ppd-cache.c | 4 ++--
+ 1 file changed, 2 insertions(+), 2 deletions(-)
+
+diff --git a/cups/ppd-cache.c b/cups/ppd-cache.c
+index e750fcc..08e0db8 100644
+--- a/cups/ppd-cache.c
++++ b/cups/ppd-cache.c
+@@ -1,7 +1,7 @@
+ /*
+ * PPD cache implementation for CUPS.
+ *
+- * Copyright © 2022-2024 by OpenPrinting.
++ * Copyright © 2022-2026 by OpenPrinting.
+ * Copyright © 2010-2021 by Apple Inc.
+ *
+ * Licensed under Apache License v2.0. See the file "LICENSE" for more
+@@ -3432,7 +3432,7 @@ _ppdCreateFromIPP2(
+ * Password/PIN printing...
+ */
+
+- if ((attr = ippFindAttribute(supported, "job-password-supported", IPP_TAG_INTEGER)) != NULL)
++ if ((attr = ippFindAttribute(supported, "job-password-supported", IPP_TAG_INTEGER)) != NULL && ippGetInteger(attr, 0) > 0)
+ {
+ char pattern[33]; /* Password pattern */
+ int maxlen = ippGetInteger(attr, 0);
+--
+2.43.7
+
^ permalink raw reply related [flat|nested] 32+ messages in thread
* [OE-core][scarthgap 20/31] cups: fix CVE-2026-39316
2026-07-26 8:29 [OE-core][scarthgap 00/31] Patch review Yoann Congal
` (18 preceding siblings ...)
2026-07-26 8:29 ` [OE-core][scarthgap 19/31] cups: fix CVE-2026-39314 Yoann Congal
@ 2026-07-26 8:29 ` Yoann Congal
2026-07-26 8:29 ` [OE-core][scarthgap 21/31] libxpm: fix CVE-2026-4367 Yoann Congal
` (10 subsequent siblings)
30 siblings, 0 replies; 32+ messages in thread
From: Yoann Congal @ 2026-07-26 8:29 UTC (permalink / raw)
To: openembedded-core
From: Deepak Rathore <deeratho@cisco.com>
Pick the upstream patch [1] as mentioned in [2].
[1] https://github.com/OpenPrinting/cups/commit/0142eeb58e0d718b7d2e1f0d5dd214bd2192cc7f
[2] https://security-tracker.debian.org/tracker/CVE-2026-39316
Signed-off-by: Deepak Rathore <deeratho@cisco.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
---
meta/recipes-extended/cups/cups.inc | 1 +
.../cups/cups/CVE-2026-39316.patch | 40 +++++++++++++++++++
2 files changed, 41 insertions(+)
create mode 100644 meta/recipes-extended/cups/cups/CVE-2026-39316.patch
diff --git a/meta/recipes-extended/cups/cups.inc b/meta/recipes-extended/cups/cups.inc
index 575dbf9c577..4c158aaee1b 100644
--- a/meta/recipes-extended/cups/cups.inc
+++ b/meta/recipes-extended/cups/cups.inc
@@ -31,6 +31,7 @@ SRC_URI = "${GITHUB_BASE_URI}/download/v${PV}/cups-${PV}-source.tar.gz \
file://CVE-2026-34979.patch \
file://CVE-2026-34990.patch \
file://CVE-2026-39314.patch \
+ file://CVE-2026-39316.patch \
"
GITHUB_BASE_URI = "https://github.com/OpenPrinting/cups/releases"
diff --git a/meta/recipes-extended/cups/cups/CVE-2026-39316.patch b/meta/recipes-extended/cups/cups/CVE-2026-39316.patch
new file mode 100644
index 00000000000..d3c9edf9745
--- /dev/null
+++ b/meta/recipes-extended/cups/cups/CVE-2026-39316.patch
@@ -0,0 +1,40 @@
+From 7c4d7951d189e931563f21086196d5a55fb2fa15 Mon Sep 17 00:00:00 2001
+From: Michael R Sweet <msweet@msweet.org>
+Date: Sun, 5 Apr 2026 11:33:23 -0400
+Subject: [PATCH] Expire per-printer subscriptions before deleting.
+
+CVE: CVE-2026-39316
+Upstream-Status: Backport [https://github.com/OpenPrinting/cups/commit/0142eeb58e0d718b7d2e1f0d5dd214bd2192cc7f]
+
+Backport Changes:
+- Rebase scheduler/printers.c delete-printer context to the CUPS 2.4.11
+ source carried by this recipe.
+- Omit the upstream CHANGES.md release-note hunk because Yocto patch metadata
+ carries the CVE details and the target source release-note sections differ.
+
+(cherry picked from commit 0142eeb58e0d718b7d2e1f0d5dd214bd2192cc7f)
+Signed-off-by: Deepak Rathore <deeratho@cisco.com>
+---
+ scheduler/printers.c | 6 ++++++
+ 1 file changed, 6 insertions(+)
+
+diff --git a/scheduler/printers.c b/scheduler/printers.c
+index bf493a3..ca983f9 100644
+--- a/scheduler/printers.c
++++ b/scheduler/printers.c
+@@ -641,6 +641,12 @@ cupsdDeletePrinter(
+ update ? "Job stopped due to printer being deleted." :
+ "Job stopped.");
+
++ /*
++ * Expire subscriptions on the printer...
++ */
++
++ cupsdExpireSubscriptions(p, /*job*/NULL);
++
+ /*
+ * Remove the printer from the list...
+ */
+--
+2.43.7
+
^ permalink raw reply related [flat|nested] 32+ messages in thread
* [OE-core][scarthgap 21/31] libxpm: fix CVE-2026-4367
2026-07-26 8:29 [OE-core][scarthgap 00/31] Patch review Yoann Congal
` (19 preceding siblings ...)
2026-07-26 8:29 ` [OE-core][scarthgap 20/31] cups: fix CVE-2026-39316 Yoann Congal
@ 2026-07-26 8:29 ` Yoann Congal
2026-07-26 8:29 ` [OE-core][scarthgap 22/31] gnutls: set status for CVE-2026-3832 Yoann Congal
` (9 subsequent siblings)
30 siblings, 0 replies; 32+ messages in thread
From: Yoann Congal @ 2026-07-26 8:29 UTC (permalink / raw)
To: openembedded-core
From: Enoch Ng <enoch.ng@windriver.com>
Backport the upstream fix for CVE-2026-4367, in which the
`xpmNextWord()` function could attempt to read beyond the file's
end due to improper validation of file boundaries.
Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-4367
Signed-off-by: Enoch Ng <enoch.ng@windriver.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
---
...67-Out-of-bounds-read-in-xpmNextWord.patch | 140 ++++++++++++++++++
.../xorg-lib/libxpm_3.5.17.bb | 1 +
2 files changed, 141 insertions(+)
create mode 100644 meta/recipes-graphics/xorg-lib/libxpm/0001-Fix-CVE-2026-4367-Out-of-bounds-read-in-xpmNextWord.patch
diff --git a/meta/recipes-graphics/xorg-lib/libxpm/0001-Fix-CVE-2026-4367-Out-of-bounds-read-in-xpmNextWord.patch b/meta/recipes-graphics/xorg-lib/libxpm/0001-Fix-CVE-2026-4367-Out-of-bounds-read-in-xpmNextWord.patch
new file mode 100644
index 00000000000..e9989a5012c
--- /dev/null
+++ b/meta/recipes-graphics/xorg-lib/libxpm/0001-Fix-CVE-2026-4367-Out-of-bounds-read-in-xpmNextWord.patch
@@ -0,0 +1,140 @@
+From 5448e1bd7252780b16db869c2253d24e0fe0ae18 Mon Sep 17 00:00:00 2001
+From: Olivier Fourdan <ofourdan@redhat.com>
+Date: Tue, 17 Feb 2026 11:59:56 +0100
+Subject: [PATCH libXpm] Fix CVE-2026-4367: Out-of-bounds read in xpmNextWord()
+
+xpmNextWord() checks for the terminator character to detect the end of
+the file, but a very small malformed XPM file may cause the function to
+read past the end of the buffer, causing out-of-bound reads:
+
+ == Invalid read of size 1
+ == at 0x48AD3A4: xpmParseColors (parse.c:239)
+ == by 0x48AF9D8: xpmParseData (parse.c:783)
+ == by 0x48B1C18: XpmCreateXpmImageFromBuffer (CrIFrBuf.c:101)
+ == by 0x4005A6: main ()
+ == Address 0x4c413bf is 0 bytes after a block of size 15 alloc'd
+ == at 0x4841B26: malloc (vg_replace_malloc.c:447)
+ == by 0x48B2809: XpmReadFileToBuffer (RdFToBuf.c:96)
+ == by 0x400554: main ()
+ ==
+ == Invalid read of size 1
+ == at 0x48AC8D5: xpmNextWord.constprop.0 (data.c:262)
+ == by 0x48AD492: xpmParseColors (parse.c:266)
+ == by 0x48AF9D8: xpmParseData (parse.c:783)
+ == by 0x48B1C18: XpmCreateXpmImageFromBuffer (CrIFrBuf.c:101)
+ == by 0x4005A6: main ()
+ == Address 0x4c413c0 is 1 bytes after a block of size 15 alloc'd
+ == at 0x4841B26: malloc (vg_replace_malloc.c:447)
+ == by 0x48B2809: XpmReadFileToBuffer (RdFToBuf.c:96)
+ == by 0x400554: main ()
+ ==
+ == Invalid read of size 1
+ == at 0x48AC965: xpmNextWord.constprop.0 (data.c:265)
+ == by 0x48AD492: xpmParseColors (parse.c:266)
+ == by 0x48AF9D8: xpmParseData (parse.c:783)
+ == by 0x48B1C18: XpmCreateXpmImageFromBuffer (CrIFrBuf.c:101)
+ == by 0x4005A6: main ()
+ == Address 0x4c413c0 is 1 bytes after a block of size 15 alloc'd
+ == at 0x4841B26: malloc (vg_replace_malloc.c:447)
+ == by 0x48B2809: XpmReadFileToBuffer (RdFToBuf.c:96)
+ == by 0x400554: main ()
+
+The problem actually comes from xpmNextString() and xpmParseColors():
+
+1) xpmNextString() checks for the NULL terminator when looking for the
+ end of the string (Eos) but not when looking for the beginning of the
+ next string (Bos).
+
+2) xpmParseColors() does not check the return value from xpmNextString()
+ and continues even when xpmNextString() raised an invalid XPM file.
+
+To avoid the issue, fix xpmNextString() to check for the NULL string
+terminator when looking for the beginning of the next string and fix
+xpmParseColors() to stop when xpmNextString() reported an invalid XPM
+error.
+
+CVE-2026-4367
+
+This vulnerability was discovered by:
+Naoki Wakamatsu
+
+v2: Fix the XPM 1 code path the same.
+
+Signed-off-by: Olivier Fourdan <ofourdan@redhat.com>
+Part-of: <https://gitlab.freedesktop.org/xorg/lib/libxpm/-/merge_requests/31>
+
+CVE: CVE-2026-4367
+Upstream-Status: Backport [https://gitlab.freedesktop.org/xorg/lib/libxpm/-/commit/5448e1bd7252780b16db869c2253d24e0fe0ae18]
+Signed-off-by: Enoch Ng <enoch.ng@windriver.com>
+
+---
+
+ src/data.c | 3 +++
+ src/parse.c | 19 ++++++++++++++-----
+ 2 files changed, 17 insertions(+), 5 deletions(-)
+
+diff --git a/src/data.c b/src/data.c
+index 6e87455..a2b4acc 100644
+--- a/src/data.c
++++ b/src/data.c
+@@ -210,6 +210,9 @@ xpmNextString(xpmData *data)
+ while ((c = *data->cptr++) && c != data->Bos && c != '\0')
+ if (data->Bcmt && c == data->Bcmt[0])
+ ParseComment(data);
++
++ if (c == '\0')
++ return XpmFileInvalid;
+ } else if (data->Bcmt) { /* XPM2 natural */
+ while (((c = *data->cptr++) == data->Bcmt[0]) && c != '\0')
+ ParseComment(data);
+diff --git a/src/parse.c b/src/parse.c
+index cd923f9..268954d 100644
+--- a/src/parse.c
++++ b/src/parse.c
+@@ -216,7 +216,9 @@ xpmParseColors(
+
+ if (!data->format) { /* XPM 2 or 3 */
+ for (a = 0, color = colorTable; a < ncolors; a++, color++) {
+- xpmNextString(data); /* skip the line */
++ ErrorStatus = xpmNextString(data); /* skip the line */
++ if (ErrorStatus != XpmSuccess)
++ goto error;
+
+ /*
+ * read pixel value
+@@ -314,7 +316,9 @@ xpmParseColors(
+ /* get to the beginning of the first string */
+ data->Bos = '"';
+ data->Eos = '\0';
+- xpmNextString(data);
++ ErrorStatus = xpmNextString(data);
++ if (ErrorStatus != XpmSuccess)
++ goto error;
+ data->Eos = '"';
+ for (a = 0, color = colorTable; a < ncolors; a++, color++) {
+
+@@ -354,7 +358,9 @@ xpmParseColors(
+ /*
+ * read color values
+ */
+- xpmNextString(data); /* get to the next string */
++ ErrorStatus = xpmNextString(data); /* get to the next string */
++ if (ErrorStatus != XpmSuccess)
++ goto error;
+ *curbuf = '\0'; /* init curbuf */
+ while ((l = xpmNextWord(data, buf, BUFSIZ))) {
+ if (*curbuf != '\0') {
+@@ -378,8 +384,11 @@ xpmParseColors(
+ memcpy(s, curbuf, len);
+ color->c_color = s;
+ *curbuf = '\0'; /* reset curbuf */
+- if (a < ncolors - 1) /* can we trust ncolors -> leave data's bounds */
+- xpmNextString(data); /* get to the next string */
++ if (a < ncolors - 1) { /* can we trust ncolors -> leave data's bounds */
++ ErrorStatus = xpmNextString(data); /* get to the next string */
++ if (ErrorStatus != XpmSuccess)
++ goto error;
++ }
+ }
+ }
+ *colorTablePtr = colorTable;
diff --git a/meta/recipes-graphics/xorg-lib/libxpm_3.5.17.bb b/meta/recipes-graphics/xorg-lib/libxpm_3.5.17.bb
index 8e15ecc0d48..9d1dd477429 100644
--- a/meta/recipes-graphics/xorg-lib/libxpm_3.5.17.bb
+++ b/meta/recipes-graphics/xorg-lib/libxpm_3.5.17.bb
@@ -22,6 +22,7 @@ PACKAGES =+ "sxpm cxpm"
FILES:cxpm = "${bindir}/cxpm"
FILES:sxpm = "${bindir}/sxpm"
+SRC_URI += " file://0001-Fix-CVE-2026-4367-Out-of-bounds-read-in-xpmNextWord.patch"
SRC_URI[sha256sum] = "64b31f81019e7d388c822b0b28af8d51c4622b83f1f0cb6fa3fc95e271226e43"
BBCLASSEXTEND = "native"
^ permalink raw reply related [flat|nested] 32+ messages in thread
* [OE-core][scarthgap 22/31] gnutls: set status for CVE-2026-3832
2026-07-26 8:29 [OE-core][scarthgap 00/31] Patch review Yoann Congal
` (20 preceding siblings ...)
2026-07-26 8:29 ` [OE-core][scarthgap 21/31] libxpm: fix CVE-2026-4367 Yoann Congal
@ 2026-07-26 8:29 ` Yoann Congal
2026-07-26 8:29 ` [OE-core][scarthgap 23/31] gnutls: fix CVE-2026-42009 Yoann Congal
` (8 subsequent siblings)
30 siblings, 0 replies; 32+ messages in thread
From: Yoann Congal @ 2026-07-26 8:29 UTC (permalink / raw)
To: openembedded-core
From: Sudhir Dumbhare <sudumbha@cisco.com>
Analysis:
- CVE-2026-3832 affects GnuTLS OCSP multi-record response handling.
- The vulnerable OCSP response handling code was introduced in GnuTLS 3.8.8.
- This vulnerable code is not present in the current GnuTLS 3.8.4.
- Hence ignoring the CVE for this version.
Reference:
https://nvd.nist.gov/vuln/detail/CVE-2026-3832
https://security-tracker.debian.org/tracker/CVE-2026-3832
https://gitlab.com/gnutls/gnutls/-/issues/1801
Signed-off-by: Sudhir Dumbhare <sudumbha@cisco.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
---
meta/recipes-support/gnutls/gnutls_3.8.4.bb | 2 ++
1 file changed, 2 insertions(+)
diff --git a/meta/recipes-support/gnutls/gnutls_3.8.4.bb b/meta/recipes-support/gnutls/gnutls_3.8.4.bb
index ccb6a2b4b2d..6d43c58df27 100644
--- a/meta/recipes-support/gnutls/gnutls_3.8.4.bb
+++ b/meta/recipes-support/gnutls/gnutls_3.8.4.bb
@@ -124,3 +124,5 @@ pkg_postinst_ontarget:${PN}-fips () {
${bindir}/fipshmac ${libdir}/libhogweed.so.6.* > ${libdir}/.libhogweed.so.6.hmac
fi
}
+
+CVE_STATUS[CVE-2026-3832] = "fixed-version: vulnerable multi-record OCSP response handling was introduced in 3.8.8 and is not present in 3.8.4"
^ permalink raw reply related [flat|nested] 32+ messages in thread
* [OE-core][scarthgap 23/31] gnutls: fix CVE-2026-42009
2026-07-26 8:29 [OE-core][scarthgap 00/31] Patch review Yoann Congal
` (21 preceding siblings ...)
2026-07-26 8:29 ` [OE-core][scarthgap 22/31] gnutls: set status for CVE-2026-3832 Yoann Congal
@ 2026-07-26 8:29 ` Yoann Congal
2026-07-26 8:29 ` [OE-core][scarthgap 24/31] libpng: Fix CVE-2026-34757 Yoann Congal
` (7 subsequent siblings)
30 siblings, 0 replies; 32+ messages in thread
From: Yoann Congal @ 2026-07-26 8:29 UTC (permalink / raw)
To: openembedded-core
From: Sudhir Dumbhare <sudumbha@cisco.com>
This patch applies the upstream fix [1] and [2], as referenced in [3],
to address a DTLS packet reordering flaw where duplicate sequence numbers
could lead to unstable ordering or undefined behavior.
[1] https://gitlab.com/gnutls/gnutls/-/commit/f01e21441e29052a6f0963840794c41d3b3ee66d
[2] https://gitlab.com/gnutls/gnutls/-/commit/f341441fad91142897d83b44a175ffc8f925b76f
[3] https://security-tracker.debian.org/tracker/CVE-2026-42009
Reference:
https://nvd.nist.gov/vuln/detail/CVE-2026-42009
Signed-off-by: Sudhir Dumbhare <sudumbha@cisco.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
---
.../gnutls/gnutls/CVE-2026-42009_p1.patch | 66 +++++++++++++++++++
.../gnutls/gnutls/CVE-2026-42009_p2.patch | 47 +++++++++++++
meta/recipes-support/gnutls/gnutls_3.8.4.bb | 2 +
3 files changed, 115 insertions(+)
create mode 100644 meta/recipes-support/gnutls/gnutls/CVE-2026-42009_p1.patch
create mode 100644 meta/recipes-support/gnutls/gnutls/CVE-2026-42009_p2.patch
diff --git a/meta/recipes-support/gnutls/gnutls/CVE-2026-42009_p1.patch b/meta/recipes-support/gnutls/gnutls/CVE-2026-42009_p1.patch
new file mode 100644
index 00000000000..03214bab0ea
--- /dev/null
+++ b/meta/recipes-support/gnutls/gnutls/CVE-2026-42009_p1.patch
@@ -0,0 +1,66 @@
+From e1f366666c12f431151a04ada9cf9a30d602751b Mon Sep 17 00:00:00 2001
+From: Alexander Sosedkin <asosedkin@redhat.com>
+Date: Tue, 21 Apr 2026 16:52:48 +0200
+Subject: [PATCH] lib/buffers: ensure packets have differing sequence
+ numbers
+
+There should normally be no packets with same sequence number and
+differing handshake type, unless an adversary crafts them.
+Discarding them allows to get rid of packets
+with duplicate sequence ID in the buffer,
+relieving us from the question of how to sort them later.
+
+CVE: CVE-2026-42009
+Upstream-Status: Backport [https://gitlab.com/gnutls/gnutls/-/commit/f01e21441e29052a6f0963840794c41d3b3ee66d]
+
+Backport Changes:
+- Adjusted the upstream hunk to match the GnuTLS 3.8.4 code layout.
+- The upstream commit uses the local recv_buf alias introduced later
+ in v3.8.13 by commit;
+ https://gitlab.com/gnutls/gnutls/-/commit/9deffca528c23bbb218f5ec3bd4bb1bf4cbd1fc0.
+- GnuTLS 3.8.4 does not have that local recv_buf alias in
+ merge_handshake_packet(), so the backport replaces recv_buf[i] with the
+ existing session->internals.handshake_recv_buffer[i] access pattern.
+
+Reported-by: Joshua Rogers of AISLE Research Team <joshua@joshua.hu>
+Fixes: #1848
+Fixes: CVE-2026-42009
+Fixes: GNUTLS-SA-2026-04-29-2
+CVSS: 7.5 High CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
+Signed-off-by: Alexander Sosedkin <asosedkin@redhat.com>
+(cherry picked from commit f01e21441e29052a6f0963840794c41d3b3ee66d)
+Signed-off-by: Sudhir Dumbhare <sudumbha@cisco.com>
+---
+ lib/buffers.c | 16 ++++++++++++++--
+ 1 file changed, 14 insertions(+), 2 deletions(-)
+
+diff --git a/lib/buffers.c b/lib/buffers.c
+index 672380b054..e7f08b5625 100644
+--- a/lib/buffers.c
++++ b/lib/buffers.c
+@@ -968,8 +968,20 @@ static int merge_handshake_packet(gnutls_session_t session,
+ int ret;
+
+ for (i = 0; i < session->internals.handshake_recv_buffer_size; i++) {
+- if (session->internals.handshake_recv_buffer[i].htype ==
+- hsk->htype) {
++ if (session->internals.handshake_recv_buffer[i].sequence == hsk->sequence) {
++ if (session->internals.handshake_recv_buffer[i].htype != hsk->htype) {
++ _gnutls_audit_log(
++ session,
++ "Discarded unexpected handshake packet "
++ "with duplicate sequence %d, but "
++ "mismatched type %s (previously %s)\n",
++ hsk->sequence,
++ _gnutls_handshake2str(hsk->htype),
++ _gnutls_handshake2str(
++ session->internals.handshake_recv_buffer[i].htype));
++ _gnutls_handshake_buffer_clear(hsk);
++ return 0;
++ }
+ exists = 1;
+ pos = i;
+ break;
+--
+2.35.6
+
diff --git a/meta/recipes-support/gnutls/gnutls/CVE-2026-42009_p2.patch b/meta/recipes-support/gnutls/gnutls/CVE-2026-42009_p2.patch
new file mode 100644
index 00000000000..b26491840b5
--- /dev/null
+++ b/meta/recipes-support/gnutls/gnutls/CVE-2026-42009_p2.patch
@@ -0,0 +1,47 @@
+From 23fdcec4c6b5669296295ad3a9f87f6467eeb0f3 Mon Sep 17 00:00:00 2001
+From: Joshua Rogers <joshua@joshua.hu>
+Date: Tue, 21 Apr 2026 18:11:39 +0200
+Subject: [PATCH] buffers: fix handshake_compare when sequence numbers
+ match
+
+The comparator function used for ordering DTLS packets
+by sequence numbers did not follow qsort comparator contracts
+in case of packets with duplicate sequence numbers,
+which could lead to unstable ordering or undefined behaviour.
+Returning 0 in such cases makes the sorting stable.
+
+CVE: CVE-2026-42009
+Upstream-Status: Backport [https://gitlab.com/gnutls/gnutls/-/commit/f341441fad91142897d83b44a175ffc8f925b76f]
+
+Reported-by: Joshua Rogers of AISLE Research Team <joshua@joshua.hu>
+Fixes: #1848
+Fixes: CVE-2026-42009
+Fixes: GNUTLS-SA-2026-04-29-2
+CVSS: 7.5 High CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
+Signed-off-by: Joshua Rogers <joshua@joshua.hu>
+(cherry picked from commit f341441fad91142897d83b44a175ffc8f925b76f)
+Signed-off-by: Sudhir Dumbhare <sudumbha@cisco.com>
+---
+ lib/buffers.c | 6 +-----
+ 1 file changed, 1 insertion(+), 5 deletions(-)
+
+diff --git a/lib/buffers.c b/lib/buffers.c
+index e7f08b5625..1ac27e4e96 100644
+--- a/lib/buffers.c
++++ b/lib/buffers.c
+@@ -844,11 +844,7 @@ static int handshake_compare(const void *_e1, const void *_e2)
+ {
+ const handshake_buffer_st *e1 = _e1;
+ const handshake_buffer_st *e2 = _e2;
+-
+- if (e1->sequence <= e2->sequence)
+- return 1;
+- else
+- return -1;
++ return (e1->sequence < e2->sequence) - (e1->sequence > e2->sequence);
+ }
+
+ #define SSL2_HEADERS 1
+--
+2.35.6
+
diff --git a/meta/recipes-support/gnutls/gnutls_3.8.4.bb b/meta/recipes-support/gnutls/gnutls_3.8.4.bb
index 6d43c58df27..d27d2cfa748 100644
--- a/meta/recipes-support/gnutls/gnutls_3.8.4.bb
+++ b/meta/recipes-support/gnutls/gnutls_3.8.4.bb
@@ -43,6 +43,8 @@ SRC_URI = "https://www.gnupg.org/ftp/gcrypt/gnutls/v${SHRT_VER}/gnutls-${PV}.tar
file://CVE-2025-14831-7.patch \
file://CVE-2025-14831-8.patch \
file://CVE-2025-14831-9.patch \
+ file://CVE-2026-42009_p1.patch \
+ file://CVE-2026-42009_p2.patch \
"
SRC_URI[sha256sum] = "2bea4e154794f3f00180fa2a5c51fe8b005ac7a31cd58bd44cdfa7f36ebc3a9b"
^ permalink raw reply related [flat|nested] 32+ messages in thread
* [OE-core][scarthgap 24/31] libpng: Fix CVE-2026-34757
2026-07-26 8:29 [OE-core][scarthgap 00/31] Patch review Yoann Congal
` (22 preceding siblings ...)
2026-07-26 8:29 ` [OE-core][scarthgap 23/31] gnutls: fix CVE-2026-42009 Yoann Congal
@ 2026-07-26 8:29 ` Yoann Congal
2026-07-26 8:29 ` [OE-core][scarthgap 25/31] glib-2.0: fix CVE-2026-58010 Yoann Congal
` (6 subsequent siblings)
30 siblings, 0 replies; 32+ messages in thread
From: Yoann Congal @ 2026-07-26 8:29 UTC (permalink / raw)
To: openembedded-core
From: Sudhir Dumbhare <sudumbha@cisco.com>
These patches apply the upstream fixes [1][2], which address
getter-to-setter aliasing issues in libpng chunk setters that could
cause stale-pointer reads, as described in [3].
[1] https://github.com/pnggroup/libpng/commit/398cbe3df03f4e11bb031e07f416dfdde3684e8a
[2] https://github.com/pnggroup/libpng/commit/55d20aaa322c9274491cda82c5cd4f99b48c6bcc
[3] https://github.com/pnggroup/libpng/issues/836
Reference:
https://security-tracker.debian.org/tracker/CVE-2026-34757
https://nvd.nist.gov/vuln/detail/CVE-2026-34757
Test results on qemux86-64 using ptest-runner:
START: ptest-runner
2026-06-04T11:29
BEGIN: /usr/lib/libpng/ptest
PASS: tests/pnggetset
Testsuite summary
# TOTAL: 33
# PASS: 33
# SKIP: 0
# XFAIL: 0
# FAIL: 0
# XPASS: 0
# ERROR: 0
DURATION: 80
END: /usr/lib/libpng/ptest
2026-06-04T11:31
STOP: ptest-runner
TOTAL: 1 FAIL: 0
Signed-off-by: Sudhir Dumbhare <sudumbha@cisco.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
---
.../libpng/files/CVE-2026-34757_p1.patch | 521 ++++++++++++++++++
.../libpng/files/CVE-2026-34757_p2.patch | 484 ++++++++++++++++
.../libpng/libpng_1.6.42.bb | 4 +-
3 files changed, 1008 insertions(+), 1 deletion(-)
create mode 100644 meta/recipes-multimedia/libpng/files/CVE-2026-34757_p1.patch
create mode 100644 meta/recipes-multimedia/libpng/files/CVE-2026-34757_p2.patch
diff --git a/meta/recipes-multimedia/libpng/files/CVE-2026-34757_p1.patch b/meta/recipes-multimedia/libpng/files/CVE-2026-34757_p1.patch
new file mode 100644
index 00000000000..cd8150b1a45
--- /dev/null
+++ b/meta/recipes-multimedia/libpng/files/CVE-2026-34757_p1.patch
@@ -0,0 +1,521 @@
+From 1fb509cdff1f9d83e2bf160259529a742de9285f Mon Sep 17 00:00:00 2001
+From: Cosmin Truta <ctruta@gmail.com>
+Date: Mon, 30 Mar 2026 17:35:30 +0300
+Subject: [PATCH] fix: Handle self-referencing pointers in getter-to-setter
+ aliasing
+
+Apply a robustness fix for a caller-side API usage pattern involving
+the getters and the setters for PLTE, tRNS, and hIST.
+
+Passing a pointer returned by the PLTE, tRNS, or hIST getters back
+into the corresponding setters used to cause the setters to read from
+a stale pointer. The fix consists in snapshotting the caller's data
+into a stack-local buffer before freeing the old internal storage.
+
+Fixes pnggroup/libpng#836
+
+CVE: CVE-2026-34757
+Upstream-Status: Backport [https://github.com/pnggroup/libpng/commit/398cbe3df03f4e11bb031e07f416dfdde3684e8a]
+
+Reported-by: Iv4n <Iv4n550@noreply.github.com>
+(cherry picked from commit 398cbe3df03f4e11bb031e07f416dfdde3684e8a)
+Signed-off-by: Sudhir Dumbhare <sudumbha@cisco.com>
+---
+ CMakeLists.txt | 12 ++
+ Makefile.am | 9 +-
+ contrib/libtests/pnggetset.c | 328 +++++++++++++++++++++++++++++++++++
+ pngset.c | 29 +++-
+ tests/pnggetset | 5 +
+ 5 files changed, 380 insertions(+), 3 deletions(-)
+ create mode 100644 contrib/libtests/pnggetset.c
+ create mode 100755 tests/pnggetset
+
+diff --git a/CMakeLists.txt b/CMakeLists.txt
+index 93a2c3434..8888d15cb 100644
+--- a/CMakeLists.txt
++++ b/CMakeLists.txt
+@@ -591,6 +591,9 @@ set(pngvalid_sources
+ set(pngstest_sources
+ contrib/libtests/pngstest.c
+ )
++set(pnggetset_sources
++ contrib/libtests/pnggetset.c
++)
+ set(pngunknown_sources
+ contrib/libtests/pngunknown.c
+ )
+@@ -758,6 +761,15 @@ if(PNG_TESTS AND PNG_SHARED)
+ COMMAND pngtest
+ FILES "${PNGTEST_PNG}")
+
++ # pnggetset test:
++ # Getter-to-setter roundtrips for various chunk types.
++ add_executable(pnggetset ${pnggetset_sources})
++ target_link_libraries(pnggetset
++ PRIVATE png_shared)
++
++ png_add_test(NAME pnggetset
++ COMMAND pnggetset)
++
+ add_executable(pngvalid ${pngvalid_sources})
+ target_link_libraries(pngvalid PRIVATE png_shared)
+
+diff --git a/Makefile.am b/Makefile.am
+index 1f06c703a..bdb40c61c 100644
+--- a/Makefile.am
++++ b/Makefile.am
+@@ -13,7 +13,7 @@ ACLOCAL_AMFLAGS = -I scripts/autoconf
+
+ # test programs - run on make check, make distcheck
+ if ENABLE_TESTS
+-check_PROGRAMS= pngtest pngunknown pngstest pngvalid pngimage pngcp
++check_PROGRAMS= pngtest pnggetset pngunknown pngstest pngvalid pngimage pngcp
+ if HAVE_CLOCK_GETTIME
+ check_PROGRAMS += timepng
+ endif
+@@ -42,6 +42,9 @@ if ENABLE_TESTS
+ pngtest_SOURCES = pngtest.c
+ pngtest_LDADD = libpng@PNGLIB_MAJOR@@PNGLIB_MINOR@.la
+
++pnggetset_SOURCES = contrib/libtests/pnggetset.c
++pnggetset_LDADD = libpng@PNGLIB_MAJOR@@PNGLIB_MINOR@.la
++
+ pngvalid_SOURCES = contrib/libtests/pngvalid.c
+ pngvalid_LDADD = libpng@PNGLIB_MAJOR@@PNGLIB_MINOR@.la
+
+@@ -75,6 +78,7 @@ TESTS =\
+ tests/pngtest-all\
+ tests/pngvalid-gamma-16-to-8 tests/pngvalid-gamma-alpha-mode\
+ tests/pngvalid-gamma-background tests/pngvalid-gamma-expand16-alpha-mode\
++ tests/pnggetset\
+ tests/pngvalid-gamma-expand16-background\
+ tests/pngvalid-gamma-expand16-transform tests/pngvalid-gamma-sbit\
+ tests/pngvalid-gamma-threshold tests/pngvalid-gamma-transform\
+@@ -273,9 +277,10 @@ $(srcdir)/scripts/pnglibconf.h.prebuilt:
+ pngtest.o: pnglibconf.h
+
+ contrib/libtests/makepng.o: pnglibconf.h
++contrib/libtests/pnggetset.o: pnglibconf.h
++contrib/libtests/pngimage.o: pnglibconf.h
+ contrib/libtests/pngstest.o: pnglibconf.h
+ contrib/libtests/pngunknown.o: pnglibconf.h
+-contrib/libtests/pngimage.o: pnglibconf.h
+ contrib/libtests/pngvalid.o: pnglibconf.h
+ contrib/libtests/readpng.o: pnglibconf.h
+ contrib/libtests/tarith.o: pnglibconf.h
+diff --git a/contrib/libtests/pnggetset.c b/contrib/libtests/pnggetset.c
+new file mode 100644
+index 000000000..b42508094
+--- /dev/null
++++ b/contrib/libtests/pnggetset.c
+@@ -0,0 +1,328 @@
++/* pnggetset.c
++ *
++ * Copyright (c) 2026 Cosmin Truta
++ *
++ * This code is released under the libpng license.
++ * For conditions of distribution and use, see the disclaimer
++ * and license in png.h
++ *
++ * Test the get-then-set roundtrip pattern for PLTE, tRNS, and hIST.
++ *
++ * Passing the internal pointer returned by a getter back into the
++ * corresponding setter is a natural API usage pattern. A previous
++ * version had a use-after-free on this path because the setter freed
++ * the internal buffer before copying from the caller-supplied pointer.
++ */
++
++#include <stdio.h>
++#include <stdlib.h>
++#include <string.h>
++
++#if defined(HAVE_CONFIG_H) && !defined(PNG_NO_CONFIG_H)
++# include <config.h>
++#endif
++
++#ifdef PNG_FREESTANDING_TESTS
++# include <png.h>
++#else
++# include "../../png.h"
++#endif
++
++/* Test: get the PLTE, pass it straight back to set, verify roundtrip. */
++static int
++test_plte_roundtrip(void)
++{
++ png_structp png_ptr;
++ png_infop info_ptr;
++ png_color palette[4];
++ png_colorp got_palette = NULL;
++ int num_palette = 0;
++ int i;
++
++ png_ptr = png_create_write_struct(PNG_LIBPNG_VER_STRING,
++ NULL, NULL, NULL);
++ if (png_ptr == NULL)
++ {
++ fprintf(stderr, "pnggetset: png_create_write_struct failed\n");
++ return 1;
++ }
++
++ info_ptr = png_create_info_struct(png_ptr);
++ if (info_ptr == NULL)
++ {
++ fprintf(stderr, "pnggetset: png_create_info_struct failed\n");
++ png_destroy_write_struct(&png_ptr, NULL);
++ return 1;
++ }
++
++ if (setjmp(png_jmpbuf(png_ptr)))
++ {
++ fprintf(stderr, "pnggetset: libpng error in test_plte_roundtrip\n");
++ png_destroy_write_struct(&png_ptr, &info_ptr);
++ return 1;
++ }
++
++ /* Set up a palette-color image header. */
++ png_set_IHDR(png_ptr, info_ptr, 1, 1, 8, PNG_COLOR_TYPE_PALETTE,
++ PNG_INTERLACE_NONE, PNG_COMPRESSION_TYPE_BASE, PNG_FILTER_TYPE_BASE);
++
++ /* Populate with recognizable values. */
++ for (i = 0; i < 4; i++)
++ {
++ palette[i].red = (png_byte)(i * 10);
++ palette[i].green = (png_byte)(i * 20);
++ palette[i].blue = (png_byte)(i * 30);
++ }
++ png_set_PLTE(png_ptr, info_ptr, palette, 4);
++
++ /* Get the internal pointer and feed it straight back. */
++ png_get_PLTE(png_ptr, info_ptr, &got_palette, &num_palette);
++ if (got_palette == NULL || num_palette != 4)
++ {
++ fprintf(stderr, "pnggetset: png_get_PLTE returned unexpected values\n");
++ png_destroy_write_struct(&png_ptr, &info_ptr);
++ return 1;
++ }
++
++ /* This is the critical call: the pointer aliases info_ptr->palette. */
++ png_set_PLTE(png_ptr, info_ptr, got_palette, num_palette);
++
++ /* Verify the data survived the roundtrip. */
++ got_palette = NULL;
++ num_palette = 0;
++ png_get_PLTE(png_ptr, info_ptr, &got_palette, &num_palette);
++ if (got_palette == NULL || num_palette != 4)
++ {
++ fprintf(stderr, "pnggetset: PLTE lost after roundtrip\n");
++ png_destroy_write_struct(&png_ptr, &info_ptr);
++ return 1;
++ }
++ for (i = 0; i < 4; i++)
++ {
++ if (got_palette[i].red != (png_byte)(i * 10) ||
++ got_palette[i].green != (png_byte)(i * 20) ||
++ got_palette[i].blue != (png_byte)(i * 30))
++ {
++ fprintf(stderr,
++ "pnggetset: PLTE entry %d corrupted after roundtrip\n", i);
++ png_destroy_write_struct(&png_ptr, &info_ptr);
++ return 1;
++ }
++ }
++
++ png_destroy_write_struct(&png_ptr, &info_ptr);
++ return 0;
++}
++
++#ifdef PNG_hIST_SUPPORTED
++/* Test: get the hIST, pass it straight back to set, verify roundtrip. */
++static int
++test_hist_roundtrip(void)
++{
++ png_structp png_ptr;
++ png_infop info_ptr;
++ png_color palette[4];
++ png_uint_16 hist[4];
++ png_uint_16p got_hist = NULL;
++ int i;
++
++ png_ptr = png_create_write_struct(PNG_LIBPNG_VER_STRING,
++ NULL, NULL, NULL);
++ if (png_ptr == NULL)
++ {
++ fprintf(stderr, "pnggetset: png_create_write_struct failed\n");
++ return 1;
++ }
++
++ info_ptr = png_create_info_struct(png_ptr);
++ if (info_ptr == NULL)
++ {
++ fprintf(stderr, "pnggetset: png_create_info_struct failed\n");
++ png_destroy_write_struct(&png_ptr, NULL);
++ return 1;
++ }
++
++ if (setjmp(png_jmpbuf(png_ptr)))
++ {
++ fprintf(stderr, "pnggetset: libpng error in test_hist_roundtrip\n");
++ png_destroy_write_struct(&png_ptr, &info_ptr);
++ return 1;
++ }
++
++ /* Set up a palette-color image header. */
++ memset(palette, 0, sizeof palette);
++ png_set_IHDR(png_ptr, info_ptr, 1, 1, 8, PNG_COLOR_TYPE_PALETTE,
++ PNG_INTERLACE_NONE, PNG_COMPRESSION_TYPE_BASE, PNG_FILTER_TYPE_BASE);
++ png_set_PLTE(png_ptr, info_ptr, palette, 4);
++
++ /* Populate with recognizable values. */
++ for (i = 0; i < 4; i++)
++ hist[i] = (png_uint_16)(i * 100 + 42);
++
++ png_set_hIST(png_ptr, info_ptr, hist);
++
++ /* Get the internal pointer and feed it straight back. */
++ if (png_get_hIST(png_ptr, info_ptr, &got_hist) == 0 || got_hist == NULL)
++ {
++ fprintf(stderr, "pnggetset: png_get_hIST returned unexpected values\n");
++ png_destroy_write_struct(&png_ptr, &info_ptr);
++ return 1;
++ }
++
++ /* This is the critical call: the pointer aliases info_ptr->hist. */
++ png_set_hIST(png_ptr, info_ptr, got_hist);
++
++ /* Verify the data survived the roundtrip. */
++ got_hist = NULL;
++ if (png_get_hIST(png_ptr, info_ptr, &got_hist) == 0 || got_hist == NULL)
++ {
++ fprintf(stderr, "pnggetset: hIST lost after roundtrip\n");
++ png_destroy_write_struct(&png_ptr, &info_ptr);
++ return 1;
++ }
++ for (i = 0; i < 4; i++)
++ {
++ if (got_hist[i] != (png_uint_16)(i * 100 + 42))
++ {
++ fprintf(stderr,
++ "pnggetset: hIST entry %d corrupted after roundtrip\n", i);
++ png_destroy_write_struct(&png_ptr, &info_ptr);
++ return 1;
++ }
++ }
++
++ png_destroy_write_struct(&png_ptr, &info_ptr);
++ return 0;
++}
++#endif /* PNG_hIST_SUPPORTED */
++
++#ifdef PNG_tRNS_SUPPORTED
++/* Test: get the tRNS, pass it straight back to set, verify roundtrip. */
++static int
++test_trns_roundtrip(void)
++{
++ png_structp png_ptr;
++ png_infop info_ptr;
++ png_color palette[4];
++ png_byte trans_alpha[4];
++ png_color_16 trans_color;
++ png_bytep got_alpha = NULL;
++ png_color_16p got_color = NULL;
++ int num_trans = 0;
++ int i;
++
++ png_ptr = png_create_write_struct(PNG_LIBPNG_VER_STRING,
++ NULL, NULL, NULL);
++ if (png_ptr == NULL)
++ {
++ fprintf(stderr, "pnggetset: png_create_write_struct failed\n");
++ return 1;
++ }
++
++ info_ptr = png_create_info_struct(png_ptr);
++ if (info_ptr == NULL)
++ {
++ fprintf(stderr, "pnggetset: png_create_info_struct failed\n");
++ png_destroy_write_struct(&png_ptr, NULL);
++ return 1;
++ }
++
++ if (setjmp(png_jmpbuf(png_ptr)))
++ {
++ fprintf(stderr, "pnggetset: libpng error in test_trns_roundtrip\n");
++ png_destroy_write_struct(&png_ptr, &info_ptr);
++ return 1;
++ }
++
++ /* Set up a palette-color image. */
++ memset(palette, 0, sizeof palette);
++ png_set_IHDR(png_ptr, info_ptr, 1, 1, 8, PNG_COLOR_TYPE_PALETTE,
++ PNG_INTERLACE_NONE, PNG_COMPRESSION_TYPE_BASE, PNG_FILTER_TYPE_BASE);
++ png_set_PLTE(png_ptr, info_ptr, palette, 4);
++
++ /* Populate tRNS with recognizable values. */
++ for (i = 0; i < 4; i++)
++ trans_alpha[i] = (png_byte)(0xff - i * 0x11);
++ memset(&trans_color, 0, sizeof trans_color);
++
++ png_set_tRNS(png_ptr, info_ptr, trans_alpha, 4, &trans_color);
++
++ /* Get the internal pointer and feed it straight back. */
++ png_get_tRNS(png_ptr, info_ptr, &got_alpha, &num_trans, &got_color);
++ if (got_alpha == NULL || num_trans != 4)
++ {
++ fprintf(stderr, "pnggetset: png_get_tRNS returned unexpected values\n");
++ png_destroy_write_struct(&png_ptr, &info_ptr);
++ return 1;
++ }
++
++ /* This is the critical call: the pointer aliases info_ptr->trans_alpha. */
++ png_set_tRNS(png_ptr, info_ptr, got_alpha, num_trans, got_color);
++
++ /* Verify the data survived the roundtrip. */
++ got_alpha = NULL;
++ num_trans = 0;
++ png_get_tRNS(png_ptr, info_ptr, &got_alpha, &num_trans, &got_color);
++ if (got_alpha == NULL || num_trans != 4)
++ {
++ fprintf(stderr, "pnggetset: tRNS lost after roundtrip\n");
++ png_destroy_write_struct(&png_ptr, &info_ptr);
++ return 1;
++ }
++ for (i = 0; i < 4; i++)
++ {
++ if (got_alpha[i] != (png_byte)(0xff - i * 0x11))
++ {
++ fprintf(stderr,
++ "pnggetset: tRNS entry %d corrupted after roundtrip\n", i);
++ png_destroy_write_struct(&png_ptr, &info_ptr);
++ return 1;
++ }
++ }
++
++ png_destroy_write_struct(&png_ptr, &info_ptr);
++ return 0;
++}
++#endif /* PNG_tRNS_SUPPORTED */
++
++int
++main(void)
++{
++ int result = 0;
++
++ printf("Testing PLTE get-then-set roundtrip... ");
++ fflush(stdout);
++ if (test_plte_roundtrip() != 0)
++ {
++ printf("FAIL\n");
++ result = 1;
++ }
++ else
++ printf("PASS\n");
++
++#ifdef PNG_hIST_SUPPORTED
++ printf("Testing hIST get-then-set roundtrip... ");
++ fflush(stdout);
++ if (test_hist_roundtrip() != 0)
++ {
++ printf("FAIL\n");
++ result = 1;
++ }
++ else
++ printf("PASS\n");
++#endif
++
++#ifdef PNG_tRNS_SUPPORTED
++ printf("Testing tRNS get-then-set roundtrip... ");
++ fflush(stdout);
++ if (test_trns_roundtrip() != 0)
++ {
++ printf("FAIL\n");
++ result = 1;
++ }
++ else
++ printf("PASS\n");
++#endif
++
++ return result;
++}
+diff --git a/pngset.c b/pngset.c
+index c4a0958aa..9f5c44510 100644
+--- a/pngset.c
++++ b/pngset.c
+@@ -204,6 +204,7 @@ void PNGAPI
+ png_set_hIST(png_const_structrp png_ptr, png_inforp info_ptr,
+ png_const_uint_16p hist)
+ {
++ png_uint_16 safe_hist[PNG_MAX_PALETTE_LENGTH];
+ int i;
+
+ png_debug1(1, "in %s storage function", "hIST");
+@@ -220,6 +221,13 @@ png_set_hIST(png_const_structrp png_ptr, png_inforp info_ptr,
+ return;
+ }
+
++ /* Snapshot the caller's hist before freeing, in case it points to
++ * info_ptr->hist (getter-to-setter aliasing).
++ */
++ memcpy(safe_hist, hist, (unsigned int)info_ptr->num_palette *
++ (sizeof (png_uint_16)));
++ hist = safe_hist;
++
+ png_free_data(png_ptr, info_ptr, PNG_FREE_HIST, 0);
+
+ /* Changed from info->num_palette to PNG_MAX_PALETTE_LENGTH in
+@@ -561,7 +569,7 @@ void PNGAPI
+ png_set_PLTE(png_structrp png_ptr, png_inforp info_ptr,
+ png_const_colorp palette, int num_palette)
+ {
+-
++ png_color safe_palette[PNG_MAX_PALETTE_LENGTH];
+ png_uint_32 max_palette_length;
+
+ png_debug1(1, "in %s storage function", "PLTE");
+@@ -595,6 +603,15 @@ png_set_PLTE(png_structrp png_ptr, png_inforp info_ptr,
+ png_error(png_ptr, "Invalid palette");
+ }
+
++ /* Snapshot the caller's palette before freeing, in case it points to
++ * info_ptr->palette (getter-to-setter aliasing).
++ */
++ if (num_palette > 0)
++ memcpy(safe_palette, palette, (unsigned int)num_palette *
++ (sizeof (png_color)));
++
++ palette = safe_palette;
++
+ png_free_data(png_ptr, info_ptr, PNG_FREE_PLTE, 0);
+
+ /* Changed in libpng-1.2.1 to allocate PNG_MAX_PALETTE_LENGTH instead
+@@ -1000,6 +1017,16 @@ png_set_tRNS(png_structrp png_ptr, png_inforp info_ptr,
+
+ if (trans_alpha != NULL)
+ {
++ /* Snapshot the caller's trans_alpha before freeing, in case it
++ * points to info_ptr->trans_alpha (getter-to-setter aliasing).
++ */
++ png_byte safe_trans[PNG_MAX_PALETTE_LENGTH];
++
++ if (num_trans > 0 && num_trans <= PNG_MAX_PALETTE_LENGTH)
++ memcpy(safe_trans, trans_alpha, (size_t)num_trans);
++
++ trans_alpha = safe_trans;
++
+ png_free_data(png_ptr, info_ptr, PNG_FREE_TRNS, 0);
+
+ if (num_trans > 0 && num_trans <= PNG_MAX_PALETTE_LENGTH)
+diff --git a/tests/pnggetset b/tests/pnggetset
+new file mode 100755
+index 000000000..57ef731a5
+--- /dev/null
++++ b/tests/pnggetset
+@@ -0,0 +1,5 @@
++#!/bin/sh
++
++# pnggetset test:
++# Getter-to-setter roundtrips for various chunk types.
++exec ./pnggetset
+--
+2.51.0
+
diff --git a/meta/recipes-multimedia/libpng/files/CVE-2026-34757_p2.patch b/meta/recipes-multimedia/libpng/files/CVE-2026-34757_p2.patch
new file mode 100644
index 00000000000..7d58ead18de
--- /dev/null
+++ b/meta/recipes-multimedia/libpng/files/CVE-2026-34757_p2.patch
@@ -0,0 +1,484 @@
+From 2d1c6585d356832bb679ad4d313f5ea542e02064 Mon Sep 17 00:00:00 2001
+From: Cosmin Truta <ctruta@gmail.com>
+Date: Mon, 30 Mar 2026 17:43:05 +0300
+Subject: [PATCH] fix: Handle getter-to-setter aliasing in append-style
+ chunk setters
+
+Apply the same class of robustness fix from the previous commit to
+`png_set_text`, `png_set_sPLT` and `png_set_unknown_chunks`. These
+append-style setters used `png_realloc_array` to grow the internal
+array, then freed the old array before copying from the caller's
+input. If the caller's pointer was obtained from the corresponding
+getter, it aliased the freed array.
+
+The fix defers the freeing of the old array until after the copy loop.
+
+Also extend the pnggetset regression test to cover all three setters.
+
+CVE: CVE-2026-34757
+Upstream-Status: Backport [https://github.com/pnggroup/libpng/commit/55d20aaa322c9274491cda82c5cd4f99b48c6bcc]
+
+(cherry picked from commit 55d20aaa322c9274491cda82c5cd4f99b48c6bcc)
+Signed-off-by: Sudhir Dumbhare <sudumbha@cisco.com>
+---
+ contrib/libtests/pnggetset.c | 330 ++++++++++++++++++++++++++++++++++-
+ pngset.c | 25 ++-
+ 2 files changed, 347 insertions(+), 8 deletions(-)
+
+diff --git a/contrib/libtests/pnggetset.c b/contrib/libtests/pnggetset.c
+index b42508094..6ae43dc66 100644
+--- a/contrib/libtests/pnggetset.c
++++ b/contrib/libtests/pnggetset.c
+@@ -6,12 +6,12 @@
+ * For conditions of distribution and use, see the disclaimer
+ * and license in png.h
+ *
+- * Test the get-then-set roundtrip pattern for PLTE, tRNS, and hIST.
++ * Test the get-then-set roundtrip for chunk types whose getters return
++ * a pointer to internal storage.
+ *
+- * Passing the internal pointer returned by a getter back into the
+- * corresponding setter is a natural API usage pattern. A previous
+- * version had a use-after-free on this path because the setter freed
+- * the internal buffer before copying from the caller-supplied pointer.
++ * Passing such a pointer back into the corresponding setter must not
++ * cause a use-after-free. A previous version freed the internal buffer
++ * before copying from the caller-supplied pointer.
+ */
+
+ #include <stdio.h>
+@@ -285,6 +285,290 @@ test_trns_roundtrip(void)
+ }
+ #endif /* PNG_tRNS_SUPPORTED */
+
++#ifdef PNG_TEXT_SUPPORTED
++/* Test: get the text array, pass it straight back to set, verify data. */
++#define TEXT_COUNT 6 /* enough to trigger reallocation on the second set */
++static int
++test_text_roundtrip(void)
++{
++ png_structp png_ptr;
++ png_infop info_ptr;
++ png_text text_entries[TEXT_COUNT];
++ png_textp got_text = NULL;
++ int got_num_text = 0;
++ int i;
++
++ /* Recognizable keys and values. */
++ static const char *keys[TEXT_COUNT] = {
++ "Title", "Author", "Desc", "Copyright", "Source", "Comment"
++ };
++ static const char *vals[TEXT_COUNT] = {
++ "t0", "t1", "t2", "t3", "t4", "t5"
++ };
++
++ png_ptr = png_create_write_struct(PNG_LIBPNG_VER_STRING,
++ NULL, NULL, NULL);
++ if (png_ptr == NULL)
++ {
++ fprintf(stderr, "pnggetset: png_create_write_struct failed\n");
++ return 1;
++ }
++
++ info_ptr = png_create_info_struct(png_ptr);
++ if (info_ptr == NULL)
++ {
++ fprintf(stderr, "pnggetset: png_create_info_struct failed\n");
++ png_destroy_write_struct(&png_ptr, NULL);
++ return 1;
++ }
++
++ if (setjmp(png_jmpbuf(png_ptr)))
++ {
++ fprintf(stderr, "pnggetset: libpng error in test_text_roundtrip\n");
++ png_destroy_write_struct(&png_ptr, &info_ptr);
++ return 1;
++ }
++
++ /* Populate the text entries. */
++ memset(text_entries, 0, sizeof text_entries);
++ for (i = 0; i < TEXT_COUNT; i++)
++ {
++ text_entries[i].compression = PNG_TEXT_COMPRESSION_NONE;
++ text_entries[i].key = (png_charp)keys[i];
++ text_entries[i].text = (png_charp)vals[i];
++ }
++ png_set_text(png_ptr, info_ptr, text_entries, TEXT_COUNT);
++
++ /* Get the internal pointer and feed it straight back (append). */
++ png_get_text(png_ptr, info_ptr, &got_text, &got_num_text);
++ if (got_text == NULL || got_num_text != TEXT_COUNT)
++ {
++ fprintf(stderr, "pnggetset: png_get_text returned unexpected values\n");
++ png_destroy_write_struct(&png_ptr, &info_ptr);
++ return 1;
++ }
++
++ /* This is the critical call: got_text aliases info_ptr->text. */
++ png_set_text(png_ptr, info_ptr, got_text, got_num_text);
++
++ /* Verify the original entries survived. */
++ got_text = NULL;
++ got_num_text = 0;
++ png_get_text(png_ptr, info_ptr, &got_text, &got_num_text);
++ if (got_text == NULL || got_num_text != TEXT_COUNT * 2)
++ {
++ fprintf(stderr, "pnggetset: text count %d, expected %d after roundtrip\n",
++ got_num_text, TEXT_COUNT * 2);
++ png_destroy_write_struct(&png_ptr, &info_ptr);
++ return 1;
++ }
++ for (i = 0; i < TEXT_COUNT; i++)
++ {
++ if (got_text[i].key == NULL ||
++ strcmp(got_text[i].key, keys[i]) != 0 ||
++ got_text[i].text == NULL ||
++ strcmp(got_text[i].text, vals[i]) != 0)
++ {
++ fprintf(stderr,
++ "pnggetset: text entry %d corrupted after roundtrip\n", i);
++ png_destroy_write_struct(&png_ptr, &info_ptr);
++ return 1;
++ }
++ }
++
++ png_destroy_write_struct(&png_ptr, &info_ptr);
++ return 0;
++}
++#undef TEXT_COUNT
++#endif /* PNG_TEXT_SUPPORTED */
++
++#ifdef PNG_sPLT_SUPPORTED
++/* Test: get the sPLT array, pass it straight back to set, verify data. */
++static int
++test_splt_roundtrip(void)
++{
++ png_structp png_ptr;
++ png_infop info_ptr;
++ png_sPLT_t splt;
++ png_sPLT_entry splt_entries[4];
++ png_sPLT_tp got_spalettes = NULL;
++ int got_num, i;
++
++ png_ptr = png_create_write_struct(PNG_LIBPNG_VER_STRING,
++ NULL, NULL, NULL);
++ if (png_ptr == NULL)
++ {
++ fprintf(stderr, "pnggetset: png_create_write_struct failed\n");
++ return 1;
++ }
++
++ info_ptr = png_create_info_struct(png_ptr);
++ if (info_ptr == NULL)
++ {
++ fprintf(stderr, "pnggetset: png_create_info_struct failed\n");
++ png_destroy_write_struct(&png_ptr, NULL);
++ return 1;
++ }
++
++ if (setjmp(png_jmpbuf(png_ptr)))
++ {
++ fprintf(stderr, "pnggetset: libpng error in test_splt_roundtrip\n");
++ png_destroy_write_struct(&png_ptr, &info_ptr);
++ return 1;
++ }
++
++ /* Populate with recognizable values. */
++ memset(splt_entries, 0, sizeof splt_entries);
++ for (i = 0; i < 4; i++)
++ {
++ splt_entries[i].red = (png_uint_16)(i * 1000);
++ splt_entries[i].green = (png_uint_16)(i * 2000);
++ splt_entries[i].blue = (png_uint_16)(i * 3000);
++ splt_entries[i].alpha = 0xffffU;
++ splt_entries[i].frequency = (png_uint_16)(i + 1);
++ }
++ memset(&splt, 0, sizeof splt);
++ splt.name = (png_charp)"test_sPLT";
++ splt.depth = 16;
++ splt.entries = splt_entries;
++ splt.nentries = 4;
++
++ png_set_sPLT(png_ptr, info_ptr, &splt, 1);
++
++ /* Get the internal pointer and feed it straight back (append). */
++ got_num = png_get_sPLT(png_ptr, info_ptr, &got_spalettes);
++ if (got_spalettes == NULL || got_num != 1)
++ {
++ fprintf(stderr, "pnggetset: png_get_sPLT returned unexpected values\n");
++ png_destroy_write_struct(&png_ptr, &info_ptr);
++ return 1;
++ }
++
++ /* This is the critical call: got_spalettes aliases internal storage. */
++ png_set_sPLT(png_ptr, info_ptr, got_spalettes, got_num);
++
++ /* Verify the original entry survived. */
++ got_spalettes = NULL;
++ got_num = png_get_sPLT(png_ptr, info_ptr, &got_spalettes);
++ if (got_spalettes == NULL || got_num != 2)
++ {
++ fprintf(stderr, "pnggetset: sPLT count %d, expected 2 after roundtrip\n",
++ got_num);
++ png_destroy_write_struct(&png_ptr, &info_ptr);
++ return 1;
++ }
++ if (strcmp(got_spalettes[0].name, "test_sPLT") != 0 ||
++ got_spalettes[0].nentries != 4 ||
++ got_spalettes[0].depth != 16)
++ {
++ fprintf(stderr,
++ "pnggetset: sPLT entry 0 corrupted after roundtrip\n");
++ png_destroy_write_struct(&png_ptr, &info_ptr);
++ return 1;
++ }
++ for (i = 0; i < 4; i++)
++ {
++ if (got_spalettes[0].entries[i].red != (png_uint_16)(i * 1000) ||
++ got_spalettes[0].entries[i].green != (png_uint_16)(i * 2000) ||
++ got_spalettes[0].entries[i].blue != (png_uint_16)(i * 3000))
++ {
++ fprintf(stderr,
++ "pnggetset: sPLT[0] entry %d corrupted after roundtrip\n", i);
++ png_destroy_write_struct(&png_ptr, &info_ptr);
++ return 1;
++ }
++ }
++
++ png_destroy_write_struct(&png_ptr, &info_ptr);
++ return 0;
++}
++#endif /* PNG_sPLT_SUPPORTED */
++
++#ifdef PNG_STORE_UNKNOWN_CHUNKS_SUPPORTED
++/* Test: get unknown chunks, pass them straight back to set, verify data. */
++static int
++test_unknown_roundtrip(void)
++{
++ png_structp png_ptr;
++ png_infop info_ptr;
++ png_unknown_chunk unk;
++ png_unknown_chunkp got_unknowns = NULL;
++ int got_num;
++ static const png_byte test_data[] = {0xde, 0xad, 0xbe, 0xef};
++
++ png_ptr = png_create_write_struct(PNG_LIBPNG_VER_STRING,
++ NULL, NULL, NULL);
++ if (png_ptr == NULL)
++ {
++ fprintf(stderr, "pnggetset: png_create_write_struct failed\n");
++ return 1;
++ }
++
++ info_ptr = png_create_info_struct(png_ptr);
++ if (info_ptr == NULL)
++ {
++ fprintf(stderr, "pnggetset: png_create_info_struct failed\n");
++ png_destroy_write_struct(&png_ptr, NULL);
++ return 1;
++ }
++
++ if (setjmp(png_jmpbuf(png_ptr)))
++ {
++ fprintf(stderr,
++ "pnggetset: libpng error in test_unknown_roundtrip\n");
++ png_destroy_write_struct(&png_ptr, &info_ptr);
++ return 1;
++ }
++
++ /* Set up an unknown chunk with recognizable data. */
++ memset(&unk, 0, sizeof unk);
++ memcpy(unk.name, "teSt", 5);
++ unk.data = (png_bytep)test_data;
++ unk.size = sizeof test_data;
++ unk.location = PNG_HAVE_IHDR;
++
++ png_set_keep_unknown_chunks(png_ptr, PNG_HANDLE_CHUNK_ALWAYS, NULL, 0);
++ png_set_unknown_chunks(png_ptr, info_ptr, &unk, 1);
++
++ /* Get the internal pointer and feed it straight back (append). */
++ got_num = png_get_unknown_chunks(png_ptr, info_ptr, &got_unknowns);
++ if (got_unknowns == NULL || got_num != 1)
++ {
++ fprintf(stderr,
++ "pnggetset: png_get_unknown_chunks returned unexpected values\n");
++ png_destroy_write_struct(&png_ptr, &info_ptr);
++ return 1;
++ }
++
++ /* This is the critical call: got_unknowns aliases internal storage. */
++ png_set_unknown_chunks(png_ptr, info_ptr, got_unknowns, got_num);
++
++ /* Verify the original entry survived. */
++ got_unknowns = NULL;
++ got_num = png_get_unknown_chunks(png_ptr, info_ptr, &got_unknowns);
++ if (got_unknowns == NULL || got_num != 2)
++ {
++ fprintf(stderr,
++ "pnggetset: unknown_chunks count %d, expected 2 after roundtrip\n",
++ got_num);
++ png_destroy_write_struct(&png_ptr, &info_ptr);
++ return 1;
++ }
++ if (memcmp(got_unknowns[0].name, "teSt", 4) != 0 ||
++ got_unknowns[0].size != sizeof test_data ||
++ memcmp(got_unknowns[0].data, test_data, sizeof test_data) != 0)
++ {
++ fprintf(stderr,
++ "pnggetset: unknown chunk 0 corrupted after roundtrip\n");
++ png_destroy_write_struct(&png_ptr, &info_ptr);
++ return 1;
++ }
++
++ png_destroy_write_struct(&png_ptr, &info_ptr);
++ return 0;
++}
++#endif /* PNG_STORE_UNKNOWN_CHUNKS_SUPPORTED */
++
+ int
+ main(void)
+ {
+@@ -324,5 +608,41 @@ main(void)
+ printf("PASS\n");
+ #endif
+
++#ifdef PNG_TEXT_SUPPORTED
++ printf("Testing tEXt get-then-set roundtrip... ");
++ fflush(stdout);
++ if (test_text_roundtrip() != 0)
++ {
++ printf("FAIL\n");
++ result = 1;
++ }
++ else
++ printf("PASS\n");
++#endif
++
++#ifdef PNG_sPLT_SUPPORTED
++ printf("Testing sPLT get-then-set roundtrip... ");
++ fflush(stdout);
++ if (test_splt_roundtrip() != 0)
++ {
++ printf("FAIL\n");
++ result = 1;
++ }
++ else
++ printf("PASS\n");
++#endif
++
++#ifdef PNG_STORE_UNKNOWN_CHUNKS_SUPPORTED
++ printf("Testing unknown chunks get-then-set roundtrip... ");
++ fflush(stdout);
++ if (test_unknown_roundtrip() != 0)
++ {
++ printf("FAIL\n");
++ result = 1;
++ }
++ else
++ printf("PASS\n");
++#endif
++
+ return result;
+ }
+diff --git a/pngset.c b/pngset.c
+index 9f5c44510..9ffaf2b5a 100644
+--- a/pngset.c
++++ b/pngset.c
+@@ -789,6 +789,7 @@ png_set_text_2(png_const_structrp png_ptr, png_inforp info_ptr,
+ png_const_textp text_ptr, int num_text)
+ {
+ int i;
++ png_textp old_text = NULL;
+
+ png_debug1(1, "in text storage function, chunk typeid = 0x%lx",
+ png_ptr == NULL ? 0xabadca11UL : (unsigned long)png_ptr->chunk_name);
+@@ -836,7 +837,10 @@ png_set_text_2(png_const_structrp png_ptr, png_inforp info_ptr,
+ return 1;
+ }
+
+- png_free(png_ptr, info_ptr->text);
++ /* Defer freeing the old array until after the copy loop below,
++ * in case text_ptr aliases info_ptr->text (getter-to-setter).
++ */
++ old_text = info_ptr->text;
+
+ info_ptr->text = new_text;
+ info_ptr->free_me |= PNG_FREE_TEXT;
+@@ -921,6 +925,7 @@ png_set_text_2(png_const_structrp png_ptr, png_inforp info_ptr,
+ {
+ png_chunk_report(png_ptr, "text chunk: out of memory",
+ PNG_CHUNK_WRITE_ERROR);
++ png_free(png_ptr, old_text);
+
+ return 1;
+ }
+@@ -974,6 +979,8 @@ png_set_text_2(png_const_structrp png_ptr, png_inforp info_ptr,
+ png_debug1(3, "transferred text chunk %d", info_ptr->num_text);
+ }
+
++ png_free(png_ptr, old_text);
++
+ return 0;
+ }
+ #endif
+@@ -1112,6 +1119,7 @@ png_set_sPLT(png_const_structrp png_ptr,
+ */
+ {
+ png_sPLT_tp np;
++ png_sPLT_tp old_spalettes;
+
+ png_debug1(1, "in %s storage function", "sPLT");
+
+@@ -1132,7 +1140,10 @@ png_set_sPLT(png_const_structrp png_ptr,
+ return;
+ }
+
+- png_free(png_ptr, info_ptr->splt_palettes);
++ /* Defer freeing the old array until after the copy loop below,
++ * in case entries aliases info_ptr->splt_palettes (getter-to-setter).
++ */
++ old_spalettes = info_ptr->splt_palettes;
+
+ info_ptr->splt_palettes = np;
+ info_ptr->free_me |= PNG_FREE_SPLT;
+@@ -1196,6 +1207,8 @@ png_set_sPLT(png_const_structrp png_ptr,
+ }
+ while (--nentries);
+
++ png_free(png_ptr, old_spalettes);
++
+ if (nentries > 0)
+ png_chunk_report(png_ptr, "sPLT out of memory", PNG_CHUNK_WRITE_ERROR);
+ }
+@@ -1244,6 +1257,7 @@ png_set_unknown_chunks(png_const_structrp png_ptr,
+ png_inforp info_ptr, png_const_unknown_chunkp unknowns, int num_unknowns)
+ {
+ png_unknown_chunkp np;
++ png_unknown_chunkp old_unknowns;
+
+ if (png_ptr == NULL || info_ptr == NULL || num_unknowns <= 0 ||
+ unknowns == NULL)
+@@ -1290,7 +1304,10 @@ png_set_unknown_chunks(png_const_structrp png_ptr,
+ return;
+ }
+
+- png_free(png_ptr, info_ptr->unknown_chunks);
++ /* Defer freeing the old array until after the copy loop below,
++ * in case unknowns aliases info_ptr->unknown_chunks (getter-to-setter).
++ */
++ old_unknowns = info_ptr->unknown_chunks;
+
+ info_ptr->unknown_chunks = np; /* safe because it is initialized */
+ info_ptr->free_me |= PNG_FREE_UNKN;
+@@ -1336,6 +1353,8 @@ png_set_unknown_chunks(png_const_structrp png_ptr,
+ ++np;
+ ++(info_ptr->unknown_chunks_num);
+ }
++
++ png_free(png_ptr, old_unknowns);
+ }
+
+ void PNGAPI
+--
+2.51.0
+
diff --git a/meta/recipes-multimedia/libpng/libpng_1.6.42.bb b/meta/recipes-multimedia/libpng/libpng_1.6.42.bb
index e4cc63686e9..b226e327b64 100644
--- a/meta/recipes-multimedia/libpng/libpng_1.6.42.bb
+++ b/meta/recipes-multimedia/libpng/libpng_1.6.42.bb
@@ -29,6 +29,8 @@ SRC_URI = "${SOURCEFORGE_MIRROR}/project/${BPN}/${BPN}${LIBV}/${PV}/${BP}.tar.xz
file://CVE-2026-33416-02.patch \
file://CVE-2026-33416-03.patch \
file://CVE-2026-33416-04.patch \
+ file://CVE-2026-34757_p1.patch \
+ file://CVE-2026-34757_p2.patch \
"
SRC_URI[sha256sum] = "c919dbc11f4c03b05aba3f8884d8eb7adfe3572ad228af972bb60057bdb48450"
@@ -66,7 +68,7 @@ do_install_ptest() {
install -m 644 ${S}/contrib/tools/*.c ${S}/contrib/tools/*.h ${D}${PTEST_PATH}/src/contrib/tools
# Install .libs directory binaries to ptest path
- install -m 755 ${B}/.libs/pngtest ${B}/.libs/pngstest ${B}/.libs/pngimage ${B}/.libs/pngunknown ${B}/.libs/pngvalid ${D}${PTEST_PATH}/src
+ install -m 755 ${B}/.libs/pngtest ${B}/.libs/pnggetset ${B}/.libs/pngstest ${B}/.libs/pngimage ${B}/.libs/pngunknown ${B}/.libs/pngvalid ${D}${PTEST_PATH}/src
# Copy png files to ptest path
cd ${S} && find contrib -name '*.png' | cpio -pd ${D}${PTEST_PATH}/src
^ permalink raw reply related [flat|nested] 32+ messages in thread
* [OE-core][scarthgap 25/31] glib-2.0: fix CVE-2026-58010
2026-07-26 8:29 [OE-core][scarthgap 00/31] Patch review Yoann Congal
` (23 preceding siblings ...)
2026-07-26 8:29 ` [OE-core][scarthgap 24/31] libpng: Fix CVE-2026-34757 Yoann Congal
@ 2026-07-26 8:29 ` Yoann Congal
2026-07-26 8:29 ` [OE-core][scarthgap 26/31] glib-2.0: fix CVE-2026-58011 Yoann Congal
` (5 subsequent siblings)
30 siblings, 0 replies; 32+ messages in thread
From: Yoann Congal @ 2026-07-26 8:29 UTC (permalink / raw)
To: openembedded-core
From: Deepak Rathore <deeratho@cisco.com>
This patch applies the upstream 2.86.5 backport for
CVE-2026-58010. The upstream fix commit is referenced in [1],
and the public CVE advisory is referenced in [2].
[1] https://gitlab.gnome.org/GNOME/glib/-/commit/aa1cb87d56111ef989811e824f0ac77484cc997f
[2] https://nvd.nist.gov/vuln/detail/CVE-2026-58010
Signed-off-by: Deepak Rathore <deeratho@cisco.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
---
.../glib-2.0/glib-2.0/CVE-2026-58010.patch | 113 ++++++++++++++++++
meta/recipes-core/glib-2.0/glib-2.0_2.78.6.bb | 1 +
2 files changed, 114 insertions(+)
create mode 100644 meta/recipes-core/glib-2.0/glib-2.0/CVE-2026-58010.patch
diff --git a/meta/recipes-core/glib-2.0/glib-2.0/CVE-2026-58010.patch b/meta/recipes-core/glib-2.0/glib-2.0/CVE-2026-58010.patch
new file mode 100644
index 00000000000..842d53af5cf
--- /dev/null
+++ b/meta/recipes-core/glib-2.0/glib-2.0/CVE-2026-58010.patch
@@ -0,0 +1,113 @@
+From 333f164f00fb874e3c670ce70d2a2a3667b9ebf9 Mon Sep 17 00:00:00 2001
+From: Philip Withnall <pwithnall@gnome.org>
+Date: Sun, 29 Mar 2026 19:10:41 +0100
+Subject: [PATCH] gvariant: Fix an off-by-one error in an offset comparison
+MIME-Version: 1.0
+Content-Type: text/plain; charset=UTF-8
+Content-Transfer-Encoding: 8bit
+
+This allows a single byte out-of-bounds read off the end of the
+(potentially untrusted) byte array backing a `GVariant` when it’s
+being checked for normal form.
+
+I can’t see how this could practically be exploited, but it’s certainly
+a security bug as the `GVariant` normal form checking code is supposed
+to be robust to malicious inputs.
+
+Spotted by linhlhq as #YWH-PGM9867-190, and fix and reproducer provided
+by them too, thanks. Confirmed and turned into a unit test by me.
+
+Fixes: #3915
+
+CVE: CVE-2026-58010
+Upstream-Status: Backport [https://gitlab.gnome.org/GNOME/glib/-/commit/aa1cb87d56111ef989811e824f0ac77484cc997f]
+
+Signed-off-by: Philip Withnall <pwithnall@gnome.org>
+(cherry picked from commit aa1cb87d56111ef989811e824f0ac77484cc997f)
+Signed-off-by: Deepak Rathore <deeratho@cisco.com>
+---
+ glib/gvariant-serialiser.c | 2 +-
+ glib/tests/gvariant.c | 48 ++++++++++++++++++++++++++++++++++++++
+ 2 files changed, 49 insertions(+), 1 deletion(-)
+
+diff --git a/glib/gvariant-serialiser.c b/glib/gvariant-serialiser.c
+index 4e4a73ad1..99a1d3fbd 100644
+--- a/glib/gvariant-serialiser.c
++++ b/glib/gvariant-serialiser.c
+@@ -1247,7 +1247,7 @@ gvs_tuple_is_normal (GVariantSerialised value)
+
+ while (offset & alignment)
+ {
+- if (offset > value.size || value.data[offset] != '\0')
++ if (offset >= value.size || value.data[offset] != '\0')
+ return FALSE;
+ offset++;
+ }
+diff --git a/glib/tests/gvariant.c b/glib/tests/gvariant.c
+index c8f13360c..55e2cee00 100644
+--- a/glib/tests/gvariant.c
++++ b/glib/tests/gvariant.c
+@@ -5637,6 +5637,52 @@ test_normal_checking_tuple_offsets5 (void)
+ g_variant_unref (variant);
+ }
+
++/* This is a regression test that looping over the padding bytes in a short
++ * (non-normal) tuple doesn’t overflow the input data.
++ *
++ * See https://gitlab.gnome.org/GNOME/glib/-/issues/3915 */
++static void
++test_normal_checking_tuple_offsets6 (void)
++{
++ /*
++ * Type: (ynqiuxthdsog) — 12 members, first member 'y' (byte) has
++ * alignment 0, second 'n' (int16) has alignment 1.
++ * With 1 byte of data (0x28), after reading the first byte member,
++ * offset=1, alignment check for 'n' requires offset to be even,
++ * so the while loop checks value.data[1] — but size is only 1.
++ *
++ * Use heap allocation via GBytes so ASan reports heap-buffer-overflow.
++ */
++ guint8 *heap_data = NULL;
++ GBytes *bytes = NULL;
++ const GVariantType *data_type = G_VARIANT_TYPE ("(ynqiuxthdsog)");
++ GVariant *variant = NULL;
++ GVariant *normal_variant = NULL;
++ GVariant *expected = NULL;
++
++ g_test_bug ("https://gitlab.gnome.org/GNOME/glib/-/issues/3915");
++
++ heap_data = g_malloc (1);
++ heap_data[0] = 0x28;
++ bytes = g_bytes_new_take (heap_data, 1);
++
++ variant = g_variant_new_from_bytes (data_type, bytes, FALSE);
++ g_assert_nonnull (variant);
++
++ g_assert_false (g_variant_is_normal_form (variant));
++
++ normal_variant = g_variant_get_normal_form (variant);
++ g_assert_nonnull (normal_variant);
++
++ expected = g_variant_new_parsed ("(byte 0x28, int16 0, uint16 0, 0, uint32 0, int64 0, uint64 0, handle 0, 0.0, '', objectpath '/', signature '')");
++ g_assert_cmpvariant (expected, variant);
++ g_assert_cmpvariant (expected, normal_variant);
++
++ g_variant_unref (expected);
++ g_variant_unref (normal_variant);
++ g_variant_unref (variant);
++}
++
+ /* Test that an otherwise-valid serialised GVariant is considered non-normal if
+ * its offset table entries are too wide.
+ *
+@@ -5890,6 +5936,8 @@ main (int argc, char **argv)
+ test_normal_checking_tuple_offsets4);
+ g_test_add_func ("/gvariant/normal-checking/tuple-offsets5",
+ test_normal_checking_tuple_offsets5);
++ g_test_add_func ("/gvariant/normal-checking/tuple-offsets6",
++ test_normal_checking_tuple_offsets6);
+ g_test_add_func ("/gvariant/normal-checking/tuple-offsets/minimal-sized",
+ test_normal_checking_tuple_offsets_minimal_sized);
+ g_test_add_func ("/gvariant/normal-checking/empty-object-path",
+--
+2.35.6
diff --git a/meta/recipes-core/glib-2.0/glib-2.0_2.78.6.bb b/meta/recipes-core/glib-2.0/glib-2.0_2.78.6.bb
index 549584f3d8f..54691690117 100644
--- a/meta/recipes-core/glib-2.0/glib-2.0_2.78.6.bb
+++ b/meta/recipes-core/glib-2.0/glib-2.0_2.78.6.bb
@@ -49,6 +49,7 @@ SRC_URI = "${GNOME_MIRROR}/glib/${SHRT_VER}/glib-${PV}.tar.xz \
file://CVE-2026-1489-04.patch \
file://CVE-2026-58016-1.patch \
file://CVE-2026-58016-2.patch \
+ file://CVE-2026-58010.patch \
"
SRC_URI:append:class-native = " file://relocate-modules.patch \
file://0001-meson.build-do-not-enable-pidfd-features-on-native-g.patch \
^ permalink raw reply related [flat|nested] 32+ messages in thread
* [OE-core][scarthgap 26/31] glib-2.0: fix CVE-2026-58011
2026-07-26 8:29 [OE-core][scarthgap 00/31] Patch review Yoann Congal
` (24 preceding siblings ...)
2026-07-26 8:29 ` [OE-core][scarthgap 25/31] glib-2.0: fix CVE-2026-58010 Yoann Congal
@ 2026-07-26 8:29 ` Yoann Congal
2026-07-26 8:29 ` [OE-core][scarthgap 27/31] glib-2.0: fix CVE-2026-58012 Yoann Congal
` (4 subsequent siblings)
30 siblings, 0 replies; 32+ messages in thread
From: Yoann Congal @ 2026-07-26 8:29 UTC (permalink / raw)
To: openembedded-core
From: Deepak Rathore <deeratho@cisco.com>
This patch applies the upstream 2.86.5 backport for
CVE-2026-58011. The upstream fix commit is referenced in [1],
and the public CVE advisory is referenced in [2].
[1] https://gitlab.gnome.org/GNOME/glib/-/commit/ae27363f025ffc131e2d75ee88a5cd8320dffe3b
[2] https://nvd.nist.gov/vuln/detail/CVE-2026-58011
Signed-off-by: Deepak Rathore <deeratho@cisco.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
---
.../glib-2.0/glib-2.0/CVE-2026-58011.patch | 78 +++++++++++++++++++
meta/recipes-core/glib-2.0/glib-2.0_2.78.6.bb | 1 +
2 files changed, 79 insertions(+)
create mode 100644 meta/recipes-core/glib-2.0/glib-2.0/CVE-2026-58011.patch
diff --git a/meta/recipes-core/glib-2.0/glib-2.0/CVE-2026-58011.patch b/meta/recipes-core/glib-2.0/glib-2.0/CVE-2026-58011.patch
new file mode 100644
index 00000000000..a8d31c1270c
--- /dev/null
+++ b/meta/recipes-core/glib-2.0/glib-2.0/CVE-2026-58011.patch
@@ -0,0 +1,78 @@
+From 371dbccb6b9a9a42b93c4b371214b159e7e94792 Mon Sep 17 00:00:00 2001
+From: Philip Withnall <pwithnall@gnome.org>
+Date: Sun, 29 Mar 2026 23:46:17 +0100
+Subject: [PATCH] gdatetime: Add missing range validation to
+ g_date_time_add_full()
+MIME-Version: 1.0
+Content-Type: text/plain; charset=UTF-8
+Content-Transfer-Encoding: 8bit
+
+Otherwise it’s possible to create a non-`NULL` but invalid `GDateTime`,
+which breaks all kinds of internal assumptions.
+
+Spotted by linhlhq as #YWH-PGM9867-191. Thanks to them for providing a
+suggested fix and a test case, which I have adapted and validated.
+
+Fixes: #3917
+
+CVE: CVE-2026-58011
+Upstream-Status: Backport [https://gitlab.gnome.org/GNOME/glib/-/commit/ae27363f025ffc131e2d75ee88a5cd8320dffe3b]
+
+Backport Changes:
+- Used the target branch's existing literal day bounds because it does
+ not have upstream's MIN_DAYS/MAX_DAYS helper macros.
+
+Signed-off-by: Philip Withnall <pwithnall@gnome.org>
+(cherry picked from commit ae27363f025ffc131e2d75ee88a5cd8320dffe3b)
+Signed-off-by: Deepak Rathore <deeratho@cisco.com>
+---
+ glib/gdatetime.c | 4 +++-
+ glib/tests/gdatetime.c | 18 ++++++++++++++++++
+ 2 files changed, 21 insertions(+), 1 deletion(-)
+
+diff --git a/glib/gdatetime.c b/glib/gdatetime.c
+index 2640e3b24..73eea643b 100644
+--- a/glib/gdatetime.c
++++ b/glib/gdatetime.c
+@@ -2024,7 +2024,9 @@ g_date_time_add_full (GDateTime *datetime,
+ new->days = full_time / USEC_PER_DAY;
+ new->usec = full_time % USEC_PER_DAY;
+
+- /* XXX validate */
++ /* Validate it’s still in the range 0001-01-01 to 9999-12-31 */
++ if (new->days < 1 || new->days > 3652059)
++ g_clear_pointer (&new, g_date_time_unref);
+
+ return new;
+ }
+diff --git a/glib/tests/gdatetime.c b/glib/tests/gdatetime.c
+index 49390c900..527d61a11 100644
+--- a/glib/tests/gdatetime.c
++++ b/glib/tests/gdatetime.c
+@@ -1117,6 +1117,24 @@ test_GDateTime_add_full (void)
+ TEST_ADD_FULL (2010, 8, 25, 22, 45, 0,
+ 0, 1, 6, 1, 25, 0,
+ 2010, 10, 2, 0, 10, 0);
++
++#define TEST_ADD_FULL_ERROR(y,m,d,h,mi,s,ay,am,ad,ah,ami,as) G_STMT_START { \
++ GDateTime *dt; \
++ dt = g_date_time_new_utc (y, m, d, h, mi, s); \
++ g_assert_null (g_date_time_add_full (dt, ay, am, ad, ah, ami, as)); \
++ g_date_time_unref (dt); \
++} G_STMT_END
++
++ TEST_ADD_FULL_ERROR ( 1, 12, 1, 0, 0, 0,
++ -1, 0, 0, 0, 0, 0);
++ TEST_ADD_FULL_ERROR ( 1, 12, 1, 0, 0, 0,
++ 10000, 0, 0, 0, 0, 0);
++ TEST_ADD_FULL_ERROR ( 9999, 12, 1, 0, 0, 0,
++ -10000, 0, 0, 0, 0, 0);
++ TEST_ADD_FULL_ERROR ( 1, 12, 1, 0, 0, 0,
++ 0, 0, 3660001, 0, 0, 0);
++ TEST_ADD_FULL_ERROR ( 9999, 12, 1, 0, 0, 0,
++ 0, 0, -3660001, 0, 0, 0);
+ }
+
+ static void
+--
+2.35.6
diff --git a/meta/recipes-core/glib-2.0/glib-2.0_2.78.6.bb b/meta/recipes-core/glib-2.0/glib-2.0_2.78.6.bb
index 54691690117..a2de973e218 100644
--- a/meta/recipes-core/glib-2.0/glib-2.0_2.78.6.bb
+++ b/meta/recipes-core/glib-2.0/glib-2.0_2.78.6.bb
@@ -50,6 +50,7 @@ SRC_URI = "${GNOME_MIRROR}/glib/${SHRT_VER}/glib-${PV}.tar.xz \
file://CVE-2026-58016-1.patch \
file://CVE-2026-58016-2.patch \
file://CVE-2026-58010.patch \
+ file://CVE-2026-58011.patch \
"
SRC_URI:append:class-native = " file://relocate-modules.patch \
file://0001-meson.build-do-not-enable-pidfd-features-on-native-g.patch \
^ permalink raw reply related [flat|nested] 32+ messages in thread
* [OE-core][scarthgap 27/31] glib-2.0: fix CVE-2026-58012
2026-07-26 8:29 [OE-core][scarthgap 00/31] Patch review Yoann Congal
` (25 preceding siblings ...)
2026-07-26 8:29 ` [OE-core][scarthgap 26/31] glib-2.0: fix CVE-2026-58011 Yoann Congal
@ 2026-07-26 8:29 ` Yoann Congal
2026-07-26 8:29 ` [OE-core][scarthgap 28/31] glib-2.0: fix CVE-2026-58013 Yoann Congal
` (3 subsequent siblings)
30 siblings, 0 replies; 32+ messages in thread
From: Yoann Congal @ 2026-07-26 8:29 UTC (permalink / raw)
To: openembedded-core
From: Deepak Rathore <deeratho@cisco.com>
This patch applies the upstream 2.86.5 backport for
CVE-2026-58012. The upstream fix commit is referenced in [1],
and the public CVE advisory is referenced in [2].
[1] https://gitlab.gnome.org/GNOME/glib/-/commit/d337aabd24ee2b8ac2a690dba3ccf26aa70e638f
[2] https://nvd.nist.gov/vuln/detail/CVE-2026-58012
Signed-off-by: Deepak Rathore <deeratho@cisco.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
---
.../glib-2.0/glib-2.0/CVE-2026-58012.patch | 228 ++++++++++++++++++
meta/recipes-core/glib-2.0/glib-2.0_2.78.6.bb | 1 +
2 files changed, 229 insertions(+)
create mode 100644 meta/recipes-core/glib-2.0/glib-2.0/CVE-2026-58012.patch
diff --git a/meta/recipes-core/glib-2.0/glib-2.0/CVE-2026-58012.patch b/meta/recipes-core/glib-2.0/glib-2.0/CVE-2026-58012.patch
new file mode 100644
index 00000000000..7f8435809c6
--- /dev/null
+++ b/meta/recipes-core/glib-2.0/glib-2.0/CVE-2026-58012.patch
@@ -0,0 +1,228 @@
+From 74564fefcec22fc1efc187c36aa1fb8dcfe34454 Mon Sep 17 00:00:00 2001
+From: Philip Withnall <pwithnall@gnome.org>
+Date: Tue, 31 Mar 2026 16:13:57 +0100
+Subject: [PATCH] gregex: Fix case changing substitutions with G_REGEX_RAW
+
+In `G_REGEX_RAW` mode, the input string is treated as a byte array
+(basically ASCII) rather than a unichar array. Accordingly, the case
+changing code for substitutions needs to operate on bytes with
+`G_REGEX_RAW`, rather than operating on unichars.
+
+This fixes a potential buffer overflow when trying to do a case change
+on a match of a set of bytes which are a truncated multi-byte UTF-8
+encoding at the end of the input buffer.
+
+Spotted by linhlhq as #YWH-PGM9867-193. I adapted their reproducer as
+the unit test, but implemented the fix in `gregex.c` independently.
+
+Fixes: #3918
+
+CVE: CVE-2026-58012
+Upstream-Status: Backport [https://gitlab.gnome.org/GNOME/glib/-/commit/d337aabd24ee2b8ac2a690dba3ccf26aa70e638f]
+
+Signed-off-by: Philip Withnall <pwithnall@gnome.org>
+(cherry picked from commit d337aabd24ee2b8ac2a690dba3ccf26aa70e638f)
+Signed-off-by: Deepak Rathore <deeratho@cisco.com>
+---
+ glib/gregex.c | 59 ++++++++++++++++++++++++++++++++++------------
+ glib/tests/regex.c | 53 +++++++++++++++++++++++++++++++++++++++++
+ 2 files changed, 97 insertions(+), 15 deletions(-)
+
+diff --git a/glib/gregex.c b/glib/gregex.c
+index 116ecacbb..496b34bbd 100644
+--- a/glib/gregex.c
++++ b/glib/gregex.c
+@@ -3147,19 +3147,25 @@ split_replacement (const gchar *replacement,
+ return g_list_reverse (list);
+ }
+
+-/* Change the case of c based on change_case. */
+-#define CHANGE_CASE(c, change_case) \
++/* Change the case of c based on change_case.
++ * g_ascii_to*() will happily pass through non-ASCII bytes unchanged. */
++#define UTF8_CHANGE_CASE(c, change_case) \
+ (((change_case) & CHANGE_CASE_LOWER_MASK) ? \
+ g_unichar_tolower (c) : \
+ g_unichar_toupper (c))
++#define RAW_CHANGE_CASE(c, change_case) \
++ (((change_case) & CHANGE_CASE_LOWER_MASK) ? \
++ g_ascii_tolower (c) : \
++ g_ascii_toupper (c))
+
++/* If @text_is_raw is set, @text might not be valid UTF-8 (but will be
++ * nul-terminated). */
+ static void
+ string_append (GString *string,
+ const gchar *text,
++ gboolean text_is_raw,
+ ChangeCase *change_case)
+ {
+- gunichar c;
+-
+ if (text[0] == '\0')
+ return;
+
+@@ -3169,22 +3175,44 @@ string_append (GString *string,
+ }
+ else if (*change_case & CHANGE_CASE_SINGLE_MASK)
+ {
+- c = g_utf8_get_char (text);
+- g_string_append_unichar (string, CHANGE_CASE (c, *change_case));
+- g_string_append (string, g_utf8_next_char (text));
++ if (!text_is_raw)
++ {
++ gunichar c = g_utf8_get_char (text);
++ g_string_append_unichar (string, UTF8_CHANGE_CASE (c, *change_case));
++ g_string_append (string, g_utf8_next_char (text));
++ }
++ else
++ {
++ g_string_append_c (string, RAW_CHANGE_CASE (text[0], *change_case));
++ g_string_append (string, text + 1);
++ }
++
+ *change_case = CHANGE_CASE_NONE;
+ }
+ else
+ {
+- while (*text != '\0')
++ if (!text_is_raw)
+ {
+- c = g_utf8_get_char (text);
+- g_string_append_unichar (string, CHANGE_CASE (c, *change_case));
+- text = g_utf8_next_char (text);
++ while (*text != '\0')
++ {
++ gunichar c = g_utf8_get_char (text);
++ g_string_append_unichar (string, UTF8_CHANGE_CASE (c, *change_case));
++ text = g_utf8_next_char (text);
++ }
++ }
++ else
++ {
++ while (*text != '\0')
++ {
++ char c = *text;
++ g_string_append_c (string, RAW_CHANGE_CASE (c, *change_case));
++ text++;
++ }
+ }
+ }
+ }
+
++/* @match_info is (nullable) */
+ static gboolean
+ interpolate_replacement (const GMatchInfo *match_info,
+ GString *result,
+@@ -3194,6 +3222,7 @@ interpolate_replacement (const GMatchInfo *match_info,
+ InterpolationData *idata;
+ gchar *match;
+ ChangeCase change_case = CHANGE_CASE_NONE;
++ gboolean is_raw = (match_info != NULL && (match_info->regex->orig_compile_opts & G_REGEX_RAW));
+
+ for (list = data; list; list = list->next)
+ {
+@@ -3201,10 +3230,10 @@ interpolate_replacement (const GMatchInfo *match_info,
+ switch (idata->type)
+ {
+ case REPL_TYPE_STRING:
+- string_append (result, idata->text, &change_case);
++ string_append (result, idata->text, is_raw, &change_case);
+ break;
+ case REPL_TYPE_CHARACTER:
+- g_string_append_c (result, CHANGE_CASE (idata->c, change_case));
++ g_string_append_c (result, UTF8_CHANGE_CASE (idata->c, change_case));
+ if (change_case & CHANGE_CASE_SINGLE_MASK)
+ change_case = CHANGE_CASE_NONE;
+ break;
+@@ -3212,7 +3241,7 @@ interpolate_replacement (const GMatchInfo *match_info,
+ match = g_match_info_fetch (match_info, idata->num);
+ if (match)
+ {
+- string_append (result, match, &change_case);
++ string_append (result, match, is_raw, &change_case);
+ g_free (match);
+ }
+ break;
+@@ -3220,7 +3249,7 @@ interpolate_replacement (const GMatchInfo *match_info,
+ match = g_match_info_fetch_named (match_info, idata->text);
+ if (match)
+ {
+- string_append (result, match, &change_case);
++ string_append (result, match, is_raw, &change_case);
+ g_free (match);
+ }
+ break;
+diff --git a/glib/tests/regex.c b/glib/tests/regex.c
+index d7a698ec6..bffb52a87 100644
+--- a/glib/tests/regex.c
++++ b/glib/tests/regex.c
+@@ -2529,6 +2529,58 @@ test_compiled_regex_after_jit_failure (void)
+ g_regex_unref (regex);
+ }
+
++static void
++test_replace_raw_change_case (void)
++{
++ GError *local_error = NULL;
++ GRegex *regex = NULL;
++
++ g_test_bug ("https://gitlab.gnome.org/GNOME/glib/-/issues/3918");
++ g_test_summary ("Test that case changes as part of a replacement are handled correctly in G_REGEX_RAW mode");
++
++ /*
++ * Match a multi-byte sequence in RAW mode. The pattern matches
++ * exactly 2 bytes. The subject contains a 4-byte UTF-8 lead (0xF4)
++ * followed by only one continuation byte, then NUL.
++ *
++ * The matched substring will be "\xf4\x80" (2 bytes, heap-allocated
++ * as 3-byte buffer with NUL). If the code regresses and tries to handle
++ * the replacement as UTF-8 then g_utf8_get_char() would see 0xF4 and try
++ * to read 4 bytes, going 1 byte past the NUL into OOB territory.
++ */
++ regex = g_regex_new ("..", G_REGEX_RAW, 0, &local_error);
++ g_assert_no_error (local_error);
++
++ /*
++ * Build a subject string with truncated UTF-8.
++ * \xF4 = 4-byte UTF-8 lead byte
++ * \x80 = continuation byte
++ * No 3rd/4th continuation bytes — the match is only 2 bytes.
++ *
++ * \U\0 = uppercase the entire match → triggers string_append()
++ * with case change on the 2-byte non-UTF-8 match.
++ */
++ char subject[] = "\xf4\x80";
++ char *result = g_regex_replace (regex, subject, -1, 0, "\\U\\0", 0, &local_error);
++ g_assert_no_error (local_error);
++
++ g_clear_pointer (&result, g_free);
++ g_clear_pointer (®ex, g_regex_unref);
++
++ /*
++ * Second variant: single-char case change \u with \0 backreference.
++ */
++ regex = g_regex_new (".", G_REGEX_RAW, 0, &local_error);
++ g_assert_no_error (local_error);
++
++ char subject2[] = "\xe6\xb0"; /* 3-byte UTF-8 lead, only 2 bytes */
++ result = g_regex_replace (regex, subject2, -1, 0, "\\u\\0", 0, &local_error);
++ g_assert_no_error (local_error);
++
++ g_clear_pointer (&result, g_free);
++ g_clear_pointer (®ex, g_regex_unref);
++}
++
+ int
+ main (int argc, char *argv[])
+ {
+@@ -2550,6 +2602,7 @@ main (int argc, char *argv[])
+ g_test_add_func ("/regex/jit-unsupported-matching", test_jit_unsupported_matching_options);
+ g_test_add_func ("/regex/unmatched-named-subpattern", test_unmatched_named_subpattern);
+ g_test_add_func ("/regex/compiled-regex-after-jit-failure", test_compiled_regex_after_jit_failure);
++ g_test_add_func ("/regex/replace-raw-change-case", test_replace_raw_change_case);
+
+ /* TEST_NEW(pattern, compile_opts, match_opts) */
+ TEST_NEW("[A-Z]+", G_REGEX_CASELESS | G_REGEX_EXTENDED | G_REGEX_OPTIMIZE, G_REGEX_MATCH_NOTBOL | G_REGEX_MATCH_PARTIAL);
+--
+2.35.6
diff --git a/meta/recipes-core/glib-2.0/glib-2.0_2.78.6.bb b/meta/recipes-core/glib-2.0/glib-2.0_2.78.6.bb
index a2de973e218..6dc3e0cc9cd 100644
--- a/meta/recipes-core/glib-2.0/glib-2.0_2.78.6.bb
+++ b/meta/recipes-core/glib-2.0/glib-2.0_2.78.6.bb
@@ -51,6 +51,7 @@ SRC_URI = "${GNOME_MIRROR}/glib/${SHRT_VER}/glib-${PV}.tar.xz \
file://CVE-2026-58016-2.patch \
file://CVE-2026-58010.patch \
file://CVE-2026-58011.patch \
+ file://CVE-2026-58012.patch \
"
SRC_URI:append:class-native = " file://relocate-modules.patch \
file://0001-meson.build-do-not-enable-pidfd-features-on-native-g.patch \
^ permalink raw reply related [flat|nested] 32+ messages in thread
* [OE-core][scarthgap 28/31] glib-2.0: fix CVE-2026-58013
2026-07-26 8:29 [OE-core][scarthgap 00/31] Patch review Yoann Congal
` (26 preceding siblings ...)
2026-07-26 8:29 ` [OE-core][scarthgap 27/31] glib-2.0: fix CVE-2026-58012 Yoann Congal
@ 2026-07-26 8:29 ` Yoann Congal
2026-07-26 8:29 ` [OE-core][scarthgap 29/31] glib-2.0: fix CVE-2026-58014 Yoann Congal
` (2 subsequent siblings)
30 siblings, 0 replies; 32+ messages in thread
From: Yoann Congal @ 2026-07-26 8:29 UTC (permalink / raw)
To: openembedded-core
From: Deepak Rathore <deeratho@cisco.com>
This patch applies the upstream 2.88.1 backport for
CVE-2026-58013. The upstream fix commit is referenced in [1],
and the public CVE advisory is referenced in [2].
[1] https://gitlab.gnome.org/GNOME/glib/-/commit/6a2583dec39bfe05553b16d9b7419d6c2a257244
[2] https://nvd.nist.gov/vuln/detail/CVE-2026-58013
Signed-off-by: Deepak Rathore <deeratho@cisco.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
---
.../glib-2.0/glib-2.0/CVE-2026-58013.patch | 140 ++++++++++++++++++
meta/recipes-core/glib-2.0/glib-2.0_2.78.6.bb | 1 +
2 files changed, 141 insertions(+)
create mode 100644 meta/recipes-core/glib-2.0/glib-2.0/CVE-2026-58013.patch
diff --git a/meta/recipes-core/glib-2.0/glib-2.0/CVE-2026-58013.patch b/meta/recipes-core/glib-2.0/glib-2.0/CVE-2026-58013.patch
new file mode 100644
index 00000000000..fa3db56bdbc
--- /dev/null
+++ b/meta/recipes-core/glib-2.0/glib-2.0/CVE-2026-58013.patch
@@ -0,0 +1,140 @@
+From cb9d97e1b261d75eb8ea255e0a9f3e846d547af7 Mon Sep 17 00:00:00 2001
+From: Philip Withnall <pwithnall@gnome.org>
+Date: Tue, 28 Apr 2026 16:45:14 +0100
+Subject: [PATCH] giochannel: Fix memcmp() off the end of the buffer with long
+ terminators
+MIME-Version: 1.0
+Content-Type: text/plain; charset=UTF-8
+Content-Transfer-Encoding: 8bit
+
+If the line terminator is longer than a single byte, and the current
+line extends to the end of the buffer, and the buffer (which is a
+`GString`) is near a power of two in length (as that’s how `GString`s
+are allocated) it’s possible for the `memcmp()` which checks the
+terminator to read off the end of the string buffer.
+
+Fix that by checking the terminator length against the last character
+before calling `memcmp()`. Add a unit test.
+
+Spotted by linhlhq as #YWH-PGM9867-199. The fix is theirs (validated by
+me), and the unit test is adapted from their proof of concept.
+
+Fixes: #3925
+
+CVE: CVE-2026-58013
+Upstream-Status: Backport [https://gitlab.gnome.org/GNOME/glib/-/commit/6a2583dec39bfe05553b16d9b7419d6c2a257244]
+
+Backport Changes:
+- Added the <stdint.h> include for the regression test because these target
+ branches do not otherwise expose uint8_t in glib/tests/io-channel.c.
+
+Signed-off-by: Philip Withnall <pwithnall@gnome.org>
+(cherry picked from commit 6a2583dec39bfe05553b16d9b7419d6c2a257244)
+Signed-off-by: Deepak Rathore <deeratho@cisco.com>
+---
+ glib/giochannel.c | 3 ++-
+ glib/tests/io-channel.c | 61 +++++++++++++++++++++++++++++++++++++++++
+ 2 files changed, 63 insertions(+), 1 deletion(-)
+
+diff --git a/glib/giochannel.c b/glib/giochannel.c
+index 7572c47a2..8d867d0fb 100644
+--- a/glib/giochannel.c
++++ b/glib/giochannel.c
+@@ -1833,7 +1833,8 @@ read_again:
+ {
+ if (channel->line_term)
+ {
+- if (memcmp (channel->line_term, nextchar, line_term_len) == 0)
++ if ((size_t) (lastchar - nextchar) >= line_term_len &&
++ memcmp (channel->line_term, nextchar, line_term_len) == 0)
+ {
+ line_length = nextchar - use_buf->str;
+ got_term_len = line_term_len;
+diff --git a/glib/tests/io-channel.c b/glib/tests/io-channel.c
+index c5dd01d04..cf81a9f6b 100644
+--- a/glib/tests/io-channel.c
++++ b/glib/tests/io-channel.c
+@@ -29,6 +29,7 @@
+
+ #include <glib.h>
+ #include <glib/gstdio.h>
++#include <stdint.h>
+
+ static void
+ test_small_writes (void)
+@@ -216,6 +217,65 @@ test_read_line_embedded_nuls (void)
+ g_free (filename);
+ }
+
++static void
++test_read_line_long_terminator (void)
++{
++ uint8_t *test_data = NULL;
++ size_t test_data_len = 0;
++ int fd;
++ char *filename = NULL;
++ GIOChannel *channel = NULL;
++ GError *local_error = NULL;
++ char *line = NULL;
++ size_t line_length, terminator_pos;
++ const char *line_term;
++ int line_term_length;
++ GIOStatus status;
++
++ g_test_summary ("Test that reading a line when using a long terminator doesn’t over-read the buffer.");
++ g_test_bug ("https://gitlab.gnome.org/GNOME/glib/-/work_items/3925");
++
++ /* Write out a temporary file containing 2047 bytes. This is enough to make it
++ * near the length of the GString buffer when read back in. */
++ fd = g_file_open_tmp ("glib-test-io-channel-XXXXXX", &filename, &local_error);
++ g_assert_no_error (local_error);
++ g_close (g_steal_fd (&fd), NULL);
++
++ test_data_len = 2047;
++ test_data = g_malloc (test_data_len);
++ memset (test_data, 'M', test_data_len);
++ g_file_set_contents (filename, (const gchar *) test_data, test_data_len, &local_error);
++ g_assert_no_error (local_error);
++
++ /* Create the channel. */
++ channel = g_io_channel_new_file (filename, "r", &local_error);
++ g_assert_no_error (local_error);
++
++ /* Use a long line terminator so it could potentially over-read the end of the buffer. */
++ g_io_channel_set_line_term (channel, "DEADBEEF", 8);
++
++ line_term = g_io_channel_get_line_term (channel, &line_term_length);
++ g_assert_cmpstr (line_term, ==, "DEADBEEF");
++ g_assert_cmpint (line_term_length, ==, 8);
++
++ g_io_channel_set_encoding (channel, "UTF-8", &local_error);
++ g_assert_no_error (local_error);
++
++ status = g_io_channel_read_line (channel, &line, &line_length,
++ &terminator_pos, &local_error);
++ g_assert_no_error (local_error);
++ g_assert_cmpint (status, ==, G_IO_STATUS_NORMAL);
++ g_assert_cmpuint (line_length, ==, 2047);
++ g_assert_cmpuint (terminator_pos, ==, 2047);
++ g_assert_cmpmem (line, line_length, test_data, test_data_len);
++
++ g_free (line);
++ g_io_channel_unref (channel);
++ g_free (test_data);
++ g_unlink (filename);
++ g_free (filename);
++}
++
+ int
+ main (int argc,
+ char *argv[])
+@@ -224,6 +283,7 @@ main (int argc,
+
+ g_test_add_func ("/io-channel/read-write", test_read_write);
+ g_test_add_func ("/io-channel/read-line/embedded-nuls", test_read_line_embedded_nuls);
++ g_test_add_func ("/io-channel/read-line/long-terminator", test_read_line_long_terminator);
+
+ return g_test_run ();
+ }
+--
+2.35.6
diff --git a/meta/recipes-core/glib-2.0/glib-2.0_2.78.6.bb b/meta/recipes-core/glib-2.0/glib-2.0_2.78.6.bb
index 6dc3e0cc9cd..9516231cbad 100644
--- a/meta/recipes-core/glib-2.0/glib-2.0_2.78.6.bb
+++ b/meta/recipes-core/glib-2.0/glib-2.0_2.78.6.bb
@@ -52,6 +52,7 @@ SRC_URI = "${GNOME_MIRROR}/glib/${SHRT_VER}/glib-${PV}.tar.xz \
file://CVE-2026-58010.patch \
file://CVE-2026-58011.patch \
file://CVE-2026-58012.patch \
+ file://CVE-2026-58013.patch \
"
SRC_URI:append:class-native = " file://relocate-modules.patch \
file://0001-meson.build-do-not-enable-pidfd-features-on-native-g.patch \
^ permalink raw reply related [flat|nested] 32+ messages in thread
* [OE-core][scarthgap 29/31] glib-2.0: fix CVE-2026-58014
2026-07-26 8:29 [OE-core][scarthgap 00/31] Patch review Yoann Congal
` (27 preceding siblings ...)
2026-07-26 8:29 ` [OE-core][scarthgap 28/31] glib-2.0: fix CVE-2026-58013 Yoann Congal
@ 2026-07-26 8:29 ` Yoann Congal
2026-07-26 8:29 ` [OE-core][scarthgap 30/31] gzip: Fix CVE-2026-41991 Yoann Congal
2026-07-26 8:29 ` [OE-core][scarthgap 31/31] bzip2: fix 'bzip2 --version > /tmp/aaa 2>&1' hang Yoann Congal
30 siblings, 0 replies; 32+ messages in thread
From: Yoann Congal @ 2026-07-26 8:29 UTC (permalink / raw)
To: openembedded-core
From: Deepak Rathore <deeratho@cisco.com>
This patch applies the upstream 2.88.1 backport for
CVE-2026-58014. The upstream fix commit is referenced in [1],
and the public CVE advisory is referenced in [2].
[1] https://gitlab.gnome.org/GNOME/glib/-/commit/94ecb5b44a1cae09f481dd5e693832f129948893
[2] https://nvd.nist.gov/vuln/detail/CVE-2026-58014
Signed-off-by: Deepak Rathore <deeratho@cisco.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
---
.../glib-2.0/glib-2.0/CVE-2026-58014.patch | 106 ++++++++++++++++++
meta/recipes-core/glib-2.0/glib-2.0_2.78.6.bb | 1 +
2 files changed, 107 insertions(+)
create mode 100644 meta/recipes-core/glib-2.0/glib-2.0/CVE-2026-58014.patch
diff --git a/meta/recipes-core/glib-2.0/glib-2.0/CVE-2026-58014.patch b/meta/recipes-core/glib-2.0/glib-2.0/CVE-2026-58014.patch
new file mode 100644
index 00000000000..4e5262b66de
--- /dev/null
+++ b/meta/recipes-core/glib-2.0/glib-2.0/CVE-2026-58014.patch
@@ -0,0 +1,106 @@
+From ba0478c206bc04542df774343c6c85f77df49f6e Mon Sep 17 00:00:00 2001
+From: Philip Withnall <pwithnall@gnome.org>
+Date: Sat, 11 Apr 2026 14:42:57 +0100
+Subject: [PATCH] gkeyfile: Fix a one-byte heap under-read with
+ g_key_file_get_locale_string_list()
+
+If this method was called on a key file key which has an empty value,
+`len == 0` and this leads to a one-byte under-read off the start of the
+key file buffer.
+
+Spotted by linhlhq as #YWH-PGM9867-200. The suggested fix is theirs, and
+the unit test is adapted from their report. I added the fuzzing test.
+
+Fixes: #3930
+
+CVE: CVE-2026-58014
+Upstream-Status: Backport [https://gitlab.gnome.org/GNOME/glib/-/commit/94ecb5b44a1cae09f481dd5e693832f129948893]
+
+Signed-off-by: Philip Withnall <pwithnall@gnome.org>
+(cherry picked from commit 94ecb5b44a1cae09f481dd5e693832f129948893)
+Signed-off-by: Deepak Rathore <deeratho@cisco.com>
+---
+ fuzzing/fuzz_key.c | 9 +++++++++
+ glib/gkeyfile.c | 2 +-
+ glib/tests/keyfile.c | 23 +++++++++++++++++++++++
+ 3 files changed, 33 insertions(+), 1 deletion(-)
+
+diff --git a/fuzzing/fuzz_key.c b/fuzzing/fuzz_key.c
+index 77cb684..7d00443 100644
+--- a/fuzzing/fuzz_key.c
++++ b/fuzzing/fuzz_key.c
+@@ -26,11 +26,20 @@ test_parse (const gchar *data,
+ GKeyFileFlags flags)
+ {
+ GKeyFile *key = NULL;
++ char *comment = NULL;
++ char **list = NULL;
+
+ key = g_key_file_new ();
+ g_key_file_load_from_data (key, (const gchar*) data, size, G_KEY_FILE_NONE,
+ NULL);
+
++ /* Also try some additional parsing and see if it crashes */
++ comment = g_key_file_get_comment (key, "group", "key", NULL);
++ g_free (comment);
++
++ list = g_key_file_get_locale_string_list (key, "group", "key", "de", NULL, NULL);
++ g_strfreev (list);
++
+ g_key_file_free (key);
+ }
+
+diff --git a/glib/gkeyfile.c b/glib/gkeyfile.c
+index d08a485..54d77a5 100644
+--- a/glib/gkeyfile.c
++++ b/glib/gkeyfile.c
+@@ -2421,7 +2421,7 @@ g_key_file_get_locale_string_list (GKeyFile *key_file,
+ }
+
+ len = strlen (value);
+- if (value[len - 1] == key_file->list_separator)
++ if (len > 0 && value[len - 1] == key_file->list_separator)
+ value[len - 1] = '\0';
+
+ list_separator[0] = key_file->list_separator;
+diff --git a/glib/tests/keyfile.c b/glib/tests/keyfile.c
+index bc125c1..289bd2b 100644
+--- a/glib/tests/keyfile.c
++++ b/glib/tests/keyfile.c
+@@ -850,6 +850,28 @@ test_locale_string_multiple_loads (void)
+ g_free (old_locale);
+ }
+
++static void
++test_locale_string_empty (void)
++{
++ GKeyFile *keyfile = NULL;
++ GError *local_error = NULL;
++ const char *data =
++ "[valid]\n"
++ "key1=\n";
++
++ g_test_summary ("Check that loading an empty translatable string works");
++ g_test_bug ("https://gitlab.gnome.org/GNOME/glib/-/issues/3930");
++
++ keyfile = g_key_file_new ();
++
++ g_key_file_load_from_data (keyfile, data, -1, G_KEY_FILE_NONE, &local_error);
++ g_assert_no_error (local_error);
++
++ check_locale_string_list_value (keyfile, "valid", "key1", NULL, NULL);
++
++ g_key_file_free (keyfile);
++}
++
+ static void
+ test_lists (void)
+ {
+@@ -1939,6 +1961,7 @@ main (int argc, char *argv[])
+ g_test_add_func ("/keyfile/number", test_number);
+ g_test_add_func ("/keyfile/locale-string", test_locale_string);
+ g_test_add_func ("/keyfile/locale-string/multiple-loads", test_locale_string_multiple_loads);
++ g_test_add_func ("/keyfile/locale-string/empty", test_locale_string_empty);
+ g_test_add_func ("/keyfile/lists", test_lists);
+ g_test_add_func ("/keyfile/lists-set-get", test_lists_set_get);
+ g_test_add_func ("/keyfile/group-remove", test_group_remove);
diff --git a/meta/recipes-core/glib-2.0/glib-2.0_2.78.6.bb b/meta/recipes-core/glib-2.0/glib-2.0_2.78.6.bb
index 9516231cbad..e15aa1fe206 100644
--- a/meta/recipes-core/glib-2.0/glib-2.0_2.78.6.bb
+++ b/meta/recipes-core/glib-2.0/glib-2.0_2.78.6.bb
@@ -53,6 +53,7 @@ SRC_URI = "${GNOME_MIRROR}/glib/${SHRT_VER}/glib-${PV}.tar.xz \
file://CVE-2026-58011.patch \
file://CVE-2026-58012.patch \
file://CVE-2026-58013.patch \
+ file://CVE-2026-58014.patch \
"
SRC_URI:append:class-native = " file://relocate-modules.patch \
file://0001-meson.build-do-not-enable-pidfd-features-on-native-g.patch \
^ permalink raw reply related [flat|nested] 32+ messages in thread
* [OE-core][scarthgap 30/31] gzip: Fix CVE-2026-41991
2026-07-26 8:29 [OE-core][scarthgap 00/31] Patch review Yoann Congal
` (28 preceding siblings ...)
2026-07-26 8:29 ` [OE-core][scarthgap 29/31] glib-2.0: fix CVE-2026-58014 Yoann Congal
@ 2026-07-26 8:29 ` Yoann Congal
2026-07-26 8:29 ` [OE-core][scarthgap 31/31] bzip2: fix 'bzip2 --version > /tmp/aaa 2>&1' hang Yoann Congal
30 siblings, 0 replies; 32+ messages in thread
From: Yoann Congal @ 2026-07-26 8:29 UTC (permalink / raw)
To: openembedded-core
From: Darsh Kelaiya <dkelaiya@cisco.com>
This patch applies the upstream fix for CVE-2026-41991 as referenced
in [2], using the upstream commit identified in [1].
[1] https://cgit.git.savannah.gnu.org/cgit/gzip.git/commit/?id=4e6f8b24ab823146ab8776f0b7fe486ab34d4269
[2] https://nvd.nist.gov/vuln/detail/CVE-2026-41991
Signed-off-by: Darsh Kelaiya <dkelaiya@cisco.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
---
.../gzip/gzip-1.13/CVE-2026-41991.patch | 75 +++++++++++++++++++
meta/recipes-extended/gzip/gzip_1.13.bb | 1 +
2 files changed, 76 insertions(+)
create mode 100644 meta/recipes-extended/gzip/gzip-1.13/CVE-2026-41991.patch
diff --git a/meta/recipes-extended/gzip/gzip-1.13/CVE-2026-41991.patch b/meta/recipes-extended/gzip/gzip-1.13/CVE-2026-41991.patch
new file mode 100644
index 00000000000..9728b38658d
--- /dev/null
+++ b/meta/recipes-extended/gzip/gzip-1.13/CVE-2026-41991.patch
@@ -0,0 +1,75 @@
+From 0af3a96047fe02690473d4e106c39552e0c1285e Mon Sep 17 00:00:00 2001
+From: Paul Eggert <eggert@cs.ucla.edu>
+Date: Thu, 16 Apr 2026 12:11:44 -0700
+Subject: [PATCH] gzexe: use -C if lacking mktemp
+MIME-Version: 1.0
+Content-Type: text/plain; charset=UTF-8
+Content-Transfer-Encoding: 8bit
+
+(Problem reported by Michał Majchrowicz.)
+* gzexe.in: If mktemp is needed but not installed,
+use ‘set -C’ to avoid a race when creating a temporary file.
+* zdiff.in: Use the same pattern here, even though the old
+code was probably OK anyway.
+
+CVE: CVE-2026-41991
+Upstream-Status: Backport [https://cgit.git.savannah.gnu.org/cgit/gzip.git/commit/?id=4e6f8b24ab823146ab8776f0b7fe486ab34d4269]
+
+(cherry picked from commit 4e6f8b24ab823146ab8776f0b7fe486ab34d4269)
+Signed-off-by: Darsh Kelaiya <dkelaiya@cisco.com>
+---
+ NEWS | 5 +++++
+ gzexe.in | 1 +
+ zdiff.in | 7 +++----
+ 3 files changed, 9 insertions(+), 4 deletions(-)
+
+diff --git a/NEWS b/NEWS
+index 6a20892..c643b2f 100644
+--- a/NEWS
++++ b/NEWS
+@@ -1,5 +1,10 @@
+ GNU gzip NEWS -*- outline -*-
+
++ On old-fashioned or limited platforms lacking mktemp, gzexe and
++ zdiff no longer have a race when creating a temporary file.
++ [bug present since the beginning]
++
++
+ * Noteworthy changes in release 1.13 (2023-08-19) [stable]
+
+ ** Changes in behavior
+diff --git a/gzexe.in b/gzexe.in
+index 5e3d4c2..f31b9c8 100644
+--- a/gzexe.in
++++ b/gzexe.in
+@@ -128,6 +128,7 @@ for i do
+ tmp=`mktemp "${dir}gzexeXXXXXXXXX"`
+ else
+ tmp=${dir}gzexe$$
++ (umask 77; set -C; > "$tmp")
+ fi && { cp -p "$file" "$tmp" 2>/dev/null || cp "$file" "$tmp"; } || {
+ res=$?
+ printf >&2 '%s\n' "$0: cannot copy $file"
+diff --git a/zdiff.in b/zdiff.in
+index e35e6fe..bbcc75b 100644
+--- a/zdiff.in
++++ b/zdiff.in
+@@ -157,12 +157,11 @@ case $file2 in
+ *) TMPDIR=/tmp/;;
+ esac
+ if type mktemp >/dev/null 2>&1; then
+- tmp=`mktemp "${TMPDIR}zdiffXXXXXXXXX"` ||
+- exit 2
++ tmp=`mktemp "${TMPDIR}zdiffXXXXXXXXX"`
+ else
+- set -C
+ tmp=${TMPDIR}zdiff$$
+- fi
++ (umask 77; set -C; > "$tmp")
++ fi &&
+ 'gzip' -cdfq -- "$file2" > "$tmp" || exit 2
+ gzip_status=$(
+ exec 4>&1
+--
+2.44.4
+
diff --git a/meta/recipes-extended/gzip/gzip_1.13.bb b/meta/recipes-extended/gzip/gzip_1.13.bb
index 208220867a6..4ab3b1d523c 100644
--- a/meta/recipes-extended/gzip/gzip_1.13.bb
+++ b/meta/recipes-extended/gzip/gzip_1.13.bb
@@ -7,6 +7,7 @@ LICENSE = "GPL-3.0-or-later"
SRC_URI = "${GNU_MIRROR}/gzip/${BP}.tar.gz \
file://run-ptest \
file://CVE-2026-41992.patch \
+ file://CVE-2026-41991.patch \
"
SRC_URI:append:class-target = " file://wrong-path-fix.patch"
^ permalink raw reply related [flat|nested] 32+ messages in thread
* [OE-core][scarthgap 31/31] bzip2: fix 'bzip2 --version > /tmp/aaa 2>&1' hang
2026-07-26 8:29 [OE-core][scarthgap 00/31] Patch review Yoann Congal
` (29 preceding siblings ...)
2026-07-26 8:29 ` [OE-core][scarthgap 30/31] gzip: Fix CVE-2026-41991 Yoann Congal
@ 2026-07-26 8:29 ` Yoann Congal
30 siblings, 0 replies; 32+ messages in thread
From: Yoann Congal @ 2026-07-26 8:29 UTC (permalink / raw)
To: openembedded-core
From: Hongxu Jia <hongxu.jia@windriver.com>
According to [1]
As of the current version 1.0.8, bzip2 --version will print version
info but it will also continue compressing stdin:
$ ./bzip2 --version
bzip2, a block-sorting file compressor. Version 1.0.8, 13-Jul-2019.
Copyright (C) 1996-2019 by Julian Seward.
This program is free software; [...]
bzip2: I won't write compressed data to a terminal.
bzip2: For help, type: `bzip2 --help'.
This is a long-standing bug, not new to 1.0.8 -- the same code
(license() followed by break, with no exit) exists in bzip2 1.0.6 and
earlier. The upstream bzip2 master branch on GitLab already includes
this fix.
Debian (and its downstreams like Ubuntu) will patch this out [2],
making the < /dev/null unnecessary, port a part of debian patch
to fix the issue
[1] https://stackoverflow.com/questions/59757176/why-using-dev-null-with-a-program-like-bzip2
[2] https://sources.debian.org/src/bzip2/1.0.8-6/debian/patches/20-legacy.patch/
Signed-off-by: Hongxu Jia <hongxu.jia@windriver.com>
Signed-off-by: Mathieu Dubois-Briand <mathieu.dubois-briand@bootlin.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
(cherry picked from commit ae4fe4263ba9d372f9b9e80df4ec4697b51c1f9b)
[Jaipaul: backport to scarthgap -- added commit message context that this is a
long-standing bug (not new to 1.0.8), updated Upstream-Status in patch
to actual mailing list URL in the patch file, this patch is already present on master,
wrynose and walnascar branches using the same bzip2 1.0.8]
Signed-off-by: Jaipaul Cheernam <jaipaul.cheernam@est.tech>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
---
...-fix-bzip2-version-tmp-aaa-will-hang.patch | 65 +++++++++++++++++++
meta/recipes-extended/bzip2/bzip2_1.0.8.bb | 1 +
2 files changed, 66 insertions(+)
create mode 100644 meta/recipes-extended/bzip2/bzip2/0001-fix-bzip2-version-tmp-aaa-will-hang.patch
diff --git a/meta/recipes-extended/bzip2/bzip2/0001-fix-bzip2-version-tmp-aaa-will-hang.patch b/meta/recipes-extended/bzip2/bzip2/0001-fix-bzip2-version-tmp-aaa-will-hang.patch
new file mode 100644
index 00000000000..2d02328d116
--- /dev/null
+++ b/meta/recipes-extended/bzip2/bzip2/0001-fix-bzip2-version-tmp-aaa-will-hang.patch
@@ -0,0 +1,65 @@
+From a9dd6acbaca836fc4e943e69a31b2e7acda32045 Mon Sep 17 00:00:00 2001
+From: Hongxu Jia <hongxu.jia@windriver.com>
+Date: Wed, 13 Nov 2024 19:49:23 +0800
+Subject: [PATCH] fix 'bzip2 --version > /tmp/aaa 2>&1' hang
+
+According to [1]
+
+As of the current version 1.0.8, bzip2 --version will print version
+info but it will also continue compressing stdin:
+
+ $ ./bzip2 --version
+ bzip2, a block-sorting file compressor. Version 1.0.8, 13-Jul-2019.
+
+ Copyright (C) 1996-2019 by Julian Seward.
+
+ This program is free software; [...]
+
+ bzip2: I won't write compressed data to a terminal.
+ bzip2: For help, type: `bzip2 --help'.
+
+Debian (and its downstreams like Ubuntu) will patch this out [2],
+making the < /dev/null unnecessary:
+
+[1] https://stackoverflow.com/questions/59757176/why-using-dev-null-with-a-program-like-bzip2
+[2] https://sources.debian.org/src/bzip2/1.0.8-6/debian/patches/20-legacy.patch/
+
+Upstream-Status: Submitted [https://sourceware.org/pipermail/bzip2-devel/2024q4/000234.html]
+Note: updated Upstream-Status URL to point to the actual mailing list
+archive entry.
+
+Signed-off-by: Hongxu Jia <hongxu.jia@windriver.com>
+Signed-off-by: Jaipaul Cheernam <jaipaul.cheernam@est.tech>
+---
+ bzip2.c | 8 +++++---
+ 1 file changed, 5 insertions(+), 3 deletions(-)
+
+diff --git a/bzip2.c b/bzip2.c
+index d95d280..6ec9871 100644
+--- a/bzip2.c
++++ b/bzip2.c
+@@ -1890,7 +1890,9 @@ IntNative main ( IntNative argc, Char *argv[] )
+ case '8': blockSize100k = 8; break;
+ case '9': blockSize100k = 9; break;
+ case 'V':
+- case 'L': license(); break;
++ case 'L': license();
++ exit ( 0 );
++ break;
+ case 'v': verbosity++; break;
+ case 'h': usage ( progName );
+ exit ( 0 );
+@@ -1916,8 +1918,8 @@ IntNative main ( IntNative argc, Char *argv[] )
+ if (ISFLAG("--keep")) keepInputFiles = True; else
+ if (ISFLAG("--small")) smallMode = True; else
+ if (ISFLAG("--quiet")) noisy = False; else
+- if (ISFLAG("--version")) license(); else
+- if (ISFLAG("--license")) license(); else
++ if (ISFLAG("--version")) { license(); exit ( 0 ); } else
++ if (ISFLAG("--license")) { license(); exit ( 0 ); } else
+ if (ISFLAG("--exponential")) workFactor = 1; else
+ if (ISFLAG("--repetitive-best")) redundant(aa->name); else
+ if (ISFLAG("--repetitive-fast")) redundant(aa->name); else
+--
+2.34.1
+
diff --git a/meta/recipes-extended/bzip2/bzip2_1.0.8.bb b/meta/recipes-extended/bzip2/bzip2_1.0.8.bb
index b661bc95465..6c02dc3ed06 100644
--- a/meta/recipes-extended/bzip2/bzip2_1.0.8.bb
+++ b/meta/recipes-extended/bzip2/bzip2_1.0.8.bb
@@ -27,6 +27,7 @@ SRC_URI = "https://sourceware.org/pub/${BPN}/${BPN}-${PV}.tar.gz \
file://Makefile.am;subdir=${BP} \
file://run-ptest \
file://CVE-2026-42250.patch;subdir=${BP} \
+ file://0001-fix-bzip2-version-tmp-aaa-will-hang.patch;subdir=${BP} \
"
SRC_URI[md5sum] = "67e051268d0c475ea773822f7500d0e5"
SRC_URI[sha256sum] = "ab5a03176ee106d3f0fa90e381da478ddae405918153cca248e682cd0c4a2269"
^ permalink raw reply related [flat|nested] 32+ messages in thread
end of thread, other threads:[~2026-07-26 8:30 UTC | newest]
Thread overview: 32+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-07-26 8:29 [OE-core][scarthgap 00/31] Patch review Yoann Congal
2026-07-26 8:29 ` [OE-core][scarthgap 01/31] scripts/install-buildtools: Update to 5.0.19 Yoann Congal
2026-07-26 8:29 ` [OE-core][scarthgap 02/31] linux-yocto/6.6: update to v6.6.143 Yoann Congal
2026-07-26 8:29 ` [OE-core][scarthgap 03/31] linux-yocto/6.6: update to v6.6.144 Yoann Congal
2026-07-26 8:29 ` [OE-core][scarthgap 04/31] linux-yocto/6.6: update CVE exclusions (6.6.144) Yoann Congal
2026-07-26 8:29 ` [OE-core][scarthgap 05/31] libxml2: Fix CVE-2026-11979 Yoann Congal
2026-07-26 8:29 ` [OE-core][scarthgap 06/31] openssh: Fix CVE-2026-59999 Yoann Congal
2026-07-26 8:29 ` [OE-core][scarthgap 07/31] openssh: Fix CVE-2026-59997 Yoann Congal
2026-07-26 8:29 ` [OE-core][scarthgap 08/31] openssh: Fix CVE-2026-59996 Yoann Congal
2026-07-26 8:29 ` [OE-core][scarthgap 09/31] openssh: Fix CVE-2026-59995 Yoann Congal
2026-07-26 8:29 ` [OE-core][scarthgap 10/31] openssh: Fix CVE-2026-60001 Yoann Congal
2026-07-26 8:29 ` [OE-core][scarthgap 11/31] openssh: Fix CVE-2026-60002 Yoann Congal
2026-07-26 8:29 ` [OE-core][scarthgap 12/31] openssh: Fix CVE-2026-60000 Yoann Congal
2026-07-26 8:29 ` [OE-core][scarthgap 13/31] cups: fix CVE-2026-27447 Yoann Congal
2026-07-26 8:29 ` [OE-core][scarthgap 14/31] cups: fix CVE-2026-41079 Yoann Congal
2026-07-26 8:29 ` [OE-core][scarthgap 15/31] cups: fix CVE-2026-34978 Yoann Congal
2026-07-26 8:29 ` [OE-core][scarthgap 16/31] cups: fix CVE-2026-34980 Yoann Congal
2026-07-26 8:29 ` [OE-core][scarthgap 17/31] cups: fix CVE-2026-34979 Yoann Congal
2026-07-26 8:29 ` [OE-core][scarthgap 18/31] cups: fix CVE-2026-34990 Yoann Congal
2026-07-26 8:29 ` [OE-core][scarthgap 19/31] cups: fix CVE-2026-39314 Yoann Congal
2026-07-26 8:29 ` [OE-core][scarthgap 20/31] cups: fix CVE-2026-39316 Yoann Congal
2026-07-26 8:29 ` [OE-core][scarthgap 21/31] libxpm: fix CVE-2026-4367 Yoann Congal
2026-07-26 8:29 ` [OE-core][scarthgap 22/31] gnutls: set status for CVE-2026-3832 Yoann Congal
2026-07-26 8:29 ` [OE-core][scarthgap 23/31] gnutls: fix CVE-2026-42009 Yoann Congal
2026-07-26 8:29 ` [OE-core][scarthgap 24/31] libpng: Fix CVE-2026-34757 Yoann Congal
2026-07-26 8:29 ` [OE-core][scarthgap 25/31] glib-2.0: fix CVE-2026-58010 Yoann Congal
2026-07-26 8:29 ` [OE-core][scarthgap 26/31] glib-2.0: fix CVE-2026-58011 Yoann Congal
2026-07-26 8:29 ` [OE-core][scarthgap 27/31] glib-2.0: fix CVE-2026-58012 Yoann Congal
2026-07-26 8:29 ` [OE-core][scarthgap 28/31] glib-2.0: fix CVE-2026-58013 Yoann Congal
2026-07-26 8:29 ` [OE-core][scarthgap 29/31] glib-2.0: fix CVE-2026-58014 Yoann Congal
2026-07-26 8:29 ` [OE-core][scarthgap 30/31] gzip: Fix CVE-2026-41991 Yoann Congal
2026-07-26 8:29 ` [OE-core][scarthgap 31/31] bzip2: fix 'bzip2 --version > /tmp/aaa 2>&1' hang Yoann Congal
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.